Doing good by fighting fraud: Ethical anti-fraud systems for mobile payments
Zain ul Abi Din, Hari Venugopalan, Henry Lin, Adam Wushensky, Steven Liu, Samuel T. King
Abstract
App builders commonly use security challenges, a form of step-up authentication, to add security to their apps. However, the ethical implications of this type of architecture has not been studied previously.In this paper, we present a large-scale measurement study of running an existing anti-fraud security challenge, Boxer, in real apps running on mobile devices. We find that although Boxer does work well overall, it is unable to scan effectively on devices that run its machine learning models at less than one frame per second (FPS), blocking users who use inexpensive devices.With the insights from our study, we design Daredevil, a new anti-fraud system for scanning payment cards that works well across the broad range of performance characteristics and hardware configurations found on modern mobile devices. Daredevil reduces the number of devices that run at less than one FPS by an order of magnitude compared to Boxer, providing a more equitable system for fighting fraud.In total, we collect data from 5,085,444 real devices spread across 496 real apps running production software and interacting with real users.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext c41f7e60-c1bd-4022-bcf9-24f08d60a083Cited by top-tier papers3
- "Get in Researchers; We're Measuring Reproducibility": A Reproducibility Study of Machine Learning Papers in Tier 1 Security ConferencesDaniel Olszewski, Allison Lu, Carson Stillman, Kevin Warren et al.CCS 2023 · 19 citations
- Aragorn: A Privacy-Enhancing System for Mobile CamerasHari Venugopalan, Zain ul Abi Din, Trevor Carpenter, Jason Lowe-Power et al.UbiComp 2024 · 8 citations
- When HTTP 402 Meets the Blockchain: Risks on Emerging x402 PaymentsQinying Wang, Yong Yang, Yuan Chen, Shouling Ji et al.USENIX Security 2026
Builds on4
- rtCaptcha: A Real-Time CAPTCHA Based Liveness Detection SystemErkam Uzun, Simon Pak Ho Chung, Irfan Essa, Wenke LeeNDSS 2018 · 60 citations
- Fear the Reaper: Characterization and Fast Detection of Card SkimmersNolen Scaife, Christian Peeters, Patrick TraynorUSENIX Security 2018 · 34 citations
- Kiss from a Rogue: Evaluating Detectability of Pay-at-the-Pump Card SkimmersNolen Scaife, Jasmine D. Bowers, Christian Peeters, Grant Hernandez et al.S&P 2019 · 10 citations
- Boxer: Preventing fraud by scanning credit cardsZain ul Abi Din, Hari Venugopalan, Jaime Park, Andy Li et al.USENIX Security 2020
Related papers
- Practical EMV Relay ProtectionAndreea-Ina Radu, Tom Chothia, Christopher J. P. Newton, Ioana Boureanu et al.S&P 2022 · 26 citations
- Transient Authentication from First-Person-View VideoLe Ngu Nguyen, Rainhard Dieter Findling, Maija Poikela, Si Zuo et al.UbiComp 2025
- Towards Transparent and Stealthy Android OS Sandboxing via Customizable Container-Based VirtualizationWenna Song, Jiang Ming, Lin Jiang, Yi Xiang et al.CCS 2021 · 11 citations
- Preventing SIM Box Fraud Using Device Model FingerprintingBeomseok Oh, Junho Ahn, Sangwook Bae, Mincheol Son et al.NDSS 2023
- Broken Fingers: On the Usage of the Fingerprint API in AndroidAntonio Bianchi, Yanick Fratantonio, Aravind Machiry, Christopher Kruegel et al.NDSS 2018 · 33 citations
