arXiv:2604.12601cs.CRcs.AI2026-04被引 1

用大模型自动优化密码猜测提示,破解率提升近4倍。

LLM-Guided Prompt Evolution for Password Guessing

  • 用大模型进化算法自动生成更有效的密码猜测提示。
  • 在测试集上破解率从2.02%提升至8.48%。
  • 适合安全审计人员和攻击行为研究者使用。

密码仍是主流认证方式,但常因用户选择习惯和大规模凭证泄露而被突破。自动化密码猜测是检验密码策略和模拟攻击者行为的重要工具。本文将大模型驱动的进化计算应用于优化用于大模型密码猜测的提示词。基于OpenEvolve——一个结合MAP-Elites质量-多样性搜索与岛屿种群模型的开源系统,我们演化出在源自RockYou的数据集上最大化破解率的提示词。评估了三种配置:本地部署的Qwen3 8B、单个轻量级云端模型Gemini-2.5 Flash,以及前沿大模型的双模型集成。该方法使破解率从2.02%提升至8.48%。字符分布分析进一步证实,演化后的提示词生成的密码更具统计真实性。自动化提示词演化是一种低门槛但高效的增强大模型密码审计能力的方法,揭示了攻击流程可通过自动化改进的趋势。

原文摘要 · Abstract (English)

Passwords still remain a dominant authentication method, yet their security is routinely subverted by predictable user choices and large-scale credential leaks. Automated password guessing is a key tool for stress-testing password policies and modeling attacker behavior. This paper applies LLM-driven evolutionary computation to automatically optimize prompts for the LLM password guessing framework. Using OpenEvolve, an open-source system combining MAP-Elites quality-diversity search with an island population model we evolve prompts that maximize cracking rate on a RockYou-derived test set. We evaluate three configurations: a local setup with Qwen3 8B, a single compact cloud model Gemini-2.5 Flash, and a two-model ensemble of frontier LLMs. The approach raises the cracking rates from 2.02\% to 8.48\%. Character distribution analysis further confirms how evolved prompts produce statistically more realistic passwords. Automated prompt evolution is a low-barrier yet effective way to strengthen LLM-based password auditing and underlining how attack pipelines show tendency via automated improvements.

密码安全大模型提示工程自动化攻击

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。