发表机构
International University of La Rioja(拉里奥ja国际大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
研究大型语言模型代理提交时间授权问题,构建受控失效套件实验,发现端点成功率高但授权完成率低,评估缓解措施,提出CommitGuard可阻止过时持久影响尝试,指出端点成功是实用指标,授权提交是安全属性。
AI 中文摘要
大型语言模型代理可以根据执行早期有效的权限证据产生持久影响,如DOM快照、批准时期、版本见证、分支令牌或工作结果。我们研究了提交边界,即早期权限证据不再授权持久影响的边界。我们将此属性称为提交时间授权:只有当许可其派生状态的见证保持新鲜、因果在先、与同一影响相关联且在提交时符合条件时,持久影响才被授权。我们构建了一个涵盖浏览器、工具/API和多智能体工作流程的受控失效套件。该套件在使权限关系在持久化之前失效的同时,保留了用户目标和有效负载形状。在主要的54任务矩阵中,端点成功率仍然很高:270次运行中有262次达到可见结果。只有55次是授权完成;在216次失效行中,有207次在授权路径失败后提交。所有54个干净的控件仍被授权,另外54次运行的权限保留检查未产生未授权的提交。然后我们评估缓解措施系列。提示谨慎和单条件检查是不够的,因为不同的风险会破坏不同的边界条件。当防御措施在持久化边界进行刷新、重新绑定、重新规划或拒绝时,它们会起作用。CommitGuard是一个故障关闭边界监视器,当运行时发出见证、依赖、绑定和合格信号时,它会阻止对受保护提交表面的过时持久影响尝试。结果是一个报告和运行时设计教训:端点成功是一个实用指标;授权提交是一个安全属性。
英文摘要
LLM agents can commit durable effects from authority evidence that was valid earlier in execution: a DOM snapshot, approval epoch, version witness, branch token, or worker result. We study the commit boundary at which earlier authority evidence no longer authorizes a durable effect. We call this property commit-time authorization: a durable effect is authorized only if the witness that licensed its derived state remains fresh, causally prior, bound to the same effect, and eligible at commit time. We build a controlled-invalidation suite spanning browser, tool/API, and multi-agent workflows. The suite preserves the user goal and payload shape while invalidating the authority relation before durability. In the primary 54-task matrix, endpoint success remains high: 262/270 runs reach the visible result. Only 55/270 are authorized completions; among the 216 invalidating rows, 207 commit after the authorizing path has failed. All 54 clean controls remain authorized, and a separate 54-run authority-preserving check produces no unauthorized commits. We then evaluate mitigation families. Prompt caution and single-condition checks are insufficient because different hazards break different boundary conditions. Defenses work when they refresh, rebind, replan, or refuse at the durability boundary. CommitGuard, a fail-closed boundary monitor, blocks stale durable-effect attempts on protected commit surfaces when runtimes emit witness, dependency, binding, and eligibility signals. The result is a reporting and runtime-design lesson: endpoint success is a utility metric; authorized commit is a security property.
Comments20 pages