{"id":"https://openalex.org/W4309562180","doi":"https://doi.org/10.1145/3571743","title":"Revisiting the Security of Biometric Authentication Systems Against Statistical Attacks","display_name":"Revisiting the Security of Biometric Authentication Systems Against Statistical Attacks","publication_year":2022,"publication_date":"2022-11-19","ids":{"openalex":"https://openalex.org/W4309562180","doi":"https://doi.org/10.1145/3571743"},"language":"en","primary_location":{"id":"doi:10.1145/3571743","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3571743","pdf_url":null,"source":{"id":"https://openalex.org/S4210174050","display_name":"ACM Transactions on Privacy and Security","issn_l":"2471-2566","issn":["2471-2566","2471-2574"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319798","host_organization_name":"Association for Computing Machinery","host_organization_lineage":["https://openalex.org/P4310319798"],"host_organization_lineage_names":["Association for Computing Machinery"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"ACM Transactions on Privacy and Security","raw_type":"journal-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5060013699","display_name":"Sohail Habib","orcid":"https://orcid.org/0000-0002-9515-6037"},"institutions":[{"id":"https://openalex.org/I79817857","display_name":"University of Guelph","ror":"https://ror.org/01r7awg59","country_code":"CA","type":"education","lineage":["https://openalex.org/I79817857"]}],"countries":["CA"],"is_corresponding":false,"raw_author_name":"Sohail Habib","raw_affiliation_strings":["University of Guelph, Canada"],"raw_orcid":"https://orcid.org/0000-0002-9515-6037","affiliations":[{"raw_affiliation_string":"University of Guelph, Canada","institution_ids":["https://openalex.org/I79817857"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5103029246","display_name":"Hassan Khan","orcid":"https://orcid.org/0000-0003-2946-5920"},"institutions":[{"id":"https://openalex.org/I79817857","display_name":"University of Guelph","ror":"https://ror.org/01r7awg59","country_code":"CA","type":"education","lineage":["https://openalex.org/I79817857"]}],"countries":["CA"],"is_corresponding":false,"raw_author_name":"Hassan Khan","raw_affiliation_strings":["University of Guelph, Canada"],"raw_orcid":"https://orcid.org/0000-0003-2946-5920","affiliations":[{"raw_affiliation_string":"University of Guelph, Canada","institution_ids":["https://openalex.org/I79817857"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5066170388","display_name":"Andrew Hamilton-Wright","orcid":"https://orcid.org/0000-0002-7459-656X"},"institutions":[{"id":"https://openalex.org/I79817857","display_name":"University of Guelph","ror":"https://ror.org/01r7awg59","country_code":"CA","type":"education","lineage":["https://openalex.org/I79817857"]}],"countries":["CA"],"is_corresponding":false,"raw_author_name":"Andrew Hamilton-Wright","raw_affiliation_strings":["University of Guelph, Canada"],"raw_orcid":"https://orcid.org/0000-0002-7459-656X","affiliations":[{"raw_affiliation_string":"University of Guelph, Canada","institution_ids":["https://openalex.org/I79817857"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5102843571","display_name":"Urs Hengartner","orcid":"https://orcid.org/0000-0002-9840-0015"},"institutions":[{"id":"https://openalex.org/I151746483","display_name":"University of Waterloo","ror":"https://ror.org/01aff2v68","country_code":"CA","type":"education","lineage":["https://openalex.org/I151746483"]}],"countries":["CA"],"is_corresponding":false,"raw_author_name":"Urs Hengartner","raw_affiliation_strings":["University of Waterloo, Waterloo, Canada"],"raw_orcid":"https://orcid.org/0000-0002-9840-0015","affiliations":[{"raw_affiliation_string":"University of Waterloo, Waterloo, Canada","institution_ids":["https://openalex.org/I151746483"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":4,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":1.2748,"has_fulltext":false,"cited_by_count":4,"citation_normalized_percentile":{"value":0.84884475,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":90,"max":96},"biblio":{"volume":"26","issue":"2","first_page":"1","last_page":"30"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11800","display_name":"User Authentication and Security Systems","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11800","display_name":"User Authentication and Security Systems","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10828","display_name":"Biometric Identification and Security","score":0.9959999918937683,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12268","display_name":"Deception detection and forensic psychology","score":0.986299991607666,"subfield":{"id":"https://openalex.org/subfields/3207","display_name":"Social Psychology"},"field":{"id":"https://openalex.org/fields/32","display_name":"Psychology"},"domain":{"id":"https://openalex.org/domains/2","display_name":"Social Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/biometrics","display_name":"Biometrics","score":0.9247320890426636},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.6823122501373291},{"id":"https://openalex.org/keywords/usability","display_name":"Usability","score":0.6431640386581421},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.6216616034507751},{"id":"https://openalex.org/keywords/keystroke-dynamics","display_name":"Keystroke dynamics","score":0.491832971572876},{"id":"https://openalex.org/keywords/authentication","display_name":"Authentication (law)","score":0.46668681502342224},{"id":"https://openalex.org/keywords/statistical-analysis","display_name":"Statistical analysis","score":0.44172734022140503},{"id":"https://openalex.org/keywords/keystroke-logging","display_name":"Keystroke logging","score":0.42600512504577637},{"id":"https://openalex.org/keywords/key","display_name":"Key (lock)","score":0.421102374792099},{"id":"https://openalex.org/keywords/identification","display_name":"Identification (biology)","score":0.4100554585456848},{"id":"https://openalex.org/keywords/statistics","display_name":"Statistics","score":0.20194631814956665},{"id":"https://openalex.org/keywords/password","display_name":"Password","score":0.1479589343070984},{"id":"https://openalex.org/keywords/mathematics","display_name":"Mathematics","score":0.13943743705749512},{"id":"https://openalex.org/keywords/human\u2013computer-interaction","display_name":"Human\u2013computer interaction","score":0.13126474618911743}],"concepts":[{"id":"https://openalex.org/C184297639","wikidata":"https://www.wikidata.org/wiki/Q177765","display_name":"Biometrics","level":2,"score":0.9247320890426636},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.6823122501373291},{"id":"https://openalex.org/C170130773","wikidata":"https://www.wikidata.org/wiki/Q216378","display_name":"Usability","level":2,"score":0.6431640386581421},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.6216616034507751},{"id":"https://openalex.org/C79540074","wikidata":"https://www.wikidata.org/wiki/Q3269465","display_name":"Keystroke dynamics","level":4,"score":0.491832971572876},{"id":"https://openalex.org/C148417208","wikidata":"https://www.wikidata.org/wiki/Q4825882","display_name":"Authentication (law)","level":2,"score":0.46668681502342224},{"id":"https://openalex.org/C2986587452","wikidata":"https://www.wikidata.org/wiki/Q938438","display_name":"Statistical analysis","level":2,"score":0.44172734022140503},{"id":"https://openalex.org/C161615301","wikidata":"https://www.wikidata.org/wiki/Q309396","display_name":"Keystroke logging","level":2,"score":0.42600512504577637},{"id":"https://openalex.org/C26517878","wikidata":"https://www.wikidata.org/wiki/Q228039","display_name":"Key (lock)","level":2,"score":0.421102374792099},{"id":"https://openalex.org/C116834253","wikidata":"https://www.wikidata.org/wiki/Q2039217","display_name":"Identification (biology)","level":2,"score":0.4100554585456848},{"id":"https://openalex.org/C105795698","wikidata":"https://www.wikidata.org/wiki/Q12483","display_name":"Statistics","level":1,"score":0.20194631814956665},{"id":"https://openalex.org/C109297577","wikidata":"https://www.wikidata.org/wiki/Q161157","display_name":"Password","level":2,"score":0.1479589343070984},{"id":"https://openalex.org/C33923547","wikidata":"https://www.wikidata.org/wiki/Q395","display_name":"Mathematics","level":0,"score":0.13943743705749512},{"id":"https://openalex.org/C107457646","wikidata":"https://www.wikidata.org/wiki/Q207434","display_name":"Human\u2013computer interaction","level":1,"score":0.13126474618911743},{"id":"https://openalex.org/C4957475","wikidata":"https://www.wikidata.org/wiki/Q242186","display_name":"S/KEY","level":3,"score":0.0},{"id":"https://openalex.org/C86803240","wikidata":"https://www.wikidata.org/wiki/Q420","display_name":"Biology","level":0,"score":0.0},{"id":"https://openalex.org/C59822182","wikidata":"https://www.wikidata.org/wiki/Q441","display_name":"Botany","level":1,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1145/3571743","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3571743","pdf_url":null,"source":{"id":"https://openalex.org/S4210174050","display_name":"ACM Transactions on Privacy and Security","issn_l":"2471-2566","issn":["2471-2566","2471-2574"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319798","host_organization_name":"Association for Computing Machinery","host_organization_lineage":["https://openalex.org/P4310319798"],"host_organization_lineage_names":["Association for Computing Machinery"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"ACM Transactions on Privacy and Security","raw_type":"journal-article"}],"best_oa_location":null,"sustainable_development_goals":[{"id":"https://metadata.un.org/sdg/16","score":0.7699999809265137,"display_name":"Peace, Justice and strong institutions"}],"awards":[],"funders":[{"id":"https://openalex.org/F4320334593","display_name":"Natural Sciences and Engineering Research Council of Canada","ror":"https://ror.org/01h531d29"}],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":60,"referenced_works":["https://openalex.org/W282499614","https://openalex.org/W1483327747","https://openalex.org/W1498636830","https://openalex.org/W1680400516","https://openalex.org/W1964160137","https://openalex.org/W1971565662","https://openalex.org/W1977543168","https://openalex.org/W1981157808","https://openalex.org/W1984188157","https://openalex.org/W1987971958","https://openalex.org/W2041282815","https://openalex.org/W2041538398","https://openalex.org/W2052279280","https://openalex.org/W2053499857","https://openalex.org/W2064376060","https://openalex.org/W2066372561","https://openalex.org/W2083358597","https://openalex.org/W2093197020","https://openalex.org/W2097267243","https://openalex.org/W2097749765","https://openalex.org/W2104354220","https://openalex.org/W2106385544","https://openalex.org/W2107589078","https://openalex.org/W2131976234","https://openalex.org/W2138350282","https://openalex.org/W2140959843","https://openalex.org/W2151854612","https://openalex.org/W2154123601","https://openalex.org/W2169908475","https://openalex.org/W2293257959","https://openalex.org/W2345317019","https://openalex.org/W2395297283","https://openalex.org/W2468988960","https://openalex.org/W2487597786","https://openalex.org/W2500258589","https://openalex.org/W2537377273","https://openalex.org/W2602531037","https://openalex.org/W2726515241","https://openalex.org/W2742650136","https://openalex.org/W2756798011","https://openalex.org/W2790382682","https://openalex.org/W2795341848","https://openalex.org/W2808631503","https://openalex.org/W2881632231","https://openalex.org/W2911971268","https://openalex.org/W2945744610","https://openalex.org/W2947243436","https://openalex.org/W2964135678","https://openalex.org/W2981087920","https://openalex.org/W2998748981","https://openalex.org/W3008038029","https://openalex.org/W3013184273","https://openalex.org/W3014370958","https://openalex.org/W3046760295","https://openalex.org/W3049345403","https://openalex.org/W3089502740","https://openalex.org/W3099824492","https://openalex.org/W4231853065","https://openalex.org/W4237456942","https://openalex.org/W4399591897"],"related_works":["https://openalex.org/W2052279280","https://openalex.org/W3094144434","https://openalex.org/W1966864883","https://openalex.org/W1563893514","https://openalex.org/W274642192","https://openalex.org/W2095735921","https://openalex.org/W3081110952","https://openalex.org/W2545016324","https://openalex.org/W4283259439","https://openalex.org/W2982224826"],"abstract_inverted_index":{"The":[0,200],"uniqueness":[1],"of":[2,56,99,202,215,224],"behavioral":[3,28],"biometrics":[4,29,50,243],"(e.g.,":[5,248],"voice":[6],"or":[7],"keystroke":[8],"patterns)":[9],"has":[10,67],"been":[11,19,68],"challenged":[12],"by":[13,187,239],"recent":[14],"works.":[15],"Statistical":[16],"attacks":[17,47,190,219,241],"have":[18],"proposed":[20,69,204],"that":[21,36,72,88,171,244],"infer":[22],"general":[23],"population":[24],"statistics":[25],"and":[26,86,107,167,186,198],"target":[27],"against":[30,48,96,104,257],"a":[31,81,97,169,231],"particular":[32],"victim.":[33],"We":[34,165],"show":[35,87],"despite":[37],"their":[38],"success,":[39],"these":[40,62,258],"approaches":[41],"require":[42],"several":[43],"attempts":[44,111],"for":[45,61,112,121,143,255],"successful":[46,95,103,113,134,157],"different":[49,54],"due":[51],"to":[52,70,210,226,242],"the":[53,122,136,144,159,174,203,216,235,253],"nature":[55],"overlap":[57],"in":[58,181],"users\u2019":[59],"behavior":[60],"biometrics.":[63],"Furthermore,":[64],"no":[65],"mechanism":[66,170,206],"date":[71],"detects":[73],"statistical":[74,84,177,189,218,232,240],"attacks.":[75,114,178,259],"In":[76],"this":[77],"work,":[78],"we":[79],"propose":[80,166],"new":[82],"hypervolumes-based":[83],"attack":[85,128,146,151],"unlike":[89],"existing":[90],"methods,":[91],"it":[92],"(1)":[93],"is":[94,102,129,152],"variety":[98],"biometrics,":[100,120],"(2)":[101],"more":[105,133,156,175],"users,":[106],"(3)":[108],"requires":[109],"fewest":[110],"More":[115],"specifically,":[116],"across":[117],"five":[118],"diverse":[119],"first":[123],"attempt,":[124,147],"on":[125,148,212],"average":[126,149,213,222],"our":[127,150,194,250],"18":[130,153],"percentage":[131,154],"points":[132,155],"than":[135,158],"second":[137,160],"best":[138,161],"(37%":[139],"vs.":[140,163],"19%).":[141],"Similarly,":[142],"fifth":[145],"(67%":[162],"49%).":[164],"evaluate":[168],"can":[172],"detect":[173,211,227],"devastating":[176],"False":[179],"rejects":[180,229],"biometric":[182],"systems":[183],"are":[184,245],"common,":[185],"distinguishing":[188],"from":[191],"false":[192,228],"rejects,":[193],"defense":[195],"improves":[196],"usability":[197],"security.":[199],"evaluation":[201],"detection":[205],"shows":[207],"its":[208],"ability":[209],"94%":[214],"tested":[217],"with":[220],"an":[221],"probability":[223],"3%":[225],"as":[230],"attack.":[233],"Given":[234],"serious":[236],"threat":[237],"posed":[238],"used":[246],"today":[247],"voice),":[249],"work":[251],"highlights":[252],"need":[254],"defending":[256]},"counts_by_year":[{"year":2025,"cited_by_count":1},{"year":2024,"cited_by_count":2},{"year":2023,"cited_by_count":1}],"updated_date":"2026-06-22T08:00:12.763002","created_date":"2025-10-10T00:00:00"}
