arXiv:2510.02374cs.CRcs.AI2025-10被引 1

用AI出题+打字节奏分析,提升验证码防机器能力

A Hybrid CAPTCHA Combining Generative AI with Keystroke Dynamics for Enhanced Bot Detection

  • 结合大模型出题与打字习惯分析,双重识别真假用户
  • 对自动化脚本和粘贴攻击检测准确率高,人类使用体验好
  • 适合需要高安全性的网站登录、注册场景

完全自动化的公共图灵测试用于区分计算机和人类(CAPTCHA)是网络安全部署的核心组件,但传统实现存在可用性与抗人工智能机器人攻击能力之间的权衡。本文提出一种新型混合式CAPTCHA系统,融合大语言模型(LLMs)带来的认知挑战与击键动态行为生物特征分析。该方法生成动态且不可预测的问题,对人类简单而对自动化代理复杂,同时分析用户输入节奏以区分人类行为与机器模式。我们阐述了系统架构,形式化了击键特征提取方法,并报告实验评估结果。结果显示,双层机制在检测机器人方面表现优异,成功抵御基于粘贴和脚本的模拟攻击,同时在人类用户中保持高可用性评分。本工作展示了结合认知与行为测试构建更安全、更友好新一代CAPTCHA的潜力。

原文摘要 · Abstract (English)

Completely Automated Public Turing tests to tell Computers and Humans Apart (CAPTCHAs) are a foundational component of web security, yet traditional implementations suffer from a trade-off between usability and resilience against AI-powered bots. This paper introduces a novel hybrid CAPTCHA system that synergizes the cognitive challenges posed by Large Language Models (LLMs) with the behavioral biometric analysis of keystroke dynamics. Our approach generates dynamic, unpredictable questions that are trivial for humans but non-trivial for automated agents, while simultaneously analyzing the user's typing rhythm to distinguish human patterns from robotic input. We present the system's architecture, formalize the feature extraction methodology for keystroke analysis, and report on an experimental evaluation. The results indicate that our dual-layered approach achieves a high degree of accuracy in bot detection, successfully thwarting both paste-based and script-based simulation attacks, while maintaining a high usability score among human participants. This work demonstrates the potential of combining cognitive and behavioral tests to create a new generation of more secure and user-friendly CAPTCHAs.

验证码行为识别AI安全

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。