BanglaQR-Quish: A Balanced Synthetic QR Image Dataset for Quishing Analysis in Bangla QR Payment Systems
Description
--------------------------------------------------------------------- 1. DATASET DESCRIPTION --------------------------------------------------------------------- BanglaQR-Quish contains 50,000 unique synthetic QR-code images created for research on quishing attacks in Bangla QR payment systems. The dataset is equally divided into 25,000 benign and 25,000 malicious images. The benign QR codes represent synthetic static merchant payment payloads containing merchant information, merchant category, city, country code, currency code, and provider-style account information. The malicious QR codes were generated from benign payloads using two attack scenarios: provider identifier manipulation and payment redirection. The dataset is designed for QR-code classification, quishing detection, computer vision, machine learning, deep learning, and digital payment security research. --------------------------------------------------------------------- 2. CLASS DISTRIBUTION (Total: 50,000 Images) --------------------------------------------------------------------- 1. BENIGN (25,000 images): - Valid synthetic merchant payment QR codes. 2. MALICIOUS (25,000 images): - Structurally valid and scannable modified QR codes. - provider_gui_url_injection: 12,500 images. - payment_redirection: 12,500 images. Five provider-style families are included: bKash, Nagad, TallyPay, Mutual Trust Bank, and DBBL/NexusPay. Each family contains 5,000 benign, 2,500 URL-injection, and 2,500 payment-redirection images. --------------------------------------------------------------------- 3. FILE STRUCTURE & COLUMNS --------------------------------------------------------------------- Folders and Files: A. benign/ Contains 25,000 benign PNG images. B. malicious/ Contains 25,000 malicious PNG images. C. metadata.csv Contains information for all 50,000 images. D. README.txt Describes the dataset, labels, files, and possible uses. metadata.csv Columns: A. image_name: Unique identifier of the QR-code image. B. label: Classification label: benign or malicious. C. attack_type: benign_valid, provider_gui_url_injection, or payment_redirection. D. provider_family: bkash, nagad, tallypay, mtb, or dbbl_nexuspay. E. source_benign_image_name: Identifies the benign source used to generate a malicious image. This field is empty for benign samples.
Files
Steps to reproduce
--------------------------------------------------------------------- 4. METHODOLOGY --------------------------------------------------------------------- 1. Installed Python and the required libraries, including qrcode and Pillow. Installed ZXing-C++ for QR-code verification. 2. Generated 25,000 synthetic benign payment payloads using the five provider-style templates: bKash, Nagad, TallyPay, Mutual Trust Bank, and DBBL/NexusPay. 3. Constructed each payload using a tag-length-value structure containing synthetic merchant information, merchant category, city, country code, currency code, and provider-style account information. 4. Generated 25,000 malicious payloads from the benign payloads: - Replaced the provider identifier with a safe synthetic test URL for provider_gui_url_injection. - Replaced merchant, receiver, account, store, or reference fields with synthetic attacker-like values for payment_redirection. 5. Recalculated the checksum after each modification. Removed duplicate or invalid payloads and retained only unique, structurally valid samples. 6. Converted each payload into a PNG image using: - QR Version: 11 - Error correction level: M - Matrix size: 61 × 61 modules - Box size: 10 - Border size: 4 - Image size: 690 × 690 pixels - Black foreground and white background 7. Stored the generated images in the benign/ and malicious/ folders. 8. Created metadata.csv with the following columns: image_name, label, attack_type, provider_family, and source_benign_image_name. 9. Decoded every generated image using ZXing-C++ and compared the decoded content with its original source payload. Retained only correctly decoded and matching images.
Institutions
- Green University of BangladeshDhaka Division, Dhaka
- North South UniversityDhaka Division, Dhaka
- Pabna University of Science and TechnologyRajshahi Division, Pābna