Source-linked AI summary

Sensor-based Continuous Authentication of Smartphones' Users Using Behavioral Biometrics: A Contemporary Survey

Mohammed Abuhamad, Ahmed Abusnaina, DaeHun Nyang, David Mohaisen

arXiv:2001.08578v2cs.CRcs.HCcs.LG

TL;DR

Mobile devices need secure access control beyond point-of-entry authentication because they store sensitive information and remain vulnerable to unauthorized access. This paper surveys more than 140 sensor-based behavioral-biometric approaches for continuous smartphone authentication, covering six modality groups and their adoption, usability, and performance challenges. The survey organizes the field’s methods and identifies practical constraints including application dependence, computational demands, and power consumption.

  • Problem

    Smartphones require authentication that protects sensitive information continuously, because conventional knowledge-based and physiological approaches generally rely on overt point-of-entry interaction.

  • Method

    The paper surveys and categorizes more than 140 smartphone continuous-authentication studies across motion, gait, keystroke dynamics, gesture, voice, and multimodal biometrics.

  • Results

    The survey reports state-of-the-art approaches and identifies adoption, usability, performance, application-generalization, computation, and power-related challenges across behavioral-biometric authentication.

  • Takeaways & Limitations

    Embedded smartphone sensors support transparent continuous authentication, but practical deployment must account for context dependence, enrollment requirements, computational overhead, and energy use.

Abstract

from arXiv · show

Mobile devices and technologies have become increasingly popular, offering comparable storage and computational capabilities to desktop computers allowing users to store and interact with sensitive and private information. The security and protection of such personal information are becoming more and more important since mobile devices are vulnerable to unauthorized access or theft. User authentication is a task of paramount importance that grants access to legitimate users at the point-of-entry and continuously through the usage session. This task is made possible with today's smartphones' embedded sensors that enable continuous and implicit user authentication by capturing behavioral biometrics and traits. In this paper, we survey more than 140 recent behavioral biometric-based approaches for continuous user authentication, including motion-based methods (28 studies), gait-based methods (19 studies), keystroke dynamics-based methods (20 studies), touch gesture-based methods (29 studies), voice-based methods (16 studies), and multimodal-based methods (34 studies). The survey provides an overview of the current state-of-the-art approaches for continuous user authentication using behavioral biometrics captured by smartphones' embedded sensors, including insights and open challenges for adoption, usability, and performance.

I. INTRODUCTION

Smartphones enable implicit continuous authentication by capturing distinctive behavioral patterns through embedded sensors. This survey synthesizes recent behavioral-biometric methods, compares them systematically, and identifies adoption challenges and research gaps.

  • Motivation: Continuous authentication validates the legitimate user implicitly during device use by capturing behavioral attributes through built-in sensors.These methods are also described as transparent, non-intrusive, adaptive, and progressive.
  • Motivation: Knowledge-based authentication requires repeated entry or memorization and can be inconvenient despite its simplicity and user acceptance.Graphical patterns may also be predictable, with 40% beginning at the top-left node.
  • Motivation: Physiological biometrics provide high efficiency, accuracy, and acceptance but generally require overt user interaction and mainly support point-of-entry authentication.Behavioral biometrics instead support transparent authentication during device use.
  • Scope and contributions: The survey covers more than 140 continuous-authentication works across motion, gait, keystroke dynamics, gesture, voice, and multimodal groups.The paper focuses on behavioral continuous authentication and multimodal methods that may incorporate physiological biometrics.
  • Scope and contributions: Studies are compared by modality, sensors, algorithms, collected data, sample size, and six evaluation metrics.The comparison is intended to clarify how works relate across the field.
  • Scope and contributions: The survey highlights adoption challenges, future work, and common gaps across biometric methods.Its stated aim is to illuminate the field’s current state and challenges for smartphone adoption.

II. CONTINUOUS AUTHENTICATION: DESIGN

Continuous-authentication systems use mobile sensors to model user behavior for authentication and verification. The survey frames these systems within broader biometric applications and sensor-enabled mobile capabilities.

  • System context: Embedded mobile sensors support applications including human-behavior modeling, user authentication, activity recognition, and healthcare monitoring.The passage identifies modern mobile technologies and sensors as the enabling infrastructure.
  • System context: Biometric authentication modalities are categorized into physiological biometrics, behavioral biometrics, and user profiles.This categorization provides the broader design context for continuous-authentication methods.

A. Used Biometric Modalities

Smartphone authentication uses physiological and behavioral biometric modalities enabled by embedded sensors. Common sensor sources include cameras, microphones, accelerometers, and gyroscopes.

  • Modalities: Authentication modalities include physiological biometrics such as face, fingerprint, and iris, alongside behavioral biometrics such as keystrokes, touch gestures, voice, and motion.Figure 1 categorizes these modalities for authentication tasks.
  • Modalities: Embedded cameras, microphones, accelerometers, and gyroscopes enable the sensing of biometric modalities and features.These sensors contribute to the enrollment and authentication process.

B. User Authentication

The authentication design consists of enrollment and verification, with both relying on data acquisition and feature extraction. Enrollment builds stored templates or models, while verification periodically compares incoming features against an authentication criterion.

  • Verification: Verification uses extracted features to validate a legitimate user at entry or periodically throughout the usage session.Continuous verification grants access to legitimate users and denies access to impostors.
  • Enrollment: Enrollment acquires data, extracts features, models the extracted information, and stores the resulting representation.The framework distinguishes template-based and model-based enrollment approaches.
  • Verification: Similarity-based verification grants access when the similarity between input x and template y reaches the predefined threshold t.The decision is C = True if f(x, y) ≥ t and False otherwise.
  • Verification: Model-based enrollment uses probability-based algorithms in which a pretrained model signals the likelihood that input data belongs to the legitimate user.The verification process remains analogous to template-based decision-making but uses the pretrained model.
  • Verification: Verification frequency is bounded by the time required for data acquisition, preprocessing, and classification.The total verification time is described as t_o = t_d + t_p + t_c, with computational power and battery consumption also relevant.

C. Authentication Evaluation Metrics

Authentication systems are evaluated by error rates that distinguish unauthorized access from legitimate-user denial, alongside broader classification metrics. FAR, FRR, and EER are the three most common measures.

  • FAR measures the proportion of attempts in which access is falsely granted to an intruder.
  • FRR measures the proportion of attempts in which access is falsely denied to the legitimate user.
  • EER is the point where FAR is roughly similar to FRR and is widely used to interpret system error.
  • Additional metrics include true-positive rate, true-negative rate, false-positive rate, false-negative rate, accuracy, precision, recall, and F1-score.True-positive and true-negative rates indicate correct validation of legitimate users and denial of impostors, respectively.

D. Behavioral Biometrics and Smartphones’ Capabilities

Behavioral biometrics use smartphone-generated behavioral patterns to support continuous authentication beyond point-of-entry access. Smartphones’ sensors and computing resources enable these systems, but adoption remains constrained by security standards and implementation requirements.

  • Behavioral biometrics continuously authenticate users without explicitly requesting input, extending protection beyond point-of-entry access.
  • Smartphones provide motion, environmental, and position sensors that researchers have leveraged for user authentication.
  • 67% fewer legitimate authentication requests were reported for behavioral biometrics than knowledge-based methods.
  • An intruder could perform more than 1,000 tasks after knowledge-based access but hardly one task with multimodal behavioral biometrics.
  • Surveyed systems require hardware- and software-independent operation and tolerance of network-connectivity differences for successful adoption.
  • Current technology does not meet the 0.01% FAR security standard cited for mass-produced smartphone authentication.

III. MOTION-BASED AUTHENTICATION

Motion-based authentication uses smartphone motion sensors and related behavioral signals to identify users continuously. Reported performance is strong in some studies, but power, resource, attack, and transparency challenges remain.

  • Accelerometers measure three-axis gravitational acceleration, while gyroscopes measure three-axis angular rotation.Accelerometer readings use meters per second squared; gyroscope readings use radians per second.
  • 1.46% FAR and 6.87% FRR were reported for motion-based signatures tested with ten participants’ smartphones.These signatures require user input and do not provide covert, transparent, continuous authentication.
  • 1.2% average EER was reported for phone-skating behavior using motion-sensor data from 20 users.
  • 90% average accuracy was reported for an SVM system using three motion sensors and data from four participants.
  • 4.66% EER was reported for SensorAuth with a five-second window after evaluating five data-augmentation methods.
  • Motion-based authentication reached up to 99.13% accuracy, while motion alone reached up to 96.87% compared with multimodal methods.Combining keystroke dynamics with motion sensors enabled higher authentication accuracy in the cited example.
  • Continuous motion authentication can increase power consumption, computation, and memory overhead, while remaining vulnerable to observation and sensor-inference attacks.Higher sampling rates can significantly increase power consumption.

IV. GAIT-BASED AUTHENTICATION

Gait-based authentication identifies users from walking patterns captured through computer vision and sensory data. The surveyed approaches follow acquisition, preprocessing, walk detection, and temporal or frequency analysis, but smartphone deployment remains constrained by data, placement, and environmental requirements.

  • Gait recognition identifies individuals by their manner of walking using computer vision or sensory data from environmental and wearable sensors.
  • The general pipeline comprises data acquisition, noise-reducing preprocessing, walk detection, and gait-feature analysis.Walk detection may use traditional cycles or machine-learning techniques, while analysis examines time intervals, frequencies, or both.
  • 85% accuracy was exceeded in two k-NN studies, with EERs of 3.54% and 5% for camera- and body-mounted movement capture, respectively.
  • 92% accuracy was achieved by two SVM-based studies using data from 11–14 users.
  • An EER of 3.5% was achieved with fuzzy commitment on 38 users, while another multimodal sensor configuration reached 96% accuracy.
  • Insights and Challenges: Smartphone gait authentication faces challenges from multimodal data collection, sensor placement, and idealized walking or floor conditions.

V. KEYSTROKE-BASED AUTHENTICATION

Keystroke dynamics provide a low-cost behavioral biometric that can continuously validate users during device interaction. Smartphone studies extend typing features with touch, motion sensing, and machine learning, while uncontrolled behavior and periods without typing remain important challenges.

  • Keystroke authentication analyzes distinctive keypress and release patterns during device use for continuous user validation.Common features include keypress frequency, key-release frequency, and latency between presses.
  • Smartphone keystroke methods incorporate touch, swipe, and embedded motion-sensor inputs, including when textual key input is unavailable.
  • More than 90% accuracy was reported for weighted keystroke features, with minimal computational overhead and increased usability.
  • 0% FRR and 2% FAR were reported for a fuzzy classifier using Particle Swarm Optimization and Genetic Algorithms on keystroke behavior.
  • 98.6% accuracy was reached by combining velocity-related metrics with an SVM classifier for ten users.
  • Insights and Challenges: Keystroke methods can reach 99% accuracy and operate on physical or on-screen keyboards, but performance is challenged by behavioral changes and periods without typing.

VI. TOUCH GESTURE-BASED AUTHENTICATION

Touch gestures provide a broad, sensor-rich behavioral modality for continuous authentication, but their performance and generalization depend strongly on application context and user behavior. The survey reports high accuracy, efficient operation, and resistance to mimicry attacks alongside practical deployment challenges.

  • Modality and applications: Touch gestures include swipes, flicks, slides, and handwriting, extending transparent authentication to touchscreen devices.The surveyed applications include smartwatches, digital cameras, navigation systems, and monitors.
  • Features and sensing: Accelerometer, pressure, gravity, velocity, touch-area, and timing features support gesture statistics and user-specific authentication patterns.These features expand the information available beyond the direct touch trajectory.
  • Reported performance: Random Forests achieved an EER of 0.004%, while gesture-based methods reported accuracy above 99%.The cited results illustrate strong performance for selected datasets and models.
  • Insights and challenges: Gesture data varies significantly across applications, limiting generalization and motivating context-aware feature tuning.In a study of 32 users across four applications, context-aware processing improved the accuracy of the device-centric approach.
  • Insights and challenges: Gesture-based authentication can reach 99.9% accuracy, operate efficiently in power and computation, and resist mimicry attacks through multiple independent features.The resistance claim is attributed to the use of several independent gesture features.
  • Insights and challenges: Important open challenges include temporal behavioral changes, application preferences, user activity, and mobility.These factors complicate stable modeling of touch behavior over time.

VII. VOICE-BASED AUTHENTICATION

Voice-based authentication uses speech features spanning physiological and behavioral characteristics, with text-independent operation offering transparency but greater sensitivity to user and environmental variation. Reported systems achieve strong accuracy, although noise and changing user conditions motivate multimodal designs.

  • Voice modality: Voice features combine physiological characteristics of the vocal tract and lips with behavioral traits such as emotion- or age-related tones.This combination creates a broad feature space for speaker analysis.
  • Authentication approaches: Text-independent authentication works regardless of spoken words and supports transparent authentication without user awareness.Its accuracy is challenged by dynamic voice-feature changes caused by user condition and environmental factors.
  • Processing pipeline: Voice recognition typically proceeds through data collection, preprocessing, feature extraction and selection, modeling, and pattern recognition.Feature quality substantially influences speaker-recognition accuracy.
  • Processing pipeline: Spectral features are described as high-quality, simple, and discriminative for speaker recognition.The cited rationale emphasizes distinctiveness and robustness against noise.
  • Reported performance: Reported systems achieved 99.34% accuracy with 1% EER and FAR, while another achieved 95% accuracy and 99% TPR.The 99.34% result used cross-correlation with 21 users and a half-second authentication time; the 95% result used a Gaussian mixed model with 104 users.
  • Challenges: Voice-only authentication is affected by background noise and changes in the user’s physical or emotional state.These shortcomings have led many studies to incorporate voice into multimodal authentication systems.

VIII. MULTIMODAL AUTHENTICATION

Multimodal authentication combines behavioral and physiological signals to improve robustness and security, using feature-, algorithm-, or decision-level fusion. The survey also highlights trade-offs involving data quality, energy use, latency, training cost, model size, and event dependence.

  • Rationale and modalities: Multimodal systems combine multiple biometric modalities to provide more robust and accurate authentication than unimodal systems.They can also address input changes during enrollment and validation and strengthen security against adversarial attacks.
  • Fusion strategies: Fusion may occur at the feature, algorithm, or decision level, combining heterogeneous features, model ensembles, or matching outputs.Feature-level fusion generally requires normalization when sources produce heterogeneous feature spaces.
  • Deployment considerations: Smartphone multimodal authentication is feasible because devices provide sensors for reading several biometric signals.The feasibility is constrained by the quality and cost of collecting data from multiple sources.
  • Reported performance: A gait-and-voice system reduced reported error ranges to 1.97%–11.8%, compared with 2.82%–43.09% for voice and 13.7%–17.2% for gait individually.The method was event-dependent and performed differently depending on whether and how the user was speaking or moving.
  • Reported performance: RiskCog reported 93.8% accuracy for steady users and 95.6% for moving users, validating users within 3.2 seconds on 1,513 users.The system used accelerometer, gyroscope, and gravity-sensor data from mobile or wearable devices.
  • Challenges: Poor input quality and multiple sensor readings can reduce performance while increasing computational and energy demands.The survey identifies data quality and resource consumption as central implementation challenges.
  • Challenges: Multimodal machine-learning systems can increase enrollment time, model size, memory overhead, and inference time.Ensembles support multiple pattern recognitions per legitimate user but add computational costs.

IX. CONCLUSION

The survey concludes that behavioral biometrics offer implicit, transparent, and continuous smartphone authentication by leveraging embedded sensors. It reviews associated methods, benefits, and challenges for secure mobile access control.

  • Conclusion: Behavioral biometrics use embedded smartphone sensors to support efficient continuous authentication beyond point-of-entry access.This contrasts with knowledge-based and physiological methods that require overt user interaction and generally protect access at a single entry point.
Loading 2001.08578v2…