arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

LoginTrap:针对基于大语言模型的Web智能体的任务无关型钓鱼式间接提示注入攻击的发现

LoginTrap: Uncovering Task-Agnostic Phishing-Style Indirect Prompt Injection Attacks against LLM-based Web Agents

Longtao Guo, Zelin Zhang, Kaifeng Huang, Yang Shi

arXiv 2608.04741首次发表:更新:

AI 中文总结

该研究提出LoginTrap攻击,是针对基于LLM的Web智能体的任务无关型登录诱导攻击,在黑盒威胁模型下可达到86%的平均端到端攻击成功率,揭示了登录诱导的认证边界风险并推动相关防御研究。

AI 中文摘要

基于大语言模型(LLM)的Web智能体通过观察网页并代表用户执行浏览器操作来自动化用户任务。由于这些智能体在真实Web服务上运行,登录成为涉及凭证和敏感信息的敏感认证边界。现有研究表明,恶意网页内容可操纵Web智能体的操作,但尚未充分研究此类内容是否能诱导登录并导致端到端的私人数据泄露。我们研究这一攻击面并提出LoginTrap,这是一种针对基于LLM的Web智能体的任务无关型登录诱导攻击。LoginTrap假设攻击者为黑盒攻击者,可控制网页上下文和诱导的登录流程,但不知道用户任务或Web智能体的内部机制。在该威胁模型下,LoginTrap利用网页上下文,通过受模糊测试启发的过程生成特定页面的间接注入,使登录看起来是继续任务的合理前提,并引导智能体进入受控的登录页面。我们在真实的Web智能体执行场景中对LoginTrap进行了全面分析,结果显示,在各类LLM主干模型上,LoginTrap的端到端攻击平均成功率达86%,且在不同智能体架构和防御措施下均保持有效。这些发现确定登录诱导是一种系统性的认证边界风险,推动针对Web智能体的认证感知防御的进一步研究。

英文摘要

LLM-based web agents automate user tasks by observing webpages and executing browser actions on behalf of users. As these agents operate on real web services, login becomes a sensitive authentication boundary because it involves credentials and sensitive information. Existing work shows that malicious webpage content can manipulate web agent actions, but it has not fully examined whether such content can induce login and cause end-to-end private data leakage. We study this attack surface and present LoginTrap, a task-agnostic login-inducing attack against LLM-based web agents. LoginTrap assumes a black box attacker that controls the webpage context and the induced login flow without knowing the user task or web agent internals. Under this threat model, LoginTrap uses webpage context to generate page-specific indirect injections through a fuzzing-inspired process, making login appear as a plausible prerequisite for continuing the task and guiding the agent to a controlled login page. We conduct a comprehensive analysis of LoginTrap across realistic web agent executions. The results show that LoginTrap reaches 86\% average end-to-end attack success across LLM backbones and remains effective across agent architectures and defenses. These findings identify login inducement as a systematic authentication boundary risk and motivate further research on authentication-aware defenses for web agents.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑