{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/sudo-rm-rf-agentic-security","title":"sudo rm -rf agentic_security","arxiv_id":"2503.20279","date":"2025-03-26","proceeding":null,"authors":["Sejin Lee","Jian Kim","Haon Park","Ashkan Yousefpour","Sangyoon Yu","Min Song"],"abstract":"Large Language Models (LLMs) are increasingly deployed as computer-use agents, autonomously performing tasks within real desktop or web environments. While this evolution greatly expands practical use cases for humans, it also creates serious security exposures. We present SUDO (Screen-based Universal Detox2Tox Offense), a novel attack framework that systematically bypasses refusal-trained safeguards in commercial computer-use agents, such as Claude for Computer Use. The core mechanism, Detox2Tox, transforms harmful requests (that agents initially reject) into seemingly benign requests via detoxification, secures detailed instructions from advanced vision language models (VLMs), and then reintroduces malicious content via toxification just before execution. Unlike conventional jailbreaks, SUDO iteratively refines its attacks based on a built-in refusal feedback, making it increasingly effective against robust policy filters. In extensive tests spanning 50 real-world tasks and multiple state-of-the-art VLMs, SUDO achieves a stark attack success rate of 24.41% (with no refinement), and up to 41.33% (by its iterative refinement) in Claude for Computer Use. By revealing these vulnerabilities and demonstrating the ease with which they can be exploited in real-world computing environments, this paper highlights an immediate need for robust, context-aware safeguards. WARNING: This paper includes harmful or offensive model outputs","url_abs":"https://arxiv.org/abs/2503.20279v3","url_pdf":"https://arxiv.org/pdf/2503.20279v3.pdf","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"abstracts"},"code_links":[{"paper_slug":"sudo-rm-rf-agentic-security","repo_url":"https://github.com/AIM-Intelligence/SUDO","is_official":1,"mentioned_in_paper":1,"mentioned_in_github":1,"framework":"none","reach":null}],"tasks":[{"task_slug":"ai-and-safety","task_name":"AI and Safety"},{"task_slug":"adversarial-attack","task_name":"Adversarial Attack"},{"task_slug":"real-world-adversarial-attack","task_name":"Real-World Adversarial Attack"},{"task_slug":"red-teaming","task_name":"Red Teaming"},{"task_slug":"safety-alignment","task_name":"Safety Alignment"}],"methods":[],"datasets_introduced":[{"slug":"sudo-dataset","name":"SUDO Dataset","full_name":""}],"methods_introduced":[],"results":[{"leaderboard":"/sota/red-teaming-on-sudo-dataset","task":"Red Teaming","dataset":"SUDO Dataset","model":"SUDO","rank_in_archive_order":1,"of":1,"metrics":{"Attack Success Rate":"41%"},"uses_additional_data":false}],"syntology":{"syntology_url":null,"atlas_url":"https://app.syntology.ai/?focus=2503.20279","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2503.20279"}},"developers":"https://syntology.ai/developers","read_at":"2026-09-24T18:15:14+00:00","read_at_is":"when the build read Syntology's graph, not when any sample ran","claim":"Per-sample execution status on synthesized fixtures; not a correctness claim about the paper. Samples come from repositories linked to the paper, official or community; repo_kind says which.","repos":[{"provenance":"external:paperswithcode_snapshot_2025-07-28","url":"https://github.com/AIM-Intelligence/SUDO","reach":null}],"summary":{"ran_draft_wrong":1,"ran":1},"by_repo_kind":{"official":{"samples":2,"ran":2,"repositories":1}},"repo_kind_vocabulary":{"official":"The archive marks this repository official for the paper","named_in_paper":"The archive records that the paper mentions this repository; it is not marked official","listed":"In the archive's code links for this paper, not marked official and not recorded as mentioned in the paper","found_in_text":"Syntology found this repository in the paper's own text; whether it is the authors' implementation is not asserted","community":"Not in the archive's code links for this paper; a community repository Syntology harvested"},"n_pointer_only_for_licence":2,"samples":[{"code_sha256_prefix":"e20cb93a08f3b666","entry":"deharm","repo":"AIM-Intelligence/SUDO","repo_kind":"official","path":"attack/static_attack.py","file_url":"https://github.com/AIM-Intelligence/SUDO/blob/HEAD/attack/static_attack.py","link_basis":"first_harvest_node","language":"python","status":"ran_draft_wrong","verification_level":1,"contract_check":"OUTPUT_MISDECLARED","metamorphic_tier":"deterministic","behaviour_fingerprint":false,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"e20cb93a08f3b666"}},{"code_sha256_prefix":"6be668955e9be30d","entry":"generate_prompts_4o","repo":"AIM-Intelligence/SUDO","repo_kind":"official","path":"attack/static_attack.py","file_url":"https://github.com/AIM-Intelligence/SUDO/blob/HEAD/attack/static_attack.py","link_basis":"first_harvest_node","language":"python","status":"ran","verification_level":1,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"6be668955e9be30d"}}]},"arxiv_metadata":null,"syntology_extracted_results":null}