WebTrap: Stealthy Mid-Task Hijacking of Browser Agents During Navigation
Researchers have introduced WebTrap, a novel stealthy mid-task hijacking attack targeting browser agents engaged in long-horizon tasks. As these agents execute extended action chains to fulfill user goals, they become vulnerable to malicious instruction injections. Existing prompt injection attacks often suffer from low effectiveness in complex real-world scenarios and weak stealthiness, as they typically conflict with user goals, reducing system usability. WebTrap addresses these limitations by employing multi-step instruction fusion steering, which seamlessly combines attacker and user goals. This allows the agent to execute the malicious intent and then resume the original task, maintaining high usability. Additionally, a context-grounded generation method aligns injected content with the task environment to maximize success rates. Experiments on extended WASP and InjecAgent environments demonstrate that WebTrap achieves high attack success while evading standard defense mechanisms. The study highlights a critical vulnerability in agent systems, showing that navigation flaws can be exploited to bind conflicting goals tightly, enabling stealthy hijacking without disrupting the user experience.
Wire timeline
WebTrap: Stealthy Mid-Task Hijacking of Browser Agents During Navigation
Researchers have introduced WebTrap, a novel stealthy mid-task hijacking attack targeting browser agents engaged in long-horizon tasks. As these agents execute extended action chains to fulfill user goals, they become vulnerable to malicious instruction injections. Existing prompt injection attacks often suffer from low effectiveness in complex real-world scenarios and weak stealthiness, as they typically conflict with user goals, reducing system usability. WebTrap addresses these limitations by employing multi-step instruction fusion steering, which seamlessly combines attacker and user goals. This allows the agent to execute the malicious intent and then resume the original task, maintaining high usability. Additionally, a context-grounded generation method aligns injected content with the task environment to maximize success rates. Experiments on extended WASP and InjecAgent environments demonstrate that WebTrap achieves high attack success while evading standard defense mechanisms. The study highlights a critical vulnerability in agent systems, showing that navigation flaws can be exploited to bind conflicting goals tightly, enabling stealthy hijacking without disrupting the user experience.
cs.AI updates on arXiv.org