{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,12,22]],"date-time":"2025-12-22T22:27:52Z","timestamp":1766442472041,"version":"3.48.0"},"publisher-location":"New York, NY, USA","reference-count":80,"publisher":"ACM","funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62222208 and 62172240"],"award-info":[{"award-number":["62222208 and 62172240"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Fundamental Research Funds for the Central Universities, Nankai University","award":["63253229"],"award-info":[{"award-number":["63253229"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2025,11,19]]},"DOI":"10.1145\/3719027.3765162","type":"proceedings-article","created":{"date-parts":[[2025,11,22]],"date-time":"2025-11-22T23:42:02Z","timestamp":1763854922000},"page":"4319-4333","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":0,"title":["How to Design Secure Honey Vault Schemes"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-7383-8379","authenticated-orcid":false,"given":"Zhenduo","family":"Hou","sequence":"first","affiliation":[{"name":"Nankai University, Tianjin, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0003-8124-2406","authenticated-orcid":false,"given":"Tingwei","family":"Fan","sequence":"additional","affiliation":[{"name":"Nankai University, Tianjin, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0009-9670-876X","authenticated-orcid":false,"given":"Fei","family":"Duan","sequence":"additional","affiliation":[{"name":"Nankai University, Tianjin, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1667-2237","authenticated-orcid":false,"given":"Ding","family":"Wang","sequence":"additional","affiliation":[{"name":"Nankai University, Tianjin, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2025,11,22]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"Account recovery options for Dashlane Aug. 2024 https:\/\/support.dashlane.com\/hc\/en-us\/articles\/11282971791634-Account-recovery-options-for-Dashlane."},{"volume-title":"The multi-protocol, highest assurance security key that enables passwordless","year":"2024","key":"e_1_3_2_1_2_1","unstructured":"YubiKey 5 Series: The multi-protocol, highest assurance security key that enables passwordless, 2024, https:\/\/www.yubico.com\/products\/yubikey-5-overview\/."},{"key":"e_1_3_2_1_3_1","unstructured":"Feds link $150M cyberheist to 2022 LastPass hacks Mar. 2025 https:\/\/krebsonsecurity.com\/2025\/03\/feds-link-150m-cyberheist-to-2022-lastpass-hacks\/."},{"key":"e_1_3_2_1_4_1","unstructured":"FIDO2 passwordless authentication 2025 https:\/\/www.yubico.com\/authentication-standards\/fido2\/."},{"key":"e_1_3_2_1_5_1","unstructured":"Generating pronounceable passwords in Enpass 2025 https:\/\/support.enpass.io\/app\/generate\/generating_pronounceable_random_passwords_in_enpass.htm."},{"key":"e_1_3_2_1_6_1","unstructured":"Have I been pwned? Pwned passwords 2025 https:\/\/haveibeenpwned.com\/Passwords."},{"volume-title":"Try our random password generator","year":"2025","key":"e_1_3_2_1_7_1","unstructured":"Strong. Secure. Awesome. Try our random password generator, 2025, https:\/\/1password.com\/password-generator."},{"key":"e_1_3_2_1_8_1","unstructured":"Using 1Password Generate and use recovery codes May 2025 https:\/\/support.1password.com\/recovery-codes\/?windows."},{"key":"e_1_3_2_1_9_1","first-page":"2061","volume-title":"USENIX SEC","author":"Al Roomi S.","year":"2023","unstructured":"S. Al Roomi and F. Li, ''A large-scale measurement of website login policies,'' in Proc. USENIX SEC 2023, pp. 2061-2078."},{"key":"e_1_3_2_1_10_1","first-page":"4643","volume-title":"ACM CCS","author":"Ameri M. H.","year":"2024","unstructured":"M. H. Ameri and J. Blocki, ''Conditional encryption with applications to secure personalized password typo correction,'' in Proc. ACM CCS 2024, pp. 4643-4657."},{"key":"e_1_3_2_1_11_1","first-page":"292","article-title":"Argon2: New generation of memory-hard functions for password hashing and other applications","author":"Biryukov A.","year":"2016","unstructured":"A. Biryukov, D. Dinu, and D. Khovratovich, ''Argon2: New generation of memory-hard functions for password hashing and other applications,'' in Proc. IEEE EuroS&P 2016, pp. 292-302.","journal-title":"Proc. IEEE EuroS&P"},{"key":"e_1_3_2_1_12_1","first-page":"286","volume-title":"ESORICS","author":"Bojinov H.","year":"2024","unstructured":"H. Bojinov, E. Bursztein, X. Boyen, and D. Boneh, ''Kamouflage: Loss-resistant password management,'' in Proc. ESORICS 2024, pp. 286-302."},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1145\/2699390"},{"key":"e_1_3_2_1_14_1","first-page":"553","article-title":"The quest to replace passwords: A framework for comparative evaluation of web authentication schemes","author":"Bonneau J.","year":"2012","unstructured":"J. Bonneau, C. Herley, P. C. Van Oorschot, and F. Stajano, ''The quest to replace passwords: A framework for comparative evaluation of web authentication schemes,'' in Proc. IEEE S&P 2012, pp. 553-567.","journal-title":"Proc. IEEE S&P"},{"key":"e_1_3_2_1_15_1","first-page":"409","volume-title":"ACM CCS","author":"Brost J.","year":"2020","unstructured":"J. Brost, C. Egger, R. W. Lai, F. Schmid, D. Schr\u00f6der, and M. Zoppelt, ''Threshold password-hardened encryption services,'' in Proc. ACM CCS 2020, pp. 409-424."},{"key":"e_1_3_2_1_16_1","first-page":"799","article-title":"pASSWORD tYPOS and how to correct them securely","author":"Chatterjee R.","year":"2016","unstructured":"R. Chatterjee, A. Athayle, D. Akhawe, A. Juels, and T. Ristenpart, ''pASSWORD tYPOS and how to correct them securely,'' in Proc. IEEE S&P 2016, pp. 799-818.","journal-title":"Proc. IEEE S&P"},{"key":"e_1_3_2_1_17_1","first-page":"481","article-title":"Cracking-resistant password vaults using natural language encoders","author":"Chatterjee R.","year":"2015","unstructured":"R. Chatterjee, J. Bonneau, A. Juels, and T. Ristenpart, ''Cracking-resistant password vaults using natural language encoders,'' in Proc. IEEE S&P 2015, pp. 481-498.","journal-title":"Proc. IEEE S&P"},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134000"},{"key":"e_1_3_2_1_19_1","first-page":"857","volume-title":"USENIX SEC","author":"Cheng H.","year":"2021","unstructured":"H. Cheng, W. Li, P. Wang, C.-H. Chu, and K. Liang, ''Incrementally updateable honey password vaults,'' in Proc. USENIX SEC 2021, pp. 857-874."},{"key":"e_1_3_2_1_20_1","first-page":"1573","volume-title":"USENIX SEC","author":"Cheng H.","year":"2019","unstructured":"H. Cheng, Z. Zheng, W. Li, P. Wang, and C. Chu, ''Probability model transforming encoders against encoding attacks,'' in Proc. USENIX SEC 2019, pp. 1573-1590."},{"key":"e_1_3_2_1_21_1","volume-title":"May","author":"Clifford C.","year":"2022","unstructured":"C. Clifford and P. Sharon, Keep Your Passwords Strong and Secure With These 9 Rules, May 2022, https:\/\/www.cnet.com\/tech\/mobile\/keep-your-passwords-strong-and-secure-with-these-9-rules\/."},{"key":"e_1_3_2_1_22_1","volume-title":"Elements of Information Theory","author":"Cover T. M.","year":"2006","unstructured":"T. M. Cover and J. A. Thomas, Elements of Information Theory (Wiley Series in Telecommunications and Signal Processing). hskip 1em plus 0.5em minus 0.4emrelax USA: Wiley-Interscience, 2006."},{"key":"e_1_3_2_1_23_1","volume-title":"Feb.","author":"Croley S.","year":"2025","unstructured":"S. Croley, RTX 5090 CUDA v6.2.6-851.Benchmark, Feb. 2025, https:\/\/gist.github.com\/Chick3nman\/09bac0775e6393468c2925c1e1363d5c."},{"key":"e_1_3_2_1_24_1","first-page":"1","volume-title":"NDSS","author":"Das A.","year":"2014","unstructured":"A. Das, J. Bonneau, M. Caesar, N. Borisov, and X. Wang, ''The tangled web of password reuse,'' in Proc. NDSS 2014, pp. 1-15."},{"key":"e_1_3_2_1_25_1","first-page":"1424","article-title":"A security analysis of honey vaults","author":"Duan F.","year":"2024","unstructured":"F. Duan, D. Wang, and C. Jia, ''A security analysis of honey vaults,'' in Proc. IEEE S&P 2024, pp. 1424-1442.","journal-title":"Proc. IEEE S&P"},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.5555\/177910.177914"},{"key":"e_1_3_2_1_27_1","first-page":"221","volume-title":"USENIX SEC","author":"Gao X.","year":"2018","unstructured":"X. Gao, Y. Yang, C. Liu, C. Mitropoulos, J. Lindqvist, and A. Oulasvirta, ''Forgetting of passwords: Ecological theory and data,'' in Proc. USENIX SEC 2018, pp. 221-238."},{"key":"e_1_3_2_1_28_1","first-page":"2043","volume-title":"USENIX SEC","author":"Gavazzi A.","year":"2023","unstructured":"A. Gavazzi, R. Williams, E. Kirda, L. Lu, A. King, A. Davis, and T. Leek, ''A study of Multi-Factor and Risk-Based authentication availability,'' in Proc. USENIX SEC 2023, pp. 2043-2060."},{"key":"e_1_3_2_1_29_1","first-page":"1230","volume-title":"ACM CCS","author":"Golla M.","year":"2016","unstructured":"M. Golla, B. Beuscher, and M. D\u00fcrmuth, ''On the security of cracking-resistant password vaults,'' in Proc. ACM CCS 2016, pp. 1230-1241."},{"key":"e_1_3_2_1_30_1","first-page":"109","volume-title":"USENIX SEC","author":"Golla M.","year":"2021","unstructured":"M. Golla, G. Ho, M. Lohmus, M. Pulluri, and E. M. Redmiles, ''Driving 2FA adoption at scale: Optimizing Two-Factor authentication notification design patterns,'' in Proc. USENIX SEC 2021, pp. 109-126."},{"key":"e_1_3_2_1_31_1","volume-title":"April","author":"Goud N.","year":"2024","unstructured":"N. Goud, UK says NO to ransom passwords such as admin, 123456 and qwerty, April 2024, https:\/\/www.cybersecurity-insiders.com\/uk-says-no-to-ransom-passwords-such-as-admin-123456-and-qwerty\/."},{"key":"e_1_3_2_1_32_1","unstructured":"P. A. Grassi E. M. Newton R. A. Perlner and et al. ''uppercaseNIST 800-63B digital identity guidelines: Authentication and lifecycle management '' McLean VA Tech. Rep. Mar. 2020."},{"key":"e_1_3_2_1_33_1","first-page":"1","volume-title":"NDSS","author":"Herley C.","year":"2019","unstructured":"C. Herley and S. E. Schechter, ''Distinguishing attacks from legitimate authentication traffic at scale,'' in Proc. NDSS 2019, pp. 1-13."},{"key":"e_1_3_2_1_34_1","first-page":"1019","volume-title":"USENIX SEC","author":"Islam M.","year":"2023","unstructured":"M. Islam, M. S. Bohuk, P. Chung, T. Ristenpart, and R. Chatterjee, ''Ara na: Discovering and characterizing password guessing attacks in practice,'' in Proc. USENIX SEC 2023, pp. 1019-1036."},{"key":"e_1_3_2_1_35_1","first-page":"758","volume-title":"EUROCRYPT","author":"Jaeger J.","year":"2016","unstructured":"J. Jaeger, T. Ristenpart, and Q. Tang, ''Honey encryption beyond message recovery security,'' in Proc. EUROCRYPT 2016, pp. 758-788."},{"key":"e_1_3_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-55220-5_17"},{"key":"e_1_3_2_1_37_1","volume-title":"USENIX SEC","author":"Lai R. W.","year":"2018","unstructured":"R. W. Lai, C. Egger, M. Reinert, S. S. Chow, M. Maffei, and D. Schr\u00f6der, ''Simple password-hardened encryption services,'' in Proc. USENIX SEC 2018."},{"key":"e_1_3_2_1_38_1","volume-title":"May","author":"Lakshmanan R.","year":"2023","unstructured":"R. Lakshmanan, KeePass exploit allows attackers to recover master passwords from memory, May 2023, https:\/\/thehackernews.com\/2023\/05\/keepass-exploit-allows-attackers-to.html."},{"key":"e_1_3_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1145\/3274694.3274714"},{"key":"e_1_3_2_1_40_1","first-page":"689","article-title":"study of probabilistic password models","author":"Ma J.","year":"2014","unstructured":"J. Ma, W. Yang, M. Luo, and N. Li, ''A study of probabilistic password models,'' in Proc. IEEE S&P 2014, pp. 689-704.","journal-title":"Proc. IEEE S&P"},{"key":"e_1_3_2_1_41_1","first-page":"175","volume-title":"USENIX SEC","author":"Melicher W.","year":"2017","unstructured":"W. Melicher, B. Ur, S. Komanduri, L. Bauer, N. Christin, and L. F. Cranor, ''Fast, lean and accurate: Modeling password guessability using neural networks,'' in Proc. USENIX SEC 2017, pp. 175-191."},{"key":"e_1_3_2_1_42_1","doi-asserted-by":"publisher","DOI":"10.1145\/3576915.3623150"},{"key":"e_1_3_2_1_43_1","first-page":"2165","volume-title":"USENIX SEC","author":"Oesch S.","year":"2020","unstructured":"S. Oesch and S. Ruoti, ''That was then, this is now: A security evaluation of password generation, storage, and autofill in browser-based password managers,'' in Proc. USENIX SEC 2020, pp. 2165-2182."},{"key":"e_1_3_2_1_44_1","volume-title":"ACM CHI","author":"Oesch S.","year":"2022","unstructured":"S. Oesch, S. Ruoti, J. Simmons, and A. Gautam, ''''It basically started using me:'' An observational study of password manager usage,'' in Proc. ACM CHI 2022."},{"volume-title":"Opera","year":"2016","key":"e_1_3_2_1_45_1","unstructured":"Opera server breach incident, Opera, Aug. 2016, https:\/\/blogs.opera.com\/security\/2016\/08\/opera-server-breach-incident\/."},{"key":"e_1_3_2_1_46_1","volume-title":"Beyond credential stuffing: Password similarity models using neural networks,'' in Proc","author":"Pal B.","year":"2019","unstructured":"B. Pal, T. Daniel, R. Chatterjee, and T. Ristenpart, ''Beyond credential stuffing: Password similarity models using neural networks,'' in Proc. IEEE S&P 2019."},{"key":"e_1_3_2_1_47_1","volume-title":"Improving password guessing via representation learning,'' in Proc","author":"Pasquini D.","year":"2021","unstructured":"D. Pasquini, A. Gangwal, G. Ateniese, M. Bernaschi, and M. Conti, ''Improving password guessing via representation learning,'' in Proc. IEEE S&P 2021."},{"key":"e_1_3_2_1_48_1","doi-asserted-by":"publisher","DOI":"10.1145\/3321705.3329818"},{"key":"e_1_3_2_1_49_1","volume-title":"May","author":"Peslyak A.","year":"2019","unstructured":"A. Peslyak, John the Ripper password cracker, May 2019, http:\/\/www.openwall.com\/john\/."},{"key":"e_1_3_2_1_50_1","volume-title":"ESORICS","author":"Rao T.","year":"2023","unstructured":"T. Rao, Y. Su, P. Xu, Y. Zheng, W. Wang, and H. Jin, ''You reset I attack! A master password guessing attack against honey password vaults,'' in Proc. ESORICS 2023."},{"key":"e_1_3_2_1_51_1","volume-title":"Oct.","author":"Shittu H.","year":"2023","unstructured":"H. Shittu, LastPass Data Breach Results in $4.4 Million Crypto Loss for 25 Victims in a Single Day, Oct. 2023, https:\/\/cryptonews.com\/news\/lastpass-data-breach-results-in-4-4-million-crypto-loss-for-25-victims-in-a-single-day\/."},{"key":"e_1_3_2_1_52_1","volume-title":"June","author":"Siegrist J.","year":"2015","unstructured":"J. Siegrist, LastPass hacked - Identified early and resolved, June 2015, https:\/\/blog.lastpass.com\/2015\/06\/lastpass-security-notice\/."},{"key":"e_1_3_2_1_53_1","volume-title":"Sok: Authentication in augmented and virtual reality,'' in Proc","author":"Stephenson S.","year":"2022","unstructured":"S. Stephenson, B. Pal, S. Fan, E. Fernandes, Y. Zhao, and R. Chatterjee, ''Sok: Authentication in augmented and virtual reality,'' in Proc. IEEE S&P 2022."},{"key":"e_1_3_2_1_54_1","unstructured":"J. Steube Hashcat Aug. 2025 https:\/\/hashcat.net\/hashcat\/."},{"key":"e_1_3_2_1_55_1","doi-asserted-by":"publisher","DOI":"10.1145\/3183341"},{"key":"e_1_3_2_1_56_1","first-page":"445","volume-title":"IMC","author":"Thomas D. R.","year":"2017","unstructured":"D. R. Thomas, S. Pastrana, A. Hutchings, R. Clayton, and A. R. Beresford, ''Ethical issues in research using datasets of illicit origin,'' in Proc. IMC 2017, pp. 445-462."},{"key":"e_1_3_2_1_57_1","volume-title":"ACM CCS","author":"Thomas K.","year":"2017","unstructured":"K. Thomas, F. Li, A. Zand, J. Barrett, J. Ranieri, L. Invernizzi, Y. Markov, O. Comanescu, V. Eranti, A. Moscicki et al., ''Data breaches, phishing, or malware? Understanding the risks of stolen credentials,'' in Proc. ACM CCS 2017."},{"key":"e_1_3_2_1_58_1","volume-title":"Dec.","author":"Toubba K.","year":"2022","unstructured":"K. Toubba, Notice of Recent Security Incident, Dec. 2022, https:\/\/blog.lastpass.com\/posts\/2022\/12\/notice-of-recent-security-incident."},{"key":"e_1_3_2_1_59_1","volume-title":"April","author":"Viezelyte K.","year":"2024","unstructured":"K. Viezelyte, Juggling security: How many passwords does the average person have in 2024?, April 2024, https:\/\/nordpass.com\/blog\/how-many-passwords-does-average-person-have\/."},{"key":"e_1_3_2_1_60_1","volume-title":"Nov.","author":"Vigderman A.","year":"2024","unstructured":"A. Vigderman, America's Password Habits, Nov. 2024, https:\/\/www.security.org\/resources\/online-password-strategies\/."},{"key":"e_1_3_2_1_61_1","volume-title":"Market structure and equilibrium. hskip 1em plus 0.5em minus 0.4emrelax Springer Science & Business Media","author":"Von Stackelberg H.","year":"2010","unstructured":"H. Von Stackelberg, Market structure and equilibrium. hskip 1em plus 0.5em minus 0.4emrelax Springer Science & Business Media, 2010."},{"key":"e_1_3_2_1_62_1","volume-title":"Dec.","author":"Whittaker Z.","year":"2018","unstructured":"vspace0mmZ. Whittaker, Why you need to use a password manager, Dec. 2018, https:\/\/techcrunch.com\/2018\/12\/25\/cybersecurity-101-guide-password-manager\/?guccounter=1."},{"key":"e_1_3_2_1_63_1","doi-asserted-by":"publisher","DOI":"10.1145\/3176258.3176332"},{"key":"e_1_3_2_1_64_1","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2017.2721359"},{"key":"e_1_3_2_1_65_1","first-page":"947","volume-title":"USENIX SEC","author":"Wang D.","year":"2023","unstructured":"D. Wang, X. Shan, Q. Dong, Y. Shen, and C. Jia, ''No single silver bullet: Measuring the accuracy of password strength meters,'' in Proc. USENIX SEC 2023, pp. 947-964."},{"key":"e_1_3_2_1_66_1","volume-title":"USENIX SEC","author":"Wang D.","year":"2019","unstructured":"D. Wang, P. Wang, D. He, and Y. Tian, ''Birthday, name and bifacial-security: uppercaseUnderstanding passwords of uppercaseChinese web users,'' in Proc. USENIX SEC 2019."},{"key":"e_1_3_2_1_67_1","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978339"},{"key":"e_1_3_2_1_68_1","first-page":"966","article-title":"How to attack and generate honeywords","author":"Wang D.","year":"2022","unstructured":"D. Wang, Y. Zou, Q. Dong, Y. Song, and X. Huang, ''How to attack and generate honeywords,'' in Proc. IEEE S&P 2022, pp. 966-983.","journal-title":"Proc. IEEE S&P"},{"key":"e_1_3_2_1_69_1","volume-title":"USENIX SEC","author":"Wang D.","year":"2023","unstructured":"D. Wang, Y. Zou, Y.-A. Xiao, S. Ma, and X. Chen, ''PASS2EDIT: A multi-step generative model for guessing edited passwords,'' in Proc. USENIX SEC, 2023."},{"key":"e_1_3_2_1_70_1","first-page":"965","volume-title":"USENIX SEC","author":"Wang D.","year":"2023","unstructured":"D. Wang, Y. Zou, Z. Zhang, and K. Xiu, ''Password guessing using random forest,'' in Proc. USENIX SEC 2023, pp. 965-982."},{"key":"e_1_3_2_1_71_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICDCS.2016.90"},{"key":"e_1_3_2_1_72_1","first-page":"391","article-title":"Password cracking using probabilistic context-free grammars","author":"Weir M.","year":"2009","unstructured":"M. Weir, S. Aggarwal, B. de Medeiros, and B. Glodek, ''Password cracking using probabilistic context-free grammars,'' in Proc. IEEE S&P 2009, pp. 391-405.","journal-title":"Proc. IEEE S&P"},{"key":"e_1_3_2_1_73_1","first-page":"157","volume-title":"USENIX SEC","author":"Wheeler D.","year":"2016","unstructured":"D. Wheeler, ''Zxcvbn: Low-budget password strength estimation,'' in Proc. USENIX SEC 2016, pp. 157-173."},{"key":"e_1_3_2_1_74_1","volume-title":"May","author":"Whitney L.","year":"2011","unstructured":"L. Whitney, LastPass CEO reveals details on security breach, May 2011, https:\/\/www.cnet.com\/news\/privacy\/lastpass-ceo-reveals-details-on-security-breach\/."},{"key":"e_1_3_2_1_75_1","first-page":"5555","volume-title":"USENIX SEC","author":"Xiu K.","year":"2024","unstructured":"K. Xiu and D. Wang, ''PointerGuess: Targeted password guessing model using pointer mechanism,'' in Proc. USENIX SEC 2024, pp. 5555-5572."},{"key":"e_1_3_2_1_76_1","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3484743"},{"key":"e_1_3_2_1_77_1","first-page":"1001","volume-title":"USENIX SEC","author":"Xu M.","year":"2023","unstructured":"M. Xu, J. Yu, X. Zhang, C. Wang, S. Zhang, H. Wu, and W. Han, ''Improving real-world password guessing attacks via bi-directional Transformers,'' in Proc. USENIX SEC 2023, pp. 1001-1018."},{"key":"e_1_3_2_1_78_1","first-page":"682","article-title":"RankGuess: Password guessing using adversarial ranking","author":"Yang T.","year":"2025","unstructured":"T. Yang and D. Wang, ''RankGuess: Password guessing using adversarial ranking,'' in Proc. IEEE S&P 2025, pp. 682-700.","journal-title":"Proc. IEEE S&P"},{"key":"e_1_3_2_1_79_1","first-page":"581","volume-title":"SOUPS","author":"Zibaei S.","year":"2022","unstructured":"S. Zibaei, D. R. Malapaya, B. Mercier, A. Salehi-Abari, and J. Thorpe, ''Do password managers nudge secure (random) passwords?'' in Proc. SOUPS 2022, pp. 581-597."},{"key":"e_1_3_2_1_80_1","volume-title":"dissertation","author":"Zimmermann V.","year":"2021","unstructured":"V. Zimmermann, ''From the quest to replace passwords towards supporting secure and usable password creation,'' Ph.D. dissertation, 2021."}],"event":{"name":"CCS '25: ACM SIGSAC Conference on Computer and Communications Security","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"],"location":"Taipei Taiwan","acronym":"CCS '25"},"container-title":["Proceedings of the 2025 ACM SIGSAC Conference on Computer and Communications Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3719027.3765162","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,12,22]],"date-time":"2025-12-22T22:26:40Z","timestamp":1766442400000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3719027.3765162"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,11,19]]},"references-count":80,"alternative-id":["10.1145\/3719027.3765162","10.1145\/3719027"],"URL":"https:\/\/doi.org\/10.1145\/3719027.3765162","relation":{},"subject":[],"published":{"date-parts":[[2025,11,19]]},"assertion":[{"value":"2025-11-22","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}