A new smart smudge attack using CNN

被引:0
|
作者
Hansub Shin
Sungyong Sim
Hyukyoon Kwon
Sangheum Hwang
Younho Lee
机构
[1] Seoul National University of Science and Technology,Department of Data Science
[2] Seoul National University of Science and Technology,Department of Industrial Engineering
来源
International Journal of Information Security | 2022年 / 21卷
关键词
Smudge Attack; Authentication; Information Security; CNN;
D O I
暂无
中图分类号
学科分类号
摘要
This paper deals with a well-known problem in the area of the smudge attacks: when a user draws a pattern to unlock the pattern lock on a smartphone screen, pattern extraction sometimes becomes difficult owing to the existence of the oily residuals around it. This is because the phone screen becomes obscured by these residuals, which significantly lower the guess rate of the pattern lock. To address this, this paper proposes a novel attack method based on a Convolutional Neural Network (CNN). CNNs are known to exhibit high accuracy in image classification. However, using only CNNs for the attack is not sufficient, because there are 389,112 possible patterns, and training the CNN for all the cases is difficult. We therefore propose two ideas to overcome the aforementioned problem. The first one is the application of ’Screen Segmentation,’ where we divide the screen into four segments to reduce the number of possible patterns to 1470 in each segment. The second is the use of pruning rules, which reduces the number of total pattern cases by combining the patterns in each segment. Furthermore, by applying the Android pattern lock constraints, we reduce the number of possible patterns. To validate the proposed idea, we collected 3500 image data by photographing the screen of Android smartphones and generated 367,500 image data based on their possible combinations. Using those data sets, we conducted an experiment whereby we investigated the success rate of our attack in various situations, dealing with different pattern lock lengths and type of prior application usage. The result shows that up to a pattern lock length of seven, the proposed method has on an average, 79% success rate, which is meaningful result in smudge attacks. In addition, in an ideal case where only the actual pattern lock is entered, without oily residuals, the proposed scheme supports an even higher performance, i.e., a 93% successful guess rate on an average.
引用
收藏
页码:25 / 36
页数:11
相关论文
共 50 条
  • [21] New remote user authentication scheme using smart cards
    Kumar, M
    IEEE TRANSACTIONS ON CONSUMER ELECTRONICS, 2004, 50 (02) : 597 - 600
  • [22] A CNN-based approach for anomaly detection in smart grid systems
    Priyadarsini, Madhukrishna
    Sonekar, Nitin
    ELECTRIC POWER SYSTEMS RESEARCH, 2025, 238
  • [23] Real-time pricing response attack in smart grid
    Liu, Yang
    Tian, Jue
    Yuan, Xiaoshu
    Ye, Binger
    Sang, Zi
    Yao, Xiangzhen
    Li, Lin
    Liu, Ting
    IET GENERATION TRANSMISSION & DISTRIBUTION, 2022, 16 (12) : 2441 - 2454
  • [24] Cryptanalysis of a New Dynamic ID-based User Authentication Scheme to Resist Smart-Card-Theft Attack
    Wen, Fengtong
    Guo, Dianli
    Li, Xuelei
    APPLIED MATHEMATICS & INFORMATION SCIENCES, 2014, 8 (04): : 1855 - 1858
  • [25] Offline Handwritten New Tai Lue Characters Recognition Using CNN-SVM
    Wang, Yongqiang
    Yu, Pengfei
    Li, Chao
    PROCEEDINGS OF 2019 IEEE 2ND INTERNATIONAL CONFERENCE ON ELECTRONIC INFORMATION AND COMMUNICATION TECHNOLOGY (ICEICT 2019), 2019, : 636 - 639
  • [26] Enhanced image classification using edge CNN (E-CNN)
    Shaima Safa aldin
    Noor Baha Aldin
    Mahmut Aykaç
    The Visual Computer, 2024, 40 : 319 - 332
  • [27] Enhanced image classification using edge CNN (E-CNN)
    Aldin, Shaima Safa
    Aldin, Noor Baha
    Aykac, Mahmut
    VISUAL COMPUTER, 2024, 40 (01): : 319 - 332
  • [28] A DDoS Attack Information Fusion Method Based on CNN for Multi-Element Data
    Cheng, Jieren
    Cai, Canting
    Tang, Xiangyan
    Sheng, Victor S.
    Guo, Wei
    Li, Mengyang
    CMC-COMPUTERS MATERIALS & CONTINUA, 2020, 63 (01): : 131 - 150
  • [29] Simultaneous Attack on CNN-Based Monocular Depth Estimation and Optical Flow Estimation
    Yamanaka, Koichiro
    Takahashi, Keita
    Fujii, Toshiaki
    Matsumoto, Ryuraroh
    IEICE TRANSACTIONS ON INFORMATION AND SYSTEMS, 2021, E104D (05): : 785 - 788
  • [30] A new modified remote user authentication scheme using smart cards
    Shen Zhong-hua
    APPLIED MATHEMATICS-A JOURNAL OF CHINESE UNIVERSITIES SERIES B, 2008, 23 (03) : 371 - 376