The No-Witness Rule: Making Fabricated Tool-Call Arguments Unreachable by Construction
Abstract
Constrained decoding is the standard way to stop a tool-using agent from inventing the identifiers, paths and order numbers it passes to tools: restrict the argument to values the agent has actually seen. Every published treatment of a candidate set that cannot supply the needed value fires when that set is empty. We show the empty set is the wrong condition to test. Whether a set is ever empty is a property of how narrowly the slot is typed rather than of the trajectory, and neither end of that choice rewards testing it — under the type function we run it never arises, and under the strictest one we price it fires on 39.85% of emissions while destroying 8.39 correct values for each fabrication caught. The condition that arises regardless is a candidate set that is non-empty and does not contain the value, 10.09% of referential emissions, and nothing treats it. There the constraint requires the model to choose a wrong value, the tool fails, no witness is added, and the next step repeats the last: a livelock we reproduce outside our own system with a small model, a synthetic loop and VLLM's guided_choice, where an abstention token sat in the candidate set for all 240 constrained emissions and was chosen 0 times. The defect is the trigger, not the enforcement. Testing whether the value the model wrote is licensed cuts unwitnessed emission from 9.00% to 2.45% at 8B and 13.03% to 2.39% at 14B, constrains 8.43% of call steps, and is equivalent to the baseline on task score within this benchmark's own 7-point resolution floor; the published prompt-based method for the same failure clears neither bar. What such a rule is worth is a property of the environment rather than of the model: where referents are validated it buys back a wasted call, and where they are not it buys the difference between a wrong write and no write.
Then back it, or bet against it.
Related papers
Open the market on this paper to see 7 more related papers.