The Verifiable Action Card: Trustworthy Human-in-the-Loop Control for Secure Autonomous Agents

📅 2026-09-16
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
该研究针对安全敏感操作易受间接提示注入等问题,提出Verifiable Action Card方法,通过验证真实待执行动作来提高安全性。
📝 Abstract
Agentic browsers can execute security-sensitive actions under a user's authenticated session, making indirect prompt injection and deceptive confirmation interfaces a direct threat to action integrity. Existing human-in-the-loop (HITL) safeguards are insufficient when the approval prompt itself can be influenced by untrusted page content or model-generated text. We present the \emph{Verifiable Action Card} (VAC), an architectural defence that reconstructs approval information from the ground-truth pending browser action and trusted intent provenance, renders it out-of-band in the trusted browser chrome, and binds approval to the exact action re-verified at dispatch. VAC combines provenance fencing, a ground-truth action descriptor, default-deny confirmation, provenance-aware risk gating, and execution binding. We implement VAC in a complete agentic browser and evaluate it on a 24-scenario benchmark covering confused-deputy attacks, Lies-in-the-Loop dialog forging, indirect prompt injection, adaptive action substitution, provenance evasion, and legitimate tasks. Across the evaluated LLMs, attack success without VAC ranges from $68\%$ to $100\%$, whereas VAC reduces attack success to $0\%$ on every model, with $78\%$ legitimate-task completion and a $0\%$ false-block rate. These results show that grounding approval in the action that will actually execute provides architectural protection against security failures that prompt-level defences and conventional HITL confirmation cannot reliably prevent.
Problem

Research questions and friction points this paper is trying to address.

Verifiable Action Card
Human-in-the-Loop Control
Secure Autonomous Agents
Action Integrity
Indirect Prompt Injection
Innovation

Methods, ideas, or system contributions that make the work stand out.

Verifiable Action Card
Human-in-the-Loop Control
Security-sensitive Actions
Provenance Fencing
Execution Binding
H
Hasnain Irshad
Department of Computer Science, Sir Syed CASE Institute of Technology, 44000, Islamabad, Pakistan
A
Anam Mughees
Department of Electrical Engineering, University of Engineering and Technology, 54890, Lahore, Pakistan
N
Neelam Mughees
School of Engineering and Technology, National Textile University, 37610, Faisalabad, Pakistan
A
Abdullah Mughees
Interdisciplinary Research Center for Smart Mobility and Logistics, King Fahd University of Petroleum and Minerals (KFUPM), 31261, Dhahran, Saudi Arabia
I
Imtiaz Ali Soomro
Department of Computer Science, Sir Syed CASE Institute of Technology, 44000, Islamabad, Pakistan