acceptodds
Under review as a conference paper at ICLR 2027

ContextGuard: Context-Conditioned Neuro-Symbolic Safety Guardrail for Fine-Grained Intervention in Mobile GUI Agents

Abstract

Mobile GUI agents increasingly perform complex tasks autonomously, making runtime safety mechanisms that account for the evolving interaction context increasingly important. Existing guardrails typically either use context as auxiliary information for model-based risk prediction or enforce predefined safety rules over fixed representations. While model-based approaches can capture contextual risks, their safety judgments may rely on opaque external models and incur additional computational cost, whereas rule-based approaches provide explicit constraints but lack a unified mechanism for grounding evolving interaction context into constraint applicability. We present , a new context-conditioned neuro-symbolic runtime safety guardrail that makes interaction context part of the safety semantics itself. ContextGuard grounds heterogeneous mobile observations into soft semantic predicates capturing interface and action semantics as well as task-dependent and history-dependent context, and incorporates these predicates directly into explicit safety constraints. A neuro-symbolic reasoning module evaluates explicit safety constraints over these predicates, allowing contextual information to directly determine which constraints apply while retaining inspectable constraint-level reasoning. The resulting decisions are mapped to three runtime interventions: , , and . On a diverse evaluation set of 592 task trajectories spanning 10 real mobile applications and 10 safety risk categories under the AndroidLab evaluation setting, ContextGuard achieves 90.9% Binary Accuracy, 4.0% False Positive Rate, and 87.8% Intervention Accuracy, achieving the highest fine-grained Intervention Accuracy among the evaluated baselines. Ablation results show that incorporating task instructions and execution history improves Intervention Accuracy from 56.6% to 87.8%, while adding execution history introduces only 0.11 ms/task of additional guardrail overhead. These results demonstrate that ContextGuard integrates contextual semantics directly into safety constraints, combines flexible semantic grounding with interpretable neuro-symbolic reasoning, and maintains practical guardrail overhead for mobile-agent safety intervention. The source code is available at https://anonymous.4open.science/r/ContextGuard/.

Then back it, or bet against it.

Related papers

Open the market on this paper to see 7 more related papers.