에이전트의 역량이 중요합니다: 실행 경로를 통해 독점적인 기술 추론
Agent Skills Matter: Inferring Proprietary Skills from Execution Trajectories
에이전트 기술은 재사용 가능한 절차를 포함하며, 이는 후속 성능을 향상시킵니다. 이들의 가볍고 휴대 가능한 형식은 마켓플레이스 수익 창출과 클라우드 기반 에이전트 인터페이스 뒤에서의 비공개 배포를 가능하게 하여 제공업체가 고가치 기술을 독점적으로 유지하도록 유도합니다. 그러나 이러한 요소들을 숨기는 것은 행동 효과를 완전히 감추지 못하며, 이는 실행 경로에서 관찰될 수 있는 '행동 부작용'을 형성합니다. 우리는 이러한 노출을 '기술 누수(Skill Leakage)'라고 정의하며, 정답이나 성공 여부 표시 없이, 양성적인 쿼리에 의해 유발되는 실행 경로를 통해 독점 기술을 재구성하는 것을 의미합니다. 본 연구에서는 SigLeak이라는 블랙박스 프레임워크를 소개하며, 이는 에이전트 행동에서 반복되는 기술 특징을 활용합니다. SigLeak은 다양한 의사 결정 기능이 포함된 진단 작업을 구축하고, 특정 기술이 활성화/비활성화된 실행 경로를 비교하여, 분리된 패턴으로부터 재구성된 기술을 반복적으로 개선합니다. 본 연구는 5가지 시나리오, 3가지 모델 패밀리, 3가지 에이전트 프레임워크에서 진행되었으며, SigLeak은 거의 모든 환경에서 세 가지 기준 성능을 능가하거나 일치하는 결과를 보였습니다. 평균적으로, SigLeak은 기술 비활성화 기준보다 성공률을 6.88%p 향상시켰으며, 전체적으로 SkillSim(거칠고 미세한 의미적 유사성을 측정하는 지표)에서 가장 높은 점수를 달성했습니다. 이러한 결과는 양성적인 실행 경로가 독점적인 절차적 지식을 노출시킬 수 있음을 보여줍니다. 코드 및 관련 자료는 https://anonymous.4open.science/r/SigLeak-D1DB 에서 확인할 수 있습니다.
Agent skills package reusable procedures that improve downstream performance. Their lightweight, portable form enables marketplace monetization and private deployment behind cloud-hosted agent interfaces, giving providers incentives to keep high-value skills proprietary. Yet hiding the artifacts does not conceal their behavioral effects, which remain observable in execution trajectories and form a behavioral side channel. We define this exposure as Skill Leakage: reconstructing proprietary skills from trajectories elicited by benign queries, without reference answers or success labels. We introduce SigLeak, a black-box framework that exploits recurring skill signatures in agent behavior. It constructs diverse, decision-rich diagnostic tasks, contrasts matched skill-enabled and skill-disabled trajectories, and iteratively refines a reconstructed skill from the isolated patterns. Across five scenarios, three model families, and three agent frameworks, SigLeak outperforms or matches three baselines in nearly every setting. It raises the success rate by 6.88 percentage points over the skill-disabled reference on average and achieves the highest overall SkillSim, our metric for coarse- and fine-grained semantic similarity. These results show that benign execution trajectories can expose proprietary procedural knowledge. The code is available at https://anonymous.4open.science/r/SigLeak-D1DB.
No Analysis Report Yet
This paper hasn't been analyzed by Gemini yet.
Log in to request an AI analysis.