TY - GEN
T1 - Temporal Guardrails for LLM Conversations
T2 - 3rd International Symposium on AI Verification, SAIV 2026
AU - Cohen, Itay
AU - Havelund, Klaus
AU - Omer, Moran
AU - Peled, Doron
N1 - Publisher Copyright: © The Author(s), under exclusive license to Springer Nature Switzerland AG 2027.
PY - 2027
Y1 - 2027
N2 - Large Language Models (LLMs) are increasingly integrated into organizational workflows, raising growing concerns about their potential abuse for fraud, security breaches, or intellectual property leakage. While LLMs embed protective mechanisms and organizations develop their own guardrails, many practical guardrail approaches remain stateless and lack formal temporal semantics, and existing formal methods are often domain-specific or rely on structured event representations. We propose a runtime verification (RV) framework that treats an LLM conversation as an execution trace that can be formally verified and develop a corresponding tool called TemporalGuard. It observes the stream of user messages and LLM-generated assistant responses, grounds each message into a set of atomic propositions, and thereby constructs a Boolean-labeled trace. Safety policies are specified as formulas in past-time linear temporal logic (ptLTL), and the monitor checks the evolving Boolean trace online to decide whether the conversation satisfies the policy. A central challenge is grounding: bridging the gap between the precise Boolean semantics of temporal logic and the ambiguity of natural language utterances. To address this, we developed a semantic grounding layer and experimentally evaluated a range of grounding strategies, including an embedding-based approach, Natural Language Inference (NLI), and LLM-based zero/few-shot classification. We demonstrate the effectiveness of TemporalGuard through grounding and end-to-end monitoring experiments.
AB - Large Language Models (LLMs) are increasingly integrated into organizational workflows, raising growing concerns about their potential abuse for fraud, security breaches, or intellectual property leakage. While LLMs embed protective mechanisms and organizations develop their own guardrails, many practical guardrail approaches remain stateless and lack formal temporal semantics, and existing formal methods are often domain-specific or rely on structured event representations. We propose a runtime verification (RV) framework that treats an LLM conversation as an execution trace that can be formally verified and develop a corresponding tool called TemporalGuard. It observes the stream of user messages and LLM-generated assistant responses, grounds each message into a set of atomic propositions, and thereby constructs a Boolean-labeled trace. Safety policies are specified as formulas in past-time linear temporal logic (ptLTL), and the monitor checks the evolving Boolean trace online to decide whether the conversation satisfies the policy. A central challenge is grounding: bridging the gap between the precise Boolean semantics of temporal logic and the ambiguity of natural language utterances. To address this, we developed a semantic grounding layer and experimentally evaluated a range of grounding strategies, including an embedding-based approach, Natural Language Inference (NLI), and LLM-based zero/few-shot classification. We demonstrate the effectiveness of TemporalGuard through grounding and end-to-end monitoring experiments.
UR - https://www.scopus.com/pages/publications/105046287931
U2 - 10.1007/978-3-032-32357-6_7
DO - 10.1007/978-3-032-32357-6_7
M3 - Conference contribution
SN - 9783032323569
T3 - Lecture Notes in Computer Science
SP - 145
EP - 166
BT - AI Verification - 3rd International Symposium, SAIV 2026, Proceedings
A2 - Avni, Guy
A2 - Schilling, Christian
PB - Springer Science and Business Media Deutschland GmbH
Y2 - 24 July 2026 through 25 July 2026
ER -