K-means++ vs. Behavioral Biometrics: One Loop to Rule Them All
Parimarjan Negi, Prafull Sharma, Vivek Jain, Bahman Bahmani
Abstract
Behavioral biometrics, a field that studies patterns in an individual's unique behavior, has been researched actively as a means of authentication for decades. Recently, it has even been adopted in many real world scenarios. In this paper, we study keystroke dynamics, the most researched of such behavioral biometrics, from the perspective of an adversary. We designed two adversarial agents with a standard accuracy convenience tradeoff: Targeted K-means++, which is an expensive, but extremely effective adversarial agent, and Indiscriminate K-means++, which is slightly less powerful, but adds no overhead cost to the attacker. With Targeted K-means++ we could compromise the security of 40-70% of users within ten tries. In contrast, with Indiscriminate K-means++, the security of 30-50% of users was compromised. Therefore, we conclude that while keystroke dynamics has potential, it is not ready for security critical applications yet. Future keystroke dynamics research should use such adversaries to benchmark the performance of the detection algorithms, and design better algorithms to foil these. Finally, we show that the K-means++ adversarial agent generalizes well to even other types of behavioral biometrics data by applying it on a dataset of touchscreen swipes.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext fb567ef6-848a-4860-8e8e-79fc2563224fCited by top-tier papers4
- Velody: Nonlinear Vibration Challenge-Response for Resilient User AuthenticationJingjie Li, Kassem Fawaz, Younghyun KimCCS 2019 · 55 citations
- How to Attack and Generate HoneywordsDing Wang, Yunkai Zou, Qiying Dong, Yuanming Song et al.S&P 2022 · 45 citations
- "Get in Researchers; We're Measuring Reproducibility": A Reproducibility Study of Machine Learning Papers in Tier 1 Security ConferencesDaniel Olszewski, Allison Lu, Carson Stillman, Kevin Warren et al.CCS 2023 · 19 citations
- Pass2Edit: A Multi-Step Generative Model for Guessing Edited PasswordsDing Wang, Yunkai Zou, Yuan-an Xiao, Siqi Ma et al.USENIX Security 2023
Builds on1
Related papers
- Leveraging Biometric-Rich Hand Gestures for Head-Mounted Display AuthenticationAmin Jalilov, Eunyong Cheon, Ian OakleyCHI 2026 · 1 citation
- Multi-touch Authentication Using Hand Geometry and Behavioral InformationYunpeng Song, Zhongmin Cai, Zhi-Li ZhangS&P 2017 · 98 citations
- Exploring the Effect of Music on User Typing and Identification through Keystroke DynamicsLukas Mecke, Assem Mahmoud, Simon Marat, Florian AltCHI 2025 · 1 citation
- When Your Fitness Tracker Betrays You: Quantifying the Predictability of Biometric Features Across ContextsSimon Eberz, Giulio Lovisotto, Andrea Patane, Marta Kwiatkowska et al.S&P 2018 · 29 citations
- SemanticAction: A Semantic-Driven and Behavior-Aware Password Framework for Adaptive VR Authentication Under Observation AttacksTingjie Wan, Yalin Deng, Chunlin Wang, Jian Pan et al.IEEE VR 2026
