{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,3]],"date-time":"2026-06-03T08:24:00Z","timestamp":1780475040502,"version":"3.54.1"},"reference-count":64,"publisher":"Association for Computing Machinery (ACM)","issue":"4","license":[{"start":{"date-parts":[[2015,4,13]],"date-time":"2015-04-13T00:00:00Z","timestamp":1428883200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"Global Research Laboratory Project through the National Research Foundation"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Inf. Syst. Secur."],"published-print":{"date-parts":[[2015,4,24]]},"abstract":"<jats:p>Picture gesture authentication has been recently introduced as an alternative login experience to text-based password on touch-screen devices. In particular, the newly on market Microsoft Windows 8\u2122 operating system adopts such an alternative authentication to complement its traditional text-based authentication. We present an empirical analysis of picture gesture authentication on more than 10,000 picture passwords collected from more than 800 subjects through online user studies. Based on the findings of our user studies, we propose a novel attack framework that is capable of cracking passwords on previously unseen pictures in a picture gesture authentication system. Our approach is based on the concept of selection function that models users\u2019 thought processes in selecting picture passwords. Our evaluation results show the proposed approach could crack a considerable portion of picture passwords under different settings. Based on the empirical analysis and attack results, we comparatively evaluate picture gesture authentication using a set of criteria for a better understanding of its advantages and limitations.<\/jats:p>","DOI":"10.1145\/2701423","type":"journal-article","created":{"date-parts":[[2015,4,14]],"date-time":"2015-04-14T12:32:19Z","timestamp":1429014739000},"page":"1-37","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":40,"title":["Picture Gesture Authentication"],"prefix":"10.1145","volume":"17","author":[{"given":"Ziming","family":"Zhao","sequence":"first","affiliation":[{"name":"Arizona State University, Tempe, AZ, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Gail-Joon","family":"Ahn","sequence":"additional","affiliation":[{"name":"Arizona State University, Tempe, AZ, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Hongxin","family":"Hu","sequence":"additional","affiliation":[{"name":"Clemson University, Clemson, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2015,4,13]]},"reference":[{"key":"e_1_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2012.28"},{"key":"e_1_2_1_2_1","volume-title":"Proceedings of the 4th USENIX Conference on Offensive Technologies. USENIX Association, 1--7.","author":"Aviv Adam J."},{"key":"e_1_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1016\/0031-3203(81)90009-1"},{"key":"e_1_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1109\/COMPSAC.2009.153"},{"key":"e_1_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1145\/2333112.2333114"},{"key":"e_1_2_1_6_1","unstructured":"Joseph Bonneau. 2012a. Guessing human-chosen secrets. University of Cambridge.  Joseph Bonneau. 2012a. Guessing human-chosen secrets. University of Cambridge."},{"key":"e_1_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2012.49"},{"key":"e_1_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2012.44"},{"key":"e_1_2_1_10_1","volume-title":"Proceedings of the the 16th International Conference on Financial Cryptography.","author":"Bonneau Joseph","year":"2012"},{"key":"e_1_2_1_11_1","doi-asserted-by":"crossref","unstructured":"Joseph Bonneau S\u00f6ren Preibusch and Ross Anderson. 2012d. A birthday present every eleven wallets&quest; The security of customer-chosen banking PINs. Financial Cryptography and Data Security (2012) 25--40.  Joseph Bonneau S\u00f6ren Preibusch and Ross Anderson. 2012d. A birthday present every eleven wallets&quest; The security of customer-chosen banking PINs. Financial Cryptography and Data Security (2012) 25--40.","DOI":"10.1007\/978-3-642-32946-3_3"},{"key":"e_1_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-33709-3_30"},{"key":"e_1_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2013.118"},{"key":"e_1_2_1_14_1","doi-asserted-by":"crossref","unstructured":"Sacha Brostoff and M. Angela Sasse. 2000. Are Passfaces more usable than passwords&quest; A field trial investigation. People and Computers (2000) 405--424.  Sacha Brostoff and M. Angela Sasse. 2000. Are Passfaces more usable than passwords&quest; A field trial investigation. People and Computers (2000) 405--424.","DOI":"10.1007\/978-1-4471-0515-2_27"},{"key":"e_1_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.1986.4767851"},{"key":"e_1_2_1_16_1","volume-title":"Proceedings of the 19th Network and Distributed System Security Symposium.","author":"Castelluccia Claude","year":"2012"},{"key":"e_1_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10207-009-0080-7"},{"key":"e_1_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2011.55"},{"key":"e_1_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.5555\/2393847.2393880"},{"key":"e_1_2_1_20_1","volume-title":"Proceedings of the 13th Conference on USENIX Security Symposium. USENIX Association, 11--23","author":"Davis Darren"},{"key":"e_1_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.ijhcs.2005.04.020"},{"key":"e_1_2_1_22_1","volume-title":"Proceedings of the 9th Conference on USENIX Security Symposium. USENIX Association.","author":"Dhamija Rachna","year":"2000"},{"key":"e_1_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1145\/1280680.1280684"},{"key":"e_1_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1145\/1315245.1315252"},{"key":"e_1_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1007\/s00453-004-1110-5"},{"key":"e_1_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2009.167"},{"key":"e_1_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1145\/1753326.1753491"},{"key":"e_1_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACSAC.2008.19"},{"key":"e_1_2_1_29_1","unstructured":"Ross B. Girshick Pedro F. Felzenszwalb and David McAllester. 2010. Discriminatively Trained Deformable Part Models Release 5. Retrieved from http:\/\/people.cs.uchicago.edu\/rbg\/latent-release5\/.  Ross B. Girshick Pedro F. Felzenszwalb and David McAllester. 2010. Discriminatively Trained Deformable Part Models Release 5. Retrieved from http:\/\/people.cs.uchicago.edu\/rbg\/latent-release5\/."},{"key":"e_1_2_1_30_1","unstructured":"Brian Honan. 2012. Visual Data Security White Paper. Retrieved from http:\/\/www.visualdatasecurity.eu\/wp-content\/uploads\/2012\/07\/Visual-Data-Security-White-Paper.pdf.  Brian Honan. 2012. Visual Data Security White Paper. Retrieved from http:\/\/www.visualdatasecurity.eu\/wp-content\/uploads\/2012\/07\/Visual-Data-Security-White-Paper.pdf."},{"key":"e_1_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2006.879305"},{"key":"e_1_2_1_32_1","volume-title":"Proceedings of the 8th USENIX Security Symposium. USENIX Association, 1--14","author":"Jermyn Ian"},{"key":"e_1_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2013.271"},{"key":"e_1_2_1_34_1","unstructured":"Jeff Johnson Steve Seixeiro Zachary Pace Giles Van der Bogert Sean Gilmour Levi Siebens and Ken Tubbs. US Patent 163201 2012. Picture gesture authentication. (US Patent 163201 2012).  Jeff Johnson Steve Seixeiro Zachary Pace Giles Van der Bogert Sean Gilmour Levi Siebens and Ken Tubbs. US Patent 163201 2012. Picture gesture authentication. (US Patent 163201 2012)."},{"key":"e_1_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2012.38"},{"key":"e_1_2_1_36_1","unstructured":"Microsoft. 2013. Microsoft by the Numbers. Retrieved from http:\/\/www.microsoft.com\/en-us\/news\/bythenumbers\/ms_numbers.pdf.  Microsoft. 2013. Microsoft by the Numbers. Retrieved from http:\/\/www.microsoft.com\/en-us\/news\/bythenumbers\/ms_numbers.pdf."},{"key":"e_1_2_1_37_1","unstructured":"Zach Pace. 2011a. Signing in with a Picture Password. Retrieved from http:\/\/blogs.msdn.com\/b\/b8\/archive\/2011\/12\/16\/signing-in-with-a-picture-password.aspx.  Zach Pace. 2011a. Signing in with a Picture Password. Retrieved from http:\/\/blogs.msdn.com\/b\/b8\/archive\/2011\/12\/16\/signing-in-with-a-picture-password.aspx."},{"key":"e_1_2_1_38_1","unstructured":"Zach Pace. 2011b. Signing into Windows 8 with a Picture Password. Retrieved from http:\/\/www.youtube.com\/watch&quest;v=Ek9N2tQzHOA.  Zach Pace. 2011b. Signing into Windows 8 with a Picture Password. Retrieved from http:\/\/www.youtube.com\/watch&quest;v=Ek9N2tQzHOA."},{"key":"e_1_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1145\/2435349.2435395"},{"key":"e_1_2_1_40_1","doi-asserted-by":"publisher","DOI":"10.1504\/IJICS.2009.026621"},{"key":"e_1_2_1_41_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACSAC.2008.18"},{"key":"e_1_2_1_42_1","volume-title":"Proceedings of the 5th USENIX conference on Hot Topics in Security. USENIX Association, 1--8.","author":"Schechter Stuart","year":"2010"},{"key":"e_1_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2007.35"},{"key":"e_1_2_1_44_1","doi-asserted-by":"publisher","DOI":"10.1109\/CSAC.2005.27"},{"key":"e_1_2_1_45_1","doi-asserted-by":"publisher","DOI":"10.1016\/0734-189X(85)90016-7"},{"key":"e_1_2_1_46_1","first-page":"273","article-title":"Pass-Go: A proposal to improve the usability of graphical passwords","volume":"7","author":"Tao Hai","year":"2008","journal-title":"International Journal of Network Security"},{"key":"e_1_2_1_47_1","doi-asserted-by":"publisher","DOI":"10.1145\/2556288.2557212"},{"key":"e_1_2_1_48_1","doi-asserted-by":"publisher","DOI":"10.1109\/CSAC.2004.44"},{"key":"e_1_2_1_49_1","doi-asserted-by":"publisher","DOI":"10.5555\/1362903.1362911"},{"key":"e_1_2_1_50_1","volume-title":"Proceedings of the 13th Conference on USENIX Security Symposium. USENIX Association, 135--150","author":"Thorpe Julie"},{"key":"e_1_2_1_51_1","doi-asserted-by":"publisher","DOI":"10.1145\/2508859.2516700"},{"key":"e_1_2_1_52_1","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2010.2053706"},{"key":"e_1_2_1_53_1","doi-asserted-by":"publisher","DOI":"10.1145\/1284680.1284685"},{"key":"e_1_2_1_54_1","doi-asserted-by":"publisher","DOI":"10.5555\/2011216.2011218"},{"key":"e_1_2_1_55_1","volume-title":"Passdoodles: A lightweight authentication method","author":"Varenhorst Christopher","year":"2004"},{"key":"e_1_2_1_56_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2014.23103"},{"key":"e_1_2_1_57_1","doi-asserted-by":"publisher","DOI":"10.1023\/B:VISI.0000013087.49260.fb"},{"key":"e_1_2_1_58_1","doi-asserted-by":"publisher","DOI":"10.1145\/1463160.1463202"},{"key":"e_1_2_1_59_1","doi-asserted-by":"publisher","DOI":"10.1145\/1073001.1073002"},{"key":"e_1_2_1_60_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.ijhcs.2005.04.010"},{"key":"e_1_2_1_61_1","volume-title":"Proceedings of the 19th Network and Distributed System Security Symposium.","author":"Yan Qiang"},{"key":"e_1_2_1_62_1","unstructured":"John C. Yuille. 1983. Imagery Memory and Cognition. Lawrence Erlbaum Associates Inc.  John C. Yuille. 1983. Imagery Memory and Cognition. Lawrence Erlbaum Associates Inc."},{"key":"e_1_2_1_63_1","doi-asserted-by":"publisher","DOI":"10.1145\/2078827.2078835"},{"key":"e_1_2_1_64_1","doi-asserted-by":"publisher","DOI":"10.1145\/1866307.1866328"},{"key":"e_1_2_1_65_1","volume-title":"Proceedings of the 22nd USENIX Security Symposium. USENIX Association, 383--398","author":"Zhao Ziming","year":"2013"}],"container-title":["ACM Transactions on Information and System Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2701423","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/2701423","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T06:13:10Z","timestamp":1750227190000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2701423"}},"subtitle":["Empirical Analysis, Automated Attacks, and Scheme Evaluation"],"short-title":[],"issued":{"date-parts":[[2015,4,13]]},"references-count":64,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2015,4,24]]}},"alternative-id":["10.1145\/2701423"],"URL":"https:\/\/doi.org\/10.1145\/2701423","relation":{},"ISSN":["1094-9224","1557-7406"],"issn-type":[{"value":"1094-9224","type":"print"},{"value":"1557-7406","type":"electronic"}],"subject":[],"published":{"date-parts":[[2015,4,13]]},"assertion":[{"value":"2014-02-01","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2014-12-01","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2015-04-13","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}