Analyzing keystroke dynamics (KD) for biometric verification has several advantages: it is among the most discriminative behavioral traits; keyboards are among the most common human-computer interfaces, being the primary means for users to enter textual data; its acquisition does not require additional hardware, and its processing is relatively lightweight; and it allows for transparently recognizing subjects. However, the heterogeneity of experimental protocols and metrics, and the limited size of the databases adopted in the literature impede direct comparisons between different systems, thus representing an obstacle in the advancement of keystroke biometrics. To alleviate this aspect, we present a new experimental framework to benchmark KD-based biometric verification performance and fairness based on tweet-long sequences of variable transcript text from over 185,000 subjects, acquired through desktop and mobile keyboards, extracted from the Aalto Keystroke Databases. The framework runs on CodaLab in the form of the Keystroke Verification Challenge (KVC). Moreover, we also introduce a novel fairness metric, the Skewed Impostor Ratio (SIR), to capture inter- and intra-demographic group bias patterns in the verification scores. We demonstrate the usefulness of the proposed framework by employing two state-of-the-art keystroke verification systems, TypeNet and TypeFormer, to compare different sets of input features, achieving a less privacy-invasive system, by discarding the analysis of text content (ASCII codes of the keys pressed) in favor of extended features in the time domain. Our experiments show that this approach allows to maintain satisfactory performance.
翻译:分析击键动力学(KD)用于生物特征验证具有若干优势:它是最具区分性的行为特征之一;键盘作为最常见的人机交互界面之一,是用户输入文本数据的主要手段;其采集无需额外硬件,且处理过程相对轻量;同时能够透明地对用户进行识别。然而,文献中实验方案和评估指标的异质性,以及所采用数据库的规模限制,阻碍了不同系统间的直接比较,从而成为击键生物特征识别发展的障碍。为缓解这一问题,我们提出了一种新的实验框架,基于来自Aalto击键数据库中超过18.5万名用户通过桌面和移动键盘采集的变长推文文本序列,对基于KD的生物特征验证性能与公平性进行基准评估。该框架以击键验证挑战(KVC)的形式运行于CodaLab平台。此外,我们提出了一种新的公平性度量指标——偏斜冒用率(SIR),用于捕捉验证分数中群体间和群体内的偏差模式。通过采用两种最先进的击键验证系统TypeNet和TypeFormer,我们比较了不同的输入特征集,证明了所提框架的有效性。通过摒弃对文本内容(按键的ASCII码)的分析,转而采用时域扩展特征,我们实现了隐私侵入性更低的系统。实验表明,该方法能够保持令人满意的性能。