arXiv:2609.06036cs.AI2026-09被引 1

提出无需依赖生成器的安全运行保障方法,确保系统在任意替换生成器时仍安全。

Generator-Independent Runtime Assurance under Partial Observation

  • 通过集合整体验证实现生成器无关的准入安全,避免多次尝试导致风险累积。
  • 在部分观测下,安全决策受状态假设差异限制,风险下界为 α+β+δ≥1。
  • 适用于强化学习、规划器等黑箱生成器部署场景,尤其适合高可靠性系统。

基于提案的控制器——如学习策略、语言模型规划器及其他黑箱生成器——正越来越多地部署在运行时验证门控之后。我们探讨何时闭环安全性可脱离生成器而独立成立。现有逐候选认证模式不具备组合性:在重试或最佳k选一选择下,每个候选的误放行率α可能膨胀至1-(1-α)^k。我们的主要定理表明,同时集上正确性(即认证一组可接受提案,其中不含不可行动作)是生成器无关准入正确性的充要条件;结合设计阶段证书与无绕过规则,足以保证合同安全,其违反界为Γ+∑_t ε_t+η,且对任意甚至对抗性生成器替换保持不变。第二个定理在部分观测下约束所有准入机制:对于固定探测与准入策略,若两个状态假设的信息律在总变差距离δ内,却需不同安全决策,则ᾱ+β+δ≥1。顺序风险账本使该保证可通过时间一致置信带实现,并表明确定性准入计算将全部统计风险集中于状态估计。单纯形风格运行时保障与控制屏障函数过滤作为退化情形被恢复。

原文摘要 · Abstract (English)

Proposal-based controllers---learned policies, language-model planners, and other black-box \emph{generators}---are increasingly deployed behind runtime verification gates. We ask when the closed-loop safety guarantee decouples from the generator. The prevailing per-candidate certification pattern does not compose: under retry or best-of-$k$ selection a per-candidate false-admission level $\alpha$ can inflate to $1-(1-\alpha)^{k}$. Our main theorem shows that \emph{simultaneous setwise soundness}---certifying a set of admissible proposals containing no nonviable action---is necessary and sufficient for generator-independent \emph{admission soundness}, the worst case over all generators of executing a nonviable proposal equalling the probability of setwise failure; together with a design-time certificate and a no-bypass rule it is sufficient for \emph{contract safety}, with violation bound $\Gamma+\sum_t\varepsilon_t+\eta$ invariant under arbitrary, even adversarial, replacement of the generator. A second theorem bounds every admission mechanism under partial observation: for a fixed probing and admission policy, if two state hypotheses whose information laws lie within total-variation distance $\delta$ require different safe decisions, then $\abar+\beta+\delta\ge1$. A sequential risk ledger makes the guarantee implementable with time-uniform confidence tubes, and shows that deterministic admission computations concentrate all statistical risk in state estimation. Simplex-style runtime assurance and control-barrier-function filtering are recovered as degenerate cases.

安全验证生成器无关运行时保障部分观测

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。