[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"branding":3,"analytics":7,"article-kernel-level-syscall-traces-improve-ai-agent-attack-detection":10,"sections":35},{"siteName":4,"siteTagline":5,"publisherName":4,"contactEmail":6},"The Revision","Tech news, decoded.","editor@therevision.news",{"gaMeasurementId":8,"adsenseClientId":9},"G-ZW2MV82GYR","ca-pub-8533917693782264",{"article":11},{"id":12,"slug":13,"title":14,"dek":15,"body_md":16,"tags_json":17,"published_at":18,"created_at":19,"updated_at":20,"status":21,"review_note":22,"review_notes":23,"image_url":22,"persona_id":22,"persona_name":22,"section":24,"tags":25,"sources":30,"feedback":34,"feedback_at":22,"cost_usd":34,"total_tokens":34},7811,"kernel-level-syscall-traces-improve-ai-agent-attack-detection","Kernel-Level Syscall Traces Improve AI Agent Attack Detection","A new research benchmark pairs kernel syscall traces with application telemetry to catch AI agent attacks that either signal alone would miss.","Watching what an AI agent says it's doing isn't enough. Researchers now argue that watching what it actually does at the operating-system level catches attacks that slip past everything else.\n\nThe team built a corpus called ACE (Agent Cross-Layer Evidence) that pairs two kinds of security logs for the same AI agent sessions: the usual application-level telemetry (prompts, tool calls, model messages) and kernel-level syscall traces, the record of every low-level request an agent's process makes to the operating system. The dataset covers 4,047 paired sessions, 17 threat models, six delivery-vector families, and 14 of the 25 threat categories in OWASP's list for LLM and agentic systems. Testing four separate detector approaches, the researchers found kernel-level evidence alone was discriminative enough to catch attacks, and combining it with application-layer logs beat either source used on its own. The detectors also generalized to attack types they hadn't seen before and transferred to a different agent runtime.\n\nMost agent-security tools today only watch the layer an attacker can talk to directly: the prompt, the tool manifest, the chat transcript. That's also the layer an attacker can manipulate or route around. If a malicious instruction can smuggle an action past that boundary without leaving a trace in the transcript, the operating system still sees it happen - which is a real blind spot given how much host access agent frameworks now hand out by default.\n\nIt's less a breakthrough than an overdue borrowing: syscall monitoring has been standard practice in endpoint security for years, and agent frameworks are only now catching up to that idea.","[\"ai-security\",\"llm-agents\",\"kernel-security\",\"agent-security\"]","2026-09-25T04:00:00.000Z","2026-09-26T00:26:47.100Z","2026-09-26T00:26:53.477Z","published",null,[],"security",[26,27,28,29],"ai-security","llm-agents","kernel-security","agent-security",[31],{"name":32,"url":33},"arXiv cs.AI","https:\u002F\u002Farxiv.org\u002Fabs\u002F2609.28915",0,{"sections":36},[37,42,46,51,56,61,66,71,76,81,86,91,96,101],{"name":38,"slug":39,"count":40,"latest_published_at":41},"AI","ai",4527,"2026-09-25T16:31:14.000Z",{"name":43,"slug":24,"count":44,"latest_published_at":45},"Security",741,"2026-09-25T15:52:13.000Z",{"name":47,"slug":48,"count":49,"latest_published_at":50},"Policy","policy",390,"2026-09-25T16:24:59.000Z",{"name":52,"slug":53,"count":54,"latest_published_at":55},"Deals","deals",256,"2026-09-25T17:00:53.000Z",{"name":57,"slug":58,"count":59,"latest_published_at":60},"Hardware","hardware",185,"2026-09-25T15:00:22.000Z",{"name":62,"slug":63,"count":64,"latest_published_at":65},"Science","science",140,"2026-09-25T11:55:23.000Z",{"name":67,"slug":68,"count":69,"latest_published_at":70},"Consumer Tech","consumer-tech",132,"2026-09-25T15:30:00.000Z",{"name":72,"slug":73,"count":74,"latest_published_at":75},"Software","software",88,"2026-09-24T23:06:55.000Z",{"name":77,"slug":78,"count":79,"latest_published_at":80},"Dev Tools","dev-tools",82,"2026-09-25T09:59:40.000Z",{"name":82,"slug":83,"count":84,"latest_published_at":85},"Startups","startups",76,"2026-09-25T18:33:59.000Z",{"name":87,"slug":88,"count":89,"latest_published_at":90},"Gaming","gaming",48,"2026-09-25T18:35:21.000Z",{"name":92,"slug":93,"count":94,"latest_published_at":95},"General","general",46,"2026-09-25T02:12:57.000Z",{"name":97,"slug":98,"count":99,"latest_published_at":100},"Reviews","reviews",30,"2026-09-24T20:07:31.000Z",{"name":102,"slug":103,"count":104,"latest_published_at":105},"How-To","how-to",6,"2026-06-16T09:00:00.000Z"]