arXiv:2609.37819v1 Announce Type: cross
Abstract: Electronic invoices are replacing paper invoices worldwide, but today's centralized architectures leave three problems unsolved on the consumption si...
By Jia Cai
arXiv:2608. 14074v1 Announce Type: new Abstract: AI agents increasingly act on external systems through standardized tool-calling protocols such as the Model Context Protocol (MCP), yet no infrastructure layer constrains their actions to what a principal has verifiably authorized: authorization logic lives in application code, is neither signed nor independently auditable, and the resulting logs lack evidentiary value.
By Giovanni Racioppi
arXiv:2607. 19436v1 Announce Type: cross Abstract: Agentic commerce protocols such as AP2 and ACP define mechanisms for secure agent-initiated transactions but do not provide interoperable, tamper-evident auditability or verifiable temporal ordering of events across heterogeneous domains.
By Rajat Srivastava
The paper presents a formal analysis of four agent payment protocols—x402, MPP, ACP, and AP2—using the Tamarin prover. By modeling each protocol’s roles, state, and trust assumptions, the authors verify 86 cases, reproducing 46 known results and uncovering 40 new formal-consistency findings. They further validate ten findings through implementation proofs of concept, SDK/schema witnesses, and executable traces, highlighting the importance of consistent delegated authorization across all protocol stages.
By Ke Jiang, Mohan Yu, Yuan Chang, Mohit Kumar Jangid, Jianyu Niu, Cong Wang, Yinqian Zhang
arXiv:2608. 02986v1 Announce Type: cross Abstract: A software agent on a public blockchain accumulates authority and economic stakes, raising the engineering question of what makes it count as an individual.
By Keisuke Suzuki
The paper introduces Issuer‑Sovereign Agentic Payments, a framework that keeps the issuing bank in control of AI‑agent payments. It allows a cardholder to set a spending rule once, which the bank’s authentication system records. When an AI agent initiates a payment, the bank verifies the merchant against the approved rule and generates the card authentication value only if the merchant is permitted, enabling the transaction to proceed through standard card rails without additional dependencies.
By Dishant Sharma, Rajneesh Kaushal, Ashu Kanaujia
arXiv:2609.05901v1 Announce Type: cross
Abstract: Autonomous LLM agents can turn untrusted content into effectful actions such as payments and permission changes. If the same process interprets this...
By Yu Zheng, Qizhi Zhang
arXiv:2606. 04193v1 Announce Type: cross Abstract: Current AI agent observability is structurally compromised: the entity producing the activity log is the same entity whose activity is being logged.
By Juan Figuera
The paper introduces DART, a Directed Acyclic Graph (DAG)-based framework that combines centralized orchestration with blockchain-enabled decentralized governance to manage reputation and incentives in large language model (LLM)-based multi-agent systems. DART dynamically allocates tasks based on agent capability, reputation, and workload, while continuously updating trust scores through post-execution evidence and smart contract accountability. Experimental results show that DART outperforms centralized baselines, achieving high task success rates, low retry rates, and effective containment of malicious agents.
By Manoj Kumala, Xinyun Liua, Ronghua Xu
arXiv:2609.14811v1 Announce Type: new
Abstract: We introduce Crypto Accounting Bench (CAB), a benchmark for assessing whether frontier and open-weight language models can reconstruct the complete jou...
By Kareem Khattab, Omar Khattab, Mohamed Ibrahem
The paper introduces PACE (Policy‑Attested Contract Execution), a framework that sits between large‑language‑model (LLM) based autonomous AI agents and on‑chain DeFi operations. PACE defines typed transaction intents, a deterministic policy verifier, and signed Policy Decision Records (PDRs) that cryptographically bind an approved intent, policy, and simulation report to the exact on‑chain execution bytes, providing replay and expiration protection. In evaluations across 40 tasks and six baselines, PACE achieves zero unsafe executions and zero false positives, outperforming unguarded agents by a large margin.
By Rabimba Karanjai (Larry), Yang Lu (Larry), Richard Williamson (Larry), Hemanth Hm (Larry), Prakhar Mehrotra (Larry), Lei Xu (Larry), Weidong (Larry), Shi
The paper proposes a tiered, reusable identity assurance model that separates assurance state from capability gates, allowing participants to disclose only what is necessary for each act. It introduces a typed entity taxonomy, a two‑axis coordinate system for assertion scope and source, and a time‑indexed jurisdiction attribute, with reliance recorded in bitemporal snapshots. The design is evaluated against existing flat‑verification and per‑credential models, addressing cross‑border reuse and data‑erasure versus evidentiary retention concerns.
By Walter Kurz