KernelArena
Yash Ramani, Prince Ramani · Team KernelArena
Submitted to AI Control Hackathon 2026. Sprint projects are early-stage work by participants, not Apart Research publications.
We introduce KernelArena, a control setting for evaluating whether AI monitors can detect xz-style sabotage in low-level code. Motivated by CVE-2024-3094, we construct 10 tasks spanning Linux kernel and embedded firmware domains, each pairing a real vulnerability class with a sabotage pattern drawn from the xz backdoor's technical primitives. Two tasks have full kernel infrastructure (compilable module, visible tests, hidden triggers); all 10 are evaluated as patch-level code review tasks across three frontier monitors (GPT-4o, Claude Sonnet 4, Gemini 2.5 Flash) totalling 210+ LLM calls including multi-run variance analysis. Our key findings: (1) GPT-4o detects only 40% of sabotaged patches at 10% FPR; (2) a 1-character firmware sabotage (< vs <=) evades all three monitors across all runs; (3) off-the-shelf static analysis (cppcheck) detects 0/10 sabotaged patches — LLM monitors are strictly superior; (4) the k_ioctl_raretrigger honest fix triggers a systematic false positive (score 8–9/10 across all models and runs) because the fix restructures control flow in a way that looks suspicious, revealing a fundamental tension between correct-but-unusual patches and monitor conservatism. We are explicit about scope: this evaluates patch-level classification, not full agentic trajectory monitoring. The domain contribution is the xz-grounded task taxonomy and the empirical finding that low-level code is structurally harder to monitor than application-level code.
Reviews
Cool idea to focus on Kernels! I agree that this type of monitoring is very important and should be studied more.
I would have liked to see the full monitor prompt in your appendix, and an explanation for how you created it. Monitor performance often depends heavily on prompting, so this would be good to present clearly.
I was occasionally confused about which attacker models were used for which experiments. I think this could have been presented more clearly in your work.
As a minor note: I think the use of 5 as a cutoff for suspicion is not fully justified. I think you should instead decide on a FPR and choose the threshold that responds to that.
Overall great project. I'd suspect that Sonnet 4 would be a better monitor than the other two models because it is more capable, but I imagine these results are somewhat noisy because of the small sample size. The results could be improved by better eliciting monitor performance and running for more epochs/samples.
Cite this project
@misc{ramani2026kernelarena,
title = {{KernelArena}},
author = {Yash Ramani and Prince Ramani},
year = {2026},
month = mar,
note = {Submitted to AI Control Hackathon 2026, an Apart Research Sprint},
howpublished = {\url{https://apartresearch.com/sprints/projects/kernelarena-83z5}},
url = {https://apartresearch.com/sprints/projects/kernelarena-83z5}
}More from AI Control Hackathon 2026
- 1st placeLinuxArena track winnerView project: Omission Attacks: When Doing Nothing Is the Attack
Omission Attacks: When Doing Nothing Is the Attack
MAIA
AI control protocols monitor agent actions to detect sabotage, but omission attacks exploit what the agent fails to do rather than what it does. We define omission attacks as security breaches caused by failing to …
- 2nd placeView project: Detecting LLM Subversion in Vulnerability Patching Settings
Detecting LLM Subversion in Vulnerability Patching Settings
Vuln4Control
LLMs are increasingly used to propose fixes to vulnerabilities in code. If the LLM is misaligned or untrustworthy, it may propose fixes that seem to fix a vulnerability but leave the core issue unresolved in a subtle …
- 3rd placeView project: ActionLens: Pre-Execution Environment Probing for Agent Action Approval
ActionLens: Pre-Execution Environment Probing for Agent Action Approval
Udbhav&Ashok
ActionLens is a pre-execution control protocol for shell and file actions proposed by AI agents. Instead of approving an action from transcript alone, a trusted monitor gathers lightweight environment evidence before …