On the Effectiveness of Kernel-Level Evidence for Agent Security

📅 2026-09-23
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
Existing security defenses for AI agents rely solely on application-layer telemetry, making it difficult to detect cross-boundary or application-invisible malicious behaviors. This work introduces ACE, the first cross-layer evidence-paired corpus that integrates application-layer telemetry with kernel-level system call tracing. It proposes a novel dual-layer evidence-paired representation to reveal complementary signals overlooked by single-layer analysis. The dataset encompasses 4,047 sessions across 17 threat models. Experimental results demonstrate that kernel-level evidence possesses independent discriminative power, and cross-layer fusion significantly outperforms single-view detection. Furthermore, the proposed approach exhibits strong generalization capabilities to unseen attack families and diverse runtime environments.
📝 Abstract
LLM agents are deployed into infrastructure that grants them broad host authority, yet existing agent-security benchmarks and defenses operate almost exclusively at the application telemetry layer: the served tool manifest, the user prompt, and the model's messages. Some threats, however, smuggle malicious instructions and actions past the application boundary, leaving them invisible to that layer. In this work, we bridge that gap by pairing application-level agent telemetry with kernel-level syscall traces to present the first paired-evidence characterization of kernel-level versus application-layer signal for agent security. To quantify the value of the enhanced telemetry, we introduce Agent Cross-Layer Evidence (ACE), a paired-session corpus of 4,047 sessions and 17 threat models spanning six delivery-vector families and 14 of the 25 OWASP LLM and agentic threat categories, organized into 12 attack mechanics with per-mechanic characterization of where the most discriminative evidence lies. Across four distinct detector families, we find that kernel evidence is discriminative on its own and that composing it with application-layer evidence generally outperforms either single-layer view, revealing complementary signals that single-layer analyses can miss. We further demonstrate generalization to unseen attack families and transfer to an alternate agent runtime. Together, these findings establish the value of cross-layer evidence for agent security.
Problem

Research questions and friction points this paper is trying to address.

LLM agent security
kernel-level evidence
application-layer telemetry
cross-layer detection
syscall traces
Innovation

Methods, ideas, or system contributions that make the work stand out.

Kernel-level evidence
Cross-layer telemetry
Agent security
Syscall traces
ACE benchmark