Title
The robustness of hollow CAPTCHAs
Abstract
CAPTCHA is now a standard security technology for differentiating between computers and humans, and the most widely deployed schemes are text-based. While many text schemes have been broken, hollow CAPTCHAs have emerged as one of the latest designs, and they have been deployed by major companies such as Yahoo!, Tencent, Sina, China Mobile and Baidu. A main feature of such schemes is to use contour lines to form connected hollow characters with the aim of improving security and usability simultaneously, as it is hard for standard techniques to segment and recognize such connected characters, which are however easy to human eyes. In this paper, we provide the first analysis of hollow CAPTCHAs' robustness. We show that with a simple but novel attack, we can successfully break a whole family of hollow CAPTCHAs, including those deployed by all the major companies. While our attack casts serious doubt on the viability of current designs, we offer lessons and guidelines for designing better hollow CAPTCHAs.
Year
DOI
Venue
2013
10.1145/2508859.2516732
ACM Conference on Computer and Communications Security
Keywords
Field
DocType
standard security technology,china mobile,standard technique,connected character,contour line,major company,hollow captchas,novel attack,hollow character,current design,convolutional neural network,captcha,security
Computer security,Computer science,Convolutional neural network,Usability,Robustness (computer science),CAPTCHA
Conference
Citations 
PageRank 
References 
11
0.52
14
Authors
6
Name
Order
Citations
PageRank
Haichang Gao117217.41
Wei Wang220258.31
Jiao Qi3140.94
Xuqin Wang4170.95
Xiyang Liu515918.55
Jianxin Jeff Yan687663.76