An Experimental Investigation of Text-based CAPTCHA Attacks and Their Robustness

26Citations
Citations of this article
22Readers
Mendeley users who have this article in their library.
Get full text

Abstract

Text-based CAPTCHA has become one of the most popular methods for preventing bot attacks. With the rapid development of deep learning techniques, many new methods to break text-based CAPTCHAs have been developed in recent years. However, a holistic and uniform investigation and comparison of these attacks' effects is lacking due to inconsistent choices of model structures, training datasets, and evaluation metrics. In this article, we perform an experimental investigation on the effects of existing attacks on text-based CAPTCHA schemes. We first summarize existing text-based CAPTCHAs using a newly proposed taxonomy based on their resistance mechanisms and systematically review corresponding attacks in terms of methods and pros/cons. Then, we introduce a unified attack framework that contains a number of different attack modules and transfer learning strategies. Applying this framework, we extensively evaluate the performance of known attacks on 20 CAPTCHA schemes in terms of accuracy and efficiency; then, we investigate the robustness of these widely used schemes and discover the effects of previously unexplored attacks. Finally, we discuss future CAPTCHA designs based on our experimental results and findings. Our work also contributes to the CAPTCHA community by offering an open-access dataset that contains 22 different CAPTCHA sample sets.

Cite

CITATION STYLE

APA

Wang, P., Gao, H., Guo, X., Xiao, C., Qi, F., & Yan, Z. (2023). An Experimental Investigation of Text-based CAPTCHA Attacks and Their Robustness. ACM Computing Surveys, 55(9). https://doi.org/10.1145/3559754

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free