{"title":"Cipher-Guard: A Machine Learning Model for Adaptive and Context-Aware Password Security","authors":"Mohammed Naif Alatawi","doi":"10.1049/ise2/3930060","DOIUrl":null,"url":null,"abstract":"<p>This research aims to enhance password security by designing, training and testing Cipher-Guard, a machine learning (ML) algorithm that incorporates complex features and techniques derived from proven feature engineering. The current model is inherently built on the equations of mathematical modelling concerning complexity metrics of passwords and contextualisation. This is in terms of password length (PL), entropy (<i>E</i>) and the character set diversity (CSD) of the passwords, as well as contextual embeddings such as user-specific password history (UPH) and temporal patterns (TPs). A simulation of the data matrix was created, containing 1000 records, which formed the basis of the model and a thorough exploratory data analysis (EDA). The proposed model demonstrates interpretability and credibility in distinguishing patterns related to password complexity metrics, yielding promising formative results in the specified evaluation metrics. PL, <i>E</i> and CSD were analysed thoroughly, and the importance of increasing password security was identified. Specific contextual embeddings were identified as UPH and TPs, which reflect the model’s ability to adapt to the particular user’s actions. Including adversarial training features also helped protect the model from potential manipulations through a proactive defence plan. Moreover, the enhancement of cryptographic principles, which include hashing and salting, also improved the dataset security, thereby increasing the standard practice within the industry. The metrics involved in the comparative assessment included receiver operating characteristic-area under the curve (ROC-AUC), learning curves, confusion matrix, precision matrix and precision-recall curves, among others. Cipher-Guard performed consistently well across these parameters, which has reinforced its authenticity in strengthening password protection. However, to appreciate such findings, certain constraints need to be well addressed, such as the quality of the chosen dataset, some ethical concerns raised in the study and the fact that new threats are constantly emerging. Recommendations for enhancing continuous dataset monitoring and establishing an ethical framework for the case are also suggested. The research directions broaden future possibilities for research while emphasising continuous model updating, individual-centred protection and compatibility with other emerging technologies. Therefore, Cipher-Guard represents a significant advancement in password protection and offers a promising prospect for flexible and personalised security in the modern era.</p>","PeriodicalId":50380,"journal":{"name":"IET Information Security","volume":"2026 1","pages":""},"PeriodicalIF":2.0000,"publicationDate":"2026-06-19","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"https://onlinelibrary.wiley.com/doi/epdf/10.1049/ise2/3930060","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"IET Information Security","FirstCategoryId":"94","ListUrlMain":"https://onlinelibrary.wiley.com/doi/10.1049/ise2/3930060","RegionNum":4,"RegionCategory":"计算机科学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"Q3","JCRName":"COMPUTER SCIENCE, INFORMATION SYSTEMS","Score":null,"Total":0}
引用次数: 0
Abstract
This research aims to enhance password security by designing, training and testing Cipher-Guard, a machine learning (ML) algorithm that incorporates complex features and techniques derived from proven feature engineering. The current model is inherently built on the equations of mathematical modelling concerning complexity metrics of passwords and contextualisation. This is in terms of password length (PL), entropy (E) and the character set diversity (CSD) of the passwords, as well as contextual embeddings such as user-specific password history (UPH) and temporal patterns (TPs). A simulation of the data matrix was created, containing 1000 records, which formed the basis of the model and a thorough exploratory data analysis (EDA). The proposed model demonstrates interpretability and credibility in distinguishing patterns related to password complexity metrics, yielding promising formative results in the specified evaluation metrics. PL, E and CSD were analysed thoroughly, and the importance of increasing password security was identified. Specific contextual embeddings were identified as UPH and TPs, which reflect the model’s ability to adapt to the particular user’s actions. Including adversarial training features also helped protect the model from potential manipulations through a proactive defence plan. Moreover, the enhancement of cryptographic principles, which include hashing and salting, also improved the dataset security, thereby increasing the standard practice within the industry. The metrics involved in the comparative assessment included receiver operating characteristic-area under the curve (ROC-AUC), learning curves, confusion matrix, precision matrix and precision-recall curves, among others. Cipher-Guard performed consistently well across these parameters, which has reinforced its authenticity in strengthening password protection. However, to appreciate such findings, certain constraints need to be well addressed, such as the quality of the chosen dataset, some ethical concerns raised in the study and the fact that new threats are constantly emerging. Recommendations for enhancing continuous dataset monitoring and establishing an ethical framework for the case are also suggested. The research directions broaden future possibilities for research while emphasising continuous model updating, individual-centred protection and compatibility with other emerging technologies. Therefore, Cipher-Guard represents a significant advancement in password protection and offers a promising prospect for flexible and personalised security in the modern era.
期刊介绍:
IET Information Security publishes original research papers in the following areas of information security and cryptography. Submitting authors should specify clearly in their covering statement the area into which their paper falls.
Scope:
Access Control and Database Security
Ad-Hoc Network Aspects
Anonymity and E-Voting
Authentication
Block Ciphers and Hash Functions
Blockchain, Bitcoin (Technical aspects only)
Broadcast Encryption and Traitor Tracing
Combinatorial Aspects
Covert Channels and Information Flow
Critical Infrastructures
Cryptanalysis
Dependability
Digital Rights Management
Digital Signature Schemes
Digital Steganography
Economic Aspects of Information Security
Elliptic Curve Cryptography and Number Theory
Embedded Systems Aspects
Embedded Systems Security and Forensics
Financial Cryptography
Firewall Security
Formal Methods and Security Verification
Human Aspects
Information Warfare and Survivability
Intrusion Detection
Java and XML Security
Key Distribution
Key Management
Malware
Multi-Party Computation and Threshold Cryptography
Peer-to-peer Security
PKIs
Public-Key and Hybrid Encryption
Quantum Cryptography
Risks of using Computers
Robust Networks
Secret Sharing
Secure Electronic Commerce
Software Obfuscation
Stream Ciphers
Trust Models
Watermarking and Fingerprinting
Special Issues. Current Call for Papers:
Security on Mobile and IoT devices - https://digital-library.theiet.org/files/IET_IFS_SMID_CFP.pdf