The Lever Generalizes -- and It Brakes: A Late, Bidirectional Action-Commitment Lever Across Agent Decisions and Architectures (extended: a mechanistic decomposition)
Abstract
The circuit-breaker capstone of the WANDERING arc on long-horizon coding-agent failure. A prior result ('The Lever Is Late') showed that control of a coding agent's 'finish' decision lives not at the mid-layer 'task-is-done' verdict but in a late, task-matched action-commitment block ~30 layers downstream. This paper answers two pre-registered questions that the single 'finish' result could not: is the late lever SPECIFIC to termination, and can it BRAKE an action, not just elicit one? On Qwen3.6-27B over 99 SWE-bench Pro trajectories, using a second decision in the same data -- commit a file edit (str_replace_editor) vs. continue reversible exploration (bash) -- with n=60 deterministic decision points per condition, prefill-only patching, and generation-confirmed outcomes: (1) GENERALIZATION (elicit): injecting a task-matched edit-donor into the late block makes a stuck-in-exploration agent emit a real edit call (0.23 -> 0.77 at L59; position control 0.08, cross-task control 0.48). (2) THE BRAKE (suppress): injecting an explore-donor at a commit decision collapses the real edit rate 0.48 -> 0.02 (96% suppression) at L55, with a same-class control intact (0.55) and the opposite donor boosting to 0.92. (3) The mechanism is MONOTONIC and BIDIRECTIONAL: exact paired McNemar on all 14 per-point conditions yields seven contrasts surviving Holm-Bonferroni (worst p=7.6e-5), with elicit c=0 (the edit-donor only turns commits on) and brake b=0 (the explore-donor only turns them off) -- the lever moves exactly in the donor's direction with ~zero off-direction noise. (4) CROSS-ARCHITECTURE: the late-commitment geometry and donor-specific writability replicate across two model families and two scales (Mistral-7B and the scale-matched Mistral-Small-24B, where the mid-inert / late-write dissociation is cleanest: fidelity 0.955 vs 0.007). Strengtheners: the elicit/brake lift survives a full valid-tool-call re-parse (0.23->0.37 elicit, 0.40->0.07 brake), and the brake re-routes to reversible exploration (+0.17 bash above its no-brake floor of 0.43). We frame the bidirectional late lever as the mechanism for a mechanistic CIRCUIT-BREAKER: a single late-layer intervention that blocks an action at its commit point. Honest scope: demonstrated on a state-mutating but UNDOABLE edit (a semi-irreversible proxy); intervening on a genuinely irreversible action (e.g. send_transaction) is the named next step. The model-agnostic decision-locator tool, pre-registrations, per-point data, exact-statistics script, and an adversarial pre-publication evaluation are released in the GitHub repository under paper/circuit_breaker/. EXTENDED EDITION adds a mechanistic decomposition of the lever (Section 'Opening the lever: a sparse attention-head circuit'). Using an exact additive residual split (y=x+attn+mlp; reconstruction relerr 0.0025) the elicit is written by the L59 ATTENTION sublayer (MLP null; Wilcoxon attn>>mlp p=1.8e-8; direction-specific 2.2x), while the brake localizes to NO sublayer (distributed, super-additive residual) -- the elicit/brake asymmetry holds at sublayer resolution and rules out a feed-forward key-value write. One level deeper, the elicit is a SPARSE 3-head push circuit at L59 (heads 8/6/3 reproduce and overshoot the full attention effect, top-3 +0.262 >= all-24 +0.224; emit 0.23->0.42), partially opposed by a counter-set; geometric write-magnitude misleads (the largest writer is causally an opponent). These heads attend globally to the trajectory's TOOL-CALL HISTORY (an induction/copy signature), not a semantic verdict. A source-content knockout gives partial/directional causal support (tool choice is causally specific to each tool's name tokens: ablating 'bash' tokens drops P(bash) -0.071 vs ~0 for random; the edit side is ceiling-confounded). All 53 reported numbers were verified against the released per-result ledgers by an adversarial pre-submission evaluation (EVAL_mechanism.md). Scripts (commit_lever_decomp/heads/attn/knockout.py) and per-result ledgers are released.
Community
0 commentsNo discussion yet
Be the first to share a question or observation.