arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

ContractWarden:通过人类授权契约实现AI智能体的内核强制损害边界

ContractWarden: Kernel-Enforced Damage Boundaries for AI Agents via Human-Authorized Contracts

Dongxu Cui, Zhichao Gu, Ping Zheng, Wenshuai Xi, Simeng Han, Yong Liao

arXiv 2609.38248首次发表:更新:

发表机构

School of Cyber Science and Technology, University of Science and Technology of China; China Greatwall Technology Group Co., Ltd.(中国科学技术大学网络空间安全学院; 中国长城科技集团股份有限公司)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

ContractWarden通过人类授权契约和eBPF/LSM内核数据平面,为AI智能体强制执行确定性损害边界,实验验证了低开销与高安全性。

AI 中文摘要

大型语言模型智能体可以执行命令、创建子进程并直接访问文件和网络,这使得提示注入或规划错误可能成为操作系统副作用。我们提出了ContractWarden,一个Linux参考监视器,它在不信任智能体或其策略建议的情况下强制执行人类授权的损害边界。模型可以提出三态资产契约——允许、拒绝或禁止外发(no_egress)——但最终选择由人类做出。在不可信代码运行之前,一个执行门将契约绑定到具体任务。随后,一个扩展的伯克利数据包过滤器(eBPF)Linux安全模块(LSM)数据平面强制执行文件和网络决策,并通过进程、常规文件、管道、FIFO和支持的Unix域套接字单调传播禁止外发(no_egress)状态。在19项安全测试中,所有570次运行均满足预定义的返回值和副作用标准。在三个并置的文件I/O工作负载上,Linux 6.15虚拟机中的中位开销为11.96%-12.89%,在Linux 6.15物理平台上为35.79%-61.54%,低于评估的冻结ActPlane基线。结果表明,对于声明的资产、支持的路径和受控的对象生命周期,实现了确定性的内核强制执行。

英文摘要

Large language model agents can execute commands, create subprocesses, and directly access files and networks, allowing prompt injection or planning errors to become operating-system side effects. We present ContractWarden, a Linux reference monitor that enforces a human-authorized damage boundary without trusting the agent or its policy suggestions. A model may propose a tri-state asset contract - allow, deny, or no_egress - but a human makes the final choice. An execution gate binds the contract to a concrete task before untrusted code runs. An extended Berkeley Packet Filter (eBPF) Linux Security Modules (LSM) data plane then enforces file and network decisions and monotonically propagates no_egress through processes, regular files, pipes, FIFOs, and supported Unix-domain sockets. All 570 runs across 19 security tests satisfy predefined return-value and side-effect criteria. On three co-located file-I/O workloads, median overhead is 11.96-12.89% in a Linux 6.15 virtual machine and 35.79-61.54% on a Linux 6.15 physical platform, lower than the evaluated frozen ActPlane baseline. The results demonstrate deterministic kernel enforcement for declared assets, supported paths, and controlled object lifecycles.

CommentsSupersedes the preprint DOI 10.21203/rs.3.rs-10865359/v1, which has a different title. Submitted to ICOIN 2027. 6 pages, 2 figures

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑