Saved in:
Bibliographic Details
Main Authors: Seip, Dominik, Hein, Matthias
Format: Preprint
Published: 2026
Subjects:
Online Access:https://arxiv.org/abs/2604.08005
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866917395110559744
author Seip, Dominik
Hein, Matthias
author_facet Seip, Dominik
Hein, Matthias
contents Advancements in multimodal foundation models have enabled the development of Computer Use Agents (CUAs) capable of autonomously interacting with GUI environments. As CUAs are not restricted to certain tools, they allow to automate more complex agentic tasks but at the same time open up new security vulnerabilities. While prior work has concentrated on the language modality, the vulnerability of the vision modality has received less attention. In this paper, we introduce PRAC, a novel attack that, unlike prior work targeting the VLM output directly, manipulates the model's internal preferences by redirecting its attention toward a stealthy adversarial patch. We show that PRAC is able to manipulate the selection process of a CUA on an online shopping platform towards a chosen target product. While we require white-box access to the model for the creation of the attack, we show that our attack generalizes to fine-tuned versions of the same model, presenting a critical threat as multiple companies build specific CUAs based on open weights models.
format Preprint
id arxiv_https___arxiv_org_abs_2604_08005
institution arXiv
publishDate 2026
record_format arxiv
spellingShingle Preference Redirection via Attention Concentration: An Attack on Computer Use Agents
Seip, Dominik
Hein, Matthias
Machine Learning
Advancements in multimodal foundation models have enabled the development of Computer Use Agents (CUAs) capable of autonomously interacting with GUI environments. As CUAs are not restricted to certain tools, they allow to automate more complex agentic tasks but at the same time open up new security vulnerabilities. While prior work has concentrated on the language modality, the vulnerability of the vision modality has received less attention. In this paper, we introduce PRAC, a novel attack that, unlike prior work targeting the VLM output directly, manipulates the model's internal preferences by redirecting its attention toward a stealthy adversarial patch. We show that PRAC is able to manipulate the selection process of a CUA on an online shopping platform towards a chosen target product. While we require white-box access to the model for the creation of the attack, we show that our attack generalizes to fine-tuned versions of the same model, presenting a critical threat as multiple companies build specific CUAs based on open weights models.
title Preference Redirection via Attention Concentration: An Attack on Computer Use Agents
topic Machine Learning
url https://arxiv.org/abs/2604.08005