Live
Black Hat USAAI BusinessBlack Hat AsiaAI BusinessSam Altman's Coworkers Say He Can Barely Code and Misunderstands Basic Machine Learning Concepts - futurism.comGoogle News: Machine LearningSam Altman promised billions for AI safety. Here’s what OpenAI actually spent. - The New StackGoogle News: AI SafetyIdentifying Nonobvious AI WinnersBloomberg TechnologyRoadtripping with ChatGPT Voice Mode - MacStoriesGoogle News: ChatGPTShow HN: Gemma 4 Multimodal Fine-Tuner for Apple SiliconHacker News TopAnthropic pulls ahead of OpenAI as revenue race heats up - Proactive financial newsGoogle News: OpenAIGemma 4 - split mode Graph (Tensor Parallelism) in ik_llama incommmingReddit r/LocalLLaMAOpenAI Just Escalated Its Feud With Elon Musk, Alleging ‘Anticompetitive’ Plot - inc.comGoogle News: OpenAIkv-cache : support attention rotation for heterogeneous iSWA by ggerganov · Pull Request #21513 · ggml-org/llama.cppReddit r/LocalLLaMACan a Pro-Tech Podcast Solve OpenAI’s PR Woes? - Vanity FairGoogle News: OpenAILooking for simple ways to evaluate an AI agentdiscuss.huggingface.coEclipse Raises $1.3 Billion to Back Manufacturing, RoboticsBloomberg TechnologyBlack Hat USAAI BusinessBlack Hat AsiaAI BusinessSam Altman's Coworkers Say He Can Barely Code and Misunderstands Basic Machine Learning Concepts - futurism.comGoogle News: Machine LearningSam Altman promised billions for AI safety. Here’s what OpenAI actually spent. - The New StackGoogle News: AI SafetyIdentifying Nonobvious AI WinnersBloomberg TechnologyRoadtripping with ChatGPT Voice Mode - MacStoriesGoogle News: ChatGPTShow HN: Gemma 4 Multimodal Fine-Tuner for Apple SiliconHacker News TopAnthropic pulls ahead of OpenAI as revenue race heats up - Proactive financial newsGoogle News: OpenAIGemma 4 - split mode Graph (Tensor Parallelism) in ik_llama incommmingReddit r/LocalLLaMAOpenAI Just Escalated Its Feud With Elon Musk, Alleging ‘Anticompetitive’ Plot - inc.comGoogle News: OpenAIkv-cache : support attention rotation for heterogeneous iSWA by ggerganov · Pull Request #21513 · ggml-org/llama.cppReddit r/LocalLLaMACan a Pro-Tech Podcast Solve OpenAI’s PR Woes? - Vanity FairGoogle News: OpenAILooking for simple ways to evaluate an AI agentdiscuss.huggingface.coEclipse Raises $1.3 Billion to Back Manufacturing, RoboticsBloomberg Technology
AI NEWS HUBbyEIGENVECTOREigenvector

SentinelAgent: Intent-Verified Delegation Chains for Securing Federal Multi-Agent AI Systems

arXiv cs.MAby KrishnaSaiReddy PatilApril 6, 20262 min read0 views
Source Quiz

arXiv:2604.02767v1 Announce Type: cross Abstract: When Agent A delegates to Agent B, which invokes Tool C on behalf of User X, no existing framework can answer: whose authorization chain led to this action, and where did it violate policy? This paper introduces SentinelAgent, a formal framework for verifiable delegation chains in federal multi-agent AI systems. The Delegation Chain Calculus (DCC) defines seven properties - six deterministic (authority narrowing, policy preservation, forensic reconstructibility, cascade containment, scope-action conformance, output schema conformance) and one probabilistic (intent preservation) - with four meta-theorems and one proposition establishing the practical infeasibility of deterministic intent verification. The Intent-Preserving Delegation Protoco

View PDF HTML (experimental)

Abstract:When Agent A delegates to Agent B, which invokes Tool C on behalf of User X, no existing framework can answer: whose authorization chain led to this action, and where did it violate policy? This paper introduces SentinelAgent, a formal framework for verifiable delegation chains in federal multi-agent AI systems. The Delegation Chain Calculus (DCC) defines seven properties - six deterministic (authority narrowing, policy preservation, forensic reconstructibility, cascade containment, scope-action conformance, output schema conformance) and one probabilistic (intent preservation) - with four meta-theorems and one proposition establishing the practical infeasibility of deterministic intent verification. The Intent-Preserving Delegation Protocol (IPDP) enforces all seven properties at runtime through a non-LLM Delegation Authority Service. A three-point verification lifecycle achieves 100% combined TPR at 0% FPR on DelegationBench v4 (516 scenarios, 10 attack categories, 13 federal domains). Under black-box adversarial conditions, the DAS blocks 30/30 attacks with 0 false positives. Deterministic properties are unbreakable under adversarial stress testing; intent verification degrades to 13% against sophisticated paraphrasing. Fine-tuning the NLI model on 190 government delegation examples improves P2 from 1.7% to 88.3% TPR (5-fold cross-validated, F1=82.1%). Properties P1, P3-P7 are mechanically verified via TLA+ model checking across 2.7 million states with zero violations. Even when intent verification is evaded, the remaining six properties constrain the adversary to permitted API calls, conformant outputs, traceable actions, bounded cascades, and compliant behavior.

Comments: 12 pages, 2 figures, 9 tables. Includes TLA+ mechanical verification, DelegationBench v4 benchmark (516 scenarios), live LangChain agent integration, and independent red-team evaluation

Subjects:

Cryptography and Security (cs.CR); Artificial Intelligence (cs.AI); Multiagent Systems (cs.MA)

Cite as: arXiv:2604.02767 [cs.CR]

(or arXiv:2604.02767v1 [cs.CR] for this version)

https://doi.org/10.48550/arXiv.2604.02767

arXiv-issued DOI via DataCite (pending registration)

Submission history

From: KrishnaSaiReddy Patil [view email] [v1] Fri, 3 Apr 2026 06:25:18 UTC (27 KB)

Was this article helpful?

Sign in to highlight and annotate this article

AI
Ask AI about this article
Powered by Eigenvector · full article context loaded
Ready

Conversation starters

Ask anything about this article…

Daily AI Digest

Get the top 5 AI stories delivered to your inbox every morning.

More about

modelannounceservice

Knowledge Map

Knowledge Map
TopicsEntitiesSource
SentinelAge…modelannounceservicemillionpolicygovernmentarXiv cs.MA

Connected Articles — Knowledge Graph

This article is connected to other articles through shared AI topics and tags.

Knowledge Graph100 articles · 174 connections
Scroll to zoom · drag to pan · click to open

Discussion

Sign in to join the discussion

No comments yet — be the first to share your thoughts!