Overview
Password security research and education depend on realistic datasets, but the field faces a real dilemma: older public password datasets are safe to use but increasingly outdated, while newer, more realistic data is too sensitive to access, share, or study directly.
This project develops ethical ways to measure how well a password dataset reflects real-world behavior, and methods for generating new synthetic datasets that are both realistic and safe to share — without ever touching real, breached credentials. The results will also be turned into teaching material so students can study realistic password security without exposure to sensitive data. An NSF proposal for this work has been submitted; in the meantime, the project continues with the lab's own resources.
Related Publications
Back to Research & ProjectsQuick Facts
- Type: Research
- Status: Active
- Funding: NSF proposal submitted; self-funded in the meantime
- Lead: Ali Arslan, Suleyman Uludag, Halil Bisgin