Understanding Password Preferences, Memorability, and Security through a Human-Centered Lens
Duru Paker, Suleyman Ozdel, Enkelejda Kasneci
TLDR
An eye-tracking study reveals AI-generated passwords are stronger but less memorable, and visual attention to context improves password security.
Key contributions
- Compared user, rule-based, and three AI-generated (DeepSeek, ChatGPT, PassGPT) passwords via eye-tracking.
- Found AI-generated passwords are more secure but less memorable than user-created ones.
- Users preferred self-generated passwords despite AI suggestions being stronger.
- Visual attention to contextual cues correlated with higher password entropy, impacting security.
Why it matters
This paper is crucial for understanding the human factors in password security, especially as AI generators become common. It reveals that user behavior, specifically visual attention, significantly impacts password strength, offering new avenues for attention-driven security design.
Original Abstract
Passwords remain the primary authentication method, yet user-created passwords are often the weakest due to the security-usability trade-off. Although AI-based password generators are emerging, little is known about their effectiveness and user perceptions. This eye-tracking study examined how behavior during password creation, selection, and memorization relates to objective and subjective password quality. Four password models, three AI-based (DeepSeek-API, ChatGPT-API, PassGPT) and one rule-based random generator, generated suggestions from participants' self-generated passwords across four website contexts. Eye movements were recorded throughout the experiment. Results confirm the expected trade-off between AI-generated password strength and human memorability but also reveal a novel behavioral link. Despite stronger AI-generated passwords, participants favored self-generated ones. Notably, visual attention to contextual cues was significantly correlated with higher password entropy. This suggests that security is shaped not only by the generation tool but also by users' visual engagement with contextual cues, highlighting the potential of attention-driven security design.
📬 Weekly AI Paper Digest
Get the top 10 AI/ML arXiv papers from the week — summarized, scored, and delivered to your inbox every Monday.