Aegis SDK Technical Audit & Benchmarks
Empirical security and latency evaluation of the Aegis Multi-Layer AI Security & Governance Engine across 51 total executions under OWASP 2025 standard test conditions.
Dataset Breakdown
Dataset A (Telemetry Traces) vs Dataset B (Automated OWASP Suite)
| Evaluation Metric | Dataset A (Telemetry Traces) | Dataset B (Automated Suite) | Unified Benchmark Total |
|---|---|---|---|
| Total Evaluation Test Runs | 27 | 24 | 51 Runs |
| Adversarial Threats Evaluated | 21 | 19 | 40 Malicious Prompts |
| Attacks Intercepted & Blocked | 20 / 21 (95.2%) | 19 / 19 (100%) | 39 / 40 (97.5%) |
| Benign Control Prompts | 6 | 5 | 11 Control Queries |
| Benign Prompts Allowed | 6 / 6 (100%) | 4 / 5 (80.0%) | 10 / 11 (90.9%) |
| Mean Interception Latency | ~612 ms | ~584 ms | ~598.2 ms |
Threat Domain Coverage & Accuracy Matrix
Categorized according to OWASP Top 10 for LLM Applications (2025 Standard)
| OWASP Code | Category Description | Prompts Tested | Intercepted | Block Rate | Primary Threat Flags Triggered |
|---|---|---|---|---|---|
| LLM01 | Direct System Prompt Override | 8 | 8 | 100% | prompt_injectionunauthorized_access |
| LLM02 | Sensitive Data Exfiltration | 6 | 6 | 100% | sensitive_data_accessdata_breach |
| LLM01 | Jailbreak & Payload Generation | 6 | 5 | 83.3% | malware_creationjailbreak |
| LLM06 | Privilege Escalation & Auth Bypass | 4 | 4 | 100% | unauthorized_accessjailbreak |
| LLM08 | Destructive Operations (SQL/OS) | 4 | 4 | 100% | destructive_actionprompt_injection |
| SEC-SOC | Social Engineering & Fraud | 4 | 4 | 100% | financial_fraudphishing |
| SEC-ROLE | Persona & Authority Hijacking | 4 | 4 | 100% | unauthorized_accessmalicious_action |
| SEC-OBF | Encoded & Obfuscated Payloads | 4 | 4 | 100% | potential_malicious_codeprompt_injection |
| CTRL-SAFE | Benign Control Suite | 11 | 10 | 90.9% (Allowed) | Clean Execution - 1 Warning |
Multi-Layer Execution Pipeline Efficiency
Two-stage execution pipeline designed to eliminate latency and API costs for enterprise workloads.
Stage 1: CPU Heuristic Pre-Filter
Instant pattern matching for known dangerous keywords, system overrides, and regex guardrails. Drops malicious inputs locally without consuming cloud tokens or causing network latency.
Stage 2: Layer 1 & 2 Policy Analysis
Contextual evaluation against custom natural language policies. Evaluates tool permissions, risk levels, and stateful human approval gates.
Threat Indicator Taxonomy
8 threat flag categories automatically tracked in telemetry logs
Direct instruction override and persona manipulation
Unauthorized namespace or system role access requests
Attempts to access environment variables, connection strings, or PII
SQL DROP/TRUNCATE/DELETE statements and destructive OS commands
Prompts requesting ransomware, keyloggers, or exploit payloads
Impersonation scripts targeting financial authorization
Social engineering SMS/email scam generation
Encoded or obfuscated instructions (Base64/Hex)
Technical Due Diligence & Assessment
Enterprise Reliability
Across 51 total evaluation runs across two independent test phases, Aegis demonstrated an empirical 97.5% threat interception score (39/40 attacks blocked) and a 90.9% precision score on benign control inputs.
Cost-Effective Defense
By intercepting over 97% of threat patterns at Layer 1/2, Aegis prevents malicious traffic from incurring downstream LLM inference costs or exhausting API quota limits.
Zero-Trust Compliance
Local execution capabilities ensure that sensitive policy evaluations occur on-device or within private VPC boundaries, fulfilling strict financial (BFSI) and enterprise compliance standards.