QuadSentinel: Sequent Safety for Machine-Checkable Control in Multi-agent Systems
Yiliu Yang, Yilei Jiang, Qunzhong Wang, Yingshui Tan, Xiaoyong Zhu, Sherman S. M. Chow, Bo Zheng, Xiangyu Yue
TL;DR
QuadSentinel introduces a modular four-agent guard that converts natural-language safety policies into machine-checkable sequents and enforces them in real time within multi-agent systems. The guard combines a State Tracker, Threat Watcher, Policy Verifier, and Referee to monitor inter-agent messages and actions, updating a predicate state via a high-salience top-k mechanism and adapting scrutiny based on risk. Offline policy translation plus online execution yields low-latency, auditable safety with formal proofs of obligation, while maintaining compatibility with existing agents. Empirical results on ST-WebAgentBench and AgentHarm show improved accuracy and recall with reduced false positives and overhead compared to single-agent baselines, supporting easy plug-in deployment and interpretable safety traces.
Abstract
Safety risks arise as large language model-based agents solve complex tasks with tools, multi-step plans, and inter-agent messages. However, deployer-written policies in natural language are ambiguous and context dependent, so they map poorly to machine-checkable rules, and runtime enforcement is unreliable. Expressing safety policies as sequents, we propose \textsc{QuadSentinel}, a four-agent guard (state tracker, policy verifier, threat watcher, and referee) that compiles these policies into machine-checkable rules built from predicates over observable state and enforces them online. Referee logic plus an efficient top-$k$ predicate updater keeps costs low by prioritizing checks and resolving conflicts hierarchically. Measured on ST-WebAgentBench (ICML CUA~'25) and AgentHarm (ICLR~'25), \textsc{QuadSentinel} improves guardrail accuracy and rule recall while reducing false positives. Against single-agent baselines such as ShieldAgent (ICML~'25), it yields better overall safety control. Near-term deployments can adopt this pattern without modifying core agents by keeping policies separate and machine-checkable. Our code will be made publicly available at https://github.com/yyiliu/QuadSentinel.
