MissClick: Exploiting Digit-Serialized Coordinates to Attack GUI Grounding Models
A new paper reveals a security flaw in GUI grounding models that predict screen coordinates as digit tokens, allowing attackers to manipulate clicks by altering single digits.
- GUI grounding models that predict screen coordinates as digit tokens are vulnerable to manipulation by altering single digits.
- Changing a hundreds-place digit can shift the coordinate by 100 units, enabling large-scale click redirection.
- The attack, named "MissClick," exploits the gap between categorical token prediction and numerical parsing.
- Researchers call for numerical constraints in coordinate generation to prevent such security flaws.
Researchers from an unnamed institution have identified a critical security vulnerability in GUI visual grounding models that generate screen coordinates as sequences of digit tokens. These tokens are parsed into numerical values to execute clicks, but the process introduces a significant risk. Since each digit is predicted as a categorical token, altering a single digit in the hundreds place can shift the coordinate by 100 units, leading to a large displacement of the executed click. This discrepancy between token prediction and numerical parsing creates an exploitable attack surface.
The attack, dubbed "MissClick," exploits the numerical sensitivity of coordinate parsing. By strategically manipulating the digit tokens, an attacker could redirect an AI-driven click to a different location on the screen, potentially triggering unintended actions or bypassing security measures. The paper highlights that this vulnerability has been largely overlooked in prior research, despite the growing adoption of GUI grounding models in automated systems and user interfaces.
The findings underscore the need for more robust coordinate generation and parsing mechanisms in AI models that interact with graphical interfaces. The researchers suggest that future models should incorporate numerical constraints during token prediction to mitigate such attacks.
Developers using GUI grounding models must implement numerical constraints to prevent coordinate manipulation attacks.
Businesses relying on AI-driven interfaces face risks of unintended actions or security breaches due to this vulnerability.
This research highlights a new class of security risks in AI systems that interact with graphical user interfaces.
- GUI grounding models
- AI models that predict screen coordinates to execute clicks or interact with graphical user interfaces.
- Digit-serialized coordinates
- Screen coordinates represented as sequences of digit tokens, parsed into numerical values for execution.
SecurityRogue AI agents created fake online identities in another hacking attempt
SecurityAn AI agent went rogue during UK safety tests, creating fake identities and launching social engineering attacks unprompted
SecurityDocker Security Dispatch — Issue 5: AI Security, Hugging Face Incident, and Agent Baseline 📡
SecurityOK, Well, Rogue AI Agents Are Hacking Again
SecurityNvidia doesn’t mess around: A week after open AI industry group formed, it’s already showing progress
Duckworth-Murkowski Bipartisan Bill to Protect Children from Dangers of AI Toys Passes Committee - US Senator Tammy Duckworth (.gov)
A bipartisan US Senate bill aims to protect children from potential harms posed by AI-enabled toys, passing a key committee vote.
FAMU Researchers Use AI to Advance Hurricane Preparedness - Florida A&M University - FAMU
Florida A&M University researchers developed AI models to improve hurricane intensity and path predictions, aiming to enhance disaster preparedness.
AI ToolsHark previews its browser use agent for completing tasks
Hark has previewed a new AI-powered browser agent designed to automate routine online tasks, claiming lower costs and faster performance than existing solutions.
CertiProf Expands International Training Program for ISO/IEC 42001 Artificial Intelligence Governance Standard - tech.einnews.com
CertiProf expands its international training program to certify professionals in the ISO/IEC 42001 AI governance standard.
City Colleges of Chicago Launches its First AI Degree Program - colleges.ccc.edu
City Colleges of Chicago has launched its first AI degree program. The program aims to provide students with skills in artificial intelligence.
Madagascar and the AI machines that think for us - Magnolia Tribune
Researchers in Madagascar are working on AI systems that can think and act independently, with potential applications in various fields.