用精心设计的弹窗就能骗过视觉语言智能体,让它们误点广告。
Attacking Vision-Language Computer Agents via Pop-ups
- 用诱导性弹窗干扰视觉语言模型,使其误操作。
- 在测试环境上平均86%成功率,任务完成率下降47%。
- 常规防御如提醒忽略弹窗完全无效,适合安全研究者看。
由大视觉语言模型(VLM)驱动的自主智能体在完成日常计算机任务(如网页订票、操作桌面软件)方面展现出巨大潜力,这需要智能体理解界面视觉输入。尽管视觉输入日益融入智能体应用,但其潜在风险与攻击方式仍不明确。本文证明,通过精心设计的对抗性弹窗可轻易攻击VLM智能体,这些弹窗对人类用户而言通常明显且可忽略。此类干扰导致智能体点击弹窗而非执行原任务。将此类弹窗集成至OSWorld和VisualWebArena等现有智能体测试环境后,平均攻击成功率达86%,任务成功率下降47%。基础防御手段(如要求智能体忽略弹窗或添加广告提示)对本攻击无效。
原文摘要 · Abstract (English)
Autonomous agents powered by large vision and language models (VLM) have demonstrated significant potential in completing daily computer tasks, such as browsing the web to book travel and operating desktop software, which requires agents to understand these interfaces. Despite such visual inputs becoming more integrated into agentic applications, what types of risks and attacks exist around them still remain unclear. In this work, we demonstrate that VLM agents can be easily attacked by a set of carefully designed adversarial pop-ups, which human users would typically recognize and ignore. This distraction leads agents to click these pop-ups instead of performing their tasks as usual. Integrating these pop-ups into existing agent testing environments like OSWorld and VisualWebArena leads to an attack success rate (the frequency of the agent clicking the pop-ups) of 86% on average and decreases the task success rate by 47%. Basic defense techniques, such as asking the agent to ignore pop-ups or including an advertisement notice, are ineffective against the attack.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。