acceptodds
Under review as a conference paper at ICLR 2027

Rollback as Authority Revocation: Binding Caches to Committed History

Abstract

Agent rollback revokes a branch at the application level. When a later privileged decision consumes separately retained inference state, that state can remain bound to the revoked history. We formulate rollback as an authority-revocation event that must also constrain inference-state provenance. In a controlled experiment, stale and rebuilt arms receive identical post-rollback decision tokens; changing the retained prefix changes authorization outcomes in 43 of 63 settings across seven model families. Rejected content remains recoverable in all 20 settings where the original action stays authorized. Local replay of one public chat application's deletion handlers demonstrates that this split between application history and inference state can arise in existing code. We specify a contract that binds cache reuse to the authoritative committed prefix, separating provenance consistency from numerical comparison and behavioral agreement. An executable reference adapter applies established prefix reuse and recomputation to this contract. It restores authorized actions in all 36 edited cases and 18 no-op controls tested, while complete continuations sometimes differ from cold computation. The contribution is a security semantics and evaluation methodology for rollback across layers, rather than a new cache algorithm.

open until 14 Dec 2026

est. 32% chance this paper gets accepted at ICLR 2027.

Reject 68%Accept 32%

What do you think this paper will get?

All positions stay anonymous.

Related papers

Loading the map…

Discussion (0)

Sign in to comment.