Conceptio › Archive › arXiv CS
arXiv CSopen access

Zero-Trust Bilateral Edge Service Trading with Deposit-Refund Regulation for Runtime Compliance

2026 · arxiv_cs
arXiv CS · Papers · License: Open Access · 2026
Open Source ↗Direct PDF ↓
distributed-systemsinternetnetworkingprotocols
networking, internet, protocols, distributed systems

Zero-Trust Bilateral Edge Service Trading with Deposit-Refund Regulation for Runtime Compliance Houyi Qi∗ , Minghui Liwang∗ , Zhipeng Cheng† , Xiaoyu Xia‡

∗ Shanghai Research Institute for Intelligent Autonomous Systems, Tongji University, Shanghai, China † School of Future Science and Engineering, Soochow University, Jiangsu, China ‡ School of Computing Technologies, RMIT University, Melbourne, Australia

arXiv:2605.02182v1 [cs.NI] 4 May 2026

Email: {[email protected], [email protected], [email protected], [email protected]} Abstract—Privacy-sensitive edge services necessitate optimizing diverse-type resource scheduling to support trustworthy provisioning within a zero-trust security framework. However, existing studies rarely model how runtime compliance jointly affects bilateral clearing, ex-post settlement, and future seller eligibility in dynamic edge markets. To address this issue, we propose ZEBRIS, a zero-trust bilateral edge service trading framework with deposit-refund regulation for privacy-sensitive services. Specifically, edge provisioning is modeled as a trading form of zero-trust-compliant service packages, where the buyerside effective valuation captures service value, delay penalty, and privacy risk, while the seller-side effective ask incorporates resource and compliance costs. This yields a resource-aware positive-margin bilateral clearing mechanism under shared resource and security constraints. To discipline post-clearing moral hazard, we further design a capped deposit-refund settlement rule based on measurable runtime compliance and update each seller’s future security posture according to realized compliance outcomes. ZEBRIS satisfies bilateral individual rationality and no-subsidy weak budget balance. Experiments demonstrate that ZEBRIS improves social welfare and compliance robustness while reducing service delay and privacy-risk-weighted cost over representative baselines. Index Terms—Zero-trust, edge service trading, deposit-refund regulation, privacy-sensitive edge services

I. I NTRODUCTION With the evolution of next-generation communication systems, particularly 6G, together with the advancement of edge intelligence, an expanding class of privacy-sensitive and latency-critical applications, such as mobile intelligent assistants, immersive interaction, and real-time visual analytics, are increasingly dependent on proximate edge computing infrastructures to obtain low-latency communication-computation services [1], [2]. Users therefore continuously submit edge service requests to reduce local processing burden and improve service timeliness [2], [3]. However, practical multi-tenant edge environments are rarely fully trusted, extending service provisioning beyond conventional bandwidth, computation, and latency constraints. Runtime zero-trust enforcement, including continuous authentication, authorization, and monitoring [4], [5], introduces verification overhead, compliance costs, and service uncertainty. Therefore, zero-trust security should be modeled not as a static trust label, but as a dynamic and measurable compliance factor that affects service feasibility, trading profitability, and post-execution accountability. Existing studies mainly fall into three separate directions, namely zero-trust security [4], [5], auction-based edge service scheduling [3], [6], and privacy-aware edge service optimization [2], [7]. Nevertheless, these lines of research are still largely developed in isolation, and they rarely provide a unified

market mechanism in which runtime compliance simultaneously affects ex-ante bilateral clearing, ex-post settlement, and future seller eligibility. In particular, zero-trust studies mainly focus on spectrum trading or secure data sharing [4], auctionbased studies usually treat security as a static assumption [3], and privacy-aware optimization does not explicitly model runtime compliance settlement or future seller-state feedback. As a result, privacy-sensitive edge service trading cannot be adequately modeled as a conventional one-shot resource assignment problem. Even after a transaction is cleared, service providers may reduce security efforts or deviate from promised quality levels, exposing buyers to privacy leakage and service degradation. Although deposit-refund mechanisms have been explored in zero-trust spectrum trading [4], directly applying them to privacy-sensitive edge service markets is insufficient, because edge service trading further couples communication– computation assignment, privacy exposure, runtime compliance, and cross-round seller competitiveness. To address this, we propose ZEBRIS, a zero-trust bilateral trading framework with deposit-refund regulation for privacysensitive edge services. ZEBRIS trades zero-trust-compliant service packages rather than bare resources. The buyer-side effective valuation captures service value, delay penalty, and privacy risk, while the seller-side effective ask incorporates resource and compliance costs. Based on positive-margin clearing, capped deposit-refund settlement, and seller-posture feedback, ZEBRIS forms a closed incentive-regulation loop between current runtime behavior and future market competitiveness. Main contributions are summarized as follows. • To enable trustworthy provisioning in privacy-sensitive edge service markets, we formulate zero-trust bilateral service provisioning as a dynamic package-based trading problem, where communication–computation resources, delay requirements, privacy exposure, and runtime security compliance are jointly embedded into package feasibility and profitability. We then design ZEBRIS, an online trading mechanism that forms a closed loop among ex-ante package clearing, ex-post capped deposit-refund settlement, and cross-round seller-posture evolution, thereby transforming runtime compliance from a static trust assumption into an economically regulated market factor. • We establish the key economic properties of ZEBRIS, including bilateral individual rationality and no-subsidy weak budget balance under the well-designed midpoint pricing and depositcapping rules. Experiments further demonstrate that ZEBRIS improves social welfare, compliance robustness, service delay, and privacy-risk-weighted service cost over representative baselines.

Fig. 1. Framework and procedure of the proposed ZEBRIS.

II. S YSTEM M ODEL AND P ROBLEM F ORMULATION As shown in Fig. 1, we consider a privacy-sensitive edge service market where buyers submit service tasks to edge sellers under platform coordination. Each seller offers zerotrust-compliant service packages characterized by bandwidth resource, computation resource, and security posture. For each buyer–seller pair, ZEBRIS evaluates candidate packages by jointly considering delay feasibility, privacy exposure, resource cost, and zero-trust compliance cost, and then performs positive-margin bilateral clearing to obtain the accepted matching. After service execution, ZEBRIS measures runtime compliance through authentication success, policy consistency, and service level agreement (SLA) satisfaction. The capped deposit is then settled according to the measured compliance outcome, leading to full refund, buyer compensation, and platform revenue. The realized refund ratio is further fed back to update the seller’s future security posture. Therefore, ZEBRIS establishes a closed-loop mechanism that integrates ex-ante package clearing, ex-post deposit-refund settlement, and crossround seller-posture evolution for trustworthy privacy-sensitive edge service trading. A. Dynamic Zero-Trust Edge Service Market We consider a dynamic privacy-sensitive edge service market composed of a buyer set U , whose members request edge services, a seller set E, whose members provide bandwidthcomputation resources and zero-trust-compliant packages, and a platform coordinator, while letting T = {1, . . . , T } denote the trading horizon. In each round t ∈ T , only a subset of buyers is active, denoted by U(t) ⊆ U . On the demand side, each active buyer ui ∈ U(t) submits a privacy-sensitive edge service request Ji (t) =  Li (t), Ci (t), Dimax (t), ℓi (t), smin (t), v (t) , where Li (t) i i and Ci (t) denote the input data size and required computation workload, respectively, Dimax (t) is the delay deadline, ℓi (t) is the privacy sensitivity level, smin (t) is the minimum required i security level, and vi (t) is the buyer’s gross valuation. Hence, each request jointly specifies communication/computation demand, timeliness requirement, and security/privacy requirement. On the supply side, each seller ej ∈ E is characterized by Sj (t) = Bj (t), Fj (t), qj (t), Zj , aj (t) , where Bj (t) and Fj (t) denote the available bandwidth and computation capacity, respectively, qj (t) ∈ [0, 1] is the current security posture, Zj ⊆ [0, 1] is the feasible normalized verificationlevel set, and aj (t) is the base ask. For each buyer–seller pair (ui , ej ) at round t, the cand platform considers a candidate package set Pi,j (t), where each candidate package is written as Pi,j (t) = cand bi,j (t), fi,j (t), zi,j (t) ∈ Pi,j (t). Here, bi,j (t) and fi,j (t) denote the assigned bandwidth and computation resource,

respectively, and zi,j (t) ∈ Zj denotes the selected normalized verification intensity. Let xi,j (t) ∈ {0, 1} be the bilateral trading indicator, where xi,j (t) = 1 means that buyer ui is matched with seller ej at round t. In this paper, bilateral clearing refers to the platform’s decision process that determines which buyer–seller pairs are accepted and which service packages are assigned, subject to positive-margin and resource-security feasibility constraints. Unlike conventional edge auctions that trade resources, ZEBRIS trades zero-trust-compliant packages whose value depends on resource assignment, privacy exposure, and runtime compliance. Here, zero trust is modeled as continuous verification rather than a one-time trust label: each package must pass ex-ante security admission, undergo runtime monitoring, and be regulated through ex-post deposit-refund settlement. The seller posture qj (t) captures the platformestimated compliance state and affects feasibility, privacy risk, delay overhead, compliance cost, and future competitiveness. B. Package Feasibility, Effective Valuation, and Effective Ask Based on the above market design, we next characterize how a candidate package affects service delay, privacy risk, and seller-side compliance cost. These factors determine both package feasibility and economic profitability under zero-trust enforcement. For a candidate package Pi,j (t), let SINRi,j (t) denote the signal-to-interference-plus-noise ratio (SINR) of the wireless link between buyer ui and seller ej .The transmission rate is ri,j (t) = bi,j (t) log2 1 + SINRi,j (t) . Then, the total service delay is modeled as  Ci (t) Li (t) + + ϑ1 zi,j (t) + ϑ2 1 − qj (t) , (1) Di,j (t) = ri,j (t) fi,j (t) where ϑ1 > 0 and ϑ2 > 0 are the delay coefficients associated with verification overhead and security-posture deficiency, respectively. To jointly capture the effects of verification intensity and seller posture, we define the package level security compliance score as gi,j (t) = g zi,j (t), qj (t) , where g(·) is nondecreasing in both arguments. For example, one simple instantiation is g(z, q) = ϖz + (1 − ϖ)q with ϖ ∈ [0, 1]. Accordingly, a candidate package is feasible only if Di,j (t) ≤ Dimax (t), gi,j (t) ≥ smin (t). These conditions i ensure that the selected package simultaneously satisfies the buyer’s timeliness requirement and zero-trust security requirement. Beyond service delay, privacy exposure must also be explicitly quantified. The privacy risk experienced by buyer ui under seller ej is modeled as  ξi,j (t) = ℓi (t) ϕ zi,j (t), qj (t) , (2) where ϕ(·) is a nonnegative privacy-risk function that is decreasing in both zi,j (t) and qj (t). Thus, stronger verification and better seller posture reduce privacy exposure. Meanwhile, zero-trust enforcement incurs an explicit seller zt side compliance cost Ci,j (t) = ψ1 zi,j (t) + ψ2 1 − qj (t) , where ψ1 > 0 and ψ2 > 0 are the cost coefficients associated with verification effort and posture deficiency, respectively. Based on the above characterizations, we define the buyerside effective valuation  as v̂i,j Pi,j (t) = vi (t) − αi Di,j (t) − βi ξi,j (t), (3) where αi > 0 and βi > 0 are the delay-penalty and privacyrisk-penalty coefficients, respectively. The seller-side effective

ask is defined as F zt âi,j Pi,j (t) = aj (t) + κB j bi,j (t) + κj fi,j (t) + Ci,j (t), (4) F where κB j > 0 and κj > 0 are the seller’s unit bandwidth and computation costs, respectively. Accordingly, the bilateral trading margin is    Ωi,j Pi,j (t) = v̂i,j Pi,j (t) − âi,j Pi,j (t) . (5) A positive margin means that the package remains beneficial after accounting for delay loss, privacy risk, resource cost, and compliance cost. fea cand Let Pi,j (t) ⊆ Pi,j (t) denote the feasible package set for pair (ui , ej ), namely the subset of candidate packages satisfying the above delay and minimum-security constraints. fea (t) ̸= ∅, the platform selects the best For each pair with Pi,j feasible package via  ⋆ Ωi,j Pi,j (t) , Pi,j (t) ∈ arg max (6) fea Pi,j (t)∈Pi,j (t)  ⋆ ⋆ ⋆ where Pi,j (t) = b⋆i,j (t), fi,j (t), zi,j (t) . For notational  ⋆ ⋆ (t) , â⋆i,j (t) ≜ convenience, define v̂i,j (t) ≜ v̂i,j Pi,j   ⋆ ⋆ fea âi,j Pi,j (t) , and Ω⋆i,j (t) ≜ Ωi,j Pi,j (t) . If Pi,j (t) = ∅, then pair (ui , ej ) is excluded from subsequent clearing. C. Runtime Compliance Settlement Ex-ante security-aware clearing cannot guarantee runtime compliance, since a winning seller may reduce verification effort, violate access-control policies, or fail to meet the promised service quality. To mitigate such post-clearing hazard under zero trust, we introduce an ex-post deposit-refund settlement mechanism based on measurable runtime compliance. Specifically, for each accepted pair (ui , ej ) at round t, we evaluate realized runtime compliance from three complementary aspects, namely authentication success, policy req succ consistency, and SLA satisfaction. Let Ni,j (t) and Ni,j (t) denote the numbers of requested and successful authenchk vio tication events, respectively, and let Ni,j (t) and Ni,j (t) denote the numbers of policy checks and detected polreal icy violations, respectively. Moreover, let Di,j (t) denote the realized end-to-end service delay after package execution. Then the three compliance scores are defined as h i1 vio succ Ni,j (t) Ni,j (t) , G (t) = 1 − , Ai,j (t) = max{1,N req i,j chk (t)} max{1,Ni,j (t)} 0 " i,j + #1 D real (t)−Dimax (t) and Si,j (t) = 1 − i,j Dmax (t) , where [x]10 ≜ i

0

min{1, max{0, x}}. As such, the ex-post settlement is grounded on measurable runtime outcomes rather than unverifiable behavioral assumptions. The refund ratio is given by ρi,j (t) = η1 Ai,j (t) + η2 Gi,j (t) + η3 Si,j (t), (7) where η1 , η2 , η3 ≥ 0 and η1 + η2 + η3 = 1. Hence, by construction, ρi,j (t) ∈ [0, 1]. A higher refund ratio indicates stronger realized compliance and better post-clearing service fulfillment. To avoid excessive punishment that destroys seller participation, thedeposit is capped as  ⋆ ∆i,j (t) = min µ1 zi,j (t) + µ2 1 − qj (t) , λ Ω⋆i,j (t) , (8) where µ1 > 0 and µ2 > 0 are deposit coefficients associated with verification level and posture deficiency, respectively, and λ ∈ (0, 12 ) is the deposit-cap ratio. This design ensures that the deposit remains large enough to discipline seller behavior while preserving participation incentives.

Let the refunded and forfeited deposits be Γi,j (t) =  ρi,j (t)∆i,j (t), Λi,j (t) = 1 − ρi,j (t) ∆i,j (t), respectively. A fraction χ ∈ [0, 1] of the forfeited deposit is returned to the buyer as compensation, and the remaining fraction is retained by the platform:  plt cmp (t) = 1 − χ Λi,j (t). (9) (t) = χ Λi,j (t), Ci,j Ci,j As a result, the proposed settlement rule not only disciplines seller-side post-clearing behavior, but also provides explicit buyer protection under weak realized compliance. D. Cross-Round Seller-Posture Evolution To further link current compliance with future competitiveness, we model cross-round seller-posture evolution. For sellerPej , define the average refund ratio at round t as  P  ui ∈U (t) xi,j (t)ρi,j (t)  P , if ui ∈U (t) xi,j (t) > 0, x (t) ρ̄j (t) = ui ∈U (t) i,j   qj (t), otherwise, (10) where the second case means that if seller ej is not selected in round t, its current posture remains the reference value. Then the seller posture evolves as qj (t + 1) = (1 − ω)qj (t) + ω ρ̄j (t), ω ∈ (0, 1]. (11) Thus, good compliance improves future posture, whereas weak compliance degrades future admissibility and competitiveness, since qj (t) affects package feasibility, privacy exposure, delay overhead, and compliance cost. E. Problem Formulation Building on the above modeling components, the platform first screens feasible packages for each buyer–seller pair and selects the best feasible package through (6). Define the fea fea sible pair set at round t as M(t) ≜ (ui , ej ) Pi,j (t) ̸= ∅ . After this screening step, each feasible pair (ui , ej ) is rep⋆ resented by its best package Pi,j (t), and the platform only needs to determine the admissibility of the candidate matching. Accordingly, we use the following long-term social welfare maximization problem as a benchmark formulation to characterize the coupled clearing and seller-posture evolution: X X P : max xi,j (t) Ω⋆i,j (t) (12) xi,j (t)

s.t.

t∈T (ui ,ej )∈M(t)

X

xi,j (t) ≤ 1,

(12a)

xi,j (t)b⋆i,j (t) ≤ Bj (t),

(12b)

⋆ xi,j (t)fi,j (t) ≤ Fj (t),

(12c)

ej :(ui ,ej )∈M(t)

X ui :(ui ,ej )∈M(t)

X ui :(ui ,ej )∈M(t)

xi,j (t) ∈ {0, 1}, ∀(ui , ej ) ∈ M(t), (12d) qj (t + 1) = (1 − ω)qj (t) + ω ρ̄j (t), ∀t ∈ T \ {T }. (12e) Here, payment, deposit, refund, and compensation are transfer terms among agents and are thus excluded from the socialwelfare objective. Constraint (12a) ensures that each buyer is matched with at most one seller in each round. Constraints (12b) and (12c) impose seller-side bandwidth and computation feasibility, respectively. Constraint (12d) specifies binary trading decisions, and (12e) captures cross-round seller-posture

evolution. Since future runtime compliance outcomes and posture transitions cannot be fully observed before service execution, directly solving P as an offline clairvoyant problem is impractical. Problem P clarifies the coupled decision structure, while ZEBRIS implements it through round-wise clearing based on current requests, seller states, and feasible packages. III. P ROPOSED ZEBRIS A. Round-Wise Clearing and Utility Settlement We next develop the proposed ZEBRIS, with its core idea to convert dynamic zero-trust-constrained service trading into a resource-aware positive-margin bilateral clearing problem. Instead of comparing raw bids and asks, the platform compares the pair-wise best effective valuation and effective ask under feasible packages. In this way, delay loss, privacy risk, and runtime compliance cost are internalized into the clearing criterion itself. We define the positive-margin feasible pair set as L(t) = {(ui , ej ) ∈ M(t) | Ω⋆i,j (t) > 0}. Only pairs in L(t) are eligible for clearing. Let X(t) = {xi,j (t)}(ui ,ej )∈L(t) be the clearingn outcome at round t. The feasible outcomeo set is X feas (t)= X(t) (12a) − (12c) hold over L(t) at round t . (13) Accordingly, the round-wise bilateral clearing problem is X max xi,j (t) Ω⋆i,j (t). (14) X(t)∈X feas (t)

(ui ,ej )∈L(t)

This problem serves as the round-wise clearing objective. To avoid myopic greedy admission, ZEBRIS adopts a resourcediscretized DP-based clearing rule over the reduced candidate graph induced by pair-wise representative packages. Each positive-margin pair (ui , ej ) is associated with a value ⋆ resource tuple Ω⋆i,j (t), b⋆i,j (t), fi,j (t) . The DP sequentially scans candidate pairs in L(t), and its state records the processed pair index, the already matched buyers, and the remaining discretized bandwidth-computation resources of sellers. For each candidate pair, the transition either rejects it or accepts it if buyer-side exclusiveness and seller-side residual resource constraints are satisfied. The accepted transition increases the objective by Ω⋆i,j (t) and reduces the corresponding ⋆ seller resources by b⋆i,j (t) and fi,j (t). This reduced-space design does not search over all raw packages jointly, but it preserves resource-aware positive-margin clearing over the selected representative packages with controllable overhead. Once a buyer–seller pair is accepted, the platform proceeds to economic settlement. For each accepted trade (ui , ej ), the platform adopts a midpoint pricing rule ⋆ v̂i,j (t) + â⋆i,j (t) . (15) pi,j (t) = 2 Based on this price, the per-trade buyer and seller utilities are respectively given by1 cmp B ⋆ Ui,j (t) = v̂i,j (t) − pi,j (t) + Ci,j (t), (16) S ⋆ Ui,j (t) = pi,j (t) − âi,j (t) − Λi,j (t). Accordingly, the aggregate utilities are obtained by summing the corresponding per-trade terms over accepted pairs. Specifically, the buyer utility is P B UiB (t) = ej :(ui ,ej )∈L(t) xi,j (t)Ui,j (t), the seller utility 1 The buyer utility in (16) is a monetary settlement utility. Weak runtime

compliance is not treated as better service experience, but is partially compencmp sated by Ci,j (t) and separately evaluated through compliance and servicequality metrics.

P S is UjS (t) = ui :(ui ,ej )∈L(t) xi,j (t)Ui,j (t), and the platform P plt (t). revenue is U P (t) = (ui ,ej )∈L(t) xi,j (t)Ci,j B. Algorithm Summary As summarized in Alg. 1, ZEBRIS performs six coupled operations in each round: feasible package screening, pairwise best-package identification, DP-based positive-margin clearing, midpoint pricing with capped deposit assignment, expost compliance settlement, and seller-posture update. Specifically, the platform first identifies the best feasible package for each buyer–seller pair and constructs the positive-margin candidate set. It then applies the resource-discretized DP-based clearing rule over the reduced candidate graph to determine accepted trades under buyer-side exclusiveness and seller-side bandwidth-computation constraints. After service execution, the platform measures realized compliance, settles deposit refunds, and updates seller postures for the next round. The per-round overhead mainly comes from feasiblepackage screening and DP-based clearing. Let Pmax = cand (t)| and let |S(t)| denote the discretized resourcemax |Pi,j state size. Since each candidate package can be evaluated in constant time, package screening costs O(|U(t)||E|Pmax ), and DP-based clearing costs O(|U (t)||E||S(t)|). Therefore, the per-round complexity is O(|U(t)||E|Pmax + |U (t)||E||S(t)|),

Algorithm 1: Proposed ZEBRIS Input: Trading horizon T , buyer requests {Ji (t)}, seller states cand (t)}. {Sj (t)}, candidate package sets {Pi,j Output: Accepted trades, assigned packages, payments, settlements, and updated seller postures. 1 for each round t ∈ T do 2 Initialize seller-side bandwidth and computation capacities by Bj (t) and Fj (t); 3 for each buyer–seller pair (ui , ej ) with ui ∈ U (t) and ej ∈ E do cand (t); 4 Enumerate candidate packages in Pi,j 5 Discard infeasible packages violating delay or minimum-security requirements; fea (t) ̸= ∅ then 6 if Pi,j ⋆ (t) and its 7 Obtain the best feasible package Pi,j margin Ω⋆i,j (t); 8

9 10

11 12 13 14 15 16 17 18 19

20 21 22

Construct nthe positive-margin candidate set o L(t) = (ui , ej ) ∈ M(t) Ω⋆i,j (t) > 0 ; Discretize seller-side bandwidth and computation capacities; Apply DP-based clearing over the reduced candidate set L(t) to obtain accepted trades {xi,j (t)} under buyer-side exclusiveness and seller-side resource constraints; for each accepted pair (ui , ej ) do ⋆ (t); Assign Pi,j Compute payment pi,j (t) by (15); Compute capped deposit ∆i,j (t) by (8); for each accepted pair (ui , ej ) do Execute the service package; Measure Ai,j (t), Gi,j (t), and Si,j (t); Compute refund ratio ρi,j (t) by (7); Compute forfeited deposit Λi,j (t) and settlement terms by (9); for each seller ej ∈ E do Compute ρ̄j (t) by (10); Update qj (t + 1) by (11);

where the discretization granularity controls the tradeoff between clearing accuracy and online overhead. C. Key Properties To demonstrate the economic soundness of ZEBRIS, we establish the following key properties. Proposition 1 (Pre-settlement bilateral individual rationality). For any accepted trade (ui , ej ) with Ω⋆i,j (t) > 0, both the buyer and the seller obtain strictly positive pre-settlement utility under the pricing rule in (15). Proof. For any accepted trade (ui , ej ), we have Ω⋆i,j (t) = ⋆ v̂i,j (t) − â⋆i,j (t) > 0. By the midpoint pricing rule in (15), S,pre B,pre ⋆ (t) = Ui,j (t) = v̂i,j (t) − pi,j (t) = 12 Ω⋆i,j (t) > 0 and Ui,j pi,j (t) − â⋆i,j (t) = 12 Ω⋆i,j (t) > 0. Thus, both sides obtain strictly positive utilities before ex-post settlement. □ Proposition 2 (Ex-post seller individual rationality under deposit capping). If the deposit is set according to (8) with λ ∈ (0, 21 ), then every accepted trade brings strictly positive S (t) > 0 for final utility to the corresponding seller, i.e., Ui,j each accepted pair (ui , ej ). Proof. Since ρi,j (t) ∈ [0, 1], we have Λi,j (t) ≤ ∆i,j (t). Using S (16), Ui,j (t) = 21 Ω⋆i,j (t) − Λi,j (t) ≥ 12 Ω⋆i,j (t) −  ∆i,j (t). By S (8), ∆i,j (t) ≤ λ Ω⋆i,j (t). Thus, Ui,j (t) ≥ 21 − λ Ω⋆i,j (t) > 0, because λ ∈ (0, 21 ) and the accepted trade has positive margin. Hence, every accepted trade yields strictly positive per-trade seller utility. Since a seller’s aggregate utility is obtained by summing its per-trade utilities over all accepted trades, the aggregate utility is nonnegative and becomes positive whenever at least one trade is accepted. □ Proposition 3 (Dynamic compliance discipline). For any seller ej , the posture update in (11) rewards above-reference runtime compliance and penalizes below-reference runtime compliance. Specifically, if ρ̄j (t) > qj (t), then qj (t + 1) > qj (t); if ρ̄j (t) < qj (t), then qj (t + 1) < qj (t); and if ρ̄j (t) = qj (t), then qj (t + 1) = qj (t).  Proof. From (11), we have qj (t+1)−qj (t) = ω ρ̄j (t)−qj (t) . Since ω ∈ (0, 1], the sign of qj (t + 1) − qj (t) is the same as the sign of ρ̄j (t) − qj (t). Therefore, above-reference realized compliance improves future posture, whereas belowreference realized compliance decreases future posture. Since qj (t) further affects package feasibility, privacy exposure, delay overhead, and compliance cost, the update links current runtime compliance to future market competitiveness. □ Remark 1. Buyer protection and weak budget balance. For every accepted trade (ui , ej ), the monetary settlement utility of B the buyer satisfies Ui,j (t) = 12 Ω⋆i,j (t)+χ Λi,j (t) ≥ 21 Ω⋆i,j (t) > 0. The compensation term should be interpreted as monetary protection against weak runtime compliance, rather than as an improvement of the realized service experience. Moreover, the platform only redistributes the forfeited deposit and retains (1−χ)Λi,j (t) ≥ 0, so it never needs to inject external subsidy. Hence, ZEBRIS is no-subsidy and weakly budget balanced. IV. E VALUATION We conduct simulations to evaluate the effectiveness of ZEBRIS. All experiments are implemented in Python 3.10 on a 12th Gen Intel Core i9-12900H processor.

A. Simulation Setup, Baselines, and Metrics We consider a dynamic privacy-sensitive edge service market with |E| = 6 sellers, average aggregate bandwidth of 48 MHz, average aggregate computation capacity of 150 × 109 cycles/s, and 180 trading rounds per episode. For each active buyer ui ∈ U (t), the request  tuple Ji (t) = Li (t), Ci (t), Dimax (t), ℓi (t), smin (t), v (t) is generated with i i Li (t) ∈ [0.15, 0.95] MB, Ci (t) ∈ [0.10, 1.00] × 109 cycles [8], Dimax (t) ∈ [0.25, 0.90] s, ℓi (t) ∈ [0.20, 1.00], (t) ∈ [0.40, 0.90], and vi (t) ∈ [8, 20]. Buyer activation smin i follows Bernoulli trials with probabilities calibrated [8] from the Chicago taxi trips dataset [9]. Other parameters are set as follows [6], [8], [10]: Bj (t) ∈ [6, 10] MHz, Fj (t) ∈ [18, 32] × 109 cycles/s, qj (t) ∈ [0.50, 0.92], aj (t) ∈ [2, 6], F αi ∈ [3, 6], βi ∈ [2, 5], κB j ∈ [0.08, 0.18], κj ∈ [0.10, 0.22], (η1 , η2 , η3 ) = (0.35, 0.30, 0.35), χ = 0.70, and λ = 0.40. We cand set ϕ(z, q) = (1 − z)(1 − q), generate Pi,j (t) by discretizing bandwidth, computation, and verification intensity, and average all results over 50 independent Monte Carlo runs. Runtime compliance outcomes are generated by a  deposit-aware effort  ∆i,j (t) level ϵi,j (t) = σ τ0 + τ1 qj (t) + τ2 â⋆ (t) , where σ(·) is the i,j

sigmoid function2 . We compare ZEBRIS with five baselines3 : (i) ResOnly, a resource-only trading benchmark inspired by [3] that clears trades using raw valuation–ask comparison without privacy risk, compliance cost, or ex-post settlement; (ii) PAware, a privacy-aware clearing benchmark inspired by [7] that considers delay and privacy penalties but removes deposit-refund regulation; (iii) ZTOnly, a zero-trust-aware benchmark inspired by [4] that considers verification overhead and compliance cost only during ex-ante clearing, but removes ex-post depositrefund settlement, buyer compensation, and posture feedback; (iv) AskFirst, a cost-oriented heuristic inspired by [6] that prioritizes feasible packages with lower effective asks; and (v) ZEBRIS-S, an ablation variant that preserves zero-trust-aware clearing and deposit-refund settlement but keeps seller posture static over time. We evaluate all methods using six metrics: (i) Social welfare (SW), the total effective bilateral surplus over accepted trades4 ; (ii) Accepted trading ratio (ATR), the fraction of active requests admitted into trading; (iii) Average end-toend delay (AED), the mean realized delay of accepted trades; (iv) Average privacy-risk-weighted cost (APRC), the average privacy penalty βi ξi,j (t); (v) Average compliance score (ACS), the average score aggregated from authentication success, policy consistency, and SLA satisfaction; and (vi) Seller utility (SU), the average realized seller utility after settlement. B. Performance Evaluation We first evaluate economic performance and trading behavior in Fig. 2. In Fig. 2(a), the SW of most compared schemes 2 The effort level only parameterizes stochastic runtime compliance, rather than deterministically favoring ZEBRIS. A larger ϵi,j (t) statistically improves authentication, policy consistency, and SLA satisfaction. 3 For fairness, all non-heuristic methods use the same resource-discretized clearing routine when applicable. For methods without deposit-refund regulation, we set ∆i,j (t) = 0, so compliance outcomes depend only on seller posture and runtime randomness. 4 Transfer terms such as payment and deposit redistribution are not counted in SW, but deposit-refund regulation can indirectly affect SW through runtime compliance, seller posture, and future feasibility.

PAware

6000

SU

SW

8000

4000

ZTOnly

AskFirst

ZEBRIS-S

5

1.2

4.5

1

4

ATR

ResOnly 10000

3.5

2000

3

0 10

20

30

40

0.6

ResOnly PAware ZTOnly

AskFirst ZEBRIS-S ZEBRIS

0.4 0.2

2.5 10

Number of buyers (a)

0.8

ZEBRIS

20

30

0

40

Number of buyers (b)

10/2

20/4

100/20 120/24

Number of buyers / sellers (c)

Fig. 2. Economic performance and trading behavior under different market scales: (a) SW, (b) SU, and (c) ATR. ResOnly

PAware

ZTOnly

AskFirst

ZEBRIS-S 1

0.8

2

0.8

0.6

1.5

0.4 0.2 0

APRC

2.5

AED

ACS

1

1 0.5

10/2

20/4

100/20

120/24

Number of buyers / sellers (a)

0

ZEBRIS

0.6 0.4 0.2

10/2

20/4

100/20

120/24

Number of buyers / sellers (b)

0

10/2

20/4

100/20

120/24

Number of buyers / sellers (c)

Fig. 3. Compliance and service quality under different market scales: (a) ACS, (b) AED, and (c) APRC.

increases with the number of buyers, since a larger buyer population creates more candidate trades and more opportunities for profitable matching. Among all methods, ZEBRIS consistently achieves the highest SW, demonstrating the benefit of jointly integrating zero-trust-compliant package selection, expost deposit-refund settlement, and cross-round seller-posture evolution. This also indicates that admitting more trades does not necessarily improve effective welfare, because trades with weak compliance, high privacy exposure, or excessive service delay may reduce the realized market quality. By contrast, ResOnly performs poorly because it admits trades without explicitly accounting for verification overhead, privacy loss, or security mismatch. Fig. 2(b) reports SU under different buyer populations. ZEBRIS increases steadily and remains among the best-performing methods. More importantly, it consistently outperforms ZEBRIS-S, highlighting the value of feeding realized compliance back to future seller posture. Although ResOnly may obtain relatively high SU in some settings, this gain comes from weakly regulated and seller-favorable trading, accompanied by inferior welfare and compliance quality. Fig. 2(c) shows that ResOnly attains the highest ATR due to aggressive admission, while ZEBRIS maintains a moderate ATR by prioritizing effective and trustworthy trades over admitted-request quantity. We next evaluate compliance and service quality in Fig. 3. In Fig. 3(a), ZEBRIS consistently achieves the highest ACS across all market scales. This verifies that coupling ex-post settlement with measurable runtime compliance can effectively discipline seller behavior after clearing. The consistent gain over ZEBRIS-S further indicates that dynamic posture evolution is important for sustaining long-term compliance robustness rather than only improving one-shot execution quality. By contrast, ResOnly obtains the lowest ACS due to the lack of explicit zero-trust regulation and ex-post discipline. Fig. 3(b) presents the AED. ZEBRIS yields the lowest delay, mainly because package selection explicitly accounts for delay feasibility and because posture feedback gradually favors sellers with more reliable runtime fulfillment. In contrast, aggressive admission without accounting for actual service quality causes ResOnly to suffer the largest delay. Fig. 3(c) reports the APRC. ZEBRIS consistently achieves the lowest

APRC, confirming its advantage in privacy-sensitive edge markets. In contrast, ZTOnly, AskFirst, and ZEBRIS-S incur higher privacy-related cost, while ResOnly performs the worst because privacy risk and zero-trust compliance are ignored during clearing. These results confirm that privacy risk and runtime compliance should be embedded into both ex-ante trading and ex-post settlement. Overall, the results in Figs. 2 and 3 verify the effectiveness of ZEBRIS from both economic and service-quality perspectives. Compared with representative baselines, ZEBRIS achieves higher SW, stronger ACS, lower AED, and lower APRC, while still maintaining favorable seller utility. More importantly, the comparison with ZEBRIS-S highlights that cross-round seller-posture evolution is not merely an auxiliary refinement, but a key component for stabilizing trustworthy bilateral edge service trading under zero trust. V. C ONCLUSION This paper investigated privacy-sensitive edge service trading in dynamic zero-trust edge markets and proposed ZEBRIS, a bilateral edge trading framework for runtime compliance regulation. By modeling edge provisioning as the trading of zerotrust-compliant service packages, ZEBRIS jointly integrates delay penalty, privacy risk, resource cost, and compliance cost into ex-ante clearing, and further disciplines seller-side runtime behavior through measurable ex-post settlement and cross-round security-posture evolution. Experiments showed that ZEBRIS improves social welfare and compliance robustness while reducing service delay and privacy-risk-weighted cost. Future work will extend ZEBRIS to multi-platform edge markets, richer zero-trust policy models, and more adaptive long-term incentive regulation. R EFERENCES [1] X. Wang, Q. Gao, X. Zheng, T. Tao, G. Yang, and L. Mo, “Privacy protection in trajectory data publication based on differential privacy,” in 2024 IEEE GLOBECOM, pp. 49–54, IEEE, 2024. [2] Z. Cheng, X. Xia, H. Wang, M. Liwang, N. Chen, X. Fan, and X. Wang, “Privacy-aware joint dnn model deployment and partitioning optimization for collaborative edge inference services,” IEEE Trans. Serv. Comput., vol. 18, no. 5, pp. 3079–3092, 2025. [3] X. Wang, X. Wang, C. Wang, R. Zeng, L. Ma, Q. He, and M. Huang, “Truthful online combinatorial auction-based mechanisms for task offloading in mobile edge computing,” IEEE Trans. Mobile Comput., vol. 24, no. 7, pp. 6488–6502, 2025. [4] G. Zheng, Q. Ni, and W. Yu, “Eo-zt: Economically informed zero-trust for secure spectrum trading in open radio access networks (o-ran),” Comput. Netw., p. 111846, 2025. [5] X. Xu, K. Meng, H. Xiang, G. Cui, X. Xia, and W. Dou, “Blockchainenabled secure, fair and scalable data sharing in zero-trust edge-end environment,” IEEE J. Sel. Areas Commun., vol. 43, no. 6, pp. 2056– 2069, 2025. [6] S. Wu, M. Liwang, D. Wang, X. Wang, C. Wu, J. Tang, L. Li, and X. Xia, “Effective two-stage double auction for dynamic resource provision over edge networks via discovering the power of overbooking,” IEEE Trans. Serv. Comput., vol. 18, no. 6, pp. 3723–3735, 2025. [7] W. Zhuang and Y. Mao, “Privacy-aware multi-device cooperative edge inference with distributed resource bidding,” in 2025 IEEE GLOBECOM, pp. 1041–1046, IEEE, 2025. [8] H. Qi, M. Liwang, S. Hosseinalipour, L. Fu, S. Zou, and W. Ni, “Future resource bank for isac: Achieving fast and stable win-win matching for both individuals and coalitions,” IEEE J. Sel. Areas Commun., vol. 44, pp. 513–530, 2026. [9] City of Chicago, “Taxi trips 2013.” [Online]. Available: https://data.cityofchicago.org/Transportation/Taxi-Trips-2013/6h2xdrp2, 2013. [10] 3GPP, “5G; Study on Scenarios and Requirements for Next Generation Access Technologies,” Technical Report TR 38.913 V17.0.0, 3GPP, May 2022. Release 17.

Record · ID 155205 · SHA-256 c5027ccc2a81efce
Retrieved via Conceptio — every document is proof-bundled with source, license, and retrieval metadata.