EdgeGuard-Agent : Edge-Level Verification and Policy Learning for Tool-Using Agents under Incomplete Information
Abstract
Tool-using agents are increasingly applied to stateful tasks such as order management, flight rebooking, and customer support, where requests are often incomplete, states are partially observable, and write actions may cause real side effects. Existing methods typically handle clarification, correction, and safety separately, making unified verification difficult. We propose EdgeGuard-Agent, an edge-level verification and policy learning framework for tool use under incomplete information. It treats each action as a state-transition edge and checks whether it is legal, grounded, executable, task-advancing, and non-redundant. At runtime, it focuses on risky or abnormal actions, including unsupported writes, invalid tools, missing arguments, state conflicts, and repeated actions, and then either accepts the action, replaces it with a safe executable repair, or blocks it if no safe option exists. Deterministic checks further prevent ungrounded arguments, unsafe writes, invalid confirmations, and cross-turn inconsistencies. During training, the same checks identify the first invalid action, restore the environment, apply a verified repair, and regenerate a causally consistent trajectory for supervised fine-tuning and GRPO with both task-level and edge-level rewards. Experiments on CAR-Bench, STATE-Bench, and -Bench-Ambiguous show improvements in task success of 29.60, 8.13, and 10.43 percentage points, respectively, with fewer premature actions and incorrect writes. On CAR-Bench, EdgeGuard-Agent-guided SFT improves task success from 27.69% to 35.30%, and GRPO further raises it to 40.42%. These results show that edge-level verification is a simple and effective way to improve both runtime reliability and policy learning in multi-turn tool-using agents.
est. 32% chance this paper gets accepted at ICLR 2027.
What do you think this paper will get?
All positions stay anonymous.