Source: arXiv (CSIRO's Data61 / UNSW) — 2026-07-09
Summary
Researchers from CSIRO's Data61 and UNSW address provenance disputes that arise when resellers rebrand an agent or silently substitute a cheaper model behind it. TRACE proposes what the authors describe as the first agent watermark that is distortion-free in action choices, self-synchronizing under log deletion, and invariant under log rewriting — since a reseller has full read/write access to the very trajectory log attribution is normally read from.
Key Takeaways
- Targets a real emerging problem: agent resale, white-labeling, and model-substitution fraud.
- The watermark is designed to survive adversarial tampering by the party who controls the evidence — a threat model prior agent watermarks didn't address.
- Cross-listed across cs.CR, cs.AI, and cs.LG.
- Relevant to the broader agent security and MCP-adjacent trust/attribution concerns already tracked in this digest.