Poster: Towards ProofWeave: A Privacy-Minimised, Integrity-Anchored Evidence Plane for Continuous Agentic Assurance

📅 2026-09-28
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
This study addresses the absence of real-time, policy-bound, and privacy-preserving evidence chains in the continuous monitoring of AI agents by proposing the ProofWeave framework. This framework introduces the concept of an "evidence chain at recording time," wherein a bounded Weaver Agent translates policy intents into proof obligations at action boundaries. It generates privacy-minimizing transactions that bind control responses to policy snapshots, storing them in an immutable ledger to construct a proof graph. Experimental results demonstrate that this approach reduces the number of candidate bindings to one, decreases verification operations to approximately 26, and lowers storage overhead from 0.79 MiB to 0.15 MiB. Consequently, ProofWeave significantly enhances adjudication efficiency, privacy protection, and tamper resistance.
📝 Abstract
Agentic AI systems increasingly act via tools, memory, delegation, and external services. Existing observability and provenance mechanisms can reconstruct events post hoc, but they rarely show, at the time of the record, whether each policy-relevant action was checked by the intended control before execution. This leaves a trust-observability gap for continuous monitoring, detection, and response: later assurance may rest on evidence that is incomplete, privacy-leaking, mutable, or detached from the policy context that governed the event. What's missing in the literature is contemporaneous, policy-bound evidence that the intended control was evaluated under the policy in force at the time. We introduce ProofWeave, a record-time chain-of-evidence concept for agentic AI assurance. At each policy-relevant action boundary, ProofWeave generates a privacy-minimised and integrity-anchored evidence transaction that binds (i) agent intent or action, (ii) control response, and (iii) a policy-at-time snapshot. Each transaction is committed to an append-only ledger and materialised into a derived proof graph. A bounded Weaver Agent translates policy intent into proof obligations, while deterministic validators check evidence completeness, privacy minimisation, policy binding, and integrity. In the minimal scenario, an agent attempts to transmit a secret to an unapproved external sink. The audit compares a logs-only correlation baseline with ProofWeave across verdict latency, join ambiguity, privacy exposure, tamper detection, and resistance to graph-only proof injection. ProofWeave reduces candidate bindings per verdict from up to `10,201` to one, validation operations from up to `10,201` to approximately `26`, and assurance evidence storage from `0.79`\~MiB to `0.15`\~MiB per project.
Problem

Research questions and friction points this paper is trying to address.

Agentic AI
trust-observability gap
policy-bound evidence
continuous assurance
provenance
Innovation

Methods, ideas, or system contributions that make the work stand out.

ProofWeave
Agentic AI Assurance
Chain-of-Evidence
Privacy-Minimisation
Policy-Bound Verification
🔎 Similar Papers
No similar papers found.
G
Guy Lupo
Swinburne University of Technology, Melbourne, VIC, Australia
N
Nguyen Hung Nguyen
Swinburne University of Technology, Melbourne, VIC, Australia
Viet Vo
Viet Vo
Department of Computing Technologies, Swinburne University
Distributed System SecurityEncrypted DatabaseTrustworthy ML/AI
C
Chamikara M. A. P.
CSIRO, Melbourne, VIC, Australia
Guangdong Bai
Guangdong Bai
Associate Professor of The University of Queensland
System SecuritySoftware SecurityTrustworthy AIPrivacy Compliance