{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,29]],"date-time":"2026-04-29T00:11:25Z","timestamp":1777421485886,"version":"3.51.4"},"publisher-location":"New York, NY, USA","reference-count":32,"publisher":"ACM","content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2025,10,13]]},"DOI":"10.1145\/3766882.3767169","type":"proceedings-article","created":{"date-parts":[[2025,10,1]],"date-time":"2025-10-01T13:55:02Z","timestamp":1759326902000},"page":"110-115","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":2,"title":["AgentSight: System-Level Observability for AI Agents Using eBPF"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0004-3193-4356","authenticated-orcid":false,"given":"Yusheng","family":"Zheng","sequence":"first","affiliation":[{"name":"UC Santa Cruz, Santa Cruz, CA, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1003-6475","authenticated-orcid":false,"given":"Yanpeng","family":"Hu","sequence":"additional","affiliation":[{"name":"ShanghaiTech University, Shanghai, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1819-5614","authenticated-orcid":false,"given":"Tong","family":"Yu","sequence":"additional","affiliation":[{"name":"eunomia-bpf Community, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0785-4119","authenticated-orcid":false,"given":"Andi","family":"Quinn","sequence":"additional","affiliation":[{"name":"UC Santa Cruz, Santa Cruz, CA, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2025,10,13]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"2024. GPT-4o Mini: Advancing Cost-Efficient Intelligence. https:\/\/openai.com\/index\/gpt-4o-mini-advancing-cost-efficient-intelligence\/. Blog post announcing GPT-4o mini."},{"key":"e_1_3_2_1_2_1","volume-title":"crewAI: Framework for Orchestrating Role Playing Autonomous AI Agents. https:\/\/github.com\/crewAIInc\/crewAI. GitHub repository, accessed","year":"2025","unstructured":"2025. crewAI: Framework for Orchestrating Role Playing Autonomous AI Agents. https:\/\/github.com\/crewAIInc\/crewAI. GitHub repository, accessed 30 Jul 2025."},{"key":"e_1_3_2_1_3_1","unstructured":"2025. Subagents. https:\/\/docs.anthropic.com\/en\/docs\/claude-code\/sub-agents. Claude Code documentation page describing custom AI sub agents."},{"key":"e_1_3_2_1_4_1","unstructured":"Anthropic. 2025. Introducing Claude Code. https:\/\/www.anthropic.com\/news\/claude-code. Agentic coding tool announcement Anthropic blog."},{"key":"e_1_3_2_1_5_1","volume-title":"Cursor: The AI powered Code Editor","author":"Anysphere Inc.","year":"2025","unstructured":"Anysphere Inc. 2025. Cursor: The AI powered Code Editor. https:\/\/cursor.com\/. AI assisted IDE with agent mode; latest release version 1.0 on June 4, 2025."},{"key":"e_1_3_2_1_6_1","volume-title":"Falco: Cloud Native Runtime Security. https:\/\/falco.org\/","author":"Authors The Falco","year":"2023","unstructured":"The Falco Authors. 2023. Falco: Cloud Native Runtime Security. https:\/\/falco.org\/"},{"key":"e_1_3_2_1_7_1","volume-title":"Uptrace Blog","author":"Bandurchin Alexandr","year":"2025","unstructured":"Alexandr Bandurchin. [n.d.]. AI Agent Observability Explained: Key Concepts and Standards. https:\/\/uptrace.dev\/blog\/ai-agent-observability. Uptrace Blog, April 16, 2025."},{"key":"e_1_3_2_1_8_1","unstructured":"Harrison Chase. 2023. LangChain: Building applications with LLMs through composability. https:\/\/github.com\/langchain-ai\/langchain"},{"key":"e_1_3_2_1_9_1","unstructured":"Linux Kernel Community. 2023. BPF Documentation - The Linux Kernel. https:\/\/www.kernel.org\/doc\/html\/latest\/bpf\/"},{"key":"e_1_3_2_1_10_1","volume-title":"Datadog Blog","author":"Datadog Inc. [n. d.]. Monitor, troubleshoot, and improve","year":"2023","unstructured":"Datadog Inc. [n. d.]. Monitor, troubleshoot, and improve AI agents with Datadog. https:\/\/www.datadoghq.com\/blog\/monitor-ai-agents\/. Datadog Blog, 2023."},{"key":"e_1_3_2_1_11_1","volume-title":"AgentOps: Enabling Observability of LLM Agents. arXiv preprint arXiv:2411.05285","author":"Dong Liming","year":"2024","unstructured":"Liming Dong, Qinghua Lu, and Liming Zhu. 2024. AgentOps: Enabling Observability of LLM Agents. arXiv preprint arXiv:2411.05285 (2024)."},{"key":"e_1_3_2_1_12_1","unstructured":"eBPF Community. 2023. eBPF Documentation. https:\/\/ebpf.io\/"},{"key":"e_1_3_2_1_13_1","unstructured":"eunomia-bpf. 2024. eBPF Developer Tutorial. https:\/\/github.com\/eunomia-bpf\/bpf-developer-tutorial. Accessed: 2025-01-29."},{"key":"e_1_3_2_1_14_1","volume-title":"BPF Performance Tools","author":"Gregg Brendan","unstructured":"Brendan Gregg. 2019. BPF Performance Tools. Addison-Wesley Professional."},{"key":"e_1_3_2_1_15_1","volume-title":"Large Language Model based Multi-Agents: A Survey of Progress and Challenges. arXiv preprint arXiv:2402.01680","author":"Guo Taicheng","year":"2024","unstructured":"Taicheng Guo, Xiuying Chen, Yaqi Wang, Ruidi Chang, Shichao Pei, Nitesh V. Chawla, Olaf Wiest, and Xiangliang Zhang. 2024. Large Language Model based Multi-Agents: A Survey of Progress and Challenges. arXiv preprint arXiv:2402.01680 (2024)."},{"key":"e_1_3_2_1_16_1","unstructured":"Helicone. 2023. Helicone \/ LLM-Observability for Developers. https:\/\/www.helicone.ai\/"},{"key":"e_1_3_2_1_17_1","volume-title":"Because we have LLMs, we Can and Should Pursue Agentic Interpretability. arXiv preprint arXiv:2506.12152","author":"Kim Been","year":"2025","unstructured":"Been Kim, John Hewitt, Neel Nanda, Noah Fiedel, and Oyvind Tafjord. 2025. Because we have LLMs, we Can and Should Pursue Agentic Interpretability. arXiv preprint arXiv:2506.12152 (2025)."},{"key":"e_1_3_2_1_18_1","unstructured":"LangChain. 2023. Observability Quick Start - LangSmith - LangChain. https:\/\/docs.smith.langchain.com\/observability"},{"key":"e_1_3_2_1_19_1","unstructured":"Langfuse. 2024. Langfuse - LLM Observability & Application Tracing. https:\/\/langfuse.com\/"},{"key":"e_1_3_2_1_20_1","volume-title":"OpenTelemetry Blog","author":"Liu Guangya","year":"2025","unstructured":"Guangya Liu and Sujay Solomon. [n. d.]. AI Agent Observability - Evolving Standards and Best Practices. https:\/\/opentelemetry.io\/blog\/2025\/ai-agent-observability\/. OpenTelemetry Blog, March 6, 2025."},{"key":"e_1_3_2_1_21_1","volume-title":"Langfuse Blog","author":"Maierh\u00f6fer Jannik","year":"2025","unstructured":"Jannik Maierh\u00f6fer. 2025. AI Agent Observability with Langfuse. https:\/\/langfuse.com\/blog\/2024-07-ai-agent-observability-with-langfuse. Langfuse Blog, March 16, 2025."},{"key":"e_1_3_2_1_22_1","unstructured":"microsoft. [n. d.]. eBPF for Windows. https:\/\/github.com\/microsoft\/ebpf-for-windows."},{"key":"e_1_3_2_1_23_1","volume-title":"Taming Uncertainty via Automation: Observing, Analyzing, and Optimizing Agentic AI Systems. arXiv preprint arXiv:2507.11277","author":"Moshkovich Dany","year":"2025","unstructured":"Dany Moshkovich and Sergey Zeltyn. 2025. Taming Uncertainty via Automation: Observing, Analyzing, and Optimizing Agentic AI Systems. arXiv preprint arXiv:2507.11277 (2025)."},{"key":"e_1_3_2_1_24_1","volume":"202","author":"Mullen Taylor","unstructured":"Taylor Mullen and Ryan J. Salva. 2025. Gemini CLI: Your Open Source AI Agent. https:\/\/blog.google\/technology\/developers\/introducinggemini-cli-open-source-ai-agent\/. Google Developers Blog, Jun 2025.","journal-title":"Ryan J. Salva."},{"key":"e_1_3_2_1_25_1","unstructured":"Cilium Project. 2023. eBPF-based Networking Observability and Security. https:\/\/cilium.io\/"},{"key":"e_1_3_2_1_26_1","volume-title":"Hassan","author":"Rombaut Benjamin","year":"2025","unstructured":"Benjamin Rombaut, Sogol Masoumzadeh, Kirill Vasilevski, Dayi Lin, and Ahmed E. Hassan. 2025. Watson: A Cognitive Observability Framework for the Reasoning of LLM-Powered Agents. arXiv preprint arXiv:2411.03455 (2025)."},{"key":"e_1_3_2_1_27_1","volume-title":"Tracee: Runtime Security and Forensics using eBPF. https:\/\/github.com\/aquasecurity\/tracee","author":"Security Aqua","year":"2023","unstructured":"Aqua Security. 2023. Tracee: Runtime Security and Forensics using eBPF. https:\/\/github.com\/aquasecurity\/tracee"},{"key":"e_1_3_2_1_28_1","volume-title":"Nguyen","author":"Tran Khanh-Tung","year":"2025","unstructured":"Khanh-Tung Tran, Dung Dao, Minh-Duong Nguyen, Quoc-Viet Pham, Barry O'Sullivan, and Hoang D. Nguyen. 2025. Multi-Agent Collaboration Mechanisms: A Survey of LLMs. arXiv preprint arXiv:2501.06322 (2025)."},{"key":"e_1_3_2_1_29_1","unstructured":"Qingyun Wu Gagan Bansal Jieyu Zhang Yiran Wu Shaokun Zhang Erkang Zhu Beibin Li Li Jiang Xiaoyun Zhang and Chi Wang. 2023. AutoGen: Enable Next-Gen Large Language Model Applications. https:\/\/github.com\/microsoft\/autogen"},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","unstructured":"Qiusi Zhan Zhixiang Liang Zifan Ying and Daniel Kang. 2024. InjecAgent: Benchmarking Indirect Prompt Injections in Tool-Integrated Large Language Model Agents. In Findings of the Association for Computational Linguistics (ACL Findings). doi:10.48550\/arXiv.2403.02691 arXiv:2403.02691.","DOI":"10.48550\/arXiv.2403.02691"},{"key":"e_1_3_2_1_31_1","volume-title":"Breaking Agents: Compromising Autonomous LLM Agents Through Malfunction Amplification. arXiv preprint arXiv:2407.20859","author":"Zhang Boyang","year":"2024","unstructured":"Boyang Zhang, Yicong Tan, Yun Shen, Ahmed Salem, Michael Backes, Savvas Zannettou, and Yang Zhang. 2024. Breaking Agents: Compromising Autonomous LLM Agents Through Malfunction Amplification. arXiv preprint arXiv:2407.20859 (2024). Introduces an \"infinite loop\" attack that forces agents to repeat actions until max iteration.."},{"key":"e_1_3_2_1_32_1","volume-title":"Extending Applications Safely and Efficiently. In 19th USENIX Symposium on Operating Systems Design and Implementation (OSDI 25)","author":"Zheng Yusheng","year":"2025","unstructured":"Yusheng Zheng, Tong Yu, Yiwei Yang, Yanpeng Hu, Xiaozheng Lai, Dan Williams, and Andi Quinn. 2025. Extending Applications Safely and Efficiently. In 19th USENIX Symposium on Operating Systems Design and Implementation (OSDI 25). 557--574."}],"event":{"name":"SOSP '25: ACM SIGOPS 31st Symposium on Operating Systems Principles","location":"Seoul Republic of Korea","acronym":"SOSP '25","sponsor":["SIGOPS ACM Special Interest Group on Operating Systems"]},"container-title":["Proceedings of the 4th Workshop on Practical Adoption Challenges of ML for Systems"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3766882.3767169","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,11,13]],"date-time":"2025-11-13T17:20:11Z","timestamp":1763054411000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3766882.3767169"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,10,13]]},"references-count":32,"alternative-id":["10.1145\/3766882.3767169","10.1145\/3766882"],"URL":"https:\/\/doi.org\/10.1145\/3766882.3767169","relation":{},"subject":[],"published":{"date-parts":[[2025,10,13]]},"assertion":[{"value":"2025-10-13","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}