On the Effectiveness of Kernel-Level Evidence for Agent Security
Organizations: University of Georgia · Amazon Web Services
Abstract
LLM agents are deployed into infrastructure that grants them broad host authority, yet existing agent-security benchmarks and defenses operate almost exclusively at the application telemetry layer: the served tool manifest, the user prompt, and the model's messages. Some threats, however, smuggle malicious instructions and actions past the application boundary, leaving them invisible to that layer. In this work, we bridge that gap by pairing application-level agent telemetry with kernel-level syscall traces to present the first paired-evidence characterization of kernel-level versus application-layer signal for agent security. To quantify the value of the enhanced telemetry, we introduce Agent Cross-Layer Evidence (ACE), a paired-session corpus of 4,047 sessions and 17 threat models spanning six delivery-vector families and 14 of the 25 OWASP LLM and agentic threat categories, organized into 12 attack mechanics with per-mechanic characterization of where the most discriminative evidence lies. Across four distinct detector families, we find that kernel evidence is discriminative on its own and that composing it with application-layer evidence generally outperforms either single-layer view, revealing complementary signals that single-layer analyses can miss. We further demonstrate generalization to unseen attack families and transfer to an alternate agent runtime. Together, these findings establish the value of cross-layer evidence for agent security.
Figures & tables
| Mechanic | OWASP Coverage | Fold | ACE | MSB | MCPT | ToB | AgD | ASB | RC | AgH | TE |
| Bash command injection | L1, L6, A2, A11 | A | |||||||||
| Credential direct read | L2, A2, A3 ∗ | B | |||||||||
| Silent exfil via logging | L2, A2 | B | |||||||||
| Resource exhaustion | L10, A4 | E | |||||||||
| Audit-log poisoning | A1, A8 | F | |||||||||
| Schema-shape tampering | L3 | G |
| Mechanic | App | Kernel | Cross | Signal | ||
| Bash command injection | .812 .051 | .846 .046 | .915 .027 | CKA | 264 | 311 |
| Credential direct read | .876 .051 | .882 .039 | .978 .012 | CKA | 227 | 529 |
| Silent exfil via logging | .586 .045 | .976 .011 | .970 .010 | KC | 244 | 469 |
| Resource exhaustion | .915 .044 | .939 .027 | .973 .016 | CKA | 109 | 309 |
| Audit-log poisoning | .608 .109 | .932 .049 | .954 .039 | CK | 11 | 108 |
| Schema-shape tampering | .672 .071 | .844 .051 | .867 .032 | CK | 85 | 214 |
Appendix figures & tables26 assets
Supplementary material from the paper’s appendix.
Appendix
| Threat model (delivery vector) | Mechanic | OWASP | Fold |
| MCP tool tampering | All 12 mechanics | (all) | A–G |
| File bash injection (built-in) | Bash command injection | LLM01+06 | A |
| Web bash injection (built-in) | Bash command injection | LLM01+06 | A |
| User-direct bash injection (built-in) | Bash command injection | LLM01+06 | A |
| Memory bash injection (built-in) | Bash command injection | LLM01+06 | A |
| File credential exfil (built-in) | Credential direct read | LLM02 | B |
| Fold | Held-out attack family | Mal. | Dorm. | Lat. | Benign | Scored | All |
| A | Bash command injection | 264 | 59 | 225 | 252 | 575 | 800 |
| B | Credential exfil (direct read + silent logging + network redirect) | 508 | 366 | 72 | 603 | 1,477 | 1,549 |
| C | Prompt injection (metadata + retrieval reference + preference manipulation) | 195 | 32 | 18 | 180 | 407 | 425 |
| D | Output directive write | 162 | 68 | 20 | 167 | 397 | 417 |
| E | Resource exhaustion | 109 | 188 | 13 | 121 | 418 | 431 |
| F | Persistence (audit-log poisoning + multi-stage persistence) | 35 | 51 | 4 | 100 | 186 | 190 |
| Family | Detector | View | F | FL | FLD | ||
| Classical | AdaBoost | App | 0.689 | 0.699 | 0.560 | ||
| AdaBoost | Kernel | 0.733 | 0.717 | 0.553 | |||
| AdaBoost | Cross | 0.840 | 0.827 | 0.681 | |||
| XGBoost | App | 0.703 | 0.686 | 0.536 | |||
| XGBoost | Kernel | 0.750 | 0.730 | 0.580 | |||
| XGBoost | Cross | 0.850 | 0.830 | 0.709 |
| p50 | p90 | p99 | ||||
| Feature | Benign | Malicious | Benign | Malicious | Benign | Malicious |
| execve | 7 | 7 | 24 | 26 | 63 | 23,453 |
| clone | 30 | 30 | 56 | 91 | 420 | 23,493 |
| connect | 29 | 31 | 51 | 67 | 259 | 93,907 |
| sendto | 24 | 28 | 75 | 74 | 241 | 251 |
| distinct external IPs | 11 | 11 | 13 | 20 | 40 | 41 |
| ID | Category | Cov. | Note |
| OWASP LLM Top 10 v2025 | |||
| LLM01 | Prompt Injection | ✓ | Metadata + retrieval-reference injection |
| LLM02 | Sensitive Information Disclosure | ✓ | Credential read + silent exfil + network redirect |
| LLM03 | Supply Chain | ✓ | Schema-shape tampering; tampered-MCP delivery |
| LLM04 | Data and Model Poisoning | Training-pipeline attack, not runtime | |
| LLM05 | Improper Output Handling | ✓ | Output directive write |
| ID | OOD | |||||
| Model | App | Kernel | Cross | App | Kernel | Cross |
| Rule-based runtime baseline (Falco default rule pack) | ||||||
| Falco | — | .565 .039 | — | — | .572 .084 | — |
| Classical | ||||||
| AdaBoost | .872 .022 | .905 .020 | .975 .007 | .689 .075 | .733 .090 | .840 .059 |
| XGBoost | .922 .016 | .931 .015 | .988 .004 | .703 .076 | .750 .081 | .850 .059 |
| ID | OOD | |||||
| Model | App | Kernel | Cross | App | Kernel | Cross |
| Classical | ||||||
| AdaBoost | .818 .035 | .867 .031 | .963 .011 | .571 .125 | .626 .140 | .773 .111 |
| XGBoost | .885 .026 | .907 .022 | .983 .006 | .589 .127 | .661 .131 | .797 .099 |
| Deep tabular | ||||||
| TabPFN | .905 .022 | .935 .017 | .982 .007 | .498 .131 | .692 .126 | .822 .103 |
| Mechanic | |||
| Bash command injection | CKA | CKA | CKA |
| Credential direct read | CKA | CKA | CKA |
| Silent exfil via logging | KC | KC | KC |
| Resource exhaustion | CKA | CKA | CKA |
| Audit-log poisoning | CK | CK | CK |
| Schema-shape tampering | CK | CK | CK |
| Full cohort | Captured-prompt subset | |||||
| Model | App | Kernel | Cross | App | Kernel | Cross |
| Qwen3-235B | .705 | .775 | .829 | .613 | .803 | .809 |
| Qwen3-80B | .678 | .725 | .810 | .608 | .698 | .791 |
| Qwen3-32B | .672 | .741 | .723 | .581 | .766 | .661 |
| Qwen2.5-3B | .713 | .901 | .881 | .716 | .914 | .935 |
| Qwen2.5-7B | .722 | .882 | .920 | .736 | .941 | .968 |
| Cross minus App | Cross minus Kernel | |||
| Detector | 95% interval | 95% interval | ||
| AdaBoost | ||||
| XGBoost | ||||
| TabPFN | ||||
| TabICL | ||||
| Qwen3-235B | ||||
| ID | OOD | |||||
| Model | App | Kernel | Cross | App | Kernel | Cross |
| Train-from-scratch | ||||||
| MLP (tuned) | .864 .022 | .781 .032 | .897 .018 | .721 .091 | .629 .094 | .664 .089 |
| FT-Transformer | .883 .020 | .796 .029 | .900 .018 | .694 .089 | .630 .087 | .670 .095 |
| Pretrained tabular foundation models (in-context) | ||||||
| TabPFN | .933 .016 | .952 .012 | .986 .006 | .633 .103 | .777 .086 | .874 .071 |
| Hidden layers | Dropout | Weight decay | AUROC |
| Dropout | AUROC | ||
| Raw ordered event stream | Summary | ||||
| Fold | LSTM-LM (Kim 2016) | BERT-MIL (windows) | Set Transformer (tokens) | Set Transformer (events) | BERT-on- summary |
| A | .560 .107 | .519 .114 | .530 .104 | .512 .104 | .752 .099 |
| B | .545 .087 | .523 .081 | .574 .072 | .532 .076 | .853 .046 |
| C | .448 .104 | .491 .105 | .538 .075 | .532 .091 | .606 .089 |
| D | .680 .210 | .472 .142 | .768 .115 | .652 .235 | .978 .021 |
| E | .585 .153 | .729 .100 | .483 .192 | .677 .153 | .877 .066 |
| ID | OOD | |||||
| Model | App | Kernel | Cross | App | Kernel | Cross |
| Baseline template, (zero-shot) | ||||||
| Qwen3-235B | .607 .032 | .581 .042 | .541 .026 | .590 .061 | .589 .085 | .520 .041 |
| Qwen3-80B | .608 .035 | .516 .019 | .540 .031 | .594 .077 | .513 .018 | .512 .067 |
| Qwen3-32B | .605 .040 | .593 .024 | .534 .035 | .573 .073 | .564 .040 | .502 .061 |
| OWASP-grounded template, (zero-shot) | ||||||
| R1 | R2 | R3 | R4 | |
| Model | (bounded summary) | (dedup verbatim) | (family tokenized) | (chronological verbatim) |
| Qwen3-235B | 0.731 | 0.541 | 0.671 | 0.599 |
| Qwen3-80B | 0.598 | 0.628 | 0.575 | 0.563 |
| Qwen3-32B | 0.679 | 0.606 | 0.508 | 0.587 |
| mean | 0.669 | 0.592 | 0.585 | 0.583 |
| Model | App | Kernel | Cross |
| Baseline template | |||
| Qwen3-235B | .695 .065 | .780 .068 | .831 .049 |
| Qwen3-80B | .688 .070 | .812 .053 | .771 .053 |
| Qwen3-32B | .660 .079 | .743 .068 | .693 .069 |
| OWASP-grounded template | |||
| Qwen3-235B | .730 .069 | .772 .061 | .842 .045 |
| Support set | Macro AUROC | Pooled AUROC |
| Zero-shot ( ) | .634 | .630 .026 |
| Canonical ( ) | .842 | .831 .022 |
| Random seed 1 | .845 | .847 .020 |
| Random seed 2 | .842 | .833 .021 |
| Random seed 3 | .837 | .847 .020 |
| Training | Evaluation | AUROC [95% interval] |
| Original | Original | .922 |
| Original | Redacted | .620 |
| Redacted | Redacted | .759 |
| Detector | View | Native (recall @ FPR) | @1% | @5% | @10% |
| Cisco mcp-scanner (YARA) | Manifest | 0.159 @ 16.3% FPR | — | — | — |
| XGBoost | Cross | 0.922 @ 3.8% FPR | 0.862 | 0.936 | 0.970 |
| TabPFN | Cross | 0.917 @ 4.0% FPR | 0.856 | 0.923 | 0.978 |
| Qwen3-80B | Cross | 0.732 @ 7.3% FPR | 0.007 | 0.007 | 0.733 |
| Llama-3.1-8B LoRA | Kernel | 0.981 @ 2.6% FPR | 0.822 | 0.993 | 1.000 |
| ACE catches | ACE misses | |
| Scanner catches | 108 | 8 |
| Scanner misses | 566 | 49 |
| ACE catches | ACE misses | |
| Scanner catches | 106 | 10 |
| Scanner misses | 564 | 51 |
| ACE catches | ACE misses | |
| Scanner catches | 75 | 41 |
| Scanner misses | 460 | 155 |
| ACE catches | ACE misses | |
| Scanner catches | 115 | 1 |
| Scanner misses | 602 | 13 |
| Detector | A | B | D | E | F | avg |
| XGBoost Cross-View | .941 | .718 | .995 | .806 | .750 | .842 |
| TabPFN Cross-View | .487 | .418 | 1.000 | .872 | .535 | .662 |
| Qwen3-80B Cross-View | 1.000 | .993 | .995 | 1.000 | 1.000 | .998 |
| Llama-3.1-8B LoRA Kernel | 1.000 | .605 | .879 | .961 | .801 | .849 |
| Model | Responses | Input (M) | Output (M) | Cost |
| Qwen3-235B-A22B-2507 | 70,542 | 536.8 | 4.02 | $122 |
| Qwen3-Next-80B-A3B | 70,542 | 536.8 | 4.56 | $86 |
| Qwen3-32B | 70,302 | 522.5 | 3.86 | $81 |
| Total | 211,386 | 1,596.2 | 12.43 | $288 |