arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

自主性受限:边缘环境中基于治理器的自适应安全

Autonomy in Check: Governor-Mediated Adaptive Security at the Edge

Ijaz Ahmad, Ijaz Ahmad, Flavio Esposito, Erkki Harjula

arXiv 2609.18338首次发表:更新:

发表机构

University of Oulu; VTT Technical Research Centre of Finland; Saint Louis University(奥卢大学; 芬兰VTT技术研究中心; 圣路易斯大学)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

针对边缘自适应安全中规划器输出可能产生语义错误动作的问题,提出分裂控制架构,通过确定性治理器检查安全等不变量,仅接纳合法意图并编译为eBPF更新,实验证明微秒级开销且不干扰受保护流。

AI 中文摘要

网络边缘的自适应安全日益依赖于自动化规划器,包括基于规则的控制器、学习策略和LLM辅助代理,这些规划器将观测结果转化为执行动作。一旦这样的规划器能够影响实时策略状态,语法有效性就不够了。由不完整或被操纵的观测结果产生的语义错误动作,可能会被无法判断任务上下文的执行底层忠实执行。我们通过将规划器输出与内核执行输入之间的边界视为主要安全对象来解决这一问题。我们提出了一种分裂控制架构,其中不可信的规划器发出类型化的安全意图,一个确定性的治理器根据安全性、资源、时间稳定性和比例性不变量检查每个意图,只有被接纳的动作才被绑定到签名收据并编译为预安装的eBPF映射更新。本文形式化了这一信任边界问题,定义了三个威胁类别,开发了治理器接纳谓词,并报告了一个端到端原型。在连接到大学5G测试网络的Raspberry Pi 5测试平台上,针对基于规则和LLM辅助的规划器,治理器以微秒级成本接纳、拒绝和限制意图,而不干扰受保护流的规律性。该贡献既是概念性的,也是实证性的:自适应安全不需要信任动作的作者。它需要一个决定动作是否可接纳的调解边界。

英文摘要

Adaptive security at the network edge increasingly relies on automated planners, including rule-based controllers, learned policies, and LLM-assisted agents, that translate observations into enforcement actions. Once such a planner can influence live policy state, syntactic validity is not enough. A semantically wrong action, produced from incomplete or manipulated observations, can be faithfully executed by an enforcement substrate that cannot judge mission context. We address this problem by treating the boundary between planner output and kernel enforcement input as the primary security object. We propose a split-control architecture in which an untrusted planner emits typed security intents, a deterministic governor checks each intent against safety, resource, temporal-stability, and proportionality invariants, and only admitted actions are bound to signed receipts and compiled into pre-installed eBPF map updates. The paper formalizes this trust-boundary problem, defines three threat classes, develops the governor admission predicate, and reports an end-to-end prototype. Across rule-based and LLM-assisted planners on a Raspberry Pi 5 testbed connected to the university 5G Test Network, the governor admits, rejects, and bounds intents at microsecond cost without disrupting protected-flow regularity. The contribution is conceptual as much as empirical: adaptive security does not need to trust the author of an action. It needs a mediation boundary that decides whether the action is admissible.

Comments9 pages, 7 figures

Journal refIEEE Conference on Communications and Network Security 2026

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑