arXiv:2603.18762cs.CRcs.AI2026-03被引 3

提出MITM框架ClawTrap,评估真实网络下OpenClaw的安全性

ClawTrap: A MITM-Based Red-Teaming Framework for Real-World OpenClaw Security Evaluation

  • 基于中间人攻击构建可定制的红队测试框架
  • 弱模型易受篡改观察影响,强模型能识别异常并安全应对
  • 适合关注自主代理网络安全的研究者与开发者

自主网络代理如OpenClaw正快速进入高影响力实际工作流,但其在真实网络威胁下的安全鲁棒性仍缺乏充分评估。现有基准主要聚焦静态沙箱环境和内容级提示攻击,未能覆盖网络层安全测试的实际需求。本文提出ClawTrap——一种基于中间人攻击的红队测试框架,支持多种可定制攻击形式,包括静态HTML替换、Iframe弹窗注入和动态内容修改,并提供规则驱动的拦截、转换与审计可复现流程。实验表明:弱模型更易信任被篡改的观测结果并生成不安全输出,而强模型展现出更好的异常识别能力与更安全的降级策略。结果表明,可靠的OpenClaw安全性评估应明确引入动态真实网络中的MITM条件,而非仅依赖静态沙箱协议。

原文摘要 · Abstract (English)

Autonomous web agents such as \textbf{OpenClaw} are rapidly moving into high-impact real-world workflows, but their security robustness under live network threats remains insufficiently evaluated. Existing benchmarks mainly focus on static sandbox settings and content-level prompt attacks, which leaves a practical gap for network-layer security testing. In this paper, we present \textbf{ClawTrap}, a \textbf{MITM-based red-teaming framework for real-world OpenClaw security evaluation}. ClawTrap supports diverse and customizable attack forms, including \textit{Static HTML Replacement}, \textit{Iframe Popup Injection}, and \textit{Dynamic Content Modification}, and provides a reproducible pipeline for rule-driven interception, transformation, and auditing. This design lays the foundation for future research to construct richer, customizable MITM attacks and to perform systematic security testing across agent frameworks and model backbones. Our empirical study shows clear model stratification: weaker models are more likely to trust tampered observations and produce unsafe outputs, while stronger models demonstrate better anomaly attribution and safer fallback strategies. These findings indicate that reliable OpenClaw security evaluation should explicitly incorporate dynamic real-world MITM conditions rather than relying only on static sandbox protocols.

安全评估中间人攻击自主代理

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。