发表机构
Technical University of Munich; Kontext(慕尼黑工业大学; Kontext)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
该研究提出三类检测框架区分人类、机器人与AI智能体,发现最小特征集可实现AI智能体的稳健检测,且基于浏览器自动化的缺失特征构建判别信号,抗规避能力优异。
AI 中文摘要
大规模部署的机器人检测器将流量视为二元分类:人类或机器人。当AI智能体通过浏览器自动化浏览网页时,这一假设会被打破,这类流量既不属于人类也不属于机器人,二元分类器在结构上无法对其进行表征。我们提出了一种三类检测框架,用于区分人类、机器人和AI智能体,并证明了二元分类器与智能体之间的混淆是架构层面的:二元人类-机器人检测器会错误路由智能体会话,因为其标签空间缺少智能体类别。在我们的受控基准测试中,多层感知机(MLP)二元分类器将39.1%的真实AI智能体错误分类为人类,SAINT二元Transformer则将34.5%的AI智能体错误分类;添加显式智能体类别后,在所有30次运行(3个模型族×10个随机种子)中,智能体的每类F1值均达到1.000。为衡量抗规避能力,我们构建了一个五级规避阶梯,涵盖被动观察、GAN生成的轨迹以及真实人类光标数据的重放(共n=2299次规避会话)。在10个随机种子和3个模型族的条件下,22990次每种子预测中未出现一次智能体漏检。这种判别信号源于浏览器自动化的产物,而非智能体推理的证据:Playwright不会生成物理输入设备产生的原始指针移动和滚轮增量流,且这种缺失特征在轨迹操纵后仍能保留。对大小为1-5的所有特征子集进行穷举搜索(9401个梯度提升机(GBM))显示,两个行为特征(mouse_event_rate、teleport_click_ratio)在每个规避级别均能实现100%的智能体召回,智能体精度为0.994;五个特征可将宏F1值提升至0.991。该信号存在冗余编码:移除teleport_click_ratio后,智能体检测仍保持100%。单特征机制是退化的,仅通过将分类器始终预测为“智能体”来标记所有智能体。两个特征可稳健地将智能体分离;五个特征可将所有三类流量分开,宏F1值≥0.99。
英文摘要
Bot detectors deployed at scale treat traffic as binary: human or bot. This assumption breaks when AI agents browse the web through browser automation, a traffic class that is neither and that binary classifiers structurally cannot represent. We present a three-class detection framework distinguishing humans, bots, and AI agents, and show that the binary-vs-agent confusion is architectural: a binary human-vs-bot detector misroutes agent sessions because its label space lacks an agent class. On our controlled benchmark, an MLP binary classifier misclassifies 39.1% of real AI agents as human and a SAINT binary transformer misclassifies 34.5%; adding an explicit agent class yields per-class agent F1 = 1.000 in all 30 runs (3 model families $\times$ 10 seeds). To measure evasion resistance, we construct a five-level evasion ladder spanning passive observation, GAN-generated trajectories, and replay of real human cursor data ($n = 2299$ evasion sessions). Across 10 seeds and 3 model families we observe zero agent misses in 22990 per-seed predictions. The discriminative signal is a browser-automation artifact, not evidence of agent reasoning: Playwright does not emit the raw pointer-move and wheel-delta streams a physical input device produces, and this absence signature survives trajectory manipulation. Exhaustive search over all feature subsets of size 1-5 (9401 GBMs) shows that two behavioral features (mouse_event_rate, teleport_click_ratio) give 100% observed agent recall at every evasion level with agent precision 0.994; five features lift macro-F1 to 0.991. The signal is redundantly encoded: removing teleport_click_ratio leaves agent detection at 100%. The single-feature regime is degenerate, flagging every agent only by collapsing the classifier to always predict "agent". Two features robustly isolate agents; five separate all three traffic classes at macro-F1 $\geq 0.99$.
Comments17 pages (11 main + appendices), 7 figures. Accepted at the North East AI Agents Day 2026 workshop, Jane Street, New York City. Workshop: https://ne-agents-day.github.io/