🤖 AI Summary
This work addresses the challenge of maintaining global consistency in LLM workflows that share structured state, where local updates can inadvertently violate system-wide invariants. The authors propose PatchOptic, a novel framework inspired by optics, which introduces a bidirectional access interface enabling safe local reads and writes through projected views, structured patches, and path-level footprint tracking. By integrating declarative region-based authorization, PatchOptic supports runtime validation, composable sub-workflows, and static certificate generation to ensure all updates adhere to global contracts. Evaluation on the PatchBench benchmark across 46 cases demonstrates that PatchOptic effectively blocks illicit updates—including contract violations and hidden-source attacks—while reducing information leakage and token overhead without compromising output quality.
📝 Abstract
Agentic workflows often operate over shared, structured state. Because LLM context windows are limited, each model invocation is typically shown only the state fragment needed for the current workflow step, a pattern commonly known as progressive disclosure. Modern systems construct such model-facing views using grep-like keyword search, retrieval-augmented generation (RAG), abstract-syntax-tree (AST) queries, and task-specific agent skills. These methods make the read side manageable, but they do not define when a locally proposed rewrite is valid after it is applied back to the full state. The missing piece is a contract between local updates and global validity. We introduce PatchOptic, an optic-inspired interface for shared-state LLM workflows. Optics are compositional bidirectional accessors that describe how views of structured data are read and updated. PatchOptic borrows this view/update intuition and realizes it through projected reads and verified structured patches. Each workflow step declares a projected read view, an authorized write region, and a patch-source region. Beyond runtime enforcement, the same declaration yields a path-level footprint that supports delegation, sub-workflow composition, and static certificates for reordering independent steps within the same phase. We evaluate this design with PatchBench, a benchmark with 46 cases across domains. The results show that projected reads reduce reported leakage and token cost while preserving accepted-output quality under the strong actor. Runtime verification blocks declared workflow-contract violations before commit, and patch-read enforcement rejects compromised patch artifacts that use hidden sources.