{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2024:5CGAGGQWUYY5R4IJK323OCUKNT","short_pith_number":"pith:5CGAGGQW","schema_version":"1.0","canonical_sha256":"e88c031a16a631d8f10956f5b70a8a6cfa2671c3b6c8d20707fdb5f5235d125d","source":{"kind":"arxiv","id":"2409.11295","version":5},"attestation_state":"computed","paper":{"title":"EIA: Environmental Injection Attack on Generalist Web Agents for Privacy Leakage","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.AI","cs.CL","cs.LG"],"primary_cat":"cs.CR","authors_text":"Bo Li, Chaowei Xiao, Chejian Xu, Huan Sun, Jiawei Zhang, Lingbo Mo, Mintong Kang, Yuan Tian, Zeyi Liao","submitted_at":"2024-09-17T15:49:44Z","abstract_excerpt":"Generalist web agents have demonstrated remarkable potential in autonomously completing a wide range of tasks on real websites, significantly boosting human productivity. However, web tasks, such as booking flights, usually involve users' PII, which may be exposed to potential privacy risks if web agents accidentally interact with compromised websites, a scenario that remains largely unexplored in the literature. In this work, we narrow this gap by conducting the first study on the privacy risks of generalist web agents in adversarial environments. First, we present a realistic threat model fo"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2409.11295","kind":"arxiv","version":5},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2024-09-17T15:49:44Z","cross_cats_sorted":["cs.AI","cs.CL","cs.LG"],"title_canon_sha256":"419a22504a0d11cc9b3b27b7970d38369c169864f63b426a9ba5f9bad342af59","abstract_canon_sha256":"e6daf534874b307b14703140563e1a49fd6ebb4bc7c1fcf5e50ad503c0826f35"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T10:30:01.865364Z","signature_b64":"aPYRblz8gliE20y+uoWO0z2XBNx1FOG5J01P671pP+wzSNjmonEY+/yvgsAzOo4lnT5rOcOTPif0Xy78vWaMAA==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"e88c031a16a631d8f10956f5b70a8a6cfa2671c3b6c8d20707fdb5f5235d125d","last_reissued_at":"2026-07-05T10:30:01.864791Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T10:30:01.864791Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"EIA: Environmental Injection Attack on Generalist Web Agents for Privacy Leakage","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.AI","cs.CL","cs.LG"],"primary_cat":"cs.CR","authors_text":"Bo Li, Chaowei Xiao, Chejian Xu, Huan Sun, Jiawei Zhang, Lingbo Mo, Mintong Kang, Yuan Tian, Zeyi Liao","submitted_at":"2024-09-17T15:49:44Z","abstract_excerpt":"Generalist web agents have demonstrated remarkable potential in autonomously completing a wide range of tasks on real websites, significantly boosting human productivity. However, web tasks, such as booking flights, usually involve users' PII, which may be exposed to potential privacy risks if web agents accidentally interact with compromised websites, a scenario that remains largely unexplored in the literature. In this work, we narrow this gap by conducting the first study on the privacy risks of generalist web agents in adversarial environments. First, we present a realistic threat model fo"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2409.11295","kind":"arxiv","version":5},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2409.11295/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2409.11295","created_at":"2026-07-05T10:30:01.864856+00:00"},{"alias_kind":"arxiv_version","alias_value":"2409.11295v5","created_at":"2026-07-05T10:30:01.864856+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2409.11295","created_at":"2026-07-05T10:30:01.864856+00:00"},{"alias_kind":"pith_short_12","alias_value":"5CGAGGQWUYY5","created_at":"2026-07-05T10:30:01.864856+00:00"},{"alias_kind":"pith_short_16","alias_value":"5CGAGGQWUYY5R4IJ","created_at":"2026-07-05T10:30:01.864856+00:00"},{"alias_kind":"pith_short_8","alias_value":"5CGAGGQW","created_at":"2026-07-05T10:30:01.864856+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":9,"internal_anchor_count":1,"sample":[{"citing_arxiv_id":"2607.08147","citing_title":"Prismata: Confining Cross-Site Prompt Injection in Web Agents","ref_index":47,"is_internal_anchor":true},{"citing_arxiv_id":"2606.05233","citing_title":"Domain-Conditioned Safety in Frontier Computer-Using Agents: A 793-Episode Browser Benchmark, a Coding-Domain Cross-Reference, and a Reproducibility Audit of Recent Red-Teaming","ref_index":11,"is_internal_anchor":false},{"citing_arxiv_id":"2606.02449","citing_title":"HLL: Can Agents Cross Humanity's Last Line of Verification?","ref_index":27,"is_internal_anchor":false},{"citing_arxiv_id":"2605.15030","citing_title":"WARD: Adversarially Robust Defense of Web Agents Against Prompt Injections","ref_index":34,"is_internal_anchor":false},{"citing_arxiv_id":"2606.14027","citing_title":"Same-Origin Policy for Agentic Browsers","ref_index":8,"is_internal_anchor":false},{"citing_arxiv_id":"2510.23883","citing_title":"Agentic AI Security: Threats, Defenses, Evaluation, and Open Challenges","ref_index":69,"is_internal_anchor":false},{"citing_arxiv_id":"2605.03378","citing_title":"ARGUS: Defending LLM Agents Against Context-Aware Prompt Injection","ref_index":141,"is_internal_anchor":false},{"citing_arxiv_id":"2605.03129","citing_title":"PIIGuard: Mitigating PII Harvesting under Adversarial Sanitization","ref_index":8,"is_internal_anchor":false},{"citing_arxiv_id":"2604.09747","citing_title":"ADAM: A Systematic Data Extraction Attack on Agent Memory via Adaptive Querying","ref_index":13,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/5CGAGGQWUYY5R4IJK323OCUKNT","json":"https://pith.science/pith/5CGAGGQWUYY5R4IJK323OCUKNT.json","graph_json":"https://pith.science/api/pith-number/5CGAGGQWUYY5R4IJK323OCUKNT/graph.json","events_json":"https://pith.science/api/pith-number/5CGAGGQWUYY5R4IJK323OCUKNT/events.json","paper":"https://pith.science/paper/5CGAGGQW"},"agent_actions":{"view_html":"https://pith.science/pith/5CGAGGQWUYY5R4IJK323OCUKNT","download_json":"https://pith.science/pith/5CGAGGQWUYY5R4IJK323OCUKNT.json","view_paper":"https://pith.science/paper/5CGAGGQW","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2409.11295&json=true","fetch_graph":"https://pith.science/api/pith-number/5CGAGGQWUYY5R4IJK323OCUKNT/graph.json","fetch_events":"https://pith.science/api/pith-number/5CGAGGQWUYY5R4IJK323OCUKNT/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/5CGAGGQWUYY5R4IJK323OCUKNT/action/timestamp_anchor","attest_storage":"https://pith.science/pith/5CGAGGQWUYY5R4IJK323OCUKNT/action/storage_attestation","attest_author":"https://pith.science/pith/5CGAGGQWUYY5R4IJK323OCUKNT/action/author_attestation","sign_citation":"https://pith.science/pith/5CGAGGQWUYY5R4IJK323OCUKNT/action/citation_signature","submit_replication":"https://pith.science/pith/5CGAGGQWUYY5R4IJK323OCUKNT/action/replication_record"}},"created_at":"2026-07-05T10:30:01.864856+00:00","updated_at":"2026-07-05T10:30:01.864856+00:00"}