cs.AISep 28, 2026

Before Acting, Change the State: Prospective State Intervention for Web Agents under Deceptive Interfaces

Authors: Ruozhao Yang, Mingfei Cheng, Xiaofei Xie

Organizations: School of Computing and Information Systems Singapore Management University Singapore 188065

Abstract

LLM-based Web agents can autonomously complete user tasks, yet deceptive interfaces can steer them toward outcomes that conflict with users' interests. Existing defenses primarily intervene on agent behavior through blocking, guidance, or replanning. We identify a distinct failure mode: a task-valid action can still realize an unauthorized consequence because of the current Web state. This motivates treating task-relevant Web state itself as a runtime control target. We introduce Veer, an agent-side runtime defense that leaves task planning to the base agent and intervenes on Web state when a proposed action would produce an unauthorized consequence. Before modifying the live environment, Veer constructs a prospective intervention trajectory toward a safe task-relevant state and executes it with runtime grounding and verification. Across TrickyArena and WebDecept, Veer achieves the highest safe task completion in all three evaluation settings, exceeding the next-best defense by 15.9 and 25.0 percentage points on TrickyArena-Single and TrickyArena-Multi, respectively, while reducing dark-pattern success on WebDecept to 0.3%. These gains persist across dark-pattern types and all 12 agent, model, and benchmark configurations. Ablations show that active state intervention provides the largest gain, while prospective rollout and temporal evidence contribute additional improvements. These results establish task-relevant Web state as an effective runtime control target for protecting Web agents from deceptive outcomes.

Figures & tables

Appendix figures & tables7 assets

Supplementary material from the paper’s appendix.

Appendix

Explore similar work

CardsList
  1. Don't Click That: Teaching Web Agents to Resist Deceptive Interfaces

    May 10, 2026Yilin Zhang, Yingkai Hua, Chunyu Wei +2Web AgentsDeception

  2. Benchmarking Web Agent Safety under E-commerce Deceptive Interfaces

    Apr 26, 2026Zijing Shi, Meng Fang, Ling ChenWeb AgentsDeception

  3. Web Agents Should Adopt the Plan-Then-Execute Paradigm

    May 14, 2026Julien Piet, Annabella Chow, Yiwei Hou +5Web AgentsWeb