We present a systematic review of keystroke-dynamics authentication across classical machine learning (ML), deep learning (DL), hybrid, and emerging quantum-ML approaches. The review synthesizes evidence from desktop, mobile, and web settings; compares common datasets (e.g., CMU, GREYC, Aalto, Clarkson); and evaluates models using EER, FAR, and FRR. Three findings stand out. First, dataset breadth, device context, and evaluation protocol explain much of the variance reported in the literature; on free-text inputs, modern DL (e.g., Transformers, Siamese networks) typically achieves EER ≈0.01–2% on large, diverse sets, outperforming classical ML. Second, hybrid designs, feature extraction with DL plus classical classifiers or multimodal fusion (keystroke + touch/mouse), improve robustness and user experience relative to single-modality systems. Third, claims of near-perfect accuracy from quantum-ML are confined to small or simulated studies and are not yet generalized. We map model risks to the OWASP Authentication Cheat Sheet (replay/spoofing, template security, adversarial examples, lockout usability) and outline mitigations (MFA, liveness, cancelable templates, throttling). Finally, we chart a practical pipeline and highlight near-term directions: federated learning and edge deployment for privacy/latency, explainable AI for auditability, and standardized benchmarks for fair comparison.
Gündoğan et al. (Fri,) studied this question.