arXiv:2601.06768cs.CRcs.LG2026-01被引 2

ALFA 通过重构二维码网格,精准识别并阻止花哨二维码中的钓鱼攻击。

ALFA: A Safe-by-Design Approach to Mitigate Quishing Attacks Launched via Fancy QR Codes

  • 将花式二维码还原为二进制网格,定位异常模块。
  • 在合成数据集上实现0.06%的极低漏检率(FNR)。
  • 适配移动端,实测比主流扫码工具更可靠地识别恶意二维码。

使用快速响应(QR)码进行的网络钓鱼称为Quishing。攻击者利用此方式诱导用户泄露敏感信息。近期,二维码呈现丰富多彩的非传统黑白模块形式,不再具备典型二值特征,成为逃避现有基于深度学习的视觉检测与其它主流防护手段的新型攻击向量。本文提出「ALFA」——一种安全优先设计方法,用于缓解此类攻击,并防止用户访问扫描后产生的有害载荷。该方法首先将花式二维码转换为二进制网格,识别其中的错误模块;随后提出「FAST」方法,可高效恢复错误模块;再基于该二进制网格提取结构特征,利用预训练模型判断二维码合法性。实验在包含多种花式变体的合成数据集上验证,仅达0.06%的漏检率(FNR)。我们还开发了移动端应用,测试方案实用性,并与真实世界二维码读取器对比,结果进一步表明本方案在实际环境中具有高分类可靠性与检测精度。

原文摘要 · Abstract (English)

Phishing with Quick Response (QR) codes is termed as Quishing. The attackers exploit this method to manipulate individuals into revealing their confidential data. Recently, we see the colorful and fancy representations of QR codes, the 2D matrix of QR codes which does not reflect a typical mixture of black-white modules anymore. Instead, they become more tempting as an attack vector for adversaries which can evade the state-of-the-art deep learning visual-based and other prevailing countermeasures. We introduce "ALFA", a safe-by-design approach, to mitigate Quishing and prevent everyone from accessing the post-scan harmful payload of fancy QR codes. Our method first converts a fancy QR code into the replica of binary grid and then identify the erroneous representation of modules in that grid. Following that, we present "FAST" method which can conveniently recover erroneous modules from that binary grid. Afterwards, using this binary grid, our solution extracts the structural features of fancy QR code and predicts its legitimacy using a pre-trained model. The effectiveness of our proposal is demonstrated by the experimental evaluation on a synthetic dataset (containing diverse variations of fancy QR codes) and achieve a FNR of 0.06% only. We also develop the mobile app to test the practical feasibility of our solution and provide a performance comparison of the app with the real-world QR readers. This comparison further highlights the classification reliability and detection accuracy of this solution in real-world environments.

二维码安全恶意检测AI防御

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。