LATIDIA · Ciberseguridad
Sobre la eficacia de la evidencia a nivel de kernel para la seguridad de los agentes.
arXiv: 2609.28915v1Tipo de anuncio: nuevo Resumen: los agentes de LLM se implementan en una infraestructura que les otorga una amplia autoridad de host, pero los puntos de referencia y las defensas de seguridad de los agentes existentes operan casi exclusivamente en la aplicación
WhatsApp ↗Telegram ↗
La noticia
arXiv:2609.28915v1 Announce Type: new Abstract: LLM agents are deployed into infrastructure that grants them broad host authority, yet existing agent-security benchmarks and defenses operate almost exclusively at the application telemetry layer: the served tool manifest, the user prompt, and the model's messages. Some threats, however, smuggle malicious instructions and actions past the application boundary, leaving them invisible to that layer. In this work, we bridge that gap by pairing application-level agent telemetry with kernel-level syscall traces to present the first paired-evidence characterization of kernel-level versus application-layer signal for agent security. To quantify the value of the enhanced telemetry, we introduce Agent Cross-Layer Evidence (ACE), a paired-session corpus of 4,047 sessions