AI Agents 相关度: 9/10

Detecting Safety Violations Across Many Agent Traces

Adam Stein, Davis Brown, Hamed Hassani, Mayur Naik, Eric Wong
arXiv: 2604.11806v1 发布: 2026-04-13 更新: 2026-04-13

AI 摘要

Meerkat通过聚类和智能搜索,高效检测多Agent轨迹中的安全违规行为。

主要贡献

  • 提出了 Meerkat 系统,结合聚类和智能搜索
  • 能够发现跨多个Agent轨迹的安全违规
  • 在多种场景下显著提升了违规检测效果

方法论

Meerkat 采用聚类方法发现潜在违规区域,并使用 Agentic Search 深入调查。

原文摘要

To identify safety violations, auditors often search over large sets of agent traces. This search is difficult because failures are often rare, complex, and sometimes even adversarially hidden and only detectable when multiple traces are analyzed together. These challenges arise in diverse settings such as misuse campaigns, covert sabotage, reward hacking, and prompt injection. Existing approaches struggle here for several reasons. Per-trace judges miss failures that only become visible across traces, naive agentic auditing does not scale to large trace collections, and fixed monitors are brittle to unanticipated behaviors. We introduce Meerkat, which combines clustering with agentic search to uncover violations specified in natural language. Through structured search and adaptive investigation of promising regions, Meerkat finds sparse failures without relying on seed scenarios, fixed workflows, or exhaustive enumeration. Across misuse, misalignment, and task gaming settings, Meerkat significantly improves detection of safety violations over baseline monitors, discovers widespread developer cheating on a top agent benchmark, and finds nearly 4x more examples of reward hacking on CyBench than previous audits.

标签

安全 Agent 聚类 智能搜索

arXiv 分类

cs.AI cs.CL