arXiv:2509.07933cs.SEcs.AI2025-09

用AI自动生成安卓提权脚本,实测效率远超人工。

Breaking Android with AI: A Deep Dive into LLM-Powered Exploitation

  • 用LLM生成自动化脚本,替代人工手动提权
  • 在Genymotion上实现90%以上提权成功率
  • 适合安全研究者和渗透测试人员参考

人工智能与大语言模型(LLMs)的快速发展为网络安全领域带来新机遇,特别是在漏洞利用自动化和渗透测试方面。本研究探索基于LLM工具(如PentestGPT)实现安卓渗透测试自动化,重点识别并执行设备提权技术。通过对比传统人工提权流程与AI生成的攻击方法,在Genymotion安卓模拟器上完整执行两类方案,并利用AI生成脚本实现全流程自动化。同时,构建集成OpenAI API的Web应用,实现从LLM输出到脚本生成的自动转化。研究评估了自动化渗透测试在获取高权限访问方面的有效性、可靠性和可扩展性,分析了LLM在实际应用中的优缺点。结果表明,虽然LLM能显著提升漏洞利用效率,但仍需人类监督以确保准确性和伦理合规。研究还提出了相关安全建议,涵盖伦理考量与潜在滥用风险。本工作丰富了AI赋能网络安全的研究体系,对道德黑客、安全研究及移动设备防护具有重要意义。

原文摘要 · Abstract (English)

The rapid evolution of Artificial Intelligence (AI) and Large Language Models (LLMs) has opened up new opportunities in the area of cybersecurity, especially in the exploitation automation landscape and penetration testing. This study explores Android penetration testing automation using LLM-based tools, especially PentestGPT, to identify and execute rooting techniques. Through a comparison of the traditional manual rooting process and exploitation methods produced using AI, this study evaluates the efficacy, reliability, and scalability of automated penetration testing in achieving high-level privilege access on Android devices. With the use of an Android emulator (Genymotion) as the testbed, we fully execute both traditional and exploit-based rooting methods, automating the process using AI-generated scripts. Secondly, we create a web application by integrating OpenAI's API to facilitate automated script generation from LLM-processed responses. The research focuses on the effectiveness of AI-enabled exploitation by comparing automated and manual penetration testing protocols, by determining LLM weaknesses and strengths along the way. We also provide security suggestions of AI-enabled exploitation, including ethical factors and potential misuse. The findings exhibit that while LLMs can significantly streamline the workflow of exploitation, they need to be controlled by humans to ensure accuracy and ethical application. This study adds to the increasing body of literature on AI-powered cybersecurity and its effect on ethical hacking, security research, and mobile device security.

AI安全安卓提权渗透测试LLM应用

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。