pwshub.com

AI Can Best Google’s Bot Detection System, Swiss Researchers Find

Researchers using artificial intelligence have cracked one of the most widely-used CAPTCHA security systems, which are designed to keep bots off of websites by determining whether a user is human.

Using advanced machine learning methods, researchers from Switzerland-based university ETH Zurich solved 100% of captchas created by Google’s popular reCAPTCHAv2 product using a similar number of attempts as human users. 

The results, published on Sept. 13, indicate that “current AI technologies can exploit image-based captchas,” the authors wrote. 

“This has been coming for a while,” said Matthew Green, an associate professor of computer science at the Johns Hopkins Information Security Institute. “The entire idea of captchas was that humans are better at solving these puzzles than computers. We’re learning that’s not true.”

CAPTCHA stands for Completely Automated Public Turing Test, designed to tell computers and humans apart. The system used in the new study, Google’s reCAPTCHA v2, tests users by asking them to select images containing objects like traffic lights and crosswalks.

While the process the Swiss researchers used to defeat reCAPTCHAv2 was not fully automated and required human intervention, a fully automated process to bypass CAPTCHA systems could be right around the corner.

“I would not be surprised if that comes up in the near term,” Phillip Mak, a cybersecurity security operations center lead for a large government organization and an adjunct professor at New York University, told Decrypt

In response to bots’ improved ability to solve captchas, companies like Google, which released a third-generation reCAPTCHA product in 2018, are continually increasing the sophistication of their products. 

“The bots are continually getting smarter,” said Forrester Principal Analyst Sandy Carielli. “What worked a few weeks ago might not work today.”

“The best players are continually evolving because they have to,” she said. “The evolution is in the detection models and putting forth the right responses in order to not just block bots but also make it so expensive for bots that they go elsewhere.” 

Yet, introducing challenges that are trickier for bots to solve risks adding an additional layer of complexity to the puzzles, which can become more inconvenient for humans.

Average users may “need to spend more and more time solving captchas and eventually might just give up,” Mak said.

While the future of CAPTCHA as a security technology remains uncertain, others, including Gene Tsudik, professor of computer science at the University of California, Irvine—are more pessimistic.

“reCAPTCHA and its descendants should just go away,” Tsudik said. “There are some other techniques that are still okay, or at least better, but not significantly. So it’s still going to be an arms race.” 

If CAPTCHA does fade, there could be serious consequences for a broad range of internet stakeholders unless cybersecurity firms are able to come up with novel solutions, Green said. 

“It’s a huge problem for advertisers and the people operating services if they don't know whether 50% of their users are real,” Green said. ”Fraud was a big problem when you had to hire people to do it, and it’s a worse problem now that you can get AI to do the fraud for you.”

Edited by Josh Quittner and Sebastian Sinclair

Generally Intelligent Newsletter

A weekly AI journey narrated by Gen, a generative AI model.

Source: decrypt.co

Related stories
1 month ago - Google introduces Gemini Live, a new AI assistant, as well as a host of new features for the Google Pixel 9.
6 days ago - Google's free NotebookLM instantly turns anything you upload into an expert-level, professional sounding podcast. Here’s how to do it.
1 month ago - Grok 2 promises great performance when compared to the best LLMs in the industry—and may be the best image generators in specific cases.
1 month ago - Yet another AI-powered necklace enters the market in the race to become your constant companion, bestie—and confidant.
3 weeks ago - Without a technical post-mortem, we’re mostly in the dark as to what caused TON's recent seven-hour outage.
Other stories
19 minutes ago - BlackRock's ETF inflows signal growing investor confidence in crypto assets, potentially driving further market stabilization and growth. The post BlackRock Bitcoin, Ethereum ETFs notch $158 million net inflows amid market recovery...
34 minutes ago - Cardano price started a decent increase above the $0.3620 resistance. ADA is now showing positive signs and might rise further toward $0.420. ADA price started a recovery wave from the $0.3420 level. The price is trading above $0.380 and...
35 minutes ago - Bank of New York Mellon (BNY Mellon) is making significant strides toward launching custody services for Bitcoin (BTC) and Ethereum (ETH), following its recent exemption from the Securities and Exchange Commission’s (SEC) Staff Accounting...
1 hour ago - Ethereum (ETH) exchange-traded funds (ETFs) posted the largest outflows since July 2024, with $79.2 million leaving the market on Monday, according to data from SoSoValue. Ethereum ETFs Continue To Underperform Despite the...
1 hour ago - Ethereum price is holding gains above the $2,650 resistance. ETH is now consolidating gains and might aim for more gains above $2,700. Ethereum is aiming for more upsides above the $2,700 resistance. The price is trading above $2,620 and...