Adversarial text inside Android accessibility data can redirect mobile AI agents to unauthorized actions, with measured attack success up to 0.822 in the most vulnerable setup.
Title resolution pending
1 Pith paper cite this work. Polarity classification is still indexing.
1
Pith paper citing it
fields
cs.AI 1years
2026 1verdicts
CONDITIONAL 1representative citing papers
citing papers explorer
-
Not an A11y: How Android Accessibility Exposes Mobile AI Agents to Indirect Prompt Injection
Adversarial text inside Android accessibility data can redirect mobile AI agents to unauthorized actions, with measured attack success up to 0.822 in the most vulnerable setup.