From CRUD to Autonomous Agents: Formal Validation and Zero-Trust Security for Semantic Gateways in AI-Native Enterprise Systems
Ignacio Peyrano

TL;DR
This paper introduces a formal validation framework for AI-native enterprise systems using semantic gateways and zero-trust security, ensuring secure autonomous agent behavior.
Contribution
It presents a novel architecture with a three-layer security model and adapted fuzzing techniques for validating stochastic AI-driven enterprise agents.
Findings
Achieved 84.2% reduction in incidental code.
100% discovery rate of hidden unauthorized state transitions.
Validated the effectiveness of dynamic formal verification for secure deployment.
Abstract
Enterprise software engineering is shifting away from deterministic CRUD/REST architectures toward AI-native systems where large language models act as cognitive orchestrators. This transition introduces a critical security tension: probabilistic LLMs weaken classical mechanisms for validation, access control, and formal testing. This paper proposes the design, formal validation, and empirical evaluation of a Semantic Gateway governed by the Model Context Protocol (MCP). The gateway reframes the enterprise API as a semantic surface where tools are dynamically discovered, authorized, and executed based on intent and policy enforcement. The central contribution rests on a paradigm shift: autonomous agents must not be validated as traditional software nor as simple API consumers, but as stochastic state-transition systems whose behavior must be abstracted, fuzzed, and audited through…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
