arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2608.17659cs.CRcs.AI

MobileWorldSafety:针对安卓应用中环境注入攻击的GUI智能体安全基准

MobileWorldSafety: Benchmarking GUI Agent Safety Against Environmental Injection Attacks in Android Apps

Sujin Chen, Lijun Li, Tianyi Du, Jing Shao

首次发表
浏览论文内容

中文总结 AI 辅助

该研究推出MobileWorldSafety基准,基于142个真实安卓应用风险任务评估6种GUI智能体,发现其对环境注入攻击的成功率达40.4%-66.9%,为相关研究奠定基础。

中文摘要 AI 辅助

由大语言模型(LLM)驱动的GUI智能体可自主操作智能手机,正迅速从研究原型过渡到早期实际部署阶段。但由于这类智能体通常会处理不可信的环境内容,它们极易遭受环境注入攻击,这类攻击包括间接提示注入和对抗性指令,可通过日常移动使用中遇到的各种渠道,在用户不知情的情况下操纵智能体的行为。尽管存在此类风险,现有基准通常无法覆盖日常用户场景,缺乏对移动设备上环境注入攻击下GUI智能体的系统评估。为填补这一空白,我们推出了MobileWorldSafety,一个基于真实安卓应用构建的包含142个风险任务的基准。针对每个任务,我们在最终系统状态上定义了可通过程序验证的风险指标,并采用两阶段流程评估结果:基于规则的验证处理明确的情况,而LLM裁决则对模糊情况进行判定。这一流程可区分安全故障与能力故障,实现客观且可重复的评估。对6个智能体(包括通用智能体和专用GUI智能体)的评估显示,所有智能体仍极易受到攻击,攻击成功率介于40.4%至66.9%之间。这些发现表明,当对抗性内容以普通移动上下文形式呈现时,当前智能体往往无法维持安全对齐。MobileWorldSafety为量化此类漏洞及推进稳健移动GUI智能体的研究提供了基础。

英文摘要

LLM-powered GUI agents that autonomously operate smartphones are rapidly transitioning from research prototypes to early real-world deployment. However, because these agents routinely process untrusted environmental content, they are highly vulnerable to environmental injection attacks, which include indirect prompt injections and adversarial instructions. Such attacks can manipulate the behavior of agents without user awareness through diverse channels encountered in everyday mobile use. Despite these risks, existing benchmarks often fail to capture everyday user scenarios, lacking a systematic evaluation of GUI agents under environmental injection attacks on mobile devices. To address this gap, we introduce MobileWorldSafety, a benchmark of 142 risk tasks built on real Android applications. For each task, we define a programmatically verifiable risk indicator over the final system state and evaluate outcomes with a two-stage pipeline: rule-based verification handles unambiguous cases, while an LLM judge adjudicates ambiguous ones. This distinguishes safety failures from capability failures and enables objective and reproducible assessment. Evaluations on six agents, including both general agents and specialized GUI agents, demonstrate that all agents remain highly vulnerable, with attack success rates ranging from 40.4% to 66.9%. These findings indicate that current agents often fail to maintain safety alignment when adversarial content is presented as ordinary mobile context. MobileWorldSafety provides a foundation for quantifying these vulnerabilities and advancing research on robust mobile GUI agents.

发表机构

  • Shanghai Artificial Intelligence Laboratory(上海人工智能实验室)

机构由 AI 辅助整理,请以论文原文为准。

↑