arXiv AI

Authorization for Self-Modifying AI Agent Populations: Conserving Authority across Replacement, Forking, and Rollback

The paper introduces "authorization succession," a framework that preserves authority across self‑modifying AI agent populations that can replace, fork, or roll back. It defines a protocol binding each generation to a manifest, root, unique parent, lineage, and population sequence, and establishes invariants that control root‑lifetime consumption and population exposure. The authors prove properties such as population‑safe succession, fork conservation, and rollback non‑reminting, and validate the approach with an executable evaluation covering 32 decisions and external adapters for two mutation systems.

arXiv AI
2d ago

Fault-Tolerant Budget Conservation in Distributed Multi-Agent Delegation

The paper introduces a fault‑tolerant budget conservation framework for distributed multi‑agent delegation, where budgets are represented as exclusive escrow credits that traverse a delegation DAG. It details how each branch converts credit into a reservation tied to lineage, epoch, and idempotency, persists a signed dispatch permit, and ensures that uncertain effects remain charged until settlement or retirement. The authors prove properties such as ownership partition, ledger conservation, and at‑most‑once settlement, and validate the mechanism through TLA+ checks, a JavaScript explorer, and crash‑injected SQLite experiments.

By Genliang Zhu, Chu Wang
arXiv AI
Sep 10

Versioned Transitive Dependency-Closure Binding and Operation-Time Effect Governance for Agent Skills: ClosureBound

ClosureBound is a reference monitor that enforces authorization boundaries for agent skills by binding each grant to an exact dependency closure, effect ceiling, purpose, validity, and epochs. It resolves typed graph nodes, normalizes operations into an external‑effect IR, and admits actions only when a joint witness satisfies all bounds, ensuring metadata non‑authority, closure determinism, and other security properties. Empirical evaluation on 549 public skills shows many lack proper dependency declarations, underscoring the need for conservative closure discovery and broader runtime validation.

By Genliang Zhu (Accentrust, Georgia Institute of Technology), Chu Wang (Accentrust, University of Illinois Urbana-Champaign)
arXiv AI
Sep 18

When AI Agents Commit: Cognitive Serializability Across Data, Evidence, Policy, and Authority

The paper introduces the concept of Cognitive Serializability for autonomous AI agents, ensuring that mutations derived from dynamic inputs—such as database reads, evidence, policy, beliefs, and delegated authority—are committed in a serial, logically consistent order. It presents a framework called Trusted Cognitive Transaction (TCT) that combines immutable executable definitions, sealed envelopes, guard-first commits, and receipt-driven reconciliation to enforce serializability and prevent anomalies. Experimental results show that the prototype implementation incurs minimal overhead while eliminating injected anomalies.

By Jun He, Deying Yu