as a basic rule of thumb, any paper on cybersecurity that does not start the discussion with a reference attack vector and listed assumptions is probably garbage.
a charitable interpretation would be that they left out such details in the leading summary, but those details matter more than the actual findings. if im an IT manager and trying to decide how to lock phones, an accurate threat model is more important than the mitigations. good mitigations against the wrong threat is much, much worse than bad mitigations against the correct threat
EDIT: woops! i did the bad thing thats ruining society and read the web article instead of the paper. the paper has a whole section on picking a threat model. i dont have time to read the whole thing, but my skimming seems to be that the list length of actually used 4 digit pins is of comparable size to 6 digit pins, which is surprising but the paper still feels a little bit published-for-the-sake-of-publishing