MAP-Graph:面向多智能体工作流的溯源感知共享内存
MAP-Graph: Provenance-Aware Shared Memory for Multi-Agent Workflows
AI总结:
MAP-Graph是面向多智能体工作流的溯源感知共享内存层,通过类型化执行图追踪谱系并结合风险敏感门控,在2700个合成任务的基准测试中取得优异性能,可作为操作控制信号保障智能体工作流的安全与效率。
AI中文摘要:
共享内存可帮助大语言模型智能体在长工作流中复用信息,但相关证据可能不被特定智能体或动作采纳。由于限制会沿推导过程传播,摘要可能隐藏私有、受污染、不可信或已撤销的来源,从而导致未授权读取或不安全动作。现有方法提供语义检索、范围访问或谱系跟踪,但未明确将硬授权与分级信任分离,也未针对动作风险调整证据要求。我们提出MAP-Graph,一种溯源感知内存层,它在类型化执行图中表示智能体、来源、内存、声明和动作,可追踪谱系、排除无权限记录、通过语义相似度与乘法路径信任对合格内存重新排序,并在动作执行前应用风险敏感门控,同时保留受影响谱系用于审计。在跨三个领域、每种方法2700个合成任务的受控基准测试中,MAP-Graph实现了94.96%的总体任务成功率、72.70%的精确决策准确率,以及干净设置下90.22%的准确率,其中成功要求正确的\textsc{Allow}而非安全干预。消融实验分离了权限过滤、路径信任和动作门控的作用,使用两个额外主干的迁移测试保留了精确决策和访问控制优势。这些结果支持溯源作为操作控制信号,而非仅事后审计元数据,在评估场景中具有重要意义。
英文摘要:
Shared memory helps language-model agents reuse information across long workflows, yet relevant evidence may not be admissible for a particular agent or action. Because restrictions propagate through derivations, summaries can conceal private, poisoned, untrusted, or revoked sources, enabling unauthorized reads or unsafe actions. Existing approaches provide semantic retrieval, scoped access, or lineage tracking, but do not clearly separate hard authorization from graded trust or adapt evidence requirements to action risk. We introduce MAP-Graph, a provenance-aware memory layer that represents agents, sources, memories, claims, and actions in a typed execution graph. It traces ancestry, excludes permission-ineligible records, reranks eligible memories by semantic similarity and multiplicative path trust, and applies a risk-sensitive gate before action execution while retaining affected lineage for audit. On a controlled benchmark of 2,700 synthetic tasks per method across three domains, MAP-Graph achieves 94.96\% overall task success, 72.70\% exact decision accuracy, and 90.22\% in the clean setting, where success requires a correct \textsc{Allow} rather than a safe intervention. Ablations isolate the roles of permission filtering, path trust, and action gating, while transfer tests with two additional backbones preserve the exact-decision and access-control advantages. These results support provenance as an operational control signal, rather than only post-hoc audit metadata, within the evaluated setting.