PulseAugur
实时 09:54:47
English(EN) Preference Redirection via Attention Concentration: An Attack on Computer Use Agents

新的“PRAC”攻击针对AI代理的视觉模态

研究人员开发了一种名为PRAC的新攻击,该攻击针对多模态基础模型的视觉模态,特别是计算机使用代理(CUAs)。与之前直接操纵模型输出的攻击不同,PRAC使用隐蔽的对抗性补丁来重定向模型的注意力。该方法已被证明成功地操纵了在线购物平台上的CUA选择特定目标产品。虽然该攻击需要白盒访问权限才能创建,但它对微调模型表现出泛化能力,对基于开放权重模型构建的CUA构成了重大的安全风险。 AI

影响 这项研究突显了基于视觉的AI代理存在关键的安全漏洞,可能影响与图形界面交互的自主系统的安全性和可靠性。

排序理由 详细介绍AI代理新攻击方法的学术论文。[lever_c_demoted from research: ic=1 ai=1.0]

在 arXiv cs.LG 阅读 →

AI 生成摘要 · Google Gemini · 来自 1 个来源。 我们如何撰写摘要 →

新的“PRAC”攻击针对AI代理的视觉模态

报道来源 [1]

  1. arXiv cs.LG TIER_1 English(EN) · Dominik Seip, Matthias Hein ·

    Preference Redirection via Attention Concentration: An Attack on Computer Use Agents

    arXiv:2604.08005v2 Announce Type: replace Abstract: Advancements in multimodal foundation models have enabled the development of Computer Use Agents (CUAs) capable of autonomously interacting with GUI environments. As CUAs are not restricted to certain tools, they allow to automa…