Agent 与自动化 5.0 · 必读 2026-09-12 · 论文

PriMobiBench: Characterizing Visual Privacy Leakage in VLM-Driven Mobile GUI Agents

截图流驱动的 VLM 移动 GUI agent 引入两类风险:屏幕敏感信息直接泄漏与意外用户画像推断,此前没有标准基准量化PriMobiBench 是首个系统评测截图驱动 mobile agent 视觉隐私的基准,统一数据生成轨迹构造与多模型评测流水线;附带 MobiLeak 数据集覆盖 16 个 App25 个隐私属性2,960 个嵌入隐私实例结果:VLM 直接抽取敏感信息最高 82.5% 成功率;不直接抽取也能聚合视觉线索做约 70% 成功率的画像推断缓解方案在云端处理前遮蔽与任务无关的隐私 UI 元素,画像成功率最多降 58%任务性能仅损失约 8%CCS 2026 全文录用

打开原文回到归档

PriMobiBench: Characterizing Visual Privacy Leakage in VLM-Driven Mobile GUI Agents

Source: https://arxiv.org/abs/2609.13873 · platform: arxiv · authors: Qihang Cen, Tianshuo Cong, Da Song, Xinlei He, Jiaxing Song, Ke Xu, Qi Li · date: 2026-09-12

TL;DR(中文摘要)

截图流驱动的 VLM 移动 GUI agent 引入两类风险:屏幕敏感信息直接泄漏与意外用户画像推断,此前没有标准基准量化。PriMobiBench 是首个系统评测截图驱动 mobile agent 视觉隐私的基准,统一数据生成、轨迹构造与多模型评测流水线;附带 MobiLeak 数据集覆盖 16 个 App、25 个隐私属性、2,960 个嵌入隐私实例。结果:VLM 直接抽取敏感信息最高 82.5% 成功率;不直接抽取也能聚合视觉线索做约 70% 成功率的画像推断。缓解方案在云端处理前遮蔽与任务无关的隐私 UI 元素,画像成功率最多降 58%、任务性能仅损失约 8%。CCS 2026 全文录用。

Summary (English)

PriMobiBench is the first benchmark for visual privacy leakage in screenshot-driven mobile GUI agents: VLMs extract sensitive info with up to 82.5% success and profile users at ~70% from aggregated visual evidence (MobiLeak: 16 apps, 25 attributes, 2,960 instances). Masking task-irrelevant privacy UI elements cuts profiling by up to 58% at ~8% task cost. Accepted at ACM CCS 2026.

Abstract

Mobile GUI agents increasingly rely on Vision-Language Models (VLMs) to automate smartphone tasks by interpreting screenshot streams. However, this design introduces serious and underexplored privacy risks, including direct leakage of sensitive on-screen information and unintended user profiling. The absence of standardized benchmarks makes it difficult to quantify these risks in realistic mobile agent workflows. To address this gap, we propose PriMobiBench, the first benchmark for systematically evaluating privacy leakage and visual profiling in screenshot-driven mobile agents. It provides a unified pipeline for data generation, agent trajectory construction, and multi-model evaluation. We also introduce MobiLeak, a dataset of execution traces from 16 apps, covering 25 privacy attributes with 2,960 embedded privacy instances. Our results reveal substantial risks: (1) VLMs can directly extract sensitive information with up to 82.5% success rate; (2) beyond explicit leakage, they can infer user profiles from aggregated visual evidence with approximately 70% success. We further propose a mitigation that masks privacy-sensitive but task-irrelevant UI elements before cloud processing, reducing profiling success by up to 58% with only approximately 8% performance loss.

基本信息

| 项 | 值 | |------|------| | 论文 ID | 2609.13873 | | 发表 | 2026-09-12 | | 作者 | Qihang Cen, Tianshuo Cong, Da Song, Xinlei He, Jiaxing Song, Ke Xu, Qi Li | | 备注 | Full version of the paper accepted at ACM CCS 2026 | | abs | <https://arxiv.org/abs/2609.13873&gt; | | PDF | <https://arxiv.org/pdf/2609.13873v1&gt; |

入库依据(同日 digest 交叉验证)

论文流水线 2026-09-16 入选:82.5%/70% 数字为「截图流→云端 VLM」架构划基线;opencli 元数据全文核实。