QR codes have become ubiquitous thanks to the ease with which smartphones can scan them, but users have no reliable way to detect tampering by eye. This creates a significant security risk: a QR code can be modified to point to a malicious destination while looking identical to the legitimate one, and the alteration may go unnoticed for a long time.
We propose a new attack method that exploits high-refresh-rate displays capable of refreshing at 120 Hz or higher. The display rapidly alternates between a legitimate and a malicious QR code, so a human observer perceives only a single, static-looking code, while a camera scanning the display will probabilistically capture one of the two. Compared to existing visual-disguise techniques, this approach is considerably harder to detect by eye and affords the attacker far greater freedom in crafting the malicious payload.

Our evaluation experiments demonstrated that malicious QR codes differing only minimally from the legitimate ones evaded detection in approximately 80% of cases. Furthermore, we confirmed that the probability of capturing malicious data can be controlled by adjusting the alternation pattern.
We also investigated how display characteristics affect this technique. Because the method alternates between two QR codes, the dots that differ between the two codes — that is, the tampered dots — flicker rapidly. When the technique is applied to an LCD, the boundaries between adjacent flickering dots become conspicuous, making the attack easier to spot. As a result, the tampered dots had to be placed apart from each other, which meant the attack worked only on certain QR codes.
To overcome this limitation, we developed a custom high-refresh-rate LED display whose panel is driven directly by a microcontroller, and applied the technique to it. On this display, the boundaries remain inconspicuous even when flickering dots are placed next to each other. This removed the constraint described above, demonstrating that the attack can be mounted against arbitrary QR codes.

A tampered QR code shown on the custom LED display
