June 2026Unreviewed
AgenticOS: An Intent-Oriented Secure Operating System Architecture for Autonomous AI Agents
Zhen Zhao, Yu Zhang, Yanpeng Zhu, Jia Wang, Songqiao Tao, Xin Cheng, Jiexin Gao
Abstract
Traditional OS security models based on "resource exposure plus permission checks" face structural challenges as LLM-driven autonomous agents acquire capabilities for planning, tool use, network access, and code execution. Once an agent runtime is compromised through prompt injection or malicious tool outputs, an attacker can compose POSIX-style resource primitives into behaviors far beyond the user's task authorization. To address this, we propose AgenticOS, an intent-oriented secure OS archite
Categories
Framework mappings
OWASP Top 10 for LLM Applications
- LLM01Prompt Injection
OWASP Top 10 for Agentic Applications
- ASI02Tool Misuse & Exploitation
MITRE ATLAS
- AML.T0051LLM Prompt Injection
- AML.T0053AI Agent Tool Invocation
Suggested from the entry's categories.
Cite
@misc{zhao2026agenticos,
title = {{AgenticOS: An Intent-Oriented Secure Operating System Architecture for Autonomous AI Agents}},
author = {Zhen Zhao and Yu Zhang and Yanpeng Zhu and Jia Wang and Songqiao Tao and Xin Cheng and Jiexin Gao},
year = {2026},
month = jun,
eprint = {2606.21129},
archivePrefix = {arXiv},
url = {https://arxiv.org/abs/2606.21129}
}