August 2026Unreviewed
MobileWorldSafety: Benchmarking GUI Agent Safety Against Environmental Injection Attacks in Android Apps
Sujin Chen, Lijun Li, Tianyi Du, Jing Shao
Abstract
LLM-powered GUI agents that autonomously operate smartphones are rapidly transitioning from research prototypes to early real-world deployment. However, because these agents routinely process untrusted environmental content, they are highly vulnerable to environmental injection attacks, which include indirect prompt injections and adversarial instructions. Such attacks can manipulate the behavior of agents without user awareness through diverse channels encountered in everyday mobile use. Despit
Categories
Framework mappings
OWASP Top 10 for LLM Applications
- LLM01Prompt Injection
MITRE ATLAS
- AML.T0051LLM Prompt Injection
Suggested from the entry's categories.
Cite
@misc{chen2026mobileworldsafety,
title = {{MobileWorldSafety: Benchmarking GUI Agent Safety Against Environmental Injection Attacks in Android Apps}},
author = {Sujin Chen and Lijun Li and Tianyi Du and Jing Shao},
year = {2026},
month = aug,
eprint = {2608.17659},
archivePrefix = {arXiv},
url = {https://arxiv.org/abs/2608.17659}
}