[Paper Review] A Key to Your Heart: Biometric Authentication Based on ECG Signals
This paper proposes ECG-based biometric authentication using consumer-grade ECG monitors, demonstrating that ECG signals collected over four months maintain sufficient stability for reliable user authentication. With an equal error rate (EER) of 2.4% within sessions and 9.7% across sessions, the study confirms the feasibility of low-cost ECG devices for secure, password-free authentication in real-world settings.
In recent years, there has been a shift of interest towards the field of biometric authentication, which proves the identity of the user using their biological characteristics. We explore a novel biometric based on the electrical activity of the human heart in the form of electrocardiogram (ECG) signals. In order to explore the stability of ECG as a biometric, we collect data from 55 participants over two sessions with a period of 4 months in between. We also use a consumer-grade ECG monitor that is more affordable and usable than a medical-grade counterpart. Using a standard approach to evaluate our classifier, we obtain error rates of 2.4% for data collected within one session and 9.7% for data collected across two sessions. The experimental results suggest that ECG signals collected using a consumer-grade monitor can be successfully used for user authentication.
Motivation & Objective
- To evaluate the long-term stability of ECG signals as a biometric for user authentication over a 4-month period.
- To assess the performance of ECG-based authentication using a consumer-grade, non-invasive ECG monitor rather than medical-grade equipment.
- To compare two evaluation methodologies—EER and HTER—for estimating classifier performance in real-world authentication scenarios.
- To determine whether ECG signals can serve as a reliable, stable, and usable biometric for continuous user authentication.
- To explore the practical feasibility of integrating low-cost ECG sensors into existing access control systems.
Proposed method
- Collected ECG data from 55 participants across two sessions spaced four months apart using a consumer-grade single-lead ECG monitor.
- Used a standard 80/20 train-test split per session, with 80% of the signal used for training and 20% for testing.
- Evaluated classifiers using two distinct approaches: equal error rate (EER) and half-target error rate (HTER), with the latter simulating a realistic threshold-based decision process.
- Applied a leave-one-out cross-validation strategy to minimize bias, where each classifier was trained on data excluding one target user and tested on that user’s data.
- Extracted biometric features from ECG traces and used standard classification models to compare user signals against stored templates.
- Reported performance using EER and HTER metrics, with results aggregated across 49 subjects to ensure statistical robustness.
Experimental results
Research questions
- RQ1Can ECG signals collected via consumer-grade ECG monitors provide stable biometric authentication over a 4-month period?
- RQ2How does the performance of ECG-based authentication degrade when training and testing data are collected across different sessions separated by four months?
- RQ3How do different evaluation methods—EER versus HTER—impact the estimation of classifier error rates in real-world authentication scenarios?
- RQ4To what extent does the use of a consumer-grade ECG device affect the reliability and accuracy of ECG-based biometric systems compared to medical-grade alternatives?
- RQ5Can ECG-based biometric systems be practically deployed in real-world access control systems using low-cost, wearable sensors?
Key findings
- The ECG-based authentication system achieved an equal error rate (EER) of 2.4% when training and testing data were collected within the same session, indicating strong performance under short-term conditions.
- When training data came from the first session and test data from the second session (four months later), the EER increased to 9.7%, demonstrating a measurable degradation in performance over time.
- Using the half-target error rate (HTER) metric, the system achieved 4.58% HTER in-session and 30.02% HTER across sessions, reflecting a more realistic performance estimate under threshold-based decision rules.
- The study confirms that ECG signals are sufficiently stable and unique for biometric authentication, even with low-cost consumer-grade ECG monitors, supporting their use in practical systems.
- The results show that ECG-based biometrics remain viable for continuous authentication, though performance degrades over time, suggesting the need for periodic template updates.
- The study highlights the potential of integrating low-cost ECG sensors into existing authentication systems, provided that spoofing resistance and user privacy are addressed in future work.
Better researchstarts right now
From reading papers to final review, dramatically reduce your research time.
No credit card · Free plan available
This review was created by AI and reviewed by human editors.