A Lightweight Behavioral Biometric Framework using Python and Flask for Continuous Authentication in Online Banking
Bibliographic record
Abstract
Traditional authentication methods in online banking, such as passwords and OTPs, remain vulnerable to phishing, credential theft, and session hijacking. This thesis proposes a lightweight, behavior-based biometric authentication framework that leverages keystroke dynamics and mouse movement patterns to provide continuous user verification. Developed using Python and Flask, the framework captures real-time behavioral data during user interaction without interrupting the user experience. Collected metrics include typing speed, key pressure intervals, cursor trajectories, and click rhythms, which are processed using machine learning models trained to recognize genuine user behavior. The system integrates seamlessly with existing banking web applications, offering a passive second-factor authentication layer that operates continuously in the background. Flask APIs handle secure communication between client-side scripts and the backend, while session management is enhanced through behavior-driven confidence scoring. By dynamically validating the user's identity throughout the session, the framework mitigates risks associated with mid-session impersonation and unauthorized access. This approach emphasizes privacy, scalability, and ease of deployment, making it a practical solution for modern financial institutions seeking to enhance security without compromising usability. The experimental results demonstrate high accuracy and minimal latency, validating the feasibility of behavior-driven authentication in real-world banking environments
Fetched live from OpenAlex and de-inverted. Abstracts are not stored in this database: the inverted indexes are 8.6 GB of the frame’s 9.3 GB of text, and the host has 13 GB free.
How this classification was reachedexpand
Full frame machine prediction
Teacher imitationNot calibrated prevalence, not ground truth. Human validation pending. The Gemma side is a direct model label for every work in the frame, read from the title-only record. The Codex side is a classifier learned from the 10,348 direct Codex labels and calibrated to design-weighted sample rates; fields without enough sample support carry no Codex call. Candidate is the union of the two sides; consensus is their intersection. These outputs are machine_predicted_unvalidated and are not human labels.
Distilled classifier scores by category (both heads)
| Category | Codex | Gemma |
|---|---|---|
| Metaresearch | 0.002 | 0.004 |
| Meta-epidemiology (narrow) | 0.001 | 0.001 |
| Meta-epidemiology (broad) | 0.001 | 0.001 |
| Bibliometrics | 0.001 | 0.000 |
| Science and technology studies | 0.000 | 0.001 |
| Scholarly communication | 0.001 | 0.003 |
| Open science | 0.002 | 0.005 |
| Research integrity | 0.001 | 0.002 |
| Insufficient payload (model declined to judge) | 0.007 | 0.004 |
Machine scores (provisional)
The two teacher heads of the student model, read on this work. A score orders the frame for review; it never asserts a category, and the validation status ships verbatim with every row.
Baseline scores from an immature model (maturity gate not passed, 7 training rounds). Scores rank; they never assert a category.
score_only:v0-immature-baseline · verbatim from the scoring run: score_only means the number may rank works, and no category label ships from itClassification
machine, unvalidatedMachine predicted; a candidate call from one source (direct Gemma or distilled Codex), not a consensus.
How this classification was reached, model by model and score by score, is at the end of the page under "How this classification was reached".