AgentHijack: Visual Patch Attacks on Multimodal Computer-Use Agents

📅 2026-09-05
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
本文通过在网页中嵌入视觉补丁,测试其能否诱导计算机使用代理执行恶意命令,评估了五种开源或公开的GUI代理和视觉-语言模型后端。
📝 Abstract
This paper presents an end-to-end evaluation framework for image-triggered command injection against computer-use agents (CUAs). The goal is to test whether a local visual patch can induce verifiable environmental consequences along the full chain of screenshot input, VLM generation, action parsing, and environment execution. We train and deploy patches on author-controlled GitHub Pages pages and a locally deployed CSDN clone, and evaluate them in real environments across five open-source or publicly available GUI-agent or vision-language-model (VLM) backends. Our experiment aggregates 600 instance-level online cases, with T-ASR, TAPR, and E2E-ASR reaching 84.5%, 47.0%, and 20.3%, respectively. Trajectory analysis further shows that in some successful cases the agent first executes a malicious terminal command and then continues the original benign task. These results indicate that optimized local visual signals can affect not only VLM outputs but also propagate through the execution pipeline of open CUAs and create real environmental risk.
Problem

Research questions and friction points this paper is trying to address.

image-triggered command injection
computer-use agents
visual patch
environmental consequences
multimodal
Innovation

Methods, ideas, or system contributions that make the work stand out.

image-triggered command injection
multimodal computer-use agents
visual patch attacks
end-to-end evaluation framework
environmental risk
Z
Zhihao Liu
Hainan University, Hainan 570228, China
H
Hongyu Sun
Hainan University, Hainan 570228, China
Z
Zhiyuan Fu
Hainan University, Hainan 570228, China; University of Chinese Academy of Sciences National Computer Network Intrusion Protection Center, Beijing 101408, China
X
Xiaonan Duan
Hainan University, Hainan 570228, China
J
Jice Wang
Hainan University, Hainan 570228, China
S
Shangru Zhao
University of Chinese Academy of Sciences National Computer Network Intrusion Protection Center, Beijing 101408, China
Weizhi Meng
Weizhi Meng
Professor, Lancaster University, United Kingdom
Cyber SecurityBlockchain and IoT/CPSIntrusion DetectionAI/Smartphone Security and Biometric
W
Wuxin Yang
Hainan University, Hainan 570228, China
Y
Yangfan Zhou
Hainan University, Hainan 570228, China
Yuqing Zhang
Yuqing Zhang
University of Groningen
computational linguisticsspeech processing