---
格式版本: 2
标题: "Attesting Outputs and Delegation Ancestry in Multi-Agent AI Systems"
原文链接: "https://arxiv.org/abs/2608.30387"
发布日期: "2026-08-31"
发布时间校准状态: "found"
发布时间需复核: "否"
发布时间来源: "rule:local:strict_original_body"
发布时间证据: "**\\[v1\\]** Mon, 31 Aug 2026 07:42:57 UTC (184 KB)"
发布时间校准原因: "规则确认唯一严格发布时间，来源 local:strict_original_body"
发布时间校准置信度: "high"
发布时间候选数量: 18
发布时间严格候选数量: 6
发布时间原页读取状态: "source template page reused from URL open"
发布时间未找到原因: ""
发布时间校准时间: "2026-09-02T03:55:20+08:00"
发布时间仲裁状态: "skipped"
发布时间仲裁尝试次数: 0
发布时间仲裁耗时毫秒: 0
发现时间: "2026-09-02T03:54:25+08:00"
入库时间: "2026-09-01T19:55:20.949Z"
来源平台: "arXiv 学术论文搜索"
搜索渠道: "source_template"
搜索词: "https://arxiv.org/search/?query=AWS&searchtype=all"
匹配关键词:
  - "deployment"
  - "latency"
  - "AI"
相关厂家:
  - "AWS"
相关专家:
  []
内容类型: "网页"
抓取工具: "Free Fetch + Defuddle"
清洗工具: "Defuddle Markdown + Defuddle/Readability 正文提取"
原始附件:
  []
AI优质: "否"
AI打分: 8
AI分档: "非优质"
AI质检状态: "不通过"
AI打分理由: "论文主题为多代理AI系统的认证与安全，属于密码学与安全领域，与超节点/AI Rack/机柜级AI基础设施完全无关。"
AI质检模型: "zj-deepseek-v4-flash"
AI质检时间: "2026-09-02T03:55:26+08:00"
AI主题相关性: 0
AI来源权威性: 8
AI新颖性: 0
AI技术细节: 0
AI商业部署信号: 0
AI完整性: 0
AI摘要: "本文提出一种面向多代理AI系统的双层认证设计，用于对输出字节和跨部署者委派血缘进行认证，并比较了签名链表、Merkle链变体与共同签名DAG；后者在子密钥泄露时仍能拒绝未授权父绑定。"
AI摘要模型: "ali-deepseek-v4-flash"
AI摘要时间: "2026-09-01T23:06:17.269Z"
采集批次: "2026年9月1日23点56分52秒"
采集批次ID: "20260901-235652-761"
去重键: "https://arxiv.org/abs/2608.30387"
---

## Computer Science > Cryptography and Security

## Title:Attesting Outputs and Delegation Ancestry in Multi-Agent AI Systems

Authors:[Lifei Liu](https://arxiv.org/search/cs?searchtype=author&query=Liu,+L), [Haoran Yu](https://arxiv.org/search/cs?searchtype=author&query=Yu,+H)

[View PDF](https://arxiv.org/pdf/2608.30387) [HTML (experimental)](https://arxiv.org/html/2608.30387v1)

> Abstract:Multi-agent applications delegate work across independently operated deployers. After an incident, a verifier must answer two questions: which deployer released the reported bytes, and whether each cross-deployer edge was authorized. Credentials establish who may act, but need not bind them to later output bytes or prove both deployers authorized a dynamically created edge. We present a two-layer attestation design for dynamic delegation without a shared authority, public log, or precommitted workflow. A trusted deployer runtime signs a hash of each released output; this records released bytes but does not prevent prompt injection. Ancestry evidence records edge authorization. Under a unified threat model, we compare a signed linked list, a Merkle-chain variant, and a co-signed DAG. The primitives are standard; the contribution is deployer-side binding and the evidence needed for the two questions. After child-key compromise, the single-signer designs permit an unauthorized parent binding, whereas the co-signed DAG rejects it because the parent must authorize the edge. Fixed adversary matrices and regression tests validate the composed verifier. On an Apple M1 Pro, ancestry-only checks take 24.3-499.2us per hop. In a live local multi-service workflow, a parent discovers the child's A2A Agent Card; the child calls an MCP tool and releases local-LLM output: all 30 signed-DAG tasks passed complete verification, while a controlled child-key-only claim was rejected; its mean end-to-end latency was 813.1ms versus 770.8ms without evidence. In a complementary three-availability-zone AWS deployment, all 1,000 valid co-signed-DAG paths verified; issuance averaged 3.651ms and complete verification 5.015ms. The cloud result excludes TLS/mTLS, KMS, and model-serving latency.

| Subjects: | Cryptography and Security (cs.CR) |
| --- | --- |
| Cite as: | [arXiv:2608.30387](https://arxiv.org/abs/2608.30387) \[cs.CR\] |
|  | (or [arXiv:2608.30387v1](https://arxiv.org/abs/2608.30387v1) \[cs.CR\] for this version) |
|  | [https://doi.org/10.48550/arXiv.2608.30387](https://doi.org/10.48550/arXiv.2608.30387) |

## Submission history

From: Lifei Liu \[[view email](https://arxiv.org/show-email/2cc9f194/2608.30387)\]  
**\[v1\]** Mon, 31 Aug 2026 07:42:57 UTC (184 KB)

[Which authors of this paper are endorsers?](https://arxiv.org/auth/show-endorsers/2608.30387) | Disable MathJax ([What is MathJax?](https://info.arxiv.org/help/mathjax.html))
