Modeling Password Guessability via Variational Auto-Encoder

Jinwei Wang, Yong Li, Xi Chen, Yongbin Zhou · 2021

Human-chosen text passwords remain an important form of authentication. To better understand properties of passwords chosen by users and password guessing models adopted by attackers, a lot of researches on password guessing are carried out. In recent studies, people try to guess passwords through deep learning models. However, existing deep learning-based guessing models (such as RNN and GAN) show unsatisfactory performance under limited guesses. In this paper, we propose PGVAE, a password guessing model based on variational autoencoder. The model can learn highly structured and continuous latent representations of passwords and then generate highquality candidate guesses. The effectiveness of PGVAE is verified in multiple leaked dataset. Results show that our model is capable of modeling the guessability of passwords, detecting vulnerable passwords and strengthening the security of authentication systems.

Read the paper · More papers on PaperTik