A Quantitative Analysis of User Interaction and Security Behaviour with Quick Response (QR) Codes
DOI:
https://doi.org/10.3991/ijim.v20i14.61501Keywords:
Quick Response Code, Observational Research, QR Code Engagement, Naturalistic ObservationAbstract
The abundance of quick response (QR) codes in our environments is increasing, yet limited observational research has examined if and how users engage with QR codes in public spaces. Moreover, previous research has relied on estimated measures of visitor traffic to an area, limiting our understanding of real-world QR code-engagement behaviour. The present study addresses this gap, combining entry and exit data with naturalistic observation to examine QR code-engagement behaviour in a UK university library. Of the 7356 people who entered the space where the QR code was displayed, 58 (0.79%) approached the QR code and only 22 (0.30%) scanned it. The QR code directed users to an online questionnaire which measured users’ reasons for scanning the QR code and any security precautions users took when interacting with the QR code. The questionnaire revealed that the scanning incentive and curiosity were influential motivators for engagement. Only five users checked the website URL and took security precautions before accessing the link. Thirty-six (0.49%) individuals approached the QR code but did not scan it. Nine of those individuals completed an additional questionnaire after being approached by the researcher, which highlighted effort, inconvenience, and disinterest in the incentive as being influential factors in their decision not to scan. This paper suggests that QR code-engagement behaviour in public settings is low and users generally do not consider security whilst interacting with QR code technology.
References
[1] S. Tiwari, “An introduction to QR code technology,” in Proc. Int. Conf. on Information Technology (ICIT), 2016, pp. 39-44. https://doi.org/10.1109/ICIT.2016.021
[2] A. S. Rafsanjani, N. B. Kamaruddin, H. M. Rusli, and M. Dabbagh, “Qsecr: Secure qr code scanner according to a novel malicious url detection framework ,” IEEE Access, vol. 11, pp. 92523-92539, 2023, https://doi.org/10.1109/ACCESS.2023.3291811
[3] L. J. L. Bekavac, S. Mayer, and J. Strecker, “QR-code integrity by design,” in Proc. Extended Abstracts of the CHI Conference on Human Factors in Computing Systems, 2024, pp. 1-9. https://doi.org/10.1145/3613905.3651006
[4] A. L. Hupp, H. M. Schroeder, B. T. West, E. Leissou, and D. R. Weir, “Who chooses a QR code over a URL to access a web screener in a national probability survey of older adults, and the impact on data quality,” Survey Methods: Insights from the Field (SMIF), vol. 3, no. 1, pp. 20208, 2025, https://doi.org/10.13094/SMIF-2025-00003
[5] T. Vidas, E. Owusu, S. Wang, C. Zeng, L. F. Cranor, and N. Christin, “ QRishing: The susceptibility of smartphone users to QR code phishing attacks,” in Proc. Int. Conf. on Financial Cryptography and Data Security, 2013, pp. 52-69. https://doi.org/10.1007/978-3-642-41320-9_4
[6] F. Sharevski, M. Mossano, M. Veit, G. Schiefer, and M. Volkamer, “Exploring phishing threats through qr codes in naturalistic settings,” in Proc. Symp. on Usable Security and Privacy (USEC), 2024, pp. 1-25. https://doi.org/10.14722/usec.2024.23050
[7] J.D. Still, T. Morris, and M. Edwards, “Investigating university QR code interactions,” in Proc. Int. Conf. on Human-Computer Interaction, 2024, pp. 204-214. https://doi.org/10.1007/978-3-031-61382-1_13
[8] M. Geisler, and D. Pöhn, “Hooked: a real-world study on QR code phishing,” arXiv preprint, 2024, [Online]. Available: https://doi.org/10.48550/arXiv.2407.16230. Accessed: 10th January 2026.
[9] aira-ly11-studio. “Red bold formal payment QR code poster.” Canva. Accessed September 2025. [Online]. Available: https://www.canva.com
[10] Qualtrics. “Qualtrics,” [Online]. Available: https://www.qualtrics.com/en-gb/. Accessed 1st September 2025.
[11] A. Tayachi, B. Ouni, A. Mourad, and A. Erbad, “Quishing attack detection and mitigation using machine learning and deep learning for malicious URL identification, “ in Proc. 2025 International Wireless Communications and Mobile Computing (IWCMC), 2025, pp. 1709-1713. https://doi.org/10.1109/IWCMC65282.2025.11059621
[12] E. Pricop, and S.F. Mihalache, “Quishing- a review of QR code attacks and a framework design for safe scanning”, in Proc. Int. Conf. on Emerging Trends and Technologies on Intelligent Systems, vol. 1591, 2025, pp. 284-296. https://doi.org/10.1007/978-981-95-0681-1_24
[13] T. Ramsey, “Quishing scams warning: how to spot and avoid dodgy QR codes”, Which? [online]. Available: https://www.which.co.uk/news/article/quishing-scams-warning-how-to-spot-and-avoid-dodgy-qr-codes-asYsH0h6jjP1. Accessed: 24th April, 2026.
[14] A. Bimantara, and R.T. Nugraha, “The politics of international cooperation in cross-border digital payment connectivity: a case study of QR payment system in ASEAN,” Sospol, vol. 11, no. 1, pp. 82-99, 2025, https://doi.org/10.22219/jurnalsospol.v11i1.38367
Downloads
Published
How to Cite
Issue
Section
License
Copyright (c) 2026 Elena Ball, Lara Warmelink, Sophie Nightingale, Trevor Crawford

This work is licensed under a Creative Commons Attribution 4.0 International License.

