Resource-Optimized and Energy-Aware Agentic AI Framework Anchored on Blockchain for Secure Software Supply Chains

📅 2026-09-25
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
This study addresses the challenges of software supply chain security and the insufficient trustworthiness of large language model (LLM)-based agents by proposing a permissioned blockchain-driven agent collaboration framework. The framework employs LLM-powered security agents to monitor the entire Software Development Life Cycle (SDLC), while integrating smart contracts and cryptographic signature authentication to achieve decentralized integrity verification, transparent provenance tracking, and verifiable deployment decisions. By establishing a generalized AI-integrated architecture, this work provides continuous security assurance for software supply chains, effectively enhancing the trustworthiness of agent collaboration and overall system robustness.
📝 Abstract
This paper proposes a blockchain-backed agentic security framework designed to safeguard the complete software development lifecycle (SDLC) while also securing the agentic AI components responsible for monitoring it. The framework coordinates a set of specialised security agents, covering source integrity, dependency and SBOM analysis, CI configura tion auditing, artifact verification, and runtime policy evaluation, each supported by a large language model (LLM) that interprets artefacts, reasons over tool outputs, and produces structured security reports. To ensure agent trustworthiness, every agent generates a cryptographically signed attestation that is recorded in a permissioned blockchain via smart contracts, including an agent registry, an immutable attestation log, and an enforceable release-policy module. Communication among agents and with blockchain nodes is secured using a consortium-operated certificate authority, ensuring authenticated and tamper-resistant interactions. A detailed use-case and sequence flow demonstrate how a source code security agent performs analysis, anchors its attestation on-chain, and triggers a verifiable allow/block deployment decision. The proposed framework of fers decentralised integrity transparent provenance, uninterrupted security assurance and a generalisable architecture to incorporate the agentic AI into the modern software supply chain security.
Problem

Research questions and friction points this paper is trying to address.

Software Supply Chain Security
Agentic AI
Software Development Lifecycle
Trustworthiness
Innovation

Methods, ideas, or system contributions that make the work stand out.

Agentic AI
Blockchain
Software Supply Chain Security
Large Language Models
Smart Contracts
🔎 Similar Papers
No similar papers found.
💼 Related Jobs
No related jobs found.
Toqeer Ali Syed
Toqeer Ali Syed
PHD, Full Professor, Islamic University of Al Madinah Al Munawara
SecurityBlockchainAIMachine LearningDeep Learning and Cloud Computing
A
Asadullah Abdullah Khan
Faculty of Computer and Information System, Islamic University in Madinah, Kingdom of Saudi Arabia