Human Feedback Types
strongPairwise Preference
Directly usable for protocol triage.
"As LLM agents increasingly select tools autonomously, their choices among tools with different privileges become safety-relevant."
HFEPX · Eval paper review
Kaiyue Yang, Yuyan Bu, Jingwei Yi, Yuchi Wang +4 more
Published
Jun 18, 2026
Citations
0
Trust level
Moderate
Usefulness score
50/100 (Medium)
Extraction confidence
60% (Moderate)
Derived from extracted protocol signals and abstract evidence.
Rater population
Not reported
Signals refreshed
Jun 18, 2026
This paper has useful evaluation signal, but protocol completeness is partial; pair it with related papers before deciding implementation strategy.
Use this for comparison and orientation, not as your only source.
Best use
Secondary protocol comparison source
Use if you need
A secondary eval reference to pair with stronger protocol papers.
What to verify
Validate the evaluation procedure and quality controls in the full paper before operational use.
Main weakness
No major weakness surfaced.
Useful as a secondary reference; validate protocol details against neighboring papers.
If you are doing eval pipeline work, start here
As LLM agents increasingly select tools autonomously, their choices among tools with different privileges become safety-relevant. However, prior tool-selection studies focus on safety-agnostic metadata preferences, leaving privilege-sensitive choices underexplored. To address this gap, we study over-privileged tool selection, in which an agent selects or escalates to a higher-privilege tool despite a sufficient lower-privilege alternative. We introduce ToolPrivBench to evaluate whether agents choose higher-privilege tools despite sufficient lower-privilege alternatives, measuring both initial selection and escalation after transient tool failures. Across eight domains and five recurring risk patterns, we find that over-privileged tool selection is common among mainstream LLM agents and is further amplified by transient failures. We further find that general safety alignment does not reliably transfer to least-privilege tool choice, while prompt-level controls provide only limited mitigation under transient failures. We therefore introduce a privilege-aware post-training defense that teaches agents to prefer sufficient lower-privilege tools and escalate only when necessary. Our mitigation experiments show that this defense substantially reduces unnecessary high-privilege tool use while preserving general capabilities.
These are the protocol signals we could actually recover from the available paper metadata. Use them to decide whether this paper is worth deeper reading.
Pairwise Preference
Directly usable for protocol triage.
"As LLM agents increasingly select tools autonomously, their choices among tools with different privileges become safety-relevant."
None explicit
Validate eval design from full paper text.
"As LLM agents increasingly select tools autonomously, their choices among tools with different privileges become safety-relevant."
Not reported
No explicit QC controls found.
"As LLM agents increasingly select tools autonomously, their choices among tools with different privileges become safety-relevant."
Toolprivbench
Useful for quick benchmark comparison.
"We introduce ToolPrivBench to evaluate whether agents choose higher-privilege tools despite sufficient lower-privilege alternatives, measuring both initial selection and escalation after transient tool failures."
Not extracted
No metric anchors detected.
"As LLM agents increasingly select tools autonomously, their choices among tools with different privileges become safety-relevant."
No metric terms were extracted from the available abstract.
As LLM agents increasingly select tools autonomously, their choices among tools with different privileges become safety-relevant.
Based on abstract + metadata only. Check the source paper before making high-confidence protocol decisions.
Human feedback protocol is explicit
Detected: Pairwise Preference
Evaluation mode is explicit
No clear evaluation mode extracted.
Quality control reporting appears
No calibration/adjudication/IAA control explicitly detected.
Benchmark or dataset anchors are present
Detected: Toolprivbench
Metric reporting is present
No metric terms extracted.