Protean:Binding Code, Authority, and Recovery Across Updates in Agent Runtimes
Abstract
Long-running LLM agents execute through tools whose implementations and permissions may change while calls are in flight. Existing runtimes typically treat code updates, authorization, and crash recovery as separate concerns. This separation creates invocation-level races: a call may be checked against one revision but dispatched to another, rollback may revive revoked authority, and retry after a crash may duplicate an external effect. PROTEAN maintains code and authority as independent version histories, but binds each admitted invocation to one immutable code revision, authority epoch, and recovery identity. This prevents code rollback from resurrecting revoked authority while ensuring that admission, dispatch, and recovery refer to the same invocation. A trusted Kernel (i) admits heterogeneous operations through a fail-closed capability contract, (ii) enforces epoch-scoped authority at every invocation, and (iii) pins execution and journals effects for safe replacement, rollback, and recovery. On AgentDojo, mixed HTTP/MCP/Python execution matches native-tool utility (95.3% vs. 93.7%). Across 1,146 out-of-grant requests, the Kernel realizes no out-of-envelope effect at its mediated boundary. Across 60,000-request replacement and rollback workloads and adversarial interleavings, PROTEAN loses no requests and exhibits none of six constructed lifecycle violations.
est. 32% chance this paper gets accepted at ICLR 2027.
What do you think this paper will get?
All positions stay anonymous.