发表机构
Accentrust; Georgia Institute of Technology; University of Illinois Urbana-Champaign(Accentrust; 佐治亚理工学院; 伊利诺伊大学厄巴纳-香槟分校)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
本文提出授权继承机制,通过外部协议和原子提交,在自修改AI智能体群体的替换、分叉和回滚中保持权限,经实验验证确保群体安全。
AI 中文摘要
自修改AI智能体可以替换、分叉和回滚承载身份的软件,而其后代仍然可执行。逐后继者授权无法约束由此产生的群体:兄弟节点可能重复配额、组合权限、在祖先被切断时幸存,或在提升过程中与前任重叠。我们定义了授权继承,它在一个单亲世代森林的活动前沿上保持权限。我们的外部协议将每一代绑定到一个清单、根、唯一父代、完整谱系和新的群体序列。独立的约束限制了根生命周期消耗和当前群体暴露。分阶段预留会在替换期间冻结前任的剩余权限,而分区式分叉则验证完整的子代家族。每次提交原子性地围栏前任并激活后继者。祖先切断会使依赖的后代失效;回滚会创建新的一代而不恢复已消耗的权限;新的根需要独立的授权。在完全中介、认证记录、健全的效果抽象、持久单调状态和完整谱系核算下,我们证明了群体安全的继承、分叉保持、撤销闭合、原子交接、回滚不重铸以及排除自认证。一项可执行评估覆盖了32个注册决策,通过直接调用和邮箱映射(64/64次重放;28次允许,36次拒绝)。一个独立检查器接受所有64条原始轨迹并拒绝28/28个语义突变体;12/12个配置文件约束、16/16个崩溃切断和32/32个竞争者调度通过。两个外部适配器在测量的OurArk和Darwin Godel Machine突变上重现了所有32个决策,包括新进程重启、原子交接和前任拒绝。结果确立了注册受保护效果的授权继承。
英文摘要
Self-modifying AI agents can replace, fork, and roll back identity-bearing software while descendants remain executable. Per-successor authorization does not constrain the resulting population: siblings may duplicate quotas, combine permissions, survive ancestor cuts, or overlap predecessors during promotion. We define authorization succession, which conserves authority across the active frontier of a single-parent generation forest. Our external protocol binds each generation to a manifest, root, unique parent, complete lineage, and fresh population sequence. Separate invariants bound root-lifetime consumption and current population exposure. A staged reservation freezes predecessor residual authority during replacement, while a partitioning fork validates the complete child family. Each commit atomically fences the predecessor and activates successors. Ancestor cuts invalidate dependent descendants; rollback creates a fresh generation without restoring spent authority; and a new root requires an independent grant. Under complete mediation, authenticated records, sound effect abstraction, durable monotone state, and complete lineage accounting, we prove population-safe succession, fork conservation, revocation closure, atomic handoff, rollback non-reminting, and exclusion of self-certification. An executable evaluation covers 32 registered decisions through direct-call and mailbox mappings (64/64 replays; 28 allows, 36 denies). An independent checker accepts all 64 original traces and rejects 28/28 semantic mutants; 12/12 profile invariants, 16/16 crash cuts, and 32/32 contender schedules pass. Two external adapters reproduce all 32 decisions around measured OurArk and Darwin Godel Machine mutations, including fresh-process restart, atomic succession, and predecessor rejection. The results establish authorization succession for registered protected effects.
Comments41 pages, 1 figure, 11 tables, and 1 algorithm; includes formal proofs and external runtime adapter evidence