A Keystroke Dynamics Approach with Ergonomic and Sentiment Safeguards
Dai-Long Ngo-Hoang · 2025
According to the 2024 ENISA Threat Landscape report, 71% of phishing kits embed JavaScript keyloggers, contributing to $4.8 billion in global losses. We propose AIMK, an on-device input method editor (IME) integrating: (i) a lightweight Isolation Forest (100 trees, 8 MB int8) using 34 keystroke dynamics (KD) features, (ii) a decoy keyboard for keylogger/rootkit detection, (iii) a SentimentGuard module for stress/anger detection, (iv) NASA-TLX-based ergonomic prompts, and (v) STIX/TAXII webhooks for real-time SOC/CERT alerts. In a 30-day study with 104 participants (7.86M keystroke events), AIMK detected impostors after 25 keystrokes (F 1 = 0.915 ± 0.023), blocked 100% of user-mode keyloggers and 66% of kernel rootkits, and reduced time-to-detect to 4.1 s versus 87 s for mobile antivirus. A banking pilot prevented $37,000 in fraudulent transactions, with 1.9% additional daily battery drain. The KD engine (Apache 2.0) and AIMKD52 dataset (CC BY-NC 4.0) are publicly available.