arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

BRA-Audit:基于累积暴露审计点放置的LLM多智能体系统预算运行时审计

BRA-Audit: Budgeted Runtime Auditing for LLM Multi-Agent Systems via Cumulative-Exposure Audit-Point Placement

Kaixiang Wang, Yidan Lin, Jiong Lou, Jie Li

arXiv 2608.14668首次发表:更新:

AI 中文总结

BRA-Audit是一种预算感知的LLM多智能体系统运行时审计框架,通过贪心调度放置审计点,在保障防护性能的同时降低了17.2%-40.6%的端到端token消耗。

AI 中文摘要

基于大语言模型的多智能体系统(LLM-MAS)通过专业化协作解决复杂任务,但智能体间的依赖关系会将幻觉或恶意输出传播为系统级故障。审计智能体可缓解这些风险,但现有策略面临效率困境:仅在结束时审计会审查长轨迹和最终输出,可能削弱审计效果并扩大回滚范围;而每轮审计所有智能体虽提升检测与定位能力,但token成本高。如何在保留防护性能的同时最小化token成本?针对该问题,本文提出BRA-Audit,一种预算感知的运行时审计框架,将MAS执行建模为动态依赖图,将审计调度建模为固定审计调用预算下的审计点放置,以最小化累积未审计暴露。其贪心调度器优先选择有影响力且长期未审计的区域,而可信审计点支持局部恢复。在结构化协作、复杂推理和开放式任务中,BRA-Audit恢复的性能接近干净设置,与重型防护方法表现相当,并将端到端token消耗降低17.2%至40.6%。

英文摘要

LLM-based multi-agent systems (LLM-MAS) solve complex tasks through specialized collaboration, but inter-agent dependencies can propagate hallucinated or malicious outputs into system-level failures. Auditor agents mitigate these risks, yet existing strategies face an efficiency dilemma: end-only auditing reviews long trajectories and final outputs, potentially weakening audit effectiveness and enlarging rollback scope, while auditing every agent each round improves detection and localization at high token cost. How can guard performance be preserved while minimizing token cost? To address this problem, we propose BRA-Audit, a budget-aware runtime auditing framework that models MAS execution as a dynamic dependency graph and formulates audit scheduling as audit-point placement under a fixed audit-call budget to minimize cumulative unchecked exposure. Its greedy scheduler prioritizes influential and long-unaudited regions, while trusted audit points enable localized recovery. Across structured coordination, complex reasoning, and open-ended tasks, BRA-Audit restores performance close to the clean setting, remains competitive with heavy guard methods and reduces end-to-end token consumption by \(17.2\%\)--\(40.6\%\).

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑