The prototype, SemIso, propagates semantic context and blocks incompatible resources and branch merges with microsecond-scale checks and shows that these guarantees can be checked and enforced efficiently in middleware.
Abstract
An AI execution can now outlive the environment in which it began. What once fit inside one model call increasingly unfolds across pauses, retries, branches, subagents, and model-selected tools. Meanwhile, prompts, model aliases, indexes, policies, and tools are deployed independently: stable names can acquire new behavior, and workflows can discover resources only after they start. The workflow can therefore combine saved state with changed assumptions, producing an internally inconsistent result even when every call succeeds. This is an isolation problem: database transactions constrain concurrent data updates, but workflow checkpointing provides no corresponding contract for concurrent changes to an AI workflow's semantic environment. We define four automatically detectable anomalies: semantic read skew, compatibility skew, context escape, and merge skew. To control which anomalies are allowed, we derive a partial order of isolation levels, from Semantic Read Committed to Semantic Snapshot Isolation, by combining three independent guarantees: resource stability, cross-resource compatibility, and continuation inheritance. In a conservative source audit of the 100 most-starred public repositories with executable LangGraph code, we find that 7.4 percent of codebases with durable workflows resolve live or dynamically selected semantic resources within the same workflow, without an evident immutable binding. We show that these guarantees can be checked and enforced efficiently in middleware. Our prototype, SemIso, propagates semantic context and blocks incompatible resources and branch merges with microsecond-scale checks.
This work identifies a state-transmission failure between information extraction and action in large language model agents, and shows how handoff transformations can retain state content while weakening its constraints on downstream action.
Yi-Heng Sun, Huifei Wang, Yan-Cheng Zhu et al.· 2 citations
CrisBench, a 1,200-question benchmark of lifecycle reasoning that combines a controlled formal setting with programs executed against Cordis, a runtime that manages component dependencies and cleanup, and asks models to identify affected components, predict state after a specified teardown order, and determine which co...
This work presents \textsc{Revise}, a validity-guided runtime for fine-grained recovery in structured agent workflows, a validity-guided runtime for fine-grained recovery in structured agent workflows that matches a latest-version oracle with no stale outputs or effects.
Ruoling Qi, Xuan'er Wu, Peng-Hang Liu et al.· 0 citations
TraceCompiler is presented, a skill-guided system that mines clusters of noisy agent traces and compiles them into executable, mostly deterministic workflows, and measures call reduction but not offline compilation cost, so it claims no net efficiency result.
Distributed LLM-agent teams can read the latest shared facts and still act on an obsolete plan. A planner may derive an action from requirement $r_3$, another agent may commit $r_4$, and an executor may receive $r_4$ without replacing the plan derived from $r_3$. We call this \emph{stale-plan execution}: state freshnes...
Evan Chen, Shi-Qiang Wang, Christopher G. Brinton· 0 citations
This work presents PULSE, an Object-Process-Methodology-inspired language that localizes four operational roles and their write effects in one typed runtime, here, modes denote operational roles rather than modal or deontic logic.
Dongxu Yang, Zi-Yi Liang· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.