利用生成视频的突变边界设计新型验证码,区分人类与AI bots。
BounTCHA: A CAPTCHA Utilizing Boundary Identification in Guided Generative AI-extended Videos
- 通过提示生成扩展视频,制造意外转折点
- 人类识别边界时间偏差显著优于AI系统
- 适合需要高安全性的网页应用防御场景
近年来,多模态大语言模型(MLLMs)快速发展,使AI能够理解文本、图像、视频等多媒体数据,并根据用户指令执行任务。然而,基于AI的机器人正日益突破现有验证码系统,对网络应用构成严重安全威胁,因此亟需设计新型验证码机制。我们观察到人类对视频中突变和边界变化极为敏感,而当前AI系统仍难以有效理解和响应此类变化。基于此,我们设计并实现了一种名为BounTCHA的验证码机制,利用人类对视频过渡中边界变化的感知优势。通过生成式AI根据提示扩展原始视频,引入意外转折与变化,构建用于验证码的引导式短视频生成流程。我们开发了原型系统,采集人类在边界识别上的时间偏差数据,作为区分真人与机器人的重要依据。此外,我们对BounTCHA进行了详尽的安全性分析,验证其对多种攻击类型的鲁棒性。我们希望BounTCHA能成为人工智能时代下保护数百万网络应用的可靠防线。
原文摘要 · Abstract (English)
In recent years, the rapid development of artificial intelligence (AI) especially multi-modal Large Language Models (MLLMs), has enabled it to understand text, images, videos, and other multimedia data, allowing AI systems to execute various tasks based on human-provided prompts. However, AI-powered bots have increasingly been able to bypass most existing CAPTCHA systems, posing significant security threats to web applications. This makes the design of new CAPTCHA mechanisms an urgent priority. We observe that humans are highly sensitive to shifts and abrupt changes in videos, while current AI systems still struggle to comprehend and respond to such situations effectively. Based on this observation, we design and implement BounTCHA, a CAPTCHA mechanism that leverages human perception of boundaries in video transitions and disruptions. By utilizing generative AI's capability to extend original videos with prompts, we introduce unexpected twists and changes to create a pipeline for generating guided short videos for CAPTCHA purposes. We develop a prototype and conduct experiments to collect data on humans' time biases in boundary identification. This data serves as a basis for distinguishing between human users and bots. Additionally, we perform a detailed security analysis of BounTCHA, demonstrating its resilience against various types of attacks. We hope that BounTCHA will act as a robust defense, safeguarding millions of web applications in the AI-driven era.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。