Agent Immune System
(AIS) is a runtime defense for AI agents. Agents act on whatever is in their
context, so an attacker can hide instructions in a retrieved document or
support ticket and make the agent exfiltrate data. This is indirect prompt
injection, the defining attack surface for agents. Detection tools raise an
alert but never say which input caused it or how to fix it. AIS closes that gap
in one loop.
When a session is
flagged, AIS does 3 things that most defenses miss. First, AIS detects from
provenance flow, not keywords, so that an external send of sensitive data while
untrusted input is present is stopped fast
and hard. Second, Causal replay re-runs
the session with each untrusted input removed to prove the exact input
responsible. Third, AIS vaccinates with an open model on AkashML that generates
evasive variants, a guardrail is synthesized, and it is verified against the
entire recorded corpus in ClickHouse, deploying only on zero false positives.
Re-running the attack is then blocked.
Live on ClickHouse
Cloud on over 601,000 rows. Detection in ~59 ms, verification in ~74 ms, 9 of 9
variants blocked with 0 false positives. The novel and innovative part is the
combination of runtime causal attribution plus auto-remediation
regression-tested against production history.