AI 中文总结
针对AI工作流因语义环境并发变更导致结果不一致的问题,提出语义隔离框架,定义四类异常,推导隔离级别偏序,原型SemIso可高效检查并阻止不兼容资源与分支合并。
AI 中文摘要
当前AI执行可超越其启动时的环境,原本单次模型调用可完成的任务,如今越来越多地通过暂停、重试、分支、子智能体及模型选定的工具逐步展开。与此同时,提示词、模型别名、索引、策略和工具均独立部署:稳定名称可获得新行为,工作流仅在启动后才能发现资源。因此,即使每次调用都成功,工作流也可能将保存的状态与变更的假设结合,产生内部不一致的结果。这是一个隔离问题:数据库事务约束并发数据更新,但工作流检查点未为AI工作流的语义环境并发变更提供对应契约。我们定义了四种可自动检测的异常:语义读偏斜、兼容性偏斜、上下文逃逸和合并偏斜。为控制允许的异常,我们结合资源稳定性、跨资源兼容性和延续继承这三个独立保障,推导了从语义读提交到语义快照隔离的隔离级别偏序。在对100个拥有可执行LangGraph代码的最受关注公共仓库进行的保守源代码审计中,我们发现7.4%的具有持久工作流的代码库在同一工作流内解析活动或动态选定的语义资源,且无明显的不可变绑定。我们证明这些保障可在中间件中高效检查和实施。我们的原型SemIso可传播语义上下文,并以微秒级检查阻止不兼容资源和分支合并。
英文摘要
An AI execution can now outlive the environment in which it began. What once fit inside one model call increasingly unfolds across pauses, retries, branches, subagents, and model-selected tools. Meanwhile, prompts, model aliases, indexes, policies, and tools are deployed independently: stable names can acquire new behavior, and workflows can discover resources only after they start. The workflow can therefore combine saved state with changed assumptions, producing an internally inconsistent result even when every call succeeds. This is an isolation problem: database transactions constrain concurrent data updates, but workflow checkpointing provides no corresponding contract for concurrent changes to an AI workflow's semantic environment. We define four automatically detectable anomalies: semantic read skew, compatibility skew, context escape, and merge skew. To control which anomalies are allowed, we derive a partial order of isolation levels, from Semantic Read Committed to Semantic Snapshot Isolation, by combining three independent guarantees: resource stability, cross-resource compatibility, and continuation inheritance. In a conservative source audit of the 100 most-starred public repositories with executable LangGraph code, we find that 7.4 percent of codebases with durable workflows resolve live or dynamically selected semantic resources within the same workflow, without an evident immutable binding. We show that these guarantees can be checked and enforced efficiently in middleware. Our prototype, SemIso, propagates semantic context and blocks incompatible resources and branch merges with microsecond-scale checks.
Comments6 pages, 4 figures, and 3 tables