Examining Risks in the AI Companion Application Ecosystem
Natalie Grace Brigham, Lucy Qin, Tadayoshi Kohno

TL;DR
This paper analyzes the security risks in AI companion apps, identifying threats to users and malicious exploitation, through systematic analysis of 30 apps and ecosystem trends, highlighting issues like data privacy, anthropomorphism, and synthetic media risks.
Contribution
It provides a comprehensive threat model and ecosystem analysis for AI companion applications, highlighting specific risks and informing future security, policy, and technical developments.
Findings
Identified 489 AI companion apps in app stores.
Analyzed 30 apps to understand threat categories.
Highlighted risks related to data sharing, synthetic media, and user manipulation.
Abstract
While computer systems that allow users to interact through conversational natural language (i.e., chatbots) have existed for many years, varying types of applications advertising AI companionship (e.g., Character AI, Replika) have proliferated in recent years due to advancements in large language models. Our work offers a threat model encompassing two distinct risk categories: harms posed to users by AI companion applications, and harms enabled by malicious users exploiting application features. To further understand this application ecosystem, we identified 489 unique apps from the App Store and Play Store that advertised AI companionship. We then systematically conducted and analyzed walkthroughs of a stratified sample of 30 apps with respect to our threat model. Through our analysis, we categorize broader ecosystem trends that provide context for understanding threats and identify…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsAI in Service Interactions · Spam and Phishing Detection · Hate Speech and Cyberbullying Detection
