🤖 AI Summary
This study addresses the vulnerability of LLM agents to task failures and unsafe operations caused by the reuse of invalid persistent states. To mitigate this, we propose a pre-action state diagnosis and repair framework that employs record-level counterfactual replanning to localize critical corrupted records, combined with typed evidence binding and reliability checks to repair states while maintaining lineage. Furthermore, independent verification is enforced prior to execution through read-only fact validation and intent clarification mechanisms. This approach enables continuous correction and decoupled state-action verification. Experimental results demonstrate that our method achieves 93.3% accuracy under corrupted states—substantially outperforming the 38.7% baseline—while ensuring zero unsafe actions and exhibiting strong cross-environment transferability.
📝 Abstract
LLM agents combine reasoning, tool use, and persistent memory to support work across tasks by reusing stored operational records as premises for later actions. However, environmental or requirement changes can invalidate these records, while existing action review, provenance tracking, and clarification mechanisms may leave the underlying persistent state uncorrected. Our audit of coding-agent trajectories identifies candidate failure chains in which invalid records are reused, leading to task failures and unsafe modifications. We propose StateWise, a framework for diagnosing and repairing persistent operational state before action execution. StateWise uses record-level counterfactual replanning to identify decision-critical records, then establishes their current validity through reliability checks, read-only verification of machine-observable facts, and targeted clarification of developer-owned intent. Typed evidence grounding binds evidence to specific records and scopes, enabling persistent corrections with repair lineage. The agent then replans from the repaired state, followed by an independent state-action check before execution. We evaluate StateWise on 150 executable coding-agent cases across diverse runtime environments, workspace configurations, and repository settings, complemented by cross-model evaluations. Under corrupted persistent state, StateWise achieves 93.3% overall correctness, compared with 38.7% for the baseline agent, with no unsafe actions. Component ablations, multi-task experiments, and transfer evaluations further demonstrate effective recovery, persistent corrections, and transferability across repositories and tool interfaces.