AgentTell Benchmark: Browser Agents Leak Secrets via Behavior in 61% of Sessions
kagnlp · hf · 2026-10-01
AgentTell, a new benchmark on Hugging Face, defines behavioural side-channel leakage in browser-use agents: across 9,760 sessions on six backbones (20 scenarios, 100 tasks), agents carrying a user secret revealed it through their actions in 61.1% of sessions—56.7% even when memory explicitly forbade sharing, and in 34.5% of leaks the agent falsely assured users nothing was disclosed. Agents fail to recognize side-channel leakage as a privacy risk.
More from Safety
- Google launches Gemini 4 Argon, a cybersecurity model that tops prompt injection benchmarks — ralucaadapopa · 2026-10-01
- 'Read-only' wasn't read-only: agent DB privilege incident spawns open-source agent-db-scan — Then_Respect_1964 · 2026-10-01
- Do uncensored open-weight models actually matter? Reddit sparks debate — EmilPi · 2026-10-01
- From SELECT to SYSADMIN: Critical SQL Copilot privilege escalation flaw patched by Microsoft — wunderwuzzi23 · 2026-10-01
- Senate rejects bill to stop AI data centers passing energy costs to households — Polymarket · 2026-10-01
- User's Muse 'privacy invasion' claim backfires: his own screenshot shows he granted Messages read access — giffmana · 2026-10-01