Shielding QR Codes: Unveiling the Real-World Illicit Promotion Behind Adversarial QR Codes
Lijie Wu, Xiaoping Zhang, Mingxuan Liu, Yue Qin, Baojun Liu, Geng Hong, Zhenrui Zhang, Chenghui Wu, Hui Jiang
摘要
Adversarial QR Code Images (AQRIs) represent an emerging threat vector for covert (usually illicit) online promotion. They use adversarial perturbations to evade QR detectors (e.g., OCR-based models) while retaining decodability for information delivery, facilitating malicious content dissemination, and posing risks to both platforms and users. Though adversarial attacks are well-studied, targeted techniques against structured QR codes are underexplored.
To systematically investigate the real-world AQRI abuse, we cooperated with a leading Internet service provider. With the help of our partner, grounded in empirical observations, we introduce Adato, an enhanced framework for AQRI detection, by prioritizing finder pattern regions and identifying adversarial techniques through cross-platform consistency checks. Experimental results demonstrate that Adato achieves 98.6% precision and 97.8% recall on AQRI detection, significantly outperforming existing detectors. With the collaboration of our partner, we legally obtained posts with images from five well-known international social media platforms from September, 2024 to March, 2025, e.g., Reddit, Baidu Tieba. We applied Adato to over 40 million images and identified 68,467 AQRIs, demonstrating their widespread real-world use and their ability to evade existing moderation mechanisms. Analysis of our detected AQRIs reveals that AQRIs are widely used for illicit promotion: 95.78% are linked to 2,079 malicious URLs, spanning 7 business categories. Additionally, we analyzed the information dissemination strategies employed, such as redirect chains and indirect propagation paths that exploit cross-platform inconsistencies. These results highlight Adato's effectiveness in strengthening existing moderation and recognition pipelines against AQRI abuses.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper20
- High-Resolution Image Synthesis with Latent Diffusion ModelsRobin Rombach, Andreas Blattmann, Dominik Lorenz, Patrick Esser 等CVPR 2022 · 被引用 13,123 次
- HopSkipJumpAttack: A Query-Efficient Decision-Based AttackJianbo Chen, Michael I. Jordan, Martin J. WainwrightS&P 2020 · 被引用 797 次
- Adversarial Attacks on Adversarial BanditsYuzhe Ma, Zhijin ZhouICLR 2023 · 被引用 199 次
- Guessing Smart: Biased Sampling for Efficient Black-Box Adversarial AttacksThomas Brunner, Frederik Diehl, Michael Truong-Le, Alois C. KnollICCV 2019 · 被引用 127 次
- Detecting and Diagnosing Adversarial Images with Class-Conditional Capsule ReconstructionsYao Qin, Nicholas Frosst, Sara Sabour, Colin Raffel 等ICLR 2020 · 被引用 76 次
相关 Paper
- Development, Evaluation, and Implementation of SEQR - a Usable Secure QR Code ScannerMattia Mossano, Maxime Fabian Veit, Tobias Länge, Benjamin Maximilian Berens 等CHI 2026 · 被引用 1 次
- Demystifying the (In)Security of QR Code-based Login in Real-world DeploymentsXin Zhang, Xiaohan Zhang, Bo Zhao, Yuhong Nan 等USENIX Security 2025
- Scalable Detection of Promotional Website Defacements in Black Hat SEO CampaignsRonghai Yang, Xianbo Wang, Cheng Chi, Dawei Wang 等USENIX Security 2021 · 被引用 27 次
- Understanding Cross-Platform Referral Traffic for Illicit Drug PromotionMingming Zha, Zilong Lin, Siyuan Tang, Xiaojing Liao 等CCS 2024
- Stealthy Porn: Understanding Real-World Adversarial Images for Illicit Online PromotionKan Yuan, Di Tang, Xiaojing Liao, XiaoFeng Wang 等S&P 2019 · 被引用 49 次
