arXiv · 2603.04469
Cross-Layer Semantic Flow Reconstruction for Attack Detection in Agentic Systems
Abstract
Agentic systems increasingly orchestrate complex, tool-using workflows within agentic execution environments, where high-level goals and tool invocations at the application layer materialize as process, file, and network activities at the operating-system layer. This cross-layer execution creates security risks that conventional input guardrails cannot capture, because malicious intent may become observable only through downstream execution effects. In multi-agent deployments, inter-agent communication and delegation introduce additional propagation paths. To address this gap, we propose AScope, an execution-aware framework that correlates application-level agent semantics with kernel-level audit events and reconstructs them as cross-layer semantic flows. AScope connects fragmented operations into causal behavioral trajectories and uses a supervisor LLM to identify data flow violations, control flow deviations, and intent inconsistencies. We evaluate AScope on published AgentDojo traces with application-layer evidence and on ten multi-agent scenarios with cross-layer telemetry. The results demonstrate strong detection sensitivity across both evidence settings and achieve node- and path-level F1-scores of 85.3% and 66.7% on the cross-layer dataset.
Explore related subjects
Keep this discovery
Qizhi Cai, Yangyang Wei, Zhipeng Chen, Shouling Ji, Zhenyuan Li. 2026-03-04. Cross-Layer Semantic Flow Reconstruction for Attack Detection in Agentic Systems. https://arxiv.org/abs/2603.04469
Cite the original work for its findings. Save a collection to share your selection of sources.