arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2609.08062cs.AIcs.CR

ResidualAuth:在可撤销委托下语言智能体必须保留哪些授权状态?

ResidualAuth: What Authorization State Must Language Agents Preserve under Revocable Delegation?

Moonwon Choi, Seokho Jeong, Sian Choi, Seunggeun Lee

首次发表
浏览论文内容

中文总结 AI 辅助

本研究提出残余授权状态概念,证明仅凭当前权限与可达性不足,并构建ResidualAuth框架与硬门机制,在语言智能体可撤销委托中实现精确授权监控与未授权影响消除。

中文摘要 AI 辅助

使用工具的语言智能体在通过外部服务行动时可以委托和撤销权限。我们证明,两个授权历史可以具有相同的当前权限和相同的全对可达性,但在相同的直接边撤销后却需要相反的决定。我们将保留此类区分所需的信息形式化为残余授权状态。我们证明,指数级多的未来不同状态可以共享一个固定的传递闭包,并给出在委托冗余变化时精确监控器所需状态的精确或紧渐近界限。ResidualAuth 将这些构造编译成配对的智能体语言片段。在四个开放权重模型中,固定的256令牌摘要解决了0-2/16对,虚假读取解决了0/16,而经过认证的当前查询读取解决了15-16/16。在另一个独立的留出在线记忆诊断中,精确的分类账序列化在768和1,024令牌下均适配了全部128个四坐标对。在任一上限下,事实支持的模型编写的记忆足以满足每个预先指定的延续,每个模型最多解决1/128对。一个硬门将八个观察到的未授权影响减少到零,而不改变先前的尝试。这些结果区分了所需授权状态、可用决策信息、在线状态维护和效果中介。

英文摘要

With revocable delegation, two histories can yield identical current permissions yet require opposite decisions for the same query after the same revocation. We introduce ResidualAuth, a theory-grounded framework characterizing the authorization state agent systems must preserve and evaluating its maintenance and use. Its formal core, residual authorization state, equates histories exactly when every future sequence of grants, revocations, and uses is valid after both or neither. We prove that exponentially many distinct residual states can nevertheless agree on who can reach whom through delegation paths. The analysis also yields exact or tight memory bounds as delegation redundancy varies and an average decision-error lower bound under an explicit bound on retained information. ResidualAuth evaluates information access, online state maintenance, and information use through a restricted executable benchmark and separate diagnostics. The benchmark pairs episodes differing in authorization-relevant history and requiring opposite decisions; pair accuracy requires both answers to be correct. To test use of supplied decisions, four open-weight models received trusted current-query Allow/Deny decisions alongside deterministic 256-token event extracts, achieving 15-16/16 correct pairs versus 0-2/16 with extracts alone. Memory diagnostics identified invalid reconstructions; models also answered incorrectly from valid memories that passed fixed future authorization tests. Together, these results distinguish what future authorization requires a system to retain from whether agents can access relevant information, maintain state across updates, and use available information to make correct decisions.

发表机构

  • Graduate School of Data Science, Seoul National University(首尔国立大学数据科学研究生院)

机构由 AI 辅助整理,请以论文原文为准。

补充信息

↑