{"id":"https://openalex.org/W7155010461","doi":"https://doi.org/10.48550/arxiv.2604.15845","title":"QUACK! Making the (Rubber) Ducky Talk: A Systematic Study of Keystroke Dynamics for HID Injection Detection","display_name":"QUACK! Making the (Rubber) Ducky Talk: A Systematic Study of Keystroke Dynamics for HID Injection Detection","publication_year":2026,"publication_date":"2026-04-17","ids":{"openalex":"https://openalex.org/W7155010461","doi":"https://doi.org/10.48550/arxiv.2604.15845"},"language":null,"primary_location":{"id":"doi:10.48550/arxiv.2604.15845","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2604.15845","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":null,"is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"article"},"type":"preprint","indexed_in":["datacite"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"https://doi.org/10.48550/arxiv.2604.15845","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5047660672","display_name":"Alessandro Lotto","orcid":"https://orcid.org/0000-0003-3556-4589"},"institutions":[],"countries":[],"is_corresponding":true,"raw_author_name":"Lotto, Alessandro","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5071242130","display_name":"Francesco Marchiori","orcid":"https://orcid.org/0000-0001-5282-0965"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Marchiori, Francesco","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"last","author":{"id":"https://openalex.org/A5134069263","display_name":"Mauro Conti","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Conti, Mauro","raw_affiliation_strings":[],"affiliations":[]}],"institutions":[],"countries_distinct_count":0,"institutions_distinct_count":3,"corresponding_author_ids":["https://openalex.org/A5047660672"],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":null,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":null,"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":null,"last_page":null},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11800","display_name":"User Authentication and Security Systems","score":0.9574999809265137,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11800","display_name":"User Authentication and Security Systems","score":0.9574999809265137,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.008799999952316284,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10789","display_name":"Interactive and Immersive Displays","score":0.007300000172108412,"subfield":{"id":"https://openalex.org/subfields/1709","display_name":"Human-Computer Interaction"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/keystroke-dynamics","display_name":"Keystroke dynamics","score":0.8723999857902527},{"id":"https://openalex.org/keywords/keystroke-logging","display_name":"Keystroke logging","score":0.7229999899864197},{"id":"https://openalex.org/keywords/emulation","display_name":"Emulation","score":0.6672000288963318},{"id":"https://openalex.org/keywords/robustness","display_name":"Robustness (evolution)","score":0.5228999853134155},{"id":"https://openalex.org/keywords/exploit","display_name":"Exploit","score":0.503600001335144},{"id":"https://openalex.org/keywords/intrusion-detection-system","display_name":"Intrusion detection system","score":0.4950000047683716},{"id":"https://openalex.org/keywords/heuristics","display_name":"Heuristics","score":0.4440999925136566},{"id":"https://openalex.org/keywords/interface","display_name":"Interface (matter)","score":0.3384000062942505}],"concepts":[{"id":"https://openalex.org/C79540074","wikidata":"https://www.wikidata.org/wiki/Q3269465","display_name":"Keystroke dynamics","level":4,"score":0.8723999857902527},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7998999953269958},{"id":"https://openalex.org/C161615301","wikidata":"https://www.wikidata.org/wiki/Q309396","display_name":"Keystroke logging","level":2,"score":0.7229999899864197},{"id":"https://openalex.org/C149810388","wikidata":"https://www.wikidata.org/wiki/Q5374873","display_name":"Emulation","level":2,"score":0.6672000288963318},{"id":"https://openalex.org/C63479239","wikidata":"https://www.wikidata.org/wiki/Q7353546","display_name":"Robustness (evolution)","level":3,"score":0.5228999853134155},{"id":"https://openalex.org/C165696696","wikidata":"https://www.wikidata.org/wiki/Q11287","display_name":"Exploit","level":2,"score":0.503600001335144},{"id":"https://openalex.org/C35525427","wikidata":"https://www.wikidata.org/wiki/Q745881","display_name":"Intrusion detection system","level":2,"score":0.4950000047683716},{"id":"https://openalex.org/C127705205","wikidata":"https://www.wikidata.org/wiki/Q5748245","display_name":"Heuristics","level":2,"score":0.4440999925136566},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.3772999942302704},{"id":"https://openalex.org/C107457646","wikidata":"https://www.wikidata.org/wiki/Q207434","display_name":"Human\u2013computer interaction","level":1,"score":0.36169999837875366},{"id":"https://openalex.org/C113843644","wikidata":"https://www.wikidata.org/wiki/Q901882","display_name":"Interface (matter)","level":4,"score":0.3384000062942505},{"id":"https://openalex.org/C507366226","wikidata":"https://www.wikidata.org/wiki/Q42378","display_name":"USB","level":3,"score":0.33180001378059387},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.3312999904155731},{"id":"https://openalex.org/C2775941552","wikidata":"https://www.wikidata.org/wiki/Q25212305","display_name":"Isolation (microbiology)","level":2,"score":0.3287000060081482},{"id":"https://openalex.org/C541664917","wikidata":"https://www.wikidata.org/wiki/Q14001","display_name":"Malware","level":2,"score":0.32679998874664307},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.32440000772476196},{"id":"https://openalex.org/C184297639","wikidata":"https://www.wikidata.org/wiki/Q177765","display_name":"Biometrics","level":2,"score":0.3240000009536743},{"id":"https://openalex.org/C89505385","wikidata":"https://www.wikidata.org/wiki/Q47146","display_name":"User interface","level":2,"score":0.3199999928474426},{"id":"https://openalex.org/C26517878","wikidata":"https://www.wikidata.org/wiki/Q228039","display_name":"Key (lock)","level":2,"score":0.3149000108242035},{"id":"https://openalex.org/C2776633304","wikidata":"https://www.wikidata.org/wiki/Q6038026","display_name":"Insider threat","level":3,"score":0.3122999966144562},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.2921999990940094},{"id":"https://openalex.org/C2779696439","wikidata":"https://www.wikidata.org/wiki/Q7512811","display_name":"Signature (topology)","level":2,"score":0.2847000062465668},{"id":"https://openalex.org/C41065033","wikidata":"https://www.wikidata.org/wiki/Q2825412","display_name":"Adversary","level":2,"score":0.26930001378059387},{"id":"https://openalex.org/C80478641","wikidata":"https://www.wikidata.org/wiki/Q195771","display_name":"Sequential analysis","level":2,"score":0.267300009727478},{"id":"https://openalex.org/C79403827","wikidata":"https://www.wikidata.org/wiki/Q3988","display_name":"Real-time computing","level":1,"score":0.25999999046325684},{"id":"https://openalex.org/C10144332","wikidata":"https://www.wikidata.org/wiki/Q14645","display_name":"Rootkit","level":3,"score":0.2567000091075897},{"id":"https://openalex.org/C173801870","wikidata":"https://www.wikidata.org/wiki/Q201413","display_name":"Heuristic","level":2,"score":0.2547000050544739}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.48550/arxiv.2604.15845","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2604.15845","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":null,"is_accepted":false,"is_published":null,"raw_source_name":null,"raw_type":"article"}],"best_oa_location":{"id":"doi:10.48550/arxiv.2604.15845","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2604.15845","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":null,"is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"article"},"sustainable_development_goals":[{"id":"https://metadata.un.org/sdg/10","display_name":"Reduced inequalities","score":0.5004998445510864},{"id":"https://metadata.un.org/sdg/16","display_name":"Peace, Justice and strong institutions","score":0.42188993096351624}],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":0,"referenced_works":[],"related_works":[],"abstract_inverted_index":{"Modern":[0],"computing":[1],"systems":[2],"inherently":[3],"trust":[4],"human":[5],"input":[6,89,118],"devices,":[7],"creating":[8],"an":[9],"exploitable":[10],"attack":[11,224],"surface":[12],"for":[13,136,167,220],"adversarial":[14],"automation.":[15],"USB":[16,29],"Human":[17],"Interface":[18],"Device":[19],"(HID)":[20],"emulation":[21],"attacks,":[22],"such":[23],"as":[24,84],"those":[25],"enabled":[26],"by":[27,73,144],"the":[28,129,165,204],"Rubber":[30],"Ducky,":[31],"exploit":[32],"this":[33,82,114,125],"assumption":[34],"to":[35,117,191],"inject":[36],"arbitrary":[37],"keystroke":[38,134,213],"sequences":[39],"while":[40],"bypassing":[41],"traditional":[42],"defenses.":[43],"Existing":[44],"countermeasures":[45],"rely":[46],"on":[47,51,161,189],"simple":[48],"heuristics":[49],"based":[50],"typing":[52,76],"speed":[53],"or":[54,170],"timing":[55,162],"regularity,":[56],"which":[57],"can":[58],"be":[59],"easily":[60],"evaded":[61],"through":[62],"basic":[63],"randomization.":[64],"Keystroke":[65],"dynamics":[66,135],"analysis":[67,174],"offers":[68],"a":[69,92],"more":[70],"robust":[71],"alternative":[72,101],"modeling":[74],"temporal":[75],"behavior.":[77],"However,":[78],"prior":[79],"work":[80],"frames":[81],"problem":[83],"behavioral":[85],"authentication,":[86],"verifying":[87],"whether":[88],"originates":[90],"from":[91],"specific":[93],"user":[94,141,171],"rather":[95,196],"than":[96,197],"detecting":[97],"automated":[98],"injection.":[99],"An":[100],"approach":[102],"is":[103,154],"continuous":[104],"monitoring":[105],"via":[106],"keylogging":[107],"integrated":[108],"with":[109],"intrusion":[110],"detection":[111,153,207],"systems,":[112],"but":[113],"requires":[115],"access":[116,169],"content,":[119],"raising":[120],"significant":[121],"privacy":[122],"concerns.":[123],"In":[124],"paper,":[126],"we":[127,148,202],"provide":[128],"first":[130],"systematic":[131],"characterization":[132],"of":[133,140],"human-vs-machine":[137],"discrimination,":[138],"independent":[139],"identity.":[142],"Guided":[143],"five":[145],"research":[146],"questions,":[147],"show":[149],"that":[150,176],"robust,":[151],"privacy-preserving":[152],"achievable":[155],"using":[156],"lightweight":[157],"models":[158],"operating":[159,218],"solely":[160],"features,":[163],"eliminating":[164],"need":[166],"content":[168],"profiling.":[172],"Our":[173],"reveals":[175],"attacker":[177],"sophistication":[178],"does":[179],"not":[180],"monotonically":[181],"translate":[182],"into":[183],"improved":[184],"evasion.":[185],"Instead,":[186],"robustness":[187],"depends":[188],"exposure":[190],"structurally":[192],"diverse":[193],"generation":[194],"strategies":[195],"increased":[198],"model":[199],"complexity.":[200],"Finally,":[201],"quantify":[203],"trade-off":[205],"between":[206],"timeliness":[208],"and":[209,222],"reliability":[210],"across":[211],"varying":[212],"sequence":[214],"lengths,":[215],"identifying":[216],"practical":[217],"points":[219],"early":[221],"effective":[223],"interception.":[225]},"counts_by_year":[],"updated_date":"2026-04-21T06:12:34.886580","created_date":"2026-04-21T00:00:00"}
