arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2609.38245cs.CRcs.OS

Agent-Warden:基于eBPF的内核原生进程-文件溯源追踪,用于LLM智能体

Agent-Warden: eBPF-Based Kernel-Native Process-File Provenance Tracking for LLM Agents

  • School of Cyber Science and Technology, University of Science and Technology of China(中国科学技术大学网络空间安全学院)
  • China Greatwall Technology Group Co., Ltd.(中国长城科技集团股份有限公司)

机构由 AI 辅助整理,请以论文原文为准。

Dongxu Cui, Zhichao Gu, Ping Zheng, Simeng Han, Yong Liao

AI总结:

针对LLM智能体动态操作对应用层不可见的问题,提出基于eBPF的内核级溯源监控器Agent-Warden,通过双状态后端和因果聚合重建跨进程因果链,实测开销仅0.2-3.5%。

AI中文摘要:

LLM智能体执行动态生成的进程和文件操作,这些操作通常对应用层追踪不可见。我们提出了Agent-Warden,一种基于扩展伯克利包过滤器(eBPF)的溯源监控器,用于跨进程创建、文件访问和进程终止追踪任务和常规文件状态。Agent-Warden提供两种可互换的状态后端:一种基于PID键控哈希映射的后端,适用于缺乏BPF本地存储支持的兼容内核;另一种基于任务/索引节点本地存储的后端,将状态回收与内核对象生命周期耦合。系统向用户空间发出增量因果边以进行异步图重建,并应用保守的退出触发因果聚合,以保留短生命周期代理任务的因果上下文。在受控的文件介导传播场景中,Agent-Warden重建了应用层追踪中缺失的跨进程因果链。在x86-64和ARM64裸机主机上,评估的工作负载显示端到端开销为0.2-3.5%,额外系统CPU时间为0.6-3.7%。这些结果表明,该原型在评估设置中提供了具有测量开销的内核级可见性。

英文摘要:

LLM agents execute dynamically generated process and file operations that are often invisible to application-layer tracing. We present Agent-Warden, an extended Berkeley Packet Filter (eBPF)-based provenance monitor for tracking task and regular-file states across process creation, file access, and process termination. Agent-Warden provides two interchangeable state backends: a PID-keyed hash-map backend for compatible kernels lacking BPF local-storage support and a task/inode-local-storage backend that couples state reclamation to kernel-object lifetimes. The system emits incremental causal edges to user space for asynchronous graph reconstruction and applies conservative exit-triggered causal aggregation to preserve causal context for short-lived proxy tasks. In a controlled file-mediated propagation scenario, Agent-Warden reconstructed a cross-process causal chain that was absent from the application-layer trace. On x86-64 and ARM64 bare-metal hosts, the evaluated workloads showed 0.2-3.5% end-to-end overhead and 0.6-3.7% additional system CPU time. These results indicate that the prototype provides kernel-level visibility with the measured overheads in the evaluated settings.

补充信息

↑