Planning over Private State: Local–Remote Delegation for Tool-Calling Agents
Ziwen Li ⋅ Tianshi Li
Abstract
Tool-calling agents may expose raw user data to untrusted cloud model providers, while fully local execution can limit access to stronger remote models. We introduce \textbf{DAM-Guard}, a trust-asymmetric architecture that keeps raw tool observations inside a trusted local runtime while allowing a \textbf{Remote} agent to retain workflow planning and tool-use control. A trusted \textbf{Host} replaces private values with stable opaque handles, and a constrained \textbf{Local} agent performs bounded semantic computation over authorized raw observations when requested by the Remote. The Remote therefore plans from protected context without directly observing the underlying private values. We evaluate three Local--Remote delegation protocols and two Remote-context settings on $\tau^2$-bench~\citep{barres2025tau2}. We measure privacy using deterministic verbatim matching and an auditor-based probe of raw-value identifiability. Under the DeepSeek Remote, the best protected configuration matches the observed task-success count of unrestricted Raw execution. Path annotation does not improve task success, but it shortens execution and reduces Remote turns. Across 1,152 protected trajectories, we find no clear case in which Local introduces a previously unseen sensitive raw value beyond candidates already supplied by Remote. In addition, protected execution increases the auditor's probability on the true raw value by only 1.7 percentage points on average, compared with an increase from 37.0\% to 94.8\% under Raw access. These results show that Local-Remote delegation can preserve substantial tool-calling utility while limiting both direct and inferential exposure of private tool state.
Chat is not available.
Successful Page Load