On the Insecurity of Internally Sampled Honeyword Schemes
inforesearchPeer-Reviewed
security
Source: IEEE Xplore (Security & AI Journals)April 23, 2026
Summary
Honeywords are fake passwords (decoys) stored alongside real passwords to detect when password databases are leaked. This research reveals critical security flaws in honeyword schemes that generate decoys by sampling from actual user passwords (internal sampling), showing that attackers can distinguish real passwords from decoys with success rates of 3.82%–44.8% depending on their capabilities, which exceeds the intended security target of 2.50%.
Classification
Attack SophisticationModerate
Monthly digest — independent AI security research
Original source: http://ieeexplore.ieee.org/document/11494073
First tracked: May 8, 2026 at 08:01 PM
Classified by LLM (prompt v3) · confidence: 95%