GitHub - uber/ADR: ADR secures enterprise AI agents through observability, security benchmarking, and threat detection. Deployed at Uber. · GitHub
/" data-turbo-transient="true" />
Skip to content
Type / to search
Sign in<br>Sign upAppearance settings
You signed in with another tab or window. Reload to refresh your session.<br>You signed out in another tab or window. Reload to refresh your session.<br>You switched accounts on another tab or window. Reload to refresh your session.
Dismiss alert
{{ message }}
Uh oh!
There was an error while loading. Please reload this page.
uber
ADR
Public
Notifications<br>You must be signed in to change notification settings
Fork<br>97
Star<br>1.2k
main
BranchesTags
Go to file
CodeOpen more actions menu
Folders and files<br>NameNameLast commit message<br>Last commit date<br>Latest commit
History<br>37 Commits<br>37 Commits
.github
.github
Detection
Detection
Sensor
Sensor
docs
docs
.gitignore
.gitignore
CITATION.cff
CITATION.cff
CODE_OF_CONDUCT.md
CODE_OF_CONDUCT.md
CONTRIBUTING.md
CONTRIBUTING.md
LICENSE
LICENSE
NOTICE.md
NOTICE.md
README.md
README.md
View all files
Repository files navigation
ADR: Agentic AI Detection and Response
ADR (Agentic AI Detection and Response) is an enterprise security system for AI agents. It helps organizations secure employee-facing agents such as Cursor, Claude Code, and Codex, as well as customer-facing agents such as AI support agents.
ADR is deployed in production at Uber , and the accompanying paper was accepted to MLSys 2026 : Paper PDF · Slides PDF
How ADR secures enterprise AI agents
ADR secures enterprise AI agents through four complementary capabilities: observing agent activity, evaluating defenses, detecting threats, and preventing unsafe actions.
ADR Observability: Understand what AI agents are doing and why. In production, ADR captures agent intent, tool use, and execution traces across 7+ AI coding tools on macOS, Linux, and Windows, as well as internal automation and customer-facing support agents.
ADR Benchmark: Test agent security under realistic enterprise conditions. ADR-Bench includes 300+ tasks, 133 MCP servers, and coverage of all 17 agent attack techniques.
ADR Detection: Detect risky agent behavior efficiently. Its two-tier architecture combines high-recall triage with deeper agentic reasoning for suspicious sessions.
ADR Prevention: Stop unsafe actions before they cause harm. This component is not included in the current open-source release. Stay tuned.
Repository layout
This repository contains the open-source ADR Sensor , ADR-Bench , and ADR Detector described in the paper. The offline ADR Explorer engine, which hardens ADR Detection through pre-deployment red teaming, is not included here.
Path<br>ADR component<br>Description
Sensor/<br>ADR Observability<br>Collect and normalize agent telemetry from Claude Code, Cursor, Codex, and others
Detection/<br>ADR Benchmark + Detection<br>Dual-agent detector, 133 MCP servers, 303 benchmark tasks, baselines, figure scripts
docs/REPRODUCIBILITY.md<br>Evaluation<br>Step-by-step workflow to reproduce benchmark detection and paper figures
Quick start: ADR Detection
git clone https://github.com/uber/ADR<br>cd ADR/Detection<br>uv sync<br>export ANTHROPIC_API_KEY="..." OPENAI_API_KEY="..."
Default detector is adr (ADR dual-agent). For keyless smoke tests, use --detector llamafirewall (see Detection/README.md).
See docs/REPRODUCIBILITY.md for the full evaluation workflow (inflate packed benchmark → run detectors → plot figures).
Component documentation:
Sensor/README.md: telemetry collection and unified schema
Detection/README.md: ADR-Bench, detector baselines, MCP infrastructure
Citation
@inproceedings{li2026adr,<br>title={ADR: An Agentic Detection System for Enterprise Agentic AI Security},<br>author={Li, Chenning and Hu, Pan and Xu, Justin and Ozbas, Baris and Liu, Olivia and Van, Caroline and Li, Manxue and Zhou, Wei and Alizadeh, Mohammad and Zhang, Pengyu and Sriramadhesikan, KK and Zhang, Ming},<br>booktitle={Proceedings of the Ninth Conference on Machine Learning and Systems},<br>year={2026}
Or use CITATION.cff.
License
Apache License 2.0. See LICENSE. Detection/benchmark/agentdojo/ is vendored third-party code under its own LICENSE (MIT).
Data notice
Detection/ includes synthetic benchmark fixtures (fake credentials, emulated environments, prompt-injection scenarios) for defensive security research only. Details: docs/OPEN_SOURCE_REVIEW.md.
About<br>ADR secures enterprise AI agents through observability, security benchmarking, and threat detection. Deployed at Uber.<br>arxiv.org/abs/2605.17380<br>Topics<br>agent-securityai-agentsai-securitybenchmarkclaudeclaude-codecodexcursorllm-securitymcpmodel-context-protocolprompt-injectionthreat-detection<br>Resources<br>Readme<br>Apache-2.0 license<br>Code of conduct<br>Code of conduct<br>Contributing<br>Contributing<br>Cite this repository<br>Activity<br>Custom properties<br>Stars<br>1.2k stars<br>Watchers<br>12 watching<br>Forks<br>97 forks<br>Report repository
Releases
Packages
Used...