Claudy Picard and Samuel Pierre
Article (2023)
Open Acess document in PolyPublie and at official publisher |
|
Open Access to the full text of this document Published Version Terms of Use: Creative Commons Attribution Download (1MB) |
Abstract
Conventional authentication systems, that are used to protect most modern mobile applications, are faced with usability and security problems related to their static and one-shot nature. Indeed, one-shot authentication mechanisms challenge the user at the beginning of a session leaving them vulnerable to attacks on lost/stolen devices or session hijacking. In addition, static authentication mechanisms always use the same challenges to authenticate the user without considering the dynamic nature of the risk related to the authentication context. To mitigate these challenges, we propose RLAuth, a risk-based authentication system that can automatically adapt the level of challenge presented to the user on each authentication request based on the current context. RLAuth is based on binary anomaly detection, which is solved using a deep reinforcement learning agent that acts as the classifier. To cope with the high class imbalance in the anomaly detection problem, we propose to use a balanced sampling technique during experience replay and an imbalanced correction factor during reward computation. We evaluate RLAuth on a public dataset using the G-mean metric which is the square root of the product of sensitivity with specificity. This metric is efficient to measure the classification performance of a model under class imbalance since it does not overfit to the majority class. Finally, RLAuth obtained a G-Mean of 92.62%. In addition, the reinforcement learning agent can be trained offline for acceptable results in about 130 s and can then be periodically retrained to improve its performance over time.
Subjects: | 2800 Artificial intelligence > 2800 Artificial intelligence (Computer vision, see 2603) |
---|---|
Department: | Department of Computer Engineering and Software Engineering |
Research Center: | LARIM - Mobile Computing and Networking Research Laboratory |
PolyPublie URL: | https://publications.polymtl.ca/54142/ |
Journal Title: | IEEE Access (vol. 11) |
Publisher: | Institute of Electrical and Electronics Engineers |
DOI: | 10.1109/access.2023.3286376 |
Official URL: | https://doi.org/10.1109/access.2023.3286376 |
Date Deposited: | 24 Jul 2023 13:47 |
Last Modified: | 30 Sep 2024 14:52 |
Cite in APA 7: | Picard, C., & Pierre, S. (2023). RLAuth: A risk-based authentication system using reinforcement learning. IEEE Access, 11, 61129-61143. https://doi.org/10.1109/access.2023.3286376 |
---|---|
Statistics
Total downloads
Downloads per month in the last year
Origin of downloads
Dimensions