临时可达性:通过使每次穿越可撤销来控制智能体
Provisional Reachability: Containing Agents by Making Every Crossing Revocable
- School of Law, Waseda University(早稻田大学法学部)
机构由 AI 辅助整理,请以论文原文为准。
AI总结:
本文提出临时可达性方案,通过托管穿越并概率审计撤销窗口,将智能体泄漏从10万比特降至59比特,并证明密钥化窗口可在不增加泄漏下恢复全部合法工作。
AI中文摘要:
一篇配套论文发现,防御者随时间必须阻止的内容具有单位:每周期比特数 [Takashita, 2026a]。本文确定了该数值。将每次穿越托管一个周期,以概率 r 独立审计每个托管项,若任何审计发现问题则撤销窗口。一个穿越 k 次、每次携带 c 比特的对手,预期为 kc(1-r)^k,在 k* = 1/ln(1/(1-r)) 处最大化,每窗口界限为 L(r) ~ c/(er)。该界限是对手选择的上确界,因此方案可以是公开的;模拟与理论匹配至 7.7 个标准误。这是一个速率而非总量:仅托管仍会让秘密在每次运行中组装。但若秘密以每周期托管比特的 μ 比例衰减,则持有量在任何时间范围收敛至 g/μ,因此一旦 μ > g/L,L 比特的秘密就不可达——这是 Eigen 意义上的错误阈值,其位置与闭式解吻合(在 20,000 个窗口上,0.9μ* 处 100% 运行组装,2μ* 处 0%)。需要对手推理失误的欺骗策略失败:名称撒谎的表面在 18 次中留下 18 次准确率,且在三种读取器强度下均为 100%。保留参考有效且方式不同:没有读取器会承诺。对入口点进行密钥化隐藏了模块行为的 0.10 比特;对指称进行密钥化在随机准确率下隐藏了 3.00 中的 2.64 比特,而 100% 的读取器仍称其为普通 Python。方差必须从审计率中移除,其中战利品在 r 上是凸的,并添加到激活预算中,其中生存是乘性的:在固定均值下,灭绝率从 70% 到 100%。端到端堆栈将泄漏从 100,000 降至 59 比特,因子为 1,704,留下 12% 的合法工作;将窗口密钥化到调用者可在无泄漏成本下将其恢复至 100%,代价是界限按主体计算。在 65 个只读工具中,托管每次调用留下 2,400 比特:因子为 10,而非无穷。
英文摘要:
A companion paper found that what a defender must block over time has units: bits per period [Takashita, 2026a]. This paper sets it. Hold every crossing in escrow for one period, audit each held item independently with probability r, and revoke the window if any audit catches something. An adversary crossing k times, each carrying c bits, expects kc(1-r)^k, maximised at k* = 1/ln(1/(1-r)), a bound of L(r) ~ c/(er) per window. The bound is a supremum over the adversary's choice, so the scheme may be public; simulation matches it to 7.7 standard errors. It is a rate, not a total: escrow alone still lets the secret assemble in every run. But if the secret decays at a fraction mu of held bits per period, holdings converge to g/mu at any horizon, so an L-bit secret is unreachable once mu > g/L -- an error threshold in Eigen's sense, sharp where the closed form puts it (100% of runs assemble at 0.9mu*, 0% at 2mu*, over 20,000 windows). Deception that needs the adversary to reason badly fails: a surface whose names lie left accuracy at 18 of 18, and 100% at three reader strengths. Withholding reference works, and differently: no reader would commit at all. Keying the entry points hides 0.10 bits of what a module does; keying the denotation hides 2.64 of 3.00 at chance accuracy, while 100% of readers still call it ordinary Python. Variance must be removed from the audit rate, where loot is convex in r, and added to the activation budget, where survival is multiplicative: extinction 70% to 100% at a fixed mean. End to end the stack takes the leak from 100,000 to 59 bits, a factor of 1,704, leaving 12% of legitimate work standing; keying the window to the caller restores that to 100% at no cost in leakage, at the price of a bound that is per principal. Of 65 read-only tools, escrow leaves 2,400 bits per call: a factor of 10, not infinity.