Digital documents in modern organizations are highly vulnerable to content and metadata manipulation such as modifications to the author name, creation date, and document status which can be altered illegally without detection by conventional systems. This research implements a PDF document integrity verification method that integrates SHA-256 cryptographic hash computation with QR Code visualization using a Hybrid Verification Architecture. The proposed approach works by representing the document binary content and metadata in a sorted canonical string, computing the SHA-256 hash as a document fingerprint before the QR Code is embedded into the PDF, and embedding the hash into a QR Code with Error Correction Level H (30% recovery rate). The hybrid verification architecture employs Two-Layer Hash Verification: (1) QR Code integrity check to detect the presence or absence of QR Code, and (2) hash-to-storage comparison to match the hash extracted from the QR Code against the Local Hash Storage. In the current system version, the PDF content hash is not recomputed during verification; the system focuses on matching the QR hash with the stored hash. Empirical testing was conducted using 75 automated scenarios across 7 testing categories using a synthetic controlled dataset generated programmatically via pdf-lib: valid PDFs, metadata tampering, content modification, QR replacement, QR replay, control PDFs without QR Code, and corrupted QR codes. Results show an overall accuracy of 86.67% (65/75 correct), with 100% detection rate on 6 out of 7 testing categories. The content modification category (0% detection, 10 false positives, FPR 18.18%) is documented as a structural limitation of the current architecture, as the QR hash still matches the stored hash when only content is modified.
Copyrights © 2026