כתבה
arXiv cs.LG ·
Who Verifies the Graph? Misspecification Attacks on Causal Action Verification for Language Agents
תקציר מקורי באנגליתarXiv:2609.40027v1 Announce Type: cross Abstract: Causal action verifiers gate an agent's state-changing tool calls by checking whether each proposed intervention is identifiable against a committed action-state graph, and they issue a certificate that carries the identification argument and a one-sided lower confidence bound. One such verifier, CIVeX, reports zero false executions on a confounded tool-use benchmark. We red-team it by corrupting only the committed graph. Omitting a single bidirected edge takes it from zero false executions to 15.3% at the benchmark's published confounding strength, with 91% of its executions harmful and utility falling from +2.27 to +0.35. Reversing one arrowhead, so that a mediator is committed as a confounder, gives 48.9% false executions and no correct
קרא במקור המקורי
arxiv.org
פתח כתבה מקורית