{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,8]],"date-time":"2026-05-08T06:12:39Z","timestamp":1778220759148,"version":"3.51.4"},"reference-count":48,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62572259"],"award-info":[{"award-number":["62572259"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"Tianjin Natural Science Foundation Project","doi-asserted-by":"publisher","award":["25JCJQJC00230"],"award-info":[{"award-number":["25JCJQJC00230"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans.Inform.Forensic Secur."],"published-print":{"date-parts":[[2026]]},"DOI":"10.1109\/tifs.2026.3687032","type":"journal-article","created":{"date-parts":[[2026,4,23]],"date-time":"2026-04-23T19:57:55Z","timestamp":1776974275000},"page":"4594-4609","source":"Crossref","is-referenced-by-count":0,"title":["On the Insecurity of Internally Sampled Honeyword Schemes"],"prefix":"10.1109","volume":"21","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-1667-2237","authenticated-orcid":false,"given":"Ding","family":"Wang","sequence":"first","affiliation":[{"name":"College of Cryptology and Cyber Science, the Key Laboratory of Data and Intelligent System Security (Ministry of Education), and Tianjin Key Laboratory of Network and Data Security Technology, Nankai University, Tianjin, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0003-8124-2406","authenticated-orcid":false,"given":"Tingwei","family":"Fan","sequence":"additional","affiliation":[{"name":"College of Cryptology and Cyber Science, the Key Laboratory of Data and Intelligent System Security (Ministry of Education), and Tianjin Key Laboratory of Network and Data Security Technology, Nankai University, Tianjin, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Fei","family":"Duan","sequence":"additional","affiliation":[{"name":"College of Cryptology and Cyber Science, the Key Laboratory of Data and Intelligent System Security (Ministry of Education), and Tianjin Key Laboratory of Network and Data Security Technology, Nankai University, Tianjin, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7383-8379","authenticated-orcid":false,"given":"Zhenduo","family":"Hou","sequence":"additional","affiliation":[{"name":"College of Cryptology and Cyber Science, the Key Laboratory of Data and Intelligent System Security (Ministry of Education), and Tianjin Key Laboratory of Network and Data Security Technology, Nankai University, Tianjin, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref1","volume-title":"Simpler, Stronger Authentication: Solving World\u2019s Password Problem","year":"2023"},{"key":"ref2","volume-title":"Have I Been Pwned: Check If Your Email Address is in a Data Breach","year":"2025"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2018.2824323"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1145\/2699390"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2012.44"},{"key":"ref6","first-page":"1","article-title":"You are what you like! information leakage through users\u2019 interests","volume-title":"Proc. NDSS","author":"Chaabane"},{"key":"ref7","first-page":"1597","article-title":"A simple framework for contrastive learning of visual representations","volume-title":"Proc. ICML","author":"Chen"},{"key":"ref8","volume-title":"RTX 4090 V6.2.6. Benchmark","author":"Croley","year":"2022"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP53844.2022.00022"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1145\/3433210.3453092"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-24192-0_2"},{"key":"ref12","volume-title":"Will Passwords Become a Thing of the Past","author":"Eitel","year":"2023"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2015.2406707"},{"key":"ref14","first-page":"221","article-title":"Forgetting of passwords: Ecological theory and data","volume-title":"Proc. USENIX SEC","author":"Gao"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2019.101689"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1145\/3678890.3678919"},{"key":"ref17","first-page":"559","article-title":"The impact of exposed passwords on honeyword efficacy","volume-title":"Proc. USENIX SEC","author":"Huang"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1145\/2508859.2516671"},{"key":"ref19","volume-title":"Yahoo Execs Botched Its Response To 2014 Breach, Investigation Finds","author":"Kan","year":"2017"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3484586"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1002\/nav.3800020109"},{"key":"ref22","volume-title":"Protecting Your Data, No Matter Where You Go on the Web","author":"Kurt Thomas","year":"2019"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1145\/3274694.3274714"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2014.50"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1145\/3334480.3382799"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1145\/3321705.3329818"},{"key":"ref27","volume-title":"Yahoo Raises Breach Estimate To Full 3 Billion Accounts","author":"Robert","year":"2017"},{"key":"ref28","volume-title":"LastPass Data Breach Results $4.4 Million Crypto Loss for 25 Victims a Single Day","author":"Shittu","year":"2023"},{"key":"ref29","volume-title":"LastPass Hacked-Identified Early Resolved","author":"Siegrist","year":"2015"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134067"},{"key":"ref31","volume-title":"Notice of Recent Security Incident","author":"Toubba","year":"2022"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.48550\/ARXIV.1706.03762"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2019.23350"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2017.2721359"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23142"},{"key":"ref36","first-page":"1537","article-title":"Birthday, name and bifacial-security: Understanding passwords of Chinese web users","volume-title":"Proc. USENIX SEC","author":"Wang"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978339"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833598"},{"key":"ref39","first-page":"983","article-title":"Pass2Edit: A multi-step generative model for guessing edited passwords","volume-title":"Proc. USENIX SEC","author":"Wang"},{"key":"ref40","first-page":"965","article-title":"Password guessing using random forest","volume-title":"Proc. USENIX SEC","author":"Wang"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2024.23295"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-16613-6_9"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2009.8"},{"key":"ref44","volume-title":"LastPass CEO Reveals Details Secur. Breach","author":"Whitney","year":"2011"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-35504-2_5"},{"key":"ref46","volume-title":"Report: Half a Million Yahoo User Accounts Exposed Breach","author":"Zetter","year":"2012"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1145\/1866307.1866328"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2014.2312547"}],"container-title":["IEEE Transactions on Information Forensics and Security"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/10206\/11313711\/11494073.pdf?arnumber=11494073","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,5,8]],"date-time":"2026-05-08T05:23:07Z","timestamp":1778217787000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11494073\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026]]},"references-count":48,"URL":"https:\/\/doi.org\/10.1109\/tifs.2026.3687032","relation":{},"ISSN":["1556-6013","1556-6021"],"issn-type":[{"value":"1556-6013","type":"print"},{"value":"1556-6021","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026]]}}}