区块链加持的智能体安全框架:保护软件供应链全生命周期
Resource-Optimized and Energy-Aware Agentic AI Framework Anchored on Blockchain for Secure Software Supply Chains
这篇论文把 LLM 驱动的安全智能体和区块链结合,每次分析结果都签名上链,能给出可验证的放行或拦截决策,做 DevSecOps 的可以看看。
论文提出一个由联盟链支撑的智能体安全框架,覆盖从源码到部署的软件开发生命周期(SDLC)。框架包含源码完整性、依赖与SBOM分析、CI配置审计、制品验证、运行时策略评估等多类安全智能体,每个智能体由一个 LLM 负责解释制品、推理工具输出并生成结构化安全报告。所有智能体生成密码学签名的 attestation,通过智能合约写入许可链,链上设有智能体注册表、不可篡改的 attestation 日志和可执行的发布策略模块。文中用源码安全智能体的用例展示了分析、上链锚定、以及可验证的部署放行/拦截决策流程。
Resource-Optimized and Energy-Aware Agentic AI Framework Anchored on Blockchain for Secure Software Supply Chains
This paper proposes a blockchain-backed agentic security framework designed to safeguard the complete software development lifecycle (SDLC) while also securing the agentic AI components responsible for monitoring it. The framework coordinates a set of specialised security agents, covering source integrity, dependency and SBOM analysis, CI configura tion auditing, artifact verification, and runtime policy evaluation, each supported by a large language model (LLM) that interprets artefacts, reasons over tool outputs, and produces structured security reports. To ensure agent trustworthiness, every agent generates a cryptographically signed attestation that is recorded in a permissioned blockchain via smart contracts, including an agent registry, an immutable attestation log, and an enforceable release-policy module. Communication among agents and with blockchain nodes is secured using a consortium-operated certificate authority, ensuring authenticated and tamper-resistant interactions. A detailed use-case and sequence flow demonstrate how a source code security agent performs analysis, anchors its attestation on-chain, and triggers a verifiable allow/block deployment decision. The proposed framework of fers decentralised integrity transparent provenance, uninterrupted security assurance and a generalisable architecture to incorporate the agentic AI into the modern software supply chain security.