AI 中文总结
针对多智能体工作流中消息选择泄露私有状态的问题,提出选择不变通信编译器(SICC),通过约束授权后表示核实现隐私保证,并在实验验证中保持协议效用。
AI 中文摘要
结构化多智能体工作流交换中间消息,即使最终输出是安全的,这些消息的内容和形式也可能泄露私有状态。我们识别出选择通道泄露:在授权固定了可发布内容之后,对语义有效实现进行私有状态感知的选择会创建额外的推理通道。我们引入了选择不变通信编译器(SICC),它约束这个授权后的表示核而不是规定模板。任何满足不变性的确定性或独立公开随机生成器都是有效的;按需求索引的规范形式是一种可审计的实现。我们证明了一个组合式通信层保证:授权、仅公开形式生成和依赖安全的效用门使得发出的记录不泄露超出完整授权视图的任何信息。在表面不相交和长度匹配的控制之后,私有状态感知的选择仍然存在漏洞。在132次AgentLeak通信重放和100个可执行的LangGraph任务中,确定性SICC在没有正超额增益信号的情况下保留了完整的协议效用;独立的公开随机化在AgentLeak和480个受控案例中保持了相同的结果。
英文摘要
Structured multi-agent workflows exchange intermediate messages whose content and form can reveal private state even when the final output is safe. We identify selection-channel leakage: after authorization fixes what may be released, a private-state-aware choice among semantically valid realizations creates an additional inference channel. We introduce the selection-invariant communication compiler(SICC), which constrains this post-authorization representation kernel rather than prescribing templates. Any deterministic or independently public-randomized generator satisfying the invariant is valid; requirement-indexed canonical forms are one auditable implementation. We prove a compositional communication-layer guarantee: authorization, public-only form generation, and a dependency-safe utility gate make the emitted transcript reveal no information beyond the complete authorized view. Private-state-aware selection remains vulnerable after surface-disjoint and length-matched controls. Across 132 AgentLeak communication replays and 100 executable LangGraph tasks, deterministic SICC retains complete protocol utility without a positive excess-gain signal; independent public randomization preserves the same result in AgentLeak and 480 controlled cases.