Toward cryptographically verifiable authorization for autonomous AI agents: A security hypothesis, preliminary formal model, and proof-of-concept implementation
M. Llamb\'i-Morillas, D. Fern\'andez-Fern\'andez
https://arxiv.org/abs/2607.21325 https://arxiv.org/pdf/2607.21325 https://arxiv.org/html/2607.21325
arXiv:2607.21325v1 Announce Type: new
Abstract: Autonomous AI agents increasingly execute actions, invoke tools, and operate on protected resources with limited human oversight. Existing authentication and authorization mechanisms establish identity and delegate authority, but do not inherently provide cryptographic evidence that a concrete request issued by a specific agent satisfies the applicable policy in a specific execution context. This paper hypothesizes that agent authorization can be formalized as a cryptographically verifiable relation, denoted $R_{CVA}$, that jointly binds an agent principal, a concrete authorization request, an execution context, and the satisfaction of an applicable policy, while selectively preserving the confidentiality of private authorization attributes. We introduce a preliminary formal abstraction for Cryptographically Verifiable Agent Authorization (CVA), define a compact set of candidate security properties including authorization soundness, principal binding, request binding, policy binding, and replay resistance, and provide an executable zero-knowledge proof of concept that instantiates selected elements of the model over a Groth16 zk-SNARK construction. We further identify and formalize the structural separation among identity binding, authorization-request binding, and runtime execution binding as a central open problem in the design of secure agentic systems (a distinction {not explicitly addressed by} current agentic security frameworks) and present a falsifiable research agenda for its resolution.
toXiv_bot_toot
Elastic Trapped States at Dislocation Defects in Scaled Coupling and Hofstadter Models
Yangkai Liu, Cheng Lin, Yuan Liu, Jiao Shen, Yifan Zhu, Haiyan Fan, Hui Zhang
https://arxiv.org/abs/2607.19890 https://arxiv.org/pdf/2607.19890 https://arxiv.org/html/2607.19890
arXiv:2607.19890v1 Announce Type: new
Abstract: Elastic topological dislocations provide a pathway for trapping elastic wave energy at internal defects, rather than being confined solely to external boundaries or corners, which are typically associated with topological insulators (TIs). However, two practical constraints persist. First, highly confined dislocation states based on conventional Su-Schrieffer-Heeger (SSH) dimerization usually require a large coupling contrast and a correspondingly enlarged bandgap, which may be challenging to realize. Second, some Hamiltonians with richer topological physics often contain complex hopping terms, synthetic gauge fields or nonlocal couplings, which substantially increase the geometric complexity of experimental samples. Here, dislocation-induced trapped states are demonstrated in both a scaled coupling (SC) model and a Hofstadter model (HM) within an elastic platform. In the SC model, the trapped mode is treated as a higher localized state in the continuum rather than an in-gap mode in the SSH model. Consequently, the SC-induced dislocation can trap an enhanced mode without the requirement of an enlarged bandgap. For the HM, Householder tridiagonalization is used to map the original tight-binding Hamiltonian with complex hopping terms onto a tridiagonal matrix with only positive-real-valued nearest-neighbour (NN) hopping terms. Truncation at a weak-hopping position preserves the topological phenomena and allows a dislocation defect to be constructed from the shortened aperiodic chain. The results establish a practical route for designing highly localized modes without relying solely on bandgap enlargement or complex couplings, which advance the topological physics of elastic wave systems and promise enhanced possibilities for elastic functional devices.
toXiv_bot_toot
Since it was relevant to a discussion I just had on here and is something most people probably haven't thought about much (unless you've taken one of a handful of philosophy classes), I thought I'd try to lay out a key piece of Descartes' Meditations (#philosophy
Build-Authorized Evidence for Opaque Calls: A Fail-Closed Rewrite-Authority Boundary
Zhonghua Yi (Toka Language Research Group)
https://arxiv.org/abs/2607.18949 https://arxiv.org/pdf/2607.18949 https://arxiv.org/html/2607.18949
arXiv:2607.18949v1 Announce Type: new
Abstract: Detached semantic facts about opaque native providers do not by themselves justify compiler rewrites: rewrite authority must be confined to the accepted fact, selected provider and build, caller, callback environment, observation, and runtime target. We present a build-authorized path-effect interface that enforces this boundary through fail-closed authorization and link receipts. The design separates receipt closure, callback-environment closure, and projection identity, and passes accepted facts to LLVM through a narrow internal API. We use one-hop topology-load reuse as a minimal observable witness of authority, not as the optimization target.
A conservative LLVM consumer reuses a pointer observation only from a noalias root or one constant nonzero projection. Rocq models prove conditional refinement and authority non-amplification under explicit effect, alias, compiler/ABI, and target-resolution premises. We instantiate checked production with Toka: a source-summary gate emits exact LLVM IR, a separate IR checker accepts only a bounded topology-preserving subset, and only accepted IR is compiled into the receipt-bound provider object. A bounded static Darwin/arm64 profile also checks the final direct branch target.
Across issuer-declared readv, recvmsg, and Cairo boundaries, authorized IR retains each opaque call, reduces the relevant loads from two to one, and preserves observed results; mismatched providers, builds, callbacks, projections, and unsupported IR remain neutral. A libjpeg case is rejected because its callback environment is open, while a bound callback singleton demonstrates the supported closure rule. The contribution is a checked deployment-compiler boundary with an explicit trust and applicability frontier, not a uniquely expressive effect encoding or a new load-elimination algorithm.
toXiv_bot_toot
On the Structural Limits of Machine Learning Decision Systems: An Information-Theoretic, Interaction-Based, and Stochastic-Dynamical Perspective
Nestor R. Barraza, Gabriel Pena
https://arxiv.org/abs/2608.13510 https://arxiv.org/pdf/2608.13510 https://arxiv.org/html/2608.13510
arXiv:2608.13510v1 Announce Type: new
Abstract: Machine learning procedures are commonly evaluated in terms of predictive accuracy and computational efficiency. However, their achievable performance is fundamentally constrained by structural properties of the underlying data-generating process, which are formalized in terms of informational bounds. In this work we examine intrinsic limits of data-driven decision systems from an information-theoretic and interaction-based perspective. We analyze minimal achievable error in classification through Fano-type bounds and precision limits in parametric estimation via the Cram\'er-Rao inequality, emphasizing that such limits depend on the underlying model rather than on algorithmic sophistication alone. We further discuss how implicit assumptions, such as independence, ergodicity, and distributional stability, affect the validity of inferential procedures. Building on interaction-based modeling principles, we review typical frameworks such as Markov Random Fields and potential based representations for encoding dependence mechanisms. We also describe decision systems, including LLM-integrated agent architectures, as feedback-driven stochastic processes where state-dependent dynamics may induce emergent macroscopic behavior. This perspective highlights the importance of having adequate models for the data as a prerequi- site for expanding predictive capability, and situates algorithmic learning within the informational limits imposed by the models.
toXiv_bot_toot
The US supreme court on Thursday ruled
in favor of the Trump administration’s bid to strip temporary protected status (TPS) from hundreds of thousands of Haitians and Syrians,
who were legally in the US and protected from deportation.
People with TPS are given the permission to live and work in the US because the Department of Homeland Security (DHS) deemed their home countries to be unsafe due to war, political instability or natural disasters.
In the past year, Tru…
EVOLVE: Efficient Learned Volume Compression with Variable-Rate Encoding on a Cross-Domain Database
Kaiyuan Tang, Maizhe Yang, Chaoli Wang
https://arxiv.org/abs/2607.18187 https://arxiv.org/pdf/2607.18187 https://arxiv.org/html/2607.18187
arXiv:2607.18187v1 Announce Type: new
Abstract: Large-scale scientific simulations generate volumetric data at rates that far outpace advances in storage and network bandwidth, making effective lossy compression increasingly critical. However, conventional compressors often struggle to preserve fine structural details at high compression ratios (CRs), and implicit neural representations (INRs) require costly per-volume optimization and produce models with fixed CRs. To respond, we present EVOLVE, an autoencoder (AE)-based volume-compression framework that targets high CRs for offline compression, with three key contributions. First, we construct a large-scale cross-domain database of 6,376 volumes from 21 scientific simulations, curated via perceptual hashing to ensure diversity, enabling the optimized model to extract features that generalize across volumes within the covered scientific simulation domains. Second, we reexamine the design space of AE-based compressors and incorporate several macro- and micro-designs into a vanilla AE to develop EVOLVE, which substantially improves the expressive power and compression capability. Third, we develop a learnable gain mechanism with a three-stage training strategy to enable variable-rate encoding, allowing a single model to support continuous CR adjustment at inference time. Experiments on multiple unseen scientific simulation datasets demonstrate that EVOLVE achieves substantially higher CRs than conventional compressors at comparable reconstruction quality, while delivering compression speeds that are orders of magnitude faster than INR-based methods, highlighting its promise as a strong alternative for compressing scientific data. The code, model weights, and results are available on our project page at https://evolve-vis.github.io.
toXiv_bot_toot
@… You may already know about this. Just in case you don't, here!
Point-&-Click Showcase & Steam Event
https://
Hierarchical Bayesian Calibration with Bayesian Committee Machine
Sebastian Heinekamp, David M. Higdon, Andreas Adelmann
https://arxiv.org/abs/2608.12603 https://arxiv.org/pdf/2608.12603 https://arxiv.org/html/2608.12603
arXiv:2608.12603v1 Announce Type: new
Abstract: Calibrating computational models to experimental data is a core task in applied statistics, especially in scientific domains, where physical experiments are costly and simulations play a central role in design and inference. Motivated by uncertainty quantification challenges in particle accelerator experiments, we develop and evaluate a Hierarchical Bayesian Calibration framework. In contrast to standard Bayesian calibration, certain inputs - such as beam injection amplitude - must be estimated separately for each experiment. We adopt the Kennedy-O'Hagan formulation and extend it with a hierarchical prior structure to model the distribution of experiment-specific calibration parameters, thus borrowing strength and improving generalisation across repeated experiments. A key methodological challenge arises from the need to evaluate a large number of forward simulations, which renders conventional Markov chain Monte Carlo approaches computationally prohibitive. To address this, we leverage the Bayesian Committee Machine as a scalable modelling strategy for Gaussian Process emulators. The BCM provides a principled divide-and-conquer approach, enabling parallel inference and reducing computational cost without requiring problem-specific tuning of the emulator approximation. Posterior sampling is performed using the No-U-Turn Sampler, supported by automatic differentiation in Julia, which removes the need for analytic gradient derivation and facilitates flexible model specification. We assess the proposed framework using established benchmark problems and simulated data from the Argonne Wakefield Accelerator. The results demonstrate substantial computational savings and robust calibration performance, highlighting the applicability of the method to large-scale scientific modelling problems.
toXiv_bot_toot
SCALE-Sim EVA: Design Principles for an Extensible, Visualizable, and Adaptable Accelerator Simulation Framework
Jingtian Dang, Ritik Raj, Tushar Krishna
https://arxiv.org/abs/2608.12354 https://arxiv.org/pdf/2608.12354 https://arxiv.org/html/2608.12354
arXiv:2608.12354v1 Announce Type: new
Abstract: Modern AI accelerators increasingly combine heterogeneous compute units, hierarchical memories, local buffers, and specialized data movement paths. This diversity makes fixed accelerator simulators difficult to extend beyond their original execution model. We present SCALE-Sim EVA, an extensible, visualizable, and adaptable simulation framework for IR-aware accelerator modeling. EVA represents workloads as tensor-based commands, tracks runtime tensor placement and readiness, and executes commands on composable hardware components with user-defined functional units and memory behavior. Instead of replaying address-level cycle traces, EVA computes cycle timing from tensor readiness, hardware-unit availability, and modeled operation or transfer latency. Its command decomposition mechanism bridges compiler-level IR granularity and hardware-level execution granularity, allowing global tensor operations to be lowered and scheduled locally across a hardware hierarchy. EVA also emits open command and storage traces for visual analysis of execution timelines, memory occupancy, and resource contention.
toXiv_bot_toot