Health & Medicinearticle2026-08-27

CurateTrust-ZT: Difficulty-calibrated curation evidence for continuous zero-trust authorization of AI agents

Open access0 citations

Abstract

Background Continuous authorization in zero-trust systems relies almost entirely on behavioural and network telemetry. Corrections made by human curators during routine data standardization are a largely unused trust signal, and naive correction-counting conflates task difficulty with unreliability, penalizing careful contributors assigned hard or unfamiliar data. Methods We built a difficulty- and consequence-aware Bayesian reliability model from curation-event evidence, fused with a behavioural signal inside a live Keycloak/OPA/Postgres/FastAPI authorization stack. We compared five naive baselines, a curation-only ablation, and the full fused model on two ontology-matching datasets (OAEI Conference and Anatomy), across nine simulated contributor profiles including collusion, with independent seed replicates for each experiment, one-at-a-time and factorial hyperparameter sweeps, and a dedicated cross-contributor collusion detector. Results Naive correction-counting was systematically backwards: over 30 seed replicates it rewarded contributors who accepted incorrect mappings (detection AUC 0.129, 95% CI [0.124, 0.135]). Our proposed model reduced the fairness gap between equally reliable contributors on easy versus difficult tasks to near zero (0.007, versus 0.018–0.025 for naive baselines) while detecting overt and compromised attackers well (AUC 0.721, 95% CI [0.711, 0.732]); the curation-only component alone achieved an even smaller gap (0.003). A dedicated pairwise-overlap detector ranked the true colluding pair among the five most suspicious of 1,225 candidate pairs in every tested seed. Slow, low-frequency manipulation remained difficult to detect, and this weakness replicated on the independent Anatomy dataset. Replaying 240 contributors and 96,000 curation events through the live stack produced a 0.0 false-denial rate for honest profiles, a 0.0% unauthorized-action rate for malicious and colluding contributors but 97.1% for slow attackers, and 57.9 ms mean decision latency. Conclusions Difficulty-calibrated curation evidence is a technically feasible and fair zero-trust signal, substantially more reliable than naive correction-counting under the simulated-contributor conditions evaluated here; detecting deliberately stealthy manipulation remains an open problem.

// Source

View paper (DOI)Open access versionOpenAlexOpen Research EuropePublished 2026-08-27

Authors: Fouad Ailabouni, Jesús-Ángel Román-Gallego

Institutions: Universidad de Salamanca, Polytechnic University of Puerto Rico, ITCL Technology Centre, Universidad de Zamora