Skip to content
Search
paperAugust 2026Unreviewed

Invisible Ink Threats: Adversarial Goals Behind Legitimate Tasks in Computer-Use Agents

Jia-Chen Zhang, Zenghui Zhang, Kai-Wei Zhang

Abstract

Computer-use agents (CUAs), which empower large language models to autonomously operate operating systems and the web, are increasingly vulnerable to indirect prompt injection attacks. A widely adopted defense is the human-in-the-loop paradigm, in which the agent pauses for explicit user confirmation before executing sensitive operations. While effective against conspicuously high-harm attacks, this defense offers little protection against what we term Invisible Ink Threats: low-harm injected go

Categories

Framework mappings

MITRE ATLAS
  • AML.T0051LLM Prompt Injection

Suggested from the entry's categories.

Cite

@misc{zhang2026invisible,
  title = {{Invisible Ink Threats: Adversarial Goals Behind Legitimate Tasks in Computer-Use Agents}},
  author = {Jia-Chen Zhang and Zenghui Zhang and Kai-Wei Zhang},
  year = {2026},
  month = aug,
  eprint = {2608.02018},
  archivePrefix = {arXiv},
  url = {https://www.semanticscholar.org/paper/452f5a76b8c18e0d4886e1aea1b1fa95201178ab}
}