arXiv:2608.09025cs.AIcs.CR2026-08

金融代理需实时验证行为授权,防止误操作

Context Is Not Authority: Structured Runtime Governance for Financial Market Agents

  • 通过类型绑定和凭证匹配实现运行时控制
  • 616个案例测试中全部达到预期输出结果
  • 适用于金融系统安全管控与合规审计

金融代理可能将正确上下文转化为未经授权的操作,如客户承诺、交易或部署策略。我们提出SAGE-Fin,一种面向金融场景的权限移交协议,将受控对象从文本改为实际执行效果。SAGE-Fin将提案编译为带类型和适配器约束的候选项;记录缺失或过期的机构义务作为覆盖债务;在当前市场、账户、策略及对话状态下约束权限;要求精确的、类型匹配的接收凭证。证据和流程进展不能替代效果授权,状态变更后需重新验证前置授权。在自建的616例测试集上,5个确定性规范生成3080个输出;标签隔离测试框架实现616/616的参考原型一致性,包含3/3响应门固定用例,22项测试覆盖关键路径。结果证明可执行符合性,而非独立安全性。此外,SAGE-Fin响应门在某保密数字资产平台处理真实客户请求。独立于开发团队的运营团队给出高度正面的实用性与流程契合度评价,用户反馈亦积极。披露仅限评审独立性、利益相关方类别、评估维度和定性结论,属定性现场佐证而非效应量化。三个去标识化前代失败案例经独立确认,均出现0/3拦截,存在重复发射漂移、过期账户证据、缺失升级状态等问题,未估算发生率或治疗效应。

原文摘要 · Abstract (English)

Financial agents can turn correct context into an unauthorized effect: a customer-facing commitment, trade, or deployed policy. We present SAGE-Fin, a finance-specific authority-handoff contract that makes the proposed effect, not merely its text, the object of runtime control. SAGE-Fin compiles proposals into typed, adapter-bound candidates; records missing or stale institutional obligations as coverage debt; contracts authority under current market, account, policy, and dialogue state; and requires an exact-artifact receipt whose nominal type matches the consuming response, execution, or policy adapter. Evidence and workflow progress cannot substitute for effect authority, and prior authorization is rechecked after state changes. Across an authored 616-case catalog, five deterministic specifications yield 3,080 outputs; a label-isolated harness obtains 616/616 binary reference-prototype parity, including 3/3 named response-gate fixtures, while 22 tests cover selected paths. These results establish executable conformance, not independent safety accuracy. Separately, SAGE-Fin's response gate processed real customer-facing production requests at a confidential digital-asset platform. An operational team independent of the implementation team reached a strongly positive post-deployment conclusion on practical usefulness and workflow fit, and end-user feedback was also strongly positive. Disclosure permits only the review's independence, stakeholder classes, assessed dimensions, and directional conclusion, so this is qualitative field corroboration rather than an aggregate effect estimate. Three distinct de-identified predecessor failures, with independently confirmed 0/3 interception, ground repeated-emission drift, stale account evidence, and missing escalation state without estimating prevalence or treatment effect.

金融安全权限控制运行时治理

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。