EffectMatch 提出 Agent 运行时校验,阻止未批准的持久化副作用
Beyond Approved Actions: Runtime Validation of Persistent Outcomes in Agent Workflows
Agent 批准了改数据库,结果顺带发了条没人要的通知,现有护栏根本拦不住。这篇论文的 EffectMatch 在提交前比对实际持久化结果,206 个任务上全拦住了错误提交。
arXiv 论文 EffectMatch 针对LLM Agent 执行数据库更新时产生未批准副作用的问题,提出在受控执行边界内收集持久化变更并与应用批准内容比对的运行时方案。在 206 个公开业务任务上,EffectMatch 保留了全部正常执行并阻止了全部测试中的错误提交。作者进行了 6 组各 20 次运行的消融实验,定位每个被移除机制导致的失败。80 个任务拓扑案例显示该方案能保证真实的任务交接并阻断无效的后续执行。
Beyond Approved Actions: Runtime Validation of Persistent Outcomes in Agent Workflows
Large language model agents increasingly act on software systems, no longer merely generating text but also changing databases and online services. However, an approved database update may succeed yet leave an unapproved notification because execution can produce persistent effects beyond the requested change. Current safeguards can approve an action or record its aftermath, but without checking the persistent result before continuation, an unapproved outcome can be accepted as success and propagated to later steps. We present EffectMatch, a runtime that collects persistent changes within a controlled execution boundary and compares them with what the application approved for the current state and execution. The comparison governs commit and dependent execution. In comparative evaluation on 206 public business tasks, EffectMatch preserved all clean executions and prevented all tested incorrect commits. Six 20-run ablations exposed the failure caused by each removed mechanism, while 80 task-topology cases preserved truthful handoffs and blocked invalid continuation. Together, these results show that EffectMatch blocks the silent acceptance and downstream propagation of persistent outcomes inconsistent with application approval.