Modeling Password Guessability via Variational Auto-Encoder
Jinwei Wang, Yong Li, Xi Chen, Yongbin Zhou · 2021
Human-chosen text passwords remain an important form of authentication. To better understand properties of passwords chosen by users and password guessing models adopted by attackers, a lot of researches on password guessing are carried out. In recent studies, people try to guess passwords through deep learning models. However, existing deep learning-based guessing models (such as RNN and GAN) show unsatisfactory performance under limited guesses. In this paper, we propose PGVAE, a password guessing model based on variational autoencoder. The model can learn highly structured and continuous latent representations of passwords and then generate highquality candidate guesses. The effectiveness of PGVAE is verified in multiple leaked dataset. Results show that our model is capable of modeling the guessability of passwords, detecting vulnerable passwords and strengthening the security of authentication systems.