Research

Watch · narrated whiteboard episodesL2

Behavior-Based Security for AI Agents

Static signatures and fixed permissions were built for deterministic software; autonomous agents defeat both. This series builds behavior-based defense for AI agents from the ground up: why signature and permission controls fail on non-deterministic agents, how to construct a behavioral baseline from action distributions and tool-call profiles, anomaly detection on agent traces with the cold-start problem, enforcement by observed behavior rather than static permission, and the mimicry-evasion limits every behavioral detector must confront. Grounded in NIST AI RMF, NIST SP 800-207 Zero Trust, OWASP LLM Top 10, the OWASP Agentic Security Initiative, MITRE ATLAS, and the anomaly-detection and intrusion-detection literature.

Murali Chillakuru·5 episodes
  1. 12 min Episode 1From Signatures to Behavior: Why Static and Permission Controls Fail on Non-Deterministic AgentsA stage conversation on why enumerating good and bad behavior collapses for autonomous agents, and why modeling normal behavior is the necessary — if bounded — alternative.
  2. 11 min Episode 2Building a Behavioral Baseline: Action Distributions, Tool-Call Profiles, and Sequence ModelsA stage conversation on how to measure an agent's normal behavior as three nested models — marginal, conditional, and sequential — and the data discipline that keeps a baseline honest.
  3. 11 min Episode 3Anomaly Detection on Agent Traces: Sequence Models, Embeddings, and the Cold-Start ProblemA stage conversation on turning a behavioral baseline into alarms — scoring and thresholds, the supervision spectrum, sequence and embedding detectors, and detecting before any normal exists.
  4. 10 min Episode 4Behavior as Enforcement: Allow and Deny by Observed Behavior, Not Just Static PermissionA stage conversation on turning a behavioral signal into runtime action — the enforcement architecture, a graduated response ladder, and fail posture keyed to reversibility.
  5. 10 min Episode 5Evasion and Robustness: Mimicry Attacks on Behavioral Detectors and Their Provable LimitsA stage conversation on the classical limit of behavioral defense — mimicry — and what robustness genuinely buys once you accept that a detector can only raise an attacker's cost.