Prof. Por Lip Yee, Professor at CSNET, Universiti Malaya.
Prof. Por Lip Yee was invited as a Keynote Speaker at the International Conference on Neural Networks and Natural Language Processing (NNNLP 2025), where he introduced a new approach to graphical password security through his keynote "A Cognitive-Aware, Graph-Based Graphical Authentication Scheme for Enhanced Shoulder-Surfing Resistance and Usability". The work proposes a framework that addresses the fundamental tension between authentication security and usability through a human-in-the-loop design approach.
The Limits of Traditional Authentication
Alphanumeric passwords remain the dominant authentication mechanism in most systems, yet they carry well-known structural weaknesses. Complexity requirements, while intended to improve security, push users toward predictable patterns such as substituting letters with numbers or appending predictable suffixes to dictionary words. These patterns are precisely what brute-force and dictionary attacks are designed to exploit. Graphical password systems attempt to sidestep these weaknesses by leveraging visual memory and pattern recognition, which tend to be more natural and robust for human users than generating and recalling arbitrary character strings.
The Remaining Vulnerability: Shoulder Surfing
Despite their advantages, existing graphical password systems face a persistent threat: shoulder-surfing attacks. When an attacker directly observes or records a user's authentication interaction, the predictability of graphical schemes makes it feasible to infer the underlying credential from a single session. This threat intensifies in public or shared environments where visual privacy cannot be controlled. The proposed framework addresses this gap by fundamentally altering the relationship between what an attacker can observe and what constitutes a valid credential.
The Proposed Framework
The system integrates three core mechanisms within a unified graph-based computational model. Dynamic image segmentation continuously changes how challenge images are divided and presented, ensuring that the visual appearance of each authentication session differs from previous ones. Stochastic pattern overlays introduce randomised graphical elements that obscure the meaningful components of each challenge from external observation without disrupting the legitimate user's ability to identify their selection. Adaptive cognitive load balancing monitors the estimated cognitive demand of each challenge and adjusts its complexity dynamically, keeping the experience within a usable range and preventing the performance degradation that often accompanies increased security measures. The graph-based model provides formal structure for reasoning about authentication state transitions and challenge relationships across sessions.
Evaluation Results
Evaluation combined simulation-based testing and human-subject experiments across realistic usage scenarios. The proposed scheme achieved an average reduction of approximately 18% in authentication time compared to conventional graphical authentication methods, alongside measurable improvements in resilience against observational inference across multiple attack categories. User feedback confirmed that the scheme is perceived as both usable and trustworthy, validating the human-in-the-loop design approach. The framework is positioned as a viable solution for secure, usability-aware authentication in sensitive domains including healthcare, finance, and educational platforms.
The paper was presented at NNNLP 2025, the International Conference on Neural Networks and Natural Language Processing.