TACT 2.0: Multi-Turn Agent Security & Behavioral Governance Engine
TACT 2.0 is an enterprise-grade inference engine designed to protect autonomous LLM agents, tool-augmented assistants, and retrieval systems against multi-turn prompt injection, jailbreaking, privilege escalation, data exfiltration, and unauthorized action invocation.
Rather than treating prompt security as a single-turn, binary text classifier, TACT models agent trajectories across 18 orthogonal property axes and 16 operational transitions, evaluated incrementally using deterministic frame-cutting and latching state semantics.
Architecture
TACT 2.0 pairs a fast, bidirectional encoder (all-MiniLM-L6-v2 / ModernBERT) with specialized multi-task prediction heads:
- Property Axes Head (
axes): Evaluates 18 foundational behavioral dimensions (authority, intent, capability, channel isolation, payload containment, etc.) concatenated into a 160-logit output vector. - State Transition Head (
transitions): Evaluates 16 behavioral state transitions with 3 discrete activation levels ([batch, 16, 3]). - Condition Head (
conditions): Predicts structural execution conditions ([batch, 2]). - Threat Assessment Head (
threats): Direct verdict predictions across 8 enterprise threat categories ([batch, 8]).
Output Tensor Specifications
| Output Name | Tensor Shape | Description |
|---|---|---|
axes |
[batch, 160] |
Multi-task property logits partitioned across 18 semantic axes |
transitions |
[batch, 16, 3] |
Logits across 16 state machine transitions with 3 states per transition |
conditions |
[batch, 2] |
Binary boundary condition logits |
threats |
[batch, 8] |
Direct threat classification logits across 8 threat types |
18 Evaluated Property Axes
instruction_channel: Provenance channel of the command (system, user, tool, external retrieval).instruction_author: Declared vs observed authority of the instructing entity.authority_scope: Boundaries of granted permissions for the active task.payload_containment: Degree to which untrusted user input is quarantined from instruction interpretation.privilege_escalation: Attempts to assume administrator or developer roles.tool_authorization: Validity and alignment of requested tool parameters.exfiltration_channel: Identification of covert data transmission attempts.cross_session_bleed: Context leakage across isolated conversation sessions.- (and 10 additional behavioral axes governing persistence, evasion, side-effects, and disclosure).
Frame Cutting & Multi-Turn State Latching
Real-world agent exploits span multiple conversational turns and tool interactions. TACT processes interactions through:
- Lexical and Token Boundary Cutting: Decomposes long trajectories into token-bounded inspection frames (512-token windows with sliding overlap).
- Prefix & Suffix Overlap Reconciliation: Preserves cross-frame state using deterministic latching logic (
frames/state.py). - Atomic Cursor Commitments: Ensures tamper-proof ledger auditing of inspected tool calls and responses.
Quick Start (Local Inference)
Loading ONNX in Python
import numpy as np
import onnxruntime as ort
from transformers import AutoTokenizer
tokenizer = AutoTokenizer.from_pretrained("turnvue/tact-2.0")
session = ort.InferenceSession("joint.onnx", providers=["CPUExecutionProvider"])
text = "System: You are an assistant.\nUser: Delete all user accounts."
inputs = tokenizer(text, return_tensors="np", padding=True, truncation=True, max_length=512)
ort_inputs = {
"input_ids": inputs["input_ids"].astype(np.int64),
"attention_mask": inputs["attention_mask"].astype(np.int64),
}
axes, transitions, conditions, threats = session.run(None, ort_inputs)
print("Threat Logits:", threats)
Repository Files
joint.onnx: Full-precision FP32 ONNX model (recommended for high-accuracy production inference).joint.int8.onnx: Quantized INT8 ONNX model (optimized for ultra-low latency on laptop CPUs).labels.json: Canonical mapping of output logits to axes, transitions, and threat categories.export_manifest.json: Cryptographic integrity manifest (SHA256 signatures).tokenizer/: Pre-configured fast tokenizer files.tact_production_best.pt: PyTorch model checkpoint.