Don't Trust the Code, Check Its Effects: Runtime Refinement for Regenerated Systems Code Under an Adversarial Generator
Jinhao Hu, Ashvin Goel, Laurent Bindschaedler
Abstract
Recent work uses large language models to generate systems code from specifications, treating the specification as the durable artifact and the implementation as disposable. Regenerating the implementation specializes it to each workload and device. However, that work lives in a forgiving setting: a component's externally visible effects, its writes and device commands, are recoverable, and the generator is honest, so trust is discharged by re-execution. We target the unforgiving setting: systems code whose effects are irreversible, produced by a generator that may be adversarial. There, re-execution cannot check an effect after the fact, and a proof fails silently when its assumptions do. We take the position that the only safe way to operate here is to deny the generated code the authority to act. The generated code only plans, while a fixed trusted mediator owns every effect and performs one only when the specification would have produced it. Because the guarantee lives in the mediator, not the code, it survives regeneration. We instantiate this as a reference monitor for regenerated device drivers, and characterize the mediability envelope, six conditions on the effect vocabulary: legibility, spec-input observability, correlatability, completeness, outcome enumerability, and explicit durability. They decide when such mediation is possible.
Create a lesson
Related papers
Capability-Gated Language Models: Security Composes, Utility Does Not
Patrikas Vanagas, Augustas Mačijauskas, Laurynas Lopata
NeuroPriv: Adversarial Representation Learning for Privacy in Wearable EEG Systems
Sarmistha Sarna Gomasta, Bhawana Chhaglani, Prashant Shenoy
OreProof: Verifiable Provenance with Limited Disclosure for Critical-Minerals Supply Chains Using Zero-Knowledge Proofs
Oleksandr Hrabar, Hossein Arshadi Soufiani, Henry M. Kim et al.
Workload Identification with Physical Side Channels for AI Governance
Simone Gargiulo, Gabriel Kulp
Delegation Without Trust: An Empirical Gap Analysis of Identity, Authorization, and Runtime Governance in Multi-Agent LLM Systems
Panduranga Sai Varma Dantuluri, Jyotirmoy Sundi
DUPIN: Attack Learning Is Still Needed! Demonstrating Few-Shot after Unsupervised Pretraining Is A Nimble Forensics Learner
Chanwoo Bae, Hailun Ding, Shiqing Ma et al.