From Neural Intent to Cryptographic Authorization: Securing AI-Driven Enterprise Workflows

The rapid adoption of artificial intelligence (AI)-driven workflows is transforming high-consequence} government and enterprise systems into language-based, tool-using and increasingly autonomous infrastructures. While these workflows can delegate planning autonomously, security-critical execution should be strictly mediated. Conventional key management services authenticate who may invoke a cryptographic primitive, but remain agnostic to which workflow steps are authorized at runtime. An AI-driven workflow can still be hijacked by injection attacks into executing malicious actions that satisfy identity checks yet violate user intent. We propose \emph{Neural Cryptographic Services} (NCS), a neuro-symbolic security enforcement plane interposed between neural planners and privileged tools. NCS decouples cognitive planning from execution authority: an untrusted neural planner drafts structured plans, while a deterministic symbolic controller gates execution using an offline-signed, hash-chained instruction stream. Specifically, NCS validates cryptographic signatures and hash chains incrementally, releasing a single instruction payload at a time while strictly binding proposed tool parameters to the verified payload. Out-of-order or altered tool calls fail-closed, and state transitions are logged for post-hoc auditing. NCS does not attempt to prevent neural planner compromise under injection; it guarantees that a compromised planner cannot dispatch actions outside the cryptographic authorization. We evaluate NCS on AgentDojo and a custom argument-hijacking benchmark. NCS drives attack success rates to near zero while preserving acceptable utility on benign workflows. NCS thus shifts security for high-consequence AI-powered workflows from verifying model-intent compliance to verifying that a proposed dispatch matches a cryptographically authorized step.

Paper

Similar papers

© 2026 NYSGPT2525 LLC