AI Web Crawler Security White Paper
Author: Guancheng Li and Zheng Wang of Tencent Xuanwu Lab
This white paper from Tencent Xuanwu Lab analyzes how moving browsers and crawlers from user endpoints into AI server-side infrastructure fundamentally changes the attack and defense landscape. As LLM-based agents increasingly rely on server-side browsing for search, data extraction, and automated task execution, the browser becomes a high-value, high-risk component embedded deep inside the data center.
Building on real-world security testing against multiple large-scale AI products, the paper reconstructs typical attack chains against server-side browsers, explains why traditional “patch + sandbox” assumptions fail in this environment, and proposes a defense-in-depth framework centered on static attack surface reduction + dynamic runtime isolation. It also introduces SEChrome, an open-sourced practical protection layer for securing server-side Chrome-based crawlers.
Download: AI Web Crawler Security White Paper.pdf