Personalized computer-use agents are rapidly moving from expert communities into mainstream use. Unlike conventional chatbots, these systems can install skills, invoke tools, access private resources, and modify local environments on users' behalf. Yet users often do not know what authority they have delegated, what the agent actually did during task execution, or whether the system has been safely removed afterward. We investigate this gap as a combined problem of risk understanding and post-hoc auditability, using OpenClaw as a motivating case. We first build a multi-source corpus of the OpenClaw ecosystem, including incidents, advisories, malicious-skill reports, news coverage, tutorials, and social-media narratives. We then conduct an interview study to examine how users and practitioners understand skills, autonomy, privilege, persistence, and uninstallation. Our findings suggest that participants often recognized these systems as risky in the abstract, but lacked concrete mental models of what skills can do, what resources agents can access, and what changes may remain after execution or removal. Motivated by these findings, we propose AgentTrace, a traceability framework and prototype interface for visualizing agent actions, touched resources, permission history, provenance, and persistent side effects. A scenario-based evaluation suggests that traceability-oriented interfaces can improve understanding of agent behavior, support anomaly detection, and foster more calibrated trust.


翻译:个性化计算机使用代理正迅速从专家社区进入主流应用。与常规聊天机器人不同,这些系统能够代表用户安装技能、调用工具、访问私人资源以及修改本地环境。然而,用户通常不清楚他们授予了哪些权限、代理在任务执行期间实际做了什么,或者系统之后是否被安全移除。我们将这一差距作为风险理解和事后可审计性的复合问题进行研究,并以OpenClaw作为典型案例。我们首先构建了OpenClaw生态系统的多源语料库,包括事件、建议、恶意技能报告、新闻报道、教程和社交媒体叙述。随后,我们进行了一项访谈研究,以考察用户和从业者如何理解技能、自主性、权限、持久性和卸载。研究结果表明,参与者通常抽象地认为这些系统具有风险,但缺乏关于技能能够做什么、代理可以访问哪些资源、以及在执行或移除后哪些变化可能残留的具体心智模型。基于这些发现,我们提出了AgentTrace,一个用于可视化代理行为、被触及资源、权限历史、来源和持久副作用的可追溯性框架和原型界面。一项基于场景的评估表明,面向可追溯性的界面能够提升对代理行为的理解、支持异常检测,并促进更校准的信任。

0
下载
关闭预览

相关内容

《软件定义网络元素与机器代码的形式化验证》
专知会员服务
14+阅读 · 2025年11月18日
中国AI Agent行业研究报告(二)
专知会员服务
48+阅读 · 2025年3月13日
《代理型人工智能全面指南》,45页ppt
专知会员服务
65+阅读 · 2025年2月12日
大型语言模型代理的安全与隐私综述
专知会员服务
30+阅读 · 2024年8月5日
AI Agent:基于大模型的自主智能体
专知会员服务
251+阅读 · 2023年9月9日
【WWW2020-微软】理解用户行为用于文档推荐
专知会员服务
36+阅读 · 2020年4月5日
NLP实践:对话系统技术原理和应用
AI100
34+阅读 · 2019年3月20日
最新人机对话系统简略综述
专知
26+阅读 · 2018年3月10日
国家自然科学基金
2+阅读 · 2017年12月31日
国家自然科学基金
2+阅读 · 2015年12月31日
国家自然科学基金
2+阅读 · 2015年12月31日
国家自然科学基金
19+阅读 · 2015年12月31日
国家自然科学基金
0+阅读 · 2015年12月31日
国家自然科学基金
2+阅读 · 2015年12月31日
国家自然科学基金
0+阅读 · 2014年12月31日
国家自然科学基金
2+阅读 · 2014年12月31日
VIP会员
最新内容
博士论文 | 用代码结构感知方法推进代码大模型
专知会员服务
0+阅读 · 今天15:20
《决策模型比较研究》
专知会员服务
8+阅读 · 今天5:16
《美军水下战与海床战概述及本地实施》
专知会员服务
5+阅读 · 今天4:30
面向未来冲突推进陆军情报体制改革
专知会员服务
4+阅读 · 今天4:12
乌克兰纵深打击如何重塑俄罗斯的战略选择
专知会员服务
3+阅读 · 7月24日
俄乌战争中关于中程打击无人机部署的经验启示
相关基金
国家自然科学基金
2+阅读 · 2017年12月31日
国家自然科学基金
2+阅读 · 2015年12月31日
国家自然科学基金
2+阅读 · 2015年12月31日
国家自然科学基金
19+阅读 · 2015年12月31日
国家自然科学基金
0+阅读 · 2015年12月31日
国家自然科学基金
2+阅读 · 2015年12月31日
国家自然科学基金
0+阅读 · 2014年12月31日
国家自然科学基金
2+阅读 · 2014年12月31日
Top
微信扫码咨询专知VIP会员