Can We Stop The Ads? Taxonomy and Characterization of Smartphone Splash Ads and Existing Countermeasures Shuhao Zhang1 , Xinyu Liu1 , Ziyu Shao1 , Yuqing Yang2 , Yan Long1 1 The Hong Kong University of Science and Technology (Guangzhou), China 2 Macau University of Science and Technology, China
arXiv:2609.17316v1 [cs.CR] 15 Sep 2026
{szhang515,zshao787}@connect.hkust-gz.edu.cn [email protected];[email protected] [email protected]
Abstract
process. Second, users may struggle to have their complaints addressed. Vendors provide limited feedback channels and may have little incentive to remove advertisements that generate revenue. Third, while national-level policies and regulations have already been announced, technical compliance by the main stakeholders still falls short. To understand how users can better address these problems, we need to take the perspective of ordinary, non-expert users, and examine how Splash Ads work, what existing tools can do, and what prevents users from using these tools effectively. As such, in this study, we investigate the landscape of Splash Ads in mobile ecosystems including Android and iOS particularly aiming to answer four research questions:
Splash ads are full-screen advertisements that pop up and appear as the first interaction page when users start an app, often tricking users into unknowingly activating certain trigger mechanisms, such as moving the phone to redirect users to other profit-driven third parties. So far, splash ads have already caused significant real-world impacts, ranging from significantly delaying emergency response to distracting drivers, as well as degrading accessibility of apps to vision-impaired users. We analyze 108 documented implementations1 of advertising defenses to examine their applicability to splash ads and the requirements users face when deploying them. Our analysis identifies substantial deployment barriers, including device rooting or jailbreaking, runtime code injection, and application modification. Options without these requirements can still involve additional permissions, rule maintenance, source compilation, or payment. In our evaluation of 13 configurations of 11 tools across 10 popular apps, only one tool prevented the target ad-triggered navigation across all ten apps. It required Accessibility permission, and ads remained visible for approximately one second before dismissal. Other tested configurations failed to prevent navigation or, in some cases, left host apps unable to launch or stuck on the ad page. We further analyze the outstanding challenges and possible future directions, highlighting the urgent need to incentivize smartphone manufacturers to provide more friendly and regulated platforms.
1
(1) What mechanisms do Splash Ads use, and how can these ads be classified? (2) Does platform difference affect the adoption and triggers of Splash Ad? (3) What mitigation methods are available, and what technical challenges do users face when deploying them? (4) What changes could help users better avoid or reduce the negative effects of Splash Ads? To answer these questions, we first conduct a comprehensive literature review of news report, technical documents, and GitHub repositories to collect incidents around Splash Ads, mechanisms behind Splash Ads, and mitigation tools from individual developers. Then, we summarize our findings to comprise a taxonomy of available approaches to enable Splash Ads. We find that Splash Ads generally rely on triggers to initiate, and such triggers can mainly be categorized into four types: single tapping, screen swiping, shaking the device, and device rotation. We also observe Splash Ads in over 30% of the top 30 Android applications we examined, with some applications implementing multiple trigger mechanisms. In terms of evaluating mitigation approaches, we perform a differential and empirical analysis, testing collected Splash Ad mitigation tools to evaluate their effectiveness and ease to use. Our investigation reveal that existing defenses are difficult for ordinary users to deploy and provide inconsistent protection. Among the 108 countermeasure instances we study, 39 require rooting or jailbreaking, runtime code injection, or APK modification. Even tools without these requirements may require additional permissions, rules, source compilation, or other configuration. In our empirical evaluation, only 28 of 130 tool-app combinations successfully prevented the target ad-triggered navigation, and some defenses even prevented host applications from launching or left them stuck on the ad page.
Introduction
Splash screen advertisements, or Splash Ads, are a common form of advertising. These ads are displayed when users launch a mobile application, before they can access its main functions. While this business model ensures that users see advertisements, it can also cause problems beyond inconvenience. Recent reports describe older adults and people with visual impairments being misled into clicking advertisements when they intended to use the application [55, 175]. There are even reports of victims contacting the fire department being forced to watch an advertisement of more than half a minute before being able to upload the required video [233]. Unfortunately, users have limited approaches to fight these ads. First, blocking Splash Ads can be technically challenging. The advertisements may be embedded in the application or downloaded from advertising servers, and users have little control over either
1 Inventory: https://github.com/SENSE-Lab-Security/SplashAds-Countermeasures
1
With these, we summarize the technical challenge around Splash Ads, namely why it is so challenging to stop Splash Ads, despite that there are numerous mitigation tools. These challenges include the difficulty of separating advertising behavior from normal application functionality, dependence on rules and configurations that may be invalidated with software updates, extensive deployment and runtime requirements, and potential legal conflicts around Splash Ad blocking tools. In the end, we propose future work directions to tackle these challenges and highlight the need of collective effort in mitigating hazards of Splash Ads in emergency or usability-centric environments. In short, this paper makes the following contributions:
Apps & Ad Providers Seek engagement, conversion, and revenue
Business Goals vs. Platform / Regulatory Constraints
Conversion vs. User Experience
Countermeasure & Regulation Transparency, consent, safeguards, and governance
Users
Seek clear, safe, and low-friction interactions
• We provide a systematic taxonomy of Splash Advertisements based on their mechanisms. • We perform comprehensive analysis of the ecosystem around Splash Ads, including the mitigation tools developed to fight against abusive Splash Ads. • We perform a large empirical evaluation on the effectiveness and usability of Splash Ads mitigation tools. • We propose approaches to mitigate Splash Ads issues in hazardous and impaired environments. • We provide a public inventory of the surveyed tools, with links to their sources and documentation of their deployment requirements and limitations.
2
Convenience vs. Security
Provide platform controls, safeguards, and policies
Figure 1: Competing objectives between the stakeholders in mobile splash advertising. Possible countermeasures and regulations may help improve balance between these parties.
Causing Accessibility Barriers. Intrusive advertisements can impose particularly severe barriersB on users who rely on accessibility services. A September 2026 report described viral footage of a visually impaired user in Jiangxi repeatedly attempting to operate a smartphone while advertisement pop-ups continued to appear and redirect the interface [175]. Phoenix Technology subsequently tested several applications using Android screen-reader mode and observed that important advertisement controls, including close buttons, could lack meaningful accessible labels, making it difficult for visually impaired users to distinguish dismissal controls from advertisement content. Impact on Elderly Users. In another widely reported incident, an elderly user in Huangshan attempted to take a photograph but encountered more than 20 advertisement pop-ups or redirects within approximately 30 seconds and eventually gave up the task [55]. The same investigation reported more than 2,800 complaints related to pop-up advertisements and documented complaints involving small close buttons, high-sensitivity “shake-toopen” triggers, and unwanted application redirection. The examples above are far from a comprehensive list of the negative real-world impact of smartphone splash ads. Together, these incidents show that aggressive advertisement interactions can affect application availability and even physical safety of users. More fundamentally, they demonstrate a significant and unaddressed tension (Figure 1): user actions or environmental inputs that do not clearly express an intention to open an advertisement can nevertheless be exploited and misinterpreted to generate profit-driven redirection operations, and the process is largely out of users’ controls.
Background & Motivation
This section introduces the real-world problems and relevant research results that motivate our work.
2.1
Device Manufacturers
Resulting Real-World Incidents
Recent incidents reported by Chinese news media illustrate that intrusive mobile app advertisements can create consequences beyond ordinary inconvenience. Below we highlight several outstanding concerning examples. Threatening Driving Safety. In June 2026, a driver reported that he opened a navigation application through voice control while driving, without touching the phone. Vehicle vibration subsequently triggered a high-sensitivity “shake-to-open” splash advertisement, causing the interface to redirect to an e-commerce application and distracting him while driving [71]. The driver reported that the incident nearly resulted in a collision. In a follow-up test, reporters also confirmed that two mainstream navigation applications displayed five-second splash ads for which shaking the phone could open the advertisement details. Hindering Emergency Response. In September 2026, a Shenzhen resident called the emergency service after observing a fire in a neighboring residence and was asked to upload a video through a link sent by the dispatcher. Opening the link launched the phone browser app, whose splash ad appeared before the upload page. While attempting to dismiss the ad, the user accidentally closed the browser and had to reopen the link, delaying the urgent video upload by approximately 30–60 seconds. The local fire department subsequently clarified that the advertisement originated from the user’s browser app rather than the emergency-service link [233].
2.2
User Attitudes and Demand for Control
Available evidence shows not only widespread dissatisfaction with intrusive splash advertisements, but also a concrete demand for mechanisms that give users greater control over advertisement activation and redirection. 2
Table 1: Semi-drive-by splash-ad prevalence and trigger distribution reported by Wu et al. [222]. Market
Tested
Detected
Touch
Motion
VIVO Xiaomi Wandoujia YingYongBao
5,262 5,998 11,682 8,881
261 (4.96%) 128 (2.13%) 198 (1.70%) 191 (2.15%)
12 (4.6%) 81 (63.3%) 18 (9.1%) 13 (6.8%)
249 (95.4%) 47 (36.7%) 180 (90.9%) 168 (88.0%)
Total
31,823 778 (2.44%) 124 (15.9%) 654 (84.1%)