Guitauditor enables detailed child safety reviews on smartphones

GUIAuditor: Enabling Post-hoc Child Safety Forensics via Action-Guided GUI Provenance on Mobile Devices

Cryptography and Security

Summary

Apps on smart devices can sometimes expose children to online dangers like scams or inappropriate contact. Automatic safety tools often make mistakes, so the authors propose a system called GUIAuditor that helps guardians review what happened after the fact. It creates readable stories from a child's app interactions on mobile devices, which can be searched with natural language questions. This system runs efficiently on smartphones without using too much power or memory. GUIAuditor aims to support human-led investigations into child safety issues in apps.

What this means in practice

  • For mobile security teams: Provide guardians a tool on smartphones to review and search a child's app usage history to identify safety concerns after incidents occur.
  • For app developers: Integrate refined activity logging and queryable safety event narratives to support user safety audits and investigations.

Authors

Junlin Liu, Yifeng Cai, Shuai Wang, Zhineng Zhong, Shaofei Li, Jiacheng Liu, Yuanchun Li, Ziqi Zhang, Xiangqun Chen, Ding Li, Yao Guo

Abstract

The proliferation of smart devices exposes children to online risks like grooming and financial scams that are deeply embedded within legitimate applications. Current approaches rely on automated prevention and detection, a paradigm that is fundamentally limited by its inherent fallibility. Whether rule-based or AI-driven, they inevitably produce false positives and negatives, failing to provide reliable protection. In this paper, we argue for a complementary, human-in-the-loop, post-hoc forensic paradigm. We present GUIAuditor, the first system designed to realize this vision by creating GUI Provenance: a queryable, semantic record of a child's interaction sequence. To generate this, GUIAuditor leverages a Multimodal Large Language Model (MLLM) to translate the temporal sequence of GUI events into a human-understandable narrative. To make this practical on mobile devices, a novel evidence distillation pipeline reduces the data requiring analysis by over 89.2% compared to periodic sampling approaches adopted by industry standards, with negligible impact on accuracy. On a new dataset of 295 interaction clips, GUIAuditor achieves a 95.23% Macro-F1 Score in logging significant events and, crucially, its two-stage forensic query engine successfully retrieves the correct evidence as the top result for over 90.20% of natural language questions. An end-to-end evaluation on three modern smartphones shows that the full pipeline, including on-device MLLM inference, adds 2.1W of power draw and 7.4s of per-event latency, with a peak memory footprint of ${\sim}$3.1GB. These results show that post-hoc GUI forensics can run on modern mobile devices and provide useful context for guardian-led safety review.