ELDetector: An Automated Approach Detecting Endless-loop in Mini Programs
Nan Hu, Ming Fan, Jingyi Lei, Jian Wen He, Zhe Hou · 2025
In recent years, mini-programs have rapidly gained popularity and are widely used in payment, travel, shopping and other fields, greatly enhancing the convenience of users’ lives. However, these services usually require access to sensitive personal information such as phone numbers, location information, ID numbers and other permissions. In the process of using them, users may frequently encounter permission requests, and sometimes even be forced to authorize them, leading to poor usage experience or even falling into an endless-loop authorization cycle that is difficult to exit. Unfortunately, most of the existing studies are fragmented and only deal with individual issues of personal information usage in mini-programs, lacking a comprehensive analysis of how permission requests affect user experience. To address this problem, this paper proposes an automated tool called ELDetector that automatically traverses mini-program pages through dynamic analysis and detects authorization endless-loops with the assistance of the Large Language Model (LLM). We find that authorization endless-loops of mini-programs are mainly classified into two categories: single-page endless-loop and multipage endless-loop, based on the number of pages caught in the loop. We evaluated ELDetector on 97 popular mini-programs with an accuracy of 79.4% in detecting the authorization endless-loop problem, of which 15 mini-programs have been fixed by the developers. In addition, with the help of the Large Language Model (LLM), ELDetector is 54% faster than the traditional monkey test in identifying authorization endless-loop entrance points.