arXiv:2609.21284v1 Announce Type: cross
Abstract: Long-running AI agents outlive initiating processes through credentials, delegated tasks, queues, callbacks, reservations, and provider-side operatio...
By Genliang Zhu, Chu Wang
arXiv:2609. 00546v1 Announce Type: cross Abstract: Agent systems are commonly described by the model and harness that currently produce their behavior.
By Zhenyu Zhao (Independent Researcher), Roy Zhao (Paul G. Allen School of Computer Science & Engineering, University of Washington)
The paper introduces "authorization succession," a framework that preserves authority across self‑modifying AI agent populations that can replace, fork, or roll back. It defines a protocol binding each generation to a manifest, root, unique parent, lineage, and population sequence, and establishes invariants that control root‑lifetime consumption and population exposure. The authors prove properties such as population‑safe succession, fork conservation, and rollback non‑reminting, and validate the approach with an executable evaluation covering 32 decisions and external adapters for two mutation systems.
By Genliang Zhu, Chu Wang
arXiv:2607. 23586v1 Announce Type: new Abstract: Long-lived AI agents increasingly evolve after deployment by retaining experience, acquiring skills and tools, revising workflows, delegating work, and moving across task phases.
By Zhaoxi Zhang, Xiaomei Zhang
The paper introduces BSC‑R, a deterministic effect‑boundary mechanism that ties a single‑use commit authorization to the specific action and the semantic state that justified it, aiming to close the proposal‑to‑commit gap in tool‑using language‑model agents. Experiments on 2,847 AgentDojo episodes and 10,302 frozen proposals show that BSC‑R preserves the agent’s original behavior while rejecting unauthorized changes, and further tests on a boundary‑drift experiment and the CONTINUITY suite demonstrate high success rates in valid contexts and robust handling of replay and ambiguous cases. However, broader testing reveals that BSC‑R still allows a 25% invalid‑effect commit rate in a larger attack set, indicating that it provides scoped, not universal, safety.
By Wesley Shu
arXiv:2609.08062v1 Announce Type: new
Abstract: Tool-using language agents can delegate and revoke permissions while acting through external services. We show that two authorization histories can hav...
By Moonwon Choi, Seokho Jeong, Seunggeun Lee