Is Puzzle-Based CAPTCHA Secure Against Attacks Based on CNN?
Kenta Terada, Yasuo Okabe, Yoshinori Matsumoto · 2023
In recent years, unauthorized access to websites by bots has been on the rise. CAPTCHA, which distinguishes bots from humans, is widely used as a means of preventing automated access by bots. However, as bots have become more sophisticated, some bots have been able to break through CAPTCHAs with conventional difficulty. On the other hand, CAPTCHAs that prevent access by advanced bots are also difficult for humans, resulting in a trade-off between user convenience and the security against bots. In this paper, we verify that the instance of Capy Puzzle CAPTCHAs difficult for machines and easy for humans exists. As a first step, we designed a machine learning model that solves instances equivalent to Capy Puzzle CAPTCHA. This model detects the position of a piece from an instance image in which the piece is embedded in a background image. The model uses a Convolutional Neural Network (CNN) to detect the position of the piece from the instance image with an accuracy of 100%, which is higher than the accuracy of conventional methods. This shows the risk that the Capy Puzzle CAPTCHA can be easily broken through by machine learning. The instances that were considered difficult by the model were also difficult enough for humans.