Poison Once, Control Anywhere: Clean-Text Visual Backdoors in VLM-based Mobile Agents

Open in new window