KIT | KIT-Bibliothek | Impressum | Datenschutz

Development, Evaluation, and Implementation of SEQR -- a Usable Secure QR Code Scanner

Mossano, Mattia ORCID iD icon 1; Fabian Veit, Maxime ORCID iD icon 1; Länge, Tobias ORCID iD icon 1; Maximilian Berens, Benjamin ORCID iD icon 1; Sharevski, Filipo; Volkamer, Melanie ORCID iD icon 1
1 Institut für Angewandte Informatik und Formale Beschreibungsverfahren (AIFB), Karlsruher Institut für Technologie (KIT)

Abstract:

QR codes are widely used, but can become the vector of phishing attacks (QRishing). To support users, we systematically developed a usable secure QR code scanner, SEQR (Security Enhanced QR code scanner). We based the SEQR’s design on two systematic reviews: (i) of academic literature (2015–2025), identifying 96 papers on QRishing, and (ii) of the MITRE ATT&CK® Mobile repository, finding 36 QRishing techniques. From these two sources, we categorized 60 potential attacks, and divided them between those that SEQR addresses only at the technology level, and those where SEQR involves the users in the decision. We evaluated SEQR effectiveness in thwarting attacks in a between-subjects online study (n = 556), where SEQR achieved 93.35\% correct answers, compared to 75.24\% for the Apple iOS QR code scanner and 65.11\% for the Samsung Android QR code scanner. We implemented SEQR as an open source Android application, available on GitHub.


Postprint §
DOI: 10.5445/IR/1000192945
Veröffentlicht am 05.05.2026
Originalveröffentlichung
DOI: 10.1145/3772318.3793213
Cover der Publikation
Zugehörige Institution(en) am KIT Institut für Angewandte Informatik und Formale Beschreibungsverfahren (AIFB)
Kompetenzzentrum für angewandte Sicherheitstechnologie (KASTEL)
Publikationstyp Proceedingsbeitrag
Publikationsjahr 2026
Sprache Englisch
Identifikator ISBN: 979-8-4007-2278-3
KITopen-ID: 1000192945
HGF-Programm 46.23.01 (POF IV, LK 01) Methods for Engineering Secure Systems
Erschienen in Proceedings of the 2026 CHI Conference on Human Factors in Computing Systems
Veranstaltung Conference on Human Factors in Computing Systems (CHI 2026), Barcelona, Spanien, 13.04.2026 – 17.04.2026
Verlag Association for Computing Machinery (ACM)
Seiten 1–33
Serie CHI ’26
Vorab online veröffentlicht am 13.04.2026
Externe Relationen Siehe auch
Schlagwörter Security, Mobile devices: Phones/Tablets, Artifact or System, Usability Study
Nachgewiesen in OpenAlex
KIT – Die Universität in der Helmholtz-Gemeinschaft
KITopen Landing Page