The Dependency-Aware Quorum Controller (DAQC) is designed to enforce structural cuts at runtime admission, evaluate its mechanics via analytical derivations and simulations, and provide a frozen 120-task external benchmark suite.
Abstract
Multi-agent quorums are widely used to authorize high-stakes infrastructure and policy mutations, yet distinct reviewers often share upstream telemetry, documents, or tool backends. When upstream inputs fail, multiple votes collapse onto a single corrupted cause: replication does not imply epistemic redundancy. We introduce Epistemic Fault Domains (EFDs) and the Structural Epistemic Cut \kappa_E, which quantifies the minimum number of modeled root faults whose exposure covers an authorizing coalition relative to an explicit Epistemic Fault Basis. Under closed causal accounting, conservative exposure, and authorization alignment, \kappa_E lower-bounds the number of roots required for semantic compromise (\kappa_S). We prove that arbitrarily large quorums can retain \kappa_E=1, that recognizing shared ancestry never increases credited resilience, and that adding voters at a fixed threshold cannot increase the cut under compatible exposure extensions. Finally, we design the Dependency-Aware Quorum Controller (DAQC) to enforce structural cuts at runtime admission, evaluate its mechanics via analytical derivations and simulations, and provide a frozen 120-task external benchmark suite.
PRIMUS, which couples prime-power identity with BLS aggregate signatures (PIAC), derives a safe-kill threshold that reduces false-positive agent termination from 80% to 0.00% under 10% channel noise, gives the closed-form economic boundary where singleton governance outperforms Byzantine quorum, and specifies VRF succe...
Dispersion–revision coupling is operationalized : the degree to which an intervention that verifiably increases the dispersion of a collective’s outputs in embedding space is accompanied by genuine revision of the collective’s epistemic stance is accompanied by premise-preserving reformulation.
LLM agents increasingly take privileged, often irreversible structured actions, such as paying an invoice. They assemble each action from action-critical fields in documents and tool outputs that an adversary can corrupt, and indirect prompt injection can drive the model itself to extract attacker-chosen values. Curren...
Anmol Pandey, A. Jain, Liang-Wei Chen et al.· 0 citations
An integrative review of the four literatures the discipline of computational jurisprudence must synthesize, namely, object-capability security; verifiable, proof-carrying, and zero-knowledge computation; policy-as-code and computational law; and agentic AI with its emerging payment protocols.
Multi-agent systems derive their capabilities from sharing evidence, delegating tasks, and combining information across agents. The same process creates a safety problem: contributions that are admissible in isolation can jointly enable a prohibited use. Blocking every sensitive action avoids disclosure but defeats the...
Yun-Bei Zhang, Saiyue Lyu, Janet Wang et al.· 0 citations
This paper introduces a compositional model explaining why no component is catastrophic alone, yet their conjunction can produce correlated destructive action, and separates three population-reach routes from a common core of dormancy, activation, authority, reachable targets, and failed recovery.
Satoshi Matsuoka· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.