Development, Evaluation, and Implementation of SEQR -- a Usable Secure QR Code Scanner

要旨

QR codes are widely used, but can become the vector of phishing attacks (QRishing). To support users, we systematically developed a usable secure QR code scanner, SEQR (Security Enhanced QR code scanner). We based the SEQR's design on two systematic reviews: (i) of academic literature (2015–2025), identifying 96 papers on QRishing, and (ii) of the MITRE ATT&CK® Mobile repository, finding 36 QRishing techniques. From these two sources, we categorized 60 potential attacks, and divided them between those that SEQR addresses only at the technology level, and those where SEQR involves the users in the decision. We evaluated SEQR effectiveness in thwarting attacks in a between-subjects online study (n=556), where SEQR achieved 93.35% correct answers, compared to 75.24% for the Apple iOS QR code scanner and 65.11% for the Samsung Android QR code scanner. We implemented SEQR as an open source Android application, available on GitHub.

著者
Mattia Mossano
SECUSO, Karlsruhe Institute of Technology (KIT), Karlsruhe, Germany
Maxime Fabian. Veit
SECUSO, Karlsruhe Institute of Technology (KIT), Karlsruhe, Germany
Tobias Länge
SECUSO, Karlsruhe Institute of Technology (KIT), Karlsruhe, Germany
Benjamin Maximilian Berens
Karlsruhe Institute of Technology (KIT), Karlsruhe, Germany
Filipo Sharevski
DePaul University, Chicago, Illinois, United States
Melanie Volkamer
SECUSO, Karlsruhe Institute of Technology, Karlsruhe, Germany

会議: CHI 2026

ACM CHI Conference on Human Factors in Computing Systems

セッション: Safety, Identity & Relatedness

P1 - Room 112
7 件の発表
2026-04-14 20:15:00
2026-04-14 21:45:00