Abstract
Generative reasoning models introduce a new paradigm in cybersecurity, enabling not only novel defenses but also sophisticated attack simulations. This article investigates the use of open-source reasoning models to simulate credential tweaking behavior and enhance password-based authentication security in Internet of Things (IoT) environments. We propose hybrid similarity scoring (HSS) and its user-contextualized variant HSSuser, a lightweight, client-side similarity metric combining structural (Damerau-Levenshtein) and character-distribution (cosine similarity) components to detect password reuse and subtle modifications or tweaks in real time. Following NIST guidelines, we analyzed over 4 billion password pairs from breached datasets and used five prompt designs in various reasoning models, such as DeepSeek-R1, Qwen-QwQ, Phi4-Reasoning, Qwen3, and Magistral series to generate password variants mimicking attacker strategies. Experimental results show that reasoning models can produce highly similar modifications resembling real-world password reuse patterns, while prompt reframing significantly reduces risky outputs. HSS effectively quantifies these behaviors and is suitable for deployment in constrained IoT devices, offering an intent-aware, proactive layer of client-side defense against AI-enhanced credential attacks.
Author supplied keywords
Cite
CITATION STYLE
Ajes, E. T., Rabbani, M., Anbiaee, Z., Lu, R., Mirani, M., Piya, G., … Dadkhah, S. (2026). Evaluating Generative Reasoning Models for Credential Tweaking and Lightweight Client-Side Defense in IoT Ecosystems. IEEE Internet of Things Journal, 13(9), 17815–17831. https://doi.org/10.1109/JIOT.2025.3602717
Register to see more suggestions
Mendeley helps you to discover research relevant for your work.