arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

检测AI智能体需要什么?浏览器自动化下行为检测的最小特征集

What Does It Take to Detect an AI Agent? Minimal Feature Sets for Behavioral Detection under Browser Automation

Vishisht Choudhary, Lukas Schmidt, Anne Zoë Kenntner, Feras Skhab, Michel Osswald, Jens Ernstberger

arXiv 2607.26935首次发表:更新:

发表机构

Technical University of Munich; Kontext(慕尼黑工业大学; Kontext)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

该研究提出三类检测框架区分人类、机器人与AI智能体,发现最小特征集可实现AI智能体的稳健检测,且基于浏览器自动化的缺失特征构建判别信号,抗规避能力优异。

AI 中文摘要

大规模部署的机器人检测器将流量视为二元分类:人类或机器人。当AI智能体通过浏览器自动化浏览网页时,这一假设会被打破,这类流量既不属于人类也不属于机器人,二元分类器在结构上无法对其进行表征。我们提出了一种三类检测框架,用于区分人类、机器人和AI智能体,并证明了二元分类器与智能体之间的混淆是架构层面的:二元人类-机器人检测器会错误路由智能体会话,因为其标签空间缺少智能体类别。在我们的受控基准测试中,多层感知机(MLP)二元分类器将39.1%的真实AI智能体错误分类为人类,SAINT二元Transformer则将34.5%的AI智能体错误分类;添加显式智能体类别后,在所有30次运行(3个模型族×10个随机种子)中,智能体的每类F1值均达到1.000。为衡量抗规避能力,我们构建了一个五级规避阶梯,涵盖被动观察、GAN生成的轨迹以及真实人类光标数据的重放(共n=2299次规避会话)。在10个随机种子和3个模型族的条件下,22990次每种子预测中未出现一次智能体漏检。这种判别信号源于浏览器自动化的产物,而非智能体推理的证据:Playwright不会生成物理输入设备产生的原始指针移动和滚轮增量流,且这种缺失特征在轨迹操纵后仍能保留。对大小为1-5的所有特征子集进行穷举搜索(9401个梯度提升机(GBM))显示,两个行为特征(mouse_event_rate、teleport_click_ratio)在每个规避级别均能实现100%的智能体召回,智能体精度为0.994;五个特征可将宏F1值提升至0.991。该信号存在冗余编码:移除teleport_click_ratio后,智能体检测仍保持100%。单特征机制是退化的,仅通过将分类器始终预测为“智能体”来标记所有智能体。两个特征可稳健地将智能体分离;五个特征可将所有三类流量分开,宏F1值≥0.99。

英文摘要

Bot detectors deployed at scale treat traffic as binary: human or bot. This assumption breaks when AI agents browse the web through browser automation, a traffic class that is neither and that binary classifiers structurally cannot represent. We present a three-class detection framework distinguishing humans, bots, and AI agents, and show that the binary-vs-agent confusion is architectural: a binary human-vs-bot detector misroutes agent sessions because its label space lacks an agent class. On our controlled benchmark, an MLP binary classifier misclassifies 39.1% of real AI agents as human and a SAINT binary transformer misclassifies 34.5%; adding an explicit agent class yields per-class agent F1 = 1.000 in all 30 runs (3 model families $\times$ 10 seeds). To measure evasion resistance, we construct a five-level evasion ladder spanning passive observation, GAN-generated trajectories, and replay of real human cursor data ($n = 2299$ evasion sessions). Across 10 seeds and 3 model families we observe zero agent misses in 22990 per-seed predictions. The discriminative signal is a browser-automation artifact, not evidence of agent reasoning: Playwright does not emit the raw pointer-move and wheel-delta streams a physical input device produces, and this absence signature survives trajectory manipulation. Exhaustive search over all feature subsets of size 1-5 (9401 GBMs) shows that two behavioral features (mouse_event_rate, teleport_click_ratio) give 100% observed agent recall at every evasion level with agent precision 0.994; five features lift macro-F1 to 0.991. The signal is redundantly encoded: removing teleport_click_ratio leaves agent detection at 100%. The single-feature regime is degenerate, flagging every agent only by collapsing the classifier to always predict "agent". Two features robustly isolate agents; five separate all three traffic classes at macro-F1 $\geq 0.99$.

Comments17 pages (11 main + appendices), 7 figures. Accepted at the North East AI Agents Day 2026 workshop, Jane Street, New York City. Workshop: https://ne-agents-day.github.io/

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑