Challenge: Existing web agents are highly susceptible to multiple classes of deceptive interfaces, but they are not designed to mitigate these failures.
Approach: They propose a lightweight plugin framework that allows controlled injection of deceptive interface patterns into existing web environments.
Outcome: The proposed framework enables controlled injection of deceptive interface patterns into web environments.

Similar Papers

A Functionality-Grounded Benchmark for Evaluating Web Agents in E-commerce Domains (2026.acl-long)

Copied to clipboard

Challenge: Existing benchmarks focus on product search tasks, but ignore potential risks.
Approach: They propose a data generation pipeline that leverages webpage content and interactive elements to create diverse, functionality-grounded user queries.
Outcome: The proposed framework assesses the performance and safety of web agents under dynamic, real-world e-commerce environments.
Don’t Click That: Teaching Web Agents to Resist Deceptive Interfaces (2026.acl-long)

Copied to clipboard

Challenge: Existing approaches to deception detection and defenses are inadequate . Existing methods do not integrate with agent decision-making .
Approach: They propose a framework that integrates hybrid-reward learning with asymmetric penalties and experience summarization to distill failure patterns into transferable guidance.
Outcome: The proposed framework reduces deception susceptibility by 53.8% while maintaining task performance, establishing an effective foundation for robust web agent deployment.
RISK: A Framework for GUI Agents in E-commerce Risk Management (2026.acl-long)

Copied to clipboard

Challenge: RISK is a framework designed to automate multi-step web interactions in e-commerce risk management.
Approach: a new framework is designed to build and deploy GUI agents for e-commerce risk management . RISK-R1 provides a scalable, domain-specific solution for automating complex web interactions .
Outcome: RISK provides a scalable, domain-specific solution for automating complex web interactions in e-commerce risk management.
Web Fraud Attacks Against LLM-Driven Multi-Agent Systems (2026.findings-acl)

Copied to clipboard

Challenge: Large Language Model (LLM)-driven multi-agent systems (MAS) are rapidly gaining popularity, and its inherent security risks are rapidly becoming a concern.
Approach: They propose a novel attack manipulating unique structures of web links to deceive MAS by using homoglyph deception, sub-directory nesting, and parameter obfuscation.
Outcome: The proposed attacks exploit unique structures of web links to deceive MAS . they exhibit significant destructive potential across different MAS architectures .
ECom-Bench: Can LLM Agent Resolve Real-World E-commerce Customer Support Issues? (2025.emnlp-industry)

Copied to clipboard

Challenge: ECom-Bench is a benchmark framework for evaluating LLM agent with multimodal capabilities in e-commerce customer support domain.
Approach: They introduce a benchmark framework for evaluating LLM agent with multimodal capabilities in the e-commerce customer support domain.
Outcome: The proposed benchmark features dynamic user simulation based on persona information from real e-commerce customer interactions and a realistic task dataset derived from authentic ecommerce dialogues.
Conjunctive Prompt Attacks in Multi-Agent LLM Systems (2026.acl-long)

Copied to clipboard

Challenge: Existing defenses do not reliably stop the attack because no single component appears malicious in isolation.
Approach: They study conjunctive prompt attacks where trigger key and adversarial template appear benign alone but activate harmful behavior when routing brings them together.
Outcome: The proposed model significantly improves performance over baselines while keeping false activations low.
The Dangers of Indirect Prompt Injection Attacks on LLM-based Autonomous Web Navigation Agents: A Demonstration (2025.emnlp-demos)

Copied to clipboard

Challenge: Large Language Model (LLM)-integrated applications are becoming more popular to support, augment, and automate tasks.
Approach: They propose to embed universal adversarial triggers in webpage HTML to hijack agents . they also use a browser-gym agent powered by Llama-3.1 to test their system .
Outcome: The proposed system software is released under the MIT License .
WebOlympus: An Open Platform for Web Agents on Live Websites (2024.emnlp-demo)

Copied to clipboard

Challenge: Web agents are emerging as powerful tools for automating tasks in cyberspace . however, there is a lack of standardized and user-friendly tools for research and development .
Approach: They propose an open platform for web agents operating on live websites with a Chrome extension and a safety monitor module to ensure their trustworthiness.
Outcome: WebOlympus is an open platform for web agents operating on live websites.
Agent-Ops: A Multi-Agent Orchestration Framework for End-to-End SOP Automation in E-Commerce Operations (2026.acl-industry)

Copied to clipboard

Challenge: Existing Large Language Models fail to execute multistep operational workflows requiring precise procedural adherence.
Approach: They propose an end-to-end multi-agent framework automating Standard Operating Procedures in e-commerce.
Outcome: The proposed framework achieves 85-97% accuracy and a 94.2% execution consistency in e-commerce . it is based on a human-AI framework that transforms ambiguous documentation into automation-ready specifications .
Multimodal Safety Evaluation in Generative Agent Social Simulations (2026.acl-long)

Copied to clipboard

Challenge: Recent advances in large language models have enabled generative agents that simulate be-like behavior through natural language interactions.
Approach: They propose a reproducible simulation framework to evaluate generative agents in multimodal scenarios . they use metrics that quantify plan revisions and unsafe-to-safe conversions to evaluate their effectiveness .
Outcome: The proposed framework evaluates generative agents in three aspects: safety improvement over time, detection of unsafe activities across social contexts, social dynamics and acceptance rates.

What is GenGO?

GenGO is an NLP powered publication search system. It currenctly indexes 30k+ papers from ACL Anthology, and implements multi-aspect summarization, semantic search, and more!

Information

About
Limitations