arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

破碎的大门:在大语言模型代理时代重新评估网络机器人防御

Broken Gates: Re-evaluating Web Bot Defenses in the Age of LLM Agents

Behzad Ousat, Nikita Turkmen, Lalchandra Rampersaud, Dillan Bailey, Amin Kharraz

arXiv 2607.18659首次发表:更新:

发表机构

Florida International University(佛罗里达国际大学)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

研究在大语言模型代理时代网络机器人防御的有效性,通过系统测量研究评估基于交互式挑战与非交互式信任的防御对商业验证码解决服务和大语言模型代理的弹性,发现非交互式防御安全边界在环境层,影响机器人管理系统设计评估。

AI 中文摘要

基于大语言模型的浏览器代理正在迅速改变网络安全的威胁格局。与执行预定义脚本的传统自动化框架不同,这些代理可以自主浏览网站、理解页面内容并使用自然语言指令与网络界面进行交互。这一演变引发了关于广泛部署以防御自动网络滥用的机器人管理系统有效性的基本问题。在本文中,我们进行了一项系统的测量研究,评估基于交互式挑战的防御和基于非交互式信任的防御对两类攻击者的弹性:商业验证码解决服务和基于大语言模型的浏览器代理。我们的评估涵盖了七个解决服务和六个代理,包括云托管、自托管、人工智能辅助和浏览器扩展配置,针对hCaptcha、reCaptcha v2、reCaptcha v3和Cloudflare Turnstile进行测试。我们的结果表明,基于挑战的防御对商业解决者大致无效,它们以可忽略不计的成本实现了近乎完美的绕过。当有专用解决模块时,基于大语言模型的代理同样可以击败这些挑战。诸如reCaptcha v3之类的非交互式防御表现出更强的抵抗力,但我们的分析表明,这种弹性并不反映基本的安全属性。通过细粒度的交互跟踪分析,我们发现两个行为足迹几乎无法区分的代理产生了不同的结果,一个绕过了防御,一个失败了,这表明执行环境的真实性而非代理行为是决定性因素。这些发现表明,非交互式防御的安全边界在于环境层,这对机器人管理系统的设计和评估具有重大影响。

英文摘要

LLM-based browser agents are rapidly changing the threat landscape for web security. Unlike traditional automation frameworks that execute predefined scripts, these agents can autonomously navigate websites, reason about page content, and interact with web interfaces using natural-language instructions. This evolution raises fundamental questions about the effectiveness of bot management systems, widely deployed to defend against automated web abuse. In this paper, we present a systematic measurement study evaluating the resilience of both interactive challenge-based defenses and non-interactive trust-based defenses against two attacker classes: commercial Captcha-solving services and LLM-based browser agents. Our evaluation spans seven solver services and six agents, including cloud-hosted, self-hosted, AI-assisted, and browser-extension configurations, tested against hCaptcha, reCaptcha v2, reCaptcha v3, and Cloudflare Turnstile. Our results show that challenge-based defenses are broadly ineffective against commercial solvers, which achieve near-perfect bypass at negligible cost. The challenges can similarly be defeated by LLM-based agents when a dedicated solver module is available. Non-interactive defenses such as reCaptcha v3 exhibit stronger resistance, but our analysis reveals that this resilience does not reflect a fundamental security property. Through fine-grained interaction trace analysis, we find that two agents with nearly indistinguishable behavioral footprints yield divergent outcomes, one bypassing the defense and one failing, isolating execution-environment authenticity, rather than agent behavior, as the determining factor. These findings suggest that the security boundary of non-interactive defenses lies at the environment layer, with significant implications for how bot management systems are designed and evaluated.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑