audit logging

Designing tamper-evident, verifiable logs and audit trails that record actions, provenance, and policy-relevant attributes to enable post-hoc inspection and certification. This includes formats and mechanisms for attaching monotone, auditable metadata to sessions, producing human-understandable explanations, and preserving opaque evidence of origin.

auditlogging

12-Month Skill Trend

Momentum and market value over time
Trending
Score
+20 in 12 mo
96
12 mo agoNow
Career
Value
+$12K in 12 mo
$42K/year
12 mo agoNow

Recommended Survey Paper

Quick overview of the field
View more

Must-Read Papers

Most classic and influential ideas
View more

This work addresses the lack of traceable and tamper-resistant transparency mechanisms in large language models (LLMs) deployed in high-stakes decision-making contexts, which undermines accountability. To bridge this gap, the paper introduces the first LLM lifecycle auditing framework that integrates technical provenance with governance records. It proposes a reference architecture enabling cross-organizational traceability and implements a lightweight, open-source Python-based auditing layer. By leveraging append-only logs, event emitters, structured metadata, and an auditor interface, the system seamlessly integrates into existing LLM workflows with minimal intrusiveness. This design ensures complete, tamper-evident traceability across critical stages—including training, deployment, and monitoring—thereby facilitating robust accountability and responsibility attribution throughout the model’s lifecycle.

accountabilityaudit trailsgovernance

This work addresses the inadequacy of current AI runtime logs in providing the structured evidence necessary for legal fact-finding—such as data boundary violations or human interventions. It formalizes, for the first time, the binary factual requirements of regulatory compliance into a criterion of evidentiary sufficiency for runtime records, mandating that logs explicitly encode the legal category of events and their determinative relationships (e.g., provenance, authorization, temporal validity). By integrating legal ontologies, event-type systems, provenance semantics, and temporal validity constraints—and drawing on the law of requisite variety and the Good Regulator theorem from cybernetics—the approach exposes limitations in tamper-proof logging and generic provenance mechanisms. Validation against selected obligations of the EU AI Act demonstrates that this criterion precisely delineates the boundary between traces and hyperproperties in runtime verification, thereby establishing a verifiable foundation for compliance.

Agentic AIevidentiary adequacylegal findings

Auditable Agents

Apr 07, 2026

This study addresses the critical lack of accountability in large language model (LLM) agents following external actions, which hinders traceability and responsibility attribution. The work introduces the first systematic framework for agent auditability, articulating five core dimensions and proposing an “Auditability Card” to standardize assessment. It further develops a full-lifecycle auditing architecture integrating detection, enforcement, and recovery mechanisms. Leveraging runtime intervention, tamper-proof logging, and log-recovery techniques—validated through ecosystem-wide security evaluations and controlled experiments—the study identifies 617 security flaws across mainstream open-source LLM agent projects. Experimental results demonstrate that a pre-execution mediation layer incurs only 8.3 milliseconds of overhead and that partial reconstruction of accountability-critical information remains feasible even in the absence of complete logs.

accountabilityauditabilityevidence integrity

This work addresses the critical limitation of current deep research agents, whose scientifically fluent outputs often lack auditability—leading to high verification costs, weak evidential chains, and potential misinformation. To remedy this, the study establishes claim-level auditability as a core design principle and introduces the AAR (Auditability, Accuracy, and Reasoning) evaluation framework. It further integrates mechanisms such as semantic provenance graphs, protocolized verification, and queryable evidence graphs to enable real-time evidence tracing, conflict detection, and transparent validation for every generated claim. Experimental results demonstrate that the proposed approach substantially enhances the trustworthiness, verifiability, and auditing efficiency of agent-generated scientific reports.

auditabilityclaim-evidence linkagedeep research agents

Rethinking Tamper-Evident Logging: A High-Performance, Co-Designed Auditing System

Sep 03, 2025
RZ
Rui Zhao
🏛️ University of Virginia | Florida State University

Existing tamper-evident logging systems suffer from high overhead and severe log loss under heavy load, support only coarse-grained tampering detection, and require kernel recompilation. This paper proposes Nitro—the first high-performance, verifiable audit logging system built entirely on eBPF. (1) We establish a formal security definition framework and co-design a lightweight cryptographic mechanism (hash chains + authenticated data structures) with log pre- and post-processing pipelines to enable fine-grained tamper localization and near-zero log loss. (2) We introduce Nitro-R, a variant integrating kernel-space log compression to further reduce overhead. (3) Nitro requires no kernel modifications—neither recompilation nor patching. Evaluation shows Nitro improves throughput by 10–25× under synthetic high-load workloads and by 2–10× in realistic deployments, significantly outperforming state-of-the-art approaches.

Address high overhead and data loss in tamper-evident loggingCo-design cryptographic and system components for optimizationProvide fine-grained tamper detection without kernel recompilation

Latest Papers

What's happening recently
View more

Existing automated approaches for mapping cyber threat intelligence (CTI) to MITRE ATT&CK lack supporting evidence, provenance tracking, and validation history, making their credibility difficult to assess. This work proposes the first knowledge graph–driven framework for CTI governance that enables auditable management of TTP assertions through fine-grained evidence preservation, complete provenance chains, versioned trust decisions, and lossless revocation mechanisms. The framework integrates multi-extractor collaborative verification, assertion aggregation, consensus modeling, and policy-driven validation, all underpinned by versioned knowledge graph management. Evaluated on 65 CTI reports comprising 5,303 sentences, the approach achieves a precision of 90.6% under six-party consensus and efficiently supports seven categories of audit queries concerning provenance, trustworthiness, and versioning.

Cyber Threat IntelligenceMITRE ATT&CKprovenance

Current large language model (LLM) agents lack verifiability, debuggability, and auditability, and relying solely on the accuracy of final answers fails to reveal their underlying reasoning. To address this, this work proposes the first unified provenance framework for LLM agents, systematically modeling causal relationships in tool usage, memory access, and environmental interactions. It introduces a comprehensive provenance taxonomy encompassing source, granularity, representation format, and trust functions. By integrating provenance-aware representation modeling, evidence attribution, runtime safeguards, provenance-informed memory management, and trajectory observability analysis, the study shifts the evaluation paradigm from outcome correctness to process accountability. The framework consolidates existing benchmarks to define a clear pathway for process-level trustworthiness assessment and highlights key challenges, including standardized trajectory schemas, semantic-level provenance, and privacy-preserving auditing.

auditabilityevidence tracingexecution provenance

This work addresses the challenge of ensuring trustworthy AI behavior in high-stakes, heavily regulated environments, where reliance solely on generative models, output safeguards, or post-hoc audits proves insufficient to prevent unacceptable execution trajectories. To this end, the paper introduces the Proposal–Certification–Execution (PCE) framework, which formalizes trajectory permissibility as an explicit safety property requiring prior certification. Central to PCE are the Permissibility Machine and a verifiable certificate mechanism that enforce a “no certificate, no execution” policy, thereby providing pre-execution trust guarantees. Integrating a policy system Π, a language for executable trajectories, proof-carrying execution, and privacy-preserving techniques, the framework establishes a structured pre-execution certification process and advances a new evaluation paradigm centered on certifiably permissible trajectories—shifting trustworthy AI from output monitoring toward pre-execution verification.

certified tracesexecution controlpermissibility

Existing autonomous commercial protocols struggle to achieve interoperable, tamper-proof auditing and event temporal verification across heterogeneous domains. This work proposes a verifiable global event timeline architecture that constructs a reproducible, tamper-resistant AI fraud intelligence training pipeline by formalizing event schemas, employing deterministic batching, leveraging Merkle append-only commitments, and anchoring events to blockchain-based timestamps. The approach innovatively integrates cryptographic fraud markers—binding risk labels with anchored evidence—and a data provenance model to establish a verifiable, traceable, AI-ready intelligence layer. Evaluated on a prototype processing 50,000 events, the system constructs Merkle trees in just 47 milliseconds, achieves end-to-end verification in under 0.013 milliseconds, and exhibits logarithmic proof size growth, yielding a 14.4× improvement in verification efficiency over linear scanning.

agentic commercefraud intelligencetamper-evident auditability

Existing blockchain-based solutions struggle to support log integrity verification for resource-constrained IoT edge devices due to high consensus overhead and strong network dependencies. This work proposes a lightweight, ledger-free tamper-evident verification mechanism that employs a resource-aware adaptive chunking strategy for log batching, combined with a Merkle tree structure and O(log n) inclusion proofs to enable deterministic single-entry verification anchored to a trusted root. Experimental evaluation on 100,000 synthetic IoT log entries demonstrates a throughput exceeding 130,000 entries per second, with per-entry verification and proof generation latency of approximately 22 ms, an average proof size of 1,006 bytes, peak memory usage under 5 MB, and perfect precision, recall, and F1 scores (all 1.0) across tampering rates ranging from 1% to 50%.

audit logsIoT edgelightweight verification

Hot Scholars

ZZ

Zibin Zheng

IEEE Fellow, Highly Cited Researcher, Sun Yat-sen University, China
BlockchainSmart ContractServices ComputingSoftware Reliability
FK

Foutse Khomh

NSERC Arthur B. McDonald Fellow, CRC Tier 1, Canada CIFAR AI Chair, FRQ-IVADO Chair, Full Professor
Software engineeringMachine learning systems engineeringMining software repositoriesReverse
FA

Faruk Alpay

Computer Engineering, Bahçeşehir University
Artificial IntelligenceSymbolic ComputationRecursive SystemsAlpay Algebra
YH

Yintong Huo

Singapore Management University
AI4SEAIOpsLog analysisMLLM for SE
TJ

Tong Jia

Peking University
AIOpsAnomaly DetectionLog AnalysisAI for Medical Research