Research
ACE Corpus Pairs 4,047 Agent Sessions With Kernel Syscall Traces and Finds Kernel Evidence Catches What App Telemetry Misses
arXiv 2609.28915 (King, Zhang, Kuznetsov et al.) argues that agent-security defenses watch only the tool manifest, prompt and model messages, which misses attacks that smuggle actions past the application boundary. Their Agent Cross-Layer Evidence corpus pairs app telemetry with syscall traces across 4,047 sessions and 17 threat models, covering 14 of the 25 OWASP LLM and agentic threat categories. Across four detector families, kernel evidence was discriminative on its own, combining both layers generally beat either one alone, and the detectors held up on unseen attack families and a second agent runtime.
Source
↳ Follow the thread