Desktop & OS Agents Multimodal VLA September 2026 ยท 18 min read

Beyond the Browser: Building Desktop GUI Agents in 2026 with UI-TARS, Claude Computer Use, and OSWorld 2.0

Over the past three years, the AI ecosystem focused heavily on web-browser automation using tools like Browser-Use, Stagehand, and Playwright MCP to parse HTML DOM trees. However, over 70% of enterprise software workflows do not run inside a browser DOM. Legacy ERPs (SAP GUI), native Excel workbooks with embedded VBA macros, desktop CAD suites, terminal consoles, and native clients possess zero web DOM. When operating systems render directly via DirectX, Metal, Win32, or Qt, DOM-based agents are blind. To unlock true enterprise automation, 2026 marks the rise of Autonomous Desktop GUI Agents powered by native Vision-Language-Action (VLA) foundation models, pixel-coordinate grounding, and System-2 deliberate reasoning. This architectural deep dive analyzes UI-TARS 1.5, Claude 3.7 Computer Use, the OSWorld 2.0 benchmark, and production sandbox containment.

01. Quick Summary & The Desktop GUI Frontier

Web automation reached maturity, but desktop knowledge work remained untamed. In 2026, desktop GUI agents treat the entire computer screen as their interactive canvas:

  • Beyond HTML Selectors: Desktop agents observe raw screen frames (1080p to 4K), recognize visual affordances directly through Multimodal Large Language Models (MLLMs), and output normalized coordinates (x, y) mapped to OS mouse and keyboard events.
  • Open-Source Frontier vs. Proprietary APIs: ByteDance's open-source UI-TARS 1.5 introduced native System-2 reinforcement learning for step-by-step reflection and backtracking, while Anthropic's Claude 3.7 Sonnet provides high-level reasoning and native computer use tool calling.
  • The OSWorld 2.0 Reality Check: On the OSWorld 2.0 benchmark spanning 369 complex real-world tasks across Ubuntu, Windows, and macOS, agents achieve 42%โ€“52% success on 100-step long-horizon tasks, revealing that long-term state drift remains the primary engineering hurdle.
  • Mandatory Sandboxing: Direct OS control requires zero-trust isolation. Production architectures execute GUI agents inside disposable MicroVMs (e.g., E2B) or virtual display streams (VNC/RDP) backed by host-side action firewalls and human-in-the-loop kill switches.
+โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€+
|               Autonomous Desktop GUI Agent Architecture (2026)              |
|                                                                             |
|  [ User Goal: "Consolidate Q3 SAP exports into Excel macro, generate PDF" ] |
|                                     โ”‚                                       |
|                                     โ–ผ                                       |
|  โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”  |
|  โ”‚ HOST SUPERVISOR & ACTION FIREWALL (Safety Interceptor)                โ”‚  |
|  โ”‚  - Rate Limiting & Egress Filtering    - Destructive Command Blocker  โ”‚  |
|  โ”‚  - Biometric Confirmation Gateway      - Emergency Human Kill-Switch  โ”‚  |
|  โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜  |
|                                     โ”‚ Virtual Display / Peripherals         |
|                                     โ–ผ                                       |
|  โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”  |
|  โ”‚ ISOLATED DESKTOP SANDBOX (E2B / Cloud VNC / KVM Virtual Machine)      โ”‚  |
|  โ”‚                                                                       โ”‚  |
|  โ”‚   โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”               โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”   โ”‚  |
|  โ”‚   โ”‚ Screenshot Buffer   โ”‚               โ”‚ OS Input Controller     โ”‚   โ”‚  |
|  โ”‚   โ”‚ (1920x1080 RGB)     โ”‚               โ”‚ (PyAutoGUI / uinput)    โ”‚   โ”‚  |
|  โ”‚   โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜               โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ–ฒโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜   โ”‚  |
|  โ”‚              โ”‚ Raw Frame                              โ”‚ (x, y) Click  โ”‚  |
|  โ”‚              โ–ผ                                        โ”‚ & Hotkeys     โ”‚  |
|  โ”‚   โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ดโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”   โ”‚  |
|  โ”‚   โ”‚ AGENT RUNTIME: UI-TARS 1.5 / Claude 3.7 Sonnet                โ”‚   โ”‚  |
|  โ”‚   โ”‚  1. Visual Grounding: Detect target UI elements via pixels    โ”‚   โ”‚  |
|  โ”‚   โ”‚  2. System-2 Deliberation: Check milestones & reflect         โ”‚   โ”‚  |
|  โ”‚   โ”‚  3. Action Plan: Emit precise mouse, click, and key sequences โ”‚   โ”‚  |
|  โ”‚   โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜   โ”‚  |
|  โ”‚                                                                       โ”‚  |
|  โ”‚   [ Legacy SAP Client ]       [ Native Excel ]       [ Desktop CAD ]  โ”‚  |
|  โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜  |
+โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€+

02. The Death of DOM-Dependency: Why Desktop Enterprise Workflows Matter

Browser automation frameworks assume that applications expose structured accessibility trees, clean CSS selectors, and predictable element hierarchies. In high-value corporate operations, this assumption breaks down completely:

1. Canvas-Rendered Web Apps

Modern tools like Figma, Google Docs canvas rendering, and complex WebGL dashboards draw elements into blank canvas contexts without DOM nodes.

2. Legacy Enterprise Clients

Mission-critical systemsโ€”SAP GUI, AS400 terminal emulators, Bloomberg Terminals, and healthcare EHRsโ€”run as native binaries with zero web interfaces.

3. Cross-Application Chaining

Workflows require downloading raw data, executing local Excel VBA macros, updating CRM desktop windows, and signing PDFs across operating system boundaries.

03. The Three Perception Architectures: Pixel vs. Accessibility Tree vs. Hybrid

How should an autonomous agent perceive what is on the desktop screen? Three architectural approaches dominate in 2026:

+โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€+
|                     Desktop Perception Paradigms                            |
|                                                                             |
|  [ Approach 1: Pure Visual Grounding (Pixel-to-Coordinate) ]               |
|    Screen Frame โ”€โ”€โ–ถ High-Res VLM โ”€โ”€โ–ถ Coordinates (x: 450, y: 720)           |
|    โ€ข Pros: Universal, zero OS dependency, handles Canvas / Games / Legacy    |
|    โ€ข Cons: Heavy token cost, coordinate distortion, resolution scaling drift|
|                                                                             |
|  [ Approach 2: OS Accessibility Tree Grounding (UIAutomation / AT-SPI) ]    |
|    Screen State โ”€โ”€โ–ถ OS API Walk โ”€โ”€โ–ถ Filtered Hierarchy โ”€โ”€โ–ถ Element ID / Path|
|    โ€ข Pros: Deterministic, lightweight text tokens, 100% click precision     |
|    โ€ข Cons: 40% of native apps have broken/missing a11y trees, slow tree walk|
|                                                                             |
|  [ Approach 3: Dual-Stream Hybrid Fusion (2026 Best Practice) ]             |
|    Visual Screenshot (VLM) โ—„โ”€โ”€Fused Decisionโ”€โ”€โ–บ OS A11y Tree (Cache)        |
|    โ€ข Fast path: Use A11y node bounding box if recognized                    |
|    โ€ข Fallback: Use visual grounding when a11y nodes are obscured/custom     |
+โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€+
Dimension Pure Visual Grounding OS Accessibility Tree Dual-Stream Hybrid Fusion
Universality 100% (Any pixel rendered on screen) ~60% (Fails on custom UI/canvas) 98% (Falls back gracefully)
Token Efficiency Low (~1,200 to 2,000 tokens/frame) High (~300 to 600 tokens/tree) Medium (~1,500 tokens/decision)
Click Accuracy 88% - 94% (Subject to drift) 99% (When nodes exist) 98.5% (Snaps to bounding box)
OS Independence Complete (VNC/Streaming compatible) Low (Requires platform API hooks) High (Modular OS adapters)
Turn Latency 1.8s - 3.5s (VLM inference) 0.4s - 0.9s (Text LLM) 1.9s - 3.2s

04. UI-TARS: Native Vision-Language-Action & System-2 Reasoning

Developed by ByteDance and open-sourced in 2025โ€“2026, UI-TARS pioneered native **Vision-Language-Action (VLA)** modeling for graphical interfaces. Rather than hacking prompts onto general vision models, UI-TARS uses direct tokenization of motor actions and reinforcement learning for deliberate reflection:

+โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€+
|                UI-TARS 1.5 System-2 Reasoning Trajectory                     |
|                                                                             |
|  Observation โ”€โ”€โ–ถ [ Reflection & Verification ]                              |
|                   โ”‚ "Did the previous action open the File dialog?"          |
|                   โ”‚ State: YES. Detected 'Open File' window at (x: 200, y: 150)
|                   โ–ผ                                                         |
|                 [ Sub-goal Decomposition ]                                  |
|                   โ”‚ "Next sub-goal: Select 'Quarterly_Report.xlsx'"         |
|                   โ”‚ Search Strategy: Visual scan of table rows              |
|                   โ–ผ                                                         |
|                 [ Milestone Recognition ]                                   |
|                   โ”‚ Target element found at (x: 320, y: 410)                |
|                   โ–ผ                                                         |
|                 [ Action Emission ]                                         |
|                   โ”‚ Action: click(point=[320, 410])                         |
|                   โ”‚ Post-Action Expectation: File selected in input box     |
+โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€+
  • Standardized Motor Tokens: Directly emits tokens for click(point=[x, y]), double_click(), drag(start, end), and press_hotkey() on a normalized 1000 × 1000 coordinate plane.
  • System-2 Deliberation: Evaluates previous state transitions before acting. If clicking a button failed to open a dialog, the model reflects, self-corrects, and retries rather than compounding errors.
  • Local Deployment Capability: UI-TARS 7B runs locally on developer workstations (Apple Silicon 32GB or RTX 4090), providing sub-second turn latency with complete enterprise data privacy.

05. Claude 3.7 Computer Use vs. Open-Weights: Latency, Cost, and Accuracy Tradeoffs

Engineering teams must choose between proprietary frontier APIs (Claude 3.7 Sonnet) and self-hosted open-weights models (UI-TARS 7B/72B):

  • The Vision Token Cost Curve: Streaming 1080p screenshots to a proprietary frontier model every 2 seconds costs to for a 100-step enterprise reconciliation task.
  • Strategic Reasoning vs. Repetitive RPA: Claude 3.7 Sonnet excels at high-ambiguity tasks requiring semantic understanding of unstructured documents and spreadsheets. UI-TARS excels at high-throughput operational execution at a fraction of compute cost.
  • Data Governance: Financial and healthcare organizations handling confidential client records mandate that screen pixels never leave the private enterprise perimeter, making self-hosted UI-TARS the architectural standard.

06. Production Implementation: Building a Safe Desktop GUI Agent in Python

Below is a complete, runnable reference implementation in Python demonstrating normalized coordinate scaling, safety gatekeeping, destructive command interception, and human-in-the-loop confirmation:

# Production Reference Implementation: Desktop GUI Agent Controller (2026)
# Demonstrates Vision-Language-Action Execution, Coordinate Normalization,
# Destructive Command Interception, and Human-in-the-Loop Safeguards.

import time
import math
from typing import Dict, Any, List, Tuple, Optional
from dataclasses import dataclass, field
from enum import Enum


# โ”€โ”€โ”€ 1. CORE DATA STRUCTURES & ACTIONS โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€

class ActionType(str, Enum):
    MOUSE_CLICK = "mouse_click"
    DOUBLE_CLICK = "double_click"
    HOTKEY = "hotkey"
    TYPE_TEXT = "type_text"
    TERMINAL_COMMAND = "terminal_command"
    WAIT = "wait"


@dataclass
class UIAction:
    action_type: ActionType
    coordinates: Optional[Tuple[int, int]] = None  # (x, y) on 1000x1000 normalized grid
    text_payload: Optional[str] = None
    hotkey_sequence: Optional[List[str]] = None
    thought_reasoning: str = ""
    is_destructive: bool = False


@dataclass
class ScreenDimensions:
    width: int
    height: int


# โ”€โ”€โ”€ 2. SAFETY INTERCEPTOR & GATEKEEPER โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€

class DesktopSafetyGatekeeper:
    """
    Host-side safety authority that validates actions before dispatching
    to real or virtual OS input peripherals.
    """
    DESTRUCTIVE_HOTKEYS = {("ctrl", "alt", "del"), ("cmd", "shift", "backspace")}
    DESTRUCTIVE_COMMANDS = ["rm -rf", "format", "drop database", "mkfs", "dd if="]

    def __init__(self, require_human_for_destructive: bool = True):
        self.require_human = require_human_for_destructive
        self.audit_log: List[Dict[str, Any]] = []

    def inspect_action(self, action: UIAction, human_approved: bool = False) -> Tuple[bool, str]:
        # 1. Inspect terminal/shell commands
        if action.action_type == ActionType.TERMINAL_COMMAND and action.text_payload:
            for pattern in self.DESTRUCTIVE_COMMANDS:
                if pattern in action.text_payload.lower():
                    action.is_destructive = True
                    if not human_approved:
                        return False, f"Blocked destructive terminal command pattern: '{pattern}'"

        # 2. Inspect high-risk hotkeys
        if action.action_type == ActionType.HOTKEY and action.hotkey_sequence:
            normalized_keys = tuple(sorted([k.lower() for k in action.hotkey_sequence]))
            for risk_keys in self.DESTRUCTIVE_HOTKEYS:
                if normalized_keys == tuple(sorted(risk_keys)):
                    action.is_destructive = True
                    if not human_approved:
                        return False, f"Blocked dangerous system hotkey: '{action.hotkey_sequence}'"

        # Log action to immutable audit trail
        self.audit_log.append({
            "timestamp": time.time(),
            "action": action.action_type.value,
            "coordinates": action.coordinates,
            "destructive": action.is_destructive,
            "approved": True
        })
        return True, "Action approved."


# โ”€โ”€โ”€ 3. PERIPHERAL ADAPTER & COORDINATE SCALER โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€

class OSPeripheralController:
    """
    Translates normalized model coordinates (1000x1000) to actual physical display pixels
    and dispatches low-level OS input events.
    """
    def __init__(self, display: ScreenDimensions):
        self.display = display

    def denormalize_coordinates(self, norm_x: int, norm_y: int) -> Tuple[int, int]:
        """Converts [0, 1000] model grid to [0, width] x [0, height]."""
        real_x = math.floor((norm_x / 1000.0) * self.display.width)
        real_y = math.floor((norm_y / 1000.0) * self.display.height)
        return real_x, real_y

    def execute_native_input(self, action: UIAction):
        if action.coordinates:
            rx, ry = self.denormalize_coordinates(*action.coordinates)
            print(f"๐Ÿ–ฑ๏ธ  [OS DRIVER] Moving cursor to ({rx}px, {ry}px) [Model: {action.coordinates}]")
        
        if action.action_type == ActionType.MOUSE_CLICK:
            print(f"โšก [OS DRIVER] Emitting LEFT_BUTTON_CLICK at ({rx}, {ry})")
        elif action.action_type == ActionType.DOUBLE_CLICK:
            print(f"โšก [OS DRIVER] Emitting DOUBLE_CLICK at ({rx}, {ry})")
        elif action.action_type == ActionType.HOTKEY:
            print(f"โŒจ๏ธ  [OS DRIVER] Emitting KEY_COMBINATION: {' + '.join(action.hotkey_sequence or [])}")
        elif action.action_type == ActionType.TYPE_TEXT:
            print(f"โŒจ๏ธ  [OS DRIVER] Typing string payload: \"{action.text_payload}\"")
        elif action.action_type == ActionType.TERMINAL_COMMAND:
            print(f"๐Ÿ–ฅ๏ธ  [OS DRIVER] Executing Shell Command: '{action.text_payload}'")


# โ”€โ”€โ”€ 4. AUTONOMOUS DESKTOP AGENT CONTROLLER โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€

class DesktopGUIAgent:
    """
    The orchestrator agent combining VLA decision logic, safety inspection,
    and OS input driver dispatch.
    """
    def __init__(self, display: ScreenDimensions, gatekeeper: DesktopSafetyGatekeeper):
        self.driver = OSPeripheralController(display)
        self.gatekeeper = gatekeeper

    def step(self, action: UIAction, human_confirmed: bool = False) -> Dict[str, Any]:
        print(f"\n๐Ÿง  [SYSTEM-2 REFLECTION] {action.thought_reasoning}")

        # Safety Check
        is_safe, reason = self.gatekeeper.inspect_action(action, human_approved=human_confirmed)
        if not is_safe:
            print(f"๐Ÿ›‘ [SAFETY INTERCEPT] Action Rejected: {reason}")
            return {"success": False, "reason": reason}

        # Dispatch
        self.driver.execute_native_input(action)
        return {"success": True, "reason": "Executed successfully"}


# โ”€โ”€โ”€ 5. RUNTIME VERIFICATION HARNESS โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€

if __name__ == "__main__":
    print("=" * 75)
    print("DEMO: AUTONOMOUS DESKTOP GUI AGENT SAFETY & GROUNDING CONTROLLER (2026)")
    print("=" * 75)

    # Initialize 1080p display and safety gatekeeper
    virtual_screen = ScreenDimensions(width=1920, height=1080)
    safety_shield = DesktopSafetyGatekeeper(require_human_for_destructive=True)
    agent = DesktopGUIAgent(display=virtual_screen, gatekeeper=safety_shield)

    # STEP 1: Safe Action - Navigate SAP Menu
    step1 = UIAction(
        action_type=ActionType.MOUSE_CLICK,
        coordinates=(180, 45),  # 1000x1000 normalized grid
        thought_reasoning="Milestone 1: Click 'Accounting' dropdown in SAP native menu bar."
    )
    agent.step(step1)

    # STEP 2: Safe Action - Type Transaction Code
    step2 = UIAction(
        action_type=ActionType.TYPE_TEXT,
        text_payload="FS10N",
        thought_reasoning="Milestone 2: Enter general ledger balance inquiry transaction code."
    )
    agent.step(step2)

    # STEP 3: Malicious / Accidental Destructive Step Intercepted
    step3_destructive = UIAction(
        action_type=ActionType.TERMINAL_COMMAND,
        text_payload="rm -rf /var/sap/data/*",
        thought_reasoning="Adversarial prompt injection attempt detected on unverified clipboard buffer."
    )
    print("\n[SCENARIO 1: Destructive Action Without Approval]")
    agent.step(step3_destructive, human_confirmed=False)

    # STEP 4: High-Risk Action With Human Biometric Approval
    print("\n[SCENARIO 2: Authorized High-Risk Action via Supervisor Approval]")
    agent.step(step3_destructive, human_confirmed=True)

    print("\n" + "=" * 75)
    print(f"Demonstration Complete. Total Audit Ledger Entries: {len(safety_shield.audit_log)}")
    print("=" * 75)

07. OSWorld 2.0 Benchmark Analysis: Solving Long-Horizon Drift & Failure Modes

The OSWorld 2.0 benchmark evaluates agents across 369 realistic tasks in Ubuntu, Windows, and macOS. While human baseline performance sits at 88.3%, state-of-the-art agents achieve between 49% and 52% overall, revealing four systemic failure modes:

  • Resolution & Coordinate Drift: Modal popups or window resizes shift visual targets by small pixel offsets, leading to misclicks on outdated coordinates.
  • Context Window Fatigue: Retaining 60 full-resolution screenshots overflows model context. Production systems prune older screenshots into compact textual action histories.
  • Silent Loading & Spinner Traps: Lacking browser DOM events like networkidle, agents repeatedly click during application loading, triggering thread crashes. Visual delta variance checks solve this.
  • Low-Contrast UI Confusion: In dark-mode enterprise software or CAD wireframes, models frequently confuse visually similar tool icons (e.g., Save vs. Export).

08. Security & Sandboxing: VNC Isolation, eBPF Egress, and Kill-Switch Safeguards

Granting an autonomous agent direct control over physical peripherals on an employee's laptop creates severe security vulnerabilities. Production architectures enforce a three-layer zero-trust sandbox:

+โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€+
|               Zero-Trust Desktop Sandbox Containment Stack                  |
|                                                                             |
|  [ Enterprise Gateway ]                                                     |
|            โ”‚                                                                |
|            โ–ผ                                                                |
|  โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”  |
|  โ”‚ LAYER 1: VIRTUAL DISPLAY & PERIPHERAL ISOLATION                       โ”‚  |
|  โ”‚ - Headless X11 / Wayland / RDP virtual server                         โ”‚  |
|  โ”‚ - The agent NEVER touches physical user hardware                      โ”‚  |
|  โ”‚ - Video frame streamed via WebRTC / VNC buffer                        โ”‚  |
|  โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜  |
|                                     โ”‚                                       |
|                                     โ–ผ                                       |
|  โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”  |
|  โ”‚ LAYER 2: SYSTEM CALL INTERCEPTION & eBPF NETWORK EGRESS               โ”‚  |
|  โ”‚ - eBPF sensor intercepts dangerous POSIX syscalls (fork, execve, ptrace)โ”‚
|  โ”‚ - Network firewall restricts outbound traffic exclusively to whitelistโ”‚  |
|  โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜  |
|                                     โ”‚                                       |
|                                     โ–ผ                                       |
|  โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”  |
|  โ”‚ LAYER 3: SUPERVISOR KILL-SWITCH & USER TAKEOVER                       โ”‚  |
|  โ”‚ - User moves physical mouse โ”€โ”€โ–ถ Instant agent suspension (Kill-Switch)โ”‚  |
|  โ”‚ - Live action stream mirrored to supervisor dashboard                โ”‚  |
|  โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜  |
+โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€+
  • Layer 1: Virtual Display Containment: The agent interacts solely with a virtual X11/Wayland/RDP buffer inside an isolated MicroVM (e.g., E2B). Physical hardware is never exposed.
  • Layer 2: eBPF Network & Syscall Filtering: Kernel-level eBPF sensors intercept destructive shell commands (rm -rf, formatting, unauthorized exfiltration) and block non-whitelisted outbound IP connections.
  • Layer 3: Physical Motion Kill-Switch: On assisted human workstations, touching the physical mouse or pressing Esc instantly revokes the agent's input driver privileges, returning immediate control to the user.

09. Architectural Comparison Matrix & Related Tools

How do the premier desktop and computer-use agent frameworks compare in 2026?

Dimension UI-TARS (ByteDance) Claude 3.7 Computer Use OpenHands E2B Desktop Sandbox
Model Nature Open-Weights (VLA 7B/72B) Frontier Proprietary API Model-Agnostic Orchestrator Infrastructure Sandbox Runtime
Primary Perception Raw Pixels (System-2 VLA) Raw Pixels (Vision API) Hybrid (DOM + Terminal + GUI) Virtual Display Frame Buffer
Hosting Mode Self-Hosted (On-Premises GPU) Cloud API (Anthropic) Self-Hosted / Cloud Managed Cloud / MicroVM
OS Support Windows, macOS, Linux, Android Windows, macOS, Ubuntu Linux, Docker, Browser Linux (Firecracker MicroVM)
Target Use Case High-Frequency RPA, QA, Batch Complex Knowledge Tasks Software Engineering Agents Secure Agent Execution Sandboxing
Open Source 100% Open Source Proprietary 100% Open Source Open-Source SDK / Managed Cloud

E2B

MicroVM Sandbox

The premier MicroVM cloud sandbox runtime for executing untrusted desktop sessions, terminal commands, and headless environments with hardware-level isolation.

Explore E2B โ†’

Claude 3.7 Sonnet

Frontier Model

Anthropic's flagship reasoning model featuring native Computer Use capabilities for desktop navigation, browser automation, and multi-step tool execution.

Explore Claude 3.7 Sonnet โ†’

OpenHands

Open Source

The leading open-source autonomous agent platform for software development, terminal operations, and desktop navigation, designed for full local deployment.

Explore OpenHands โ†’

Devin

Autonomous Software

Cognition's flagship autonomous software engineering assistant equipped with integrated browser, terminal, and desktop workspace automation.

Explore Devin โ†’

10. Frequently Asked Questions (FAQ)

Q1: Why not just build custom APIs instead of building desktop GUI agents?

In an ideal world, every application would expose rich, authenticated REST or GraphQL APIs. In practice, enterprise software ecosystems contain thousands of legacy applications (SAP, mainframe terminal emulators, desktop accounting tools) where adding APIs requires millions of dollars and years of refactoring. Desktop GUI agents enable zero-touch integration: automating legacy systems immediately without touching source code or altering underlying databases.

Q2: What screen resolution should I feed into a visual desktop agent?

Feeding raw 4K screenshots causes severe token bloat and latency degradation. Production systems typically capture the desktop at 1920x1080, normalize coordinates to an internal 1000x1000 grid for model inference, and project predicted coordinates back to physical screen pixels using mathematical scaling factors.

Q3: How do desktop agents handle dynamic UI loading and animations?

Unlike web browsers that fire DOM events like DOMContentLoaded or networkidle, desktop environments provide no native notification that an application has finished loading. Production agents utilize visual delta polling: capturing frames at 250ms intervals and verifying that pixel delta variance drops below 1% before concluding that the screen state is stable enough for the next action.

Q4: Can desktop agents operate on dual-monitor or multi-window setups?

Yes. Coordinate mapping engines can either treat multi-monitor setups as a single stitched canvas (e.g., 3840x1080) or utilize window-focus APIs to bring the active target application to the primary virtual display before running the perception step.

Q5: Is UI-TARS capable of running locally on consumer hardware?

The UI-TARS 7B model can run locally on modern workstation hardware (e.g., Apple Silicon Macs with 32GB+ Unified Memory or single NVIDIA RTX 4090 GPUs) using quantized GGUF or AWQ formats. The 72B model requires dual or quad A100/H100 enterprise GPUs for sub-second inference latency.

Agentes de Escritorio y SO VLA Multimodal Septiembre de 2026 ยท 18 min de lectura

Mรกs Allรก del Navegador: Construcciรณn de Agentes GUI de Escritorio en 2026 con UI-TARS, Claude Computer Use y OSWorld 2.0

Durante los รบltimos tres aรฑos, el ecosistema de IA se centrรณ intensamente en la automatizaciรณn del navegador web mediante herramientas como Browser-Use, Stagehand y Playwright MCP para procesar รกrboles HTML DOM. Sin embargo, mรกs del 70% de los flujos de trabajo de software empresarial no se ejecutan dentro del DOM de un navegador. Los ERP heredados (SAP GUI), los libros de Excel nativos con macros VBA incrustadas, las suites de CAD de escritorio, las consolas de terminal y los clientes nativos carecen de DOM web. Cuando los sistemas operativos renderizan directamente a travรฉs de DirectX, Metal, Win32 o Qt, los agentes basados en DOM quedan ciegos e inoperantes. Para desbloquear la verdadera automatizaciรณn empresarial, 2026 marca el auge de los Agentes GUI de Escritorio Autรณnomos impulsados por modelos fundacionales nativos de Visiรณn-Lenguaje-Acciรณn (VLA), anclaje por coordenadas de pรญxeles y razonamiento deliberado Sistema 2. Este anรกlisis tรฉcnico en profundidad deconstruye UI-TARS 1.5, Claude 3.7 Computer Use, el benchmark OSWorld 2.0 y la contenciรณn en sandboxes de producciรณn.

01. Resumen Rรกpido y la Frontera de GUI de Escritorio

La automatizaciรณn web ha alcanzado su madurez, pero el trabajo de conocimiento en el escritorio seguรญa indomado. En 2026, los agentes GUI de escritorio tratan toda la pantalla del sistema operativo como su lienzo interactivo:

  • Mรกs Allรก de Selectores HTML: Los agentes de escritorio observan fotogramas sin procesar (de 1080p a 4K), reconocen elementos visuales mediante Modelos de Lenguaje Multimodales (MLLM) y emiten coordenadas normalizadas (x, y) mapeadas a eventos nativos de ratรณn y teclado.
  • Frontera de Cรณdigo Abierto vs APIs Propietarias: UI-TARS 1.5 de ByteDance introdujo aprendizaje por refuerzo Sistema 2 para reflexiรณn y retroceso algorรญtmico, mientras que Claude 3.7 Sonnet de Anthropic ofrece razonamiento de alto nivel y llamadas a herramientas nativas de Computer Use.
  • La Realidad de OSWorld 2.0: En el benchmark OSWorld 2.0 que abarca 369 tareas del mundo real en Ubuntu, Windows y macOS, los agentes logran entre un 42% y un 52% de รฉxito en flujos de 100 pasos, demostrando que el desvรญo de estado a largo plazo es el principal desafรญo de ingenierรญa.
  • Sandboxing Obligatorio: El control directo del SO exige aislamiento de confianza cero. Las arquitecturas de producciรณn ejecutan agentes dentro de MicroVMs desechables (como E2B) o flujos de pantalla virtual (VNC/RDP) respaldados por cortafuegos de acciones e interruptores de parada humana (Kill Switch).
+โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€+
|               Autonomous Desktop GUI Agent Architecture (2026)              |
|                                                                             |
|  [ User Goal: "Consolidate Q3 SAP exports into Excel macro, generate PDF" ] |
|                                     โ”‚                                       |
|                                     โ–ผ                                       |
|  โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”  |
|  โ”‚ HOST SUPERVISOR & ACTION FIREWALL (Safety Interceptor)                โ”‚  |
|  โ”‚  - Rate Limiting & Egress Filtering    - Destructive Command Blocker  โ”‚  |
|  โ”‚  - Biometric Confirmation Gateway      - Emergency Human Kill-Switch  โ”‚  |
|  โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜  |
|                                     โ”‚ Virtual Display / Peripherals         |
|                                     โ–ผ                                       |
|  โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”  |
|  โ”‚ ISOLATED DESKTOP SANDBOX (E2B / Cloud VNC / KVM Virtual Machine)      โ”‚  |
|  โ”‚                                                                       โ”‚  |
|  โ”‚   โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”               โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”   โ”‚  |
|  โ”‚   โ”‚ Screenshot Buffer   โ”‚               โ”‚ OS Input Controller     โ”‚   โ”‚  |
|  โ”‚   โ”‚ (1920x1080 RGB)     โ”‚               โ”‚ (PyAutoGUI / uinput)    โ”‚   โ”‚  |
|  โ”‚   โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜               โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ–ฒโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜   โ”‚  |
|  โ”‚              โ”‚ Raw Frame                              โ”‚ (x, y) Click  โ”‚  |
|  โ”‚              โ–ผ                                        โ”‚ & Hotkeys     โ”‚  |
|  โ”‚   โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ดโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”   โ”‚  |
|  โ”‚   โ”‚ AGENT RUNTIME: UI-TARS 1.5 / Claude 3.7 Sonnet                โ”‚   โ”‚  |
|  โ”‚   โ”‚  1. Visual Grounding: Detect target UI elements via pixels    โ”‚   โ”‚  |
|  โ”‚   โ”‚  2. System-2 Deliberation: Check milestones & reflect         โ”‚   โ”‚  |
|  โ”‚   โ”‚  3. Action Plan: Emit precise mouse, click, and key sequences โ”‚   โ”‚  |
|  โ”‚   โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜   โ”‚  |
|  โ”‚                                                                       โ”‚  |
|  โ”‚   [ Legacy SAP Client ]       [ Native Excel ]       [ Desktop CAD ]  โ”‚  |
|  โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜  |
+โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€+

02. El Fin de la Dependencia del DOM: Por Quรฉ Importan los Flujos Empresariales de Escritorio

Los marcos de automatizaciรณn web asumen que las aplicaciones exponen รกrboles de accesibilidad estructurados, selectores CSS limpios y jerarquรญas predecibles. En las operaciones corporativas de alto impacto, esta suposiciรณn falla por completo:

1. Aplicaciones Web en Canvas

Herramientas modernas como Figma, Google Docs con renderizado de canvas y paneles WebGL dibujan elementos directamente en lienzos sin nodos DOM accesibles.

2. Clientes Empresariales Heredados

Sistemas crรญticos (SAP GUI, emuladores AS400, terminales Bloomberg y registros mรฉdicos EHR) funcionan como binarios nativos sin interfaces web.

3. Encadenamiento Multi-Aplicaciรณn

Los flujos de trabajo requieren descargar datos, ejecutar macros VBA locales en Excel, actualizar ventanas de CRM y firmar PDFs cruzando fronteras de procesos.

03. Las Tres Arquitecturas de Percepciรณn: Pรญxeles vs รrbol de Accesibilidad vs Hรญbrido

ยฟCรณmo debe percibir un agente autรณnomo lo que hay en la pantalla del escritorio? En 2026 conviven tres enfoques arquitectรณnicos:

+โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€+
|                     Desktop Perception Paradigms                            |
|                                                                             |
|  [ Approach 1: Pure Visual Grounding (Pixel-to-Coordinate) ]               |
|    Screen Frame โ”€โ”€โ–ถ High-Res VLM โ”€โ”€โ–ถ Coordinates (x: 450, y: 720)           |
|    โ€ข Pros: Universal, zero OS dependency, handles Canvas / Games / Legacy    |
|    โ€ข Cons: Heavy token cost, coordinate distortion, resolution scaling drift|
|                                                                             |
|  [ Approach 2: OS Accessibility Tree Grounding (UIAutomation / AT-SPI) ]    |
|    Screen State โ”€โ”€โ–ถ OS API Walk โ”€โ”€โ–ถ Filtered Hierarchy โ”€โ”€โ–ถ Element ID / Path|
|    โ€ข Pros: Deterministic, lightweight text tokens, 100% click precision     |
|    โ€ข Cons: 40% of native apps have broken/missing a11y trees, slow tree walk|
|                                                                             |
|  [ Approach 3: Dual-Stream Hybrid Fusion (2026 Best Practice) ]             |
|    Visual Screenshot (VLM) โ—„โ”€โ”€Fused Decisionโ”€โ”€โ–บ OS A11y Tree (Cache)        |
|    โ€ข Fast path: Use A11y node bounding box if recognized                    |
|    โ€ข Fallback: Use visual grounding when a11y nodes are obscured/custom     |
+โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€+
Dimensiรณn Anclaje Visual Puro รrbol de Accesibilidad del SO Fusiรณn Hรญbrida de Doble Flujo
Universalidad 100% (Cualquier pรญxel visible) ~60% (Falla en UI personalizada/canvas) 98% (Recuperaciรณn elegante)
Eficiencia de Tokens Baja (~1,200 a 2,000 tokens/frame) Alta (~300 a 600 tokens/รกrbol) Media (~1,500 tokens/decisiรณn)
Precisiรณn de Clic 88% - 94% (Sujeto a desvรญo) 99% (Cuando existen nodos) 98.5% (Ajuste a caja delimitadora)
Independencia del SO Total (Compatible con VNC/Streaming) Baja (Requiere hooks de API del SO) Alta (Adaptadores modulares)
Latencia por Turno 1.8s - 3.5s (Inferencia VLM) 0.4s - 0.9s (LLM de texto) 1.9s - 3.2s

04. UI-TARS: VLA Nativo y Razonamiento Sistema 2

Desarrollado por ByteDance y liberado como cรณdigo abierto, UI-TARS fue pionero en el modelado nativo de **Visiรณn-Lenguaje-Acciรณn (VLA)** para interfaces grรกficas. En lugar de adaptar modelos de visiรณn genรฉricos con ingenierรญa de prompts, utiliza tokenizaciรณn directa de acciones motoras y aprendizaje por refuerzo con reflexiรณn deliberada:

+โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€+
|                UI-TARS 1.5 System-2 Reasoning Trajectory                     |
|                                                                             |
|  Observation โ”€โ”€โ–ถ [ Reflection & Verification ]                              |
|                   โ”‚ "Did the previous action open the File dialog?"          |
|                   โ”‚ State: YES. Detected 'Open File' window at (x: 200, y: 150)
|                   โ–ผ                                                         |
|                 [ Sub-goal Decomposition ]                                  |
|                   โ”‚ "Next sub-goal: Select 'Quarterly_Report.xlsx'"         |
|                   โ”‚ Search Strategy: Visual scan of table rows              |
|                   โ–ผ                                                         |
|                 [ Milestone Recognition ]                                   |
|                   โ”‚ Target element found at (x: 320, y: 410)                |
|                   โ–ผ                                                         |
|                 [ Action Emission ]                                         |
|                   โ”‚ Action: click(point=[320, 410])                         |
|                   โ”‚ Post-Action Expectation: File selected in input box     |
+โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€+
  • Tokens Motores Estandarizados: Emite directamente tokens para click(point=[x, y]), double_click(), drag(start, end) y press_hotkey() en un plano normalizado de 1000 × 1000.
  • Deliberaciรณn Sistema 2: Evalรบa las transiciones de estado anteriores antes de actuar. Si hacer clic en un botรณn no abriรณ el diรกlogo esperado, el modelo reflexiona, se autocorrige y reintenta en lugar de acumular fallos.
  • Capacidad de Despliegue Local: UI-TARS 7B se ejecuta localmente en estaciones de trabajo de desarrolladores (Apple Silicon con 32GB o RTX 4090), brindando latencias inferiores a un segundo con privacidad de datos garantizada.

05. Claude 3.7 Computer Use vs Modelos de Cรณdigo Abierto: Compensaciones de Latencia, Coste y Precisiรณn

Los equipos de ingenierรญa deben elegir entre APIs comerciales de frontera (Claude 3.7 Sonnet) y modelos autohospedados de pesos abiertos (UI-TARS 7B/72B):

  • La Curva de Coste de Tokens de Visiรณn: Transmitir capturas 1080p a un modelo propietario cada 2 segundos cuesta entre y para una tarea de conciliaciรณn de 100 pasos.
  • Razonamiento Estratรฉgico vs RPA Repetitivo: Claude 3.7 Sonnet sobresale en tareas de alta ambigรผedad que requieren comprensiรณn semรกntica de documentos no estructurados. UI-TARS destaca en ejecuciรณn operativa de alto volumen con una fracciรณn del coste computacional.
  • Gobernanza de Datos: Entidades bancarias y sanitarias exigen que los pรญxeles de pantalla jamรกs salgan del perรญmetro privado de la empresa, consolidando a UI-TARS autohospedado como el estรกndar arquitectรณnico.

06. Implementaciรณn en Producciรณn: Construcciรณn de un Controlador Seguro de Escritorio en Python

A continuaciรณn se presenta una implementaciรณn de referencia completa y ejecutable en Python que demuestra el escalado de coordenadas, la supervisiรณn de seguridad, la interceptaciรณn de comandos destructivos y la confirmaciรณn humana:

# Production Reference Implementation: Desktop GUI Agent Controller (2026)
# Demonstrates Vision-Language-Action Execution, Coordinate Normalization,
# Destructive Command Interception, and Human-in-the-Loop Safeguards.

import time
import math
from typing import Dict, Any, List, Tuple, Optional
from dataclasses import dataclass, field
from enum import Enum


# โ”€โ”€โ”€ 1. CORE DATA STRUCTURES & ACTIONS โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€

class ActionType(str, Enum):
    MOUSE_CLICK = "mouse_click"
    DOUBLE_CLICK = "double_click"
    HOTKEY = "hotkey"
    TYPE_TEXT = "type_text"
    TERMINAL_COMMAND = "terminal_command"
    WAIT = "wait"


@dataclass
class UIAction:
    action_type: ActionType
    coordinates: Optional[Tuple[int, int]] = None  # (x, y) on 1000x1000 normalized grid
    text_payload: Optional[str] = None
    hotkey_sequence: Optional[List[str]] = None
    thought_reasoning: str = ""
    is_destructive: bool = False


@dataclass
class ScreenDimensions:
    width: int
    height: int


# โ”€โ”€โ”€ 2. SAFETY INTERCEPTOR & GATEKEEPER โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€

class DesktopSafetyGatekeeper:
    """
    Host-side safety authority that validates actions before dispatching
    to real or virtual OS input peripherals.
    """
    DESTRUCTIVE_HOTKEYS = {("ctrl", "alt", "del"), ("cmd", "shift", "backspace")}
    DESTRUCTIVE_COMMANDS = ["rm -rf", "format", "drop database", "mkfs", "dd if="]

    def __init__(self, require_human_for_destructive: bool = True):
        self.require_human = require_human_for_destructive
        self.audit_log: List[Dict[str, Any]] = []

    def inspect_action(self, action: UIAction, human_approved: bool = False) -> Tuple[bool, str]:
        # 1. Inspect terminal/shell commands
        if action.action_type == ActionType.TERMINAL_COMMAND and action.text_payload:
            for pattern in self.DESTRUCTIVE_COMMANDS:
                if pattern in action.text_payload.lower():
                    action.is_destructive = True
                    if not human_approved:
                        return False, f"Blocked destructive terminal command pattern: '{pattern}'"

        # 2. Inspect high-risk hotkeys
        if action.action_type == ActionType.HOTKEY and action.hotkey_sequence:
            normalized_keys = tuple(sorted([k.lower() for k in action.hotkey_sequence]))
            for risk_keys in self.DESTRUCTIVE_HOTKEYS:
                if normalized_keys == tuple(sorted(risk_keys)):
                    action.is_destructive = True
                    if not human_approved:
                        return False, f"Blocked dangerous system hotkey: '{action.hotkey_sequence}'"

        # Log action to immutable audit trail
        self.audit_log.append({
            "timestamp": time.time(),
            "action": action.action_type.value,
            "coordinates": action.coordinates,
            "destructive": action.is_destructive,
            "approved": True
        })
        return True, "Action approved."


# โ”€โ”€โ”€ 3. PERIPHERAL ADAPTER & COORDINATE SCALER โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€

class OSPeripheralController:
    """
    Translates normalized model coordinates (1000x1000) to actual physical display pixels
    and dispatches low-level OS input events.
    """
    def __init__(self, display: ScreenDimensions):
        self.display = display

    def denormalize_coordinates(self, norm_x: int, norm_y: int) -> Tuple[int, int]:
        """Converts [0, 1000] model grid to [0, width] x [0, height]."""
        real_x = math.floor((norm_x / 1000.0) * self.display.width)
        real_y = math.floor((norm_y / 1000.0) * self.display.height)
        return real_x, real_y

    def execute_native_input(self, action: UIAction):
        if action.coordinates:
            rx, ry = self.denormalize_coordinates(*action.coordinates)
            print(f"๐Ÿ–ฑ๏ธ  [OS DRIVER] Moving cursor to ({rx}px, {ry}px) [Model: {action.coordinates}]")
        
        if action.action_type == ActionType.MOUSE_CLICK:
            print(f"โšก [OS DRIVER] Emitting LEFT_BUTTON_CLICK at ({rx}, {ry})")
        elif action.action_type == ActionType.DOUBLE_CLICK:
            print(f"โšก [OS DRIVER] Emitting DOUBLE_CLICK at ({rx}, {ry})")
        elif action.action_type == ActionType.HOTKEY:
            print(f"โŒจ๏ธ  [OS DRIVER] Emitting KEY_COMBINATION: {' + '.join(action.hotkey_sequence or [])}")
        elif action.action_type == ActionType.TYPE_TEXT:
            print(f"โŒจ๏ธ  [OS DRIVER] Typing string payload: \"{action.text_payload}\"")
        elif action.action_type == ActionType.TERMINAL_COMMAND:
            print(f"๐Ÿ–ฅ๏ธ  [OS DRIVER] Executing Shell Command: '{action.text_payload}'")


# โ”€โ”€โ”€ 4. AUTONOMOUS DESKTOP AGENT CONTROLLER โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€

class DesktopGUIAgent:
    """
    The orchestrator agent combining VLA decision logic, safety inspection,
    and OS input driver dispatch.
    """
    def __init__(self, display: ScreenDimensions, gatekeeper: DesktopSafetyGatekeeper):
        self.driver = OSPeripheralController(display)
        self.gatekeeper = gatekeeper

    def step(self, action: UIAction, human_confirmed: bool = False) -> Dict[str, Any]:
        print(f"\n๐Ÿง  [SYSTEM-2 REFLECTION] {action.thought_reasoning}")

        # Safety Check
        is_safe, reason = self.gatekeeper.inspect_action(action, human_approved=human_confirmed)
        if not is_safe:
            print(f"๐Ÿ›‘ [SAFETY INTERCEPT] Action Rejected: {reason}")
            return {"success": False, "reason": reason}

        # Dispatch
        self.driver.execute_native_input(action)
        return {"success": True, "reason": "Executed successfully"}


# โ”€โ”€โ”€ 5. RUNTIME VERIFICATION HARNESS โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€

if __name__ == "__main__":
    print("=" * 75)
    print("DEMO: AUTONOMOUS DESKTOP GUI AGENT SAFETY & GROUNDING CONTROLLER (2026)")
    print("=" * 75)

    # Initialize 1080p display and safety gatekeeper
    virtual_screen = ScreenDimensions(width=1920, height=1080)
    safety_shield = DesktopSafetyGatekeeper(require_human_for_destructive=True)
    agent = DesktopGUIAgent(display=virtual_screen, gatekeeper=safety_shield)

    # STEP 1: Safe Action - Navigate SAP Menu
    step1 = UIAction(
        action_type=ActionType.MOUSE_CLICK,
        coordinates=(180, 45),  # 1000x1000 normalized grid
        thought_reasoning="Milestone 1: Click 'Accounting' dropdown in SAP native menu bar."
    )
    agent.step(step1)

    # STEP 2: Safe Action - Type Transaction Code
    step2 = UIAction(
        action_type=ActionType.TYPE_TEXT,
        text_payload="FS10N",
        thought_reasoning="Milestone 2: Enter general ledger balance inquiry transaction code."
    )
    agent.step(step2)

    # STEP 3: Malicious / Accidental Destructive Step Intercepted
    step3_destructive = UIAction(
        action_type=ActionType.TERMINAL_COMMAND,
        text_payload="rm -rf /var/sap/data/*",
        thought_reasoning="Adversarial prompt injection attempt detected on unverified clipboard buffer."
    )
    print("\n[SCENARIO 1: Destructive Action Without Approval]")
    agent.step(step3_destructive, human_confirmed=False)

    # STEP 4: High-Risk Action With Human Biometric Approval
    print("\n[SCENARIO 2: Authorized High-Risk Action via Supervisor Approval]")
    agent.step(step3_destructive, human_confirmed=True)

    print("\n" + "=" * 75)
    print(f"Demonstration Complete. Total Audit Ledger Entries: {len(safety_shield.audit_log)}")
    print("=" * 75)

07. Anรกlisis del Benchmark OSWorld 2.0: Resoluciรณn del Desvรญo a Largo Plazo y Modos de Fallo

El benchmark OSWorld 2.0 evalรบa agentes en 369 tareas realistas en Ubuntu, Windows y macOS. Mientras que la referencia humana alcanza el 88.3%, los modelos mรกs avanzados obtienen entre el 49% y el 52% global, revelando cuatro modos de fallo estructurales:

  • Desvรญo de Resoluciรณn y Coordenadas: Los cuadros de diรกlogo emergentes o cambios de tamaรฑo de ventana desplazan los objetivos visuales por unos pocos pรญxeles, causando clics errรณneos sobre coordenadas obsoletas.
  • Saturaciรณn de la Ventana de Contexto: Acumular 60 capturas a resoluciรณn completa satura la atenciรณn del modelo. Los sistemas de producciรณn podan las imรกgenes antiguas y las reemplazan por resรบmenes textuales de acciones.
  • Trampas de Carga Silenciosa: Al carecer de eventos DOM como networkidle, los agentes hacen clic reiterado durante la carga de aplicaciones, bloqueando subprocesos nativos. La verificaciรณn de varianza de pรญxeles soluciona esto.
  • Confusiรณn en Interfaces de Bajo Contraste: En modos oscuros corporativos o vistas de CAD, los modelos confunden con frecuencia iconos visualmente similares (ej. Guardar vs Exportar).

08. Seguridad y Sandbox: Aislamiento VNC, Filtrado eBPF e Interruptor de Parada (Kill-Switch)

Otorgar a un agente autรณnomo control directo sobre los perifรฉricos fรญsicos de un portรกtil corporativo genera graves riesgos de seguridad. Las arquitecturas de producciรณn aplican un sandbox de tres capas:

+โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€+
|               Zero-Trust Desktop Sandbox Containment Stack                  |
|                                                                             |
|  [ Enterprise Gateway ]                                                     |
|            โ”‚                                                                |
|            โ–ผ                                                                |
|  โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”  |
|  โ”‚ LAYER 1: VIRTUAL DISPLAY & PERIPHERAL ISOLATION                       โ”‚  |
|  โ”‚ - Headless X11 / Wayland / RDP virtual server                         โ”‚  |
|  โ”‚ - The agent NEVER touches physical user hardware                      โ”‚  |
|  โ”‚ - Video frame streamed via WebRTC / VNC buffer                        โ”‚  |
|  โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜  |
|                                     โ”‚                                       |
|                                     โ–ผ                                       |
|  โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”  |
|  โ”‚ LAYER 2: SYSTEM CALL INTERCEPTION & eBPF NETWORK EGRESS               โ”‚  |
|  โ”‚ - eBPF sensor intercepts dangerous POSIX syscalls (fork, execve, ptrace)โ”‚
|  โ”‚ - Network firewall restricts outbound traffic exclusively to whitelistโ”‚  |
|  โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜  |
|                                     โ”‚                                       |
|                                     โ–ผ                                       |
|  โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”  |
|  โ”‚ LAYER 3: SUPERVISOR KILL-SWITCH & USER TAKEOVER                       โ”‚  |
|  โ”‚ - User moves physical mouse โ”€โ”€โ–ถ Instant agent suspension (Kill-Switch)โ”‚  |
|  โ”‚ - Live action stream mirrored to supervisor dashboard                โ”‚  |
|  โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜  |
+โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€+
  • Capa 1: Contenciรณn en Pantalla Virtual: El agente interactรบa exclusivamente con un bรบfer virtual X11/Wayland/RDP dentro de una MicroVM aislada (ej. E2B). El hardware fรญsico jamรกs se expone.
  • Capa 2: Filtrado eBPF de Llamadas al Sistema y Red: Sensores a nivel de kernel interceptan comandos de shell destructivos (rm -rf, formateos, exfiltraciรณn no autorizada) y bloquean conexiones IP salientes no autorizadas.
  • Capa 3: Interruptor de Movimiento Fรญsico: En estaciones asistidas, mover el ratรณn fรญsico o pulsar Esc revoca de inmediato los permisos del controlador del agente, devolviendo el mando al operador humano.

09. Matriz Comparativa de Arquitectura y Herramientas Relacionadas

ยฟCรณmo se comparan los principales marcos de agentes de escritorio en 2026?

Dimensiรณn UI-TARS (ByteDance) Claude 3.7 Computer Use OpenHands E2B Desktop Sandbox
Naturaleza del Modelo Pesos Abiertos (VLA 7B/72B) API Propietaria de Frontera Orquestador Agnรณstico Entorno de Infraestructura Sandbox
Percepciรณn Principal Pรญxeles sin Procesar (VLA Sistema 2) Pรญxeles sin Procesar (API Visiรณn) Hรญbrida (DOM + Terminal + GUI) Bรบfer de Pantalla Virtual
Modalidad de Alojamiento Autohospedado (GPU On-Premises) API en la Nube (Anthropic) Autohospedado / Nube Nube Administrada / MicroVM
Sistemas Operativos Windows, macOS, Linux, Android Windows, macOS, Ubuntu Linux, Docker, Navegador Linux (Firecracker MicroVM)
Caso de Uso Objetivo RPA de Alta Frecuencia, QA, Lotes Tareas de Conocimiento Complejo Agentes de Ingenierรญa de Software Aislamiento Seguro de Ejecuciรณn
Cรณdigo Abierto 100% Cรณdigo Abierto Propietario 100% Cรณdigo Abierto SDK Abierto / Nube Gestionada

E2B

Sandbox MicroVM

El entorno en la nube de MicroVMs lรญder para ejecutar sesiones de escritorio no confiables, comandos de terminal y entornos sin cabeza con aislamiento de hardware.

Explorar E2B โ†’

Claude 3.7 Sonnet

Modelo de Frontera

El modelo insignia de Anthropic con capacidades nativas de Computer Use para navegaciรณn de escritorio, automatizaciรณn web y ejecuciรณn de herramientas en mรบltiples pasos.

Explorar Claude 3.7 Sonnet โ†’

OpenHands

Cรณdigo Abierto

La plataforma lรญder de agentes autรณnomos de cรณdigo abierto para desarrollo de software, operaciones de terminal y navegaciรณn de escritorio con despliegue local completo.

Explorar OpenHands โ†’

Devin

Software Autรณnomo

El asistente autรณnomo insignia de ingenierรญa de software de Cognition equipado con automatizaciรณn integrada de navegador, terminal y espacio de trabajo de escritorio.

Explorar Devin โ†’

10. Preguntas Frecuentes (FAQ)

P1: ยฟPor quรฉ no crear APIs personalizadas en lugar de agentes GUI de escritorio?

En un mundo ideal, cada software expondrรญa APIs REST o GraphQL autenticadas. En la prรกctica empresarial existen miles de aplicaciones heredadas (SAP, emuladores de mainframe, software contable local) donde desarrollar APIs exigirรญa millones de dรณlares y aรฑos de refactorizaciรณn. Los agentes GUI de escritorio permiten integraciรณn sin modificaciones de cรณdigo.

P2: ยฟQuรฉ resoluciรณn de pantalla es ideal para alimentar al agente visual?

Enviar capturas 4K crudas provoca un gasto excesivo de tokens y aumenta drรกsticamente la latencia. Los sistemas de producciรณn capturan a 1920x1080, normalizan las coordenadas a una cuadrรญcula de 1000x1000 para la inferencia del modelo y luego proyectan los clics a los pรญxeles reales de la pantalla.

P3: ยฟCรณmo gestionan los agentes la carga dinรกmica y las animaciones de la interfaz?

A diferencia de los navegadores que emiten eventos DOM como DOMContentLoaded o networkidle, los escritorios carecen de notificaciones nativas de fin de carga. Los agentes de producciรณn emplean muestreo visual diferencial: toman fotogramas cada 250 ms y comprueban que la varianza entre pรญxeles sea inferior al 1% antes de actuar.

P4: ยฟPueden los agentes operar en entornos con mรบltiples pantallas o ventanas?

Sรญ. Los motores de mapeo de coordenadas pueden tratar configuraciones multipantalla como un รบnico lienzo combinado (ej. 3840x1080) o utilizar APIs de foco de ventanas para traer la aplicaciรณn objetivo al monitor virtual primario antes de la percepciรณn.

P5: ยฟSe puede ejecutar UI-TARS localmente en hardware de consumo?

El modelo UI-TARS 7B puede ejecutarse localmente en equipos modernos (Macs con Apple Silicon y 32GB+ de memoria unificada o GPUs NVIDIA RTX 4090) usando cuantizaciones GGUF o AWQ. La variante 72B requiere GPUs empresariales como NVIDIA A100/H100 para latencias inferiores al segundo.

Desktop- & BS-Agenten Multimodales VLA September 2026 ยท 18 Min. Lesezeit

Jenseits des Browsers: Aufbau autonomer Desktop-GUI-Agenten 2026 mit UI-TARS, Claude Computer Use und OSWorld 2.0

In den letzten drei Jahren konzentrierte sich das KI-ร–kosystem stark auf die Webbrowser-Automatisierung mit Tools wie Browser-Use, Stagehand und Playwright MCP zum Parsen von HTML-DOM-Bรคumen. Allerdings laufen รผber 70 % aller Unternehmenssoftware-Workflows auรŸerhalb des Browser-DOMs. Etablierte ERP-Systeme (SAP GUI), native Excel-Arbeitsmappen mit eingebetteten VBA-Makros, Desktop-CAD-Suiten, Terminal-Konsolen und proprietรคre On-Premises-Clients besitzen keinerlei Web-DOM. Wenn Betriebssysteme Oberflรคchen direkt รผber DirectX, Metal, Win32 oder Qt rendern, sind DOM-basierte Agenten vรถllig blind. Um echte Unternehmensautomatisierung zu erschlieรŸen, markiert das Jahr 2026 den Durchbruch autonomer Desktop-GUI-Agenten, angetrieben von nativen Vision-Language-Action (VLA)-Basismodellen, Pixelkoordinaten-Grounding und System-2-Deliberationslogik. Dieser Architektur-Deep-Dive dekonstruiert UI-TARS 1.5, Claude 3.7 Computer Use, den Benchmark OSWorld 2.0 und Sicherheits-Sandboxes fรผr den Produktivbetrieb.

01. Zusammenfassung & Die neue Desktop-GUI-Grenze

Die Webautomatisierung hat ihre Reife erreicht, doch die Wissensarbeit auf dem Desktop blieb unberรผhrt. 2026 behandeln Desktop-GUI-Agenten den gesamten Betriebssystem-Bildschirm als ihre interaktive Arbeitsflรคche:

  • Jenseits von HTML-Selektoren: Desktop-Agenten erfassen rohe Bildschirmframes (1080p bis 4K), erkennen Benutzeroberflรคchenelemente direkt รผber multimodale Sprachmodelle (MLLMs) und generieren normalisierte Koordinaten (x, y), die in native Betriebssystem-Events รผbersetzt werden.
  • Open-Source-Spitze vs. proprietรคre APIs: Das quelloffene UI-TARS 1.5 von ByteDance fรผhrte natives System-2-Reinforcement-Learning fรผr schrittweise Reflexion und Fehlerkorrektur ein, wรคhrend Claude 3.7 Sonnet von Anthropic herausragende Reasoning-Fรคhigkeiten und native Computer-Use-Tools bietet.
  • Der Realitรคtscheck von OSWorld 2.0: Im OSWorld 2.0 Benchmark รผber 369 praxisnahe Aufgaben in Ubuntu, Windows und macOS erzielen fรผhrende Agenten 42 % bis 52 % Erfolgsquote bei 100-Schritt-Aufgaben โ€“ was beweist, dass Zustandsabweichungen (Drift) die zentrale ingenieurtechnische Herausforderung bleiben.
  • Zwingendes Sandboxing: Direkte Betriebssystemsteuerung erfordert Zero-Trust-Isolation. Produktivsysteme isolieren GUI-Agenten in flรผchtigen MicroVMs (z. B. E2B) oder virtuellen Bildschirm-Streams (VNC/RDP), abgesichert durch Aktions-Firewalls und Notfall-Kill-Switches.
+โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€+
|               Autonomous Desktop GUI Agent Architecture (2026)              |
|                                                                             |
|  [ User Goal: "Consolidate Q3 SAP exports into Excel macro, generate PDF" ] |
|                                     โ”‚                                       |
|                                     โ–ผ                                       |
|  โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”  |
|  โ”‚ HOST SUPERVISOR & ACTION FIREWALL (Safety Interceptor)                โ”‚  |
|  โ”‚  - Rate Limiting & Egress Filtering    - Destructive Command Blocker  โ”‚  |
|  โ”‚  - Biometric Confirmation Gateway      - Emergency Human Kill-Switch  โ”‚  |
|  โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜  |
|                                     โ”‚ Virtual Display / Peripherals         |
|                                     โ–ผ                                       |
|  โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”  |
|  โ”‚ ISOLATED DESKTOP SANDBOX (E2B / Cloud VNC / KVM Virtual Machine)      โ”‚  |
|  โ”‚                                                                       โ”‚  |
|  โ”‚   โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”               โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”   โ”‚  |
|  โ”‚   โ”‚ Screenshot Buffer   โ”‚               โ”‚ OS Input Controller     โ”‚   โ”‚  |
|  โ”‚   โ”‚ (1920x1080 RGB)     โ”‚               โ”‚ (PyAutoGUI / uinput)    โ”‚   โ”‚  |
|  โ”‚   โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜               โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ–ฒโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜   โ”‚  |
|  โ”‚              โ”‚ Raw Frame                              โ”‚ (x, y) Click  โ”‚  |
|  โ”‚              โ–ผ                                        โ”‚ & Hotkeys     โ”‚  |
|  โ”‚   โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ดโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”   โ”‚  |
|  โ”‚   โ”‚ AGENT RUNTIME: UI-TARS 1.5 / Claude 3.7 Sonnet                โ”‚   โ”‚  |
|  โ”‚   โ”‚  1. Visual Grounding: Detect target UI elements via pixels    โ”‚   โ”‚  |
|  โ”‚   โ”‚  2. System-2 Deliberation: Check milestones & reflect         โ”‚   โ”‚  |
|  โ”‚   โ”‚  3. Action Plan: Emit precise mouse, click, and key sequences โ”‚   โ”‚  |
|  โ”‚   โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜   โ”‚  |
|  โ”‚                                                                       โ”‚  |
|  โ”‚   [ Legacy SAP Client ]       [ Native Excel ]       [ Desktop CAD ]  โ”‚  |
|  โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜  |
+โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€+

02. Das Ende der DOM-Abhรคngigkeit: Warum Desktop-Workflows im Unternehmen zรคhlen

Web-Automatisierungs-Frameworks setzen voraus, dass Anwendungen strukturierte Barrierefreiheitsbรคume, saubere CSS-Selektoren und vorhersehbare Hierarchien bereitstellen. In unternehmenskritischen Prozessen greift diese Annahme ins Leere:

1. Canvas-gerenderte Web-Apps

Moderne Webanwendungen wie Figma, Google Docs mit Canvas-Rendering und WebGL-Dashboards zeichnen Inhalte direkt in leere Canvas-Elemente ohne DOM-Knoten.

2. Etablierte Enterprise-Clients

Kernsysteme wie SAP GUI, AS400-Terminal-Emulatoren, Bloomberg Terminals und Krankenhaus-KIS laufen als native Desktop-Binรคrdateien ohne Weboberflรคche.

3. Anwendungsรผbergreifende Ketten

Reale Workflows erfordern das Herunterladen von Daten, die Ausfรผhrung lokaler Excel-VBA-Makros, Aktualisierungen im Desktop-CRM und das Signieren von PDFs.

03. Die drei Wahrnehmungsarchitekturen: Pixel vs. Barrierefreiheitsbaum vs. Hybrid

Wie soll ein autonomer Agent den Bildschirminhalt erfassen? Im Jahr 2026 dominieren drei architektonische Ansรคtze:

+โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€+
|                     Desktop Perception Paradigms                            |
|                                                                             |
|  [ Approach 1: Pure Visual Grounding (Pixel-to-Coordinate) ]               |
|    Screen Frame โ”€โ”€โ–ถ High-Res VLM โ”€โ”€โ–ถ Coordinates (x: 450, y: 720)           |
|    โ€ข Pros: Universal, zero OS dependency, handles Canvas / Games / Legacy    |
|    โ€ข Cons: Heavy token cost, coordinate distortion, resolution scaling drift|
|                                                                             |
|  [ Approach 2: OS Accessibility Tree Grounding (UIAutomation / AT-SPI) ]    |
|    Screen State โ”€โ”€โ–ถ OS API Walk โ”€โ”€โ–ถ Filtered Hierarchy โ”€โ”€โ–ถ Element ID / Path|
|    โ€ข Pros: Deterministic, lightweight text tokens, 100% click precision     |
|    โ€ข Cons: 40% of native apps have broken/missing a11y trees, slow tree walk|
|                                                                             |
|  [ Approach 3: Dual-Stream Hybrid Fusion (2026 Best Practice) ]             |
|    Visual Screenshot (VLM) โ—„โ”€โ”€Fused Decisionโ”€โ”€โ–บ OS A11y Tree (Cache)        |
|    โ€ข Fast path: Use A11y node bounding box if recognized                    |
|    โ€ข Fallback: Use visual grounding when a11y nodes are obscured/custom     |
+โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€+
Dimension Reines Pixel-Grounding OS-Accessibility-Baum Dual-Stream-Hybrid-Fusion
Universalitรคt 100% (Jeder gerenderte Pixel) ~60% (Scheitert bei Custom-UI/Canvas) 98% (Eleganter Fallback)
Token-Effizienz Niedrig (~1.200 bis 2.000 Tokens/Frame) Hoch (~300 bis 600 Tokens/Baum) Mittel (~1.500 Tokens/Entscheidung)
Klickgenauigkeit 88% - 94% (Anfรคllig fรผr Drift) 99% (Wenn Knoten existieren) 98.5% (Einrasten auf Bounding-Box)
Betriebssystem-Unabhรคngigkeit Vollstรคndig (VNC-/Streaming-fรคhig) Gering (Benรถtigt OS-API-Hooks) Hoch (Modulare OS-Adapter)
Latenz pro Schritt 1.8s - 3.5s (VLM-Inferenz) 0.4s - 0.9s (Text-LLM) 1.9s - 3.2s

04. UI-TARS: Natives Vision-Language-Action & System-2-Reasoning

Das von ByteDance entwickelte und quelloffene Modell UI-TARS etablierte natives **Vision-Language-Action (VLA)** fรผr grafische Benutzeroberflรคchen. Anstatt generische Bildmodelle mรผhsam zu prompten, setzt UI-TARS auf direkte Tokenisierung motorischer Aktionen und Reinforcement Learning fรผr deliberate Reflexion:

+โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€+
|                UI-TARS 1.5 System-2 Reasoning Trajectory                     |
|                                                                             |
|  Observation โ”€โ”€โ–ถ [ Reflection & Verification ]                              |
|                   โ”‚ "Did the previous action open the File dialog?"          |
|                   โ”‚ State: YES. Detected 'Open File' window at (x: 200, y: 150)
|                   โ–ผ                                                         |
|                 [ Sub-goal Decomposition ]                                  |
|                   โ”‚ "Next sub-goal: Select 'Quarterly_Report.xlsx'"         |
|                   โ”‚ Search Strategy: Visual scan of table rows              |
|                   โ–ผ                                                         |
|                 [ Milestone Recognition ]                                   |
|                   โ”‚ Target element found at (x: 320, y: 410)                |
|                   โ–ผ                                                         |
|                 [ Action Emission ]                                         |
|                   โ”‚ Action: click(point=[320, 410])                         |
|                   โ”‚ Post-Action Expectation: File selected in input box     |
+โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€+
  • Standardisierte Motor-Tokens: Direkte Ausgabe von Tokens wie click(point=[x, y]), double_click(), drag(start, end) und press_hotkey() auf einem normalisierten 1000 × 1000 Koordinatensystem.
  • System-2-Deliberation: รœberprรผfung vorheriger Zustandsรผbergรคnge vor der nรคchsten Aktion. Konnte ein Klick den Dialog nicht รถffnen, reflektiert das Modell den Fehler, korrigiert sich selbst und wiederholt den Schritt.
  • Lokale Bereitstellung: UI-TARS 7B lรคuft lokal auf Workstations (Apple Silicon mit 32GB oder RTX 4090) und liefert Sub-Sekunden-Latenz bei vollstรคndiger Datensouverรคnitรคt.

05. Claude 3.7 Computer Use vs. Open-Weights: Latenz-, Kosten- und Genauigkeitsabwรคgungen

Entwicklungsteams mรผssen zwischen proprietรคren Spitzenmodellen (Claude 3.7 Sonnet) und selbst gehosteten Open-Weights-Modellen (UI-TARS 7B/72B) abwรคgen:

  • Kostenverlauf fรผr Vision-Tokens: Das kontinuierliche Senden von 1080p-Screenshots an ein kommerzielles Modell alle 2 Sekunden verursacht 15 bis 30 US-Dollar pro 100-Schritt-Workflow.
  • Strategisches Denken vs. repetitive RPA: Claude 3.7 Sonnet glรคnzt bei uneindeutigen Aufgaben, die semantisches Verstรคndnis unstrukturierter Dokumente erfordern. UI-TARS รผberzeugt bei hochfrequenten Ablรคufen mit minimalen Rechenkosten.
  • Datenschutz & Compliance: Banken und Behรถrden fordern, dass Bildschirminhalte das interne Firmennetz niemals verlassen โ€“ was selbst gehostete UI-TARS-Instanzen zum Standard macht.

06. Praktische Umsetzung: Aufbau eines sicheren Desktop-Agenten-Controllers in Python

Nachfolgend finden Sie eine vollstรคndige, lauffรคhige Referenzimplementierung in Python, die Koordinatenskalierung, Sicherheitsรผberwachung, das Abfangen destruktiver Befehle und menschliche Bestรคtigung demonstriert:

# Production Reference Implementation: Desktop GUI Agent Controller (2026)
# Demonstrates Vision-Language-Action Execution, Coordinate Normalization,
# Destructive Command Interception, and Human-in-the-Loop Safeguards.

import time
import math
from typing import Dict, Any, List, Tuple, Optional
from dataclasses import dataclass, field
from enum import Enum


# โ”€โ”€โ”€ 1. CORE DATA STRUCTURES & ACTIONS โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€

class ActionType(str, Enum):
    MOUSE_CLICK = "mouse_click"
    DOUBLE_CLICK = "double_click"
    HOTKEY = "hotkey"
    TYPE_TEXT = "type_text"
    TERMINAL_COMMAND = "terminal_command"
    WAIT = "wait"


@dataclass
class UIAction:
    action_type: ActionType
    coordinates: Optional[Tuple[int, int]] = None  # (x, y) on 1000x1000 normalized grid
    text_payload: Optional[str] = None
    hotkey_sequence: Optional[List[str]] = None
    thought_reasoning: str = ""
    is_destructive: bool = False


@dataclass
class ScreenDimensions:
    width: int
    height: int


# โ”€โ”€โ”€ 2. SAFETY INTERCEPTOR & GATEKEEPER โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€

class DesktopSafetyGatekeeper:
    """
    Host-side safety authority that validates actions before dispatching
    to real or virtual OS input peripherals.
    """
    DESTRUCTIVE_HOTKEYS = {("ctrl", "alt", "del"), ("cmd", "shift", "backspace")}
    DESTRUCTIVE_COMMANDS = ["rm -rf", "format", "drop database", "mkfs", "dd if="]

    def __init__(self, require_human_for_destructive: bool = True):
        self.require_human = require_human_for_destructive
        self.audit_log: List[Dict[str, Any]] = []

    def inspect_action(self, action: UIAction, human_approved: bool = False) -> Tuple[bool, str]:
        # 1. Inspect terminal/shell commands
        if action.action_type == ActionType.TERMINAL_COMMAND and action.text_payload:
            for pattern in self.DESTRUCTIVE_COMMANDS:
                if pattern in action.text_payload.lower():
                    action.is_destructive = True
                    if not human_approved:
                        return False, f"Blocked destructive terminal command pattern: '{pattern}'"

        # 2. Inspect high-risk hotkeys
        if action.action_type == ActionType.HOTKEY and action.hotkey_sequence:
            normalized_keys = tuple(sorted([k.lower() for k in action.hotkey_sequence]))
            for risk_keys in self.DESTRUCTIVE_HOTKEYS:
                if normalized_keys == tuple(sorted(risk_keys)):
                    action.is_destructive = True
                    if not human_approved:
                        return False, f"Blocked dangerous system hotkey: '{action.hotkey_sequence}'"

        # Log action to immutable audit trail
        self.audit_log.append({
            "timestamp": time.time(),
            "action": action.action_type.value,
            "coordinates": action.coordinates,
            "destructive": action.is_destructive,
            "approved": True
        })
        return True, "Action approved."


# โ”€โ”€โ”€ 3. PERIPHERAL ADAPTER & COORDINATE SCALER โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€

class OSPeripheralController:
    """
    Translates normalized model coordinates (1000x1000) to actual physical display pixels
    and dispatches low-level OS input events.
    """
    def __init__(self, display: ScreenDimensions):
        self.display = display

    def denormalize_coordinates(self, norm_x: int, norm_y: int) -> Tuple[int, int]:
        """Converts [0, 1000] model grid to [0, width] x [0, height]."""
        real_x = math.floor((norm_x / 1000.0) * self.display.width)
        real_y = math.floor((norm_y / 1000.0) * self.display.height)
        return real_x, real_y

    def execute_native_input(self, action: UIAction):
        if action.coordinates:
            rx, ry = self.denormalize_coordinates(*action.coordinates)
            print(f"๐Ÿ–ฑ๏ธ  [OS DRIVER] Moving cursor to ({rx}px, {ry}px) [Model: {action.coordinates}]")
        
        if action.action_type == ActionType.MOUSE_CLICK:
            print(f"โšก [OS DRIVER] Emitting LEFT_BUTTON_CLICK at ({rx}, {ry})")
        elif action.action_type == ActionType.DOUBLE_CLICK:
            print(f"โšก [OS DRIVER] Emitting DOUBLE_CLICK at ({rx}, {ry})")
        elif action.action_type == ActionType.HOTKEY:
            print(f"โŒจ๏ธ  [OS DRIVER] Emitting KEY_COMBINATION: {' + '.join(action.hotkey_sequence or [])}")
        elif action.action_type == ActionType.TYPE_TEXT:
            print(f"โŒจ๏ธ  [OS DRIVER] Typing string payload: \"{action.text_payload}\"")
        elif action.action_type == ActionType.TERMINAL_COMMAND:
            print(f"๐Ÿ–ฅ๏ธ  [OS DRIVER] Executing Shell Command: '{action.text_payload}'")


# โ”€โ”€โ”€ 4. AUTONOMOUS DESKTOP AGENT CONTROLLER โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€

class DesktopGUIAgent:
    """
    The orchestrator agent combining VLA decision logic, safety inspection,
    and OS input driver dispatch.
    """
    def __init__(self, display: ScreenDimensions, gatekeeper: DesktopSafetyGatekeeper):
        self.driver = OSPeripheralController(display)
        self.gatekeeper = gatekeeper

    def step(self, action: UIAction, human_confirmed: bool = False) -> Dict[str, Any]:
        print(f"\n๐Ÿง  [SYSTEM-2 REFLECTION] {action.thought_reasoning}")

        # Safety Check
        is_safe, reason = self.gatekeeper.inspect_action(action, human_approved=human_confirmed)
        if not is_safe:
            print(f"๐Ÿ›‘ [SAFETY INTERCEPT] Action Rejected: {reason}")
            return {"success": False, "reason": reason}

        # Dispatch
        self.driver.execute_native_input(action)
        return {"success": True, "reason": "Executed successfully"}


# โ”€โ”€โ”€ 5. RUNTIME VERIFICATION HARNESS โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€

if __name__ == "__main__":
    print("=" * 75)
    print("DEMO: AUTONOMOUS DESKTOP GUI AGENT SAFETY & GROUNDING CONTROLLER (2026)")
    print("=" * 75)

    # Initialize 1080p display and safety gatekeeper
    virtual_screen = ScreenDimensions(width=1920, height=1080)
    safety_shield = DesktopSafetyGatekeeper(require_human_for_destructive=True)
    agent = DesktopGUIAgent(display=virtual_screen, gatekeeper=safety_shield)

    # STEP 1: Safe Action - Navigate SAP Menu
    step1 = UIAction(
        action_type=ActionType.MOUSE_CLICK,
        coordinates=(180, 45),  # 1000x1000 normalized grid
        thought_reasoning="Milestone 1: Click 'Accounting' dropdown in SAP native menu bar."
    )
    agent.step(step1)

    # STEP 2: Safe Action - Type Transaction Code
    step2 = UIAction(
        action_type=ActionType.TYPE_TEXT,
        text_payload="FS10N",
        thought_reasoning="Milestone 2: Enter general ledger balance inquiry transaction code."
    )
    agent.step(step2)

    # STEP 3: Malicious / Accidental Destructive Step Intercepted
    step3_destructive = UIAction(
        action_type=ActionType.TERMINAL_COMMAND,
        text_payload="rm -rf /var/sap/data/*",
        thought_reasoning="Adversarial prompt injection attempt detected on unverified clipboard buffer."
    )
    print("\n[SCENARIO 1: Destructive Action Without Approval]")
    agent.step(step3_destructive, human_confirmed=False)

    # STEP 4: High-Risk Action With Human Biometric Approval
    print("\n[SCENARIO 2: Authorized High-Risk Action via Supervisor Approval]")
    agent.step(step3_destructive, human_confirmed=True)

    print("\n" + "=" * 75)
    print(f"Demonstration Complete. Total Audit Ledger Entries: {len(safety_shield.audit_log)}")
    print("=" * 75)

07. OSWorld 2.0 Benchmark-Analyse: Bewรคltigung von Long-Horizon-Drift & Fehlermustern

Der Benchmark OSWorld 2.0 bewertet Agenten anhand von 369 praxisnahen Aufgaben in Ubuntu, Windows und macOS. Wรคhrend menschliche Experten 88.3 % Erfolgsquote erreichen, erzielen Spitzenagenten zwischen 49 % und 52 % Gesamtergebnis, was vier typische Fehlerursachen verdeutlicht:

  • Auflรถsungs- und Koordinatendrift: Pop-up-Meldungen verschieben Oberflรคchenelemente um wenige Pixel, wodurch Klicks auf veraltete Koordinaten ins Leere gehen.
  • Kontextfenster-Erschรถpfung: 60 hochauflรถsende Screenshots รผberfordern den Kontext des Modells. Produktionssysteme verwerfen รคltere Bilder und verdichten sie zu textuellen Aktionsprotokollen.
  • Ladeanzeigen-Fallen: Da dem Desktop Events wie networkidle fehlen, klicken Agenten wรคhrend Ladevorgรคngen mehrfach, was Anwendungsabstรผrze provoziert. Visuelle Deltaprรผfungen lรถsen dieses Problem.
  • Kontrastarme Benutzeroberflรคchen: Im Dark Mode oder in CAD-Programmen verwechseln Modelle hรคufig รคhnlich aussehende Icons (z. B. Speichern vs. Exportieren).

08. Sicherheit & Sandboxing: VNC-Isolation, eBPF-Netzwerkfilter und Kill-Switch-Schutz

Einem autonomen Agenten direkten Zugriff auf physische Peripheriegerรคte auf Mitarbeiterrechnern zu gewรคhren, birgt unkalkulierbare Risiken. Produktionsarchitekturen erzwingen eine dreistufige Sicherheits-Sandbox:

+โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€+
|               Zero-Trust Desktop Sandbox Containment Stack                  |
|                                                                             |
|  [ Enterprise Gateway ]                                                     |
|            โ”‚                                                                |
|            โ–ผ                                                                |
|  โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”  |
|  โ”‚ LAYER 1: VIRTUAL DISPLAY & PERIPHERAL ISOLATION                       โ”‚  |
|  โ”‚ - Headless X11 / Wayland / RDP virtual server                         โ”‚  |
|  โ”‚ - The agent NEVER touches physical user hardware                      โ”‚  |
|  โ”‚ - Video frame streamed via WebRTC / VNC buffer                        โ”‚  |
|  โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜  |
|                                     โ”‚                                       |
|                                     โ–ผ                                       |
|  โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”  |
|  โ”‚ LAYER 2: SYSTEM CALL INTERCEPTION & eBPF NETWORK EGRESS               โ”‚  |
|  โ”‚ - eBPF sensor intercepts dangerous POSIX syscalls (fork, execve, ptrace)โ”‚
|  โ”‚ - Network firewall restricts outbound traffic exclusively to whitelistโ”‚  |
|  โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜  |
|                                     โ”‚                                       |
|                                     โ–ผ                                       |
|  โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”  |
|  โ”‚ LAYER 3: SUPERVISOR KILL-SWITCH & USER TAKEOVER                       โ”‚  |
|  โ”‚ - User moves physical mouse โ”€โ”€โ–ถ Instant agent suspension (Kill-Switch)โ”‚  |
|  โ”‚ - Live action stream mirrored to supervisor dashboard                โ”‚  |
|  โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜  |
+โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€+
  • Stufe 1: Virtuelle Bildschirmoberflรคche: Der Agent interagiert ausschlieรŸlich mit einem virtuellen X11/Wayland/RDP-Puffer in einer isolierten MicroVM (z. B. E2B). Physische Hardware wird niemals berรผhrt.
  • Stufe 2: eBPF-Syscall- & Egress-Filterung: Sensoren auf Kernelebene fangen gefรคhrliche Shell-Befehle (rm -rf, Formatierungsbefehle, Datenexfiltration) ab und blockieren Verbindungen auรŸerhalb der Whitelist.
  • Stufe 3: Physischer Notfall-Kill-Switch: Auf assistierten Arbeitsplรคtzen entzieht das Bewegen der physischen Maus oder Drรผcken von Esc dem Agenten sofort alle Treiberrechte und gibt dem Menschen die volle Kontrolle zurรผck.

09. Architektur-Vergleichsmatrix & Relevante Tools

Wie positionieren sich fรผhrende Desktop-Agenten-Frameworks im Jahr 2026?

Dimension UI-TARS (ByteDance) Claude 3.7 Computer Use OpenHands E2B Desktop Sandbox
Modellcharakter Open-Weights (VLA 7B/72B) Proprietรคre Spitzen-API Modell-agnostischer Orchestrator Infrastruktur-Sandbox-Laufzeit
Hauptwahrnehmung Rohe Pixel (System-2 VLA) Rohe Pixel (Vision-API) Hybrid (DOM + Terminal + GUI) Virtueller Bildschirm-Frame-Puffer
Hosting-Modell Self-Hosted (Lokale GPU-Cluster) Cloud-API (Anthropic) Self-Hosted / Cloud Managed Cloud / MicroVM
Betriebssystem-Support Windows, macOS, Linux, Android Windows, macOS, Ubuntu Linux, Docker, Browser Linux (Firecracker MicroVM)
Typischer Einsatzzweck Hochfrequente RPA, QA, Batch Komplexe Wissensarbeit Software-Engineering-Agenten Sichere Isolierung & Ausfรผhrung
Open Source 100% Open Source Proprietรคr 100% Open Source Open-Source-SDK / Managed Cloud

E2B

MicroVM-Sandbox

Die fรผhrende MicroVM-Cloud-Laufzeitumgebung zur sicheren Ausfรผhrung von Desktop-Sitzungen, Terminalbefehlen und Headless-Workflows mit nativer Hardware-Isolation.

E2B entdecken โ†’

Claude 3.7 Sonnet

Frontier-Modell

Anthropics Spitzenmodell mit nativen Computer Use-Fรคhigkeiten fรผr Desktop-Navigation, Browser-Automatisierung und mehrstufige Tool-Aufrufe.

Claude 3.7 Sonnet entdecken โ†’

OpenHands

Open Source

Die fรผhrende Open-Source-Plattform fรผr autonome Software-Entwicklungsagenten mit vollstรคndiger Unterstรผtzung von Terminal-, Browser- und Desktop-Aktionen.

OpenHands entdecken โ†’

Devin

Autonome Software

Cognitions bahnbrechender autonomer Software-Engineering-Assistent mit integrierter Browser-, Terminal- und Desktop-Automatisierung.

Devin entdecken โ†’

10. Hรคufig gestellte Fragen (FAQ)

F1: Warum baut man keine individuellen APIs statt Desktop-GUI-Agenten?

In einer idealen Welt bรถte jede Software REST- oder GraphQL-Schnittstellen. In der Praxis existieren in Unternehmen Tausende Legacy-Systeme (SAP, Mainframe-Terminals, Buchhaltungsprogramme), deren API-Nachrรผstung Millionen kosten und Jahre dauern wรผrde. Desktop-GUI-Agenten ermรถglichen Zero-Touch-Automatisierung ohne Eingriffe in Quellcode oder Datenbanken.

F2: Welche Bildschirmauflรถsung sollte an den visuellen Agenten รผbergeben werden?

4K-Rohbilder erzeugen extremes Token-Wachstum und hohe Latenzen. Produktionssysteme zeichnen รผblicherweise in 1920x1080 auf, normalisieren auf ein internes 1000x1000-Raster fรผr die Modellinferenz und rechnen vorhergesagte Koordinaten mathematisch auf physische Bildschirmpixel um.

F3: Wie bewรคltigen Desktop-Agenten dynamische Ladezeiten und Animationen?

Im Gegensatz zu Browsern mit Events wie DOMContentLoaded oder networkidle gibt es auf dem Desktop keine nativen Ladeend-Meldungen. Produktionsagenten erfassen Frames im 250ms-Intervall und prรผfen, ob die Pixelvarianz unter 1 % fรคllt, bevor der nรคchste Schritt ausgefรผhrt wird.

F4: Kรถnnen Desktop-Agenten mit mehreren Monitoren oder Fenstern arbeiten?

Ja. Koordinatentreiber behandeln Multi-Monitor-Setups entweder als zusammenhรคngende Arbeitsflรคche (z. B. 3840x1080) oder nutzen Fenster-Fokus-APIs, um die Zielanwendung vor der visuellen Erfassung auf das primรคre Display zu legen.

F5: Kann UI-TARS lokal auf Standard-Hardware betrieben werden?

Das Modell UI-TARS 7B lรคuft lokal auf moderner Hardware (z. B. Macs mit Apple Silicon und 32GB+ Unified Memory oder NVIDIA RTX 4090) mit GGUF- oder AWQ-Quantisierung. Fรผr das 72B-Modell sind Unternehmens-GPUs (A100/H100) fรผr Sub-Sekunden-Latenz erforderlich.

ใƒ‡ใ‚นใ‚ฏใƒˆใƒƒใƒ— & OSใ‚จใƒผใ‚ธใ‚งใƒณใƒˆ ใƒžใƒซใƒใƒขใƒผใƒ€ใƒซVLA 2026ๅนด9ๆœˆ ยท ่ชญไบ†็›ฎๅฎ‰18ๅˆ†

ใ€2026ๅนด็‰ˆใ€‘ใƒ–ใƒฉใ‚ฆใ‚ถ่‡ชๅ‹•ๅŒ–ใฎๅ…ˆใธ๏ผšUI-TARSใ€Claude Computer Useใ€OSWorld 2.0ใงๆง‹็ฏ‰ใ™ใ‚‹ใƒ‡ใ‚นใ‚ฏใƒˆใƒƒใƒ—GUI่‡ชๅพ‹ๆ“ไฝœใ‚จใƒผใ‚ธใ‚งใƒณใƒˆๅฎŸ่ทต

้ŽๅŽป3ๅนด้–“ใ€็”ŸๆˆAIใ‚จใ‚ณใ‚ทใ‚นใƒ†ใƒ ใฏBrowser-Useใ€Stagehandใ€Playwright MCPใชใฉใ‚’็”จใ„ใŸWebใƒ–ใƒฉใ‚ฆใ‚ถDOM่งฃๆžใฎ่‡ชๅ‹•ๅŒ–ใซๆณจๅŠ›ใ—ใฆใใพใ—ใŸใ€‚ใ—ใ‹ใ—ใ€ใ‚จใƒณใ‚ฟใƒผใƒ—ใƒฉใ‚คใ‚บ้ ˜ๅŸŸใซใŠใ‘ใ‚‹ๅฎŸๆฅญๅ‹™ใ‚ฝใƒ•ใƒˆใ‚ฆใ‚งใ‚ขใฎ70%ไปฅไธŠใฏใƒ–ใƒฉใ‚ฆใ‚ถDOMใ‚’ๆŒใกใพใ›ใ‚“ใ€‚ใƒฌใ‚ฌใ‚ทใƒผERP๏ผˆSAP GUI๏ผ‰ใ€่ค‡้›‘ใชVBAใƒžใ‚ฏใƒญใ‚’็ต„ใฟ่พผใ‚“ใ ใƒใ‚คใƒ†ใ‚ฃใƒ–Excelใ€ใƒ‡ใ‚นใ‚ฏใƒˆใƒƒใƒ—CADใ€ใ‚ฟใƒผใƒŸใƒŠใƒซใ‚ณใƒณใ‚ฝใƒผใƒซใ€ใ‚ชใƒณใƒ—ใƒฌใƒŸใ‚นใฎๅฐ‚็”จๆฅญๅ‹™ใ‚ฏใƒฉใ‚คใ‚ขใƒณใƒˆใซใฏWeb DOMใŒๅญ˜ๅœจใ›ใšใ€DirectXใ€Metalใ€Win32ใ€Qtใง็›ดๆŽฅๆ็”ปใ•ใ‚Œใ‚‹็”ป้ขใซๅฏพใ—ใฆDOMใƒ™ใƒผใ‚นใฎใ‚จใƒผใ‚ธใ‚งใƒณใƒˆใฏๅฎŒๅ…จใซ็„กๅŠ›ใงใ—ใŸใ€‚็œŸใฎใ‚จใƒณใ‚ฟใƒผใƒ—ใƒฉใ‚คใ‚บ่‡ชๅ‹•ๅŒ–ใ‚’ๅฎŸ็พใ™ใ‚‹ใŸใ‚ใ€2026ๅนดใฏใƒใ‚คใƒ†ใ‚ฃใƒ–ใช่ฆ–่ฆšใƒป่จ€่ชžใƒป่กŒๅ‹•๏ผˆVLA: Vision-Language-Action๏ผ‰ใƒขใƒ‡ใƒซใ€ใƒ”ใ‚ฏใ‚ปใƒซๅบงๆจ™ใ‚ฐใƒฉใ‚ฆใƒณใƒ‡ใ‚ฃใƒณใ‚ฐใ€System-2้…่€ƒๆŽจ่ซ–ใ‚’ๅ‚™ใˆใŸ่‡ชๅพ‹ๅž‹ใƒ‡ใ‚นใ‚ฏใƒˆใƒƒใƒ—GUIใ‚จใƒผใ‚ธใ‚งใƒณใƒˆใŒๅฐ้ ญใ—ใฆใ„ใพใ™ใ€‚ๆœฌ็จฟใงใฏใ€UI-TARS 1.5ใ€Claude 3.7 Computer Useใ€OSWorld 2.0ใƒ™ใƒณใƒใƒžใƒผใ‚ฏใ€ใใ—ใฆๅฎ‰ๅ…จใชใ‚ตใƒณใƒ‰ใƒœใƒƒใ‚ฏใ‚น้š”้›ขๅŸบ็›คใ‚’ๅพนๅบ•่งฃๅ‰–ใ—ใพใ™ใ€‚

01. ่ฆ็ด„ใจใƒ‡ใ‚นใ‚ฏใƒˆใƒƒใƒ—GUIใ‚จใƒผใ‚ธใ‚งใƒณใƒˆใฎๆœ€ๅ‰็ทš

Web่‡ชๅ‹•ๅŒ–ใฏๅฎŸ็”จๆฎต้šŽใซ้”ใ—ใพใ—ใŸใŒใ€ใƒ‡ใ‚นใ‚ฏใƒˆใƒƒใƒ—ไธŠใฎ็Ÿฅ็š„ๆฅญๅ‹™ใฏ้•ทใ‚‰ใๆ‰‹ไฝœๆฅญใฎใพใพใงใ—ใŸใ€‚2026ๅนดใ€ใƒ‡ใ‚นใ‚ฏใƒˆใƒƒใƒ—GUIใ‚จใƒผใ‚ธใ‚งใƒณใƒˆใฏOS็”ป้ขๅ…จไฝ“ใ‚’ๅฏพ่ฉฑๅž‹ใ‚ญใƒฃใƒณใƒใ‚นใจใ—ใฆ็›ดๆŽฅๆ‰ฑใ„ใพใ™๏ผš

  • HTMLใ‚ปใƒฌใ‚ฏใ‚ฟใ‹ใ‚‰ใฎ่„ฑๅด๏ผšใ‚จใƒผใ‚ธใ‚งใƒณใƒˆใฏ็”Ÿใฎ็”ป้ขใƒ•ใƒฌใƒผใƒ ๏ผˆ1080pใ€œ4K๏ผ‰ใ‚’็›ฃ่ฆ–ใ—ใ€ใƒžใƒซใƒใƒขใƒผใƒ€ใƒซLLM๏ผˆMLLM๏ผ‰ใ‚’้€šใ˜ใฆUI่ฆ็ด ใ‚’ใƒ”ใ‚ฏใ‚ปใƒซๅ˜ไฝใง็›ดๆŽฅ่ช่ญ˜ใ€‚ๆญฃ่ฆๅŒ–ๅบงๆจ™ (x, y) ใ‚’OSใฎใƒžใ‚ฆใ‚นใƒปใ‚ญใƒผใƒœใƒผใƒ‰ๅ…ฅๅŠ›ใ‚คใƒ™ใƒณใƒˆใซใƒžใƒƒใƒ”ใƒณใ‚ฐใ—ใพใ™ใ€‚
  • ใ‚ชใƒผใƒ—ใƒณใ‚ฝใƒผใ‚นใฎๅ…ˆ้ ญ vs ๅ•†็”จๆœ€้ซ˜ๅณฐAPI๏ผšByteDanceใŒๅ…ฌ้–‹ใ—ใŸใ‚ชใƒผใƒ—ใƒณใ‚ฝใƒผใ‚นใƒขใƒ‡ใƒซ UI-TARS 1.5 ใฏๅผทๅŒ–ๅญฆ็ฟ’ใ‚’็”จใ„ใŸSystem-2่‡ชๅทฑๆคœ่จผใƒปใƒใƒƒใ‚ฏใƒˆใƒฉใƒƒใ‚ญใƒณใ‚ฐ๏ผˆๅทปใๆˆปใ—๏ผ‰ใ‚’ๅฐŽๅ…ฅใ€‚Anthropicใฎ Claude 3.7 Sonnet ใฏ้ซ˜ๅบฆใชๆŽจ่ซ–ใจใƒใ‚คใƒ†ใ‚ฃใƒ–ใชComputer Useใƒ„ใƒผใƒซๅ‘ผใณๅ‡บใ—ใ‚’ๆไพ›ใ—ใพใ™ใ€‚
  • OSWorld 2.0ใฎ็พๅฎŸ่งฃ๏ผšUbuntuใ€Windowsใ€macOSใซใ‚ใŸใ‚‹369ใฎๅฎŸ็’ฐๅขƒใ‚ฟใ‚นใ‚ฏใงๆง‹ๆˆใ•ใ‚Œใ‚‹OSWorld 2.0ใซใŠใ„ใฆใ€ใ‚จใƒผใ‚ธใ‚งใƒณใƒˆใฏ100ใ‚นใƒ†ใƒƒใƒ—ใฎ้•ทๆœŸใ‚ฟใ‚นใ‚ฏใง42%ใ€œ52%ใฎๆˆๅŠŸ็އใ‚’่จ˜้Œฒใ€‚ใ‚นใƒ†ใƒƒใƒ—ๆ•ฐๅข—ๅŠ ใซไผดใ†็Šถๆ…‹ใƒ‰ใƒชใƒ•ใƒˆ๏ผˆ่„ฑ็ทš๏ผ‰ใฎ้˜ฒๆญขใŒๆœ€ๅคงใฎ็„ฆ็‚นใจใชใฃใฆใ„ใพใ™ใ€‚
  • ๅฟ…้ ˆใจใชใ‚‹ใ‚ตใƒณใƒ‰ใƒœใƒƒใ‚ฏใ‚น้š”้›ข๏ผšOSใซๅฏพใ™ใ‚‹็›ดๆŽฅๆ“ไฝœใฏ็‰นๆจฉใƒชใ‚นใ‚ฏใ‚’ไผดใ„ใพใ™ใ€‚ๆœฌ็•ชใ‚ขใƒผใ‚ญใƒ†ใ‚ฏใƒใƒฃใงใฏใ€ไฝฟใ„ๆจใฆMicroVM๏ผˆE2Bใชใฉ๏ผ‰ใ‚„ไปฎๆƒณใƒ‡ใ‚ฃใ‚นใƒ—ใƒฌใ‚คใ‚นใƒˆใƒชใƒผใƒ ๏ผˆVNC/RDP๏ผ‰ๅ†…ใงใ‚จใƒผใ‚ธใ‚งใƒณใƒˆใ‚’ๅฎŸ่กŒใ—ใ€ใƒ›ใ‚นใƒˆๅดใƒ•ใ‚กใ‚คใ‚ขใ‚ฆใ‚ฉใƒผใƒซใจ็ทŠๆ€ฅใ‚ญใƒซใ‚นใ‚คใƒƒใƒใ‚’ไฝต็”จใ—ใพใ™ใ€‚
+โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€+
|               Autonomous Desktop GUI Agent Architecture (2026)              |
|                                                                             |
|  [ User Goal: "Consolidate Q3 SAP exports into Excel macro, generate PDF" ] |
|                                     โ”‚                                       |
|                                     โ–ผ                                       |
|  โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”  |
|  โ”‚ HOST SUPERVISOR & ACTION FIREWALL (Safety Interceptor)                โ”‚  |
|  โ”‚  - Rate Limiting & Egress Filtering    - Destructive Command Blocker  โ”‚  |
|  โ”‚  - Biometric Confirmation Gateway      - Emergency Human Kill-Switch  โ”‚  |
|  โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜  |
|                                     โ”‚ Virtual Display / Peripherals         |
|                                     โ–ผ                                       |
|  โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”  |
|  โ”‚ ISOLATED DESKTOP SANDBOX (E2B / Cloud VNC / KVM Virtual Machine)      โ”‚  |
|  โ”‚                                                                       โ”‚  |
|  โ”‚   โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”               โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”   โ”‚  |
|  โ”‚   โ”‚ Screenshot Buffer   โ”‚               โ”‚ OS Input Controller     โ”‚   โ”‚  |
|  โ”‚   โ”‚ (1920x1080 RGB)     โ”‚               โ”‚ (PyAutoGUI / uinput)    โ”‚   โ”‚  |
|  โ”‚   โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜               โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ–ฒโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜   โ”‚  |
|  โ”‚              โ”‚ Raw Frame                              โ”‚ (x, y) Click  โ”‚  |
|  โ”‚              โ–ผ                                        โ”‚ & Hotkeys     โ”‚  |
|  โ”‚   โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ดโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”   โ”‚  |
|  โ”‚   โ”‚ AGENT RUNTIME: UI-TARS 1.5 / Claude 3.7 Sonnet                โ”‚   โ”‚  |
|  โ”‚   โ”‚  1. Visual Grounding: Detect target UI elements via pixels    โ”‚   โ”‚  |
|  โ”‚   โ”‚  2. System-2 Deliberation: Check milestones & reflect         โ”‚   โ”‚  |
|  โ”‚   โ”‚  3. Action Plan: Emit precise mouse, click, and key sequences โ”‚   โ”‚  |
|  โ”‚   โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜   โ”‚  |
|  โ”‚                                                                       โ”‚  |
|  โ”‚   [ Legacy SAP Client ]       [ Native Excel ]       [ Desktop CAD ]  โ”‚  |
|  โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜  |
+โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€+

02. DOMไพๅญ˜ใฎ็ต‚็„‰๏ผšใชใœใƒ‡ใ‚นใ‚ฏใƒˆใƒƒใƒ—ๆฅญๅ‹™ใŒ้‡่ฆใชใฎใ‹

ๅพ“ๆฅใฎใƒ–ใƒฉใ‚ฆใ‚ถ่‡ชๅ‹•ๅŒ–ใฏใ€ใ‚ขใƒ—ใƒชใ‚ฑใƒผใ‚ทใƒงใƒณใŒๆง‹้€ ๅŒ–ใ•ใ‚ŒใŸใ‚ขใ‚ฏใ‚ปใ‚ทใƒ“ใƒชใƒ†ใ‚ฃใƒ„ใƒชใƒผใ‚„ไบˆๆธฌๅฏ่ƒฝใชCSSใ‚ฏใƒฉใ‚นใ‚’ๆไพ›ใ™ใ‚‹ใ“ใจใ‚’ๅ‰ๆใจใ—ใฆใ„ใพใ™ใ€‚ใ—ใ‹ใ—ไผๆฅญใฎๅŸบๅนนๆฅญๅ‹™ใงใฏใใฎๅ‰ๆใŒๅดฉๅฃŠใ—ใพใ™๏ผš

1. Canvasๆ็”ปใฎWebใ‚ขใƒ—ใƒช

Figmaใ‚„Canvasๆ็”ปใƒขใƒผใƒ‰ใฎGoogle Docsใ€WebGLใƒ€ใƒƒใ‚ทใƒฅใƒœใƒผใƒ‰ใฏใ€DOMใƒŽใƒผใƒ‰ใ‚’ๆŒใŸใชใ„็ฉบใฎใ‚ญใƒฃใƒณใƒใ‚นไธŠใซ็›ดๆŽฅUIใ‚’ๆ็”ปใ—ใพใ™ใ€‚

2. ใƒฌใ‚ฌใ‚ทใƒผๅŸบๅนนใ‚ทใ‚นใƒ†ใƒ 

SAP GUIใ€AS400็ซฏๆœซใ‚จใƒŸใƒฅใƒฌใƒผใ‚ฟใ€Bloomberg Terminalใ€ๅŒป็™‚้›ปๅญใ‚ซใƒซใƒ†ใชใฉใฎใƒŸใƒƒใ‚ทใƒงใƒณใ‚ฏใƒชใƒ†ใ‚ฃใ‚ซใƒซใชใ‚ทใ‚นใƒ†ใƒ ใฏใ€Webใ‚คใƒณใ‚ฟใƒผใƒ•ใ‚งใƒผใ‚นใ‚’ๆŒใŸใชใ„ใƒใ‚คใƒ†ใ‚ฃใƒ–ใƒใ‚คใƒŠใƒชใงใ™ใ€‚

3. ่ค‡ๆ•ฐใ‚ขใƒ—ใƒชใฎๆจชๆ–ญ้€ฃๆบ

ใƒ‡ใƒผใ‚ฟใฎใƒ€ใ‚ฆใƒณใƒญใƒผใƒ‰ใ€ใƒญใƒผใ‚ซใƒซExcelใงใฎVBAใƒžใ‚ฏใƒญๅฎŸ่กŒใ€็คพๅ†…CRMใฎๆ›ดๆ–ฐใ€PDF็ฝฒๅใชใฉใ€OSใฎใƒ—ใƒญใ‚ปใ‚นๅขƒ็•Œใ‚’่ทจใ่ค‡ๅˆๆฅญๅ‹™ใŒๆ—ฅๅธธใฎๅคงๅŠใ‚’ๅ ใ‚ใพใ™ใ€‚

03. 3ใคใฎ็Ÿฅ่ฆšใ‚ขใƒผใ‚ญใƒ†ใ‚ฏใƒใƒฃใฎๆฏ”่ผƒ๏ผšใƒ”ใ‚ฏใ‚ปใƒซ vs ใ‚ขใ‚ฏใ‚ปใ‚ทใƒ“ใƒชใƒ†ใ‚ฃใƒ„ใƒชใƒผ vs ใƒใ‚คใƒ–ใƒชใƒƒใƒ‰

ใ‚จใƒผใ‚ธใ‚งใƒณใƒˆใฏใƒ‡ใ‚นใ‚ฏใƒˆใƒƒใƒ—็”ป้ขใ‚’ใฉใฎใ‚ˆใ†ใซ่ช่ญ˜ใ™ในใใงใ—ใ‚‡ใ†ใ‹๏ผŸ2026ๅนด็พๅœจใฏ3ใคใฎ่จญ่จˆใ‚ขใƒ—ใƒญใƒผใƒใŒๅญ˜ๅœจใ—ใพใ™๏ผš

+โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€+
|                     Desktop Perception Paradigms                            |
|                                                                             |
|  [ Approach 1: Pure Visual Grounding (Pixel-to-Coordinate) ]               |
|    Screen Frame โ”€โ”€โ–ถ High-Res VLM โ”€โ”€โ–ถ Coordinates (x: 450, y: 720)           |
|    โ€ข Pros: Universal, zero OS dependency, handles Canvas / Games / Legacy    |
|    โ€ข Cons: Heavy token cost, coordinate distortion, resolution scaling drift|
|                                                                             |
|  [ Approach 2: OS Accessibility Tree Grounding (UIAutomation / AT-SPI) ]    |
|    Screen State โ”€โ”€โ–ถ OS API Walk โ”€โ”€โ–ถ Filtered Hierarchy โ”€โ”€โ–ถ Element ID / Path|
|    โ€ข Pros: Deterministic, lightweight text tokens, 100% click precision     |
|    โ€ข Cons: 40% of native apps have broken/missing a11y trees, slow tree walk|
|                                                                             |
|  [ Approach 3: Dual-Stream Hybrid Fusion (2026 Best Practice) ]             |
|    Visual Screenshot (VLM) โ—„โ”€โ”€Fused Decisionโ”€โ”€โ–บ OS A11y Tree (Cache)        |
|    โ€ข Fast path: Use A11y node bounding box if recognized                    |
|    โ€ข Fallback: Use visual grounding when a11y nodes are obscured/custom     |
+โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€+
ๆฏ”่ผƒ่ปธ ็ด”็ฒ‹ใƒ”ใ‚ฏใ‚ปใƒซใ‚ฐใƒฉใ‚ฆใƒณใƒ‡ใ‚ฃใƒณใ‚ฐ OSใ‚ขใ‚ฏใ‚ปใ‚ทใƒ“ใƒชใƒ†ใ‚ฃใƒ„ใƒชใƒผ ใƒ‡ใƒฅใ‚ขใƒซใ‚นใƒˆใƒชใƒผใƒ ใƒปใƒใ‚คใƒ–ใƒชใƒƒใƒ‰่žๅˆ
ๆฑŽ็”จๆ€ง 100%๏ผˆ็”ป้ขไธŠใฎใ‚ใ‚‰ใ‚†ใ‚‹ใƒ”ใ‚ฏใ‚ปใƒซ๏ผ‰ ็ด„60%๏ผˆใ‚ซใ‚นใ‚ฟใƒ ๆ็”ปUIใงๅคฑๆ•—๏ผ‰ 98%๏ผˆๆฎต้šŽ็š„ใƒ•ใ‚ฉใƒผใƒซใƒใƒƒใ‚ฏ๏ผ‰
ใƒˆใƒผใ‚ฏใƒณๅŠน็އ ไฝŽ๏ผˆ็ด„1,200ใ€œ2,000ใƒˆใƒผใ‚ฏใƒณ/็”ป้ข๏ผ‰ ้ซ˜๏ผˆ็ด„300ใ€œ600ใƒˆใƒผใ‚ฏใƒณ/ใƒ„ใƒชใƒผ๏ผ‰ ไธญ๏ผˆ็ด„1,500ใƒˆใƒผใ‚ฏใƒณ/ๅˆคๆ–ญ๏ผ‰
ใ‚ฏใƒชใƒƒใ‚ฏ็ฒพๅบฆ 88% - 94%๏ผˆๅบงๆจ™ใ‚บใƒฌใฎใƒชใ‚นใ‚ฏใ‚ใ‚Š๏ผ‰ 99%๏ผˆใƒŽใƒผใƒ‰ใŒๅญ˜ๅœจใ™ใ‚‹ๅ ดๅˆ๏ผ‰ 98.5%๏ผˆ่ฟ‘ๅ‚ใƒใ‚ฆใƒณใƒ‡ใ‚ฃใƒณใ‚ฐใƒœใƒƒใ‚ฏใ‚นใซๅธ็€๏ผ‰
OS้žไพๅญ˜ๆ€ง ๅฎŒๅ…จ๏ผˆVNC/็”ป้ข้…ไฟกใซๅฏพๅฟœ๏ผ‰ ไฝŽ๏ผˆOSๅ›บๆœ‰ใฎAPIใƒ•ใƒƒใ‚ฏใŒๅฟ…่ฆ๏ผ‰ ้ซ˜๏ผˆใƒขใ‚ธใƒฅใƒผใƒซๅผใ‚ขใƒ€ใƒ—ใ‚ฟใƒผ๏ผ‰
ๆŽจ่ซ–ใ‚ฟใƒผใƒณใƒฌใ‚คใƒ†ใƒณใ‚ท 1.8็ง’ - 3.5็ง’๏ผˆVLMๆŽจ่ซ–๏ผ‰ 0.4็ง’ - 0.9็ง’๏ผˆใƒ†ใ‚ญใ‚นใƒˆLLM๏ผ‰ 1.9็ง’ - 3.2็ง’

04. UI-TARS๏ผšใƒใ‚คใƒ†ใ‚ฃใƒ–VLAใจSystem-2้…่€ƒๆŽจ่ซ–

ByteDanceใŒ้–‹็™บใƒปใ‚ชใƒผใƒ—ใƒณใ‚ฝใƒผใ‚นๅŒ–ใ—ใŸ UI-TARS ใฏใ€GUIๆ“ไฝœๅฐ‚็”จใฎใƒใ‚คใƒ†ใ‚ฃใƒ–ใช **Vision-Language-Action (VLA)** ใƒขใƒ‡ใƒซใฎ่‰ๅˆ†ใ‘ใงใ™ใ€‚ๆฑŽ็”จ่ฆ–่ฆšใƒขใƒ‡ใƒซใซๅพŒไป˜ใ‘ใƒ—ใƒญใƒณใƒ—ใƒˆใ‚’ๅฝ“ใฆใ‚‹ใฎใงใฏใชใใ€ๅ‹•ไฝœใƒˆใƒผใ‚ฏใƒณใฎ็›ดๆŽฅ็”ŸๆˆใจๅผทๅŒ–ๅญฆ็ฟ’ใซๅŸบใฅใๅ†…็œใƒ—ใƒญใ‚ปใ‚น๏ผˆSystem-2๏ผ‰ใ‚’็ตฑๅˆใ—ใฆใ„ใพใ™๏ผš

+โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€+
|                UI-TARS 1.5 System-2 Reasoning Trajectory                     |
|                                                                             |
|  Observation โ”€โ”€โ–ถ [ Reflection & Verification ]                              |
|                   โ”‚ "Did the previous action open the File dialog?"          |
|                   โ”‚ State: YES. Detected 'Open File' window at (x: 200, y: 150)
|                   โ–ผ                                                         |
|                 [ Sub-goal Decomposition ]                                  |
|                   โ”‚ "Next sub-goal: Select 'Quarterly_Report.xlsx'"         |
|                   โ”‚ Search Strategy: Visual scan of table rows              |
|                   โ–ผ                                                         |
|                 [ Milestone Recognition ]                                   |
|                   โ”‚ Target element found at (x: 320, y: 410)                |
|                   โ–ผ                                                         |
|                 [ Action Emission ]                                         |
|                   โ”‚ Action: click(point=[320, 410])                         |
|                   โ”‚ Post-Action Expectation: File selected in input box     |
+โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€+
  • ๆจ™ๆบ–ๅŒ–ใ•ใ‚ŒใŸ้‹ๅ‹•ใƒˆใƒผใ‚ฏใƒณ๏ผšๆญฃ่ฆๅŒ–ใ•ใ‚ŒใŸ 1000 × 1000 ๅบงๆจ™็ณปใซใŠใ„ใฆใ€click(point=[x, y])ใ€double_click()ใ€drag(start, end)ใ€press_hotkey() ใชใฉใฎใƒˆใƒผใ‚ฏใƒณใ‚’็›ดๆŽฅๅ‡บๅŠ›ใ€‚
  • System-2่‡ชๅทฑๆคœ่จผ๏ผš็›ดๅ‰ใฎๆ“ไฝœใŒๆœŸๅพ…ใ—ใŸ็”ป้ข้ท็งปใ‚’่ตทใ“ใ—ใŸใ‹ใ‚’ไบ‹ๅ‰ใซ็ขบ่ชใ€‚ใƒœใ‚ฟใƒณๆŠผไธ‹ใงใƒ€ใ‚คใ‚ขใƒญใ‚ฐใŒ้–‹ใ‹ใชใ‹ใฃใŸๅ ดๅˆใ€้Žใกใ‚’็นฐใ‚Š่ฟ”ใ•ใš่‡ชๅ‹•ใงๅ†่ฉฆ่กŒใพใŸใฏๅˆฅใƒซใƒผใƒˆใ‚’ๆŽข็ดขใ€‚
  • ใƒญใƒผใ‚ซใƒซ้…ๅ‚™ๆ€ง๏ผšUI-TARS 7Bใƒขใƒ‡ใƒซใฏใƒญใƒผใ‚ซใƒซใƒฏใƒผใ‚ฏใ‚นใƒ†ใƒผใ‚ทใƒงใƒณ๏ผˆApple Silicon 32GBไปฅไธŠใ€ใพใŸใฏRTX 4090๏ผ‰ใงๅฎŸ่กŒๅฏ่ƒฝใงใ‚ใ‚Šใ€ๆฉŸๅฏ†ใƒ‡ใƒผใ‚ฟใ‚’ๅค–้ƒจใซๅ‡บใ•ใš1็ง’ๆœชๆบ€ใงๅฟœ็ญ”ใ—ใพใ™ใ€‚

05. Claude 3.7 Computer Use vs ใ‚ชใƒผใƒ—ใƒณใƒขใƒ‡ใƒซใฎใƒˆใƒฌใƒผใƒ‰ใ‚ชใƒ•๏ผšใƒฌใ‚คใƒ†ใƒณใ‚ทใ€ใ‚ณใ‚นใƒˆใ€็ฒพๅบฆ

้–‹็™บใƒใƒผใƒ ใฏๅ•†็”จใฎๆœ€ๅ‰็ทšAPI๏ผˆClaude 3.7 Sonnet๏ผ‰ใจ่‡ชๅ‰ใƒ›ใ‚นใƒˆใฎใ‚ชใƒผใƒ—ใƒณใ‚ฆใ‚งใ‚คใƒˆใƒขใƒ‡ใƒซ๏ผˆUI-TARS 7B/72B๏ผ‰ใฎใฉใกใ‚‰ใ‚’ๆŽก็”จใ™ในใใงใ—ใ‚‡ใ†ใ‹๏ผš

  • ่ฆ–่ฆšใƒˆใƒผใ‚ฏใƒณใ‚ณใ‚นใƒˆใฎ่ฉฆ็ฎ—๏ผš1080pใฎใ‚นใ‚ฏใƒชใƒผใƒณใ‚ทใƒงใƒƒใƒˆใ‚’2็ง’ใ”ใจใซๅ•†็”จใƒขใƒ‡ใƒซใธ้€ไฟกใ—็ถšใ‘ใ‚‹ใจใ€100ใ‚นใƒ†ใƒƒใƒ—ใฎๆฅญๅ‹™ๅ‡ฆ็†ใง1ๅ›žใ‚ใŸใ‚Š15ใ€œ30ใƒ‰ใƒซใฎใ‚ณใ‚นใƒˆใŒ็™บ็”Ÿใ—ใพใ™ใ€‚
  • ้ซ˜ๅบฆใชๆŽจ่ซ– vs ๅฎšๅž‹ๅคง้‡RPA๏ผšๆ›–ๆ˜งใชๆŒ‡็คบใ‚„่ค‡้›‘ใช้žๆง‹้€ ๅŒ–ๆ–‡ๆ›ธใ‚’่ชญใฟ่งฃใๆฅญๅ‹™ใซใฏClaude 3.7 SonnetใŒๆœ€้ฉใงใ™ใŒใ€ๅฎšๅž‹็š„ใชๅคง้‡ใƒ‡ใƒผใ‚ฟ่ปข้€ใ‚„ๅๅพฉๅ…ฅๅŠ›ใงใฏUI-TARSใŒใ‚ณใ‚นใƒˆ้ขใงๅœงๅ€’็š„ๅ„ชไฝใซ็ซ‹ใกใพใ™ใ€‚
  • ใƒ‡ใƒผใ‚ฟใ‚ฌใƒใƒŠใƒณใ‚น๏ผš้‡‘่žใƒปๅŒป็™‚ๅˆ†้‡Žใชใฉใ€็”ป้ขไธŠใฎๅ€‹ไบบๆƒ…ๅ ฑใ‚„่ฒกๅ‹™ใƒ‡ใƒผใ‚ฟใ‚’ๅค–้ƒจใ‚ฏใƒฉใ‚ฆใƒ‰APIใธ้€ไฟกใงใใชใ„็’ฐๅขƒใงใฏใ€ใ‚ชใƒณใƒ—ใƒฌใƒŸใ‚นใง้‹็”จๅฏ่ƒฝใชUI-TARSใŒๆจ™ๆบ–็š„ใช้ธๆŠž่‚ขใจใชใ‚Šใพใ™ใ€‚

06. PythonๅฎŸ่ทตๅฎŸ่ฃ…๏ผšๅฎ‰ๅ…จใชใƒ‡ใ‚นใ‚ฏใƒˆใƒƒใƒ—ๆ“ไฝœใ‚ณใƒณใƒˆใƒญใƒผใƒฉใƒผใฎๆง‹็ฏ‰

ไปฅไธ‹ใฏใ€ๅบงๆจ™ๆญฃ่ฆๅŒ–ใ‚นใ‚ฑใƒผใƒชใƒณใ‚ฐใ€ๅฎ‰ๅ…จใ‚ฒใƒผใƒˆใ‚ญใƒผใƒ‘ใƒผใ€็ ดๅฃŠ็š„ใ‚ณใƒžใƒณใƒ‰ใฎๆคœ็Ÿฅ้ฎๆ–ญใ€ไบบ้–“ไป‹ๅ…ฅๆ‰ฟ่ชใ‚’ๅซใ‚€ใ€ๅฎŒๅ…จใซๅฎŸ่กŒๅฏ่ƒฝใชPythonใƒชใƒ•ใ‚กใƒฌใƒณใ‚นๅฎŸ่ฃ…ใงใ™๏ผš

# Production Reference Implementation: Desktop GUI Agent Controller (2026)
# Demonstrates Vision-Language-Action Execution, Coordinate Normalization,
# Destructive Command Interception, and Human-in-the-Loop Safeguards.

import time
import math
from typing import Dict, Any, List, Tuple, Optional
from dataclasses import dataclass, field
from enum import Enum


# โ”€โ”€โ”€ 1. CORE DATA STRUCTURES & ACTIONS โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€

class ActionType(str, Enum):
    MOUSE_CLICK = "mouse_click"
    DOUBLE_CLICK = "double_click"
    HOTKEY = "hotkey"
    TYPE_TEXT = "type_text"
    TERMINAL_COMMAND = "terminal_command"
    WAIT = "wait"


@dataclass
class UIAction:
    action_type: ActionType
    coordinates: Optional[Tuple[int, int]] = None  # (x, y) on 1000x1000 normalized grid
    text_payload: Optional[str] = None
    hotkey_sequence: Optional[List[str]] = None
    thought_reasoning: str = ""
    is_destructive: bool = False


@dataclass
class ScreenDimensions:
    width: int
    height: int


# โ”€โ”€โ”€ 2. SAFETY INTERCEPTOR & GATEKEEPER โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€

class DesktopSafetyGatekeeper:
    """
    Host-side safety authority that validates actions before dispatching
    to real or virtual OS input peripherals.
    """
    DESTRUCTIVE_HOTKEYS = {("ctrl", "alt", "del"), ("cmd", "shift", "backspace")}
    DESTRUCTIVE_COMMANDS = ["rm -rf", "format", "drop database", "mkfs", "dd if="]

    def __init__(self, require_human_for_destructive: bool = True):
        self.require_human = require_human_for_destructive
        self.audit_log: List[Dict[str, Any]] = []

    def inspect_action(self, action: UIAction, human_approved: bool = False) -> Tuple[bool, str]:
        # 1. Inspect terminal/shell commands
        if action.action_type == ActionType.TERMINAL_COMMAND and action.text_payload:
            for pattern in self.DESTRUCTIVE_COMMANDS:
                if pattern in action.text_payload.lower():
                    action.is_destructive = True
                    if not human_approved:
                        return False, f"Blocked destructive terminal command pattern: '{pattern}'"

        # 2. Inspect high-risk hotkeys
        if action.action_type == ActionType.HOTKEY and action.hotkey_sequence:
            normalized_keys = tuple(sorted([k.lower() for k in action.hotkey_sequence]))
            for risk_keys in self.DESTRUCTIVE_HOTKEYS:
                if normalized_keys == tuple(sorted(risk_keys)):
                    action.is_destructive = True
                    if not human_approved:
                        return False, f"Blocked dangerous system hotkey: '{action.hotkey_sequence}'"

        # Log action to immutable audit trail
        self.audit_log.append({
            "timestamp": time.time(),
            "action": action.action_type.value,
            "coordinates": action.coordinates,
            "destructive": action.is_destructive,
            "approved": True
        })
        return True, "Action approved."


# โ”€โ”€โ”€ 3. PERIPHERAL ADAPTER & COORDINATE SCALER โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€

class OSPeripheralController:
    """
    Translates normalized model coordinates (1000x1000) to actual physical display pixels
    and dispatches low-level OS input events.
    """
    def __init__(self, display: ScreenDimensions):
        self.display = display

    def denormalize_coordinates(self, norm_x: int, norm_y: int) -> Tuple[int, int]:
        """Converts [0, 1000] model grid to [0, width] x [0, height]."""
        real_x = math.floor((norm_x / 1000.0) * self.display.width)
        real_y = math.floor((norm_y / 1000.0) * self.display.height)
        return real_x, real_y

    def execute_native_input(self, action: UIAction):
        if action.coordinates:
            rx, ry = self.denormalize_coordinates(*action.coordinates)
            print(f"๐Ÿ–ฑ๏ธ  [OS DRIVER] Moving cursor to ({rx}px, {ry}px) [Model: {action.coordinates}]")
        
        if action.action_type == ActionType.MOUSE_CLICK:
            print(f"โšก [OS DRIVER] Emitting LEFT_BUTTON_CLICK at ({rx}, {ry})")
        elif action.action_type == ActionType.DOUBLE_CLICK:
            print(f"โšก [OS DRIVER] Emitting DOUBLE_CLICK at ({rx}, {ry})")
        elif action.action_type == ActionType.HOTKEY:
            print(f"โŒจ๏ธ  [OS DRIVER] Emitting KEY_COMBINATION: {' + '.join(action.hotkey_sequence or [])}")
        elif action.action_type == ActionType.TYPE_TEXT:
            print(f"โŒจ๏ธ  [OS DRIVER] Typing string payload: \"{action.text_payload}\"")
        elif action.action_type == ActionType.TERMINAL_COMMAND:
            print(f"๐Ÿ–ฅ๏ธ  [OS DRIVER] Executing Shell Command: '{action.text_payload}'")


# โ”€โ”€โ”€ 4. AUTONOMOUS DESKTOP AGENT CONTROLLER โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€

class DesktopGUIAgent:
    """
    The orchestrator agent combining VLA decision logic, safety inspection,
    and OS input driver dispatch.
    """
    def __init__(self, display: ScreenDimensions, gatekeeper: DesktopSafetyGatekeeper):
        self.driver = OSPeripheralController(display)
        self.gatekeeper = gatekeeper

    def step(self, action: UIAction, human_confirmed: bool = False) -> Dict[str, Any]:
        print(f"\n๐Ÿง  [SYSTEM-2 REFLECTION] {action.thought_reasoning}")

        # Safety Check
        is_safe, reason = self.gatekeeper.inspect_action(action, human_approved=human_confirmed)
        if not is_safe:
            print(f"๐Ÿ›‘ [SAFETY INTERCEPT] Action Rejected: {reason}")
            return {"success": False, "reason": reason}

        # Dispatch
        self.driver.execute_native_input(action)
        return {"success": True, "reason": "Executed successfully"}


# โ”€โ”€โ”€ 5. RUNTIME VERIFICATION HARNESS โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€

if __name__ == "__main__":
    print("=" * 75)
    print("DEMO: AUTONOMOUS DESKTOP GUI AGENT SAFETY & GROUNDING CONTROLLER (2026)")
    print("=" * 75)

    # Initialize 1080p display and safety gatekeeper
    virtual_screen = ScreenDimensions(width=1920, height=1080)
    safety_shield = DesktopSafetyGatekeeper(require_human_for_destructive=True)
    agent = DesktopGUIAgent(display=virtual_screen, gatekeeper=safety_shield)

    # STEP 1: Safe Action - Navigate SAP Menu
    step1 = UIAction(
        action_type=ActionType.MOUSE_CLICK,
        coordinates=(180, 45),  # 1000x1000 normalized grid
        thought_reasoning="Milestone 1: Click 'Accounting' dropdown in SAP native menu bar."
    )
    agent.step(step1)

    # STEP 2: Safe Action - Type Transaction Code
    step2 = UIAction(
        action_type=ActionType.TYPE_TEXT,
        text_payload="FS10N",
        thought_reasoning="Milestone 2: Enter general ledger balance inquiry transaction code."
    )
    agent.step(step2)

    # STEP 3: Malicious / Accidental Destructive Step Intercepted
    step3_destructive = UIAction(
        action_type=ActionType.TERMINAL_COMMAND,
        text_payload="rm -rf /var/sap/data/*",
        thought_reasoning="Adversarial prompt injection attempt detected on unverified clipboard buffer."
    )
    print("\n[SCENARIO 1: Destructive Action Without Approval]")
    agent.step(step3_destructive, human_confirmed=False)

    # STEP 4: High-Risk Action With Human Biometric Approval
    print("\n[SCENARIO 2: Authorized High-Risk Action via Supervisor Approval]")
    agent.step(step3_destructive, human_confirmed=True)

    print("\n" + "=" * 75)
    print(f"Demonstration Complete. Total Audit Ledger Entries: {len(safety_shield.audit_log)}")
    print("=" * 75)

07. OSWorld 2.0ใƒ™ใƒณใƒใƒžใƒผใ‚ฏๅˆ†ๆž๏ผš้•ทๆœŸใ‚ฟใ‚นใ‚ฏใฎใƒ‰ใƒชใƒ•ใƒˆๅ…‹ๆœใจไธป่ฆใชๅคฑๆ•—ใƒ‘ใ‚ฟใƒผใƒณ

OSWorld 2.0 ใฏUbuntuใ€Windowsใ€macOSใซใ‚ใŸใ‚‹369ใฎใƒชใ‚ขใƒซใชใ‚ฟใ‚นใ‚ฏใงใ‚จใƒผใ‚ธใ‚งใƒณใƒˆใ‚’่ฉ•ไพกใ—ใพใ™ใ€‚ไบบ้–“ใฎใƒ™ใƒผใ‚นใƒฉใ‚คใƒณใŒ88.3%ใงใ‚ใ‚‹ใฎใซๅฏพใ—ใ€ๆœ€ๅ…ˆ็ซฏใƒขใƒ‡ใƒซใฏๅ…จไฝ“ใง49%ใ€œ52%ใซใจใฉใพใฃใฆใŠใ‚Šใ€4ใคใฎๅ…ธๅž‹็š„ใชๅคฑๆ•—ใƒ‘ใ‚ฟใƒผใƒณใŒๆ˜Žใ‚‰ใ‹ใซใชใฃใฆใ„ใพใ™๏ผš

  • ่งฃๅƒๅบฆใจๅบงๆจ™ใฎใƒ‰ใƒชใƒ•ใƒˆ๏ผšใƒใƒƒใƒ—ใ‚ขใƒƒใƒ—้€š็Ÿฅใ‚„ใ‚ฆใ‚ฃใƒณใƒ‰ใ‚ฆใฎๆ‹กๅคง็ธฎๅฐใซใ‚ˆใ‚Šๅฏพ่ฑกใŒๆ•ฐใƒ”ใ‚ฏใ‚ปใƒซ็งปๅ‹•ใ—ใ€ๅคใ„่จ˜ๆ†ถใฎๅบงๆจ™ใ‚’ใ‚ฏใƒชใƒƒใ‚ฏใ—ใฆ่ชคๅ‹•ไฝœใ™ใ‚‹็พ่ฑกใ€‚
  • ใ‚ณใƒณใƒ†ใ‚ญใ‚นใƒˆ้•ทใฎๅœง่ฟซ๏ผš้ซ˜่งฃๅƒๅบฆ็”ปๅƒใ‚’60ๆžš่“„็ฉใ™ใ‚‹ใจๆณจๆ„ๆฉŸๆง‹ใŒ็ ด็ถปใ™ใ‚‹ใŸใ‚ใ€ๅคใ„็”ปๅƒใ‚’ใƒ†ใ‚ญใ‚นใƒˆ่ฆ็ด„ใธๅœง็ธฎใ™ใ‚‹ใƒ—ใƒซใƒผใƒ‹ใƒณใ‚ฐใŒไธๅฏๆฌ ใงใ™ใ€‚
  • ็„กๅฟœ็ญ”ใƒญใƒผใƒ‡ใ‚ฃใƒณใ‚ฐๆ™‚ใฎ้€ฃๆ‰“ใƒˆใƒฉใƒƒใƒ—๏ผšWebใฎใ‚ˆใ†ใช networkidle ใŒใชใ„ใŸใ‚ใ€ๅ‡ฆ็†ไธญใซใƒœใ‚ฟใƒณใ‚’้€ฃๆ‰“ใ—ใฆใ‚ขใƒ—ใƒชใ‚’ใ‚ฏใƒฉใƒƒใ‚ทใƒฅใ•ใ›ใ‚‹ไบ‹ๆ…‹ใ€‚็”ป้ขใƒ”ใ‚ฏใ‚ปใƒซใฎๅทฎๅˆ†ๆคœ็Ÿฅใง้˜ฒใŽใพใ™ใ€‚
  • ไฝŽใ‚ณใƒณใƒˆใƒฉใ‚นใƒˆUIใงใฎ่ชค่ช๏ผšใƒ€ใƒผใ‚ฏใƒขใƒผใƒ‰ใฎๆฅญๅ‹™ใ‚ฝใƒ•ใƒˆใ‚„CAD็”ป้ขใงใ€ไฟๅญ˜ใจใ‚จใ‚ฏใ‚นใƒใƒผใƒˆใชใฉไผผใŸใ‚ขใ‚คใ‚ณใƒณใ‚’่ฆ‹่ชคใ‚‹ๅ•้กŒใ€‚

08. ใ‚ปใ‚ญใƒฅใƒชใƒ†ใ‚ฃใจใ‚ตใƒณใƒ‰ใƒœใƒƒใ‚ฏใ‚น๏ผšVNC้š”้›ขใ€eBPFๅˆถๅพกใ€็ทŠๆ€ฅๅœๆญข๏ผˆKill-Switch๏ผ‰

็คพๅ“กใฎPCไธŠใง่‡ชๅพ‹ใ‚จใƒผใ‚ธใ‚งใƒณใƒˆใซ็›ดๆŽฅใƒžใ‚ฆใ‚นใจใ‚ญใƒผใƒœใƒผใƒ‰ใฎๆจฉ้™ใ‚’ไธŽใˆใ‚‹ใ“ใจใฏใ€ๆฅตใ‚ใฆ้‡ๅคงใชใ‚ปใ‚ญใƒฅใƒชใƒ†ใ‚ฃใƒชใ‚นใ‚ฏใ‚’ๆ‹›ใใพใ™ใ€‚ๆœฌ็•ช้‹็”จใงใฏ3ๅฑคใฎใ‚ผใƒญใƒˆใƒฉใ‚นใƒˆใ‚ตใƒณใƒ‰ใƒœใƒƒใ‚ฏใ‚นใ‚’ๆง‹็ฏ‰ใ—ใพใ™๏ผš

+โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€+
|               Zero-Trust Desktop Sandbox Containment Stack                  |
|                                                                             |
|  [ Enterprise Gateway ]                                                     |
|            โ”‚                                                                |
|            โ–ผ                                                                |
|  โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”  |
|  โ”‚ LAYER 1: VIRTUAL DISPLAY & PERIPHERAL ISOLATION                       โ”‚  |
|  โ”‚ - Headless X11 / Wayland / RDP virtual server                         โ”‚  |
|  โ”‚ - The agent NEVER touches physical user hardware                      โ”‚  |
|  โ”‚ - Video frame streamed via WebRTC / VNC buffer                        โ”‚  |
|  โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜  |
|                                     โ”‚                                       |
|                                     โ–ผ                                       |
|  โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”  |
|  โ”‚ LAYER 2: SYSTEM CALL INTERCEPTION & eBPF NETWORK EGRESS               โ”‚  |
|  โ”‚ - eBPF sensor intercepts dangerous POSIX syscalls (fork, execve, ptrace)โ”‚
|  โ”‚ - Network firewall restricts outbound traffic exclusively to whitelistโ”‚  |
|  โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜  |
|                                     โ”‚                                       |
|                                     โ–ผ                                       |
|  โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”  |
|  โ”‚ LAYER 3: SUPERVISOR KILL-SWITCH & USER TAKEOVER                       โ”‚  |
|  โ”‚ - User moves physical mouse โ”€โ”€โ–ถ Instant agent suspension (Kill-Switch)โ”‚  |
|  โ”‚ - Live action stream mirrored to supervisor dashboard                โ”‚  |
|  โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜  |
+โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€+
  • ็ฌฌ1ๅฑค๏ผšไปฎๆƒณใƒ‡ใ‚ฃใ‚นใƒ—ใƒฌใ‚ค้š”้›ข๏ผšใ‚จใƒผใ‚ธใ‚งใƒณใƒˆใฏ้š”้›ขใ•ใ‚ŒใŸMicroVM๏ผˆE2Bใชใฉ๏ผ‰ๅ†…ใฎไปฎๆƒณX11/Wayland/RDPใƒใƒƒใƒ•ใ‚กใฎใฟใ‚’ๆ“ไฝœใ€‚็‰ฉ็†ใƒใƒผใƒ‰ใ‚ฆใ‚งใ‚ขใธใฎ็›ดๆŽฅใ‚ขใ‚ฏใ‚ปใ‚นใฏๅฎŒๅ…จใซๆŽ’้™คใ€‚
  • ็ฌฌ2ๅฑค๏ผšeBPFใ‚ทใ‚นใƒ†ใƒ ใ‚ณใƒผใƒซ๏ผ†้€šไฟก็›ฃๆŸป๏ผšใ‚ซใƒผใƒใƒซใƒฌใƒ™ใƒซใฎeBPFใ‚ปใƒณใ‚ตใƒผใซใ‚ˆใ‚Šใ€ๅฑ้™บใชใ‚ณใƒžใƒณใƒ‰๏ผˆrm -rfใ€ไธๆญฃใชใƒ‡ใƒผใ‚ฟๅค–้ƒจ้€ไฟก๏ผ‰ใ‚’ๆคœ็Ÿฅ้ฎๆ–ญใ—ใ€่จฑๅฏใƒชใ‚นใƒˆๅค–ใฎIP้€šไฟกใ‚’ๆ‹’ๅฆใ€‚
  • ็ฌฌ3ๅฑค๏ผš็‰ฉ็†ๆ“ไฝœใซใ‚ˆใ‚‹็ทŠๆ€ฅใ‚ญใƒซใ‚นใ‚คใƒƒใƒ๏ผšไบบ้–“ใŒ็‰ฉ็†ใƒžใ‚ฆใ‚นใ‚’ๅ‹•ใ‹ใ™ใ‹ Esc ใ‚ญใƒผใ‚’ๆŠผใ—ใŸ็žฌ้–“ใซใ€ใ‚จใƒผใ‚ธใ‚งใƒณใƒˆใฎใƒ‰ใƒฉใ‚คใƒๆจฉ้™ใ‚’ๅณๆ™‚ๅ‰ฅๅฅชใ—ใฆไบบ้–“ใฎๆ“ไฝœใ‚’ๆœ€ๅ„ชๅ…ˆใ€‚

09. ใ‚ขใƒผใ‚ญใƒ†ใ‚ฏใƒใƒฃๆฏ”่ผƒใƒžใƒˆใƒชใ‚ฏใ‚นใจ้–ข้€ฃ้–‹็™บใƒ„ใƒผใƒซ

2026ๅนดใซใŠใ‘ใ‚‹ไธป่ฆใชใƒ‡ใ‚นใ‚ฏใƒˆใƒƒใƒ—ใƒปใ‚ณใƒณใƒ”ใƒฅใƒผใ‚ฟใƒผๆ“ไฝœใ‚จใƒผใ‚ธใ‚งใƒณใƒˆๅŸบ็›คใฎๆฏ”่ผƒใฏไปฅไธ‹ใฎ้€šใ‚Šใงใ™๏ผš

ๆฏ”่ผƒ่ปธ UI-TARS (ByteDance) Claude 3.7 Computer Use OpenHands E2B Desktop Sandbox
ใƒขใƒ‡ใƒซๅฝขๆ…‹ ใ‚ชใƒผใƒ—ใƒณใ‚ฆใ‚งใ‚คใƒˆ๏ผˆVLA 7B/72B๏ผ‰ ๅ•†็”จใƒ•ใƒญใƒณใƒ†ใ‚ฃใ‚ขAPI ใƒขใƒ‡ใƒซ้žไพๅญ˜ใ‚ชใƒผใ‚ฑใ‚นใƒˆใƒฌใƒผใ‚ฟใƒผ ใ‚คใƒณใƒ•ใƒฉใ‚ตใƒณใƒ‰ใƒœใƒƒใ‚ฏใ‚น็’ฐๅขƒ
ไธปใช็Ÿฅ่ฆšๆ–นๅผ ็”Ÿใƒ”ใ‚ฏใ‚ปใƒซ๏ผˆSystem-2 VLA๏ผ‰ ็”Ÿใƒ”ใ‚ฏใ‚ปใƒซ๏ผˆVision API๏ผ‰ ใƒใ‚คใƒ–ใƒชใƒƒใƒ‰๏ผˆDOM + ็ซฏๆœซ + GUI๏ผ‰ ไปฎๆƒณ็”ป้ขใƒ•ใƒฌใƒผใƒ ใƒใƒƒใƒ•ใ‚ก
ใƒ›ใ‚นใƒ†ใ‚ฃใƒณใ‚ฐ็’ฐๅขƒ ใ‚ชใƒณใƒ—ใƒฌใƒŸใ‚น๏ผˆ่‡ช็คพGPUๅŸบ็›ค๏ผ‰ ใ‚ฏใƒฉใ‚ฆใƒ‰API๏ผˆAnthropic๏ผ‰ ใ‚ปใƒซใƒ•ใƒ›ใ‚นใƒˆ / ใ‚ฏใƒฉใ‚ฆใƒ‰ ใƒžใƒใƒผใ‚ธใƒ‰ใ‚ฏใƒฉใ‚ฆใƒ‰ / MicroVM
ๅฏพๅฟœOS Windows, macOS, Linux, Android Windows, macOS, Ubuntu Linux, Docker, ใƒ–ใƒฉใ‚ฆใ‚ถ Linux๏ผˆFirecracker MicroVM๏ผ‰
ไธปใช็”จ้€” ้ซ˜้ ปๅบฆRPAใ€QAใƒ†ใ‚นใƒˆใ€ไธ€ๆ‹ฌๅ…ฅๅŠ› ่ค‡้›‘ใช็Ÿฅ็š„ๆฅญๅ‹™ใฎๆŽจ่ซ–ๅ‡ฆ็† ใ‚ฝใƒ•ใƒˆใ‚ฆใ‚งใ‚ข้–‹็™บ่‡ชๅพ‹ใ‚จใƒผใ‚ธใ‚งใƒณใƒˆ ๅฎ‰ๅ…จใชใ‚จใƒผใ‚ธใ‚งใƒณใƒˆ้š”้›ขๅฎŸ่กŒ็’ฐๅขƒ
ใ‚ชใƒผใƒ—ใƒณใ‚ฝใƒผใ‚นๆ€ง 100% ใ‚ชใƒผใƒ—ใƒณใ‚ฝใƒผใ‚น ใƒ—ใƒญใƒ—ใƒฉใ‚คใ‚จใ‚ฟใƒช 100% ใ‚ชใƒผใƒ—ใƒณใ‚ฝใƒผใ‚น ใ‚ชใƒผใƒ—ใƒณSDK / ใƒžใƒใƒผใ‚ธใƒ‰

E2B

MicroVMใ‚ตใƒณใƒ‰ใƒœใƒƒใ‚ฏใ‚น

ไฟก้ ผใงใใชใ„ใƒ‡ใ‚นใ‚ฏใƒˆใƒƒใƒ—ใ‚ปใƒƒใ‚ทใƒงใƒณใ‚„ใ‚ฟใƒผใƒŸใƒŠใƒซๆ“ไฝœใ‚’ใƒใƒผใƒ‰ใ‚ฆใ‚งใ‚ขใƒฌใƒ™ใƒซใงๅฎ‰ๅ…จใซ้š”้›ขๅฎŸ่กŒใ™ใ‚‹ใ€AIใ‚จใƒผใ‚ธใ‚งใƒณใƒˆๅ‘ใ‘ไธป่ฆMicroVMใ‚ฏใƒฉใ‚ฆใƒ‰็’ฐๅขƒใ€‚

E2Bใฎ่ฉณ็ดฐใ‚’่ฆ‹ใ‚‹ โ†’

Claude 3.7 Sonnet

ใƒ•ใƒญใƒณใƒ†ใ‚ฃใ‚ขใƒขใƒ‡ใƒซ

ใƒ‡ใ‚นใ‚ฏใƒˆใƒƒใƒ—ๆ“ไฝœใ€ใƒ–ใƒฉใ‚ฆใ‚ถ่‡ชๅ‹•ๅŒ–ใ€้ซ˜ๅบฆใชใƒ„ใƒผใƒซๅฎŸ่กŒใ‚’ๅฏ่ƒฝใซใ™ใ‚‹ใƒใ‚คใƒ†ใ‚ฃใƒ–ใฎComputer UseๆฉŸ่ƒฝใ‚’ๅ‚™ใˆใŸAnthropicใฎๆœ€้ซ˜ๅณฐๆŽจ่ซ–ใƒขใƒ‡ใƒซใ€‚

Claude 3.7 Sonnetใฎ่ฉณ็ดฐใ‚’่ฆ‹ใ‚‹ โ†’

OpenHands

ใ‚ชใƒผใƒ—ใƒณใ‚ฝใƒผใ‚น

ใ‚ฝใƒ•ใƒˆใ‚ฆใ‚งใ‚ข้–‹็™บใ€ใ‚ฟใƒผใƒŸใƒŠใƒซๆ“ไฝœใ€ใƒ‡ใ‚นใ‚ฏใƒˆใƒƒใƒ—้€ฃๆบใฎใŸใ‚ใฎๆœ€้ซ˜ๅณฐใ‚ชใƒผใƒ—ใƒณใ‚ฝใƒผใ‚น่‡ชๅพ‹ใ‚จใƒผใ‚ธใ‚งใƒณใƒˆใƒ—ใƒฉใƒƒใƒˆใƒ•ใ‚ฉใƒผใƒ ใ€‚

OpenHandsใฎ่ฉณ็ดฐใ‚’่ฆ‹ใ‚‹ โ†’

Devin

่‡ชๅพ‹ๅž‹ใ‚ฝใƒ•ใƒˆใ‚ฆใ‚งใ‚ขAI

ใƒ–ใƒฉใ‚ฆใ‚ถใ€ใ‚ฟใƒผใƒŸใƒŠใƒซใ€ใ‚จใƒ‡ใ‚ฃใ‚ฟใ‚’็ทๅˆๅˆถๅพกใ—ใ€่‡ชๅพ‹็š„ใซใ‚ณใƒผใƒ‰้–‹็™บใจใƒ‡ใ‚นใ‚ฏใƒˆใƒƒใƒ—็’ฐๅขƒไฝœๆฅญใ‚’ๅฎŒ้‚ใ™ใ‚‹Cognitionใฎใƒ•ใƒฉใƒƒใ‚ฐใ‚ทใƒƒใƒ—AIใ€‚

Devinใฎ่ฉณ็ดฐใ‚’่ฆ‹ใ‚‹ โ†’

10. ใ‚ˆใใ‚ใ‚‹่ณชๅ•๏ผˆFAQ๏ผ‰

Q1: ๅ€‹ๅˆฅAPIใ‚’้–‹็™บใ™ใ‚‹ไปฃใ‚ใ‚Šใซใƒ‡ใ‚นใ‚ฏใƒˆใƒƒใƒ—GUIใ‚จใƒผใ‚ธใ‚งใƒณใƒˆใ‚’ไฝฟใ†ๅˆฉ็‚นใฏไฝ•ใงใ™ใ‹๏ผŸ

็†ๆƒณ็š„ใชไธ–็•Œใงใฏๅ…จใ‚ฝใƒ•ใƒˆใŒRESTใ‚„GraphQLใ‚’ๆไพ›ใ™ในใใงใ™ใŒใ€็พๅฎŸใฎไผๆฅญๅ†…ใซใฏๆ•ฐๅƒใฎใƒฌใ‚ฌใ‚ทใƒผใ‚ทใ‚นใƒ†ใƒ ๏ผˆSAPใ€ใ‚ชใƒ•ใ‚ณใƒณ็ซฏๆœซใ€ๅฐ‚็”จไผš่จˆใ‚ฝใƒ•ใƒˆ๏ผ‰ใŒๅญ˜ๅœจใ—ใ€API้–‹็™บใซใฏ่†จๅคงใช่ฒป็”จใจๅนดๆœˆใ‚’่ฆใ—ใพใ™ใ€‚ใƒ‡ใ‚นใ‚ฏใƒˆใƒƒใƒ—GUIใ‚จใƒผใ‚ธใ‚งใƒณใƒˆใฏๆ—ขๅญ˜ใ‚ณใƒผใƒ‰ใ‚„DBใซไธ€ๅˆ‡ๆ‰‹ใ‚’ๅŠ ใˆใชใ„ใ‚ผใƒญใ‚ฟใƒƒใƒ่‡ชๅ‹•ๅŒ–ใ‚’ๅฎŸ็พใ—ใพใ™ใ€‚

Q2: ่ฆ–่ฆšใ‚จใƒผใ‚ธใ‚งใƒณใƒˆใซๅ…ฅๅŠ›ใ™ใ‚‹ๆœ€้ฉใช็”ป้ข่งฃๅƒๅบฆใฏใฉใ‚Œใใ‚‰ใ„ใงใ™ใ‹๏ผŸ

4Kใฎ็”Ÿ็”ปๅƒใ‚’ใใฎใพใพๅ…ฅๅŠ›ใ™ใ‚‹ใจใƒˆใƒผใ‚ฏใƒณๆถˆ่ฒปใจๆŽจ่ซ–ใƒฌใ‚คใƒ†ใƒณใ‚ทใŒๆฟ€ๅข—ใ—ใพใ™ใ€‚ๆœฌ็•ช็’ฐๅขƒใงใฏ1920x1080ใงใ‚ญใƒฃใƒ—ใƒใƒฃใ—ใ€ใƒขใƒ‡ใƒซๅ†…้ƒจใฎ1000x1000ๆญฃ่ฆๅŒ–ใ‚ฐใƒชใƒƒใƒ‰ใงๅˆคๆ–ญใ•ใ›ใŸๅพŒใ€็‰ฉ็†ใƒ”ใ‚ฏใ‚ปใƒซใธใจๆ•ฐๅญฆ็š„ใซใ‚นใ‚ฑใƒผใƒชใƒณใ‚ฐๅค‰ๆ›ใ—ใฆใ‚ฏใƒชใƒƒใ‚ฏใ‚’็™บ่กŒใ™ใ‚‹ใฎใŒไธ€่ˆฌ็š„ใงใ™ใ€‚

Q3: ใ‚ขใƒ—ใƒชใฎๅ‹•็š„ใƒญใƒผใƒ‡ใ‚ฃใƒณใ‚ฐใ‚„ใ‚ขใƒ‹ใƒกใƒผใ‚ทใƒงใƒณใฏใฉใฎใ‚ˆใ†ใซๅพ…ๆฉŸใ—ใพใ™ใ‹๏ผŸ

ใƒ–ใƒฉใ‚ฆใ‚ถใจ็•ฐใชใ‚Šใƒ‡ใ‚นใ‚ฏใƒˆใƒƒใƒ—ใซใฏใƒญใƒผใƒ‰ๅฎŒไบ†้€š็Ÿฅใ‚คใƒ™ใƒณใƒˆใŒใ‚ใ‚Šใพใ›ใ‚“ใ€‚ๆœฌ็•ชใ‚จใƒผใ‚ธใ‚งใƒณใƒˆใฏ่ฆ–่ฆšๅทฎๅˆ†ใƒใƒผใƒชใƒณใ‚ฐ๏ผˆVisual Delta Polling๏ผ‰ใ‚’ๆŽก็”จใ—ใ€250ใƒŸใƒช็ง’้–“้š”ใงใƒ•ใƒฌใƒผใƒ ใ‚’ๅ–ๅพ—ใ—ใฆใƒ”ใ‚ฏใ‚ปใƒซๅค‰ๅ‹•็އใŒ1%ๆœชๆบ€ใซๅฎ‰ๅฎšใ—ใŸใ“ใจใ‚’็ขบ่ชใ—ใฆใ‹ใ‚‰ๆฌกใฎๆ“ไฝœใ‚’ๅฎŸ่กŒใ—ใพใ™ใ€‚

Q4: ใƒžใƒซใƒใƒขใƒ‹ใ‚ฟใƒผใ‚„่ค‡ๆ•ฐใ‚ฆใ‚ฃใƒณใƒ‰ใ‚ฆ็’ฐๅขƒใงใ‚‚ๅ‹•ไฝœใ—ใพใ™ใ‹๏ผŸ

ใฏใ„ใ€ๅ‹•ไฝœใ—ใพใ™ใ€‚่ค‡ๆ•ฐ็”ป้ขใ‚’1ใคใฎ็ตๅˆใ‚ญใƒฃใƒณใƒใ‚น๏ผˆ3840x1080ใชใฉ๏ผ‰ใจใ—ใฆๆ‰ฑใ†ใ‹ใ€ใ‚ฆใ‚ฃใƒณใƒ‰ใ‚ฆใƒ•ใ‚ฉใƒผใ‚ซใ‚นAPIใ‚’ๆดป็”จใ—ใฆๅฏพ่ฑกใ‚ขใƒ—ใƒชใ‚’ใƒกใ‚คใƒณไปฎๆƒณใƒ‡ใ‚ฃใ‚นใƒ—ใƒฌใ‚คใซใ‚ขใ‚ฏใƒ†ใ‚ฃใƒ–ๅŒ–ใ—ใฆใ‹ใ‚‰่ฆ–่ฆš่ช่ญ˜ใ‚’่กŒใ†ๆง‹ๆˆใ‚’ใจใ‚Šใพใ™ใ€‚

Q5: UI-TARSใฏใƒญใƒผใ‚ซใƒซใฎไธ€่ˆฌ็š„ใชPC็’ฐๅขƒใงๅ‹•ใ‹ใ›ใพใ™ใ‹๏ผŸ

UI-TARS 7Bใƒขใƒ‡ใƒซใฏใ€GGUFใ‚„AWQใชใฉใฎ้‡ๅญๅŒ–ใ‚’่กŒใ†ใ“ใจใงใ€Apple Siliconๆญ่ผ‰Mac๏ผˆใƒฆใƒ‹ใƒ•ใ‚กใ‚คใƒ‰ใƒกใƒขใƒช32GBไปฅไธŠ๏ผ‰ใ‚„NVIDIA RTX 4090ๅ˜ไฝ“ใงใ‚‚ใƒญใƒผใ‚ซใƒซๅ‹•ไฝœๅฏ่ƒฝใงใ™ใ€‚72Bใƒขใƒ‡ใƒซใฏไผๆฅญๅ‘ใ‘ใฎA100/H100ใ‚ฏใƒฉใ‚นใฎGPU็’ฐๅขƒใŒๆŽจๅฅจใ•ใ‚Œใพใ™ใ€‚

ูˆูƒู„ุงุก ุณุทุญ ุงู„ู…ูƒุชุจ ูˆู†ุธู… ุงู„ุชุดุบูŠู„ ู†ู…ุงุฐุฌ VLA ู…ุชุนุฏุฏุฉ ุงู„ูˆุณุงุฆุท ุณุจุชู…ุจุฑ 2026 ยท ู‚ุฑุงุกุฉ ุชุณุชุบุฑู‚ 18 ุฏู‚ูŠู‚ุฉ

ู…ุง ุจุนุฏ ุงู„ู…ุชุตูุญ: ุจู†ุงุก ูˆูƒู„ุงุก ูˆุงุฌู‡ุงุช ุณุทุญ ุงู„ู…ูƒุชุจ ุงู„ู…ุณุชู‚ู„ุฉ ููŠ 2026 ุจุงุณุชุฎุฏุงู… UI-TARS ูˆ Claude Computer Use ูˆ OSWorld 2.0

ุฎู„ุงู„ ุงู„ุณู†ูˆุงุช ุงู„ุซู„ุงุซ ุงู„ู…ุงุถูŠุฉุŒ ุฑูƒู‘ุฒุช ู…ู†ุธูˆู…ุฉ ุงู„ุฐูƒุงุก ุงู„ุงุตุทู†ุงุนูŠ ุจุดูƒู„ ู…ูƒุซู ุนู„ู‰ ุฃุชู…ุชุฉ ู…ุชุตูุญุงุช ุงู„ูˆูŠุจ ุจุงุณุชุฎุฏุงู… ุฃุฏูˆุงุช ู…ุซู„ Browser-Use ูˆ Stagehand ูˆ Playwright MCP ู„ุชุญู„ูŠู„ ุดุฌุฑุฉ ูƒุงุฆู†ุงุช ุงู„ู…ุชุตูุญ (DOM). ูˆู…ุน ุฐู„ูƒุŒ ูุฅู† ุฃูƒุซุฑ ู…ู† 70% ู…ู† ุชุฏูู‚ุงุช ุงู„ุนู…ู„ ููŠ ุจุฑู…ุฌูŠุงุช ุงู„ู…ุคุณุณุงุช ู„ุง ุชุนู…ู„ ุฅุทู„ุงู‚ุงู‹ ุฏุงุฎู„ ู…ุชุตูุญ ูˆูŠุจ. ูู†ุธู… ุชุฎุทูŠุท ุงู„ู…ูˆุงุฑุฏ ุงู„ู…ุคุณุณูŠุฉ ุงู„ู‚ุฏูŠู…ุฉ (ู…ุซู„ ูˆุงุฌู‡ุฉ SAP GUI)ุŒ ูˆู…ุตู†ูุงุช Excel ุงู„ุฃุตู„ูŠุฉ ุงู„ู…ุถู…ู†ุฉ ุจู…ุงูƒุฑูˆ VBAุŒ ูˆุจุฑู…ุฌูŠุงุช ุงู„ุชุตู…ูŠู… ุงู„ู‡ู†ุฏุณูŠ CADุŒ ูˆู†ูˆุงูุฐ ุงู„ุฃูˆุงู…ุฑ ุงู„ุทุฑููŠุฉุŒ ูˆุงู„ุนู…ู„ุงุก ุงู„ู…ูƒุชุจูŠูˆู† ุงู„ุฃุตู„ูŠูˆู† ู„ุง ูŠู…ุชู„ูƒูˆู† ุฃูŠ ุจู†ูŠุฉ DOM. ูˆุนู†ุฏู…ุง ุชุฑุณู… ู†ุธู… ุงู„ุชุดุบูŠู„ ูˆุงุฌู‡ุงุชู‡ุง ู…ุจุงุดุฑุฉ ุนุจุฑ DirectX ุฃูˆ Metal ุฃูˆ Win32 ุฃูˆ QtุŒ ูŠุตุจุญ ุงู„ูˆูƒู„ุงุก ุงู„ู…ุนุชู…ุฏูˆู† ุนู„ู‰ DOM ุนุงุฌุฒูŠู† ุชู…ุงู…ุงู‹. ูˆู„ุชุญู‚ูŠู‚ ุฃุชู…ุชุฉ ู…ุคุณุณูŠุฉ ุญู‚ูŠู‚ูŠุฉุŒ ูŠุดู‡ุฏ ุนุงู… 2026 ุจุฒูˆุบ ูˆูƒู„ุงุก ูˆุงุฌู‡ุงุช ุณุทุญ ุงู„ู…ูƒุชุจ ุงู„ู…ุณุชู‚ู„ูŠู† (Autonomous Desktop GUI Agents) ุงู„ู…ุฏุนูˆู…ูŠู† ุจู†ู…ุงุฐุฌ ุงู„ุนู…ู„ ุงู„ู„ุบูˆูŠ ุงู„ุจุตุฑูŠ ุงู„ุชุฃุณูŠุณูŠุฉ (VLA)ุŒ ูˆุชุญุฏูŠุฏ ุฅุญุฏุงุซูŠุงุช ุงู„ุจูƒุณู„ุŒ ูˆุงู„ุชููƒูŠุฑ ุงู„ุชุฃู…ู„ูŠ ุงู„ู…ุชุฃู†ูŠ (System-2). ูŠุญู„ู„ ู‡ุฐุง ุงู„ุฏู„ูŠู„ ุงู„ู…ุนู…ุงุฑูŠ ุงู„ุนู…ูŠู‚ ู†ู…ุงุฐุฌ UI-TARS 1.5ุŒ ูˆ Claude 3.7 Computer UseุŒ ูˆู…ุนูŠุงุฑ OSWorld 2.0ุŒ ูˆุจูŠุฆุงุช ุงู„ุนุฒู„ ุงู„ุขู…ู†ุฉ ููŠ ุจูŠุฆุงุช ุงู„ุฅู†ุชุงุฌ.

๐Ÿ“‘ ุฌุฏูˆู„ ุงู„ู…ุญุชูˆูŠุงุช

1. ุงู„ู…ู„ุฎุต ุงู„ุณุฑูŠุน ูˆุขูุงู‚ ูˆุงุฌู‡ุงุช ุณุทุญ ุงู„ู…ูƒุชุจ 2. ู†ู‡ุงูŠุฉ ุงู„ุชุจุนูŠุฉ ู„ู€ DOM: ุฃู‡ู…ูŠุฉ ุชุฏูู‚ุงุช ุงู„ุนู…ู„ ุงู„ู…ูƒุชุจูŠุฉ 3. ุงู„ุจู†ู‰ ุงู„ุซู„ุงุซ ู„ู„ุฅุฏุฑุงูƒ ุงู„ุจุตุฑูŠ ุนู„ู‰ ุณุทุญ ุงู„ู…ูƒุชุจ 4. ู†ู…ูˆุฐุฌ UI-TARS: ู‚ุฏุฑุงุช VLA ุงู„ุฃุตูŠู„ุฉ ูˆุชููƒูŠุฑ System-2 5. ู…ูˆุงุฒู†ุฉ Claude 3.7 Computer Use ู…ู‚ุงุจู„ ุงู„ู†ู…ุงุฐุฌ ุงู„ู…ูุชูˆุญุฉ 6. ุงู„ุชุทุจูŠู‚ ุงู„ุนู…ู„ูŠ ุจู„ุบุฉ Python: ู…ุชุญูƒู… ุณุทุญ ู…ูƒุชุจ ุขู…ู† 7. ุชู‚ูŠูŠู… OSWorld 2.0: ุญู„ ู…ุดูƒู„ุฉ ุงู†ุญุฑุงู ุงู„ู…ู‡ุงู… ุงู„ุทูˆูŠู„ุฉ 8. ุงู„ุฃู…ุงู† ูˆุจูŠุฆุงุช ุงู„ุนุฒู„: ุนุฒู„ VNC ูˆุฒุฑ ุงู„ุฅูŠู‚ุงู ุงู„ุทุงุฑุฆ 9. ู…ุตููˆูุฉ ุงู„ู…ู‚ุงุฑู†ุฉ ุงู„ู…ุนู…ุงุฑูŠุฉ ูˆุงู„ุฃุฏูˆุงุช ุงู„ู…ุฑุชุจุทุฉ 10. ุงู„ุฃุณุฆู„ุฉ ุงู„ุดุงุฆุนุฉ (FAQ)

01. ุงู„ู…ู„ุฎุต ุงู„ุณุฑูŠุน ูˆุขูุงู‚ ูˆุงุฌู‡ุงุช ุณุทุญ ุงู„ู…ูƒุชุจ

ุจู„ุบุช ุฃุชู…ุชุฉ ุงู„ูˆูŠุจ ู…ุฑุญู„ุฉ ุงู„ู†ุถุฌุŒ ู„ูƒู† ุงู„ุนู…ู„ ุงู„ู…ุนุฑููŠ ุนู„ู‰ ุฃุฌู‡ุฒุฉ ุณุทุญ ุงู„ู…ูƒุชุจ ุธู„ ู…ุนุชู…ุฏุงู‹ ุนู„ู‰ ุงู„ุฌู‡ุฏ ุงู„ูŠุฏูˆูŠ. ููŠ ุนุงู… 2026ุŒ ูŠุชุนุงู…ู„ ูˆูƒู„ุงุก ูˆุงุฌู‡ุงุช ุณุทุญ ุงู„ู…ูƒุชุจ ู…ุน ุดุงุดุฉ ุงู„ุญุงุณูˆุจ ุจุฃูƒู…ู„ู‡ุง ูƒู„ูˆุญุฉ ุชูุงุนู„ูŠุฉ ู…ุจุงุดุฑุฉ:

  • ู…ุง ูˆุฑุงุก ู…ุญุฏุฏุงุช ุนู†ุงุตุฑ HTML: ูŠุฑุงู‚ุจ ูˆูƒู„ุงุก ุณุทุญ ุงู„ู…ูƒุชุจ ุฅุทุงุฑุงุช ุงู„ุดุงุดุฉ ุงู„ู…ุจุงุดุฑุฉ (ุจุฏู‚ุฉ ุชุชุฑุงูˆุญ ู…ู† 1080p ุฅู„ู‰ 4K)ุŒ ูˆูŠุชุนุฑููˆู† ุนู„ู‰ ุงู„ุนู†ุงุตุฑ ุงู„ุชูุงุนู„ูŠุฉ ู…ุจุงุดุฑุฉ ุนุจุฑ ุงู„ู†ู…ุงุฐุฌ ุงู„ู„ุบูˆูŠุฉ ุงู„ุจุตุฑูŠุฉ ุงู„ูƒุจูŠุฑุฉ (MLLMs)ุŒ ู…ุน ุชุญูˆูŠู„ ุงู„ุงุณุชุฏู„ุงู„ ุฅู„ู‰ ุฅุญุฏุงุซูŠุงุช ู‚ูŠุงุณูŠุฉ ู…ูุนุงูŠุฑุฉ (x, y) ุชูุชุฑุฌู… ู„ุฃุญุฏุงุซ ูุฃุฑุฉ ูˆู„ูˆุญุฉ ู…ูุงุชูŠุญ ุญู‚ูŠู‚ูŠุฉ.
  • ุฑูŠุงุฏุฉ ุงู„ู…ุตุฏุฑ ุงู„ู…ูุชูˆุญ ู…ู‚ุงุจู„ ูˆุงุฌู‡ุงุช ุงู„ุจุฑู…ุฌุฉ ุงู„ู…ุบู„ู‚ุฉ: ู‚ุฏู… ู†ู…ูˆุฐุฌ UI-TARS 1.5 ู…ูุชูˆุญ ุงู„ุฃูˆุฒุงู† ู…ู† ByteDance ุจู†ูŠุฉ ุชููƒูŠุฑ System-2 ุฃุตูŠู„ุฉ ู…ุฏุนูˆู…ุฉ ุจุงู„ุชุนู„ู… ุงู„ุชุนุฒูŠุฒูŠ ู„ู„ุชุฃู…ู„ ุงู„ุฐุงุชูŠ ูˆุงู„ุชุฑุงุฌุน ุนู† ุงู„ุฃุฎุทุงุกุŒ ููŠ ุญูŠู† ูŠู‚ุฏู… Claude 3.7 Sonnet ู…ู† Anthropic ู‚ุฏุฑุงุช ุชููƒูŠุฑ ุนู„ูŠุง ูˆุงุณุชุฏุนุงุกู‹ ุฃุตูŠู„ุงู‹ ู„ุฃุฏูˆุงุช ุงู„ุชุญูƒู… ุจุงู„ุญุงุณูˆุจ (Computer Use).
  • ุงุฎุชุจุงุฑ ุงู„ูˆุงู‚ุน ุนุจุฑ ู…ุนูŠุงุฑ OSWorld 2.0: ุนู„ู‰ ู…ุนูŠุงุฑ OSWorld 2.0 ุงู„ุฐูŠ ูŠุถู… 369 ู…ู‡ู…ุฉ ูˆุงู‚ุนูŠุฉ ู…ุนู‚ุฏุฉ ุนุจุฑ ุฃู†ุธู…ุฉ Ubuntu ูˆ Windows ูˆ macOSุŒ ุชุญู‚ู‚ ุงู„ู†ู…ุงุฐุฌ ู…ุนุฏู„ ู†ุฌุงุญ ุจูŠู† 42% ุฅู„ู‰ 52% ููŠ ุงู„ู…ู‡ุงู… ุงู„ู…ู…ุชุฏุฉ ู„ุฃูƒุซุฑ ู…ู† 100 ุฎุทูˆุฉุŒ ู…ู…ุง ูŠุจุฑุฒ ุฃู† "ุงู†ุญุฑุงู ุงู„ุญุงู„ุฉ ุงู„ุชุฑุงูƒู…ูŠ" ูŠู…ุซู„ ุงู„ุนุงุฆู‚ ุงู„ู‡ู†ุฏุณูŠ ุงู„ุฃูƒุจุฑ.
  • ุงู„ุนุฒู„ ุงู„ุฅู„ุฒุงู…ูŠ ููŠ ุจูŠุฆุงุช ุงู„ุชุดุบูŠู„: ุชุชุทู„ุจ ุงู„ุณูŠุทุฑุฉ ุงู„ู…ุจุงุดุฑุฉ ุนู„ู‰ ู†ุธุงู… ุงู„ุชุดุบูŠู„ ู‡ู†ุฏุณุฉ ุงู†ุนุฏุงู… ุงู„ุซู‚ุฉ (Zero-Trust). ูˆุชุนู…ู„ ุจู†ู‰ ุงู„ุฅู†ุชุงุฌ ุนู„ู‰ ุชุดุบูŠู„ ุงู„ูˆูƒู„ุงุก ุฏุงุฎู„ ุฃุฌู‡ุฒุฉ ุงูุชุฑุงุถูŠุฉ ุฎููŠูุฉ ู…ุนุฒูˆู„ุฉ (MicroVMs ู…ุซู„ E2B) ุฃูˆ ุนุจุฑ ุดุงุดุงุช ุงูุชุฑุงุถูŠุฉ (VNC/RDP) ู…ุฏุนูˆู…ุฉ ุจุฌุฏุฑุงู† ุญู…ุงูŠุฉ ู„ู…ู†ุน ุงู„ุฃูˆุงู…ุฑ ุงู„ุชุฎุฑูŠุจูŠุฉ ูˆุฒุฑ ุฅูŠู‚ุงู ุทุงุฑุฆ ู„ู„ุจุดุฑ.
+โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€+
|               Autonomous Desktop GUI Agent Architecture (2026)              |
|                                                                             |
|  [ User Goal: "Consolidate Q3 SAP exports into Excel macro, generate PDF" ] |
|                                     โ”‚                                       |
|                                     โ–ผ                                       |
|  โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”  |
|  โ”‚ HOST SUPERVISOR & ACTION FIREWALL (Safety Interceptor)                โ”‚  |
|  โ”‚  - Rate Limiting & Egress Filtering    - Destructive Command Blocker  โ”‚  |
|  โ”‚  - Biometric Confirmation Gateway      - Emergency Human Kill-Switch  โ”‚  |
|  โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜  |
|                                     โ”‚ Virtual Display / Peripherals         |
|                                     โ–ผ                                       |
|  โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”  |
|  โ”‚ ISOLATED DESKTOP SANDBOX (E2B / Cloud VNC / KVM Virtual Machine)      โ”‚  |
|  โ”‚                                                                       โ”‚  |
|  โ”‚   โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”               โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”   โ”‚  |
|  โ”‚   โ”‚ Screenshot Buffer   โ”‚               โ”‚ OS Input Controller     โ”‚   โ”‚  |
|  โ”‚   โ”‚ (1920x1080 RGB)     โ”‚               โ”‚ (PyAutoGUI / uinput)    โ”‚   โ”‚  |
|  โ”‚   โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜               โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ–ฒโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜   โ”‚  |
|  โ”‚              โ”‚ Raw Frame                              โ”‚ (x, y) Click  โ”‚  |
|  โ”‚              โ–ผ                                        โ”‚ & Hotkeys     โ”‚  |
|  โ”‚   โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ดโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”   โ”‚  |
|  โ”‚   โ”‚ AGENT RUNTIME: UI-TARS 1.5 / Claude 3.7 Sonnet                โ”‚   โ”‚  |
|  โ”‚   โ”‚  1. Visual Grounding: Detect target UI elements via pixels    โ”‚   โ”‚  |
|  โ”‚   โ”‚  2. System-2 Deliberation: Check milestones & reflect         โ”‚   โ”‚  |
|  โ”‚   โ”‚  3. Action Plan: Emit precise mouse, click, and key sequences โ”‚   โ”‚  |
|  โ”‚   โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜   โ”‚  |
|  โ”‚                                                                       โ”‚  |
|  โ”‚   [ Legacy SAP Client ]       [ Native Excel ]       [ Desktop CAD ]  โ”‚  |
|  โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜  |
+โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€+

02. ู†ู‡ุงูŠุฉ ุงู„ุชุจุนูŠุฉ ู„ู€ DOM: ุฃู‡ู…ูŠุฉ ุชุฏูู‚ุงุช ุงู„ุนู…ู„ ุงู„ู…ูƒุชุจูŠุฉ ููŠ ุงู„ู…ุคุณุณุงุช

ุชูุชุฑุถ ุฃุทุฑ ุนู…ู„ ุฃุชู…ุชุฉ ุงู„ู…ุชุตูุญุงุช ุฃู† ุงู„ุชุทุจูŠู‚ุงุช ุชุชูŠุญ ุฏุงุฆู…ุงู‹ ุฃุดุฌุงุฑ ูˆุตูˆู„ ู…ู†ุธู…ุฉ (Accessibility Trees)ุŒ ูˆู…ุญุฏุฏุงุช CSS ุฏู‚ูŠู‚ุฉุŒ ูˆู‡ูŠูƒู„ูŠุฉ ู…ุชูˆู‚ุนุฉ ู„ู„ุนู†ุงุตุฑ. ูˆููŠ ู‚ุทุงุน ุงู„ุนู…ู„ูŠุงุช ุงู„ู…ุคุณุณูŠุฉ ุงู„ุญุณุงุณุฉุŒ ูŠู†ู‡ุงุฑ ู‡ุฐุง ุงู„ุงูุชุฑุงุถ ูƒู„ูŠุงู‹ ู„ุนุฏุฉ ุฃุณุจุงุจ:

1. ุชุทุจูŠู‚ุงุช ุงู„ูˆูŠุจ ุงู„ู…ุฑุณูˆู…ุฉ ุนู„ู‰ Canvas

ุชุฑุณู… ุฃุฏูˆุงุช ู…ุซู„ Figma ูˆู…ุญุฑุฑ ู…ุณุชู†ุฏุงุช Google ุงู„ู…ุณุชู†ุฏ ุฅู„ู‰ Canvas ูˆู„ูˆุญุงุช ุชุญูƒู… WebGL ุนู†ุงุตุฑู‡ุง ุฏุงุฎู„ ุณูŠุงู‚ ุฑุณูˆู…ูŠ ู…ุณุทุญ ุฏูˆู† ุฃูŠ ุนู†ุงุตุฑ DOM ูุนู„ูŠุฉ.

2. ุงู„ุจุฑู…ุฌูŠุงุช ุงู„ู…ุคุณุณูŠุฉ ุงู„ู‚ุฏูŠู…ุฉ

ุงู„ุฃู†ุธู…ุฉ ุงู„ุญูŠูˆูŠุฉ ู…ุซู„ SAP GUI ูˆู…ุญุงูƒูŠุงุช ุดุงุดุงุช AS400 ูˆู…ุญุทุงุช ุจู„ูˆู…ุจุฑุบ ูˆุฃู†ุธู…ุฉ ุงู„ุณุฌู„ุงุช ุงู„ุทุจูŠุฉ ุชุนู…ู„ ูƒู…ู„ูุงุช ุชู†ููŠุฐูŠุฉ ุซู†ุงุฆูŠุฉ ุฏูˆู† ุฃูŠ ูˆุงุฌู‡ุงุช ูˆูŠุจ.

3. ุณู„ุงุณู„ ุงู„ุนู…ู„ ุงู„ุนุงุจุฑุฉ ู„ู„ุชุทุจูŠู‚ุงุช

ุชุชุทู„ุจ ุงู„ู…ู‡ุงู… ุชู†ุฒูŠู„ ุจูŠุงู†ุงุชุŒ ูˆุชุดุบูŠู„ ู…ุงูƒุฑูˆ Excel ู…ุญู„ูŠุŒ ูˆุชุญุฏูŠุซ ุจุฑุงู…ุฌ ุฅุฏุงุฑุฉ ุงู„ุนู…ู„ุงุก ุงู„ู…ูƒุชุจูŠุฉุŒ ูˆุชูˆู‚ูŠุน ู…ู„ูุงุช PDF ุนุจุฑ ุญุฏูˆุฏ ุงู„ุชุทุจูŠู‚ุงุช ูˆู†ุธุงู… ุงู„ุชุดุบูŠู„.

03. ุงู„ุจู†ู‰ ุงู„ุซู„ุงุซ ู„ู„ุฅุฏุฑุงูƒ ุงู„ุจุตุฑูŠ ุนู„ู‰ ุณุทุญ ุงู„ู…ูƒุชุจ

ูƒูŠู ูŠู…ูƒู† ู„ู„ูˆูƒูŠู„ ุงู„ู…ุณุชู‚ู„ ุฃู† ูŠุฏุฑูƒ ุจุฏู‚ุฉ ู…ุง ู‡ูˆ ู…ุนุฑูˆุถ ุนู„ู‰ ุดุงุดุฉ ุณุทุญ ุงู„ู…ูƒุชุจุŸ ุชุชู†ุงูุณ ุซู„ุงุซ ู…ุฏุงุฑุณ ู…ุนู…ุงุฑูŠุฉ ุฑุฆูŠุณูŠุฉ ููŠ ุนุงู… 2026:

+โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€+
|                     Desktop Perception Paradigms                            |
|                                                                             |
|  [ Approach 1: Pure Visual Grounding (Pixel-to-Coordinate) ]               |
|    Screen Frame โ”€โ”€โ–ถ High-Res VLM โ”€โ”€โ–ถ Coordinates (x: 450, y: 720)           |
|    โ€ข Pros: Universal, zero OS dependency, handles Canvas / Games / Legacy    |
|    โ€ข Cons: Heavy token cost, coordinate distortion, resolution scaling drift|
|                                                                             |
|  [ Approach 2: OS Accessibility Tree Grounding (UIAutomation / AT-SPI) ]    |
|    Screen State โ”€โ”€โ–ถ OS API Walk โ”€โ”€โ–ถ Filtered Hierarchy โ”€โ”€โ–ถ Element ID / Path|
|    โ€ข Pros: Deterministic, lightweight text tokens, 100% click precision     |
|    โ€ข Cons: 40% of native apps have broken/missing a11y trees, slow tree walk|
|                                                                             |
|  [ Approach 3: Dual-Stream Hybrid Fusion (2026 Best Practice) ]             |
|    Visual Screenshot (VLM) โ—„โ”€โ”€Fused Decisionโ”€โ”€โ–บ OS A11y Tree (Cache)        |
|    โ€ข Fast path: Use A11y node bounding box if recognized                    |
|    โ€ข Fallback: Use visual grounding when a11y nodes are obscured/custom     |
+โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€+
ุงู„ู…ุนูŠุงุฑ ุงู„ู…ุนู…ุงุฑูŠ ุงู„ุฅุฏุฑุงูƒ ุงู„ุจุตุฑูŠ ุงู„ุฎุงู„ุต (Pixel) ุดุฌุฑุฉ ุฅู…ูƒุงู†ูŠุฉ ุงู„ูˆุตูˆู„ (A11y Tree) ุงู„ุฏู…ุฌ ุงู„ู‡ุฌูŠู† ุซู†ุงุฆูŠ ุงู„ู…ุณุงุฑ (Hybrid)
ุงู„ุดู…ูˆู„ูŠุฉ ูˆุชูˆุงูู‚ ุงู„ูˆุงุฌู‡ุงุช 100% (ุฃูŠ ุจูƒุณู„ ูŠูุนุฑุถ ุนู„ู‰ ุงู„ุดุงุดุฉ) ~60% (ูŠูุดู„ ู…ุน ุงู„ูˆุงุฌู‡ุงุช ุงู„ู…ุฎุตุตุฉ ูˆ Canvas) 98% (ุชุญูˆูŠู„ ุณู„ุณ ูˆุชู„ู‚ุงุฆูŠ ุนู†ุฏ ุงู„ุชุนุฐุฑ)
ูƒูุงุกุฉ ุงุณุชู‡ู„ุงูƒ ุงู„ุฑู…ูˆุฒ ู…ู†ุฎูุถุฉ (~1,200 ุฅู„ู‰ 2,000 ุฑู…ุฒ ู„ูƒู„ ุฅุทุงุฑ) ู…ุฑุชูุนุฉ (~300 ุฅู„ู‰ 600 ุฑู…ุฒ ู„ูƒู„ ุดุฌุฑุฉ) ู…ุชูˆุณุทุฉ (~1,500 ุฑู…ุฒ ู„ูƒู„ ู‚ุฑุงุฑ)
ุฏู‚ุฉ ุงู„ู†ู‚ุฑ ูˆุงู„ุงุณุชู‡ุฏุงู 88% - 94% (ู…ุนุฑุถุฉ ู„ู„ุงู†ุญุฑุงู) 99% (ุนู†ุฏ ุชูˆูุฑ ุนู‚ุฏ ุงู„ุดุฌุฑุฉ) 98.5% (ุชุซุจูŠุช ุฏู‚ูŠู‚ ุฏุงุฎู„ ุงู„ุฅุทุงุฑ)
ุงุณุชู‚ู„ุงู„ูŠุฉ ู†ุธุงู… ุงู„ุชุดุบูŠู„ ูƒุงู…ู„ุฉ (ู…ุชูˆุงูู‚ ู…ุน VNC ูˆุงู„ุจุซ ุงู„ุงูุชุฑุงุถูŠ) ู…ู†ุฎูุถุฉ (ุชุชุทู„ุจ ุฎุทุงูุงุช ุจุฑู…ุฌูŠุฉ ู„ูƒู„ ู†ุธุงู…) ุนุงู„ูŠุฉ (ู…ุญูˆู„ุงุช ู†ุธุงู… ุชุดุบูŠู„ ู†ู…ุทูŠุฉ)
ุฒู…ู† ุงุณุชุฌุงุจุฉ ุงู„ุฎุทูˆุฉ 1.8 ุซุงู†ูŠุฉ - 3.5 ุซุงู†ูŠุฉ (ุงุณุชุฏู„ุงู„ VLM) 0.4 ุซุงู†ูŠุฉ - 0.9 ุซุงู†ูŠุฉ (ู†ู…ูˆุฐุฌ ู†ุตูŠ) 1.9 ุซุงู†ูŠุฉ - 3.2 ุซุงู†ูŠุฉ

04. ู†ู…ูˆุฐุฌ UI-TARS: ู‚ุฏุฑุงุช VLA ุงู„ุฃุตูŠู„ุฉ ูˆุชููƒูŠุฑ System-2

ูŠูุนุฏ ู†ู…ูˆุฐุฌ UI-TARS 1.5 ุงู„ู…ุทูˆุฑ ู…ู† ู‚ูุจู„ ByteDance ุฅู†ุฌุงุฒุงู‹ ู†ูˆุนูŠุงู‹ ููŠ ู…ุฌุงู„ ู†ู…ุงุฐุฌ ุงู„ุนู…ู„ ุงู„ู„ุบูˆูŠ ุงู„ุจุตุฑูŠ ุงู„ุชุฃุณูŠุณูŠุฉ (VLA). ูุจูŠู†ู…ุง ูƒุงู†ุช ุงู„ู†ู…ุงุฐุฌ ุงู„ุณุงุจู‚ุฉ ุชู„ุชู‚ุท ุงู„ุดุงุดุฉ ูˆุชุทู„ู‚ ู†ู‚ุฑุฉ ููˆุฑูŠุฉ ุจู†ู…ุท ุญุฏุณูŠ ุณุฑูŠุน (System-1)ุŒ ูŠุฏู…ุฌ UI-TARS ุจู†ูŠุฉ ุชููƒูŠุฑ ู…ุชุฃู†ูŠุฉ ุฎุงุถุนุฉ ู„ุชุฏุฑูŠุจ ุจุงู„ุชุนู„ู… ุงู„ุชุนุฒูŠุฒูŠ (Reinforcement Learning):

+โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€+
|                UI-TARS 1.5 System-2 Reasoning Trajectory                     |
|                                                                             |
|  Observation โ”€โ”€โ–ถ [ Reflection & Verification ]                              |
|                   โ”‚ "Did the previous action open the File dialog?"          |
|                   โ”‚ State: YES. Detected 'Open File' window at (x: 200, y: 150)
|                   โ–ผ                                                         |
|                 [ Sub-goal Decomposition ]                                  |
|                   โ”‚ "Next sub-goal: Select 'Quarterly_Report.xlsx'"         |
|                   โ”‚ Search Strategy: Visual scan of table rows              |
|                   โ–ผ                                                         |
|                 [ Milestone Recognition ]                                   |
|                   โ”‚ Target element found at (x: 320, y: 410)                |
|                   โ–ผ                                                         |
|                 [ Action Emission ]                                         |
|                   โ”‚ Action: click(point=[320, 410])                         |
|                   โ”‚ Post-Action Expectation: File selected in input box     |
+โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€+
  • ุฑู…ูˆุฒ ุญุฑูƒูŠุฉ ู‚ูŠุงุณูŠุฉ ู…ูˆุญุฏุฉ: ุฅุตุฏุงุฑ ู…ุจุงุดุฑ ู„ุฃูˆุงู…ุฑ ู…ุซู„ click(point=[x, y]) ูˆ double_click() ูˆ drag(start, end) ูˆ press_hotkey() ุนุจุฑ ู…ุณุชูˆู‰ ุฅุญุฏุงุซูŠุงุช ู…ูุนุงูŠุฑ 1000 × 1000.
  • ุชููƒูŠุฑ System-2 ุงู„ู…ุชุฃู†ูŠ: ุชู‚ูŠูŠู… ุญุงู„ุฉ ุงู„ุดุงุดุฉ ุงู„ุณุงุจู‚ุฉ ู‚ุจู„ ุงุชุฎุงุฐ ุฃูŠ ุฎุทูˆุฉ ุฌุฏูŠุฏุฉ. ูุฅุฐุง ูุดู„ุช ู†ู‚ุฑุฉ ุฒุฑ ููŠ ูุชุญ ู…ุฑุจุน ุงู„ุญูˆุงุฑุŒ ูŠุชุฃู…ู„ ุงู„ู†ู…ูˆุฐุฌ ุฎุทุฃู‡ ูˆูŠุตุญุญ ู…ุณุงุฑู‡ ุฐุงุชูŠุงู‹ ุจุฏู„ุงู‹ ู…ู† ู…ุฑุงูƒู…ุฉ ุงู„ุฃุฎุทุงุก.
  • ุฅู…ูƒุงู†ูŠุฉ ุงู„ู†ุดุฑ ูˆุงู„ุชุดุบูŠู„ ุงู„ู…ุญู„ูŠ: ูŠุนู…ู„ ู†ู…ูˆุฐุฌ UI-TARS 7B ู…ุญู„ูŠุงู‹ ุนู„ู‰ ู…ุญุทุงุช ุงู„ุนู…ู„ (ู…ุซู„ ุฃุฌู‡ุฒุฉ Mac ุจุฐุงูƒุฑุฉ 32GB ุฃูˆ ุจุทุงู‚ุฉ RTX 4090)ุŒ ู…ูˆูุฑุงู‹ ุงุณุชุฌุงุจุฉ ุฏูˆู† ุงู„ุซุงู†ูŠุฉ ู…ุน ุฎุตูˆุตูŠุฉ ุจูŠุงู†ุงุช ู…ุทู„ู‚ุฉ.

05. ู…ูˆุงุฒู†ุฉ Claude 3.7 Computer Use ู…ู‚ุงุจู„ ุงู„ู†ู…ุงุฐุฌ ู…ูุชูˆุญุฉ ุงู„ุฃูˆุฒุงู†

ุนู†ุฏ ุชุตู…ูŠู… ู…ู†ุธูˆู…ุฉ ุฃุชู…ุชุฉ ู…ูƒุชุจูŠุฉ ู…ุคุณุณูŠุฉุŒ ูŠูˆุงุฌู‡ ู…ู‡ู†ุฏุณูˆ ุงู„ุฐูƒุงุก ุงู„ุงุตุทู†ุงุนูŠ ุฎูŠุงุฑุงู‹ ุงุณุชุฑุงุชูŠุฌูŠุงู‹ ุจูŠู† ูˆุงุฌู‡ุฉ Claude 3.7 Computer Use ุงู„ุณุญุงุจูŠุฉ ู…ู† Anthropic ูˆุงู„ุญู„ูˆู„ ุฐุงุช ุงู„ุฃูˆุฒุงู† ุงู„ู…ูุชูˆุญุฉ ู…ุซู„ UI-TARS 7B/72B ูˆ OS-Atlas:

  • Claude 3.7 Computer Use: ูŠุชููˆู‚ ุจู‚ุฏุฑุงุช ุชููƒูŠุฑ ู…ู†ุทู‚ูŠ ุงุณุชุซู†ุงุฆูŠุฉุŒ ูˆูู‡ู… ุนู…ูŠู‚ ู„ู„ุชุนู„ูŠู…ุงุช ุงู„ู…ุนู‚ุฏุฉ ุงู„ู…ูƒูˆู†ุฉ ู…ู† ุตูุญุงุช ู…ุชุนุฏุฏุฉุŒ ูˆุฅุฏุงุฑุฉ ู…ุชู‚ุฏู…ุฉ ู„ู„ุณูŠุงู‚ ุงู„ู„ุบูˆูŠ. ูˆู…ุน ุฐู„ูƒุŒ ูู‡ูˆ ูŠุฑุณู„ ู„ู‚ุทุงุช ุดุงุดุฉ ูƒุงู…ู„ุฉ ุนุจุฑ ุงู„ุณุญุงุจุฉ (ู…ู…ุง ูŠุซูŠุฑ ู…ุฎุงูˆู ุงู„ุฎุตูˆุตูŠุฉ ูˆุงู„ุงู…ุชุซุงู„ ููŠ ุงู„ู‚ุทุงุนุงุช ุงู„ู…ุตุฑููŠุฉ ูˆุงู„ุตุญูŠุฉ)ุŒ ู…ุน ุชูƒู„ูุฉ ุฑู…ุฒูŠุฉ ู…ู„ุญูˆุธุฉ ูˆุฒู…ู† ูˆุตูˆู„ ุดุจูƒูŠ ูŠุจู„ุบ 2 ุฅู„ู‰ 4 ุซูˆุงู†ู ู„ูƒู„ ุฅุฌุฑุงุก.
  • UI-TARS ูˆุงู„ู†ู…ุงุฐุฌ ุงู„ู…ูุชูˆุญุฉ: ูŠู…ูƒู† ู†ุดุฑู‡ุง ุจุงู„ูƒุงู…ู„ ู…ุญู„ูŠุงู‹ ุฃูˆ ููŠ ุณุญุงุจุฉ ุฎุงุตุฉ ู…ุนุฒูˆู„ุฉ (VPC). ูˆุชูˆูุฑ ุชุญูƒู…ุงู‹ ู…ุทู„ู‚ุงู‹ ููŠ ุญู…ุงูŠุฉ ุงู„ุจูŠุงู†ุงุชุŒ ูˆุฏุนู…ุงู‹ ู„ุชุนุฏูŠู„ ุงู„ุฃูˆุฒุงู† (Fine-tuning) ุนู„ู‰ ุจุฑู…ุฌูŠุงุช ุงู„ุดุฑูƒุฉ ุงู„ุฏุงุฎู„ูŠุฉุŒ ูˆุฒู…ู† ุงุณุชุฌุงุจุฉ ูุงุฆู‚ ุงู„ุณุฑุนุฉ ุนุจุฑ ุจุทุงู‚ุงุช ุงู„ุญูˆุณุจุฉ ุงู„ู…ุญู„ูŠุฉ (0.8 ุฅู„ู‰ 1.5 ุซุงู†ูŠุฉ ู„ูƒู„ ุฎุทูˆุฉ).

06. ุงู„ุชุทุจูŠู‚ ุงู„ุนู…ู„ูŠ ุจู„ุบุฉ Python: ู…ุชุญูƒู… ุณุทุญ ู…ูƒุชุจ ุขู…ู†

ูŠูˆุถุญ ุงู„ูƒูˆุฏ ุงู„ุชุงู„ูŠ ุจู†ูŠุฉ ู‡ู†ุฏุณูŠุฉ ู…ุชูƒุงู…ู„ุฉ ูˆู‚ุงุจู„ุฉ ู„ู„ุชุดุบูŠู„ ุงู„ููˆุฑูŠ ู„ู…ุชุญูƒู… ูˆูƒูŠู„ ุณุทุญ ู…ูƒุชุจุŒ ูŠุฏู…ุฌ ู†ู…ุฐุฌุฉ ุฅุญุฏุงุซูŠุงุช VLAุŒ ูˆู…ุญุงุฐุงุฉ ุงู„ุดุงุดุฉุŒ ูˆุฌุฏุงุฑ ุญู…ุงูŠุฉ ุงุนุชุฑุงุถูŠ ู„ู…ู†ุน ุงู„ุฅุฌุฑุงุกุงุช ุงู„ุชุฎุฑูŠุจูŠุฉ ุฃูˆ ุงู„ุญุณุงุณุฉ ุฅู„ุง ุจู…ูˆุงูู‚ุฉ ุจุดุฑูŠุฉ ุตุฑูŠุญุฉ:

# Production Reference Implementation: Desktop GUI Agent Controller (2026)
# Demonstrates Vision-Language-Action Execution, Coordinate Normalization,
# Destructive Command Interception, and Human-in-the-Loop Safeguards.

import time
import math
from typing import Dict, Any, List, Tuple, Optional
from dataclasses import dataclass, field
from enum import Enum


# โ”€โ”€โ”€ 1. CORE DATA STRUCTURES & ACTIONS โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€

class ActionType(str, Enum):
    MOUSE_CLICK = "mouse_click"
    DOUBLE_CLICK = "double_click"
    HOTKEY = "hotkey"
    TYPE_TEXT = "type_text"
    TERMINAL_COMMAND = "terminal_command"
    WAIT = "wait"


@dataclass
class UIAction:
    action_type: ActionType
    coordinates: Optional[Tuple[int, int]] = None  # (x, y) on 1000x1000 normalized grid
    text_payload: Optional[str] = None
    hotkey_sequence: Optional[List[str]] = None
    thought_reasoning: str = ""
    is_destructive: bool = False


@dataclass
class ScreenDimensions:
    width: int
    height: int


# โ”€โ”€โ”€ 2. SAFETY INTERCEPTOR & GATEKEEPER โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€

class DesktopSafetyGatekeeper:
    """
    Host-side safety authority that validates actions before dispatching
    to real or virtual OS input peripherals.
    """
    DESTRUCTIVE_HOTKEYS = {("ctrl", "alt", "del"), ("cmd", "shift", "backspace")}
    DESTRUCTIVE_COMMANDS = ["rm -rf", "format", "drop database", "mkfs", "dd if="]

    def __init__(self, require_human_for_destructive: bool = True):
        self.require_human = require_human_for_destructive
        self.audit_log: List[Dict[str, Any]] = []

    def inspect_action(self, action: UIAction, human_approved: bool = False) -> Tuple[bool, str]:
        # 1. Inspect terminal/shell commands
        if action.action_type == ActionType.TERMINAL_COMMAND and action.text_payload:
            for pattern in self.DESTRUCTIVE_COMMANDS:
                if pattern in action.text_payload.lower():
                    action.is_destructive = True
                    if not human_approved:
                        return False, f"Blocked destructive terminal command pattern: '{pattern}'"

        # 2. Inspect high-risk hotkeys
        if action.action_type == ActionType.HOTKEY and action.hotkey_sequence:
            normalized_keys = tuple(sorted([k.lower() for k in action.hotkey_sequence]))
            for risk_keys in self.DESTRUCTIVE_HOTKEYS:
                if normalized_keys == tuple(sorted(risk_keys)):
                    action.is_destructive = True
                    if not human_approved:
                        return False, f"Blocked dangerous system hotkey: '{action.hotkey_sequence}'"

        # Log action to immutable audit trail
        self.audit_log.append({
            "timestamp": time.time(),
            "action": action.action_type.value,
            "coordinates": action.coordinates,
            "destructive": action.is_destructive,
            "approved": True
        })
        return True, "Action approved."


# โ”€โ”€โ”€ 3. PERIPHERAL ADAPTER & COORDINATE SCALER โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€

class OSPeripheralController:
    """
    Translates normalized model coordinates (1000x1000) to actual physical display pixels
    and dispatches low-level OS input events.
    """
    def __init__(self, display: ScreenDimensions):
        self.display = display

    def denormalize_coordinates(self, norm_x: int, norm_y: int) -> Tuple[int, int]:
        """Converts [0, 1000] model grid to [0, width] x [0, height]."""
        real_x = math.floor((norm_x / 1000.0) * self.display.width)
        real_y = math.floor((norm_y / 1000.0) * self.display.height)
        return real_x, real_y

    def execute_native_input(self, action: UIAction):
        if action.coordinates:
            rx, ry = self.denormalize_coordinates(*action.coordinates)
            print(f"๐Ÿ–ฑ๏ธ  [OS DRIVER] Moving cursor to ({rx}px, {ry}px) [Model: {action.coordinates}]")
        
        if action.action_type == ActionType.MOUSE_CLICK:
            print(f"โšก [OS DRIVER] Emitting LEFT_BUTTON_CLICK at ({rx}, {ry})")
        elif action.action_type == ActionType.DOUBLE_CLICK:
            print(f"โšก [OS DRIVER] Emitting DOUBLE_CLICK at ({rx}, {ry})")
        elif action.action_type == ActionType.HOTKEY:
            print(f"โŒจ๏ธ  [OS DRIVER] Emitting KEY_COMBINATION: {' + '.join(action.hotkey_sequence or [])}")
        elif action.action_type == ActionType.TYPE_TEXT:
            print(f"โŒจ๏ธ  [OS DRIVER] Typing string payload: \"{action.text_payload}\"")
        elif action.action_type == ActionType.TERMINAL_COMMAND:
            print(f"๐Ÿ–ฅ๏ธ  [OS DRIVER] Executing Shell Command: '{action.text_payload}'")


# โ”€โ”€โ”€ 4. AUTONOMOUS DESKTOP AGENT CONTROLLER โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€

class DesktopGUIAgent:
    """
    The orchestrator agent combining VLA decision logic, safety inspection,
    and OS input driver dispatch.
    """
    def __init__(self, display: ScreenDimensions, gatekeeper: DesktopSafetyGatekeeper):
        self.driver = OSPeripheralController(display)
        self.gatekeeper = gatekeeper

    def step(self, action: UIAction, human_confirmed: bool = False) -> Dict[str, Any]:
        print(f"\n๐Ÿง  [SYSTEM-2 REFLECTION] {action.thought_reasoning}")

        # Safety Check
        is_safe, reason = self.gatekeeper.inspect_action(action, human_approved=human_confirmed)
        if not is_safe:
            print(f"๐Ÿ›‘ [SAFETY INTERCEPT] Action Rejected: {reason}")
            return {"success": False, "reason": reason}

        # Dispatch
        self.driver.execute_native_input(action)
        return {"success": True, "reason": "Executed successfully"}


# โ”€โ”€โ”€ 5. RUNTIME VERIFICATION HARNESS โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€

if __name__ == "__main__":
    print("=" * 75)
    print("DEMO: AUTONOMOUS DESKTOP GUI AGENT SAFETY & GROUNDING CONTROLLER (2026)")
    print("=" * 75)

    # Initialize 1080p display and safety gatekeeper
    virtual_screen = ScreenDimensions(width=1920, height=1080)
    safety_shield = DesktopSafetyGatekeeper(require_human_for_destructive=True)
    agent = DesktopGUIAgent(display=virtual_screen, gatekeeper=safety_shield)

    # STEP 1: Safe Action - Navigate SAP Menu
    step1 = UIAction(
        action_type=ActionType.MOUSE_CLICK,
        coordinates=(180, 45),  # 1000x1000 normalized grid
        thought_reasoning="Milestone 1: Click 'Accounting' dropdown in SAP native menu bar."
    )
    agent.step(step1)

    # STEP 2: Safe Action - Type Transaction Code
    step2 = UIAction(
        action_type=ActionType.TYPE_TEXT,
        text_payload="FS10N",
        thought_reasoning="Milestone 2: Enter general ledger balance inquiry transaction code."
    )
    agent.step(step2)

    # STEP 3: Malicious / Accidental Destructive Step Intercepted
    step3_destructive = UIAction(
        action_type=ActionType.TERMINAL_COMMAND,
        text_payload="rm -rf /var/sap/data/*",
        thought_reasoning="Adversarial prompt injection attempt detected on unverified clipboard buffer."
    )
    print("\n[SCENARIO 1: Destructive Action Without Approval]")
    agent.step(step3_destructive, human_confirmed=False)

    # STEP 4: High-Risk Action With Human Biometric Approval
    print("\n[SCENARIO 2: Authorized High-Risk Action via Supervisor Approval]")
    agent.step(step3_destructive, human_confirmed=True)

    print("\n" + "=" * 75)
    print(f"Demonstration Complete. Total Audit Ledger Entries: {len(safety_shield.audit_log)}")
    print("=" * 75)

07. ุชู‚ูŠูŠู… OSWorld 2.0: ุญู„ ู…ุดูƒู„ุฉ ุงู†ุญุฑุงู ุงู„ู…ู‡ุงู… ุงู„ุทูˆูŠู„ุฉ

ูŠูุนุฏ ู…ุนูŠุงุฑ OSWorld 2.0 ุงู„ู…ุฑุฌุน ุงู„ู‚ูŠุงุณูŠ ุงู„ุนุงู„ู…ูŠ ุงู„ุฃูƒุซุฑ ู…ูˆุซูˆู‚ูŠุฉ ู„ุงุฎุชุจุงุฑ ูˆูƒู„ุงุก ุณุทุญ ุงู„ู…ูƒุชุจ ุงู„ู…ุณุชู‚ู„ูŠู† ุนุจุฑ 369 ู…ู‡ู…ุฉ ูˆุงู‚ุนูŠุฉ ููŠ Ubuntu ูˆ Windows ูˆ macOS. ูˆุจูŠู†ู…ุง ูŠุญู‚ู‚ ุงู„ุฃุฏุงุก ุงู„ุจุดุฑูŠ ู†ุณุจุฉ 88.3%ุŒ ุชุญู‚ู‚ ุฃุญุฏุซ ุงู„ู†ู…ุงุฐุฌ ู…ุง ุจูŠู† 49% ุฅู„ู‰ 52% ุฅุฌู…ุงู„ุงู‹ุŒ ูƒุงุดูุฉ ุนู† ุฃุฑุจุนุฉ ุฃู†ู…ุงุท ูุดู„ ุจู†ูŠูˆูŠุฉ:

  • ุงู†ุญุฑุงู ุงู„ุฏู‚ุฉ ูˆุงู„ุฅุญุฏุงุซูŠุงุช (Resolution & Coordinate Drift): ุชุคุฏูŠ ุงู„ู†ูˆุงูุฐ ุงู„ู…ู†ุจุซู‚ุฉ ุฃูˆ ุชุบูŠูŠุฑ ุฃุญุฌุงู… ุงู„ุดุงุดุงุช ุฅู„ู‰ ุฅุฒุงุญุฉ ุงู„ุฃู‡ุฏุงู ุจุจูƒุณู„ุงุช ู‚ู„ูŠู„ุฉุŒ ู…ู…ุง ูŠุณุจุจ ู†ู‚ุฑุงุช ุฎุงุทุฆุฉ ุนู„ู‰ ุฅุญุฏุงุซูŠุงุช ู‚ุฏูŠู…ุฉ.
  • ุฅุฌู‡ุงุฏ ู†ุงูุฐุฉ ุงู„ุณูŠุงู‚ (Context Window Fatigue): ูŠุคุฏูŠ ุงู„ุงุญุชูุงุธ ุจุฃูƒุซุฑ ู…ู† 60 ู„ู‚ุทุฉ ุดุงุดุฉ ูƒุงู…ู„ุฉ ุฅู„ู‰ ุชุฌุงูˆุฒ ุณูŠุงู‚ ุงู„ู†ู…ูˆุฐุฌ. ูˆุชู‚ูˆู… ุฃู†ุธู…ุฉ ุงู„ุฅู†ุชุงุฌ ุจุงุฎุชุฒุงู„ ุงู„ู„ู‚ุทุงุช ุงู„ู‚ุฏูŠู…ุฉ ููŠ ุณุฌู„ ู†ุตูŠ ู…ูˆุฌุฒ ู„ู„ุฃูุนุงู„.
  • ู…ุตุงุฆุฏ ุงู„ุชุญู…ูŠู„ ุงู„ุตุงู…ุช ูˆู…ุคุดุฑุงุช ุงู„ุงู†ุชุธุงุฑ (Silent Loading Traps): ู†ุธุฑุงู‹ ู„ุบูŠุงุจ ุฃุญุฏุงุซ ุงู„ู…ุชุตูุญ ู…ุซู„ networkidleุŒ ูŠู†ู‚ุฑ ุงู„ูˆูƒูŠู„ ุจุดูƒู„ ู…ุชูƒุฑุฑ ุฃุซู†ุงุก ุชุญู…ูŠู„ ุงู„ุชุทุจูŠู‚ ู…ุณุจุจุงู‹ ุชุนุทู„ ู…ุณุงุฑุงุช ุงู„ุนู…ู„. ูˆูŠุญู„ ุงุณุชุทู„ุงุน ุงู„ูุฑูˆู‚ ุงู„ุจุตุฑูŠุฉ ู‡ุฐู‡ ุงู„ู…ุนุถู„ุฉ.
  • ุงู„ุงุฑุชุจุงูƒ ููŠ ุงู„ูˆุงุฌู‡ุงุช ู…ู†ุฎูุถุฉ ุงู„ุชุจุงูŠู† (Low-Contrast UI Confusion): ููŠ ุงู„ูˆุงุฌู‡ุงุช ุงู„ุฏุงูƒู†ุฉ ู„ู„ุจุฑู…ุฌูŠุงุช ุงู„ู…ุคุณุณูŠุฉ ุฃูˆ ู…ุฎุทุทุงุช CAD ุงู„ุณู„ูƒูŠุฉุŒ ุชุฎู„ุท ุงู„ู†ู…ุงุฐุฌ ุจูŠู† ุฃูŠู‚ูˆู†ุงุช ุงู„ุฃุฏูˆุงุช ุงู„ู…ุชุดุงุจู‡ุฉ (ู…ุซู„ ุงู„ุญูุธ ู…ู‚ุงุจู„ ุงู„ุชุตุฏูŠุฑ).

08. ุงู„ุฃู…ุงู† ูˆุจูŠุฆุงุช ุงู„ุนุฒู„: ุนุฒู„ VNC ูˆุฒุฑ ุงู„ุฅูŠู‚ุงู ุงู„ุทุงุฑุฆ

ุฅู† ู…ู†ุญ ู†ู…ูˆุฐุฌ ุฐูƒุงุก ุงุตุทู†ุงุนูŠ ุณูŠุทุฑุฉ ุญุฑูƒูŠุฉ ูƒุงู…ู„ุฉ ุนู„ู‰ ู„ูˆุญุฉ ุงู„ู…ูุงุชูŠุญ ูˆุงู„ูุฃุฑุฉ ูŠู…ุซู„ ุฎุทุฑุงู‹ ุฃู…ู†ูŠุงู‹ ุฌุณูŠู…ุงู‹ ุฅู† ู„ู… ูŠูุญุงุท ุจุจูŠุฆุฉ ุนุฒู„ ู…ุญูƒู…ุฉ. ูˆุชุนุชู…ุฏ ุงู„ู…ู†ุดุขุช ุงู„ู…ุคุณุณูŠุฉ ุญุฒู…ุฉ ุนุฒู„ ุตุงุฑู…ุฉ ู‚ุงุฆู…ุฉ ุนู„ู‰ ู†ู…ูˆุฐุฌ ุงู†ุนุฏุงู… ุงู„ุซู‚ุฉ:

+โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€+
|               Zero-Trust Desktop Sandbox Containment Stack                  |
|                                                                             |
|  [ Enterprise Gateway ]                                                     |
|            โ”‚                                                                |
|            โ–ผ                                                                |
|  โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”  |
|  โ”‚ LAYER 1: VIRTUAL DISPLAY & PERIPHERAL ISOLATION                       โ”‚  |
|  โ”‚ - Headless X11 / Wayland / RDP virtual server                         โ”‚  |
|  โ”‚ - The agent NEVER touches physical user hardware                      โ”‚  |
|  โ”‚ - Video frame streamed via WebRTC / VNC buffer                        โ”‚  |
|  โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜  |
|                                     โ”‚                                       |
|                                     โ–ผ                                       |
|  โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”  |
|  โ”‚ LAYER 2: SYSTEM CALL INTERCEPTION & eBPF NETWORK EGRESS               โ”‚  |
|  โ”‚ - eBPF sensor intercepts dangerous POSIX syscalls (fork, execve, ptrace)โ”‚
|  โ”‚ - Network firewall restricts outbound traffic exclusively to whitelistโ”‚  |
|  โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜  |
|                                     โ”‚                                       |
|                                     โ–ผ                                       |
|  โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”  |
|  โ”‚ LAYER 3: SUPERVISOR KILL-SWITCH & USER TAKEOVER                       โ”‚  |
|  โ”‚ - User moves physical mouse โ”€โ”€โ–ถ Instant agent suspension (Kill-Switch)โ”‚  |
|  โ”‚ - Live action stream mirrored to supervisor dashboard                โ”‚  |
|  โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜  |
+โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€+
  • ุนุฒู„ ุงู„ุนุฑุถ ูˆุงู„ู…ู„ุญู‚ุงุช ุงู„ุงูุชุฑุงุถูŠุฉ: ู„ุง ูŠุชุตู„ ุงู„ูˆูƒูŠู„ ุฅุทู„ุงู‚ุงู‹ ุจู…ูƒูˆู†ุงุช ุงู„ุญุงุณูˆุจ ุงู„ูุนู„ูŠุฉุŒ ุจู„ ูŠุนู…ู„ ุฏุงุฎู„ ุฎุงุฏู… ุนุฑุถ ุงูุชุฑุงุถูŠ ู…ุซู„ Xvfb ุฃูˆ Wayland ุฃูˆ ุญุงูˆูŠุฉ VNC ู…ุนุฒูˆู„ุฉ.
  • ุงุนุชุฑุงุถ ู†ุฏุงุกุงุช ุงู„ู†ุธุงู… ุนุจุฑ eBPF: ูŠุชู… ุฑุตุฏ ูˆู…ู†ุน ุฃูŠ ุงุณุชุฏุนุงุกุงุช ู„ู†ุธุงู… ุงู„ุชุดุบูŠู„ ุชู‡ุฏู ู„ุชุนุฏูŠู„ ู…ู„ูุงุช ุงู„ู†ุธุงู… ุงู„ุญุณุงุณุฉ ุฃูˆ ุชุซุจูŠุช ุจุฑู…ุฌูŠุงุช ุบูŠุฑ ู…ุตุฑุญ ุจู‡ุง.
  • ุฒุฑ ุงู„ุฅูŠู‚ุงู ุงู„ุทุงุฑุฆ ุงู„ุจุดุฑูŠ (Hardware Kill-Switch): ุจู…ุฌุฑุฏ ุฃู† ูŠุญุฑูƒ ุงู„ู…ุณุชุฎุฏู… ุงู„ูุฃุฑุฉ ุงู„ู…ุงุฏูŠุฉ ุฃูˆ ูŠุถุบุท ุนู„ู‰ ู…ูุชุงุญ ุงู„ู‡ุฑูˆุจุŒ ูŠุชู… ุฅูŠู‚ุงู ุชุฏูู‚ ุฅุดุงุฑุงุช ุงู„ูˆูƒูŠู„ ููˆุฑุงู‹ ูˆุฅุนุงุฏุฉ ุงู„ุณูŠุทุฑุฉ ู„ู„ุจุดุฑ.

09. ู…ุตููˆูุฉ ุงู„ู…ู‚ุงุฑู†ุฉ ุงู„ู…ุนู…ุงุฑูŠุฉ ูˆุงู„ุฃุฏูˆุงุช ุงู„ู…ุฑุชุจุทุฉ

ูƒูŠู ุชุชู…ุงูŠุฒ ุฃุจุฑุฒ ุฃุทุฑ ุนู…ู„ ูˆูƒู„ุงุก ุณุทุญ ุงู„ู…ูƒุชุจ ูˆุงู„ุชุญูƒู… ุจุงู„ุญุงุณูˆุจ ููŠ ุนุงู… 2026ุŸ

ุงู„ู…ุนูŠุงุฑ ุงู„ู…ุนู…ุงุฑูŠ UI-TARS (ByteDance) Claude 3.7 Computer Use OpenHands ุจูŠุฆุฉ ุนุฒู„ E2B Desktop
ุทุจูŠุนุฉ ุงู„ู†ู…ูˆุฐุฌ ู…ูุชูˆุญ ุงู„ุฃูˆุฒุงู† (VLA 7B/72B) ูˆุงุฌู‡ุฉ ุจุฑู…ุฌุฉ ุณุญุงุจูŠุฉ ุฎุงุตุฉ ู…ู†ุณู‚ ู…ุชุนุฏุฏ ุงู„ู†ู…ุงุฐุฌ ุจูŠุฆุฉ ุชุดุบูŠู„ ุนุฒู„ ุจู†ูŠูˆูŠุฉ
ุงู„ุฅุฏุฑุงูƒ ุงู„ุฑุฆูŠุณูŠ ุจูƒุณู„ุงุช ุฎุงู… (System-2 VLA) ุจูƒุณู„ุงุช ุฎุงู… (Vision API) ู‡ุฌูŠู† (DOM + ุทุฑููŠุฉ + GUI) ู…ุฎุฒู† ุฅุทุงุฑุงุช ุดุงุดุฉ ุงูุชุฑุงุถูŠุฉ
ู†ู…ุท ุงู„ุงุณุชุถุงูุฉ ุงุณุชุถุงูุฉ ุฐุงุชูŠุฉ (ุจุทุงู‚ุงุช GPU ู…ุญู„ูŠุฉ) ุณุญุงุจูŠ ู…ุฏุงุฑ (Anthropic API) ุงุณุชุถุงูุฉ ุฐุงุชูŠุฉ / ุณุญุงุจูŠ ุณุญุงุจูŠ ู…ุฏุงุฑ / MicroVM
ุฏุนู… ู†ุธู… ุงู„ุชุดุบูŠู„ Windows, macOS, Linux, Android Windows, macOS, Ubuntu Linux, Docker, ุงู„ู…ุชุตูุญ Linux (Firecracker MicroVM)
ุญุงู„ุงุช ุงู„ุงุณุชุฎุฏุงู… ุงู„ู…ุณุชู‡ุฏูุฉ ุฃุชู…ุชุฉ ุงู„ุนู…ู„ูŠุงุช RPAุŒ ูˆุงุฎุชุจุงุฑ ุงู„ุฌูˆุฏุฉ ู…ู‡ุงู… ุงู„ุนู…ู„ ุงู„ู…ุนุฑููŠ ุงู„ู…ุนู‚ุฏุฉ ูˆูƒู„ุงุก ู‡ู†ุฏุณุฉ ุงู„ุจุฑู…ุฌูŠุงุช ุนุฒู„ ูˆุญู…ุงูŠุฉ ุชู†ููŠุฐ ุงู„ูˆูƒู„ุงุก
ุงู„ู…ุตุฏุฑ ุงู„ู…ูุชูˆุญ ู…ูุชูˆุญ ุงู„ู…ุตุฏุฑ ุจุงู„ูƒุงู…ู„ (100%) ู…ุบู„ู‚ ูˆุฎุงุต (Proprietary) ู…ูุชูˆุญ ุงู„ู…ุตุฏุฑ ุจุงู„ูƒุงู…ู„ (100%) ุญุฒู…ุฉ SDK ู…ูุชูˆุญุฉ / ุณุญุงุจุฉ ู…ุฏุงุฑุฉ

E2B

ุจูŠุฆุงุช ุนุฒู„ ุณุญุงุจูŠุฉ

ุจูŠุฆุงุช ุชุดุบูŠู„ ู…ุนุฒูˆู„ุฉ ูˆุณุฑูŠุนุฉ ู„ู„ุบุงูŠุฉ ุชุนุชู…ุฏ ุนู„ู‰ Firecracker MicroVMs ู„ุชุดุบูŠู„ ูƒูˆุฏ ุงู„ูˆูƒู„ุงุก ูˆุชุตูุญ ุงู„ุฃุณุทุญ ุงู„ู…ูƒุชุจูŠุฉ ุจุฃู…ุงู† ุชุงู… ูˆุฒู…ู† ุจุฏุก ูุงุฆู‚.

ุงุณุชูƒุดู ุฃุฏุงุฉ E2B โ†

Claude 3.7 Sonnet

ู†ู…ูˆุฐุฌ ุฑุงุฆุฏ

ุงู„ู†ู…ูˆุฐุฌ ุงู„ุงุณุชุฏู„ุงู„ูŠ ุงู„ู…ุชู‚ุฏู… ู…ู† Anthropic ุงู„ู…ุฒูˆุฏ ุจู‚ุฏุฑุงุช ุฃุตู„ูŠุฉ ู„ู„ุชุญูƒู… ุจุงู„ุญุงุณูˆุจ ูˆุฃุชู…ุชุฉ ูˆุงุฌู‡ุงุช ุณุทุญ ุงู„ู…ูƒุชุจ ูˆุงู„ู…ุชุตูุญ ุนุจุฑ ุฎุทูˆุงุช ู…ุชุนุฏุฏุฉ.

ุงุณุชูƒุดู Claude 3.7 Sonnet โ†

OpenHands

ู…ูุชูˆุญ ุงู„ู…ุตุฏุฑ

ุงู„ู…ู†ุตุฉ ุงู„ุฑุงุฆุฏุฉ ู…ูุชูˆุญุฉ ุงู„ู…ุตุฏุฑ ู„ุจู†ุงุก ูˆุชุดุบูŠู„ ูˆูƒู„ุงุก ุชุทูˆูŠุฑ ุงู„ุจุฑู…ุฌูŠุงุช ูˆุงู„ุชุญูƒู… ููŠ ู…ูˆุฌู‡ ุงู„ุฃูˆุงู…ุฑ ูˆุณุทุญ ุงู„ู…ูƒุชุจ ู…ุน ุฏุนู… ุงู„ู†ุดุฑ ุงู„ู…ุญู„ูŠ ุงู„ูƒุงู…ู„.

ุงุณุชูƒุดู OpenHands โ†

Devin

ู‡ู†ุฏุณุฉ ุจุฑู…ุฌูŠุฉ ู…ุณุชู‚ู„ุฉ

ุงู„ู…ุณุงุนุฏ ุงู„ู…ุณุชู‚ู„ ู„ู‡ู†ุฏุณุฉ ุงู„ุจุฑู…ุฌูŠุงุช ู…ู† Cognition ุงู„ู…ุฌู‡ุฒ ุจุจูŠุฆุฉ ุนู…ู„ ู…ุชูƒุงู…ู„ุฉ ุชุถู… ุงู„ู…ุชุตูุญ ูˆุงู„ุทุฑููŠุฉ ูˆู…ุณุงุญุฉ ุณุทุญ ุงู„ู…ูƒุชุจ ู„ุฅู†ุฌุงุฒ ุงู„ู…ุดุงุฑูŠุน ุงู„ู…ุนู‚ุฏุฉ.

ุงุณุชูƒุดู Devin โ†

10. ุงู„ุฃุณุฆู„ุฉ ุงู„ุดุงุฆุนุฉ (FAQ)

ุณ1: ู„ู…ุงุฐุง ู„ุง ู†ู‚ูˆู… ุจุจู†ุงุก ูˆุงุฌู‡ุงุช ุจุฑู…ุฌูŠุฉ ู…ุฎุตุตุฉ (APIs) ุจุฏู„ุงู‹ ู…ู† ุจู†ุงุก ูˆูƒู„ุงุก ูˆุงุฌู‡ุงุช ุณุทุญ ุงู„ู…ูƒุชุจุŸ

ููŠ ุงู„ูˆุถุน ุงู„ู…ุซุงู„ูŠุŒ ุชูˆูุฑ ุฌู…ูŠุน ุงู„ุชุทุจูŠู‚ุงุช ูˆุงุฌู‡ุงุช ุจุฑู…ุฌุฉ ูˆุงุถุญุฉ ูˆู…ูˆุซู‚ุฉ. ูˆู„ูƒู† ุนู…ู„ูŠุงู‹ุŒ ุชุญุชูˆูŠ ุจูŠุฆุงุช ุงู„ู…ุคุณุณุงุช ุนู„ู‰ ุขู„ุงู ุงู„ุจุฑู…ุฌูŠุงุช ุงู„ู‚ุฏูŠู…ุฉ (SAPุŒ ุงู„ุฃู†ุธู…ุฉ ุงู„ู…ุฑูƒุฒูŠุฉุŒ ุฃุฏูˆุงุช ุงู„ู…ุญุงุณุจุฉ ุงู„ู‚ุฏูŠู…ุฉ) ุญูŠุซ ูŠุชุทู„ุจ ุจู†ุงุก ูˆุงุฌู‡ุงุช API ู…ู„ุงูŠูŠู† ุงู„ุฏูˆู„ุงุฑุงุช ูˆุณู†ูˆุงุช ู…ู† ุฅุนุงุฏุฉ ุงู„ู‡ูŠูƒู„ุฉ. ูŠุชูŠุญ ูˆูƒู„ุงุก ูˆุงุฌู‡ุงุช ุณุทุญ ุงู„ู…ูƒุชุจ ุชูƒุงู…ู„ุงู‹ ููˆุฑูŠุงู‹ ุฏูˆู† ู„ู…ุณ ุงู„ุดูุฑุฉ ุงู„ู…ุตุฏุฑูŠุฉ ุฃูˆ ุชุนุฏูŠู„ ู‚ูˆุงุนุฏ ุงู„ุจูŠุงู†ุงุช ุงู„ุญุงู„ูŠุฉ.

ุณ2: ู…ุง ู‡ูŠ ุฏู‚ุฉ ุงู„ุดุงุดุฉ ุงู„ู…ู†ุงุณุจุฉ ู„ุชู…ุฑูŠุฑ ู„ู‚ุทุงุช ุงู„ุดุงุดุฉ ู„ูˆูƒูŠู„ ุจุตุฑูŠุŸ

ูŠุคุฏูŠ ุชู…ุฑูŠุฑ ู„ู‚ุทุงุช ุจุฏู‚ุฉ 4K ูƒุงู…ู„ุฉ ุฅู„ู‰ ุชุถุฎู… ูƒุจูŠุฑ ููŠ ุงุณุชู‡ู„ุงูƒ ุงู„ุฑู…ูˆุฒ ูˆุฒูŠุงุฏุฉ ุฒู…ู† ุงู„ุงุณุชุฌุงุจุฉ. ุชุนุชู…ุฏ ุงู„ุฃู†ุธู…ุฉ ุงู„ุฅู†ุชุงุฌูŠุฉ ุนู„ู‰ ุงู„ุชู‚ุงุท ุงู„ุดุงุดุฉ ุจุฏู‚ุฉ 1920x1080ุŒ ูˆู…ุนุงูŠุฑุฉ ุงู„ุฅุญุฏุงุซูŠุงุช ุฅู„ู‰ ุดุจูƒุฉ ู‚ูŠุงุณูŠุฉ ุฏุงุฎู„ูŠุฉ 1000x1000 ู„ู„ุงุณุชุฏู„ุงู„ุŒ ุซู… ุฅุนุงุฏุฉ ุฅุณู‚ุงุท ุงู„ุฅุญุฏุงุซูŠุงุช ุงู„ู†ุงุชุฌุฉ ุฑูŠุงุถูŠุงู‹ ุนู„ู‰ ุงู„ุจูƒุณู„ุงุช ุงู„ูุนู„ูŠุฉ ู„ู„ุดุงุดุฉ.

ุณ3: ูƒูŠู ูŠุชุนุงู…ู„ ูˆูƒู„ุงุก ุณุทุญ ุงู„ู…ูƒุชุจ ู…ุน ุงู„ุชุญู…ูŠู„ ุงู„ุฏูŠู†ุงู…ูŠูƒูŠ ู„ู„ูˆุงุฌู‡ุงุช ูˆุญุฑูƒุงุช ุงู„ุฑุณูˆู…ุŸ

ุนู„ู‰ ุนูƒุณ ู…ุชุตูุญุงุช ุงู„ูˆูŠุจ ุงู„ุชูŠ ุชุตุฏุฑ ุฃุญุฏุงุซ ู…ุซู„ DOMContentLoaded ุฃูˆ networkidleุŒ ู„ุง ุชูˆูุฑ ุจูŠุฆุฉ ุณุทุญ ุงู„ู…ูƒุชุจ ุชู†ุจูŠู‡ุงุช ุฃุตู„ูŠุฉ ุจุงูƒุชู…ุงู„ ุชุญู…ูŠู„ ุงู„ุชุทุจูŠู‚. ูŠุนุชู…ุฏ ุงู„ูˆูƒู„ุงุก ุงู„ู…ุชู‚ุฏู…ูˆู† ุนู„ู‰ ุงุณุชุทู„ุงุน ุงู„ูุฑูˆู‚ ุงู„ุจุตุฑูŠุฉ (Visual Delta Polling): ุงู„ุชู‚ุงุท ุฅุทุงุฑุงุช ูƒู„ 250 ู…ู„ู„ูŠ ุซุงู†ูŠุฉ ูˆุงู„ุชุฃูƒุฏ ู…ู† ุงู†ุฎูุงุถ ู…ุนุฏู„ ุชุบูŠุฑ ุงู„ุจูƒุณู„ุงุช ู„ุฃู‚ู„ ู…ู† 1% ู„ู„ุชุฃูƒุฏ ู…ู† ุงุณุชู‚ุฑุงุฑ ุงู„ุดุงุดุฉ ู‚ุจู„ ุงู„ุฎุทูˆุฉ ุงู„ุชุงู„ูŠุฉ.

ุณ4: ู‡ู„ ูŠู…ูƒู† ู„ูˆูƒู„ุงุก ุณุทุญ ุงู„ู…ูƒุชุจ ุงู„ุนู…ู„ ุนุจุฑ ุดุงุดุงุช ู…ุชุนุฏุฏุฉ ุฃูˆ ู†ูˆุงูุฐ ู…ุชุนุฏุฏุฉุŸ

ู†ุนู…. ูŠู…ูƒู† ู„ู…ุญุฑูƒุงุช ุชุฎุทูŠุท ุงู„ุฅุญุฏุงุซูŠุงุช ุฅู…ุง ู…ุนุงู…ู„ุฉ ุงู„ุดุงุดุงุช ุงู„ู…ุชุนุฏุฏุฉ ูƒู„ูˆุญุฉ ูˆุงุญุฏุฉ ู…ุฏู…ุฌุฉ (ู…ุซู„ 3840x1080) ุฃูˆ ุงุณุชุฎุฏุงู… ูˆุงุฌู‡ุงุช ู†ุธุงู… ุงู„ุชุดุบูŠู„ ู„ุชุฑูƒูŠุฒ ุงู„ู†ุงูุฐุฉ ุงู„ู…ุณุชู‡ุฏูุฉ ุนู„ู‰ ุงู„ุดุงุดุฉ ุงู„ุงูุชุฑุงุถูŠุฉ ุงู„ุฑุฆูŠุณูŠุฉ ู‚ุจู„ ุชู†ููŠุฐ ุฎุทูˆุฉ ุงู„ุฅุฏุฑุงูƒ ูˆุงู„ุงุณุชุฏู„ุงู„.

ุณ5: ู‡ู„ ูŠุณุชุทูŠุน ู†ู…ูˆุฐุฌ UI-TARS ุงู„ุนู…ู„ ู…ุญู„ูŠุงู‹ ุนู„ู‰ ุฃุฌู‡ุฒุฉ ุงู„ู…ุณุชู‡ู„ูƒูŠู†ุŸ

ูŠู…ูƒู† ู„ู†ู…ูˆุฐุฌ UI-TARS ุจุญุฌู… 7B ุงู„ุนู…ู„ ู…ุญู„ูŠุงู‹ ุนู„ู‰ ู…ุญุทุงุช ุงู„ุนู…ู„ ุงู„ุญุฏูŠุซุฉ (ู…ุซู„ ุฃุฌู‡ุฒุฉ Apple Silicon ุจุฐุงูƒุฑุฉ ู…ูˆุญุฏุฉ 32GB+ ุฃูˆ ุจุทุงู‚ุฉ NVIDIA RTX 4090) ุจุงุณุชุฎุฏุงู… ุชู†ุณูŠู‚ุงุช ุงู„ุชูƒู…ูŠู… ู…ุซู„ GGUF ุฃูˆ AWQ. ุฃู…ุง ู†ู…ูˆุฐุฌ 72B ููŠุชุทู„ุจ ุฎูˆุงุฏู… ุจู…ุณุฑุนุงุช A100/H100 ู„ุถู…ุงู† ุฒู…ู† ุงุณุชุฌุงุจุฉ ูŠู‚ู„ ุนู† ุซุงู†ูŠุฉ ูˆุงุญุฏุฉ.