acceptodds
Under review as a conference paper at ICLR 2027

Decoder Silencing: Cloned GUI Agents Know When to Ask, and Greedy Decoding Discards It

Abstract

A GUI agent that sends messages, deletes files or makes payments should ask before acting on an instruction it cannot resolve. Policies cloned from demonstrations routinely ask on no such instruction, and the field reads a ask-rate as a behaviour the supervision failed to teach. We measure the probability such a policy puts on asking with one teacher-forced forward pass per held-out state, no rollouts and no outcome labels. Across reruns of a single recipe, with nothing varied that the trainer reads, it spans to . Greedy decoding compares each against one half, so a run holding substantial ask-mass and one holding almost none deploy at the same ask-rate. We call the first case decoder silencing: the behaviour is present in the belief and discarded at the decoder, not missing from the policy. The distinction is actionable: only a silenced behaviour can be repaired without retraining, and the probe says before deployment which runs a decode-time threshold will repair. We test this on AmbiGUI, a testbed we release where ambiguity comes from environment state rather than instruction text and every instance is verified on both sides: the question resolves it, guessing causes an irreversible action. On a pre-registered set it repairs about half of them, cutting irreversible wrong actions and raising task success, though a minority of runs come out worse on each. On AndroidWorld the probe is blind before training, when the tiers do not separate, and names what the agent does after. There, a backbone trained on whole episodes and deployed live on the emulator asks on every ambiguous instance and finishes of them with no irreversible error. No arm completes a task when its demonstrations stop at the decision rather than the finished state. Put plainly, a policy that never asks has usually been silenced rather than left untaught — so a ask-rate should be measured before it is believed.

open until 14 Dec 2026

est. 32% chance this paper gets accepted at ICLR 2027.

Reject 68%Accept 32%

What do you think this paper will get?

All positions stay anonymous.

Related papers

Loading the map…

Discussion (0)

Sign in to comment.