← 返回信息流

arXiv cs.AI论文

OnTrack:通过流式结构感知最优传输实时监测和干预 LLM 智能体轨迹

arxiv.org作者:Babak Barazandeh, Connor Swanson, Chinmay Kulkarni, Nikhil Mungel论文AI评分:70/100

该论文针对大语言模型智能体在自主执行任务时缺乏规则保护导致的安全与成本问题,提出了一种名为 OnTrack 的实时监测与干预框架。不同于增加延迟的监控智能体或事后评估日志的方法,该方法利用流式结构感知最优传输技术,在智能体运行过程中实时分析其轨迹并进行干预,从而有效降低不可逆操作带来的风险。

这篇是正式发表的长论文,站内提供中文解读,全文请到原文阅读 PDF。

Abstract:Agents are deployed in applications from trip planners and stock trading to IT incident triage. In most cases, LLM agents work autonomously with minimal rule-based safeguarding, leading to cost and safety issues from irreversible actions. Recent works resolve this either by using a safeguard agent to monitor behavior or evaluating logs post-hoc. The first adds cost and latency to every step; the second delivers its verdict after the run, when tokens are burned and damage is done. To overcome this, we propose OnTrack, a streaming monitoring mechanism that compares an agent's steps and dependencies against recorded successful runs to alert users or block the agent in about a millisecond per step. We study this problem in three regimes of decreasing access: full reference access (historical runs and tool schemas), intermediate access (only tool schemas), and no prior knowledge (only step logs as generated). Expectation of OnTrack's monitoring capabilities reduces as data access drops, ranging from plan violation detection to identifying loops, stalls, and repeated tool calls. Finally, we evaluate OnTrack using SWE-bench trajectories. Based on the first 8 steps, our method ranks failing trajectories below succeeding ones better than content similarity approaches (+0.057 AUROC). With an abort policy, we save about 18% of compute that would be burned on failing runs, where 83% of interrupted runs were actually heading to failure (5 out of 6 aborts were correct).

阅读原文