Research on the Security of Visual Reasoning CAPTCHA

被引:0
|
作者
Gao, Yipeng [1 ]
Gao, Haichang [1 ]
Luo, Sainan [1 ]
Zi, Yang [1 ]
Zhang, Shudong [1 ]
Mao, Wenjie [1 ]
Wang, Ping [1 ]
Shen, Yulong [1 ]
Yan, Jeff [2 ]
机构
[1] Xidian Univ, Sch Comp Sci & Technol, Xian, Peoples R China
[2] Linkoping Univ, Dept Comp & Informat Sci, Linkoping, Sweden
来源
PROCEEDINGS OF THE 30TH USENIX SECURITY SYMPOSIUM | 2021年
关键词
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
CAPTCHA is an effective mechanism for protecting computers from malicious bots. With the development of deep learning techniques, current mainstream text-based CAPTCHAs have been proven to be insecure. Therefore, a major effort has been directed toward developing image-based CAPTCHAs, and image-based visual reasoning is emerging as a new direction of such development. Recently, Tencent deployed the Visual Turing Test (VTT) CAPTCHA. This appears to have been the first application of a visual reasoning scheme. Subsequently, other CAPTCHA service providers (Geetest, NetEase, Dingxiang, etc.) have proposed their own visual reasoning schemes to defend against bots. It is, therefore, natural to ask a fundamental question: are visual reasoning CAPTCHAs as secure as their designers expect? This paper presents the first attempt to solve visual reasoning CAPTCHAs. We implemented a holistic attack and a modular attack, which achieved overall success rates of 67.3% and 88.0% on VTT CAPTCHA, respectively. The results show that visual reasoning CAPTCHAs are not as secure as anticipated; this latest effort to use novel, hard AI problems for CAPTCHAs has not yet succeeded. Based on the lessons we learned from our attacks, we also offer some guidelines for designing visual CAPTCHAs with better security.
引用
收藏
页码:3291 / 3308
页数:18
相关论文
共 50 条
  • [41] THE CAPTCHA CONFLICT - A CONSUMER'S CHOICE BETWEEN SECURITY AND CONVENIENCE
    Zorn, Steffen
    Hayati, Pedram
    Marketing Dynamism & Sustainability-Things Change, Things Stay the Same..., 2015, : 62 - 65
  • [42] A survey of research on CAPTCHA designing and breaking techniques
    Zhang, Yang
    Gao, Haichang
    Pei, Ge
    Luo, Sainan
    Chang, Guoqin
    Cheng, Nuo
    2019 18TH IEEE INTERNATIONAL CONFERENCE ON TRUST, SECURITY AND PRIVACY IN COMPUTING AND COMMUNICATIONS/13TH IEEE INTERNATIONAL CONFERENCE ON BIG DATA SCIENCE AND ENGINEERING (TRUSTCOM/BIGDATASE 2019), 2019, : 75 - 84
  • [43] Research of the CAPTCHA Application in Platform Based on AJAX
    Chen, Dong
    CEA'09: PROCEEDINGS OF THE 3RD WSEAS INTERNATIONAL CONFERENCE ON COMPUTER ENGINEERING AND APPLICATIONS, 2009, : 77 - +
  • [44] Research on Text-Based Adversarial CAPTCHA
    Li, Jianming
    Yan, Qiao
    Computer Engineering and Applications, 2023, 59 (21) : 278 - 286
  • [45] Multimedia instructional software for visual reasoning: Visual reasoning tutor (VRT)
    Hubbard, C
    Mengshoel, OJ
    Moon, C
    Kim, YS
    PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON MULTIMEDIA COMPUTING AND SYSTEMS, 1996, : 261 - 268
  • [46] Neuro-Symbolic Visual Reasoning: Disentangling "Visual" from "Reasoning"
    Amizadeh, Saeed
    Palangi, Hamid
    Polozov, Oleksandr
    Huang, Yichen
    Koishida, Kazuhito
    INTERNATIONAL CONFERENCE ON MACHINE LEARNING, VOL 119, 2020, 119
  • [47] Non-Intrusive Intellectual Gaming CAPTCHA for Optimal Web Security
    Rajpal, Deepika
    Tiwari, Abhigyan
    2018 INTERNATIONAL CONFERENCE ON ADVANCED COMPUTATION AND TELECOMMUNICATION (ICACAT), 2018,
  • [48] Application of knowledge-based cognitive CAPTCHA in Cloud of Things security
    Ogiela, Marek R.
    Krzyworzeka, Natalia
    Ogiela, Lidia
    CONCURRENCY AND COMPUTATION-PRACTICE & EXPERIENCE, 2018, 30 (21):
  • [49] Augment CAPTCHA Security Using Adversarial Examples With Neural Style Transfer
    Dinh, Nghia
    Tran-Trung, Kiet
    Hoang, Vinh Truong
    IEEE ACCESS, 2023, 11 : 83553 - 83561
  • [50] Enhancing Security of Online Interfaces: Adversarial Handwritten Arabic CAPTCHA Generation
    Alrasheed, Ghady
    Alsuhibany, Suliman A.
    APPLIED SCIENCES-BASEL, 2025, 15 (06):