Monitoring computer-use agents in OSWorld-control

·LessWrong··

TL;DR: I built a control setting for computer-use agents and studied a few monitoring setups. I found that attackers can leverage the opacity of computer-use tool calls and gaps between screenshot-action pairs to access credentials or exfiltrate data to other devices on a network without being caught by a monitor. These results validate a possible attack strategy but are not comprehensive evidence that the strategy is uniquely dangerous, given the small sample sizes and limited task set.The sett...

Read full article →

Related Articles

New HIV vaccine shows unprecedented success in preclinical study
codebyaditya · Hacker News · 4h ago
GrapheneOS Defends Data-Wiping Function That Blocked US Border Search
pseudolus · Hacker News · 2h ago
US citizen charged after GrapheneOS phone wipes during airport search
eecc · Hacker News · 1d ago
Italy Blocks Reproductive Health Websites Women on Web and Women Help Women
miniBill · Hacker News · 3h ago
DMARC Has Been Public Since 2012. 68.4% of Domains Still Don't Enforce It
adulion · Hacker News · 7h ago