arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

从审批到执行:面向LLM智能体软件的感知重建修复分析

From Approval to Execution: Reconstruction-Aware Repair Analysis for LLM-Agent Software

Junchi Zhu, Zhenguang Liu, Shaojing Fan, Jianhai Chen, Qinming He

arXiv 2609.26529首次发表:更新:

AI 中文总结

针对LLM智能体软件中审批后操作可能被重建导致授权绕过的问题,提出重建稳定授权(ReSA)分析,通过APAS-Finder工具验证修复充分性,实验证明其有效性。

AI 中文摘要

审批机制已成为LLM智能体软件中高风险操作的主要安全保障。然而,用于审批所展示的操作往往并非最终实际消费的对象:工作流重载、转录投影、参数重新绑定以及持久状态查找可能在执行前对其进行重建。现有的字段流和检查覆盖分析可以确定预期字段已被检查,但无法确定被检查的对象版本是否到达汇点,也无法确定在检查与使用之间是否存在替换干预。因此,局部完整的修复在重建后仍可能留下残余的授权绕过。我们通过三项设计解决此问题。(1)我们针对表示转换、汇点依赖、消费版本和授权范围,形式化定义了重建稳定授权(ReSA)。(2)我们推导出用于评判候选修复并暴露残余汇点后缀的义务。(3)我们在APAS-Finder中实现该分析,并在独立的汇点预言机观察执行之前冻结预测。预测与全部28个受控结果一致。四对匹配案例尽管具有相同的字段流和检查覆盖,却需要相反的判断;当提供对象流、支配关系、干扰以及相同的授权契约时,一个CodeQL复合查询可恢复全部八个案例。两位分析师对所有四个模型验证处置及19/20个汇点依赖达成一致。在已发布的消费者上,五项修复阻止了60/60个测试的越界效应,而三项机制对比则暴露了预测的残余效应。因此,修复的充分性取决于所消费的重建操作,而不仅仅取决于审批记录或先前检查的表示。

英文摘要

Approval mechanisms have become a primary safeguard for consequential actions in LLM-agent software. Yet the action shown for approval is often not the object ultimately consumed: workflow reload, transcript projection, argument rebinding, and durable-state lookup may reconstruct it before execution. Existing fieldflow and check-coverage analyses can establish that expected fields were inspected, but not that the inspected object version reaches the sink or that no replacement intervenes between check and use. Consequently, a locally complete repair may still leave a residual authorization bypass after reconstruction. We address this problem through three designs. (1) We formulate reconstruction-stable authorization (ReSA) over representation transitions, sink dependencies, consumed versions, and grant scope. (2) We derive obligations that judge candidate repairs and expose residual sink suffixes. (3) We implement the analysis in APAS-Finder and freeze predictions before an independent sink oracle observes execution. Predictions agree with all 28 controlled outcomes. Four matched pairs require opposite judgments despite identical field-flow and check coverage; a CodeQL composite recovers all eight when supplied object flow, dominance, interference, and the same grant contract. Two analysts agree on all four model-validation dispositions and 19/20 sink dependencies. On released consumers, five repairs prevent 60/60 tested out-of-scope effects, while three mechanism contrasts expose the predicted residual effects. Repair sufficiency therefore depends on the reconstructed action consumed, not merely on an approval record or earlier checked representation.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑