E.Yu. Bolshakov1
1 Russian Biotechnological University (ROSBIOTECH) (Moscow, Russia)
1 emil.bolshakov@mgupp.ru
Large language models (LLMs) can accelerate the preparation of entities, relations, roles and automation rules for information and analytical management systems (IAMSs). Their probabilistic output, however, may contain invalid references, unauthorized tool calls, unsafe network destinations or a plan based on an obsolete schema version. A metaresource is a typed description of a domain object from which software components are produced. Interfaces that constrain tool-call parameters by type do not by themselves preserve domain consistency rules or prevent a partially published registry version.
The purpose of the article is to improve the safety and reliability of metaresource changes in information and analytical management systems that use large language models by separating probabilistic LLM proposals from deterministic server-side decisions on plan admissibility and execution.
A metaresource is represented by typed structural, behavioral, access, presentation and integration components. The generated plan is defined as an ordered sequence of calls over a closed tool catalogue. The method validates argument types, references, symbolic dependencies, permissions, organization data boundaries, network restrictions, version freshness and consistency rules. A three-level policy distinguishes automatically admissible, confirmation-required and blocked plans. Local changes are committed transactionally, whereas external effects are processed through a separate compensating mechanism. In a reproducible corpus of 120 plans, the full method detected all 80 controlled violations and did not falsely reject any of the 40 valid plans. Syntactic and typed-semantic baselines detected 12,5% and 37,5% of violations, respectively. The original registry state has been preserved in all 120 injected-failure trials; 40 valid packages have been committed, 40 stale plans have been rejected, and all 120 inspected audit records contained the required trace fields.
The method can be used in enterprise system constructors in which an LLM prepares a change while authorization, schema consistency, network boundaries, publication and auditability remain under deterministic server control. The experiment evaluates the control layer rather than the quality of a particular LLM, which makes the reported verification results independently reproducible.
Bolshakov E.Yu. Method for controlled formation and deterministic verification of metaresources of information and analytical management system using large language models // Neurocomputers. 2026. V. 28. № 4. P. 34–46. DOI: https://doi.org/10.18127/j19998554-202604-03
- Skryl' S.V., Terekhov V.I., Goryachkin B.S., Myshenkov K.S. Polnota i svoevremennost' informatsionnogo vzaimodejstviya v ASOI kak ob''ektivnaya kharakteristika effektivnosti kognitivnoj deyatel'nosti v takoj sisteme. Dinamika slozhnykh sistem. 2026. T. 20. № 2. S. 5–13. DOI: 10.18127/j19997493-202602-01. (in Russian)
- Antsifrov N.S., Myshenkov K.S. Evaluation of software lifecycle models based on project parameter metrics. International Conference on Integrated Intelligence and Cognitive Engineering (ICIICE). United Arab Emirates, Dubai. 2026. P. 1–6. DOI: 10.1109/ICIICE69672. 2026.11565157.
- Schick T., Dwivedi-Yu J., Dess R. et al. Toolformer: Language models can teach themselves to use tools. Advances in Neural Information Processing Systems. 2023. V. 36. URL: https://arxiv.org/abs/2302.04761 (data obrashcheniya: 15.07.2026).
- Yao S., Zhao J., Yu D. et al. ReAct: Synergizing reasoning and acting in language models. International Conference on Learning Representations. 2023. URL: https://arxiv.org/abs/2210.03629 (data obrashcheniya: 15.07.2026).
- Ruan Y., Dong H., Wang A. et al. Identifying the risks of LM agents with an LM-emulated sandbox. International Conference on Learning Representations. 2024. URL: https://openreview.net/forum?id=GEcwtMk1uA (data obrashcheniya: 15.07.2026).
- Yao S., Shinn N., Razavi P. et al. -bench: A benchmark for tool-agent-user interaction in real-world domains. arXiv:2406.12045. 2024. URL: https://arxiv.org/abs/2406.12045 (data obrashcheniya: 15.07.2026).
- Yuan T., He Z., Dong K. et al. R-Judge: Benchmarking safety risk awareness for LLM agents. arXiv:2401.10019. 2024. URL: https://arxiv.org/ abs/2401.10019 (data obrashcheniya: 15.07.2026).
- Xiang Z., Zheng L., Li Y. et al. GuardAgent: Safeguard LLM agents by a guard agent via knowledge-enabled reasoning. arXiv:2406.09187. 2024. URL: https://arxiv.org/abs/2406.09187 (data obrashcheniya: 15.07.2026).
- Wang H., Poskitt C.M., Sun J. AgentSpec: Customizable runtime enforcement for safe and reliable LLM agents. arXiv:2503.18666. 2025. URL: https://arxiv.org/abs/2503.18666 (data obrashcheniya: 15.07.2026).
- Greshake K., Abdelnabi S., Mishra S. et al. Not what you've signed up for: Compromising real-world LLM-integrated applications with indirect prompt injection. arXiv:2302.12173. 2023. URL: https://arxiv.org/abs/2302.12173 (data obrashcheniya: 15.07.2026).
- National Institute of Standards and Technology. Artificial intelligence risk management framework (AI RMF 1.0). NIST AI 100-1. Gaithersburg. 2023. DOI: 10.6028/NIST.AI.100-1.
- National Institute of Standards and Technology. Artificial intelligence risk management framework: Generative artificial intelligence profile. NIST AI 600-1. Gaithersburg. 2024. DOI: 10.6028/NIST.AI.600-1.
- OWASP Foundation. OWASP Top 10 for LLM Applications 2025. URL: https://genai.owasp.org/llm-top-10/ (data obrashcheniya: 15.07.2026).
- OWASP Foundation. OWASP API Security Top 10 – 2023. URL: https://owasp.org/API-Security/ (data obrashcheniya: 15.07.2026).
- ISO/IEC 42001:2023. Information technology – Artificial intelligence – Management system. Geneva: ISO. 2023.
- ISO/IEC/IEEE 29148:2018. Systems and software engineering – Life cycle processes – Requirements engineering. Geneva: ISO. 2018.
- OpenAPI Initiative. OpenAPI specification. Version 3.1.1. 2024. URL: https://spec.openapis.org/oas/v3.1.1.html (data obrashcheniya: 15.07.2026).
- Object management group. Object constraint language. Version 2.4. 2014. URL: https://www.omg.org/spec/OCL/2.4/ (data obrashcheniya: 15.07.2026).
- Bézivin J. On the unification power of models. Software and Systems Modeling. 2005. V. 4. P. 171–188. DOI: 10.1007/s10270-005-0079-0.
- Schmidt D.C. Model-driven engineering. Computer. 2006. V. 39. № 2. P. 25–31. DOI: 10.1109/MC.2006.58.
- Bol'shakov E.Yu., Novitskij V.O. Avtomatizirovannaya razrabotka programmnogo obespecheniya dlya sozdaniya bekend-veb-serverov. Dinamika slozhnykh sistem – XXI vek. 2025. T. 19. № 3. S. 58–66. DOI: 10.18127/j19997493-202503-06. (in Russian)
- Bol'shakov E.Yu., Novitskij V.O. Integratsiya ontologicheskikh modelej i biznes-protsessov v informatsionno-analiticheskoj sisteme predpriyatiya. Dinamika slozhnykh sistem – XXI vek. 2026. T. 20. № 3. S. 28–39. DOI: 10.18127/j19997493-202603-03. (in Russian)

