RankGuess: Password Guessing Using Adversarial Ranking
Tao Yang, Ding Wang
摘要
The understanding of password security highly relates to our knowledge of how adversaries guess passwords, and this makes the modeling of guessing attacks a pivotal task. To maximize guessing effectiveness, the adversary generally attempts to guess in descending order of likelihood, akin to the way generative retrieval learning-to-rank works in a recommendation system, which prioritizes information to targeted users based on predicted relevance. In this paper, we propose a password guessing framework based on adversarial ranking, named RankGuess. We regard the password creation process as sequential decision trajectories. In this context, the adversary is assumed to train an agent where the current state is represented by the password sequence generated up to that point. The action taken is to generate the next token, and the evaluation score assigned by the ranker serves as the reward signal received. Consequently, we frame the problem of password guessing as a Markov Decision Process and tackle it using adversarial ranking techniques. Due to the generality of our framework, RankGuess can be applicable to various guessing scenarios (i.e., trawling guessing, targeted password guessing based on personally identifiable information (PII), and conditional password guessing). By employing 12 large-scale password datasets and six PII datasets, we demonstrate that our models are effective: (1) RankGuess surpasses all current state-of-the-art models and outperforms GAN-based methods by 26.29% 43.69% (avg. 34.80%); (2) When the victim's PII at site (namely PIIA) is known, RankGuess-PII for targeted password guessing based on PIIA, which guesses 58.21% 91.95% of common users within 1012 guesses, outperforms its foremost counterparts by 6.32% 17.09%; (3) Within 107 guesses, our RankGuess-Mask based on victims' partial passwords (e.g., d**102), improves the password cracking success rates by 7.70% 14.85% (avg. 8.21%) compared to its state-of-the-art counterparts. The paper provides a new technical approach to a well-known challenge in the password-guessing field.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper4
- Success Rates Doubled with Only One Character: Mask Password GuessingYunkai Zou, Ding Wang, Fei DuanNDSS 2026 · 被引用 1 次
- Password Guessing Using Large Language ModelsYunkai Zou, Maoxiang An, Ding WangUSENIX Security 2025
- CoT-DPG: A Co-Training based Dynamic Password Guessing MethodChenyang Wang, Fan Shi, Min Zhang, Chengxi Xu 等NDSS 2026
- MoPE: A Mixture of Password Experts for Improving Password GuessingMingjian Duan, Ming Xu, Shenghao Zhang, Weili HanS&P 2026
它引用的顶会 Paper27
- Unsupervised Data Augmentation for Consistency TrainingQizhe Xie, Zihang Dai, Eduard H. Hovy, Thang Luong 等NeurIPS 2020 · 被引用 2,774 次
- Scaling Laws for Reward Model OveroptimizationLeo Gao, John Schulman, Jacob HiltonICML 2023 · 被引用 963 次
- Targeted Online Password Guessing: An Underestimated ThreatDing Wang, Zijian Zhang, Ping Wang, Jeff Yan 等CCS 2016 · 被引用 385 次
- Fast, Lean, and Accurate: Modeling Password Guessability Using Neural NetworksWilliam Melicher, Blase Ur, Sean M. Segreti, Saranga Komanduri 等USENIX Security 2016 · 被引用 331 次
- zxcvbn: Low-Budget Password Strength EstimationDaniel Lowe WheelerUSENIX Security 2016 · 被引用 243 次
相关 Paper
- Password Guessing Using Random ForestDing Wang, Yunkai Zou, Zijian Zhang, Kedong XiuUSENIX Security 2023
- MAYA: Addressing Inconsistencies in Generative Password Guessing Through a Unified BenchmarkWilliam Corrias, Fabio De Gaspari, Dorjan Hitaj, Luigi V. ManciniS&P 2026 · 被引用 1 次
- Targeted Password Guessing Using k-Nearest NeighborsZhen Li, Ding WangNDSS 2026 · 被引用 2 次
- Improving Password Guessing via Representation LearningDario Pasquini, Ankit Gangwal, Giuseppe Ateniese, Massimo Bernaschi 等S&P 2021 · 被引用 101 次
- A Security Analysis of HoneywordsDing Wang, Haibo Cheng, Ping Wang, Jeff Yan 等NDSS 2018 · 被引用 1,102 次
