arXiv:2609.21284v1 Announce Type: cross
Abstract: Long-running AI agents outlive initiating processes through credentials, delegated tasks, queues, callbacks, reservations, and provider-side operatio...
By Genliang Zhu, Chu Wang
The paper introduces a fault‑tolerant budget conservation framework for distributed multi‑agent delegation, where budgets are represented as exclusive escrow credits that traverse a delegation DAG. It details how each branch converts credit into a reservation tied to lineage, epoch, and idempotency, persists a signed dispatch permit, and ensures that uncertain effects remain charged until settlement or retirement. The authors prove properties such as ownership partition, ledger conservation, and at‑most‑once settlement, and validate the mechanism through TLA+ checks, a JavaScript explorer, and crash‑injected SQLite experiments.
By Genliang Zhu, Chu Wang
arXiv:2608. 11632v1 Announce Type: cross Abstract: Persistent AI agents accumulate versioned state across long horizons, but storage retention alone does not identify authoritative state.
By Jun He, Deying Yu
arXiv:2608.21159v1 Announce Type: cross
Abstract: Tool-using AI agents turn delegated tasks into provider effects, yet authorization often ends at admission while provider state, delivery, retry, and...
By Yingzhe Tong, Leyu Dai, Songhui Guo
arXiv:2607. 23586v1 Announce Type: new Abstract: Long-lived AI agents increasingly evolve after deployment by retaining experience, acquiring skills and tools, revising workflows, delegating work, and moving across task phases.
By Zhaoxi Zhang, Xiaomei Zhang
arXiv:2608.30091v1 Announce Type: new
Abstract: Modern agent frameworks compose planners, tool agents, remote services, and shared specialists into runtime delegation graphs, but their revocation API...
By Lifei Liu, Haoran Yu, Xiaochong Jiang
arXiv:2609. 00546v1 Announce Type: cross Abstract: Agent systems are commonly described by the model and harness that currently produce their behavior.
By Zhenyu Zhao (Independent Researcher), Roy Zhao (Paul G. Allen School of Computer Science & Engineering, University of Washington)
arXiv:2607. 10487v1 Announce Type: cross Abstract: LLM agents can commit durable effects from authority evidence that was valid earlier in execution: a DOM snapshot, approval epoch, version witness, branch token, or worker result.
By Igor Santos-Grueiro
arXiv:2606. 22504v1 Announce Type: cross Abstract: Coding agents often receive broad tool access for an entire task, even when a resource is needed only for one subgoal.
By Igor Santos-Grueiro
ClosureBound is a reference monitor that enforces authorization boundaries for agent skills by binding each grant to an exact dependency closure, effect ceiling, purpose, validity, and epochs. It resolves typed graph nodes, normalizes operations into an external‑effect IR, and admits actions only when a joint witness satisfies all bounds, ensuring metadata non‑authority, closure determinism, and other security properties. Empirical evaluation on 549 public skills shows many lack proper dependency declarations, underscoring the need for conservative closure discovery and broader runtime validation.
By Genliang Zhu (Accentrust, Georgia Institute of Technology), Chu Wang (Accentrust, University of Illinois Urbana-Champaign)
arXiv:2609.14744v2 Announce Type: replace
Abstract: By acquiring compute, credentials, accounts, services, and other agents, autonomous AI agents can introduce new authority into a task. Payment, bud...
By Genliang Zhu (Accentrust, Georgia Institute of Technology), Chu Wang (Accentrust, University of Illinois Urbana-Champaign)
The paper introduces the concept of Cognitive Serializability for autonomous AI agents, ensuring that mutations derived from dynamic inputs—such as database reads, evidence, policy, beliefs, and delegated authority—are committed in a serial, logically consistent order. It presents a framework called Trusted Cognitive Transaction (TCT) that combines immutable executable definitions, sealed envelopes, guard-first commits, and receipt-driven reconciliation to enforce serializability and prevent anomalies. Experimental results show that the prototype implementation incurs minimal overhead while eliminating injected anomalies.
By Jun He, Deying Yu