Hijacking JARVIS: Benchmarking Mobile GUI Agents against Unprivileged Third Parties

Guohong Liu, Jialei Ye, J. Liu, Yuanchun Li, Wei Liu, Pengzhi Gao, Jian Luan, Yunxin Liu · 2025

Mobile GUI agents are designed to autonomously execute diverse device-control tasks by interpreting and interacting with mobile screens. Despite notable advancements, their resilience in real-world scenarios---where screen content may be partially manipulated by untrustworthy third parties---remains largely unexplored. Owing to their black-box and autonomous nature, these agents are vulnerable to manipulations that could compromise user devices. In this work, we present the first systematic investigation into the vulnerabilities of mobile GUI agents. We introduce a scalable attack simulation framework AgentHazard, which enables flexible and targeted modifications of screen content within existing applications. Leveraging this framework, we develop a human-annotated test set of over 50 reproducible tasks in an emulator with various types of hazardous UI content. We evaluate 6 mobile GUI agents using our benchmark, and find that all agents are significantly influenced by misleading third-party content (with an average misleading rate of 35.8%).

Read the paper · More papers on PaperTik