ADR: Agentic AI Detection and Response
ADR (Agentic AI Detection and Response) is an enterprise security system for AI agents. It helps organizations secure employee-facing agents such as Cursor, Claude Code, and Codex, as well as customer-facing agents such as AI support agents.
ADR is deployed in production at Uber , and the accompanying paper was accepted to MLSys 2026 : Paper PDF · Slides PDF
How ADR secures enterprise AI agents
ADR secures enterprise AI agents through four complementary capabilities: observing agent activity, evaluating defenses, detecting threats, and preventing unsafe actions.
ADR Observability: Understand what AI agents are doing and why. In production, ADR captures agent intent, tool use, and execution traces across 7+ AI coding tools on macOS, Linux, and Windows, as well as internal automation and customer-facing support agents.
ADR Benchmark: Test agent security under realistic enterprise conditions. ADR-Bench includes 300+ tasks, 133 MCP servers, and coverage of all 17 agent attack techniques.
ADR Detection: Detect risky agent behavior efficiently. Its two-tier architecture combines high-recall triage with deeper agentic reasoning for suspicious sessions.
ADR Prevention: Stop unsafe actions before they cause harm. This component is not included in the current open-source release. Stay tuned.
Repository layout
This repository contains the open-source ADR Sensor , ADR-Bench , and ADR Detector described in the paper. The offline ADR Explorer engine, which hardens ADR Detection through pre-deployment red teaming, is not included here.
Quick start: ADR Detection
Default detector is adr (ADR dual-agent). For keyless smoke tests, use --detector llamafirewall (see Detection/README.md ).
See docs/REPRODUCIBILITY.md for the full evaluation workflow (inflate packed benchmark → run detectors → plot figures).
Component documentation:
Sensor/README.md : telemetry collection and unified schema
Detection/README.md : ADR-Bench, detector baselines, MCP infrastructure
Citation
Or use CITATION.cff .
License
Apache License 2.0. See LICENSE . Detection/benchmark/agentdojo/ is vendored third-party code under its own LICENSE (MIT).
Data notice
Detection/ includes synthetic benchmark fixtures (fake credentials, emulated environments, prompt-injection scenarios) for defensive security research only. Details: docs/OPEN_SOURCE_REVIEW.md .