WASP
收藏资源简介:
WASP是一个针对Web Agent安全性的基准测试数据集,它通过引入真实的Web Agent劫持目标和隔离环境来测试这些目标,不会影响真实用户或实时Web。该数据集包括针对三个流行的Web Agent系统(VisualWebArena、Claude Computer Use和Operator)的基准攻击,这些系统使用了各种最先进的模型。WASP的数据集由手工制作的恶意指令组成,旨在模拟真实世界中的攻击者行为。数据集包含了21个攻击目标和2个用户目标,每个目标都在VisualWebArena环境中进行了测试,以确保其可执行性。WASP旨在解决Web Agent在面临恶意指令注入攻击时的安全问题,为研究人员提供一个平台来评估和改进Web Agent的安全性。
WASP is a benchmark dataset for Web Agent security. It tests targets by introducing real Web Agent hijacking targets and isolated environments, without affecting real users or the live Web. This dataset includes benchmark attacks against three popular Web Agent systems: VisualWebArena, Claude Computer Use, and Operator, which utilize various state-of-the-art models. The WASP dataset consists of hand-crafted malicious instructions designed to simulate real-world attacker behaviors. It contains 21 attack targets and 2 user targets, each tested in the VisualWebArena environment to ensure executability. WASP aims to address the security issues of Web Agents facing malicious instruction injection attacks, providing a platform for researchers to evaluate and improve the security of Web Agents.




