发表机构
Universidad Torcuato Di Tella(托库阿托·迪·特拉大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
该研究针对智能体AI的元数据缺陷问题,提出SARC-DQ运行时数据质量门控机制,实验显示模型能力未提升怀疑能力,所提门控结合下游修复可恢复部分损失,无模型预言机能精准跟踪缺陷率。
AI 中文摘要
智能体系统会执行动作,因此其检索到的证据存在缺陷时会导致产生附带货币成本的错误动作。企业中最危险的缺陷源自元数据:如过时的价格或已被取代的记录,这些缺陷在有效载荷中完全合规,仅通过新鲜度、谱系或来源可被识别。此类缺陷永远不会进入智能体的上下文,智能体无法对其未看到的数据产生怀疑。在定价补货基准测试中,能力较强的智能体约60%的概率会将注入的元数据缺陷转化为高成本动作,且无任何数据质量标记,行为怀疑标记的表现与随机水平相当(AUC≤0.50)。在推理价格跨度约15倍的四个模型层级中,该比例保持稳定:能力提升并未带来怀疑能力的提升。一种感知元数据的预动作门控机制结合仅下游修复,在其谓词覆盖的信号上可完全恢复损失,在未覆盖的信号上则完全无法恢复。基于任务决策几何的无模型预言机以0.015的平均绝对误差(MAE)跟踪测量比例(皮尔逊相关系数r=0.876,区间覆盖率15/16单元格),为该稳定规律提供了分析形式。证据完整性是与模型能力不同的系统维度,缓解措施取决于执行位置和谓词覆盖范围。代码、冻结结果及确定性分析管道可通过该https URL获取。
英文摘要
Agentic systems act, so a defect in the evidence they retrieve becomes a wrong action with a currency cost. The most dangerous enterprise defects are metadata-borne: a stale price or a superseded record, perfectly well-formed in the payload and betrayed only by freshness, lineage, or provenance. Such a defect never enters the agent's context, and an agent cannot doubt data it cannot see. On a priced replenishment benchmark, a competent agent silently converts an injected metadata-borne defect into a costly action about 60% of the time, with zero data-quality flags and behavioral doubt markers at chance (AUC <= 0.50). Across four model tiers spanning roughly 15x in inference price, the rate stays flat: capability does not buy skepticism. A metadata-aware pre-action gate with downstream-only remediation recovers the loss fully on the signals its predicates cover and not at all on those they miss. A model-free oracle derived from the task's decision geometry tracks the measured rates with MAE 0.015 (Pearson r = 0.876, interval coverage 15/16 cells), giving the flat ladder an analytical form. Evidence integrity is a systems axis distinct from model capability; mitigation depends on enforcement placement and predicate coverage. Code, frozen results, and a deterministic analysis pipeline: https://github.com/besanson/dqSarc
Commentshttps://github.com/besanson/dqSarc