Mostrar el registro sencillo del ítem
The Agent in the Middle: A Security and Privacy Analysis of Android AppFunctions
| dc.contributor.author | Jackevicius, Tautvydas | |
| dc.contributor.author | Girish, Aniketh | |
| dc.contributor.author | Bandara, Vinuri | |
| dc.contributor.author | Suarez-Tangil, Guillermo | |
| dc.contributor.author | Tapiador, Juan | |
| dc.contributor.author | Vallina-Rodriguez, Narseo | |
| dc.date.accessioned | 2026-09-18T11:40:45Z | |
| dc.date.available | 2026-09-18T11:40:45Z | |
| dc.date.issued | 2027-07-19 | |
| dc.identifier.citation | [1] Kevin Allix, Tegawendé F. Bissyandé, Jacques Klein, and Yves Le Traon. 2016. AndroZoo: Collecting Millions of Android Apps for the Research Community. In Proceedings of the 13th International Conference on Mining Software Repositories. [2] Android Developers. 2025. The Intelligent OS: Making AI Agents More Helpful for Android Apps. https://developer.android.com/blog/posts/the-intelligent-os- making-ai-agents-more-helpful-for-android-apps [3] Android Developers. 2026. Activity Security. https://developer.android.com/ guide/components/activities/secure-bal#foreground-services [4] Android Developers. 2026. Add the AppFunctions API to Your App. https:// developer.android.com/ai/appfunctions/add-appfunctions [5] Android Developers. 2026. Android AppFunctions Library (Non-Jetpack Ver- sion). https://developer.android.com/reference/android/app/appfunctions/ package-summary [6] Android Developers. 2026. Android Jetpack. https://developer.android.com/ jetpack [7] Android Developers. 2026. The Android Show: Developer’s Cut 2026. https://android-developers.googleblog.com/2026/05/the-android-show- developers-cut-2026.html [8] Android Developers. 2026. AppFunctionManager. https://developer.android.com/ reference/android/app/appfunctions/AppFunctionManager [9] Android Developers. 2026. AppFunctionMetadata. https://developer.android. com/reference/kotlin/android/app/appfunctions/AppFunctionMetadata [10] Android Developers. 2026. AppSearch. https://developer.android.com/develop/ ui/views/search/appsearch [11] Android Developers. 2026. Features and APIs Overview. https://developer.android. com/about/versions/12/features#security-privacy [12] Android Developers. 2026. The Intelligent OS: Making AI Agents Work for You. https://android-developers.googleblog.com/2026/02/the-intelligent-os- making-ai-agents.html [13] Android Developers. 2026. Intents and Intent Filters. https://developer.android. com/training/basics/intents [14] Android Developers. 2026. Overview of AppFunctions. https://developer.android. com/ai/appfunctions [15] Android Developers. 2026. Request App Permissions. https://developer.android. com/training/permissions/requesting [16] Android Open Source Project. 2026. Android AppFunctionManager AIDL Inter- face. https://android.googlesource.com/platform/frameworks/base/+/refs/heads/ main/core/java/android/app/appfunctions/IAppFunctionManager.aidl [17] Eduardo Blázquez, Sergio Pastrana, Álvaro Feal, Julien Gamba, Platon Kotzias, Narseo Vallina-Rodriguez, and Juan Tapiador. 2021. Trouble Over-the-Air: An Analysis of FOTA Apps in the Android Ecosystem. In 2021 IEEE Symposium on Security and Privacy (SP). 1606–1622. [18] Seth Bromberger, Ankur Shah, and Evan R. Murphy. 2025. Mitigating Prompt Injection Attacks with a Layered Defense Strategy. https://security.googleblog. com/2025/06/mitigating-prompt-injection-attacks.html [19] Edoardo Debenedetti, Sahar Jain, Rishub Bhatt, Nicholas Carlini, and Flo- rian Tramèr. 2025. Defeating Prompt Injections by Design. arXiv preprint arXiv:2503.18813 (2025). [20] Álvaro Feal, Julien Gamba, Juan Tapiador, Primal Wijesekera, Joel Reardon, Serge Egelman, and Narseo Vallina-Rodriguez. 2021. Don’t Accept Candy from Strangers: An Analysis of Third-party Mobile SDKs. Data Protection and Privacy: Data Protection and Artificial Intelligence 13 (2021), 1. [21] Julien Gamba, Álvaro Feal, Eduardo Blazquez, Vinuri Bandara, Abbas Razagh- panah, Juan Tapiador, and Narseo Vallina-Rodriguez. 2023. Mules and Permission Laundering in Android: Dissecting Custom Permissions in the Wild. IEEE Trans- actions on Dependable and Secure Computing 21, 4 (2023), 1801–1816. [22] Julien Gamba, Mohammed Rashed, Abbas Razaghpanah, Juan Tapiador, and Narseo Vallina-Rodriguez. 2020. An Analysis of Pre-installed Android Software. In 2020 IEEE Symposium on Security and Privacy (SP). 1039–1055. [23] Aniketh Girish, Tianrui Hu, Vijay Prakash, Daniel J. Dubois, Srdjan Matic, Danny Yuxing Huang, Serge Egelman, Joel Reardon, Juan Tapiador, David Choffnes, et al. 2023. In the Room Where It Happens: Characterizing Local Communication and Threats in Smart Homes. In Proceedings of the 2023 ACM Internet Measurement Conference. 437–456. [24] Google. 2026. Deceptive Behavior. https://support.google.com/googleplay/ android-developer/answer/17006354 [25] Google. 2026. Provide Information for Google Play’s Data Safety Section. https: //support.google.com/googleplay/android-developer/answer/10787469?hl=en [26] Google. 2026. User Data. https://support.google.com/googleplay/android- developer/answer/10144311 [27] Kai Greshake, Sahar Abdelnabi, Shailesh Mishra, Christoph Endres, Thorsten Holz, and Mario Fritz. 2023. More Than You’ve Asked For: A Comprehensive Analysis of Novel Prompt Injection Threats to Application-integrated Large Language Models. arXiv preprint arXiv:2302.12173 (2023). [28] Kaspar Hageman, Álvaro Feal, Julien Gamba, Aniketh Girish, Jakob Bleier, Mar- tina Lindorfer, Juan Tapiador, and Narseo Vallina-Rodriguez. 2023. Mixed Signals: Analyzing Software Attribution Challenges in the Android Ecosystem. IEEE Transactions on Software Engineering 49, 4 (2023), 2964–2979. [29] Juhee Kim, Wenbo Guo, and Dawn Song. 2026. SoK: Attack and Defense Land- scape of Agentic AI Systems. In 35th USENIX Security Symposium (USENIX Secu- rity 26). [30] Deepak Kumar, Riccardo Paccagnella, Paul Murley, Eric Hennenfent, Joshua Mason, Adam Bates, and Michael Bailey. 2018. Skill Squatting Attacks on Amazon Alexa. In 27th USENIX Security Symposium (USENIX Security 18). 33–47. [31] Priyanshu Kumar, Elaine Lau, Saranya Vijayakumar, Tu Trinh, Elaine Chang, Vaughn Robinson, Shuyan Zhou, Matt Fredrikson, Sean Hendryx, Summer Yue, et al. 2025. Aligned LLMs Are Not Aligned Browser Agents. In International Conference on Learning Representations. [32] Codrin-Gabriel Lates. 2026. Android AppFunctions Are Indexed/Enabled on Device but Gemini Cannot Resolve Custom Function Metadata. https://github.com/google- gemini/cookbook/issues/1151 [33] Christopher Lentzsch, Sheel Jayesh Shah, Benjamin Andow, Martin Degeling, Anupam Das, and William Enck. 2021. Hey Alexa, Is This Skill Safe? Taking a Closer Look at the Alexa Skill Ecosystem. In 28th Annual Network and Distributed System Security Symposium (NDSS). [34] LF Projects, LLC. 2026. Architecture Overview – MCP. https:// modelcontextprotocol.io/docs/2026-07-28/learn/architecture#notifications [35] LF Projects, LLC. 2026. What Is the Model Context Protocol (MCP)? https: //modelcontextprotocol.io/docs/getting-started/intro [36] Yi Liu, Gelei Deng, Yuekang Li, Kailong Wang, Zihao Wang, Xiaofeng Wang, Tianwei Zhang, Yepang Liu, Haoyu Wang, Yan Zheng, and Yang Liu. 2023. Prompt Injection Attack Against LLM-integrated Applications. arXiv preprint arXiv:2306.05499 (2023). [37] René Mayrhofer, Jeffrey Vander Stoep, Chad Brubaker, and Nick Kralevich. 2021. The Android Platform Security Model. ACM Transactions on Privacy and Security 24, 3 (2021), 1–35. [38] Matthew McCullough. 2026. The Intelligent OS: Making AI Agents More Help- ful for Android Apps. https://android-developers.googleblog.com/2026/02/the- intelligent-os-making-ai-agents.html [39] MyClaw. 2026. MyClaw: AI Agent Browser. https://myclaw.ai/ [40] NVIDIA. 2025. What OpenClaw Agents Mean for Every Organization. https: //blogs.nvidia.com/blog/what-openclaw-agents-mean-for-every-organization/ [41] Joel Reardon, Álvaro Feal, Primal Wijesekera, Amit Elazari Bar On, Narseo Vallina- Rodriguez, and Serge Egelman. 2019. 50 Ways to Leak Your Data: An Exploration of Apps’ Circumvention of the Android Permissions System. In 28th USENIX Security Symposium (USENIX Security 19). 603–620. [42] Suranga Seneviratne, Aruna Seneviratne, Prasant Mohapatra, and Anirban Ma- hanti. 2015. Your Installed Apps Reveal Your Gender and More! ACM SIGMOBILE Mobile Computing and Communications Review 18, 3 (2015), 55–61. [43] Chongyang Shi, Sharon Lin, Shuang Song, Jamie Hayes, Ilia Shumailov, Itay Yona, Juliette Pluto, Aneesh Pappu, Christopher A. Choquette-Choo, Milad Nasr, et al. 2025. Lessons from Defending Gemini Against Indirect Prompt Injections. arXiv preprint arXiv:2505.14534 (2025). [44] Hao Song, Yiming Shen, Wenxuan Luo, Leixin Guo, Ting Chen, Jiashui Wang, Beibei Li, Xiaosong Zhang, and Jiachi Chen. 2025. Beyond the Protocol: Unveiling Attack Vectors in the Model Context Protocol (MCP) Ecosystem. arXiv preprint arXiv:2506.02040 (2025). https://arxiv.org/abs/2506.02040 [45] Raphael Spreitzer, Veelasha Moonsamy, Thomas Kober, and Stefan Mangard. 2018. Systematic Classification of Side-channel Attacks: A Case Study for Mobile Devices. IEEE Communications Surveys & Tutorials 20, 1 (2018), 465–488. [46] Marcos Tileria, Jorge Blasco, and Guillermo Suarez-Tangil. 2020. WearFlow: Expanding Information Flow Analysis to Companion Apps in Wear OS. In 23rd International Symposium on Research in Attacks, Intrusions and Defenses (RAID 2020). 63–75. [47] Güliz Seray Tuncay, Soteris Demetriou, Karan Ganju, and Carl A. Gunter. 2018. Resolving the Predicament of Android Custom Permissions. In Network and Distributed System Security Symposium (NDSS). [48] Alisha Ukani, Hamed Haddadi, Ali Shahin Shamsabadi, and Peter Snyder. 2025. Privacy Practices of Browser Agents. arXiv preprint arXiv:2512.07725 (2025). [49] Tim Vlummens, Aniketh Girish, Nipuna Weerasekara, Frederik Zuiderveen Bor- gesius, Gunes Acar, Narseo Vallina-Rodriguez, et al. 2026. Bridges to Self: Silent Web-to-App Tracking on Mobile via Localhost. In USENIX Security Symposium. [50] Haoyu Wang, Zhe Liu, Jingyue Liang, Narseo Vallina-Rodriguez, Yao Guo, Li Li, Juan Tapiador, Jingcun Cao, and Guoai Xu. 2018. Beyond Google Play: A Large-scale Comparative Study of Chinese Android App Markets. In Proceedings of the Internet Measurement Conference 2018. 293–307. [51] Yuhao Wu, Franziska Roesner, Tadayoshi Kohno, Ning Zhang, and Umar Iqbal. 2025. IsolateGPT: An Execution Isolation Architecture for LLM-based Agentic Systems. In Network and Distributed System Security Symposium (NDSS). [52] Qiusi Zhan, Zhixiang Liang, Zifan Ying, and Daniel Kang. 2024. InjecAgent: Benchmarking Indirect Prompt Injections in Tool-integrated Large Language Model Agents. In Findings of the Association for Computational Linguistics: ACL 2024. 10471–10506. [53] Kaiyuan Zhang, Mark Tenenholtz, Kyle Polley, Jerry Ma, Denis Yarats, and Ninghui Li. 2025. BrowseSafe: Understanding and Preventing Prompt Injec- tion within AI Browser Agents. arXiv preprint arXiv:2511.20597 (2025). [54] Nan Zhang, Xianghang Mi, Xuan Feng, XiaoFeng Wang, Yuan Tian, and Feng Qian. 2019. Dangerous Skills: Understanding and Mitigating Security Risks of Voice-controlled Third-party Functions on Virtual Personal Assistant Systems. In 2019 IEEE Symposium on Security and Privacy (SP). 1381–1396. [55] Weibo Zhao, Jiahao Liu, Bonan Ruan, Shaofei Li, and Zhenkai Liang. 2025. When MCP Servers Attack: Taxonomy, Feasibility, and Mitigation. arXiv preprint arXiv:2509.24272 (2025). https://arxiv.org/abs/2509.24272 [56] Xiaoyong Zhou, Soteris Demetriou, Dongjing He, Muhammad Naveed, Xiaorui Pan, XiaoFeng Wang, Carl A. Gunter, and Klara Nahrstedt. 2013. Identity, Loca- tion, Disease and More: Inferring Your Secrets from Android Public Resources. In Proceedings of the 2013 ACM SIGSAC Conference on Computer and Communications Security (CCS). 1017–1028. [57] Wei Zou, Runpeng Geng, Binghui Wang, and Jinyuan Jia. 2025. PoisonedRAG: Knowledge Corruption Attacks to Retrieval-Augmented Generation of Large Language Models. In 34th USENIX Security Symposium (USENIX Security 25). 3827–3844. | es |
| dc.identifier.uri | https://hdl.handle.net/20.500.12761/2072 | |
| dc.description.abstract | Operating systems are beginning to integrate LLMs as agents capable of autonomously orchestrating actions across applications (apps) and services. Android AppFunctions represents one of the first major implementations of this paradigm, enabling privileged AI assistants to discover and invoke functionality exposed by third-party apps on behalf of users. While this architecture promises more capable and seamless user experiences, it also introduces a new security primitive: a privileged, non-deterministic orchestration layer operating across traditional process and permission boundaries. In this paper, we present the first systematic security and privacy analysis of Android AppFunctions. We develop a comprehensive threat model that characterizes the trust relationships between users, AI executors, the operating system, and AppFunction providers. We identify three fundamental classes of risks: (i) privacy violations, (ii) breaches of OS-enforced access control and process isolation mechanisms, and (iii) LLM-integrity attacks. We experimentally validate seven representative attacks, including three reproduced against commercial deployments on Samsung Galaxy S26 and Google Pixel 10 Pro devices. Our evaluation demonstrates that AI-mediated orchestration can enable permission-transitive information flows, provider-controlled side effects, and promptinjection attacks. We further conduct the first study of AppFunctions deployments in the wild and find that many security-critical decisions are delegated to individual providers, resulting in inconsistent protections and limited platform-level enforcement. Our findings show that AppFunctions challenges current Android security principles, assumptions, and privacy protections. By introducing AI assistants as privileged decision-making entities that can orchestrate actions across otherwise isolated apps, AppFunctions reshape Android’s long-standing trust boundaries. These results highlight the need for new approaches to permission mediation, access control, platform policies, app vetting mechanisms, and AI-agent governance. | es |
| dc.description.sponsorship | European Cybersecurity Competence Centre | es |
| dc.description.sponsorship | Comunidad de Madrid | es |
| dc.description.sponsorship | Google Ireland Limited | es |
| dc.description.sponsorship | Agencia Estatal de Investigación | es |
| dc.language.iso | eng | es |
| dc.title | The Agent in the Middle: A Security and Privacy Analysis of Android AppFunctions | es |
| dc.type | conference object | es |
| dc.conference.date | 19-24 July 2027 | es |
| dc.conference.place | Delft, Netherlands | es |
| dc.conference.title | Privacy Enhancing Technologies Symposium (was International Workshop of Privacy Enhancing Technologies) | * |
| dc.event.type | conference | es |
| dc.pres.type | paper | es |
| dc.type.hasVersion | AM | es |
| dc.rights.accessRights | open access | es |
| dc.acronym | PETS | * |
| dc.page.final | 20 | es |
| dc.page.initial | 1 | es |
| dc.rank | A | * |
| dc.relation.projectName | EMACS (Metodos Avanzados de Investigacion Basada En la Evidencia en Ciberseguridad) | es |
| dc.relation.projectName | REAL-PETS (Empirical Detection Methods And Privacy-Enhancing Technologies For Real-World Tracking) | es |
| dc.relation.projectName | CYCAD (CIBERSEGURIDAD A DISTANCIA) | es |
| dc.relation.projectName | CYBERACTIONING (Training Cybersecurity Skills through Advanced Higher Education Joint Programmes) | es |
| dc.subject.keyword | Android | es |
| dc.subject.keyword | AppFunctions | es |
| dc.subject.keyword | AI | es |
| dc.subject.keyword | LLM | es |
| dc.subject.keyword | Agents | es |
| dc.subject.keyword | Android Permissions | es |
| dc.subject.keyword | Sandboxing | es |
| dc.subject.keyword | Process Isolation | es |
| dc.description.refereed | TRUE | es |
| dc.description.status | inpress | es |


