KAPG: Adaptive Password Guessing via Knowledge-Augmented Generation

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Yang, Xudong, Li, Jincheng, Xing, Kaiwen, Xiao, Zhenjia, Duan, Mingjian, Han, Weili, Xiong, Hu
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866908614260686848
author Yang, Xudong
Li, Jincheng
Xing, Kaiwen
Xiao, Zhenjia
Duan, Mingjian
Han, Weili
Xiong, Hu
author_facet Yang, Xudong
Li, Jincheng
Xing, Kaiwen
Xiao, Zhenjia
Duan, Mingjian
Han, Weili
Xiong, Hu
contents As the primary mechanism of digital authentication, user-created passwords exhibit common patterns and regularities that can be learned from leaked datasets. Password choices are profoundly shaped by external factors, including social contexts, cultural trends, and popular vocabulary. Prevailing password guessing models primarily emphasize patterns derived from leaked passwords, while neglecting these external influences -- a limitation that hampers their adaptability to emerging password trends and erodes their effectiveness over time. To address these challenges, we propose KAPG, a knowledge-augmented password guessing framework that adaptively integrates external lexical knowledge into the guessing process. KAPG couples internal statistical knowledge learned from leaked passwords with external information that reflects real-world trends. By using password prefixes as anchors for knowledge lookup, it dynamically injects relevant external cues during generation while preserving the structural regularities of authentic passwords. Experiments on twelve leaked datasets show that KnowGuess achieves average improvements of 36.5\% and 74.7\% over state-of-the-art models in intra-site and cross-site scenarios, respectively. Further analyses of password overlap and model efficiency highlight its robustness and computational efficiency. To counter these attacks, we further develop KAPSM, a trend-aware and site-specific password strength meter. Experiments demonstrate that KAPSM significantly outperforms existing tools in accuracy across diverse evaluation settings.
format Preprint
id arxiv_https___arxiv_org_abs_2510_23036
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle KAPG: Adaptive Password Guessing via Knowledge-Augmented Generation
Yang, Xudong
Li, Jincheng
Xing, Kaiwen
Xiao, Zhenjia
Duan, Mingjian
Han, Weili
Xiong, Hu
Cryptography and Security
As the primary mechanism of digital authentication, user-created passwords exhibit common patterns and regularities that can be learned from leaked datasets. Password choices are profoundly shaped by external factors, including social contexts, cultural trends, and popular vocabulary. Prevailing password guessing models primarily emphasize patterns derived from leaked passwords, while neglecting these external influences -- a limitation that hampers their adaptability to emerging password trends and erodes their effectiveness over time. To address these challenges, we propose KAPG, a knowledge-augmented password guessing framework that adaptively integrates external lexical knowledge into the guessing process. KAPG couples internal statistical knowledge learned from leaked passwords with external information that reflects real-world trends. By using password prefixes as anchors for knowledge lookup, it dynamically injects relevant external cues during generation while preserving the structural regularities of authentic passwords. Experiments on twelve leaked datasets show that KnowGuess achieves average improvements of 36.5\% and 74.7\% over state-of-the-art models in intra-site and cross-site scenarios, respectively. Further analyses of password overlap and model efficiency highlight its robustness and computational efficiency. To counter these attacks, we further develop KAPSM, a trend-aware and site-specific password strength meter. Experiments demonstrate that KAPSM significantly outperforms existing tools in accuracy across diverse evaluation settings.
title KAPG: Adaptive Password Guessing via Knowledge-Augmented Generation
topic Cryptography and Security
url https://arxiv.org/abs/2510.23036