Development, Evaluation, and Implementation of SEQR -- a Usable Secure QR Code Scanner

Privacy by Design & User ControlPasswords & AuthenticationPrivacy Perception & Decision-MakingSoftware Engineers & DevelopersCybersecurity EngineersAI/ML Researchers & EngineersPrivacy Policy Makers

Paper Title

Development, Evaluation, and Implementation of SEQR -- a Usable Secure QR Code Scanner

Publication Info

  • Topic area: Usable security for QR code scanning and phishing prevention.
  • Keywords: QRishing, phishing, QR code scanner, usable security, SEQR, mobile security, systematic review, MITRE ATT&CK®, user study, open source.

Background and Problem

  • Problem / challenge: QR codes are increasingly used as phishing vectors (QRishing), but existing QR code scanners lack adequate user support to detect and prevent phishing attacks.
  • Significance: QRishing poses risks such as account compromise, malware dissemination, financial theft, and IT system disruption. Addressing this threat is critical for protecting users.
  • Motivation and related work: Previous works on phishing focused on email and SMS contexts, neglecting QR codes. Existing QR code scanners fail to provide effective security features or user involvement, leaving users vulnerable to QRishing attacks.

Solution

  • Proposed approach: SEQR (Security Enhanced QR code scanner), a secure QR code scanner designed to thwart phishing attacks through technology and user involvement.
  • Novelty:
    1. Systematic categorization of QRishing attacks using academic literature and MITRE ATT&CK® Mobile repository.
    2. Development of SEQR with risk levels, enhanced URL visualization, and user tutorials.
    3. Evaluation showing SEQR significantly outperforms default QR code scanners (Apple iOS and Samsung Android) and the Privacy Friendly QR Scanner.
    4. Open-source implementation of SEQR for Android, enabling widespread adoption and further development.
  • Procedure and key techniques:
    • Categorized QRishing attacks into 60 techniques based on systematic reviews.
    • Designed SEQR to address attacks through risk levels (low-risk, unknown-risk, high-risk), domain-only URL visualization, kerning, and a tutorial.
    • Implemented SEQR as an Android app, integrating features like PhishTank checks, redirect resolution, and user feedback dialogs.
    • Conducted two user studies to evaluate SEQR 1.0 and SEQR 2.0 against baselines.

Results

  • Concrete findings:
    • SEQR achieved 93.35% correct answers in distinguishing phishing QR codes from legitimate ones, compared to 75.24% for Apple iOS and 65.11% for Samsung Android.
    • SEQR 2.0 achieved 94.18% correct answers, outperforming the Privacy Friendly QR Scanner (76.26%).
  • Advantage over baselines:
    • SEQR significantly improved phishing detection rates compared to default QR scanners and the baseline app, with large effect sizes in user studies.
    • Features like risk levels and tutorials enhanced user effectiveness.
  • Experiments / evaluation:
    • Two between-subjects online studies with 556 participants (SEQR 1.0) and 417 participants (SEQR 2.0).
    • Tested scenarios with legitimate and phishing URLs using obfuscation techniques (e.g., mangle, mislead, obfuscate).
    • Metrics included correct answers, false positives, and false negatives.
  • Limitations and future work:
    • SEQR currently supports only URLs and phone numbers; other QR code formats (e.g., vCards) need implementation.
    • Reliance on online services like PhishTank may cause issues if services are unreachable.
    • Further studies needed to evaluate long-term effectiveness, accessibility, and iOS implementation.

Summary

SEQR is a secure QR code scanner designed to address QRishing threats through systematic categorization, user involvement, and technological features. Evaluations demonstrated its significant effectiveness over default QR scanners and the Privacy Friendly QR Scanner. SEQR’s open-source implementation provides a foundation for improving QR code security and usability. Future work should expand its functionality, address reliance on online services, and conduct real-world and longitudinal studies to ensure widespread adoption and effectiveness.

Quick Actions

Share

Share this page

ios_share

https://hci.top/en/papers/chi/221932/2026

AdRecommended

Learn AI Coding at CodeNow

open_in_newOpen DOI Link
DOI: https://doi.org/10.1145/3772318.3793213
At a Glance

Paper Snapshot

fact_check
dataset
Source
CHI
calendar_month
Year
2026
emoji_events
Award
No award tagged
group
Authors
6 authors
sell
Subtopics
Privacy by Design & User Control, Passwords & Authentication, Privacy Perception & Decision-Making
work
Professions
Software Engineers & Developers, Cybersecurity Engineers, AI/ML Researchers & Engineers, Privacy Policy Makers
article
Content Status
Full text indexed
hub
Related Papers
10 related papers