VeriWeave Govern:面向企业AI智能体的证据门控确定性运行时治理
VeriWeave Govern: Evidence-Gated Deterministic Runtime Governance for Enterprise AI Agents
- Institute for Smart System Technologies, University of Klagenfurt(克拉根福大学智能系统技术研究所)
- Faculté Polytechnique, Université de Kinshasa(金沙萨大学理工学院)
机构由 AI 辅助整理,请以论文原文为准。
AI总结:
针对企业AI智能体动作授权需求,提出VeriWeave Govern确定性运行时治理层,通过证据门控、拒绝优先级和人工审查实现安全控制,在GovernBench上达到高准确率与零误允许,并揭示安全-效用权衡。
AI中文摘要:
企业人工智能智能体越来越多地调用工具、修改基础设施和处理受保护数据,从而产生了将动作生成与动作授权分离的需求。本文介绍了VeriWeave Govern,一个确定性的运行时治理层,它根据版本化策略评估结构化智能体动作,验证类型化证据,应用固定的拒绝>审查>允许优先级,将后果性动作路由到负责任的人工审查,并记录可重放的防篡改审计状态。GovernBench评估了该设计,涵盖30个独立种子和60,000个Oracle标记案例,跨越五个企业领域、对抗性证据、分布外动作和时间策略演变。VeriWeave在评估案例上实现了0.9888的平均准确率、0.9836的宏F1分数、零观察到的聚合误允许和零观察到的治理攻击成功率。六项消融研究表明,证据门控、拒绝优先级、分布外故障安全行为、人工审查、矛盾处理和时间重放贡献了互补的安全性。部署的API还通过了12/12端到端场景和40,040请求并发矩阵,零失败。一个独立的150案例欧盟/奥地利法规接地评估使用冻结预测和两名独立的盲人人类标注者,他们对所有决策达成一致。在这组案例上,确定性引擎保持保守,而Gemma 4 31B比较器更接近人类共识。结果揭示了可衡量的安全-效用权衡,并激励了证据感知、可重放的治理作为企业智能体执行的独立控制平面。
英文摘要:
Enterprise artificial-intelligence agents increasingly call tools, modify infrastructure, and process protected data, creating a need to separate action generation from action authorization. This article presents VeriWeave Govern, a deterministic runtime governance layer that evaluates structured agent actions against versioned policies, validates typed evidence, applies fixed deny > review > allow precedence, routes consequential actions to accountable human review, and records replayable tamper-evident audit state. GovernBench evaluates the design over 30 independent seeds and 60,000 oracle-labelled cases spanning five enterprise domains, adversarial evidence, out-of-distribution actions, and temporal policy evolution. VeriWeave achieves 0.9888 mean accuracy, 0.9836 macro-F1, zero observed aggregate false allows, and zero observed Governance Attack Success Rate on the evaluated cases. Six ablations show that evidence gating, deny precedence, out-of-distribution fail-safe behavior, human review, contradiction handling, and temporal replay contribute complementary safety. The deployed API additionally passes 12/12 end-to-end scenarios and a 40,040-request concurrency matrix with zero failures. A separate 150-case EU/Austria regulation-grounded evaluation uses frozen predictions and two independent blinded human annotators, who agree on all decisions. On this set, deterministic engines remain conservative, while a Gemma 4 31B comparator aligns more closely with the human consensus. The results expose a measurable safety--utility trade-off and motivate evidence-aware, replayable governance as an independent control plane for enterprise agent execution.