KAPG: Adaptive Password Guessing via Knowledge-Augmented Generation

📅 2025-10-27
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
Existing password-guessing models rely solely on statistical patterns in leaked datasets, neglecting external factors such as sociocultural trends—resulting in poor adaptability to emerging password patterns and low temporal relevance. To address this, we propose KAPSM, the first knowledge-augmented, adaptive password-sequence modeling framework that integrates external knowledge. KAPSM employs a prefix-anchoring mechanism to dynamically inject real-time sociolinguistic trends into generation, synergistically combining internal statistical modeling with external trend awareness. Evaluated across 12 breached datasets, KAPSM achieves average improvements of 74.7% (cross-site) and 36.5% (in-site) in guessing efficiency over state-of-the-art baselines. Furthermore, KAPSM enables trend-aware, fine-grained password strength assessment—introducing a novel paradigm for password security analysis grounded in dynamic, contextual knowledge integration.

Technology Category

Application Category

📝 Abstract
As the primary mechanism of digital authentication, user-created passwords exhibit common patterns and regularities that can be learned from leaked datasets. Password choices are profoundly shaped by external factors, including social contexts, cultural trends, and popular vocabulary. Prevailing password guessing models primarily emphasize patterns derived from leaked passwords, while neglecting these external influences -- a limitation that hampers their adaptability to emerging password trends and erodes their effectiveness over time. To address these challenges, we propose KAPG, a knowledge-augmented password guessing framework that adaptively integrates external lexical knowledge into the guessing process. KAPG couples internal statistical knowledge learned from leaked passwords with external information that reflects real-world trends. By using password prefixes as anchors for knowledge lookup, it dynamically injects relevant external cues during generation while preserving the structural regularities of authentic passwords. Experiments on twelve leaked datasets show that KnowGuess achieves average improvements of 36.5% and 74.7% over state-of-the-art models in intra-site and cross-site scenarios, respectively. Further analyses of password overlap and model efficiency highlight its robustness and computational efficiency. To counter these attacks, we further develop KAPSM, a trend-aware and site-specific password strength meter. Experiments demonstrate that KAPSM significantly outperforms existing tools in accuracy across diverse evaluation settings.
Problem

Research questions and friction points this paper is trying to address.

Adaptively integrates external lexical knowledge into password guessing
Couples internal statistical knowledge with real-world trend information
Addresses limitations of models neglecting external influences on passwords
Innovation

Methods, ideas, or system contributions that make the work stand out.

Integrates external lexical knowledge into password guessing
Couples internal statistical knowledge with external trends
Uses password prefixes as anchors for knowledge lookup
🔎 Similar Papers
No similar papers found.
X
Xudong Yang
University of Electronic Science and Technology of China, Chengdu, China
J
Jincheng Li
University of Electronic Science and Technology of China, Chengdu, China
K
Kaiwen Xing
University of Electronic Science and Technology of China, Chengdu, China
Z
Zhenjia Xiao
University of Electronic Science and Technology of China, Chengdu, China
M
Mingjian Duan
Fudan University, Shanghai, China
Weili Han
Weili Han
Fudan University
Systems SecurityData SecurityAccess ControlPassword SecurityAI Security
Hu Xiong
Hu Xiong
University of Electronic Science and Technology of China, Chengdu, China