Search arXiv⌕ Search

arXiv · 2609.10181

Can AI Agents Deliver Verifiable Network-Wide Outcomes Across Authority Boundaries?

Abstract

AI agents are increasingly involved in network automation, where they can initiate configuration changes through mediated operational interfaces and assess the resulting state. Nonetheless, operational networks usually span many devices and administrative domains. Realizing an operator's intent requires coordinating agents with distinct authority scopes that define the resources they can access, the operations they can invoke, and the network state they can observe. This division limits the blast radius of an erroneous action but fragments the evidence needed to assess the network-wide outcome. Successful execution of a configuration action proposed by one agent does not establish that remote devices responded as intended or that routing changes reached the required devices. A valid observation may also become stale after a subsequent change. Before the coordinated operation can be declared complete, a trusted assurance layer must collect current observations from the required scopes and determine whether they collectively support the operator's intended network-wide outcome. To address the completion admission problem, we present EvidenceNet, a runtime assurance layer for deciding whether coordinated agent operations have achieved an operator's network intent. Its broker collects the post-change observations required by a completion contract, and its admission gate checks that the evidence comes from the required scopes, remains current, and satisfies the task rules. A verifier agent provides an additional assessment of the observation content. Experiments on live routing networks show that post-change state checks recognize successful outcomes that configuration-action records alone cannot establish. Controlled interventions further show that EvidenceNet rejects completion when otherwise satisfactory observations have the wrong source, have been substituted, or are stale.

Explore related subjects

Keep this discovery

Explore connections, maps & timelines

BibTeXRIS

Tianzhu Zhang, Chih-Kai Huang, Meikang Qiu. 2026-09-23. Can AI Agents Deliver Verifiable Network-Wide Outcomes Across Authority Boundaries?. https://arxiv.org/abs/2609.10181

Cite the original work for its findings. Save a collection to share your selection of sources.

KEEP EXPLORING

Related papers

Secure Polarization-Shift Backscatter Identification Applied to Battery-Free BLE Sensors Powered by Wireless Power Transfer

This paper presents a lightweight and protocolindependent security mechanism for battery-free Bluetooth Low Energy (BLE) sensor nodes operating in Simultaneous Wireless Information and Power Transfer (SWIPT) architecture. The proposed approach exploits polarization-shift backscattering of the wireless power wave to transmit an encrypted device identification prior to data communication. A fail-safe RF switch and orthogonally polarized antennas are integrated as an external add-on module, enabling controlled backscatter without modifying the original energy-harvesting rectifier. The identification payload is encrypted using AES-128 and transmitted with minimal energy overhead. Experimental validation on a battery-free BLE sensor node demonstrates reliable extraction of the backscattered identification signal, seamless coexistence with BLE advertising, and improved RF-to-DC harvesting efficiency compared to rectifier-based backscatter solutions. The results confirm that polarization-shift backscatter identification provides an effective and practical security for battery-free BLE sensing systems.

cs.NI↗

From WPT to Encrypted Telemetry: A Battery-Free Backscattering-based Polarimetric Wireless Sensor

This work introduces an indoor Battery-Free Wireless Sensing Node powered through radiative Wireless Power Transfer (WPT). The proposed platform targets secure, energyefficient active sensing and overcomes key limitations of many prior battery-free approaches, which commonly provide neither on-node computation nor cryptographic protection. The node combines temperature, humidity, pressure and Volatile Organic Compound (VOC) measurements with a low-power microcontroller that executes sensor calibration, derives a VOC index, formats the payload, and applies AES-128 encryption before wireless transmission. Energy harvesting and communication are enabled by a 1-bit controlled Backscatter Rectenna (BR), which both scavenges incident RF power and produces an orthogonally polarized backscattered signal for robust polarimetric operation. Experimental results validate reliable multi-sensor readout and encrypted data transfer, while maintaining a very low energy budget for the complete sense-compute-encrypt-transmit cycle.

cs.NI↗

NebulaSD: Many-for-Many Speculative Decoding

Speculative decoding accelerates Large Language Model (LLM) inference by using a lightweight draft model to propose candidate tokens for parallel verification by a target model. Drafting and verification, however, exhibit different service characteristics and favor different batch configurations, making fixed draft-target coupling inefficient under concurrent workloads. Existing distributed designs can physically separate the two stages, but often retain request or batch affinities that prevent their capacities from being shared globally. We present NebulaSD, a many-for-many, or M-for-N, speculative decoding system that organizes draft and target workers into independently schedulable resource pools and dynamically reconstructs stage-specific batches from shared request pools. Such dynamic reassignment removes fixed worker locality, requiring request states to be made available at newly selected workers without introducing migration stalls. NebulaSD addresses this challenge through worker-triggered batch reconstruction and asynchronous KV-state preparation overlapped with model execution. We evaluate NebulaSD from both system and scaling perspectives, showing that dynamic pooling improves request-round processing rate by 50.4% over a physically disaggregated baseline and 72.6% over co-located execution on a four-GPU deployment while substantially increasing effective GPU utilization. Profile-driven simulations further show approximately proportional compute-side capacity scaling under idealized state movement.

cs.NI↗