<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.3 20210610//EN" "JATS-journalpublishing1-3.dtd">
<article article-type="research-article" dtd-version="1.3" xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xml:lang="ru"><front><journal-meta><journal-id journal-id-type="publisher-id">kaz29</journal-id><journal-title-group><journal-title xml:lang="ru">Вестник Казахстанско-Британского технического университета</journal-title><trans-title-group xml:lang="en"><trans-title>Herald of the Kazakh-British Technical University</trans-title></trans-title-group></journal-title-group><issn pub-type="ppub">1998-6688</issn><issn pub-type="epub">2959-8109</issn><publisher><publisher-name>Казахстанско-Британский Технический Университет</publisher-name></publisher></journal-meta><article-meta><article-id pub-id-type="doi">10.55452/1998-6688-2026-23-3-347-361</article-id><article-id custom-type="elpub" pub-id-type="custom">kaz29-3197</article-id><article-categories><subj-group subj-group-type="heading"><subject>Research Article</subject></subj-group><subj-group subj-group-type="section-heading" xml:lang="ru"><subject>КОМПЬЮТЕРНЫЕ НАУКИ</subject></subj-group><subj-group subj-group-type="section-heading" xml:lang="en"><subject>COMPUTER SCIENCE</subject></subj-group></article-categories><title-group><article-title>AQRACE: ОБНАРУЖЕНИЕ ВРЕДОНОСНЫХ URL-АДРЕСОВ В QR-КОДАХ НА ОСНОВЕ МАШИННОГО ОБУЧЕНИЯ ДЛЯ ОЦЕНКИ БЕЗОПАСНОСТИ В РЕАЛЬНОМ ВРЕМЕНИ</article-title><trans-title-group xml:lang="en"><trans-title>AQRACE: MACHINE-LEARNING-BASED DETECTION OF MALICIOUS URLS IN QR CODES FOR REAL-TIME SECURITY ASSESSMENT</trans-title></trans-title-group></title-group><contrib-group><contrib contrib-type="author" corresp="yes"><contrib-id contrib-id-type="orcid">https://orcid.org/0000-0001-8805-2574</contrib-id><name-alternatives><name name-style="eastern" xml:lang="ru"><surname>Катук</surname><given-names>Норлиза</given-names></name><name name-style="western" xml:lang="en"><surname>Katuk</surname><given-names>Norliza</given-names></name></name-alternatives><bio xml:lang="ru"><p>PhD</p><p> </p></bio><bio xml:lang="en"><p>PhD</p></bio><email xlink:type="simple">k.norliza@uum.edu.my</email><xref ref-type="aff" rid="aff-1"/></contrib><contrib contrib-type="author" corresp="yes"><contrib-id contrib-id-type="orcid">https://orcid.org/0009-0001-3766-5482</contrib-id><name-alternatives><name name-style="eastern" xml:lang="ru"><surname>Нурдин</surname><given-names>Хикма</given-names></name><name name-style="western" xml:lang="en"><surname>Hikmah</surname><given-names>Hikmah</given-names></name></name-alternatives><bio xml:lang="ru"><p>Бакалавр</p><p> </p></bio><bio xml:lang="en"><p>B. Comp. Science</p></bio><email xlink:type="simple">hikmahnurdin750@gmail.com</email><xref ref-type="aff" rid="aff-1"/></contrib><contrib contrib-type="author" corresp="yes"><contrib-id contrib-id-type="orcid">https://orcid.org/0000-0002-9696-2807</contrib-id><name-alternatives><name name-style="eastern" xml:lang="ru"><surname>Али Фаузи</surname><given-names>М.</given-names></name><name name-style="western" xml:lang="en"><surname>Ali Fauzi</surname><given-names>М.</given-names></name></name-alternatives><bio xml:lang="ru"><p>PhD, факультет компьютерных наук</p><p> </p></bio><bio xml:lang="en"><p>PhD</p><p>Faculty of Science and Technology</p></bio><email xlink:type="simple">moch.ali.fauzi@ub.ac.id</email><xref ref-type="aff" rid="aff-2"/></contrib><contrib contrib-type="author" corresp="yes"><contrib-id contrib-id-type="orcid">https://orcid.org/0000-0002-7255-4454</contrib-id><name-alternatives><name name-style="eastern" xml:lang="ru"><surname>Фуркан</surname><given-names>Мхд.</given-names></name><name name-style="western" xml:lang="en"><surname>Furqan</surname><given-names>Mhd.</given-names></name></name-alternatives><bio xml:lang="ru"><p>PhD, факультет науки и технологий</p><p> </p><p> </p></bio><bio xml:lang="en"><p>PhD</p><p>Faculty of Science and Technology</p></bio><email xlink:type="simple">mfurqan@uinsu.ac.id</email><xref ref-type="aff" rid="aff-3"/></contrib></contrib-group><aff-alternatives id="aff-1"><aff xml:lang="ru"><institution>Школа вычислительной техники, Университет Утара Малайзия</institution><country>Малайзия</country></aff><aff xml:lang="en"><institution>School of Computing, Universiti Utara Malaysia</institution><country>Malaysia</country></aff></aff-alternatives><aff-alternatives id="aff-2"><aff xml:lang="ru"><institution>Университет Бравиджая</institution><country>Индонезия</country></aff><aff xml:lang="en"><institution>Universitas Islam Negeri Sumatera</institution><country>Indonesia</country></aff></aff-alternatives><aff-alternatives id="aff-3"><aff xml:lang="ru"><institution>Государственный исламский университет Северной Суматры</institution><country>Индонезия</country></aff><aff xml:lang="en"><institution>Universitas Islam Negeri Sumatera</institution><country>Indonesia</country></aff></aff-alternatives><pub-date pub-type="collection"><year>2026</year></pub-date><pub-date pub-type="epub"><day>26</day><month>09</month><year>2026</year></pub-date><volume>23</volume><issue>3</issue><fpage>347</fpage><lpage>361</lpage><permissions><copyright-statement>Copyright &amp;#x00A9; Катук Н., Нурдин Х., Али Фаузи М., Фуркан М., 2026</copyright-statement><copyright-year>2026</copyright-year><copyright-holder xml:lang="ru">Катук Н., Нурдин Х., Али Фаузи М., Фуркан М.</copyright-holder><copyright-holder xml:lang="en">Katuk N., Hikmah H., Ali Fauzi М., Furqan M.</copyright-holder><license xml:lang="ru" license-type="creative-commons-attribution" xlink:href="https://creativecommons.org/licenses/by/4.0/" xlink:type="simple"><license-p>Данная работа распространяется под лицензией Creative Commons Attribution 4.0.</license-p></license><license xml:lang="en" license-type="creative-commons-attribution" xlink:href="https://creativecommons.org/licenses/by/4.0/" xlink:type="simple"><license-p>This work is licensed under a Creative Commons Attribution 4.0 License.</license-p></license></permissions><self-uri xlink:href="https://vestnik.kbtu.edu.kz/jour/article/view/3197">https://vestnik.kbtu.edu.kz/jour/article/view/3197</self-uri><abstract><p>Широкое распространение кодов быстрого реагирования (Quick Response, QR) увеличило риск QRфишинга, вредоносной переадресации и распространения вредоносного программного обеспечения, поскольку пользователи не могут непосредственно проверить адрес назначения до сканирования QR-кода. В данном исследовании разработано приложение aQRace для обеспечения безопасности QR-кодов на основе машинного обучения, которое анализирует встроенные URL-адреса до перехода пользователя по соответствующей ссылке. Исследование объединяет извлечение признаков URL-адресов, сравнительную оценку моделей машинного обучения и их интеграцию в функционирующую систему. Для классификации были извлечены структурные, лингвистические, технические и расширенные характеристики URL-адресов. Четыре алгоритма машинного обучения с учителем – XGBoost, Random Forest, Decision Tree и Logistic Regression – были обучены и оценены на сбалансированном наборе данных, содержащем 14 000 URL-адресов, из которых 7000 являлись безопасными и 7000 – вредоносными. Производительность моделей сравнивалась по показателям accuracy, precision, recall и F1-score. XGBoost продемонстрировал наивысшую accuracy, равную 84%, и precision 0,80, тогда как Random Forest показал наивысший recall, равный 0,95. Обе модели достигли значения F1-score 0,84. На основе совокупности показателей производительности XGBoost был выбран для внедрения и интегрирован в клиент-серверное приложение, состоящее из мобильного интерфейса на Flutter и облачной серверной части на Flask. Приложение поддерживает загрузку изображений QR-кодов и сканирование с помощью камеры, а также выполняет обработку URL-адреса, извлечение признаков, классификацию и предупреждение пользователя до перехода по целевому адресу. Функциональное тестирование на репрезентативных безопасных и вредоносных QR-кодах подтвердило работоспособность полного процесса обнаружения угроз. Полученные результаты показывают, что традиционные методы машинного обучения на основе признаков URL-адресов могут использоваться для оценки безопасности QR-кодов до перехода пользователя по ссылке, обеспечивая практическую альтернативу все более сложным подходам на основе глубокого обучения.</p></abstract><trans-abstract xml:lang="en"><p>The widespread use of Quick Response (QR) codes has increased exposure to QR-based phishing, malicious redirection, and malware distribution because users cannot readily inspect the destination before scanning. This study develops aQRace, a machine-learning-based QR code security application that analyses embedded Universal Resource Locators (URLs) before users access their destinations. The study combines URL-based feature extraction, comparative machine-learning evaluation, and operational system integration. URL characteristics covering structural, linguistic, technical, and advanced properties were extracted for classification. Four supervised machine-learning algorithms–XGBoost, Random Forest, Decision Tree, and Logistic Regression–were trained and evaluated using a balanced dataset of 14,000 URLs comprising 7,000 safe and 7,000 malicious samples. Model performance was compared using accuracy, precision, recall, and F1-score. XGBoost achieved the highest accuracy of 84% and precision of 0.80, whereas Random Forest achieved the highest recall of 0.95. Both models achieved an F1 Score of 0.84. XGBoost was selected for deployment based on its overall performance profile and integrated into a client-server application comprising a Flutter mobile frontend and Flask cloud backend. The application supports QR code image uploads and camera-based scanning, and performs URL processing, feature extraction, classification, and user warnings before destination access. Functional testing with representative safe and malicious QR codes confirmed the operation of the complete detection workflow. The findings demonstrate that conventional machine learning using URL-based features can support pre-access QR code security assessment while providing an operational alternative to increasingly complex deep learning approaches.</p></trans-abstract><kwd-group xml:lang="ru"><kwd>безопасность QR-кодов</kwd><kwd>quishing</kwd><kwd>обнаружение вредоносных URL-адресов</kwd><kwd>машинное обучение</kwd><kwd>XGBoost</kwd><kwd>обнаружение фишинга</kwd><kwd>кибербезопасность</kwd></kwd-group><kwd-group xml:lang="en"><kwd>QR code security</kwd><kwd>quishing</kwd><kwd>malicious URL detection</kwd><kwd>machine learning</kwd><kwd>XGBoost</kwd><kwd>phishing detection</kwd><kwd>cybersecurity</kwd></kwd-group></article-meta></front><back><ref-list><title>References</title><ref id="cit1"><label>1</label><citation-alternatives><mixed-citation xml:lang="ru">Alsawi, W., Ibrahim, D. M. QR Code-Based Access Control Systems: Architectural Taxonomy, Security Landscape, and Future Research Directions. International Journal of Advanced Computer Science and Applications, 17(4), (2026).</mixed-citation><mixed-citation xml:lang="en">Alsawi, W., Ibrahim, D. M. QR Code-Based Access Control Systems: Architectural Taxonomy, Security Landscape, and Future Research Directions. International Journal of Advanced Computer Science and Applications, 17(4), (2026).</mixed-citation></citation-alternatives></ref><ref id="cit2"><label>2</label><citation-alternatives><mixed-citation xml:lang="ru">Njuguna, D., Ndia, J. Quick Response Code Security Attacks and Countermeasures: A Systematic Literature Review. Journal of Cybersecurity (2579-0072), 7(1), 1 (2025). https://doi.org/10.32604/ jcs.2025.059398</mixed-citation><mixed-citation xml:lang="en">Njuguna, D., Ndia, J. Quick Response Code Security Attacks and Countermeasures: A Systematic Literature Review. Journal of Cybersecurity (2579-0072), 7(1), 1 (2025). https://doi.org/10.32604/ jcs.2025.059398</mixed-citation></citation-alternatives></ref><ref id="cit3"><label>3</label><citation-alternatives><mixed-citation xml:lang="ru">Trad, F., Chehab, A. Detecting quishing attacks with machine learning techniques through qr code analysis. IFIP International Conference on Artificial Intelligence Applications and Innovations, 194–206 (2026). https://doi.org/10.1007/978-3-032-30805-4_14</mixed-citation><mixed-citation xml:lang="en">Trad, F., Chehab, A. Detecting quishing attacks with machine learning techniques through qr code analysis. IFIP International Conference on Artificial Intelligence Applications and Innovations, 194–206 (2026). https://doi.org/10.1007/978-3-032-30805-4_14</mixed-citation></citation-alternatives></ref><ref id="cit4"><label>4</label><citation-alternatives><mixed-citation xml:lang="ru">Vaithilingam, S., Shankar, S. a. M. Enhancing security in QR code technology using AI: Exploration and mitigation strategies. International Journal of Intelligence Science, 14(02), 49–57 (2024). https://doi.org/10.4236/ijis.2024.142003</mixed-citation><mixed-citation xml:lang="en">Vaithilingam, S., Shankar, S. a. M. Enhancing security in QR code technology using AI: Exploration and mitigation strategies. International Journal of Intelligence Science, 14(02), 49–57 (2024). https://doi.org/10.4236/ijis.2024.142003</mixed-citation></citation-alternatives></ref><ref id="cit5"><label>5</label><citation-alternatives><mixed-citation xml:lang="ru">Al-Zahrani, M. S., Wahsheh, H. A., Alsaade, F. W. Secure Real‐Time Artificial Intelligence System against Malicious QR Code Links. Security and Communication Networks, 2021(1), 5540670 (2021). https://doi.org/10.1155/2021/5540670</mixed-citation><mixed-citation xml:lang="en">Al-Zahrani, M. S., Wahsheh, H. A., Alsaade, F. W. Secure Real‐Time Artificial Intelligence System against Malicious QR Code Links. Security and Communication Networks, 2021(1), 5540670 (2021). https://doi.org/10.1155/2021/5540670</mixed-citation></citation-alternatives></ref><ref id="cit6"><label>6</label><citation-alternatives><mixed-citation xml:lang="ru">Sarkhi, M., Mishra, S. Detection of QR code-based cyberattacks using a lightweight deep learning model. Engineering, Technology &amp; Applied Science Research, 14(4), 15209–15216 (2024). https://www.etasr.com/index.php/ETASR/article/view/7777/3803</mixed-citation><mixed-citation xml:lang="en">Sarkhi, M., Mishra, S. Detection of QR code-based cyberattacks using a lightweight deep learning model. Engineering, Technology &amp; Applied Science Research, 14(4), 15209–15216 (2024). https://www.etasr.com/index.php/ETASR/article/view/7777/3803</mixed-citation></citation-alternatives></ref><ref id="cit7"><label>7</label><citation-alternatives><mixed-citation xml:lang="ru">Herlina, B., Soeparno, H. Machine learning model to improve classification performance in the process of detecting phishing URLs in QR codes. Journal of Theoretical and Applied Information Technology, 101(18), 5755–5765 (2023). http://www.jatit.org/volumes/Vol101No18/27Vol101No18.pdf</mixed-citation><mixed-citation xml:lang="en">Herlina, B., Soeparno, H. Machine learning model to improve classification performance in the process of detecting phishing URLs in QR codes. Journal of Theoretical and Applied Information Technology, 101(18), 5755–5765 (2023). http://www.jatit.org/volumes/Vol101No18/27Vol101No18.pdf</mixed-citation></citation-alternatives></ref><ref id="cit8"><label>8</label><citation-alternatives><mixed-citation xml:lang="ru">Pawar, A., Fatnani, C., Sonavane, R., Waghmare, R., Saoji, S. Secure qr code scanner to detect malicious url using machine learning. 2022 2nd Asian Conference on Innovation in Technology (ASIANCON), 1-8 (2022). https://doi.org/10.1109/ASIANCON55314.2022.9908759</mixed-citation><mixed-citation xml:lang="en">Pawar, A., Fatnani, C., Sonavane, R., Waghmare, R., Saoji, S. Secure qr code scanner to detect malicious url using machine learning. 2022 2nd Asian Conference on Innovation in Technology (ASIANCON), 1-8 (2022). https://doi.org/10.1109/ASIANCON55314.2022.9908759</mixed-citation></citation-alternatives></ref><ref id="cit9"><label>9</label><citation-alternatives><mixed-citation xml:lang="ru">Furqan, M., Katuk, N., Hartama, D. Multiclass Skin Lesion Classification Algorithm using AttentionBased Vision Transformer with Metadata Fusion. Journal of Applied Data Sciences, 7(1), 203–217 (2026). https://doi.org/10.47738/jads.v7i1.1017</mixed-citation><mixed-citation xml:lang="en">Furqan, M., Katuk, N., Hartama, D. Multiclass Skin Lesion Classification Algorithm using AttentionBased Vision Transformer with Metadata Fusion. Journal of Applied Data Sciences, 7(1), 203–217 (2026). https://doi.org/10.47738/jads.v7i1.1017</mixed-citation></citation-alternatives></ref><ref id="cit10"><label>10</label><citation-alternatives><mixed-citation xml:lang="ru">Alsulami, A.-A., Al-Haija, Q.-A., Alturki, B., Yafoz, A., Alqahtani, A., Alsini, R., Binyamin, S.-S. Efficient Malicious QR Code Detection System Using an Advanced Deep Learning Approach. Computer Modeling in Engineering &amp; Sciences, 145(1), 1117–1140 (2025). https://doi.org/10.32604/cmes.2025.070745</mixed-citation><mixed-citation xml:lang="en">Alsulami, A.-A., Al-Haija, Q.-A., Alturki, B., Yafoz, A., Alqahtani, A., Alsini, R., Binyamin, S.-S. Efficient Malicious QR Code Detection System Using an Advanced Deep Learning Approach. Computer Modeling in Engineering &amp; Sciences, 145(1), 1117–1140 (2025). https://doi.org/10.32604/cmes.2025.070745</mixed-citation></citation-alternatives></ref><ref id="cit11"><label>11</label><citation-alternatives><mixed-citation xml:lang="ru">Tian, Y., Zhu, E. Incremental Phishing Defense Method Based on QR Code Decoding and Multimodal Deep Learning. Proceedings of the 2026 5th International Conference on Cryptography, Network Security and Communication Technology, 209–214 (2026). https://doi.org/10.1145/3802927.3802959</mixed-citation><mixed-citation xml:lang="en">Tian, Y., Zhu, E. Incremental Phishing Defense Method Based on QR Code Decoding and Multimodal Deep Learning. Proceedings of the 2026 5th International Conference on Cryptography, Network Security and Communication Technology, 209–214 (2026). https://doi.org/10.1145/3802927.3802959</mixed-citation></citation-alternatives></ref><ref id="cit12"><label>12</label><citation-alternatives><mixed-citation xml:lang="ru">Fauzi, M. A., Yang, B., Hayati, Y. S., Setiawan, B. D., Sari, I. N., Bayona, J., Katuk, N., Dewi, D. A., Surasak, T. Hybrid GCN-LSTM for Privacy-Preserving Fall Detection in Human Pose-Based Elderly Monitoring Systems. Proceedings of the 14th International Conference on Advances in Information Technology, 1–8 (2026). https://doi.org/10.1145/3816713.3819508</mixed-citation><mixed-citation xml:lang="en">Fauzi, M. A., Yang, B., Hayati, Y. S., Setiawan, B. D., Sari, I. N., Bayona, J., Katuk, N., Dewi, D. A., Surasak, T. Hybrid GCN-LSTM for Privacy-Preserving Fall Detection in Human Pose-Based Elderly Monitoring Systems. Proceedings of the 14th International Conference on Advances in Information Technology, 1–8 (2026). https://doi.org/10.1145/3816713.3819508</mixed-citation></citation-alternatives></ref></ref-list><fn-group><fn fn-type="conflict"><p>The authors declare that there are no conflicts of interest present.</p></fn></fn-group></back></article>
