Beyond Trust: Proof-Carrying Generation and Independent Release Assurance for Multi-Agent LLMs
Abstract
Multi-agent LLM systems act across trust boundaries, yet downstream consumers cannot independently verify *why* an output was released or how often released outputs fail. We introduce **PCG-MAS**, a proof-carrying release-assurance framework with two certificates. A *DecisionCertificate* binds each release to a consumer-derived acceptance scope, exact execution and policy obligations, semantic checks, and replay metadata, so a producer that curates what the checker sees cannot force acceptance. An *EpochRiskCertificate* binds the complete committed release stream to an independent risk-limiting audit. Across seven models and eight factual and agentic datasets, we test controlled-coverage acceptance, exhaustive curation attacks, log-bypass attacks, weighted auditing, replay, and cost. Relative to frozen primary comparators, the worst-case released-failure difference under selective- view curation is −3.1 pp and the natural released-failure difference at matched coverage is −1.3 pp; the governed population records 0 unlogged consequential releases, and the pooled epoch audit reaches CERTIFY with a 36.7% label saving over uniform auditing.
est. 32% chance this paper gets accepted at ICLR 2027.
What do you think this paper will get?
All positions stay anonymous.