ceLLMate: Sandboxing Browser AI Agents

Fuente: arXiv
Salvato in:
Dettagli Bibliografici
Autori principali: Meng, Luoxi, Feng, Henry, Shumailov, Ilia, Fernandes, Earlence
Natura: Preprint
Pubblicazione: 2025
Soggetti:
Accesso online:
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866910039876304896
author Meng, Luoxi
Feng, Henry
Shumailov, Ilia
Fernandes, Earlence
author_facet Meng, Luoxi
Feng, Henry
Shumailov, Ilia
Fernandes, Earlence
contents Browser-using agents (BUAs) are an emerging class of AI agents that interact with web browsers in human-like ways, including clicking, scrolling, filling forms, and navigating across pages. While these agents help automate repetitive online tasks, they are vulnerable to prompt injection attacks that trick an agent into performing undesired actions, such as leaking private information or issuing unintended state-changing requests. We propose ceLLMate, a browser-level sandboxing framework that restricts the agent's ambient authority and reduces the blast radius of prompt injections. We address the semantic gap challenge that is fundamental to BUAs -- writing and enforcing security policies for low-level UI tools like clicks and keystrokes is brittle and error-prone. Our core insight is to perform sandboxing at the HTTP layer because all side-effecting UI operations will result in network communication to the website's backend. We implement ceLLMate as an agent-agnostic browser extension and demonstrate how it enables sandboxing policies that block prompt injection attacks in the WASP benchmark with 7.25--15% latency overhead.
format Preprint
id arxiv_https___arxiv_org_abs_2512_12594
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle ceLLMate: Sandboxing Browser AI Agents
Meng, Luoxi
Feng, Henry
Shumailov, Ilia
Fernandes, Earlence
Cryptography and Security
Machine Learning
Browser-using agents (BUAs) are an emerging class of AI agents that interact with web browsers in human-like ways, including clicking, scrolling, filling forms, and navigating across pages. While these agents help automate repetitive online tasks, they are vulnerable to prompt injection attacks that trick an agent into performing undesired actions, such as leaking private information or issuing unintended state-changing requests. We propose ceLLMate, a browser-level sandboxing framework that restricts the agent's ambient authority and reduces the blast radius of prompt injections. We address the semantic gap challenge that is fundamental to BUAs -- writing and enforcing security policies for low-level UI tools like clicks and keystrokes is brittle and error-prone. Our core insight is to perform sandboxing at the HTTP layer because all side-effecting UI operations will result in network communication to the website's backend. We implement ceLLMate as an agent-agnostic browser extension and demonstrate how it enables sandboxing policies that block prompt injection attacks in the WASP benchmark with 7.25--15% latency overhead.
title ceLLMate: Sandboxing Browser AI Agents
topic Cryptography and Security
Machine Learning
url https://arxiv.org/abs/2512.12594