Awesome-GUI-Agent-Security

agent
Guvenlik Denetimi
Uyari
Health Uyari
  • License — License: MIT
  • Description — Repository has a description
  • Active repo — Last push 0 days ago
  • Low visibility — Only 9 GitHub stars
Code Uyari
  • network request — Outbound network request in scripts/check_links.py
Permissions Gecti
  • Permissions — No dangerous permissions requested

Bu listing icin henuz AI raporu yok.

SUMMARY

GUI / Computer-Use / Browser Agent 安全论文清单 —— 按攻防轴组织,每篇附中文简介

README.md

Awesome-GUI-Agent-Security

English简体中文

A curated list of papers on GUI / Computer-Use / Browser Agent security — organized by attack surface and defense layer, not by runtime environment.

Last Update Papers Time Range Link Check Awesome

This page is the index — one line per paper. Each section links to a page with a 3–5 sentence summary per paper.

Scope: papers whose primary subject is a GUI / computer-use / browser / mobile agent, with a security contribution. Not included: general LLM/agent security that only uses GUI agents as a testbed · agents for security work (pentest, CTF) · pure capability work.

Why organized by attack surface instead of environment?

Most GUI agent lists split papers by runtime environment (Web / Mobile / Desktop), which scatters a single attack class across sections: multi-step indirect injection lands under Desktop, efficiency backdoors under Mobile, pop-up attacks under both Web and Desktop. Answering "what visual-layer attacks exist?" means reading every section.

Here the primary axis is attack vector and defense intervention point. Runtime environment is a cross-cutting tag, used as a primary dimension only inside the benchmarks chapter.

Contents

Browse by environment: WebMobileDesktopCross-env


0 Surveys & Threat Models

Surveys, SoKs, and mappings onto threat taxonomies such as OWASP ASI and MITRE ATLAS · Summaries →

  • CUA Vuln SoK — A Systematization of Security Vulnerabilities in Computer Use Agents · 2025-07 · 🖥️🌐
  • Trustworthy GUI Survey — Towards Trustworthy GUI Agents: A Survey · 2025-03 · 🧩

1 Attack Surfaces

Organized by attack vector and entry point, not by runtime environment

1.1 Indirect Prompt Injection

Injection carried by external content: web pages, documents, email · Summaries →

  • SIR — Self-improving Red-teaming for Compute Use Agents · 2026-08 · 🖥️🌐
  • StepJack — Benchmarking Computer-Use Agent Safety Against Multi-Step Indirect Prompt Injection · 2026-08 · 🖥️🧩
  • Invisible Ink — Invisible Ink Threats: Adversarial Goals Behind Legitimate Tasks in Computer-Use Agents · 2026-08 · 🖥️

1.2 Visual-Layer Attacks

Adversarial patches, pop-up lures, typographic attacks, screenshot poisoning · Summaries →

  • MIRAGE — Stealthy Visual Prompt Injection for Vulnerability Detection in Web Agents · 2026-06 · 🌐
  • Semantic UI Injection — Are GUI Agents Focused Enough? Automated Distraction via Semantic-level UI Element Injection · 2026-04 · 🧩

1.3 Environmental Injection

UI element injection, accessibility tree, spoofed notifications, overlays · Summaries →

  • AnTrap — Are Android GUI Agents Robust Against Runtime Anomalies? AnTrap: Evaluating Agents in Dynamic Adversarial Environments · 2026-08 · 📱
  • Not an A11y — How Android Accessibility Exposes Mobile AI Agents to Indirect Prompt Injection · 2026-08 · 📱
  • eTAMP — Poison Once, Exploit Forever: Environment-Injected Memory Poisoning Attacks on Web Agents · 2026-04 · 🌐
  • AdInject — Real-World Black-Box Attacks on Web Agents via Advertising Delivery · 2025-05 · 🌐

1.4 Privilege Escalation & Permission Abuse

OS-level escalation, cross-app privilege abuse, permission-dialog manipulation, TOCTOU · Summaries →

  • Allow to Achieve — "Allow" to Achieve, Over-Privileged Inadvertently: The Unintended Cost of Task-Completion-Driven Pop-up Decisions in Mobile GUI Agents · 2026-08 · 📱
  • AI Sees — (A)I Sees What You Don't: Exploiting New Attack Surfaces in Third-Party Mobile Agents · 2026-07 · 📱
  • PUSV — Temporal UI State Inconsistency in Desktop GUI Agents: Formalizing and Defending Against TOCTOU Attacks on Computer-Use Agents · 2026-04 · 🖥️
  • Action Rebinding — Mind the Gap: Action Rebinding Attacks against Android GUI Agents · 2026-01 · 📱

1.5 Data Exfiltration & Privacy

Credential theft, PII leakage, contextual-integrity violations, oversharing · Summaries →

  • LoginTrap — Uncovering Task-Agnostic Phishing-Style Indirect Prompt Injection Attacks against LLM-based Web Agents · 2026-08 · 🌐
  • Capable but Careless — Do Computer-Use Agents Follow Contextual Integrity? · 2026-06 · 🖥️
  • MyPhoneBench — Do Phone-Use Agents Respect Your Privacy? · 2026-04 · 📱
  • WebPII — Benchmarking Visual PII Detection for Computer-Use Agents · 2026-03 · 🌐🖥️
  • SPILLage — Agentic Oversharing on the Web · 2026-02 · 🌐

1.6 Backdoors & Poisoning

Grounding backdoors, efficiency backdoors, memory poisoning · Summaries →

  • AgentRAE — Remote Action Execution through Notification-based Visual Backdoors against Screenshots-based Mobile GUI Agents · 2026-03 · 📱
  • SlowBA — An Efficiency Backdoor Attack towards VLM-based GUI Agents · 2026-03 · 📱🧩

1.7 Unintended Harm from Benign Instructions

No adversary involved — harm arising from the agent's own behavior on normal tasks · Summaries →

  • Alignment Is Local — A Paired Diagnostic for GUI Agents under User Persuasion · 2026-07 · 📱🧩

2 Defense Layers

Organized by where the defense intervenes in the execution chain

2.1 Input Filtering & Sanitization

Filtering or masking untrusted content before it enters the model context · Summaries →

  • UCM — Untrusted Content Masking for Web Agents with Security Guarantees · 2026-07 · 🌐
  • Cognitive Firewall — The Cognitive Firewall: Securing Browser Based AI Agents Against Indirect Prompt Injection Via Hybrid Edge Cloud Defense · 2026-03 · 🌐

2.2 Pre-execution Risk Assessment

World-model prediction, action risk scoring · Summaries →

  • WebGuard — Building a Generalizable Guardrail for Web Agents · 2025-07 · 🌐

2.3 Runtime Interception & Access Control

Information-flow tracking, OS-level policy enforcement, sandboxing · Summaries →

  • CURA — Certified Runtime Alarms for Computer-Use Agents · 2026-08 · 🖥️
  • Prismata — Confining Cross-Site Prompt Injection in Web Agents · 2026-07 · 🌐
  • CSAgent — Secure and Efficient Access Control for Computer-Use Agents via Context Space · 2025-09 · 🖥️

2.4 Human-in-the-Loop & Confirmation

Confirmation before critical actions, approval gates, interruptibility

No entries yet

2.5 Post-hoc Recovery & Rollback

Failure attribution, state rollback, repair after harm has occurred · Summaries →

  • CUADebug — Diagnosing and Repairing Computer-Use Agent Failures · 2026-07 · 🖥️

2.6 Formal Guarantees & Verification

Defenses with provable guarantees: formal verification, control-flow integrity, conformal risk control · Summaries →

  • CORA — Conformal Risk-Controlled Agents for Safeguarded Mobile GUI Automation · 2026-04 · 📱

3 Benchmarks & Datasets

The only chapter where runtime environment serves as a primary organizing dimension

3.1 Comprehensive & Cross-environment

Benchmarks spanning multiple environments or threat classes · Summaries →

  • ADeptS-Bench — Measuring the Trustworthiness of Computer Use Agents Across Devices · 2026-08 · 🖥️📱
  • AgentHazard — A Benchmark for Evaluating Harmful Behavior in Computer-Use Agents · 2026-04 · 🖥️

3.2 Web Environment

Security evaluation for web / browser agents · Summaries →

  • Who Pays the Price — Who Pays the Price? Stakeholder-Centric Prompt Injection Benchmarking for Real-world Web Agents · 2026-06 · 🌐

3.3 Mobile Environment

Security evaluation for mobile / Android / iOS agents · Summaries →

  • MobileWorldSafety — Benchmarking GUI Agent Safety Against Environmental Injection Attacks in Android Apps · 2026-08 · 📱
  • GhostEI-Bench — Do Mobile Agents Resilience to Environmental Injection in Dynamic On-Device Environments? · 2025-10 · 📱

3.4 Desktop & OS Environment

Security evaluation for desktop / OS-level computer-use agents · Summaries →

  • OS-Harm — A Benchmark for Measuring Safety of Computer Use Agents · 2025-06 · 🖥️

4 Commercial AI Browsers & Product Security

Primarily non-arXiv sources: vendor security advisories, CVEs, security blogs, disclosures. See docs/MAINTENANCE.md for how this chapter is tracked.

No entries yet


Contributing

Edit data/papers.yaml only — README.md, README.zh-CN.md, and everything under docs/ are generated by GitHub Actions. See CONTRIBUTING.md for inclusion criteria and entry format, and MAINTENANCE.md for the update workflow.

Related lists

This list focuses on the security of GUI/CUA agents. For adjacent areas:

  • General agent security (full OWASP ASI spectrum): LLMSecurity/awesome-agent-skills-security
  • Using agents for security work (red teaming / pentest): kagnlp/Awesome-Agentic-Security
  • Agent auditing and provenance: yzhao062/awesome-auditable-ai
  • GUI agent capability research: OSU-NLP-Group/GUI-Agents-Paper-List

Yorumlar (0)

Sonuc bulunamadi