arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2609.22724cs.CRcs.AI

MATE:基于合成驱动的轨迹学习实现策略感知的移动智能体安全审计

MATE: Policy-Aware Security Auditing for Mobile Agents via Synthesis-Driven Trajectory Learning

Changyue Jiang, Jiayi Wang, Xin Wen, Jiarun Dai, Geng Hong, Xudong Pan

首次发表
浏览论文内容

中文总结 AI 辅助

提出MATE,一种策略条件审计器,通过合成驱动轨迹学习编码轨迹与自然语言策略,实现细粒度安全审计,在MATEBench及真实设备上准确率超95%,优于先前方法20%以上。

中文摘要 AI 辅助

由基础模型驱动的移动智能体现在能够在真实设备上自动化执行复杂的多步骤工作流,但其轨迹可能违反特定应用的安全策略。现有的轨迹级防御依赖于大语言模型提示或刚性规则,因此无法支持跨应用和任务泛化的细粒度自然语言策略。在本工作中,我们提出了MATE,一个轻量级的策略条件审计器,它对智能体轨迹和自然语言安全策略进行编码,以判断轨迹是否违反给定策略并解释原因。将策略视为可编辑的文本而非固定的模型参数,使得MATE无需重新训练即可处理用户自定义和不断演化的需求。为构建MATE,我们从全球数百个流行应用中提取应用描述、工作流和策略,构建了一个知识库,并通过多阶段流水线合成了超过14万条语义逼真、策略条件的轨迹。我们进一步发布了MATEBench,一个轨迹级审计基准,包含两个合成子集和一个手动收集轨迹的真实世界子集。使用我们的合成驱动轨迹学习训练的模型在MATEBench上实现了超过95%的准确率,在外部安全基准上保持强劲性能,并在真实设备上对智谱AutoGLM和阿里巴巴Mobile-Agent的轨迹进行审计,准确率超过95%,比先前方法高出20%以上。MATE表明,对异构移动智能体进行实用的细粒度安全审计既可行又有效。

英文摘要

Mobile agents powered by foundation models now automate complex, multi-step workflows on real devices, but their trajectories can violate app-specific security policies. Existing trajectory-level defenses rely on LLM prompting or rigid rules, and thus fail to support fine-grained, natural-language policies that generalize across apps and tasks. In this work, we introduce MATE, a lightweight, policy-conditioned auditor that encodes both agent trajectories and natural-language security policies to determine whether a trajectory violates a given policy and to explain why. Treating policies as editable text rather than fixed model parameters allows MATE to handle user-defined and evolving requirements without retraining. To construct MATE, we build a knowledge base by extracting app descriptions, workflows, and policies from hundreds of popular mobile apps worldwide, and synthesizing over 140K semantically realistic, policy-conditioned trajectories with a multi-stage pipeline. We further release MATEBench, a trajectory-level auditing benchmark with two synthetic subsets and one real-world subset of manually collected trajectories. Models trained with our synthesis-driven trajectory learning achieve over 95% accuracy on MATEBench, retain strong performance on external safety benchmarks, and audit trajectories from Zhipu's AutoGLM and Alibaba's Mobile-Agent on real devices with over 95% accuracy, outperforming prior methods by over 20%. MATE shows that practical, fine-grained security auditing for heterogeneous mobile agents is both feasible and effective.

发表机构

  • Fudan University(复旦大学)
  • Shanghai Innovation Institute(上海创新研究院)

机构由 AI 辅助整理,请以论文原文为准。

补充信息

↑