الملخص
Modern Computer Use Agents (CUAs) directly interact with graphical user interfaces and execute third-party web tools, exposing them to indirect prompt injection across every rendered page and tool response. While the Dual-LLM pattern is the primary system-level architecture offering formal security guarantees - using an isolated Planner LLM (P-LLM) to fix execution paths before processing untrusted inputs via a Quarantined LLM (Q-LLM) - these guarantees break down in graphical environments. Because CUA interaction is inherently dynamic, plans cannot remain data-independent; they must branch based on anticipated runtime web content - covering all possible cases the agent may encounter. This exposes agents to branch steering attacks, where an adversary crafts untrusted data to coerce a CUA down a hazardous, pre-approved branch without injecting explicit instructions. We systematically study branch steering attacks and introduce STEER-Bench (101 tasks across 9 domains), showing high attack success against both standard (94.4%) and vanilla Dual-LLM (89.5%) CUAs. We then propose COBRA, an architecture that pairs trusted branching plans with ahead-of-time capability constraints, strictly bounding the parameters and destinations each branch may execute. On STEER-Bench, COBRA reduces attack success to 0% while retaining 97% benign utility.
الكلمات المفتاحية
الموضوع
بيانات النشر
- المجلة
- غير متاح
- وصول مفتوح
- وصول مفتوح أخضر
اقتبس هذه المقالة
APA 7
Zingrillo, G., Foerster, H., Shumailov, I., Zhao, Y., & Mullins, R. (2026). Securing Computer-Use Agents Against Branch Steering Attacks. https://omanscience.com/ar/articles/securing-computer-use-agents-against-branch-steering-attacks
MLA 9
Zingrillo, Giulio, et al. "Securing Computer-Use Agents Against Branch Steering Attacks." https://omanscience.com/ar/articles/securing-computer-use-agents-against-branch-steering-attacks.
شيكاغو (المؤلف–التاريخ)
Zingrillo, Giulio, Hanna Foerster, Ilia Shumailov, Yiren Zhao, and Robert Mullins. 2026. "Securing Computer-Use Agents Against Branch Steering Attacks." https://omanscience.com/ar/articles/securing-computer-use-agents-against-branch-steering-attacks.
هارفارد
Zingrillo, G., Foerster, H., Shumailov, I., Zhao, Y. and Mullins, R. (2026) 'Securing Computer-Use Agents Against Branch Steering Attacks', Available at: https://omanscience.com/ar/articles/securing-computer-use-agents-against-branch-steering-attacks.
فانكوفر
Zingrillo G, Foerster H, Shumailov I, Zhao Y, Mullins R. Securing Computer-Use Agents Against Branch Steering Attacks. https://omanscience.com/ar/articles/securing-computer-use-agents-against-branch-steering-attacks
IEEE
G. Zingrillo, H. Foerster, I. Shumailov, Y. Zhao, and R. Mullins, "Securing Computer-Use Agents Against Branch Steering Attacks," https://omanscience.com/ar/articles/securing-computer-use-agents-against-branch-steering-attacks.