Score
Design and build systems that extract, represent, and analyze multi‑layer signals from web clients—including network/transport and TLS features, HTTP-level metadata, and in‑browser interaction and behavioral traces—to create persistent fingerprints that differentiate human users, crawlers, bots, and stealthy/LLM-driven agents. This competence covers instrumentation for signal capture, feature engineering and cross‑layer fusion, modeling or anomaly detection to identify agents, and evaluation for robustness against evasion.
This work addresses the growing privacy and security risks posed by AI-powered autonomous web agents that commonly bypass protective mechanisms such as robots.txt. To counter this, the authors propose a multi-layer fingerprinting approach that integrates network-level features (e.g., TLS/HTTP protocol characteristics) with browser interaction behaviors, enabling precise differentiation among AI agents, human users, and traditional web crawlers. The method introduces a deployable logging framework that achieves fine-grained, cross-layer attribution of mainstream AI agents for the first time, demonstrating strong evasion resistance and robustness. Experimental evaluation across six widely used agent frameworks shows a classification accuracy of 97%, effectively isolating distinct traffic types and establishing a novel paradigm for content protection on the web.
This study addresses the challenge of effectively detecting and distinguishing large language model (LLM) web agents employing stealth and anti-detection techniques from genuine human users. By deploying honeypot websites integrated with multiple anti-scraping mechanisms—including robots.txt, CAPTCHA, proof-of-work challenges, and Cloudflare protections—and combining multi-layer fingerprinting across network, HTTP, and browser levels, the authors systematically evaluate behavioral characteristics of six prominent LLM agents. The research reveals, for the first time, that all tested agents can be clearly differentiated from both humans and each other through these multi-layer fingerprints. Notably, some agents successfully bypass all deployed anti-scraping measures, while their stealth strategies often prove counterproductive, inadvertently increasing detectability and thereby challenging prevailing assumptions about the efficacy of current anti-detection approaches.
This work identifies a novel website impersonation attack targeting LLM-driven autonomous web browsing agents. Adversaries accurately identify AI agent traffic via browser fingerprinting, automation framework signatures, and network behavioral patterns. Method: They dynamically serve visually benign yet maliciously poisoned web pages—embedding indirect prompt injection and other stealthy instructions—that exclusively affect AI agents while appearing normal to humans. The authors introduce the “parallel poisoning web attack” model, defining a covert threat surface specific to AI agents, and design a coordinated attack framework integrating multi-dimensional traffic fingerprinting with dynamic HTML content poisoning. Results: Experiments demonstrate that mainstream AI agents are vulnerable in realistic settings to data exfiltration, arbitrary code execution (e.g., malware deployment), and disinformation propagation, exposing fundamental weaknesses in current defense mechanisms against agent-specific threats.
Existing website fingerprinting (WFP) methods exhibit poor generalization in modern web environments—particularly single-page applications (SPAs)—largely because script-based traffic replay fails to capture the diversity and continuity of real user behavior. Method: We propose a novel, continuous traffic synthesis paradigm powered by multi-agent large language models (LLMs). Departing from page-boundary constraints, our approach employs a role-driven, collaborative multi-agent system that simulates personalized, semantically rich, and temporally coherent browsing behaviors to generate high-fidelity encrypted network traffic. Contribution/Results: This paradigm drastically reduces data synthesis cost and enhances scalability. Evaluations across 20 modern websites and traffic from 30 real users show that WFP models trained on LLM-synthesized data achieve >80% accuracy—surpassing <10% accuracy attained with script-generated data. Results demonstrate that modeling behavioral continuity and user persona is critical for improving WFP generalization.
This study addresses the critical gap in empirical research and labeled data concerning malicious behaviors in third-party large language model (LLM) agent skills. We present the first open-sourced, annotated dataset of malicious agent skills, derived from a large-scale behavioral analysis of 98,380 skills in community registries. Our investigation identifies 157 malicious skills containing 632 vulnerabilities, uncovering two dominant attack paradigms—data exfiltration and agent hijacking—and revealing sophisticated exploitation techniques targeting shadow features and platform hook systems. By integrating behavioral verification, vulnerability discovery, kill-chain modeling, and a responsible disclosure framework, our approach facilitated the removal of 93.6% of identified malicious skills within 30 days of disclosure, establishing essential infrastructure for advancing LLM agent security research.
This work reveals a previously unexamined vulnerability in large language model (LLM) browser agents: their underlying models can be passively fingerprinted through UI interaction patterns during web tasks, exposing them to targeted attacks. The study introduces the first systematic analysis of this risk and proposes a JavaScript-based passive tracking method that leverages behavioral sequence modeling and machine learning classifiers to identify the specific LLM powering an agent with high accuracy from minimal early interactions. Evaluated across 14 prominent LLMs and four distinct web environments, the approach achieves up to 96% F1 score, demonstrating strong generalization across model scales and families. To facilitate further research, the authors publicly release the collected interaction trajectory dataset and the evaluation framework.
This study addresses the challenge of effectively distinguishing AI-powered browsing agents from human users, a task where existing detection mechanisms fall short. The authors construct honeypot websites to collect browser fingerprints and fine-grained behavioral data—including keystrokes, scrolling, and mouse interactions—from seven prominent AI agents and human participants performing typical web tasks. They propose FP-Agent, a multiclass classifier trained on this multimodal dataset, which leverages behavioral fingerprints to differentiate both between AI agents and humans and among distinct AI agent types. This work is the first to systematically demonstrate the critical role of behavioral fingerprints in AI agent identification, overcoming the limitations of approaches relying solely on traditional browser fingerprinting. Experimental results show that FP-Agent accurately identifies all seven AI agent categories, substantially outperforming mainstream anti-bot services such as Cloudflare, which detect only one type, thereby affirming the decisive value of behavioral fingerprints in AI agent detection.
This study addresses a critical limitation in existing binary bot detectors, which fail to distinguish traffic generated by AI agents based on browser automation from that of humans or traditional bots. To resolve this, the work proposes the first ternary classification framework explicitly differentiating human users, traditional bots, and AI agents, thereby exposing the systematic misclassification of AI agents by conventional binary models. Leveraging browser automation behavioral features—such as mouse_event_rate and teleport_click_ratio—and combining MLP, SAINT, and large-scale GBM-based feature subset search, the approach achieves 100% recall for AI agents using only two features. Under five levels of evasion attacks (22,990 predictions), it attains zero false negatives, with a precision of 0.994 for the two-feature combination and a macro F1-score of at least 0.99 when using five features.
This work addresses a critical security gap in large language model (LLM) agents that rely on third-party API routers to forward tool invocations without end-to-end encryption, rendering them vulnerable to malicious intermediaries. We formalize, for the first time, a threat model for adversarial routers within the LLM supply chain and introduce a taxonomy of four attack classes, with particular emphasis on payload injection and credential theft—including their adaptive variants. Through empirical measurements, honeypot credential tracking, and a custom attack agent dubbed Mine, we uncover active exploitation across 68 real-world routers, including incidents involving Ethereum private key exfiltration. We further evaluate three client-side defenses—fail-closed policies, response anomaly detection, and append-only transparent logging—and demonstrate their efficacy, establishing a reproducible framework for secure LLM tool invocation.
This study addresses the growing challenge posed by AI-driven automated scanning tools that undermine foundational assumptions of intrusion detection systems in industrial control systems (ICS) and Industrial Internet of Things (IIoT) environments. Leveraging a modular analytical pipeline applied to 192 million darknet packets captured between 2021 and 2025, this work reveals for the first time that modern botnets employ microsecond-scale artificial delays to smooth traffic and evade conventional threshold-based anomaly detection. Multidimensional evaluation—including average packet rate, Shannon entropy, inter-arrival time burstiness, geolocation provenance, and port distribution—demonstrates that ICS-targeted scan traffic nearly doubled over four years. Alarmingly, 97.47% of botnet traffic successfully bypasses standard detection mechanisms, while increasing detector sensitivity incurs an unacceptably high false positive rate of 68.10%.