Amulet: Integrating Sensitive Information Access with Identity Authentication on Mobile Devices
Daibo Liu, Yunpeng Feng, Baixing Liu, Taiyuan Zhang, Haowen Chen, Minjie Cai
Abstract
Mobile devices have become essential in people's daily lives, housing vast amounts of sensitive information through installed applications. To maintain security and protect user privacy, continuous user authentication is crucial even after a login session. However, previous studies have left potential vulnerabilities by separating the authentication process from operations involving sensitive information handling on mobile devices. In this paper, we present Amulet, a click-to-access authentication system that integrates access to sensitive information on mobile devices with the user's identity authentication process, providing ongoing protection against potential adversaries. By leveraging the unique physical structure of each user's finger, we capture the vibration response of their implicit identity traits during finger-screen interactions for sensitive information access. These finger-emitted vibrations (FEV) exhibit distinct and consistent characteristics, allowing us to utilize passive FEV traces for continuous user identification throughout an App's login session. To achieve flexible and robust user authentication, we decouple the FEV biometric features from position- and behavior-dependent vibrations. Our deep learning-based authentication system utilizes collected vibration signals, containing FEV characteristics, as input data. To ensure generalizability across diverse use scenarios, we employ a variational auto-encoder (VAE) to generate synthetic data using a limited input dataset. Additionally, we propose a contrastive learning strategy to disentangle identity-related features from behavior/position-related features, enhancing the system's resilience to various use scenarios. Evaluation results demonstrate that Amulet achieves high authentication accuracy with a low false positive rate, while maintaining strong robustness against diverse attack vectors.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 31a048b4-88d5-4695-bfdb-1c632be9af16Related papers
- TouchPass: towards behavior-irrelevant on-touch user authentication on smartphones leveraging vibrationsXiangyu Xu, Jiadi Yu, Yingying Chen, Qin Hua et al.MobiCom 2020 · 101 citations
- VibWrite: Towards Finger-input Authentication on Ubiquitous Surfaces via Physical VibrationJian Liu, Chen Wang, Yingying Chen, Nitesh SaxenaCCS 2017 · 93 citations
- VibPath: Two-Factor Authentication with Your Hand's Vibration Response to Unlock Your PhoneSeokmin Choi, Junghwan Yim, Se Jun Kim, Yincheng Jin et al.UbiComp 2023 · 10 citations
- Velody: Nonlinear Vibration Challenge-Response for Resilient User AuthenticationJingjie Li, Kassem Fawaz, Younghyun KimCCS 2019 · 55 citations
- HandID: Towards Unobtrusive Gesture-independent User Authentication on Smartphones Using Vibration-based Hand BiometricsYuezhong Wu, Wei Song, Chun Tung Chou, Jiankun Hu et al.UbiComp 2025 · 1 citation
