ZERO-LEAKAGE ARCHITECTURE ON-DEVICE AI GOVERNMENT & DEFENSE READY

Visual Perception & Privacy Layer for Browser Agents

VEIL-X enables autonomous browser agents to understand and interact with visual web content while keeping credentials, biometric faces, and sensitive data protected directly on-device.

Launch Live Demo →
100% On-Device
Length-Hiding Pre-Mask
Solid Blackout Redaction
Fail-Closed Gate
🔒 https://isro.gov.in/telemetry/classified_manifest
VEIL-X VEIL-X ACTIVE
VIEWPORT STAGE:
Flight Commander Email: somanath@isro.gov.in
Satellite Emergency Phone: +91 98450 12345
Telemetry Uplink Card: 4532 8901 2345 6789
Officer Biometric Photo:
UltraFace ONNX Scan Target
👨‍✈️
FACE REDACTED
ON-DEVICE FSM FAIL-CLOSED VERIFIED
Vision Engine UltraFace ONNX (31ms)
PII Scanner 12 Local Rules (Ready)
Privacy Gate Zero Leakage
The Dilemma

Browser agents need vision.
Vision sees sensitive data.

Autonomous web agents require screen perception to click buttons, inspect canvas layouts, and navigate complex interfaces. But an unredacted screen exposes passwords, Aadhaar numbers, private messages, and biometric faces directly to third-party reasoning models.

⚠️ Unprotected Screen Capture (Conventional Agent)

HIGH PRIVACY RISK
Officer Name: Flight Lt. R. Sharma
Officer Email: r.sharma@isro.gov.in
Cryptographic Key: MySecretPassword2026!#
UIDAI Aadhaar ID: 5482 9104 3821
Comms Billing Card: 4532 8912 3456 7890

Conventional multimodal agents capture high-resolution screenshots of the user's browser and send them directly over the wire to remote VLMs.

Once visual credentials cross the network boundary, prompt injections can exfiltrate them, server logs can persist them, and model inference windows can memorize them.

The VEIL-X Imperative: Privacy cannot be an afterthought enforced by prompt instructions. It must be an architectural enforcement boundary evaluated directly on-device before any byte leaves the browser.
System Architecture

Keep perception local.
Send only what the agent needs.

VEIL-X intercepts the browser perception loop. A multi-layer fusion pipeline detects, masks, and redacts sensitive regions on-device, verifying zero leakage before releasing sanitized context.

🖥️ 01 RAW SCREEN Client Viewport
➔
👁️ 02 LOCAL VISION WASM / WebGPU
➔
🧩 03 REGION FUSION DOM + Layout
➔
🛡️ 04 PII DETECTION 12 Local Rules
➔
⬛ 05 REDACTION Solid Blackout
➔
🔒 06 PRIVACY GATE Fail-Closed FSM
➔
☁️ 07 REASONING Sanitized VLM
➔
⚡ 08 SAFE ACTION Policy Guardrail
Device Boundary

The privacy boundary is enforced before transmission.

Compare what happens exclusively on your physical client device versus the sanitized context received by remote reasoning models.

🔒 YOUR DEVICE (MV3 Client Edge) STRICTLY LOCAL
  • ✓ Raw Screen Viewport & Canvas Buffers
  • ✓ Passwords, PINs & Cryptographic Keys
  • ✓ Aadhaar, PAN, SSN & Phone Numbers
  • ✓ Biometric Face Portraits & ID Badges
  • ✓ Local ONNX Inference (UltraFace + MobileNet)
  • ✓ Tesseract WASM OCR Engine
  • ✓ Uniform Pre-Capture Masking (••••••••)
  • ✓ Fail-Closed Verification Enforcement
VEIL-X Shield
FAIL-CLOSED
PRIVACY GATE
Zero Raw PII
Permitted
☁️ REASONING SERVER (VLM / LLM) SANITIZED ONLY
  • ✓ Solid Blackout Redacted Visual Image
  • ✓ Uniform Masked Text Tokens (••••••••)
  • ✓ Sanitized DOM Structure Tree
  • ✓ Public Navigational Buttons & Selectors
  • ✓ Abstract Next-Action Emission
  • ✕ Zero Plaintext Credentials
  • ✕ Zero Biometric Facial Features
  • ✕ Zero Token-Length Leakage Vectors
Defense-in-Depth

Two layers. One privacy boundary.

Uniform fixed-length pre-capture masking + solid pixel blackout. Protecting against visual edge-bleeding and token length side-channels simultaneously.

STAGE 01

Original Raw Data

flight.commander@isro...

Sensitive credential exists on DOM or canvas. Unprotected transmission here leads to complete privacy compromise.

STAGE 02

Uniform Pre-Mask

••••••••

Length-Hiding Defense: Replaces DOM text with fixed 8-dot tokens prior to capture, eliminating character-count side channels.

STAGE 03

Solid Blackout

████████████

Visual Zeroing: The local redactor overwrites bounding box pixels with solid black (RGB: 0,0,0) before encoding to JPEG/PNG.

STAGE 04

Privacy Gate

✓ VERIFIED & TRANSMITTED

Fail-Closed Gate: Scans the final payload for leakage. If any residual PII is found, transmission is aborted immediately.

flight.commander@isro.gov.in

1. Raw Unprotected Field: Direct email address visible on DOM/canvas. Exposing this crosses the privacy line.

On-Device Capabilities

Perception happens where the data lives.

Six specialized on-device modules work in synergy to perceive, understand, and sanitize browser surfaces without external cloud dependencies.

👁️

Local Vision Engine

MobileNetV2 neural vision model running on WASM and WebGPU. Classifies UI elements and structural screen context in under 35 milliseconds.

🔤

Tesseract WASM OCR

Zero-DOM text extraction engine. Reads raw pixel canvas buffers, PDFs, and scanned charts where HTML DOM elements do not exist.

👤

UltraFace ONNX

Lightweight on-device face detector. Detects human faces, biometric badges, and ID portraits at multiple scales with tight bounding boxes.

🛡️

Multi-Pattern PII Detector

High-precision regex and semantic classifiers for Indian and international identities: Aadhaar, PAN, emails, phones, PINs, cards, and OTPs.

🧩

Region Fusion Engine

Fuses DOM semantic regions, OCR text coordinates, and visual neural bounding boxes using IoU overlap resolution into a unified perception scene.

🔒

Fail-Closed Privacy Gate

Formal finite state machine (FSM). Guarantees that if perception or redaction encounters any anomaly, zero bytes are transmitted to the server.

Autonomous Execution

Understand. Act. Verify. Repeat.

Browser agents cannot rely on static perceptions. After every action, VEIL-X dynamically re-perceives the updated screen state while enforcing a strict action whitelist.

VEIL-X MULTI-TURN
1. PERCEIVE
2. REDACT
3. REASON
4. SAFE ACT

Deterministic Action Protocol

To prevent unauthorized script execution or prompt-injection hijacking, the browser extension validates every emitted model command against a strict whitelist:

✓ CLICK (Safe Targets)
✓ SCROLL (Bounded Y)
✓ TYPE (Public Fields)
✓ SELECT (Dropdowns)
Security Invariant: Any action attempting to type into sensitive/password fields, execute arbitrary scripts (eval), or bypass human authorization is automatically intercepted and BLOCKED.
Empirical Validation

Measured, not claimed.

Evaluated against a weighted rubric spanning visual context accuracy, PII detection quality, redaction precision, resource efficiency, and task latency — plus comprehensive adversarial privacy test suites.

Visual Context Accuracy 25%
PII Precision & Recall 20%
Redaction Precision (IoU) 20%
Resource Utilization 20%
Task Latency (E2E) 15%
PII Precision
0%
Zero False Positives 120-item v2 benchmark
PII Recall
0%
F1 Score: 96.77% 80 ground-truth PII targets
Redaction Overlap
0.0
Mean IoU Overlap 0.00% under-redaction
Adversarial Attacks
0
100% Defeated Pixel, OCR & byte recovery
Agent Tasks Passed
0
100% Task Success 5 unsafe actions blocked
Turn Latency (E2E)
0 ms
P50: 49.95 ms | P95: 89.82 ms Local pipeline turn time
Client Model Bundle
0 MB
UltraFace + MobileNet + Tesseract WASM & ONNX local bundle
Backend Test Suite
0
Pytest Regression Passing Rate limits, injections & headers
Architecture & Requirements Coverage

Capabilities at a glance

Every core requirement of a privacy-preserving, on-device browser agent, mapped directly to its implementation in VEIL-X.

Requirement VEIL-X Implementation Architecture Verification Status
Local Visual Processing Client-side MobileNetV2 (WASM/WebGPU) + UltraFace ONNX + Tesseract WASM running purely in browser MV3 sandbox. ● IMPLEMENTED & VERIFIED
Privacy-Preserving Filter Multi-pattern PII detector + Uniform Fixed-Length Pre-Masking (••••••••) + Solid Pixel Blackout Redaction. ● IMPLEMENTED & VERIFIED
Sanitized Visual Context Redacted visual viewport buffers + sanitized UI context tree; fail-closed verification ensures zero raw PII leaks. ● IMPLEMENTED & VERIFIED
Server-Side Reasoning Hardened FastAPI server interfacing with multimodal VLM / LLM models; rate-limited and injection-sanitized. ● IMPLEMENTED & VERIFIED
Controlled Browser Actions Strict action whitelist protocol (click, scroll, type, select); blocks typing into sensitive fields and eval scripts. ● IMPLEMENTED & VERIFIED
End-to-End Autonomous Task Continuous multi-turn agent loop with dynamic re-perception; validated across 18 standardized browser tasks. ● IMPLEMENTED & VERIFIED
Cross-Browser Support Manifest V3 client-side extension architecture supporting Chrome, Chromium-based browsers, and Firefox. ● IMPLEMENTED & VERIFIED
Latency vs. Accuracy Balance Automated benchmark suite measuring PII precision, IoU redaction overlap, heap utilization, and turn latency. ● IMPLEMENTED & VERIFIED
Simulation Portals

Explore All 3 Live Demo Environments

VEIL-X includes three specialized interactive portals designed to test different facets of the on-device perception layer: full browser agent automation, empirical benchmarks, and zero-DOM canvas processing.

Evaluation Metrics Telemetry & Audit
📊

Empirical Benchmark Dashboard

Comprehensive empirical validation dashboard measuring live telemetry across core performance, precision, and latency evaluation criteria.

  • ✓ Core 25/20/20/20/15 evaluation weight criteria breakdown
  • ✓ 30/30 adversarial attacks defeated (100%)
  • ✓ Live memory & heap telemetry graphs
  • ✓ P50 (49.95ms) & P95 (89.82ms) turn latencies
Open Benchmark Dashboard 📊
Zero-DOM Vision Canvas & WASM OCR
📄

Zero-DOM Canvas Vault

Specialized environment testing visual edge perception on interfaces where no HTML DOM elements exist (scanned PDFs, encrypted telemetry canvases, and raw images).

  • ✓ Tesseract WASM client-side OCR extraction
  • ✓ Coordinate-based solid blackout redaction
  • ✓ Scanned PDF & image manifest defense
  • ✓ Zero cloud text extraction dependencies
Open Canvas Vault 📄
⚡

Local First

Perception begins directly in the browser's execution context. Heavy visual analysis is computed on-device using WebAssembly and WebGPU without raw screen telemetry leaving the machine.

🛡️

Privacy by Construction

Privacy is not guaranteed by prompt requests or model goodwill. A deterministic finite state machine physically verifies the visual payload before any HTTP transmission is permitted.

🤖

Agent Ready

Sanitized screen context retains structural labels, actionable coordinates, and layout hierarchy, giving autonomous agents the context they need while guarding the data they shouldn't see.

Let the agent see.
Not your secrets.

Experience the on-device perception layer live in your browser, or install the extension to protect your real-world browsing sessions.

Launch Interactive Simulator → View Source on GitHub ↗