系统梳理计算机使用代理的安全风险与防御策略,为构建安全智能助手提供指南。
A Survey on the Safety and Security Threats of Computer-Using Agents: JARVIS or Ultron?
- 定义计算机使用代理并构建安全威胁分类体系
- 提出涵盖防御策略的完整分类框架
- 总结评估工具与数据集,适合安全研究者与开发者参考
近年来,基于大语言模型的智能体已从原型工具演变为能模拟人类操作图形界面的复杂系统,催生出能够自主执行桌面应用、网页和移动应用任务的计算机使用代理(CUAs)。随着其能力增强,新型安全与风险问题随之浮现。大模型推理漏洞,叠加多软件组件集成与多模态输入的复杂性,进一步加剧了安全挑战。本文系统梳理了CUAs的安全与风险问题,围绕四个目标展开:(i) 明确适于安全分析的CUA定义;(ii) 对现有安全威胁进行分类;(iii) 提出全面的防御策略分类体系;(iv) 梳理主流基准、数据集与评估指标。基于这些发现,本工作为未来研究者探索未知漏洞提供结构化基础,并为从业者设计与部署安全代理提供可操作指导。
原文摘要 · Abstract (English)
Recently, AI-driven interactions with computing devices have advanced from basic prototype tools to sophisticated, LLM-based systems that emulate human-like operations in graphical user interfaces. We are now witnessing the emergence of \emph{Computer-Using Agents} (CUAs), capable of autonomously performing tasks such as navigating desktop applications, web pages, and mobile apps. However, as these agents grow in capability, they also introduce novel safety and security risks. Vulnerabilities in LLM-driven reasoning, with the added complexity of integrating multiple software components and multimodal inputs, further complicate the security landscape. In this paper, we present a systematization of knowledge on the safety and security threats of CUAs. We conduct a comprehensive literature review and distill our findings along four research objectives: \textit{\textbf{(i)}} define the CUA that suits safety analysis; \textit{\textbf{(ii)} } categorize current safety threats among CUAs; \textit{\textbf{(iii)}} propose a comprehensive taxonomy of existing defensive strategies; \textit{\textbf{(iv)}} summarize prevailing benchmarks, datasets, and evaluation metrics used to assess the safety and performance of CUAs. Building on these insights, our work provides future researchers with a structured foundation for exploring unexplored vulnerabilities and offers practitioners actionable guidance in designing and deploying secure Computer-Using Agents.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。