ALFA: A Safe-by-Design Approach to Mitigate Quishing Attacks Launched via Fancy QR Codes
Muhammad Wahid Akram, Keshav Sood, Muneeb Ul Hassan, and Dhananjay Thiruvady

TL;DR
ALFA is a comprehensive safe-by-design approach that detects and mitigates malicious fancy QR codes, enhancing security against Quishing attacks by converting, correcting, and analyzing QR code structures with high accuracy.
Contribution
The paper introduces ALFA, a novel method combining binary grid conversion, error correction, and structural analysis to effectively identify and prevent malicious fancy QR codes.
Findings
Achieved a false negative rate of 0.06% in detection.
Demonstrated high classification reliability in real-world tests.
Validated effectiveness on diverse synthetic QR code datasets.
Abstract
Phishing with Quick Response (QR) codes is termed as Quishing. The attackers exploit this method to manipulate individuals into revealing their confidential data. Recently, we see the colorful and fancy representations of QR codes, the 2D matrix of QR codes which does not reflect a typical mixture of black-white modules anymore. Instead, they become more tempting as an attack vector for adversaries which can evade the state-of-the-art deep learning visual-based and other prevailing countermeasures. We introduce "ALFA", a safe-by-design approach, to mitigate Quishing and prevent everyone from accessing the post-scan harmful payload of fancy QR codes. Our method first converts a fancy QR code into the replica of binary grid and then identify the erroneous representation of modules in that grid. Following that, we present "FAST" method which can conveniently recover erroneous modules from…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsQR Code Applications and Technologies · Advanced Malware Detection Techniques · Spam and Phishing Detection
