构建统一框架,提升计算机使用智能体在真实环境中的可靠性。
Securing Computer-Use Agents: A Unified Architecture-Lifecycle Framework for Deployment-Grounded Reliability

- 分架构与生命周期双视角,分析感知-决策-执行链路与部署各阶段风险
- 揭示失败可见性与成因源头的分离,定位控制干预的关键节点
- 适合关注智能体安全、系统可靠性和长期运维的研究者
计算机使用智能体(CUAs)正从受限基准测试转向真实软件环境,需操作浏览器、桌面、移动应用、文件系统、终端及工具后端。在此类环境中,可靠性不再仅由任务成功率定义:感知误差、规划偏差、记忆使用、工具调用、权限范围和运行时监管共同决定智能体行为是否符合用户意图。现有综述多按方法、平台、基准或安全威胁分类,但未能明确关联能力形成、权限暴露、故障显现与控制位置之间的关系。为此,本文提出一个面向部署落地的可靠性架构-生命周期框架。架构层面将感知、决策、执行视为耦合层,实现软件观测到授权动作的转换;生命周期层面考察创建、部署、运行与维护四个阶段,涵盖先验学习、工具与权限绑定、运行轨迹压力测试及漂移下的保障维持。通过该框架,分析代表性系统、基准与安全/隐私研究,区分故障显现点与根源引入点,并映射出重复出现的控制、监督与保证干预面。OpenClaw仅作为开放部署模式的公开示例,非内部验证案例。结论指出可控接地、长程约束保持、安全权限绑定、混合信任运行时防御、隐私保护记忆及持续保证等开放挑战。
原文摘要 · Abstract (English)
Computer-use agents(CUAs)are moving frombounded benchmarks toward real software environments, wherethey operate browsers, desktops, mobile applications, flesystems,terminals, and tool backends. In such settings, reliability isno longer captured by task success alone: perception errors,planning drift, memory use, tool mediation, permission scope,and runtime oversight jointly determine whether agent actionsremain aligned with user intent, Existing surveys organize theCUA landscape by methods, platforms, benchmarks, or securitythreats, but less explicitly connect capability formation, author-ity exposure, failure manifestation, and control placement. Toaddress this gap, the article develops an architecture-lifecycleframework for deployment-grounded reliability in CUAs. Thearchitectural view analyzes Perception, Decision, and Executionas coupled layers that transform software observations intoauthority-bearing actions, The lifecycle view examines Creation.Deployment, Operation, and Maintenance as stages in which priorsare learned, tools and permissions are bound, runtime trajecto.ries are stressed, and assurance must be preserved under drift.Using this lens, the analysis synthesizes representative systems,benchmarks, and security/privacy studies; distinguishes wherefailures become visible from where their enabling conditions areintroduced, and maps recurring intervention surfaces for controloversight, and assurance. OpenClaw is used only as a public moti.vating example of an open deployment pattern, not as a verifedinternal case study. The conclusion highlights open challengesin controllable grounding, long-horizon constraint preservation,safe authority binding, mixed-trust runtime defense, privacy-preserving memory,and continual assurance.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。