TY - GEN
T1 - Cleaner Adversarial CAPTCHAs
T2 - 25th International Conference on Autonomous Agents and Multiagent Systems, AAMAS 2026
AU - Litman, Meir
AU - Hajaj, Chen
N1 - Publisher Copyright:
© 2026 International Foundation for Autonomous Agents and Multiagent Systems.
PY - 2026/5/24
Y1 - 2026/5/24
N2 - Traditional CAPTCHAs are increasingly vulnerable to deep learning-based solvers that decode text and images with high accuracy. In this work, we propose methods to strengthen adversarial CAPTCHAs without compromising human usability. First, we introduce a Precise Gradient Method (PGM) that preserves gradient magnitude (rather than discarding it via a sign operator), producing adversarial perturbations with significantly lower perceptual noise. Second, we develop intelligent target class selection, using either dataset-level confusion structure (Class Relations Network) or image-specific softmax probabilities (Distance-Based Target), to steer adversarial perturbations more efficiently. Across multiple modern architectures (MobileNets, EfficientNets, ResNet, and Vision Transformer), our framework achieves faster convergence (fewer iterations), reduced visual distortion, and notably greater robustness under iterative adversarial retraining. Experiments show that our methods consistently reduce iteration counts and perceptual distortion while significantly increasing the difficulty for automated attacks. Our results offer a practical, scalable path toward the next generation of CAPTCHA systems and contribute new insights to the adversarial machine learning landscape focused on security and usability.
AB - Traditional CAPTCHAs are increasingly vulnerable to deep learning-based solvers that decode text and images with high accuracy. In this work, we propose methods to strengthen adversarial CAPTCHAs without compromising human usability. First, we introduce a Precise Gradient Method (PGM) that preserves gradient magnitude (rather than discarding it via a sign operator), producing adversarial perturbations with significantly lower perceptual noise. Second, we develop intelligent target class selection, using either dataset-level confusion structure (Class Relations Network) or image-specific softmax probabilities (Distance-Based Target), to steer adversarial perturbations more efficiently. Across multiple modern architectures (MobileNets, EfficientNets, ResNet, and Vision Transformer), our framework achieves faster convergence (fewer iterations), reduced visual distortion, and notably greater robustness under iterative adversarial retraining. Experiments show that our methods consistently reduce iteration counts and perceptual distortion while significantly increasing the difficulty for automated attacks. Our results offer a practical, scalable path toward the next generation of CAPTCHA systems and contribute new insights to the adversarial machine learning landscape focused on security and usability.
KW - Adversarial CAPTCHA
KW - Adversarial Robustness
KW - Intelligent Target Selection
KW - Usable Security
UR - https://www.scopus.com/pages/publications/105041367963
U2 - 10.65109/AFAW3962
DO - 10.65109/AFAW3962
M3 - ???researchoutput.researchoutputtypes.contributiontobookanthology.conference???
AN - SCOPUS:105041367963
T3 - AAMAS 2026 - Proceedings of the 25th International Conference on Autonomous Agents and Multiagent Systems
SP - 412
EP - 421
BT - AAMAS 2026 - Proceedings of the 25th International Conference on Autonomous Agents and Multiagent Systems
Y2 - 25 May 2026 through 29 May 2026
ER -