Text Captcha Is Dead? A Large Scale Deployment and Empirical Study

Text Captcha Is Dead? A Large Scale Deployment and Empirical Study
复制标题

DOI:
10.1145/3372297.3417258
复制
发表时间:
2020-10
期刊:
Proceedings of the 2020 ACM SIGSAC Conference on Computer and Communications Security
影响因子:
--
通讯作者:
Chenghui Shi;S. Ji;Qianjun Liu;Changchang Liu;YueFeng Chen;Yuan He;Zhe Liu;R. Beyah;Ting Wang
Chenghui Shi;S. Ji;Qianjun Liu;Changchang Liu;YueFeng Chen;Yuan He;Zhe Liu;R. Beyah;Ting Wang
中科院分区:
其他
文献类型:
--
作者:
Chenghui Shi;S. Ji;Qianjun Liu;Changchang Liu;YueFeng Chen;Yuan He;Zhe Liu;R. Beyah;Ting Wang

文献摘要

相似文献

深度学习技术的发展大大提高了计算机识别CAPTCHA(完全自动化的公共图灵测试,以区分计算机和人类)的能力,从而打破或减轻了现有验证码方案的安全性。为了防止这些攻击,最近的工作已经提出利用对抗性机器学习来干扰验证码图片。然而,它们要么需要验证码求解模型的先验知识,要么缺乏对攻击者不断变化的行为的适应性。最重要的是,它们都没有在实际应用中部署,其实际适用性和有效性未知。在这项工作中,我们介绍了advCAPTCHA,一个实用的对抗性验证码生成系统,可以抵御基于深度学习的验证码求解器,并将其部署在一个拥有近十亿用户的大规模在线平台上。据我们所知,这是第一个在国际大型在线平台上部署的此类工作。通过以一种新的方式应用对抗性学习技术,advCAPTCHA可以生成有效的对抗性验证码,从而显著降低攻击者的成功率,这一点已经在一项大规模的在线研究中得到了证明。此外,我们还验证了advCAPTCHA在实际应用中的可行性,以及它在抵御各种攻击的鲁棒性。我们利用现有的用户风险分析系统来识别潜在的攻击者,并向他们提供advCAPTCHA。然后,我们使用他们的答案作为攻击模型的查询。以这种方式,可以调整/微调advCAPTCHA以适应攻击模型的演变。总的来说,advCAPTCHA可以作为在实践中生成强大的验证码的关键推动者,并为验证码开发人员和从业者提供有用的指导。
The development of deep learning techniques has significantly increased the ability of computers to recognize CAPTCHA (Completely Automated Public Turing test to tell Computers and Humans Apart), thus breaking or mitigating the security of existing captcha schemes. To protect against these attacks, recent works have been proposed to leverage adversarial machine learning to perturb captcha pictures. However, they either require the prior knowledge of captcha solving models or lack adaptivity to the evolving behaviors of attackers. Most importantly, none of them has been deployed in practical applications, and their practical applicability and effectiveness are unknown. In this work, we introduce advCAPTCHA, a practical adversarial captcha generation system that can defend against deep learning based captcha solvers, and deploy it on a large-scale online platform with near billion users. To the best of our knowledge, this is the first such work that has been deployed on international large-scale online platforms. By applying adversarial learning techniques in a novel manner, advCAPTCHA can generate effective adversarial captchas to significantly reduce the success rate of attackers, which has been demonstrated by a large-scale online study. Furthermore, we also validate the feasibility of advCAPTCHA in practical applications, as well as its robustness in defending against various attacks. We leverage the existing user risk analysis system to identify potential attackers and serve advCAPTCHA to them. We then use their answers as queries to the attack model. In this manner, advCAPTCHA can be adapted/fine-tuned to accommodate the attack model evolution. Overall, advCAPTCHA can serve as a key enabler for generating robust captchas in practice and providing useful guidelines for captcha developers and practitioners.