The SADB_X_KM_COOKIE extension was intended to provide at least indicators of which KM process introduced a particular IPsec SA. Look at SADB_X_KMP_* values, and how the 64-bit cookie can be used. The PF_KEY tests have example usages.
The KM_COOKIE extension may need to be leveraged more fully in mass-DELETE/FLUSH or other such operations, but it's a very good start.