Behavior-manipulation attacks, such as fake virus alerts, scareware, and deceptive software downloads, work by showing users something alarming or enticing. What these pages look like is often more telling than their code or URL. PP3D builds on the behavioral indicators from our measurement work to turn that observation into a practical defense.
From discovery to defense
PP3D has three parts:
- Discovery. Instrumented browsers on different device types visit suspicious pages. The screenshots are clustered and labeled to build an attack dataset.
- Detection. A multimodal model combines visual features from a MobileNetV3 image encoder with text features from OCR-extracted page text (BERT-mini) to classify a screenshot.
- Defense. The model is converted to run entirely in the browser, with ONNX Web Runtime for the model and Tesseract.js (WASM) for OCR, so pages are checked locally.
Key findings
- Over 99% detection at a 1% false-positive rate.
- Detection runs locally in the browser, preserving user privacy: screenshots never leave the device.