USENIX Security2026Top-tier venue
Shielding QR Codes: Unveiling the Real-World Illicit Promotion Behind Adversarial QR Codes
Lijie Wu, Xiaoping Zhang, Mingxuan Liu, Yue Qin, Baojun Liu, Geng Hong, Zhenrui Zhang, Chenghui Wu, Hui Jiang
Abstract
Adversarial QR Code Images (AQRIs) represent an emerging threat vector for covert (usually illicit) online promotion. They use adversarial perturbations to evade QR detectors (e.g., OCR-based models) while retaining decodability for information delivery, facilitating malicious content dissemination, and posing risks to both platforms and users. Though adversarial attacks are well-studied, targeted techniques against structured QR codes are underexplored.
To systematically investigate the real-world AQRI abuse, we cooperated with a leading Internet service provider. With the help of our partner, grounded in empirical observations, we introduce Adato, an enhanced framework for AQRI detection, by prioritizing finder pattern regions and identifying adversarial techniques through cross-platform consistency checks. Experimental results demonstrate that Adato achieves 98.6% precision and 97.8% recall on AQRI detection, significantly outperforming existing detectors. With the collaboration of our partner, we legally obtained posts with images from five well-known international social media platforms from September, 2024 to March, 2025, e.g., Reddit, Baidu Tieba. We applied Adato to over 40 million images and identified 68,467 AQRIs, demonstrating their widespread real-world use and their ability to evade existing moderation mechanisms. Analysis of our detected AQRIs reveals that AQRIs are widely used for illicit promotion: 95.78% are linked to 2,079 malicious URLs, spanning 7 business categories. Additionally, we analyzed the information dissemination strategies employed, such as redirect chains and indirect propagation paths that exploit cross-platform inconsistencies. These results highlight Adato's effectiveness in strengthening existing moderation and recognition pipelines against AQRI abuses.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 670e0740-3067-4fc6-a73e-691d356cfb22Builds on20
- High-Resolution Image Synthesis with Latent Diffusion ModelsRobin Rombach, Andreas Blattmann, Dominik Lorenz, Patrick Esser et al.CVPR 2022 · 13,123 citations
- HopSkipJumpAttack: A Query-Efficient Decision-Based AttackJianbo Chen, Michael I. Jordan, Martin J. WainwrightS&P 2020 · 797 citations
- Adversarial Attacks on Adversarial BanditsYuzhe Ma, Zhijin ZhouICLR 2023 · 199 citations
- Guessing Smart: Biased Sampling for Efficient Black-Box Adversarial AttacksThomas Brunner, Frederik Diehl, Michael Truong-Le, Alois C. KnollICCV 2019 · 127 citations
- Detecting and Diagnosing Adversarial Images with Class-Conditional Capsule ReconstructionsYao Qin, Nicholas Frosst, Sara Sabour, Colin Raffel et al.ICLR 2020 · 76 citations
Related papers
- Development, Evaluation, and Implementation of SEQR - a Usable Secure QR Code ScannerMattia Mossano, Maxime Fabian Veit, Tobias Länge, Benjamin Maximilian Berens et al.CHI 2026 · 1 citation
- Demystifying the (In)Security of QR Code-based Login in Real-world DeploymentsXin Zhang, Xiaohan Zhang, Bo Zhao, Yuhong Nan et al.USENIX Security 2025
- Scalable Detection of Promotional Website Defacements in Black Hat SEO CampaignsRonghai Yang, Xianbo Wang, Cheng Chi, Dawei Wang et al.USENIX Security 2021 · 27 citations
- Understanding Cross-Platform Referral Traffic for Illicit Drug PromotionMingming Zha, Zilong Lin, Siyuan Tang, Xiaojing Liao et al.CCS 2024
- Stealthy Porn: Understanding Real-World Adversarial Images for Illicit Online PromotionKan Yuan, Di Tang, Xiaojing Liao, XiaoFeng Wang et al.S&P 2019 · 49 citations
