Adapting Agent Architectures under Non-Stationarity with Bounded, Reversible Search
Ali A Alzahrani
Abstract
Long-lived AI agents must adapt as environments, tools and specialist competence change, but adaptation itself creates a new reliability surface: a system can replace a functioning configuration on weak evidence, absorb a compromised component, or optimize an incomplete objective. We study this at the agent-architecture level and introduce Conservative Meta-Agent Search (CMAS), a bounded meta-agent loop for reversible architecture updates under non-stationarity. Foundation-model weights remain fixed. CMAS restricts proposals to compile-checked typed edits over workers, communication, prompts, model assignments, budgets, aggregation and verification, while risk projection, authorization, accounting and data cutoffs stay outside the LLM-editable boundary. Each candidate is compared against the incumbent by paired shadow replay under common random numbers, and CMAS promotes only when an empirically calibrated score clears a pre-specified margin; accepted candidates run in a simulated canary stage and can be rolled back. On MetaInvest-Bench, across 96 controlled streams CMAS reduces normalized mean dynamic-oracle regret from $0.116$ to $0.104$ and raises held-out utility from $0.44$ to $0.48$ relative to the strongest adaptive common-budget reimplementation, while retaining the incumbent on 42% of update decisions. False promotion is 3.4% of updates and 4.8% in a sealed rerun; removing paired evaluation raises it to 6.1% and removing simultaneous correction to 8.4%. Across 576 simulated adversarial and operational incidents, CMAS recovers within three updates in 78% of episodes with rollback precision/recall $0.85/0.80$. A return-only evaluator produces a growing simulated-canary/deployed-configuration utility gap, illustrating objective misspecification despite successful optimization of the measured signal. Scope. These results concern a controlled and replay-based setting: the implemented gate is not a confidence bound, Track C is simulated, and we claim neither production security, sequence-level safety, nor safe open-ended self-improvement.
Chat is not available.
Successful Page Load