Behaviour-Based Authentication in IoT Environments
This work is done in collaboration with the Joint Research Centre of the European Commission in Ispra, Italy
Project team:
- Dr. Veljko Pejović
- Andraž Krašovec
- Dr. Gianmarco Baldini
Description
Human behaviour is dynamic, activities are performed in different environments, and there is often a lot of multitasking involved. Nevertheless, the methods we use for authentication, such as passwords, are not conceptually different from centuries-old key-based access.
In this work we aim to redesign the authentication so that it harnesses the plethora of sensing-enabled Internet of Things (IoT) devices that surround us. In collaboration with The European Commission’s Joint Research Center (JRC) at Ispra, Italy, we develop machine learning models that are capable of learning how an individual’s behaviour gets reflected in the sensor data, so that later authentication can be performed purely from the unobtrusive sensor data.
At two premises in two different countries we have constructed testbeds for sensor data collection. In total over 70 users conducted different tasks in these testbeds. A part of the data we have collected is publicly available.
We have developed machine learning pipelines that enable:
- High-accuracy continuous behaviour-based authentication from sensor data
- Methods for hiding sensitive information, such as a user’s activity, in the sensor data
In future, we plan to expand our work with the consideration of internal factors, such as a user’s cognitive load, that might affect a person’s behaviour and the way this behaviour is reflected in the sensor data.
Publications:
- A. Krasovec and V. Pejovic
Investigating Sensor Modality Informativeness and Stability for Behavioural Authentication
Human-Computer Interaction Slovenia 2021 (HCI-SI 2021), November 2021
- A. Krasovec, G. Baldini, and V. Pejovic
Opposing Data Exploitation: Behaviour Biometrics for Privacy-Preserving Authentication in IoT Environments
3rd International Workshop on Behavioral Authentication for System Security (BASS) collocated with ARES'21, August 2021
- A. Krasovec, D. Pellarini, D. Geneiatakis, G. Baldini, and V. Pejovic
Not Quite Yourself Today: Behaviour-Based Continuous Authentication in IoT Environments
Proceedings of the ACM on Interactive, Mobile, Wearable and Ubiquitous Technologies (IMWUT), 2020
Code and data: