arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2609.14631cs.CRcs.OS

LLM智能体能力应遵循任务意图与上下文来源

LLM Agent Capabilities Should Follow Task Intent and Context Source

Yusheng Zheng, Wenhui Zhang, Yu Mao

首次发表
浏览论文内容

中文总结 AI 辅助

针对LLM智能体能力动态授权问题,提出IntentCap,从用户意图、工作流指令、工具模式、运行时环境四来源组合权限,经确定性检查器验证并强制执行,实现任务范围限定的最小权限,有效阻止违规且不误拒良性操作。

中文摘要 AI 辅助

LLM智能体会采取真实行动,包括执行代码、修改文件、调用服务以及委派任务,这些行动由上下文来源驱动:用户请求、工具结果、文档、Shell输出、技能与MCP指令、记忆。与传统系统中能力预定义不同,智能体所需的最小权限能力是动态的,取决于其任务意图:它想做什么以及如何做。这带来了安全与安保挑战:所有输入进入一个共享的规划通道,具有同等影响力,无论是通过对抗性注入还是意外范围扩大,然而用户的明确请求与文档提取的文本承载着不同的信任级别,不应共享选择目的地或扩大访问权限的权力。现有防御措施限制操作和信息流;我们研究任务范围限定、多来源权限组合。我们认为智能体能力应限定于当前任务意图,而非沙箱或会话生命周期,且没有任何单一上下文来源能定义完整能力。IntentCap从四个此类来源组合能力:用户意图、工作流指令、工具模式、运行时环境,具有字段级所有权和单调收窄。每个来源贡献特定字段,任何来源都不能填补另一来源的字段,且租约仅收窄用户已授权的权限,绝不扩大。IntentCap使用LLM从这些来源生成短期租约,在任何副作用提交前由确定性检查器验证,并由工具级和操作系统级信息流策略强制执行。评估表明,IntentCap阻止了测试的违规行为而不拒绝良性操作,每个来源边界都是独立必要的,且检查器在工具、执行、放置和委派边界上具有泛化能力。

英文摘要

LLM agents take real actions, including executing code, modifying files, calling services, and delegating tasks, driven by context sources: user requests, tool results, documents, shell outputs, Skill and MCP instructions, memory. Unlike traditional systems, where capability is predefined, the least-privilege capability an agent needs is dynamic, depending on its task intent: what it wants to do and how. This creates a security and safety challenge: all inputs enter one shared planning channel with equal influence, by adversarial injection or accidental scope widening, yet a user's explicit request and a document's extracted text carry different trust and should not share authority to choose a destination or widen access. Existing defenses constrain operations and information flow; we study task-scoped, multi-source authority composition. We argue that agent capabilities should be scoped to the current task intent, not a sandbox or session lifetime, and that no single context source defines a complete capability. IntentCap composes capabilities from four such sources: user intent, workflow instructions, tool schemas, and runtime environment, with field-level ownership and monotonic narrowing. Each source contributes specific fields, none can fill another's, and the lease only narrows the user's authorized authority, never widens it. IntentCap uses an LLM to generate short-lived leases from these sources, validated by a deterministic checker before any side effect commits and enforced by tool- and OS-level information flow policies. Evaluation shows IntentCap blocks tested violations without rejecting benign actions, each source boundary is independently necessary, and the checker generalizes across tool, execution, placement, and delegation boundaries.

发表机构

  • UC Santa Cruz(加州大学圣克鲁兹分校)
  • Roblox(罗布乐思)
  • Bytedance(字节跳动)

机构由 AI 辅助整理,请以论文原文为准。

补充信息

↑