Research on the Security of Visual Reasoning CAPTCHA

被引:0
|
作者
Gao, Yipeng [1 ]
Gao, Haichang [1 ]
Luo, Sainan [1 ]
Zi, Yang [1 ]
Zhang, Shudong [1 ]
Mao, Wenjie [1 ]
Wang, Ping [1 ]
Shen, Yulong [1 ]
Yan, Jeff [2 ]
机构
[1] Xidian Univ, Sch Comp Sci & Technol, Xian, Peoples R China
[2] Linkoping Univ, Dept Comp & Informat Sci, Linkoping, Sweden
关键词
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
CAPTCHA is an effective mechanism for protecting computers from malicious bots. With the development of deep learning techniques, current mainstream text-based CAPTCHAs have been proven to be insecure. Therefore, a major effort has been directed toward developing image-based CAPTCHAs, and image-based visual reasoning is emerging as a new direction of such development. Recently, Tencent deployed the Visual Turing Test (VTT) CAPTCHA. This appears to have been the first application of a visual reasoning scheme. Subsequently, other CAPTCHA service providers (Geetest, NetEase, Dingxiang, etc.) have proposed their own visual reasoning schemes to defend against bots. It is, therefore, natural to ask a fundamental question: are visual reasoning CAPTCHAs as secure as their designers expect? This paper presents the first attempt to solve visual reasoning CAPTCHAs. We implemented a holistic attack and a modular attack, which achieved overall success rates of 67.3% and 88.0% on VTT CAPTCHA, respectively. The results show that visual reasoning CAPTCHAs are not as secure as anticipated; this latest effort to use novel, hard AI problems for CAPTCHAs has not yet succeeded. Based on the lessons we learned from our attacks, we also offer some guidelines for designing visual CAPTCHAs with better security.
引用
收藏
页码:3291 / 3308
页数:18
相关论文
共 50 条
  • [1] Extended Research on the Security of Visual Reasoning CAPTCHA
    Wang, Ping
    Gao, Haichang
    Xiao, Chenxuan
    Guo, Xiaoyan
    Gao, Yipeng
    Zi, Yang
    IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2023, 20 (06) : 4976 - 4992
  • [2] A CAPTCHA DESIGN BASED ON VISUAL REASONING
    Wang, Haipeng
    Zheng, Feng
    Chen, Zhuoming
    Lu, Yi
    Gao, Jing
    Wei, Renjia
    2018 IEEE INTERNATIONAL CONFERENCE ON ACOUSTICS, SPEECH AND SIGNAL PROCESSING (ICASSP), 2018, : 1967 - 1971
  • [3] Security of Visual Captcha for Authentication Procedures
    Ogiela, Urszula
    Takizawa, Makoto
    Ogiela, Lidia
    ADVANCES IN NETWORK-BASED INFORMATION SYSTEMS, NBIS-2017, 2018, 7 : 148 - 152
  • [4] Security and Understanding Techniques for Visual CAPTCHA Interpretation
    Krzyworzeka, Natalia
    Ogiela, Lidia
    ADVANCES ON P2P, PARALLEL, GRID, CLOUD AND INTERNET COMPUTING (3PGCIC-2017), 2018, 13 : 277 - 283
  • [5] Research on the Security of Microsoft's Two-Layer Captcha
    Gao, Haichang
    Tang, Mengyun
    Liu, Yi
    Zhang, Ping
    Liu, Xiyang
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2017, 12 (07) : 1671 - 1685
  • [6] Usability and Security of Arabic Text-based CAPTCHA Using Visual Cryptography
    Alsuhibany, Suliman A.
    Alquraishi, Meznah
    COMPUTER SYSTEMS SCIENCE AND ENGINEERING, 2022, 40 (02): : 421 - 440
  • [7] Usability and security of Arabic text-based CAPTCHA using visual cryptography
    Alsuhibany S.A.
    Alquraishi M.
    Computer Systems Science and Engineering, 2021, 40 (02): : 421 - 440
  • [8] CAPTCHA Security A Case Study
    Yan, Jeff
    El Ahmad, Ahmad Salah
    IEEE SECURITY & PRIVACY, 2009, 7 (04) : 22 - 28
  • [9] Algorithm To Break Visual CAPTCHA
    Chandavale, A. A.
    Sapkal, A. M.
    Jalnekar, R. M.
    2009 SECOND INTERNATIONAL CONFERENCE ON EMERGING TRENDS IN ENGINEERING AND TECHNOLOGY (ICETET 2009), 2009, : 1169 - 1173
  • [10] Simple Visual CAPTCHA Approach
    Arif, Hera
    Hajjdiab, Hassan
    Khalil, Ashraf
    2016 IEEE INTERNATIONAL CONFERENCE ON KNOWLEDGE ENGINEERING AND APPLICATIONS (ICKEA 2016), 2016, : 108 - 112