arXiv:2608.16402cs.AI2026-08

为智能体执行设计信任保障的策略代数,确保操作合规且可审计。

A Policy Algebra for Trust-Preserving Agentic AI Execution

  • 提出策略代数,统一管理身份、工具、预算等多维度约束。
  • 干预94.8%违规事件,任务完成率达86.9%,审计完整度达98.6%。
  • 适合企业级智能体系统研发,保障可靠性与可追溯性。

基于大语言模型的智能体框架主要优化能力:是否能推理、检索信息、调用工具、委派任务并达成目标。企业级执行需更强属性:若通过未经授权的数据访问、越权委托、未批准副作用、不可恢复的预算消耗或证据不全产生结果,则成功不可靠。本文将可靠能力定义为路径属性:只有在行动事件始终符合身份、配置文件、工具、数据、记忆、预算、产物、审批和审计约束时,智能体才具备可靠能力。我们提出一种策略代数,定义了智能体能力可行使的可信范围。安全配置文件与运行时义务通过连接、交集、预算收缩、审批继承和证据累积组合,生成既保信任又最宽松的状态。该代数还跨多智能体调用传播限制,并引入成本感知的产物生成机制,在预算暴露增加时引导开放执行走向可恢复结果。评估以可靠性-能力权衡为准,而非单纯能力基准:策略代数运行时干预94.8%策略违规事件,保留86.9%任务完成率,消除观察到的配置文件单调性与零产物耗尽违规,审计完整度提升至98.6%。该方法为研究者与实践者提供形式化正确性条件、可执行决策语义与可追溯证据,构建不仅有能,而且可靠的智能体。

原文摘要 · Abstract (English)

Large language model-based agentic frameworks primarily optimize capability: whether an agent can reason, retrieve information, call tools, delegate work, and complete a goal. Enterprise execution requires a stronger property. A successful result is not reliable if it was produced through unauthorized data access, widened delegated authority, unapproved side effects, unrecoverable budget consumption, or incomplete evidence. This paper defines reliable capability as a path property: an agent is reliably capable only when it completes a task through action events that remain admissible under identity, profile, tool, data, memory, budget, artifact, approval, and audit constraints. We propose a policy algebra that defines the reliability envelope within which agent capability may be exercised. Security profiles and runtime obligations compose through joins, intersections, budget narrowing, approval inheritance, and evidence accumulation; the resulting composition is both trust-preserving and the least restrictive state satisfying all governing inputs. The algebra also propagates restrictions across multi-agent calls and introduces cost-aware artifact materialization, which redirects open-ended execution toward a recoverable outcome as budget exposure grows. The evaluation is interpreted as a reliability-capability trade-off rather than a capability benchmark: the policy-algebra runtime intervenes on 94.8% of policy-violating events while retaining an 86.9% task-completion rate, eliminates the observed profile-monotonicity and zero-artifact-exhaustion violations, and increases audit completeness to 98.6%. The method provides researchers and practitioners with formal correctness conditions, executable decision semantics, and trace evidence for building agents that are not only capable, but reliably capable.

智能体策略代数信任保障企业级

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。