WebAgentGuard: A Reasoning-Driven Guard Model for Detecting Prompt Injection Attacks in Web Agents

Fuente: arXiv
Guardado en:
Detalles Bibliográficos
Autores principales: Chen, Yulin, Cao, Tri, Li, Haoran, Liu, Yue, Li, Yibo, He, Yufei, Khoi, Le Minh, Song, Yangqiu, Yan, Shuicheng, Hooi, Bryan
Formato: Preprint
Publicado: 2026
Materias:
Acceso en línea:
Etiquetas: Agregar Etiqueta
Sin Etiquetas, Sea el primero en etiquetar este registro!
_version_ 1866911591878885376
author Chen, Yulin
Cao, Tri
Li, Haoran
Liu, Yue
Li, Yibo
He, Yufei
Khoi, Le Minh
Song, Yangqiu
Yan, Shuicheng
Hooi, Bryan
author_facet Chen, Yulin
Cao, Tri
Li, Haoran
Liu, Yue
Li, Yibo
He, Yufei
Khoi, Le Minh
Song, Yangqiu
Yan, Shuicheng
Hooi, Bryan
contents Web agents powered by vision-language models (VLMs) enable autonomous interaction with web environments by perceiving and acting on both visual and textual webpage content to accomplish user-specified tasks. However, they are highly vulnerable to prompt injection attacks, where adversarial instructions embedded in HTML or rendered screenshots can manipulate agent behavior and lead to harmful outcomes such as information leakage. Existing defenses, including system prompt defenses and direct fine-tuning of agents, have shown limited effectiveness. To address this issue, we propose a defense framework in which a web agent operates in parallel with a dedicated guard agent, decoupling prompt injection detection from the agent's own reasoning. Building on this framework, we introduce WebAgentGuard, a reasoning-driven, multimodal guard model for prompt injection detection. We construct a synthetic multimodal dataset using GPT-5 spanning 164 topics and 230 visual and UI design styles, and train the model via reasoning-intensive supervised fine-tuning followed by reinforcement learning. Experiments across multiple benchmarks show that WebAgentGuard consistently outperforms strong baselines while preserving agent utility, without introducing additional latency.
format Preprint
id arxiv_https___arxiv_org_abs_2604_12284
institution arXiv
publishDate 2026
record_format arxiv
spellingShingle WebAgentGuard: A Reasoning-Driven Guard Model for Detecting Prompt Injection Attacks in Web Agents
Chen, Yulin
Cao, Tri
Li, Haoran
Liu, Yue
Li, Yibo
He, Yufei
Khoi, Le Minh
Song, Yangqiu
Yan, Shuicheng
Hooi, Bryan
Cryptography and Security
Web agents powered by vision-language models (VLMs) enable autonomous interaction with web environments by perceiving and acting on both visual and textual webpage content to accomplish user-specified tasks. However, they are highly vulnerable to prompt injection attacks, where adversarial instructions embedded in HTML or rendered screenshots can manipulate agent behavior and lead to harmful outcomes such as information leakage. Existing defenses, including system prompt defenses and direct fine-tuning of agents, have shown limited effectiveness. To address this issue, we propose a defense framework in which a web agent operates in parallel with a dedicated guard agent, decoupling prompt injection detection from the agent's own reasoning. Building on this framework, we introduce WebAgentGuard, a reasoning-driven, multimodal guard model for prompt injection detection. We construct a synthetic multimodal dataset using GPT-5 spanning 164 topics and 230 visual and UI design styles, and train the model via reasoning-intensive supervised fine-tuning followed by reinforcement learning. Experiments across multiple benchmarks show that WebAgentGuard consistently outperforms strong baselines while preserving agent utility, without introducing additional latency.
title WebAgentGuard: A Reasoning-Driven Guard Model for Detecting Prompt Injection Attacks in Web Agents
topic Cryptography and Security
url https://arxiv.org/abs/2604.12284