arXiv:2608.12761cs.AIcs.CR2026-08被引 2

让智能体工作可审计,确保每一步都有可查的依据。

Correct Is Not Governed: Provenance Integrity in Agentic Workflows

  • 用确定性因果状态层记录决策来源与依赖关系。
  • 验证完成证据,自动失效受变更影响的任务。
  • 适合需要合规审计的机构级智能体系统使用。

智能体工作通常以是否得出正确结果来评估,但在机构场景中这不够:正确操作可能依赖错误权限、无支持的完成声明,或已被后续更改过时的工作。我们定义了受控执行——即决策、完成和对变更响应均需有可检查的溯源证据。提出Matrix系统,作为确定性因果状态层,记录权威与事实依赖,验证完成证据,并选择性地使受影响工作失效。在控制对比实验中,受控与直接工作流常达相同结果,但仅受控路径持续保留管控证据,拒绝无支持的关闭,并将恢复限制在依赖任务内。角色分离的迁移挑战失败:严格强制的完整性合约严重阻塞了外部上下文生成的合成数据包。这些结果不证明Matrix能提升通用准确性,而是支持其作为机构级完整性层,使智能体工作可审计且独立可验证。

原文摘要 · Abstract (English)

Agentic workflows are commonly evaluated by whether they reach the correct outcome. That is insufficient in institutional settings, where a correct action may rely on the wrong authority, an unsupported completion claim, or work made stale by a later change. We define governed execution as work whose decisions, completion, and response to change are supported by inspectable provenance. We present Matrix, a deterministic causal-state layer that records authority and fact dependencies, verifies completion evidence, and selectively invalidates affected work. Across controlled comparisons, governed and direct workflows often reached the same outcomes, but only the governed path consistently preserved governing evidence, refused unsupported closure, and limited recovery to dependent tasks. A role-separated transfer challenge then failed: a deterministically enforced completeness contract severely over-blocked synthetic packets produced outside its authoring context. These results do not establish Matrix as a general accuracy enhancer; they support its primary role as an institutional integrity layer for making agentic work auditable and independently verifiable.

智能体溯源审计

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。