acceptodds
Under review as a conference paper at ICLR 2027

CAF: Task-Scoped Authorization against Cross-Channel Composition Attacks in Web Agents

Abstract

Web agents are increasingly used in everyday work and daily life. In this context, an agent often needs to combine information from multiple channels, including DOM/accessibility, visual content, and tool returns. This creates a new attack surface: cross-channel composition attacks, where individually plausible information from different channels can jointly form a complete unauthorized operation. Such attacks can cause the agent to execute operations that fall outside the user’s intended task. However, existing defenses have paid limited attention to this threat, and benchmarks also provide limited support for evaluating such attacks. Therefore, we propose CAF, a pre-execution gateway that checks whether the complete operation proposed by the agent remains within the user’s authorized task scope. We further build C3 Bench, a gym-like execution benchmark that provides a standardized evaluation framework for cross-channel composition attacks and defenses. In the main C3 replay across five models, CAF reduces observed unauthorized-effect rates from 7.7–21.5% to 0% while retaining all authorized effects in the paired baseline runs.

open until 14 Dec 2026

est. 32% chance this paper gets accepted at ICLR 2027.

Reject 68%Accept 32%

What do you think this paper will get?

All positions stay anonymous.

Related papers

Loading the map…

Discussion (0)

Sign in to comment.