发表机构
Purdue University; University of Exeter(普渡大学; 埃克塞特大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
针对分布式LLM智能体存在的过时计划执行问题,提出PlanFence依赖范围动作验证协议,通过仅验证相关记录解决该问题,在受控实验中其表现优于仅依赖新鲜性的执行器。
AI 中文摘要
分布式大语言模型(LLM)智能体团队能够读取最新的共享事实,却仍可能依据过时的计划采取行动:规划器可能从需求$r_3$推导出一个动作,另一个智能体可能提交$r_4$,而执行器收到$r_4$后却未替换由$r_3$推导的计划,我们将这种情况称为“过时计划执行”——状态的新鲜性无法证明授权动作的计划仍然有效。我们提出PlanFence,一种依赖范围的动作验证协议:计划会引用其使用的精确公共记录,执行器仅验证可能影响待处理外部动作的记录,当验证不完整时要么重新规划要么阻塞。在30个包含计划后修订的受控工作流中,仅采用新鲜性机制的执行器在所有任务中都依据过时计划行动,而PlanFence完成了所有任务且无无效动作。受控重放揭示了两个条件边界:主动同步在低 churn( churn 指状态变更频率)下产生更低的协调停滞,而随着 churn 增长,PlanFence 可避免重复的更新路径协调,且随着共享键空间增大,可避免验证无关状态。这些是受控安全性和系统成本方面的结果,而非通用任务准确性的提升。
英文摘要
A large language model (LLM) agent that inherits a plan through shared memory can hold the latest requirement yet act on a plan derived from an older one: fresh memory, stale plan. Freshness checks miss this failure because they compare local copies with current state (observation currency) rather than the inputs the plan was derived from (derivation currency). Planfence makes derivation currency checkable after a handoff. Stored plans carry exact links to their recorded inputs; before a protected action, Planfence follows those links to an action-specific dependency frontier, asks each input's owner for its current head, refreshes what changed, and allows one replan before blocking. Application code supplies the links and declares the scope; no shared memory service is required. Holding the native S-Bus validator fixed, supplying inherited input versions raises detected handoff conflicts from 0/30 to 30/30: retained evidence is the missing ingredient. In 30 live five-agent workflows with a revision inserted after planning, a freshness-only executor acts on the stale plan every time, whereas Planfence, like a centralized-lineage baseline that requires a shared store, completes all 30 correctly. In matched replay under emulated LTE traces, Planfence's stall stays within 143-237ms per action across a 64$\times$ range of update rates while per-update synchronization grows from 52 to 1196ms; synchronization is cheaper only at the lowest tested rates. Scoping queries to the declared dependencies holds traffic at 8.1KiB per action, a tenth of all-key validation at 128 keys; at full scope the two tie.