AI 中文总结
研究针对使用工具的智能体,提出多提供方类型化运行时Metis,通过中介机制优化耗时,验证其权限控制等效果,明确其能力边界。
AI 中文摘要
软件智能体将概率模型的输出与变更仓库、流程、网络和图形应用程序的操作相连。我们提出Metis,这是一种多提供方运行时,可在调用到达外部效应之前,将提供方流转换为类型化事件。其执行路径使权限决策、干扰类别、终端结果和生命周期转换明确且可检查。我们在冻结源代码制品上评估这些机制:在30对匹配的真实I/O对中,四类中介将中位耗时从强制序列化下的25.958毫秒降至14.146毫秒;平均配对差值为-12.295毫秒(95%自举区间[-12.968, -11.694]),且所有对中中介均更快。十例故障矩阵暴露了重复标识符和回滚限制;在子边界消融实验中,完整的网关加注册表条件阻止了声明的未授权效应并隐藏了全部五个逃逸工具,移除两项保护则反转两项观测结果;仅决策权限预言机在五条调用路径上匹配全部十例声明情况;五个模型条件在3/3次试验中均完成了固定Read-marker协议。这些结果支持关于调度、权限路由、子权限和提供方有效跟踪闭合的有限结论,但未确立模型能力、语义安全性、回滚或优于其他运行时。
英文摘要
Software agents connect probabilistic model output to operations that change repositories, processes, networks, and graphical applications. We present Metis, a multi-provider runtime that converts provider streams into typed events before admitted calls reach external effects. Its execution path makes permission decisions, interference classes, terminal results, and lifecycle transitions explicit and inspectable. We evaluate these mechanisms on frozen source artifacts. Across 30 matched real-I/O pairs, four-class mediation reduced median elapsed time from 25.958 ms under forced serialization to 14.146 ms. The mean paired difference was -12.295 ms (95% bootstrap interval [-12.968, -11.694]), with mediation faster in all pairs. A ten-case fault matrix exposed duplicate-identifier and rollback limits. In a child-boundary ablation, the full gate-plus-registry condition blocked the declared unauthorized effect and hid all five escape tools. Removing both protections reversed both observations. A decision-only permission oracle matched all ten declared cases across five invocation routes. Five model conditions also completed a fixed Read-marker protocol in 3/3 trials each. These results support bounded claims about dispatch, permission routing, child authority, and provider-valid trace closure. They do not establish model competence, semantic safety, rollback, or superiority over another runtime.
Comments18 pages, 7 figures, 6 tables. Public preprint; supporting artifact is being curated