AnTrap injects runtime anomalies into Android GUI agent trajectories and finds all 16 leading models degrade, with state deadlock unfixable by training
Posted 25 August (arXiv 2608.24099), AnTrap is a benchmark that injects dynamic perturbations, from unexpected pop-ups to action misuse, into live GUI agent execution, organized by a taxonomy of four layers (State, Thinking, Action, Round) and ten subcategories, with a construction pipeline that preserves task solvability. Evaluating 16 leading GUI models shows universal vulnerability, with even the strongest suffering significant degradation. The useful separation comes from their GRPO training in both clean and adversarial environments: single-step traps at the state and action layers are largely learnable through adversarial RL, but deep contextual traps like state deadlock are reasoning bottlenecks that training in trap-laden environments alone does not resolve.
Source
↳ Follow the thread