EvidenceNet验证AI代理跨域网络操作
Can AI Agents Deliver Verifiable Network-Wide Outcomes Across Authority Boundaries?
EvidenceNet解决了AI代理跨域网络操作的验证难题,确保网络变更真正达到预期效果。
EvidenceNet是一个运行时保证层,用于判断协调的代理操作是否实现了网络意图。该系统通过收集变更后的观察结果,验证其来源、时效性和任务规则合规性。实验表明,在实时路由网络中,变更后状态检查能识别出配置操作记录无法确认的成功结果。受控干预显示,EvidenceNet能正确拒绝来源错误、被替换或过时的观察结果。
Can AI Agents Deliver Verifiable Network-Wide Outcomes Across Authority Boundaries?
AI agents are increasingly involved in network automation, where they can initiate configuration changes through mediated operational interfaces and assess the resulting state. Nonetheless, operational networks usually span many devices and administrative domains. Realizing an operator's intent requires coordinating agents with distinct authority scopes that define the resources they can access, the operations they can invoke, and the network state they can observe. This division limits the blast radius of an erroneous action but fragments the evidence needed to assess the network-wide outcome. Successful execution of a configuration action proposed by one agent does not establish that remote devices responded as intended or that routing changes reached the required devices. A valid observation may also become stale after a subsequent change. Before the coordinated operation can be declared complete, a trusted assurance layer must collect current observations from the required scopes and determine whether they collectively support the operator's intended network-wide outcome. To address the completion admission problem, we present EvidenceNet, a runtime assurance layer for deciding whether coordinated agent operations have achieved an operator's network intent. Its broker collects the post-change observations required by a completion contract, and its admission gate checks that the evidence comes from the required scopes, remains current, and satisfies the task rules. A verifier agent provides an additional assessment of the observation content. Experiments on live routing networks show that post-change state checks recognize successful outcomes that configuration-action records alone cannot establish. Controlled interventions further show that EvidenceNet rejects completion when otherwise satisfactory observations have the wrong source, have been substituted, or are stale.