Conceptio › Archive › arXiv CS
arXiv CSopen access

Can We Stop The Ads? Taxonomy and Characterization of Smartphone Splash Ads and Existing Countermeasures

· arxiv_cs
arXiv CS · Papers · License: Open Access
Open Source ↗Direct PDF ↓
cryptographycybersecurityprivacysecurity
cryptography, security, privacy, cybersecurity

Can We Stop The Ads? Taxonomy and Characterization of Smartphone Splash Ads and Existing Countermeasures Shuhao Zhang1 , Xinyu Liu1 , Ziyu Shao1 , Yuqing Yang2 , Yan Long1 1 The Hong Kong University of Science and Technology (Guangzhou), China 2 Macau University of Science and Technology, China

arXiv:2609.17316v1 [cs.CR] 15 Sep 2026

{szhang515,zshao787}@connect.hkust-gz.edu.cn [email protected];[email protected] [email protected]

Abstract

process. Second, users may struggle to have their complaints addressed. Vendors provide limited feedback channels and may have little incentive to remove advertisements that generate revenue. Third, while national-level policies and regulations have already been announced, technical compliance by the main stakeholders still falls short. To understand how users can better address these problems, we need to take the perspective of ordinary, non-expert users, and examine how Splash Ads work, what existing tools can do, and what prevents users from using these tools effectively. As such, in this study, we investigate the landscape of Splash Ads in mobile ecosystems including Android and iOS particularly aiming to answer four research questions:

Splash ads are full-screen advertisements that pop up and appear as the first interaction page when users start an app, often tricking users into unknowingly activating certain trigger mechanisms, such as moving the phone to redirect users to other profit-driven third parties. So far, splash ads have already caused significant real-world impacts, ranging from significantly delaying emergency response to distracting drivers, as well as degrading accessibility of apps to vision-impaired users. We analyze 108 documented implementations1 of advertising defenses to examine their applicability to splash ads and the requirements users face when deploying them. Our analysis identifies substantial deployment barriers, including device rooting or jailbreaking, runtime code injection, and application modification. Options without these requirements can still involve additional permissions, rule maintenance, source compilation, or payment. In our evaluation of 13 configurations of 11 tools across 10 popular apps, only one tool prevented the target ad-triggered navigation across all ten apps. It required Accessibility permission, and ads remained visible for approximately one second before dismissal. Other tested configurations failed to prevent navigation or, in some cases, left host apps unable to launch or stuck on the ad page. We further analyze the outstanding challenges and possible future directions, highlighting the urgent need to incentivize smartphone manufacturers to provide more friendly and regulated platforms.

1

(1) What mechanisms do Splash Ads use, and how can these ads be classified? (2) Does platform difference affect the adoption and triggers of Splash Ad? (3) What mitigation methods are available, and what technical challenges do users face when deploying them? (4) What changes could help users better avoid or reduce the negative effects of Splash Ads? To answer these questions, we first conduct a comprehensive literature review of news report, technical documents, and GitHub repositories to collect incidents around Splash Ads, mechanisms behind Splash Ads, and mitigation tools from individual developers. Then, we summarize our findings to comprise a taxonomy of available approaches to enable Splash Ads. We find that Splash Ads generally rely on triggers to initiate, and such triggers can mainly be categorized into four types: single tapping, screen swiping, shaking the device, and device rotation. We also observe Splash Ads in over 30% of the top 30 Android applications we examined, with some applications implementing multiple trigger mechanisms. In terms of evaluating mitigation approaches, we perform a differential and empirical analysis, testing collected Splash Ad mitigation tools to evaluate their effectiveness and ease to use. Our investigation reveal that existing defenses are difficult for ordinary users to deploy and provide inconsistent protection. Among the 108 countermeasure instances we study, 39 require rooting or jailbreaking, runtime code injection, or APK modification. Even tools without these requirements may require additional permissions, rules, source compilation, or other configuration. In our empirical evaluation, only 28 of 130 tool-app combinations successfully prevented the target ad-triggered navigation, and some defenses even prevented host applications from launching or left them stuck on the ad page.

Introduction

Splash screen advertisements, or Splash Ads, are a common form of advertising. These ads are displayed when users launch a mobile application, before they can access its main functions. While this business model ensures that users see advertisements, it can also cause problems beyond inconvenience. Recent reports describe older adults and people with visual impairments being misled into clicking advertisements when they intended to use the application [55, 175]. There are even reports of victims contacting the fire department being forced to watch an advertisement of more than half a minute before being able to upload the required video [233]. Unfortunately, users have limited approaches to fight these ads. First, blocking Splash Ads can be technically challenging. The advertisements may be embedded in the application or downloaded from advertising servers, and users have little control over either

1 Inventory: https://github.com/SENSE-Lab-Security/SplashAds-Countermeasures

1

With these, we summarize the technical challenge around Splash Ads, namely why it is so challenging to stop Splash Ads, despite that there are numerous mitigation tools. These challenges include the difficulty of separating advertising behavior from normal application functionality, dependence on rules and configurations that may be invalidated with software updates, extensive deployment and runtime requirements, and potential legal conflicts around Splash Ad blocking tools. In the end, we propose future work directions to tackle these challenges and highlight the need of collective effort in mitigating hazards of Splash Ads in emergency or usability-centric environments. In short, this paper makes the following contributions:

Apps & Ad Providers Seek engagement, conversion, and revenue

Business Goals vs. Platform / Regulatory Constraints

Conversion vs. User Experience

Countermeasure & Regulation Transparency, consent, safeguards, and governance

Users

Seek clear, safe, and low-friction interactions

• We provide a systematic taxonomy of Splash Advertisements based on their mechanisms. • We perform comprehensive analysis of the ecosystem around Splash Ads, including the mitigation tools developed to fight against abusive Splash Ads. • We perform a large empirical evaluation on the effectiveness and usability of Splash Ads mitigation tools. • We propose approaches to mitigate Splash Ads issues in hazardous and impaired environments. • We provide a public inventory of the surveyed tools, with links to their sources and documentation of their deployment requirements and limitations.

2

Convenience vs. Security

Provide platform controls, safeguards, and policies

Figure 1: Competing objectives between the stakeholders in mobile splash advertising. Possible countermeasures and regulations may help improve balance between these parties.

Causing Accessibility Barriers. Intrusive advertisements can impose particularly severe barriersB on users who rely on accessibility services. A September 2026 report described viral footage of a visually impaired user in Jiangxi repeatedly attempting to operate a smartphone while advertisement pop-ups continued to appear and redirect the interface [175]. Phoenix Technology subsequently tested several applications using Android screen-reader mode and observed that important advertisement controls, including close buttons, could lack meaningful accessible labels, making it difficult for visually impaired users to distinguish dismissal controls from advertisement content. Impact on Elderly Users. In another widely reported incident, an elderly user in Huangshan attempted to take a photograph but encountered more than 20 advertisement pop-ups or redirects within approximately 30 seconds and eventually gave up the task [55]. The same investigation reported more than 2,800 complaints related to pop-up advertisements and documented complaints involving small close buttons, high-sensitivity “shake-toopen” triggers, and unwanted application redirection. The examples above are far from a comprehensive list of the negative real-world impact of smartphone splash ads. Together, these incidents show that aggressive advertisement interactions can affect application availability and even physical safety of users. More fundamentally, they demonstrate a significant and unaddressed tension (Figure 1): user actions or environmental inputs that do not clearly express an intention to open an advertisement can nevertheless be exploited and misinterpreted to generate profit-driven redirection operations, and the process is largely out of users’ controls.

Background & Motivation

This section introduces the real-world problems and relevant research results that motivate our work.

2.1

Device Manufacturers

Resulting Real-World Incidents

Recent incidents reported by Chinese news media illustrate that intrusive mobile app advertisements can create consequences beyond ordinary inconvenience. Below we highlight several outstanding concerning examples. Threatening Driving Safety. In June 2026, a driver reported that he opened a navigation application through voice control while driving, without touching the phone. Vehicle vibration subsequently triggered a high-sensitivity “shake-to-open” splash advertisement, causing the interface to redirect to an e-commerce application and distracting him while driving [71]. The driver reported that the incident nearly resulted in a collision. In a follow-up test, reporters also confirmed that two mainstream navigation applications displayed five-second splash ads for which shaking the phone could open the advertisement details. Hindering Emergency Response. In September 2026, a Shenzhen resident called the emergency service after observing a fire in a neighboring residence and was asked to upload a video through a link sent by the dispatcher. Opening the link launched the phone browser app, whose splash ad appeared before the upload page. While attempting to dismiss the ad, the user accidentally closed the browser and had to reopen the link, delaying the urgent video upload by approximately 30–60 seconds. The local fire department subsequently clarified that the advertisement originated from the user’s browser app rather than the emergency-service link [233].

2.2

User Attitudes and Demand for Control

Available evidence shows not only widespread dissatisfaction with intrusive splash advertisements, but also a concrete demand for mechanisms that give users greater control over advertisement activation and redirection. 2

Table 1: Semi-drive-by splash-ad prevalence and trigger distribution reported by Wu et al. [222]. Market

Tested

Detected

Touch

Motion

VIVO Xiaomi Wandoujia YingYongBao

5,262 5,998 11,682 8,881

261 (4.96%) 128 (2.13%) 198 (1.70%) 191 (2.15%)

12 (4.6%) 81 (63.3%) 18 (9.1%) 13 (6.8%)

249 (95.4%) 47 (36.7%) 180 (90.9%) 168 (88.0%)

Total

31,823 778 (2.44%) 124 (15.9%) 654 (84.1%)

$orƒƏ ѵѵĺƕѸ

$orƐƏƏ ƕƏѸ

$orƒƏ

ƐƔĺƔѸ ƒѶĺƐѸ ѶĺѵѸ

o|u;1ou7;7

Ő-őm|;u-1|bomu;1ou7v

$orƐƏƏ

ƓƓĺѶѸ

ƓĺѶѸ ƒƐѸ

ƑѶĺѵѸ !;1ou7;7

$-rņ_o|-u;-

"‰br;

"_-h;

$‰bv|ņoub;m|-|bom

Ő0őm|;u-1|bomlo7;v

Figure 2: Interaction records and interaction modes observed in popular Android apps selected from the QuestMobile Top30 and MoonFox Top-100 rankings for June 2026. All apps were tested in September 2026.

A poll conducted by the Jiangsu Consumer Protection Committee shows that 78% of respondents reported frequently encountering “shake-to-open” advertisements, 92% expressed dislike toward this form of splash advertising, and 90% considered the behavior an infringement of their rights. More importantly, 76% supported stopping shake-triggered splash advertisements or related behaviors. Empirical research focusing specifically on splash advertisements reaches a similar conclusion regarding the importance of user control. Zheng et al. [235] surveyed users in China and found that the responsiveness and visual salience of the skip option increase users’ perceived control, which in turn improves their attitudes toward both the splash advertisement and the hosting application. Complementary controlled experiments by An et al. [24] found that the presence of splash advertisements decreases users’ attitudes toward advertisements and their satisfaction with the corresponding applications, largely because such advertisements are perceived as obstacles to the users’ intended goals. These findings suggest that an important user requirement is effective and readily accessible control over whether an advertisement is viewed, dismissed, or allowed to initiate a navigation action. Unfortunately, as of September 2026, splash advertisement SDKs and apps using these services still do not provide such controls.

2.3

ƒƏѸ ƑѶĺѵѸ

ƒƒĺƒѸ

popular Chinese apps, including misleading advertisement interactions and easy-to-trigger behaviors [140, 141]. More recently, Shang et al. found shake-to-open advertisements to be particularly prevalent in their Chinese app dataset [193]. Wu et al. [222] examined 31,823 Android applications across four major Chinese app markets and identified 261, 128, 198, and 191 applications exhibiting such behavior in VIVO, Xiaomi, Wandoujia, and YingYongBao, respectively. Among these detected cases, sensor-triggered mechanisms accounted for 95.4%, 36.7%, 90.9%, and 88.0%, respectively, highlighting the importance of motion-sensor-based activation in semi-drive-by advertising. Gap Between Policy and Deployment. These findings suggest that the main practical gap is no longer the absence of well-defined expectations, but uneven compliance and enforcement within the advertising ecosystem. This motivates our investigation of technical countermeasures that end users may deploy immediately to protect themselves, without requiring every application or advertising provider to first adopt the intended behavior.

3

Taxonomy of Intrusive Splash Ads

We further examined the Android versions of the top 30 applications in QuestMobile’s 2026 H1 China Mobile Internet APP User Scale Ranking and observed splash advertisements in 10 of them (33.3%). The result shows that splash advertising remains common among today’s most widely used applications, making its interaction mechanisms particularly relevant to a large population of mobile users.Figure 2 summarizes the observed occurrence of splash ads and the distribution of trigger types in the Top-30 and Top-100 app samples. Trigger-to-Navigation Pipeline. Despite their diverse interaction designs, interactive splash advertisements generally follow a common on-device pipeline from user input to advertisement navigation, as illustrated in Fig. 3. We divide this pipeline into two stages: the Trigger Side and the Navigation Side. The Trigger Side determines when and how an advertisement is activated. Based on the source and interpretation of the input, we classify these mechanisms into two major categories: touchtriggered advertisements, including Tap/Hot Area and Swipe/Slide, and motion-triggered advertisements, including Shake and Rotate/Tilt. This distinction is important because the two categories rely on different device inputs and recognition logic, and therefore expose different opportunities for intervention.

Policy Expectations and Current Status

The current policy and industry framework in China already establishes a relatively clear expectation for more user-friendly splash advertising, but the actual executive compliance of existing apps still shows a significant gap. Prior work notes that splash advertisements have been subject to dedicated rectification and that users should retain effective control, such as readily accessible skip options [24]. For motiontriggered advertisements, recent technical work further adopts established industry thresholds specifically designed to prevent ordinary activities—such as walking, picking up a phone, or riding in a vehicle—from being interpreted as intentional advertisement engagement [222]. In the intended compliant case, advertisement navigation should therefore follow a clear and deliberate user action, while incidental touch or device motion should not cause redirection. The remaining challenge lies largely in how these requirements are implemented by applications, advertising SDKs, and advertising networks. Empirical studies continue to observe substantial use of deceptive or overly sensitive interaction mechanisms in deployed apps. Long et al. found dark UI patterns in 82% of 150 3

Trigger Side

Navigation Side

From input signals to advertisement triggers

Input (on device)

User

Input Processing

Trigger Recognition

Advertisement Trigger

Navigation Mechanism

(in Ad SDK)

(in Ad SDK)

(semantic actions)

(initiated by Ad SDK)

Touch Input

Touch interaction

Tap Scroll Swipe …

Device movement / motion

Motion Input Accelerometer Gyroscope Orientation …

From triggers to navigation and destination

Event filtering Region matching Gesture feature extraction

Touch event analysis (e.g., tap, swipe)

Threshold checking

Debouncing

…

…

Motion event analysis (e.g., shake, tilt)

Touch-triggered

Android Intent

Tap / Hot Area Swipe / Slide

(e.g., startActivity())

Destination

(advertised target)

Web Page (e.g., product page)

Deep Link

…

Another App

(e.g., app://, https://)

Shake

WebView Navigation (e.g., loadUrl())

Rotate / Tilt

Browser URL

…

(e.g., https://)

Motion-triggered

(e.g., installed app)

App Store (e.g., app download)

…

…

User Device

(App with Ad SDK)

On-device Ad Interaction Pipeline

Figure 3: The common pipeline of splash ads. Table 2: Interaction trigger mechanisms observed in the top30 popular Android applications. Touch-Triggered Host App Baidu Sogou Input Baidu Maps Baidu Input Weibo QQ Browser Tencent Video iQIYI Tencent News Mango TV

AD content area AD content area

Motion-Triggered

Tap / Hot Area

Swipe

Shake

Twist / Orientation

✓ ✓ ✓ ✓ ✓ ✓ – – ✓ ✓

– ✓ ✓ ✓ ✓ ✓ – – ✓ –

– – – – – – – – – ✓

– ✓ ✓ – – – ✓ ✓ ✓ ✓

Touch-trigger cue region

Figure 4: Touch-triggered splash ads with visually separated interaction regions and explicit interaction animations, which guide users toward deliberate interaction with the ad.

Once an advertisement has been triggered, the Navigation Side determines where and how the user is redirected. Although splash advertisements employ heterogeneous trigger mechanisms, their resulting actions often converge on a relatively small set of navigation primitives, such as Android Intents, deep links, WebView navigation, and browser URLs. These primitives can subsequently redirect users to webpages, other applications, or app stores.

3.1

Touch-trigger cue region

of that clickable region rather than a separate gesture type. Swipetriggered advertisements instead require finger movement that satisfies conditions such as a minimum displacement or a specified direction. The main usability problem arises when the effective clickable region is substantially larger than the visually indicated advertisement element, including designs in which most or all of the splash screen acts as an advertisement target. Misleading or deceptive close controls further blur the distinction between advertisement activation and advertisement dismissal because a touch intended to close an advertisement may instead be interpreted as an advertisement click.

Deceptive Trigger Mechanism

The feature of intrusive splash ads that users complain about the most is that after they pop up, there will be certain kinds of user action trigger that users often do unwittingly, without users knowing the ads are exploiting this common unintentional behavior as a trigger. Even worse, some of the triggers cannot even be controlled by users. We summarize the common types of triggers below.

3.1.2 Swipe-Triggered Advertisements. Swipe-triggered advertisements infer interaction intent from a sequence of touchscreen coordinates, typically by measuring displacement, direction, duration, velocity, or similarity to a predefined trajectory. A swipe trigger can therefore be activated without access to motion sensors, which makes sensor-permission controls ineffective against this class of advertisements. The technical ambiguity of swipe-based activation comes from the fact that short scrolling gestures, one-handed

3.1.1 Tap- and Hot-Area-Triggered Advertisements. Both tap- and swipe-triggered advertisements use touchscreen input, but differ in their activation conditions. Tap-triggered advertisements initiate navigation when the user taps within a clickable region, without requiring a directional sliding gesture. “Hot area” refers to the extent 4

AD content area (full-screen)

Motion-trigger cue region

Table 3: Visual salience of trigger cues in touch- and motiontriggered splash advertisements.

AD content area

Motion-trigger cue region

Touch-Triggered

Motion-Triggered

Contrast Text Size Spatial Separation Visual Guidance

High Large High Strong

Low Small Low Weak

each time it was opened. For example, Baidu Maps displayed splash ads on nearly every observed iOS launch but intermittently or not at all on the tested Android devices. The frequency of advertising interruptions therefore varied across the inspected platforms and devices. Several factors may explain this difference. The Android and iOS versions of an app may use different display rules, such as showing an ad on every opening or imposing a minimum interval between displays. Advertising platforms provide frequency controls for appopen ads, allowing developers to limit impressions per user over a specified period [90]. Advertising availability may also differ across devices. Campaign targeting can distinguish operating systems and device models, allowing different devices to receive different advertising opportunities [91]. The two app versions may also load ads at different times. A preloaded ad can be displayed immediately, whereas an ad requested only when the app opens may not become available before the loading screen ends [87, 88]. Background-app management may also contribute by affecting whether reopening an app resumes an existing page or starts a new session. Its effect depends on the app’s advertising logic. Returning to an existing session can still trigger another ad, while a fresh launch may display none. App-open advertising supports foreground presentation on both Android and iOS [87, 88]. Differences in display policies, advertising availability, and startup behavior are therefore plausible explanations for the observed patterns, although their individual contributions were not measured in our comparison.

Figure 5: Motion-triggered splash ads with motion instructions overlaid on full-screen video content. The reduced visual salience of these instructions can make the trigger difficult to notice, increasing the risk of unintended advertisement activation.

repositioning, and deliberate advertisement-opening gestures may generate partially overlapping touchscreen trajectories. 3.1.3 Shake-Triggered Advertisements. Shake-triggered advertisements monitor accelerometer, gyroscope, or related motion-sensor streams and compare derived motion features against thresholds selected by the application or advertisement SDK. A typical implementation aggregates acceleration magnitude, angular displacement, event duration, or motion velocity and invokes an advertisement callback when one or more thresholds are satisfied. Because natural activities such as picking up the phone, walking, riding in a vehicle, or adjusting device orientation can produce similar sensor patterns, the choice of trigger threshold directly determines the probability of accidental activation. Advertisement SDKs may additionally obtain trigger parameters through remote configuration, allowing motion sensitivity to change without an application update and making one-time application inspection insufficient. By far, shake-triggered ads have been known as the most disturbing and deceptive type of intrusive splash ads. 3.1.4 Rotation- and Orientation-Triggered Advertisements. Rotationor orientation-triggered advertisements use gyroscope, orientation, or fused motion information to detect changes in device pose and trigger navigation after a required angular displacement or motion pattern. These mechanisms are technically similar to shaketriggered advertisements from a permission perspective but can rely on different sensor combinations and feature-extraction logic. The existence of several motion-triggered interaction styles means that blocking one specific motion pattern does not necessarily remove an advertisement SDK’s ability to construct another motion-based trigger.

3.2

Visual Dimension

4

Existing Countermeasures

This section examines ad defense deployment from the user’s perspective, including the software, permissions, and additional operations required. We compiled 108 countermeasure instances: 93 related to splash ads and 15 targeting feed, video, audio, and other ad formats. We classify them by where their defensive operations intervene and describe their scope and deployment requirements. An instance is a tool, rule set, version, prototype, or control, rather than necessarily an independent product. The inclusion criteria and counting rules are given in Appendix A. Another nine advertising SDK controls, two developer integration libraries, and one advertising-platform confirmation mechanism require action by host-app developers or advertising platforms. They are listed in Appendix A.5. Classification Basis. We classify defensive operations into six categories by their intervention point. A tool can cover multiple stages: Fuck AD, for example, includes ad-loading interception,

Platform Comparison: Android vs. iOS

Splash ads exist on both Android and iOS. In our manual observations, splash ads appeared more frequently and consistently on iOS than on Android. Among the inspected iOS apps that displayed splash ads, advertisements appeared on nearly every launch, whereas the same Android app did not necessarily display an ad 5

initialization prevention, and interface hiding or automatic skipping [105]. Of the 108 instances, 22 include operations spanning multiple stages and are counted in each corresponding category. Runtime injection, APK modification, and system configuration are implementation techniques. Ads may be preloaded, and motion monitoring may start before display, so the intervention stages need not follow a single strict sequence. Deployment Requirements. Root or jailbreak denotes a system privilege condition, runtime injection modifies an app’s behavior through a framework while it runs, and APK modification changes the installation package and requires reinstallation. We label these requirements separately. Xposed and LSPosed are runtime injection frameworks, which are not equivalent to APK modification. Accessibility, VPN, debugging, and overlay authorization provide different capabilities for cross-app control. Table 4 marks requirements for specific deployment paths and separately describes system settings, rules, certificates, source builds, and models. The appendix provides individual requirements and complete distributions.

4.1

in Appendix A.4 outside the main-inventory counts because its installation or complete build route is unresolved. Modifying Responses and Configurations. These methods allow requests to complete, then remove advertising entries from returned data or modify ad status. Clients such as Surge and Quantumult X execute app2smile’s ad-network rules to modify status or result fields at specified endpoints. blackmatrix7’s rules also modify display duration, dimensions, and validity periods [30, 31, 41]. Users need a compatible client and rules. The listed iOS proxy path additionally requires a VPN, and HTTPS content modification requires the app to accept the proxy certificate. Apps that trust only prespecified certificates may reject the connection [200]. Returned data can also be processed inside an app: BetterHeybox uses Runtime Injection to remove advertising entries from content lists. This path requires loading a module but does not require decrypting responses in a network proxy [155]. The same method applies to feed and recommendation ads. Discover Feed Filter filters advertising data through injection, while BiliRoamingX handles recommendation ads through APK patches. The latter’s referenced prebuilt distribution channel is unavailable, and its patchbuilding and installation channels remain unconfirmed [39, 40, 107]. BiliRoamingX is therefore retained in Appendix A.4 outside the main-inventory counts. Restricting Local Ad Resource Reads. Filtering new requests does not prevent an app from reading cached ads or ads bundled in its installation package. MiFitnessAdAway replaces the result of reading the splash-ad cache inside the app with an empty value. Its listed deployment path requires Root and Runtime Injection [94]. Its protection is limited to matching cache-read paths. These methods must distinguish advertising from normal data and cover the resource sources actually used. Unmatched rules, readable caches, or a switch in ad sources can allow ads to continue appearing.

Ad Defense Methods

We describe defensive operations, user deployment requirements, and principal limitations across the six intervention stages. 4.1.1 Blocking and Modifying Ad Resources. These methods prevent apps from obtaining usable ad content by blocking requests, modifying responses and configurations, or restricting local resource reads. Users can choose a VPN client or System Setting for DNS or network management. Modifying HTTPS content additionally requires a proxy and certificate trust, while in-app processing may require Runtime Injection or APK Modification. Of the 58 instances in this category, 36 use network tools, DNS, or vendor network-management configurations, and 22 involve app internals or system files. Blocking Network Ad Requests. Domain filtering refuses to resolve ad server addresses, while URL filtering additionally examines request paths. For example, AdAway filters using advertisingdomain rules, and R-Store provides rules for blocking specific ad requests [8, 236]. When blocking succeeds, users do not need separate protection configurations for taps, swipes, or shakes. However, a domain may also serve normal data, and rules require updates as server interfaces change. Filtering can run on the device or at a remote resolver. DNS66, personalDNSfilter, and Blokada 5 provide local paths, while Blokada Cloud and the inspected Block This implementation use remote filtering services. The former require a configured local executor, while the latter depend on the corresponding service [44, 80, 109, 117]. TrackerControl processes connections through a VPN and blocks requests according to domain associations, advertising categories, and user choices [209]. On supported iOS and iPadOS versions, users can enable Wipr 2’s Filtr system URL filtering extension. Coverage still depends on requests passing through supported paths [38, 119]. Classifiers can also identify ad requests in place of individual rules: NoMoAds, for example, uses network and visiblecontent features to classify advertising traffic [195]. It is retained

4.1.2 Preventing Ad Initialization and Startup. These methods disable ad initialization or startup functions, or bypass or block ad-page launches. Users typically need a Runtime Injection framework and an advertising module, or a target app installed through APK Modification. A root-based framework also requires Root. All 22 instances in this category involve injection or APK modification: 18 provide injection paths, five provide APK modification paths, and one provides both. Two require source builds. Disabling Ad Initialization or Startup Functions. Runtime injection can replace a specified function’s behavior when an app calls it, making the function return immediately. For example, FanqieHook intercepts splash entry points in supported apps, and Fuck AD intercepts initialization of supported advertising SDKs [23, 105]. An SDK is an advertising library integrated into the host app, and users intervene in its execution by installing a module. They need to install a compatible framework, enable the module, and select the target apps in its scope. On iOS, ChaoxingLaunchAdBlock also intercepts advertising startup code in Chaoxing Xuexitong. User deployment requires jailbreaking and a corresponding tweak-loading environment [212, 6

Table 4: Deployment Paths, Requirements, and Estimated Effort for Advertising Defenses.

Deployment Path

Effort

Root Jailbreak

Runtime APK Injection Mod.

Accessibility

Debugging

Other Permissions and VPN Overlay Setup

Representative Approaches and Fees

Blocking and Modifying Ad Resources (58) System DNS configuration

Low

Local VPN domain filtering

Low

Root hosts filtering

High

✓

Advertising-domain lists

AdAway (root) [8]

Proxy, rules, certificate trust

Surge + app2smile (paid client) [31, 201]

Framework, module, scope

MiFitnessAdAway [94]

✓

Apply patches, re-sign, install

Adobo patches [115]

Framework, module, scope

Fuck AD [105]

✓

Compatible tweak-loading environment Patch selection, re-signing, installation Match version / signature; replace target app

✓

iOS HTTPS response Moderate rewriting In-app ad data / cache ✓ High processing Modifying APK loading High logic Preventing Ad Initialization and Startup (22) Android entry-point ✓ High interception iOS entry-point ✓ High interception Applying APK patches

System Setting; DNS AdGuard DNS (partly paid) [13] address or configuration profile Built-in advertising-domain AdAway (VPN) [8] lists

✓ ✓

✓ ✓

High

Installing a premodified ✓ Moderate APK Suppressing Ad Presentation and Automatically Dismissing Ads (44) Auto-dismissal with ✓ Low built-in rules Auto-dismissal with ✓ Moderate imported rules Screenshot-based ✓ Low dismissal Injection-based interface ✓ ✓ High hiding Audio-ad muting

Adobo advertising patches [115] CAD Viewer patch [150]

Background-execution Li Tiaotiao [187] settings Import subscription; GKD + Lin-arm rules [85, 136] background use Screen access; built-in obaby; Ad Skipper (no added recognition; background use VLM) [147, 168]

Low

Restricting Inputs and Disabling Triggers (9) Vendor motion Low permissions

Framework, module, scope

MinMinGuard; Fuck AD [54, 105]

Notification Access; enable audio-ad muting

ad-free [6, 7]

System Setting; Huawei; OPPO [100, 171] supported device / firmware

Regular overlay touch Moderate interception Accessibility-overlay Moderate touch interception Temporary sensor Moderate control via debugging Sensor listener ✓ ✓ High interception Intercepting Ad Navigation and Requiring Confirmation (3) User-enabled navigation Low reminder Injection-based link / ✓ High component interception Automatically Returning After Navigation (1) Automatic return after High navigation

ChaoxingLaunchAdBlock [212, 213]

✓ ✓ ✓

✓

User-selected region

Framework, module, scope

System Setting; supported device Framework, module, matching rules

✓

Source Build; rules; background use

✓

One Patch (overlay path) [173]

Select a region; alternative One Patch (accessibility path) [173] overlay path Shizuku pairing; background NoShakingAD [219] use Fuck Shake; AdClose 4.3.7 [180, 239]

Honor navigation reminder [97] FuckAdJump; Li Tiansuo [29, 216]

ShakeGuard (prototype) [113, 114]

Deployment Effort. Deployment effort is rated qualitatively based on the technical skills and setup steps required of ordinary users. Low installation and authorization, or an existing system setting; Moderate rules, region selection, certificates, debugging, or replacement-app setup; High root / jailbreak, runtime instrumentation, APK patching, or source compilation. Deployment Symbols. Root / Jailbreak; Runtime Injection; APK Modification; Accessibility; Debugging; VPN; Overlay; System Setting; Source Build; Additional Model; Notification Access. The key denotes root on Android and jailbreaking on iOS. Requirement Indicators. A checkmark denotes a requirement of the listed path; blanks do not mean no setup is needed. Other permissions appear in their own column. The APK column includes premodified apps. Alternative paths are separate rows. Counts and Fees. Category counts cover 108 instances; 22 span multiple stages. Splitting paths does not add instances. As of September 13, 2026, “paid” requires a software / service purchase; “partly paid” combines a free path with paid features. Details appear in Appendix A.7.

7

213]. Another path modifies the installation package: Adobo’s advertising patches make specified SDK display entry points return early. Users can directly use compiled patches, modify an APK through a manager, and install it [115]. Bypassing or Blocking Ad-Page Launches. The CAD Viewer patch changes the launch entry point to the home page, and users can install the modified APK provided by the project. CoolApkNoSplash instead intercepts launch requests targeting CoolApk’s splash page at runtime and requires an injection framework and the corresponding module [138, 150]. The former installs a modified app; the latter loads a module while the app runs. These operations depend on accurately identifying ad entry points. Existing adaptations may fail when functions, call patterns, or startup order change. If advertising and normal initialization share functions, skipping an entire function may also affect hostapp functionality.

tool captures screenshots, uses object detection to locate buttons, and clicks through an accessibility service. Ad Skipper combines interface-node, text, and image recognition [147, 168]. Both require screen access and recognition computation, and Ad Skipper also offers an optional configuration with an additional downloaded VLM. User-configured visual rules also support video-ad dismissal: Klick’r matches image and text conditions, and users have reported using it to recognize and automatically click close buttons after game video ads end [47, 95]. Muting Audio Ads. ad-free identifies audio ads from playback states in supported apps and reduces interruptions by lowering the volume or playing replacement audio. Users need to grant Notification Access and allow the corresponding audio control. They can directly install the package provided by F-Droid [6, 7]. Automatic dismissal must first detect the ad and act, before which the ad may still trigger. Interface changes or deceptive close buttons may also cause clicks to land in the ad region. Hiding the interface may leave background advertising logic running, and muting does not shorten the audio ad’s playback time. Accessibility authorization also gives the tool access to non-ad interfaces.

4.1.3 Suppressing Ad Presentation and Automatically Dismissing Ads. These methods reduce advertising interruptions by hiding ad elements, operating close controls, or muting audio. Automatic dismissal typically requires Accessibility, and visual recognition also involves screen access and local computation. Interface hiding typically uses Runtime Injection or APK Modification, while audio-ad muting uses notification access and audio control. Of the 44 instances in this category, 24 provide accessibility paths and 20 provide injection or package-modification paths, with one providing both. Another uses notification access and audio control. Seven require source builds, and one has paid features. Hiding or Removing Ad Elements. MinMinGuard sets ad View heights to zero, while MiFitnessAdAway hides the corresponding ad interface and removes its occupied space [54, 93]. The listed Android injection paths require Root and Runtime Injection. Users must enable the module and match the target version. Fuck AD provides both injection-based interface hiding and accessibility-based automatic skipping, requiring an injection framework and accessibility authorization, respectively [105]. Some automatic-click paths additionally use Shizuku and require Debugging. The same interface-hiding mechanism is used for other ad formats: GmailHideAds hides advertising controls in email lists, and amznkiller injects styles into Amazon Shopping’s web container to hide sponsored content. Both require a module loaded in the target app [106, 156]. Automatically Dismissing Ads. Once authorized, an Android accessibility service can read interface information exposed by other apps and perform clicks. Li Tiaotiao, TapClick, GKD, and its advertising subscriptions locate skip buttons using text, positions, or control identifiers and operate them for the user. GKD’s specific coverage is determined by its subscription rules [85, 89, 135, 136, 187]. Users need Accessibility, rule configuration as required by the tool, and background execution. They typically do not need to modify the target app. Android’s accessibility-based autoskipping does not have a directly equivalent deployment path for ordinary third-party tools on iOS. App isolation and code signing restrict those tools from reading and operating other apps in the same way [34, 36]. When an ad does not expose an independently operable control, its close button can be recognized from a screenshot. obaby’s

4.1.4 Restricting Inputs and Disabling Triggers. These methods restrict ads’ access to touch or motion input through touch-region overlays, vendor motion permissions, or sensor restrictions implemented through debugging services or injection modules. Of the nine instances in this category, four are user-enabled system settings, three use injection, one controls sensors through Shizuku debugging authorization, and one provides an overlay. Overlays can use overlay or accessibility paths, each requiring its corresponding authorization. Intercepting Touch Input. One Patch lets users select a rectangular region and uses an overlay to receive touches within it, preventing events from reaching the ad. Its regular overlay path requires Overlay, while its accessibility-overlay path requires Accessibility [173]. Users must select the region themselves. Normal controls inside it are also blocked, while touches outside it and motion input remain unaffected. Restricting Motion Sensor Access. On supported devices, Huawei, OPPO, and Honor users can deny device-orientation or motion permissions to a target app through System Setting. Some vivo firmware also provides an option to deny access only during splash ads [99, 100, 171, 172]. These are user-enabled system controls whose protection depends on the device model, firmware, and permission implementation. Third-party tools provide two different deployment paths. NoShakingAD requires Accessibility and Debugging: accessibility events observe the foreground app, while Shizuku provides debugging authorization to switch the global sensor mode and schedule restoration after five seconds [217, 219]. Fuck Shake, the verified AdClose 4.3.7 configuration, and QzxyAdBlock restrict sensor listeners through Root and Runtime Injection [52, 180, 239]. Fuck Shake intercepts one listener-registration interface. Other interfaces and previously established listeners require separate handling. Sensor restrictions also affect normal motion-based functions, and global restrictions involve other apps. Ads still displayed after 8

a temporary protection period may regain access to motion input. Input control does not directly dismiss ads, and restricting motion does not automatically prevent tap- or swipe-triggered navigation.

code-injection framework used in these tests, and Shizuku provides debugging authorization for the corresponding configuration. Successful Protection Covered Only a Minority of Combinations. Of the 130 combinations, 28 (21.5%) succeeded, 62 failed, 17 had no observed baseline ad, three experienced host-app failures, and 20 belonged to configurations that were not successfully validated. Success means preventing navigation triggered by the target ad. Ad Delivery Limited Evaluation Coverage. Baidu, Baidu Maps, and Baidu Input displayed no splash ads on the Pixel 6 even with defenses disabled, suggesting that delivery may depend on conditions such as the device environment. We did not count this absence of ads as successful protection. Network Filtering Left Multiple Apps Unprotected. AdAway’s VPN mode succeeded in three of ten apps, and TrackerControl’s VPN configuration succeeded in five. AdAway’s Root mode succeeded in none of the seven evaluable apps. Domain filtering depends on rules, while app-open ad SDKs support preloading. Uncovered domains and ads cached before filtering was enabled are possible failure paths [8, 87]. Accessibility Tools’ Effectiveness Varied by Configuration. Li Tiaotiao 2.2, GKD with Lin-arm rules, and Ad Skipper without an additional VLM all use Accessibility. They succeeded in all ten apps, none of the ten apps, and five of seven evaluable apps, respectively. Missing rules or interface changes may prevent target location [85, 136]. In manual observations, ads remained visible for approximately one second before Li Tiaotiao dismissed them. Ad Skipper’s node matching, OCR, and built-in YOLO also require corresponding local computation. Root and Injection Do Not Guarantee Effectiveness or Compatibility. The tested configurations of Fuck AD, Fuck Shake, FuckAdJump, and AdClose all require Root and Runtime Injection, together producing only three successful combinations. With AdClose enabled, Baidu could not launch, while QQ Browser and Tencent Video remained on the ad page. Its 4.3.7 configuration enabled sensor restrictions and request inspection, had no network-blocking rules, and did not implement the SDK initialization interception described in the old README. Motion Protection Leaves Touch Triggers and Ad Display Intact. NoShakingAD’s Accessibility and Debugging configuration can prevent motion-triggered navigation but does not dismiss the ad or prevent touch-triggered navigation. According to the trigger categories listed in Section 3, Tencent Video and iQIYI have only motion triggers and are therefore marked successful in the table. Apps with touch triggers are marked unsuccessful even when their motion-triggered navigation was prevented. Model Initialization Failed Before Ad Recognition. On the Pixel 6 running Android 13, Ad Skipper v1.3’s Accessibility and Additional Model configuration crashed while loading either InternVL3 2B or Qwen2.5-VL 3B, despite complete downloads of the models and their visual projection files. Both failures occurred at the same Vulkan buffer-allocation call before ad recognition began. The configuration without an additional VLM could still run. Source-Level Tests Revealed State-Management Defects in ShakeGuard. ShakeGuard requires a Source Build and Accessibility; its on-device deployment was not completed.

4.1.5 Intercepting Ad Navigation and Requiring Confirmation. These methods rewrite destination links, deny destination-page launches, or require user confirmation when an ad is about to open a web page or another app. Of the three instances in this category, two use Root and Runtime Injection, and one uses System Setting on supported devices. Rewriting Links and Intercepting Page Launches. When an app parses a URI, FuckAdJump replaces strings matching Taobao or JD scheme prefixes with an empty string. Li Tiansuo’s UC rules intercept launches of ad landing pages or browser Activities specified in the rule list [29, 216]. Users need a compatible injection framework, a module, and its target-app scope. Protection is determined by the matching links and components. Requiring User Confirmation for Navigation. Honor’s automatic app redirection reminder lets users enable a setting on supported systems to display a reminder for recognized navigation caused by accidental ad interactions. Official documentation includes third-party app launches caused by shaking, swiping, and tapping [97, 98]. Users can enable the setting directly without installing an injection framework. Navigation control requires requests to pass through the configured checkpoint and may also affect shopping, login, or payment links that users intentionally open. Ads can continue to display. Denying an external launch does not establish that other paths, such as in-app web pages, have also been blocked. 4.1.6 Automatically Returning After Navigation. These methods detect a transition after the destination app has opened and attempt to return, shortening the interruption. The one included instance is ShakeGuard, which requires a Source Build, Accessibility, source and destination rules, and background execution. ShakeGuard combines accessibility window events, appmatching rules, and a protection period to determine whether a transition needs handling, then sends a system Back operation. If returning fails, it can attempt to reopen the source app [113]. Users need JDK 17, Android SDK 35, and Gradle, then build and install the APK before granting authorization and configuring rules [114]. The defense tool itself is compiled; the host APK remains unchanged. Recovery occurs after navigation and cannot undo pages already displayed or network requests already sent by the destination app. It also does not guarantee a return to the original host-app page. Source, destination, and time-window information provide only indirect clues, so normal transitions may also match the rules.

4.2

Case Study: Empirical Evaluation of Representative Defenses

We selected 13 configurations of 11 tools and tested the ten host apps listed in Section 3 on a Pixel 6 and a Xiaomi MIX 2S. Each cell in Table 5 represents a configuration and app combination, summarizing results from both devices. Deployment labels in the table describe the configurations actually tested. Vector is the runtime 9

Table 5: Empirical Results for 13 Configurations of 11 Defense Tools Across 10 Tested Apps. Tool / Configuration AdAway (VPN) [8]

Deployment Requirements

Sogou Input

Baidu

Baidu Maps

Baidu Input

Weibo

QQ Browser

Tencent Video

iQIYI

Tencent News

Mango TV

×

✓

×

✓

×

×

×

×

×

✓

AdAway (root)

×

△

△

△

×

×

×

×

×

×

TrackerControl (ad blocking) [210]

✓

✓

✓

✓

×

×

×

×

×

✓

AdClose [239]

×

⋄

△

△

×

⋄

⋄

×

×

×

Fuck AD [105]

×

△

△

△

×

✓

×

✓

×

×

Li Tiaotiao 2.2 [187]

✓

✓

✓

✓

✓

✓

✓

✓

✓

✓

GKD + Lin-arm rules [85, 136]

×

×

×

×

×

×

×

×

×

×

Ad Skipper (without VLM) [147]

✓

△

△

△

×

✓

×

✓

✓

✓

Ad Skipper (with VLM)

—

—

—

—

—

—

—

—

—

—

NoShakingAD [219]

×

×

×

×

×

×

✓

✓

×

×

Fuck Shake [180]

×

△

△

△

×

✓

×

×

×

×

FuckAdJump [216]

×

△

△

△

×

×

×

×

×

×

ShakeGuard [113]

—

—

—

—

—

—

—

—

—

—

✓: prevented navigation triggered by the target ad; ×: failed to prevent it; △: not evaluated because the target splash ad was not observed with the defense disabled; ⋄: the host app failed to launch or became stuck with the defense enabled; —: not successfully validated. The tested injection framework was Vector 2.2, which requires root. Shizuku provides debugging authorization for NoShakingAD. The additional-VLM configuration did not run successfully; the configuration without an additional VLM still performs built-in local inference. ShakeGuard requires compiling the defense tool itself. Deployment Icons. VPN; Root; Runtime Injection; Accessibility; Additional Model; Debugging; Source Build. Configuration Details. AdAway (root): Modifies system hosts; Li Tiaotiao 2.2: Background execution; GKD + Lin-arm rules: Lin-arm rules, background execution; Ad Skipper (without VLM): Screen access, built-in inference; Ad Skipper (with VLM): Additional VLM + visual projection files; NoShakingAD: Shizuku, background execution; ShakeGuard: Build toolchain, source and destination rules.

We separately executed its original state-management code on the JVM with controlled foreground events and return outcomes, reproducing two defects. After a failed return, the prototype could remain in its recovery state and stop evaluating transitions from other protected apps. Returning to the launcher and reopening the same app could also retain the previous protection-window start time, causing a new redirect to be allowed as outside the window [113].

5

can prevent ads from obtaining shake data, but also limits motionbased interactions within the same application [100]. This control covers the entire application and cannot deny sensor access only to advertising code. Selective interception depends on accurately identifying advertising code. Disabling only ad initialization functions or restricting only sensor listeners registered by ads can reduce the impact on normal functionality. However, the defense must accurately locate these entry points and accommodate how they are invoked. For example, Fuck AD’s interception of ad SDK initialization requires matching the corresponding functions in supported SDKs [105]. This control requires adaptation to individual advertising implementations. Interception based on destination links has difficulty distinguishing advertising from normal navigation. FuckAdJump blocks external app launches based on Taobao and JD link prefixes, but the same prefixes can also be used in shopping links that users intentionally open [216]. Removing ads that have already been identified does not require determining whether users intended to trigger them; the distinction needed is between advertising and normal operations that share the same navigation path. HONOR’s navigation reminders request an additional confirmation, allowing users to decide whether to proceed [97]. This approach adds an interaction, and its coverage also depends on which navigation attempts enter the confirmation process.

Why So Challenging to Stop Splash Ads

Section 4 shows that most existing countermeasure tools show unreliable performance, even with technical resource requirements for deployment that far exceed the capability of average smartphone users. Unfortunately, most of these tools’ capabilities do not always translate into protection that users can continue to use. This section draws on existing mechanisms and our empirical results to analyze how these difficulties affect defenses.

5.1

Difficulty Separating Advertising from Normal Functionality

Advertising code is integrated into the host application and shares application capabilities and navigation paths with normal functionality. Defenses need to block advertising behavior while preserving host functionality, but the scope defined by application permissions, internal functions, and destination links does not always align with the scope of advertising behavior. Restricting capabilities per application also affects normal functionality. Restricting motion-sensor access per application 10

5.2

5.4

Intervention Timing and Execution Paths Limit Coverage

A tool’s ability to intervene at one stage of the advertising process does not mean that it can address every trigger type before navigation occurs. Protection depends both on when the defense takes effect and on whether the actual resource, input, and navigation paths pass through it. Ads may still trigger navigation before a defense takes effect. Automatic skipping must first detect the ad, locate its dismissal control, and then perform a click. Although Li Tiaotiao succeeded in all ten applications in our tests, ads remained visible for approximately one second before dismissal. During this interval, the ad has not yet exited, and its touch or motion trigger logic may still execute. Returning after navigation can attempt recovery only after the interruption has occurred. These operations cannot continuously prevent navigation from the moment an ad appears. Advertising behavior that does not pass through the interception point can continue to execute. Network filtering can block resources before an ad appears, but blocking new requests alone cannot address content that has already been cached; appopen advertising SDKs themselves also support preloading [87]. Input control can operate before a dismissal button appears, but our NoShakingAD results show that restricting motion triggers still leaves ad presentation and touch triggers intact. Navigation control also requires requests to pass through the intercepted interface and therefore cannot guarantee the same protection for other paths.

5.3

Ordinary Users Face Deployment and Runtime Barriers

Users need not only to obtain a tool but also to make the defense run correctly while keeping the host application usable. The additional privileges, build or model dependencies, and runtime failures associated with different approaches can all prevent users from obtaining effective protection. The privileges required by a defense may entail additional authorization or system modifications. The approaches in Section 4 variously require VPN or accessibility authorization, debugging privileges obtained through Shizuku, root access and runtime code-injection frameworks, or modification and reinstallation of the target application. Advertising code can execute within its host application, whereas an independent defense tool requires additional privileges to observe or change the behavior of other applications. These control capabilities often cannot be obtained simply by installing an application. Build and model environments can also prevent tools from running. Tools that do not require root may still have additional dependencies. ShakeGuard requires users to configure a build environment and compile an installation package before enabling the accessibility service and rules [113, 114]. In our Pixel 6 tests, Ad Skipper crashed before ad recognition began when loading either of the two tested VLM models, even though the models and their visual projection files had been fully downloaded. Both failures occurred while the Vulkan graphics backend was allocating a buffer; the configuration without an additional VLM could still run. Problems in execution logic and compatibility may interrupt defenses or host functionality. In tests executing ShakeGuard’s original state-management code on the JVM, a failed return could leave the prototype in its recovery state, preventing it from evaluating subsequent navigation from other protected applications. Returning to the home screen and reopening the same application could also retain the previous timer start, incorrectly treating a new navigation attempt as outside the protection window [113]. In our phone tests, enabling AdClose prevented Baidu from launching and left QQ Browser and Tencent Video stuck on the ad page.

Defenses Depend on Rule Coverage and Correct Configuration

Defenses that rely on rules identify ads through predefined matching conditions. After a tool is installed, protection still requires rules to be correctly enabled, cover the target ad, and remain applicable to the particular ad served. Tools cannot handle the target ad when rules do not cover it or are not enabled. Domain filtering must match advertising addresses, automatic skipping must match dismissal controls, and function interception must locate the corresponding advertising entry points. For example, GKD provides its execution capabilities separately from advertising rule subscriptions, which determine the applications and controls to match [85, 136]. Enabling the execution tool alone cannot compensate for ads that its rules do not cover. In the AdClose configuration we tested, request inspection was enabled, but no network-blocking rules were configured; inspecting requests does not itself block them. The same application version may exhibit different advertising behavior. An example in AdHive shows an advertising SDK reading shake enablement and thresholds from a server response and using local defaults when the corresponding parameters are absent [222]. The installed application version therefore does not fully determine the ad’s trigger conditions. Rule applicability also depends on the interface, configuration, and execution path of the particular ad presentation. Claiming support solely by application name cannot adequately express these differences in coverage; one successful attempt does not guarantee that subsequently served ads will meet the same conditions.

5.5

Fragmented Maintenance and Distribution Increase the Cost of Continued Use

Continued use of advertising defenses requires users to obtain tools that are still maintained, select versions that include the required features, and keep rules compatible with target applications. Fragmented maintenance and distribution of tools and rules make these tasks difficult to complete through a single installation. Rule adaptation and project migration require users to keep track of updates. Existing rules may need revision when advertising addresses, interfaces, or internal functions change, while tools, rules, and target applications may be released separately by different teams. Project migrations also change where updates are obtained: Ad-Cleaner has been archived and is no longer maintained, with subsequent functionality moving to R-Store [237]. Users who continue using the old project need to find the subsequent maintenance source to obtain further compatibility updates. Diverse names and versions increase the burden of choosing an installation package. A website introducing Li Tiaotiao 11

downloads lists both “Paidaxing” 2.2 and 2.4 alongside similar tools such as Lei Tiaotiao and Yizhichan. The site identifies 2.2 as the original author’s final release and describes 2.4 as a third-party modification. It also states that rules continue to be updated after software updates have ceased and provides instructions for manual import [133]. Users must distinguish versions of the same tool from separate projects and check maintenance sources, system compatibility, and accompanying rules. Names and version numbers alone make it difficult to determine which package to download; an unchanged software version also does not mean that its rules no longer require updates. Different distribution channels may also provide different advertising defense features. NetGuard’s project documentation explicitly states that its hosts-based ad filtering is not included in the Google Play release [146]. Thus, even after selecting a tool, users must verify that the installed version includes the features they need.

5.6

for blanket ad blocking. However, making these protections effective while preserving sustainable advertising revenue still requires coordination among advertising providers, application developers, and defense-tool developers.

6

Future Paths Toward Better Ecosystems

Finally, we provide some thoughts on the possible paths forward for better balance between ad providers’ power and users’ controls.

6.1

Technical Research Exploration for More Usable Third-Party Tools

An important research direction is whether stronger rootless crossapp intervention can be achieved for ordinary users. Existing examples suggest that user-space applications can sometimes observe or even influence another application without modifying the target app. For example, ARMOUR detects another application’s zero-permission sensor usage entirely from user space, without root or additional permissions, by exploiting shared behaviors of the Android sensor framework [141]. The work explicitly applied the approach to detecting shake-to-open splash ads. GPS spoofing provides an even stronger intervention example. After a user selects a mock-location application, Android allows it to replace location data delivered to other applications through test location providers [27]. These mechanisms demonstrate that rootless crossapp observation and data mediation are technically possible under certain system abstractions, although it remains unclear whether similar design methodologies can be generalized to sensor, touch, or navigation paths involved in splash advertisements. Future research could therefore investigate new user-space signals and system-supported interfaces that enable intervention at common points of the splash-ad pipeline, while avoiding per-app reverse engineering. Combining app-agnostic context—such as foreground state, sensor-usage indicators, interface information, and cross-app transitions—may enable more usable third-party defenses with lower deployment and maintenance costs than today’s rootand rule-dependent approaches.

Potential Legal Problems

Overly intrusive ads drive users to seek ad-removal tools, but tools that indiscriminately remove all ads may affect applications’ advertising-supported business models. Balancing reduced ad intrusion with the preservation of advertising revenue presents another challenge for existing defenses. Li Tiaotiao is free to use and was the only tool in our tests that prevented the target ad-triggered navigation across all ten applications. However, its developer announced an indefinite suspension of updates in August 2023 after receiving a lawyer’s letter. The letter alleged that the tool interfered with a browser’s advertising business and constituted unfair competition. The developer emphasized that the tool merely clicked existing skip buttons on users’ behalf and argued that difficultto-use or misleading dismissal controls drove users to seek such tools [181]. Protecting Users from Intrusion Does Not Necessarily Require Removing All Ads. The Li Tiaotiao dispute illustrates that the parties may differ in their understanding of which behaviors a defense actually changes. Automatically clicking an existing skip button exercises an interface-provided exit option on the user’s behalf. Restricting motion triggers or external-app navigation can preserve ad display while preventing unintended behavior. Blocking ad-resource loading directly affects opportunities to display ads. These approaches affect user experience and advertising businesses differently, but their impact cannot simply be ranked by technical mechanism: navigation interception that preserves ad display may still affect conversions, while automatic skipping may reduce the time users spend viewing ads. Thus, even defenses targeting intrusive interactions may not entirely avoid conflicts with advertising revenue. Restricting Defense Tools Alone Cannot Resolve This Tension. If dismissal controls remain difficult to use and everyday movements can still trigger navigation, users retain an incentive to seek more comprehensive ad blocking. Conversely, indiscriminately removing all ads fails to accommodate services supported by nonintrusive advertising. Clearer, easier-to-use exit options and restrictions on unintended navigation may reduce users’ demand

6.2

Incentivize Smartphone Manufacturers for Platform Improvements

In the multi-party ecosystem involving users, application developers, advertising platforms, and smartphone manufacturers, we believe smartphone manufacturers are particularly well positioned to drive practical improvements. Unlike advertising providers whose revenue may depend on advertisement engagement, manufacturers also compete on overall user experience. In ad previous large-scale user survey [208], 82% of respondents in a consumer survey indicated that the availability of features blocking “shake-to-open” redirects could influence their smartphone purchase decisions. Similar device-level security and privacy protections, such as anti-peeping notifications and deepfake call detection, have already been integrated into commercial smartphones [96, 170, 192]. User demand could therefore provide a direct incentive for manufacturers to offer stronger controls over intrusive splash-ad behavior. This direction has already begun to emerge. Huawei and OPPO provide per-application controls over motion or orientation sensors to suppress shake-triggered advertisement redirects, while HONOR 12

provides system-level warnings for suspected advertisement-induced cross-application jumps [97, 102, 171]. These mechanisms can protect existing applications without requiring every app or advertising SDK provider to modify its implementation, although current solutions remain largely trigger-specific. Prior work has already demonstrated OS-level fine-grained sensor mediation [45, 142, 232] and privilege separation between advertising components and host applications [194]. Compared with third-party tools that rely on Accessibility, root access, or hooking frameworks, manufacturerprovided controls could therefore offer a more deployable path toward systematic protection against intrusive splash ads.

7

[18] AdGuard. [n.d.]. AdGuard for iOS: Free vs. Full Version. https://adguard.com/ kb/adguard-for-ios/features/free-vs-full/ Accessed September 13, 2026. [19] AdGuard. [n.d.]. AdGuard Home: Encryption and iOS Client Configuration. GitHub. https://github.com/AdguardTeam/AdGuardHome/wiki/Encryption Accessed September 13, 2026. [20] AdguardTeam. [n.d.]. AdGuard for Android. GitHub. https://github.com/ AdguardTeam/AdguardForAndroid Accessed September 12, 2026. [21] AdLock. [n.d.]. AdLock: Full Installation and Adjustment Guide. https://adlock. com/user-guide/ Accessed September 13, 2026. [22] afwfv. 2026. FanqieHook. GitHub. https://github.com/afwfv/FanqieHook/blob/ 5a4f54f3c4e08d2e6c0c475ab394b3ff28f0bfb1/README.md Source snapshot dated 2026-09-12. Commit 5a4f54f3c4e0. Accessed September 12, 2026. [23] afwfv. 2026. FanqieHook: AdHooks.kt. GitHub. https://github.com/afwfv/ FanqieHook/blob/5a4f54f3c4e08d2e6c0c475ab394b3ff28f0bfb1/app/src/main/ java/dev/operit/fanqiehook/hooks/AdHooks.kt Source snapshot dated 2026-09-12. Commit 5a4f54f3c4e0. [24] Qingxian An, Haifeng Li, and Bowen Zheng. 2026. Exploring the Dilemma of Full-Screen Ads When Opening an App: The Roles of Users’ Perceived Goal Impediment and Processing Fluency. International Journal of Advertising 45, 4 (2026), 967–989. doi:10.1080/02650487.2025.2516870 [25] anar-bastanov. 2026. ad-skipper-android. GitHub. https://github.com/anar-bastanov/ad-skipper-android/tree/ e7f924c946de2591817b9d2046c3ca3406e0cc49 Source snapshot dated 2026-06-04. Commit e7f924c946de. Accessed September 13, 2026. [26] Android Developers. [n.d.]. DevicePolicyManager: setApplicationHidden. https://developer.android.com/reference/kotlin/android/app/admin/ DevicePolicyManager Accessed September 13, 2026. [27] Android Developers. [n.d.]. LocationManager. Android API Reference. https:// developer.android.com/reference/android/location/LocationManager Accessed September 2026. [28] Android Open Source Project. [n.d.]. Sensors off. https://source.android.com/ docs/core/interaction/sensors/sensors-off Accessed September 12, 2026. [29] AngBang852. [n.d.]. Li Tiansuo / LiTianSuo. GitHub. https://github.com/ AngBang852/LiTianSuo Accessed September 12, 2026. [30] app2smile. 2026. Quantumult X Advertising Network Response Filtering Configuration. GitHub. https://github.com/app2smile/rules/blob/ df6366a7024e0b3f0aa3510c5b791eea6f3cba89/module/adsense.conf Source snapshot dated 2026-03-04. Commit df6366a7024e. Accessed September 13, 2026. [31] app2smile. 2026. Surge ad response filtering configuration at commit df6366a. GitHub. https://github.com/app2smile/rules/blob/ df6366a7024e0b3f0aa3510c5b791eea6f3cba89/module/adsense.sgmodule Source snapshot dated 2026-03-04. Commit df6366a7024e. Accessed September 12, 2026. [32] app2smile. [n.d.]. rules. GitHub. https://github.com/app2smile/rules Accessed September 12, 2026. [33] Apple. [n.d.]. Allowing apps and websites to link to your content. https://developer.apple.com/documentation/xcode/allowing-apps-andwebsites-to-link-to-your-content Accessed September 12, 2026. [34] Apple. [n.d.]. App code signing process in iOS, iPadOS, tvOS, visionOS, and watchOS. https://support.apple.com/en-euro/guide/security/sec7c917bf14/web Accessed September 12, 2026. [35] Apple. [n.d.]. iTunes Lookup API Response for DNSCloak (App ID 1452162351). Apple iTunes Lookup API. https://itunes.apple.com/lookup?id=1452162351& country=us Accessed September 13, 2026. [36] Apple. [n.d.]. Security of runtime process in iOS, iPadOS, and visionOS. https://support.apple.com/en-ae/guide/security/sec15bfe098e/web Accessed September 12, 2026. [37] Apple. [n.d.]. TN3134: Network Extension provider deployment. https://developer.apple.com/documentation/technotes/tn3134-networkextension-provider-deployment Accessed September 12, 2026. [38] Apple. [n.d.]. URL filters. https://developer.apple.com/documentation/ networkextension/url-filters Accessed September 12, 2026. [39] BiliRoamingX. 2024. BiliRoamingX. GitHub. https://github.com/BiliRoamingX/ BiliRoamingX/tree/ae58109f3acdd53ec2d2b3fb439c2a2ef1886221 Source snapshot dated 2024-09-24. Commit ae58109f3acd. Accessed September 13, 2026. [40] BiliRoamingX. [n.d.]. BiliRoamingX: Releases. GitHub. https://github.com/ BiliRoamingX/BiliRoamingX-PreBuilds/releases Accessed September 13, 2026. [41] blackmatrix7. [n.d.]. ios_rule_script. GitHub. https://github.com/blackmatrix7/ ios_rule_script Accessed September 12, 2026. [42] Blokada. 2022. Blokada 5 vs Blokada 6: official community comparison. https: //community.blokada.org/t/blokada-5-vs-blokada-6/25411 Accessed September 12, 2026. [43] Blokada. 2025. Why Do We Need to Get the Subscription? https://community. blokada.org/t/why-do-we-need-to-get-the-subscription/40894 Accessed September 13, 2026. [44] Blokada. [n.d.]. Blokada: Mobile Ad Blocking and VPN for Android and iOS. https://blokada.org/ Accessed September 13, 2026.

Conclusion

We studied how splash ads cause unintended app or webpage openings and whether existing ad-blocking tools can help users avoid them. Our analysis and tests show that users face difficulties both setting up these tools and obtaining reliable protection. Some tools failed to stop redirects, and others left apps unable to open or stuck on the ad page. Even tools requiring root access did not consistently work. Smartphone manufacturers and platform providers could reduce this burden by giving users built-in options to disable unwanted ad interactions. The goal is to let users open and use their apps without accidental redirects, while allowing advertising that respects their choices.

References [1] 1205417239. 2026. AdSkipTweak. GitHub. https://github.com/1205417239/ AdSkipTweak/tree/e335fbecb1cf411f7fcc66da9195ea9acfce7136 Source snapshot dated 2026-08-29. Commit e335fbecb1cf. Accessed September 13, 2026. [2] 1205417239. [n.d.]. AdSkipTweak: GitHub Actions. GitHub. https://github. com/1205417239/AdSkipTweak/actions Accessed September 13, 2026. [3] 33lilil. 2026. SplashGuard. GitHub. https://github.com/33lilil/SplashGuard/tree/ c6918c85ded69c4d34b7ddd5b4136d3eed365841 Source snapshot dated 2026-0829. Commit c6918c85ded6. Accessed September 13, 2026. [4] 33lilil. [n.d.]. SplashGuard (33lilil): Repository. GitHub. https://github.com/ 33lilil/SplashGuard Accessed September 13, 2026. [5] 743859910. [n.d.]. LiTiaoTiao_Custom_Rules. GitHub. https://github.com/ 743859910/LiTiaoTiao_Custom_Rules Accessed September 12, 2026. [6] abertschi. [n.d.]. ad-free. GitHub. https://github.com/abertschi/ad-free Accessed September 13, 2026. [7] abertschi. [n.d.]. ad-free: F-Droid Package Listing. https://f-droid.org/packages/ ch.abertschi.adfree/ Accessed September 13, 2026. [8] AdAway. [n.d.]. AdAway. GitHub. https://github.com/AdAway/AdAway Accessed September 12, 2026. [9] AdBlock Labs. [n.d.]. AdBlock: App Store Listing. https://apps.apple.com/us/ app/adblock/id691121579 Accessed September 13, 2026. [10] AdBlocker-Reborn. [n.d.]. AdBlocker Reborn. GitHub. https://github.com/ AdBlocker-Reborn/AdBlocker_Reborn Accessed September 12, 2026. [11] AdBlocker-Reborn. [n.d.]. AdBlocker Reborn: APK Distribution. GitHub. https://github.com/AdBlocker-Reborn/AdBlocker_Reborn/blob/master/app/ release/app-release.apk Accessed September 13, 2026. [12] adblockplus. 2021. libadblockplus-android. GitHub. https://github.com/adblockplus/libadblockplus-android/tree/ 9038f35795b16ac6da348729e57ecbd1746e63b3 Source snapshot dated 2021-05-19. Commit 9038f35795b1. Accessed September 13, 2026. [13] AdGuard. [n.d.]. AdGuard DNS. https://adguard-dns.io/en/welcome.html Accessed September 13, 2026. [14] AdGuard. [n.d.]. AdGuard DNS: Subscription Plans. https://adguard-dns.io/ en/license.html Accessed September 13, 2026. [15] AdGuard. [n.d.]. AdGuard for Android: Free vs. Full Version. https://adguard. com/kb/adguard-for-android/features/free-vs-full/ Accessed September 14, 2026. [16] AdGuard. [n.d.]. AdGuard for iOS: Ads in apps. https://adguard.com/en/ support/adguard_for_ios/doesnt_block_ads/in_apps.html Accessed September 12, 2026. [17] AdGuard. [n.d.]. AdGuard for iOS: DNS protection. https://adguard.com/kb/ adguard-for-ios/features/dns-protection/ Accessed September 12, 2026. 13

[71] Guangran Du. 2026. Blogger Says Navigation App’s “Shake-to-Open” Splash Ad Affected Driving Safety; Customer Service Says Improvements Are Underway. Jimu News. https://www.ctdsb.net/c1476_202606/2777613.html In Chinese. Published June 20, 2026. Accessed September 13, 2026. https://github.com/Edsuns/ [72] Edsuns. 2021. AdblockAndroid. GitHub. AdblockAndroid/tree/a585487eb19328f635a5b7b983fa38d4c97f2bc8 Source snapshot dated 2021-08-19. Commit a585487eb193. Accessed September 13, 2026. [73] F-Droid. [n.d.]. Klick’r: F-Droid Package Listing. https://f-droid.org/packages/ com.buzbuz.smartautoclicker/ Accessed September 13, 2026. [74] fmz200. 2026. WeChatMiniAds Loon plugin at commit 3ca7487. GitHub. https://github.com/fmz200/wool_scripts/blob/ 3ca7487b4e4b86d9af76e50df72c62eacfbb659e/Loon/plugin/WeChatMiniAds. plugin Source snapshot dated 2026-09-10. Commit 3ca7487b4e4b. Accessed September 12, 2026. [75] fmz200. [n.d.]. wool_scripts. GitHub. https://github.com/fmz200/wool_scripts Accessed September 12, 2026. [76] FreeTeaspoon. 2026. MapsAdBlock. GitHub. https://github.com/FreeTeaspoon/ MapsAdBlock/tree/db5489ef6966af7678131603a6ef7f0bd2a87633 Source snapshot dated 2026-09-11. Commit db5489ef6966. Accessed September 13, 2026. [77] FutureMind. [n.d.]. AdBlock for iOS and iPadOS: FAQ. https://www.adblockios. com/faq/ Accessed September 13, 2026. [78] Gameye98. 2026. DTL-X. GitHub. https://github.com/Gameye98/DTL-X/tree/ 6f9472e8dbcd0ae93052050e254812c6ee298232 Source snapshot dated 2026-02-23. Commit 6f9472e8dbcd. Accessed September 13, 2026. [79] Gedsh. 2026. InviZible. GitHub. https://github.com/Gedsh/InviZible/tree/ 3a2067ef07af1a09946697518c70901d417ab0c6 Source snapshot dated 2026-0906. Commit 3a2067ef07af. Accessed September 13, 2026. [80] ggsava. 2025. Block This: README. GitHub. https://github.com/ggsava/blockthis/blob/6c415352c9be96a336d6641e74aa75fcbfa4fa02/README.md Source snapshot dated 2025-11-04. Commit 6c415352c9be. Accessed September 12, 2026. [81] Giftedcat. 2023. AdSkipHelper. GitHub. https://github.com/Giftedcat/ AdSkipHelper/blob/baffbff2d2173bae0e11cd4367c9f84edbd45335/README. md Source snapshot dated 2023-09-05. Commit baffbff2d217. Accessed September 12, 2026. [82] Giftedcat. [n.d.]. AdSkipHelper: Repository. GitHub. https://github.com/ Giftedcat/AdSkipHelper Accessed September 13, 2026. [83] GimleLarpes. 2025. AdSkipper. GitHub. https://github.com/GimleLarpes/ AdSkipper/tree/63749b2e545a25238c92bc6cf9705225673eb4e5 Source snapshot dated 2025-02-25. Commit 63749b2e545a. Accessed September 13, 2026. [84] GimleLarpes. [n.d.]. AdSkipper (GimleLarpes): Repository. GitHub. https: //github.com/GimleLarpes/AdSkipper Accessed September 13, 2026. [85] gkd-kit. [n.d.]. GKD. GitHub. https://github.com/gkd-kit/gkd Accessed September 12, 2026. [86] Google. [n.d.]. About Confirmed Click. https://support.google.com/admob/ answer/10094971?hl=en Accessed September 12, 2026. [87] Google. [n.d.]. App open ads: Android. https://developers.google.com/admob/ android/app-open Accessed September 12, 2026. [88] Google. [n.d.]. App open ads: iOS. https://developers.google.com/admob/ios/ app-open Accessed September 12, 2026. [89] Google. [n.d.]. Create an accessibility service. https://developer.android.com/ guide/topics/ui/accessibility/service Accessed September 12, 2026. [90] Google. [n.d.]. Set Frequency Caps for Apps or Ad Units. Google AdMob Help. https://support.google.com/admob/answer/6244508?hl=en Accessed September 14, 2026. [91] Google. [n.d.]. Set Up Mobile Device Targeting. Google Ads Help. https: //support.google.com/google-ads/answer/7101715?hl=en Accessed September 14, 2026. [92] GuoXiCheng. [n.d.]. SKIP. GitHub. https://github.com/GuoXiCheng/SKIP Accessed September 12, 2026. [93] hao1196561270. 2026. MiFitnessAdAway. GitHub. https://github.com/hao1196561270/MiFitnessAdAway/blob/ 55e578d30b2e23d13692248b73c8fe52d6352d71/README.md Source snapshot dated 2026-09-10. Commit 55e578d30b2e. Accessed September 12, 2026. [94] hao1196561270. 2026. MiFitnessAdAway: AdAwayModule.java. GitHub. https://github.com/hao1196561270/MiFitnessAdAway/blob/ 55e578d30b2e23d13692248b73c8fe52d6352d71/app/src/main/java/io/github/ hao1196561270/mifitnessadaway/AdAwayModule.java Source snapshot dated 2026-09-10. Commit 55e578d30b2e. [95] hatbrox. 2026. Shared Screen Event Between Scenarios. GitHub. https: //github.com/Nain57/Smart-AutoClicker/discussions/840 GitHub discussion 840. Posted May 11, 2026. Accessed September 13, 2026. [96] HONOR. 2025. MagicOS 10.0 Security Technical White Paper. Technical Report. Honor Device Co., Ltd. https://www.honor.com/content/dam/honor/om-ar/ privacy/overview/pdf/MagicOS-10.0-Security-Technical-White-Paper.pdf Published October 15, 2025. Accessed September 13, 2026.

[45] Connor Bolton, Yan Long, Jun Han, Josiah Hester, and Kevin Fu. 2023. Characterizing and mitigating touchtone eavesdropping in smartphone motion sensors. In Proceedings of the 26th International Symposium on Research in Attacks, Intrusions and Defenses. 164–178. [46] Bottom-Pump. 2026. dongqiudi-adblock. GitHub. https://github.com/BottomPump/dongqiudi-adblock/tree/0e3b8b76ef3e29165d2a59fbfcc906bf8c7b2678 Source snapshot dated 2026-07-04. Commit 0e3b8b76ef3e. Accessed September 13, 2026. [47] Buzbuz Software. [n.d.]. Klick’r—Smart AutoClicker: Image and Text Conditions and Accessibility Actions. https://play.google.com/store/apps/details?id=com. buzbuz.smartautoclicker&hl=en Accessed September 13, 2026. [48] ByteDance. [n.d.]. GroMore Android Splash Ad Integration. https://www. csjplatform.com/supportcenter/28660 Accessed September 12, 2026. [49] CELESTIAN GOLDEN APPS. [n.d.]. Lockdown Privacy: Firewall Features and In-App Purchases. https://apps.apple.com/us/app/lockdown-privacy-adblockvpn/id1469783711 Accessed September 13, 2026. [50] celzero. 2026. rethink-app. GitHub. https://github.com/celzero/rethink-app/ tree/22e129d7277cc19899219aee116814371a5fda01 Source snapshot dated 202609-09. Commit 22e129d7277c. Accessed September 13, 2026. [51] Celzero. [n.d.]. Rethink Downloads: Free Application and Paid RPN. https: //www.rethinkdns.com/download Accessed September 13, 2026. [n.d.]. QzxyAdBlock. GitHub. [52] chenzhengyuan2351. https://github.com/chenzhengyuan2351/QzxyAdBlock/tree/ 56b8f0ed4e034fc784d708d984dc12b7dbb93b2d Commit 56b8f0ed4e03. Accessed September 13, 2026. [53] chenzhengyuan2351. [n.d.]. QzxyAdBlock: APK Distribution. GitHub. https://github.com/chenzhengyuan2351/QzxyAdBlock/blob/main/lsposed/ QzxyAdBlock.apk Accessed September 13, 2026. [54] chiehmin. [n.d.]. MinMinGuard. GitHub. https://github.com/chiehmin/ MinMinGuard Accessed September 12, 2026. [55] China Media Group, China National Radio. 2026. Elderly User Encounters 20 Pop-Up Ads in 30 Seconds While Trying to Take a Photo: Why Are App Ads So Difficult to Close? Xinhua News App. https://app.xinhuanet.com/news/ article.html?articleId=202608127c94496a43e14e688bfddbc1b49fd566 In Chinese. Published August 12, 2026. Accessed September 13, 2026. [56] chr233. 2026. PureNGA. GitHub. https://github.com/chr233/PureNGA/blob/ 33ccde4381ed42f558e3e2c2005b74826a4e47f1/README.md Source snapshot dated 2026-09-10. Commit 33ccde4381ed. Accessed September 12, 2026. [57] cinit. 2026. QAuxiliary. GitHub. https://github.com/cinit/QAuxiliary/tree/ 9d3159b9d29e3fca5d7e5a6564a943b75053ed3b Source snapshot dated 2026-0904. Commit 9d3159b9d29e. Accessed September 13, 2026. [58] clarithromycine. 2026. AdAuto (Hongguo Short Drama ad skipping). GitHub. https://github.com/clarithromycine/ad-auto/blob/ 4424e36531825247cd6e4294d8f8c5a4d2556613/README.md Source snapshot dated 2026-09-03. Commit 4424e3653182. Accessed September 12, 2026. [59] code-wanghao. [n.d.]. ZeroStart. GitHub. https://github.com/codewanghao/ZeroStart/tree/4914b5c375a374bef57f0d8020457063845198a5 Commit 4914b5c375a3. Accessed September 13, 2026. [60] Community Ad-Skipping Tool Archive [n.d.]. Community-Shared Ad-Skipping Tool Archive. https://pan.quark.cn/s/69b1c25213f9 Accessed September 12, 2026. [61] confirmedcode. 2025. Lockdown-iOS. GitHub. https://github.com/confirmedcode/Lockdown-iOS/tree/ e456e0974a78aa2e44b3e07f2022f98d26d615f0 Source snapshot dated 2025-03-12. Commit e456e0974a78. Accessed September 13, 2026. [62] Control D. [n.d.]. Control D: Ads and Trackers Filter Modes. https://docs. controld.com/docs/ads-filter-modes Accessed September 13, 2026. [63] Control D. [n.d.]. Free DNS Resolvers and Paid Profile Features. https://docs. controld.com/docs/free-dns Accessed September 13, 2026. [64] CoolestEnoch. 2023. TheMessWorld: README. GitHub. https://github.com/CoolestEnoch/TheMessWorld/blob/ 5a2b8ea2ef396889fe63559cf93fef19674c0738/README.md Source snapshot dated 2023-05-09. Commit 5a2b8ea2ef39. Accessed September 12, 2026. [65] cranone. 2024. CleanSplash. GitHub. https://github.com/cranone/CleanSplash/ tree/2ed35a32fd9fe67d2006db9c78e5c63729429571 Source snapshot dated 202401-07. Commit 2ed35a32fd9f. Accessed September 13, 2026. [66] cranone. [n.d.]. CleanSplash: Repository. GitHub. https://github.com/cranone/ CleanSplash Accessed September 13, 2026. [67] Cross Utility Ltd. [n.d.]. Quantumult X: App Store Listing. https://apps.apple. com/us/app/quantumult-x/id1443988620 Accessed September 13, 2026. [68] dabtech. [n.d.]. Adhell3. GitHub. https://github.com/dabtech/Adhell3 Accessed September 12, 2026. [69] ddgksf2013. [n.d.]. Rewrite. GitHub. https://github.com/ddgksf2013/Rewrite Accessed September 12, 2026. [70] decemberpei. [n.d.]. AdSkipper: Google Play listing. https://play.google.com/ store/apps/details?id=decemberpei.gmail.adskipper Accessed September 13, 2026. 14

[125] Kin69. 2026. Athena: DnsScreen.kt. GitHub. https://github.com/Kin69/Athena/ blob/240c94a86ac2708242c2cceaf5081f83b6a2cb52/app/src/main/java/com/ kin/athena/presentation/screens/settings/subSettings/dns/DnsScreen.kt Source snapshot dated 2026-01-26. Commit 240c94a86ac2. Accessed September 13, 2026. [126] Kingtous. 2023. rule_imprison_android. GitHub. https://github.com/Kingtous/ rule_imprison_android/tree/e2686ec4012010d69a40682c1d51220a38a53060 Source snapshot dated 2023-11-03. Commit e2686ec40120. Accessed September 13, 2026. [127] Kingtous. [n.d.]. Rule Imprison: Repository. GitHub. https://github.com/ Kingtous/rule_imprison_android Accessed September 13, 2026. [128] kiraio-moe. [n.d.]. Lain-Patches. GitHub. https://github.com/kiraio-moe/LainPatches Accessed September 12, 2026. [129] KonghuanSmart. 2022. SkipAds. GitHub. https://github.com/KonghuanSmart/ SkipAds/tree/2ad5afa4594cbfc210fa2459d6e4b9b29529db0c Source snapshot dated 2022-07-20. Commit 2ad5afa4594c. Accessed September 13, 2026. [130] KonghuanSmart. [n.d.]. SkipAds (KonghuanSmart): Repository. GitHub. https: //github.com/KonghuanSmart/SkipAds Accessed September 13, 2026. iOS advertising SDK integration guide, version [131] Kuaishou. [n.d.]. 3.3.28. https://static.yximgs.com/udata/pkg/KSAdSDKTarGz/doc/ksadsdk-iOSreadme-ad-3.3.28--1182.pdf Accessed September 12, 2026. [132] ldxm666. 2026. XTA-AdKiller. GitHub. https://github.com/ldxm666/XTAAdKiller/tree/b1c94af10c04786a19e2c459ad14875cad022194 Source snapshot dated 2026-09-10. Commit b1c94af10c04. Accessed September 13, 2026. [133] Lei Tiao Tiao [n.d.]. Lei Tiaotiao. https://www.ad-litiaotiao.com/ Accessed September 12, 2026. [134] leihaogit. 2025. LeiTiaoTiao: SkipAdServiceImpl.kt. GitHub. https://github. com/leihaogit/leitt/blob/40fe9a011287a069219d1291cd844857c7cc1588/app/ src/main/java/com/hal/leitt/service/SkipAdServiceImpl.kt Source snapshot dated 2025-02-13. Commit 40fe9a011287. Accessed September 12, 2026. [135] LGH1996. [n.d.]. TapClick. GitHub. https://github.com/LGH1996/TapClick Accessed September 12, 2026. [136] Lin-arm. [n.d.]. GKD_subscription. GitHub. https://github.com/Lin-arm/GKD_ subscription Accessed September 12, 2026. [137] Lizhi Software Store. [n.d.]. Qing Qidong: Free Edition and Full-Version Activation. https://lizhi.shop/site/products/id/439 Accessed September 13, 2026. [138] lkchx123. 2026. CoolApkNoSplash. GitHub. https://github.com/lkchx123/ CoolApkNoSplash/tree/7a137d86dacd8336da9e388b74ef61fabca5bbb4 Source snapshot dated 2026-08-02. Commit 7a137d86dacd. Accessed September 13, 2026. [139] lkchx123. [n.d.]. CoolApkNoSplash: GitHub Actions. GitHub. https://github. com/lkchx123/CoolApkNoSplash/actions Accessed September 13, 2026. [140] Mengyi Long, Yue Xu, Jiangrong Wu, Qihua Ou, and Yuhong Nan. 2023. Understanding Dark UI Patterns in the Mobile Ecosystem: A Case Study of Apps in China. In Proceedings of the 2023 ACM Workshop on Secure and Trustworthy Superapps. ACM, New York, NY, USA, 33–40. doi:10.1145/3605762.3624431 [141] Yan Long, Jiancong Cui, Yuqing Yang, Tobias Alam, Zhiqiang Lin, and Kevin Fu. 2025. ARMOUR US: Android Runtime Zero-permission Sensor Usage Monitoring from User Space. In 18th ACM Conference on Security and Privacy in Wireless and Mobile Networks (WiSec 2025). Association for Computing Machinery, New York, NY, USA, 100–111. doi:10.1145/3734477.3734704 [142] Yan Long and Kevin Fu. 2022. Side Auth: Synthesizing Virtual Sensors for Authentication. In Proceedings of the 2022 New Security Paradigms Workshop. 35–44. [143] Loon Lab Limited. [n.d.]. Loon: App Store Listing. https://apps.apple.com/us/ app/loon/id1373567447 Accessed September 13, 2026. [144] luestr. [n.d.]. ProxyResource. GitHub. https://github.com/luestr/ProxyResource Accessed September 12, 2026. [145] LY Corporation. 2026. What to know when "Open in LINE" or "Log in with LINE" doesn’t work as expected. https://developers.line.biz/en/tips/2026/05/07/linelaunch-issue/ Published May 7, 2026. Accessed September 12, 2026. [146] M66B. 2026. NetGuard. GitHub. https://github.com/M66B/NetGuard/tree/ 166df969c3cedd7023c13613d9816c185702c6c9 Source snapshot dated 2026-08-01. Commit 166df969c3ce. Accessed September 13, 2026. [147] madeye. [n.d.]. madeye/ad-skipper. GitHub. https://github.com/madeye/adskipper Accessed September 12, 2026. NetGuard FAQ: Pro Features and Pur[148] Marcel Bokhorst. 2026. chases. GitHub. https://github.com/M66B/NetGuard/blob/ 166df969c3cedd7023c13613d9816c185702c6c9/FAQ.md Source snapshot dated 2026-08-01. Commit 166df969c3ce. Accessed September 13, 2026. [149] Mer3y1338. 2026. cad-viewer-ad-cleaner. GitHub. https://github.com/Mer3y1338/cad-viewer-ad-cleaner/blob/ 68782f3511a58bacdd578751289507bef94a17c9/README.md Source snapshot dated 2026-07-05. Commit 68782f3511a5. Accessed September 12, 2026. [150] Mer3y1338. 2026. cad-viewer-ad-cleaner: build_minimal_patch.py. GitHub. https://github.com/Mer3y1338/cad-viewer-ad-cleaner/blob/ 68782f3511a58bacdd578751289507bef94a17c9/scripts/build_minimal_patch.py Source snapshot dated 2026-07-05. Commit 68782f3511a5.

[97] HONOR. [n.d.]. Enable Automatic App Navigation Reminders. https://www. honor.com/cn/support/content/zh-cn15849565/ Accessed September 12, 2026. [98] HONOR. [n.d.]. Environmental, Social and Responsible Governance Report 2024. https://www.honor.com/content/dam/honor/cn/honor-esg/esg-report2023/section-pdf/2024ESG%E6%8A%A5%E5%91%8A_250527.pdf Accessed September 12, 2026. [99] HONOR. [n.d.]. HONOR 100 Series 8.0.0.150 Release Notes. https://club.honor. com/cn/thread-28839549-1-1.html Accessed September 12, 2026. [100] Huawei. [n.d.]. Ads appear when entering or using third-party apps. https: //consumer.huawei.com/cn/support/content/zh-cn16002151/ Accessed September 12, 2026. [101] Huawei. [n.d.]. Manage app access permissions. https://consumer.huawei.com/ cn/support/content/zh-cn15999149/ Accessed September 12, 2026. [102] Huawei. [n.d.]. Manage App Access Permissions: Device Orientation Access. Huawei Consumer Support. https://consumer.huawei.com/cn/support/content/ zh-cn16100686/ Accessed September 13, 2026. [103] hui01101. [n.d.]. SplashCleaner-Android. GitHub. https://github.com/hui01101/ SplashCleaner-Android Accessed September 12, 2026. SplashCleaner-Android: APK Distribution. GitHub. [104] hui01101. [n.d.]. https://github.com/hui01101/SplashCleaner-Android/blob/main/dist/ SplashCleaner-3.1.1-xiaomi-fix-debug.apk Accessed September 13, 2026. [105] hujiayucc. [n.d.]. Fuck AD. GitHub. https://github.com/hujiayucc/Fuck-AD Accessed September 12, 2026. [106] hxreborn. 2026. amznkiller. GitHub. https://github.com/hxreborn/amznkiller/ tree/076af0f37fbc72573dd60463a848bcb16ddb2084 Source snapshot dated 202609-07. Commit 076af0f37fbc. Accessed September 13, 2026. [107] hxreborn. 2026. discover-ads-filter. GitHub. https://github.com/hxreborn/ discover-ads-filter/tree/8233942238cc2becd9ce9c46f7fe9932cc46fdaf Source snapshot dated 2026-09-07. Commit 8233942238cc. Accessed September 13, 2026. [108] hxreborn. 2026. playstore-adblock. GitHub. https://github.com/hxreborn/ playstore-adblock/tree/202ea6e9bf9df9f8447a9f07d20daafc6c90c971 Source snapshot dated 2026-09-10. Commit 202ea6e9bf9d. Accessed September 13, 2026. [109] IngoZenz. [n.d.]. personalDNSfilter. GitHub. https://github.com/IngoZenz/ personaldnsfilter Accessed September 12, 2026. [110] iTXTech. 2022. Daedalus: Built-in Advertising Rule Sources and DNS Rule Resolution. GitHub. https://github.com/iTXTech/Daedalus/tree/ 0deea908d99dd4665efab8523841670bde66b21f Source snapshot dated 202206-26. Commit 0deea908d99d. Accessed September 13, 2026. [111] IVPN. [n.d.]. IVPN: AntiTracker FAQ. https://www.ivpn.net/knowledgebase/ general/antitracker-faq/ Accessed September 13, 2026. [112] IVPN. [n.d.]. IVPN Subscription Plans. https://www.ivpn.net/es/pricing/ Accessed September 13, 2026. [113] JiangZi0721. 2026. shakeguard. GitHub. https://github.com/JiangZi0721/ shakeguard/tree/f04760656d3f1d25e6dcb9cde933be902b9e3598 Source snapshot dated 2026-08-30. Commit f04760656d3f. Accessed September 13, 2026. [114] JiangZi0721. [n.d.]. ShakeGuard: Repository. GitHub. https://github.com/ JiangZi0721/shakeguard Accessed September 13, 2026. [115] jkennethcarino. 2026. adobo. GitHub. https://github.com/jkennethcarino/ adobo/tree/0d56b693d53cd36309018f162f4101d906364094 Source snapshot dated 2026-08-31. Commit 0d56b693d53c. Accessed September 13, 2026. [116] Johnny520. 2026. JohnnyAdBlock. GitHub. https://github.com/Johnny520/ JohnnyAdBlock/tree/0be137959a1110d0b0ea5afa5051bc522cca7aa0 Source snapshot dated 2026-07-20. Commit 0be137959a11. Accessed September 13, 2026. [117] julian-klode. [n.d.]. DNS66. GitHub. https://github.com/julian-klode/dns66 Accessed September 12, 2026. [118] kaisar945. 2023. Xposed-GodMode. GitHub. https://github.com/kaisar945/ Xposed-GodMode/tree/3a38e542542e500a82cd5676ff8cb0beb01adf52 Source snapshot dated 2023-01-10. Commit 3a38e542542e. Accessed September 13, 2026. [119] Kaylee Calderolla. [n.d.]. Wipr 2: Filtr App Store Description and Release Notes. https://apps.apple.com/ca/app/wipr-2/id1662217862 Accessed September 13, 2026. [120] Kaylee Calderolla and Apple Developer Forums participants. [n.d.]. Getting a basic URL Filter to work: Wipr developer discussion. https://developer.apple. com/forums/thread/791352 Accessed September 13, 2026. [121] KEJIYUNB. 2026. AutoClickerPurifier. GitHub. https://github.com/KEJIYUNB/ AutoClickerPurifier/tree/658f830374d022e591dd7ffc6ea0ee48eb4a1232 Source snapshot dated 2026-08-01. Commit 658f830374d0. Accessed September 13, 2026. [122] KEJIYUNB. [n.d.]. AutoClickerPurifier: Repository. GitHub. https://github. com/KEJIYUNB/AutoClickerPurifier Accessed September 13, 2026. [123] Kelee. [n.d.]. Kelee Plugin Hub. https://hub.kelee.one/ Accessed September 12, 2026. [124] Kin69. 2026. Athena. GitHub. https://github.com/Kin69/Athena/tree/ 240c94a86ac2708242c2cceaf5081f83b6a2cb52 Source snapshot dated 2026-01-26. Commit 240c94a86ac2. Accessed September 13, 2026. 15

[175] Phoenix Technology. 2026. Even Blind Users Cannot Escape Pop-Up Advertisements: A Business That Breaks the Bottom Line. Phoenix Technology, republished by 36Kr. https://eu.36kr.com/zh/p/3978322257443842 In Chinese; title translated into English. Published September 11, 2026. Accessed September 13, 2026. [176] Private Internet Access. [n.d.]. PIA: Website and App Access Troubleshooting, Including MACE. https://helpdesk.privateinternetaccess.com/hc/enus/articles/54646120515611-Can-t-Access-Specific-Websites-or-Apps-WhileUsing-PIA-VPN Accessed September 13, 2026. [177] Private Internet Access. [n.d.]. VPN with Ad Blocking: MACE. https://www. privateinternetaccess.com/ad-blocking-vpn Accessed September 13, 2026. [178] Promisin. 2020. ADSkip. GitHub. https://github.com/Promisin/ADSkip/tree/ 13e00bcc789c760d0e3fb8602dd0196436862ef7 Source snapshot dated 2020-07-04. Commit 13e00bcc789c. Accessed September 13, 2026. [179] Proton. [n.d.]. Proton VPN: NetShield. https://protonvpn.com/support/ netshield Accessed September 13, 2026. [180] pwh-pwh. [n.d.]. Fuck Shake. GitHub. https://github.com/pwh-pwh/fuck_ shake Accessed September 12, 2026. [181] Qing Xiaowa. 2023. Android Ad-Skipping Apps Taken Down After Receiving Tencent Lawyer Letters: Li Tiaotiao, Bengda, Dasheng Jinghua, and Ding Xiaotiao. Appinn. https://www.appinn.com/xiajia-antiad-apps/ In Chinese; title translated into English. Accessed September 12, 2026. [182] ReChronoRain. 2023. Cemiuiler. GitHub. https://github.com/ReChronoRain/ Cemiuiler/tree/b66a0b6fc3e0be823cd837daf4db07172f9be360 Source snapshot dated 2023-11-04. Commit b66a0b6fc3e0. Accessed September 13, 2026. [183] ReChronoRain. 2026. HyperCeiler. GitHub. https://github.com/ReChronoRain/ HyperCeiler/tree/879df1d3792611d4cda1bdfa6f94d947ca8816c6 Source snapshot dated 2026-09-06. Commit 879df1d37926. Accessed September 13, 2026. [184] Repcz. 2026. Tool X-branch tree at commit 64a61f5. GitHub. https://github.com/ Repcz/Tool/tree/64a61f52c2914c9d86e77ce4d6e0a7f428c3aeb9 Source snapshot dated 2026-09-11. Commit 64a61f52c291. Accessed September 12, 2026. [185] ReVanced. [n.d.]. ReVanced Manager: Download and Patching Overview. https: //revanced.app/download Accessed September 13, 2026. [186] ReVanced community. [n.d.]. ReVanced Manager issue 3377: Reddit Hide ads patch log. GitHub. https://github.com/ReVanced/revanced-manager/issues/ 3377 Accessed September 13, 2026. [187] rongzhiy. [n.d.]. LiTiaotiao. GitHub. https://github.com/rongzhiy/LiTiaotiao Accessed September 12, 2026. [188] Sergey Smirnov. 2020. DNSCloak: DNSCrypt and DNS-over-HTTPS Client for iOS. GitHub. https://github.com/s-s/dnscloak/tree/ 6a7a3bbf91969ab8a93b089f1ffe28da99fa1e36 Source snapshot dated 2020-11-01. Commit 6a7a3bbf9196. Accessed September 13, 2026. [189] SEVEN Networks. [n.d.]. AdClear Content Blocker. https://sevennetworks. com/products/adclear Accessed September 12, 2026. [190] SEVEN Networks. [n.d.]. AdClear Content Blocker distribution and developer replies. https://play.google.com/store/apps/details?id=com.seven.adclear.fsb Accessed September 12, 2026. [191] SEVEN Networks. [n.d.]. adX. https://sevennetworks.com/products/adx/ Accessed September 12, 2026. [192] Nina Shamsi, Yan Long, and Kevin Fu. 2025. EyeHearYou: Probing Location Identification via Occluded Smartphone Cameras and Ultrasound. In 2025 IEEE International Symposium on Hardware Oriented Security and Trust (HOST). IEEE, 23–34. [193] Yuxuan Shang, Guanxiao Wang, Mengxia Ren, Haomin Zhang, Xingming Chen, Haitao Xu, Chuan Yue, Shuai Hao, Bo Zhou, Wenrui Ma, Fan Zhang, and Zhao Li. 2025. AdsDP: A Video Dataset for Recognizing and Examining Dark Patterns in iOS In-App Advertisements. Proceedings of the ACM on Interactive, Mobile, Wearable and Ubiquitous Technologies 9, 3, Article 127 (2025), 31 pages. doi:10.1145/3749515 [194] Shashi Shekhar, Michael Dietz, and Dan S. Wallach. 2012. AdSplit: Separating Smartphone Advertising from Applications. In 21st USENIX Security Symposium (USENIX Security). USENIX Association, Bellevue, WA, 553– 567. https://www.usenix.org/conference/usenixsecurity12/technical-sessions/ presentation/shekhar [195] Anastasia Shuba, Athina Markopoulou, and Zubair Shafiq. 2018. NoMoAds: Effective and Efficient Cross-App Mobile Ad-Blocking. Proceedings on Privacy Enhancing Technologies 2018, 4 (2018), 125–140. doi:10.1515/popets-2018-0035 [196] Sigmob. [n.d.]. Sigmob SDK Compliance Guide: Sensor and Interaction Controls. https://doc.sigmob.com/sigmob/143/ Accessed September 12, 2026. [197] Sigmob. [n.d.]. ToBid Android Privacy Settings. https://doc.sigmob.com/tobid/ 21161/ Accessed September 12, 2026. [198] Surfshark. [n.d.]. How to Use CleanWeb In-App. https://support.surfshark. com/hc/en-us/articles/360021008640-How-to-use-CleanWeb-in-app Accessed September 13, 2026. [199] Surfshark. [n.d.]. Surfshark: CleanWeb. https://surfshark.com/features/cleanweb Accessed September 13, 2026. [200] Surge. [n.d.]. HTTPS Decryption (MITM). https://manual.nssurge.com/http/ mitm.html Accessed September 12, 2026.

[151] miaomiao636. 2026. PureSkip. GitHub. https://github.com/miaomiao636/ PureSkip/tree/8620083fed2f4186c03992349b0aac39f43cb62e Source snapshot dated 2026-07-26. Commit 8620083fed2f. Accessed September 13, 2026. [152] miaomiao636. [n.d.]. PureSkip: Repository. GitHub. https://github.com/ miaomiao636/PureSkip Accessed September 13, 2026. [153] mirad-tech. 2026. mirad-tech/Skip. GitHub. https://github.com/mirad-tech/ Skip/blob/272332727f6430309ea84a88121c205495f23da0/README.md Source snapshot dated 2026-08-22. Commit 272332727f64. Accessed September 12, 2026. [154] Mrmiaomrzh. 2026. BetterHeybox. GitHub. https://github.com/Mrmiaomrzh/ BetterHeybox/blob/9ff65e2a02da9f675625087abb95b2425618219a/README. md Source snapshot dated 2026-09-12. Commit 9ff65e2a02da. Accessed September 12, 2026. [155] Mrmiaomrzh. 2026. BetterHeybox: AdFilterHook.java. GitHub. https://github.com/Mrmiaomrzh/BetterHeybox/blob/ 9ff65e2a02da9f675625087abb95b2425618219a/app/src/main/java/com/ better/heybox/hooks/AdFilterHook.java Source snapshot dated 2026-09-12. Commit 9ff65e2a02da. [156] MrxSiN. 2026. GmailHideAds. GitHub. https://github.com/MrxSiN/ GmailHideAds/tree/2f978ffc9133f6b2e9b0feb873482f45fad9d275 Source snapshot dated 2026-09-09. Commit 2f978ffc9133. Accessed September 13, 2026. [157] MrxSiN. 2026. ThreadsHideAds. GitHub. https://github.com/MrxSiN/ ThreadsHideAds/tree/7ac6a78b7b086b6ac4aeaca7fcb8b27444a960ec Source snapshot dated 2026-09-09. Commit 7ac6a78b7b08. Accessed September 13, 2026. [158] MrxSiN. 2026. TwitterHideAds. GitHub. https://github.com/MrxSiN/ TwitterHideAds/tree/81d6417739b5b7f7166b3404074309f20105421d Source snapshot dated 2026-09-09. Commit 81d6417739b5. Accessed September 13, 2026. [159] Mullvad. 2026. Shutting down our public encrypted DNS servers and sponsoring Quad9 instead. https://mullvad.net/uk/blog/2026/9/3/shutting-downour-public-encrypted-dns-servers-and-sponsoring-quad9-instead Accessed September 13, 2026. [160] Mullvad. [n.d.]. Mullvad: DNS over HTTPS and DNS over TLS. https://mullvad. net/en/help/dns-over-https-and-dns-over-tls Accessed September 13, 2026. [161] NextDNS. [n.d.]. NextDNS: Ads and Trackers Blocking. https://nextdns.io Accessed September 13, 2026. [162] NextDNS. [n.d.]. NextDNS Pricing and Free Query Quota. https://nextdns.io/ pricing Accessed September 13, 2026. [163] nolesapex. 2026. LinkedInAdblockerXposed. GitHub. https://github.com/nolesapex/LinkedInAdblockerXposed/tree/ 60c91808b42c9c0dfb26c82c8cc7c10c863f699b Source snapshot dated 2026-07-27. Commit 60c91808b42c. Accessed September 13, 2026. [164] nolesapex. [n.d.]. LinkedInAdblockerXposed: Repository. GitHub. https: //github.com/nolesapex/LinkedInAdblockerXposed Accessed September 13, 2026. [165] Nord Security. [n.d.]. NordVPN: Android Application and Subscription. https: //play.google.com/store/apps/details?id=com.nordvpn.android Accessed September 13, 2026. [166] NordVPN. [n.d.]. NordVPN: Scam, Phishing, and Malware Protection. https://support.nordvpn.com/hc/en-us/articles/19508765521425-What-isNordVPN-s-Scam-Phishing-and-Malware-protection Accessed September 13, 2026. [167] obaby. 2021. obaby/skip_ads_android. GitHub. https://github.com/obaby/skip_ ads_android/blob/f35289d71428282b0774425ff09dce0638126c7f/readme.md Source snapshot dated 2021-11-10. Commit f35289d71428. Accessed September 12, 2026. [168] obaby. 2021. skip_ads_android: BabyAccessibilityService.java. GitHub. https://github.com/obaby/skip_ads_android/blob/ f35289d71428282b0774425ff09dce0638126c7f/app/src/main/java/cn/org/ obaby/adsskiper/BabyAccessibilityService.java Source snapshot dated 2021-11-10. Commit f35289d71428. [169] OnePlus software release community. [n.d.]. OxygenOS 14.0.0.712 for the OnePlus 10T [GLO ADDED]. https://community.oneplus.com/thread/ 1688716132111876102 Accessed September 12, 2026. [170] OPPO. 2021. ColorOS 12: Privacy and Security Features. https://www.oppo. com/en/coloros12/ Accessed September 13, 2026. Guide for Older Smartphone Users: Ad Intercep[171] OPPO. [n.d.]. tion. https://www.oppo.com/content/dam/oppo/cn/support/servicenews/wnjizhinan250509.pdf Accessed September 12, 2026. [172] OriginOS Yuanxitong (account marked as official vivo). [n.d.]. Vol.159: This Week’s System Update News. https://bbs.vivo.com.cn/newbbs/thread/38117730 Accessed September 12, 2026. [173] Overbaker. 2026. One-Patch. GitHub. https://github.com/Overbaker/OnePatch/tree/b5a19eb1606a0a2dc4738036ca4e07d6e2a9aee8 Source snapshot dated 2026-04-29. Commit b5a19eb1606a. Accessed September 13, 2026. [174] pass-with-high-score. [n.d.]. BlockAds. GitHub. https://github.com/pass-withhigh-score/blockads-android Accessed September 12, 2026. 16

[225] Xposed-Modules-Repo. 2024. Yao Ni Ming San Qian. GitHub. https://github.com/Xposed-Modules-Repo/cn.kwaiching.hook/blob/ 9b53c2d7e78b4cc6d2dbf02f4de834fc075bdfd3/README.md Source snapshot dated 2024-08-04. Commit 9b53c2d7e78b. Accessed September 12, 2026. bili-hook. GitHub. https: [226] Xposed-Modules-Repo. 2026. //github.com/Xposed-Modules-Repo/io.github.yylsping.bilihook/blob/ b585c7a0ed9728d5494d3b3ca9c9f15c6f2f663a/README.md Source snapshot dated 2026-08-21. Commit b585c7a0ed97. Accessed September 12, 2026. FuckApp. GitHub. https: [227] Xposed-Modules-Repo. 2026. //github.com/Xposed-Modules-Repo/com.znliang.fucksoul/blob/ 441de736edeb88d9f42328202b710ed2935ed5a1/README.md Source snapshot dated 2026-05-02. Commit 441de736edeb. Accessed September 12, 2026. [228] Xposed-Modules-Repo. 2026. Kuan Jinghua / Coolapk Purifier. GitHub. https: //github.com/Xposed-Modules-Repo/io.github.yylsping.coolapkpurifier/blob/ ca5b314dec8a18c70368a4b9195c408d7b19c340/README.md Source snapshot dated 2026-09-08. Commit ca5b314dec8a. Accessed September 12, 2026. [229] Xposed-Modules-Repo. 2026. QQTamer / QQ Keeper. GitHub. https://github.com/Xposed-Modules-Repo/com.tamer.qq/blob/ 4d4746a9943bd8536fec81d7aa22667b53431700/README.md Source snapshot dated 2026-08-24. Commit 4d4746a9943b. Accessed September 12, 2026. [230] Xposed-Modules-Repo. 2026. ReWeibo: README. GitHub. https: //github.com/Xposed-Modules-Repo/com.tianqianguai.reweibo/blob/ 9f64fb70ae90052184c2f8b9980d801e6df16a6d/README.md Source snapshot dated 2026-09-12. Commit 9f64fb70ae90. Accessed September 12, 2026. [231] Xposed-Modules-Repo. [n.d.]. Dasheng Jinghua. GitHub. https://github.com/ Xposed-Modules-Repo/com.ext.star.wars Accessed September 12, 2026. [232] Zhi Xu and Sencun Zhu. 2015. SemaDroid: A Privacy-Aware Sensor Management Framework for Smartphones. In Proceedings of the 5th ACM Conference on Data and Application Security and Privacy (CODASPY). ACM, New York, NY, USA, 61–72. doi:10.1145/2699026.2699114 [233] Chuying Yang and Cancan Tang. 2026. Woman Encounters Splash Advertisement While Uploading Fire-Emergency Video, Delaying Access to the Upload Page. Yangcheng Evening News, republished by New Express. https: //www.xkb.com.cn/articleDetail/521298 In Chinese. Published September 2, 2026. Accessed September 13, 2026. [234] zfdang. [n.d.]. AdSkip / Android-Touch-Helper. GitHub. https://github.com/ zfdang/Android-Touch-Helper Accessed September 12, 2026. [235] Bowen Zheng, Haifeng Li, and Qingxian An. 2025. Understanding the UIdesign Features Paradox of the Skip Option in Splash Advertising: The Roles of Perceived Control and Skipping Habit. Behaviour & Information Technology 44, 13 (2025), 3165–3179. doi:10.1080/0144929X.2024.2436506 [236] zirawell. 2026. R-Store MStand rewrite configuration at commit 1d4754a. GitHub. https://github.com/zirawell/R-Store/blob/ 1d4754a2a785603ed8fa2d1af1c87c3672f00443/Rule/QuanX/Adblock/Applet/ Wechat/M/MStand/rewrite/mstand.conf Source snapshot dated 2026-09-09. Commit 1d4754a2a785. Accessed September 12, 2026. [237] zirawell. [n.d.]. Ad-Cleaner migration notice. GitHub. https://github.com/ zirawell/Ad-Cleaner Accessed September 12, 2026. [238] zirawell. [n.d.]. R-Store. GitHub. https://github.com/zirawell/R-Store Accessed September 12, 2026. [239] zjyzip. [n.d.]. AdClose. GitHub. https://github.com/zjyzip/AdClose Accessed September 12, 2026. [240] zoffelf. 2026. zoffelf/skipad. GitHub. https://github.com/zoffelf/skipad/blob/ 3985395e711d018ca401e9ccb52bea8cd2b0e18f/README.md Source snapshot dated 2026-05-31. Commit 3985395e711d. Accessed September 12, 2026. [241] zoffelf. [n.d.]. zoffelf/skipad: Repository. GitHub. https://github.com/zoffelf/ skipad Accessed September 13, 2026. [242] zwz211123. 2026. AdPopupBlocker. GitHub. https://github.com/zwz211123/ AdPopupBlocker/tree/dd9782f8babe209820a1e5ced1fd80397bddda80 Source snapshot dated 2026-08-30. Commit dd9782f8babe. Accessed September 13, 2026.

[201] Surge Networks. [n.d.]. Surge iOS Licensing FAQs. https://kb.nssurge.com/ surge-knowledge-base/license/ios-faq Accessed September 14, 2026. [202] t895. 2026. DNSNet. GitHub. https://github.com/t895/DNSNet/tree/ cc26d82ce86fe0127e508ca9d943b78737a8e07f Source snapshot dated 2026-08-16. Commit cc26d82ce86f. Accessed September 13, 2026. [203] Taku. [n.d.]. Android Privacy Settings: Advertising Interaction Control. https: //help.takuad.com/docs/wNPGmZ Accessed September 12, 2026. [204] Taku. [n.d.]. Shake interaction configuration for iOS. https://help.takuad.com/ docs/4Vnwc4nU Accessed September 12, 2026. [205] Tencent Advertising. [n.d.]. Splash advertisement integration. https://ylh.qq. com/help_detail.html?cid=3431&pid=10048 Accessed September 12, 2026. [206] TG-Twilight. [n.d.]. AWAvenue Ads Rule / Qiufeng Advertising Rules. GitHub. https://github.com/TG-Twilight/AWAvenue-Ads-Rule Accessed September 12, 2026. [207] The Chromium Authors. [n.d.]. Chromium: app_launcher_tab_helper.mm. https://chromium.googlesource.com/chromium/src/+/ 948482539664436a761c35e7b96aa18b926298dd/ios/chrome/browser/app_ launcher/model/app_launcher_tab_helper.mm Commit 948482539664. Accessed September 12, 2026. [208] Tiantian and Yan Ma. 2023. More Than 90 Percent of Consumers Dislike Shaketo-Open Ads: Jiangsu Consumer Protection Committee Calls for Returning Choice to Users. Yangtze Evening Post, p. A10. https://doss.xhby.net/zpaper/ yzwb/pad/att/202311/16/c3fc2a8c-d1a0-4f5f-a446-135bafd5f28b.pdf In Chinese; title translated into English. Published November 16, 2023. Accessed September 13, 2026. [209] TrackerControl contributors. 2026. TrackerControl for Android: Advertising Categories and Connection Blocking. GitHub. https://github.com/TrackerControl/tracker-control-android/tree/ 09759cabde54e727bee7298df6f4d3606063faf7 Source snapshot dated 2026-09-11. Commit 09759cabde54. Accessed September 13, 2026. [210] TrackerControl contributors. [n.d.]. TrackerControl for Android. GitHub. https: //github.com/TrackerControl/tracker-control-android Accessed September 13, 2026. [211] TremendoX. 2019. UnclutterIG. GitHub. https://github.com/TremendoX/ UnclutterIG/tree/0607f57fa356c6440686e1e7195e392812f2d7f6 Source snapshot dated 2019-08-11. Commit 0607f57fa356. Accessed September 13, 2026. [212] tunecc. 2026. ChaoxingLaunchAdBlock: Makefile. GitHub. https://github.com/tunecc/ChaoxingLaunchAdBlock/blob/ 01dadebdb254a25ab40a5956deaaa6a94a0fcaa6/Makefile Source snapshot dated 2026-04-11. Commit 01dadebdb254. Accessed September 12, 2026. [213] tunecc. [n.d.]. ChaoxingLaunchAdBlock. GitHub. https://github.com/tunecc/ ChaoxingLaunchAdBlock Accessed September 12, 2026. [214] VindroidH. 2026. VindroidH/SkipAds. GitHub. https://github.com/VindroidH/ SkipAds/blob/4ee073603d8ee149e4f2e729704896e542142b79/README.md Source snapshot dated 2026-03-27. Commit 4ee073603d8e. Accessed September 12, 2026. [215] vivo. [n.d.]. Y500 Pro: shake-ad control. https://www.vivo.com.cn/vivo/y500pro Accessed September 12, 2026. [216] weixiansen574. 2024. FuckAdJump. GitHub. https://github.com/weixiansen574/ FuckAdJump/tree/66a8313969dde4af4e6c5a03770fbd19680a5d6e Source snapshot dated 2024-06-18. Commit 66a8313969dd. Accessed September 13, 2026. [217] WeiyePlayer. 2026. NoShakingAD: SensorControlUserService.kt. GitHub. https://github.com/WeiyePlayer/no-shakingAD/blob/ 761638826db6d053f138490b5025c19c0264ad2e/app/src/main/java/com/ shizukucontrol/service/SensorControlUserService.kt Source snapshot dated 2026-07-13. Commit 761638826db6. Accessed September 12, 2026. [218] WeiyePlayer. 2026. NoShakingAD: ShizukuHelper.kt. GitHub. https://github.com/WeiyePlayer/no-shakingAD/blob/ 761638826db6d053f138490b5025c19c0264ad2e/app/src/main/java/com/ shizukucontrol/util/ShizukuHelper.kt Source snapshot dated 2026-07-13. Commit 761638826db6. Accessed September 12, 2026. [219] WeiyePlayer. [n.d.]. NoShakingAD / Bu Xu Tiaozhuan. GitHub. https://github. com/WeiyePlayer/no-shakingAD Accessed September 12, 2026. [220] Windscribe. [n.d.]. Windscribe: R.O.B.E.R.T. https://windscribe.com/features/ robert Accessed September 13, 2026. [221] Winkey W., Software Team. [n.d.]. OxygenOS 14.0.0.603 for the OnePlus 9R [IN ONLY]. https://community.oneplus.com/thread/1712468764643033093 Accessed September 12, 2026. [222] Song Wu, Bo Wang, Yifan Zhang, Yinfeng Cao, and Xueqiang Wang. 2026. When Ad Networks Misbehave: Understanding Risks of Semi-Drive-By Splash Ads. arXiv:2609.09574 [cs.CR] doi:10.48550/arXiv.2609.09574 Version 1, submitted September 9, 2026. [223] X-Force. 2021. Qing Qidong: Automatically Skip App Splash Ads. iPlaySoft. https://www.iplaysoft.com/qing-qi-dong.html Accessed September 12, 2026. [224] xiaojie-yahu. 2026. Tmall Campus / Quzhi Campus ad removal. GitHub. https://github.com/xiaojie-yahu/TmallCampus-AdBlock/blob/ 70a50b592ec38ecc0862f69f93e2c5d7d61f2c60/README.md Source snapshot dated 2026-05-12. Commit 70a50b592ec3. Accessed September 12, 2026. 17

A

Ad Defenses, Deployment Requirements, and Related Mechanisms

The main inventory contains 108 advertising countermeasure instances: Appendix A.1 lists 88 splash-related tools, rules, and prototypes; Appendix A.2 lists five user-enabled vendor settings; and Appendix A.3 lists 15 instances targeting other ad formats. The resulting 93 splash-related instances include general defenses applicable to in-app advertising, not only tools designed exclusively for splash ads. The other-format instances contribute to the mechanism comparison, but their inclusion does not establish splash-ad coverage. Inclusion and Evidence. Main-inventory entries have an identifiable ad-related operation supported by source code, a research description, or technical documentation, together with an identified package, service, configuration, or source-build route. Source availability alone is not required, but a general feature claim alone does not establish the operation. Historical versions are retained with their scope and maintenance limits. Appendix A.4 separately records entries with insufficient implementation evidence, incomplete implementations, or unresolved installation routes and required external prerequisites. These entries are excluded from the main-inventory counts, even when their mechanisms are discussed in the main text. Availability and Evaluation. Mechanism evidence, deployment availability, and tested effectiveness are separate. The operation column describes the mechanism or explicitly attributes a claim; the deployment column describes how users obtain and enable it; the limitations column identifies unresolved conditions. An identified package or source-build route does not establish current device compatibility or successful compilation. Empirical outcomes apply only to the configurations in Table 5; inclusion here does not imply that a tool passed those tests. Fees and distribution information retain the survey snapshot of September 13, 2026. Counting Unit. We count tools, rule sets, historical versions, prototypes, and system controls as separate countermeasure instances. For example, GKD and its listed rule subscription are separate entries, as are Cemiuiler and its successor HyperCeiler. Deployment percentages describe the surveyed entries rather than independent products; ecosystems represented by multiple entries contribute more observations. Each instance is counted once in the overall totals and once in each intervention stage it covers. The 22 multistage instances produce 137 stage memberships across the 108 instances. Deployment Labels. Labels joined by “+” within a path are simultaneous requirements; separately listed paths are alternatives. Root / Jailbreak, Runtime Injection, and APK Modification are distinct: injection needs a compatible framework, a module, and a selected target-app scope; APK modification needs a compatible patching workflow, signing, and installation of the modified app. Accessibility and Debugging denote separate authorizations; Shizuku supplies the latter in the listed click and sensor-control paths. VPN denotes VPN authorization, not all network filtering. Overlay and Notification Access denote their respective cross-app permissions. System Setting denotes configuration in an existing operating-system or service interface, rather than an additional permission. Source Build denotes compilation of the defense tool, not merely patching a target APK. Rules inherit the requirements of the listed executor paths. Optional models, certificate trust, and other configuration details are stated separately.

A.1

Splash-Related Tools, Rules, and Prototypes

Includes operations explicitly targeting splash ads and general defenses applicable to in-app advertising resources or interfaces. Table 6: Splash-Related Tools, Rules, and Prototypes. Tool / Control

Stage

Operation / Mechanism Evidence Deployment and Availability

Scope and Limitations

Li Tiaotiao rules [5] Presentation Provide interface-matching and / Dismissal skip-action rules

Accessibility; Rules are executed by Includes non-advertising Li Tiaotiao and inherit its automation; this appendix accessibility and includes only advertising rules. background-execution requirements. Li Tiaotiao and compatible rule implementations

AdAway [8]

Resource Blocking / Modification: VPN; Advertising-domain rules Resource Blocking / Modification: Root / Jailbreak; Advertising-domain rules. Android; local network filtering, or system privileges to modify host mappings

Resource Reject resolution or connections Blocking / using advertising-domain rules Modification

Normal traffic sharing a domain may be blocked; cached ads can still appear.

Continued on next page

18

Table 6 (continued) Tool / Control

Stage

Operation / Mechanism Evidence Deployment and Availability

Scope and Limitations

AdBlocker Reborn [10, 11]

Resource Blocking / Modification; Initialization / Startup; Presentation / Dismissal

Resource Supply: Intercepts ad requests using URL / hosts rules. Initialization and Startup: Intercepts launches of matching ad Activities. Display and Dismissal: Hides matching ad Views.

Historical implementation dependent on older interfaces and advertising class names.

AdBlock (FutureMind): DNS proxy [9, 77]

Resource A local VPN extension resolves VPN; Advertising rules / filtering Distinct from Safari extensions Blocking / domains in advertising hosts lists to server and client configuration. with the same name and its own Modification unusable addresses. iOS; VPN extension configuration Safari module; handles only and imported domain rules. Paid. domains passing through the One-time app purchase includes the DNS proxy and cannot distinguish same-origin local DNS proxy. The same App Store ID is now listed under AdBlock advertising content. Labs.

AdClose 4.3.7 Input / (verified Trigger configuration) [239]

Root / Jailbreak + Runtime Injection. Android; Xposed An APK is included in the repository; users need not build it from source.

Root / Jailbreak + Runtime Injection. Android; the tested path uses root and Vector 2.2 runtime injection; enable the module and select its host-app scope.

Intercepts accelerometer listener registration; the tested request-inspection feature only observes requests.

Motion options impose interface-level restrictions without distinguishing advertising from normal motion functions. The SDK initialization interception described in the old README is not implemented in HookLogic in the installed version 4.3.7, and the tested configuration has no network-blocking rules. These two operations are therefore not counted as verified defenses in this version.

AdGuard DNS: ad-filtering service [13, 14]

Resource Filters advertising domains at the Blocking / resolver, providing a public filtering Modification configuration and customizable private configurations.

Recorded separately from local System Setting; Ad-filtering DNS address / profile; other client paths AdGuard apps as a deployment option; non-filtering follow the respective client’s configurations do not block ads. requirements. Android / iOS; DNS configuration or Depends on the resolution path a corresponding client. Partly paid. and service availability. Public ad-filtering DNS and private DNS Starter are free; higher quotas and plans are paid. These are separate from AdGuard app licenses.

AdGuard for Android [15, 20]

Resource Combine domain filtering with Blocking / network content filtering Modification

VPN; Advertising rules or filtering Encrypted-content processing server; HTTPS content modification depends on certificate additionally requires certificate trust. compatibility; features vary by Android; local VPN or proxy mode and product license. configuration Paid. A license is required for ad blocking in non-browser apps; this function is absent from the free version. Continued on next page

19

Table 6 (continued) Tool / Control

Stage

AdGuard for iOS [16–18]

Resource Filter advertising domains accessed Blocking / by applications and browsers Modification

VPN; Advertising rules / filtering Ads and normal content on the server and client configuration. same domain cannot be iOS; local filtering or system resolver separated; VPN coexistence configuration Paid. Cross-app DNS conditions differ across modes. filtering requires Premium or a purchased AdGuard Pro app; free Safari blocking does not provide this function.

AdLock: mobile ad filtering [21]

Resource Uses a local VPN for DNS / HTTP Blocking / filtering on Android; its cross-app Modification advertising feature on iOS uses DNS filtering.

VPN; Advertising rules or filtering The mechanisms differ between server; HTTPS content modification platforms; the free iOS Safari additionally requires certificate trust. module is not equivalent to Android / iOS; VPN or DNS cross-app filtering, and DNS configuration; HTTPS content mode cannot remove inspection additionally requires same-origin ads. certificate trust. Paid. The listed cross-app filtering requires a license or subscription; the free iOS Safari module excludes system-wide DNS filtering.

Adobo: advertising Resource patches (loadable by Blocking / Morphe) [115] Modification; Initialization / Startup

Operation / Mechanism Evidence Deployment and Availability

Scope and Limitations

APK Modification; Install a The manager applies patches, Resource Supply: Statically while the advertising logic modifies matching AdMob methods modified APK, or apply patches, such as load / loadAd to return early. re-sign, and install; this is not comes from Adobo; failed Initialization and Startup: Applies equivalent to compiling patch source matching or SDK changes early-return patches to ad startup code. require patch updates, and entry points such as show / Android; a patch manager / build signatures and app updates showInterstitial. workflow and the modified introduce compatibility costs. installation package. Compiled patch files are available; applying them to the target APK and installing it is still required, but compiling patch source is not.

AdPopupBlocker [242]

Initialization Terminates forced interstitial or Root / Jailbreak + Runtime / Startup splash entry points according to app Injection. rules and invokes adapted Android; an environment supporting game-resumption logic when Modern Xposed API 102. needed.

AdSkip / AndroidTouch-Helper [234]

Presentation Dismiss ads using keywords, / Dismissal controls, or coordinates

Accessibility; Control rules / recognition configuration and background execution. Android; accessibility service

AdSkipHelper [81, 82]

Presentation Scan window nodes and click after / Dismissal matching "Skip"

Accessibility + Source Build; Example project; keyword Control rules / recognition matching may misidentify configuration and background controls, and internal return execution. values do not establish dismissal. Android; accessibility service Source build required: only source code was found through the inspected public channels; configure the Android SDK / build tools and generate an APK.

The inspected version lists only two games; resuming gameplay differs from returning after ad navigation and does not establish general interception of all SDKs. Author notes limited maintenance time and recommends GKD as an alternative.

Continued on next page 20

Table 6 (continued) Tool / Control

Stage

ADSkip (Promisin) [178]

Presentation Dismisses splash ads through / Dismissal per-app configurations for control clicks, screen-coordinate clicks, or delayed custom clicks.

app2smile ad Resource network rules + Blocking / Surge / Quantumult Modification X [30–32, 67, 201]

Athena: DNS ad filtering [124, 125]

Operation / Mechanism Evidence Deployment and Availability

The corresponding client matches specified advertising endpoints and runs scripts to modify status or result fields in responses from Pangle, Tencent GDT, Kuaishou, and others.

Scope and Limitations

Accessibility; Control rules / recognition configuration and background execution. Android; accessibility authorization and background execution.

Fixed coordinates and delays depend on layout and loading speed; they do not automatically establish that the target is a genuine close button.

VPN; Rules / scripts; HTTPS content rewriting additionally requires certificate trust; Surge or a compatible client. iOS; configurations in the format required by Surge or Quantumult X, and the configuration needed for HTTPS decryption. Paid. Rules / scripts are free; the listed configuration requires a paid Surge Pro / Quantumult X client. Only the chosen compatible client is needed.

The two clients’ configurations do not match exactly the same URLs; they depend on endpoints, response structures, and certificate compatibility. Different deployments of the same advertising script are not counted as independent methods.

VPN; Advertising rules / filtering The project also supports Root / server and client configuration. Shizuku modes, but this does Android; this review confirmed DNS not establish equivalent filtering in the VPN ad-filtering capabilities across packet-processing path. Partly paid. all modes; depends on rules and Basic ad filtering is free; custom visible DNS queries. blocklists require a feature purchase or Premium upgrade.

Resource DNSRule queries a local rule Blocking / database and returns a blocking Modification result for requests matching advertising domains.

Depends on the target app’s AutoClickerPurifier: Initialization Initialization and Startup: Root / Jailbreak + Runtime Injection + Source Build. internal classes and version; its advertising / Startup; Modifies the target app’s ad Android; targets com.zidongdianji; other features are outside this features [121, 122] Presentation initialization state. Display and Dismissal: Opens the main interface Xposed / LSPosed. Source build inventory. Splash-page dismissal / Dismissal after the splash page’s onCreate and required: only source code was occurs after onCreate and does calls finish on the original page; calls found through the inspected public not guarantee that the page was removeAds to remove banners. channels; configure the Android SDK not initialized or displayed. / build tools and generate an APK. AWAvenue Ads Rule Resource Provide domain rules for advertising Resource Blocking / Modification: / Qiufeng Blocking / servers and libraries VPN; Import the compatible Advertising Modification domain-rule format into a VPN Rules [206] filtering client Resource Blocking / Modification: Root / Jailbreak; Apply the compatible hosts rules through a root-based executor. Executed by compatible domain or network filtering tools BetterHeybox (advertising features) [154]

Resource Blocking / Modification; Initialization / Startup

Resource Supply: Removes ad entries from content lists during deserialization. Initialization and Startup: Makes the Xiaoheihe splash-ad function return early.

A rule set; format conversions derived from the same source share coverage.

Root / Jailbreak + Runtime Splash rules depend on fixed Injection. obfuscated names; data filtering Android; Xposed / LSPosed or a depends on content tags. corresponding loading environment

Continued on next page

21

Table 6 (continued) Tool / Control

Stage

Operation / Mechanism Evidence Deployment and Availability

bili-hook: advertising subset [226]

Initialization Mark Bilibili’s regular splash-ad / Startup model as invalid

blackmatrix7 startup [41, 67, 143, 201]

Resource Remove splash-ad fields and change VPN; Rules / scripts; HTTPS content Blocking / display duration, dimensions, and rewriting additionally requires Modification expiration certificate trust; Surge or a compatible client. iOS; compatible proxy-rule clients Paid. Rules / scripts are free; the listed configuration requires a paid Surge Pro / Quantumult X / Loon client. Only the chosen compatible client is needed.

Depends on the target application’s response format; repository-wide updates do not ensure continued adaptation of this script.

Block This (historical implementation) [80]

Resource Send domain queries to the author’s VPN; Advertising rules / filtering Blocking / configured remote ad-filtering server and client configuration. Modification service Android; local VPN configuration

Historical implementation; filtering depends on the remote service, and the client does not maintain a local blocklist.

BlockAds [174]

Resource VPN; Advertising rules or filtering Certificate and protocol Filter domains and process Blocking / encrypted content for selected traffic server; HTTPS content modification compatibility affect connections; Modification additionally requires certificate trust. some traffic may bypass Android; local VPN or privileged filtering. proxy

Blokada 5 [42, 44]

Resource Filter advertising traffic locally on Blocking / the device Modification

Blokada 6 / Cloud [43, 44]

Resource Filter advertising domains through a System Setting; Ad-filtering DNS Depends on the remote service; Blocking / cloud resolution service address / profile; other client paths distinguishes content only by Modification follow the respective client’s domain. requirements. Android, iOS, and other platforms; filtering-service configuration Paid. Blokada 6 / Cloud requires a filtering-service subscription, unlike the free local mode of Blokada 5.

CAD viewer patch [149]

Initialization Remove matching advertising APK Modification; Install a Patch for a specific CAD viewer; / Startup components and change the startup modified APK, or apply patches, warm starts, other entry points, entry to the home screen re-sign, and install; this is not and version updates require equivalent to compiling patch source separate adaptation. code. Android; offline package modification and re-signing Releases provides a modified APK; local repackaging is an alternative rather than a prerequisite for using the published package.

Root / Jailbreak + Runtime Injection. Android; libxposed

VPN; Advertising rules / filtering server and client configuration. Android; local VPN Partly paid. Local ad filtering is free; the optional paid Blokada Plus VPN is not required for local filtering.

Scope and Limitations Inspected documentation specifies client versions and retains birthday splash screens.

Listed as an older version on the official website; local rules and device configuration affect filtering.

Continued on next page

22

Table 6 (continued) Tool / Control

Stage

Operation / Mechanism Evidence Deployment and Availability

Scope and Limitations

Cemiuiler: historical Initialization advertising / Startup; features [182] Presentation / Dismissal

Initialization and Startup: Historical Theme Store rules disable ad support / display eligibility checks. Display and Dismissal: Sets the corresponding ad Views to zero size and hides them.

The repository is archived and recorded as part of the same project’s evolution, not as an additional independent technical approach or a currently maintained tool.

ChaoxingLaunchAd- Resource Block [212, 213] Blocking / Modification; Initialization / Startup

Root / Jailbreak + Runtime Resource Supply: Blocks Injection; Jailbreak and a Xuexitong splash-ad requests by compatible tweak-loading URL. Initialization and Startup: Makes methods for splash-ad display, environment. window creation, and ad-page entry iOS; jailbreaking and Theos / return early. MobileSubstrate loading environment

Targets only Chaoxing Xuexitong; depends on application and system versions.

CleanSplash [65, 66] Initialization / Startup; Presentation / Dismissal

Initialization and Startup: Modifies splash-ad enablement / display checks in supported apps. Display and Dismissal: Sets the corresponding Cainiao ad interface elements to GONE.

Root / Jailbreak + Runtime Injection + Source Build. Android; Xposed / LSPosed. Source build required: only source code was found through the inspected public channels; configure the Android SDK / build tools and generate an APK.

Documentation targets specified older versions of Cainiao, Bilibili, and QQ; it is not a uniform shake-sensor interceptor.

Control D: Ads & Trackers filtering [62, 63]

System Setting; Ad-filtering DNS Resource The resolver blocks requests using advertising and tracking domain lists, address / profile; other client paths Blocking / follow the respective client’s Modification with different levels of strictness. requirements. Android / iOS; a DNS endpoint managed by the corresponding Profile. Partly paid. Public Ads & Trackers resolvers are free; the profile management and custom filtering described in this entry belong to the paid service.

Only this ad-filtering feature is included; stricter rules may block shared legitimate services and require maintaining exceptions.

CoolApkNoSplash [138, 139]

Initialization Intercepts a specified / Startup Instrumentation launch interface and refuses to open CoolApk’s SplashAdActivity.

Root / Jailbreak + Runtime Injection. Android; an Xposed / LSPosed module loaded in the CoolApk process. CI download: GitHub Actions provides a prebuilt debug package; downloading generally requires a GitHub account, and artifacts may expire.

Blocks the ad page itself, not the ad’s destination app; depends on the component name and launch path.

VPN; Advertising rules / filtering server and client configuration. Android; local VPN, with the corresponding advertising rules downloaded and enabled.

The latest confirmed commit on the default branch dates to 2022; compatibility with current Android and availability of old rule URLs were not verified. Domain filtering has difficulty distinguishing normal content from ads on the same domain and does not handle cached resources.

Daedalus + AdAway Resource / anti-AD rules Blocking / (historical impleModification mentation) [110]

Loads advertising hosts / DNSMasq rules from sources built into the project, matches domains during DNS processing, and returns the addresses specified by the rules.

Root / Jailbreak + Runtime Injection. Historical Android / MIUI versions and an Xposed environment.

Continued on next page 23

Table 6 (continued) Tool / Control

Stage

Operation / Mechanism Evidence Deployment and Availability

Scope and Limitations

DNS66 [117]

Resource Intercept domain queries and match VPN; Advertising rules / filtering Blocking / advertising blocklists server and client configuration. Modification Android; local VPN

Repository archived; retained as a historical implementation.

DNSNet [202]

VPN; Advertising rules / filtering Resource Follows the DNS66 approach, server and client configuration. Blocking / matching advertising hosts lists in Modification the DNS request-processing path of a Android; VPN authorization and local VPN. domain rules.

A DNS66 derivative whose maintenance source is recorded separately, rather than a new recognition algorithm; same-origin and cached ads may remain.

dongqiudiadblock [46]

Resource Modifies permissions on Dongqiudi’s Root / Jailbreak; Cache Blocking / advertising cache directory and permissions, hosts, and network Modification combines hosts, iptables string rules. matching, and IP rules to restrict ad Android; Magisk / Root and the sources. relevant network commands.

Cache paths and network rules require continual updates; advertising domains in HTTPS are not directly exposed to plaintext string matching, and rules for shared IP addresses may disrupt normal traffic.

DTL-X: rmads feature [78]

Resource Blocking / Modification; Initialization / Startup

FanqieHook (advertising features) [22]

Initialization Modify ad-display decisions and / Startup intercept specified splash entry points

fmz200/wool_ scripts: advertising subset [74, 75, 143, 184, 201]

Resource Reject ad requests inline and remove VPN; Rules / scripts; HTTPS content Blocking / or replace advertising fields rewriting additionally requires Modification certificate trust; Surge or a compatible client. iOS; proxy-rule clients supporting the corresponding format Paid. Rules / scripts are free; the listed configuration requires the selected paid Loon / Surge Pro or equivalent client. Only the chosen compatible client is needed.

Resource Supply: rmads4 replaces APK Modification; Install a Coarse-grained and dependent modified APK, or apply patches, on string patterns; some modes matching ad-loading calls with re-sign, and install; this is not attempt to remove network no-ops; ad unit identifiers are also equivalent to compiling patch source permission for the entire app modified. Initialization and and may break functionality or Startup: rmads1 removes matching code. ad Activity declarations; rmads4 also An Android installation package and builds. This cannot be described replaces matching show-type calls. an external APK modification / as selective advertising SDK rebuilding toolchain. removal. Command-line toolchain: requires Python and APK unpacking, rebuilding, and signing tools; it is not a defense APK that users simply install. Root / Jailbreak + Runtime Injection. Android; Xposed / LSPosed or a corresponding loading environment

Targets supported versions of Fanqie Novel and Hongguo Short Drama; retains some user-initiated rewarded ads. Some external scripts used by the inspected plugin are missing; inline rules and standalone scripts require separate use.

Continued on next page

24

Table 6 (continued) Tool / Control

Stage

Operation / Mechanism Evidence Deployment and Availability

Fuck AD [105]

Resource Blocking / Modification; Initialization / Startup; Presentation / Dismissal

Resource Supply: Intercepts ad loading and requests. Initialization and Startup: Prevents initialization of supported advertising SDKs. Display and Dismissal: Hides ad Views through code injection or automatically clicks skip controls through an accessibility service.

Fuck Shake [180]

Input / Trigger

Input acquisition: intercepts one Root / Jailbreak + Runtime sensor listener registration interface Injection. Android; Xposed code-loading environment

Does not distinguish advertising sources or sensor types; other interfaces and existing listeners require separate handling.

FuckAdJump [216]

Navigation Control

Intercepts Uri.parse(String) and replaces strings matching JD or Taobao scheme prefixes with empty strings.

Root / Jailbreak + Runtime Injection. Android; an Xposed / LSPosed module loaded within its scope.

Uses link prefixes rather than advertising semantics; normal shopping links may also be blocked, while HTTP links and paths bypassing this parsing interface can evade it.

FuckApp (formerly listed as "Zheng Nengliang"): advertising subset [227]

Resource Blocking / Modification; Initialization / Startup; Presentation / Dismissal

Resource Supply: Intercepts ad requests on a per-app basis. Initialization and Startup: Intercepts the corresponding advertising SDK or in-app ad entry point. Display and Dismissal: Hides ad interfaces or performs skip clicks.

Root / Jailbreak + Runtime Injection. Android; Xposed / LSPosed or a corresponding loading environment

Depends on advertising method names and interface structure; only advertising features are included.

GKD with specified advertising subscriptions [85]

Presentation Match advertising controls with / Dismissal interface selectors and execute actions

Accessibility; Control rules / recognition configuration and background execution. Android; accessibility service; some paths can use Shizuku

Forms a defense together with specified advertising subscriptions; other automation rules are excluded.

HyperCeiler: advertising features [183]

Resource Blocking / Modification; Initialization / Startup; Presentation / Dismissal

Root / Jailbreak + Runtime Injection. Android / HyperOS; Xposed / LSPosed, subject to the specific module’s compatibility.

Only advertising features are listed; system and target-app version changes require adaptation. The current branch’s support cannot be attributed to older Cemiuiler versions.

Resource Supply: Wallet rules terminate ad data acquisition and return empty data to the listener. Initialization and Startup: Mi Fitness rules set the splash-ad enablement check to false. Display and Dismissal: Wallet rules hide splash_container and end splash-ad display.

Scope and Limitations

Features intervene at different Resource Blocking / Modification; Initialization / Startup; Presentation / stages and depend on supported Dismissal: Root / Jailbreak + advertising libraries and Runtime Injection versions. Presentation / Dismissal: Accessibility; Automatic skipping through accessibility; separate from injection-based hiding Presentation / Dismissal: Accessibility + Debugging; Enable Shizuku for click methods using debugging authorization. Android; resource supply and initialization interception and View hiding require Xposed / a corresponding code-loading environment; automatic skipping uses an accessibility service, with Shizuku additionally used for some click paths.

Continued on next page 25

Table 6 (continued) Tool / Control

Stage

Operation / Mechanism Evidence Deployment and Availability

Scope and Limitations

VPN; Advertising rules / filtering server and client configuration. Android; selection of an ad-filtering resolver and the corresponding operating mode.

The feature depends on the selected server, and documentation states that the Google Play version does not provide it; DNS encryption itself does not identify ads.

IVPN: AntiTracker [111, 112]

Resource Rejects matching domains through VPN; Advertising rules / filtering Blocking / DNS servers maintaining advertising server and client configuration. Android / iOS; the IVPN client and Modification and tracking lists. corresponding connection configuration. Paid. AntiTracker is included in paid IVPN plans; no separate ad-blocking add-on purchase is needed.

Although named AntiTracker, the feature explicitly includes ads in official documentation; it remains domain filtering and cannot directly hide ad views.

Lain-Patches: Disable Ads subset [128]

Initialization Locate advertising functions by / Startup method characteristics and return early

APK Modification; Install a modified APK, or apply patches, re-sign, and install; this is not equivalent to compiling patch source code. Android; Morphe package-patching workflow Compiled patch files are available; applying them to the target APK and installing it is still required, but compiling patch source is not.

The inspected example targets a specific application and version; only ad-removal patches are included.

Lin-arm/GKD_ subscription advertising subset [136]

Presentation Provide control-selection rules for / Dismissal splash and pop-up ads

Accessibility; Rules are executed by Used together with GKD; rule GKD and inherit its accessibility and changes affect target-application background-execution requirements. support. Executed by GKD

Lockdown Privacy: advertising domain blocking [49, 61]

Resource Its Firewall feature uses on-device Blocking / blocking rules for advertising and Modification tracking domains.

VPN; Advertising rules / filtering Only the explicit ad-blocking server and client configuration. feature is recorded; Secure iOS; Network Extension / local VPN Tunnel is a separate feature. configuration. Partly paid. Basic Correspondence between the Firewall has a free path; Advanced public repository and the current store version has not Firewall / selected lists and VPN have paid subscriptions. The current been verified. store version should not be described as having an entirely free firewall.

madeye/ ad-skipper [147]

Presentation Combine node, text, and image / Dismissal recognition, then click the located target

Accessibility; Control rules / recognition configuration and background execution; screen access and local recognition computation; an additional VLM is optional and is not counted as required for every deployment. Android; accessibility screenshots and gestures

InviZible: Resource Sends DNS requests to a DNSCrypt ad-filtering resolver Blocking / resolver that provides ad filtering. configuration [79] Modification

Adds recognition overhead; maturity of the optional language-model branch requires separate assessment.

Continued on next page

26

Table 6 (continued) Tool / Control

Stage

Operation / Mechanism Evidence Deployment and Availability

Scope and Limitations

MiFitnessAdAway [93]

Resource Blocking / Modification; Presentation / Dismissal

Resource Supply: Makes splash-ad cache reads return an empty value and filters page ad data. Display and Dismissal: Hides the corresponding ad Views and clears their interface space.

Targets Xiaomi fitness and health applications; normal health functions require separate checks.

MinMinGuard [54]

Resource Blocking / Modification; Initialization / Startup; Presentation / Dismissal

Root / Jailbreak + Runtime Resource Supply: GoogleGms Injection. intercepts loadAd / loadAds. Android; Xposed Initialization and Startup: Intercepts ad startup entry points such as InterstitialAd.show. Display and Dismissal: Sets ad View height to zero to clear occupied space.

mirad-tech/ Skip [153]

Presentation Locate nodes by rules, recheck / Dismissal targets, then click or issue gestures

Root / Jailbreak + Runtime Injection. Android; system administration privileges and LSPosed / libxposed

Accessibility; Control rules / recognition configuration and background execution. Android 9+; accessibility service

Archived; inspected examples cover banner and interstitial ads.

Rechecks and cooldown policies are enforced by the tool; still depends on nodes and timing.

Mullvad: advertising Resource Filters DNS using advertising domain System Setting; Ad-filtering DNS Public encrypted DNS is DNS Blocking / lists, distinguishing DNS within the address / profile; other client paths announced to shut down on 2026-11-02; this announcement filtering [159, 160] Modification VPN from public encrypted DNS. follow the respective client’s requirements. does not imply that DNS within the VPN will also shut down. Android / iOS; the corresponding VPN or DNS configuration. Partly Alternative resolvers do not paid. Public ad-filtering DNS is free, automatically provide the same whereas filtering inside the VPN advertising lists. requires the paid VPN. Public DNS is scheduled to close on November 2, 2026; the two paths are distinguished. NetGuard: Resource hosts-based ad Blocking / filtering in non-Play Modification builds [146, 148]

NextDNS: ad filtering [161, 162]

Non-Google Play distributions provide hosts-based advertising domain filtering and process the corresponding requests through a local VPN.

Resource Refuses to resolve matching domains Blocking / at the remote DNS resolution stage Modification according to selected advertising lists.

VPN; Advertising rules / filtering server and client configuration. Android; a build supporting this feature, VPN authorization, and an advertising hosts list. Partly paid. Hosts-based ad filtering in the non-Play build is free; selected advanced features such as logging and traffic analysis require Pro and are not prerequisites for basic ad filtering.

Only the officially documented ad-filtering feature is included, not the general firewall; the Google Play version does not provide this feature.

System Setting; Ad-filtering DNS address / profile; other client paths follow the respective client’s requirements. Android / iOS; system DNS settings, a configuration profile, or a client. Partly paid. The first 300,000 queries per month are free; above this quota DNS resolution continues without filtering. Higher usage requires a paid plan.

Depends on the service, lists, and whether queries pass through the resolver; cannot filter specific ad elements within the same domain.

Continued on next page 27

Table 6 (continued) Tool / Control

Stage

Operation / Mechanism Evidence Deployment and Availability

VPN; Advertising rules / filtering The current official name is server and client configuration. Scam and phishing protection, Android / iOS; a subscription plan formerly Threat Protection; supporting the feature and a VPN download scanning or content connection. Paid. Mobile DNS ad inspection in the desktop Pro filtering is provided through the paid version should not be attributed NordVPN service; desktop feature to mobile versions. coverage does not apply.

Blocks advertising domains on NordVPN: mobile ad Resource filtering [165, 166] Blocking / mobile through the DNS service Modification used by the VPN.

NoShakingAD / Bu Input / Xu Tiaozhuan [217– Trigger 219]

Scope and Limitations

Input acquisition: restricts the global Accessibility + Debugging; Enable sensor mode after a foreground-app Shizuku, accessibility, and change and schedules re-enabling background execution. after five seconds Android; Shizuku and accessibility service

Affects other applications; preserving prior state and restoring it after abnormal exits have limitations.

obaby/skip_ads_ android [167]

Presentation Capture screenshots, locate skip / Dismissal buttons with object detection, and click their coordinates

Accessibility; Control rules / recognition configuration and background execution; screen access and local recognition computation. Android; accessibility and screen-capture authorization

Image recognition and page changes may cause misalignment; targets need rechecking before action.

One Patch: touch blocking for ad regions [173]

Input / Trigger

Input / Trigger: Overlay; User-selected region Input / Trigger: Accessibility; User-selected region; an alternative to the regular overlay path. Android; floating-window or accessibility-overlay permission.

The official description explicitly lists use for ad regions, but provides no automatic ad recognition; normal buttons are also blocked, while touches outside the region and motion triggers remain.

personalDNSfilter [109]

Resource Locally match preconfigured Blocking / advertising-domain lists Modification

VPN; Advertising rules / filtering server and client configuration. Android / Java; platform-specific configuration

Limited for shared-domain content and requests that bypass the resolver.

Private Internet Access: MACE [176, 177]

Resource MACE on Android filters advertising VPN; Advertising rules / filtering Blocking / domains through DNS; current server and client configuration. Modification official documentation associates the Android; a client / distribution iOS control with Safari content supporting MACE and the service blocking. configuration. Paid. MACE is provided with a PIA subscription and requires a distribution that supports the feature.

Android DNS capabilities cannot be directly described as a defense against native-app ads on iOS; installation channels and platforms must be confirmed separately.

Proton VPN: NetShield ad filtering [179]

Resource Rejects matching domains when the Blocking / advertising and tracking blocking Modification level is selected on the DNS service used by the VPN.

After a user selects a rectangular region, an overlay consumes touch events within it.

VPN; Advertising rules / filtering server and client configuration. Android / iOS; a supporting subscription plan, client, and VPN connection. Paid. NetShield requires VPN Plus or another paid Proton VPN plan; the free VPN plan excludes it.

The malware-only level is not equivalent to ad filtering; paths that bypass the corresponding DNS or use Tor do not receive the same protection.

Continued on next page

28

Table 6 (continued) Tool / Control

Stage

Operation / Mechanism Evidence Deployment and Availability

PureNGA: advertising subset [56]

Resource Blocking / Modification; Initialization / Startup; Presentation / Dismissal

Depends on NGA’s internal Resource Supply: Intercepts SDK Resource Blocking / Modification; ad-loading methods such as load*Ad. Initialization / Startup; Presentation / fields and startup flow; normal Dismissal: Root / Jailbreak + initialization must be preserved. Initialization and Startup: Runtime Injection; Module and Prevents the corresponding SDK scope initialization and ad startup callbacks. Display and Dismissal: Resource Blocking / Modification; Initialization / Startup; Presentation / Enters the home page in Dismissal: APK Modification; LoadingActivity foreground Modified installation package; an callbacks and hides the corresponding ad / recommendation alternative to the injection path. Android; Xposed / LSPosed or Views. package modification

PureSkip [151, 152]

Presentation Finds and clicks close buttons during Accessibility + Source Build; The inspected implementation the startup window according to Control rules / recognition / Dismissal primarily uses rule-based target-app and control rules. configuration and background recognition; coverage changes execution. with built-in adaptations and Android; an accessibility service. should not be described as OCR Source build required: only source or model-based recognition. code was found through the inspected public channels; configure the Android SDK / build tools and generate an APK.

QzxyAdBlock [52, 53]

Presentation / Dismissal; Input / Trigger

Display and Dismissal: Exits the Root / Jailbreak + Runtime Quzhi Campus ad page and removes Injection. specified ad Views. Input and Android; all listed interface and Evaluation: Intercepts sensor operations require Xposed / accelerometer listener registration. LSPosed; documentation targets Quzhi Campus 6.5.28. An APK is included in the repository; users need not build it from source.

Scope and Limitations

Spans display and input; interface and sensor rules depend on the specific version, and sensor restrictions may also affect normal functions. Recorded separately from the other TmallCampus project.

VPN; Rules / scripts; HTTPS content Successor to Ad-Cleaner; each rewriting additionally requires target’s rules depend on specific addresses and scripts. certificate trust; Surge or a compatible client. iOS; compatible proxy-rule clients Paid. Rules / scripts are free; the listed configuration requires a paid Surge Pro / Quantumult X client. Only the chosen compatible client is needed.

R-Store [67, 201, 236– Resource Reject ad requests and modify 238] Blocking / application and mini-program Modification responses

Rethink DNS + Resource Blocks DNS requests entering the VPN; Advertising rules / filtering Firewall: advertising Blocking / filtering path according to a selected server and client configuration. domain Modification advertising domain blocklist. Android; local VPN and the rules [50, 51] corresponding DNS / rule configuration. Partly paid. The base app and advertising-domain filtering are free; the optional RPN VPN subscription is paid and is not required for basic filtering.

Only the explicit advertising blocklist feature is included; ordinary per-app network blocking is excluded. Depends on the selected lists and DNS path.

Continued on next page

29

Table 6 (continued) Tool / Control

Stage

ReWeibo: Weibo Lite Resource advertising Blocking / subset [230] Modification; Initialization / Startup

Operation / Mechanism Evidence Deployment and Availability

Scope and Limitations

Resource Supply: Filters feed ad data in Weibo Lite. Initialization and Startup: Modifies the startup branch to enter the main interface directly.

Targets only Weibo Lite; depends on internal methods and versions.

Root / Jailbreak + Runtime Injection. Android; LSPosed / libxposed

ShakeGuard [113, 114]

Return After Matches foreground transitions that Accessibility + Source Build; JDK Navigation have already occurred against source 17, Android SDK 35 / Gradle; source apps, destination apps, and and destination rules and protection periods, then sends one background execution. Back action; attempts to reopen the Android; accessibility window events source app when needed. and the global Back action. Source build required: only source code was found through the inspected public channels; configure the Android SDK / build tools and generate an APK.

SKIP [92]

Presentation Click using advertising-control / Dismissal identifiers, pages, and coordinate conditions

Accessibility; Control rules / recognition configuration and background execution. Android; accessibility service

SkipAds (Konghuan- Presentation Matches ad skip controls through an Accessibility + Source Build; Smart) [129, 130] / Dismissal accessibility service and clicks them, Control rules / recognition with an option to exclude specified configuration and background apps. execution. Android; an accessibility service. Source build required: only source code was found through the inspected public channels; configure the Android SDK / build tools and generate an APK.

Acts after navigation and does not read motion data. Tests of the original state-management code reproduced a recovery state that persists after a failed return, and a stale protection-window start after reopening the same app from the launcher. These can suppress later checks or allow new redirects. On-device recovery was not validated. Reopening the source app cannot undo prior network requests or guarantee restoration of the original page. Some rules specify screen resolution; layout changes require adaptation. Depends on visible nodes and matching rules; no sensor or final-navigation interception has been established.

SplashCleanerAndroid [103, 104]

Presentation Locate dismissal controls using text, Accessibility; Control rules / Depends on exposed interface / Dismissal identifiers, and structure during a recognition configuration and information and the scan startup scan background execution. window; uses node recognition Android; accessibility service An rather than image recognition. APK is included in the repository; users need not build it from source.

SplashGuard (33lilil) [3, 4]

Presentation Coalesces accessibility window / Dismissal events, finds close buttons using features such as keywords and position, and invokes node clicks.

Accessibility + Source Build; Control rules / recognition configuration and background execution. Android; an accessibility service. Source build required: only source code was found through the inspected public channels; configure the Android SDK / build tools and generate an APK.

A small source-code prototype; delayed scans can still encounter stale nodes or deceptive close controls and do not constitute sensor or navigation interception.

Continued on next page 30

Table 6 (continued) Tool / Control

Stage

Operation / Mechanism Evidence Deployment and Availability

Scope and Limitations

Resource Blocks advertising network sources Surfshark: CleanWeb mobile ad Blocking / through the VPN app’s ad-filtering filtering [198, 199] Modification feature.

VPN; Advertising rules / filtering server and client configuration. Android / iOS; the corresponding Surfshark client, subscription plan, and connection settings. Paid. CleanWeb is included in paid Surfshark subscriptions without a separate feature purchase.

Only officially documented in-app ad filtering is included; browser extensions’ page-processing capabilities cannot be applied to native apps. Public product descriptions do not establish coverage of each splash-ad category.

TapClick (formerly ADGO) [135]

Accessibility; Control rules / recognition configuration and background execution. Android; accessibility service

Former ADGO links redirect to this project; depends on control and coordinate rules.

Root / Jailbreak + Runtime Injection. Android; Xposed / LSPosed or a corresponding loading environment

Single-application approach; application hardening and initialization changes affect compatibility.

Presentation Match advertising controls, then / Dismissal click or issue gestures

TheMessWorld: Initialization Replace Pangguai Life splash Pangguai Life splash / Startup initialization and launch the home subset [64] screen directly TrackerControl: advertising-related network filtering [209]

Processes app connections through a VPN; Advertising rules / filtering Resource local VPN and blocks matching server and client configuration. Blocking / Android; activation of a version Modification connections according to user settings, using rules such as domain supporting blocking and a local VPN. associations and advertising categories.

Only advertising-related filtering is recorded; blocking advertising tracking connections does not mean removing all ad displays. Coverage depends on domain rules, network paths, and settings; cached and bundled ads may remain.

VindroidH/ SkipAds [214]

Presentation Click using application, window, and Accessibility; Control rules / / Dismissal keyword rules; fall back to recognition configuration and coordinates or back actions background execution. Android; accessibility service

Layout and rule changes affect results; non-advertising automation rules are excluded.

Windscribe: R.O.B.E.R.T. ad filtering [220]

Resource Blocks resolution of advertising Blocking / domains through the DNS-side Modification Ad+Trackers list while connected to Windscribe.

VPN; Advertising rules / filtering server and client configuration. Android / iOS; the Windscribe service and corresponding rule configuration. Partly paid. The free plan includes Malware & Ads; additional rule capacity, lists, and VPN resources are available in paid plans.

Only the named ad-filtering feature is included; requests bypassing this DNS are not covered, and same-origin ads may still appear.

Wipr 2: Filtr extension [38, 119, 120]

Resource Extends ad request filtering beyond Blocking / Safari to other apps through a Modification system URL filtering extension.

System Setting; Purchase and enable the extension; requires supported iOS / iPadOS versions. iOS / iPadOS versions supporting URL Filter; purchase and activation of Filtr. Paid. Requires purchasing Wipr 2 and unlocking the Filtr add-on; cross-app filtering is not part of the base Safari functionality.

The Safari module must be distinguished from the later Filtr release; the store now lists cross-app functionality, so the Safari-only description no longer applies. Coverage depends on URL paths the system can inspect; no splash-ad-specific tests were conducted. Continued on next page

31

Table 6 (continued) Tool / Control

Stage

Operation / Mechanism Evidence Deployment and Availability

Xposed-GodMode: ad element blocking [118]

Presentation Lets users select ad controls, saves / Dismissal rules, and hides the corresponding views in the target app.

Root / Jailbreak + Runtime Injection. Android; Xposed / LSPosed.

Uses manual selection rather than automatic ad recognition; reused list controls may cause normal content to be affected. APK export is planned in the documentation and cannot be described as implemented.

ZeroStart [59]

Presentation First matches accessibility nodes; if / Dismissal matching fails, uses offline text recognition and position rules, then clicks the skip control.

Accessibility; Control rules / recognition configuration and background execution; screen access and local recognition computation. Android; an accessibility service; screenshot recognition requires the corresponding screen access capability.

Startup windows, text, and position rules can cause missed detections or incorrect clicks; the shake-prevention effect in the name and description comes from early dismissal, not sensor control.

Moyu Rewrite: advertising subset [67, 69, 201]

Resource Reject ads by request address or VPN; Rules / scripts; HTTPS content Blocking / invoke response-modification scripts rewriting additionally requires Modification certificate trust; Surge or a compatible client. iOS; compatible proxy-rule clients Paid. Rules / scripts are free; the listed configuration requires the selected paid Quantumult X / Surge Pro or equivalent client. Only the chosen compatible client is needed.

The inspected mini-program configuration explicitly excludes five-second splash ads; some scripts come from external repositories.

Li Tiansuo / LiTianSuo [29]

Initialization / Startup; Presentation / Dismissal; Navigation Control

Root / Jailbreak + Runtime Initialization and Startup: Injection. Intercepts splash display entry Android; libxposed code-loading points or ad-page launches on a environment per-app basis. Display and Dismissal: UC rules hide SplashWindow and the corresponding ad Views. Navigation: Intercepts launches of ad landing pages / browser Activities specified in the rule list.

Li Tiaotiao (original Presentation Locate and operate skip or dismissal version and rule / Dismissal controls using rules ecosystem) [181, 187]

Accessibility; Control rules / recognition configuration and background execution. Android; accessibility service

Resource Supply: Filters CoolApk’s Root / Jailbreak + Runtime ad entity lists. Display and Injection. Dismissal: Finishes the splash page Android; libxposed and opens the home page after a splash lifecycle call.

Kuan Jinghua / Coolapk Purifier [228]

Resource Blocking / Modification; Presentation / Dismissal

Lei Tiaotiao [133, 134]

Presentation Match node text or identifiers and / Dismissal click the control or its parent

Accessibility; Control rules / recognition configuration and background execution. Android; accessibility service

32

Scope and Limitations

Covers only listed applications; internal function changes require rule updates. Navigation control is limited to the listed destination components and does not imply interception of arbitrary cross-app navigation.

Original version discontinued; original engine, third-party modified packages, and community rules are maintained separately. Page switching occurs after startup; initial adaptation and application versions affect behavior.

Consistency between inspected source and same-named shared packages remains unverified; listed by source implementation.

A.2

User-Enabled Vendor Advertising Controls

Users can enable these controls on supported devices and firmware; this does not mean that all Android devices provide the same option. Table 7: User-Enabled Vendor Advertising Controls. Tool / Control

Stage

Operation / Mechanism Evidence Deployment and Availability

OPPO: motion and orientation permission [171]

Input / Trigger

Input acquisition: denies access to motion or orientation data per app

System Setting; Restricted by device model and OS version. User setting listed in the official guide

The guide provides no complete model and firmware compatibility matrix.

vivo / iQOO: motion Input / and orientation Trigger control [172, 215]

Input acquisition: restricts motion data; some firmware supports blocking only during splash ads

System Setting; Restricted by device model and OS version. User setting; models and firmware supporting the option

No uniform duration is officially specified; options require checking for each firmware version.

Huawei: device orientation permission [100, 101]

Input / Trigger

Input acquisition: restricts access to orientation data per app

System Setting; Restricted by device model and OS version. User setting; corresponding HarmonyOS versions

Normal orientation functions in the application are also restricted.

HONOR: automatic app navigation reminder [97, 98]

Navigation Control

Add a reminder for detected accidental ad navigation

System Setting; Restricted by device model and OS version. Manufacturer system support and user setting

Scope depends on accidental-activation detection and the navigation being checked.

HONOR: device sensor permission [99]

Input / Trigger

Input acquisition: restricts motion and orientation access per app

System Setting; Restricted by device model and OS version. User setting; HONOR 100 / 100 Pro 8.0.0.150 release notes

Version evidence applies to the listed models; normal motion-based functions may be affected.

A.3

Scope and Limitations

Defense Tools for Other Ad Formats

These 15 instances target feed, video, audio, or other non-splash placements. They contribute to the main mechanism and deployment counts, with their advertising scope stated individually. Table 8: Defense Tools for Other Ad Formats. Tool / Control

Stage

Operation / Mechanism Evidence Deployment and Availability

Scope and Limitations

Ad Skipper Presentation Finds and automatically clicks (anar-bastanov) [25] / Dismissal buttons for skippable ads in the official YouTube app.

Accessibility; Control rules / recognition configuration and background execution. Android; an accessibility service.

Only for YouTube playback ads, rather than a general splash-ad tool; unskippable ads still require waiting.

ad-free: audio ad handling [6, 7]

Notification Access; Notification / playback-state access and audio control; no accessibility service or injection framework required. Android; the corresponding playback-state / notification access and audio control. F-Droid provides an installation package; a source build is not required.

Targets audio apps such as Spotify, rather than splash ads; ads typically continue playing and consuming time. This is not equivalent to removing ads or blocking navigation.

Presentation Identifies audio ads using playback / Dismissal state exposed by supported apps, then lowers the volume or plays replacement audio.

Continued on next page

33

Table 8 (continued) Tool / Control

Stage

Operation / Mechanism Evidence Deployment and Availability

AdAuto (Hongguo Short Drama ad skipping) [58]

Presentation Use advertising terms, countdowns, / Dismissal and playback state to close ads or swipe up

Accessibility; Ad skipping through accessibility; optional auxiliary overlay features are not included in this path. Android; the surveyed path uses accessibility. Auxiliary overlay features are outside this path.

AdSkipper (GimleLarpes) [83, 84]

Presentation Matches YouTube ad button / Dismissal identifiers and clicks automatically; can mute during ads and restore audio afterward.

Accessibility + Source Build; Targets YouTube playback ads, rather than splash ads generally; Control rules / recognition configuration and background ads continue running while the execution; Android SDK / build tools; tool waits for buttons. muting additionally uses audio control. Android; an accessibility service and audio control. Source build required: only source code was found through the inspected public channels; configure the Android SDK / build tools and generate an APK.

amznkiller [106]

Presentation Injects styles into Amazon / Dismissal Shopping’s WebView to hide matching sponsored ad elements.

Root / Jailbreak + Runtime Injection. Android; an Xposed module loaded in the target app.

Performs interface hiding; ad network requests can still occur. Depends on page structure and selectors and does not cover other native interfaces.

Discover Feed Filter [107]

Resource Identifies advertising structures in Blocking / the Google Discover data model and Modification filters the corresponding entries before the list is constructed.

Root / Jailbreak + Runtime Injection. Android; Xposed and DexKit for code location.

Targets the Discover feed; changes in advertising structures, obfuscation, and app versions require adaptation.

GmailHideAds [156] Presentation Identifies Gmail ad entries when / Dismissal child views are added, makes them invisible, and reduces their height.

Root / Jailbreak + Runtime Injection. Android; an Xposed module loaded in Gmail.

Targets native email-list ads, not splash ads; depends on ad view classes, and hiding does not imply request blocking.

Klick’r / Smart Presentation AutoClicker: / Dismissal user-configured ad dismissal [47, 73, 95]

Accessibility; Screen-capture authorization, local image / text matching, user-configured ad-dismissal scenarios, and background execution. Android; screen observation, user-configured recognition scenarios, and accessibility service authorization. Partly paid. The current Play version provides all features free but requires watching an ad to start a scenario; a one-time Pro purchase removes the tool’s own ads. A free F-Droid build is also available.

An explicit advertising use of a general automation tool, supported by a user report; the user’s full scenario file was not obtained, and splash-ad coverage was not verified. Button style changes require rule updates, and recognition and clicking introduce latency.

Users set image or text conditions, and matching triggers actions through an accessibility service; users have reported recognizing and clicking close buttons after game video ads end.

Scope and Limitations Currently focuses on Hongguo Short Drama; swipe actions apply only to the corresponding ad contexts.

Continued on next page

34

Table 8 (continued) Tool / Control

Stage

MapsAdBlock [76]

Resource Removes advertising entries from Blocking / data structures after Google Maps Modification responses are parsed.

Root / Jailbreak + Runtime Injection. Android; Xposed / LSPosed.

The inspected implementation is restricted to 26.37.00.977222275 and does not install the same hooks on other versions; it is not a general network filter.

Play Store Adblock [108]

Resource Filters sponsored apps and Blocking / advertising recommendations in the Modification Google Play content-processing path.

Root / Jailbreak + Runtime Injection. Android; a libxposed environment, scoped to Google Play.

Primarily targets store search and recommendation ads, rather than splash ads; versions and caches affect results, and modifying the store may also affect its integrity checks.

QAuxiliary: advertising features [57]

Resource Blocking / Modification; Presentation / Dismissal

Root / Jailbreak + Runtime Injection. Android; module loading in supported QQ / TIM processes.

Only explicit advertising features are counted; different features support different app versions, and the entire utility cannot be treated as a splash-ad defense.

ThreadsHideAds [157]

Resource Locates the feed insertion boundary Root / Jailbreak + Runtime Blocking / and filters data entries marked as Injection. Modification sponsored content. Android; libxposed and DexKit.

Targets the Threads feed; depends on sponsorship markers and function characteristics, and does not directly restrict touch or motion input.

TwitterHideAds [158]

Resource Blocking / Modification; Presentation / Dismissal

Resource Supply: Removes promoted data entries from video lists. Display and Dismissal: Suppresses promoted content at the Compose rendering boundary.

Root / Jailbreak + Runtime Injection. Android; a libxposed module loaded in X / Twitter.

Spans data and display; depends on models and rendering entry points and does not establish splash-ad coverage.

UnclutterIG (historical implementation) [211]

Resource Blocking / Modification; Presentation / Dismissal

Resource Supply: Removes sponsored ad data from Stories content lists. Display and Dismissal: Hides Views matching sponsored content after the feed returns ad Views.

Root / Jailbreak + Runtime Injection. Android; Xposed.

A historical project whose documented supported versions date from around 2019; not evidence of effectiveness on current Instagram versions.

XTA-AdKiller [132]

Resource Blocking / Modification; Presentation / Dismissal

Resource Supply: Intercepts Super Root / Jailbreak + Runtime Timetable requests such as loadAd, Injection. invokes callbacks with a no-ad result, Android; a Modern Xposed module and clears banner configurations. adapted to a specific app. Display and Dismissal: Sets the corresponding ad Views or containers to GONE.

A.4

Operation / Mechanism Evidence Deployment and Availability

Resource Supply: RemoveCommentAd traverses QQ short-video comment data and removes ad entries. Display and Dismissal: HideQZoneAD / QWalletNoAD hides or removes the corresponding ad Views.

Scope and Limitations

Not an SDK disabler for arbitrary apps; depends on class-loading timing after decryption, method signatures, and ad callback conventions.

Candidates with Unverified Implementations or Limited Availability

These 22 entries are excluded from the main-inventory counts. An established mechanism with unresolved access is distinguished from a developer claim or an incomplete implementation; the reason for exclusion is recorded for each entry.

35

Table 9: Candidates with Unverified Implementations or Limited Availability. Tool / Control

Stage

Operation / Mechanism Evidence Deployment and Availability

Scope and Limitations

DNSCloak + Resource The client sends DNS requests over AdGuard Home ad Blocking / DoH to the configured AdGuard filtering [19, 35, 188] Modification Home service, which filters them using advertising rules.

iOS; DNSCloak network Ad identification is performed configuration, the server’s DNS by server-side rules, not by DNS encryption itself. The inspected Stamp, and an AdGuard Home public DNSCloak source was service with ad filtering enabled. Historical download unavailable: last committed in 2020; this was the original App Store ID returns no not used to infer its current distribution status. Apps result in the US, China, or UK; the source route needs Xcode, signing, bypassing this resolution path or using caches may remain and legacy dependencies, and its unaffected. buildability has not been verified.

NoMoAds (research Resource Obtains outbound packets through a local VPN and identifies and blocks prototype) [195] Blocking / Modification ad requests using a classifier trained on network and visible HTTP features.

Android; AntMonitor-based traffic interception; content features depend on decryptability. Installation channel unconfirmed: the paper’s project page could not be accessed to verify an APK or a complete build procedure; this entry is excluded from the confirmed source-build count.

A prototype from a 2018 paper; depends on training samples and feature visibility. Certificate pinning makes content features unavailable, and the paper’s results do not establish coverage of current splash ads.

adX / adX Launcher [191]

Mechanism awaiting verification or limited scope

Vendor describes ad removal in enhanced applications and isolated execution spaces

Android; author-provided runtime environment

Internal modification mechanism is undisclosed; listed as a candidate pending implementation verification.

Ding Xiaotiao [60, 181]

Mechanism awaiting verification or limited scope

Download records and contemporaneous reports indicate ad-skipping use

Android distribution package; mechanism unverified

Package identity and implementation are unconfirmed; download channels were previously closed.

Yi Zhi Chan [60]

Mechanism awaiting verification or limited scope

Ad-skipping application listed in distribution records

Android distribution package; mechanism unverified

Original documentation site is unavailable; correspondence between the package and feature descriptions remains unverified.

Zhihui Dao [60]

Mechanism awaiting verification or limited scope

Application in distribution records; advertising operations unverified

Platform and package identity unverified

A renaming relationship with "Chanshi" has not been established, so its implementation description cannot be directly adopted.

Qing Qidong [137, 223]

Mechanism awaiting verification or limited scope

Author documents accessibility, Android; feature-specific coordinate clicks, and optional code authorization or module loading interception Partly paid. Distribution materials list a free edition and a paid full edition / activation code. Its implementation-review status is unchanged, and it is excluded from main-table fee counts.

Advertising use is primarily supported by historical reports; current advertising implementation remains unverified.

Continued on next page

36

Table 9 (continued) Tool / Control

Stage

Kelee Plugin Center Mechanism / awaiting ProxyResource [123, verification 143, 144] or limited scope

Operation / Mechanism Evidence Deployment and Availability Provide configuration entries for advertising plugins across applications and mini programs

iOS; Loon; some plugins also require application re-signing Paid. Plugin rules are public; the listed Loon client requires purchase. This entry remains excluded from the main inventory.

Some configurations are inaccessible; the Tencent Video plugin declares discontinued maintenance and version restrictions.

Android; specified browser content-filtering interfaces

Current product is browser-only; separate from the historical AdClear native-application filtering product.

AdClear Content Blocker (current product) [189, 190]

Resource Filter ads in Samsung Internet / Blocking / Yandex browsers Modification (specified browsers only)

zoffelf/skipad (implementation unverified) [240, 241]

Mechanism awaiting verification or limited scope

Author describes node scanning and Android; author states skip clicks accessibility-service use Source only / build needed. No prebuilt installation package was found; building does not resolve the implementation issues listed here.

Yao Ni Ming San Qian: advertising subset (mechanism unverified) [225]

Mechanism awaiting verification or limited scope

Author lists ad handling in Douyin, Kuaishou, and other applications, including some startup ads

Rule Imprison Navigation Interception (permissions and / Confirmastate handling awaiting tion verification) [26, 126, (permissions 127] and state handling awaiting verification)

AdSkipTweak (dismissal flow awaiting verification) [1, 2]

Scope and Limitations

Public tree lacks the application implementation and described build workflow; listed as an unverified candidate.

Android; Xposed / LSPosed or a Public distribution tree lacks corresponding loading environment implementation; specific intervention operations remain unverified.

The initial isHidden value may Monitors when a source app enters Android; device / profile owner or the foreground and calls corresponding delegated privileges, cause the first hiding call to be setApplicationHidden to temporarily an accessibility service, and skipped; set-active-admin in the hide specified shopping apps, compilation after configuring targets documentation does not confer restricting destination-app launches; in source code. Source only / build the owner status required by the corresponds to ad navigation. needed. No prebuilt installation API. Actual authorization, initial package was found; building does hiding, and restoration need not resolve the implementation verification. The XML issues listed here. configuration uses typeAllMask, so the dynamic configuration alone does not establish that no events can be received.

Initialization Includes advertising-related method replacement, video acceleration, and / Startup Prevention / WebView scripts, affecting ad Presentation execution and display. Suppression / Dismissal (flow awaiting verification)

iOS; a Theos build and a The inspected Makefile compiles Substrate-style code injection only Tweak.xm and does not environment. CI download: include AdSkipManager.m, unexpired build artifacts exist which contains automatic dismissal logic; changing despite the empty Releases page; package contents, signing / injection, countdown text or accelerating and dismissal logic still require video does not establish that checking. dismissal occurs. General playback acceleration may also affect normal videos. Continued on next page

37

Table 9 (continued) Tool / Control

Stage

Operation / Mechanism Evidence Deployment and Availability

JohnnyAdBlock (compatibility awaiting verification) [116]

Installs early-return hooks on Android; Xposed / LSPosed. Resource methods of specified advertising Blocking / Modification classes, affecting ad initialization, loading, or display depending on the / Initialization call. / Startup Prevention / Presentation Suppression / Dismissal (compatibility awaiting verification)

LinkedInAdblocker- Unfinished; Locates LinkedIn click methods and Xposed (unfinished no installs hooks, with the aim of prototype) [163, 164] ad-removal handling in-app ads. operation yet

ReVanced Manager + Determined specific advertising by the patches (source and specific versions awaiting patch (source verification) [185, code 186] awaiting verification)

QQTamer / QQ Keeper: historical advertising subset [229]

Android; Xposed. Source only / build needed. No prebuilt installation package was found; building does not resolve the implementation issues listed here.

Manager executes the Android; the corresponding patch package-patching workflow; user and target-app versions, and logs in the official repository record installation of the modified package. the Reddit Hide ads patch, with the actual modification point determined by the patch.

Author describes intercepting Authorspecified QQ splash-cache use and listed ad navigation functions concern: Resource Blocking / Modification; Navigation Interception / Confirmation (implementation awaiting verification)

Scope and Limitations Actual interception code exists, but the listed class and method names do not establish compatibility with the corresponding SDKs. Target-app versions, methods actually intercepted, and blocking outcomes need to be recorded; exceptions are ignored, so the absence of errors does not demonstrate successful matching. Only advertising features are listed. The inspected before / after callbacks are empty and do not yet remove ads. Not counted as an implemented defense, and display-control capabilities are not inferred from the project’s goals. Access to the main patch repository returned HTTP 451 during this review, so the specific patch source has not been verified; available logs record patch failure, not successful ad removal. Static modification alone does not place it in ad initialization, and Manager and its patch are not counted twice.

Android; Xposed / LSPosed or a The public materials do not corresponding loading environment establish the interception points and supported versions for the claimed cache and navigation functions. Some real-time splash and feed ads are explicitly outside its advertised scope.

Continued on next page

38

Table 9 (continued) Tool / Control

Stage

Operation / Mechanism Evidence Deployment and Availability

Scope and Limitations

Dasheng Jinghua [231]

AuthorAuthor lists page replacement, view Android; Xposed or privileges listed blocking, and request and file rules required by each feature functions concern: Resource Blocking / Modification; Presentation Suppression / Dismissal (implementation awaiting verification)

Distribution materials describe page replacement, interface hiding, and request or file rules, but the available evidence does not link those functions to a working implementation in a specific version.

Tmall Campus / Quzhi Campus ad removal [224]

AuthorAuthor describes direct home-screen Android; system administration listed entry, hidden ads, and intercepted ad privileges and libxposed functions loading concern: Resource Blocking / Modification; Initialization / Startup Prevention; Presentation Suppression / Dismissal (implementation awaiting verification)

The listed functions are version-specific. The available repository does not establish which calls or interfaces implement home-page entry, interface hiding, or advertising-load interception.

Adhell3 (historical source) [68]

Resource Write advertising-domain and Blocking / connection rules to Samsung Modification network controls

System Setting + Source Build; Historical source documents Device administrator authorization, Samsung Knox rule configuration. Deployment a Knox license, and compatible additionally needs administrator firmware. Samsung devices; Knox management, authorization and a Knox administrator authorization, and a license; current license license Source build required: only availability is unconfirmed. source code was found through the New-device compatibility is also inspected public channels; configure unconfirmed. This entry is the Android SDK / build tools and excluded because the required generate an APK. external deployment prerequisite is unresolved, not simply because the code is historical. Continued on next page

39

Table 9 (continued) Tool / Control

Stage

AdSkipper (decemberpei) [70]

Accessibility; Control rules / Claimed: The developer describes presentation automatically finding and clicking ad recognition configuration and Skip buttons using accessibility background execution. / dismissal interface information. Android; accessibility authorization and background execution settings.

The store description states automatic ad skipping, but the available evidence does not establish its recognition and intervention mechanism beyond that claim. The implementation is not counted as established. A store listing and a verified defensive operation are separate forms of evidence.

BiliRoamingX: advertising patches [39, 40]

Resource Modifies the Bilibili package so that Blocking / data retrieval for Modification creator-recommended ads returns an empty value; it also clears specified advertising response lists.

APK Modification; ReVanced patching workflow; the prebuilt distribution channel is unavailable, and patch-building and installation channels remain unconfirmed; not counted as a ready-to-install APK. Android; the ReVanced patching workflow and installation of the modified app. Distribution unavailable at the cited channel: the official README’s prebuilt repository currently returns 404, and the source repository has no release packages; ready-to-install deployment cannot be assumed.

Source code establishes advertising-response patches for Bilibili recommendations. The cited prebuilt repository is unavailable, and a complete usable build-and-install route has not been established. It is therefore retained with availability-limited research and tools, outside the main counts.

A.5

Operation / Mechanism Evidence Deployment and Availability

Scope and Limitations

Mechanisms Requiring Action by Host-App Developers or Advertising Platforms

Ordinary users cannot independently deploy these interfaces, integration libraries, or platform policies; they are excluded from the main-text method classification and statistics. Table 10: Mechanisms Requiring Action by Host-App Developers or Advertising Platforms. Tool / Control

Stage

Operation / Mechanism Evidence Deployment and Availability

Scope and Limitations

AdblockAndroid: developer integration library [72]

Resource Blocking / Modification; Presentation / Dismissal

Resource Supply: Checks resource requests against advertising rules in the integrated WebView. Display and Dismissal: Uses ElementHiding to hide matching web ad elements.

Android; integration of the ad-filtering library by the host developer. Requires developer integration and a host-app build; a sample APK does not provide general control over other apps.

Integrated / configured by host-app developers or enabled by advertising platforms; users cannot deploy it themselves. Covers only integrated web containers, rather than allowing users to control other native apps after installation; depends on filtering rules and WebView interfaces.

libadblockplusandroid: AdblockWebView [12]

Resource Blocking / Modification; Presentation / Dismissal

Resource Supply: AdblockWebView filters web ad resource requests. Display and Dismissal: Hides web ad elements.

Android; host integration of the library, subscription configuration, and JavaScript support. Requires developer integration and a host-app build; a sample APK does not provide general control over other apps.

Integrated / configured by host-app developers or enabled by advertising platforms; users cannot deploy it themselves. Spans resource supply and display; does not cover unintegrated native ad interfaces or provide general cross-app control. Continued on next page

40

Table 10 (continued) Tool / Control

Stage

Operation / Mechanism Evidence Deployment and Availability

Scope and Limitations

Google Confirmed Click [86]

Navigation Control

Add confirmation before entering an Enabled by Google for selected ad destination placements

Integrated / configured by host-app developers or enabled by advertising platforms; users cannot deploy it themselves. Limited to Google Ads demand; specific splash-format coverage requires evaluation.

GroMore Android [48]

Input / Trigger

Trigger evaluation: configures splash-ad shaking through setSplashShakeButton

Developer sets mediation request parameters

Integrated / configured by host-app developers or enabled by advertising platforms; users cannot deploy it themselves. Documentation does not list complete ad-source coverage or default values.

Sigmob Android [196]

Input / Trigger

Input acquisition: disables SDK sensor use through setSensorStatus(false)

Developer configuration before ad requests

Integrated / configured by host-app developers or enabled by advertising platforms; users cannot deploy it themselves. Applies to that SDK; its sensor uses also include fraud prevention.

Sigmob HarmonyOS [196]

Input / Trigger

Input acquisition: controls SDK sensor access through isCanUseSensor

Developer supplies privacy-control configuration

Integrated / configured by host-app developers or enabled by advertising platforms; users cannot deploy it themselves. Applies only to the corresponding platform SDK and supported paths.

Sigmob iOS [196]

Input / Trigger

Trigger evaluation: disables motion interaction components through isCanUseMotionManager

Developer sets the corresponding interface to NO

Integrated / configured by host-app developers or enabled by advertising platforms; users cannot deploy it themselves. The interface contract covers interaction components; other advertising interactions may remain.

Taku Android [203]

Input / Trigger

Trigger evaluation: configures permitted or prohibited shake, rotation, and swipe interactions

Developer configuration; 6.5.09+; some ad sources have additional version requirements

Integrated / configured by host-app developers or enabled by advertising platforms; users cannot deploy it themselves. Support depends on the ad source, adapter version, and ad format.

Taku iOS [204]

Input / Trigger

Trigger evaluation: configures motion interaction features of ad sources

Developer configuration; 6.4.90+; Integrated / configured by some sources require newer versions host-app developers or enabled by advertising platforms; users cannot deploy it themselves. Custom sources are unsupported; Kuaishou support is limited to splash and native ads. Continued on next page 41

Table 10 (continued) Tool / Control

Operation / Mechanism Evidence Deployment and Availability

Scope and Limitations

ToBid Android [197] Input / Trigger

Input acquisition: passes the sensor collection choice to supported ad sources

Integrated / configured by host-app developers or enabled by advertising platforms; users cannot deploy it themselves. Documentation explicitly describes propagation to Sigmob; other sources require separate verification.

Tencent GDT Android [205]

Input / Trigger

Trigger evaluation: disables Developer setting per ad request splash-ad shaking with shakable="0"

Kuaishou iOS [131]

Input / Trigger

Trigger evaluation: disables splash-ad shaking through disableShake

A.6

Stage

Developer initialization configuration; 5.0.2+

Integrated / configured by host-app developers or enabled by advertising platforms; users cannot deploy it themselves. Omission or a value of 1 does not block shaking; documentation does not uniquely identify the parameter’s first release.

Developer setting before the request; Integrated / configured by cited guide is version 3.3.28 host-app developers or enabled by advertising platforms; users cannot deploy it themselves. Not blocked by default; affects only the specified interaction.

General Platform Capabilities Related to Ad Defense

Provided only as technical background; the underlying general capability itself cannot be counted as an ad-specific tool. Table 11: General Platform Capabilities Related to Ad Defense. Tool / Control

Stage

Operation / Mechanism Evidence Deployment and Availability

Scope and Limitations

AOSP Sensors off [28]

Input / Trigger Restriction (general capability)

Globally stop delivery of the corresponding sensor events

A general platform capability, not counted as an ad-specific tool. Affects other sensors and normal functionality; not a per-application advertising switch.

OnePlus: startup motion permission [169, 221]

Input / Trigger Restriction (general capability)

Deny motion and orientation access Official notes for 10T 14.0.0.712 / 9R A general platform capability, during application startup 14.0.0.603 not counted as an ad-specific tool. General startup permission; official documentation does not limit it to advertising control.

iOS browser app Navigation launching and link Interception routing [33, 145, 207] / Confirmation (general capability)

Android developer quick setting; manufacturers may modify it

Browsers conditionally confirm, Browser implementation, system allow, or deny external-app launches; settings, and user choices the system routes links by association

A general platform capability, not counted as an ad-specific tool. Browser checks apply only to navigation they handle; link routing itself does not identify ads. Continued on next page

42

Table 11 (continued) Tool / Control

Stage

iOS URL Filter [37, 38]

Resource The system allows or denies requests iOS 26+; developers configure using an address dataset entitlements and filtering services Blocking / Modification (general capability)

A.7

Operation / Mechanism Evidence Deployment and Availability

Scope and Limitations A general platform capability, not counted as an ad-specific tool. Other network stacks must actively participate; Filtr’s advertising feature is listed separately under resource supply, and its splash-ad coverage still requires specific testing.

Deployment Requirements and Fees

Requirement Counts. Tables 12 and 13 count the 108 instances in Appendices A.1–A.3. A stage row includes only requirements of the operation at that stage. Each requirement counts an instance once if at least one listed path uses it; alternative-path columns can therefore overlap. The overall row deduplicates instances across stages. A nonzero Root count does not mean that every path for those instances requires root. Network filtering is a mechanism, so it is not treated as a permission column. AWAvenue rules inherit VPN authorization or root from the respective executor paths. Fuck AD has injection-based hiding, accessibilitybased skipping, and Shizuku-assisted click paths; only the last also contributes to Debugging under presentation. AdAuto’s auxiliary overlay features and other optional capabilities not established for the listed defensive path are excluded. The counts describe listed paths rather than every possible feature of a multifunction tool. Table 12: Permissions and Execution Requirements of Listed Paths; Columns May Overlap. Stage

Instances VPN

Accessibility

Debug.

Root / Jailbreak

Injection

APK

Overlay

Notif. Access

Resource Blocking / Modification

58

30

0

0

22

19

3

0

0

Initialization / Startup

22

0

0

0

18

18

5

0

0

Presentation / Dismissal

44

0

24

1

20

20

1

0

1

Input / Trigger

9

0

2

1

3

3

0

1

0

Navigation Control

3

0

0

0

2

2

0

0

0

Return After Navigation

1

0

1

0

0

0

0

0

0

Overall (Deduplicated)

108

30

27

2

38

35

5

1

1

Table 13: System Configuration, Source Builds, and Fees of Listed Paths. Stage

Instances

System Setting

Source Build

Paid

Partly Paid

Resource Blocking / Modification

58

6

0

16

10

Initialization / Startup

22

0

2

0

0

Presentation / Dismissal

44

0

7

0

1

Input / Trigger

9

4

0

0

0

Navigation Control

3

1

0

0

0

Return After Navigation

1

0

1

0

0

Overall (Deduplicated)

108

11

8

16

11

Deployment Barriers and Fees. For 39 of the 108 instances (36.1%), every listed path requires at least one of root / jailbreak, runtime injection, or APK modification. The other 69 provide at least one path without those operations. This differs from counting any path that uses root: a tool with a VPN alternative belongs to the latter group. No software or service fee was identified for the 39 instances. Among 43

the other 69, 16 require payment for the listed defense and 11 offer free paths alongside paid features or plans. The remaining 42 have no identified software or service fee; this is not a guarantee about future pricing. Client or service charges are inherited by rule configurations, so these counts do not represent 27 independent paid products. Of the 69 instances with a path without root, injection, or APK modification, 50 use existing apps or services, six require source builds, eight are rule sets, and five are vendor settings. Existing packages can still require VPN or accessibility authorization, rules, certificates, debugging setup, or compatible devices. Fee definitions follow Table 4.

44

Record · ID 919240 · SHA-256 99c7b1d3a6f86fb6
Retrieved via Conceptio — every document is proof-bundled with source, license, and retrieval metadata.