@VivekIntel: ADR: Agentic AI Detection & Response Framework Building or securing AI agents in enterprise environments? ADR (Agentic …
Summary
Uber open-sourced ADR, an enterprise security framework for monitoring, evaluating, and detecting risks in AI agents, including a 300+ task benchmark and support for 133 MCP servers.
View Cached Full Text
Cached at: 08/03/26, 11:55 PM
ADR: Agentic AI Detection & Response Framework
Building or securing AI agents in enterprise environments?
ADR (Agentic AI Detection and Response) is an open-source security framework from Uber designed to monitor, evaluate, and detect security risks in AI agents used by developers and organizations.
Key highlights: • AI agent observability & telemetry collection • Benchmark suite with 300+ security tasks • Detection of risky AI agent behavior • Support for 133 MCP servers • Security evaluation for coding assistants & enterprise agents • Cross-platform support for macOS, Linux & Windows • Reproducible benchmarking & research workflows • Based on the MLSys 2026 research paper
A valuable resource for AI security researchers, security engineers, platform teams, and AI developers working on secure agentic AI systems.
https://github.com/uber/ADR
#GitHub #OpenSource #AISecurity #AgenticAI #LLM #CyberSecurity #MachineLearning #SecurityResearch #MCP #InfoSec
uber/ADR
Source: https://github.com/uber/ADR
ADR: Agentic AI Detection and Response
ADR (Agentic AI Detection and Response) is an enterprise security system for AI agents. It helps organizations secure employee-facing agents such as Cursor, Claude Code, and Codex, as well as customer-facing agents such as AI support agents.
ADR is deployed in production at Uber, and the accompanying paper was accepted to MLSys 2026: Paper PDF · Slides PDF
How ADR secures enterprise AI agents
ADR secures enterprise AI agents through four complementary capabilities: observing agent activity, evaluating defenses, detecting threats, and preventing unsafe actions.
- ADR Observability: Understand what AI agents are doing and why. In production, ADR captures agent intent, tool use, and execution traces across 7+ AI coding tools on macOS, Linux, and Windows, as well as internal automation and customer-facing support agents.
- ADR Benchmark: Test agent security under realistic enterprise conditions. ADR-Bench includes 300+ tasks, 133 MCP servers, and coverage of all 17 agent attack techniques.
- ADR Detection: Detect risky agent behavior efficiently. Its two-tier architecture combines high-recall triage with deeper agentic reasoning for suspicious sessions.
- ADR Prevention: Stop unsafe actions before they cause harm. This component is not included in the current open-source release. Stay tuned.
Repository layout
This repository contains the open-source ADR Sensor, ADR-Bench, and ADR Detector described in the paper. The offline ADR Explorer engine, which hardens ADR Detection through pre-deployment red teaming, is not included here.
| Path | ADR component | Description |
|---|---|---|
| Sensor/ | ADR Observability | Collect and normalize agent telemetry from Claude Code, Cursor, Codex, and others |
| Detection/ | ADR Benchmark + Detection | Dual-agent detector, 133 MCP servers, 303 benchmark tasks, baselines, figure scripts |
| docs/REPRODUCIBILITY.md | Evaluation | Step-by-step workflow to reproduce benchmark detection and paper figures |
Quick start: ADR Detection
git clone https://github.com/uber/ADR
cd ADR/Detection
uv sync
export ANTHROPIC_API_KEY="..." OPENAI_API_KEY="..."
Default detector is adr (ADR dual-agent). For keyless smoke tests, use --detector llamafirewall (see Detection/README.md).
See docs/REPRODUCIBILITY.md for the full evaluation workflow (inflate packed benchmark → run detectors → plot figures).
Component documentation:
- Sensor/README.md: telemetry collection and unified schema
- Detection/README.md: ADR-Bench, detector baselines, MCP infrastructure
Citation
@inproceedings{li2026adr,
title={ADR: An Agentic Detection System for Enterprise Agentic AI Security},
author={Li, Chenning and Hu, Pan and Xu, Justin and Ozbas, Baris and Liu, Olivia and Van, Caroline and Li, Manxue and Zhou, Wei and Alizadeh, Mohammad and Zhang, Pengyu and Sriramadhesikan, KK and Zhang, Ming},
booktitle={Proceedings of the Ninth Conference on Machine Learning and Systems},
year={2026}
}
Or use CITATION.cff.
License
Apache License 2.0. See LICENSE. Detection/benchmark/agentdojo/ is vendored third-party code under its own LICENSE (MIT).
Data notice
Detection/ includes synthetic benchmark fixtures (fake credentials, emulated environments, prompt-injection scenarios) for defensive security research only. Details: docs/OPEN_SOURCE_REVIEW.md.
Similar Articles
uber/ADR
Uber released ADR (Agentic AI Detection and Response), an open-source enterprise security system for AI agents, including telemetry sensors, a benchmark, and a dual-agent detector. The accompanying paper was accepted to MLSys 2026.
Best tools for monitoring and auditing autonomous AI agent behavior at runtime, what's actually working in prod?
A practitioner shares challenges and tools for monitoring autonomous AI agents in production, covering runtime prompt injection detection, tool-call auditing with reasoning traces, behavioral drift detection, and multi-agent authorization, while testing tools like Arize Phoenix, Protect AI Guardian, Metoro, Alice, Asqav, and Microsoft Agent Governance Toolkit.
Securing the AI Agent: A Unified Framework for Multi-Layer Agent Red Teaming
AI-Infra-Guard is an open-source framework for multi-layer red teaming of AI agents, covering infrastructure, protocol, behavior, and model layers with diverse detection paradigms.
Solving an ARD problem in AI: Agentic Resource Discovery (2 minute read)
A new protocol called Agentic Resource Discovery (ARD), backed by Google, Microsoft, Cisco, Nvidia, and Salesforce, aims to standardize how AI agents discover and use tools and services across enterprise systems, enabling agents to autonomously find and query resources from different silos.
@0x0SojalSec: Awesome AI Security : Everyone’s racing to deploy AI agents, Almost few peoples is securing them properly. this repo co…
A curated GitHub repository aggregating frameworks, tools, attack matrices, red team guides, policy templates, datasets, and research for securing AI systems, covering topics like prompt injection, jailbreaking, and OWASP/NIST standards.