LATIDIA · Ciberseguridad
NOMOS: compilación de políticas escritas en puertas de llamada de herramientas verificadas estáticamente para agentes de LLM
arXiv: 2610.11030v1Announce Type: new Resumen: Los agentes LLM que utilizan herramientas violan las políticas para las que se implementan, a menudo en silencio. Las defensas anteriores escriben a mano las reglas, consultan a un verificador de LLM por acción o compilan la policía
WhatsApp ↗Telegram ↗
La noticia
arXiv:2610.11030v1 Announce Type: new Abstract: Tool-using LLM agents violate the policies they are deployed to enforce, often silently. Prior defenses hand-write rules, query an LLM verifier per action, or compile policies through heavyweight formal machinery. Naive compilation fails: extracted rules block the tool satisfying their own precondition, or read arguments their tool lacks. NOMOS, a four-pass compiler, turns a natural-language policy into a deterministic tool-call gate; static verification with tool-schema-level checks alone (no prover, solver, or LLM) repairs or rejects 37% (airline) and 13% (retail) of candidates, without which most shipped rules are inoperable. Replaying compiled rules over undefended transcripts flags bindings that refuse legitimate work (a development binding refused