arXiv:2609.16313v1 Announce Type: cross
Abstract: In agentic distributed systems, an agent may be authorized to mutate external infrastructure while lacking evidence that the mutation is ready to exe...
By Jun He, Deying Yu
arXiv:2608.21159v1 Announce Type: cross
Abstract: Tool-using AI agents turn delegated tasks into provider effects, yet authorization often ends at admission while provider state, delivery, retry, and...
By Yingzhe Tong, Leyu Dai, Songhui Guo
arXiv:2607. 00269v1 Announce Type: new Abstract: LLMs, solvers, and agent teams increasingly generate workflow actions, repairs, and plans, but a generated action may be syntactically valid yet stale, infeasible, conflicting, or destructive of the evidence that triggered a repair.
By Edward Y. Chang, Longling Geng, Emily J. Chang
arXiv:2609.14744v2 Announce Type: replace
Abstract: By acquiring compute, credentials, accounts, services, and other agents, autonomous AI agents can introduce new authority into a task. Payment, bud...
By Genliang Zhu (Accentrust, Georgia Institute of Technology), Chu Wang (Accentrust, University of Illinois Urbana-Champaign)
AcquireBound is a runtime authorization framework that ensures AI agents can safely acquire and activate resources such as compute, credentials, and services. It quarantines acquired outputs, resolves their capabilities through authenticated evidence, and activates them only after verifying a manifest, provenance, and relational constraints. The system demonstrates strong safety properties, passing extensive benign and unsafe trace tests across multiple resource classes.
By Genliang Zhu
The paper introduces PACE (Policy‑Attested Contract Execution), a framework that sits between large‑language‑model (LLM) based autonomous AI agents and on‑chain DeFi operations. PACE defines typed transaction intents, a deterministic policy verifier, and signed Policy Decision Records (PDRs) that cryptographically bind an approved intent, policy, and simulation report to the exact on‑chain execution bytes, providing replay and expiration protection. In evaluations across 40 tasks and six baselines, PACE achieves zero unsafe executions and zero false positives, outperforming unguarded agents by a large margin.
By Rabimba Karanjai (Larry), Yang Lu (Larry), Richard Williamson (Larry), Hemanth Hm (Larry), Prakhar Mehrotra (Larry), Lei Xu (Larry), Weidong (Larry), Shi
The paper investigates how multiple pre‑action controls—authority, resource, and evidence gates—interact in agentic AI systems. It formalizes remediation‑induced control coupling, showing that remediation can invalidate earlier judgments and that the order of remediation matters. The authors propose a remediate‑and‑regate protocol to restore soundness, analyze non‑commuting remediation operators, and demonstrate the approach on a deterministic open‑data artifact with three published engines.
By Gaston Besanson
arXiv:2607. 01988v1 Announce Type: new Abstract: Long-running adaptive intelligent agents face a structural tension between knowledge consolidation and information integrity.
By Xue Qin, Simin Luan, Cong Yang, Zhijun Li
The paper introduces a framework for evaluating how large language model agents revise their success criteria after failures, defining five non‑compensatory conditions that must be met for a criterion revision to be considered valid. Using the CMB‑0.1 protocol, the authors test twelve cross‑domain scenarios across four system configurations, finding that no model trial satisfies all five conditions and highlighting specific failure modes such as zero‑state reconstruction and inadequate intervention sensitivity. They propose a more stringent trace‑anchored CMB‑0.4 protocol to better isolate and measure criterion revision in future studies.
By Guodong Xu
The paper introduces a fault‑tolerant budget conservation framework for distributed multi‑agent delegation, where budgets are represented as exclusive escrow credits that traverse a delegation DAG. It details how each branch converts credit into a reservation tied to lineage, epoch, and idempotency, persists a signed dispatch permit, and ensures that uncertain effects remain charged until settlement or retirement. The authors prove properties such as ownership partition, ledger conservation, and at‑most‑once settlement, and validate the mechanism through TLA+ checks, a JavaScript explorer, and crash‑injected SQLite experiments.
By Genliang Zhu, Chu Wang
The paper introduces "authorization succession," a framework that preserves authority across self‑modifying AI agent populations that can replace, fork, or roll back. It defines a protocol binding each generation to a manifest, root, unique parent, lineage, and population sequence, and establishes invariants that control root‑lifetime consumption and population exposure. The authors prove properties such as population‑safe succession, fork conservation, and rollback non‑reminting, and validate the approach with an executable evaluation covering 32 decisions and external adapters for two mutation systems.
By Genliang Zhu, Chu Wang
arXiv:2609.08015v1 Announce Type: new
Abstract: Long-running AI agents may read state, reason, wait for tools or human approval, and perform an external action much later. The state that justified th...
By Yongjian Lyu, Yang Ren, Ruofei Lai, Wenting Liu