发表机构
Institute of Computing Technology, Chinese Academy of Sciences; University of Chinese Academy of Sciences; Fuxi Institution; Center for Internet Governance, Tsinghua University(中国科学院计算技术研究所; 中国科学院大学; 伏羲研究院; 清华大学互联网治理研究中心)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
针对多步骤工具工作流中的授权漂移问题,提出运行时授权一致性检查(RAC),通过谱系继承的授权状态在控制器侧拦截越权调用,显著降低漏检率并保持亚毫秒级延迟。
AI 中文摘要
智能体系统日益通过涉及文件、服务和外部资源的多步骤工具工作流来满足用户请求。在这些工作流中,孤立的逐调用检查可能遗漏工作流级别的失败:每个调用在局部可能是可接受的,但整个序列可能超出为会话建立的授权边界。我们将这种失败模式识别为“授权漂移”。为解决此问题,我们提出了运行时授权一致性检查(RAC),一种在控制器侧工具调用边界处的轻量级守护机制。RAC将授权视为由已接受的工作流步骤携带的运行时状态。对于每个待处理操作,它从控制器观察到的元数据中重建一个可信的授权事件,并且仅当该调用保持不比通过已接受谱系继承的基础更具许可性时才允许该调用。被拒绝的步骤被排除在谱系之外,因此后续延续只能从已接受的工作流历史中获取支持。我们的评估表明,RAC在受控和规划器生成的工作流中均减少了遗漏的授权漂移。在包含1,248个工作流的TraceBench套件上,RAC没有遗漏阻止的情况,而最强的Static+History基线在1,008个oracle-BLOCK工作流中遗漏了509个。在盲法LLM生成计划的高置信度可观察子集上,RAC达到了92.8%的阻止召回率,而最强基线为68.8%。在真实的MCP文件系统规划器重放中,RAC在服务器执行前阻止了九个不安全的延续,且p99检查延迟低于毫秒。
英文摘要
Agentic systems increasingly fulfill user requests through multi-step tool workflows over files, services, and external resources. In these workflows, isolated per-call checks can miss a workflow-level failure: each call may be locally admissible, but the sequence can exceed the authorization boundary established for the session. We identify this failure mode "authorization drift." To address this problem, we present Runtime Authorization Consistency Checking (RAC), a lightweight guard at the controller-side tool-call boundary. RAC treats authorization as runtime state carried by accepted workflow steps. For each pending action, it reconstructs a trusted authorization event from controller-observed metadata and admits the call only when it remains no more permissive than the basis inherited through accepted lineage. Rejected steps are excluded from lineage, so later continuations can draw support only from accepted workflow history. Our evaluation shows that RAC reduces missed authorization drift across both controlled and planner-generated workflows. On the 1,248-workflow TraceBench suite, RAC has no missed-block cases, while the strongest Static+History baseline misses 509 of 1,008 oracle-BLOCK workflows. On a high-confidence observable subset of blind LLM-generated plans, RAC reaches 92.8% block recall, compared with 68.8% for the strongest baseline. In the real MCP filesystem planner replay, RAC stops nine unsafe continuations before server execution, with sub-millisecond p99 checking latency.