Awesome-GUI-Agent-Security
Health Uyari
- License — License: MIT
- Description — Repository has a description
- Active repo — Last push 0 days ago
- Low visibility — Only 9 GitHub stars
Code Uyari
- network request — Outbound network request in scripts/check_links.py
Permissions Gecti
- Permissions — No dangerous permissions requested
Bu listing icin henuz AI raporu yok.
GUI / Computer-Use / Browser Agent 安全论文清单 —— 按攻防轴组织,每篇附中文简介
Awesome-GUI-Agent-Security
English | 简体中文
A curated list of papers on GUI / Computer-Use / Browser Agent security — organized by attack surface and defense layer, not by runtime environment.
This page is the index — one line per paper. Each section links to a page with a 3–5 sentence summary per paper.
Why organized by attack surface instead of environment?Scope: papers whose primary subject is a GUI / computer-use / browser / mobile agent, with a security contribution. Not included: general LLM/agent security that only uses GUI agents as a testbed · agents for security work (pentest, CTF) · pure capability work.
Most GUI agent lists split papers by runtime environment (Web / Mobile / Desktop), which scatters a single attack class across sections: multi-step indirect injection lands under Desktop, efficiency backdoors under Mobile, pop-up attacks under both Web and Desktop. Answering "what visual-layer attacks exist?" means reading every section.
Here the primary axis is attack vector and defense intervention point. Runtime environment is a cross-cutting tag, used as a primary dimension only inside the benchmarks chapter.
Contents
- 0 Surveys & Threat Models · 2
- 1 Attack Surfaces
- 2 Defense Layers
- 3 Benchmarks & Datasets
- 4 Commercial AI Browsers & Product Security
Browse by environment: Web | Mobile | Desktop | Cross-env
0 Surveys & Threat Models
Surveys, SoKs, and mappings onto threat taxonomies such as OWASP ASI and MITRE ATLAS · Summaries →
- CUA Vuln SoK — A Systematization of Security Vulnerabilities in Computer Use Agents · 2025-07 · 🖥️🌐
- Trustworthy GUI Survey — Towards Trustworthy GUI Agents: A Survey · 2025-03 · 🧩
1 Attack Surfaces
Organized by attack vector and entry point, not by runtime environment
1.1 Indirect Prompt Injection
Injection carried by external content: web pages, documents, email · Summaries →
- SIR — Self-improving Red-teaming for Compute Use Agents · 2026-08 · 🖥️🌐
- StepJack — Benchmarking Computer-Use Agent Safety Against Multi-Step Indirect Prompt Injection · 2026-08 · 🖥️🧩
- Invisible Ink — Invisible Ink Threats: Adversarial Goals Behind Legitimate Tasks in Computer-Use Agents · 2026-08 · 🖥️
1.2 Visual-Layer Attacks
Adversarial patches, pop-up lures, typographic attacks, screenshot poisoning · Summaries →
- MIRAGE — Stealthy Visual Prompt Injection for Vulnerability Detection in Web Agents · 2026-06 · 🌐
- Semantic UI Injection — Are GUI Agents Focused Enough? Automated Distraction via Semantic-level UI Element Injection · 2026-04 · 🧩
1.3 Environmental Injection
UI element injection, accessibility tree, spoofed notifications, overlays · Summaries →
- AnTrap — Are Android GUI Agents Robust Against Runtime Anomalies? AnTrap: Evaluating Agents in Dynamic Adversarial Environments · 2026-08 · 📱
- Not an A11y — How Android Accessibility Exposes Mobile AI Agents to Indirect Prompt Injection · 2026-08 · 📱
- eTAMP — Poison Once, Exploit Forever: Environment-Injected Memory Poisoning Attacks on Web Agents · 2026-04 · 🌐
- AdInject — Real-World Black-Box Attacks on Web Agents via Advertising Delivery · 2025-05 · 🌐
1.4 Privilege Escalation & Permission Abuse
OS-level escalation, cross-app privilege abuse, permission-dialog manipulation, TOCTOU · Summaries →
- Allow to Achieve — "Allow" to Achieve, Over-Privileged Inadvertently: The Unintended Cost of Task-Completion-Driven Pop-up Decisions in Mobile GUI Agents · 2026-08 · 📱
- AI Sees — (A)I Sees What You Don't: Exploiting New Attack Surfaces in Third-Party Mobile Agents · 2026-07 · 📱
- PUSV — Temporal UI State Inconsistency in Desktop GUI Agents: Formalizing and Defending Against TOCTOU Attacks on Computer-Use Agents · 2026-04 · 🖥️
- Action Rebinding — Mind the Gap: Action Rebinding Attacks against Android GUI Agents · 2026-01 · 📱
1.5 Data Exfiltration & Privacy
Credential theft, PII leakage, contextual-integrity violations, oversharing · Summaries →
- LoginTrap — Uncovering Task-Agnostic Phishing-Style Indirect Prompt Injection Attacks against LLM-based Web Agents · 2026-08 · 🌐
- Capable but Careless — Do Computer-Use Agents Follow Contextual Integrity? · 2026-06 · 🖥️
- MyPhoneBench — Do Phone-Use Agents Respect Your Privacy? · 2026-04 · 📱
- WebPII — Benchmarking Visual PII Detection for Computer-Use Agents · 2026-03 · 🌐🖥️
- SPILLage — Agentic Oversharing on the Web · 2026-02 · 🌐
1.6 Backdoors & Poisoning
Grounding backdoors, efficiency backdoors, memory poisoning · Summaries →
- AgentRAE — Remote Action Execution through Notification-based Visual Backdoors against Screenshots-based Mobile GUI Agents · 2026-03 · 📱
- SlowBA — An Efficiency Backdoor Attack towards VLM-based GUI Agents · 2026-03 · 📱🧩
1.7 Unintended Harm from Benign Instructions
No adversary involved — harm arising from the agent's own behavior on normal tasks · Summaries →
- Alignment Is Local — A Paired Diagnostic for GUI Agents under User Persuasion · 2026-07 · 📱🧩
2 Defense Layers
Organized by where the defense intervenes in the execution chain
2.1 Input Filtering & Sanitization
Filtering or masking untrusted content before it enters the model context · Summaries →
- UCM — Untrusted Content Masking for Web Agents with Security Guarantees · 2026-07 · 🌐
- Cognitive Firewall — The Cognitive Firewall: Securing Browser Based AI Agents Against Indirect Prompt Injection Via Hybrid Edge Cloud Defense · 2026-03 · 🌐
2.2 Pre-execution Risk Assessment
World-model prediction, action risk scoring · Summaries →
- WebGuard — Building a Generalizable Guardrail for Web Agents · 2025-07 · 🌐
2.3 Runtime Interception & Access Control
Information-flow tracking, OS-level policy enforcement, sandboxing · Summaries →
- CURA — Certified Runtime Alarms for Computer-Use Agents · 2026-08 · 🖥️
- Prismata — Confining Cross-Site Prompt Injection in Web Agents · 2026-07 · 🌐
- CSAgent — Secure and Efficient Access Control for Computer-Use Agents via Context Space · 2025-09 · 🖥️
2.4 Human-in-the-Loop & Confirmation
Confirmation before critical actions, approval gates, interruptibility
No entries yet
2.5 Post-hoc Recovery & Rollback
Failure attribution, state rollback, repair after harm has occurred · Summaries →
- CUADebug — Diagnosing and Repairing Computer-Use Agent Failures · 2026-07 · 🖥️
2.6 Formal Guarantees & Verification
Defenses with provable guarantees: formal verification, control-flow integrity, conformal risk control · Summaries →
- CORA — Conformal Risk-Controlled Agents for Safeguarded Mobile GUI Automation · 2026-04 · 📱
3 Benchmarks & Datasets
The only chapter where runtime environment serves as a primary organizing dimension
3.1 Comprehensive & Cross-environment
Benchmarks spanning multiple environments or threat classes · Summaries →
- ADeptS-Bench — Measuring the Trustworthiness of Computer Use Agents Across Devices · 2026-08 · 🖥️📱
- AgentHazard — A Benchmark for Evaluating Harmful Behavior in Computer-Use Agents · 2026-04 · 🖥️
3.2 Web Environment
Security evaluation for web / browser agents · Summaries →
- Who Pays the Price — Who Pays the Price? Stakeholder-Centric Prompt Injection Benchmarking for Real-world Web Agents · 2026-06 · 🌐
3.3 Mobile Environment
Security evaluation for mobile / Android / iOS agents · Summaries →
- MobileWorldSafety — Benchmarking GUI Agent Safety Against Environmental Injection Attacks in Android Apps · 2026-08 · 📱
- GhostEI-Bench — Do Mobile Agents Resilience to Environmental Injection in Dynamic On-Device Environments? · 2025-10 · 📱
3.4 Desktop & OS Environment
Security evaluation for desktop / OS-level computer-use agents · Summaries →
- OS-Harm — A Benchmark for Measuring Safety of Computer Use Agents · 2025-06 · 🖥️
4 Commercial AI Browsers & Product Security
Primarily non-arXiv sources: vendor security advisories, CVEs, security blogs, disclosures. See docs/MAINTENANCE.md for how this chapter is tracked.
No entries yet
Contributing
Edit data/papers.yaml only — README.md, README.zh-CN.md, and everything under docs/ are generated by GitHub Actions. See CONTRIBUTING.md for inclusion criteria and entry format, and MAINTENANCE.md for the update workflow.
Related lists
This list focuses on the security of GUI/CUA agents. For adjacent areas:
- General agent security (full OWASP ASI spectrum):
LLMSecurity/awesome-agent-skills-security - Using agents for security work (red teaming / pentest):
kagnlp/Awesome-Agentic-Security - Agent auditing and provenance:
yzhao062/awesome-auditable-ai - GUI agent capability research:
OSU-NLP-Group/GUI-Agents-Paper-List
Yorumlar (0)
Yorum birakmak icin giris yap.
Yorum birakSonuc bulunamadi