Completely Automated Public Turing test to tell Computers and Humans Apart, short for CAPTCHA, is an essential and relatively easy way to defend against malicious attacks implemented by bots. The security and usability trade-off limits the use of massive geometric transformations to interfere deep model recognition and deep models even outperformed humans in complex CAPTCHAs. The discovery of adversarial examples provides an ideal solution to the security and usability trade-off by integrating adversarial examples and CAPTCHAs to generate adversarial CAPTCHAs that can fool the deep models. In this paper, we extend the definition of adversarial CAPTCHAs and propose a classification method for adversarial CAPTCHAs. Then we systematically review some commonly used methods to generate adversarial examples and methods that are successfully used to generate adversarial CAPTCHAs. Also, we analyze some defense methods that can be used to defend adversarial CAPTCHAs, indicating potential threats to adversarial CAPTCHAs. Finally, we discuss some possible future research directions for adversarial CAPTCHAs at the end of this paper.
翻译:全自动区分计算机和人类的图灵测试(Completely Automated Public Turing test to tell Computers and Humans Apart,简称CAPTCHA)是一种防御机器人恶意攻击的重要且相对简单的方法。安全性与可用性之间的权衡限制了大规模几何变换对深度模型识别的干扰,而在复杂验证码任务中,深度模型甚至超越了人类表现。对抗性样本的发现通过将对抗性样本与验证码相结合,为安全性与可用性权衡提供了理想解决方案,能够生成欺骗深度模型的对抗性验证码。本文拓展了对抗性验证码的定义,并提出了一种对抗性验证码的分类方法。随后,我们系统梳理了常用的对抗性样本生成方法,以及已成功应用于对抗性验证码生成的技术。同时,我们分析了可用于防御对抗性验证码的若干方法,指出了对抗性验证码面临的潜在威胁。最后,本文探讨了对抗性验证码未来可能的研究方向。