{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,12]],"date-time":"2026-03-12T15:34:26Z","timestamp":1773329666532,"version":"3.50.1"},"publisher-location":"New York, NY, USA","reference-count":35,"publisher":"ACM","content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2025,10,13]]},"DOI":"10.1145\/3766882.3767179","type":"proceedings-article","created":{"date-parts":[[2025,10,1]],"date-time":"2025-10-01T13:55:02Z","timestamp":1759326902000},"page":"63-68","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":1,"title":["Towards Safe Agentic AI Performance Engineering"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-1537-0525","authenticated-orcid":false,"given":"Dan","family":"Williams","sequence":"first","affiliation":[{"name":"Virginia Tech, IBM, Blacksburg, VA, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0009-6341-4028","authenticated-orcid":false,"given":"Milo","family":"Craun","sequence":"additional","affiliation":[{"name":"Virginia Tech, Blacksburg, VA, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5000-6393","authenticated-orcid":false,"given":"Michael V.","family":"Le","sequence":"additional","affiliation":[{"name":"IBM, Yorktown Heights, NY, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2613-531X","authenticated-orcid":false,"given":"Julian","family":"Stephen","sequence":"additional","affiliation":[{"name":"IBM, Yorktown Heights, NY, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0290-5367","authenticated-orcid":false,"given":"Salman","family":"Ahmed","sequence":"additional","affiliation":[{"name":"IBM, Yorktown Heights, NY, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6143-1064","authenticated-orcid":false,"given":"Hani","family":"Jamjoom","sequence":"additional","affiliation":[{"name":"IBM, Yorktown Heights, NY, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2025,10,13]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"2021. CVE-2021-31440. https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2021-31440."},{"key":"e_1_3_2_1_2_1","unstructured":"2021. CVE-2021-45402. https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2021-45402."},{"key":"e_1_3_2_1_3_1","unstructured":"2022. CVE-2022-23222. https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2022-23222."},{"key":"e_1_3_2_1_4_1","unstructured":"2022. CVE-2022-2785. https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2022-2785."},{"key":"e_1_3_2_1_5_1","unstructured":"2025. DSPy. https:\/\/dspy.ai\/."},{"key":"e_1_3_2_1_6_1","unstructured":"2025. E2B. https:\/\/e2b.dev\/docs."},{"key":"e_1_3_2_1_7_1","unstructured":"2025. Guardrails AI. https:\/\/www.guardrailsai.com\/docs."},{"key":"e_1_3_2_1_8_1","unstructured":"2025. LLM Guard. https:\/\/github.com\/protectai\/llm-guard."},{"key":"e_1_3_2_1_9_1","unstructured":"2025. Model Context Protocol. https:\/\/modelcontextprotocol.io\/overview."},{"key":"e_1_3_2_1_10_1","unstructured":"2025. NVIDIA Nemo Guardrails. https:\/\/github.com\/NVIDIA\/NeMo-Guardrails."},{"key":"e_1_3_2_1_11_1","unstructured":"2025. Rasa. https:\/\/github.com\/rasahq."},{"key":"e_1_3_2_1_12_1","unstructured":"2025. What is AI Monitoring? https:\/\/www.trustible.ai\/post\/what-is-ai-monitoring."},{"key":"e_1_3_2_1_13_1","volume-title":"Firecracker: Lightweight Virtualization for Serverless Applications.","author":"Agache Alexandru","year":"2020","unstructured":"Alexandru Agache, Marc Brooker, Alexandra Iordache, Anthony Liguori, Rolf Neugebauer, Phil Piwonka, and Diana-Maria Popa. 2020. Firecracker: Lightweight Virtualization for Serverless Applications. Santa Clara, CA."},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1145\/3729398"},{"key":"e_1_3_2_1_15_1","volume-title":"POSIX Capabilities. In Proceedings of the 2000 USENIX Annual Technical Conference: FREENIX Track. USENIX Association","author":"Bacarella Serge E.","year":"2000","unstructured":"Serge E. Bacarella. 2000. POSIX Capabilities. In Proceedings of the 2000 USENIX Annual Technical Conference: FREENIX Track. USENIX Association, San Diego, CA, USA, 29--36."},{"key":"e_1_3_2_1_16_1","volume-title":"Unsafe Nesting in BPF Programs. Master's thesis","author":"Chintamaneni Siddharth","unstructured":"Siddharth Chintamaneni. 2025. Unsafe Nesting in BPF Programs. Master's thesis. Virginia Polytechnic Institute and State University."},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1145\/3672197.3673440"},{"key":"e_1_3_2_1_18_1","unstructured":"Manuel Costa Boris K\u00f6pf Aashish Kolluri Andrew Paverd Mark Russinovich Ahmed Salem Shruti Tople Lukas Wutschitz and Santiago Zanella-B\u00e9guelin. 2025. Securing AI Agents with Information-Flow Control. arXiv:2505.23643 [cs.CR] https:\/\/arxiv.org\/abs\/2505.23643"},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1145\/3672197.3673431"},{"key":"e_1_3_2_1_20_1","unstructured":"Edoardo Debenedetti Ilia Shumailov Tianqi Fan Jamie Hayes Nicholas Carlini Daniel Fabian Christoph Kern Chongyang Shi Andreas Terzis and Florian Tram\u00e8r. 2025. Defeating Prompt Injections by Design. arXiv:2503.18813 [cs.CR] https:\/\/arxiv.org\/abs\/2503.18813"},{"key":"e_1_3_2_1_21_1","volume-title":"Preventing Unintended Data Access: Information Flow Control in eBPF. Master's thesis","author":"Dimobi Chinecherem Stephanie","unstructured":"Chinecherem Stephanie Dimobi. 2025. Preventing Unintended Data Access: Information Flow Control in eBPF. Master's thesis. Virginia Polytechnic Institute and State University."},{"key":"e_1_3_2_1_22_1","volume-title":"Proceedings of the 15th National Computer Security Conference (NCSC). National Institute of Standards and Technology (NIST), 554--563","author":"Ferraiolo David F.","unstructured":"David F. Ferraiolo and D. Richard Kuhn. 1992. Role-Based Access Controls. In Proceedings of the 15th National Computer Security Conference (NCSC). National Institute of Standards and Technology (NIST), 554--563."},{"key":"e_1_3_2_1_23_1","volume-title":"BPF Performance Tools Workshop. https:\/\/github.com\/brendangregg\/bpf-perf-workshop.","author":"Gregg Brendan","year":"2019","unstructured":"Brendan Gregg. 2019. BPF Performance Tools Workshop. https:\/\/github.com\/brendangregg\/bpf-perf-workshop."},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1145\/3593856.3595892"},{"key":"e_1_3_2_1_25_1","volume-title":"Proceedings of the 2nd International System Administration and Networking (SANE 2000) Conference. NLUUG","author":"Kamp Poul-Henning","unstructured":"Poul-Henning Kamp and Robert N. M. Watson. 2000. Jails: Confining the Omnipotent Root. In Proceedings of the 2nd International System Administration and Networking (SANE 2000) Conference. NLUUG, Maastricht, The Netherlands."},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1145\/3729355"},{"key":"e_1_3_2_1_27_1","volume-title":"Proceedings of the FREENIX Track: 2001 USENIX Annual Technical Conference. USENIX Association","author":"Peter","unstructured":"Peter A. Loscocco and Stephen D. Smalley. 2001. Integrating Flexible Support for Security Policies into the Linux Operating System. In Proceedings of the FREENIX Track: 2001 USENIX Annual Technical Conference. USENIX Association, Boston, MA, USA, 29--42."},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.parco.2004.04.001"},{"key":"e_1_3_2_1_29_1","unstructured":"Long Ouyang Jeff Wu Xu Jiang Diogo Almeida Carroll L. Wainwright Pamela Mishkin Chong Zhang Sandhini Agarwal Katarina Slama Alex Ray John Schulman Jacob Hilton Fraser Kelton Luke Miller Maddie Simens Amanda Askell Peter Welinder Paul Christiano Jan Leike and Ryan Lowe. 2022. Training language models to follow instructions with human feedback. arXiv:2203.02155 [cs.CL] https:\/\/arxiv.org\/abs\/2203.02155"},{"key":"e_1_3_2_1_30_1","volume-title":"Proceedings of the 18th Large Installation System Administration Conference (LISA","author":"Price Daniel","year":"2004","unstructured":"Daniel Price and Andrew Tucker. 2004. Solaris Zones: Operating System Support for Consolidating Commercial Workloads. In Proceedings of the 18th Large Installation System Administration Conference (LISA 2004). USENIX Association, Atlanta, GA, USA, 241--254."},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1145\/3609021.3609297"},{"key":"e_1_3_2_1_32_1","volume-title":"Linux Plumbers Conference (LPC'23)","author":"Sahu Raj","year":"2023","unstructured":"Raj Sahu and Dan Williams. 2023. When BPF programs need to die: exploring the design space for early BPF termination. In Linux Plumbers Conference (LPC'23). https:\/\/lpc.events\/event\/17\/contributions\/1610\/. (Nov. 2023)."},{"key":"e_1_3_2_1_33_1","volume-title":"Linux Plumbers Conference (LPC'23)","author":"Somaraju Sai Roop","year":"2023","unstructured":"Sai Roop Somaraju, Siddharth Chintamaneni, and Dan Williams. [n. d.]. Overflowing the kernel stack with BPF. In Linux Plumbers Conference (LPC'23). https:\/\/lpc.events\/event\/17\/contributions\/1595\/. (Nov. 2023)."},{"key":"e_1_3_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.2410.19135"},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-37709-9_12"}],"event":{"name":"SOSP '25: ACM SIGOPS 31st Symposium on Operating Systems Principles","location":"Seoul Republic of Korea","acronym":"SOSP '25","sponsor":["SIGOPS ACM Special Interest Group on Operating Systems"]},"container-title":["Proceedings of the 4th Workshop on Practical Adoption Challenges of ML for Systems"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3766882.3767179","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,11,13]],"date-time":"2025-11-13T17:19:47Z","timestamp":1763054387000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3766882.3767179"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,10,13]]},"references-count":35,"alternative-id":["10.1145\/3766882.3767179","10.1145\/3766882"],"URL":"https:\/\/doi.org\/10.1145\/3766882.3767179","relation":{},"subject":[],"published":{"date-parts":[[2025,10,13]]},"assertion":[{"value":"2025-10-13","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}