From the 1 of 4 linked papers with an AI index.
4 papers
(A)I Sees What You Don't: Exploiting New Attack Surfaces in Third-Party Mobile Agents
Zidong Zhang, Zhentao Xie, Wenrui Diao +1
The paper investigates new security vulnerabilities in third‑party mobile agents that use vision‑language models, identifying novel attack surfaces such as screen perception gaps a…
Mini-Programs, Mega-Problems: Unveiling OAuth-based Authentication Misuses in Mini-Programs via Dynamic Analysis
Zidong Zhang, Zhentao Xie, Lingyun Ying +4
Mini-programs have become a dominant paradigm for lightweight application deployment within super apps such as WeChat. To support seamless integration, super apps provide OAuth mec…
CAPED: Context-Aware Privacy Exposure Defense for Mobile GUI Agents
Siyu Shen, Fenghao Xu, Wenrui Diao +1
Screenshot-based mobile GUI agents can operate ordinary smartphone apps through the same visual interface as a human user, but this capability also turns every screen observation i…
Lost in Migration: Exposing Android Framework Vulnerabilities in Parallel Java-Kotlin Implementations
Rui Li, Wenrui Diao, Debin Gao
Android has adopted Kotlin alongside Java across apps and core system components. During this shift, we observe parallel implementations in the Android Open Source Project (AOSP) w…