• español
    • English
  • Login
  • English 
    • español
    • English
  • Publication Types
    • bookbook partconference objectdoctoral thesisjournal articlemagazinemaster thesispatenttechnical documentationtechnical report
View Item 
  •   IMDEA Networks Home
  • View Item
  •   IMDEA Networks Home
  • View Item
JavaScript is disabled for your browser. Some features of this site may not work without it.

The Agent in the Middle: A Security and Privacy Analysis of Android AppFunctions

Share
Files
Main article (16.88Mb)
Identifiers
URI: https://hdl.handle.net/20.500.12761/2072
Metadata
Show full item record
Author(s)
Jackevicius, Tautvydas; Girish, Aniketh; Bandara, Vinuri; Suarez-Tangil, Guillermo; Tapiador, Juan; Vallina-Rodriguez, Narseo
Date
2027-07-19
Abstract
Operating systems are beginning to integrate LLMs as agents capable of autonomously orchestrating actions across applications (apps) and services. Android AppFunctions represents one of the first major implementations of this paradigm, enabling privileged AI assistants to discover and invoke functionality exposed by third-party apps on behalf of users. While this architecture promises more capable and seamless user experiences, it also introduces a new security primitive: a privileged, non-deterministic orchestration layer operating across traditional process and permission boundaries. In this paper, we present the first systematic security and privacy analysis of Android AppFunctions. We develop a comprehensive threat model that characterizes the trust relationships between users, AI executors, the operating system, and AppFunction providers. We identify three fundamental classes of risks: (i) privacy violations, (ii) breaches of OS-enforced access control and process isolation mechanisms, and (iii) LLM-integrity attacks. We experimentally validate seven representative attacks, including three reproduced against commercial deployments on Samsung Galaxy S26 and Google Pixel 10 Pro devices. Our evaluation demonstrates that AI-mediated orchestration can enable permission-transitive information flows, provider-controlled side effects, and promptinjection attacks. We further conduct the first study of AppFunctions deployments in the wild and find that many security-critical decisions are delegated to individual providers, resulting in inconsistent protections and limited platform-level enforcement. Our findings show that AppFunctions challenges current Android security principles, assumptions, and privacy protections. By introducing AI assistants as privileged decision-making entities that can orchestrate actions across otherwise isolated apps, AppFunctions reshape Android’s long-standing trust boundaries. These results highlight the need for new approaches to permission mediation, access control, platform policies, app vetting mechanisms, and AI-agent governance.
Share
Files
Main article (16.88Mb)
Identifiers
URI: https://hdl.handle.net/20.500.12761/2072
Metadata
Show full item record

Browse

All of IMDEA NetworksBy Issue DateAuthorsTitlesKeywordsTypes of content

My Account

Login

Statistics

View Usage Statistics

Dissemination

emailContact person Directory wifi Eduroam rss_feed News
IMDEA initiative About IMDEA Networks Organizational structure Annual reports Transparency
Follow us in:
Community of Madrid

EUROPEAN UNION

European Social Fund

EUROPEAN UNION

European Regional Development Fund

EUROPEAN UNION

European Structural and Investment Fund

© 2021 IMDEA Networks. | Accesibility declaration | Privacy Policy | Disclaimer | Cookie policy - We value your privacy: this site uses no cookies!