arXiv:2509.00124cs.CRcs.AI2025-09被引 4

AI浏览代理被网站伪装攻击,人类无感却可能被操控

A Whole New World: Creating a Parallel-Poisoned Web Only AI-Agents Can See

  • 通过识别AI代理指纹,动态呈现伪装网页内容
  • 人类见正常页面,代理却接收含恶意指令的隐藏版
  • 适合关注AI安全、自动化系统防护的研究者阅读

本文提出一种新型攻击方式,利用网站伪装技术针对由大语言模型(LLMs)驱动的自主网络浏览代理。随着这类代理日益普及,其独特的数字指纹——包括浏览器属性、自动化框架标识和网络特征——形成了可区分的网络流量类别。恶意网站能识别出请求来自AI代理,并动态提供内容不同的伪装版本:人类用户看到的是正常页面,而代理则接收到外观相同但嵌入隐藏恶意指令的页面,如间接提示注入。该机制使攻击者可劫持代理行为,导致数据泄露、恶意代码执行或虚假信息传播,且对人类用户和传统安全爬虫完全隐形。本文构建了威胁模型,详述代理指纹识别与伪装机制,并讨论其对智能体人工智能未来的深远安全影响,强调亟需防御此类隐蔽且可扩展的攻击。

原文摘要 · Abstract (English)

This paper introduces a novel attack vector that leverages website cloaking techniques to compromise autonomous web-browsing agents powered by Large Language Models (LLMs). As these agents become more prevalent, their unique and often homogenous digital fingerprints - comprising browser attributes, automation framework signatures, and network characteristics - create a new, distinguishable class of web traffic. The attack exploits this fingerprintability. A malicious website can identify an incoming request as originating from an AI agent and dynamically serve a different, "cloaked" version of its content. While human users see a benign webpage, the agent is presented with a visually identical page embedded with hidden, malicious instructions, such as indirect prompt injections. This mechanism allows adversaries to hijack agent behavior, leading to data exfiltration, malware execution, or misinformation propagation, all while remaining completely invisible to human users and conventional security crawlers. This work formalizes the threat model, details the mechanics of agent fingerprinting and cloaking, and discusses the profound security implications for the future of agentic AI, highlighting the urgent need for robust defenses against this stealthy and scalable attack.

AI安全代理攻击网站伪装

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。