AI 中文总结
该研究针对大语言模型智能体重规划等行为引发的语义重放问题,提出 CapLease 授权消耗层,结合服务器账本实现抗重放,证明持久授权状态是抗重放智能体执行的系统要求。
AI 中文摘要
使用工具的大语言模型智能体经常进行重新规划、重试失败的操作、委派任务以及在崩溃后恢复。这些行为会导致,即使每个单独的令牌是单次使用的,也会在新颁发的令牌标识符下请求并执行同一用户授权多次。我们将这种故障称为语义重放:超出与令牌无关的授权实例的执行预算,而非仅仅重用旧的令牌标识符。我们证明,除非颁发方对授权行动、确认事件和剩余执行预算保留单调持久状态,否则标识符局部的令牌消耗无法阻止新的重颁发。我们提出 CapLease,这是一个遵循提案和权限级别防御的授权消耗层,将经过身份验证的用户确认绑定到规范行动,并强制执行事务性的颁发-准备-提交转换。在大语言模型智能体的重新规划、重试、委派、并发、确认重放和崩溃恢复场景中,标识符局部令牌允许新的语义重颁发,而 CapLease 和同样具有状态的服务器账本可防止重复接纳,并且借助幂等汇点可防止重复的外部效果。我们的结果确定,持久授权状态而非仅令牌表示,是抗重放智能体执行的系统要求。
英文摘要
Tool-using large language model agents frequently replan, retry failed operations, delegate tasks, and resume after crashes. These behaviors can cause one user authorization to be requested and executed multiple times under freshly issued token identifiers, even when each individual token is single-use. We call this failure semantic replay: exceeding the execution budget of a token-independent authorization instance rather than merely reusing an old token identifier. We show that identifier-local token consumption cannot prevent fresh reissuance unless the issuer retains monotonic durable state over the authorized action, confirmation event, and remaining execution budget. We introduce CapLease, an authorization-consumption layer that follows proposal- and authority-level defenses, binds an authenticated user confirmation to a canonical action, and enforces transactional Issue-Prepare-Commit transitions. Across LLM-agent replanning, retry, delegation, concurrency, confirmation-replay, and crash-recovery scenarios, identifier-local tokens permit fresh semantic reissuance, whereas CapLease and an equally stateful Server Ledger prevent duplicate admission and, with an idempotent sink, duplicate external effects. Our results identify durable authorization state, rather than token representation alone, as the systems requirement for replay-resistant agent execution.