{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,17]],"date-time":"2026-07-17T11:06:53Z","timestamp":1784286413108,"version":"3.55.0"},"publisher-location":"Cham","reference-count":42,"publisher":"Springer Nature Switzerland","isbn-type":[{"value":"9783032323569","type":"print"},{"value":"9783032323576","type":"electronic"}],"license":[{"start":{"date-parts":[[2026,7,18]],"date-time":"2026-07-18T00:00:00Z","timestamp":1784332800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2026,7,18]],"date-time":"2026-07-18T00:00:00Z","timestamp":1784332800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2027]]},"DOI":"10.1007\/978-3-032-32357-6_7","type":"book-chapter","created":{"date-parts":[[2026,7,17]],"date-time":"2026-07-17T10:35:13Z","timestamp":1784284513000},"page":"145-166","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Temporal Guardrails for\u00a0LLM Conversations: A Runtime Verification Framework"],"prefix":"10.1007","author":[{"given":"Itay","family":"Cohen","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Klaus","family":"Havelund","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Moran","family":"Omer","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Doron","family":"Peled","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2026,7,18]]},"reference":[{"key":"7_CR1","doi-asserted-by":"publisher","unstructured":"Bai, Y., et\u00a0al.: Constitutional ai: Harmlessness from ai feedback. arXiv preprint arXiv:2212.08073 (2022). https:\/\/doi.org\/10.48550\/arXiv.2212.08073","DOI":"10.48550\/arXiv.2212.08073"},{"key":"7_CR2","doi-asserted-by":"publisher","unstructured":"Bartocci, E., Falcone, Y. (eds.): Lectures on Runtime Verification. LNCS, vol. 10457. Springer, Cham (2018). https:\/\/doi.org\/10.1007\/978-3-319-75632-5","DOI":"10.1007\/978-3-319-75632-5"},{"key":"7_CR3","doi-asserted-by":"publisher","unstructured":"Bowman, S.R., Angeli, G., Potts, C., Manning, C.D.: A large annotated corpus for learning natural language inference. In: Proceedings of the 2015 Conference on Empirical Methods in Natural Language Processing (EMNLP), pp. 632\u2013642 (2015). https:\/\/doi.org\/10.18653\/v1\/D15-1075","DOI":"10.18653\/v1\/D15-1075"},{"key":"7_CR4","doi-asserted-by":"publisher","unstructured":"Carbonell, J., Goldstein, J.: The use of MMR, diversity-based reranking for reordering documents and producing summaries. In: Proceedings of the 21st Annual International ACM SIGIR Conference on Research and Development in Information Retrieval, pp. 335\u2013336 (1998). https:\/\/doi.org\/10.1145\/290941.291025","DOI":"10.1145\/290941.291025"},{"key":"7_CR5","unstructured":"Cohen, I., Omer, M., Peled, D.: LLMrv: Runtime verification framework for LLM conversations. https:\/\/github.com\/moraneus\/LLMrv (2026), source code, datasets, and experiment logs"},{"key":"7_CR6","doi-asserted-by":"publisher","unstructured":"Cohen, I., Peled, D.: End-to-end AI generated runtime verification from natural language specification. In: Bridging the Gap Between AI and Reality (AISoLA 2023 Selected Papers. LNCS, vol. 14129, pp. 362\u2013384. Springer (2025). https:\/\/doi.org\/10.1007\/978-3-031-73741-1_23","DOI":"10.1007\/978-3-031-73741-1_23"},{"issue":"1","key":"7_CR7","doi-asserted-by":"publisher","first-page":"21","DOI":"10.1109\/TIT.1967.1053964","volume":"13","author":"T Cover","year":"1967","unstructured":"Cover, T., Hart, P.: Nearest neighbor pattern classification. IEEE Trans. Inf. Theory 13(1), 21\u201327 (1967). https:\/\/doi.org\/10.1109\/TIT.1967.1053964","journal-title":"IEEE Trans. Inf. Theory"},{"key":"7_CR8","doi-asserted-by":"crossref","unstructured":"Davidson, T., Warmsley, D., Macy, M., Weber, I.: Automated hate speech detection and the problem of offensive language. In: ICWSM (2017)","DOI":"10.1609\/icwsm.v11i1.14955"},{"key":"7_CR9","doi-asserted-by":"publisher","unstructured":"Eisner, C., Fisman, D., Havlicek, J., Lustig, Y., McIsaac, A., Van Campenhout, D.: Reasoning with temporal logic on truncated paths. In: Hunt, W.A., Somenzi, F. (eds.) CAV 2003. LNCS, vol. 2725, pp. 27\u201339. Springer, Heidelberg (2003). https:\/\/doi.org\/10.1007\/978-3-540-45069-6_3","DOI":"10.1007\/978-3-540-45069-6_3"},{"key":"7_CR10","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"89","DOI":"10.1007\/978-3-642-16612-9_9","volume-title":"Runtime Verification","author":"Y Falcone","year":"2010","unstructured":"Falcone, Y.: You should better enforce than verify. In: Barringer, H., et al. (eds.) RV 2010. LNCS, vol. 6418, pp. 89\u2013105. Springer, Heidelberg (2010). https:\/\/doi.org\/10.1007\/978-3-642-16612-9_9"},{"key":"7_CR11","doi-asserted-by":"publisher","unstructured":"Gatti, A., Ferrando, A., Mascardi, V.: RV4Rasa: a formalism-agnostic runtime verification framework for verifying ChatBots in Rasa. In: Proceedings of VORTEX (2023). https:\/\/doi.org\/10.1145\/3605159.3605855","DOI":"10.1145\/3605159.3605855"},{"key":"7_CR12","doi-asserted-by":"crossref","unstructured":"Gatti, A., Mascardi, V., Ferrando, A.: RV4Chatbot: are chatbots allowed to dream of electric sheep?, arXiv preprint arXiv:2411.14368 (2024)","DOI":"10.4204\/EPTCS.411.5"},{"key":"7_CR13","unstructured":"Google Jigsaw: Perspective api (2017). https:\/\/perspectiveapi.com"},{"key":"7_CR14","doi-asserted-by":"crossref","unstructured":"Havelund, K., Peled, D., Ulus, D.: First order temporal logic monitoring with bdds. In: Stewart, D., Weissenbacher, G. (eds.) 2017 Formal Methods in Computer Aided Design, FMCAD 2017, Vienna, Austria, 2-6 October 2017, pp. 116\u2013123. IEEE (2017)","DOI":"10.23919\/FMCAD.2017.8102249"},{"key":"7_CR15","doi-asserted-by":"publisher","unstructured":"Havelund, K., Ro\u015fu, G.: Synthesizing monitors for safety properties. In: Katoen, J.-P., Stevens, P. (eds.) TACAS 2002. LNCS, vol. 2280, pp. 342\u2013356. Springer, Heidelberg (2002). https:\/\/doi.org\/10.1007\/3-540-46002-0_24","DOI":"10.1007\/3-540-46002-0_24"},{"issue":"2","key":"7_CR16","doi-asserted-by":"publisher","first-page":"158","DOI":"10.1007\/s10009-004-0143-7","volume":"6","author":"K Havelund","year":"2004","unstructured":"Havelund, K., Rosu, G.: Efficient monitoring of safety properties. Int. J. Softw. Tools Technol. Transfer 6(2), 158\u2013173 (2004). https:\/\/doi.org\/10.1007\/s10009-004-0143-7","journal-title":"Int. J. Softw. Tools Technol. Transfer"},{"key":"7_CR17","doi-asserted-by":"publisher","unstructured":"He, P., Gao, J., Chen, W.: Debertav3: Improving deberta using electra-style pre-training with gradient-disentangled embedding sharing. arXiv preprint arXiv:2111.09543 (2021). https:\/\/doi.org\/10.48550\/arXiv.2111.09543","DOI":"10.48550\/arXiv.2111.09543"},{"key":"7_CR18","unstructured":"Inan, H., Upasani, K., Chi, J.: Llama guard: Llm-based input-output safeguard for human-ai conversations, arXiv preprint arXiv:2312.06674 (2023)"},{"issue":"5","key":"7_CR19","doi-asserted-by":"publisher","first-page":"293","DOI":"10.1016\/j.jlap.2008.08.004","volume":"78","author":"M Leucker","year":"2009","unstructured":"Leucker, M., Schallhart, C.: A brief account of runtime verification. J. Logic Algebraic Program. 78(5), 293\u2013303 (2009). https:\/\/doi.org\/10.1016\/j.jlap.2008.08.004","journal-title":"J. Logic Algebraic Program."},{"key":"7_CR20","unstructured":"Li, H.: Multi-turn jailbreak attacks on large language models, arXiv preprint arXiv:2310.01810 (2023)"},{"key":"7_CR21","doi-asserted-by":"publisher","DOI":"10.1109\/LRA.2025.3577444","author":"Z Li","year":"2026","unstructured":"Li, Z., et al.: Roboguard: safety guardrails for llm-enabled robots. IEEE Robot. Autom. Lett. (2026). https:\/\/doi.org\/10.1109\/LRA.2025.3577444","journal-title":"IEEE Robot. Autom. Lett."},{"key":"7_CR22","doi-asserted-by":"publisher","unstructured":"Lichtenstein, O., Pnueli, A., Zuck, L.: The glory of the past. In: Parikh, R. (ed.) Logic of Programs 1985. LNCS, vol. 193, pp. 196\u2013218. Springer, Heidelberg (1985). https:\/\/doi.org\/10.1007\/3-540-15648-8_16","DOI":"10.1007\/3-540-15648-8_16"},{"key":"7_CR23","doi-asserted-by":"publisher","unstructured":"Manning, C.D., Raghavan, P., Sch\u00fctze, H.: Introduction to Information Retrieval. Cambridge University Press (2008). https:\/\/doi.org\/10.1017\/CBO9780511809071","DOI":"10.1017\/CBO9780511809071"},{"key":"7_CR24","doi-asserted-by":"publisher","unstructured":"Osei, E., et al.: Agent-c: enforcing temporal constraints for llm agents. arXiv preprint arXiv:2503.04562 (2025). https:\/\/doi.org\/10.48550\/arXiv.2503.04562","DOI":"10.48550\/arXiv.2503.04562"},{"key":"7_CR25","doi-asserted-by":"publisher","unstructured":"Ouyang, L., et\u00a0al.: Training language models to follow instructions with human feedback. In: NeurIPS (2022). https:\/\/doi.org\/10.48550\/arXiv.2203.02155","DOI":"10.48550\/arXiv.2203.02155"},{"key":"7_CR26","unstructured":"Perez, F., Ribeiro, I.: Ignore previous prompt: Attack techniques for language models. arXiv preprint arXiv:2211.09527 (2022)"},{"key":"7_CR27","doi-asserted-by":"publisher","unstructured":"Peskine, Y., Koren\u010di\u0107, D., Grubisic, I., Papotti, P., Troncy, R., Rosso, P.: Definitions matter: guiding gpt for multi-label classification. In: Findings of the Association for Computational Linguistics: EMNLP 2023, pp. 4054\u20134063. Association for Computational Linguistics, Singapore (2023). https:\/\/doi.org\/10.18653\/v1\/2023.findings-emnlp.267, https:\/\/aclanthology.org\/2023.findings-emnlp.267\/","DOI":"10.18653\/v1\/2023.findings-emnlp.267"},{"key":"7_CR28","doi-asserted-by":"crossref","unstructured":"Rafailov, R., Sharma, A., Mitchell, E., Manning, C.D., Ermon, S., Finn, C.: Direct preference optimization: Your language model is secretly a reward model. In: Advances in Neural Information Processing Systems (NeurIPS), (2023)","DOI":"10.52202\/075280-2338"},{"key":"7_CR29","doi-asserted-by":"crossref","unstructured":"Rebedea, T., Dinu, R., Sreedhar, M., Parisien, C., Cohen, J.: Nemo guardrails: a toolkit for controllable and safe llm applications with programmable rails, arXiv preprint arXiv:2310.10501 (2023)","DOI":"10.18653\/v1\/2023.emnlp-demo.40"},{"key":"7_CR30","doi-asserted-by":"publisher","unstructured":"Reimers, N., Gurevych, I.: Sentence-bert: sentence embeddings using siamese bert-networks. In: Proceedings of the 2019 Conference on Empirical Methods in Natural Language Processing and the 9th International Joint Conference on Natural Language Processing (EMNLP-IJCNLP), pp. 3980\u20133990 (2019). https:\/\/doi.org\/10.18653\/v1\/D19-1410","DOI":"10.18653\/v1\/D19-1410"},{"key":"7_CR31","unstructured":"Ren, T., Sun, Y., Lu, M., Bian, Y., Lin, C., Yuan, Y.: Agentspec: formal specification and verification framework for large language model based agent. arXiv preprint arXiv:2503.18666 (2025)"},{"key":"7_CR32","doi-asserted-by":"publisher","unstructured":"Schopf, T., Braun, D., Matthes, F.: Evaluating unsupervised text classification: Zero-shot and similarity-based approaches. In: Proceedings of the 2022 6th International Conference on Natural Language Processing and Information Retrieval (NLPIR), pp. 6\u201315. Association for Computing Machinery, Bangkok, Thailand (2023). https:\/\/doi.org\/10.1145\/3582768.3582795","DOI":"10.1145\/3582768.3582795"},{"issue":"4","key":"7_CR33","first-page":"35","volume":"24","author":"A Singhal","year":"2001","unstructured":"Singhal, A.: Modern information retrieval: a brief overview. IEEE Data Eng. Bull. 24(4), 35\u201343 (2001)","journal-title":"IEEE Data Eng. Bull."},{"key":"7_CR34","unstructured":"Wallace, E., Xiao, K., Leike, R., Weng, L., Heidecke, J., Beutel, A.: The instruction hierarchy: Training LLMs to prioritize privileged instructions, arXiv preprint arXiv:2404.13208 (2024)"},{"key":"7_CR35","doi-asserted-by":"publisher","unstructured":"Wang, G., et al.: Joint embedding of words and labels for text classification. In: Proceedings of the 56th Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Papers). pp. 2321\u20132331. Association for Computational Linguistics, Melbourne, Australia (2018). https:\/\/doi.org\/10.18653\/v1\/P18-1216, https:\/\/aclanthology.org\/P18-1216\/","DOI":"10.18653\/v1\/P18-1216"},{"key":"7_CR36","doi-asserted-by":"publisher","unstructured":"Wang, S., et al.: Logidebrief: integrating signal temporal logic and llms for enhanced 9-1-1 dispatch debriefing. In: Proceedings of the 34th International Joint Conference on Artificial Intelligence (IJCAI), pp. 9578\u20139586 (2025). https:\/\/doi.org\/10.24963\/ijcai.2025\/1065","DOI":"10.24963\/ijcai.2025\/1065"},{"key":"7_CR37","doi-asserted-by":"publisher","unstructured":"Wang, Z., Pang, Y., Lin, Y.: Large language models are zero-shot text classifiers. arXiv preprint arXiv:2312.01044 (2023). https:\/\/doi.org\/10.48550\/arXiv.2312.01044","DOI":"10.48550\/arXiv.2312.01044"},{"key":"7_CR38","doi-asserted-by":"publisher","unstructured":"Wei, A., Haghtalab, N., Steinhardt, J.: Jailbroken: How does llm safety training fail? arXiv preprint arXiv:2307.02483 (2023). https:\/\/doi.org\/10.48550\/arXiv.2307.02483","DOI":"10.48550\/arXiv.2307.02483"},{"key":"7_CR39","doi-asserted-by":"publisher","unstructured":"Williams, A., Nangia, N., Bowman, S.R.: A broad-coverage challenge corpus for sentence understanding through inference. In: Proceedings of the 2018 Conference of the North American Chapter of the Association for Computational Linguistics: Human Language Technologies (NAACL-HLT), pp. 1112\u20131122. (2018). https:\/\/doi.org\/10.18653\/v1\/N18-1101","DOI":"10.18653\/v1\/N18-1101"},{"key":"7_CR40","doi-asserted-by":"publisher","unstructured":"Xiao, S., Liu, Z., Zhang, P., Muennighoff, N., Liang, D., Dou, Z.: C-Pack: Packaged resources to advance general Chinese embedding. arXiv preprint arXiv:2309.07597 (2024). https:\/\/doi.org\/10.48550\/arXiv.2309.07597","DOI":"10.48550\/arXiv.2309.07597"},{"key":"7_CR41","doi-asserted-by":"publisher","unstructured":"Yin, W., Hay, J., Roth, D.: Benchmarking zero-shot text classification: datasets, evaluation and entailment approach. In: Proceedings of the 2019 Conference on Empirical Methods in Natural Language Processing and the 9th International Joint Conference on Natural Language Processing (EMNLP-IJCNLP). pp. 3914\u20133923. Association for Computational Linguistics (2019). https:\/\/doi.org\/10.18653\/v1\/D19-1404, https:\/\/aclanthology.org\/D19-1404\/","DOI":"10.18653\/v1\/D19-1404"},{"key":"7_CR42","unstructured":"Zhang, Y., Emma, S.Y., En, A.L.J., Dong, J.S.: Rvllm: LLM runtime verification with domain knowledge. CoRR abs\/ arXiv:2505.18585 (2025)"}],"container-title":["Lecture Notes in Computer Science","AI Verification"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-032-32357-6_7","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,7,17]],"date-time":"2026-07-17T10:35:18Z","timestamp":1784284518000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-032-32357-6_7"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,7,18]]},"ISBN":["9783032323569","9783032323576"],"references-count":42,"URL":"https:\/\/doi.org\/10.1007\/978-3-032-32357-6_7","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,7,18]]},"assertion":[{"value":"18 July 2026","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"SAIV","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Symposium on AI Verification","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Lisbon","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Portugal","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2026","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"24 July 2026","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"25 July 2026","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"3","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"saiv2026","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/aiverification.org\/2026","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}