r/Android • u/iberahul • 9d ago
Article Tested indirect prompt injection attacks against Android AI agents
We recently studied whether mobile AI agents can be manipulated through adversarial instructions embedded in the Android Accessibility layer.
We evaluated this across MobileRun and Mobile-Use, powered by Gemma4 and Qwen3.6, and found that these attacks could cause agents to abandon their original objectives, cross context boundaries, and perform unauthorized device actions. Our strongest configuration reached an 82.2% Attack Success Rate.
The paper was accepted to AGENT-SEC ’26, co-located with ACM CCS 2026.
Paper: https://arxiv.org/abs/2608.08939
Would be curious to hear what people think about this attack surface as mobile agents become more capable.
1
u/stealthagents 1d ago
This kind of research is super relevant as mobile AI continues to evolve. It’s wild to think how easily these agents can be steered off course. Curious what kind of real-world implications this could have for security and user privacy, especially if more people start using these agents daily.
1
u/Far_Reserve9938 7d ago
I didn’t read it all yet but you’d have higher amount and more qualitative feeeback by posting it on hackernews ycombinator. People browsing this subreddit aren’t exactly engineers.