Skip to content
Search
paperAugust 2026Unreviewed

MobileWorldSafety: Benchmarking GUI Agent Safety Against Environmental Injection Attacks in Android Apps

Sujin Chen, Lijun Li, Tianyi Du, Jing Shao

Abstract

LLM-powered GUI agents that autonomously operate smartphones are rapidly transitioning from research prototypes to early real-world deployment. However, because these agents routinely process untrusted environmental content, they are highly vulnerable to environmental injection attacks, which include indirect prompt injections and adversarial instructions. Such attacks can manipulate the behavior of agents without user awareness through diverse channels encountered in everyday mobile use. Despit

Categories

Framework mappings

MITRE ATLAS
  • AML.T0051LLM Prompt Injection

Suggested from the entry's categories.

Cite

@misc{chen2026mobileworldsafety,
  title = {{MobileWorldSafety: Benchmarking GUI Agent Safety Against Environmental Injection Attacks in Android Apps}},
  author = {Sujin Chen and Lijun Li and Tianyi Du and Jing Shao},
  year = {2026},
  month = aug,
  eprint = {2608.17659},
  archivePrefix = {arXiv},
  url = {https://arxiv.org/abs/2608.17659}
}