The authors designed COBRA, a Dual-LLM architecture where a Planner LLM (P-LLM) compiles the user request into an executable program annotated with branch-level constraints before any untrusted data is observed.
New defense eliminates branch steering attacks on computer-use agents
COBRA architecture enforces data-flow integrity by constraining branch-level capabilities ahead of time, reducing attack success to 0% while retaining 97% benign utility.
Top University
Giulio Zingrillo · Hanna Foerster · Ilia Shumailov · Yiren Zhao · Robert Mullins
ETH Zurich · University of Cambridge · AI Sequrity Company · Imperial College London
Research Digest··2 min read
Thread:Agent Security & Attacks
The authors systematically study branch steering attacks, where adversarial web content coerces a computer-use agent down a hazardous pre-approved branch without injecting explicit instructions.
Why this paper
From ETH Zurich and 3 others · Part of Agent Security & Attacks, now 65 papers
In one line
Branch steering attacks on computer-use agents can be defeated by combining pre-authorized branching plans with ahead-of-time capability constraints.
What we could check
- ·No code link found
- ·No weights link found
- ·No dataset link found
- ·No compute details found
- ✓Limitations stated by the authors
- ✓Reports numbers on named benchmarks (2 benchmarks)
Observed from the paper text and links we have. Absence here means we did not find it, not that it does not exist.
§