上下文不等于权限:金融市场智能体的结构化运行时治理
文章背景与核心概要
在金融市场中,智能体(Agents)常常面临一个关键的漏洞:它们可能会将准确的上下文信息转化为未授权的操作——例如未经授权的客户承诺、交易执行或主动策略部署。这种“上下文即权限”的错位给金融自动化带来了巨大的合规与资金安全风险。
为了解决这一挑战,本文作者推出了 SAGE-Fin,这是一个专为金融领域设计的权限交接契约(authority-handoff contract)。该框架将运行时控制的对象从单纯的文本输出转移到了“所提出的实际影响(proposed tangible effects)”上。SAGE-Fin 通过将提案编译为带类型的候选对象、将缺失的责任记录为债务、强制执行严格的上下文契约,以及在执行前要求精确的工件收据(exact-artifact receipt),建立了一套完整的结构化治理框架,从而确保金融智能体在复杂市场环境下的安全、合规运行。
执行摘要 (Executive Summary)
Financial market agents often struggle with a critical vulnerability: they can translate accurate contextual information into unauthorized actions—such as unintended customer commitments, trades, or active policy deployments.
金融市场智能体经常面临一个关键漏洞:它们可能会将准确的上下文信息转化为未授权的操作——例如意料之外的客户承诺、交易或主动策略部署。
To address this challenge, the authors introduce SAGE-Fin, a finance-specific authority-handoff contract that is designed to shift runtime control from simple text outputs to the proposed tangible effects. SAGE-Fin introduces a structured governance framework that compiles proposals into typed candidates, tracks missing obligations as debt, enforces strict contextual contracts, and mandates exact-artifact receipts before execution.
为了应对这一挑战,作者推出了 SAGE-Fin。这是一个专为金融领域设计的权限交接契约,旨在将运行时控制从简单的文本输出转移到所提出的实际影响上。SAGE-Fin 引入了一个结构化治理框架,该框架可将提案编译为带类型的候选对象,将缺失的责任记录为债务,强制执行严格的上下文契约,并在执行前要求提供精确的工件收据(exact-artifact receipt)。
摘要 (Abstract)
Financial agents can turn correct context into an unauthorized effect: a customer-facing commitment, trade, or deployed policy. We present SAGE-Fin, a finance-specific authority-handoff contract that makes the proposed effect, not merely its text, the object of runtime control.
金融智能体可能会将正确的上下文转化为未授权的影响:面向客户的承诺、交易或已部署的策略。我们提出了 SAGE-Fin,这是一个金融专用的权限交接契约,它使所提出的影响(而不仅仅是其文本)成为运行时控制的对象。
SAGE-Fin operates through several key mechanisms: * Compiles proposals into typed, adapter-bound candidates. * Records missing or stale institutional obligations as coverage debt. * Contracts authority under current market, account, policy, and dialogue states. * Requires an exact-artifact receipt whose nominal type matches the consuming response, execution, or policy adapter.
SAGE-Fin 通过以下几个关键机制运作: * 将提案编译为带类型的、绑定适配器的候选对象。 * 将缺失或过期的机构责任记录为覆盖债务(coverage debt)。 * 在当前的市场、账户、策略和对话状态下收紧权限契约。 * 要求提供精确的工件收据,其名义类型必须与消费响应、执行或策略适配器相匹配。
Evidence and workflow progress cannot substitute for effect authority, and prior authorization is rechecked after state changes.
证据和工作流进度不能替代影响权限,并且在状态更改后会重新检查先前的授权。
Across an authored 616-case catalog, five deterministic specifications yield 3,080 outputs; a label-isolated harness obtains 616/616 binary reference-prototype parity, including 3/3 named response-gate fixtures, while 22 tests cover selected paths. These results establish executable conformance, not independent safety accuracy.
在包含 616 个案例的编写目录中,五个确定性规范产生了 3,080 个输出;一个标签隔离的测试夹具获得了 616/616 的二进制参考原型一致性(包括 3/3 个命名的响应门夹具),同时有 22 个测试覆盖了选定的路径。这些结果确立的是可执行的一致性,而不是独立的安全性准确率。
Separately, SAGE-Fin's response gate processed real customer-facing production requests at a confidential digital-asset platform. An operational team independent of the implementation team reached a strongly positive post-deployment conclusion on practical usefulness and workflow fit, and end-user feedback was also strongly positive. Disclosure permits only the review's independence, stakeholder classes, assessed dimensions, and directional conclusion, so this is qualitative field corroboration rather than an aggregate effect estimate. Three distinct de-identified predecessor failures, with independently confirmed 0/3 interception, ground repeated-emission drift, stale account evidence, and missing escalation state without estimating prevalence or treatment effect.
另外,SAGE-Fin 的响应门在一个机密的数字资产平台上处理了真实的面向客户的生产请求。独立于实施团队的运营团队在部署后对其实际效用和工作流契合度得出了高度肯定的结论,终端用户的反馈也同样非常积极。披露信息仅限于审查的独立性、利益相关者类别、评估维度和方向性结论,因此这是定性的现场印证,而不是总体影响估计。三个不同的匿名化前代故障(经独立确认拦截率为 0/3)阐明了重复输出漂移、陈旧的账户证据以及缺失的升级状态,且未估计其流行度或处理效果。
文章元数据 (Article Metadata)
| 字段 (Field) | 详情 (Details) |
|---|---|
| Primary Subject | Artificial Intelligence (cs.AI) |
| Secondary Subjects | Cryptography and Security (cs.CR), Machine Learning (stat.ML) |
| ACM Classes | I.2.11; D.4.6; K.4.1 |
| DOI Link | 10.48550/arXiv.2608.09025 |
| Full-Text Resources | View PDF | TeX Source |
字段 (Field) 详情 (Details) 主要学科 (Primary Subject) 人工智能 ( cs.AI)次要学科 (Secondary Subjects) 密码学与安全 ( cs.CR)、机器学习 (stat.ML)ACM 类别 (ACM Classes) I.2.11; D.4.6; K.4.1 DOI 链接 (DOI Link) 10.48550/arXiv.2608.09025 全文资源 (Full-Text Resources) 查看 PDF | TeX 源码