Pith. sign in

Paper Citation Record · LEDGER

Measuring the Security of Mobile LLM Agents under Adversarial Prompts from Untrusted Third-Party Channels

As of 7 August 2026, this Paper Citation Record lists 93 of 93 outbound references and 0 inbound Pith citation observations for arXiv:2510.27140.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2510.27140 v3

Coverage vector

measured 93 of 93 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links, observed 2026-08-04T07:06:38.165220Z

measured 93 of 93 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-06T06:34:29.942622+00:00

measured 0 of 0 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links

measured 0 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: cited_works

Reference resolution

93 of 93 outbound references displayed

  • verified exact0
  • verified fuzzy0
  • unresolved93
  • parse uncertain0
  • malformed identifier0
  • metadata mismatch0

External citation measurements

No source-named external measurement is stored.

Outbound references

Observation 310a5515-6355-416c-8f2e-ef6ed69bc748 · outbound

This paper cites ‘hey mum, i dropped my phone down the toilet’: Investigating hi mum and dad sms scams in the united kingdom.

Measuring the Security of Mobile LLM Agents under Adversarial Prompts from Untrusted Third-Party Channels ‘hey mum, i dropped my phone down the toilet’: Investigating hi mum and dad sms scams in the united kingdom

Reference 1

Resolution
unresolved
no resolver link, observed 2026-08-04T07:06:37.173387Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T07:06:37.173387Z digest=sha256:988e9c93d1579729b11ca31cfa0a62b90234d2cc495119d10074c871a0ee8028

Observation 699ba449-4c43-40a0-8492-1bd65da38e0e · outbound

This paper cites Dissect- ing ghost clicks: Ad fraud via misdirected human clicks.

Measuring the Security of Mobile LLM Agents under Adversarial Prompts from Untrusted Third-Party Channels Dissect- ing ghost clicks: Ad fraud via misdirected human clicks

Reference 2

Resolution
unresolved
no resolver link, observed 2026-08-04T07:06:37.286007Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T07:06:37.286007Z digest=sha256:4580bc7353b4a6f72e767f65779c981201e57ac93edd581f8d585a9ad16f7fe4

Observation 1a4ffbcf-013a-404a-8ce1-addc73b53173 · outbound

This paper cites AgentHarm: A Benchmark for Measuring Harmfulness of LLM Agents.

Measuring the Security of Mobile LLM Agents under Adversarial Prompts from Untrusted Third-Party Channels AgentHarm: A Benchmark for Measuring Harmfulness of LLM Agents

Reference 3

Resolution
unresolved
no resolver link, observed 2026-08-04T07:06:37.405911Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T07:06:37.405911Z digest=sha256:da8081209e94e4edcb390c5d0ec93c683fa0f9db200dcad5d082d3a3ba0637bf

Observation 4eebf578-7e29-4bd9-9a67-81dff3c95de1 · outbound

This paper cites Alipay.https://www.alipay.com/.

Measuring the Security of Mobile LLM Agents under Adversarial Prompts from Untrusted Third-Party Channels Alipay.https://www.alipay.com/

Reference 4

Resolution
unresolved
no resolver link, observed 2026-08-04T07:06:37.458396Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T07:06:37.458396Z digest=sha256:0d9f0f4abf013b35c71d7f5738604e4515638f66c008105262b7efbfdffc6797

Observation 769a3e91-46c6-4a37-8bae-a21760946667 · outbound

This paper cites Malvertising in facebook: Analysis, quan- tification and solution.Electronics, 9(8):1332, 2020.

Measuring the Security of Mobile LLM Agents under Adversarial Prompts from Untrusted Third-Party Channels Malvertising in facebook: Analysis, quan- tification and solution.Electronics, 9(8):1332, 2020

Reference 5

Resolution
unresolved
no resolver link, observed 2026-08-04T07:06:37.586404Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T07:06:37.586404Z digest=sha256:f6f705b4dde8b028ff96c1cfc3d1ebcae7b7adf0f539516b09f8bc926a882bf8

Observation b42fbd9b-b91c-4bfc-b6bf-c196b246aecf · outbound

This paper cites Click-fraud monetizing malware: A survey and case study.

Measuring the Security of Mobile LLM Agents under Adversarial Prompts from Untrusted Third-Party Channels Click-fraud monetizing malware: A survey and case study

Reference 6

Resolution
unresolved
no resolver link, observed 2026-08-04T07:06:37.659433Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T07:06:37.659433Z digest=sha256:36a2311a1794bde9edf2a3f34d259d2e0dc83206826f09d0a2fc4d2a90d1e050

Observation c9883fca-74ed-41df-ad2e-2ea9cc0eb131 · outbound

This paper cites Evaluating the Susceptibility of Pre-Trained Language Models via Handcrafted Adversarial Examples.

Measuring the Security of Mobile LLM Agents under Adversarial Prompts from Untrusted Third-Party Channels Evaluating the Susceptibility of Pre-Trained Language Models via Handcrafted Adversarial Examples

Reference 7

Resolution
unresolved
no resolver link, observed 2026-08-04T07:06:37.731914Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T07:06:37.731914Z digest=sha256:ed39a57990909775d0636acf8be27e933cad214b608fabf533e7a24e32fafde1

Observation fd2d9a99-948e-4d09-a1d3-46ae37c93dbe · outbound

This paper cites Language models are few-shot learners.Advances in neural information processing systems, 33:1877–1901, 2020.

Measuring the Security of Mobile LLM Agents under Adversarial Prompts from Untrusted Third-Party Channels Language models are few-shot learners.Advances in neural information processing systems, 33:1877–1901, 2020

Reference 8

Resolution
unresolved
no resolver link, observed 2026-08-04T07:06:37.808700Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T07:06:37.808700Z digest=sha256:45a127dd7ce8cb88026b54501653b97db7d1d276170c181a730f43a1aa606f4b

Observation 6a3961a7-4288-4339-9d70-9cb4c9a0a79c · outbound

This paper cites A large scale study of user be- havior, expectations and engagement with android permissions.

Measuring the Security of Mobile LLM Agents under Adversarial Prompts from Untrusted Third-Party Channels A large scale study of user be- havior, expectations and engagement with android permissions

Reference 9

Resolution
unresolved
no resolver link, observed 2026-08-04T07:06:37.820896Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T07:06:37.820896Z digest=sha256:2606f1b5d6988508ea2d68740e572198a75b23811f22b85b8e878ae8b39dfa2d

Observation afc194ca-50ce-4f15-b2c8-45761eb90adf · outbound

This paper cites Spa-bench: A comprehensive benchmark for smartphone agent evaluation.

Measuring the Security of Mobile LLM Agents under Adversarial Prompts from Untrusted Third-Party Channels Spa-bench: A comprehensive benchmark for smartphone agent evaluation

Reference 10

Resolution
unresolved
no resolver link, observed 2026-08-04T07:06:37.865995Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T07:06:37.865995Z digest=sha256:b0526507acdf03f4a95ceeadd20e25d4e0b4dc8cd0672030e637d2fe8cfe82fa

Observation 97d1c926-8515-46b4-8a4b-58af8219a60e · outbound

This paper cites StruQ: Defending Against Prompt Injection with Structured Queries.

Measuring the Security of Mobile LLM Agents under Adversarial Prompts from Untrusted Third-Party Channels StruQ: Defending Against Prompt Injection with Structured Queries

Reference 11

Resolution
unresolved
no resolver link, observed 2026-08-04T07:06:37.935210Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T07:06:37.935210Z digest=sha256:8c2513d63f8c501717edb7569bf0a300197e797d880d73bcf45e56738ef77330

Observation a9091b94-22eb-48b4-8f30-978e86cc66db · outbound

This paper cites Bifocals: Analyzing webview vulnerabilities in android applications.

Measuring the Security of Mobile LLM Agents under Adversarial Prompts from Untrusted Third-Party Channels Bifocals: Analyzing webview vulnerabilities in android applications

Reference 12

Resolution
unresolved
no resolver link, observed 2026-08-04T07:06:37.956001Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T07:06:37.956001Z digest=sha256:fa351d0494c7ed6ef976799820efb2cedeacf1316d01832b8a0a16ff8da2f434

Observation e908770b-f620-4839-a470-3d5f8b1920ed · outbound

This paper cites An empirical study of click fraud in mobile ad- vertising networks.

Measuring the Security of Mobile LLM Agents under Adversarial Prompts from Untrusted Third-Party Channels An empirical study of click fraud in mobile ad- vertising networks

Reference 13

Resolution
unresolved
no resolver link, observed 2026-08-04T07:06:37.966247Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T07:06:37.966247Z digest=sha256:5613e360654172e57cb90dba6f0a0f6b5a1ad8b4f99db1eb36cda73bb306d87d

Observation fa552caf-104e-48b6-8fff-e155093c02f6 · outbound

This paper cites Madfraud: Investigating ad fraud in android applications.

Measuring the Security of Mobile LLM Agents under Adversarial Prompts from Untrusted Third-Party Channels Madfraud: Investigating ad fraud in android applications

Reference 14

Resolution
unresolved
no resolver link, observed 2026-08-04T07:06:37.989989Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T07:06:37.989989Z digest=sha256:f33f9323817e1a0b43b4615480da11c5c8684f08ce072dcab254331b96eab84a

Observation 699d9ddf-8fff-4638-8a05-83a5233affbb · outbound

This paper cites Advancing mobile gui agents: A verifier-driven approach to practical deployment.arXiv preprint arXiv:2503.15937, 2025.

Measuring the Security of Mobile LLM Agents under Adversarial Prompts from Untrusted Third-Party Channels Advancing mobile gui agents: A verifier-driven approach to practical deployment.arXiv preprint arXiv:2503.15937, 2025

Reference 15

Resolution
unresolved
no resolver link, observed 2026-08-04T07:06:38.000471Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T07:06:38.000471Z digest=sha256:934a7df1218bff09dc5c6e56fb16c3772a192fab8a7ac34cfcdd0414bc125936

Observation fc959d86-7914-4a3f-92e4-a961064ba38b · outbound

This paper cites Defeating Prompt Injections by Design.

Measuring the Security of Mobile LLM Agents under Adversarial Prompts from Untrusted Third-Party Channels Defeating Prompt Injections by Design

Reference 16

Resolution
unresolved
no resolver link, observed 2026-08-04T07:06:38.002885Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T07:06:38.002885Z digest=sha256:64a201966fe2640d58440afc7e094c894cfb94f2c8fa59c17e5dd1d2d7bb0562

Observation 7305b20a-4194-4769-b0a5-6859adf43956 · outbound

This paper cites Agent- dojo: A dynamic environment to evaluate attacks and defenses for llm agents.arXiv e-prints, pages arXiv–2406, 2024.

Measuring the Security of Mobile LLM Agents under Adversarial Prompts from Untrusted Third-Party Channels Agent- dojo: A dynamic environment to evaluate attacks and defenses for llm agents.arXiv e-prints, pages arXiv–2406, 2024

Reference 17

Resolution
unresolved
no resolver link, observed 2026-08-04T07:06:38.005564Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T07:06:38.005564Z digest=sha256:bd6791d535d1d5c02e76f5f3cc3ae267a3612c4c89cc9ac10117c25950a1b6eb

Observation fcb273dc-49b8-4a6d-ba7d-90cd7f6f5ee0 · outbound

This paper cites Delgado-Soto, J.E.L.

Measuring the Security of Mobile LLM Agents under Adversarial Prompts from Untrusted Third-Party Channels Delgado-Soto, J.E.L

Reference 18

Resolution
unresolved
no resolver link, observed 2026-08-04T07:06:38.007481Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T07:06:38.007481Z digest=sha256:9bbd9d68cdb7661cb2d0f6cfb575b4ab8ea1c1d105bdbbefebea32772f5a8618

Observation bf108a2c-87a1-4d0e-ac04-6a3bfc2e3c92 · outbound

This paper cites Mobile-Bench: An Evaluation Benchmark for LLM-based Mobile Agents.

Measuring the Security of Mobile LLM Agents under Adversarial Prompts from Untrusted Third-Party Channels Mobile-Bench: An Evaluation Benchmark for LLM-based Mobile Agents

Reference 19

Resolution
unresolved
no resolver link, observed 2026-08-04T07:06:38.009250Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T07:06:38.009250Z digest=sha256:13d70e3cfd88e53437da4cc618c6ece0f72b757f0c66c1f9279f2cef2aac267c

Observation 03cd65a9-4301-4b7d-87f6-ad55c6a55a51 · outbound

This paper cites Fossify notes beta.

Measuring the Security of Mobile LLM Agents under Adversarial Prompts from Untrusted Third-Party Channels Fossify notes beta

Reference 20

Resolution
unresolved
no resolver link, observed 2026-08-04T07:06:38.011496Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T07:06:38.011496Z digest=sha256:7d83f27e5b240184af9af9674332e7d2d52fab3c5f6af19a36233d81d7ab03f2

Observation d1c35412-5d4c-4fc8-ac02-d46d2beeeee5 · outbound

This paper cites Fraud- droid: Automated ad fraud detection for android apps.

Measuring the Security of Mobile LLM Agents under Adversarial Prompts from Untrusted Third-Party Channels Fraud- droid: Automated ad fraud detection for android apps

Reference 21

Resolution
unresolved
no resolver link, observed 2026-08-04T07:06:38.013294Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T07:06:38.013294Z digest=sha256:f97837b2f023b415e1a70ca395d6f1894cb5031037228cd0c93b019d7ac32924

Observation 804d0b1e-c747-4dee-8974-c5897a8032b1 · outbound

This paper cites Why eve and mal- lory love android: An analysis of android ssl (in) security.

Measuring the Security of Mobile LLM Agents under Adversarial Prompts from Untrusted Third-Party Channels Why eve and mal- lory love android: An analysis of android ssl (in) security

Reference 22

Resolution
unresolved
no resolver link, observed 2026-08-04T07:06:38.015242Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T07:06:38.015242Z digest=sha256:00748ff63c2878cbc0201b91aa363f62481a034c294c684170cef315d7a2a084

Observation 18322551-6a8b-457e-926c-7323c6fe4b79 · outbound

This paper cites Not what you’ve signed up for: Compromising real-world llm-integrated ap- plications with indirect prompt injection.

Measuring the Security of Mobile LLM Agents under Adversarial Prompts from Untrusted Third-Party Channels Not what you’ve signed up for: Compromising real-world llm-integrated ap- plications with indirect prompt injection

Reference 23

Resolution
unresolved
no resolver link, observed 2026-08-04T07:06:38.017253Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T07:06:38.017253Z digest=sha256:5754ad72374a8f9345abac6bf974e6e486ce2d96bbc3e21fe23d1392f2a4e03e

Observation 04424b68-ee78-4b48-a29d-d030d565ed77 · outbound

This paper cites Defending against phishing attacks: taxonomy of methods, cur- rent issues and future directions.Telecommunication Systems, 67(2):247–267, 2018.

Measuring the Security of Mobile LLM Agents under Adversarial Prompts from Untrusted Third-Party Channels Defending against phishing attacks: taxonomy of methods, cur- rent issues and future directions.Telecommunication Systems, 67(2):247–267, 2018

Reference 24

Resolution
unresolved
no resolver link, observed 2026-08-04T07:06:38.019243Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T07:06:38.019243Z digest=sha256:ad538bc00fd13a40055cf2a91c928b096b214f2f43a596bf122adfb73258e136

Observation 9e790620-dd76-45dd-a521-fbb54978512f · outbound

This paper cites Medusa attack: Exploring security hazards of {in- app}{QR} code scanning.

Measuring the Security of Mobile LLM Agents under Adversarial Prompts from Untrusted Third-Party Channels Medusa attack: Exploring security hazards of {in- app}{QR} code scanning

Reference 25

Resolution
unresolved
no resolver link, observed 2026-08-04T07:06:38.021134Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T07:06:38.021134Z digest=sha256:b53c40a8957131b19a58349fdc150833409d381e34e051cd35f967e949213049

Observation dde38284-d17b-4cf9-a32c-f02a3dd3d49f · outbound

This paper cites Securing llm systems against prompt injec- tion.Online], https://developer.

Measuring the Security of Mobile LLM Agents under Adversarial Prompts from Untrusted Third-Party Channels Securing llm systems against prompt injec- tion.Online], https://developer

Reference 26

Resolution
unresolved
no resolver link, observed 2026-08-04T07:06:38.022997Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T07:06:38.022997Z digest=sha256:e1a7b892e2e36801f7fa5fd74bbe1debcfd3046eca3c2cf1c68a6a086d910571

Observation 99aee33e-018c-48ee-af4e-a307b05b5173 · outbound

This paper cites OS Agents: A Survey on MLLM-based Agents for General Computing Devices Use.

Measuring the Security of Mobile LLM Agents under Adversarial Prompts from Untrusted Third-Party Channels OS Agents: A Survey on MLLM-based Agents for General Computing Devices Use

Reference 27

Resolution
unresolved
no resolver link, observed 2026-08-04T07:06:38.024864Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T07:06:38.024864Z digest=sha256:341a8197a5a63d55009f33833d50382109953016313e697ea63d5430c4414cc3

Observation 6b35ec04-0d94-4e8d-b232-badedc26f76b · outbound

This paper cites TrustAgent: Towards Safe and Trustworthy LLM-based Agents.

Measuring the Security of Mobile LLM Agents under Adversarial Prompts from Untrusted Third-Party Channels TrustAgent: Towards Safe and Trustworthy LLM-based Agents

Reference 28

Resolution
unresolved
no resolver link, observed 2026-08-04T07:06:38.027003Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T07:06:38.027003Z digest=sha256:6def4383e6d81cf2ebf727f7a7b3be6dc5c6c96a1b99aa6dd2f41f5c9c368c6a

Observation 0e6398dc-a637-4733-a6e0-2f75f01a1e29 · outbound

This paper cites ileakage: browser-based timerless speculative execu- tion attacks on apple devices.

Measuring the Security of Mobile LLM Agents under Adversarial Prompts from Untrusted Third-Party Channels ileakage: browser-based timerless speculative execu- tion attacks on apple devices

Reference 29

Resolution
unresolved
no resolver link, observed 2026-08-04T07:06:38.029117Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T07:06:38.029117Z digest=sha256:fb30387cf4f6b9b5e9047e165f2fde0023e40931a36cdbc23c8e84142c0ea72e

Observation bc260061-43e6-4363-b407-5ae756be8242 · outbound

This paper cites an unresolved cited work.

Measuring the Security of Mobile LLM Agents under Adversarial Prompts from Untrusted Third-Party Channels Unresolved cited work

Reference 30

Resolution
unresolved
no resolver link, observed 2026-08-04T07:06:38.031025Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T07:06:38.031025Z digest=sha256:3158c500422b57a4d0863fb58dc1d73b964c97fbcd74f3c0a972bdc0239d2cfb

Observation c50f0a73-6ec3-451d-93d6-fc8011508c09 · outbound

This paper cites Refusal-Trained LLMs Are Easily Jailbroken As Browser Agents.

Measuring the Security of Mobile LLM Agents under Adversarial Prompts from Untrusted Third-Party Channels Refusal-Trained LLMs Are Easily Jailbroken As Browser Agents

Reference 31

Resolution
unresolved
no resolver link, observed 2026-08-04T07:06:38.033013Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T07:06:38.033013Z digest=sha256:cfd8756b9d39f396c56d22a5b2c9b753fad2237e3c39429bdc948590d95278e4

Observation 911e5dc9-49d3-44b4-92db-cc9c66b639e4 · outbound

This paper cites Deep learning.nature, 521(7553):436–444, 2015.

Measuring the Security of Mobile LLM Agents under Adversarial Prompts from Untrusted Third-Party Channels Deep learning.nature, 521(7553):436–444, 2015

Reference 32

Resolution
unresolved
no resolver link, observed 2026-08-04T07:06:38.035761Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T07:06:38.035761Z digest=sha256:dfd141b7d8b2ecc1b6612102ce7aa75cfc37da34e399c6b670ac136c235a99c7

Observation 5f4dad8d-5910-450d-b5f5-65e786669759 · outbound

This paper cites sudo rm -rf agentic_security.

Measuring the Security of Mobile LLM Agents under Adversarial Prompts from Untrusted Third-Party Channels sudo rm -rf agentic_security

Reference 33

Resolution
unresolved
no resolver link, observed 2026-08-04T07:06:38.037639Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T07:06:38.037639Z digest=sha256:d983b16c62aef2092849cab04c30c1320f46af87dcbbc3e095882fa96882db2d

Observation 210a4307-8758-4608-ac59-fb2f5a9acbd7 · outbound

This paper cites Don’t kill my ads! balancing privacy in an ad-supported mobile application market.

Measuring the Security of Mobile LLM Agents under Adversarial Prompts from Untrusted Third-Party Channels Don’t kill my ads! balancing privacy in an ad-supported mobile application market

Reference 34

Resolution
unresolved
no resolver link, observed 2026-08-04T07:06:38.040014Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T07:06:38.040014Z digest=sha256:32011100a435f45b0581239915962914592a9b0b743d122dcf055ff28fd242f2

Observation e36b5551-e79c-4033-9e44-68fbdd28bc08 · outbound

This paper cites Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks.

Measuring the Security of Mobile LLM Agents under Adversarial Prompts from Untrusted Third-Party Channels Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks

Reference 35

Resolution
unresolved
no resolver link, observed 2026-08-04T07:06:38.041872Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T07:06:38.041872Z digest=sha256:8a148e4c4925a2059483f284f3ba0711e6dfdac6c0da502fe069fb95d6722a60

Observation beac10fb-3bc2-42ca-8322-1fe362c96b88 · outbound

This paper cites Knowing your enemy: understanding and detecting malicious web advertising.

Measuring the Security of Mobile LLM Agents under Adversarial Prompts from Untrusted Third-Party Channels Knowing your enemy: understanding and detecting malicious web advertising

Reference 36

Resolution
unresolved
no resolver link, observed 2026-08-04T07:06:38.043896Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T07:06:38.043896Z digest=sha256:48cf4056800b20ef50ad9d2c7d77aae965b94a6c6bf76cd84e1be487b0b2d757

Observation c6ff12cc-cb1e-4b67-9f72-282fd2f18fdd · outbound

This paper cites {DECAF}: Detecting and characterizing ad fraud in mobile apps.

Measuring the Security of Mobile LLM Agents under Adversarial Prompts from Untrusted Third-Party Channels {DECAF}: Detecting and characterizing ad fraud in mobile apps

Reference 37

Resolution
unresolved
no resolver link, observed 2026-08-04T07:06:38.045705Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T07:06:38.045705Z digest=sha256:13db210dba5517de1b7c9bd7b94139a1fa5a79644bfcdc7f4632da29fa905144

Observation 3e6c2a87-6315-4465-837a-8113aa7ede74 · outbound

This paper cites Maddroid: Characterizing and detecting devious ad contents for android apps.

Measuring the Security of Mobile LLM Agents under Adversarial Prompts from Untrusted Third-Party Channels Maddroid: Characterizing and detecting devious ad contents for android apps

Reference 38

Resolution
unresolved
no resolver link, observed 2026-08-04T07:06:38.047700Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T07:06:38.047700Z digest=sha256:8070bced8743029266d15ba77d28b402da32c31cbc176f91fa96a59f254df3f5

Observation e87b3f56-3e5a-4b8f-909d-9501f9c5527d · outbound

This paper cites an unresolved cited work.

Measuring the Security of Mobile LLM Agents under Adversarial Prompts from Untrusted Third-Party Channels Unresolved cited work

Reference 39

Resolution
unresolved
no resolver link, observed 2026-08-04T07:06:38.050185Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T07:06:38.050185Z digest=sha256:f59a33ce66bb76d3bc187d5e491fbdf9020b4dbc7af3ef5eb956c92d00af7fb7

Observation 5c07a228-5615-42d9-88b4-b5175bdfd3ff · outbound

This paper cites Formalizing and benchmarking prompt injection attacks and defenses.

Measuring the Security of Mobile LLM Agents under Adversarial Prompts from Untrusted Third-Party Channels Formalizing and benchmarking prompt injection attacks and defenses

Reference 40

Resolution
unresolved
no resolver link, observed 2026-08-04T07:06:38.052124Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T07:06:38.052124Z digest=sha256:deb63c88f438c5a40f4aa639cfbcb918c31c3505d2089c9d51899459d946b622

Observation ca4b09a4-c7c3-4696-a862-1dc80ce817fd · outbound

This paper cites Agen- trewardbench: Evaluating automatic evaluations of web agent trajectories.arXiv preprint arXiv:2504.08942, 2025.

Measuring the Security of Mobile LLM Agents under Adversarial Prompts from Untrusted Third-Party Channels Agen- trewardbench: Evaluating automatic evaluations of web agent trajectories.arXiv preprint arXiv:2504.08942, 2025

Reference 41

Resolution
unresolved
no resolver link, observed 2026-08-04T07:06:38.054066Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T07:06:38.054066Z digest=sha256:23411bb29593e8aa8661cc32e5c817e4809fe61eec4376a6a43abce12ebc1a7e

Observation 30373810-42a6-40ba-924e-099ccc24dee6 · outbound

This paper cites Careful About What App Promotion Ads Recommend! Detecting and Explaining Malware Promotion via App Promotion Graph.

Measuring the Security of Mobile LLM Agents under Adversarial Prompts from Untrusted Third-Party Channels Careful About What App Promotion Ads Recommend! Detecting and Explaining Malware Promotion via App Promotion Graph

Reference 42

Resolution
unresolved
no resolver link, observed 2026-08-04T07:06:38.055973Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T07:06:38.055973Z digest=sha256:7629d5ff2e4df14b6070067eb217ccf11283e1a5e3ace3556165496849d57590

Observation c23c29b1-f0d1-467f-a850-c81adff2cc90 · outbound

This paper cites When advertising turns nasty.Net- work Security, 2015(11):5–8, 2015.

Measuring the Security of Mobile LLM Agents under Adversarial Prompts from Untrusted Third-Party Channels When advertising turns nasty.Net- work Security, 2015(11):5–8, 2015

Reference 43

Resolution
unresolved
no resolver link, observed 2026-08-04T07:06:38.058145Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T07:06:38.058145Z digest=sha256:30c541799f5b83d2ae374411a39fc2ec24e895f16f88a0cbea3597ba94a3af36

Observation fa287ee1-605e-462a-8647-772a7aa7f3c0 · outbound

This paper cites A Study of MAC Address Randomization in Mobile Devices and When it Fails.

Measuring the Security of Mobile LLM Agents under Adversarial Prompts from Untrusted Third-Party Channels A Study of MAC Address Randomization in Mobile Devices and When it Fails

Reference 44

Resolution
unresolved
no resolver link, observed 2026-08-04T07:06:38.060137Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T07:06:38.060137Z digest=sha256:cb43d6ba48eeb24e2f47e4ed3cbfe25e697b61cc78141b1f68f2b9aa32154915

Observation b0afa7e6-7665-4908-970f-08ef33fb8777 · outbound

This paper cites The price of free: Privacy leakage in personalized mobile in-apps ads.

Measuring the Security of Mobile LLM Agents under Adversarial Prompts from Untrusted Third-Party Channels The price of free: Privacy leakage in personalized mobile in-apps ads

Reference 45

Resolution
unresolved
no resolver link, observed 2026-08-04T07:06:38.062410Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T07:06:38.062410Z digest=sha256:f98210bf829c7c5a9ad36397a4d07cef6c080b1183af7f6cc0259d5f626b2b99

Observation fcf5328f-4e73-460e-be55-bc68304fa976 · outbound

This paper cites Whatsapp.

Measuring the Security of Mobile LLM Agents under Adversarial Prompts from Untrusted Third-Party Channels Whatsapp

Reference 46

Resolution
unresolved
no resolver link, observed 2026-08-04T07:06:38.064248Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T07:06:38.064248Z digest=sha256:eb3677706b10c2ca6f6dbac7e23ad2d30ecc200d577c394aa67dae8e736004ba

Observation ef328913-b292-42b3-83ef-511f21018122 · outbound

This paper cites What’s clicking what? techniques and innova- tions of today’s clickbots.

Measuring the Security of Mobile LLM Agents under Adversarial Prompts from Untrusted Third-Party Channels What’s clicking what? techniques and innova- tions of today’s clickbots

Reference 47

Resolution
unresolved
no resolver link, observed 2026-08-04T07:06:38.066347Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T07:06:38.066347Z digest=sha256:42be68c168fae924d4b786669eeb88f2c9afee86b44876b39eb6ffde3ac849f5

Observation 8a163b47-e7da-491e-9eeb-e80097ff3d55 · outbound

This paper cites Dial one for scam: A large-scale analysis of technical support scams.

Measuring the Security of Mobile LLM Agents under Adversarial Prompts from Untrusted Third-Party Channels Dial one for scam: A large-scale analysis of technical support scams

Reference 48

Resolution
unresolved
no resolver link, observed 2026-08-04T07:06:38.068423Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T07:06:38.068423Z digest=sha256:8347967f331500fff2e740ade852ebdd080d1e8e40154e1cd509c43574a5c0c1

Observation f524fa72-2f51-47c5-ba3b-bd6094da5982 · outbound

This paper cites Mobile tactics.

Measuring the Security of Mobile LLM Agents under Adversarial Prompts from Untrusted Third-Party Channels Mobile tactics

Reference 49

Resolution
unresolved
no resolver link, observed 2026-08-04T07:06:38.070733Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T07:06:38.070733Z digest=sha256:d0e6d4098e1d6cd85ae8a8be4a1a7186f30b7be201798703c772b17743835575

Observation cc3821ed-ec6a-4d86-838c-d7ebe0b06b50 · outbound

This paper cites On sms phishing tactics and infrastructure.

Measuring the Security of Mobile LLM Agents under Adversarial Prompts from Untrusted Third-Party Channels On sms phishing tactics and infrastructure

Reference 50

Resolution
unresolved
no resolver link, observed 2026-08-04T07:06:38.072635Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T07:06:38.072635Z digest=sha256:c01f058e7c5653fd4014de00f7b851fe2719015174051f9903e3702ee072953a

Observation 530c5378-d131-41e9-a941-d5d00217dbf9 · outbound

This paper cites Ignore Previous Prompt: Attack Techniques For Language Models.

Measuring the Security of Mobile LLM Agents under Adversarial Prompts from Untrusted Third-Party Channels Ignore Previous Prompt: Attack Techniques For Language Models

Reference 51

Resolution
unresolved
no resolver link, observed 2026-08-04T07:06:38.074424Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T07:06:38.074424Z digest=sha256:f014b840562cd03423162f76eac68af6eaacaa3602df0489113de6e623a63c73

Observation 76ec4a41-819f-4c03-b9b3-8a24fa14a0d2 · outbound

This paper cites Tricking LLMs into Disobedience: Formalizing, Analyzing, and Detecting Jailbreaks.

Measuring the Security of Mobile LLM Agents under Adversarial Prompts from Untrusted Third-Party Channels Tricking LLMs into Disobedience: Formalizing, Analyzing, and Detecting Jailbreaks

Reference 52

Resolution
unresolved
no resolver link, observed 2026-08-04T07:06:38.076927Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T07:06:38.076927Z digest=sha256:598c63dbf22a95d47f886e1bdb7bead0ea917a0e5312b452c16b0dd6149c37d3

Observation 53c99c5b-a7fa-4781-bdc5-065f59d8fb16 · outbound

This paper cites Are these ads safe: Detecting hidden attacks through the mobile app-web interfaces.

Measuring the Security of Mobile LLM Agents under Adversarial Prompts from Untrusted Third-Party Channels Are these ads safe: Detecting hidden attacks through the mobile app-web interfaces

Reference 53

Resolution
unresolved
no resolver link, observed 2026-08-04T07:06:38.078981Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T07:06:38.078981Z digest=sha256:8176b34af2bbd6596644296c30dde97bd0fb57b1e554caae3d5e4d5979a3b6f1

Observation 4168044c-5d3c-41e6-8a3a-d1845437f86e · outbound

This paper cites AndroidWorld: A Dynamic Benchmarking Environment for Autonomous Agents.

Measuring the Security of Mobile LLM Agents under Adversarial Prompts from Untrusted Third-Party Channels AndroidWorld: A Dynamic Benchmarking Environment for Autonomous Agents

Reference 54

Resolution
unresolved
no resolver link, observed 2026-08-04T07:06:38.080767Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T07:06:38.080767Z digest=sha256:0055e9a2f13c997f43a9397b3a59007a50d4cc488ed16098b319a9f723ce98db

Observation 2fd5e405-8914-4acb-833a-e3bdedb018bb · outbound

This paper cites Ba- belview: Evaluating the impact of code injection attacks in mobile webviews.

Measuring the Security of Mobile LLM Agents under Adversarial Prompts from Untrusted Third-Party Channels Ba- belview: Evaluating the impact of code injection attacks in mobile webviews

Reference 55

Resolution
unresolved
no resolver link, observed 2026-08-04T07:06:38.083186Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T07:06:38.083186Z digest=sha256:2ddabeeffbdb9fe72cbc23c56e931af678607d600ed3aeaf264da9b98def1f2e

Observation dc5f364a-254c-4acd-b37b-729a53c31945 · outbound

This paper cites Identifying the Risks of LM Agents with an LM-Emulated Sandbox.

Measuring the Security of Mobile LLM Agents under Adversarial Prompts from Untrusted Third-Party Channels Identifying the Risks of LM Agents with an LM-Emulated Sandbox

Reference 56

Resolution
unresolved
no resolver link, observed 2026-08-04T07:06:38.085299Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T07:06:38.085299Z digest=sha256:0c523cd65e9ff44c19276bb4c29f39fa416618384bb169f3c79cdca4fa853d76

Observation 75215638-5e13-4422-9efb-69520a1a0b52 · outbound

This paper cites Understanding in-app ads and detecting hidden attacks through the mobile app-web interface.

Measuring the Security of Mobile LLM Agents under Adversarial Prompts from Untrusted Third-Party Channels Understanding in-app ads and detecting hidden attacks through the mobile app-web interface

Reference 57

Resolution
unresolved
no resolver link, observed 2026-08-04T07:06:38.087636Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T07:06:38.087636Z digest=sha256:ccce5021885a153a8ebc03a53cce4e62f121cd198d047808295e761e39728dc7

Observation b70b3c18-cd7f-44a7-ab6b-3e132ac482f7 · outbound

This paper cites do anything now.

Measuring the Security of Mobile LLM Agents under Adversarial Prompts from Untrusted Third-Party Channels do anything now

Reference 58

Resolution
unresolved
no resolver link, observed 2026-08-04T07:06:38.089785Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T07:06:38.089785Z digest=sha256:d25ae069c756171b80206d02a0827bfeee139cbbd7eeb07db1d654a9a71d1e35

Observation 6d8ce6a7-300b-481b-b0b0-fbb4e6f12f1e · outbound

This paper cites What mo- bile ads know about mobile users.

Measuring the Security of Mobile LLM Agents under Adversarial Prompts from Untrusted Third-Party Channels What mo- bile ads know about mobile users

Reference 59

Resolution
unresolved
no resolver link, observed 2026-08-04T07:06:38.091710Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T07:06:38.091710Z digest=sha256:0120fce95283c146322131936024ad6e95446d06cb83f7607dd343c7e09934d2

Observation 0fcdb333-3133-4be5-a0ae-beb878d463ec · outbound

This paper cites Scan- droid: Automated side-channel analysis of android apis.

Measuring the Security of Mobile LLM Agents under Adversarial Prompts from Untrusted Third-Party Channels Scan- droid: Automated side-channel analysis of android apis

Reference 60

Resolution
unresolved
no resolver link, observed 2026-08-04T07:06:38.093680Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T07:06:38.093680Z digest=sha256:4536feb8cff904514d0b1d98a412d66a7e42c7292fd8770d8042cf85c2511e2d

Observation 3e2df3cf-134e-47b9-8a64-ee0b3883b322 · outbound

This paper cites Autoeval: A practical framework for autonomous evaluation of mobile agents.arXiv preprint arXiv:2503.02403, 2025.

Measuring the Security of Mobile LLM Agents under Adversarial Prompts from Untrusted Third-Party Channels Autoeval: A practical framework for autonomous evaluation of mobile agents.arXiv preprint arXiv:2503.02403, 2025

Reference 61

Resolution
unresolved
no resolver link, observed 2026-08-04T07:06:38.095626Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T07:06:38.095626Z digest=sha256:dc856ca7111770b7d458acddc4ae14630a9bc57c991efc476a1075847a8acae0

Observation 3e12a5b2-1f8b-4ba3-ae80-550cdf80c428 · outbound

This paper cites Understanding and detecting mobile ad fraud through the lens of invalid traf- fic.

Measuring the Security of Mobile LLM Agents under Adversarial Prompts from Untrusted Third-Party Channels Understanding and detecting mobile ad fraud through the lens of invalid traf- fic

Reference 62

Resolution
unresolved
no resolver link, observed 2026-08-04T07:06:38.097448Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T07:06:38.097448Z digest=sha256:df7bce03fffdea4f94f81560440b19092b8507531eed9fc08373ddc238ad40db

Observation b5c21188-30a4-44cb-924c-ac616e75638b · outbound

This paper cites Data breaches, phishing, or malware? understanding the risks of stolen credentials.

Measuring the Security of Mobile LLM Agents under Adversarial Prompts from Untrusted Third-Party Channels Data breaches, phishing, or malware? understanding the risks of stolen credentials

Reference 63

Resolution
unresolved
no resolver link, observed 2026-08-04T07:06:38.099808Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T07:06:38.099808Z digest=sha256:eb8d33d01f869392ba8ed24c49faedf0ce41c65b1cb8aa3f8aa2ed0e975a9e16

Observation a4870b70-7b04-4b7e-af3a-a73c18c5b763 · outbound

This paper cites Understanding influences on SMS phishing de- tection: User behavior, demographics, and message attributes.

Measuring the Security of Mobile LLM Agents under Adversarial Prompts from Untrusted Third-Party Channels Understanding influences on SMS phishing de- tection: User behavior, demographics, and message attributes

Reference 64

Resolution
unresolved
no resolver link, observed 2026-08-04T07:06:38.101896Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T07:06:38.101896Z digest=sha256:6d44546313d1447ef9210cba6decc8e6009792ae45048ad7fbdd2d98a9ffdc2f

Observation 96ff0790-60ff-4665-9633-7e7b669fbf03 · outbound

This paper cites SafeArena: Evaluating the Safety of Autonomous Web Agents.

Measuring the Security of Mobile LLM Agents under Adversarial Prompts from Untrusted Third-Party Channels SafeArena: Evaluating the Safety of Autonomous Web Agents

Reference 65

Resolution
unresolved
no resolver link, observed 2026-08-04T07:06:38.104345Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T07:06:38.104345Z digest=sha256:62f776ae97a02bf3cc8df2a0991b3687a607a8bf53572c96e94612c102116f18

Observation 08d8ff27-a72c-4464-bad1-8c30bc57d3fb · outbound

This paper cites Vladika, A.

Measuring the Security of Mobile LLM Agents under Adversarial Prompts from Untrusted Third-Party Channels Vladika, A

Reference 66

Resolution
unresolved
no resolver link, observed 2026-08-04T07:06:38.106510Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T07:06:38.106510Z digest=sha256:f301a2385c46e23af6f5430b1b833c502c9828c2266f7f382a90d221e3012d10

Observation 3a67007b-9e3f-46c9-a6f3-25d611243972 · outbound

This paper cites The Instruction Hierarchy: Training LLMs to Prioritize Privileged Instructions.

Measuring the Security of Mobile LLM Agents under Adversarial Prompts from Untrusted Third-Party Channels The Instruction Hierarchy: Training LLMs to Prioritize Privileged Instructions

Reference 67

Resolution
unresolved
no resolver link, observed 2026-08-04T07:06:38.108715Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T07:06:38.108715Z digest=sha256:aa581b60dddb20de02a5966031a348ce66aac50ce58151dcca4dc3d4f7803bb4

Observation 893ea7e0-223a-4eb8-88ae-7e2c013efb31 · outbound

This paper cites Mobile-Agent: Autonomous Multi-Modal Mobile Device Agent with Visual Perception.

Measuring the Security of Mobile LLM Agents under Adversarial Prompts from Untrusted Third-Party Channels Mobile-Agent: Autonomous Multi-Modal Mobile Device Agent with Visual Perception

Reference 68

Resolution
unresolved
no resolver link, observed 2026-08-04T07:06:38.110838Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T07:06:38.110838Z digest=sha256:bfeab4e2f7314d923d305922d623bf985a87eadee223a5dba5172662f13672af

Observation ef74d904-99af-4f85-aee3-56bbc3fe0d1f · outbound

This paper cites MobileAgentBench: An Efficient and User-Friendly Benchmark for Mobile LLM Agents.

Measuring the Security of Mobile LLM Agents under Adversarial Prompts from Untrusted Third-Party Channels MobileAgentBench: An Efficient and User-Friendly Benchmark for Mobile LLM Agents

Reference 69

Resolution
unresolved
no resolver link, observed 2026-08-04T07:06:38.113238Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T07:06:38.113238Z digest=sha256:9bf8c9e2588816c30b71ce4710da207cce9b86647e33e93abf8b5b167fbcb566

Observation 8f25db0f-8281-408f-8b19-34c60911675a · outbound

This paper cites Mobile-Agent-E: Self-Evolving Mobile Assistant for Complex Tasks.

Measuring the Security of Mobile LLM Agents under Adversarial Prompts from Untrusted Third-Party Channels Mobile-Agent-E: Self-Evolving Mobile Assistant for Complex Tasks

Reference 70

Resolution
unresolved
no resolver link, observed 2026-08-04T07:06:38.116080Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T07:06:38.116080Z digest=sha256:04665b4a485715a00497cf023f8cbd0a53078ac0be82e3260ec19d3eacbee092

Observation 13b1dfed-95de-4903-ba57-8e0ab1e377c5 · outbound

This paper cites The danger of minimum exposures: Understanding cross-app information leaks on ios through multi-side-channel learning.

Measuring the Security of Mobile LLM Agents under Adversarial Prompts from Untrusted Third-Party Channels The danger of minimum exposures: Understanding cross-app information leaks on ios through multi-side-channel learning

Reference 71

Resolution
unresolved
no resolver link, observed 2026-08-04T07:06:38.118434Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T07:06:38.118434Z digest=sha256:d3a47e119d4ee76d92901ff83207c8658799caf1630a92d099efba451cf22711

Observation 5187e3f8-ddbc-49ef-b93f-23f7013e2313 · outbound

This paper cites Jailbreak and Guard Aligned Language Models with Only Few In-Context Demonstrations.

Measuring the Security of Mobile LLM Agents under Adversarial Prompts from Untrusted Third-Party Channels Jailbreak and Guard Aligned Language Models with Only Few In-Context Demonstrations

Reference 72

Resolution
unresolved
no resolver link, observed 2026-08-04T07:06:38.120540Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T07:06:38.120540Z digest=sha256:f5a28eed3e94fe719b4c7959b4be4aa872af4c95cd8a515317f721de78503e46

Observation a7c52400-5df9-4352-bfc8-0d86194a92cd · outbound

This paper cites Autodroid: Llm-powered task automation in android.

Measuring the Security of Mobile LLM Agents under Adversarial Prompts from Untrusted Third-Party Channels Autodroid: Llm-powered task automation in android

Reference 73

Resolution
unresolved
no resolver link, observed 2026-08-04T07:06:38.123202Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T07:06:38.123202Z digest=sha256:10d11d9d07c6545de4cdeeb1f79e1ff576ea91d375eb3be3c62424efa7b307f0

Observation 077d67eb-3cee-4220-9fe0-249b7cb1504e · outbound

This paper cites DroidBot-GPT: GPT-powered UI Automation for Android.

Measuring the Security of Mobile LLM Agents under Adversarial Prompts from Untrusted Third-Party Channels DroidBot-GPT: GPT-powered UI Automation for Android

Reference 74

Resolution
unresolved
no resolver link, observed 2026-08-04T07:06:38.125358Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T07:06:38.125358Z digest=sha256:052c3425e5d32cbbea4509607b5f0fd56ad9bd350cd57fcf58d519b26b0794f1

Observation 848eac8b-7613-413b-bd90-4e51f175d1f7 · outbound

This paper cites Dissecting Adversarial Robustness of Multimodal LM Agents.

Measuring the Security of Mobile LLM Agents under Adversarial Prompts from Untrusted Third-Party Channels Dissecting Adversarial Robustness of Multimodal LM Agents

Reference 75

Resolution
unresolved
no resolver link, observed 2026-08-04T07:06:38.127507Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T07:06:38.127507Z digest=sha256:6f334a43feef00d85a69202ae49042558642fba6dcf6bb15c5bfc2c06cab772c

Observation 42f0340d-d8d1-404f-971d-136ec7b942af · outbound

This paper cites From Assistants to Adversaries: Exploring the Security Risks of Mobile LLM Agents.

Measuring the Security of Mobile LLM Agents under Adversarial Prompts from Untrusted Third-Party Channels From Assistants to Adversaries: Exploring the Security Risks of Mobile LLM Agents

Reference 76

Resolution
unresolved
no resolver link, observed 2026-08-04T07:06:38.129664Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T07:06:38.129664Z digest=sha256:87889ba022977bc09f46d9ffc07843e40d361b4d83989e1581d914b4d4a930d7

Observation be2008a9-e718-4f92-ac24-039d8f74acc3 · outbound

This paper cites GuardAgent: Safeguard LLM Agents by a Guard Agent via Knowledge-Enabled Reasoning.

Measuring the Security of Mobile LLM Agents under Adversarial Prompts from Untrusted Third-Party Channels GuardAgent: Safeguard LLM Agents by a Guard Agent via Knowledge-Enabled Reasoning

Reference 77

Resolution
unresolved
no resolver link, observed 2026-08-04T07:06:38.131932Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T07:06:38.131932Z digest=sha256:2082cb2dddb37bb6b4fc47bd3852467d2bdeae5e7adf651ebade14f148903bf7

Observation bd05fd27-4f0e-4221-84b0-9de671b3f133 · outbound

This paper cites Under- standing and detecting overlay-based android malware at mar- ket scales.

Measuring the Security of Mobile LLM Agents under Adversarial Prompts from Untrusted Third-Party Channels Under- standing and detecting overlay-based android malware at mar- ket scales

Reference 78

Resolution
unresolved
no resolver link, observed 2026-08-04T07:06:38.134335Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T07:06:38.134335Z digest=sha256:d4d8ed685c8065ddac2b34ffe2c80145ea5197669a6452f9dadf51c9e658df38

Observation f6594acf-0b67-49e7-b3e5-98d8357b23cd · outbound

This paper cites {Iframes/Popups} are dangerous in mobile {WebView}: Studying and mitigating differential context vulnerabilities.

Measuring the Security of Mobile LLM Agents under Adversarial Prompts from Untrusted Third-Party Channels {Iframes/Popups} are dangerous in mobile {WebView}: Studying and mitigating differential context vulnerabilities

Reference 79

Resolution
unresolved
no resolver link, observed 2026-08-04T07:06:38.136404Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T07:06:38.136404Z digest=sha256:5c79b823d70f60155cc51c1352c4b933ca40bd58c9da23519d734fe25d95b642

Observation 685663bc-a762-4cc2-a462-ddb1c8deee68 · outbound

This paper cites In-Context Defense in Computer Agents: An Empirical Study.

Measuring the Security of Mobile LLM Agents under Adversarial Prompts from Untrusted Third-Party Channels In-Context Defense in Computer Agents: An Empirical Study

Reference 80

Resolution
unresolved
no resolver link, observed 2026-08-04T07:06:38.138263Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T07:06:38.138263Z digest=sha256:549f11182fc6ea85f1247efe27c4d3c4c254d7a8186def1e758e8a30254113b4

Observation 00ece843-2841-4e4c-920f-741b93f918b6 · outbound

This paper cites Benchmarking and defend- ing against indirect prompt injection attacks on large language models.

Measuring the Security of Mobile LLM Agents under Adversarial Prompts from Untrusted Third-Party Channels Benchmarking and defend- ing against indirect prompt injection attacks on large language models

Reference 81

Resolution
unresolved
no resolver link, observed 2026-08-04T07:06:38.140603Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T07:06:38.140603Z digest=sha256:b674ce21d031e338cd80530cd763507ca6aebffba4abcbb115a6901283198f83

Observation ca5295f3-4cd3-4494-800b-26547420341e · outbound

This paper cites Yuan, L.A.

Measuring the Security of Mobile LLM Agents under Adversarial Prompts from Untrusted Third-Party Channels Yuan, L.A

Reference 82

Resolution
unresolved
no resolver link, observed 2026-08-04T07:06:38.142649Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T07:06:38.142649Z digest=sha256:7fe14111c73ef3b028b2c1335d23bf2bdf706662614668bae4920f7362f03ea9

Observation 3f281932-5d65-49e8-8d7a-b745b7c28f33 · outbound

This paper cites R-Judge: Benchmarking Safety Risk Awareness for LLM Agents.

Measuring the Security of Mobile LLM Agents under Adversarial Prompts from Untrusted Third-Party Channels R-Judge: Benchmarking Safety Risk Awareness for LLM Agents

Reference 83

Resolution
unresolved
no resolver link, observed 2026-08-04T07:06:38.144746Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T07:06:38.144746Z digest=sha256:7db27bf8a94d9127169548e6c79d83fdd639f6303b998dfdea70809046e3a5e0

Observation a9b566a5-ee7c-4e37-92ae-3a58e6dc53d0 · outbound

This paper cites Leveraging LLMs and attention-mechanism for automatic annotation of historical maps.

Measuring the Security of Mobile LLM Agents under Adversarial Prompts from Untrusted Third-Party Channels Leveraging LLMs and attention-mechanism for automatic annotation of historical maps

Reference 84

Resolution
unresolved
no resolver link, observed 2026-08-04T07:06:38.146945Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T07:06:38.146945Z digest=sha256:8447f4288ca3db7459ffae4146d01c9c73fb5d0887986ab85dff0a9182d83d06

Observation 9a58d006-8bdf-4b43-8c99-d0ca4e8ce987 · outbound

This paper cites The dark alleys of madison avenue: Understanding malicious adver- tisements.

Measuring the Security of Mobile LLM Agents under Adversarial Prompts from Untrusted Third-Party Channels The dark alleys of madison avenue: Understanding malicious adver- tisements

Reference 85

Resolution
unresolved
no resolver link, observed 2026-08-04T07:06:38.149378Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T07:06:38.149378Z digest=sha256:52e21569dec4e570779c1ed4f9522c5e0ff9d95e9625a2700a1a11d1b12c1dc0

Observation 83d778b0-5208-4d57-920a-5873b4caff8b · outbound

This paper cites Research on third-party libraries in android apps: A taxonomy and systematic literature review.

Measuring the Security of Mobile LLM Agents under Adversarial Prompts from Untrusted Third-Party Channels Research on third-party libraries in android apps: A taxonomy and systematic literature review

Reference 86

Resolution
unresolved
no resolver link, observed 2026-08-04T07:06:38.151478Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T07:06:38.151478Z digest=sha256:357292b93141259a34d755e55311e6f02e2bac6bf7cf083c56730881e49cea56

Observation 9d7ec842-253c-4e49-b352-c27462e692b5 · outbound

This paper cites Appagent: Multimodal agents as smartphone users.

Measuring the Security of Mobile LLM Agents under Adversarial Prompts from Untrusted Third-Party Channels Appagent: Multimodal agents as smartphone users

Reference 87

Resolution
unresolved
no resolver link, observed 2026-08-04T07:06:38.153403Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T07:06:38.153403Z digest=sha256:432c6dcaba789a702a06a6ebc9823710cecbf02939ff7753ada00bc0700d1fbb

Observation a86d7c8c-49a7-4c9f-af6d-dbf61872b44a · outbound

This paper cites Agent Security Bench (ASB): Formalizing and Benchmarking Attacks and Defenses in LLM-based Agents.

Measuring the Security of Mobile LLM Agents under Adversarial Prompts from Untrusted Third-Party Channels Agent Security Bench (ASB): Formalizing and Benchmarking Attacks and Defenses in LLM-based Agents

Reference 88

Resolution
unresolved
no resolver link, observed 2026-08-04T07:06:38.155316Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T07:06:38.155316Z digest=sha256:101f4581b7620baf45f917cf147e87b6a79098ff16010bf99b1505874dc08268

Observation 78b7bcd3-b282-4374-9897-debc9b60c4f8 · outbound

This paper cites Identity confusion in {WebView-based} mobile app- in-app ecosystems.

Measuring the Security of Mobile LLM Agents under Adversarial Prompts from Untrusted Third-Party Channels Identity confusion in {WebView-based} mobile app- in-app ecosystems

Reference 89

Resolution
unresolved
no resolver link, observed 2026-08-04T07:06:38.157447Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T07:06:38.157447Z digest=sha256:35fa150b3128abbc542db5ec89699cb90741090ac63b56fa7d808da5cd17e22a

Observation b93f3110-dcd8-4a69-b6f1-c34dd5be42c6 · outbound

This paper cites Attacking Vision-Language Computer Agents via Pop-ups.

Measuring the Security of Mobile LLM Agents under Adversarial Prompts from Untrusted Third-Party Channels Attacking Vision-Language Computer Agents via Pop-ups

Reference 90

Resolution
unresolved
no resolver link, observed 2026-08-04T07:06:38.159564Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T07:06:38.159564Z digest=sha256:78c6e31d5f3f1c06d5ca7ce85401e171ddbbeef0486741b9bc21e752d0761ad9

Observation 96a7df1a-d014-448a-80d2-bccedc3905e9 · outbound

This paper cites Gpt-4v(ision) is a generalist web agent, if grounded.

Measuring the Security of Mobile LLM Agents under Adversarial Prompts from Untrusted Third-Party Channels Gpt-4v(ision) is a generalist web agent, if grounded

Reference 91

Resolution
unresolved
no resolver link, observed 2026-08-04T07:06:38.161591Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T07:06:38.161591Z digest=sha256:d315651042dd0aa8eba67d1fa40c8d86afd8ca13498cafc6301a360c9cea2bbc

Observation 87524caa-95f4-4643-bee0-1bfaf953c421 · outbound

This paper cites Moba: A two-level agent system for efficient mobile task automation.CoRR, abs/2410.13757, 2024.

Measuring the Security of Mobile LLM Agents under Adversarial Prompts from Untrusted Third-Party Channels Moba: A two-level agent system for efficient mobile task automation.CoRR, abs/2410.13757, 2024

Reference 92

Resolution
unresolved
no resolver link, observed 2026-08-04T07:06:38.163433Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T07:06:38.163433Z digest=sha256:8a381cec1a41bc954282cba54e37e043d5754226e1f530d5af64bef7565d2d46

Observation 6210567d-69dd-4eab-8f75-5da1556b6cbd · outbound

This paper cites Universal and Transferable Adversarial Attacks on Aligned Language Models.

Measuring the Security of Mobile LLM Agents under Adversarial Prompts from Untrusted Third-Party Channels Universal and Transferable Adversarial Attacks on Aligned Language Models

Reference 93

Resolution
unresolved
no resolver link, observed 2026-08-04T07:06:38.165220Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T07:06:38.165220Z digest=sha256:b25f71d74405292a8a3288d06ab58ebad81fa682aebfbf6bb0477fa96105b6a9

Pith citing papers

No inbound Pith citation observations are available.