ICSE 2026
Sun 12 - Sat 18 April 2026 Rio de Janeiro, Brazil
Wed 15 Apr 2026 11:15 - 11:30 at Oceania X - Dependability and Security 1 Chair(s): Tevfik Bultan

User-generated content (UGC) that has not been audited may pose risks when visualized on the client-side graphical user interface (GUI). Therefore, it is critical to accurately identify which fields delivered by the server-side will be visualized on the client-side. This paper proposes ViTAL, an end-to-end taint analysis framework that deeply synergizes static analysis with Large Language Models (LLMs) to audit whether server-side fields in Android applications are ultimately visualized. Given an APK and its set of server-side fields, ViTAL maps these fields to their client-side counterparts, applies transfer rules to track data flow, and employs LLM-powered code summarization to identify GUI visualization features. The identified features are then validated through expert review and maintained in an updatable knowledge base. To support rigorous evaluation, we constructed and publicly released a high-quality dataset, VisualFieldBench, by collecting fields from three popular applications: Douyin, Tomato Novel, and Toutiao. To enhance usability, we also provide an executable tool. Our experiments show that ViTAL achieves an average recall of 93% and precision of 79%, uncovering previously overlooked visualization fields. These results underscore ViTAL’s practical value for real-world mobile content security auditing.

Wed 15 Apr

Displayed time zone: Brasilia, Distrito Federal, Brazil change

11:00 - 12:30
Dependability and Security 1Research Track / SE In Practice (SEIP) at Oceania X
Chair(s): Tevfik Bultan University of California at Santa Barbara
11:00
15m
Talk
Towards Global Matches for Third-Party Library Detection in Android
Research Track
Lige Zhan Wuhan University, Jiang Ming Tulane University, USA, Chenke Luo Tulane University, Guojun Peng Wuhan University, Jianming Fu Wuhan University
DOI
11:15
15m
Talk
ViTAL: LLM-Powered Taint Analysis for GUI Field Visualization Auditing in AndroidVirtual Attendance
SE In Practice (SEIP)
Liuyang Jiang Beijing University of Posts and Telecommunications, Shenghan Liu Douyin, Qiuping Yi Beijing University of Posts and Telecommunications, Hongliang Liang Beijing University of Posts ad Telecommunications, xiangxingqian Douyin, Qingyun Kong Douyin, Yixiu Chen Douyin, XiaoQiang Fan Douyin, LiangXu Zou Douyin
Media Attached
11:30
15m
Talk
Out of Distribution, Out of Luck: How Well Can LLMs Trained on Vulnerability Datasets Detect Top 25 CWE Weaknesses?
Research Track
Yikun Li Singapore Management University, Ngoc Tan Bui Singapore Management University, Ting Zhang Monash University, Chengran Yang Singapore Management University, Singapore, Xin Zhou Singapore Management University, Singapore, Martin Weyssow Singapore Management University, Jinfeng Jiang Singapore Management University, Junkai Chen Singapore Management University, Singapore, Huihui Huang Singapore Management University, Singapore, Huu Hung Nguyen Singapore Management University, Chiok Yew Ho Chinese University of Hong Kong, Jie Tan University of Groningen, Ruiyin Li Wuhan University, China; University of Groningen, The Netherlands, Yide Yin GovTech, Han Wei Ang GovTech, Frank Liauw Government Technology Agency Singapore, Eng Lieh Ouh Singapore Management University, Singapore, Lwin Khin Shar Singapore Management University, David Lo Singapore Management University
Pre-print
11:45
15m
Talk
OctopusGuard: K-Line Enhanced Token Scam Detector Powered by Multimodal LLMs
Research Track
Litong Sun SUN YAT-SEN UNIVERSITY, YangTian Mi Sun Yat-Sen University, Xiapu Luo Hong Kong Polytechnic University, Weigang Wu Sun Yat-sen University
12:00
15m
Talk
UnPII: Unlearning Personally Identifiable Information with Quantifiable Exposure Risk
SE In Practice (SEIP)
Intae Jeon Samsung Research, Yujeong Kwon Sungkyunkwan University, Hyungjoon Koo Sungkyunkwan University
12:15
15m
Talk
Foiegras: Source Code Based Software Composition Analysis For C/C++ Applications
SE In Practice (SEIP)
Georgios Gousios Endor Labs, Philip Hamer Endor Labs, Camilla Odlund Endor Labs, Leandro Melo Endor Labs, Joseph Hejderup Endor Labs & Delft University of Technology, Sridhara Muniraju Endor Labs, Thomas Durieux Endor Labs