Evaluating the Robustness of Multimodal Agents Against Active Environmental Injection Attacks
Yurun Chen, Xueyu Hu, Keting Yin, Juncheng Li, Shengyu Zhang
摘要
As researchers continue to optimize AI agents for more effective task execution within operating systems, they often overlook a critical security concern: the ability of these agents to detect ''impostors'' within their environment. Through an analysis of the agents' operational context, we identify a significant threat-attackers can disguise malicious attacks as environmental elements, injecting active disturbances into the agents' execution processes to manipulate their decision-making. We define this novel threat as the Active Environment Injection Attack (AEIA). Focusing on the interaction mechanisms of the Android OS, we conduct a risk assessment of AEIA and identify two critical security vulnerabilities: (1) Adversarial content injection in multimodal interaction interfaces, where attackers embed adversarial instructions within environmental elements to mislead agent decision-making; and (2) Reasoning gap vulnerabilities in the agent's task execution process, which increase susceptibility to AEIA attacks during reasoning. To evaluate the impact of these vulnerabilities, we propose AEIA-MN, an attack scheme that exploits interaction vulnerabilities in mobile operating systems to assess the robustness of MLLM-based agents. Experimental results show that even advanced MLLMs are highly vulnerable to this attack, achieving a maximum attack success rate of 93% on the AndroidWorld benchmark by combining two vulnerabilities.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper5
- Are Large Language Models Sensitive to the Motives Behind Communication?Addison J. Wu, Ryan Liu, Kerem Oktar, Theodore R. Sumers 等NeurIPS 2025 · 被引用 9 次
- GhostEI-Bench: Do Mobile Agent Resilience to Environmental Injection in Dynamic On-Device Environments?Chiyu Chen, Xinhao Song, Yunkai Chai, Yang Yao 等ICLR 2026 · 被引用 8 次
- LaSM: Layer-wise Scaling Mechanism for Defending Pop-up Attack on GUI AgentsZihe Yan, Zhuosheng Zhang, Jiaping Gui, Gongshen LiuCVPR 2026 · 被引用 5 次
- Faithful Mobile GUI Agents with Guided Advantage EstimatorHaowen Hu, Pengzhou Cheng, Zheng Wu, Lingzhong Dong 等ICML 2026
- Mind the Gap: Action Rebinding Attacks against Android GUI AgentsYi Qian, Kunwei Qian, Xingbang He, Ligeng Chen 等CCS 2026
它引用的顶会 Paper14
- GPT-4V(ision) is a Generalist Web Agent, if GroundedBoyuan Zheng, Boyu Gou, Jihyung Kil, Huan Sun 等ICML 2024 · 被引用 496 次
- A Real-World WebAgent with Planning, Long Context Understanding, and Program SynthesisIzzeddin Gur, Hiroki Furuta, Austin V. Huang, Mustafa Safdari 等ICLR 2024 · 被引用 359 次
- Mobile-Agent-v2: Mobile Device Operation Assistant with Effective Navigation via Multi-Agent CollaborationJunyang Wang, Haiyang Xu, Haitao Jia, Xi Zhang 等NeurIPS 2024 · 被引用 245 次
- InfiAgent-DABench: Evaluating Agents on Data Analysis TasksXueyu Hu, Ziyu Zhao, Shuang Wei, Ziwei Chai 等ICML 2024 · 被引用 110 次
- Attacking Vision-Language Computer Agents via Pop-upsYanzhe Zhang, Tao Yu, Diyi YangACL 2025 · 被引用 99 次
相关 Paper
- AdapAction: Adaptive Target Action Backdoor Attack against GUI AgentsBaicheng Chen, Mingda Zhang, Min Zhang, Haizhou Li 等CVPR 2026
- Environmental Injection Attacks against GUI Agents in Realistic Dynamic EnvironmentsYitong Zhang, Ximo Li, Liyi Cai, Jia LiISSTA 2026
- Caution for the Environment: Multimodal LLM Agents are Susceptible to Environmental DistractionsXinbei Ma, Yiting Wang, Yao Yao, Tongxin Yuan 等ACL 2025 · 被引用 54 次
- Manipulating Multimodal Agents via Cross-Modal Prompt InjectionLe Wang, Zonghao Ying, Tianyuan Zhang, Siyuan Liang 等ACM MM 2025 · 被引用 8 次
- Eia: Environmental Injection Attack on Generalist Web Agents for Privacy LeakageZeyi Liao, Lingbo Mo, Chejian Xu, Mintong Kang 等ICLR 2025
