arXiv:2606. 04296v1 Announce Type: new Abstract: As autonomous AI agents move from conversational systems to long-horizon software execution, runtime safety layers that decide when to interrupt an agent have become essential.
By Manvendra Modgil
arXiv:2608.30502v1 Announce Type: new
Abstract: Machine learning systems are increasingly corrected while they run, and the decision of when to intervene is increasingly delegated to statistical moni...
By Weijia Han, Lisha Qu
The paper derives precise cost formulas for self‑calibrating monitors that adjust thresholds online to maintain a specified long‑run false‑alarm rate under arbitrary drift. It shows that the guarantee is an accounting identity, independent of the monitored signal, and provides exact evidence identities for both step and ramp drift scenarios, as well as an exact law for the fluctuation of the certificate’s own alarm rate. Additionally, it proves that any monitor designed to tolerate a drift class is blind to all faults in the difference of that class, identifying the blind set for speed‑bounded drift classes and quantifying power outside this set with a sharp Gaussian projection bound.
By Abdou-Raouf Atarmla
arXiv:2607. 24339v1 Announce Type: new Abstract: Large language model (LLM) agents inherit reactive failure modes: escalation under provocation, sycophantic drift under flattery, perseveration when stuck.
By Dushyant Sharma
arXiv:2608. 02464v1 Announce Type: cross Abstract: LLM agents fail mid-episode -- they loop, cascade tool errors, drift off goal, fabricate results, or silently absorb corrupted content -- and the standard remedy, judging every step with a second LLM, costs more than the agent itself.
By Sunny Dubey
The paper reports that agent evaluations often show a tool‑call rate of zero even when the model emits valid calls, because the interface censors the trajectory before downstream components see it. Experiments on BFCL v4 and tau‑bench demonstrate that swapping the serving adapter can change the observed call rate from 0.00 to 0.96/0.19 or from 0 to 636 calls, indicating that the interface—not the model—causes the discrepancy. A 98‑line preflight check is released to detect such silent failures, highlighting that tool‑call rates depend on the model‑interface stack rather than the model alone.
By Wenbo Wang
arXiv:2606. 23993v1 Announce Type: cross Abstract: High-throughput scientific facilities such as the Large Hadron Collider depend on real-time event filtering (\textit{triggering}) under tight constraints on bandwidth, latency, and storage.
By Zixin Ding, Shaghayegh Emam, Giovanna Salvi, Cecilia Tosciri, Abhijith Gandrakota, Jennifer Ngadiuba, Nhan Tran, Christian Herwig, David W. Miller, Yuxin Chen
arXiv:2608. 05784v1 Announce Type: new Abstract: Computer-use agents pay full frontier inference to re-derive routines their user has already performed, because an agent's memory today records what the user said, not what the user did.
By Nossa Iyamu
The paper introduces a claim‑safe protocol for evaluating closed‑loop AI systems, consisting of three actions: Refuse, Decompose, and Refresh. It demonstrates the protocol in a simulator with 24 policy components and 1,440 held‑out cases, showing that abstention and stable false admission rates are low while providing detailed statistical diagnostics. The approach emphasizes that evaluation results should be tied to observable support and statistical calibration rather than a single PASS/FAIL label.
By Peiying Zhu, Sidi Chang
The paper demonstrates that aggregate accuracy figures for chain‑of‑thought (CoT) monitors can be misleading because a large portion of detected hacks rely solely on action patterns rather than reasoning. By rewriting only the agent’s reasoning to appear truthful while keeping actions identical, the authors show that the monitor’s performance on the reasoning‑dependent subset collapses dramatically, yet the overall pooled accuracy drops only modestly. The study reveals that CoT monitors are fragile when reasoning is the key signal and that accuracy should be reported separately for this subset.
By Shikhar Shiromani, Leo Richter
arXiv:2606. 15474v1 Announce Type: new Abstract: Continuous evaluation of LLM products relies on a strong LLM judge treated as ground truth: a cheap monitor scores every interaction and a team is paged when the score drifts down.
By Yitao Li
The paper presents a runtime monitoring framework for stochastic systems that distinguishes normal distributional relaxation from regime changes while limiting false alarms. It combines relative‑entropy dissipation, information geometry, and sequential inference within a bounded first‑passage architecture, employing Gaussian window surrogates, covariance shrinkage, and conformal ranking aggregated by a mixture power‑martingale. Validation on Ornstein–Uhlenbeck dynamics and network intrusion datasets (NSL‑KDD, UNSW‑NB15) shows high detection rates with low false positives, highlighting calibration transport as a key deployment challenge.
By Hikmat Karimov, Rahid Zahid Alekberli