构建混合环境测试框架,揭示智能助手在网页与系统间易受攻击的隐患。
RedTeamCUA: Realistic Adversarial Testing of Computer-Use Agents in Hybrid Web-OS Environments
- 设计虚拟机+容器混合沙箱,支持真实可控的跨界面攻击测试。
- 864个案例测试显示,最强模型仍有60%成功率被诱导执行恶意任务。
- 适合安全研究人员和智能助手开发者,关注间接提示注入风险。
计算机使用代理(CUA)有望在操作系统与网络间自动化复杂任务,但易受间接提示注入攻击。现有评估或缺乏真实可控环境,或忽略网页与系统协同的攻击场景。为此,我们提出RedTeamCUA,一个集成虚拟机操作系统与Docker网页平台的新型混合沙箱,支持灵活配置攻击场景,并可直接在注入点启动测试以脱离导航限制。基于该框架,我们构建了RTC-Bench基准,包含864个真实混合攻击案例,揭示了基础安全漏洞。测试表明,Claude 3.7 Sonnet | CUA的攻击成功率为42.9%,最安全的Operator仍有7.6%;多数代理尝试执行攻击任务的尝试率达92.5%,但因能力不足失败。值得注意的是,在真实端到端环境中,最新版Claude 4.5 Sonnet | CUA的最高攻击成功率达到60%,表明威胁已具现实风险。RedTeamCUA为系统性分析CUA漏洞提供了必要工具,凸显部署前亟需强化防御机制。
原文摘要 · Abstract (English)
Computer-use agents (CUAs) promise to automate complex tasks across operating systems (OS) and the web, but remain vulnerable to indirect prompt injection. Current evaluations of this threat either lack support realistic but controlled environments or ignore hybrid web-OS attack scenarios involving both interfaces. To address this, we propose RedTeamCUA, an adversarial testing framework featuring a novel hybrid sandbox that integrates a VM-based OS environment with Docker-based web platforms. Our sandbox supports key features tailored for red teaming, such as flexible adversarial scenario configuration, and a setting that decouples adversarial evaluation from navigational limitations of CUAs by initializing tests directly at the point of an adversarial injection. Using RedTeamCUA, we develop RTC-Bench, a comprehensive benchmark with 864 examples that investigate realistic, hybrid web-OS attack scenarios and fundamental security vulnerabilities. Benchmarking current frontier CUAs identifies significant vulnerabilities: Claude 3.7 Sonnet | CUA demonstrates an ASR of 42.9%, while Operator, the most secure CUA evaluated, still exhibits an ASR of 7.6%. Notably, CUAs often attempt to execute adversarial tasks with an Attempt Rate as high as 92.5%, although failing to complete them due to capability limitations. Nevertheless, we observe concerning high ASRs in realistic end-to-end settings, with the strongest-to-date Claude 4.5 Sonnet | CUA exhibiting the highest ASR of 60%, indicating that CUA threats can already result in tangible risks to users and computer systems. Overall, RedTeamCUA provides an essential framework for advancing realistic, controlled, and systematic analysis of CUA vulnerabilities, highlighting the urgent need for robust defenses to indirect prompt injection prior to real-world deployment.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。