May 2026Unreviewed
MIRAGE: Context-Aware Prompt Injection against Mobile GUI Agents via User-Generated Content
Ruoqi Guo, Yi Liu, Gelei Deng, Yiheng Xiong, Yuekang Li, Ying Zhang, Leo Yu Zhang, Lida Zhao, Ji Jie, Yuxiao Lu
Abstract
Mobile graphical user interface (GUI) agents driven by vision-language models (VLMs) perceive the screen as rendered pixels and choose actions from what they see, so they cannot reliably separate trusted interface elements from user-generated content. We present MIRAGE (Mobile Injection of Realistic Adversarial GUI Examples), a pipeline that turns benign mobile screenshots into prompt-injection samples by placing attacker-controlled text into ordinary user-generated content regions, without modi
Categories
Framework mappings
OWASP Top 10 for LLM Applications
- LLM01Prompt Injection
MITRE ATLAS
- AML.T0051LLM Prompt Injection
Suggested from the entry's categories.
Cite
@misc{guo2026mirage,
title = {{MIRAGE: Context-Aware Prompt Injection against Mobile GUI Agents via User-Generated Content}},
author = {Ruoqi Guo and Yi Liu and Gelei Deng and Yiheng Xiong and Yuekang Li and Ying Zhang and Leo Yu Zhang and Lida Zhao and Ji Jie and Yuxiao Lu},
year = {2026},
month = may,
eprint = {2605.28116},
archivePrefix = {arXiv},
url = {https://arxiv.org/abs/2605.28116}
}