Uber开源ADR智能体安全检测与响应系统
Uber 在 GitHub 上开源了 ADR(Agentic AI Detection and Response)企业级 AI 智能体安全系统,并将其部署在生产环境中。开源仓库包含 ADR Discovery、ADR Sensor、ADR-Bench 和 ADR Detector 四部分,可盘点终端上的 AI 应用、CLI 智能体、IDE 扩展、本地模型运行时和 MCP 服务器,并从 Claude Code、Cursor、Codex、GitHub Copilot CLI、DeepSeek Harness、opencode、Claude Desktop、Gemini CLI 等 7 种以上编码工具采集智能体意图、工具调用与执行轨迹。据项目介绍,ADR-Bench 含 304 项任务、134 个 MCP 服务器,覆盖全部 17 种智能体攻击手法;ADR Prevention 组件与 ADR Explorer 引擎未纳入本次开源,配套论文被 MLSys 2026 接收。
为什么重要:它把企业智能体的可观测性与威胁检测做成可复用的开源组件,为企业落地 AI 编码智能体提供了安全基线参考。
ADR secures enterprise AI agents through observability, security benchmarking, and threat detection. Deployed at Uber.
https://arxiv.org/abs/2605.17380
ADR: Agentic AI Detection and Response
ADR (Agentic AI Detection and Response) is an enterprise security system for AI agents. It helps organizations secure employee-facing agents such as Cursor, Claude Code, Codex, GitHub Copilot CLI, and DeepSeek Harness, as well as customer-facing agents such as AI support agents.
ADR is deployed in production at Uber, and the accompanying paper was accepted to MLSys 2026: Paper PDF · Slides PDF
How ADR secures enterprise AI agents
ADR secures enterprise AI agents through five complementary capabilities: discovering unsanctioned AI tools, observing agent activity, evaluating defenses, detecting threats, and preventing unsafe actions.
- ADR Discovery: Find the AI tools present on employee endpoints. Inventories installed AI applications, CLI agents, IDE extensions, local model runtimes, and MCP servers, and flags unknown surfaces for review.
- ADR Observability: Understand what AI agents are doing and why. In production, ADR captures agent intent, tool use, and execution traces across 7+ AI coding tools on macOS, Linux, and Windows, as well as internal automation and customer-facing support agents.
- ADR Benchmark: Test agent security under realistic enterprise conditions. ADR-Bench includes 300+ tasks, 134 MCP servers, and coverage of all 17 agent attack techniques.
- ADR Detection: Detect risky agent behavior efficiently. Its two-tier architecture combines high-recall triage with deeper agentic reasoning for suspicious sessions.
- ADR Prevention: Stop unsafe actions before they cause harm. This component is not included in the current open-source release. Stay tuned.
Repository layout
This repository contains the open-source ADR Discovery, ADR Sensor, ADR-Bench, and ADR Detector described in the paper. The offline ADR Explorer engine, which hardens ADR Detection through pre-deployment red teaming, is not included here.
| Path | ADR component | Description |
|---|---|---|
| Discovery/ | ADR Discovery | Inventory the AI apps, CLI agents, IDE extensions, model runtimes, and MCP servers on an endpoint, and flag unknown surfaces for review |
| Sensor/ | ADR Observability | Collect and normalize agent telemetry from Claude Code, Cursor, Codex, GitHub Copilot CLI, DeepSeek Harness, opencode, Claude Desktop, and others |
| Detection/ | ADR Benchmark + Detection | Dual-agent detector, 134 MCP servers, 304 benchmark tasks, baselines, figure scripts |
| docs/REPRODUCIBILITY.md | Evaluation | Step-by-step workflow to reproduce benchmark detection and paper figures |
Quick start: ADR Detection
git clone https://github.com/uber/ADR
cd ADR/Detection
uv sync
export ANTHROPIC_API_KEY="..." OPENAI_API_KEY="..."
Default detector is adr (ADR dual-agent). For keyless smoke tests, use --detector llamafirewall (see Detection/README.md).
See docs/REPRODUCIBILITY.md for the full evaluation workflow (inflate packed benchmark → run detectors → plot figures).
Component documentation:
ADR Sensor also captures Gemini CLI session journals on macOS, Linux, and Windows, including tool results and nested subagent sessions.
- Discovery/README.md: endpoint inventory, probes, and the fingerprint catalog
- Sensor/README.md: telemetry collection and unified schema
- Detection/README.md: ADR-Bench, detector baselines, MCP infrastructure
Citation
@inproceedings{li2026adr,
title={ADR: An Agentic Detection System for Enterprise Agentic AI Security},
author={Li, Chenning and Hu, Pan and Xu, Justin and Ozbas, Baris and Liu, Olivia and Van, Caroline and Li, Manxue and Zhou, Wei and Alizadeh, Mohammad and Zhang, Pengyu and Sriramadhesikan, KK and Zhang, Ming},
booktitle={Proceedings of the Ninth Conference on Machine Learning and Systems},
year={2026}
}
Or use CITATION.cff.
Star History
License
Apache License 2.0. See LICENSE. Detection/benchmark/agentdojo/ is vendored third-party code under its own LICENSE (MIT).
Data notice
Detection/ includes synthetic benchmark fixtures (fake credentials, emulated environments, prompt-injection scenarios) for defensive security research only. Details: docs/OPEN_SOURCE_REVIEW.md.
前因后果
- Meta Muse 五天为 CEO 省下 3105 美元The Next Web · Claude Code
- gpt-instruct 发布 Codex 破甲提示词预发布版GitHub Trending · Python · Codex
- Addy Osmani 开源智能体技能包GitHub Trending(每日) · Claude Code
- cmux:面向 AI 编程智能体的开源 macOS 终端GitHub Trending(每日) · Claude Code
- Cua 发布智能体桌面平台 Cua SpacesGitHub Trending(每日) · Claude Code
- OpenAI推出多智能体Dots,研究员称其功劳不足10%InfoQ 中文 AI&大模型 · Codex