DeUEDroid: Detecting Underground Economy Apps Based on UTG Similarity
Zhuo Chen, Jie Liu, Yubo Hu, Lei Wu, Yajin Zhou, Yiling He, Xianhao Liao, Ke Wang, Jinku Li, Zhan Qin
Abstract
In recent years, the underground economy is proliferating in the mobile system. These underground economy apps (UEware for short) make profits from providing non-compliant services, especially in sensitive areas (e.g., gambling, porn, loan). Unlike traditional malware, most of them (over 80%) do not have malicious payloads. Due to their unique characteristics, existing detection approaches cannot effectively and efficiently mitigate this emerging threat. To address this problem, we propose a novel approach to effectively and efficiently detect UEware by considering their UI transition graphs (UTGs). Based on the proposed approach, we design and implement a system, named DeUEDroid, to perform the detection. To evaluate DeUEDroid, we collect 25, 717 apps and build up the first large-scale ground-truth dataset (1, 700 apps) of UEware. The evaluation result based on the ground-truth dataset shows that DeUEDroid can cover new UI features and statically construct precise UTG. It achieves 98.22% detection F1-score and 98.97% classification accuracy, a significantly better performance than the traditional approaches. The evaluation result involving 24, 017 apps demonstrates the effectiveness and efficiency of UEware detection in real-world scenarios. Furthermore, the result also reveals that UEware are prevalent, i.e., 54% apps in the wild and 11% apps in the app stores are UEware. Our work sheds light on the future work of analyzing and detecting UEware. To engage the community, we have made our prototype system and the dataset available online.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 5a5b317b-a5dc-4c97-8319-abfa79b7cfb5Cited by top-tier papers5
- Combating Concept Drift with Explanatory Detection and Adaptation for Android Malware ClassificationYiling He, Junchi Lei, Zhan Qin, Kui Ren et al.CCS 2025 · 2 citations
- PacDroid: A Pointer-Analysis-Centric Framework for Security Vulnerabilities in Android AppsMenglong Chen, Tian Tan, Minxue Pan, Yue LiICSE 2025 · 1 citation
- CHAMELEOSCAN: Demystifying and Detecting iOS Chameleon Apps via LLM-Powered UI ExplorationHongyu Lin, Yicheng Hu, Haitao Xu, Yanchen Lu et al.NDSS 2026 · 1 citation
- Unveiling the Fragility of Binary Code Similarity Detection via Targeted Attacks with Model ExplanationsMingjie Chen, Tiancheng Zhu, Mingxue Zhang, Yiling He et al.FSE 2026
- Careful About What App Promotion Ads Recommend! Detecting and Explaining Malware Promotion via App Promotion GraphShang Ma, Chaoran Chen, Shao Yang, Shifu Hou et al.NDSS 2025
Builds on13
- Contrastive Multi-View Representation Learning on GraphsKaveh Hassani, Amir Hosein Khas AhmadiICML 2020 · 1,663 citations
- MaMaDroid: Detecting Android Malware by Building Markov Chains of Behavioral ModelsEnrico Mariconti, Lucky Onwuzurike, Panagiotis Andriotis, Emiliano De Cristofaro et al.NDSS 2017 · 471 citations
- IntelliDroid: A Targeted Input Generator for the Dynamic Analysis of Android MalwareMichelle Y. Wong, David LieNDSS 2016 · 253 citations
- Enhancing State-of-the-art Classifiers with API Semantics to Detect Evolved Android MalwareXiaohan Zhang, Yuan Zhang, Ming Zhong, Daizong Ding et al.CCS 2020 · 173 citations
- DeepIntent: Deep Icon-Behavior Learning for Detecting Intention-Behavior Discrepancy in Mobile AppsShengqu Xi, Shao Yang, Xusheng Xiao, Yuan Yao et al.CCS 2019 · 74 citations
Related papers
- TacDroid: Detection of Illicit Apps Through Hybrid Analysis of UI-Based Transition GraphsYanchen Lu, Hongyu Lin, Zehua He, Haitao Xu et al.ICSE 2025
- MadDroid: Characterizing and Detecting Devious Ad Contents for Android AppsTianming Liu, Haoyu Wang, Li Li, Xiapu Luo et al.WWW 2020 · 44 citations
- Enhancing Malware Detection for Android Apps: Detecting Fine-Granularity Malicious ComponentsZhijie Liu, Liang Feng Zhang, Yutian TangASE 2023 · 10 citations
- UIHash: Detecting Similar Android UIs through Grid-Based Visual Appearance RepresentationJiawei Li, Jian Mao, Jun Zeng, Qixiao Lin et al.USENIX Security 2024 · 2 citations
- Fine-Grained In-Context Permission Classification for Android Apps Using Control-Flow Graph EmbeddingVikas Kumar Malviya, Yan Naing Tun, Chee Wei Leow, Ailys Tee Xynyn et al.ASE 2023 · 4 citations
