Xingbang He

h-index: 0 0 citations 2 papers (total)

Papers in Database (1)

attack arXiv Jan 18, 2026 · 11w ago

Zero-Permission Manipulation: Can We Trust Large Multimodal Model Powered GUI Agents?

Yi Qian, Kunwei Qian, Xingbang He et al. · Nanjing University · Ltd +1 more

Attacks VLM-powered Android GUI agents by hijacking UI state between observation and action, achieving 100% success with zero permissions

Prompt Injection Excessive Agency multimodal
PDF