arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

认知准入控制:智能体分布式系统中后果性行动的风险条件化保证

Cognitive Admission Control: Risk-Conditioned Assurance for Consequential Actions in Agentic Distributed Systems

Jun He, Deying Yu

arXiv 2609.16313首次发表:更新:

AI 中文总结

针对智能体分布式系统中行动证据不足的问题,提出认知准入控制方法,通过策略映射风险到保证义务并形式化准入演算,原型测试表明在受控试验中实现无有害效果完成。

AI 中文摘要

在智能体分布式系统中,智能体可能被授权修改外部基础设施,但缺乏该修改已准备好执行的证据。认知准入控制(CAC)使这一证据要求变得明确。策略将类型化行动及其建模风险映射到保证义务,这些义务指定谓词、证据类别、范围、新鲜度和见证集约束。确定性评估器区分已满足、已违反和未解决的义务;未解决的条件会产生针对性的证据获取请求。成功的准入产生一个证书,将行动、其见证清单和派发时防护绑定在一起。我们形式化了准入演算以及将其与中介执行联系起来的假设。这些保证是策略相对的:物理安全额外要求可靠的证据、充分的环境模型,以及通过效果保持相关条件。一个TypeScript原型在2,730次受控本地试验中进行了评估,这些试验具有独立的效果观察和匹配的故障调度。在390次CAC试验中,120个效果在无建模伤害的情况下完成,且未发生有害效果。一个实时策略基线实现了相同的完成次数,但接纳了构造的相关见证故障。机制消融隔离了防护、证据类别、结构切割和修复行为。另有9,000次测量执行了具有持久重放保护的完整本地派发路径。这些结果确立了已测试的实现行为和本地成本,而非生产故障率或语言模型能力的比较。

英文摘要

In agentic distributed systems, an agent may be authorized to mutate external infrastructure while lacking evidence that the mutation is ready to execute. Cognitive Admission Control (CAC) makes this evidence requirement explicit. A policy maps a typed action and its modeled risk to assurance obligations specifying predicates, evidence classes, scope, freshness, and witness-set constraints. A deterministic evaluator distinguishes satisfied, violated, and unresolved obligations; unresolved conditions produce targeted evidence-acquisition requests. Successful admission produces a certificate binding the action, its witness manifest, and dispatch-time guards. We formalize the admission calculus and the assumptions connecting it to mediated execution. The guarantees are policy-relative: physical safety additionally requires sound evidence, an adequate environment model, and preservation of relevant conditions through the effect. A TypeScript prototype is evaluated in 2,730 controlled local trials with independent effect observation and matched fault schedules. Across 390 CAC trials, 120 effects complete without modeled harm and no harmful effects occur. A live-policy baseline achieves the same completion count but admits the constructed correlated-witness failure. Mechanism ablations isolate guard, evidence-class, structural-cut, and remediation behavior. A further 9,000 measurements exercise the complete local dispatch path with persistent replay protection. These results establish tested implementation behaviors and local costs, not production failure rates or comparisons of language-model capability.

Comments15 pages, 1 figure, 2 tables; includes formal proofs, obligation catalogue, and empirical local evaluation

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑