How Loopjacking Hijacks Human Approval in AI Workflows
Imagine an AI agent asks you to approve a small payment to a familiar vendor. You check the amount, verify the recipient, and approve it.
The workflow continues. A much larger payment goes to a different destination.
You return to the approval record. It still contains the original request.
This scenario illustrates Loopjacking: a failure in which software uses a human’s approval for one operation to authorize or release something materially different. The experiments discussed here used harmless mock transfers and local recording tools; no money moved.
The uncomfortable part is that the human can make the correct decision. The software fails to preserve what that decision authorized.
Researcher Adithyan Arun Kumar examines this gap in Loopjacking: Hijacking Human-in-the-Loop Approval. The study distinguishes two ways it can happen: an operation changes after approval, or the approval view leaves out consequential details that were present all along. Both break...
Copyright of this story solely belongs to hackernoon.com. To see the full text click HERE