August 2026Unreviewed
SIR: Self-improving Red-teaming for Compute Use Agents
Chen Xiong, Zhiyuan He, Pin-Yu Chen, Stjepan Picek, Tsung-Yi Ho
Abstract
Computer use agents (CUAs) are vision-language models that perceive a screen and act on a real operating system through mouse, keyboard, and terminal, and they are increasingly deployed to automate everyday digital tasks. Because they can be exposed to untrusted content while operating, they are vulnerable to indirect prompt injection (IPI), in which an adversary plants instructions in content the agent will read and redirects it toward actions that violate the user's intent. Existing CUA safety
Categories
Framework mappings
OWASP Top 10 for LLM Applications
- LLM01Prompt Injection
MITRE ATLAS
- AML.T0051LLM Prompt Injection
NIST AI Risk Management Framework
- MEASUREMeasure
Suggested from the entry's categories.
Cite
@misc{xiong2026sir,
title = {{SIR: Self-improving Red-teaming for Compute Use Agents}},
author = {Chen Xiong and Zhiyuan He and Pin-Yu Chen and Stjepan Picek and Tsung-Yi Ho},
year = {2026},
month = aug,
eprint = {2608.30207},
archivePrefix = {arXiv},
url = {https://arxiv.org/abs/2608.30207}
}