为具身智能体设计运行时治理框架,实现安全可控的实时执行。
Harnessing Embodied Agents: Runtime Governance for Policy-Constrained Execution
- 将认知与执行监管分离,通过独立层实现策略检查、监控与回滚。
- 在千次测试中拦截96.2%违规动作,异常持续率从100%降至22.2%。
- 支持持续运行检测与结构化恢复,适合高风险场景部署。
具身智能体正从被动推理系统演变为可操作工具与物理环境的主动执行者。一旦获得执行权限,核心挑战由‘如何行动’转为‘如何实时管控行为’。现有方法将安全、恢复与决策约束嵌入智能体循环,导致控制难以标准化、审计与跨环境适配。本文提出一种面向策略约束执行的运行时治理框架,将治理功能外置于专用运行层,实现策略校验、能力准入、执行监控、回滚及人工干预。我们形式化了持久化具身智能体、模块化能力包与治理层之间的控制边界,并在受控仿真下评估了策略约束执行流程。在超过1000次随机测试中,该框架对未经授权行为的拦截率达96.2%±2.7%,在运行时漂移下不安全行为持续率从100%降至22.2%±3.1%,恢复成功率高达90.7%±3.0%且完全合规。与五种基线(包括AutoRT式宪法过滤与RoboGuard式双阶段护栏)对比表明,预执行过滤在各治理感知方法中效果相当,但仅本框架提供持续运行时检测(RVDR=61.3% vs. 0%)和结构化恢复(所有p<0.001)。全检测范围敏感性分析确认了真实存在的检测-延续权衡。本工作主张未来具身系统应以可治理执行为目标设计。
原文摘要 · Abstract (English)
Embodied Agents are evolving from passive reasoning systems into active executors that interact with tools, robots, and physical environments. Once an agent gains execution authority, the central challenge shifts from how to make it act to how to keep its actions governable at runtime. Existing approaches embed safety, recovery, and decision constraints inside the agent loop, making execution control difficult to standardize, audit, and adapt across environments. We propose a runtime governance framework for policy-constrained execution that separates agent cognition from execution oversight. Governance is externalized into a dedicated runtime layer performing policy checking, capability admission, execution monitoring, rollback, and human override. We formalize the control boundary among a persistent Embodied Agent, modular Capability Packages, and the governance layer, and define a policy-constrained execution pipeline evaluated under controlled simulation. Over 1000 randomized trials, the framework achieves 96.2%+/-2.7% interception of unauthorized actions, reduces unsafe continuation from 100% to 22.2%+/-3.1% under runtime drift, and attains 90.7%+/-3.0% recovery success with full policy compliance. Comparison with five baselines, including AutoRT-style constitution filtering and RoboGuard-style two-stage guardrails, shows that pre-execution filtering is equally effective across governance-aware methods, while only the proposed framework provides continuous runtime detection (RVDR = 61.3% vs. 0%) and structured recovery (all p<0.001). A sensitivity sweep across the full detection range confirms a genuine detection-continuation trade-off. This work argues future embodied systems should be designed for governable execution.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。