arXiv:2606.13686cs.CLcs.CY2026-06ACL

测试电商网页欺骗性界面下智能代理的安全性,发现现有模型极易被误导。

Benchmarking Web Agent Safety under E-commerce Deceptive Interfaces

论文配图:Benchmarking Web Agent Safety under E-commerce Deceptive Interfaces
图 1 · 摘自论文原文
  • 构建可配置的插件框架WebDecept,注入七类真实存在的欺骗界面。
  • 多模态代理在欺骗界面下失败率高,提示约束难以有效防御。
  • 揭示界面设计如何影响欺骗成功率,为安全防护提供依据。

随着自主网络代理被越来越多地用于执行现实任务,其安全性已成为关键问题。本文研究了在电商领域真实欺骗性界面下的代理行为。我们提出了WebDecept——一个轻量且可配置的插件框架,可将欺骗性界面模式注入现有网页环境。利用该框架,我们实例化了七类开放网络中常见的欺骗模式,包括定向广告、域名跳转和购物操纵。通过在任务执行过程中注入这些模式,对多个多模态网络代理进行了受控评估。结果表明,当前网络代理对多种欺骗界面高度敏感,且基于提示的约束通常无法有效缓解此类失效。我们进一步分析了欺骗模式的设计选择如何影响操纵的成功率。这些发现凸显了在代理向真实世界部署时亟需解决的安全挑战。

原文摘要 · Abstract (English)

As autonomous web agents are increasingly deployed to perform real-world tasks, ensuring their safety has become a critical concern. In this work, we study web agent behavior under realistic deceptive interfaces in the e-commerce domain. We introduce WebDecept, a lightweight and configurable plugin framework that enables controlled injection of deceptive interface patterns into existing web environments. Using WebDecept, we instantiate seven deceptive patterns commonly observed on the open web, including targeted advertisements, domain redirection, and shopping manipulation. By injecting these patterns into the frontend during task execution, we perform controlled evaluation of multiple multimodal web agents. Our results show that current web agents are highly susceptible to multiple classes of deceptive interfaces, and that prompt-based constraints are often insufficient to mitigate these failures. We further analyze how the design choices of deceptive patterns influence the success of such manipulations. These findings highlight safety challenges that should be addressed as web agents are scaled toward real-world deployment.

web代理安全评测电商欺骗

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。