GUI Agents Papers
Star · 902

StepJack: Benchmarking Computer-Use Agent Safety Against Multi-Step Indirect Prompt Injection

Zhuoxin Zhan , Akbar Rafiey , Avery Ma , Leila Pishdad , Layla El Asri

🏛 Institutions
Unknown
📅 Date
August 6, 2026
📑 Publisher
arXiv
💻 Env
Web
🔑 Keywords
TLDR

StepJack studies indirect prompt injection chains in which a harmful goal is split into seemingly innocuous steps across linked pages. Its 480-example benchmark evaluates whether computer-use agents follow these multi-step attacks and releases the attack-generation pipeline.

Open paper Code Report issue
Related papers (24)