Yunkai Zou

dblp:273/1791 · DBLP profile ↗
← Back
8ranked-venue papers
2as first author
8since 2021 · last 2026
0000-0003-2399-1532ORCID · reported

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 8 · 2 first-author · 8 since 2021
YearPublicationVenuePosition
2026 Success Rates Doubled with Only One Character: Mask Password Guessing
Yunkai Zou, Ding Wang 0002, Fei Duan
NDSS1
2025 Password Guessing Using Large Language Models
Yunkai Zou, Maoxiang An, Ding Wang 0002
USENIX Security Symposium1
2024 EditPSM: A New Password Strength Meter Based on Password Reuse via Deep Learning
Zhenduo Hou, Yunkai Zou, Ding Wang 0002
Inscrypt (1)3
2024 Prob-Hashcat: Accelerating Probabilistic Password Guessing with Hashcat by Hundreds of Times
abstract
While the academic community has proposed dozens of probabilistic password guessing models to improve the success rate of password guessing, few studies have considered the speed of generating password guesses (which is a crucial factor in realistic password guessing scenarios). Real-world attackers often aim to crack more passwords in less time, and the speed of these models thus becomes a significant concern. Consequently, real-world attackers tend to prefer simple heuristic methods (such as Rule attack and Mask attack) and off-the-shelf password cracking tools (such as Hashcat and John the Ripper), over academic probabilistic password guessing models, despite the latter’s superior scientific flavor.
Ding Wang 0002, Yunkai Zou
RAID3
2023 Password Guessing Using Random Forest
Ding Wang 0002, Yunkai Zou, Zijian Zhang 0003, Kedong Xiu
USENIX Security Symposium2
2023 Pass2Edit: A Multi-Step Generative Model for Guessing Edited Passwords
Ding Wang 0002, Yunkai Zou, Yuan-an Xiao, Siqi Ma 0001, Xiaofeng Chen 0001
USENIX Security Symposium2
2022 Improving Deep Learning Based Password Guessing Models Using Pre-processing
Ding Wang 0002, Yunkai Zou
ICICS3
2022 How to Attack and Generate Honeywords
abstract
Honeywords are decoy passwords associated with each user account to timely detect password leakage. The key issue lies in how to generate honeywords that are hard to be differentiated from real passwords. This security mechanism was first introduced by Juels and Rivest at CCS’13, and has been covered by hundreds of media and adopted in dozens of research domains. Existing research deals with honeywords primarily in an ad hoc manner, and it is challenging to develop a secure honeyword-generation method and well evaluate (attack) it. In this work, we tackle this problem in a principled approach. We first propose four theoretic models for characterizing the attacker $\mathcal{A}$’s best distinguishing strategies, with each model based on a different combination of information available to $\mathcal{A}$ (e.g., public datasets, the victim’s personal information and registration order). These theories guide us to design effective experiments with real-world password datasets to evaluate the goodness (flatness) of a given honeyword-generation method.Armed with the four best attacking theories, we develop the corresponding honeyword-generation method for each type of attackers, by using various representative probabilistic password guessing models. Through a series of exploratory investigations, we show the use of these password models is not straightforward, but requires creative and significant efforts. Both empirical experiments and user-study results demonstrate that our methods significantly outperform prior art. Besides, we manage to resolve several previously unexplored challenges that arise in the practical deployment of a honeyword method. We believe this work pushes the honeyword research towards statistical rigor.
Ding Wang 0002, Yunkai Zou, Qiying Dong, Yuanming Song 0002, Xinyi Huang 0001
SP2