AI 中文总结
本文识别了第三方移动代理在屏幕感知和通道滥用方面的两种新攻击面,并设计了七种具体攻击,证明恶意应用可在无权限下劫持代理行为。
AI 中文摘要
由视觉语言模型驱动的第三方移动代理已成为自动化智能手机交互的有前景范式。这些代理作为高权限决策者,通过截图感知设备状态并借助VLM推理执行操作,改变了代理应用与环境(即其他应用或操作系统)的交互方式。相应地,这种转变引入了新的攻击面,或将良性的/无害的接口转化为可被利用的移动设备接口。在本文中,我们总结了第三方移动代理应用与通用应用在环境交互时的关键差异,分析了代理的安全态势,并识别出与通用移动应用相比的两个独特攻击面:屏幕感知攻击面(利用人类与机器视觉之间的差距)和误用通道攻击面(拦截或操纵代理的执行流水线)。我们设计并实现了七种具体攻击,从阈下文本注入、不可见像素区域利用到屏幕截图篡改和主机PC命令注入。我们对五种流行移动代理框架的评估表明,恶意应用可以劫持代理动作,并在无需任何权限的情况下实现任意命令执行,同时对用户保持视觉上不可区分。这些发现揭示了自主代理设计中的根本信任错配,并凸显了在多租户平台上开发感知感知安全模型的紧迫性。
英文摘要
Third-party mobile agents powered by Vision-Language Models (VLMs) have emerged as a promising paradigm for automating smartphone interactions. These agents act as high-privilege decision-makers, perceiving device states through screenshots and executing actions via VLM reasoning, transforming how an agent app interacts with the environment (i.e., other apps or the OS). Correspondingly, this transformation introduces new attack surfaces or transforms benign/harmless interfaces into exploitable ones for mobile devices. In this paper, we summarize key differences between third-party mobile agent apps and general apps when interacting with the environment, analyze the security posture of agents, and identify two unique attack surfaces compared to general mobile apps: the Screen Perception Attack Surface, which exploits the gap between human and machine vision, and the Misused Channel Attack Surface, which intercepts or manipulates the agent's execution pipeline. We design and implement seven concrete attacks, from subliminal text injection and invisible pixel zone exploitation to screenshot tampering and host PC command injection. Our evaluation of five popular mobile agent frameworks demonstrates that a malicious app can hijack agent actions and achieve arbitrary command execution even without any privilege permissions, while remaining visually indistinguishable to users. These findings reveal a fundamental trust mismatch in autonomous agent design and highlight the urgent need for perception-aware security models on multi-tenant platforms.