{"id":"https://openalex.org/W4415346178","doi":"https://doi.org/10.1145/3745756.3809249","title":"Mobile GUI Agents under Real-world Threats: Are We There Yet?","display_name":"Mobile GUI Agents under Real-world Threats: Are We There Yet?","publication_year":2026,"publication_date":"2026-05-29","ids":{"openalex":"https://openalex.org/W4415346178","doi":"https://doi.org/10.1145/3745756.3809249"},"language":"en","primary_location":{"id":"doi:10.1145/3745756.3809249","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3745756.3809249","pdf_url":null,"source":null,"license":"cc-by-nc-nd","license_id":"https://openalex.org/licenses/cc-by-nc-nd","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 24th Annual International Conference on Mobile Systems, Applications and Services","raw_type":"proceedings-article"},"type":"article","indexed_in":["arxiv","crossref","datacite"],"open_access":{"is_oa":true,"oa_status":"gold","oa_url":"https://doi.org/10.1145/3745756.3809249","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5101888173","display_name":"Guohong Liu","orcid":"https://orcid.org/0000-0002-5959-8604"},"institutions":[{"id":"https://openalex.org/I99065089","display_name":"Tsinghua University","ror":"https://ror.org/03cve4549","country_code":"CN","type":"education","lineage":["https://openalex.org/I99065089"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Guohong Liu","raw_affiliation_strings":["Institute for AI Industry Research (AIR), Tsinghua University, Beijing, China"],"raw_orcid":"https://orcid.org/0000-0002-5959-8604","affiliations":[{"raw_affiliation_string":"Institute for AI Industry Research (AIR), Tsinghua University, Beijing, China","institution_ids":["https://openalex.org/I99065089"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5084436776","display_name":"Jialei Ye","orcid":null},"institutions":[{"id":"https://openalex.org/I150229711","display_name":"University of Electronic Science and Technology of China","ror":"https://ror.org/04qr3zq92","country_code":"CN","type":"education","lineage":["https://openalex.org/I150229711"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Jialei Ye","raw_affiliation_strings":["University of Electronic Science and Technology of China, Chengdu, China"],"raw_orcid":"https://orcid.org/0009-0009-2069-711X","affiliations":[{"raw_affiliation_string":"University of Electronic Science and Technology of China, Chengdu, China","institution_ids":["https://openalex.org/I150229711"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100656307","display_name":"Jiacheng Liu","orcid":"https://orcid.org/0000-0003-0378-2311"},"institutions":[{"id":"https://openalex.org/I20231570","display_name":"Peking University","ror":"https://ror.org/02v51f717","country_code":"CN","type":"education","lineage":["https://openalex.org/I20231570"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Jiacheng Liu","raw_affiliation_strings":["Peking University, Beijing, China"],"raw_orcid":"https://orcid.org/0009-0004-3759-6247","affiliations":[{"raw_affiliation_string":"Peking University, Beijing, China","institution_ids":["https://openalex.org/I20231570"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100628298","display_name":"Yuanchun Li","orcid":"https://orcid.org/0000-0002-1591-2526"},"institutions":[{"id":"https://openalex.org/I4210158522","display_name":"PLA Academy of Military Science","ror":"https://ror.org/05ct4s596","country_code":"CN","type":"facility","lineage":["https://openalex.org/I4210158522"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Wei Liu","raw_affiliation_strings":["MiLM Plus, Xiaomi Inc., Beijing, China"],"raw_orcid":"https://orcid.org/0009-0009-4327-1920","affiliations":[{"raw_affiliation_string":"MiLM Plus, Xiaomi Inc., Beijing, China","institution_ids":["https://openalex.org/I4210158522"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100641142","display_name":"Wei Liu","orcid":"https://orcid.org/0000-0002-7409-0948"},"institutions":[{"id":"https://openalex.org/I4210158522","display_name":"PLA Academy of Military Science","ror":"https://ror.org/05ct4s596","country_code":"CN","type":"facility","lineage":["https://openalex.org/I4210158522"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Pengzhi Gao","raw_affiliation_strings":["MiLM Plus, Xiaomi Inc., Beijing, China"],"raw_orcid":"https://orcid.org/0009-0009-9392-6657","affiliations":[{"raw_affiliation_string":"MiLM Plus, Xiaomi Inc., Beijing, China","institution_ids":["https://openalex.org/I4210158522"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5119805131","display_name":"Pengzhi Gao","orcid":null},"institutions":[{"id":"https://openalex.org/I4210158522","display_name":"PLA Academy of Military Science","ror":"https://ror.org/05ct4s596","country_code":"CN","type":"facility","lineage":["https://openalex.org/I4210158522"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Jian Luan","raw_affiliation_strings":["MiLM Plus, Xiaomi Inc., Beijing, China"],"raw_orcid":"https://orcid.org/0000-0002-2383-226X","affiliations":[{"raw_affiliation_string":"MiLM Plus, Xiaomi Inc., Beijing, China","institution_ids":["https://openalex.org/I4210158522"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5054843960","display_name":"Jian Luan","orcid":"https://orcid.org/0000-0002-2383-226X"},"institutions":[{"id":"https://openalex.org/I99065089","display_name":"Tsinghua University","ror":"https://ror.org/03cve4549","country_code":"CN","type":"education","lineage":["https://openalex.org/I99065089"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Yuanchun Li","raw_affiliation_strings":["Institute for AI Industry Research (AIR), Tsinghua University, Beijing, China"],"raw_orcid":"https://orcid.org/0000-0002-1591-2526","affiliations":[{"raw_affiliation_string":"Institute for AI Industry Research (AIR), Tsinghua University, Beijing, China","institution_ids":["https://openalex.org/I99065089"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5102880548","display_name":"Yunxin Liu","orcid":"https://orcid.org/0000-0001-7352-8955"},"institutions":[{"id":"https://openalex.org/I99065089","display_name":"Tsinghua University","ror":"https://ror.org/03cve4549","country_code":"CN","type":"education","lineage":["https://openalex.org/I99065089"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Yunxin Liu","raw_affiliation_strings":["Institute for AI Industry Research (AIR), Tsinghua University, Beijing, China"],"raw_orcid":"https://orcid.org/0000-0001-7352-8955","affiliations":[{"raw_affiliation_string":"Institute for AI Industry Research (AIR), Tsinghua University, Beijing, China","institution_ids":["https://openalex.org/I99065089"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":8,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":0.0,"has_fulltext":true,"cited_by_count":0,"citation_normalized_percentile":{"value":0.00688332,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":"960","last_page":"978"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T12203","display_name":"Mobile Agent-Based Network Management","score":0.9975000023841858,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T12203","display_name":"Mobile Agent-Based Network Management","score":0.9975000023841858,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10742","display_name":"Peer-to-Peer Network Technologies","score":0.9853000044822693,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10772","display_name":"Distributed systems and fault tolerance","score":0.968500018119812,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/benchmarking","display_name":"Benchmarking","score":0.654699981212616},{"id":"https://openalex.org/keywords/robustness","display_name":"Robustness (evolution)","score":0.5726000070571899},{"id":"https://openalex.org/keywords/suite","display_name":"Suite","score":0.538100004196167},{"id":"https://openalex.org/keywords/benchmark","display_name":"Benchmark (surveying)","score":0.45019999146461487},{"id":"https://openalex.org/keywords/task","display_name":"Task (project management)","score":0.4399000108242035},{"id":"https://openalex.org/keywords/mobile-device","display_name":"Mobile device","score":0.41670000553131104},{"id":"https://openalex.org/keywords/scalability","display_name":"Scalability","score":0.40310001373291016},{"id":"https://openalex.org/keywords/resilience","display_name":"Resilience (materials science)","score":0.39480000734329224},{"id":"https://openalex.org/keywords/safer","display_name":"SAFER","score":0.37599998712539673}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.765999972820282},{"id":"https://openalex.org/C86251818","wikidata":"https://www.wikidata.org/wiki/Q816754","display_name":"Benchmarking","level":2,"score":0.654699981212616},{"id":"https://openalex.org/C63479239","wikidata":"https://www.wikidata.org/wiki/Q7353546","display_name":"Robustness (evolution)","level":3,"score":0.5726000070571899},{"id":"https://openalex.org/C79581498","wikidata":"https://www.wikidata.org/wiki/Q1367530","display_name":"Suite","level":2,"score":0.538100004196167},{"id":"https://openalex.org/C185798385","wikidata":"https://www.wikidata.org/wiki/Q1161707","display_name":"Benchmark (surveying)","level":2,"score":0.45019999146461487},{"id":"https://openalex.org/C2780451532","wikidata":"https://www.wikidata.org/wiki/Q759676","display_name":"Task (project management)","level":2,"score":0.4399000108242035},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.4300000071525574},{"id":"https://openalex.org/C186967261","wikidata":"https://www.wikidata.org/wiki/Q5082128","display_name":"Mobile device","level":2,"score":0.41670000553131104},{"id":"https://openalex.org/C107457646","wikidata":"https://www.wikidata.org/wiki/Q207434","display_name":"Human\u2013computer interaction","level":1,"score":0.4049000144004822},{"id":"https://openalex.org/C48044578","wikidata":"https://www.wikidata.org/wiki/Q727490","display_name":"Scalability","level":2,"score":0.40310001373291016},{"id":"https://openalex.org/C2779585090","wikidata":"https://www.wikidata.org/wiki/Q3457762","display_name":"Resilience (materials science)","level":2,"score":0.39480000734329224},{"id":"https://openalex.org/C2776654903","wikidata":"https://www.wikidata.org/wiki/Q2601463","display_name":"SAFER","level":2,"score":0.37599998712539673},{"id":"https://openalex.org/C43126263","wikidata":"https://www.wikidata.org/wiki/Q128751","display_name":"Source code","level":2,"score":0.361299991607666},{"id":"https://openalex.org/C144543869","wikidata":"https://www.wikidata.org/wiki/Q2738570","display_name":"Mobile computing","level":2,"score":0.3427000045776367},{"id":"https://openalex.org/C97686452","wikidata":"https://www.wikidata.org/wiki/Q7604153","display_name":"Static analysis","level":2,"score":0.3368000090122223},{"id":"https://openalex.org/C115903868","wikidata":"https://www.wikidata.org/wiki/Q80993","display_name":"Software engineering","level":1,"score":0.30239999294281006},{"id":"https://openalex.org/C2779903281","wikidata":"https://www.wikidata.org/wiki/Q6888026","display_name":"Modalities","level":2,"score":0.29750001430511475},{"id":"https://openalex.org/C26760741","wikidata":"https://www.wikidata.org/wiki/Q160402","display_name":"Perception","level":2,"score":0.2969000041484833},{"id":"https://openalex.org/C51929080","wikidata":"https://www.wikidata.org/wiki/Q2425187","display_name":"Codebase","level":3,"score":0.2946999967098236},{"id":"https://openalex.org/C136764020","wikidata":"https://www.wikidata.org/wiki/Q466","display_name":"World Wide Web","level":1,"score":0.29330000281333923},{"id":"https://openalex.org/C2776760102","wikidata":"https://www.wikidata.org/wiki/Q5139990","display_name":"Code (set theory)","level":3,"score":0.28139999508857727},{"id":"https://openalex.org/C2777615720","wikidata":"https://www.wikidata.org/wiki/Q11888847","display_name":"Prioritization","level":2,"score":0.2770000100135803},{"id":"https://openalex.org/C95713431","wikidata":"https://www.wikidata.org/wiki/Q631425","display_name":"Vulnerability (computing)","level":2,"score":0.27489998936653137},{"id":"https://openalex.org/C201025465","wikidata":"https://www.wikidata.org/wiki/Q11248500","display_name":"User experience design","level":2,"score":0.2671000063419342},{"id":"https://openalex.org/C557433098","wikidata":"https://www.wikidata.org/wiki/Q94","display_name":"Android (operating system)","level":2,"score":0.25189998745918274},{"id":"https://openalex.org/C91262260","wikidata":"https://www.wikidata.org/wiki/Q528074","display_name":"End user","level":2,"score":0.2517000138759613},{"id":"https://openalex.org/C140547941","wikidata":"https://www.wikidata.org/wiki/Q7797194","display_name":"Threat model","level":2,"score":0.2502000033855438}],"mesh":[],"locations_count":4,"locations":[{"id":"doi:10.1145/3745756.3809249","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3745756.3809249","pdf_url":null,"source":null,"license":"cc-by-nc-nd","license_id":"https://openalex.org/licenses/cc-by-nc-nd","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 24th Annual International Conference on Mobile Systems, Applications and Services","raw_type":"proceedings-article"},{"id":"pmh:oai:arXiv.org:2507.04227","is_oa":true,"landing_page_url":"http://arxiv.org/abs/2507.04227","pdf_url":"https://arxiv.org/pdf/2507.04227","source":{"id":"https://openalex.org/S4393918464","display_name":"ArXiv.org","issn_l":"2331-8422","issn":["2331-8422"],"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"text"},{"id":"pmh:oai:arXiv.org:2507.04227","is_oa":true,"landing_page_url":"https://arxiv.org/abs/2507.04227","pdf_url":"https://arxiv.org/pdf/2507.04227","source":{"id":"https://openalex.org/S4393918464","display_name":"ArXiv.org","issn_l":"2331-8422","issn":["2331-8422"],"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by-nc-nd","license_id":"https://openalex.org/licenses/cc-by-nc-nd","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"text"},{"id":"doi:10.48550/arxiv.2507.04227","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2507.04227","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":null,"raw_source_name":null,"raw_type":"article"}],"best_oa_location":{"id":"doi:10.1145/3745756.3809249","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3745756.3809249","pdf_url":null,"source":null,"license":"cc-by-nc-nd","license_id":"https://openalex.org/licenses/cc-by-nc-nd","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 24th Annual International Conference on Mobile Systems, Applications and Services","raw_type":"proceedings-article"},"sustainable_development_goals":[],"awards":[{"id":"https://openalex.org/G4968693648","display_name":null,"funder_award_id":"62272261","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"},{"id":"https://openalex.org/G6396942078","display_name":null,"funder_award_id":"20242001120","funder_id":"https://openalex.org/F4320322392","funder_display_name":"Tsinghua University"}],"funders":[{"id":"https://openalex.org/F4320321001","display_name":"National Natural Science Foundation of China","ror":"https://ror.org/01h0zpd94"},{"id":"https://openalex.org/F4320322392","display_name":"Tsinghua University","ror":"https://ror.org/03cve4549"}],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":0,"referenced_works":[],"related_works":[],"abstract_inverted_index":{"Recent":[0],"years":[1],"have":[2,110],"witnessed":[3],"a":[4,192,213,218,224],"rapid":[5],"development":[6],"of":[7,32,158,227,243,281],"mobile":[8],"GUI":[9,64,229,259],"agents":[10,34,51,65,88,267],"powered":[11],"by":[12,55],"large":[13],"language":[14,27],"models":[15],"(LLMs),":[16],"which":[17],"can":[18,89,268],"autonomously":[19],"execute":[20],"diverse":[21],"device-control":[22],"tasks":[23],"based":[24,103],"on":[25,35,104,171,254],"natural":[26],"instructions.":[28],"The":[29,231,291],"increasing":[30],"accuracy":[31],"these":[33],"standard":[36],"benchmarks":[37,100],"has":[38,295],"raised":[39],"expectations":[40],"for":[41,63],"large-scale":[42],"real-world":[43,94,121,165,173],"deployment,":[44],"and":[45,53,137,150,201,223,238,257,283,287,293],"there":[46],"are":[47,59,102,123,168,185],"already":[48],"several":[49],"commercial":[50,249,258],"released":[52,297],"used":[54],"early":[56],"adopters.":[57],"However,":[58],"we":[60,190,211],"really":[61],"ready":[62],"integrated":[66],"into":[67],"our":[68],"daily":[69],"devices":[70],"as":[71,132],"system":[72],"building":[73],"blocks?":[74],"We":[75,251],"argue":[76],"that":[77,101,264],"an":[78,277],"important":[79],"pre-deployment":[80],"validation":[81],"is":[82,161],"missing":[83],"to":[84,111,114,198,273],"examine":[85],"whether":[86],"the":[87,146,152,164,239],"maintain":[90],"their":[91],"performance":[92],"under":[93],"threats.":[95],"Specifically,":[96],"unlike":[97],"existing":[98,206],"common":[99],"simple":[105],"static":[106,225,240,288],"app":[107,166,183,194],"contents":[108,126,141,167,184],"(they":[109],"do":[112],"so":[113],"ensure":[115],"environment":[116,222,233],"consistency":[117],"between":[118],"different":[119],"tests),":[120],"apps":[122,174],"filled":[124],"with":[125,276],"from":[127,248],"untrustworthy":[128],"third":[129],"parties,":[130],"such":[131],"advertisement":[133],"emails,":[134],"user-generated":[135],"posts":[136],"medias,":[138],"etc.":[139],"These":[140],"may":[142],"inevitably":[143],"appear":[144],"in":[145,285],"agents'":[147],"observation":[148],"space":[149],"influence":[151],"task":[153,220],"execution":[154,221],"process.":[155],"Systematic":[156],"investigation":[157],"this":[159,188,209],"problem":[160],"challenging":[162,228],"since":[163,181],"significantly":[169,270],"skewed\u2014testing":[170],"normal":[172],"usually":[175],"cannot":[176],"uncover":[177],"any":[178],"potential":[179],"risk":[180],"most":[182],"benign.":[186],"To":[187],"end,":[189],"introduce":[191],"scalable":[193],"content":[195,203],"instrumentation":[196],"framework":[197,292],"enable":[199],"flexible":[200],"targeted":[202],"modifications":[204],"within":[205],"applications.":[207],"Leveraging":[208],"framework,":[210],"create":[212],"test":[214],"suite":[215],"comprising":[216],"both":[217,255],"dynamic":[219,232,286],"dataset":[226,241],"states.":[230],"encompasses":[234],"122":[235],"reproducible":[236],"tasks,":[237],"consists":[242],"over":[244],"3,000":[245],"scenarios":[246],"constructed":[247],"apps.":[250],"perform":[252],"experiments":[253],"open-source":[256],"agents.":[260],"Our":[261],"findings":[262],"reveal":[263],"all":[265],"examined":[266],"be":[269],"degraded":[271],"due":[272],"third-party":[274],"contents,":[275],"average":[278],"misleading":[279],"rate":[280],"42.0%":[282],"36.1%":[284],"environments":[289],"respectively.":[290],"benchmark":[294],"been":[296],"at":[298],"https://agenthazard.github.io.":[299]},"counts_by_year":[],"updated_date":"2026-06-11T09:08:48.828518","created_date":"2025-10-20T00:00:00"}
