Passtrans: an Improved Password Reuse Model Based on Transformer

Xiaoxi He,Haibo Cheng,Jiahong Xie,Ping Wang,Kaitai Liang
DOI: https://doi.org/10.1109/icassp43922.2022.9746731
2022-01-01
Abstract:Passwords have been widely used in online authentication, and they form the front line that protects our data security and privacy. But the security of password may be easily harmed by insecure password generator. Massive reports state that users are always keen to generate new passwords by reusing or fine-tuning old secrets. Once an old password is leaked, the users may suffer from credential tweaking attacks. We propose a password reuse model PassTrans and simulate credential tweaking attacks. We evaluate the performance in leaked password datasets, and the results show that 67.51% of accounts is breakable under 1,000 guesses, indicating our model is accurate in capturing password reuse behavior.
What problem does this paper attempt to address?