发表机构
Rice University; Columbia University; Carnegie Mellon University(莱斯大学; 哥伦比亚大学; 卡内基梅隆大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
针对AI修复操作在生产环境中的安全风险,提出GuardedAct框架,通过爆炸半径感知沙箱和回滚置信门控,将附带损害降低79.7%,恢复率达87.4%。
AI 中文摘要
大型语言模型(LLMs)在生成微服务故障修复操作方面展现出令人期待的能力。然而,在生产环境中直接执行AI生成的修复操作存在引发级联附带损害的风险。我们提出GuardedAct,一种沙箱优先的修复框架,在LLM操作生成器与生产环境之间插入一个爆炸半径感知的验证层。GuardedAct分四个阶段运行:(1)摄取诊断报告以及实时系统拓扑和近期遥测数据;(2)提示LLM生成排序的候选修复操作列表;(3)在轻量级数字孪生沙箱中模拟每个操作,该沙箱估算爆炸半径并分配风险标签;(4)实施回滚置信门控,仅自动执行低风险操作,同时将高风险操作升级以供人工审查。我们在注入到DeathStarBench社交网络应用中的五个故障场景上评估了GuardedAct。实验结果表明,相对于直接LLM执行,GuardedAct实现了87.4%的总体恢复率,同时将附带损害降低了79.7%(从25.6%降至5.2%),代价是平均恢复时间略有增加(约8秒),这归因于沙箱开销。消融研究证实,每个组件都对安全-速度权衡做出了有意义的贡献。
英文摘要
Large Language Models (LLMs) have shown promising capabilities in generating remediation actions for microservice failures. However, directly executing AI-generated repair actions in production risks cascading collateral damage. We propose GuardedAct, a sandbox-first remediation framework that interposes a blast-radius-aware verification layer between the LLM action generator and the production environment. GuardedAct operates in four phases: (1) ingesting a diagnosis report together with the live system topology and recent telemetry, (2) prompting an LLM to produce a ranked list of candidate remediation actions, (3) simulating each action in a lightweight digital-twin sandbox that estimates the blast radius and assigns a risk label, and (4) enforcing a rollback-confidence gate that auto-executes only low-risk actions while escalating high-risk ones for human review. We evaluate GuardedAct on five fault scenarios injected into the DeathStarBench social-network application. Experimental results show that GuardedAct achieves an overall recovery rate of 87.4% while reducing collateral damage by 79.7% relative to direct LLM execution (from 25.6% to 5.2%), at the cost of a modest sandbox-induced increase in mean time to recovery (approximately 8 s). Ablation studies confirm that each component contributes meaningfully to the safety-speed trade-off.