AI Agents 相关度: 9/10

Preference Redirection via Attention Concentration: An Attack on Computer Use Agents

Dominik Seip, Matthias Hein
arXiv: 2604.08005v1 发布: 2026-04-09 更新: 2026-04-09

AI 摘要

提出PRAC攻击,通过控制注意力改变CUA选择目标,针对CUA视觉模态的安全漏洞。

主要贡献

  • 提出PRAC攻击,通过注意力重定向操纵CUA的偏好
  • 证明PRAC攻击在白盒条件下有效,并能泛化到微调模型
  • 揭示了CUA视觉模态的安全漏洞,强调了防御的重要性

方法论

通过在GUI界面中嵌入隐蔽的对抗性补丁,重定向VLM的注意力,使其偏好攻击者选择的目标。

原文摘要

Advancements in multimodal foundation models have enabled the development of Computer Use Agents (CUAs) capable of autonomously interacting with GUI environments. As CUAs are not restricted to certain tools, they allow to automate more complex agentic tasks but at the same time open up new security vulnerabilities. While prior work has concentrated on the language modality, the vulnerability of the vision modality has received less attention. In this paper, we introduce PRAC, a novel attack that, unlike prior work targeting the VLM output directly, manipulates the model's internal preferences by redirecting its attention toward a stealthy adversarial patch. We show that PRAC is able to manipulate the selection process of a CUA on an online shopping platform towards a chosen target product. While we require white-box access to the model for the creation of the attack, we show that our attack generalizes to fine-tuned versions of the same model, presenting a critical threat as multiple companies build specific CUAs based on open weights models.

标签

Computer Use Agents 安全攻击 对抗性攻击 注意力机制 视觉模态

arXiv 分类

cs.LG