arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2609.31282cs.CRcs.AI

基于区块链的资源优化与能量感知智能体AI框架,用于安全的软件供应链

Resource-Optimized and Energy-Aware Agentic AI Framework Anchored on Blockchain for Secure Software Supply Chains

  • Islamic University in Madinah(麦地那伊斯兰大学)

机构由 AI 辅助整理,请以论文原文为准。

Toqeer Ali Syed, Asadullah Abdullah Khan

AI总结:

提出基于区块链的智能体安全框架,协调多个LLM驱动的安全智能体覆盖SDLC,通过链上签名证明和智能合约实现可信审计与可验证部署决策,提供去中心化完整性保障。

AI中文摘要:

本文提出了一种基于区块链的智能体安全框架,旨在保护完整的软件开发生命周期(SDLC),同时确保负责监控该生命周期的智能体AI组件安全。该框架协调一组专门的安全智能体,涵盖源代码完整性、依赖项和SBOM分析、CI配置审计、工件验证以及运行时策略评估,每个智能体均由一个大型语言模型(LLM)支持,该模型解释工件、对工具输出进行推理并生成结构化的安全报告。为确保智能体的可信度,每个智能体生成一个加密签名的证明,该证明通过智能合约记录在许可区块链中,包括智能体注册表、不可变证明日志和可执行的发布策略模块。智能体之间以及与区块链节点之间的通信通过联盟运营的证书颁发机构进行保护,确保经过身份验证且防篡改的交互。一个详细的用例和序列流程展示了源代码安全智能体如何执行分析、将其证明锚定在链上,并触发可验证的允许/阻止部署决策。所提出的框架提供了去中心化的完整性、透明的来源、不间断的安全保障以及一个可泛化的架构,以将智能体AI整合到现代软件供应链安全中。

英文摘要:

This paper proposes a blockchain-backed agentic security framework designed to safeguard the complete software development lifecycle (SDLC) while also securing the agentic AI components responsible for monitoring it. The framework coordinates a set of specialised security agents, covering source integrity, dependency and SBOM analysis, CI configura tion auditing, artifact verification, and runtime policy evaluation, each supported by a large language model (LLM) that interprets artefacts, reasons over tool outputs, and produces structured security reports. To ensure agent trustworthiness, every agent generates a cryptographically signed attestation that is recorded in a permissioned blockchain via smart contracts, including an agent registry, an immutable attestation log, and an enforceable release-policy module. Communication among agents and with blockchain nodes is secured using a consortium-operated certificate authority, ensuring authenticated and tamper-resistant interactions. A detailed use-case and sequence flow demonstrate how a source code security agent performs analysis, anchors its attestation on-chain, and triggers a verifiable allow/block deployment decision. The proposed framework of fers decentralised integrity transparent provenance, uninterrupted security assurance and a generalisable architecture to incorporate the agentic AI into the modern software supply chain security.

补充信息

↑