arXiv:2605.02102cs.CRcs.HC2026-05中稿 · 2026 IEEE Internat…

建模部分信息泄露下的密码输入过程,量化安全可靠性下降。

Stochastic Modeling of Human-Machine Authentication Channels under Partial Information Leakage

论文配图:Stochastic Modeling of Human-Machine Authentication Channels under Partial Information Leakage
图 1 · 摘自论文原文
  • 将缺失数字视为隐变量,用上下文驱动概率推断还原
  • 单个数字丢失时预测准确率达55.31%,三个丢失时仍达12.12%
  • 适用于评估真实物联网场景下用户认证通道的脆弱性

可靠的可信人机通信是物联网与网络物理系统的基础,智能手机和可穿戴设备常作为认证控制器。基于PIN的认证可视为一种低带宽通信信道,在实际约束下传输数字凭证。然而,传统评估将此类信道简单视为完全安全或完全泄露,忽略了真实物联网环境中部分信息泄露导致的渐进式可靠性下降。本文将PIN输入过程建模为随机的人-物联网通信系统,提出一种上下文条件化的概率推理框架,以量化部分符号暴露下的可靠性损失与服务质量退化。该方法将缺失数字视为隐变量,利用平滑的条件概率分布与回退先验进行估计。不同于传统序列模型对连续位置依赖的假设,本方法不显式参数化隐藏状态转移或发射,而是通过上下文驱动的概率推断近似跨位数的隐含依赖。基于超过一百万条真实四位PIN样本,评估了单、双、三数字泄露场景,得到位置相关的可靠性指标。所提模型在单个数字缺失时达到55.31%的预测准确率,三个缺失时为12.12%,且在精确率、召回率和F1分数上持续优于标准序列模型与经典机器学习基线。结果将PIN输入形式化为噪声人-物联网通信信道,并证明在现实部分暴露条件下存在显著可靠性下降。

原文摘要 · Abstract (English)

Reliable and secure human-machine communication is fundamental to IoT and cyber-physical ecosystems, where smartphones and wearables commonly serve as authentication controllers. PIN-based authentication can be viewed as a low-bandwidth communication channel through which users transmit numeric credentials under practical constraints. However, conventional evaluations adopt a binary view of security-treating such channels as either fully secure or fully compromised-thereby overlooking the progressive reliability degradation caused by partial information leakage in real-world IoT settings. In this paper, we model the PIN entry process as a stochastic human-IoT communication system and propose a context-conditioned probabilistic inference framework to quantify reliability loss and Quality-of-Service degradation under partial symbol exposure. The proposed approach treats missing digits as latent variables and estimates them using smoothed conditional probability distributions with fallback priors. Unlike traditional sequential models that assume contiguous positional dependencies, the method does not explicitly parameterize hidden-state transitions or emissions; instead, it performs context-driven probabilistic inference to approximate latent dependencies across digit positions. Using over one million real-world four-digit PIN samples, we evaluate single-, double-, and triple-digit leakage scenarios and derive position-dependent reliability metrics. The proposed model achieves up to 55.31% prediction accuracy for one missing digit and 12.12% for three missing digits, while consistently outperforming a standard sequence-model baseline and classical machine learning models in terms of precision, recall, and F1-score. These results formalize PIN entry as a noisy human--IoT communication channel and demonstrate substantial reliability degradation under realistic partial exposure conditions.

认证安全概率建模信息泄露

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。