2025/12/05 by Teofil Bodea, Bodea, Teofil, Masanori Misono +17
Computer Science · Social Sciences · #Access Control and Trust #Artificial Intelligence (cs.AI) #Cloud Data Security Solutions #Cryptography and Security (cs.CR) #FOS: Computer and information sciences #Multiagent Systems (cs.MA) #Security and Verification in Computing
paper · pdf · doi:10.48550/arxiv.2512.05951
openalex publication_date 2025/12/05 · openalex created_date 2025/12/09 · openalex updated_date 2026/07/28
AI agents powered by large language models are increasingly deployed as cloud services that autonomously access sensitive data, invoke external tools, and interact with other agents. However, these agents run within a complex multi-party ecosystem, where untrusted components can lead to data leakage, tampering, or unintended behavior. Existing Confidential Virtual Machines (CVMs) provide only per binary protection and offer no guarantees for cross-principal trust, accelerator-level isolation, or supervised agent behavior. We present Omega, a system that enables trusted AI agents by enforcing end-to-end isolation, establishing verifiable trust across all contributing principals, and supervising every external interaction with accountable provenance. Omega builds on Confidential VMs and Confidential GPUs to create a Trusted Agent Platform that hosts many agents within a single CVM using nested isolation. It also provides efficient multi-agent orchestration with cross-principal trust establishment via differential attestation, and a policy specification and enforcement framework that governs data access, tool usage, and inter-agent communication for data protection and regulatory compliance. Implemented on AMD SEV-SNP and NVIDIA H100, Omega fully secures agent state across CVM-GPU, and achieves high performance while enabling high-density, policy-compliant multi-agent deployments at cloud scale.