CHAMELEOSCAN: Demystifying and Detecting iOS Chameleon Apps via LLM-Powered UI Exploration
Hongyu Lin, Yicheng Hu, Haitao Xu, Yanchen Lu, Mengxia Ren, Shuai Hao, Chuan Yue, Zhao Li, Fan Zhang, Yixin Jiang
Abstract
Chameleon apps evade iOS App Store review by presenting legitimate functionality during submission while transforming into illicit variants post-installation. While prevalent, their underlying transformation methods and developer-user collusion dynamics remain poorly understood. Existing detection approaches, constrained by static analysis or metadata dependencies, prove ineffective against hybrid implementations, novel variants, or metadata-scarce instances. To address these limitations, we establish a curated dataset of 500 iOS Chameleon apps collected through covert distribution channels, enabling systematic identification of 10 categories of distinct transformation patterns (including 4 previously undocumented variants). Building upon these findings, we present ChameleoScan, the first LLM-driven automated UI exploration framework for reliable Chameleon app verification. The system maintains local decision interpretability while ensuring global detection consistency through its core innovation - predictive metadata analytics, semantic interface comprehension, and human-comparable interaction strategies. Comprehensive evaluation on 1,644 iOS apps demonstrates operational efficacy (9.85% detection rate, 92.59% precision), with findings formally acknowledged by Apple. Implementation and datasets are available at https://github.com/ChameleoScan.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext cff4b943-c2a8-479b-b3c1-8210eb0ba16eBuilds on15
- Enabling Conversational Interaction with Mobile UI using Large Language ModelsBryan Wang, Gang Li, Yang LiCHI 2023 · 149 citations
- AutoDroid: LLM-powered Task Automation in AndroidHao Wen, Yuanchun Li, Guohong Liu, Shanhui Zhao et al.MobiCom 2024 · 94 citations
- Mapping Natural Language Instructions to Mobile UI Action SequencesYang Li, Jiacong He, Xin Zhou, Yuan Zhang et al.ACL 2020 · 75 citations
- Short Text, Large Effect: Measuring the Impact of User Reviews on Android App Security & PrivacyDuc Cuong Nguyen, Erik Derr, Michael Backes, Sven BugielS&P 2019 · 66 citations
- Identifying Key Features from App User ReviewsHuayao Wu, Wenjun Deng, Xintao Niu, Changhai NieICSE 2021 · 44 citations
Related papers
- Beyond Jailbreak: Unveiling Risks in LLM Applications Arising from Blurred Capability BoundariesYunyi Zhang, Shibo Cui, Baojun Liu, Jingkai Yu et al.NDSS 2026
- A Longitudinal Study of Removed Apps in iOS App StoreFuqi Lin, Haoyu Wang, Liu Wang, Xuanzhe LiuWWW 2021 · 20 citations
- Unveiling the Tricks: Automated Detection of Dark Patterns in Mobile ApplicationsJieshan Chen, Jiamou Sun, Sidong Feng, Zhenchang Xing et al.UIST 2023 · 42 citations
- A Sanity Check for AI-generated Image DetectionShilin Yan, Ouxiang Li, Jiayin Cai, Yanbin Hao et al.ICLR 2025
- AdsDP: A Video Dataset for Recognizing and Examining Dark Patterns in iOS In-App AdvertisementsYuxuan Shang, Guanxiao Wang, Mengxia Ren, Haomin Zhang et al.UbiComp 2025 · 1 citation
