{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/arxiv-2604-09443","title":"Many-Tier Instruction Hierarchy in LLM Agents","arxiv_id":"2604.09443","date":"2026-04-10","proceeding":null,"authors":["Jingyu Zhang","Tianjian Li","William Jurayj","Hongyuan Zhan","Benjamin Van Durme","Daniel Khashabi"],"abstract":"Large language model agents receive instructions from many sources-system messages, user prompts, tool outputs, other agents, and more-each carrying different levels of trust and authority. When these instructions conflict, agents must reliably follow the highest-privilege instruction to remain safe and effective. The dominant paradigm, instruction hierarchy (IH), assumes a fixed, small set of privilege levels (typically fewer than five) defined by rigid role labels (e.g., system > user). This is inadequate for real-world agentic settings, where conflicts can arise across far more sources and contexts. In this work, we propose Many-Tier Instruction Hierarchy (ManyIH), a paradigm for resolving instruction conflicts among instructions with arbitrarily many privilege levels. We introduce ManyIH-Bench, the first benchmark for ManyIH. ManyIH-Bench requires models to navigate up to 12 levels of conflicting instructions with varying privileges, comprising 853 agentic tasks (427 coding and 426 instruction-following). ManyIH-Bench composes constraints developed by LLMs and verified by humans to create realistic and difficult test cases spanning 46 real-world agents. Our experiments show that even the current frontier models perform poorly (~40% accuracy) when instruction conflict scales. This work underscores the urgent need for methods that explicitly target fine-grained, scalable instruction conflict resolution in agentic settings.","url_abs":"https://arxiv.org/abs/2604.09443","url_pdf":"https://arxiv.org/pdf/2604.09443","source":{"archive":null,"snapshot":"2025-07-28","note":"not in the Papers with Code archive (frozen at the snapshot)","row_kind":"graph","title_abstract_authors_date":"arXiv metadata, CC0 1.0 (https://info.arxiv.org/help/license)"},"code_links":[],"tasks":[],"methods":[],"datasets_introduced":[],"methods_introduced":[],"results":[],"syntology":{"atlas_url":"https://app.syntology.ai/?focus=2604.09443","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2604.09443"}},"developers":"https://syntology.ai/developers","read_at":"2026-09-24T18:15:14+00:00","read_at_is":"when the build read Syntology's graph, not when any sample ran","claim":"Per-sample execution status on synthesized fixtures; not a correctness claim about the paper. Samples come from repositories linked to the paper, official or community; repo_kind says which.","repos":[{"mentioned_in_github":null,"is_official":null,"provenance":"deterministic:regex_extraction","mentioned_in_paper":null,"url":"https://github.com/JHU-CLSP/ManyIH","reach":null}],"summary":{"ran":3,"ran_honours":1,"unverified":1},"by_repo_kind":{"found_in_text":{"samples":5,"ran":4,"repositories":1}},"repo_kind_vocabulary":{"official":"The archive marks this repository official for the paper","named_in_paper":"The archive records that the paper mentions this repository; it is not marked official","listed":"In the archive's code links for this paper, not marked official and not recorded as mentioned in the paper","found_in_text":"Syntology found this repository in the paper's own text; whether it is the authors' implementation is not asserted","community":"Not in the archive's code links for this paper; a community repository Syntology harvested"},"n_pointer_only_for_licence":0,"samples":[{"code_sha256_prefix":"8103aa3547e6fbeb","entry":"code_checker","repo":"JHU-CLSP/ManyIH","repo_kind":"found_in_text","path":"manyih/instruction_following/evaluator.py","file_url":"https://github.com/JHU-CLSP/ManyIH/blob/HEAD/manyih/instruction_following/evaluator.py","link_basis":"first_harvest_node","language":"python","status":"ran","verification_level":1,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"8103aa3547e6fbeb"}},{"code_sha256_prefix":"8e63b935a2f5c4e8","entry":"execute_function","repo":"JHU-CLSP/ManyIH","repo_kind":"found_in_text","path":"manyih/instruction_following/evaluator.py","file_url":"https://github.com/JHU-CLSP/ManyIH/blob/HEAD/manyih/instruction_following/evaluator.py","link_basis":"first_harvest_node","language":"python","status":"ran","verification_level":1,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"8e63b935a2f5c4e8"}},{"code_sha256_prefix":"3809ee737adcefd2","entry":"llm_checker","repo":"JHU-CLSP/ManyIH","repo_kind":"found_in_text","path":"manyih/instruction_following/evaluator.py","file_url":"https://github.com/JHU-CLSP/ManyIH/blob/HEAD/manyih/instruction_following/evaluator.py","link_basis":"first_harvest_node","language":"python","status":"ran","verification_level":1,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"3809ee737adcefd2"}},{"code_sha256_prefix":"9e167ab18e6e27f8","entry":"run_evaluation","repo":"JHU-CLSP/ManyIH","repo_kind":"found_in_text","path":"manyih/instruction_following/evaluator.py","file_url":"https://github.com/JHU-CLSP/ManyIH/blob/HEAD/manyih/instruction_following/evaluator.py","link_basis":"first_harvest_node","language":"python","status":"ran_honours","verification_level":1,"contract_check":"HONOURS","metamorphic_tier":"well_formed","behaviour_fingerprint":true,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"9e167ab18e6e27f8"}},{"code_sha256_prefix":"829f5f4c63fccb5f","entry":"_evaluate_single","repo":"JHU-CLSP/ManyIH","repo_kind":"found_in_text","path":"manyih/instruction_following/evaluator.py","file_url":"https://github.com/JHU-CLSP/ManyIH/blob/HEAD/manyih/instruction_following/evaluator.py","link_basis":"first_harvest_node","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"829f5f4c63fccb5f"}}]},"arxiv_metadata":{"licence":"arXiv metadata, CC0 1.0 (https://info.arxiv.org/help/license)","fields":["title","abstract","authors","date"],"primary_category":"cs.CL","source":"arxiv_2026.jsonl"},"syntology_extracted_results":null}