发表机构
The Third Research Institute of the Ministry of Public Security; Bureau of Science and Technology Information Ministry of Public Security of the People’s Republic of China; School of Information and Cyber Security People’s Public Security University of China(公安部第三研究所; 中华人民共和国公安部科技信息局; 中国人民公安大学信息与网络安全学院)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
针对工具使用型LLM智能体的安全管控需求,提出Agentao运行时,通过分层架构分离动作提案与授权执行,将权限等构建为显式抽象,提升智能体可管控性与可检查性。
AI 中文摘要
大语言模型智能体正日益成为调用工具、修改本地状态、使用持久化内存并与外部协议交互的执行系统。这些能力让智能体变得有用,但也带来了与权限过高的操作、可审计性薄弱、提示注入、工具投毒及不受控副作用相关的风险。本文提出了Agentao,一种面向使用工具的大语言模型智能体的受管控本地优先运行时。Agentao通过分层架构将模型生成的动作提案与主机授权的执行分离开,该架构包括面向主机的接口、主机契约、运行时核心、权限中介的工具系统,以及内存、回放、插件、技能、子智能体和协议集成的支持子系统。我们描述了该系统的动机、威胁模型、设计目标、管控模型、执行流水线和结构化事件接口。Agentao不提供形式化安全保证;相反,它展示了如何将权限、状态、协议边界和执行踪迹构建为显式运行时抽象,以构建更具可管控性、可检查性且适用于主机控制的本地环境的智能体。代码可在this https URL获取。
英文摘要
LLM agents increasingly operate as execution systems that invoke tools, modify local state, use persistent memory, and interact with external protocols. These capabilities make agents useful, but they also introduce risks related to over-privileged actions, weak auditability, prompt injection, tool poisoning, and uncontrolled side effects. This paper presents Agentao, a governed local-first runtime for tool-using LLM agents. Agentao separates model-generated action proposals from host-authorized execution through a layered architecture consisting of host-facing surfaces, a host contract, a runtime core, a permission-mediated tool system, and supporting subsystems for memory, replay, plugins, skills, sub-agents, and protocol integration. We describe the motivation, threat model, design goals, governance model, execution pipeline, and structured event interface of the system. Agentao does not provide formal safety guarantees; rather, it demonstrates how permissions, state, protocol boundaries, and execution traces can be made explicit runtime abstractions for building agents that are more governable, inspectable, and suitable for host-controlled local environments. The code is publicly available at https://github.com/jin-bo/agentao .
CommentsThe code is publicly available at Github. We are conducting testing and analysis of this framework, and will provide experimental results and examples in future versions