Trusted AI Agents in the Cloud

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Bodea, Teofil, Misono, Masanori, Pritzi, Julian, Sabanic, Patrick, Sommer, Thore, Unnibhavi, Harshavardhan, Schall, David, Santos, Nuno, Stavrakakis, Dimitrios, Bhatotia, Pramod
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866915672219451392
author Bodea, Teofil
Misono, Masanori
Pritzi, Julian
Sabanic, Patrick
Sommer, Thore
Unnibhavi, Harshavardhan
Schall, David
Santos, Nuno
Stavrakakis, Dimitrios
Bhatotia, Pramod
author_facet Bodea, Teofil
Misono, Masanori
Pritzi, Julian
Sabanic, Patrick
Sommer, Thore
Unnibhavi, Harshavardhan
Schall, David
Santos, Nuno
Stavrakakis, Dimitrios
Bhatotia, Pramod
contents AI agents powered by large language models are increasingly deployed as cloud services that autonomously access sensitive data, invoke external tools, and interact with other agents. However, these agents run within a complex multi-party ecosystem, where untrusted components can lead to data leakage, tampering, or unintended behavior. Existing Confidential Virtual Machines (CVMs) provide only per binary protection and offer no guarantees for cross-principal trust, accelerator-level isolation, or supervised agent behavior. We present Omega, a system that enables trusted AI agents by enforcing end-to-end isolation, establishing verifiable trust across all contributing principals, and supervising every external interaction with accountable provenance. Omega builds on Confidential VMs and Confidential GPUs to create a Trusted Agent Platform that hosts many agents within a single CVM using nested isolation. It also provides efficient multi-agent orchestration with cross-principal trust establishment via differential attestation, and a policy specification and enforcement framework that governs data access, tool usage, and inter-agent communication for data protection and regulatory compliance. Implemented on AMD SEV-SNP and NVIDIA H100, Omega fully secures agent state across CVM-GPU, and achieves high performance while enabling high-density, policy-compliant multi-agent deployments at cloud scale.
format Preprint
id arxiv_https___arxiv_org_abs_2512_05951
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Trusted AI Agents in the Cloud
Bodea, Teofil
Misono, Masanori
Pritzi, Julian
Sabanic, Patrick
Sommer, Thore
Unnibhavi, Harshavardhan
Schall, David
Santos, Nuno
Stavrakakis, Dimitrios
Bhatotia, Pramod
Cryptography and Security
Artificial Intelligence
Multiagent Systems
AI agents powered by large language models are increasingly deployed as cloud services that autonomously access sensitive data, invoke external tools, and interact with other agents. However, these agents run within a complex multi-party ecosystem, where untrusted components can lead to data leakage, tampering, or unintended behavior. Existing Confidential Virtual Machines (CVMs) provide only per binary protection and offer no guarantees for cross-principal trust, accelerator-level isolation, or supervised agent behavior. We present Omega, a system that enables trusted AI agents by enforcing end-to-end isolation, establishing verifiable trust across all contributing principals, and supervising every external interaction with accountable provenance. Omega builds on Confidential VMs and Confidential GPUs to create a Trusted Agent Platform that hosts many agents within a single CVM using nested isolation. It also provides efficient multi-agent orchestration with cross-principal trust establishment via differential attestation, and a policy specification and enforcement framework that governs data access, tool usage, and inter-agent communication for data protection and regulatory compliance. Implemented on AMD SEV-SNP and NVIDIA H100, Omega fully secures agent state across CVM-GPU, and achieves high performance while enabling high-density, policy-compliant multi-agent deployments at cloud scale.
title Trusted AI Agents in the Cloud
topic Cryptography and Security
Artificial Intelligence
Multiagent Systems
url https://arxiv.org/abs/2512.05951