Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
84 changes: 84 additions & 0 deletions data/research.json
Original file line number Diff line number Diff line change
Expand Up @@ -108,13 +108,97 @@
"spec": "https://wcm.agentrust-io.com/",
"code": "https://github.com/agentrust-io/weight-custody-manifest",
"patent_pending": true,
"doi": "10.5281/zenodo.23020644",
"date": "2026-09-27",
"abstract": "Deploying proprietary model weights into infrastructure controlled by a customer reverses the usual confidential-computing trust problem: the model builder, rather than the infrastructure owner, supplies the secret. Existing confidential-computing stacks can attest workloads and release secrets, while model-signing systems authenticate model artifacts. Neither capability alone specifies continuing custody of a particular weight artifact after release. This technical report describes the Weight Custody Manifest (WCM), a vendor-neutral protocol and conformance model that binds an exact weight digest, an approved workload measurement, attestation policy, a fresh transport key, renewable authorization, terminal refusal and wipe evidence, and derivative lineage. WCM distinguishes cryptographic custody against software adversaries from accountability-grade controls when the infrastructure operator physically owns the machine. The evaluated Python reference implementation, version 0.28.0, supplies 91 portable conformance vectors across four levels. Its test suite produced 618 passing tests and three skips on September 3, 2026, and the same counts when rerun at the same commit for this edition. Two later findings bound those results: a published advisory showed that the evaluated key broker did not require GPU confidential-compute mode before release, and the SEV-SNP platform used for the hardware run does not enable the ciphertext hiding that the cryptographic-custody claim against a hypervisor-privileged operator requires. The contribution is a portable artifact-to-runtime custody contract with explicit lifecycle evidence, derivative accountability, and conformance, not a new attestation primitive or a certification of any deployment.",
"pages": 6,
"sha256": {
"paper.pdf": "a0338db4e4f8a35f134f5b8313a167f81b829a047c9439d8b3c2b34e3c5e0c59",
"source.zip": "ce91e7c14ef7abde96b922129eb4467a5e47720933acee707c5c3cd7c080ddeb"
}
},
{
"slug": "ca2a",
"short_title": "cA2A",
"title": "cA2A: Confidential Agent-to-Agent Delegation as a Profile on A2A",
"authors": [
"Rishabh Poddar",
"Aaron Fulkerson",
"Imran Siddique"
],
"topic": "Delegation evidence",
"description": "cA2A technical report: attenuated, attested delegation between AI agents on A2A, rerun experiments, later findings and hardware limits.",
"contribution": "A trust profile on A2A composing narrowing delegation credentials, peer attestation appraisal, sealed payloads and linked per-hop provenance records.",
"limits": [
"Software experiments were rerun on September 27, 2026 against ca2a 0.3.1: correctness counts matched the July 2026 draft, and chain verification cost about 216 rather than 195 microseconds per hop.",
"Cross-operator attestation was exercised only with synthetic evidence. Recorded hardware runs cover one-directional appraisal across clouds and a same-operator diagnostic, not mutual attestation between independent operators.",
"The results do not show that a peer's key is confined to attested code. Provenance checks on unsigned records establish structural consistency only; authenticity rests on signed records."
],
"changes": "Narrows claims to what the code validates, reruns the experiments on ca2a 0.3.1, corrects three citations, and adds a post-evaluation findings section.",
"spec": "https://ca2a.agentrust-io.com/",
"code": "https://github.com/agentrust-io/ca2a",
"patent_pending": true,
"date": "2026-09-27",
"abstract": "The Agent2Agent (A2A) protocol moves tasks between agents, and its Signed Agent Card lets a client check that a domain owner issued a card. The card does not bound the authority a delegating agent passes on, establish what code a peer runs, keep a task payload from the peer's host, or leave an offline record of who delegated what to whom. This technical report describes cA2A (Confidential A2A), a trust profile layered on A2A rather than a new transport. It composes four mechanisms: signed delegation credentials whose scope can only narrow at each hop, appraisal of a peer's attestation evidence before a task is sent, a payload sealed to the channel key that evidence vouches for, and a signed per-hop provenance record linked to its parent. Attenuated delegation and provenance binding are covered by prior capability-token work and IETF drafts; the contribution here is their composition on A2A with an open implementation. We state six properties and report software experiments rerun against ca2a 0.3.1: attenuation checks over 5,400 generated chains, rejection of in-chain replay and cross-chain splicing, intersection of delegated scope with local policy, sealed-payload behavior at the cryptographic layer, structural checks on linked provenance records, and a cross-operator attestation protocol exercised with synthetic evidence. Chain verification cost about 0.22 ms per hop in this environment. These results do not show that a peer's key is confined to attested code or that attestation works across independent operators. Recorded hardware runs cover one-directional appraisal of an Intel TDX peer by an AMD SEV-SNP peer in another cloud and a same-operator mutual SEV-SNP diagnostic; mutual attestation between independent operators has not been demonstrated.",
"pages": 21,
"sha256": {
"paper.pdf": "2e9fc6b2c9acebd252594985eaecf783b1e8714b57d39449fa914efc2e2846fb",
"source.zip": "9289ce4ea510d3c36fac3f91580ab1ae6aba2e570682507f2fd636c96dc01dbc"
}
},
{
"slug": "agentrust-telemetry",
"short_title": "AgenTrust Telemetry",
"title": "From Agent Observability to Governance Evidence: A Privacy-Constrained Telemetry Contract",
"authors": [
"Imran Siddique"
],
"topic": "Governance telemetry",
"description": "AgenTrust Telemetry technical report: a privacy-constrained contract separating agent observability from governance evidence, with rerun results.",
"contribution": "A backend-neutral contract for six governance event families that keeps lossy operational telemetry separate from evidence whose completeness is stated.",
"limits": [
"The evaluated release is 0.1.0-alpha.2. On September 27, 2026 its 111 Python tests passed and all 13 fixtures gave their expected verdicts again, with agentrust-trace pinned to 0.9.0. The TypeScript suite was not rerun.",
"Completeness is a producer assertion that the accumulator records but does not measure.",
"A defect found after the evaluation let an edited evidence snapshot be signed at the evaluated release; it was fixed later and is reported beside the results."
],
"changes": "Aligns claims with the evaluated code, positions the contract against prior governance telemetry work, and adds a post-evaluation findings section.",
"spec": "https://agentrust-io.com/telemetry/",
"code": "https://github.com/agentrust-io/agentrust-telemetry",
"patent_pending": false,
"date": "2026-09-27",
"abstract": "Agent observability conventions describe model, tool, and agent operations, but governance facts are commonly fragmented across policy engines, approval stores, cost modules, and audit systems. Copying those facts into ordinary traces creates two hazards: sensitive payload capture and the false inference that sampled operational telemetry is complete audit evidence. This technical report describes AgenTrust Telemetry, a backend-neutral contract for six governance event families: policy decisions, approval lifecycles, usage, classified data flows, action execution, and evidence lifecycle. The contract correlates with W3C Trace Context and OpenTelemetry without installing a provider, exporter, or competing tracing model. A metadata-only profile rejects prompts, outputs, source code, tool arguments and results, credentials, and authorization tokens by key. Durable run and action identifiers survive process and asynchronous handoffs; propagated metadata remains untrusted and does not confer identity or authority. An optional accumulator accepts events before lossy export and can be finalized into a separately verifiable TRACE record. Its completeness status is a producer assertion that the accumulator records but does not measure. The evaluated release, 0.1.0-alpha.2, ships Python and TypeScript reference SDKs over shared schemas and a portable conformance set of six valid and seven invalid fixtures. At that commit 111 Python unit tests pass and all 13 fixtures produce their expected verdicts, on September 3, 2026 and again when rerun for this edition. A defect found after the evaluation let an edited evidence snapshot be signed; it is reported beside the results it qualifies. The contribution is not another agent tracing convention; it is a narrow semantic boundary between operational observation and governance evidence whose completeness must be stated rather than inferred.",
"pages": 6,
"sha256": {
"paper.pdf": "502c3d61e335d47c642ff8d6b7c1cf9ec9c25f5c99213f2eefea0b01b5d7359b",
"source.zip": "34517b8856bae49bf757beb3ba4c43b4b7db9f0df25e9b5dd2e40b6d2f30afaa"
}
},
{
"slug": "confidential-handoffs",
"short_title": "Confidential Handoffs",
"title": "Confidentiality Across Agent Handoffs: Conditions for preserving an inference guarantee through tools and delegation",
"authors": [
"Imran Siddique"
],
"topic": "Confidential handoffs",
"description": "Confidential handoffs technical report: conditions for keeping inference confidentiality through agent tool calls and delegation, software evidence.",
"contribution": "A conditional composition argument and proposed handoff contract for when tool calls and delegations preserve an authorized plaintext-holder boundary.",
"limits": [
"All results are software results: attestation in the composed experiment is synthetic and one operator runs every party.",
"The composed experiment was rerun on September 27, 2026 at WCM main 94d5519: 36 of 36 hosted and 32 portable cases locally, matching every recorded observation.",
"Hardware acceptance and independently operated peers are future work. Raw hardware diagnostic captures are not published."
],
"changes": "Reframes the draft as a bounded software edition, records the rerun, updates dependency status and corrects two references.",
"spec": "https://wcm.agentrust-io.com/",
"code": "https://github.com/agentrust-io/weight-custody-manifest/tree/main/python/composed",
"patent_pending": true,
"date": "2026-09-27",
"abstract": "This paper states conditions under which tool calls and agent handoffs preserve an authorized plaintext-holder boundary. This requires a protected channel bound to an appraised workload, restricted authority, enforceable downstream information-flow rules, and control over every other plaintext sink. A signature on an execution record or a valid hardware quote alone cannot establish these conditions. If a recipient cannot satisfy them, the sender must withhold the data or obtain authorization for a precisely described disclosure. This paper develops a conditional composition argument, a proposed handoff contract, and component experiments that expose failures of appraisal, supervision, and outcome inference. A composed software harness joins provisioning, diagnostic model computation, a confined agent, a mediated tool, delegated peer authentication, and exact-output disclosure. Its paired mutations expose earlier leaks despite successful final delivery; a rerun on September 27, 2026 reproduced all 36 recorded observations. All results are software results with synthetic attestation and a single operator. AgenTrust supplies relevant identity, key-release, gateway, delegation, and evidence primitives, but its present components do not demonstrate the complete property. The distinction matters most at remote tools, CPU-GPU transfers, operator-controlled key brokers, runtime changes, and audit systems.",
"pages": 13,
"sha256": {
"paper.pdf": "21a1abd5e6fbc822105437c2a639c59368880a3ff79c2dc32b4cfac652602728",
"source.zip": "b0f2ea632176aff353d78813fe74293bd80e12bed53448d3e1395b1dc699b641"
}
}
]
}
Loading
Loading