On the Effectiveness of Kernel-Level Evidence for Agent Security
This work pairs application-level agent telemetry with kernel-level syscall traces to present the first paired-evidence characterization of kernel-level versus application-layer signal for agent security, finding that kernel evidence is discriminative on its own and that composing it with application-layer evidence gen...