不可逆预算:智能体操作系统的舰队级风险核算与准入控制
The Irreversibility Budget: Fleet-Level Risk Accounting and Admission Control for Agent Operating Systems
浏览论文内容
中文总结 AI 辅助
该研究针对LLM智能体舰队的不可逆影响风险,提出不可逆预算机制,通过运行时计费与准入控制实现舰队级风险管控,受控研究验证其有效性,但合理定价仍是待解决问题。
中文摘要 AI 辅助
大型语言模型(LLM)智能体舰队如今会产生无法完全撤销的影响:它们转移资金、部署代码、删除数据及披露信息。当前的控制措施每次仅检查一种影响,因此,在每个本地闸口均正确的情况下,经单独授权的智能体舰队可能会在共享触发条件下透支其委托人的风险。我们提出不可逆预算,即可信运行时为每个委托人跨智能体、工作流及租户维护的剩余风险价值累计账户。将不可逆性视为一级资源,运行时会对每种影响收取其在智能体下的剩余损失,并在累计金额将透支预算时拒绝边际影响。确定合理的价格难度较大,因为影响具有异质性、受对抗性声明且相互关联。我们开展了一项受控研究,其中,按影响设置的闸口允许舰队级透支高达租户风险限制的48倍,而预算则将所有正确计费的运行控制在该限制内。对于可部署设计而言,保守的、依赖关系感知的定价仍是核心未解决问题。
英文摘要
Fleets of LLM agents now externalize effects that cannot be fully undone: they move money, deploy code, delete data, and disclose information. Current controls check one effect at a time, so a fleet of individually authorized agents can overdraw its principal's risk under a shared trigger while every local gate stays correct. We propose the irreversibility budget, a cumulative account of residual value-at-risk that a trusted runtime maintains for each principal across agents, workflows, and tenants. Treating irreversibility as a first-class resource, the runtime charges each effect its residual loss below the agent and denies the marginal effect once the aggregate would overdraw the budget. Getting the price right is hard, because effects are heterogeneous, adversarially declared, and correlated. We perform a controlled study in which per-effect gates admit fleet-level overdraws of up to 48 times the tenant's risk limit while the budget holds every correctly charged run within that limit. Conservative, dependency-aware pricing remains the central open problem for a deployable design.
发表机构
- Max Planck Institute for Software Systems(马克斯·普朗克软件系统研究所)
机构由 AI 辅助整理,请以论文原文为准。