发表机构
The Hong Kong Polytechnic University; Hong Kong Baptist University(香港理工大学; 香港浸会大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
针对大语言模型发布中验证边界失败导致的语义遗漏问题,提出H-CRSPV复制准入层,通过权威记录和多重集检查强制要求集完整性,实验证明能拒绝所有遗漏工件并接受诚实发布。
AI 中文摘要
大语言模型发布管道日益将承诺、签名、来源记录和异构验证后端结合在一起。然而,验证每个提交的对象并不能确立发布实现了其注册转换的每项要求。不受信任的实现提议者可能省略必需的关系、提议未经授权的证据共享分配,或将有效证据绑定到错误的对象。这种验证边界失败被称为“有效证据下的语义遗漏”(SOVE)。混合密码学基于关系的语义计划验证(H-CRSPV)是一个复制的准入层,在发布消费之前强制执行必需集的完整性。在证据选择之前,授权的注册实体提交一份经过认证的权威记录。验证者独立推导必需义务多重集,检查精确的条目出现覆盖率,验证提议引发的证据共享,并将可接受的组一对一地绑定到保管者解析的对象。证据在挑战窗口关闭且原子终结器激活发布之前保持临时状态。分析在明确假设下确立了结构精确性和条件性语义保证。在36个遗漏工件中,提交对象验证接受全部36个,因为每个提交的对象都通过其后端特定的验证器。H-CRSPV拒绝全部36个,同时接受所有六个诚实的发布。原型还验证了六个受限的源到RelationIR绑定,并拒绝了所有60个测试的突变。在连续的四个验证器Qwen2.5-1.5B工作流中,相同的权威记录在三个具有不同注册后可用性状态的合法发布中保持固定。这些结果表明,每个对象的有效性并不能确立完整、正确绑定和最终化的发布证据。
英文摘要
Large-language-model release pipelines increasingly combine commitments, signatures, provenance records, and heterogeneous verification backends. Yet validating every submitted object does not establish that a release realizes every requirement of its registered transformation. An untrusted realization proposer may omit a required relation, propose an unauthorized evidence-sharing assignment, or bind valid evidence to the wrong object. This verification-boundary failure is termed Semantic Omission under Valid Evidence (SOVE). Hybrid Cryptographic Relation-based Semantic Plan Verification (H-CRSPV) is a replicated admission layer that enforces required-set completeness before release consumption. Before evidence selection, an authorized registration entity commits an authenticated authority record. Validators independently derive the required-obligation multiset, check exact entry-occurrence coverage, validate proposal-induced evidence sharing, and bind admissible groups one-to-one to keeper-resolved objects. Evidence remains provisional until the challenge window closes and an atomic finalizer activates the release. The analysis establishes structural exactness and conditional semantic guarantees under explicit assumptions. Across 36 omission artifacts, submitted-object validation accepts all 36 because every submitted object passes its backend-specific verifier. H-CRSPV rejects all 36 while accepting all six honest releases. The prototype also validates six restricted source-to-RelationIR bindings and rejects all 60 tested mutations. In a continuous four-validator Qwen2.5-1.5B workflow, the same authority record remains fixed across three legal releases with different post-registration availability states. These results show that per-object validity does not establish complete, correctly bound, and finalized release evidence.
Comments22 pages, 2 figures; preprint