论内核级证据对智能体安全性的有效性
On the Effectiveness of Kernel-Level Evidence for Agent Security
- University of Georgia(佐治亚大学)
- Amazon Web Services(亚马逊云科技)
机构由 AI 辅助整理,请以论文原文为准。
AI总结:
本研究通过配对内核级系统调用与应用级遥测,提出ACE语料库,证明跨层证据能提升智能体安全检测性能,并具泛化与迁移能力。
AI中文摘要:
LLM智能体被部署到赋予其广泛主机权限的基础设施中,然而现有的智能体安全基准和防御措施几乎完全在应用遥测层运行:即所服务的工具清单、用户提示和模型的消息。然而,某些威胁会将恶意指令和操作偷偷越过应用边界,使它们在该层不可见。在本工作中,我们通过将应用级智能体遥测与内核级系统调用跟踪配对,弥合了这一差距,首次呈现了针对智能体安全的内核级与应用层信号配对证据表征。为量化增强遥测的价值,我们引入了智能体跨层证据(ACE),这是一个配对会话语料库,包含4,047个会话和17种威胁模型,涵盖六个投递向量家族和OWASP LLM及智能体威胁类别25项中的14项,组织成12种攻击机制,并针对每种机制刻画了最具判别力的证据所在位置。在四个不同的检测器家族中,我们发现内核证据本身具有判别力,且将其与应用层证据组合通常优于任一单层视图,揭示了单层分析可能遗漏的互补信号。我们进一步证明了对未见攻击家族的泛化能力以及向替代智能体运行时的迁移能力。综上所述,这些发现确立了跨层证据对智能体安全性的价值。
英文摘要:
LLM agents are deployed into infrastructure that grants them broad host authority, yet existing agent-security benchmarks and defenses operate almost exclusively at the application telemetry layer: the served tool manifest, the user prompt, and the model's messages. Some threats, however, smuggle malicious instructions and actions past the application boundary, leaving them invisible to that layer. In this work, we bridge that gap by pairing application-level agent telemetry with kernel-level syscall traces to present the first paired-evidence characterization of kernel-level versus application-layer signal for agent security. To quantify the value of the enhanced telemetry, we introduce Agent Cross-Layer Evidence (ACE), a paired-session corpus of 4,047 sessions and 17 threat models spanning six delivery-vector families and 14 of the 25 OWASP LLM and agentic threat categories, organized into 12 attack mechanics with per-mechanic characterization of where the most discriminative evidence lies. Across four distinct detector families, we find that kernel evidence is discriminative on its own and that composing it with application-layer evidence generally outperforms either single-layer view, revealing complementary signals that single-layer analyses can miss. We further demonstrate generalization to unseen attack families and transfer to an alternate agent runtime. Together, these findings establish the value of cross-layer evidence for agent security.