arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

智能体技能很重要:从执行轨迹推断专有技能

Agent Skills Matter: Inferring Proprietary Skills from Execution Trajectories

Jianing Geng, Ruiqi He, Zekun Fei, Biao Yi, Xuansheng Wu, Ruijie Wang, Zheli Liu, Xia Hu, Qingkai Zeng

arXiv 2607.25560首次发表:更新:

发表机构

Nankai University; Shanghai Artificial Intelligence Laboratory; Alibaba Group; East China University of Science and Technology; Beihang University(南开大学; 上海人工智能实验室; 阿里巴巴集团; 华东理工大学; 北京航空航天大学)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

研究从智能体执行轨迹推断专有技能的问题,提出SigLeak黑盒框架,利用技能特征构建诊断任务,通过对比轨迹迭代优化重构技能,在多场景和框架中表现出色,证明良性轨迹可暴露专有知识。

AI 中文摘要

智能体技能包含可提高下游性能的可重复使用程序。其轻量级、便携式形式支持市场货币化和在云托管智能体接口后的私人部署,促使提供商将高价值技能保密。但行为效果会在执行轨迹中显现形成行为侧信道,即技能泄漏。我们定义了技能泄漏,介绍了SigLeak框架,它利用智能体行为中反复出现的技能特征,构建诊断任务,对比启用和未启用技能的轨迹,迭代优化重构技能。在五个场景、三个模型家族和三个智能体框架中,SigLeak在几乎每个设置中都优于或匹配三个基线,平均成功率比无技能参考提高6.88个百分点,实现最高SkillSim。结果表明良性执行轨迹会暴露专有程序知识。

英文摘要

Agent skills package reusable procedures that improve downstream performance. Their lightweight, portable form enables marketplace monetization and private deployment behind cloud-hosted agent interfaces, giving providers incentives to keep high-value skills proprietary. Yet hiding the artifacts does not conceal their behavioral effects, which remain observable in execution trajectories and form a behavioral side channel. We define this exposure as Skill Leakage: reconstructing proprietary skills from trajectories elicited by benign queries, without reference answers or success labels. We introduce SigLeak, a black-box framework that exploits recurring skill signatures in agent behavior. It constructs diverse, decision-rich diagnostic tasks, contrasts matched skill-enabled and skill-disabled trajectories, and iteratively refines a reconstructed skill from the isolated patterns. Across five scenarios, three model families, and three agent frameworks, SigLeak outperforms or matches three baselines in nearly every setting. It raises the success rate by 6.88 percentage points over the skill-disabled reference on average and achieves the highest overall SkillSim, our metric for coarse- and fine-grained semantic similarity. These results show that benign execution trajectories can expose proprietary procedural knowledge. The code is available at https://anonymous.4open.science/r/SigLeak-D1DB.

Comments18 pages, 6 figures, 2 tables

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑