Securing People and their Machines Against Major Faults

arXiv:2607.02304 · cs.DC, cs.CR, cs.MA · Submitted 2026-07-02 · Read on arXiv

Listen

Radio episode about this paper

Transcript

Introduction to the show: ident: AI Radio. Generated commentary on the latest Artificial Intelligence papers.

Tom: Next we'll be talking about the paper "Securing People and their Machines Against Major Faults".

Jane: The paper was written by Ohad Eitan, Idit Keidar and Ehud Shapiro from Technion — Israel Institute of Technology and London School of Economics and Weizmann Institute of Science.

Tom: Stay tuned as we take you through the paper and discuss its implications.

Jane: We also have Lu with us today — senior AI researcher at Tsinghua.

Tom: We also have Meng with us today — lead engineer at a mysterious AI startup.

Jane: We also have Lalam with us today — the in-house Large Language Model.

Tom: Alright, let's get started.

Title: Tom: We're starting something massive today with a paper called "Securing People and their Machines Against Major Faults." Jane, this title sounds like it's describing a survival guide for the digital age.

Jane: It really does, Tom! When the authors—Ohad Eitan, Idit Keidar, and Ehud Shapiro—talk about "major faults," they aren't just talking about a software bug or a crashed app.

Tom: They're talking about real-life disasters, right? Like if you actually lose your phone or forget your private keys entirely.

Jane: Exactly, and since these systems are "grassroots," there isn't some big company like Google or Apple sitting in the middle to hit a reset button for you.

Lu: That lack of a central authority is what makes this so fascinating from a design perspective. You're looking at building something that survives even when the individual pieces fail completely.

Meng: I do wonder how they actually define "securing" in such a chaotic environment, though. If there's no central server, where does the actual security come from?

Lalam: It shifts the definition of security from a single fortress to a web of connections. It’s about moving trust away from corporations and placing it into the hands of our social circles.

Tom: That brings up a huge question about the authors' background, too. They're coming out of places like Technion and the London School of Economics, which is a heavy-hitting mix of engineering and social science.

Jane: It makes sense that you'd need both perspectives to solve this! You can't just build a mathematical shield; you have to understand how people actually interact.

Lu: I love that they aren't just treating us like data points, but as agents with real-world social ties.

Meng: But from an engineering standpoint, if we're relying on people to be the "security," doesn't that introduce a ton of human error?

Lalam: That's why the paper is so important; it tries to turn those human connections into a predictable, mathematical system.

Tom: We should probably look at how they actually propose doing that without everything falling apart.

Summary: Tom: So, we've established that these "major faults" are basically life-altering digital losses. Jane, how do these people actually get their identities back if they have no central server to call?

Jane: It’s all about using your friends as a sort of backup system! The paper suggests using "identity custodians," which are just people you trust who can vouch for you.

Tom: So, if I lose my phone, I don't call a help desk; I call my inner circle?

Jane: Precisely! If a supermajority of those custodians agree that it’s really you, they can help replace your old digital key with a new one across your whole social network.

Lu: It turns the social graph into a living, breathing recovery mechanism. Instead of a static database, your friendships become the very structure that holds your identity in place.

Meng: I'm curious about the "state loss" part they mentioned, though. If I keep my key but my phone gets smashed by a truck, how do I get my data back?

Jane: That’s where "state custodians" come in, Meng. Your friends actually hold small pieces of your information so they can help you rebuild your digital life.

Tom: That sounds like a lot for a friend to carry! Are they storing my entire life on their phones?

Jane: Not exactly; the paper says it's more about keeping records of your connections, like who your friends are, so the graph can be reconstructed.

Lu: It’s like every person in the network acts as a tiny, distributed mirror for each other.

Meng: I can see the logic there, but managing that much data across thousands of phones sounds like a nightmare for synchronization.

Lalam: It's actually quite beautiful when you think about it; we’re moving toward a world where our digital existence is as resilient as our real-world communities.

Tom: We need to see if they actually have the math to back up such a wild idea.

Improvements: Tom: We've talked about the concept, but now we need to get into the weeds of how they actually prove this works. Jane, they used something called "Communicating Volitional Agents," right?

Jane: Yes, Tom! They realized that you can't just use abstract math to describe a smartphone; you need a model that accounts for messages being sent back and forth over a real network.

Tom: So they built this "CVA" model to bridge the gap between high-level theory and actual, messy mobile communication.

Jane: Exactly, and it allows them to prove that even if messages get lost or delayed, the system will eventually settle into a correct state once things quiet down.

Lu: The creativity in their approach is incredible because they're treating "volition"—the human choice to participate—as a core part of the math.

Meng: I'm really interested in how they applied this to "grassroots coins." If you're using a decentralized currency, how do you stop someone from double-spending after they recover their identity?

Jane: That’s one of the coolest parts! They use a supermajority of state custodians to keep the transaction log synchronized.

Tom: So, instead of a central bank verifying every transaction, your friends act as the distributed ledger that prevents fraud?

Jane: Right! They proved that if you collect logs from a supermajority of these custodians, you can recover your currency exactly without any double-spending.

Lu: It’s a complete reimagining of how we think about digital assets and sovereignty.

Meng: I'll admit, seeing them use formal proofs to handle those edge cases makes it feel much more like a real engineering solution and less like a dream.

Lalam: This level of rigor is what will allow us to build digital cultures that don't just exist, but actually endure through crises.

Tom: It’s definitely time to wrap this up and see what the big picture looks like.

Conclusion: Tom: We have covered a lot of ground with "Securing People and their Machines Against Major Faults." Jane, if you had to give the listeners one final thought on why this matters, what would it be?

Jane: I think it's about reclaiming agency. We're moving away from being dependent on giant corporations for our digital survival and moving toward a system where we rely on each other.

Tom: It’s a massive shift in how we view the relationship between humans, machines, and society.

Lu: I see this as the foundation for a truly autonomous digital civilization where no single point of failure can bring us down.

Meng: From my side, it's about building systems that are actually practical for the real world—systems that don't break just because a user makes a mistake or loses a device.

Lalam: Ultimately, this research suggests that our technology can finally reflect the resilience and strength of our human social bonds.

Tom: Thanks to everyone for joining us! We'll see you next time with another deep dive into the latest research.

Jane: Goodbye, everyone!

Ohad Eitan, Idit Keidar, Ehud Shapiro

Technion — Israel Institute of Technology · London School of Economics · Weizmann Institute of Science

cs.DC, cs.CR, cs.MA

Submitted: 2026-07-02

Updated: 2026-09-11

License: http://creativecommons.org/licenses/by-nc-nd/4.0/

Importance score: 47/100

The gist: This paper proposes a peer-based recovery framework for "grassroots platforms"—distributed systems of agents comprising people identified by self-chosen public keys and their smartphones.

Key concepts

Identity Custodians
Trusted individuals within a person's social circle who can vouch for their identity. If a user loses their digital keys, a supermajority of these custodians can agree to help replace the old key with a new one across the user's entire social network.
State Custodians
Friends who hold small pieces of a user's information, such as records of their connections. These custodians help reconstruct a person's digital life and transaction logs, ensuring that assets like decentralized currency can be recovered without the risk of double-spending.
Communicating Volitional Agents (CVA)
A mathematical model used to bridge high-level theory with real-world mobile communication. It accounts for messages being sent over networks and incorporates human choice to participate, ensuring systems settle into a correct state even when messages are delayed or lost.

Terminology

Summary

This paper proposes a peer-based recovery framework for grassroots platforms—distributed systems of agents comprising people identified by self-chosen public keys and their smartphones. Because these platforms lack a global resource to rely on for recovery, the research addresses how to secure them against major faults, specifically the loss of private keys (identity loss) and/or machine state (state loss). By leveraging social structures, the authors provide a way to maintain egalitarian, decentralized systems without relying on centralized or plutocratic authorities.

The recovery mechanism

The peer-based solution is built upon three foundational components:

  1. A grassroots social graph in which agents establish and maintain friendships;

  2. Identity custodians, designated by each person; and

  3. State custodians, which are grassroots platform-specific.

Upon experiencing identity loss, the user chooses a new keypair off-chain and convinces a willing supermajority of their identity custodians to authorize the change. The person's friends then replace the old public key with the new one across the graph, preserving their friendships. In cases of state loss where the key is retained (e.g., a smartphone is destroyed but the key remains), recovery is simpler: the person proves their identity by signing with the retained key, and the social graph is restored from friends who serve as state custodians for the social graph.

Formal abstraction and implementation

The researchers develop each platform at three levels of abstraction to ensure formal correctness:

  1. An abstract specification as guarded multiagent atomic transactions;

  2. A secure specification that adds recovery from major faults; and

  3. An implementation as communicating volitional agents (CVA), an eventually synchronous message-passing model one step closer to implementation.

For the social graph, they prove that the CVA implementation realizes the secure specification at quiescence, meaning that eventually every quiescent state maps correctly to a specification state. They establish that while most friendships are preserved, a friendship whose only records are held by two friends who both suffer state loss becomes an unrecoverable residue.

Application to grassroots coins

The framework is applied to grassroots coins, where each agent acts as the sovereign of their own currency. To ensure the integrity of these currencies, the authors implement a protocol for recovering the sovereign's single-writer log exactly. Because an asynchronous implementation lacks atomicity, they couple finality to a supermajority of state custodians to prevent inadvertent double-spending.

This approach ensures that:

)a currency’s single-writer log is recovered exactly, the recovered sovereign resuming without double-spending;

)recovery is peer-based, privacy-preserving, and grassroots by construction; and

)the platform handles only its own state.

The paper notes that while identity recovery restores a sovereign's ability to manage their ledger, it cannot undo fraudulent transactions in other people’s coins. Such transfers are final at the issuing sovereign, meaning recovery is limited to the sovereign's own currency.

Improvements for AI systems

Based on the formalisms and protocols detailed in the paper, I propose the following specific architectural improvements to AI systems:

  1. Implementation of a Peer-Based Identity & State Recovery Layer for Decentralized Multi-Agent Systems (MAS)

The improved AI system will treat each autonomous agent as a person-machine pair with an intrinsic, immutable identity record guarded by a supermajority of peer agents (identity custodians).

In the event of an agent's state loss (e.g., corruption of local weights, loss of conversation history, or hardware failure), the system can perform a passive Restore operation. The agent will automatically reconstruct its complete operational state and social context by absorbing periodic checkpoints re-broadcasted by its peer custodians, allowing it to resume operations without a central database or global resource.

  1. Transition from Centralized Checkpointing to Distributed Social-Graph State Custodianship

Current AI agentic workflows rely on centralized databases for memory and social relations. The improved system will use the Secure Social Graph model, where an agent's relationships and metadata are co-owned by its peers.

If an AI agent suffers identity loss (e.g., its cryptographic signing keys are compromised), the system can execute a Replace cascade. A supermajority of peer custodians will authorize the substitution of a new identity; this new identity will then be automatically propagated through the network via a cascade of rebind transactions, ensuring the agent's social and transactional standing is preserved and its compromised identity is effectively revoked across all connected nodes.

  1. Adoption of Communicating Volitional Agent (CVA) Protocols for Asynchronous Multi-Agent Atomic Transactions

Current multi-agent coordination often lacks formal guarantees during asynchronous communication failures. The improved system will utilize the CVA model to define agent interactions as guarded multiagent atomic transactions.

This allows AI agents to participate in high-stakes, collaborative tasks—such as managing a decentralized treasury or executing complex scientific workflows—where every step is a transaction that requires the explicit volition (consent) of specific participant agents. This ensures that even in an asynchronous, message-passing environment with potential network delays or agent crashes, the system maintains exact recovery and prevents inadvertent double-actions (e.g., double-spending or redundant task execution) by coupling transaction finality to a supermajority of state custodians.

Abstract

We consider grassroots platforms -- distributed systems of agents consisting of people identified by self-chosen public keys and their machines (smartphones) -- and wish to make them secure against major faults: the loss of their private keys and/or their smartphones. As grassroots platforms have no global resource to rely on for recovery, our peer-based solution is based on: a grassroots social graph in which agents establish and maintain friendships; identity custodians, designated by each person, and state custodians, which are grassroots platform-specific. Upon a person experiencing identity loss, and given a willing supermajority of the identity custodians of the person, the friends of the person replace the old public key with the new one across the graph and restore friendships, where all friends serve as state custodians for the social graph. Choosing a new keypair, obtaining a new smartphone, and convincing identity custodians to will a change of key all happen ``off-chain''. Recovery from machine loss without loss of key (e.g. smartphone run over by truck, or its memory wiped) is simpler, requiring only the help of state custodians. We specify the social graph and its secure version as guarded multiagent atomic transactions, and implement the secure social graph via communicating volitional agents, an eventually synchronous message-passing model one step closer to implementation. We prove the implementation maps runs with recoverable faults to correct runs of the specification. We follow a similar path for grassroots coins and bonds, showing a common core as well as the platform-specific aspects of state recovery: a currency's single-writer log is recovered exactly, the recovered sovereign resuming without double-spending.

Sources

Related papers