arXiv:2504.11281cs.HCcs.CL2025-04被引 69

LLM GUI代理易受细文字攻击,可能泄露用户隐私。

The Obvious Invisible Threat: LLM-Powered GUI Agents' Vulnerability to Fine-Print Injections

  • 用细文字注入误导代理执行恶意操作
  • 6种攻击在234个网页上均成功触发代理异常
  • 人类也难察觉,需设计更安全的代理系统

基于大语言模型(LLM)的GUI代理是一种根据高层指令自主执行任务的系统,通过视觉感知和理解应用界面,推断操作序列并完成点击、输入等交互。为完成表单填写或服务预订等真实任务,这类代理常需处理敏感用户数据,其自主性引入了新的隐私与安全风险。攻击者可通过向GUI中注入恶意内容,改变代理行为或诱导私密信息泄露。这些攻击利用代理与人类在视觉注意力上的差异,或代理对任务上下文完整性破坏的识别能力不足。本文归纳了六类攻击,并通过实验评估六款先进GUI代理在234个恶意网页上的表现,涉及39名参与者。结果表明,代理高度脆弱,尤其易受上下文嵌入式威胁影响;同时人类用户也普遍受骗,说明单纯人工监督不可靠。这一错位凸显了隐私感知代理设计的迫切需求。论文提出实用防御策略,以推动更安全可靠的GUI代理发展。

原文摘要 · Abstract (English)

A Large Language Model (LLM) powered GUI agent is a specialized autonomous system that performs tasks on the user's behalf according to high-level instructions. It does so by perceiving and interpreting the graphical user interfaces (GUIs) of relevant apps, often visually, inferring necessary sequences of actions, and then interacting with GUIs by executing the actions such as clicking, typing, and tapping. To complete real-world tasks, such as filling forms or booking services, GUI agents often need to process and act on sensitive user data. However, this autonomy introduces new privacy and security risks. Adversaries can inject malicious content into the GUIs that alters agent behaviors or induces unintended disclosures of private information. These attacks often exploit the discrepancy between visual saliency for agents and human users, or the agent's limited ability to detect violations of contextual integrity in task automation. In this paper, we characterized six types of such attacks, and conducted an experimental study to test these attacks with six state-of-the-art GUI agents, 234 adversarial webpages, and 39 human participants. Our findings suggest that GUI agents are highly vulnerable, particularly to contextually embedded threats. Moreover, human users are also susceptible to many of these attacks, indicating that simple human oversight may not reliably prevent failures. This misalignment highlights the need for privacy-aware agent design. We propose practical defense strategies to inform the development of safer and more reliable GUI agents.

GUI代理隐私安全细文字攻击LLM

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。