Known By Their Actions: Fingerprinting LLM Browser Agents via UI Traces

Fuente: arXiv
Guardado en:
Detalles Bibliográficos
Autores principales: Lugoloobi, William, Marro, Samuelle, Magomere, Jabez, Wright, Joss, Russell, Chris
Formato: Preprint
Publicado: 2026
Materias:
Acceso en línea:
Etiquetas: Agregar Etiqueta
Sin Etiquetas, Sea el primero en etiquetar este registro!
_version_ 1866917495759175680
author Lugoloobi, William
Marro, Samuelle
Magomere, Jabez
Wright, Joss
Russell, Chris
author_facet Lugoloobi, William
Marro, Samuelle
Magomere, Jabez
Wright, Joss
Russell, Chris
contents As LLM-based agents increasingly browse the web on users' behalf, a natural question arises: can websites passively identify which underlying model powers an agent? Doing so would represent a significant security risk, enabling targeted attacks tailored to known model vulnerabilities. Across 14 frontier LLMs and four web environments spanning information retrieval and shopping tasks, we show that an agent's actions and interaction timings, captured via a passive JavaScript tracker, are sufficient to identify the underlying model with up to 96\% F1. We formalise this attack surface by demonstrating that classifiers trained on agent actions generalise across model sizes and families. We further show that strong classifiers can be trained from few interaction traces and that agent identity can be inferred early within an episode. Injecting randomised timing delays between actions substantially degrades classifier performance, but does not provide robust protection: a classifier retrained on delayed traces largely recovers performance. We release our harness and a labelled corpus of agent traces \href{https://github.com/KabakaWilliam/known_actions}{here}.
format Preprint
id arxiv_https___arxiv_org_abs_2605_14786
institution arXiv
publishDate 2026
record_format arxiv
spellingShingle Known By Their Actions: Fingerprinting LLM Browser Agents via UI Traces
Lugoloobi, William
Marro, Samuelle
Magomere, Jabez
Wright, Joss
Russell, Chris
Cryptography and Security
Artificial Intelligence
Human-Computer Interaction
Machine Learning
As LLM-based agents increasingly browse the web on users' behalf, a natural question arises: can websites passively identify which underlying model powers an agent? Doing so would represent a significant security risk, enabling targeted attacks tailored to known model vulnerabilities. Across 14 frontier LLMs and four web environments spanning information retrieval and shopping tasks, we show that an agent's actions and interaction timings, captured via a passive JavaScript tracker, are sufficient to identify the underlying model with up to 96\% F1. We formalise this attack surface by demonstrating that classifiers trained on agent actions generalise across model sizes and families. We further show that strong classifiers can be trained from few interaction traces and that agent identity can be inferred early within an episode. Injecting randomised timing delays between actions substantially degrades classifier performance, but does not provide robust protection: a classifier retrained on delayed traces largely recovers performance. We release our harness and a labelled corpus of agent traces \href{https://github.com/KabakaWilliam/known_actions}{here}.
title Known By Their Actions: Fingerprinting LLM Browser Agents via UI Traces
topic Cryptography and Security
Artificial Intelligence
Human-Computer Interaction
Machine Learning
url https://arxiv.org/abs/2605.14786