Enhancing Android Lock Pattern Security with Personalized Federated Learning and Multi-Modal Framework
Sina Apak, Peri Güneş · 2025
The Android Lock Pattern is a popular authentication technique because of its simplicity, ease, and security. Nonetheless, this authentication mechanism is vulnerable to several attacks including man-in-the-middle (MITM) attacks, spoofing, and identity impersonation. This study presents an innovative multimodal framework designed to detect anomalous behaviors and fortify Android lock pattern authentication. This method is highly effective in countering advanced threats such as man-in-the-middle (MITM) attacks, spoofing, and identity impersonation attempts. The proposed framework consists of two core components that work together: (1) a Long Short-Term Memory (LSTM) attention autoencoder that analyzes network traffic for abnormal timing patterns and (2) a Neural Architecture Search (NAS) optimized MobileNetV3 model that l generates heatmaps to capture lock pattern characteristics. A multimodal deep learning technique fuses these features to create a unique profile for each individual within the personalized Federated Learning (PFL) framework. This method improves anomaly detection precision by tailoring model training to the specific behaviors of individual clients while concurrently safeguarding data privacy via localized model training on each client's device. Experimental results prove the framework's exceptional performance in multimodal settings, achieving accuracies of 99.17%, 97.0%, and 99.0% for the detection of touch logging, fake lock screens, and shoulder surfing attacks, respectively. Furthermore, we evaluated the framework's efficacy in recognizing software-based threats using the CICMalDroid 2020 Android malware public dataset. The framework achieved an accuracy of 98.0%, comparable to state-of-the-art algorithms, demonstrating its adaptability in tackling various types of threats. These results highlight the framework's robustness and scalability, offering a comprehensive and adaptable solution to emerging security threats in Android authentication systems.