{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2025:AMCEPARA3YDCWNT7IYOACWYFBU","short_pith_number":"pith:AMCEPARA","schema_version":"1.0","canonical_sha256":"0304478220de062b367f461c015b050d240c0bc80c827b4bb48e2afc714a2cb7","source":{"kind":"arxiv","id":"2503.09241","version":1},"attestation_state":"computed","paper":{"title":"In-Context Defense in Computer Agents: An Empirical Study","license":"http://creativecommons.org/licenses/by-sa/4.0/","headline":"","cross_cats":[],"primary_cat":"cs.AI","authors_text":"Hai Ci, Mike Zheng Shou, Pei Yang","submitted_at":"2025-03-12T10:38:15Z","abstract_excerpt":"Computer agents powered by vision-language models (VLMs) have significantly advanced human-computer interaction, enabling users to perform complex tasks through natural language instructions. However, these agents are vulnerable to context deception attacks, an emerging threat where adversaries embed misleading content into the agent's operational environment, such as a pop-up window containing deceptive instructions. Existing defenses, such as instructing agents to ignore deceptive elements, have proven largely ineffective. As the first systematic study on protecting computer agents, we intro"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2503.09241","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by-sa/4.0/","primary_cat":"cs.AI","submitted_at":"2025-03-12T10:38:15Z","cross_cats_sorted":[],"title_canon_sha256":"fdd4d4c33f10e2fe9c994dee2cb15e44220398d6e07ec2b48e0f7902b5dee2cb","abstract_canon_sha256":"c0c84c4e8aee59de80c74910785830993ff25d547ae0d31ac7d3b1101959ee05"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T10:29:52.549277Z","signature_b64":"iK6mBWLoMoYmXStP4/1SB2hTzjGRj50aNZ3E5u9QyKJATWfAYpOpKamWT+Srq+/c2ggtVd3h33sfDXQ/1JrUAA==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"0304478220de062b367f461c015b050d240c0bc80c827b4bb48e2afc714a2cb7","last_reissued_at":"2026-07-05T10:29:52.548480Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T10:29:52.548480Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"In-Context Defense in Computer Agents: An Empirical Study","license":"http://creativecommons.org/licenses/by-sa/4.0/","headline":"","cross_cats":[],"primary_cat":"cs.AI","authors_text":"Hai Ci, Mike Zheng Shou, Pei Yang","submitted_at":"2025-03-12T10:38:15Z","abstract_excerpt":"Computer agents powered by vision-language models (VLMs) have significantly advanced human-computer interaction, enabling users to perform complex tasks through natural language instructions. However, these agents are vulnerable to context deception attacks, an emerging threat where adversaries embed misleading content into the agent's operational environment, such as a pop-up window containing deceptive instructions. Existing defenses, such as instructing agents to ignore deceptive elements, have proven largely ineffective. As the first systematic study on protecting computer agents, we intro"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2503.09241","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2503.09241/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2503.09241","created_at":"2026-07-05T10:29:52.548578+00:00"},{"alias_kind":"arxiv_version","alias_value":"2503.09241v1","created_at":"2026-07-05T10:29:52.548578+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2503.09241","created_at":"2026-07-05T10:29:52.548578+00:00"},{"alias_kind":"pith_short_12","alias_value":"AMCEPARA3YDC","created_at":"2026-07-05T10:29:52.548578+00:00"},{"alias_kind":"pith_short_16","alias_value":"AMCEPARA3YDCWNT7","created_at":"2026-07-05T10:29:52.548578+00:00"},{"alias_kind":"pith_short_8","alias_value":"AMCEPARA","created_at":"2026-07-05T10:29:52.548578+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":4,"internal_anchor_count":1,"sample":[{"citing_arxiv_id":"2607.08147","citing_title":"Prismata: Confining Cross-Site Prompt Injection in Web Agents","ref_index":94,"is_internal_anchor":true},{"citing_arxiv_id":"2606.06904","citing_title":"ActionMap: Robot Policy Learning via Voxel Action Heatmap","ref_index":44,"is_internal_anchor":false},{"citing_arxiv_id":"2507.10610","citing_title":"LaSM: Layer-wise Scaling Mechanism for Defending Pop-up Attack on GUI Agents","ref_index":15,"is_internal_anchor":false},{"citing_arxiv_id":"2605.07110","citing_title":"Securing Computer-Use Agents: A Unified Architecture-Lifecycle Framework for Deployment-Grounded Reliability","ref_index":126,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/AMCEPARA3YDCWNT7IYOACWYFBU","json":"https://pith.science/pith/AMCEPARA3YDCWNT7IYOACWYFBU.json","graph_json":"https://pith.science/api/pith-number/AMCEPARA3YDCWNT7IYOACWYFBU/graph.json","events_json":"https://pith.science/api/pith-number/AMCEPARA3YDCWNT7IYOACWYFBU/events.json","paper":"https://pith.science/paper/AMCEPARA"},"agent_actions":{"view_html":"https://pith.science/pith/AMCEPARA3YDCWNT7IYOACWYFBU","download_json":"https://pith.science/pith/AMCEPARA3YDCWNT7IYOACWYFBU.json","view_paper":"https://pith.science/paper/AMCEPARA","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2503.09241&json=true","fetch_graph":"https://pith.science/api/pith-number/AMCEPARA3YDCWNT7IYOACWYFBU/graph.json","fetch_events":"https://pith.science/api/pith-number/AMCEPARA3YDCWNT7IYOACWYFBU/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/AMCEPARA3YDCWNT7IYOACWYFBU/action/timestamp_anchor","attest_storage":"https://pith.science/pith/AMCEPARA3YDCWNT7IYOACWYFBU/action/storage_attestation","attest_author":"https://pith.science/pith/AMCEPARA3YDCWNT7IYOACWYFBU/action/author_attestation","sign_citation":"https://pith.science/pith/AMCEPARA3YDCWNT7IYOACWYFBU/action/citation_signature","submit_replication":"https://pith.science/pith/AMCEPARA3YDCWNT7IYOACWYFBU/action/replication_record"}},"created_at":"2026-07-05T10:29:52.548578+00:00","updated_at":"2026-07-05T10:29:52.548578+00:00"}