An ML and GenAI-based application that analyzes password strength, identifies potential weaknesses, and generates stronger password suggestions.
The system combines machine learning-based strength scoring, dictionary-based analysis using the RockYou dataset, and Mistral AI for generating alternative password suggestions.
Application: https://passwordstrengthanalyzer.onrender.com
Project Presentation: https://www.canva.com/design/DAGqbLW6gy0/s9N9_gviSXHVTyesxpp7RQ/edit
Password Strength Analyzer evaluates a user's password using multiple approaches rather than relying on a single rule-based check.
The application performs:
User Password
↓
Password Analysis
↓
┌───────────────────────────┐
│ ML-based Strength Scoring │
│ Dictionary Analysis │
└───────────────────────────┘
↓
Weakness Identification
↓
AI-generated Suggestions
↓
Stronger Password Alternatives
The project was developed to explore the use of machine learning and generative AI in cybersecurity-oriented applications.
-
🔢 Machine Learning Strength Scoring Uses a trained machine learning model to evaluate password strength.
-
📖 Dictionary-Based Analysis Supports analysis against the RockYou password dataset to identify commonly used passwords or password patterns.
-
🤖 AI-Generated Suggestions Uses the Mistral AI API to generate alternative password suggestions.
-
⚙️ Flask Backend Provides the backend application and handles password analysis requests.
-
🔐 Environment-Based Configuration API credentials and configuration values are stored through environment variables rather than hard-coded into the application.
-
🧪 Testable Structure The project includes a dedicated
testsdirectory for testing different inputs and application behavior.
The user provides a password through the application interface.
The password is then passed to the backend for analysis.
The application uses the trained model:
password_strength_model.joblib
to generate a password strength assessment.
The trained model is loaded by the password-strength analysis component in:
backend/ml_models/password_strength_model.py
The application can also use the RockYou dataset as a source of commonly occurring passwords.
This provides an additional check beyond the machine learning model and helps identify passwords that may be commonly used.
When stronger alternatives are required, the application can use the Mistral AI API to generate password suggestions.
The GenAI functionality is implemented separately in:
backend/ml_models/genai_suggestions.py
This keeps the AI suggestion component separate from the main password-strength analysis logic.
PasswordStrengthAnalyzer/
│
├── backend/
│ ├── app.py
│ ├── config.py
│ │
│ └── ml_models/
│ ├── password_strength_model.py
│ └── genai_suggestions.py
│
├── frontend/
│
├── tests/
│
├── password_strength_model.joblib
├── requirements.txt
└── README.md
| Component | Purpose |
|---|---|
app.py |
Flask application entry point |
config.py |
Application configuration |
password_strength_model.py |
Loads and uses the trained ML model |
genai_suggestions.py |
Handles Mistral AI-based suggestions |
password_strength_model.joblib |
Saved machine learning model |
tests/ |
Test cases and mock inputs |
frontend/ |
User interface |
Backend
- Python
- Flask
Machine Learning
- Scikit-learn / trained ML model
- Joblib
Generative AI
- Mistral AI API
Data
- RockYou password dataset
Testing
- Python testing tools
git clone https://github.com/Harshal0308/PasswordStrengthAnalyzer.git
cd PasswordStrengthAnalyzerpython -m venv venvOn Windows:
venv\Scripts\activatepip install -r backend/requirements.txtCreate a .env file according to the application's configuration requirements.
Example:
MISTRAL_API_KEY=your_mistral_api_key
SSL_CERT_PATH=path_to_certificateDo not commit .env files or API keys to the repository.
The project supports dictionary-based analysis using the RockYou password dataset.
If the dataset is unavailable, the dictionary-based analysis component cannot perform its intended comparison.
The dataset should be obtained and used according to its applicable terms and restrictions rather than being unnecessarily committed to the repository.
The project contains a dedicated tests/ directory for testing password inputs and application behavior.
Example test categories include:
- Weak passwords
- Strong passwords
- Common passwords
- Different password patterns
- Mock inputs for application components
Additional test cases can be added as the project evolves.
This project is intended as an educational and development project for exploring password analysis techniques.
It should not be treated as a complete password-security solution.
In particular:
- Passwords should not be stored unnecessarily.
- API keys must be kept outside the source code.
- Real user passwords should not be included in datasets or test files.
- Password-strength results should be treated as an estimation rather than a guarantee of security.
- Add more password-analysis features and test cases.
- Improve the machine learning model using a larger and more diverse dataset.
- Provide more detailed explanations for detected password weaknesses.
- Improve the user interface and visualization of strength results.
- Add additional evaluation metrics for the ML model.
- Sidharth Maharana
- Harshal Kale
- Shiv Tangloo
This project was developed to explore the practical application of machine learning, dictionary-based analysis, Flask, and generative AI in a cybersecurity-related problem.
It demonstrates how multiple analysis techniques can be combined to provide password-strength feedback and generate alternative suggestions.