arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2609.35234cs.CR

Poster: 迈向ProofWeave:面向持续智能体安全保障的隐私最小化、完整性锚定证据平面

Poster: Towards ProofWeave: A Privacy-Minimised, Integrity-Anchored Evidence Plane for Continuous Agentic Assurance

  • Swinburne University of Technology(斯威本科技大学)
  • CSIRO(澳大利亚联邦科学与工业研究组织)
  • City University of Hong Kong(香港城市大学)

机构由 AI 辅助整理,请以论文原文为准。

Guy Lupo, Nguyen Hung Nguyen, Viet Vo, Chamikara M. A. P., Guangdong Bai

更新

AI总结:

针对智能体AI系统现有可观测机制缺乏同期策略合规证据的问题,提出ProofWeave记录时证据链框架,通过绑定操作、控制响应与策略快照生成锚定完整性的最小隐私证据,实验验证其在判决效率、隐私保护等多方面性能显著优于仅日志基线。

AI中文摘要:

智能体AI系统越来越多地通过工具、内存、委派和外部服务执行操作。现有的可观测性和溯源机制可以事后重构事件,但它们很少能在记录时证明每个与策略相关的操作在执行前都经过了预期控制的检查。这给持续监控、检测和响应留下了信任-可观测性缺口:后续的安全保障可能依赖于不完整、泄露隐私、可篡改或与事件当时的策略上下文脱节的证据。现有文献中缺失的是,能够证明预期控制已根据当时生效的策略完成评估的、与策略绑定的同期证据。\n 我们提出了ProofWeave,一种用于智能体AI安全保障的记录时证据链概念。在每个与策略相关的操作边界,ProofWeave会生成一笔隐私最小化且完整性锚定的证据交易,该交易绑定了(i)智能体意图或操作、(ii)控制响应以及(iii)当时的策略快照。每笔交易都会被提交到仅追加式账本中,并具体化为一个派生证明图。一个有界的Weaver Agent(织网智能体)将策略意图转化为证明义务,而确定性验证器会检查证据的完整性、隐私最小化程度、策略绑定性和完整性。\n 在最小场景中,一个智能体试图将秘密传输到未经批准的外部接收端。审计工作在判决延迟、关联歧义性、隐私暴露程度、篡改检测能力和对纯图证明注入的抵抗力这几个维度上,对比了仅日志关联基线与ProofWeave的表现。ProofWeave将每次判决的候选绑定数从最高10201个减少到1个,验证操作数从最高10201次减少到约26次,每个项目的安全保障证据存储量从0.79MiB减少到0.15MiB。

英文摘要:

Agentic AI systems increasingly act via tools, memory, delegation, and external services. Existing observability and provenance mechanisms can reconstruct events post hoc, but they rarely show, at the time of the record, whether each policy-relevant action was checked by the intended control before execution. This leaves a trust-observability gap for continuous monitoring, detection, and response: later assurance may rest on evidence that is incomplete, privacy-leaking, mutable, or detached from the policy context that governed the event. What's missing in the literature is contemporaneous, policy-bound evidence that the intended control was evaluated under the policy in force at the time. We introduce ProofWeave, a record-time chain-of-evidence concept for agentic AI assurance. At each policy-relevant action boundary, ProofWeave generates a privacy-minimised and integrity-anchored evidence transaction that binds (i) agent intent or action, (ii) control response, and (iii) a policy-at-time snapshot. Each transaction is committed to an append-only ledger and materialised into a derived proof graph. A bounded Weaver Agent translates policy intent into proof obligations, while deterministic validators check evidence completeness, privacy minimisation, policy binding, and integrity. In the minimal scenario, an agent attempts to transmit a secret to an unapproved external sink. The audit compares a logs-only correlation baseline with ProofWeave across verdict latency, join ambiguity, privacy exposure, tamper detection, and resistance to graph-only proof injection. ProofWeave reduces candidate bindings per verdict from up to `10,201` to one, validation operations from up to `10,201` to approximately `26`, and assurance evidence storage from `0.79`MiB to `0.15`MiB per project.

补充信息

↑