MATE: Policy-Aware Security Auditing for Mobile Agents via Synthesis-Driven Trajectory Learning

📅 2026-09-18
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
本文提出MATE,一种轻量级策略感知审计方法,通过合成驱动的轨迹学习来解决移动代理在执行多步骤工作流时违反安全策略的问题。
📝 Abstract
Mobile agents powered by foundation models now automate complex, multi-step workflows on real devices, but their trajectories can violate app-specific security policies. Existing trajectory-level defenses rely on LLM prompting or rigid rules, and thus fail to support fine-grained, natural-language policies that generalize across apps and tasks. In this work, we introduce MATE, a lightweight, policy-conditioned auditor that encodes both agent trajectories and natural-language security policies to determine whether a trajectory violates a given policy and to explain why. Treating policies as editable text rather than fixed model parameters allows MATE to handle user-defined and evolving requirements without retraining. To construct MATE, we build a knowledge base by extracting app descriptions, workflows, and policies from hundreds of popular mobile apps worldwide, and synthesizing over 140K semantically realistic, policy-conditioned trajectories with a multi-stage pipeline. We further release MATEBench, a trajectory-level auditing benchmark with two synthetic subsets and one real-world subset of manually collected trajectories. Models trained with our synthesis-driven trajectory learning achieve over 95% accuracy on MATEBench, retain strong performance on external safety benchmarks, and audit trajectories from Zhipu's AutoGLM and Alibaba's Mobile-Agent on real devices with over 95% accuracy, outperforming prior methods by over 20%. MATE shows that practical, fine-grained security auditing for heterogeneous mobile agents is both feasible and effective.
Problem

Research questions and friction points this paper is trying to address.

Mobile Agents
Security Policies
Trajectory Learning
Natural-Language Policies
Security Auditing
Innovation

Methods, ideas, or system contributions that make the work stand out.

policy-aware auditing
synthesis-driven trajectory learning
natural-language policies
lightweight auditor
MATEBench
💼 Related Jobs
No related jobs found.
C
Changyue Jiang
Fudan University, Shanghai Innovation Institute
J
Jiayi Wang
Fudan University
X
Xin Wen
Fudan University
Jiarun Dai
Jiarun Dai
Assistant Professor, Fudan Univerisity
Vulnerability DetectionAI System Security
Geng Hong
Geng Hong
Fudan University
SecurityCybercrimeLLM Security and Safety
X
Xudong Pan
Fudan University, Shanghai Innovation Institute