---
格式版本: 2
标题: "Explicit State Elicitation Is Not Enough: A Controlled Audit of Memory-Policy Classification"
原文链接: "https://arxiv.org/abs/2608.17247"
发布日期: "2026-08-18"
发布时间校准状态: "found"
发布时间需复核: "否"
发布时间来源: "rule:local:strict_original_body"
发布时间证据: "**\\[v1\\]** Tue, 18 Aug 2026 01:04:45 UTC (35 KB)"
发布时间校准原因: "规则确认唯一严格发布时间，来源 local:strict_original_body"
发布时间校准置信度: "high"
发布时间候选数量: 18
发布时间严格候选数量: 6
发布时间原页读取状态: "source template page reused from URL open"
发布时间未找到原因: ""
发布时间校准时间: "2026-08-20T14:58:12+08:00"
发布时间仲裁状态: "skipped"
发布时间仲裁尝试次数: 0
发布时间仲裁耗时毫秒: 0
发现时间: "2026-08-20T14:53:31+08:00"
入库时间: "2026-08-20T06:58:12.393Z"
来源平台: "arXiv 学术论文搜索"
搜索渠道: "source_template"
搜索词: "https://arxiv.org/search/?query=SUE&searchtype=all"
匹配关键词:
  - "SUE"
  - "AI"
相关厂家:
  []
相关专家:
  []
内容类型: "网页"
抓取工具: "Free Fetch + Defuddle"
清洗工具: "Defuddle Markdown + Defuddle/Readability 正文提取"
原始附件:
  []
AI优质: "否"
AI打分: 12
AI分档: "非优质"
AI质检状态: "不通过"
AI打分理由: "论文主题为AI智能体的记忆策略分类审计，与超节点、AI Rack、GPU互连、供电、液冷等关注领域完全无关。"
AI质检模型: "ali-deepseek-v4-flash"
AI质检时间: "2026-08-20T14:59:53+08:00"
AI主题相关性: 0
AI来源权威性: 5
AI新颖性: 2
AI技术细节: 0
AI商业部署信号: 0
AI完整性: 5
AI摘要: "研究者对个性化代理的记忆策略分类进行了受控审计，提出一套结构化中间输出审计协议。在160个受控反事实样本上，显式状态输出字段未显著提升Llama-3.3-70B与GPT-OSS-120B的策略准确率，且完整四路家族的一致性成功很罕见。"
AI摘要模型: "ali-deepseek-v4-flash"
AI摘要时间: "2026-09-07T03:22:02.934Z"
采集批次: "2026年8月20日14点19分32秒"
采集批次ID: "20260820-141932-079"
去重键: "https://arxiv.org/abs/2608.17247"
---

## Computer Science > Artificial Intelligence

## Title:Explicit State Elicitation Is Not Enough: A Controlled Audit of Memory-Policy Classification

Authors:[Yihang Chen](https://arxiv.org/search/cs?searchtype=author&query=Chen,+Y), [Pin Qian](https://arxiv.org/search/cs?searchtype=author&query=Qian,+P), [Su Wang](https://arxiv.org/search/cs?searchtype=author&query=Wang,+S), [Chong Peng](https://arxiv.org/search/cs?searchtype=author&query=Peng,+C), [Huan Xu](https://arxiv.org/search/cs?searchtype=author&query=Xu,+H), [Shuaiting Li](https://arxiv.org/search/cs?searchtype=author&query=Li,+S), [Yiqi Sun](https://arxiv.org/search/cs?searchtype=author&query=Sun,+Y)

[View PDF](https://arxiv.org/pdf/2608.17247) [HTML (experimental)](https://arxiv.org/html/2608.17247v1)

> Abstract:Personalized agents must decide whether retrieved user memory should be used, ignored, updated, or queried before it affects a current task. We use this setting to develop an empirical audit protocol for structured intermediate outputs: first audit dataset shortcuts, then isolate bundled prompt changes, check whether intermediate labels are answer-associated, test decomposed semantic evidence, and audit provider-level execution failures. A 480-example synthetic development set initially suggested large gains from a state-structured prompt bundle, but TF-IDF diagnostics showed lexical separability and no positive standalone Ignore cases. We therefore construct a frozen 160-example controlled counterfactual set with 40 matched four-way families and rule-derived reference policies. On this set, exposing the four state definitions improves accuracy, but an isolated explicit state-output field does not significantly improve policy accuracy for Llama-3.3-70B and gives only a marginal, non-significant gain for GPT-OSS-120B. Supplying benchmark-associated state labels shifts policy predictions, but because those labels deterministically map to policies, this is a label-conditioning diagnostic rather than evidence of a faithful internal mechanism. Family-level and seed-stability analyses further show that example-level accuracy overstates counterfactual consistency: complete four-way family success is rare. An exploratory follow-up that elicits decomposed semantic evidence also fails to improve routing for the cleanly evaluated endpoint; the corresponding GPT-OSS condition was unavailable because of provider-side request validation. We evaluate policy classification only, not downstream responses, tool actions, or memory-store mutation.

| Comments: |  |
| --- | --- |
| Subjects: | Artificial Intelligence (cs.AI) |
| Cite as: | [arXiv:2608.17247](https://arxiv.org/abs/2608.17247) \[cs.AI\] |
|  | (or [arXiv:2608.17247v1](https://arxiv.org/abs/2608.17247v1) \[cs.AI\] for this version) |
|  | [https://doi.org/10.48550/arXiv.2608.17247](https://doi.org/10.48550/arXiv.2608.17247) |

## Submission history

From: Yihang Chen \[[view email](https://arxiv.org/show-email/5b874f0f/2608.17247)\]  
**\[v1\]** Tue, 18 Aug 2026 01:04:45 UTC (35 KB)

[Which authors of this paper are endorsers?](https://arxiv.org/auth/show-endorsers/2608.17247) | Disable MathJax ([What is MathJax?](https://info.arxiv.org/help/mathjax.html))
