USENIX Security2023Top-tier venue
Improving Real-world Password Guessing Attacks via Bi-directional Transformers
Ming Xu, Jitao Yu, Xinyi Zhang, Chuanwang Wang, Shenghao Zhang, Haoqi Wu, Weili Han
Abstract
Password guessing attacks, prevalent issues in the real world, can be conceptualized as efforts to approximate the probability distribution of text tokens. Techniques in the natural language processing (NLP) field naturally lend themselves to password guessing. Among them, bi-directional transformers stand out with their ability to utilize bi-directional contexts to capture the nuances in texts. To further improve password guessing attacks, we propose a bi-directional-transformer-based guessing framework, referred to as PassBERT, which applies the pre-training / finetuning paradigm to password guessing attacks. We first prepare a pre-trained password model, which contains the knowledge of the general password distribution. Then, we design three attack-specific fine-tuning approaches to tailor the pretrained password model to the following real-world attack scenarios: (1) conditional password guessing, which recovers the complete password given a partial password; (2) targeted password guessing, which compromises the password(s) of a specific user using their personal information; (3) adaptive rule-based password guessing, which selects adaptive mangling rules for a word (i.e., base password) to generate rule-transformed password candidates. The experimental results show that our fine-tuned models can outperform the state-of-the-art models by 14.53%, 21.82% and 4.86% in the three attacks, respectively, demonstrating the effectiveness of bi-directional transformers on downstream guessing attacks. Finally, we propose a hybrid password strength meter to mitigate the risks from the three attacks.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 7aed3b33-31af-48d4-beb9-73e6010db33dCited by top-tier papers10
- The Impact of Exposed Passwords on Honeyword EfficacyZonghao Huang, Lujo Bauer, Michael K. ReiterUSENIX Security 2024 · 7 citations
- PreAcher: Secure and Practical Password Pre-Authentication by Content Delivery NetworksShihan Lin, Suting Chen, Yunming Xiao, Yanqi Gu et al.NSDI 2025 · 2 citations
- Targeted Password Guessing Using k-Nearest NeighborsZhen Li, Ding WangNDSS 2026 · 2 citations
- Success Rates Doubled with Only One Character: Mask Password GuessingYunkai Zou, Ding Wang, Fei DuanNDSS 2026 · 1 citation
- MAYA: Addressing Inconsistencies in Generative Password Guessing Through a Unified BenchmarkWilliam Corrias, Fabio De Gaspari, Dorjan Hitaj, Luigi V. ManciniS&P 2026 · 1 citation
Builds on13
- Targeted Online Password Guessing: An Underestimated ThreatDing Wang, Zijian Zhang, Ping Wang, Jeff Yan et al.CCS 2016 · 385 citations
- Fast, Lean, and Accurate: Modeling Password Guessability Using Neural NetworksWilliam Melicher, Blase Ur, Sean M. Segreti, Saranga Komanduri et al.USENIX Security 2016 · 331 citations
- zxcvbn: Low-Budget Password Strength EstimationDaniel Lowe WheelerUSENIX Security 2016 · 243 citations
- Protecting accounts from credential stuffing with password breach alertingKurt Thomas, Jennifer Pullman, Kevin Yeo, Ananth Raghunathan et al.USENIX Security 2019 · 154 citations
- Improving Password Guessing via Representation LearningDario Pasquini, Ankit Gangwal, Giuseppe Ateniese, Massimo Bernaschi et al.S&P 2021 · 101 citations
Related papers
- Password Guessing Using Large Language ModelsYunkai Zou, Maoxiang An, Ding WangUSENIX Security 2025
- Backdoor Pre-trained Models Can Transfer to AllLujia Shen, Shouling Ji, Xuhong Zhang, Jinfeng Li et al.CCS 2021 · 72 citations
- Can Foundation LLMs Accurately Estimate Password Strength and Provide Appropriate Password Feedback?Madison Pickering, Garrison Hinson-Hasty, Luca Dovichi, Helena Williams et al.S&P 2026
- Chunk-Level Password Guessing: Towards Modeling Refined Password Composition RepresentationsMing Xu, Chuanwang Wang, Jitao Yu, Junjie Zhang et al.CCS 2021 · 32 citations
- Password Guessing Using Random ForestDing Wang, Yunkai Zou, Zijian Zhang, Kedong XiuUSENIX Security 2023
