Skip to content
Search
paperAugust 2026Unreviewed

SIR: Self-improving Red-teaming for Compute Use Agents

Chen Xiong, Zhiyuan He, Pin-Yu Chen, Stjepan Picek, Tsung-Yi Ho

Abstract

Computer use agents (CUAs) are vision-language models that perceive a screen and act on a real operating system through mouse, keyboard, and terminal, and they are increasingly deployed to automate everyday digital tasks. Because they can be exposed to untrusted content while operating, they are vulnerable to indirect prompt injection (IPI), in which an adversary plants instructions in content the agent will read and redirects it toward actions that violate the user's intent. Existing CUA safety

Categories

Framework mappings

MITRE ATLAS
  • AML.T0051LLM Prompt Injection

Suggested from the entry's categories.

Cite

@misc{xiong2026sir,
  title = {{SIR: Self-improving Red-teaming for Compute Use Agents}},
  author = {Chen Xiong and Zhiyuan He and Pin-Yu Chen and Stjepan Picek and Tsung-Yi Ho},
  year = {2026},
  month = aug,
  eprint = {2608.30207},
  archivePrefix = {arXiv},
  url = {https://arxiv.org/abs/2608.30207}
}