UI-CTX: Understanding UI Behaviors with Code Contexts for Mobile Applications

Jiawei Li

Network and Distributed System Security (NDSS) Symposium 2025 · Day 1 · Privacy & Usability 1 · Privacy & Usability 1

Overview

This talk, presented by Jiawei Li at the NDSS Symposium, introduces UI-CTX, a novel approach for understanding the intended behaviors of UI widgets in mobile applications by analyzing their underlying code context. The core problem addressed is the pervasive inconsistency between a UI widget's apparent function (e.g., a "login" button) and its actual runtime behavior (e.g., silently exfiltrating credentials). Such discrepancies pose significant security threats, as users may unknowingly trigger malicious actions by interacting with seemingly innocuous UI elements. UI-CTX aims to bridge this gap by providing an accurate, concise, and robust representation of UI behaviors.

Watch on YouTube · Slides

Key moments

  1. 0:00 Inconsistent UI widget behavior causes security threats
  2. 0:50 Limitations of existing UI behavior analysis approaches
  3. 2:40 Three key challenges in using code context for UI behaviors
  4. 5:20 Novel insights to accurately understand UI behaviors
  5. 6:00 Overview of the proposed UI-CTX system architecture
  6. 7:00 How UI-CTX accurately binds widgets to code contexts
  7. 8:00 Reducing unnecessary code from third-party libraries

UI-CTX: Understanding UI Behaviors with Code Contexts for Mobile Applications

Speakers: Jiawei Li

Conference: NDSS Symposium

YouTube: https://www.youtube.com/watch?v=NrXaOWgBhtk

Overview

This talk, presented by Jiawei Li at the NDSS Symposium, introduces UI-CTX, a novel approach for understanding the intended behaviors of UI widgets in mobile applications by analyzing their underlying code context. The core problem addressed is the pervasive inconsistency between a UI widget's apparent function (e.g., a "login" button) and its actual runtime behavior (e.g., silently exfiltrating credentials). Such discrepancies pose significant security threats, as users may unknowingly trigger malicious actions by interacting with seemingly innocuous UI elements. UI-CTX aims to bridge this gap by providing an accurate, concise, and robust representation of UI behaviors.

The research highlights the limitations of existing methods that rely on visual appearance or requested permissions, which often fail to capture the true operational semantics. Instead, UI-CTX delves into the code behind UI widgets, proposing a systematic framework called USCTS (UI-CTX System) to extract, represent, and investigate these behaviors. This work is crucial for enhancing mobile application security, enabling more effective detection of malicious apps, and providing a deeper understanding of app functionality beyond surface-level observations.

Jiawei Li's presentation underscores the importance of correctly interpreting UI widget behaviors to counter sophisticated threats where malicious functionalities are hidden behind legitimate-looking interfaces. By focusing on the direct code execution paths triggered by UI interactions, UI-CTX offers a powerful tool for security analysts, researchers, and app developers to identify and mitigate these subtle, yet dangerous, inconsistencies. The methodology promises a more reliable way to uncover hidden data collection, unauthorized actions, or other nefarious activities embedded within mobile applications.

Background

▶ Watch: Inconsistent UI widget behavior causes security threats (0:00)

Mobile applications heavily rely on UI widgets (buttons, input fields, etc.) to facilitate user interaction and trigger specific functionalities. Ideally, the function implied by a widget's design should align with its actual behavior. However, this is not always the case, leading to significant security vulnerabilities. For instance, a "login" button might not only verify credentials but also surreptitiously collect and transmit user data to an unauthorized server. Identifying and understanding these discrepancies is paramount for mobile security.

Previous research into UI behavior representation has explored three main directions, each with inherent limitations:

  1. Appearance-based approaches: These methods utilize the image, text, or visual layout associated with UI widgets to infer their behavior. While intuitive, they often fail to capture the actual backend code execution. As such, they cannot recognize the true, potentially hidden, intended behaviors because they don't touch the underlying implementation logic.
  2. Permission-based approaches: These approaches attempt to infer UI behaviors based on the permissions requested by the application (e.g., INTERNET, SMS). The drawback here is the coarse granularity of permissions. Many distinct behaviors, such as "login" and "send email," might both require android.permission.INTERNET, making it difficult to distinguish between them based solely on permissions. The complexity of modern app behaviors often leads to shared permissions, reducing the efficacy of this approach for fine-grained analysis.
  3. Code-based approaches: Recognizing that the code behind UI widgets contains the most detailed descriptions of their behaviors, these methods aim to analyze the actual program logic. For example, a code graph might show information being retrieved from user input and then sent out for verification. While promising, existing code-based solutions face several significant challenges that limit their accuracy and conciseness:
  • Over-automated Widget-Code Context Pairing: Traditional methods often use variable reachability analysis, tracking data flow from UI values to backend event handlers. This approach can lead to numerous false connections between UI widgets and event handlers. For example, a temporal variable might be associated with a UI widget and then flow into multiple event callbacks, creating ambiguity about the true handler for a specific UI interaction. This makes it difficult to precisely bind a UI widget to its correct code context.
  • Unreachable Code in Event Callbacks: Even when an accurate event callback is identified, not all code within that callback may be executed during runtime. Applications often incorporate conditional logic (e.g., checking UI widget conditions) that determines which code branches are active. Existing solutions often fail to prune these unreachable code blocks, leading to an overly broad and inaccurate representation of the widget's true behavior.
  • Unnecessary Code Context from Libraries: Mobile applications frequently integrate third-party libraries and Software Development Kits (SDKs) to implement common functionalities, such as HTTP requests for internet access. The problem is that these libraries introduce a vast amount of extraneous code that obscures the core behavior triggered by a UI widget. An empirical analysis conducted by the researchers on 20,000 applications revealed that in 88% of applications, over 30% of function calls originate from internal libraries, and in over half of applications, internal APIs constitute over 60% of the code. This bloat makes it challenging to pinpoint the essential operational logic.
  • Obfuscated Function Semantics: Code shrinking and protection technologies are widely used to obfuscate application binaries, often renaming classes and functions to meaningless strings (e.g., HttpClient becoming a.z). This obfuscation causes the loss of critical functional semantics that would otherwise be conveyed by descriptive names, hindering static analysis efforts to understand code behavior.

These challenges highlight the need for a more sophisticated approach to accurately and concisely represent UI widget behaviors using their underlying code context, which UI-CTX aims to provide.

Key Findings

▶ Watch: Three key challenges in using code context for UI behaviors (2:40)

The researchers developed UI-CTX based on three core insights designed to overcome the limitations of prior code-based analysis methods. These insights form the foundation of their proposed framework, USCTS, which facilitates a more accurate and concise understanding of UI behaviors:

  1. Event Handler-Centric Analysis: Instead of attempting to trace variable reachability from UI widgets to their code contexts, UI-CTX reverses the approach. It starts the analysis from the event handler itself. From an identified event handler, it performs backward tracking to determine the specific UI widget that triggers it. This ensures a guaranteed connection between the UI widget and its corresponding event handler, eliminating the ambiguity and false positives associated with forward reachability analysis. Once the UI widget is confirmed, forward tracking is then used from the event handler to identify the relevant code context.
  2. Abstraction and Summarization of External Libraries: To address the issue of unnecessary code context introduced by third-party libraries and SDKs, UI-CTX proposes abstracting and summarizing these external components. By focusing on the core behaviors rather than the intricate details of library implementations, the approach significantly reduces the noise in the code context. This allows the analysis to concentrate on the unique functionalities implemented by the application itself, which are directly relevant to the UI widget's behavior.
  3. Opcode-based Functional Semantics: To counter the obfuscation of class and function names, UI-CTX leverages the fundamental unit of functions: instruction opcodes. Rather than relying on potentially obfuscated names, the system uses the sequence and types of opcodes to represent the functional semantics of code blocks. This provides a robust and resilient way to understand what a function does, even when its symbolic names have been stripped or altered.

The evaluation of USCTS demonstrated its superior performance compared to existing representations like permission sets and call sequences across various UI behaviors related to account management and data operations. Specifically, the contributions of code content pruning (removing unreachable code), API summary (abstracting libraries), and opcode embedding were shown to significantly improve the accuracy and informativeness of UI behavior classification. A notable case study involving a malicious "net button" further validated USCTS's ability to accurately identify and represent hidden malicious behaviors in real-world applications.

Technical Deep Dive

▶ Watch: Novel insights to accurately understand UI behaviors (5:20)

The USCTS (UI-CTX System) framework is an end-to-end approach designed to build, summarize, and embed the semantics of UI behaviors into a meaningful representation. It comprises three main parts: Knowledge Extraction, UG Construction, and Behavior Investigation.

1. Knowledge Extraction

This initial phase focuses on gathering comprehensive information from both the UI and code layers of a mobile application.

  • UI Layer Semantic Extraction:
  • The system analyzes the application's layout files (e.g., XML files in Android) to identify unique UI widgets. This involves extracting layout IDs and widget IDs to create distinct labels for each UI element.
  • Once identified, the system also extracts associated textual content (asserted text) and image information (e.g., image descriptions or resource IDs) from the UI widgets, which can provide initial semantic hints.
  • Code Layer Semantic Extraction:
  • The application's binary is subjected to reverse engineering to obtain its intermediate representation (IR) or bytecode (e.g., Android Dalvik bytecode or Java bytecode). This step is crucial for static analysis without requiring the original source code.
  • From the reverse-engineered code, the system identifies event handlers (e.g., setOnClickListener, onTouchListener), method implementations, and individual code blocks. These elements form the raw material for understanding the operational logic.

2. UG Construction (UI Graph)

The objective of this phase is to bind UI widgets with their relevant code contexts into a representation called a UI Graph (UG). The construction process emphasizes accuracy and conciseness, directly addressing the challenges identified earlier.

  • Event Handler-Centric Binding:
  • Instead of starting from UI widgets, USCTS initiates its analysis from identified event handlers. For example, it looks for calls to setOnClickListener.
  • From these event handler registrations, the system performs backward tracking through the control flow graph to identify the specific UI widget ID that registers this handler. This ensures that the identified UI widget is definitively connected to the event handler, resolving the ambiguity of variable reachability analysis.
  • The code within this identified event handler serves as the initial code context for predicting the UI widget's intended behavior.
  • Accurate Code Branch Pruning:
  • Once the correct event handler is identified, USCTS refines the code context by identifying and pruning unreachable code branches.
  • It analyzes conditional statements within the event handler, checking conditions related to the UI widget's ID or state. Only the code branches that can actually be executed during runtime, given the context of the UI interaction, are retained. This step ensures that the representation of the widget's behavior is accurate and does not include irrelevant or dead code.
  • Internal Library Summarization:
  • To reduce the bloat from third-party libraries, USCTS employs a summarization technique. It works by passing essential information from child nodes (e.g., functions within a library) up to their parent nodes (e.g., the application's calling function).
  • For example, instead of including the entire call graph of an HTTP library, USCTS might summarize its functionality as "makes HTTP request," reducing the complexity while retaining the core semantic. This allows the system to focus on the unique, application-specific behaviors triggered by the UI widget, rather than the generic functionalities provided by external dependencies. The speaker specifically mentioned passing the opcode information of sub-functions to their parent functions during this summarization.

After these steps, each UI widget is associated with an accurate and consistent UG that represents its pruned and summarized behavior.

3. Behavior Investigation

With the UG constructed, the final phase involves investigating and classifying the UI behaviors.

  • Graph Embedding:
  • The UG, being a graph structure, captures both the structural information and node features of the UI behavior.
  • Structural Information: USCTS considers global graph properties such as community structure and connectivity patterns. Graph labeling metrics are utilized to capture these global structural characteristics, providing insight into how different code components interact within the context of the UI behavior.
  • Node Information (Opcode Embedding): To capture instruction-level node features and overcome obfuscation, USCTS uses opcodes. The opcode sequence within each code block is extracted. To create a numerical representation, the system calculates the average pooling (representing central tendency) and the standard deviation (representing dispersion) of the opcode embeddings. This provides a robust and informative vector representation of the functional semantics of each node in the graph, resilient to name obfuscation.
  • Behavior Classification:
  • Based on the embedding of the UG (combining structural and opcode features), USCTS groups UGs with similar behavioral patterns. This allows for the classification of UI widgets into predefined categories of behavior (e.g., login, data upload, payment).
  • The evaluation was conducted on eight UI behaviors related to account management and data operation, which are prevalent in mobile applications.

The overall framework of USCTS provides a powerful mechanism to transform raw application code into a semantically rich and actionable representation of UI widget behaviors, enabling more effective security analysis.

Demo / Proof of Concept

▶ Watch: How UI-CTX accurately binds widgets to code contexts (7:00)

While the talk did not feature a live, interactive demo, Jiawei Li presented a compelling case study to illustrate UI-CTX's capability in real-world application analysis. The example involved a "net button" found in a real-world mobile application, which, despite its innocuous appearance, harbored malicious functionality.

The speaker described how this "net button" initialized a series of covert actions:

  1. Collecting phone numbers: The button's code context included instructions to gather sensitive user data, specifically phone numbers.
  2. Zipping them into a file: After collection, the phone numbers were compressed into a file, likely to prepare them for exfiltration and minimize detection.
  3. Sending them via email and HTTP: The zipped file containing the phone numbers was then transmitted out of the device using multiple channels—both email and HTTP requests. This dual exfiltration mechanism increases the likelihood of success for the attacker.

The UI Graph (UG) generated by USCTS for this "net button" accurately reflected this complex and malicious sequence of behaviors. The graph's nodes and edges, informed by the pruned code context and opcode-based semantics, clearly indicated the data collection, packaging, and multi-channel exfiltration. This demonstrated that USCTS could effectively identify and represent such sophisticated malicious behaviors, which would likely be missed by appearance-based or permission-based analysis due to the button's benign UI and potentially broad permissions.

The successful identification of this malicious behavior in a real-world app highlights UI-CTX's potential to facilitate robust security analysis, enabling defenders to uncover hidden threats that manipulate user trust through deceptive UI elements.

Defensive Implications

▶ Watch: Reducing unnecessary code from third-party libraries (8:00)

The UI-CTX framework, and specifically the USCTS implementation, offers significant defensive implications for enhancing mobile application security. By providing an accurate and concise understanding of UI widget behaviors, it empowers defenders to:

  1. Detect Hidden Malicious Functionality: UI-CTX can identify instances where seemingly harmless UI elements (e.g., a "Login" button, a "Cancel" button, or an unlabelled widget) secretly trigger malicious actions like data exfiltration, unauthorized purchases, or installation of other malware. This capability is crucial for uncovering UI-based phishing, covert data collection, and trojanized applications where malicious code is disguised behind legitimate interfaces.
  2. Improve Application Security Audits: Security analysts can integrate UI-CTX into their static analysis pipelines to automatically generate behavior profiles for UI widgets. This allows for more comprehensive and efficient security audits, highlighting suspicious behaviors that deviate from expected functionality or privacy policies. It can help prioritize manual review efforts by flagging high-risk UI interactions.
  3. Enhance Malware Analysis and Attribution: For malware analysts, UI-CTX provides a deeper understanding of how malicious apps interact with users and perform their illicit activities. By accurately mapping UI interactions to code behaviors, analysts can better understand attack chains, identify specific data points being targeted, and potentially attribute malware to specific threat actors based on unique behavioral patterns.
  4. Support Automated Vulnerability Discovery: The detailed behavioral representations generated by USCTS can be used as input for automated vulnerability scanning tools. These tools could leverage the UG to identify unusual data flows, sensitive API calls triggered unexpectedly by a UI element, or violations of security policies related to user interaction.
  5. Facilitate Privacy Compliance: With increasing regulatory scrutiny on user data privacy, UI-CTX can help identify if UI widgets are collecting more data than explicitly consented to or implied by their function. This aids in ensuring applications comply with regulations like GDPR or CCPA by making explicit the data collection practices linked to user interactions.
  6. Develop More Robust Security Policies: The insights gained from UI-CTX can inform the creation of more granular and effective security policies for mobile app stores or enterprise mobile device management (MDM) solutions. Policies could be designed to flag or reject applications exhibiting specific risky UI-triggered behaviors that are not transparent to the user.
  7. Aid in Reverse Engineering Obfuscated Apps: By relying on opcodes for functional semantics rather than obfuscated names, UI-CTX provides a resilient analysis method. This is particularly valuable when dealing with highly obfuscated or protected applications, allowing defenders to penetrate layers of obfuscation to understand core functionalities.

In essence, UI-CTX shifts the defensive paradigm from reactive detection of known signatures to proactive identification of behavioral anomalies at the critical interface between the user and the application's underlying logic.

Key Takeaways

  • Inconsistency is a Major Threat: Mobile UI widgets often exhibit behaviors inconsistent with their design purpose, posing significant security risks like hidden data theft or unauthorized actions.
  • Traditional Methods Fall Short: Appearance-based and permission-based approaches are insufficient for understanding true UI behavior, while prior code-based methods suffer from false positives, unreachable code, library bloat, and code obfuscation.
  • USCTS Offers a Robust Solution: The UI-CTX System (USCTS) addresses these challenges through an event handler-centric analysis, accurate code pruning, library summarization, and opcode-based functional semantics.
  • UI Graph (UG) for Representation: USCTS constructs a UI Graph (UG) that precisely binds UI widgets to their relevant, pruned, and summarized code contexts, leveraging both graph structure and opcode features.
  • Superior Performance Demonstrated: Empirical evaluation on 40,000 Android applications confirmed that the UG representation significantly outperforms other methods (e.g., permission sets, call sequences) in classifying UI behaviors.
  • Real-World Malicious Behavior Detection: A case study of a "net button" demonstrated USCTS's ability to accurately identify and represent complex malicious behaviors, such as collecting, zipping, and exfiltrating phone numbers via email and HTTP.

About the Speaker(s)

Jiawei Li is the presenter of this research work on understanding UI behaviors with code contexts for mobile applications. As the sole speaker, he is responsible for conceptualizing and developing the UI-CTX framework and its underlying USCTS system, as well as conducting the extensive empirical analysis and evaluation presented at the NDSS Symposium. His work focuses on addressing critical challenges in mobile application security, particularly concerning the accurate interpretation of UI widget functionality and the detection of hidden malicious behaviors. The presentation highlights his expertise in static analysis, reverse engineering, and graph-based representations for security applications.

Reviews

Dr. Zero (Offensive Security Researcher) — SOLID

Competent academic systems paper that solves a real problem — UI/code semantic mismatch in mobile apps — with a methodologically sound pipeline. The event-handler-centric binding, dead-branch pruning, and opcode-based obfuscation resilience are sensible contributions, but none individually break new ground, and the aggregate novelty lands squarely in 'solid conference paper' territory rather than 'must-see talk.'

Heather Calloway (CISO) — WEAK

Technically credible research on a real attack surface — UI/behavior inconsistency in mobile apps is a genuine threat vector — but the work stops well short of where defenders and security leaders need it to land. The gap between 'we can classify UI behaviors' and 'here is what your organization does with that' is never crossed.

→ Top-rated talks at Network and Distributed System Security (NDSS) Symposium 2025

All talks from Network and Distributed System Security (NDSS) Symposium 2025