2607.01919v1 Jul 02, 2026 cs.AI

ElephantAgent: 에이전트 시스템에서의 문맥 상태 연속성

ElephantAgent: Contextual State Continuity in Agentic Systems

Deyue Zhang
Deyue Zhang
Citations: 158
h-index: 4
Xiangzheng Zhang
Xiangzheng Zhang
Citations: 20
h-index: 3
Dongdong Yang
Dongdong Yang
Citations: 71
h-index: 3
Jiankai Jin
Jiankai Jin
Citations: 76
h-index: 3
Zhao Liu
Zhao Liu
Citations: 31
h-index: 3
Quanchen Zou
Quanchen Zou
Citations: 24
h-index: 2
Wenzhuo Xu
Wenzhuo Xu
Citations: 24
h-index: 3

에이전트 시스템은 외부 도구를 활용하고 지속적인 메모리를 유지함으로써 기능을 향상시킵니다. 그러나 이러한 외부 의존성은 새로운 공격 경로를 발생시킵니다. 최근의 도구 및 메모리 오염 공격은 악의적으로 조작된 도구 설명자와 오염된 메모리가 에이전트의 동작을 은밀하게 왜곡할 수 있음을 보여줍니다. 이러한 위협은 계획 및 실행을 위한 에이전트의 문맥 상태에서 검증 가능한 연속성이 부족하다는 근본적인 문제를 반영합니다. 본 논문에서는 문맥 상태 오염으로부터 보호하기 위해 문맥 상태 연속성을 강화하는 프로토콜인 ElephantAgent를 제안합니다. 기존의 상태 연속성 메커니즘(예: Nimble)에 영감을 받아, ElephantAgent는 에이전트 시스템의 진화하는 문맥 상태에 대한 이러한 보호 기능을 확장합니다. 우리는 에이전트의 전체 컨텍스트에서 보안적으로 중요한 부분집합인 '문맥 상태'를 정의합니다(예: 도구 상태 및 메모리). ElephantAgent는 각 쿼리를 처리하기 전에 로컬 문맥 상태의 다이제스트를 다시 계산하고 최신 승인된 다이제스트와 비교하여 이를 검증합니다. 또한, ElephantAgent는 복제된 신뢰할 수 있는 하드웨어를 사용하여 승인된 문맥 상태 변환에 대한 선형화 가능한 원장을 유지하며, 외부에서 발생하는 상태 조작을 감지합니다. 더불어, ElephantAgent는 '역사적 추적 기능'을 제공하여 내부적인 의미 변경 공격에 대응하고, 조건부 후 감사 및 알려진 정상 상태로의 복구를 가능하게 합니다.

Original Abstract

Agentic systems enhance their capabilities by invoking external tools and maintaining persistent memory. However, these external dependencies introduce novel attack surfaces. Recent tool and memory poisoning attacks show that maliciously crafted tool descriptors and poisoned memory can covertly bias agent behavior. These threats reflect a deeper issue: the lack of verifiable continuity in the agent's contextual state for planning and execution. We present ElephantAgent, a protocol that enforces Contextual State Continuity to defend against contextual state poisoning. Inspired by prior state-continuity mechanisms (e.g., Nimble), ElephantAgent extends this protection to the evolving contextual state of agentic systems. We define the contextual state as the bounded, security-critical subset of the agent's entire context (e.g., tool state and memory). Before processing each query, ElephantAgent recomputes the digest of the local contextual state and verifies it against the latest authorized digest. Using replicated trusted hardware, ElephantAgent maintains a linearizable ledger of authorized contextual state transitions and detects out-of-band state tampering. To handle in-band semantic abuse, ElephantAgent additionally provides Historical Traceability, enabling conditional post-hoc audit and recovery to a known-good prior state.

0 Citations
0 Influential
2 Altmetric
10.0 Score
Original PDF

No Analysis Report Yet

This paper hasn't been analyzed by Gemini yet.

Log in to request an AI analysis.

댓글

댓글을 작성하려면 로그인하세요.

아직 댓글이 없습니다. 첫 번째 댓글을 남겨보세요!