arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2609.35300cs.CR

作为安全资源的持续参与:有界参与通道

Sustained Participation as a Security Resource: The Bounded Participation Channel

  • DeustoTech, University of Deusto Bilbao(德乌斯托大学毕尔巴鄂分校)
  • International University of La Rioja (UNIR) Logroño(拉里奥哈国际大学)

机构由 AI 辅助整理,请以论文原文为准。

Homayoun Maleki, Nekane Sainz, Jon Legarda, Igor Santos-Grueiro

更新

AI总结:

针对反女巫防御中身份存续无成本的问题,提出有界参与通道BPC形式化原语,通过四项结构属性证明持续参与的线性成本下限,实验验证自动化求解虽准确率高但吞吐量受限,将持续参与转化为可度量安全资源。

AI中文摘要:

能否将基于身份的持续参与构建为一种安全资源?大多数反女巫(Sybil)防御机制为身份创建定价,而非为身份存续定价。一旦获得准入,攻击者无需支付持续成本即可维持大量身份。我们提出有界参与通道(Bounded Participation Channel, BPC),这是一种用于逐窗口反复验证参与情况的形式化原语。BPC在严格的截止期限下发布与身份绑定的全新挑战,并强制执行四项结构属性:身份绑定性、新鲜性、实时响应性以及单通道吞吐量有界性。这些属性共同推导出一个可证明的成本定理:在T个时间窗口内维持s个身份所需的参与通道-窗口数满足C(s,T) ≥ sT/τ_h。该保障与求解者无关:通道可由人类、AI系统或人机混合模式运行。\n我们提出了一种基于哈希的构造方案,可生成公开可验证的参与证明,描述了四类可采纳的挑战族,并在600次试验中针对GPT-4o、Gemini 2.5 Flash和Claude Sonnet 4.5评估了其中两类挑战。尽管被评估的自动化通道在感知任务上准确率接近完美(97%–100%),但在测试的部署条件下其吞吐量仍受限制。结果阐明了一个关键区别:可解性并不意味着吞吐量无限制。通过要求每个身份在每个时间窗口都重新争取参与资格,BPC将持续参与转化为一种可度量的安全资源,具有线性结构成本下限,且与参与由人类、AI系统还是混合模式提供无关。

英文摘要:

Can sustained, per-identity participation be engineered into a security resource? Most anti-Sybil defenses price identity creation rather than identity survival. Once admitted, an adversary may sustain many identities without paying a recurring cost. We introduce the Bounded Participation Channel (BPC), a formal primitive for repeatedly verifying participation window by window. BPC issues fresh, identity-bound challenges under a strict deadline and enforces four structural properties: identity binding, freshness, real-time response, and bounded per-channel throughput. Together, these yield a provable cost theorem: sustaining $s$ identities over $T$ windows requires $C(s,T) \geq sT/τ_h$ participation channel-windows. The guarantee is solver-agnostic: a channel may be operated by a human, an AI system, or a hybrid. We give a hash-based construction with publicly verifiable participation proofs, characterize four admissible challenge families, and evaluate two against GPT-4o, Gemini 2.5 Flash, and Claude Sonnet 4.5 across 600 trials. Despite near-perfect accuracy (97--100%) on the perceptual tasks, the evaluated automated channels remain throughput-bounded under the tested deployment conditions. The results illustrate a key distinction: solvability does not imply unlimited throughput. By requiring participation to be re-earned by every identity in every time window, BPC turns sustained participation into a measurable security resource with a linear structural cost floor, independent of whether the participation is supplied by humans, AI systems, or hybrids.

补充信息

↑