arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2608.29381cs.CRcs.AI

是否可以安全恢复?通过回滚破坏智能体执行的连续性

Safe to Resume? Breaking Execution Continuity of Agent Execution via Rollback

Guanlong Wu, Dahui Li, Ke Jiang, Jianyu Niu, Cong Wang, Yinqian Zhang

首次发表
浏览论文内容

中文总结 AI 辅助

本文对现有智能体系统的检查点与回滚进行首次系统性安全研究,识别出五种基本故障模式,通过三个端到端攻击展示安全影响,发现相关故障源于检查点恢复状态与安全继续执行所需依赖的差距。

中文摘要 AI 辅助

AI智能体正朝着跨多种应用的持久、有状态执行方向发展,其积累的执行状态和外部效应在发生故障后重建成本高昂。检查点与回滚(Checkpoint and Rollback,C/R)正成为恢复的关键,但它们的安全影响在很大程度上仍未被探索。正确的回滚并不意味着安全的恢复:被忠实恢复的检查点可能会恢复其状态、假设和外部效应从未在任何有效历史中共存的执行。在本文中,我们对现有智能体系统中的检查点与回滚展开了首次系统性安全研究。通过检查代表性的智能体C/R系统,我们刻画了现有C/R机制的设计空间,并开发了一个通用执行模型,以捕捉它们的恢复边界和状态依赖关系。从该模型出发,我们识别出五种基本故障模式,涵盖内部状态不完整或不一致、过时的外部依赖、非确定性重放以及未记录的外部效应。我们进一步通过对Hermes、Cline和LangGraph的三个端到端攻击展示了它们的安全影响,这些攻击可实现恶意软件验证绕过、未授权邮件转发和双重支付。为了在实践中系统性研究这些故障,我们开发了一个多智能体分析流水线,用于重构执行语义、识别对五种故障条件的违反,并通过实际回滚验证它们。在五个代表性框架上的评估表明,这些故障在异构C/R设计中反复出现,且源于检查点恢复的状态与安全继续执行所需的依赖之间的共同差距。

英文摘要

AI agents are moving toward persistent, stateful execution across various applications, accumulating execution state and external effects that are costly to reconstruct after failures. Checkpoint and rollback (C/R) are becoming essential for recovery, yet their security implications remain largely unexplored. Correct rollback does not imply secure recovery: a faithfully restored checkpoint may resume an execution whose states, assumptions, and external effects never coexisted in any valid history. In this paper, we present the first systematic security study of checkpoint and rollback in existing agent systems. By examining representative agent C/R systems, we characterize the design space of existing C/R mechanisms and develop a general execution model that captures their recovery boundaries and state dependencies. From this model, we identify five fundamental failure modes spanning incomplete or inconsistent internal state, stale external dependencies, nondeterministic replay, and unrecorded external effects. We further demonstrate their security impact through three end-to-end attacks on Hermes, Cline, and LangGraph, enabling malware-verification bypass, unauthorized mail forwarding, and double payment. To systematically study these failures in practice, we develop a multi-agent analysis pipeline that reconstructs execution semantics, identifies violations of the five failure conditions, and validates them through actual rollback. Across five representative frameworks, our evaluation shows that these failures recur across heterogeneous C/R designs and stem from a common gap between the state restored by a checkpoint and the dependencies required for secure continuation.

发表机构

  • Southern University of Science and Technology(南方科技大学)
  • City University of Hong Kong(香港城市大学)

机构由 AI 辅助整理,请以论文原文为准。

↑