arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

MindReader:使用大语言模型促进可记忆且安全的密码替换

MindReader: Using LLMs to Encourage Memorable and Secure Password Replacement

Anna Gerchanovsky, Lujo Bauer, Michael K. Reiter

arXiv 2607.12148首次发表:更新:

AI 中文总结

研究旨在帮助用户安全替换密码,MindReader利用大语言模型,通过推断原密码组件含义来建议语义相关但句法无关的新密码组件,经用户研究验证其创建的密码更安全且记忆性相当。

AI 中文摘要

我们报告了MindReader的设计与评估,它是一种在用户需要时帮助其替换密码的工具。若让用户自行选择,他们倾向于用原始密码的可预测变体来替换。MindReader利用大语言模型来建议密码变体,这些变体对用户来说易于记忆,但对攻击者而言更难预测。为此,MindReader推断原始密码组件背后的含义,然后为新密码建议语义相关(但句法无关)的组件。在一项用户研究中,使用MindReader创建的密码比不使用它创建的替换密码以及原始密码都更安全。特别是,即使攻击者知晓原始密码和工具实现的全部信息,MindReader替换密码在在线攻击中也比其他替换密码更难被猜出。用MindReader创建的密码在用户创建密码一周后成功登录的能力方面,与其他替换密码和原始密码相当。

英文摘要

We report on the design and evaluation of MindReader, a tool that helps a user replace her password when she is required to do so. Left to their own devices, users tend to replace their previous passwords with predictable variations of the original ones. MindReader leverages LLMs to suggest password variations that are chosen to be easy for the user to remember but harder for an attacker to predict. To do this, MindReader infers the meaning behind original password components and then suggests semantically related (yet syntactically unrelated) components for the new password. In a user study, passwords created using MindReader were more secure than both replacement passwords created without using MindReader and original passwords. In particular, MindReader replacement passwords were harder to guess in an online attack than alternative replacement passwords even by an attacker with knowledge of the original password and full knowledge of the tool implementation. Passwords created with MindReader were also comparably memorable to alternative replacement passwords and original passwords, as measured by the ability of users to successfully log in a week after creating their password.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑