Blog

What Behavioural Biometrics Measure

Behavioural biometrics sits alongside device fingerprinting but measures something different. It models how a person operates an interface rather than what their device reports about itself.

The subject is motor behaviour

Human input is produced by muscles under neural control, and that production process has consistent characteristics: acceleration profiles, correction patterns, and the timing of pauses between actions.

These characteristics are stable enough to be recognisable and difficult to alter deliberately, because they operate below conscious control. People cannot easily choose to type with a different rhythm for long.

What is measured is the dynamics, not the content. The system models how a field was filled in rather than what was entered into it.

Distributions matter more than averages

A single measurement is meaningless. The models work on distributions built from many observations within a session and across sessions.

Human distributions have characteristic shapes, particularly long tails caused by interruption and hesitation. Those tails are the part that scripted input most consistently fails to reproduce.

Comparison is therefore statistical, asking whether an observed distribution is plausible for the population or for this specific account rather than whether a value falls in a range.

Two different questions are being asked

The first is whether the input was produced by a human at all, which is a population-level question answered against general models of human interaction.

The second is whether it was produced by this particular human, which requires an enrolled profile built from that account's own history and is a much stronger claim.

Systems conflate these at their peril. Population-level plausibility is common and weakly identifying; individual matching needs enough enrolment data to be meaningful and degrades when a person changes device.

Context contaminates the measurement

The same person types differently on a phone than on a keyboard, differently when tired, and differently when copying text rather than composing it.

Assistive technologies change the picture entirely. Screen readers, switch access and voice input produce input patterns that no human-typing model recognises as human.

Systems that fail to account for this generate false positives concentrated on disabled users, which is both a fairness problem and a legal exposure in most jurisdictions.

The data is sensitive by nature

Interaction dynamics captured at fine resolution can reveal more than intended, including hesitation over particular fields and, with careless capture, the content being typed.

Responsible implementations extract features on the device and transmit only derived statistics, keeping raw event streams out of the collection path entirely. Where consent regimes apply, this data usually falls within them.