DeepIPA: Multi-Agent Static Security Dissection of iOS IPA Binaries with MCP-Orchestrated Analysis and Evidence-Based Vulnerability Verification

Authors

  • Memoona Sadaf Murdoch University Author
  • Muhammad Ahmad Ali Qureshi Murdoch University, Australia Author

DOI:

https://doi.org/10.68127/8se70967

Keywords:

iOS Security, IPA, Multi-Agent LLM, Model Context Protocol, Static Analysis

Abstract

iOS applications are distributed as IPA archives that contain Mach-O executables, frameworks, resources, property lists, entitlements, provisioning information, and third-party components. These artifacts expose substantial security-relevant information without requiring application execution, yet conventional scanners typically produce fragmented findings, and large language models can overstate vulnerabilities when reasoning is not tied to machine-checkable evidence. This paper presents DeepIPA, a multi-agent framework for static security dissection of iOS IPA binaries. The framework features deterministic multi-engine static analysis, a normalised program and security evidence graph, tool access based on the Model Context Protocol (MCP), and a three-role workflow called Planner, Investigator, and Validator. A deterministic evidence-contract gate is a type of gate that affects outcomes, where it is known that an outcome cannot become confirmed if it is not submitted to the gate. A deterministic evidence-contract gate is a type of gate that impacts outcomes; that is, if an outcome is not submitted to the gate, that outcome will not be confirmed. In evaluation, DeepIPA was compared with the other tools MobSF, IPA Auditor, Pavise, YARA, Gitleaks, and Semgrep on 25 IPA files. Under the specified score threshold, DeepIPA’s precision was 1.00, recall was 0.72, F1 was 0.84, accuracy was 80%, and false-positive rate was 0 at the application level. It also achieved the best C-V score separation and the highest level of finding coverage on the DVIA-v2 benchmark. The findings agree with evidence-gated multi-agent orchestration as a promising strategy for conducting static mobile security analysis with high precision, and with the unknown as a safe conclusion for evidence that needs to be confirmed during runtime.  

 

References

[1] OWASP Foundation, “Mobile Application Security Verification Standard (MASVS),” OWASP Mobile Application Security, 2026. https://mas.owasp.org/MASVS/

[2] Apple Inc., “Preventing insecure network connections,” Apple Developer Documentation. https://developer.apple.com/documentation

[3] Apple Inc., “Mach-O programming topics,” Apple Developer Documentation Archive. https://www.cs.miami.edu/home/burt/learning/Csc521.091/docs/MachOTopics.pdf

[4] MITRE Corporation, “Common Weakness Enumeration (CWE).” https://cwe.mitre.org/

[5] MobSF Project, “Mobile Security Framework (MobSF),” GitHub repository and documentation. https://github.com/MobSF/Mobile-Security-Framework-MobSF

[6] National Security Agency, “Ghidra Software Reverse Engineering Framework,” GitHub repository. https://github.com/NationalSecurityAgency/ghidra

[7] R. Thomas, “LIEF – Library to Instrument Executable Formats,” https://www.romainthomas.fr/publication/lief/

[8] VirusTotal, “YARA: The pattern matching swiss knife,” GitHub repository. https://github.com/VirusTotal/yara

[9] Gitleaks, “Gitleaks: Find secrets with Gitleaks,” GitHub repository. https://github.com/gitleaks/gitleaks

[10] Semgrep, “Semgrep Static Analysis,” Documentation and repository.https://github.com/semgrep/semgrep

[11] N. A. Quynh, “Capstone: Next-generation disassembly framework,” Black Hat USA, 2014. https://blackhat.com/docs/us-14/materials/us-14-NguyenAnh-Capstone-Next-Generation-Disassembly-Framework.pdf

[12] A. A. Hagberg, D. A. Schult, and P. J. Swart, “Exploring network structure, dynamics, and function using NetworkX,” in Proc. 7th Python in Science Conf. (SciPy2008), Pasadena, CA, USA, 2008, pp. 11–15.

[13] Model Context Protocol, “Model Context Protocol Specification,” 2026. https://modelcontextprotocol.io/specification/2026-07-28

[14] P. Gianchandani, “Damn Vulnerable iOS App (DVIA),” intentionally vulnerable iOS application benchmark. https://github.com/prateek147/DVIA-v2

[15] The Cyber Sandeep, “IPA Auditor,” GitHub repository. https://github.com/thecybersandeep/ipaauditor

[16] A. Mutlugun, “Pavise,” GitHub repository. https://github.com/ahmetmutlugun/pavise

Downloads

Published

2026-09-11

Data Availability Statement

Data will be available upon request.