{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,2]],"date-time":"2026-07-02T07:02:22Z","timestamp":1782975742016,"version":"3.54.5"},"reference-count":62,"publisher":"IEEE","license":[{"start":{"date-parts":[[2026,5,18]],"date-time":"2026-05-18T00:00:00Z","timestamp":1779062400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,5,18]],"date-time":"2026-05-18T00:00:00Z","timestamp":1779062400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2026,5,18]]},"DOI":"10.1109\/sp63933.2026.00191","type":"proceedings-article","created":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T19:34:20Z","timestamp":1782934460000},"page":"3017-3036","source":"Crossref","is-referenced-by-count":0,"title":["MoPE: A Mixture of Password Experts for Improving Password Guessing"],"prefix":"10.1109","author":[{"given":"Mingjian","family":"Duan","sequence":"first","affiliation":[{"name":"Fudan University,Laboratory for Data Security and Governance"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ming","family":"Xu","sequence":"additional","affiliation":[{"name":"National University of Singapore"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Shenghao","family":"Zhang","sequence":"additional","affiliation":[{"name":"Fudan University,Laboratory for Data Security and Governance"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Weili","family":"Han","sequence":"additional","affiliation":[{"name":"Fudan University,Laboratory for Data Security and Governance"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref1","author":"Abrams","year":"2025","journal-title":"Penn hacker claims to have stolen 1.2 million donor records in data breach"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2012.44"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1145\/2699390"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134067"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2018.00009"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978339"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2016.2568187"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2014.23357"},{"key":"ref9","first-page":"123","article-title":"\u2019i added \u2018!\u2019 at the end to make it secure\u201d: Observing password creation in the lab","volume-title":"Proceedings of Eleventh Symposium On Usable Privacy and Security (SOUPS 2015)","author":"Ur","year":"2015"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2009.8"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2014.50"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1145\/1102120.1102168"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/TASSP.1987.1165125"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-15618-7_10"},{"key":"ref15","first-page":"175","article-title":"Fast, lean, and accurate: Modeling password guessability using neural networks","volume-title":"25th USENIX Security Symposium (USENIX Security 16)","author":"Melicher","year":"2016"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00056"},{"key":"ref17","first-page":"1001","article-title":"Improving real-world password guessing attacks via bi-directional transformers","volume-title":"32nd USENIX Security Symposium (USENIX Security 23)","author":"Xu"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1162\/neco.1991.3.1.79"},{"key":"ref19","article-title":"Outrageously large neural networks: The sparsely-gated mixture-of-experts layer","volume-title":"International Conference on Learning Representations","author":"Shazeer","year":"2017"},{"key":"ref20","article-title":"Learning factored representations in a deep mixture of experts","volume-title":"ICLR Workshop","author":"Eigen","year":"2014"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1145\/3219819.3220007"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1109\/SP61157.2025.00040"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1109\/SP40001.2021.00016"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.21236\/ADA570747"},{"key":"ref25","author":"Komanduri","year":"2016","journal-title":"Modeling the adversary to evaluate password strength with limited samples"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2020.3003696"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.3115\/v1\/W14-3912"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-21568-2_11"},{"key":"ref29","volume-title":"Rockyou2024: Unpacking the largest password leak in history","author":"McAfee","year":"2025"},{"key":"ref30","author":"Casal","year":"2017","journal-title":"1.4 billion cleartext credentials discovered in a single database"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2015.2490620"},{"key":"ref32","first-page":"559","article-title":"A large-scale empirical analysis of chinese web passwords","volume-title":"Proceedings of the 23rd USENIX Security Symposium","author":"Li"},{"key":"ref33","first-page":"463","article-title":"Measuring \\{Real-World\\} accuracies and biases in modeling password guessability","volume-title":"24th USENIX Security Symposium (USENIX Security 15)","author":"Ur","year":"2015"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1109\/SP54263.2024.00032"},{"key":"ref35","volume-title":"Rockyou","year":"2009"},{"key":"ref36","volume-title":"Neopets","year":"2011"},{"key":"ref37","volume-title":"What you need to know about the cit0day data leak","year":"2025"},{"key":"ref38","volume-title":"CSDN","year":"2011"},{"key":"ref39","volume-title":"Rumor: 178 gaming site part of chinese data breach","author":"Consulting","year":"2025"},{"key":"ref40","volume-title":"Hackers in china attack 20 m accounts on alibaba\u2019s taobao shopping site","author":"Guardian","year":"2025"},{"key":"ref41","volume-title":"1.4 billion clear text credentials discovered in a single database","year":"2025"},{"key":"ref42","volume-title":"Collection#1 data breach","year":"2019"},{"key":"ref43","doi-asserted-by":"crossref","first-page":"5","DOI":"10.1145\/3460120.3484743","article-title":"Chunklevel password guessing: Towards modeling refined password composition representations","volume-title":"Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security","author":"Xu","year":"2021"},{"key":"ref44","first-page":"821","article-title":"Reducing bias in modeling real-world password strength via deep learning and dynamic dictionaries","volume-title":"30th USENIX Security Symposium (USENIX Security 21)","author":"Pasquini","year":"2021"},{"key":"ref45","first-page":"13","article-title":"A second look at password composition policies in the wild: Comparing samples from 2010 and 2016","volume-title":"Thirteenth Symposium on Usable Privacy and Security (SOUPS 2017)","author":"Mayer","year":"2017"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1145\/1978942.1979321"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1016\/0377-0427(87)90125-7"},{"key":"ref48","volume-title":"Silhouette (clustering) - Wikipedia, The Free Encyclopedia","year":"2025"},{"key":"ref49","first-page":"983","article-title":"\\{Pass2Edit\\}: A \\{Multi-Step\\} generative model for guessing edited passwords","volume-title":"32nd USENIX Security Symposium (USENIX Security 23)","author":"Wang","year":"2023"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.1406.3269"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.1145\/2810103.2813631"},{"key":"ref52","doi-asserted-by":"publisher","DOI":"10.1109\/SP46215.2023.10179365"},{"key":"ref53","volume-title":"pcfg_cracker: A pcfg password cracker","author":"Lakin","year":"2025"},{"key":"ref54","doi-asserted-by":"publisher","DOI":"10.1109\/sp46215.2023.10179431"},{"key":"ref55","doi-asserted-by":"publisher","DOI":"10.1145\/2858036.2858546"},{"key":"ref56","doi-asserted-by":"publisher","DOI":"10.1145\/2934663"},{"key":"ref57","article-title":"Adaptive passwordstrength meters from markov models","volume-title":"19th Annual Network and Distributed System Security Symposium, NDSS 2012","author":"Castelluccia"},{"key":"ref58","first-page":"561","article-title":"Password policies of most top websites fail to follow best practices","volume-title":"Eighteenth Symposium on Usable Privacy and Security, SOUPS 2022","author":"Lee","year":"2022"},{"key":"ref59","doi-asserted-by":"publisher","DOI":"10.1145\/3576915.3623156"},{"key":"ref60","doi-asserted-by":"publisher","DOI":"10.1145\/1753326.1753384"},{"key":"ref61","volume-title":"Digital identity guidelines: Authentication and lifecycle management","author":"Grassi","year":"2017"},{"key":"ref62","first-page":"965","article-title":"Password guessing using random forest","volume-title":"32nd USENIX Security Symposium (USENIX Security 23)","author":"Wang"}],"event":{"name":"2026 IEEE Symposium on Security and Privacy (SP)","location":"San Francisco, CA, USA","start":{"date-parts":[[2026,5,18]]},"end":{"date-parts":[[2026,5,21]]}},"container-title":["2026 IEEE Symposium on Security and Privacy (SP)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/11573355\/11573356\/11573568.pdf?arnumber=11573568","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,7,2]],"date-time":"2026-07-02T05:36:10Z","timestamp":1782970570000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11573568\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,5,18]]},"references-count":62,"URL":"https:\/\/doi.org\/10.1109\/sp63933.2026.00191","relation":{},"subject":[],"published":{"date-parts":[[2026,5,18]]}}}