How Dark Patterns Manipulate Web Agents
Phil Cuvin, Hao Zhu, Diyi Yang
Abstract
Deceptive UI designs, widely instantiated across the web and commonly known as dark patterns, manipulate users into performing actions misaligned with their goals. In this paper, we show that dark patterns are highly effective in steering agent trajectories, posing a significant risk to agent robustness. To quantify this risk, we introduce D E C E P T I C O N, an environment for testing individual dark patterns in isolation. DECEPTICON includes 700 web navigation tasks with dark patterns-600 generated tasks and 100 real-world tasks, designed to measure instruction-following success and dark pattern effectiveness. Across state-of-the-art agents, we find dark patterns successfully steer agent trajectories towards malicious outcomes in over 70% of tested generated and real-world tasks-compared to a human average of 31%. Moreover, we find that dark pattern effectiveness correlates positively with model size and test-time reasoning, making larger, more capable models more susceptible. Leading countermeasures against adversarial attacks, including in-context prompting and guardrail models, fail to consistently reduce the success rate of dark pattern interventions. Our findings reveal dark patterns as a latent and unmitigated risk to web agents, highlighting the urgent need for robust defenses against manipulative designs. 4444-4444-4444-4444 $1000/mo when trial ends. Introduction Consider a common scenario: You need to purchase flowers quickly. You perform a browser search, visit the non-sponsored top search result, select what appears to be the most popular and reasonably-priced option, and complete your purchase with just a few clicks. The process seems routine until you realize the most expensive bouquet and premium shipping were pre-selected and
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 56655ace-1c3a-4798-ba73-839aec43e433Cited by top-tier papers2
- Deception at Scale: Deceptive Designs in 1K LLM-Generated E-Commerce ComponentsZiwei Chen, Jiawen Shen, Luna, Hanyu Zhang et al.CHI 2026 · 3 citations
- Don't Click That: Teaching Web Agents to Resist Deceptive InterfacesYilin Zhang, Yingkai Hua, Chunyu Wei, Xin Wang et al.ACL 2026
Builds on8
- Language Models are Few-Shot LearnersTom B. Brown, Benjamin Mann, Nick Ryder, Melanie Subbiah et al.NeurIPS 2020 · 64,255 citations
- Dark Patterns after the GDPR: Scraping Consent Pop-ups and Demonstrating their InfluenceMidas Nouwens, Ilaria Liccardi, Michael Veale, David R. Karger et al.CHI 2020 · 491 citations
- Image Hijacks: Adversarial Images can Control Generative Models at RuntimeLuke Bailey, Euan Ong, Stuart Russell, Scott EmmonsICML 2024 · 171 citations
- Tensor Trust: Interpretable Prompt Injection Attacks from an Online GameSam Toyer, Olivia Watkins, Ethan Adrian Mendes, Justin Svegliato et al.ICLR 2024 · 123 citations
- Robust CLIP: Unsupervised Adversarial Fine-Tuning of Vision Embeddings for Robust Large Vision-Language ModelsChristian Schlarmann, Naman Deep Singh, Francesco Croce, Matthias HeinICML 2024 · 114 citations
Related papers
- Investigating the Impact of Dark Patterns on LLM-Based Web AgentsDevin Ersoy, Brandon Lee, Ananth Shreekumar, Arjun Arunasalam et al.S&P 2026 · 16 citations
- Benchmarking Web Agent Safety under E-commerce Deceptive InterfacesZijing Shi, Meng Fang, Ling ChenACL 2026
- Dark Patterns Meet GUI Agents: LLM Agent Susceptibility to Manipulative Interfaces and the Role of Human OversightJingyu Tang, Chaoran Chen, Jiawen Li, Zhiping Zhang et al.CHI 2026 · 4 citations
- AidUI: Toward Automated Recognition of Dark Patterns in User InterfacesS. M. Hasan Mansur, Sabiha Salma, Damilola Awofisayo, Kevin MoranICSE 2023 · 27 citations
- UI Dark Patterns and Where to Find Them: A Study on Mobile Applications and User PerceptionLinda Di Geronimo, Larissa Braz, Enrico Fregnan, Fabio Palomba et al.CHI 2020 · 262 citations
