arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

角色-执行分离:一种用于在执行审计下演进大型语言模型智能体的架构模式

Persona-Execution Separation: An Architecture Pattern for Evolving LLM Agents under Execution Audit

Yisen Xi

arXiv 2608.27427首次发表:更新:

AI 中文总结

本文提出角色-执行分离(PES)架构模式,将LLM智能体的角色与执行分属不同信任域,满足角色自由演进、执行可追溯等需求,并通过试点验证其有效性。

AI 中文摘要

受监管组织中的大型语言模型(LLM)智能体必须让角色(指令、语气、自我呈现)自由演进,同时保持执行(有状态、可审计的工作)可追溯。单一信任域无法廉价地同时满足这两个需求。我们提出角色-执行分离(PES):角色和执行驻留在不同的信任域中,由受监管的契约桥接器连接。角色是单归属的,可能会发生漂移;执行是无身份的,可被审计。状态摘要可返回;数据主体保留在限制性域中,仅存在分级数据丢失防护(DLP)例外;身份保持连续。审批矩阵、DLP和审计机制确保跨域交互。PES遵循三个目标——自由漂移、执行可追溯性和解耦。在LLM表示不可区分的情况下,任何满足所有三个目标的单域机制都必须重新引入类型化变更对象、外部网关和稳定审计锚点:PES以更高的耦合成本重建了这些要素。在受监管的数字员工平台中进行的开发/试点案例记录了一个月内的五个决策,每个决策都有一个被拒绝的替代方案。对已部署实现的机制检查发现,在角色扰动(五种模型配置)下,执行侧无需重新验证,且硬断言字段上没有角色指纹。对分离前构建版本的探查发现,受监管的执行路径通过省略而非构造与角色解耦;后续的布线变更可能会逆转这种隔离,而PES将这种隔离确立为可审计的架构规则。该模式适用于多用户部署、执行审计和预期角色变动同时存在的场景。

英文摘要

Large language model (LLM) agents in governed organizations must let the persona (instructions, tone, self-presentation) evolve freely, while keeping execution (stateful, audited work) traceable. A single trust domain does not satisfy both cheaply. We present Persona-Execution Separation (PES): persona and execution reside in different trust domains, connected by a governed contract bridge. The persona is singly-homed and may drift; execution is faceless and audited. Status summaries may return; data bodies remain in the restrictive domain except a data-loss-prevention (DLP) exception; identity stays continuous. An approval matrix, DLP, and audit enforce the crossing. PES follows from three goals: free drift, execution traceability, and decoupling. Under LLM representational indistinguishability, any single-domain mechanism meeting all three must re-introduce typed change objects, an external gate, and a stable audit anchor: PES rebuilt at higher coupling cost. A development/pilot case in a regulated platform records five decisions over one month, four with rejected alternatives. A mechanism check found no execution-side re-validation under persona perturbation (five configurations) and no persona fingerprint on hard-asserted fields of completed runs. A controlled replication in regulated coding agents reproduced the separation under isolation across five models and four providers; bridge overhead was under 0.2% of end-to-end time in both environments. A probe of a pre-separation build found the execution path decoupled from the persona by omission, not by construction. The pattern applies when multi-user deployment, execution audit, and persona churn hold jointly.

Comments43 pages. v2: new Section 7.5 (cross-domain replication, bridge overhead); framing and Section 8.4 revised; conclusions unchanged

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑