GUI Agents Papers
Star · 753

EIA: Environmental Injection Attack on Generalist Web Agents for Privacy Leakage

Zeyi Liao, Lingbo Mo, Chejian Xu, Mintong Kang, Jiawei Zhang, Chaowei Xiao, Yuan Tian, Bo Li, Huan Sun

🏛 Institutions
OSU, Amazon, UIUC, University of Chicago, JHU, University of Virginia
📅 Date
September 17, 2024
📑 Publisher
ICLR 2025 (Poster)
💻 Env
Web
🔑 Keywords
TLDR

EIA studies privacy leakage in generalist web agents under adversarial webpages and introduces Environmental Injection Attack, which hides malicious content in the environment to steal user information. Using 177 action steps built from realistic Mind2Web scenarios, the paper reports up to 70% attack success for stealing specific PII and 16% for stealing a full user request at a step, while also arguing that well-adapted attacks are difficult to detect or mitigate.

Open paper Report issue
Related papers