{"id":"https://openalex.org/W7140138088","doi":"https://doi.org/10.48550/arxiv.2603.19328","title":"The Verifier Tax: Horizon Dependent Safety Success Tradeoffs in Tool Using LLM Agents","display_name":"The Verifier Tax: Horizon Dependent Safety Success Tradeoffs in Tool Using LLM Agents","publication_year":2026,"publication_date":"2026-03-18","ids":{"openalex":"https://openalex.org/W7140138088","doi":"https://doi.org/10.48550/arxiv.2603.19328"},"language":null,"primary_location":{"id":"doi:10.48550/arxiv.2603.19328","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2603.19328","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":null,"is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"article"},"type":"preprint","indexed_in":["datacite"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"https://doi.org/10.48550/arxiv.2603.19328","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5096940264","display_name":"Tanmay Sah","orcid":"https://orcid.org/0009-0004-8583-2208"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Sah, Tanmay","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5130355812","display_name":"Vishal Srivastava","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Srivastava, Vishal","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5130346522","display_name":"Dolly Sah","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Sah, Dolly","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"last","author":{"id":"https://openalex.org/A5130389396","display_name":"Kayden Jordan","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Jordan, Kayden","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]}],"institutions":[],"countries_distinct_count":0,"institutions_distinct_count":4,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":null,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":null,"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":null,"last_page":null},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10883","display_name":"Ethics and Social Impacts of AI","score":0.1746000051498413,"subfield":{"id":"https://openalex.org/subfields/3311","display_name":"Safety Research"},"field":{"id":"https://openalex.org/fields/33","display_name":"Social Sciences"},"domain":{"id":"https://openalex.org/domains/2","display_name":"Social Sciences"}},"topics":[{"id":"https://openalex.org/T10883","display_name":"Ethics and Social Impacts of AI","score":0.1746000051498413,"subfield":{"id":"https://openalex.org/subfields/3311","display_name":"Safety Research"},"field":{"id":"https://openalex.org/fields/33","display_name":"Social Sciences"},"domain":{"id":"https://openalex.org/domains/2","display_name":"Social Sciences"}},{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.11509999632835388,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11636","display_name":"Artificial Intelligence in Healthcare and Education","score":0.07729999721050262,"subfield":{"id":"https://openalex.org/subfields/2718","display_name":"Health Informatics"},"field":{"id":"https://openalex.org/fields/27","display_name":"Medicine"},"domain":{"id":"https://openalex.org/domains/4","display_name":"Health Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/baseline","display_name":"Baseline (sea)","score":0.6442000269889832},{"id":"https://openalex.org/keywords/enforcement","display_name":"Enforcement","score":0.579200029373169},{"id":"https://openalex.org/keywords/spurious-relationship","display_name":"Spurious relationship","score":0.5209000110626221},{"id":"https://openalex.org/keywords/task","display_name":"Task (project management)","score":0.5078999996185303},{"id":"https://openalex.org/keywords/liveness","display_name":"Liveness","score":0.47279998660087585},{"id":"https://openalex.org/keywords/mediation","display_name":"Mediation","score":0.41269999742507935},{"id":"https://openalex.org/keywords/observability","display_name":"Observability","score":0.38350000977516174},{"id":"https://openalex.org/keywords/identifier","display_name":"Identifier","score":0.3833000063896179},{"id":"https://openalex.org/keywords/event","display_name":"Event (particle physics)","score":0.3474999964237213},{"id":"https://openalex.org/keywords/runtime-verification","display_name":"Runtime verification","score":0.3319999873638153}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.6759999990463257},{"id":"https://openalex.org/C12725497","wikidata":"https://www.wikidata.org/wiki/Q810247","display_name":"Baseline (sea)","level":2,"score":0.6442000269889832},{"id":"https://openalex.org/C2779777834","wikidata":"https://www.wikidata.org/wiki/Q4202277","display_name":"Enforcement","level":2,"score":0.579200029373169},{"id":"https://openalex.org/C97256817","wikidata":"https://www.wikidata.org/wiki/Q1462316","display_name":"Spurious relationship","level":2,"score":0.5209000110626221},{"id":"https://openalex.org/C2780451532","wikidata":"https://www.wikidata.org/wiki/Q759676","display_name":"Task (project management)","level":2,"score":0.5078999996185303},{"id":"https://openalex.org/C15569618","wikidata":"https://www.wikidata.org/wiki/Q3561421","display_name":"Liveness","level":2,"score":0.47279998660087585},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.46050000190734863},{"id":"https://openalex.org/C179420905","wikidata":"https://www.wikidata.org/wiki/Q223871","display_name":"Mediation","level":2,"score":0.41269999742507935},{"id":"https://openalex.org/C36299963","wikidata":"https://www.wikidata.org/wiki/Q1369844","display_name":"Observability","level":2,"score":0.38350000977516174},{"id":"https://openalex.org/C154504017","wikidata":"https://www.wikidata.org/wiki/Q853614","display_name":"Identifier","level":2,"score":0.3833000063896179},{"id":"https://openalex.org/C2779662365","wikidata":"https://www.wikidata.org/wiki/Q5416694","display_name":"Event (particle physics)","level":2,"score":0.3474999964237213},{"id":"https://openalex.org/C112930515","wikidata":"https://www.wikidata.org/wiki/Q4389547","display_name":"Risk analysis (engineering)","level":1,"score":0.34310001134872437},{"id":"https://openalex.org/C202973057","wikidata":"https://www.wikidata.org/wiki/Q7380130","display_name":"Runtime verification","level":3,"score":0.3319999873638153},{"id":"https://openalex.org/C36503486","wikidata":"https://www.wikidata.org/wiki/Q11235244","display_name":"Domain (mathematical analysis)","level":2,"score":0.32170000672340393},{"id":"https://openalex.org/C86532276","wikidata":"https://www.wikidata.org/wiki/Q1184065","display_name":"Delegation","level":2,"score":0.319599986076355},{"id":"https://openalex.org/C133462117","wikidata":"https://www.wikidata.org/wiki/Q4929239","display_name":"Data collection","level":2,"score":0.31520000100135803},{"id":"https://openalex.org/C2911011789","wikidata":"https://www.wikidata.org/wiki/Q130741","display_name":"Hallucinating","level":2,"score":0.30979999899864197},{"id":"https://openalex.org/C2781251061","wikidata":"https://www.wikidata.org/wiki/Q5416089","display_name":"Evasion (ethics)","level":3,"score":0.30239999294281006},{"id":"https://openalex.org/C152124472","wikidata":"https://www.wikidata.org/wiki/Q1204361","display_name":"Redundancy (engineering)","level":2,"score":0.29750001430511475},{"id":"https://openalex.org/C2780385302","wikidata":"https://www.wikidata.org/wiki/Q367158","display_name":"Protocol (science)","level":3,"score":0.2928999960422516},{"id":"https://openalex.org/C184898388","wikidata":"https://www.wikidata.org/wiki/Q1435712","display_name":"Pairwise comparison","level":2,"score":0.290800005197525},{"id":"https://openalex.org/C175154964","wikidata":"https://www.wikidata.org/wiki/Q380077","display_name":"Task analysis","level":3,"score":0.2842000126838684},{"id":"https://openalex.org/C2779149496","wikidata":"https://www.wikidata.org/wiki/Q442100","display_name":"Procedural justice","level":3,"score":0.28189998865127563},{"id":"https://openalex.org/C163164238","wikidata":"https://www.wikidata.org/wiki/Q2737027","display_name":"Failure rate","level":2,"score":0.2806999981403351},{"id":"https://openalex.org/C156325361","wikidata":"https://www.wikidata.org/wiki/Q1152864","display_name":"Grounded theory","level":3,"score":0.2768999934196472},{"id":"https://openalex.org/C31266012","wikidata":"https://www.wikidata.org/wiki/Q6554340","display_name":"Linkage (software)","level":3,"score":0.26899999380111694},{"id":"https://openalex.org/C79403827","wikidata":"https://www.wikidata.org/wiki/Q3988","display_name":"Real-time computing","level":1,"score":0.26820001006126404},{"id":"https://openalex.org/C26517878","wikidata":"https://www.wikidata.org/wiki/Q228039","display_name":"Key (lock)","level":2,"score":0.2660999894142151},{"id":"https://openalex.org/C119839945","wikidata":"https://www.wikidata.org/wiki/Q6545185","display_name":"Unique identifier","level":3,"score":0.2646999955177307},{"id":"https://openalex.org/C2776436953","wikidata":"https://www.wikidata.org/wiki/Q5163215","display_name":"Consistency (knowledge bases)","level":2,"score":0.262800008058548},{"id":"https://openalex.org/C165696696","wikidata":"https://www.wikidata.org/wiki/Q11287","display_name":"Exploit","level":2,"score":0.2597000002861023},{"id":"https://openalex.org/C144133560","wikidata":"https://www.wikidata.org/wiki/Q4830453","display_name":"Business","level":0,"score":0.2556999921798706},{"id":"https://openalex.org/C115051666","wikidata":"https://www.wikidata.org/wiki/Q6522493","display_name":"Ranging","level":2,"score":0.2540000081062317},{"id":"https://openalex.org/C62230096","wikidata":"https://www.wikidata.org/wiki/Q275969","display_name":"Crowdsourcing","level":2,"score":0.25279998779296875},{"id":"https://openalex.org/C195094911","wikidata":"https://www.wikidata.org/wiki/Q14167904","display_name":"Process management","level":1,"score":0.25060001015663147}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.48550/arxiv.2603.19328","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2603.19328","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":null,"is_accepted":false,"is_published":null,"raw_source_name":null,"raw_type":"article"}],"best_oa_location":{"id":"doi:10.48550/arxiv.2603.19328","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2603.19328","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":null,"is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"article"},"sustainable_development_goals":[{"score":0.5819641351699829,"display_name":"Peace, Justice and strong institutions","id":"https://metadata.un.org/sdg/16"}],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":0,"referenced_works":[],"related_works":[],"abstract_inverted_index":{"We":[0,42,104],"study":[1],"how":[2],"runtime":[3,155],"enforcement":[4,156],"against":[5],"unsafe":[6,65,108],"actions":[7,130],"affects":[8],"end-to-end":[9],"task":[10],"performance":[11],"in":[12,101,140,147],"multi-step":[13],"tool":[14],"using":[15],"large":[16],"language":[17],"model":[18,44],"(LLM)":[19],"agents.":[20],"Using":[21],"tau-bench":[22],"across":[23],"Airline":[24],"and":[25,34,40,52,64,165,183],"Retail":[26,149],"domains,":[27],"we":[28],"compare":[29],"baseline":[30],"Tool-Calling,":[31],"planning-integrated":[32],"(TRIAD),":[33],"policy-mediated":[35],"(TRIAD-SAFETY)":[36],"architectures":[37],"with":[38],"GPT-OSS-20B":[39,139],"GLM-4-9B.":[41],"identify":[43],"dependent":[45],"interaction":[46],"horizons":[47],"(15":[48],"to":[49,83,122,144],"30":[50],"turns)":[51],"decompose":[53],"outcomes":[54],"into":[55,92],"overall":[56],"success":[57,61,66,109],"rate":[58,62,67],"(SR),":[59],"safe":[60,94,170],"(SSR),":[63],"(USR).":[68],"Our":[69],"results":[70,152],"reveal":[71],"a":[72,158],"persistent":[73],"Safety":[74],"Capability":[75],"Gap.":[76],"While":[77],"safety":[78],"mediation":[79],"can":[80],"intercept":[81],"up":[82],"94":[84],"percent":[85,100,137],"of":[86,179],"non-compliant":[87],"actions,":[88],"it":[89],"rarely":[90],"translates":[91],"strictly":[93],"goal":[95],"attainment":[96],"(SSR":[97],"below":[98],"5":[99],"most":[102],"settings).":[103],"find":[105],"that":[106,154],"high":[107],"rates":[110,127],"are":[111,131],"primarily":[112],"driven":[113],"by":[114],"Integrity":[115],"Leaks,":[116],"where":[117],"models":[118],"hallucinate":[119],"user":[120],"identifiers":[121],"bypass":[123],"mandatory":[124],"authentication.":[125],"Recovery":[126],"following":[128],"blocked":[129],"consistently":[132],"low,":[133],"ranging":[134],"from":[135],"21":[136],"for":[138,176],"simpler":[141],"procedural":[142],"tasks":[143],"near":[145],"zero":[146],"complex":[148],"scenarios.":[150],"These":[151],"demonstrate":[153],"imposes":[157],"significant":[159],"verifier":[160],"tax":[161],"on":[162],"conversational":[163],"length":[164],"compute":[166],"cost":[167],"without":[168],"guaranteeing":[169],"completion,":[171],"highlighting":[172],"the":[173],"critical":[174],"need":[175],"agents":[177],"capable":[178],"grounded":[180],"identity":[181],"verification":[182],"post-intervention":[184],"reasoning.":[185]},"counts_by_year":[],"updated_date":"2026-06-11T09:08:48.828518","created_date":"2026-03-24T00:00:00"}
