acceptodds
Under review as a conference paper at ICLR 2027

PACT: What Agents See Must Not Decide What Their Tools Do

Abstract

External content may inform the tool call an agent proposes, but it must not grant permission to execute that call. Before a call runs, the Provenance-Aware Contract for Tools (PACT) checks its operation, destination, arguments, sources, evidence, and approval against a task contract, an executable list of what the trusted request permits. With complete contracts supplied by the task, recorded sources, interception of every registered call that changes or discloses application state (a protected call), and permitted alternatives, PACT blocks all 1,500 controlled attacks and completes all 2,000 tasks without human intervention. On the same 100 adapted ARPIbench cases, the attack success rate (ASR) in executed protected calls falls from 2%–85% to 0 for each of eight models. On all 7,560 cases with DeepSeek V4 Flash, ASR falls from 58.4% to zero while permitted tool calls still run. On AgentDojo, PACT ties the best task success under attack and the best safe success, and no protected call requested by an attack executes. Building complete contracts is harder. A 72B model that generates contracts from the request finds 70/72 write tools but correctly constrains only 20/223 argument fields, and PACT enforces such incomplete permissions exactly as written.

open until 14 Dec 2026

est. 32% chance this paper gets accepted at ICLR 2027.

Reject 68%Accept 32%

What do you think this paper will get?

All positions stay anonymous.

Related papers

Loading the map…

Discussion (0)

Sign in to comment.