What the DOM Forgets: Provenance, Relevance and Browser-Agent Security
Abstract
Browser agents operate on browsers optimized around human limitations, despite facing very different constraints. Humans need browsers to be fast and highly interactive, and often struggle to make accurate security decisions from the single URL presented in the address bar. As a result, browsers discard enormous amounts of information that is too costly or confusing for human users, including which actors created or edited which elements in the page. The different tradeoffs faced by agentic browsers make it practical to track this per-element edit history and use it to make better security and privacy decisions. We propose ProvDOM, an agent-optimized system for improving agentic security in two steps. First, ProvDOM tracks which actors (i.e., script origins) created and edited each element in the page. This is achieved by instrumenting the browser's execution runtime, and so is transparent to the webpage. Second, ProvDOM supplies these per-element annotations to a task-conditioned relevance scorer that distinguishes page content relevant to the user's goals from content that is irrelevant or maliciously injected. We then demonstrate that ProvDOM protects against attacks that current systems fail to defend against. We define a category of attack we call In-Page State Forgery, in which an attacker rewrites task-relevant portions of the page to alter an agent's decision making, exploiting multi-principal composition against agents fed a representation built for humans. Because ProvDOM uniquely tracks which page content was created or modified by which actors, it defends against such agent-confusion attacks where current approaches fail.
Then back it, or bet against it.
Related papers
Open the market on this paper to see 7 more related papers.