New defense eliminates branch steering attacks on computer-use agents

COBRA architecture enforces data-flow integrity by constraining branch-level capabilities ahead of time, reducing attack success to 0% while retaining 97% benign utility.

Top University
Giulio Zingrillo · Hanna Foerster · Ilia Shumailov · Yiren Zhao · Robert Mullins

ETH Zurich · University of Cambridge · AI Sequrity Company · Imperial College London

Research Digest··2 min read
The authors systematically study branch steering attacks, where adversarial web content coerces a computer-use agent down a hazardous pre-approved branch without injecting explicit instructions.

The authors designed COBRA, a Dual-LLM architecture where a Planner LLM (P-LLM) compiles the user request into an executable program annotated with branch-level constraints before any untrusted data is observed.

Why this paper

From ETH Zurich and 3 others · Part of Agent Security & Attacks, now 65 papers

In one line

Branch steering attacks on computer-use agents can be defeated by combining pre-authorized branching plans with ahead-of-time capability constraints.

What we could check

  • ·No code link found
  • ·No weights link found
  • ·No dataset link found
  • ·No compute details found
  • ✓Limitations stated by the authors
  • ✓Reports numbers on named benchmarks (2 benchmarks)

Observed from the paper text and links we have. Absence here means we did not find it, not that it does not exist.

§

Research Digest

Written by software from the reporting listed above, scored by an automated standards desk, and published without a person reading it first. If something here is wrong, tell the editor and it will be put right.