"Your Eyes Say You Have Used This Password Before": Identifying Password Reuse from Gaze Behavior and Keystroke Dynamics

Eye Tracking & Gaze InteractionPasswords & Authentication

Paper Title

"Your Eyes Tell You Have Used This Password Before": Identifying Password Reuse from Gaze and Keystroke Dynamics

Paper Information

  • Research Area: Usable Security, User Authentication, Behavioral Biometrics
  • Keywords: Password reuse, eye tracking, keystroke dynamics, machine learning, security enhancement, biometric authentication, user behavior analysis, password strength, data sensitivity

Research Background and Problem Statement

  • Identified Problems or Challenges:
    The widespread use of passwords as an authentication method has made password reuse a significant security vulnerability. If reused passwords are leaked, attackers can easily gain access to other user accounts. Additionally, many users lack trust in password managers, exacerbating the issue. Existing password reuse detection methods primarily rely on literal password comparisons or user notifications, but these techniques fail to address real-time intervention during password creation.

  • Significance:
    Password reuse is considered a critical security issue in authentication, potentially leading to severe data breaches or cross-account attacks. Detecting password reuse and providing real-time intervention can effectively enhance users' password security.

  • Research Motivation and Related Work:
    Existing password reuse detection techniques, such as keystroke dynamics, have limited accuracy and typically require waiting until the user completes input. The authors propose leveraging eye tracking (users' visual behavior patterns) to improve the accuracy of password reuse detection while reducing potential security risks. Previous research has shown that users' visual behavior during password creation is related to cognitive load, suggesting that such behavior can be used to identify password strength or reuse.

Proposed Solution

  • Method or Solution:
    The authors propose combining users' eye tracking data with keystroke dynamics data and using machine learning techniques to detect whether a password is newly created or reused. The study analyzes data collected during different stages of the password registration process.

  • Innovations:

    • Eye tracking data alone can detect password reuse in real-time during registration (without accessing the actual password content).
    • A multi-stage machine learning model based on user behavior data (e.g., gaze features and keystroke dynamics) is proposed.
    • The study compares the impact of sensitive data (e.g., email clients) and non-sensitive data (e.g., news websites) to demonstrate how data sensitivity affects user behavior and password reuse.
  • Implementation Steps and Key Techniques:

    1. Data Collection: Eye tracking and keystroke dynamics data were collected from 49 participants who registered accounts in two scenarios (email client and news website).
    2. Feature Extraction: Features such as gaze behavior (e.g., fixation duration, saccade distance) and keystroke dynamics (e.g., flight time and input intervals) were extracted.
    3. Classifier Construction: Machine learning models, including Support Vector Machine (SVM), decision trees, and random forests, were trained. The classifiers used eye tracking data, keystroke data, and combined data to predict whether a password was reused.
    4. Stage Division: The registration process was divided into four stages (interface browsing, identity input, password input, password confirmation) to analyze their relationship with password reuse prediction.

Research Findings

  • Specific Results:

    • Using eye tracking data alone achieved a password reuse detection accuracy of 88.75%, outperforming keystroke dynamics data (75.8%).
    • When combining eye tracking and keystroke data, the classifier achieved a peak accuracy of 88.75%, demonstrating robust performance across all stages of password registration.
    • The experiments showed that even before users began typing passwords, gaze behavior data could predict reuse behavior with an accuracy of 86%.
  • Advantages:

    • Early Intervention: Unlike traditional models relying on keystroke dynamics, the gaze behavior model can predict reuse risks before password input begins, enabling effective real-time intervention.
    • Data Independence: Predictions are made solely based on behavioral data without accessing users' actual passwords, reducing privacy risks.
  • Experimental and Evaluation Results:

    • Across two interface types (email client and news website), gaze features performed better in high-sensitivity scenarios.
    • Observing users' visual trajectories revealed that when reusing passwords, users exhibited significantly fewer keyboard fixations and lower cognitive load.
  • Limitations and Future Directions:

    • Limitations:
      • The sample size was relatively small (49 participants), requiring more data to validate the model's generalizability.
      • Certain variables, such as users' "truthful responses" to password reuse questions, could not be fully verified.
      • The influence of interface characteristics and interaction methods on results has not been thoroughly explored.
    • Future Directions:
      • Explore cross-device and cross-interface behavior prediction models, such as differences between mobile and desktop platforms.
      • Develop real-time prediction-based interactive intervention systems to help users create more secure passwords.
      • Expand physiological feature datasets, including user stress levels and gaze pattern distributions.

Conclusion

This paper introduces a novel technical approach for real-time password reuse detection by integrating gaze behavior and keystroke dynamics into a data analysis model. The study demonstrates accurate prediction capabilities across all stages of password registration, paving the way for the development of new real-time intervention measures. This approach has the potential to enhance users' password security significantly while reducing the complexity of password management.

Quick Actions

Share

Share this page

ios_share

https://hci.top/en/papers/chi/72183/2022

AdRecommended

Learn AI Coding at CodeNow

open_in_newOpen DOI Link
DOI: https://dl.acm.org/doi/abs/10.1145/3491102.3517531
At a Glance

Paper Snapshot

fact_check
dataset
Source
CHI
calendar_month
Year
2022
emoji_events
Award
No award tagged
group
Authors
7 authors
sell
Subtopics
Eye Tracking & Gaze Interaction, Passwords & Authentication
work
Professions
—
article
Content Status
Full text indexed
hub
Related Papers
4 related papers