Approved Too Late: Verdict Staleness in LLM-Guarded Self-Adaptive Systems

📅 2026-08-26
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
研究解决自适应系统中语言模型护栏判决过时问题,提出新鲜度边界防护方法估计批准的有效期,减少批准过期率。
📝 Abstract
A large language model (LLM) guardrail for a self-adaptive system (SAS) may issue an approval that is correct at check time but stale by actuation. This creates an Execute-stage time-of-check to time-of-use (TOCTOU) hazard. We study verdict freshness: whether a guardrail verdict remains valid when used. We distinguish three quantities that answer different questions: all-candidate verdict change under fixed-action replay, oracle-labeled approval expiry on recorded closed-loop trajectories, and judge-conditioned use-time invalidity. Across five reproducible SAS environments, all-candidate verdict-change rates span 5.3-48.4% at a common replay shift of eight simulator steps. We introduce the Freshness-Bounded Shield (FBS), which estimates each approval's validity horizon from its safe-side margin and recent feature volatility, without an explicit plant-dynamics model. Using fixed settings documented in the artifact, FBS reduces oracle-labeled approval-expiry rates from 3.4-24.7% to 0-1.8% at the same shift. A separate audit of four LLM judges finds nonzero judge-conditioned use-time invalidity in every approval stream. We formulate a freshness contract: every approval must be correct at check time and remain valid at use time.
Problem

Research questions and friction points this paper is trying to address.

LLM
SAS
TOCTOU
Verdict Staleness
Innovation

Methods, ideas, or system contributions that make the work stand out.

Verdict Staleness
Freshness-Bounded Shield
Self-Adaptive Systems
🔎 Similar Papers
💼 Related Jobs
No related jobs found.
I
Ilai Shraga
University of Cambridge
R
Roei Eshel
Maccabim-Re’ut High School
L
Lior Gorelik
The Open University of Israel