Sub-session per-tool-call attribution

Establish reliable attribution of individual syscalls or kernel events to specific tool calls within an agent session, extending beyond the session-level attribution provided by the one-strace-per-single-session-container design.

Background

The ACE corpus guarantees attribution at the session level by running each agent execution in a separate Docker container with its own PID namespace and a single strace attached to the session's root process tree. This design ensures that recorded events can be assigned to the corresponding session, but it does not identify which individual tool call generated each event.

The paper explicitly distinguishes this unresolved granularity problem from its achieved session-level guarantee. Per-tool-call attribution would support finer-grained auditing and detection within long or multi-step agent sessions, but the paper leaves the problem outside its scope.

References

Session-level attribution is deterministic under our capture design (\S\ref{sec:corpus:attribution}), but sub-session per-tool-call attribution is a harder open problem out of scope for this work.

— On the Effectiveness of Kernel-Level Evidence for Agent Security  (2609.28915 - King et al., 24 Sep 2026) in Appendix, Section "Limitations," limitation (iii), "Session-level attribution"

Open problems include the restriction to one active request at a time, dependence on application externalization, and reduced effectiveness on encrypted database connections.

— TraceLib: System-Call Bitmap Feedback Mechanism for Language-Agnostic Web Fuzzing  (2609.34778 - Dharmaadi et al., 28 Sep 2026) in Abstract; Section ‘Limitations’, subsection ‘Single Active Request’