提出可验证终止机制,确保工具型大模型停止时有证据支持。
When May an Agent Stop? Evidence-Carrying Termination for Tool-Using LLMs

- 设计证书绑定答案与有效执行证据,仅当可复现时才允许完成
- 在48个合成任务中零不安全完成,远优于基线的252/288
- 适合对可靠性要求高的自动化系统或需可审计决策的场景
工具使用型智能体必须决定何时停止。现有系统虽能判断结果正确性、验证执行轨迹或强制运行策略,但未在受控终止故障下全面检验其在完整边界上的表现。本文提出证据携带终止(ECT):只有当类型化证书将每个必要答案声明绑定到有效且在范围内的轨迹证据,并且确定性重放可重建声称值时,代理才返回完成。一项静态研究覆盖6类工具使用中的48个全合成任务,含清洁执行与8种故障。ECT实现0/288次不安全完成,而对照组为252/288(差异-87.50个百分点,95%置信区间[-87.50, -87.50])。另一项预设冻结的576轨迹研究比较ECT与对照组、其忠实控制器及全轨迹大模型评论者。在22个独立测试任务簇上,ECT实现0/66次提前无支持终止,对照组为40/66(差异-60.61个百分点,95%区间[-78.79, -40.91]),支持完成率97/132对92/132(差异+3.79个百分点,区间[0.00, 9.09]),满足-10点非劣效标准。ECT在66条轨迹中成功恢复18次,其中17次最终获得支持;所有闭环门控均通过。ECT在声明假设下基于记录轨迹认证支持,而非外部真实、安全或对齐。
原文摘要 · Abstract (English)
Tool-using agents must decide when to stop. Existing systems already gate terminal success, certify execution traces, or enforce runtime polici es, but do not test this particular receipt-, scope-, and closed-replay design at the COMPLETE boundary across controlled termination faults. W e instantiate and evaluate Evidence-Carrying Termination (ECT): an agent may return COMPLETE only when a typed certificate binds every required answer claim to valid, in-scope trace evidence and a deterministic replay reconstructs the claimed value. A locked static study crosses 48 ful ly synthetic tasks in six tool-use families with clean execution and eight faults. ECT produced 0/288 unsafe completions versus 252/288 for the inspected termination-critic core (difference -87.50 pp, 95% task-cluster interval [-87.50, -87.50] pp). A fresh, prespecified and frozen 576- trajectory study then compares ECT with the critic core, its faithful controller, and a full-trace LLM critic. On 22 primary held-out task clus ters, ECT produced 0/66 premature unsupported terminations versus 40/66 for the controller (difference -60.61 pp, 95% interval [-78.79, -40.91] pp), while supported completion was 97/132 versus 92/132 (difference 3.79 pp, interval [0.00, 9.09] pp), satisfying a -10-point noninferiority margin. ECT executed successful recovery in 18/66 trajectories, of which 17 subsequently completed with support; all three closed-loop gates p assed. ECT certifies support in a recorded trace under declared assumptions, not external truth, safety, or alignment.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。