paper-with-me

Papers

Attacking Multimodal OS Agents with Malicious Image Patches

2025-03-13 · Lukas Aichberger, Alasdair Paren, Yarin Gal, Philip Torr, Adel Bibi

Recent advances in operating system (OS) agents enable vision-language models to interact directly with the graphical user interface of an OS. These multimodal OS agents autonomously perform computer-based tasks in response to a single prompt via application programming interfaces (APIs). Such APIs typically support low-level operations, including mouse clicks, keyboard inputs, and screenshot captures. We introduce a novel attack vector: malicious image patches (MIPs) that have been adversarially perturbed so that, when captured in a screenshot, they cause an OS agent to perform harmful actions by exploiting specific APIs. For instance, MIPs embedded in desktop backgrounds or shared on social media can redirect an agent to a malicious website, enabling further exploitation. These MIPs generalise across different user requests and screen layouts, and remain effective for multiple OS agents. The existence of such attacks highlights critical security vulnerabilities in OS agents, which should be carefully addressed before their widespread adoption.

📄 PDF Abstract BibTeX arXiv:2503.10809

Code (0)

등록된 구현이 없습니다.

Similar Papers 제목 키워드 기반

Manipulating Multimodal Agents via Cross-Modal Prompt Injection

2025-04-19 · Le Wang, Zonghao Ying, Tianyuan Zhang, Siyuan Liang 외

The emergence of multimodal large language models has redefined the agent paradigm by integrating language and vision modalities with external data sources, enabling agents to better interpret human instructions and exec…

Large Language Model

Mitigation and Resiliency of Multi-Agent Systems Subject to Malicious Cyber Attacks on Communication Links

2020-09-14

This paper aims at investigating a novel type of cyber attack that is injected to multi-agent systems (MAS) having an underlying directed graph. The cyber attack, which is designated as the controllability attack, is inj…

Sensitivity Curve Maximization: Attacking Robust Aggregators in Distributed Learning

2024-12-23 · Christian A. Schroth, Stefan Vlaski, Abdelhak M. Zoubir

In distributed learning agents aim at collaboratively solving a global learning problem. It becomes more and more likely that individual agents are malicious or faulty with an increasing size of the network. This leads t…

Sensitivity

When Backdoors Meet Partial Observability: Attacking Real-World Reinforcement Learning

2026-01-20 · Tairan Huang, Qingqing Ye, Yulin Jin, Jiawei Lian 외 arxiv

Backdoor attacks can cause reinforcement learning (RL) policies to behave normally under clean inputs while executing malicious behaviors when triggers are present. Existing RL backdoor attacks are primarily studied in s…

Reinforcement Learning

Distraction is All You Need: Memory-Efficient Image Immunization against Diffusion-Based Image Editing

2024-01-01 · CVPR 2024 1 · Ling Lo, Cheng Yu Yeo, Hong-Han Shuai, Wen-Huang Cheng

Recent text-to-image (T2I) diffusion models have revolutionized image editing by empowering users to control outcomes using natural language. However the ease of image manipulation has raised ethical concerns with th…

AllDenoisingGPUImage Inpainting+1