USENIX Security2026Top-tier venue
When Fun Turns Toxic: A First Look at Aggressive Advertising in Mini-games
Pei Chen, Geng Hong, Yicheng Qin, Huazhe Wang, Mengying Wu, Min Yang, Ziru Zhao, Yuanpeng Zhu, Tao Su
Abstract
Mini-games have emerged as a dominant paradigm within super-app ecosystems, enabling lightweight services like casual games to reach millions of users instantly. While official advertisement interfaces simplify monetization, the ease of integration and insufficient oversight have led to aggressive and potentially deceptive advertising practices, severely degrading the user experience. Aggressive advertising, though not malware, still subverts platform security boundaries by abusing legitimate APIs to bypass auditing, manipulate user interaction, and undermine platform trust, constituting a systemic security risk rather than mere policy violation. In this work, we conduct the first systematic security analysis of aggressive advertising in mini-games. We analyze platform policies and developer capabilities across nine minigame platforms, and characterize aggressive advertising behaviors. We further design a scalable detection framework, MAAD, and perform a large-scale measurement across three major platforms, i.e., WeChat, Facebook Instant Games, and Quickgame, revealing that 49.95% of mini-games exhibit aggressive advertising, including cases in highly popular titles with over 100k user reviews. Our analysis further uncovers their disruptive behavioral patterns, such as game-specific triggers, excessive pop-up frequency, and misleading strategies, as well as adversarial bypass techniques. These findings uncover that aggressive advertising constitutes a widespread form of platform abuse enabled by structural blind spots in current enforcement mechanisms. We provide actionable implications for strengthening platform governance, detection, and long-term ecosystem resilience. Repeated pop-ups every +15s ① An ad appears. ③ Ad reappears after 15s.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext e8713fc3-6fb9-4338-ad5e-ea7c832dde9fBuilds on20
- What Mobile Ads Know About Mobile UsersSooel Son, Daehyeok Kim, Vitaly ShmatikovNDSS 2016 · 101 citations
- Demystifying Resource Management Risks in Emerging Mobile App-in-App EcosystemsHaoran Lu, Luyi Xing, Yue Xiao, Yifan Zhang et al.CCS 2020 · 48 citations
- MadDroid: Characterizing and Detecting Devious Ad Contents for Android AppsTianming Liu, Haoyu Wang, Li Li, Xiapu Luo et al.WWW 2020 · 44 citations
- Unveiling the Tricks: Automated Detection of Dark Patterns in Mobile ApplicationsJieshan Chen, Jiamou Sun, Sidong Feng, Zhenchang Xing et al.UIST 2023 · 42 citations
- Cross Miniapp Request Forgery: Root Causes, Attacks, and Vulnerability DetectionYuqing Yang, Yue Zhang, Zhiqiang LinCCS 2022 · 29 citations
Related papers
- MiniChecker: Detecting Data Privacy Risk of Abusive Permission Request Behavior in Mini-ProgramsYin Wang, Ming Fan, Hao Zhou, Haijun Wang et al.ASE 2024 · 2 citations
- Real or Rogue? Detecting Malicious Miniapps with Deceptive Reporting InterfaceYuqing Yang, Zhiqiang LinWWW 2026
- Mini-Programs, Mega-Problems: Unveiling OAuth-based Authentication Misuses in Mini-Programs via Dynamic AnalysisZidong Zhang, Zhentao Xie, Lingyun Ying, Qinsheng Hou et al.CCS 2026
- Raising the Flag: Detecting Missing Permission Controls in Mini-Program APIsZhiao Wei, Chao Wang, Haseeb-Ur-Rehman Faheem, Luyi Xing et al.USENIX Security 2026
- Demystifying Cookie Sharing Risks in WebView-based Mobile App-in-app EcosystemsMiao Zhang, Shenao Wang, Guilin Zheng, Yanjie Zhao et al.ASE 2025 · 1 citation
