Detection of password reuse and credential stuffing: a server-side approach

Abstract The widespread adoption of password-based authentication across diverse digital platforms, has significantly heightened exposure to security threats. Due to memorability constraints, users often reuse passwords across multiple platforms, thereby increasing vulnerability to credential-stuffing attacks. Although password managers mitigate this issue, they face practical adoption challenges. Existing password reuse detection mechanisms typically require access to sensitive credentials, raising serious privacy concerns. Password database breach detection represents another critical and challenging problem. Among existing approaches, honeyword-based techniques have gained considerable attention in the research community; however, generating realistic and secure honeywords remains a non-trivial task. To address the above mentioned challenges, we propose two privacy-preserving protocols built on Private Set Intersection (PSI). We first introduce a Password Reuse Detection (PRD) protocol with two instantiations: a Diffie–Hellman (DH)-based PSI construction and an Oblivious Transfer (OT)-based PSI construction. We further present a Breach Detection (BD) protocol that leverages DH-based PSI to identify credential-stuffing attacks in real time. Compared to existing approaches, including Wang et al., our PRD protocol achieves approximately 2.8 $$\\times $$ improvement in computational efficiency and reduced storage overhead for 5000 honeywords, while the BD protocol enables real-time detection. Both protocols prevent disclosure of password values during cross-site comparison and preserve user privacy. We formally prove their semantic security in the Real-or-Random (RoR) model under the Decisional Diffie–Hellman (DDH) assumption.

Authors

Institutions

Publication Details

Journal
Scientific Reports
Published
2026-09-18
DOI
https://doi.org/10.1038/s41598-026-71089-x
Primary Topic
User Authentication and Security Systems
Type
article
Field-Weighted Citation Impact
0.00
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
article

Detection of password reuse and credential stuffing: a server-side approach

Sunil Panday, Sweta Mishra, Sai Sandilya Konduru, Ashutosh Mishra
Scientific Reports
User Authentication and Security Systems
article

Detection of password reuse and credential stuffing: a server-side approach

Sunil Panday, Sweta Mishra, Sai Sandilya Konduru, Ashutosh Mishra
article en

Abstract

Abstract The widespread adoption of password-based authentication across diverse digital platforms, has significantly heightened exposure to security threats. Due to memorability constraints, users often reuse passwords across multiple platforms, thereby increasing vulnerability to credential-stuffing attacks. Although password managers mitigate this issue, they face practical adoption challenges. Existing password reuse detection mechanisms typically require access to sensitive credentials, raising serious privacy concerns. Password database breach detection represents another critical and challenging problem. Among existing approaches, honeyword-based techniques have gained considerable attention in the research community; however, generating realistic and secure honeywords remains a non-trivial task. To address the above mentioned challenges, we propose two privacy-preserving protocols built on Private Set Intersection (PSI). We first introduce a Password Reuse Detection (PRD) protocol with two instantiations: a Diffie–Hellman (DH)-based PSI construction and an Oblivious Transfer (OT)-based PSI construction. We further present a Breach Detection (BD) protocol that leverages DH-based PSI to identify credential-stuffing attacks in real time. Compared to existing approaches, including Wang et al., our PRD protocol achieves approximately 2.8 $$\times $$ improvement in computational efficiency and reduced storage overhead for 5000 honeywords, while the BD protocol enables real-time detection. Both protocols prevent disclosure of password values during cross-site comparison and preserve user privacy. We formally prove their semantic security in the Real-or-Random (RoR) model under the Decisional Diffie–Hellman (DDH) assumption.

Scientific Reports
National Institute of Technology Manipur (IN), Shiv Nadar University (IN)
Peace, Justice and strong institutions
Openalex Percentile: Top 4%
User Authentication and Security Systems
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.

Detection of password reuse and credential stuffing: a server-side approach — Sunil Panday, Sweta Mishra, et al. · Scientific Reports (2026) | TGRS Research Map | TGRS