Secure-CUA: Controlling Untrusted Influence in Computer-Use Agents
cs.CR, cs.AI
Submitted: 2026-10-07
Updated: 2026-10-07
Terminology
Sources
- Design Patterns for Securing LLM Agents against Prompt Injections
- Securing AI Agents with Information-Flow Control
- Defeating Prompt Injections by Design
- Secure and Efficient Access Control for Computer-Use Agents via Context Space
- Preventing Prompt Injection with Type-Directed Privilege Separation
- Optimizing Agent Planning for Security and Autonomy
- InjecGuard: Benchmarking and Mitigating Over-defense in Prompt Injection Guardrail Models
- DRIFT: Dynamic Rule-Based Defense with Injection Isolation for Securing LLM Agents
- ceLLMate: Sandboxing Browser AI Agents
- Untrusted Content Masking for Web Agents with Security Guarantees
- Context manipulation attacks : Web agents are susceptible to corrupted memory
- Web Agents Should Adopt the Plan-Then-Execute Paradigm
- Hijacking Robots with a Piece of Paper: A Systematic Study of Physical Prompt Injection in VLM-Controlled Robots
- Progent: Securing AI Agents with Privilege Control
- Prismata: Confining Cross-Site Prompt Injection in Web Agents
- The Instruction Hierarchy: Training LLMs to Prioritize Privileged Instructions
- GPT-4V(ision) is a Generalist Web Agent, if Grounded
Related papers
- SoK: AI-Augmented Binary Reversing
- Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM
- Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages
- Efficient Fuzzy PSI under One-Sided Assumptions
- Sealing the Audit-Runtime Gap for LLM Skills
- Token Composition: A Graph Based on EVM Logs