发表机构
Shenzhen University(深圳大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
该研究针对LLM智能体工作流中交接转换弱化状态约束的问题,通过1296个受控合成场景实验,发现常规交接压缩会导致高失活和禁止动作率,恢复全部状态字段可解决该问题。
AI 中文摘要
大型语言模型(LLM)智能体通过多角色、多阶段工作流协调复杂任务。上游状态会被反复转换为中间语言产物,如摘要、计划、工单、记忆和交接说明,下游组件据此采取行动。对于受动作约束的状态,主题保留是不够的:某个产物可能提及未解决的条件,同时将其从“必须在执行前解决”的要求转变为“仅可为后续行动提供信息”的内容。我们将这种动作绑定角色研究称为操作状态保留。安全阻断器提供了一个受控实例,因为每个源状态都有明确的前提条件、权限、 fallback(回退)和执行后果。我们以正确的上游识别为条件,改变交接转换方式,并评估受所得产物限制的执行器。在1296个受控合成场景中,直接交接控制保留了所有阻断器,而压缩、计划同化、收敛、所有权推迟和先例替换会反复将绑定状态变为警告或非绑定考虑因素。常规交接压缩产生100.0%的失活率和54.2%的禁止动作率。恢复全部四个状态字段可将保留率提升至100.0%,并将禁止动作率降至0.0%。固定产物干预进一步将保留与遏制分开:下游验证消除了禁止动作,而产物失活率仍为95.3%。这些结果揭示了信息提取与动作之间的状态传输故障:交接转换可在保留状态内容的同时弱化其对下游动作的约束,语义可用性不保证操作保留。
英文摘要
Large language model (LLM) agents coordinate complex tasks through multi-role and multi-stage workflows. Upstream state is repeatedly transformed into intermediate language artifacts, such as summaries, plans, tickets, memories, and handoff notes, from which downstream components act. For action-constraining state, topical retention is insufficient: an artifact may mention an unresolved condition while changing it from a requirement that must be resolved before execution into information that may merely inform the next action. We study this action-binding role as operational state preservation. Safety blockers provide a controlled instance because each source state has an explicit prerequisite, authority, fallback, and execution consequence. We condition on correct upstream identification, vary the handoff transformation, and evaluate an executor restricted to the resulting artifact. Across 1,296 controlled synthetic episodes, direct-handoff controls preserve every blocker, whereas compression, plan assimilation, convergence, ownership deferral, and precedent substitution repeatedly turn binding state into caveats or non-binding considerations. Normal handoff compression produces 100.0% deactivation and 54.2% forbidden action. Restoring all four state fields raises preservation to 100.0% and reduces forbidden action to 0.0%. Fixed-artifact interventions further separate preservation from containment: downstream verification eliminates forbidden action while artifact deactivation remains 95.3%. These results identify a state-transmission failure between information extraction and action. Handoff transformations can retain state content while weakening its constraints on downstream action. Semantic availability does not guarantee operational preservation.
Comments21 pages, 4 figures