Articles | Open Access | https://doi.org/10.55640/ijns-06-02-03

Zero-Trust Identity Federation for Autonomous AI Agents Using SPIFFE and Workload Identity

Ananya Kulkarni , Machine Learning Research Analyst, India

Abstract

Autonomous AI agents increasingly operate across heterogeneous computing environments, including cloud platforms, edge infrastructures, specialized accelerators, and distributed service architectures. This evolution creates an identity-management problem that differs fundamentally from conventional user authentication because autonomous agents may initiate actions, invoke tools, exchange information, and delegate tasks without continuous human intervention. A zero-trust architecture therefore requires identities that are cryptographically verifiable, workload-oriented, short-lived, and independent of network location. This paper proposes a conceptual zero-trust identity federation architecture for autonomous AI agents based on SPIFFE and workload identity principles. The proposed framework separates agent identity, authorization, workload attestation, federation, and policy enforcement while establishing continuous identity verification across agent-to-agent and agent-to-service interactions. The methodology develops an identity lifecycle model, federation mechanism, trust-evaluation process, and policy-enforcement architecture. The analysis further examines how distributed AI workloads and edge environments influence identity requirements. Existing literature demonstrates the growing heterogeneity and distribution of AI computing platforms, but comparatively limited attention has been directed toward identity federation specifically for autonomous agents. The resulting framework provides a structured basis for reducing identity ambiguity, limiting credential persistence, improving cross-domain trust, and supporting policy-driven agent autonomy. The paper concludes that workload-oriented identity can provide an appropriate foundation for zero-trust agent ecosystems, although federation governance, identity revocation, policy consistency, and computational overhead remain significant research challenges.

Keywords

Zero Trust, SPIFFE, Workload Identity, Autonomous AI Agents

References

Karine, T. Napoléon, J.-Y. Mulot, and Y. Auffret, “Video seals recognition using transfer learning of convolutional neural network,” in Proc. 10th Int. Conf. Image Process. Theory, Tools, Appl., 2020, pp. 1–4.

A. N. Mazumder, “A survey on the optimization of neural network accelerators for micro-AI on-device inference,” IEEE Trans. Emerg. Sel. Topics Circuits Syst., vol. 11, no. 4, pp. 532–547, Dec. 2021.

A. Reuther, P. Michaleas, M. Jones, V. Gadepally, S. Samsi, and J. Kepner, “AI accelerator survey and trends,” in Proc. IEEE High Perform. Extreme Comput. Conf., 2021, pp. 1–9.

A. Vaswani, “Attention is all you need,” in Proc. Int. Conf. Neural Inf. Process. Syst., 2017, vol. 30, pp. 6000–6010.

B. Varghese, N. Wang, S. Barbhuiya, P. Kilpatrick, and D. S. Nikolopoulos, “Challenges and opportunities in edge computing,” in Proc. IEEE Int. Conf. Smart Cloud, 2016, pp. 20–26.

C. Zhu, S. Han, H. Mao, and W. J. Dally, “Trained ternary quantization,” in Proc. 5th Int. Conf. Learn. Representations, Toulon, France, 2017.

E. Manor and S. Greenberg, “Custom hardware inference accelerator for tensorflow lite for microcontrollers,” IEEE Access, vol. 10, pp. 73484–73493, 2022.

E. Wang, “Deep neural network approximation for custom hardware: Where we've been, where we're going,” ACM Comput. Surv., vol. 52, no. 2, pp. 1–39, 2019.

I. Hubara, M. Courbariaux, D. Soudry, R. El-Yaniv, and Y. Bengio, “Binarized neural networks,” Proc. Adv. Neural Inform. Process. Syst., D. Lee, M. Sugiyama, U. Luxburg, I. Guyon, and R. Garnett, eds., vol. 29, 2016.

K. Pappu, B. Bhushan and A. Mittal, "SPIFFE-Based Zero-Trust Authentication for AI Agent Ecosystems," 2025 International Conference on Computer and Applications (ICCA), Bahrain, Bahrain, 2025, pp. 1-7, doi: 10.1109/ICCA66035.2025.11431026.

L. Deng, G. Li, S. Han, L. Shi, and Y. Xie, “Model compression and hardware acceleration for neural networks: A comprehensive survey,” Proc. IEEE, vol. 108, no. 4, pp. 485–532, Apr. 2020.

L. Sekanina, “Neural architecture search and hardware accelerator co-search: A survey,” IEEE Access, vol. 9, pp. 151337–151362, 2021.

N. Wu, T. Jiang, L. Zhang, F. Zhou, and F. Ge, “A reconfigurable convolutional neural network-accelerated coprocessor based on RISC-V instruction set,” Electronics, vol. 9, no. 6, 2020, Art. no. 1005.

P. P. Ray, “A review on TinyML: State-of-the-art and prospects,” J. King Saud Univ.-Comput. Inf. Sci., vol. 34, no. 4, pp. 1595–1623, 2022.

S. Han, H. Mao, and W. J. Dally, “Deep compression: Compressing deep neural networks with pruning, trained quantization and Huffman coding,” in Proc. 4th Int. Conf. Learn. Representations, Y. Bengio and Y. LeCun, eds., San Juan, Puerto Rico, 2016.

S. Mittal, “A survey of FPGA-based accelerators for convolutional neural networks,” Neural Comput. Appl., vol. 32, no. 4, pp. 1109–1139, 2020.

S. Pouyanfar, “A survey on deep learning: Algorithms, techniques, and applications,” ACM Comput. Surv., vol. 51, no. 5, pp. 1–36, 2018.

S.-H. Lim, W. W. Suh, J.-Y. Kim, and S.-Y. Cho, “RISC-V virtual platform-based convolutional neural network accelerator implemented in systemC,” Electronics, vol. 10, no. 13, 2021, Art. no. 1514.

V. Murahari, C. E. Jimenez, R. Yang, and K. Narasimhan, “DataMUX: Data multiplexing for neural networks,” in Proc. Adv. Neural Inform. Process. Syst., A. H. Oh, A. Agarwal, D. Belgrave, and Kyunghyun Cho, eds., 2022.

W. Shi, J. Cao, Q. Zhang, Y. Li, and L. Xu, “Edge computing: Vision and challenges,” IEEE Internet Things J., vol. 3, no. 5, pp. 637–646, Oct. 2016.

Z. Liu, J. Jiang, G. Lei, K. Chen, B. Qin, and X. Zhao, “A heterogeneous processor design for CNN-based AI applications on IoT devices,” Procedia Comput. Sci., vol. 174, pp. 2–8, 2020.

Article Statistics

Downloads

Download data is not yet available.

Copyright License

Download Citations

How to Cite

Ananya Kulkarni. (2026). Zero-Trust Identity Federation for Autonomous AI Agents Using SPIFFE and Workload Identity. International Journal of Networks and Security, 6(02), 40-49. https://doi.org/10.55640/ijns-06-02-03