$Z^2$-ACT: End-to-End Verifiable Agentic Intent Control for Open 6G RAN
作者: Sunder Ali Khowaja, Kapal Dev, George C. Alexandropoulos
分类: cs.CR, cs.AI, cs.NI
发布日期: 2026-08-21
备注: 12 pages, 2 figures, 6 tables
💡 一句话要点
提出$Z^2$-ACT以解决开放6G RAN中的多供应商控制问题
🎯 匹配领域: 支柱二:RL算法与架构 (RL & Architecture) 支柱九:具身大模型 (Embodied Foundation Models)
关键词: 开放6G 无线接入网络 AI控制 多供应商 安全性 可审计性 零知识证明 对抗意图检查
📋 核心要点
- 现有方法在多供应商环境中面临AI控制环路的安全性和可审计性不足的挑战。
- 本文提出的$Z^2$-ACT架构集成了零知识审计控制和零信任验证,确保了意图的安全性和可验证性。
- 实验结果显示,$Z^2$-ACT在攻击抵御和延迟方面表现优越,相较于传统方法有显著提升。
📝 摘要(中文)
随着开放和分散的6G无线接入网络的发展,预计系统将能够支持多供应商。为了实现这一目标,AI辅助控制环路必须在并发操作员意图和不可信模型输入下保持安全、可验证和可审计。现有研究在代理协调、正式意图约束、零信任提示验证和密码学问责方面各自独立,导致在预实现安全性、持续语义验证和跨域审计方面的不足。为此,本文提出了零知识可审计控制和零信任可验证代理意图架构($Z^2$-ACT),将上述四个原语整合到非实时和近实时的RIC中。我们将类型化的意图合同编码为操作员目标,并在经过实际对抗意图检查后才允许大型语言模型输入。实验评估表明,该架构在目标消融和传统强化学习基线下表现出色。
🔬 方法详解
问题定义:本文旨在解决开放6G无线接入网络中多供应商环境下AI控制环路的安全性、可验证性和可审计性不足的问题。现有方法在处理并发操作员意图和不可信输入时存在局限性。
核心思路:$Z^2$-ACT架构通过集成零知识审计和零信任验证,确保在多供应商环境中,AI控制环路能够安全、可验证地执行操作员意图。设计上强调了对抗意图检查,以防止不良输入影响系统。
技术框架:该架构包括非实时和近实时的RIC模块,采用类型化意图合同作为操作员目标,并通过大型语言模型进行意图翻译。系统在满足自管理门控后才释放技能序列,并记录每次成功提交的绑定承诺。
关键创新:本文的主要创新在于将零知识审计和零信任验证结合,形成一个全面的控制框架,克服了现有方法在安全性和可审计性方面的不足。
关键设计:在设计中,采用了对抗意图检查机制,确保只有经过验证的输入才能进入系统。此外,成功提交的意图合同会生成零知识证明,增强了系统的安全性和可审计性。实验中使用了公共ColO-RAN测量数据进行评估。
🖼️ 关键图片
📊 实验亮点
实验结果表明,$Z^2$-ACT在攻击抵御能力和延迟方面表现优越,相较于传统强化学习基线,提升了意图过滤的准确性和系统的响应速度。具体而言,非实时路径的意图翻译准确率显著提高,且无效或幻觉合同的发生率降低。
🎯 应用场景
$Z^2$-ACT架构在开放6G无线接入网络中具有广泛的应用潜力,能够为多供应商环境下的AI控制提供安全、可验证的解决方案。这一研究不仅提升了网络的安全性,还为未来的智能网络管理奠定了基础,具有重要的实际价值和影响。
📄 摘要(原文)
With the progression in open and disaggregated 6G radio access networks, it is expected that the system will be able to host multi-vendors. In order to host multi-vendors, it is essential that AI-assisted control loops remain safe, verifiable, and auditable under concurrent operator intents and untrusted model inputs. The existing studies address the agentic coordination, formal intent constraints, zero-trust prompt verification and cryptographic accountability in isolation, which leaves pre-realization safety, continuous semantic verification and cross-domain audit incomplete when used individually. In this regard, we propose zero-knowledge auditable control and zero-trust verifiable agentic intent architecture ($Z^2$-ACT), which integrates the aforementioned four primitives across the non-real-time and near-real-time RICs. We encode the typed Intent Contracts as operator goals while the large language model inputs are only admitted after a practical adversarial intent check. The skill sequences in the proposed study are released only when a self-management gate is satisfied while every successful commit is recorded as a binding commitment with a zero-knowledge proof. Our experimental evaluation on public ColO-RAN measurements compares the full architecture against targeted ablations and a conventional reinforcement-learning baseline. A live large language model is used in the non-real-time path to translate operator intents into Intent Contracts; we report translation accuracy, the rate of invalid or hallucinated contracts, non-real-time latency, and behavior under adversarial or misleading intents. Near-real-time control remains trace-driven on the public KPM sequences. Results indicate improved actuation filtering and attack resilience at modest latency and signaling cost inside the near-real-time envelope.