A2 Enhances Android Security With Vulnerability Detection

06 Sep 2025

An innovative AI agent named A2, developed through collaboration between Nanjing University and the University of Sydney, is making notable advancements in Android application security by effectively locating and validating vulnerabilities. Building upon the foundation of its predecessor, the A1 project, which focused on smart contracts, A2 has demonstrated significant potential in its targeted field.

Greater Efficacy in Vulnerability Detection

A2 achieved remarkable results, with a 78.3% coverage on testing, surpassing the 30% coverage recorded by the static analyzer, APKHunt. This accomplishment was demonstrated on 169 real APKs, where A2 identified 104 zero-day vulnerabilities. Of these, 57 vulnerabilities were confirmed by automatically generated exploits. A medium-severity bug was detected in a popular app with over 10 million downloads, posing risks of malicious redirection and unauthorized control.

Unlike its predecessor, A2 introduces a unique validation module. Instead of employing a static verification scheme, A2 breaks down the verification process into specific tasks, confirming vulnerabilities incrementally. An example includes the detection of an AES key stored in plain text, where A2 extracted the key from strings.xml, employed it in generating a fake password reset token, and validated the token's ability to bypass authentication through automated checks at each step.

A2's Multi-Model Architecture

The architecture of A2 integrates an ensemble of large language models, including OpenAI o3, Gemini 2.5 Pro, Gemini 2.5 Flash, and GPT-oss-120b, each fulfilling distinct roles like planning, executing, and validating processes. This distributed model assignment reflects human-style strategy-calculation confirmation, minimizing false positives while fortifying verified outcomes, contrasting with traditional tools often limited by accuracy.

Operational costs associated with A2 range from $0.0004 to $0.03 per app, contingent on the deployed models. Completing a full detection and verification cycle costs on average $1.77. Opting solely for Gemini 2.5 Pro increases this to $8.94 per identified bug, compared to GPT-4's capability of creating an exploit from a vulnerability at around $8.80.

While A2 surpasses Android static analyzers in efficiency, offering potential acceleration in both defensive and offensive cybersecurity research, some experts express concerns regarding vulnerability bounty programs that may not encompass all discovered flaws. The access to A2's source code is currently restricted to partnered researchers, maintaining a balance between accessibility and responsible disclosure.

Top charts for Mobile Android

uTorrent

uTorrent

Latest update uTorrent download for free for Windows PC or Android mobile

5
1032 reviews
7344151
downloads
Zona

Zona

Latest update Zona download for free for Windows PC or Android mobile

4
614 reviews
1696451
downloads
WinRAR

WinRAR

Streamline file management with fast compression, secure your documents, and save space.

5
735 reviews
728254
downloads
Minecraft

Minecraft

Shape environments, explore vast worlds, and survive against monsters with endless creativity.

5
750 reviews
491136
downloads

News and reviews for Mobile Android

Pixel Search Enhances Local Search on Android Devices

Pixel Search app brings streamlined local search capabilities to Android, offering quick access to apps, files, and contacts.

Read more

Exclusive App Deals Boost Android Users' Options

A range of app deals enhances Android options this week, featuring games and customization apps with significant price cuts.

Read more

Local Desktop Enables Full Linux Experience on Android

Local Desktop app allows Android devices to run Arch Linux without root, enhancing utility with desktop environments and apps.

Read more

Android 16 Eliminates Need for Third-Party Cleaner Apps

Android 16, released by Google, replaces third-party cleaner apps with built-in tools, enhancing security and efficiency.

Read more

Deezer Overhauls Android TV App for Enhanced Experience

Deezer upgrades its Android TV app for better speed, visuals, and Hi-Fi audio. Release begins on Google Play, with plans for Fire TV expansion.

Read more

Pepelo 2 Launches on iOS and Android with Global Levels

Tafusoft has released Pepelo 2 for iOS and Android, featuring global-inspired levels. The game offers enhanced visuals and expanded gameplay.

Read more

Intrusion Logging Feature Surfaces in Android Update

Google's Intrusion Logging emerges in Android Advanced Protection, with encrypted logs for enhanced security scrutiny.

Read more

Launches AutoSecT: AI-Driven Vulnerability Scanner

AutoSecT debuts as an AI-powered Android vulnerability scanner, enhancing security for enterprise apps by identifying and verifying threats.

Read more

New Android App Deals: Big Price Drops Today

Discover today's top Android app deals, featuring price drops on Maneater, Pocket Stables, and more. Find exciting options for your device.

Read more

New App Deals: Maneater, Pocket Stables Top Discounts

Android app deals on 2026-01-15 include discounts on Maneater and Pocket Stables, offering major savings for users.

Read more