Measuring the Security of Mobile LLM Agents under Adversarial Prompts from Untrusted Third-Party Channels

Fuente: arXiv
Salvato in:
Dettagli Bibliografici
Autori principali: Du, Chenghao, Huang, Quanfeng, Tang, Tingxuan, Wang, Zihao, Nadkarni, Adwait, Xiao, Yue
Natura: Preprint
Pubblicazione: 2025
Soggetti:
Accesso online:
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866917063999619072
author Du, Chenghao
Huang, Quanfeng
Tang, Tingxuan
Wang, Zihao
Nadkarni, Adwait
Xiao, Yue
author_facet Du, Chenghao
Huang, Quanfeng
Tang, Tingxuan
Wang, Zihao
Nadkarni, Adwait
Xiao, Yue
contents Large Language Models (LLMs) have transformed software development, enabling AI-powered applications known as LLM-based agents that promise to automate tasks across diverse apps and workflows. Yet, the security implications of deploying such agents in adversarial mobile environments remain poorly understood. In this paper, we present the first systematic study of security risks in mobile LLM agents. We design and evaluate a suite of adversarial case studies, ranging from opportunistic manipulations such as pop-up advertisements to advanced, end-to-end workflows involving malware installation and cross-app data exfiltration. Our evaluation covers eight state-of-the-art mobile agents across three architectures, with over 2,000 adversarial and paired benign trials. The results reveal systemic vulnerabilities: low-barrier vectors such as fraudulent ads succeed with over 80% reliability, while even workflows requiring the circumvention of operating-system warnings, such as malware installation, are consistently completed by advanced multi-app agents. By mapping these attacks to the MITRE ATT&CK Mobile framework, we uncover novel privilege-escalation and persistence pathways unique to LLM-driven automation. Collectively, our findings provide the first end-to-end evidence that mobile LLM agents are exploitable in realistic adversarial settings, where untrusted third-party channels (e.g., ads, embedded webviews, cross-app notifications) are an inherent part of the mobile ecosystem.
format Preprint
id arxiv_https___arxiv_org_abs_2510_27140
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Measuring the Security of Mobile LLM Agents under Adversarial Prompts from Untrusted Third-Party Channels
Du, Chenghao
Huang, Quanfeng
Tang, Tingxuan
Wang, Zihao
Nadkarni, Adwait
Xiao, Yue
Cryptography and Security
Large Language Models (LLMs) have transformed software development, enabling AI-powered applications known as LLM-based agents that promise to automate tasks across diverse apps and workflows. Yet, the security implications of deploying such agents in adversarial mobile environments remain poorly understood. In this paper, we present the first systematic study of security risks in mobile LLM agents. We design and evaluate a suite of adversarial case studies, ranging from opportunistic manipulations such as pop-up advertisements to advanced, end-to-end workflows involving malware installation and cross-app data exfiltration. Our evaluation covers eight state-of-the-art mobile agents across three architectures, with over 2,000 adversarial and paired benign trials. The results reveal systemic vulnerabilities: low-barrier vectors such as fraudulent ads succeed with over 80% reliability, while even workflows requiring the circumvention of operating-system warnings, such as malware installation, are consistently completed by advanced multi-app agents. By mapping these attacks to the MITRE ATT&CK Mobile framework, we uncover novel privilege-escalation and persistence pathways unique to LLM-driven automation. Collectively, our findings provide the first end-to-end evidence that mobile LLM agents are exploitable in realistic adversarial settings, where untrusted third-party channels (e.g., ads, embedded webviews, cross-app notifications) are an inherent part of the mobile ecosystem.
title Measuring the Security of Mobile LLM Agents under Adversarial Prompts from Untrusted Third-Party Channels
topic Cryptography and Security
url https://arxiv.org/abs/2510.27140