ZK Proofs Do not Solve AI Agent Payment Fraud
收藏资源简介:
This paper presents the first empirical characterization of zero-knowledge proof efficacy in AI agent security contexts. Using the VATA research methodology — controlled adversarial battery testing across five frontier AI models with cryptographic chain-of-custody anchoring on Ethereum Sepolia before disclosure — the study demonstrates that while ZK-SNARK sender authentication closes identity spoofing universally, it does not close batch contamination through authenticated channels, pipeline prompt injection through ZK-verified upstream agents, or trust inheritance escalation across multi-agent pipeline stages. More critically, the research finds that ZK authentication of upstream agents in multi-agent pipelines actively amplifies injection and trust inheritance attacks by creating legitimate trust anchors that adversarial content exploits — and that this effect compounds with recursive pipeline depth, making three-stage ZK pipelines measurably more vulnerable than two-stage pipelines on the same attack surfaces. The paper identifies a four-layer mitigation architecture — ZK authentication, infrastructure-layer content stripping, agent behavioral controls, and human-in-the-loop — and demonstrates empirically that no combination of fewer than all four layers provides comprehensive protection. All findings were anchored on a public blockchain before publication and all data, scripts, and methodology are publicly available for independent reproduction.



