safety security
The App Name Changed Every Permission Answer
Android-style tests found multimodal agents treated the same request differently when a calendar app became an unfamiliar music requester.
Summary
Android-style tests found multimodal agents treated the same request differently when a calendar app became an unfamiliar music requester.
Researchers tested four frontier multimodal models on Android-style permission pop-ups embedded in tasks. In one comparison, changing the requesting app from a calendar to PiMusic moved grants from 26 of 32 cases to zero, even when the requested permission stayed the same. Task context also strongly affected decisions, while explanations were inconsistent. The authors propose separating task execution from authorization; their benchmark measures simulated interface choices, not production-device security.
Why it matters
Android-style tests found multimodal agents treated the same request differently when a calendar app became an unfamiliar music requester.
Limits and context
- The authors propose separating task execution from authorization; their benchmark measures simulated interface choices, not production-device security.
Key claims
Android-style tests found multimodal agents treated the same request differently when a calendar app became an unfamiliar music requester.
Qualification: The authors propose separating task execution from authorization; their benchmark measures simulated interface choices, not production-device security.
Evidence: source-2026-08-06-004
Sources
- arXiv preprint 2608.04755arXiv · primary research
Corrections
No corrections have been recorded for this story.