arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2609.29647cs.CRcs.AI

AgentKernel:信任原生的智能体操作系统

AgentKernel: The Trust-Native Agentic Operating System

Zhenhua Zou, Sheng Guo, Qiuyang Zhan, Lepeng Zhao, Shuo Li, Zhuotao Liu

首次发表
浏览论文内容

中文总结 AI 辅助

AgentKernel提出以安全为第一约束的智能体操作系统,通过身份、感知、认知、执行四支柱强制边界,解决提示注入、内存投毒等安全威胁,实现全生命周期防护。

中文摘要 AI 辅助

现代AI智能体经常跨越信任边界:它们摄取不受信任的内容,将其与特权指令结合,在长期记忆中持久化中间信念,并调用特权工具。这造成了一个攻击面,恶意载荷可以通过模型输入进入并导致有害的工具操作。然而,当前的治理栈仍然是应用级中间件,与它们监控的智能体共享进程信任边界。我们认为,智能体需要一个操作系统底层,提供强制的、不可绕过的身份、输入中介、内存治理和执行控制服务。我们引入了AgentKernel,一个信任原生的智能体操作系统,其前提是安全必须是一等设计约束。AgentKernel将智能体生命周期包裹在一个强制执行的边界中,该边界组织为四个支柱:身份、感知、认知和执行。每个支柱将经典操作系统安全原则应用于语义层面的失败,包括委托滥用、提示注入、内存投毒和工具误用。AgentKernel将结构安全视为能力倍增器。内核管理的身份支持可信的跨组织协作;渐进式感知取代脆弱的单点过滤器;信息流控制的内存提高了检索保真度,同时限制了投毒;语义到内核的强制允许在不可绕过边界后面授予更广泛的工具特权。我们将AgentKernel定位为编排框架、智能体运行时、治理平台和执行沙箱之下的缺失操作系统层,并使用系统比较和安全分析来展示单一集成架构如何在整个智能体生命周期中强制安全。

英文摘要

Modern AI agents routinely cross trust boundaries: they ingest untrusted content, combine it with privileged instructions, persist intermediate beliefs in long-term memory, and invoke privileged tools. This creates an attack surface in which malicious payloads can enter through model inputs and cause harmful tool actions. Yet current governance stacks remain application-level middleware that share a process trust boundary with the agents they monitor. We argue that agents need an operating-system substrate providing mandatory, non-bypassable services for identity, input mediation, memory governance, and execution control. We introduce AgentKernel, a trust-native agent operating system built around the premise that security must be a first-class design constraint. AgentKernel wraps the agent lifecycle in a mandatory enforcement boundary organized into four pillars: Identity, Perception, Cognition, and Execution. Each pillar adapts classical OS security principles to failures at the semantic plane, including delegation abuse, prompt injection, memory poisoning, and tool misuse. AgentKernel treats structural security as a capability multiplier. Kernel-managed identity supports trustworthy cross-organization collaboration; graduated perception replaces brittle single-point filters; information-flow-controlled memory improves retrieval fidelity while limiting poisoning; and semantic-to-kernel enforcement permits broader tool privileges behind a non-bypassable boundary. We position AgentKernel as the missing OS layer beneath orchestration frameworks, agent runtimes, governance platforms, and execution sandboxes, and use systematic comparison and security analysis to show how a single integrated architecture can enforce security across the full agent lifecycle.

发表机构

  • DeepKernel Lab(深度内核实验室)

机构由 AI 辅助整理,请以论文原文为准。

补充信息

↑