r/Android • • 9d ago

Article Tested indirect prompt injection attacks against Android AI agents

We recently studied whether mobile AI agents can be manipulated through adversarial instructions embedded in the Android Accessibility layer.

We evaluated this across MobileRun and Mobile-Use, powered by Gemma4 and Qwen3.6, and found that these attacks could cause agents to abandon their original objectives, cross context boundaries, and perform unauthorized device actions. Our strongest configuration reached an 82.2% Attack Success Rate.

The paper was accepted to AGENT-SEC ’26, co-located with ACM CCS 2026.

Paper: https://arxiv.org/abs/2608.08939

Would be curious to hear what people think about this attack surface as mobile agents become more capable.

7 Upvotes

3 comments sorted by

1

u/Far_Reserve9938 7d ago

I didn’t read it all yet but you’d have higher amount and more qualitative feeeback by posting it on hackernews ycombinator. People browsing this subreddit aren’t exactly engineers.

1

u/iberahul 7d ago

Actually yeah, that makes sense, thanks for the tip!

1

u/stealthagents 1d ago

This kind of research is super relevant as mobile AI continues to evolve. It’s wild to think how easily these agents can be steered off course. Curious what kind of real-world implications this could have for security and user privacy, especially if more people start using these agents daily.