<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta>
      <journal-title-group>
        <journal-title>X (S. Prykhodko);</journal-title>
      </journal-title-group>
    </journal-meta>
    <article-meta>
      <title-group>
        <article-title>Keystroke Dynamics Recognition Using an Eight-Variate Prediction Ellipsoid for Normalized Data with a Reduced Feature Set</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Sergiy Prykhodko</string-name>
          <email>sergiy.prykhodko@nuos.edu.ua</email>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Artem Trukhov</string-name>
          <email>artem.trukhov@gmail.com</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Admiral Makarov National University of Shipbuilding, Heroes of Ukraine Ave.</institution>
          ,
          <addr-line>9, Mykolaiv, 54007</addr-line>
          ,
          <country country="UA">Ukraine</country>
        </aff>
        <aff id="aff1">
          <label>1</label>
          <institution>Odesa Polytechnic National University</institution>
          ,
          <addr-line>Shevchenko Ave., 1, Odesa, 65044</addr-line>
          ,
          <country country="UA">Ukraine</country>
        </aff>
      </contrib-group>
      <volume>000</volume>
      <fpage>0</fpage>
      <lpage>0002</lpage>
      <abstract>
        <p>Keystroke dynamics recognition is a prominent technique in behavioral biometrics, offering continuous and non-intrusive user authentication based on individual typing patterns. It leverages temporal features such as key press durations and inter-key latencies, which are distinctive for each user. Despite advantages like hardware independence and applicability in security-critical contexts, many existing methods rely on the assumption of multivariate normality, which real-world keystroke data often violates, leading to reduced recognition accuracy, recall, and specificity. To address this limitation, this study explores the impact of data-normalizing transformations designed to transform keystroke features toward a multivariate normal distribution. Specifically, it examines the decimal logarithm, univariate Box-Cox, and multivariate Box-Cox transformations. The univariate transformations normalize each feature independently, without considering relationships between them. In contrast, the multivariate Box-Cox transformation processes all features jointly, taking into account their correlations, though it requires more complex computations. Parameters for Box-Cox transformations are estimated using the maximum likelihood method. In contrast to previous work, which utilized a nine-dimensional feature vector composed exclusively of key hold durations, the current approach employs a reduced eight-dimensional feature set that combines key hold times and inter-key latencies. Despite the lower dimensionality, this set offers a more informative and representative characterization of user typing behavior. Results demonstrate that applying normalizing transformations improves recognition accuracy, recall, and specificity, highlighting the importance of data normalization. Among the constructed models, the eightvariate prediction ellipsoid based on normalized data using the multivariate Box-Cox transformation shows the best recognition accuracy, recall, and specificity, significantly outperforming models built on nonnormalized data. In addition, the use of a reduced eight-dimensional feature vector, combining hold durations and inter-key intervals, resulted in a more informative and compact representation of typing behavior, which further improved recognition accuracy, recall, and specificity. These findings emphasize the key role of data normalization and correct feature selection in enhancing the accuracy, recall, and specificity of keystroke dynamics recognition systems. Future work should explore the application of alternative normalizing transformations and evaluate the proposed approach on larger, more diverse datasets that better capture the variability of user behavior.</p>
      </abstract>
      <kwd-group>
        <kwd>keystroke dynamics</kwd>
        <kwd>multivariate normal distribution</kwd>
        <kwd>normalizing transformation</kwd>
        <kwd>mathematical modeling1</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>1. Introduction</title>
      <p>
        Keystroke dynamics recognition is a behavioral biometric technique that identifies or verifies
individuals based on their unique typing patterns [
        <xref ref-type="bibr" rid="ref1">1</xref>
        ]. It analyzes temporal characteristics such as
key press durations and latencies between successive keystrokes, which are difficult to replicate and
remain relatively stable over time. This approach offers a non-intrusive, continuous method of user
authentication and is commonly applied in areas such as secure system access, fraud detection, and
user behavior monitoring, especially in environments where traditional authentication methods may
be insufficient or inconvenient [
        <xref ref-type="bibr" rid="ref2">2</xref>
        ].
      </p>
      <p>
        Since keystroke dynamics systems are typically used for user authentication, they are often
modeled as one-class classification problems, where models are trained only on data from the target
user and aim to detect deviations that may indicate unauthorized access [
        <xref ref-type="bibr" rid="ref3">3</xref>
        ].
      </p>
      <p>
        Many existing methods used for recognition rely on statistical models that assume the underlying
data follow a multivariate normal distribution [
        <xref ref-type="bibr" rid="ref4">4</xref>
        ]. However, in practice, this assumption for
keystroke dynamics data is often violated [
        <xref ref-type="bibr" rid="ref5">5</xref>
        ] due to natural variability in human typing behavior,
noise, and external factors. As a result, the accuracy, recall, and specificity of recognition can
decrease significantly when these models are applied to real-world data.
      </p>
      <p>Given the widespread use of keystroke dynamics recognition, including in security-sensitive
applications, there is a clear need to improve recognition methods to ensure higher recognition
accuracy, recall, and specificity. In particular, enhancing mathematical models to better
accommodate deviations from the multivariate normal distribution can lead to more accurate
systems. This study addresses this challenge by applying normalizing transformations that aim to
adjust keystroke data toward a multivariate Gaussian distribution, thereby aligning more closely
with the assumptions of statistical recognition models.</p>
    </sec>
    <sec id="sec-2">
      <title>2. Literature review</title>
      <p>Keystroke dynamics recognition has become a well-established approach in behavioral biometrics,
used for verifying individuals based on how they type. It typically extracts temporal features such as
key press durations and
interfeatures are widely used due to their stability and ability to differentiate users.</p>
      <p>
        A variety of methods have been employed to recognize typing patterns, including tree-based
models [
        <xref ref-type="bibr" rid="ref6 ref7">6, 7</xref>
        ], support vector machines [
        <xref ref-type="bibr" rid="ref8 ref9">8, 9</xref>
        ], neural networks [
        <xref ref-type="bibr" rid="ref10 ref11">10, 11</xref>
        ], and others.
      </p>
      <p>
        In practical applications such as authentication, keystroke dynamics is frequently modeled as a
one-class classification problem. In this setting, the system is trained solely on data from the target
class and attempts to detect whether new samples match this profile. This approach is particularly
suited to real-world conditions, where data from unauthorized users may not be available during
training. One-class classification is conceptually linked to outlier detection, as it identifies deviations
from the normal behavior of the target user [
        <xref ref-type="bibr" rid="ref12">12</xref>
        ].
      </p>
      <p>
        Several techniques are commonly used in one-class classification, including one-class SVM [
        <xref ref-type="bibr" rid="ref13 ref14">13,
14</xref>
        ], autoencoders [
        <xref ref-type="bibr" rid="ref15 ref16">15, 16</xref>
        ], GANs [
        <xref ref-type="bibr" rid="ref17">17</xref>
        ], and prediction ellipsoids [
        <xref ref-type="bibr" rid="ref18">18</xref>
        ]. Prediction ellipsoids construct
a statistical boundary in the form of a multivariate ellipsoid that encompasses the known data. If a
new point lies outside the ellipsoid, it is considered an outlier. This method is attractive due to its
simplicity and well-defined mathematical formulation, particularly when the input data is assumed
to follow a multivariate normal distribution.
      </p>
      <p>
        However, the accuracy of prediction ellipsoids depends on how closely the data distribution
matches the Gaussian assumption [
        <xref ref-type="bibr" rid="ref19">19</xref>
        ]. In practice, keystroke dynamics data often deviates from
normality due to factors such as individual variability, typing inconsistencies, device differences, and
external noise. These deviations can lead to incorrect estimation of the ellipsoid boundary and result
in decreased recognition accuracy, recall, and specificity.
      </p>
      <p>
        To address this issue, data normalization transformations are used to adjust feature distributions
closer to a multivariate Gaussian [
        <xref ref-type="bibr" rid="ref20">20, 21</xref>
        ]. Common transformations include the decimal logarithm,
univariate Box-Cox, and multivariate Box-Cox transformations. The univariate approaches adjust
each feature independently, while the multivariate Box-Cox transformation jointly transforms all
features while preserving their correlation structure.
      </p>
      <p>In [22], a nine-variate prediction ellipsoid for normalized data was constructed using the
BoxCox transformation. However, the feature set in that study included only key hold times, which in
some cases led to insufficient recognition accuracy. This limitation is addressed in the present study
by using a broader set of temporal features that better represent user behavior.</p>
      <p>This study investigates the impact of normalizing transformations on recognition accuracy, recall,
and specificity in keystroke dynamics. The aim is to improve these metrics by applying
transformations that adjust the data distribution to better align with the Gaussian assumption.</p>
    </sec>
    <sec id="sec-3">
      <title>3. Materials and methods</title>
      <p>Keystroke dynamics recognition relies heavily on the quality, structure, and temporal precision of
the input data. To evaluate the proposed approach, this study uses the CMU Keystroke Dynamics
Benchmark Dataset [23], a widely used [24] and publicly available dataset designed for
authentication research. It contains keystroke data from 51 users, each of whom typed the same fixed
every session, the password was typed 50 times, resulting in a total of 400 samples per subject and
20,400 samples in total.</p>
      <p>Each entry includes timestamps for key press and key release events, recorded with
submillisecond precision. From these events, 31 timing features are derived, including key hold
durations (the time from pressing to releasing a key), keydown keydown (DD) intervals, and keyup
keydown (UD) intervals. Feature names follow a standard notation: H.k for hold time of key k,
DD.k1.k2 for the interval between pressing keys k1 and k2, and UD.k1.k2 for the delay between
equals the corresponding DD value.</p>
      <p>In this study, a reduced subset of eight features was selected to create vector  : H.o, UD.o.a, H.a,
UD.a.n, H.n, UD.n.l, H.l, and UD.l.Return. These features represent a continuous segment of the
password near its end and include both hold times and inter-key latencies [25]. This selection
captures individual key behavior and transitions between keys, providing a compact but informative
representation of typing patterns suitable for multivariate modeling.</p>
      <p>After extracting the feature vectors, an essential preprocessing step involves the identification
and removal of outliers. Such anomalous observations may arise due to involuntary user behavior,
external distractions, hardware inconsistencies, or inaccuracies in event logging. If not addressed,
these outliers can introduce bias into parameter estimation, distort statistical decision boundaries,
and negatively impact the accuracy of recognition models. The removal of outliers ensures that the
training dataset more accurately reflects typical user behavior, thereby enhancing the stability and
interpretability of the resulting model.</p>
      <p>For this purpose, the squared Mahalanobis distance (SMD) is employed, which measures the
distance between each sample and the center of the distribution, accounting for the covariance
between features. Under the assumption that the data follows a multivariate normal distribution, the
SMD of inliers is expected to follow a chi-square distribution with degrees of freedom equal to the
number of features [26]. This statistical property enables the selection of a significance level to define
a threshold beyond which samples are considered outliers.</p>
      <p>However, this approach relies on the assumption that the input data follows an approximately
multivariate Gaussian distribution, which is often not true for raw keystroke dynamics features due
to inherent variability in human typing behavior. To evaluate whether the distribution significantly
deviates from the Gaussian, the Mardia test is applied. This test evaluates the joint distribution of
the features based on two measures: multivariate skewness  1 and multivariate kurtosis  2. If the
test indicates that the data significantly deviates from multivariate normality, a normalization
transformation must be applied to convert a non-Gaussian data  =  1,  2, … ,  8 to a Gaussian
vector  =  1,  2, … ,  8 .</p>
      <p>Normalizing transformations can be categorized into univariate and multivariate approaches.
Univariate transformations, such as the logarithmic and the Box-Cox, operate on individual features
independently. The logarithm is typically used to compress large values and reduce positive
skewness.
parameterized by λ
transformation is defined as:

 =  (λ ) = {( 
λ
 − 1)/λ ,
ln(  ) ,
λ ≠ 0;
λ = 0,
The Box-Cox transformation (BCT) generalizes this adjustment through a power function
where   is a j-th non-Gaussian variable;   is a normalized variable; λ is j-th transformation

 =1

 =1

2
 ( , θ) = ∑( λ − 1) ∑ ln(  ) −
ln[det(  )] ,
which measures h
space and the desired significance level.</p>
      <p>where k is the number of variables;   is the value of variable j for observation i; λ is j-th
transformation parameter;   is the covariance matrix of the transformed data.</p>
      <p>To evaluate whether the data distribution has been successfully approximated to multivariate
normality, the Mardia test is applied to assess multivariate skewness and kurtosis before and after
normalization. If the results confirm sufficient normality, the data can be reliably used in subsequent
modeling stages. Otherwise, further preprocessing or the application of more robust modeling
techniques may be necessary.</p>
      <p>The next step involves constructing the prediction ellipsoid, which defines a decision boundary
for one-class classification. The left-hand side of the comparison is the squared Mahalanobis distance,
a critical value derived from the chi-square distribution, based on the dimensionality of the feature
parameter.
parameters:</p>
      <p>The univariate BCT is applied element-wise to each feature using a single parameter λ. When
dealing with multivariate data, this transformation is typically applied independently to each of the
k features, resulting in k separate transformations, one per feature, with individual parameters drawn
from the k-dimensional vector Ɵ = {λ1, λ2, … , λ }. Determining the optimal values of λ is a crucial
possible. Maximum likelihood estimation (MLE) is commonly employed to identify these optimal
 ( ) = ( − 1) ∑ ln(  ) −

,
where   is the i-th data point; λ is the transformation parameter; N is the number of observations.</p>
      <p>While univariate methods can improve the separate distributions of individual features, they do
not account for the correlations between variables. This limitation is addressed by multivariate
normalization, particularly the multivariate BCT, which applies a transformation to the entire feature
vector. This method preserves the dependency structure among features. The components of the
transformed vector  are defined as in equation (1). However, it requires the estimation of multiple
transformation parameters by maximizing a multivariate log-likelihood function, which may
introduce additional computational complexity:
. The
(1)
(2)
(3)
-hand side is
(4)
( −  ̄ )   −1( −  ̄ ) =  82, 0.005,
where  is a non-Gaussian random vector;   is a sample covariance matrix for initial data;  ̄ is
a vector of sample means of the variables;  82, 0.005 is the chi-square distribution quantile with 8
degrees of freedom and significance level 0.005.</p>
      <p>
        Assuming multivariate normality, the SMD follows a chi-square distribution with degrees of
freedom equal to the number of features, in this study, 8. This allows the threshold to be determined
according to a selected significance level; for one-class classification, a commonly used value is
0.005 [
        <xref ref-type="bibr" rid="ref19">19</xref>
        ].
anomaly, likely representing a different class. If the distance is below the threshold, the point is
accepted as part of the target class.
      </p>
      <p>In cases where the raw data does not follow a Gaussian distribution, normalization is applied first
to bring the data closer to multivariate normality. After this step, the eight-variate prediction
ellipsoid is constructed according to (4):
( −  ̄ )  −1( −  ̄ ) =  28, 0.005,
(5)
where  is a Gaussian random vector;  ̄ is a vector of sample means of the variables;   is a
sample covariance matrix for normalized data;  82, 0.005 is the chi-square distribution quantile with 8
degrees of freedom and significance level 0.005.</p>
      <p>At a significance level of 0.005 and with 8 degrees of freedom, the corresponding critical value
from the chi-square distribution is 21.96. Any sample with a Mahalanobis distance below this value
is considered to lie within the ellipsoid and thus to belong to the target class.</p>
      <p>To evaluate the constructed models, several widely used metrics are applied: accuracy, specificity,
precision, recall, and the F1 score [27, 28]. These metrics are calculated based on four possible
recognition outcomes. A true positive occurs when a sample from the target class is correctly
recognized as a target. A false positive refers to an outlier that is incorrectly identified as belonging
to the target class. A true negative is an outlier sample that is correctly rejected, and a false negative
is a sample that is mistakenly rejected as an outlier.</p>
      <p>Accuracy measures the overall proportion of correctly recognized samples, encompassing both
target and outlier classes. While it provides a general view of system performance, it may be less
informative when class distributions are imbalanced. Recall, also known as sensitivity, indicates the
proportion of target samples that are correctly identified, reflecting the system's ability to minimize
false rejections. Precision expresses the proportion of samples predicted as target that are indeed
from the target class, and is particularly relevant when the cost of false acceptances is high.
Specificity measu
against unauthorized access. Lastly, the F1 score is the harmonic mean of precision and recall. It
provides a single balanced metric that accounts for both false positives and false negatives, which is
particularly useful in scenarios where both types of errors are costly [29].</p>
      <p>Accuracy provides a general measure of overall correctness by considering all samples, both target
and outlier. The probability of recognition is reflected by the combination of recall and specificity.</p>
    </sec>
    <sec id="sec-4">
      <title>4. Experiments</title>
      <p>In this study, the data associated with subject identifier s036 was randomly selected to represent the
target class, while the data from s022 was used to represent an outlier class. Each subject contributed
400 keystroke samples. The first step in the analysis involved identifying and removing outliers from
the target class data. Data preprocessing, normalization, and statistical calculations were performed
using built-in Microsoft Excel formulas and matrix operations.</p>
      <p>To evaluate whether the target data followed a multivariate normal distribution, the Mardia test
was applied. The results indicated significant deviation from normality. Specifically, the test statistic
for multivariate skewness  1/6 was 5207.45, exceeding the quantile of the chi-square distribution,
which is 163.65 for 120 degrees of freedom at a 0.005 significance level. Similarly, the multivariate
kurtosis statistic  2 was 211, which is higher than the corresponding normal quantile value of 83.25,
based on a mean of 80 and a variance of 1.6 at the same significance level. These results suggest that
the raw data significantly deviates from multivariate normality, indicating the need for
normalization before further analysis.</p>
      <p>At this stage, where the primary goal is to detect and remove outliers from the target class data,
the multivariate BCT is applied. This approach is chosen because it adjusts all features
simultaneously while preserving their correlations. In contrast to univariate transformations that
process each feature separately, the multivariate form ensures consistent scaling across the feature
space, which is especially important for computing Mahalanobis distances. Since this distance metric
assumes that the data follows an approximately multivariate normal distribution, the applied
transformation helps bring the feature distribution closer to Gaussian, making it suitable for outlier
detection.</p>
      <p>As a result of applying the maximum likelihood method to the log-likelihood function (3), the
following parameter estimates were obtained: λ̂1 = 0.0523, λ̂2 = 0.1285, λ̂3 = 2.0907, λ̂4 = 0.1095,
λ̂5 = 0.6797, λ̂6 = -2.5205, λ̂7 = -0.8415, λ̂8 = -0,8439.</p>
      <p>After applying the eight-variate BCT, the resulting feature set with component (1) was evaluated
using the Mardia test. The test statistic for multivariate skewness,  1/6 = 396.16, exceeds the
critical value of 163.64 from the chi-square distribution with 120 degrees of freedom at a 0.005
significance level. Similarly, the test statistic for multivariate kurtosis,  2 = 94.04, is higher than the
corresponding quantile value of 83.25, given a mean of 80 and a variance of 1.6.</p>
      <p>These results indicate that, despite the transformation, the data still deviates from multivariate
normality, mainly due to the presence of outliers, which distort the distribution. Nevertheless,
working with the transformed dataset remains advantageous, as it shifts the distribution closer to a
Gaussian form, thereby improving the reliability of Mahalanobis distance calculations in the outlier
detection process.</p>
      <p>Next, the SMD is computed for each feature vector to detect potential outliers. These distances
are compared against the critical value of 21.96 from the chi-square distribution with 8 degrees of
freedom at a significance level of 0.005. In each iteration, only the feature vector with the highest
SMD, if it exceeds the critical value, is removed from the dataset.</p>
      <p>In the first iteration, the 24th vector, which had the maximum SMD of 55.43, was identified as an
outlier and excluded. This process is repeated iteratively: after each removal, the normalization is
applied again using the multivariate BCT, and the SMDs are recalculated for the updated dataset.
The procedure continues until all remaining vectors have SMD values below the threshold. Table 1
presents the indices and corresponding SMD values of all removed outliers. In total, 13 vectors were
excluded.
546.59, exceeds the quantile of the chi-square distribution, which is 163.65 at 120 degrees of freedom
and a significance level of 0.005. In addition, the test statistic for multivariate kurtosis,  2 = 101.39,
is greater than the value of 84.69, based on a normal distribution with a mean of 80, a variance of
3.32, and a 0.005 significance level. These results confirm significant deviation from multivariate
normality. However, the transformation improved the distribution, bringing it closer to the Gaussian.</p>
      <p>The univariate BCT was applied to the training set. Using the maximum likelihood estimation
method for the logarithmic function (2), the following parameter estimates were obtained:
λ̂1 = 0.0501, λ̂2 = 0.1127, λ̂3 = 2.0209, λ̂4 = 0.9140, λ̂5 = 0.9446, λ̂6 = -2.6803, λ̂7 = -1.1806, λ̂8 = -0.9382.
As a result of applying the univariate BCT with components (1), where each variable is transformed
independently of the others, the normalized training set has the following mean vector:  ̅= {-2.9101;
-1.5283; -0.4933; -0.7298; -1.0090; -1.9666; -36.4872; -0.5659}, the corresponding covariance matrix is
presented in Table 5.
 1/6 = 163.03, does not exceed the quantile of the chi-square distribution, which is 163.65 for 120
degrees of freedom at a 0.005 significance level. Similarly, the test statistic for multivariate kurtosis,
 2 = 80.98, remains below the critical threshold of 84.69, calculated for a normal distribution with a
mean of 80 and a variance of 3.32. These results indicate that the distribution of the training set
normalized using the univariate BCT follows an approximately multivariate normal distribution.</p>
      <p>The eight-variate BCT was applied to the training dataset. The parameter estimates were obtained
by maximizing the log-likelihood function (3), resulting in the following values: λ̂1 = 0.0668,
λ̂2 = 0.2385, λ̂3 = 1.9483, λ̂4 = 0.7088, λ̂5 = 0.8871, λ̂6 = -2.5191, λ̂7 = -1.1207, λ̂8 = -0.9131. Unlike the
univariate approach, where each variable is transformed independently, the eight-variate BCT
accounts for the joint structure of the data, preserving the correlations between features.</p>
    </sec>
    <sec id="sec-5">
      <title>5. Results</title>
      <p>The next step is the construction of mathematical models in the form of prediction ellipsoids and the
comparison of recognition metrics. The first model corresponds to the prediction ellipsoid
constructed for non-Gaussian data (4) (PENGD), the original training set without any normalization.
The second model is a prediction ellipsoid for normalized data (5) using the univariate decimal
logarithm transformation (PE-Log). The third model is a prediction ellipsoid for normalized data (5)
transformed by the univariate Box-Cox transformation (PE-UBCT). The fourth model is a prediction
ellipsoid for normalized data (5) by the eight-variate Box-Cox transformation (PE-EBCT).
Recognition metrics for all models are presented in Table 7.</p>
    </sec>
    <sec id="sec-6">
      <title>6. Discussion</title>
      <p>The results demonstrate that applying a prediction ellipsoid for normalized data significantly
improves the recognition accuracy, recall, and specificity when the training set deviates from
multivariate normality. Among the tested transformations, the eight-variate BCT achieved the most
accurate and balanced results, as it preserves the correlations between features.</p>
      <p>The univariate decimal logarithm transformation brought the data closer to multivariate
ated that the distribution still exhibited a statistically significant
deviation. As a result, the corresponding model PE-Log showed improvement in recognition metrics
compared to the non-normalized PE-NGD, but its performance was lower than that of the prediction
ellipsoid for normalized data using other transformations. The PE-UBCT model showed further
improvement, as it more effectively corrected skewness and kurtosis in individual variables.
However, since it transforms features independently, it does not preserve inter-feature dependencies,
which results in lower recognition accuracy, recall, and specificity compared to the multivariate
transformation.</p>
      <p>In all models, prediction ellipsoids were constructed using a significance level of 0.005. This
threshold is commonly used in one-class classification and outlier detection tasks, where high
specificity is desirable. A stricter significance level results in a smaller ellipsoid, reducing the false
positive rate, but may also exclude borderline true positives. The balance between sensitivity and
specificity must therefore be considered when selecting this parameter.</p>
      <p>Another important aspect is the size and representativeness of the training data. Since the
prediction ellipsoid relies on estimating the mean vector and covariance matrix, it requires a
sufficient number of samples to ensure stability. In this study, 13 data points were removed as outliers
before model construction. While this removal improved the approximation to multivariate
normality, it may also have excluded meaningful variation in the data, especially if the outliers
reflected rare but valid behavior.</p>
      <p>Although the eight-variate transformation provided the best results in this experiment, selecting
an appropriate normalization method remains a nontrivial task, particularly when the data have
complex, multimodal, or heavy-tailed distributions.</p>
      <p>The dataset used in this study is limited to input sequences of fixed structure and moderate length,
which may not fully capture the diversity observed in real-world typing behavior. In practical
scenarios, longer input sequences, such as passwords or phrases containing 20 22 characters, are
generally more suitable, as they allow for more comprehensive feature extraction. Moreover, in this
work, only eight features were selected from the available data, which may restrict the model's ability
to fully represent the user's typing dynamics. In addition to the length and content of the typed
password, other important factors were not included in this study. Contextual influences, such as
the user's physical condition, emotional state, time of day, or even environmental conditions like
temperature or humidity, can affect how a person types. These factors may lead to changes in typing
rhythm or key timing and could have a noticeable impact on recognition accuracy in real-world
applications [30]. Although this study focused only on timing features from controlled input, future
work could benefit from considering these real-life conditions, as they may help improve the
reliability and robustness of keystroke-based biometric systems.</p>
    </sec>
    <sec id="sec-7">
      <title>7. Conclusions</title>
      <p>This study explored the impact of non-Gaussian data and examined how the application of prediction
ellipsoids for normalized data affects keystroke dynamics recognition accuracy, recall, and
specificity. A new, reduced feature set was used, consisting of hold time and inter-key time features.
This combination reflects different aspects of user behavior, key press duration, and transition time
between keys, allowing the model to capture more diverse typing characteristics and improve
recognition outcomes.</p>
      <p>The results demonstrated that the application of prediction ellipsoids for normalized data
significantly enhances the recognition accuracy, recall, and specificity. Among the evaluated
transformations, the eight-variate Box-Cox transformation achieved the most accurate and balanced
results. This confirms the advantage of multivariate normalization, which preserves correlations
between features and brings the data closer to a multivariate normal distribution. In contrast,
univariate transformations: decimal logarithm and univariate Box Cox, showed only moderate
improvements, as they treat each feature independently and do not account for inter-feature
dependencies.</p>
      <p>Despite the improvements achieved in this study, there are still some limitations and
disadvantages.</p>
      <p>One disadvantage is the need for a large and representative dataset. Building a reliable prediction
ellipsoid requires enough data to accurately estimate both the average values and the relationships
between features, typically at least 100 samples in the training set. Another disadvantage is the
difficulty of selecting an appropriate normalizing transformation. While the multivariate Box-Cox
transformation gave the best results, choosing the most suitable normalization method is not always
an easy task, especially when the data contains outliers or has a complex structure.</p>
      <p>A key limitation of this work is that 13 outliers were removed before model construction.
Although this improved the fit to a multivariate normal distribution, it may have excluded rare but
valid typing patterns.</p>
      <p>Future research will focus on several directions to further improve keystroke dynamics
recognition. First, more advanced normalization techniques could be explored. While the
multivariate Box-Cox transformation showed the best results in this study, it may not be optimal for
all datasets. The Johnson transformation, for example, may provide better adaptability to complex
or multimodal data distributions, especially when the deviation from normality is strong. Second, it
would be beneficial to use a more comprehensive dataset that includes a larger number of features.
he current dataset contains only 10
characters, while longer sequences, such as those with 20 to 22 characters, are generally preferred,
as they allow for more detailed feature extraction and better capture of individual typing patterns. It
would also be useful to consider contextual factors that can influence keystroke dynamics, such as</p>
    </sec>
    <sec id="sec-8">
      <title>Declaration on Generative AI</title>
      <p>The author(s) have not employed any Generative AI tools.
[21] S. Prykhodko, A. Trukhov, Application of a ten-variate prediction ellipsoid for normalized data
and machine learning algorithms for face recognition, in: Selected Papers of the Seventh
International Workshop on Computer Modeling and Intelligent Systems (CMIS-2024).
Workshop Proceedings (CMIS-2024), Zaporizhzhia, Ukraine, May 3, 2024. CEUR Workshop
Proceedings, vol. 3702, 2024, pp. 362-375. https://ceur-ws.org/Vol-3702/paper30.pdf
[22] S. Prykhodko, A. Trukhov, Application of a Nine-Variate Prediction Ellipsoid for Normalized
Data and Machine Learning Algorithms for Keystroke Dynamics Recognition, in: Proceedings
of the Information Technology and Implementation (IT&amp;I) Workshop: Intelligent Systems and
Security (IT&amp;I-WS 2024: ISS), CEUR Workshop Proceedings, vol. 3933, 2024, pp. 51-64.
https://ceur-ws.org/Vol-3933/Paper_5.pdf
[23] K. Killourhy, R. Maxion, CMU Keystroke Dynamics Benchmark Dataset, Carnegie Mellon</p>
      <p>University. URL: https://www.cs.cmu.edu/~keystroke/.
[24] HC. Chang, J. Li, CS. Wu, M. Stamp, Machine Learning and Deep Learning for Fixed-Text
Keystroke Dynamics, in: Stamp, M., Aaron Visaggio, C., Mercaldo, F., Di Troia, F. (eds) Artificial
Intelligence for Cybersecurity. Advances in Information Security 54 (2022). Springer, Cham.
https://doi.org/10.1007/978-3-030-97087-1_13
[25] I. Tsimperidis, O. Asvesta, E. Vrochidou, G. Papakostas, IKDD: A Keystroke Dynamics Dataset
for User Classification. Information 15 9 (2024) 511. https://doi.org/10.3390/info15090511
[26] T. Etherington, Mahalanobis distances for ecological niche modelling and outlier detection:
implications of sample size, error, and bias for selecting and parameterising a multivariate
location and scatter method, PeerJ 9:e11436, (2021). https://doi.org/10.7717/peerj.11436
[27] S. Nurmaini, A. Darmawahyuni, A. Sakti Mukti, M. Rachmatullah, F. Firdaus, B. Tutuko, Deep
Learning-Based Stacked Denoising and Autoencoder for ECG Heartbeat Classification,
Electronics, 9 135 (2020). https://doi.org/10.3390/electronics9010135
[28] H. Waleed, S. Gadsden, J. Yawney, Financial Fraud: A Review of Anomaly Detection Techniques
and Recent Advances, Expert Systems with Applications 193 (2021) 116429.
https://doi.org/10.1016/j.eswa.2021.116429
[29] X. Wang, D. Hou, Enhancing Keystroke Dynamics Authentication with Ensemble Learning and
Data Resampling Techniques, Electronics 13 22 (2024) 4559.
https://doi.org/10.3390/electronics13224559
[30] S. Bilan, M. Bilan, A. Bilan, Interactive biometric identification system based on the keystroke
dynamic, in: Proceedings of the Biometric Identification Technologies Based on Modern Data
Mining Methods. Springer, Cham, 2021, pp. 39-58. https://doi.org/10.1007/978-3-030-48378-4_3</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          [1]
          <string-name>
            <given-names>R.</given-names>
            <surname>Shadman</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Wahab</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Manno</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Lukaszewski</surname>
          </string-name>
          ,
          <string-name>
            <given-names>D.</given-names>
            <surname>Hou</surname>
          </string-name>
          ,
          <string-name>
            <given-names>F.</given-names>
            <surname>Hussain</surname>
          </string-name>
          , Keystroke Dynamics: Concepts,
          <string-name>
            <surname>Techniques</surname>
          </string-name>
          , and
          <string-name>
            <surname>Applications</surname>
          </string-name>
          , ACM Computer Survey 57
          <volume>11</volume>
          (
          <year>2025</year>
          )
          <article-title>283</article-title>
          . https://doi.org/10.1145/3733103
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          [2]
          <string-name>
            <given-names>P.</given-names>
            <surname>Kasprowski</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Z.</given-names>
            <surname>Borowska</surname>
          </string-name>
          ,
          <string-name>
            <given-names>K.</given-names>
            <surname>Harezlak</surname>
          </string-name>
          ,
          <source>Biometric Identification Based on Keystroke Dynamics, Sensors 22 9</source>
          (
          <year>2022</year>
          )
          <article-title>3158</article-title>
          . https://doi.org/10.3390/s22093158
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          [3]
          <string-name>
            <given-names>S.</given-names>
            <surname>Roy</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Pradhan</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Kumar</surname>
          </string-name>
          ,
          <string-name>
            <given-names>D.</given-names>
            <surname>Adhikary</surname>
          </string-name>
          ,
          <string-name>
            <given-names>U.</given-names>
            <surname>Roy</surname>
          </string-name>
          ,
          <string-name>
            <given-names>D.</given-names>
            <surname>Sinha</surname>
          </string-name>
          ,
          <string-name>
            <given-names>R.</given-names>
            <surname>Pal</surname>
          </string-name>
          ,
          <article-title>A systematic literature review on latest keystroke dynamics based models</article-title>
          .
          <source>IEEE Access</source>
          ,
          <volume>10</volume>
          (
          <year>2022</year>
          )
          <fpage>92192</fpage>
          -
          <lpage>92236</lpage>
          . http://doi.org/10.1109/ACCESS.
          <year>2022</year>
          .3197756
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          [4]
          <string-name>
            <given-names>O.</given-names>
            <surname>Rippel</surname>
          </string-name>
          ,
          <string-name>
            <given-names>P.</given-names>
            <surname>Mertens</surname>
          </string-name>
          ,
          <string-name>
            <given-names>D.</given-names>
            <surname>Merhof</surname>
          </string-name>
          ,
          <article-title>Modeling the distribution of normal data in pre-trained deep features for anomaly detection</article-title>
          ,
          <source>in: 25th IEEE International Conference on Pattern Recognition (ICPR)</source>
          , Milan, Italy,
          <year>2021</year>
          , pp.
          <fpage>6726</fpage>
          -
          <lpage>6733</lpage>
          . http://doi.org/ 10.1109/ICPR48806.
          <year>2021</year>
          .
          <volume>9412109</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          [5]
          <string-name>
            <given-names>O.</given-names>
            <surname>Oyebola</surname>
          </string-name>
          ,
          <article-title>Examining the distribution of keystroke dynamics features on computer, tablet and mobile phone platforms</article-title>
          ,
          <source>in: Proceedings of the Mobile Computing and Sustainable Informatics ICMCSI</source>
          ,
          <year>2023</year>
          , pp.
          <fpage>613</fpage>
          -
          <lpage>620</lpage>
          . DOI: https://doi.org/10.1007/
          <fpage>978</fpage>
          -981-99-0835-6_
          <fpage>43</fpage>
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          [6]
          <string-name>
            <given-names>B.</given-names>
            <surname>Saini</surname>
          </string-name>
          ,
          <string-name>
            <given-names>P.</given-names>
            <surname>Singh</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Nayyar</surname>
          </string-name>
          ,
          <string-name>
            <given-names>N.</given-names>
            <surname>Kaur</surname>
          </string-name>
          ,
          <string-name>
            <given-names>K.</given-names>
            <surname>Bhatia</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>El-Sappagh</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Hu</surname>
          </string-name>
          ,
          <article-title>A three-step authentication model for mobile phone user using keystroke dynamics</article-title>
          .
          <source>IEEE Access</source>
          ,
          <volume>8</volume>
          (
          <year>2020</year>
          )
          <fpage>125909</fpage>
          -
          <lpage>125922</lpage>
          . https://doi.org/10.1109/ACCESS.
          <year>2020</year>
          .3008019
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          [7]
          <string-name>
            <given-names>A.</given-names>
            <surname>Tanapat</surname>
          </string-name>
          ,
          <article-title>Strengthening Password Authentication using Keystroke Dynamics and Smartphone Sensors</article-title>
          ,
          <source>in: Proceedings of the 9th International Conference on Information Communication and Management (ICICM'19)</source>
          , Association for Computing Machinery, New York, NY, USA,
          <year>2019</year>
          , pp.
          <fpage>70</fpage>
          -
          <lpage>74</lpage>
          . https://doi.org/10.1145/3357419.3357425
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          [8]
          <string-name>
            <given-names>Q.</given-names>
            <surname>Li</surname>
          </string-name>
          ,
          <string-name>
            <given-names>H.</given-names>
            <surname>Chen</surname>
          </string-name>
          ,
          <article-title>CDAS: A Continuous Dynamic Authentication System</article-title>
          ,
          <source>in: Proceedings of the 2019 8th International Conference on Software and Computer Applications (ICSCA'19)</source>
          , Association for Computing Machinery, New York, NY, USA,
          <year>2019</year>
          , pp.
          <fpage>447</fpage>
          -
          <lpage>452</lpage>
          . https://doi.org/10.1145/3316615.3316691
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          [9]
          <string-name>
            <given-names>L.</given-names>
            <surname>Chen</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Y.</given-names>
            <surname>Zhong</surname>
          </string-name>
          ,
          <string-name>
            <given-names>W.</given-names>
            <surname>Ai</surname>
          </string-name>
          ,
          <string-name>
            <given-names>D.</given-names>
            <surname>Zhang</surname>
          </string-name>
          ,
          <source>Continuous Authentication Based on User Interaction Behavior, in: Proceedings of the 2019 7th International Symposium on Digital Forensics and Security (ISDFS)</source>
          , Barcelos, Portugal,
          <year>2019</year>
          , pp.
          <fpage>1</fpage>
          -
          <lpage>6</lpage>
          , https://doi.org/10.1109/ISDFS.
          <year>2019</year>
          .8757539
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          [10]
          <string-name>
            <given-names>A.</given-names>
            <surname>Alvin</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Jayabalan</surname>
          </string-name>
          ,
          <string-name>
            <given-names>V.</given-names>
            <surname>Thiruchelvam</surname>
          </string-name>
          ,
          <article-title>Keystroke Dynamics Based User Authentication using Deep Multilayer Perceptron</article-title>
          ,
          <source>International Journal of Machine Learning and Computing</source>
          <volume>10</volume>
          2020
          <fpage>134</fpage>
          -
          <lpage>139</lpage>
          . https://doi.org/10.18178/ijmlc.
          <year>2020</year>
          .
          <volume>10</volume>
          .1.
          <fpage>910</fpage>
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          [11]
          <string-name>
            <surname>H. AbdelRaouf</surname>
          </string-name>
          ,
          <string-name>
            <surname>SA</surname>
          </string-name>
          . Chelloug,
          <string-name>
            <given-names>A.</given-names>
            <surname>Muthanna</surname>
          </string-name>
          ,
          <string-name>
            <given-names>N.</given-names>
            <surname>Semary</surname>
          </string-name>
          ,
          <string-name>
            <given-names>K.</given-names>
            <surname>Amin</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Ibrahim</surname>
          </string-name>
          ,
          <article-title>Efficient Convolutional Neural Network-Based Keystroke Dynamics for Boosting User Authentication</article-title>
          .
          <source>Sensors 23</source>
          <volume>10</volume>
          (
          <year>2023</year>
          )
          <article-title>4898</article-title>
          . https://doi.org/10.3390/s23104898
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          [12]
          <string-name>
            <given-names>H.</given-names>
            <surname>Marques</surname>
          </string-name>
          ,
          <string-name>
            <given-names>L.</given-names>
            <surname>Swersky</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Sander</surname>
          </string-name>
          ,
          <article-title>On the evaluation of outlier detection and one-class classification: a comparative study of algorithms, model selection, and ensembles</article-title>
          ,
          <source>Data Min Knowl Disc</source>
          <volume>37</volume>
          (
          <year>2023</year>
          )
          <fpage>1473</fpage>
          -
          <lpage>1517</lpage>
          . https://doi.org/10.1007/s10618-023-00931-x
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          [13]
          <string-name>
            <given-names>N.</given-names>
            <surname>Seliya</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A. Abdollah</given-names>
            <surname>Zadeh</surname>
          </string-name>
          ,
          <string-name>
            <given-names>T.</given-names>
            <surname>Khoshgoftaar</surname>
          </string-name>
          ,
          <article-title>A literature review on one-class classification and its potential applications in big data</article-title>
          ,
          <source>J Big Data</source>
          <volume>8</volume>
          <fpage>122</fpage>
          (
          <year>2021</year>
          ). https://doi.org/10.1186/s40537- 021-00514-x
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          [14]
          <string-name>
            <given-names>S.</given-names>
            <surname>Yerima</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Bashar</surname>
          </string-name>
          ,
          <article-title>Semi-supervised novelty detection with one class SVM for SMS spam detection</article-title>
          ,
          <source>in: 2022 29th International Conference on Systems, Signals and Image Processing (IWSSIP)</source>
          , Sofia, Bulgaria,
          <year>2022</year>
          , pp.
          <fpage>1</fpage>
          -
          <lpage>4</lpage>
          . https://doi.org/10.1109/IWSSIP55020.
          <year>2022</year>
          .9854496
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          [15]
          <string-name>
            <given-names>A.</given-names>
            <surname>He</surname>
          </string-name>
          ,
          <string-name>
            <given-names>X.</given-names>
            <surname>Jin</surname>
          </string-name>
          ,
          <article-title>Deep Variational Autoencoder Classifier for Intelligent Fault Diagnosis Adaptive to Unseen Fault Categories</article-title>
          ,
          <source>in: IEEE Transactions on Reliability</source>
          , vol.
          <volume>70</volume>
          , no.
          <issue>4</issue>
          , pp.
          <fpage>1581</fpage>
          -
          <lpage>1595</lpage>
          ,
          <year>2021</year>
          . https://doi.org/10.1109/TR.
          <year>2021</year>
          .3090310
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          [16]
          <string-name>
            <given-names>Y.</given-names>
            <surname>Patel</surname>
          </string-name>
          ,
          <string-name>
            <given-names>K.</given-names>
            <surname>Ouazzane</surname>
          </string-name>
          ,
          <string-name>
            <given-names>V.</given-names>
            <surname>Vassilev</surname>
          </string-name>
          , I. Faruqi,
          <string-name>
            <given-names>G. L.</given-names>
            <surname>Walker</surname>
          </string-name>
          ,
          <article-title>Keystroke Dynamics using Auto Encoders</article-title>
          ,
          <source>in: Proceedings of the 2019 International Conference on Cyber Security and Protection of Digital Services (Cyber Security)</source>
          , Oxford, UK,
          <year>2019</year>
          , pp.
          <fpage>1</fpage>
          -
          <lpage>8</lpage>
          , https://doi.org/10.1109/CyberSecPODS.
          <year>2019</year>
          .8885203
        </mixed-citation>
      </ref>
      <ref id="ref17">
        <mixed-citation>
          [17]
          <string-name>
            <given-names>I.</given-names>
            <surname>Eizagirre</surname>
          </string-name>
          ,
          <string-name>
            <given-names>L.</given-names>
            <surname>Segurola-Gil</surname>
          </string-name>
          ,
          <string-name>
            <given-names>F.</given-names>
            <surname>Zola</surname>
          </string-name>
          ,
          <string-name>
            <given-names>R.</given-names>
            <surname>Orduna</surname>
          </string-name>
          , Keystroke Presentation Attack:
          <article-title>Generative Adversarial Networks for replacing user behaviour</article-title>
          ,
          <source>in: Proceedings of the 2022 European Symposium on Software Engineering (ESSE'22)</source>
          .
          <article-title>Association for Computing Machinery</article-title>
          , New York, NY, USA,
          <year>2023</year>
          , pp.
          <fpage>119</fpage>
          -
          <lpage>126</lpage>
          . https://doi.org/10.1145/3571697.3571714
        </mixed-citation>
      </ref>
      <ref id="ref18">
        <mixed-citation>
          [18]
          <string-name>
            <given-names>S.</given-names>
            <surname>Kim</surname>
          </string-name>
          ,
          <string-name>
            <given-names>D.</given-names>
            <surname>Park</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Jung</surname>
          </string-name>
          ,
          <article-title>Evaluation of One-Class Classifiers for Fault Detection: Mahalanobis Classifiers and the Mahalanobis Taguchi System</article-title>
          , Processes,
          <year>2021</year>
          ,
          <volume>9</volume>
          , 1450. https://doi.org/10.3390/pr9081450
        </mixed-citation>
      </ref>
      <ref id="ref19">
        <mixed-citation>
          [19]
          <string-name>
            <given-names>S.</given-names>
            <surname>Prykhodko</surname>
          </string-name>
          ,
          <string-name>
            <given-names>L.</given-names>
            <surname>Makarova</surname>
          </string-name>
          ,
          <string-name>
            <given-names>K.</given-names>
            <surname>Prykhodko</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Pukhalevych</surname>
          </string-name>
          ,
          <article-title>Application of Transformed Prediction Ellipsoids for Outlier Detection in Multivariate Non-Gaussian Data</article-title>
          ,
          <source>in: Proceedings of the 2020 IEEE 15th International Conference on Advanced Trends in Radioelectronics</source>
          , Telecommunications and Computer Engineering (TCSET),
          <source>Lviv-Slavske, Ukraine</source>
          ,
          <year>2020</year>
          , pp.
          <fpage>359</fpage>
          -
          <lpage>362</lpage>
          . https://doi.org/10.1109/TCSET49122.
          <year>2020</year>
          .235454
        </mixed-citation>
      </ref>
      <ref id="ref20">
        <mixed-citation>
          [20]
          <string-name>
            <given-names>K.</given-names>
            <surname>Lam</surname>
          </string-name>
          ,
          <string-name>
            <given-names>K.</given-names>
            <surname>Meijer</surname>
          </string-name>
          ,
          <string-name>
            <given-names>F.</given-names>
            <surname>Loonstra</surname>
          </string-name>
          ,
          <string-name>
            <given-names>E.</given-names>
            <surname>Coerver</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Twose</surname>
          </string-name>
          ,
          <string-name>
            <given-names>E.</given-names>
            <surname>Redeman</surname>
          </string-name>
          ,
          <string-name>
            <given-names>B.</given-names>
            <surname>Moraal</surname>
          </string-name>
          ,
          <string-name>
            <given-names>F.</given-names>
            <surname>Barkhof</surname>
          </string-name>
          ,
          <string-name>
            <given-names>B.</given-names>
            <surname>Uitdehaag</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Killestein</surname>
          </string-name>
          ,
          <article-title>Real-world keystroke dynamics are a potentially valid biomarker for clinical disability in multiple sclerosis, Multiple sclerosis (Houndmills, Basingstoke</article-title>
          , England)
          <volume>27 9</volume>
          (
          <year>2021</year>
          )
          <fpage>1421</fpage>
          -
          <lpage>1431</lpage>
          . https://doi.org/10.1177/1352458520968797
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>