← Back to search
paper llmsec-2026-00116

Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation

Di Lu, Bo Zhang, Xiyuan Li, Yongzhi Liao, Xuewen Dong, Yulong Shen, Zhiquan Liu, Jianfeng Ma

2026-05

Abstract

Self-hosted computer-use agents (SHCUAs), such as OpenClaw, combine natural-language interaction with direct access to host-side resources, including browsers, files, scripts, system commands, and external communication channels. While useful for automating real tasks, this capability also creates a host-level abuse surface: a legitimately deployed agent may be steered toward unsafe operations through malicious messages, indirect prompt injection, unsafe skills, or tampering along the host-side

Cite This Resource

@article{llmsec202600116,
  title = {Constraining Host-Level Abuse in Self-Hosted Computer-Use Agents via TEE-Backed Isolation},
  author = {Di Lu and Bo Zhang and Xiyuan Li and Yongzhi Liao and Xuewen Dong and Yulong Shen and Zhiquan Liu and Jianfeng Ma},
  year = {2026},
  url = {https://arxiv.org/abs/2605.06393},
}

Metadata

Added
2026-05-17
Added by
automation
Source
arxiv
arxiv_id
2605.06393