HDP-P: Human Delegation Provenance for Physical AI Agents

Fuente: Zenodo
Gespeichert in:
Bibliographische Detailangaben
1. Verfasser: Dalugoda, Asiri
Format: Recurso digital
Sprache:Englisch
Veröffentlicht: Zenodo 2026
Schlagworte:
Online-Zugang:
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
_version_ 1866901491937181696
author Dalugoda, Asiri
author_facet Dalugoda, Asiri
contents <p>The Human Delegation Provenance (HDP) protocol provides a cryptographic mechanism for verifying that AI agent actions are legitimately delegated by a human principal. While HDP addresses delegation integrity in digital environments, existing orchestration frameworks for embodied AI systems continue to authenticate systems without verifying the provenance of physical actions.</p> <p>This paper introduces HDP-P, an authorization layer for physical AI agents that enforces pre-execution verification of human delegation for actions with irreversible real-world consequences. HDP-P extends the HDP token model with embodiment constraints, policy attestation, and a formal irreversibility classification (Class 0–3) that determines required authorization strength.</p> <p>We define a threat model specific to embodied AI pipelines, including prompt injection into orchestration layers, unauthorized cross-fleet delegation, sim-to-real policy tampering, and irreversibility-targeted exploitation. We show that these classes are not sufficiently mitigated by existing robotics safety standards or network authentication models.</p> <p>A reference implementation and live demonstration validate the protocol in a simulated robotic manipulation environment. In controlled experiments, HDP-P prevents execution of unauthorized Class 3 actions under adversarial prompt injection, blocking actuator movement within sub-100 ms latency.</p> <p>HDP-P reframes physical AI safety from post-hoc auditing to pre-execution authorization, establishing a composable trust layer between LLM reasoning systems and physical actuation. The protocol is compatible with ROS2, NVIDIA OSMO, Hugging Face LeRobot, and VLA pipelines, and is designed for integration with emerging IETF attestation frameworks.</p>
format Recurso digital
id zenodo_https___doi_org_10_5281_zenodo_19594396
institution Zenodo
language eng
publishDate 2026
publisher Zenodo
record_format zenodo
spellingShingle HDP-P: Human Delegation Provenance for Physical AI Agents
Dalugoda, Asiri
physical AI security
embodied agents
delegation provenance
cryptographic authorization
prompt injection
sim-to-real transfer
robot fleet security
irreversibility classification
HDP
<p>The Human Delegation Provenance (HDP) protocol provides a cryptographic mechanism for verifying that AI agent actions are legitimately delegated by a human principal. While HDP addresses delegation integrity in digital environments, existing orchestration frameworks for embodied AI systems continue to authenticate systems without verifying the provenance of physical actions.</p> <p>This paper introduces HDP-P, an authorization layer for physical AI agents that enforces pre-execution verification of human delegation for actions with irreversible real-world consequences. HDP-P extends the HDP token model with embodiment constraints, policy attestation, and a formal irreversibility classification (Class 0–3) that determines required authorization strength.</p> <p>We define a threat model specific to embodied AI pipelines, including prompt injection into orchestration layers, unauthorized cross-fleet delegation, sim-to-real policy tampering, and irreversibility-targeted exploitation. We show that these classes are not sufficiently mitigated by existing robotics safety standards or network authentication models.</p> <p>A reference implementation and live demonstration validate the protocol in a simulated robotic manipulation environment. In controlled experiments, HDP-P prevents execution of unauthorized Class 3 actions under adversarial prompt injection, blocking actuator movement within sub-100 ms latency.</p> <p>HDP-P reframes physical AI safety from post-hoc auditing to pre-execution authorization, establishing a composable trust layer between LLM reasoning systems and physical actuation. The protocol is compatible with ROS2, NVIDIA OSMO, Hugging Face LeRobot, and VLA pipelines, and is designed for integration with emerging IETF attestation frameworks.</p>
title HDP-P: Human Delegation Provenance for Physical AI Agents
topic physical AI security
embodied agents
delegation provenance
cryptographic authorization
prompt injection
sim-to-real transfer
robot fleet security
irreversibility classification
HDP
url https://doi.org/10.5281/zenodo.19594396