A2 Enhances Android Security With Vulnerability Detection

06 Sep 2025

An innovative AI agent named A2, developed through collaboration between Nanjing University and the University of Sydney, is making notable advancements in Android application security by effectively locating and validating vulnerabilities. Building upon the foundation of its predecessor, the A1 project, which focused on smart contracts, A2 has demonstrated significant potential in its targeted field.

Greater Efficacy in Vulnerability Detection

A2 achieved remarkable results, with a 78.3% coverage on testing, surpassing the 30% coverage recorded by the static analyzer, APKHunt. This accomplishment was demonstrated on 169 real APKs, where A2 identified 104 zero-day vulnerabilities. Of these, 57 vulnerabilities were confirmed by automatically generated exploits. A medium-severity bug was detected in a popular app with over 10 million downloads, posing risks of malicious redirection and unauthorized control.

Unlike its predecessor, A2 introduces a unique validation module. Instead of employing a static verification scheme, A2 breaks down the verification process into specific tasks, confirming vulnerabilities incrementally. An example includes the detection of an AES key stored in plain text, where A2 extracted the key from strings.xml, employed it in generating a fake password reset token, and validated the token's ability to bypass authentication through automated checks at each step.

A2's Multi-Model Architecture

The architecture of A2 integrates an ensemble of large language models, including OpenAI o3, Gemini 2.5 Pro, Gemini 2.5 Flash, and GPT-oss-120b, each fulfilling distinct roles like planning, executing, and validating processes. This distributed model assignment reflects human-style strategy-calculation confirmation, minimizing false positives while fortifying verified outcomes, contrasting with traditional tools often limited by accuracy.

Operational costs associated with A2 range from $0.0004 to $0.03 per app, contingent on the deployed models. Completing a full detection and verification cycle costs on average $1.77. Opting solely for Gemini 2.5 Pro increases this to $8.94 per identified bug, compared to GPT-4's capability of creating an exploit from a vulnerability at around $8.80.

While A2 surpasses Android static analyzers in efficiency, offering potential acceleration in both defensive and offensive cybersecurity research, some experts express concerns regarding vulnerability bounty programs that may not encompass all discovered flaws. The access to A2's source code is currently restricted to partnered researchers, maintaining a balance between accessibility and responsible disclosure.

Top charts for Mobile Android

uTorrent

uTorrent

Latest update uTorrent download for free for Windows PC or Android mobile

5
1032 reviews
6439605
downloads
Zona

Zona

Latest update Zona download for free for Windows PC or Android mobile

4
614 reviews
1295161
downloads
WinRAR

WinRAR

Latest update WinRAR download for free for Windows PC or Android mobile

5
735 reviews
498126
downloads
Minecraft

Minecraft

Latest update Minecraft download for free for Windows PC or Android mobile

5
750 reviews
454487
downloads

News and reviews for Mobile Android

SaverTuner Extends Android Battery Life With System-Level Profiles

SaverTuner app enables Android users to optimize battery life by utilizing built-in system power profiles, reducing overnight standby drain.

Read more

Find Top Android Deals on Black Friday App Discounts

Discover top Android deals this Black Friday with discounts on popular apps and games, impacting global users. Explore new lows in prices.

Read more

Sora Tops Google Play as Most Downloaded Free App

OpenAI's Sora app surpasses ChatGPT on Google Play, reaching 470,000 downloads as key AI features like video creation expand accessibility.

Read more

Capcom Announces Global Release of Survival Unit Game

Resident Evil Survival Unit launches globally on 2023-11-18, offering strategy gameplay on iOS and Android.

Read more

Android Users Seek More Native Apps for Key Services

Android needs native apps for services like Google Finance and Have I Been Pwned to boost user experience.

Read more

Five Services That Need Android Apps for Better Access

Five services lack Android apps, limiting mobile access. New apps could enhance user engagement and convenience.

Read more

Google and Epic Stir Android Game Monetisation

Google and Epic propose new monetisation strategies for Android, potentially reshaping mobile game revenues.

Read more

Android Productivity Apps Enhance Work-Life Balance

Discover how Android apps like Pixel Bookmarks, Google Keep, Clockify, and Notion boost productivity by minimizing distractions.

Read more

QuickTiles Expands Android Quick Settings Customization

QuickTiles enhances Android users' experience with customizable Quick Settings tiles, improving efficiency without root access.

Read more

Samsung Updates RegiStar to Fix Key Bugs

Samsung releases RegiStar update, improving Back Tap and Gemini features on Galaxy devices.

Read more