Capture the Bot: Using Adversarial Examples to Improve CAPTCHA Robustness to Bot Attacks

Capture the Bot: Using Adversarial Examples to Improve CAPTCHA Robustness to Bot Attacks
复制标题

DOI:
10.1109/mis.2020.3036156
复制
发表时间:
2020-10
影响因子:
6.4
通讯作者:
Dorjan Hitaj;B. Hitaj;S. Jajodia;L. Mancini
Dorjan Hitaj;B. Hitaj;S. Jajodia;L. Mancini
中科院分区:
计算机科学3区
文献类型:
--
作者:
Dorjan Hitaj;B. Hitaj;S. Jajodia;L. Mancini

文献摘要

相似文献

迄今为止,Captchas是防止(恶意)机器人对基于Web的服务的未经授权访问的第一道防线,同时还要维持人类访客的无故障体验。表明,使用机器学习中的进步(ML)可以轻松地绕过基于验证码的防御,这是一种基于验证的捕获。我们试图“充分利用”此类机制,以提高现有的验证码方案的鲁棒性和安全性。可以有效地阻止基于ML的机器人求解器。
To date, CAPTCHAs have served as the first line of defense to prevent unauthorized access by (malicious) bots to web-based services, while at the same time maintaining a trouble-free experience for human visitors. However, recent work in the literature has shown that sophisticated bots using advancements in Machine Learning (ML) can easily bypass existing CAPTCHA-based defenses. This work introduces CAPTURE, a novel CAPTCHA scheme based on adversarial examples. Typically adversarial examples are used to lead an ML model astray. With CAPTURE, we attempt to make a “good use” of such mechanisms in order to increase the robustness and security of existing CAPTCHA schemes. Our empirical evaluations show that CAPTURE can produce CAPTCHA challenges that are easy for humans to solve, while at the same time, CAPTURE can effectively thwart sophisticated ML-based bot solvers.