English static mirror for SEO/GEO · AI-assisted translation · Read Chinese original

uber/ADR: Bringing the EDR Paradigm to AI Agent Security

Forum topic · ✨步子哥 · 2026-08-04

Summary

Uber open-sourced ADR (Agentic AI Detection and Response), a framework that applies the Endpoint Detection and Response (EDR) paradigm to enterprise AI agents. After discovering 7+ AI coding and automation tools (Claude Code, Cursor, Codex, internal agents) running in production with no visibility into MCP calls, tool use, or prompt injection, Uber built ADR around four components: Observability (capturing agent intent and execution traces across macOS/Linux/Windows), a Benchmark (ADR-Bench with 300+ tasks, 133 MCP servers, and 17 known attack techniques), a two-layer Detection architecture (high-recall triage followed by deeper agentic reasoning), and Prevention (not open-sourced). Deployed in Uber production for over 10 months and accepted to the MLSys 2026 Industry Track, ADR is released under Apache 2.0. The key insight: traditional security tools cannot see agent behavior, so each computing paradigm shift creates a security blind spot filled by tools borrowing from the previous paradigm.

uber/ADR: Bringing the EDR Paradigm to AI Agent Security

> Repository: https://github.com/uber/ADR > Paper: ADR: An Agentic Detection System for Enterprise Agentic AI Security (MLSys 2026 Industry Track)

An Overlooked Fact: AI Agents Are Already Running in Enterprises

Uber's security team realized the company was simultaneously running Cursor, Claude Code, Codex, internal automation agents, and customer service agents — over 7 AI coding/automation tools in total, each capable of calling MCP, reading and writing files, sending HTTP requests, and executing shell commands.

What were these agents doing? Why? Were any hijacked by prompt injection? Nobody could answer.

It's not that Uber lacked security — it's that traditional security tools simply cannot see agents.

EDR (Endpoint Detection and Response) watches processes, files, and network traffic; DLP watches data exfiltration; SIEM watches logs. But agent behavior happens on a new continent: MCP calls, tool use, prompt injections in context, poisoned tool return values. That continent had no sentinels.

Uber's answer is the open-source uber/ADR — Agentic AI Detection and Response. The name is no coincidence: it ported the EDR paradigm to the agent world.

Four Pieces: Observe, Evaluate, Detect, Prevent

ADR is not a single-point tool but four pieces:

1. ADR Observability — the agent observability layer. Captures agent intent, tool use, and execution traces from 7+ AI coding tools on macOS/Linux/Windows. Not "what process did the agent run," but "what did the agent intend, which MCP did it call, what is the execution chain."

2. ADR Benchmark — a benchmark dedicated to agent security: 300+ tasks, 133 MCP servers, covering all 17 known agent attack techniques. Not a run-once benchmark but a continuously regressing security test suite.

3. ADR Detection — a two-layer architecture: a first layer of high-recall triage, a second layer of deeper agentic reasoning. Rough screening first, deep digging second — a fast-but-coarse layer paired with a slow-but-accurate one.

4. ADR Prevention — not open-sourced. "Stay tuned."

Key Insight: Extending "Verification as a Control Signal" from Code to Agents

The two-layer detection architecture echoes the idea that "verification is not just a post-hoc filter; it defines transitions between research rounds."

ADR does the agent version of the same thing: instead of checking logs after agent execution, it uses verification signals during execution to decide next steps. The first-layer triage quickly filters clearly safe sessions and sends suspicious ones to second-layer deep reasoning — isomorphic to the "explore → verify → execute" loop in agents.

Behind this architectural choice is an engineering reality: agent sessions are too long and complex for a single-layer detector to be either fast enough (full deep-dive) or accurate enough (full triage). Two-layer division of labor is the only approach that can run in production for ten months.

ADR-Bench: 133 MCP Servers and 17 Attack Techniques

ADR-Bench is not another prompt injection dataset but an enterprise-grade agent attack simulation environment:

  • 300+ tasks: from simple tool misuse to complex multi-step attacks
  • 133 MCP servers: simulating a real enterprise MCP ecosystem (databases, file systems, APIs, internal tools)
  • 17 attack techniques: prompt injection, tool poisoning, context hijacking, credential leakage, and more
  • The number 133 is not arbitrary. Uber genuinely runs 133 MCP servers internally — that is their real production scale. The benchmark was not built in a lab but copied from a real battlefield.

    Why This Matters: The "EDR Moment" for the Agent Era

    In the 2010s, EDR emerged because traditional antivirus couldn't see fileless attacks or memory attacks. The same story is repeating: traditional security cannot see prompt injection, MCP call chains, or agent context hijacking.

    Every computing paradigm shift creates a security blind spot, and the tools that fill it always borrow paradigms from the old one. EDR filled the endpoint blind spot; ADR fills the agent blind spot. The shared name is no coincidence — it's paradigm isomorphism.

    ADR has its limits, though — only the Sensor, Benchmark, and Detector are open-sourced; Prevention is not. The community can observe, evaluate, and detect, but not block. Uber kept the sharpest part for itself. Understandable: prevention requires deep integration into enterprise workflows that an open-source version can't deliver out of the box.

    The Numbers

  • Deployment: 10+ months in Uber production
  • Coverage: 7+ AI coding tools (Claude Code, Cursor, Codex, etc.) + internal automation + customer service agents
  • Benchmark scale: 300+ tasks, 133 MCP servers, 17 attack techniques
  • Academic recognition: accepted to MLSys 2026 Industry Track
  • License: Apache 2.0

Takeaways for Agent Developers

1. Observability first: build the "what is my agent doing" collection layer before writing the agent. Without observability, detection and prevention are empty talk. 2. Two-layer detection: fast triage + deep reasoning. Don't try to make one model do everything — division of labor beats unification. 3. Benchmarks are assets: ADR-Bench itself is a security asset — every newly discovered attack gets added, forming a continuously regressing feedback loop.

---

One-line summary: uber/ADR ported the EDR paradigm to the agent world — observe, evaluate, detect, prevent. The first three are open-sourced; the sharpest fourth is not. But even the first three already draw a starting line for agent security.

> Repository: uber/ADR > Paper: arXiv:2605.17380 > MLSys 2026 Slides: PDF

Tags

#ai-agents#security#edr#mcp#prompt-injection#uber#open-source#detection-and-response

This page is an English static mirror generated for search and AI citation. It may be a full translation or structured summary of the Chinese original. Canonical interactive discussion lives on the Chinese page: https://zhichai.net/topic/178585128