Passwords remain the primary authentication method, yet user-created passwords are often the weakest due to the security-usability trade-off. Although AI-based password generators are emerging, little is known about their effectiveness and user perceptions. This eye-tracking study examined how behavior during password creation, selection, and memorization relates to objective and subjective password quality. Four password models, three AI-based (DeepSeek-API, ChatGPT-API, PassGPT) and one rule-based random generator, generated suggestions from participants' self-generated passwords across four website contexts. Eye movements were recorded throughout the experiment. Results confirm the expected trade-off between AI-generated password strength and human memorability but also reveal a novel behavioral link. Despite stronger AI-generated passwords, participants favored self-generated ones. Notably, visual attention to contextual cues was significantly correlated with higher password entropy. This suggests that security is shaped not only by the generation tool but also by users' visual engagement with contextual cues, highlighting the potential of attention-driven security design.
翻译:密码仍是最主要的认证方法,然而用户创建的密码往往由于安全性与可用性之间的权衡而最为薄弱。尽管基于人工智能的密码生成器正在兴起,但对其有效性及用户感知的研究仍十分有限。本眼动追踪研究考察了在密码创建、选择与记忆过程中的行为如何与客观及主观密码质量相关联。研究采用了四种密码模型,其中三种为基于人工智能的模型(DeepSeek-API、ChatGPT-API、PassGPT),一种为基于规则的随机生成器,从参与者在四种网站情境下自行生成的密码中生成建议。实验全程记录了眼动数据。结果证实了人工智能生成密码强度与人类记忆性之间存在预期的权衡,同时也揭示了一种新颖的行为关联。尽管人工智能生成的密码强度更高,参与者却更青睐自己生成的密码。值得注意的是,对情境线索的视觉关注与更高的密码熵显著相关。这表明,安全性不仅受密码生成工具的影响,还取决于用户对情境线索的视觉投入程度,凸显了以注意力为导向的安全设计潜力。