arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

长期运行AI智能体记忆中的压缩 cliff

The Compaction Cliff in Long-Running AI Agent Memory

Saber Zerhoudi, Jelena Mitrovic, Michael Granitzer

arXiv 2608.22752首次发表:更新:

发表机构

University of Passau; IT:U(帕绍大学; IT:U)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

针对AI智能体记忆压缩时安全规则保留率骤降的压缩cliff问题,提出Knowledge Triage框架,通过三类算子优化上下文管理,在多基准测试中优于现有方法,并发布了相关数据集与工具。

AI 中文摘要

在AI智能体的上下文环境中,安全规则与事件日志会争夺相同的 token。当预算溢出时,两者会以相同的速率被压缩;但安全规则需要精确的措辞才能保持可执行性。在20种生产级智能体配置上,Sonnet 4.6中Claude Code的/compact提示在一轮压缩后保留了53%的安全规则,五轮后仅保留10%,我们将此现象命名为压缩 cliff。我们通过知识分类(Knowledge Triage)框架解决该问题,该框架会对智能体知识库的每一行按类型分类,并为每种类型配置独立的保留策略。三种确定性算子在三类上下文管理操作中实现该分类:TypeCompact在按类型保真度的前提下就地重写条目;TypeDecompose对过大而无法安全压缩的主题进行分区,在各分区中复制范围内的安全规则;TypeRetrieve从外部存储获取条目,在按相关性检索前固定范围内的安全规则。在五个公开语料库上,TypeCompact在所有比例下保留的安全规则是最强单步LLM压缩器的2-4倍,五轮后的召回率达96%;TypeDecompose的局部性违规率为0%,而均匀分区下为93%;TypeRetrieve的召回率@50达100%,而最佳单步LLM检索器为73%。在三个下游行为基准测试中,我们在医疗合规性上优于生产级Sonnet压缩器(配对McNemar检验,保留率p<10⁻⁸,样本量N=200),在零售任务通过率上优于全策略和分层基线(p<0.01,N=115),在航空领域优于分层压缩(p=0.024)。我们发布了AgentArtifactCorpus(来自54628个公开GitHub仓库的396934种智能体配置)、分类器及参考实现。

英文摘要

A safety rule and an episodic log compete for the same tokens in an AI agent's context. When the budget overflows, both are summarized at the same rate; only the rule needs exact wording to remain enforceable. On 20 production agent configurations, Claude Code's /compact prompt on Sonnet 4.6 preserves 53\% of safety rules after one compaction round and 10\% after five. We name this the Compaction Cliff. We address it with Knowledge Triage, a framework that classifies each line of an agent's knowledge base by type and routes each type through its own retention policy. Three deterministic operators implement this triage across the three context-management operations: TypeCompact rewrites items in place under per-type fidelity, TypeDecompose partitions a topic too large to compact safely, replicating in-scope safety rules across partitions, and TypeRetrieve fetches items from external storage with in-scope rules pinned ahead of relevance. On five public corpora, TypeCompact preserves 2--4$\times$ more safety rules than the strongest single-shot LLM compactor at every ratio, with 96\% recall over five rounds. TypeDecompose reaches 0\% locality violations against 93\% under uniform partitioning. TypeRetrieve reaches 100\% recall@50 against 73\% for the best single-shot LLM retriever. On three downstream behavioral benchmarks, we outperform the production Sonnet compactor on medical compliance (paired McNemar $p < 10^{-8}$ on preservation, $N = 200$), the full-policy and hierarchical baselines on retail task pass rate ($p < 0.01$, $N = 115$), and the hierarchical compaction on the airline domain ($p = 0.024$). We release AgentArtifactCorpus (396{,}934 agent configurations from 54{,}628 public GitHub repositories), the classifier, and the reference implementation.

Journal refProceedings of the 35th ACM International Conference on Information and Knowledge Management (CIKM 2026)

DOI:10.1145/3799682.3840567

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑