主体,而非作者:智能体数据空间中的作者危害
Subjects, Not Authors: The Authorship Hazard in Agentic Dataspaces
浏览论文内容
中文总结 AI 辅助
针对智能体数据空间中智能体既是策略主体又是作者的风险,提出“智能体是主体而非作者”原则,通过关闭发布通道并将分类视为作者身份以强制审查,实验证明该方法能有效防止未授权发布。
中文摘要 AI 辅助
数据空间连接器决定传输是否可以进行,而非传输值包含什么内容,这对于合同化应用是可容忍的,但对于组合工具调用并生成子智能体的LLM智能体则不可容忍。关于生成治理工件的研究评估输出质量;谁可以授权工件使用介于该文献与治理文献之间,两者均未涵盖。已发布的策略是数据空间决策点所执行的,因此发布是一个治理事件,而既是策略主体又是策略作者的智能体编写约束自身的规范。我们将此命名为作者危害,并陈述一项原则:智能体是治理平面的主体,绝不是其作者。其发布授权通道在构造上被关闭;其影响通道(起草人类批准的内容)被视为执行问题。在智能体草稿的冻结语料库上,未经批准发布逆转了80项授权决定,其中大多数通过仅更改字段敏感性分类且不更改策略文本的草稿实现;读取策略差异的分类器必然遗漏此类草稿。将分类视为作者身份将其全部路由至审查;此所需的注册表持有的分类在此设计并建模,尚未在原型中实现。在执行边界,受保护字段在提示所述职责下于105/105例中到达模型,在ODRL职责编译为调用时工具调用约束时于0/105例中到达,但当值不限于命名字段时,编译条件在7/7例中暴露该值。集中供应的批准池无法扩展到激发该问题的参与者规模。
英文摘要
Dataspace connectors decide whether a transfer may occur, not what the transferred value contains, tolerable for contracted applications, not for LLM agents that compose tool calls. Work on agents that generate governance artifacts evaluates output quality, not who may authorize an artifact for use. A published policy is what the decision point enforces, so publication is a governance event, and agents that are both policy subjects and policy authors write the norms that bind them. We name this the authorship hazard and state one principle: an agent is a subject of the governance plane, never an author of it. Its authorization channel to publication is closed by construction; its influence channel, drafting what humans approve, becomes an enforcement problem. Across 90 preregistered edits to the paper's running agreement, each evaluated on 344,512 requests, the six that only reclassify a field all change authorization and narrow a duty without touching policy text, and a policy-diff classifier passes all six. Read as worded, the privilege-delta conditions also pass 33 of 69 effective policy-text edits; read as covering any relaxation, none. Treating classification as authorship routes all six to review; the registry this requires is not yet built. At the execution boundary, protected fields reach the model in 105 of 105 cases under prompt-stated duties and in 0 of 105 under a compiled tool-call constraint, but values outside named fields are exposed in 7 of 7. At the review share measured, a central approval pool needs one approver per 20 to 138 participants.
发表机构
- Korea Trade Network (KTNET)(韩国贸易网络(KTNET))
机构由 AI 辅助整理,请以论文原文为准。