arXiv:2510.17175cs.CRcs.LG2025-10被引 5

通过分析二维码结构特征提前识别钓鱼攻击,提升可解释性与实战可用性。

QRïS: A Preemptive Novel Method for Quishing Detection Through Structural Features of QR

  • 基于二维码布局模式提取24个结构特征,构建透明分类方法
  • 在40万样本数据上实现最高83.18%的检测准确率
  • 开发移动端应用验证实际部署可行性,适合安全防护场景

全球范围内,个人与组织广泛使用快速响应(QR)码实现高效通信。然而,网络犯罪分子利用此技术在二维码中嵌入虚假或误导性信息,实施各类钓鱼攻击,即“Quishing”。现有防御方法多依赖黑箱模型,通过内容分类或视觉特征(如深度特征、直方图密度分析)进行判断,但缺乏可解释性与透明度,导致信任度低、偏差检测困难等问题。本文提出QRïS,首个基于二维码结构特征的前瞻性检测方法,通过全面分析二维码布局模式,实现对钓鱼二维码的早期识别。研究构建了包含40万样本的二维码数据集,从真实URL数据集生成;设计简单算法提取24个结构性特征,并在此基础上训练机器学习模型,达到最高83.18%的准确率。通过与现有方法对比验证其有效性,并开发移动端应用,证明该方案在真实场景中的可行性和实用性。

原文摘要 · Abstract (English)

Globally, individuals and organizations employ Quick Response (QR) codes for swift and convenient communication. Leveraging this, cybercriminals embed falsify and misleading information in QR codes to launch various phishing attacks which termed as Quishing. Many former studies have introduced defensive approaches to preclude Quishing such as by classifying the embedded content of QR codes and then label the QR codes accordingly, whereas other studies classify them using visual features (i.e., deep features, histogram density analysis features). However, these approaches mainly rely on black-box techniques which do not clearly provide interpretability and transparency to fully comprehend and reproduce the intrinsic decision process; therefore, having certain obvious limitations includes the approaches' trust, accountability, issues in bias detection, and many more. We proposed QRïS, the pioneer method to classify QR codes through the comprehensive structural analysis of a QR code which helps to identify phishing QR codes beforehand. Our classification method is clearly transparent which makes it reproducible, scalable, and easy to comprehend. First, we generated QR codes dataset (i.e. 400,000 samples) using recently published URLs datasets [1], [2]. Then, unlike black-box models, we developed a simple algorithm to extract 24 structural features from layout patterns present in QR codes. Later, we train the machine learning models on the harvested features and obtained accuracy of up to 83.18%. To further evaluate the effectiveness of our approach, we perform the comparative analysis of proposed method with relevant contemporary studies. Lastly, for real-world deployment and validation, we developed a mobile app which assures the feasibility of the proposed solution in real-world scenarios which eventually strengthen the applicability of the study.

二维码安全结构特征钓鱼检测可解释性

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。