发表机构
Radboud University Nijmegen(奈梅亨拉德堡德大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
本文揭示安卓移动智能体框架因依赖未过滤的无障碍元数据,存在间接提示注入漏洞,经实证验证其攻击成功率达0.822,需强化零信任输入验证等安全措施。
AI 中文摘要
自主智能体的兴起代表着用户与移动设备交互方式的重大范式转变。MobileRun和Mobile-Use等框架可自主导航安卓应用并执行复杂的多步骤任务。为解释用户界面,这些框架主要依赖安卓无障碍(A11y)树,其次依赖视觉截图。本文中,我们证明这种对未经过滤的无障碍元数据及视觉输入的架构依赖,引入了间接提示注入的系统性漏洞。我们表明,对抗性提示可导致自主智能体放弃其原始目标、违反上下文边界并执行未授权的设备操作。我们的实证评估在视觉隐藏和完全暴露的攻击场景中均展示了目标劫持、上下文漂移和未授权操作。总体而言,MobileRun搭配Gemma4:31B的攻击成功率达到0.822,而Mobile-Use搭配Qwen3.6:35B虽将该比率降至0.150,但未消除上下文漂移或未授权操作。这些发现表明,当前移动智能体框架未能强制执行语义上下文边界,将被动环境文本视为可信指令。最后,我们提出此类攻击的分类法,并讨论在移动智能体架构中实施零信任输入验证、专用安全智能体及严格上下文隔离的必要性。
英文摘要
The rise of autonomous AI agents represents a major paradigm shift in how users interact with mobile devices. Frameworks such as MobileRun and Mobile-Use can autonomously navigate Android applications and execute complex multi-step tasks. To interpret user interfaces, these frameworks rely primarily on Android accessibility (A11y) trees and secondarily on visual screenshots. In this paper, we demonstrate that this architectural dependence on unsanitized accessibility metadata, together with visual input, introduces a systemic vulnerability to indirect prompt injection. We show that adversarial prompts can cause autonomous agents to abandon their original objectives, violate context boundaries, and perform unauthorized device actions. Our empirical evaluation demonstrates goal hijacking, context drift, and unauthorized actions across visually hidden and fully exposed attack scenarios. In aggregate, MobileRun reaches an attack success rate of 0.822 with Gemma4:31B, while Mobile-Use with Qwen3.6:35B reduces this to 0.150 but does not eliminate context drift or unauthorized actions. These findings reveal that current mobile agent frameworks fail to enforce semantic context boundaries, treating passive environmental text as trusted instructions. Finally, we present a taxonomy of these attacks and discuss the need for zero-trust input validation, dedicated security agents, and strict context isolation within mobile agent architectures.