[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"article-open-source-android-ai-agents-host-code-en":3,"article-related-open-source-android-ai-agents-host-code-en":30,"series-research-b08d275c-56cc-4614-b108-a07cbd7657f4":73},{"id":4,"slug":5,"title":6,"content":7,"summary":8,"source":9,"source_url":10,"author":11,"image_url":12,"cover_image":12,"category":13,"language":14,"translated_content":11,"related_article_id":15,"keywords":16,"key_takeaways":22,"views":26,"created_at":27,"published_at":28,"topic_cluster_id":29},"b08d275c-56cc-4614-b108-a07cbd7657f4","open-source-android-ai-agents-host-code-en","Open-Source Android AI Agents Can Run Host Code","\u003Cp data-speakable=\"summary\">Five open-source Android \u003Ca href=\"\u002Ftag\u002Fai-agents\">AI agents\u003C\u002Fa> can be pushed into running commands on the host PC.\u003C\u002Fp>\u003Cp>An Android app with the right permissions can hide text from human eyes, feed it to an \u003Ca href=\"\u002Ftag\u002Fai-agent\">AI agent\u003C\u002Fa>, and end up with code execution on the computer driving that phone. Researchers tested five open-source frameworks and found that every one of them fell to at least six of seven attack paths.\u003C\u002Fp>\u003Ctable>\u003Cthead>\u003Ctr>\u003Cth>Framework\u003C\u002Fth>\u003Cth>Notable weakness\u003C\u002Fth>\u003Cth>Research result\u003C\u002Fth>\u003C\u002Ftr>\u003C\u002Fthead>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Ca href=\"https:\u002F\u002Fgithub.com\u002FOSU-NLP-Group\u002FAppAgent\" target=\"_blank\" rel=\"noopener\">AppAgent\u003C\u002Fa>\u003C\u002Ftd>\u003Ctd>Shell command injection, screenshot race\u003C\u002Ftd>\u003Ctd>Hit by 6 of 7 attacks\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd>\u003Ca href=\"https:\u002F\u002Fgithub.com\u002FOSU-NLP-Group\u002FAppAgentX\" target=\"_blank\" rel=\"noopener\">AppAgentX\u003C\u002Fa>\u003C\u002Ftd>\u003Ctd>Shell command injection, screenshot race\u003C\u002Ftd>\u003Ctd>Hit by 6 of 7 attacks\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd>\u003Ca href=\"https:\u002F\u002Fgithub.com\u002FAlibabaResearch\u002FDAMO-ConvAI\u002Ftree\u002Fmain\u002FMobile-Agent-v3\" target=\"_blank\" rel=\"noopener\">Mobile-Agent-v3\u003C\u002Fa>\u003C\u002Ftd>\u003Ctd>Shell injection path, screenshot race\u003C\u002Ftd>\u003Ctd>Hit by 6 of 7 attacks\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd>\u003Ca href=\"https:\u002F\u002Fgithub.com\u002FTHUDM\u002FOpenAutoGLM\" target=\"_blank\" rel=\"noopener\">Open-AutoGLM\u003C\u002Fa>\u003C\u002Ftd>\u003Ctd>Input broadcast exposure\u003C\u002Ftd>\u003Ctd>Hit by 6 of 7 attacks\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd>\u003Ca href=\"https:\u002F\u002Fgithub.com\u002FBAAI-DCAI\u002FMobA\" target=\"_blank\" rel=\"noopener\">MobA\u003C\u002Fa>\u003C\u002Ftd>\u003Ctd>Input broadcast exposure\u003C\u002Ftd>\u003Ctd>Hit by 6 of 7 attacks\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>What the researchers actually showed\u003C\u002Fh2>\u003Cp>The paper, posted to \u003Ca href=\"https:\u002F\u002Farxiv.org\u002Fabs\u002F2607.00123\" target=\"_blank\" rel=\"noopener\">arXiv\u003C\u002Fa> on July 1 and revised on July 14, comes from researchers at Simon Fraser University, the Chinese University of Hong Kong, Shandong University, and QAX’s Xingtu Lab. The Hacker News checked the code on July 17 and found the risky paths still present in the main branches of all five projects.\u003C\u002Fp>\n\u003Cfigure class=\"my-6\">\u003Cimg src=\"https:\u002F\u002Fxxdpdyhzhpamafnrdkyq.supabase.co\u002Fstorage\u002Fv1\u002Fobject\u002Fpublic\u002Fcovers\u002Finline-1784729008289-7bn6.png\" alt=\"Open-Source Android AI Agents Can Run Host Code\" class=\"rounded-xl w-full\" loading=\"lazy\" \u002F>\u003C\u002Ffigure>\n\u003Cp>The key idea is simple and ugly: the \u003Ca href=\"\u002Ftag\u002Fagent\">agent\u003C\u002Fa> trusts what it sees, and the host machine trusts what the agent types. If an attacker can alter the screenshot, the text input, or the path between those two steps, the model can be turned into a relay for the attacker’s payload.\u003C\u002Fp>\u003Cul>\u003Cli>Five frameworks were tested: AppAgent, AppAgentX, Mobile-Agent-v3, Open-AutoGLM, and MobA.\u003C\u002Fli>\u003Cli>Researchers reported seven attack classes across hidden text, screenshot tampering, overlay tricks, and input abuse.\u003C\u002Fli>\u003Cli>All five frameworks failed at least six of the seven attacks.\u003C\u002Fli>\u003Cli>One payload designed to launch \u003Ca href=\"https:\u002F\u002Flearn.microsoft.com\u002Fen-us\u002Fwindows\u002Fwin32\u002Fapi\u002Fshellapi\u002Fnf-shellapi-shellexecutea\" target=\"_blank\" rel=\"noopener\">calc.exe\u003C\u002Fa> worked in 20 of 20 trials against four frameworks.\u003C\u002Fli>\u003C\u002Ful>\u003Cp>That matters because these tools are built for real automation, not toy demos. Their job is to read a phone screen, decide what to do next, and type on behalf of the user. Once that typing crosses back into the host shell, the attack stops being theoretical.\u003C\u002Fp>\u003Ch2>The easiest path is command injection\u003C\u002Fh2>\u003Cp>The most direct bug was in the way some agents send text to Android Debug Bridge. In \u003Ca href=\"https:\u002F\u002Fgithub.com\u002FOSU-NLP-Group\u002FAppAgent\" target=\"_blank\" rel=\"noopener\">AppAgent\u003C\u002Fa>, the controller calls \u003Ccode>subprocess.run(adb_command, shell=True)\u003C\u002Fcode> and drops model output into \u003Ccode>adb shell input text\u003C\u002Fcode> with no sanitization. The live code only strips spaces and single quotes in some paths, which leaves shell metacharacters free to do their work.\u003C\u002Fp>\u003Cp>That means a string read from the phone can be split by the host shell, with the second half executed on the operator’s Windows machine. The researchers showed a payload that launched Calculator and another that wrote the host working directory to a file using \u003Ccode>test;pwd&gt;rce_success\u003C\u002Fcode>.\u003C\u002Fp>\u003Cblockquote>“Your LLM is not a security boundary.” — Microsoft, in its May 2026 writeup on Semantic Kernel\u003C\u002Fblockquote>\u003Cp>That \u003Ca href=\"\u002Ftag\u002Fmicrosoft\">Microsoft\u003C\u002Fa> line fits this paper well. The model is making decisions, but the security boundary is still the shell, the ADB bridge, and the code that glues them together. If that glue is careless, the model becomes an attacker-controlled input generator.\u003C\u002Fp>\u003Cul>\u003Cli>\u003Ca href=\"https:\u002F\u002Fgithub.com\u002FOSU-NLP-Group\u002FAppAgent\" target=\"_blank\" rel=\"noopener\">AppAgent\u003C\u002Fa> used \u003Ccode>shell=True\u003C\u002Fcode> in the attack path described by the paper.\u003C\u002Fli>\u003Cli>\u003Ca href=\"https:\u002F\u002Fgithub.com\u002FOSU-NLP-Group\u002FAppAgentX\" target=\"_blank\" rel=\"noopener\">AppAgentX\u003C\u002Fa>, \u003Ca href=\"https:\u002F\u002Fgithub.com\u002FAlibabaResearch\u002FDAMO-ConvAI\u002Ftree\u002Fmain\u002FMobile-Agent-v3\" target=\"_blank\" rel=\"noopener\">Mobile-Agent-v3\u003C\u002Fa>, and \u003Ca href=\"https:\u002F\u002Fgithub.com\u002FBAAI-DCAI\u002FMobA\" target=\"_blank\" rel=\"noopener\">MobA\u003C\u002Fa> all accepted payloads that triggered host-side command execution in testing.\u003C\u002Fli>\u003Cli>\u003Ca href=\"https:\u002F\u002Fgithub.com\u002FTHUDM\u002FOpenAutoGLM\" target=\"_blank\" rel=\"noopener\">Open-AutoGLM\u003C\u002Fa> was the only one of the five immune to this specific host injection path.\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>Screenshot races gave attackers a second opening\u003C\u002Fh2>\u003Cp>The next problem is timing. Several frameworks write screenshots to shared storage, then pull them back to the host in a separate step. That split creates a race window. The paper measured gaps from 50 to 500 milliseconds, with an average of about 210 milliseconds over 100 runs.\u003C\u002Fp>\n\u003Cfigure class=\"my-6\">\u003Cimg src=\"https:\u002F\u002Fxxdpdyhzhpamafnrdkyq.supabase.co\u002Fstorage\u002Fv1\u002Fobject\u002Fpublic\u002Fcovers\u002Finline-1784728995967-npzn.png\" alt=\"Open-Source Android AI Agents Can Run Host Code\" class=\"rounded-xl w-full\" loading=\"lazy\" \u002F>\u003C\u002Ffigure>\n\u003Cp>That sounds tiny until you remember how fast a background service can poll a file. The researchers showed that a service checking every 5 to 10 milliseconds had enough time to lock the file, repaint the PNG, and release it before the agent read it. Tampering succeeded 19 out of 20 or 20 out of 20 times against four of the five frameworks.\u003C\u002Fp>\u003Cul>\u003Cli>\u003Ca href=\"https:\u002F\u002Fgithub.com\u002FTHUDM\u002FOpenAutoGLM\" target=\"_blank\" rel=\"noopener\">Open-AutoGLM\u003C\u002Fa> used \u003Ccode>screencap -p \u002Fsdcard\u002Ftmp.png\u003C\u002Fcode> followed by a separate \u003Ccode>adb pull\u003C\u002Fcode>.\u003C\u002Fli>\u003Cli>\u003Ca href=\"https:\u002F\u002Fgithub.com\u002FAlibabaResearch\u002FDAMO-ConvAI\u002Ftree\u002Fmain\u002FMobile-Agent-v3\" target=\"_blank\" rel=\"noopener\">Mobile-Agent-v3\u003C\u002Fa> wrote to a fixed \u003Ccode>\u002Fsdcard\u002Fscreenshot.png\u003C\u002Fcode> and slept 0.5 seconds between steps.\u003C\u002Fli>\u003Cli>\u003Ca href=\"https:\u002F\u002Fgithub.com\u002FOSU-NLP-Group\u002FAppAgent\" target=\"_blank\" rel=\"noopener\">AppAgent\u003C\u002Fa> still defaults its screenshot directory to \u003Ccode>\u002Fsdcard\u003C\u002Fcode> in the shipped config.\u003C\u002Fli>\u003Cli>\u003Ca href=\"https:\u002F\u002Fgithub.com\u002FBAAI-DCAI\u002FMobA\" target=\"_blank\" rel=\"noopener\">MobA\u003C\u002Fa> avoided the file race by streaming screenshots over \u003Ccode>exec-out\u003C\u002Fcode>.\u003C\u002Fli>\u003C\u002Ful>\u003Cp>The cleanest fix here is also the least glamorous: stop writing the screenshot to device storage at all. Stream the image directly to the host, and the attacker loses the file window.\u003C\u002Fp>\u003Ch2>Invisible text, overlays, and fake prompts\u003C\u002Fh2>\u003Cp>The researchers then pushed on the perception layer. They hid instructions in 2% opacity text, in the rounded corners and camera cutouts that phones do not fully render, and in overlays that told the agent to wait. The models read the hidden instructions anyway.\u003C\u002Fp>\u003Cp>All six vision models in the paper detected 2% opacity text in at least 18 of 20 trials, and four models, including \u003Ca href=\"https:\u002F\u002Fopenai.com\u002Findex\u002Fgpt-4o-and-gpt-4o-mini-advancing-ai-for-everyone\u002F\" target=\"_blank\" rel=\"noopener\">GPT-4o\u003C\u002Fa>, \u003Ca href=\"https:\u002F\u002Fwww.anthropic.com\u002Fnews\u002Fclaude-opus-4-5\" target=\"_blank\" rel=\"noopener\">Claude Opus 4.5\u003C\u002Fa>, and \u003Ca href=\"https:\u002F\u002Fdeepmind.google\u002Fmodels\u002Fgemini\u002F\" target=\"_blank\" rel=\"noopener\">Gemini 3 Pro\u003C\u002Fa>, scored 20 out of 20. The weakest model, AutoGLM-Phone, still read the text 18 times out of 20.\u003C\u002Fp>\u003Cp>That is the uncomfortable part: the model does not care that the text is nearly invisible to a human. If the pixels are there, the model can read them. If the pixels sit under a bezel or in a cutout, the screenshot still captures them.\u003C\u002Fp>\u003Cul>\u003Cli>On a Pixel 4, the hidden corner area leaves about 78 pixels of width for payload text.\u003C\u002Fli>\u003Cli>All five agents read payloads hidden in that corner region.\u003C\u002Fli>\u003Cli>None of the five agents stopped the fake login prompt delivered through an accessibility overlay across 100 trials.\u003C\u002Fli>\u003C\u002Ful>\u003Cp>There is a real-world lesson here for anyone shipping agentic phone automation: the screen is not a trustworthy source of truth. If the app can draw over other windows, or if the agent can be shown a screenshot that was altered after capture, the model may follow instructions that no person would notice.\u003C\u002Fp>\u003Ch2>Broadcasts and accessibility make the input path worse\u003C\u002Fh2>\u003Cp>The paper also showed that the text path into Android is often more dangerous than the screen path. \u003Ca href=\"https:\u002F\u002Fgithub.com\u002FTHUDM\u002FOpenAutoGLM\" target=\"_blank\" rel=\"noopener\">Open-AutoGLM\u003C\u002Fa> base64-encodes typed text and sends it to \u003Ccode>ADB_INPUT_B64\u003C\u002Fcode>, an implicit broadcast consumed by \u003Ca href=\"https:\u002F\u002Fgithub.com\u002Fsenzhk\u002FADBKeyBoard\" target=\"_blank\" rel=\"noopener\">ADB Keyboard\u003C\u002Fa>. That keyboard is a legitimate test tool, but it also means any app that can broadcast the same action can inject text.\u003C\u002Fp>\u003Cp>\u003Ca href=\"https:\u002F\u002Fgithub.com\u002FAlibabaResearch\u002FDAMO-ConvAI\u002Ftree\u002Fmain\u002FMobile-Agent-v3\" target=\"_blank\" rel=\"noopener\">Mobile-Agent-v3\u003C\u002Fa> tries to be more selective, sending ASCII through \u003Ccode>adb shell input text\u003C\u002Fcode> and non-ASCII characters through \u003Ccode>ADB_INPUT_TEXT\u003C\u002Fcode>. \u003Ca href=\"https:\u002F\u002Fgithub.com\u002FBAAI-DCAI\u002FMobA\" target=\"_blank\" rel=\"noopener\">MobA\u003C\u002Fa> takes an even rougher approach: if any character in the string is non-ASCII, the whole message goes through the broadcast path in one shot.\u003C\u002Fp>\u003Cp>That matters because broadcasts can be received by any app that registers the same action. No permission prompt appears. The user gets no warning. If an accessibility service is in play, the paper says \u003Ccode>TYPE_VIEW_TEXT_CHANGED\u003C\u002Fcode> can leak plaintext too, including passwords.\u003C\u002Fp>\u003Cul>\u003Cli>\u003Ca href=\"https:\u002F\u002Fgithub.com\u002Fsenzhk\u002FADBKeyBoard\" target=\"_blank\" rel=\"noopener\">ADB Keyboard\u003C\u002Fa> is a test harness, not an attack tool, but it becomes part of the input chain.\u003C\u002Fli>\u003Cli>Open-AutoGLM’s broadcast path can be intercepted by any app listening for the same action.\u003C\u002Fli>\u003Cli>The accessibility-based leak affected all five frameworks in the paper.\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>What this means for developers shipping agent tools\u003C\u002Fh2>\u003Cp>The paper’s authors say they notified maintainers privately before posting the preprint, and The Hacker News found no dedicated security policy on any of the five repositories. That silence matters because these are open-source tools people install themselves, often by following setup docs that explicitly ask them to enable USB debugging and trust a keyboard sidecar.\u003C\u002Fp>\u003Cp>That is a lot of trust to hand to a system that can read hidden text, race your screenshots, and type into your host shell. The fixes the paper recommends are straightforward: remove \u003Ccode>shell=True\u003C\u002Fcode>, pass argument lists instead of concatenated strings, stream screenshots, restrict broadcasts with signature permissions, and compare the foreground app before and after each action.\u003C\u002Fp>\u003Cp>Some problems still need human judgment. The paper says there is no clean software fix for hidden corner pixels caused by hardware cutouts and rounded screens. That is a reminder that agent security is not just about model quality. It is about every boundary between the phone, the host, and the code in between.\u003C\u002Fp>\u003Cp>If you are building or deploying one of these tools, the right question is not whether the model can solve the task. It is whether the surrounding plumbing can survive an attacker who controls a screen, a file, or a broadcast. The next release worth waiting for is the one that removes those trust gaps before anyone else gets to test them in the wild.\u003C\u002Fp>","Researchers showed five Android AI agent frameworks can be tricked into running host PC commands through hidden on-screen text and file races.","thehackernews.com","https:\u002F\u002Fthehackernews.com\u002F2026\u002F07\u002Fopen-source-android-ai-agents-could-let.html",null,"https:\u002F\u002Fxxdpdyhzhpamafnrdkyq.supabase.co\u002Fstorage\u002Fv1\u002Fobject\u002Fpublic\u002Fcovers\u002Finline-1784729008289-7bn6.png","research","en","53ada7ee-eeb4-4675-b8a9-29742e2c8fe4",[17,18,19,20,21],"Android AI agents","command injection","screenshot tampering","open-source security","ADB",[23,24,25],"Five open-source Android agent frameworks were shown vulnerable to hidden-text and host-command attacks.","File-based screenshot handling and shell-based input creation created the biggest risks.","Developers should remove shell execution, stream screenshots, and lock down broadcasts.",1,"2026-07-22T14:02:48.514029+00:00","2026-07-22T14:02:48.506+00:00","b867a62a-7124-4d9a-a5c2-22b6b11793de",{"tags":31,"relatedLang":32,"relatedPosts":36},[],{"id":15,"slug":33,"title":34,"language":35},"open-source-android-ai-agents-host-code-zh","Android AI Agent 會把主機命令跑出來","zh",[37,43,49,55,61,67],{"id":38,"slug":39,"title":40,"cover_image":41,"image_url":41,"created_at":42,"category":13},"302ac5a7-8d8f-462e-88ea-739f7aa89fb1","coderescue-budget-calibrated-recovery-routing-en","CodeRescue routes coding-agent recovery by budget","https:\u002F\u002Fxxdpdyhzhpamafnrdkyq.supabase.co\u002Fstorage\u002Fv1\u002Fobject\u002Fpublic\u002Fcovers\u002Finline-1784703782443-v9xu.png","2026-07-22T07:02:33.432859+00:00",{"id":44,"slug":45,"title":46,"cover_image":47,"image_url":47,"created_at":48,"category":13},"370eab09-3a2b-44cb-8900-2ef2fa2687de","appearance-pointers-region-control-dits-en","Appearance Pointers bring region control to DiTs","https:\u002F\u002Fxxdpdyhzhpamafnrdkyq.supabase.co\u002Fstorage\u002Fv1\u002Fobject\u002Fpublic\u002Fcovers\u002Finline-1784701977102-6s2p.png","2026-07-22T06:32:28.561668+00:00",{"id":50,"slug":51,"title":52,"cover_image":53,"image_url":53,"created_at":54,"category":13},"5df4c442-0663-4423-b917-00de6965f627","gear-cuts-copying-long-context-reasoning-en","GEAR cuts copying in long-context reasoning","https:\u002F\u002Fxxdpdyhzhpamafnrdkyq.supabase.co\u002Fstorage\u002Fv1\u002Fobject\u002Fpublic\u002Fcovers\u002Finline-1784700183820-l53a.png","2026-07-22T06:02:30.227905+00:00",{"id":56,"slug":57,"title":58,"cover_image":59,"image_url":59,"created_at":60,"category":13},"84f909d5-e578-49ad-9f8e-c8cafc7562ea","rag17-sod1-als-nature-medicine-template-en","RAG-17 turns SOD1-ALS data into a template","https:\u002F\u002Fxxdpdyhzhpamafnrdkyq.supabase.co\u002Fstorage\u002Fv1\u002Fobject\u002Fpublic\u002Fcovers\u002Finline-1784678589143-aopn.png","2026-07-22T00:02:48.345502+00:00",{"id":62,"slug":63,"title":64,"cover_image":65,"image_url":65,"created_at":66,"category":13},"33248bb8-c831-4d24-a0e5-b8cc13cac750","survey-of-large-language-models-en","A Survey of Large Language Models","https:\u002F\u002Fxxdpdyhzhpamafnrdkyq.supabase.co\u002Fstorage\u002Fv1\u002Fobject\u002Fpublic\u002Fcovers\u002Finline-1784629987559-3qtb.png","2026-07-21T10:32:29.824097+00:00",{"id":68,"slug":69,"title":70,"cover_image":71,"image_url":71,"created_at":72,"category":13},"332f5dcb-3420-4277-9ac9-4cb3e690c3c7","evaluating-memory-in-llm-agents-en","How to test memory in LLM agents","https:\u002F\u002Fxxdpdyhzhpamafnrdkyq.supabase.co\u002Fstorage\u002Fv1\u002Fobject\u002Fpublic\u002Fcovers\u002Finline-1784628193788-ty9w.png","2026-07-21T10:02:36.648611+00:00",[74,79,84,89,94,99,104,109,114,119],{"id":75,"slug":76,"title":77,"created_at":78},"a2715e72-1fe8-41b3-abb1-d0cf1f710189","ai-predictions-2026-big-changes-en","AI Predictions for 2026: Brace for Big Changes","2026-03-26T01:25:07.788356+00:00",{"id":80,"slug":81,"title":82,"created_at":83},"8404bd7b-4c2f-4109-9ec4-baf29d88af2b","ml-papers-of-the-week-github-research-desk-en","ML Papers of the Week Turns GitHub Into a Research Desk","2026-03-27T01:11:39.480259+00:00",{"id":85,"slug":86,"title":87,"created_at":88},"87897a94-8065-4464-a016-1f23e89e17cc","ai-ml-conferences-to-watch-in-2026-en","AI\u002FML Conferences to Watch in 2026","2026-03-27T01:51:54.184108+00:00",{"id":90,"slug":91,"title":92,"created_at":93},"6f1987cf-25f3-47a4-b3e6-db0997695be8","openclaw-agents-manipulated-self-sabotage-en","OpenClaw Agents Can Be Manipulated Into Failure","2026-03-28T03:03:18.899465+00:00",{"id":95,"slug":96,"title":97,"created_at":98},"a53571ad-735a-4178-9f93-cb09b699d99c","vega-driving-language-instructions-en","Vega: Driving with Natural Language Instructions","2026-03-28T14:54:04.698882+00:00",{"id":100,"slug":101,"title":102,"created_at":103},"a34581d6-f36e-46da-88bb-582fb3e7425c","personalizing-autonomous-driving-styles-en","Drive My Way: Personalizing Autonomous Driving Styles","2026-03-28T14:54:26.148181+00:00",{"id":105,"slug":106,"title":107,"created_at":108},"2bc1ad7f-26ce-4f02-9885-803b35fd229d","training-knowledge-bases-writeback-rag-en","Training Knowledge Bases with WriteBack-RAG","2026-03-28T14:54:45.643433+00:00",{"id":110,"slug":111,"title":112,"created_at":113},"71adc507-3c54-4605-bbe2-c966acd6187e","packforcing-long-video-generation-en","PackForcing: Efficient Long-Video Generation Method","2026-03-28T14:55:02.646943+00:00",{"id":115,"slug":116,"title":117,"created_at":118},"675942ef-b9ec-4c5f-a997-381250b6eacb","pixelsmile-facial-expression-editing-en","PixelSmile Framework Enhances Facial Expression Editing","2026-03-28T14:55:20.633463+00:00",{"id":120,"slug":121,"title":122,"created_at":123},"6954fa2b-8b66-4839-884b-e46f89fa1bc3","adaptive-block-scaled-data-types-en","IF4: Smarter 4-Bit Quantization That Adapts to Your Data","2026-03-31T06:00:36.65963+00:00"]