Enhanced free-form gesture authentication scheme based on behavioral biometric features
Online published: 2026-01-04
Copyright
Free-form gesture authentication, offering more complex input patterns and a larger key space, is considered a promising alternative for password authentication in mobile environments. However, recent research reveals that online dictionary attacks can compromise over 10.33% of gestures within 20 attempts, posing a potential threat to the security and usability of gesture authentication systems. To build a more secure yet practical solution, we present StrokeFG, an enhanced free-form gesture authentication scheme that leverages behavioral biometrics. In addition to measuring trajectory similarity, StrokeFG exploits users’ unique behavioral traits exhibited during gesture input to verify identity. Experiments on same-category gesture datasets show that StrokeFG achieves an equal-error rate of 5.64%~6.81%, reducing the recognition error of the baseline by 64.25%~70.67%. Against an adversary who knows the gesture, StrokeFG achieves 6.50~8.41 bits of α-guesswork entropy under online dictionary attacks, effectively raising the security boundary of the baseline model.
YAO Jingyu , WANG Ding , LI Xinyang . Enhanced free-form gesture authentication scheme based on behavioral biometric features[J]. Journal of Cybersecurity, 2025 , 3(4) : 29 -42 . DOI: 10.20172/j.issn.2097-3136.250403
表 1 特征提取器超参数Table 1 Hyperparameters of the feature extractor |
| 超参数 | 预设值 |
| 学习率 | 0.1、0.01、0.001、 |
| 批次大小 | 32、4、128 |
| 边界值 | 1.0、0.5、0.1、0.05、0.01 |
| 输出维度 | 64、128、256 |
表 2 决策网络超参数Table 2 Hyperparameters of the decision network |
| 超参数 | 预设值 |
| 学习率 | 0.1、0.01、0.001、 |
| 批次大小 | 32、64、128 |
表 3 最优超参数组合Table 3 Optimal hyperparameter combinations |
| 网络 | 学习率 | 批次大小 | 边界值 | 输出维度 |
| 孪生网络 | 128 | 0.01 | 256 | |
| 决策网络 | 0.001 | 32 | — | — |
| 1 |
WANG D, GU Q, HUANG X, et al. Understanding human-chosen pins: Characteristics, distribution and security[C]//Proceedings of ACM ASIACC. New York, NY, USA: ACM, 2017: 372-385.
|
| 2 |
CHO G, HUH J H, CHO J, et al. Syspal: System guided pattern locks for android[C]//2017 IEEE symposium on security and privacy(S&P). San Jose, CA, USA: IEEE, 2017: 338-356.
|
| 3 |
WU C, HE K, CHEN J, et al. Liveness is not enough: Enhancing fingerprint authentication with behavioral biometrics to defeat puppet attacks[C]//Proceeding of USENIX Security Symposium 2020. Boston, MA, USA: USENIX, 2020: 2219-2236.
|
| 4 |
WU Z, CHENG Y, ZHANG S, et al. UniID: Spoofing face authentication system by universal identity[C]//Proceedings of ISOC NDSS 2024. San Diego, CA, USA: ISOC, 2024: 1-15.
|
| 5 |
ZHOU M, SU S, WANG Q, et al. PrintListener: Uncovering the vulnerability of fingerprint authentication via the finger friction sound[C]//Proceedings of ISOC NDSS 2024. San Diego, CA, USA: ISOC, 2024: 1-16.
|
| 6 |
DE LUCA A, VON ZEZSCHWITZ E, NGUYEN N D H, et al. Back-of-device authentication on smartphones[C]//Proceedings of ACM CHI 2013. New York, NY, USA: ACM, 2013: 2389-2398.
|
| 7 |
UELLENBECK S, DÜRMUTH M, WOLF C, et al. Quantifying the security of graphical passwords: The case of android unlock patterns[C]//Proceedings of ACM CCS 2013. New York, NY, USA: ACM, 2013: 161-172.
|
| 8 |
RAMACHANDRA R, BUSCH C. Presentation attack detection methods for face recognition systems: A comprehensive survey[J]. ACM Computing Surveys (CSUR), 2017, 50 (1): 1- 37.
|
| 9 |
ROY A, MEMON N, ROSS A. Masterprint: Exploring the vulnerability of partial fingerprint-based authentication systems[J]. IEEE Transactions on Information Forensics and Security (TIFS), 2017, 12 (9): 2013- 2025.
|
| 10 |
WANG D, ZHANG Z, WANG P, et al. Targeted online password guessing: An underestimated threat[C]//Proceedings of ACM CCS 2016. New York, NY, USA: ACM, 2016: 1242-1254.
|
| 11 |
XIU K, WANG D. PointerGuess: Targeted password guessing model using pointer mechanism[C]//Proceedings of USENIX Security Symposium 2024. Philadelphia, PA, USA: USENIX, 2024: 5555-5572.
|
| 12 |
龚雪鸾, 陈艳姣, 王涛, 等. SeqGANPass: 使用序列生成式对抗网络进行口令猜测[J]. 电子学报, 2023, 51 (5): 1148- 1153.
GONG X L, CHEN Y J, WANG T, et al. SeqGANPass: Password guessing with sequence generative adversarial Nets[J]. Acta Electronica Sinica, 2023, 51 (5): 1148- 1153.
|
| 13 |
周满, 李向前, 王骞, 等. 基于声感知的移动终端身份认证综述[J]. 软件学报, 2025, 36 (5): 2229- 2253.
ZHOU M, LI X Q, WANG Q, et al. Survey on acoustic-sensing-based authentication on mobile devices[J]. Journal of Software, 2025, 36 (5): 2229- 2253.
|
| 14 |
姜奇, 文悦, 张瑞杰, 等. 面向智能手机的自适应触屏持续认证方案[J]. 电子学报, 2022, 50 (5): 1131- 1139.
JIANG Q, WEN Y, ZHANG R J, et al. An adaptive touchscreen based continuous authentication scheme for smart phones[J]. Acta Electronica Sinica, 2022, 50 (5): 1131- 1139.
|
| 15 |
高焕芝, 曹秀莲, 王磊, 等. 基于动态手势的身份认证方法及其在智能手机上的应用[J]. 电子学报, 2014, 42 (9): 1857- 1862.
GAO H Z, CAO X L, WANG L, et al. An identity authentication method based on dynamic gesture and its application in mobile phone[J]. Acta Electronica Sinica, 2014, 42 (9): 1857- 1862.
|
| 16 |
SONG W, KANG W. Depthwise temporal non-local network for faster and better dynamic hand gesture authentication[J]. IEEE Transactions on Information Forensics and Security(TIFS), 2023, 18 (3): 1870- 1883.
|
| 17 |
CHEON E, SHIN Y, HUH J H, et al. Gesture authentication for smartphones: Evaluation of gesture password selection policies[C]//Proceedings of IEEE S&P 2020. San Francisco, CA, USA: IEEE, 2020: 249-267.
|
| 18 |
YANG Y, CLARK G D, LINDQVIST J, et al. Free-form gesture authentication in the wild[C]//Proceedings of ACM CHI 2016. New York, NY, USA: ACM, 2016: 3722-3735.
|
| 19 |
LIU C, CLARK G D, LINDDQVIST J. Where usability and security go hand-in-hand: Robust gesture-based authentication for mobile systems[C]//Proceedings ACM CHI 2017. New York, NY, USA: ACM, 2017: 374-386.
|
| 20 |
SHERMAN M, CLARK G, YANG Y, et al. User generated free-form gestures for authentication: Security and memorability[C]//Proceedings of ACM MOBISYS 2014. New York, NY, USA: ACM, 2014: 176-189.
|
| 21 |
LI Y. Protractor: A fast and accurate gesture recognizer[C]//Proceedings of ACM CHI 2010. New York, NY, USA: ACM, 2010: 2169-2172.
|
| 22 |
LI L, ZHAO X, XUE G. Unobservable re-authentication for smartphones[C]//Proceedings of ISOC NDSS 2013. San Diego, California: ISOC, 2013: 57-59.
|
| 23 |
FEREIDOONI H, KÖNIG J, RIEGER P, et al. Authentisense: A scalable behavioral biometrics authentication scheme using few-shot learning for mobile platform[C]//Proceedings of ISOC NDSS 2023. San Diego, California: ISOC, 2023: 1-16.
|
| 24 |
TARANTA II E M, SAMIEI A, MAGHOUMI M, et al. Jackknife: A reliable recognizer with few samples and many modalities[C]//Proceedings ACM CHI 2017. New York, NY, USA: ACM, 2017: 5850-5861.
|
| 25 |
CHEON E, HUH J H, OAKLEY I. GestureMeter: Design and evaluation of a gesture password strength meter[C]//Proceedings ACM CHI 2023. New York, NY, USA: ACM, 2023: 1-19.
|
| 26 |
CHEON E, OAKLEY I. Securing gesture passwords against shoulder surfing using behavioral features[C]//Proceedings ACM CHI 2025. New York, NY, USA: ACM, 2025: 1-8.
|
| 27 |
FRANK M, BIEDERT R, MA E, et al. Touchalytics: On the applicability of touchscreen input as a behavioral biometric for continuous authentication[J]. IEEE Transactions on Information Forensics and Security (TIFS), 2012, 8 (1): 136- 148.
|
| 28 |
SHEN C, ZHANG Y, GUAN X, et al. Performance analysis of touch-interaction behavior for active smartphone authentication[J]. IEEE Transactions on Information Forensics and Security(TIFS), 2015, 11 (3): 498- 513.
|
| 29 |
SHEN Z, LI S, ZHAO X, et al. IncreAuth: Incremental learning-based behavioral biometric authentication on smartphones[J]. IEEE Internet of Things Journal, 2023, 11 (1): 1589- 1603.
|
| 30 |
FIERREZ J, POZO A, MARTINEZDIAZ M, et al. Benchmarking touchscreen biometrics for mobile authentication[J]. IEEE Transactions on Information Forensics and Security (TIFS), 2018, 13 (11): 2720- 2733.
|
| 31 |
SERWADDA A, PHOHA V V. When kids’ toys breach mobile phone security[C]//Proceedings of ACM CCS 2013. New York, NY, USA: ACM, 2013: 599-610.
|
| 32 |
KHAN H, HENGARTNER U, VOGEL D. Targeted mimicry attacks on touch input based implicit authentication schemes[C]//Proceedings of ACM MOBISYS 2016. New York, NY, USA: ACM, 2016: 387-398.
|
| 33 |
ZHAO B Z H, ASGHAR H J, KAAFAR M A. On the resilience of biometric authentication systems against random inputs[C]//Proceedings of ISOC NDSS 2020. San Diego, CA, USA: ISOC, 2020: 1-18.
|
| 34 |
LI Y, HU H, ZHOU G. Using data augmentation in continuous authentication on smartphones[J]. IEEE Internet of Things Journal, 2018, 6 (1): 628- 640.
|
| 35 |
ZOU Q, WANG Y, WANG Q, et al. Deep learning based gait recognition using smartphones in the wild[J]. IEEE Transactions on Information Forensics and Security (TIFS), 2020, 15 (4): 3197- 3212.
|
| 36 |
SHEN Z, LI S, ZHAO X, et al. MMAuth: A continuous authentication framework on smartphones using multiple modalities[J]. IEEE Transactions on Information Forensics and Security(TIFS), 2022, 17 (3): 1450- 1465.
|
| 37 |
SHEN C, LI Y, CHEN Y, et al. Performance analysis of multi-motion sensor behavior for active smartphone authentication[J]. IEEE Transactions on Information Forensics and Security (TIFS), 2017, 13 (1): 48- 62.
|
| 38 |
ZHAO C, GAO F, SHEN Z. AttAuth: An implicit authentication framework for smartphone users using multi-modality data[J]. IEEE Internet of Things Journal, 2023, 11 (4): 6928- 6942.
|
| 39 |
VAN HAMME T, GAROFALO G, RÚA E A, et al. A novel evaluation framework for biometric security: Assessing guessing difficulty as a metric[J]. IEEE Transactions on Information Forensics and Security (TIFS), 2024, 19 (9): 8369- 8384.
|
| 40 |
NEGI, PARIMARJAN, et al. K-means++ vs. behavioral biometrics: One loop to rule them all[C]//Proceedings of ISOC NDSS 2018. San Diego, California: ISOC, 2018: 1-18.
|
| 41 |
DUAN Y, WANG D, FU Y. Security analysis of master-password-protected password management protocols[C]//Proceedings of IEEE S&P 2025. San Francisco, CA, USA: IEEE, 2025: 701-719.
|
| 42 |
KIM, HYOUNGSHICK, JUN HO HUH. PIN selection policies: Are they really effective?[J]. Computers & Security, 2012, 31 (4): 377- 390.
|
/
| 〈 |
|
〉 |