Dissecting Click Fraud Autonomy in the Wild
Tong Zhu, Yan Meng, Haotian Hu, Xiaokuan Zhang, Minhui Xue, Haojin Zhu
摘要
Although the use of pay-per-click mechanisms stimulates the prosperity of the mobile advertisement network, fraudulent ad clicks result in huge financial losses for advertisers. Extensive studies identify click fraud according to click/traffic patterns based on dynamic analysis. However, in this study, we identify a novel click fraud, named humanoid attack, which can circumvent existing detection schemes by generating fraudulent clicks with similar patterns to normal clicks. We implement the first tool ClickScanner to detect humanoid attacks on Android apps based on static analysis and variational AutoEncoders (VAEs) with limited knowledge of fraudulent examples. We define novel features to characterize the patterns of humanoid attacks in the apps' bytecode level. ClickScanner builds a data dependency graph (DDG) based on static analysis to extract these key features and form a feature vector. We then propose a classification model only trained on benign datasets to overcome the limited knowledge of humanoid attacks. We leverage ClickScanner to conduct the first large-scale measurement on app markets (i.e., 120,000 apps from Google Play and Huawei AppGallery) and reveal several unprecedented phenomena. First, even for the top-rated 20,000 apps, ClickScanner still identifies 157 apps as fraudulent, which shows the prevalence of humanoid attacks. Second, it is observed that the ad SDK-based attack (i.e., the fraudulent codes are in the third-party ad SDKs) is now a dominant attack approach. Third, the manner of attack is notably different across apps of various categories and popularities. Finally, we notice there are several existing variants of the humanoid attack. Additionally, our measurements demonstrate the proposed ClickScanner is accurate and time-efficient (i.e., the detection overhead is only 15.35% of those of existing schemes).
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper7
- "Get in Researchers; We're Measuring Reproducibility": A Reproducibility Study of Machine Learning Papers in Tier 1 Security ConferencesDaniel Olszewski, Allison Lu, Carson Stillman, Kevin Warren 等CCS 2023 · 被引用 19 次
- Welcome to the Dark Side: Analyzing the Revenue Flows of Fraud in the Online Ad EcosystemEmmanouil Papadogiannakis, Nicolas Kourtellis, Panagiotis Papadopoulos, Evangelos P. MarkatosWWW 2025 · 被引用 3 次
- Unveiling Collusion-Based Ad Attribution Laundering Fraud: Detection, Analysis, and Security ImplicationsTong Zhu, Chaofan Shou, Zhen Huang, Guoxing Chen 等CCS 2024 · 被引用 3 次
- When Ad Networks Misbehave: Understanding Risks of Semi-Drive-By Splash AdsSong Wu, Bo Wang, Yifan Zhang, Yinfeng Cao 等CCS 2026
- POLICYCOMP: Counterpart Comparison of Privacy Policies Uncovers Overbroad Personal Data Collection PracticesLu Zhou, Chengyongxiao Wei, Tong Zhu, Guoxing Chen 等USENIX Security 2023
它引用的顶会 Paper6
- Reliable Third-Party Library Detection in Android and its Security ApplicationsMichael Backes, Sven Bugiel, Erik DerrCCS 2016 · 被引用 345 次
- TriggerScope: Towards Detecting Logic Bombs in Android ApplicationsYanick Fratantonio, Antonio Bianchi, William K. Robertson, Engin Kirda 等S&P 2016 · 被引用 161 次
- Dark Hazard: Learning-based, Large-Scale Discovery of Hidden Sensitive Operations in Android AppsXiaorui Pan, Xueqiang Wang, Yue Duan, XiaoFeng Wang 等NDSS 2017 · 被引用 69 次
- Smoke Screener or Straight Shooter: Detecting Elite Sybil Attacks in User-Review Social NetworksHaizhong Zheng, Minhui Xue, Hao Lu, Shuang Hao 等NDSS 2018 · 被引用 57 次
- Measuring and Modeling the Label Dynamics of Online Anti-Malware EnginesShuofei Zhu, Jianjun Shi, Limin Yang, Boqin Qin 等USENIX Security 2020
相关 Paper
- Understanding and Detecting Mobile Ad Fraud Through the Lens of Invalid TrafficSuibin Sun, Le Yu, Xiaokuan Zhang, Minhui Xue 等CCS 2021 · 被引用 22 次
- MadDroid: Characterizing and Detecting Devious Ad Contents for Android AppsTianming Liu, Haoyu Wang, Li Li, Xiapu Luo 等WWW 2020 · 被引用 44 次
- Robust Android Malware Detection against Adversarial Example AttacksHeng Li, Shiyao Zhou, Wei Yuan, Xiapu Luo 等WWW 2021 · 被引用 56 次
- The Abuser Inside Apps: Finding the Culprit Committing Mobile Ad FraudJoongyum Kim, Junghwan Park, Sooel SonNDSS 2021
- Careful About What App Promotion Ads Recommend! Detecting and Explaining Malware Promotion via App Promotion GraphShang Ma, Chaoran Chen, Shao Yang, Shifu Hou 等NDSS 2025
