arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

机器人视野:零成本零样本攻破 reCAPTCHA

Robot Visions: Breaking reCAPTCHA at Zero Cost and Zero Shot

Suphannee Sivakorn, Samantha Gottlieb

arXiv 2609.18518首次发表:更新:

AI 中文总结

本文证明免费本地模型(CLIP、OWLv2)可零成本零样本攻破Google reCAPTCHA,端到端求解器在500次真实会话中达92.6%成功率,且非技术用户通过自然语言即可实现,挑战型视觉验证码已失效。

AI 中文摘要

Google reCAPTCHA 是部署最广泛的视觉验证码服务,保护着数十万个网站免受自动化机器人的侵扰。它是对抗自动化攻击的关键防线,这些攻击包括撞库、批量创建账户和自动化表单滥用。自2007年推出以来,它已被证明在很大程度上是有效的。然而,如今易于获取的AI正在威胁其有效性。先前的研究已表明,商业云端视觉语言模型(VLM)能够解决视觉验证码挑战,但每次尝试都需付出不菲的金钱成本。在本文中,我们展示了免费且本地运行的模型可以攻破 Google reCAPTCHA。我们对 reCAPTCHA 进行了全面研究,并提出了其挑战类型的分类法:类型A(独立图像块,具有静态和动态子变体)和类型B(单个图像被分割成4x4网格),每种类型都需要不同的解决策略。我们设计了完全基于开源本地模型的零样本、零成本求解器,具体包括 CLIP(在类型A上每次挑战准确率为58%)和 OWLv2(在类型B上准确率为43.5%),无需模型训练,也无需API访问。我们的端到端自动化求解器在500个真实世界的 reCAPTCHA 会话中实现了92.6%的每次会话成功率。我们进一步证明,非技术性攻击者仅通过使用自然语言指令指挥一个普通AI助手,就能击败 reCAPTCHA。这将实际攻击者的技能门槛降至接近零,从根本上改变了基于挑战的验证码的威胁模型。尽管 reCAPTCHA 越来越倾向于基于信誉的验证,但基于视觉挑战的备用机制仍然存在,而矛盾的是,它已成为防御链中最薄弱的环节,这表明基于挑战的视觉验证码可能已走到其有效寿命的尽头。

英文摘要

Google reCAPTCHA is the most widely deployed visual CAPTCHA service, protecting hundreds of thousands of websites from automated bots. It serves as a critical line of defense against automated attacks, including credential stuffing, bulk account creation, and automated form abuse. It has proven largely effective since its introduction in 2007. However, the rise of accessible AI now threatens its efficacy. Prior work has demonstrated that commercial cloud-based vision-language models (VLMs) can solve visual CAPTCHA challenges, but at non-trivial monetary cost per attempt. In this paper, we show that free and locally-run models can break Google reCAPTCHA. We conduct a comprehensive study of reCAPTCHA and present a taxonomy of its challenge types: Type A (independent image tiles, with static and dynamic sub-variants) and Type B (a single image partitioned into a 4x4 grid), each demanding a distinct solving strategy. We design zero-shot, no-cost solvers built entirely on open-source local models, specifically CLIP (58% per-challenge accuracy on Type A) and OWLv2 (43.5% on Type B), requiring no model training and no API access. Our end-to-end automated solver achieves a 92.6% per-session success rate across 500 real-world reCAPTCHA sessions. We further demonstrate that reCAPTCHA can be defeated by a non-technical adversary, using only natural-language instructions to a commodity AI assistant. This collapses the practical attacker skill floor to near zero and fundamentally changes the threat model for challenge-based CAPTCHAs. Although reCAPTCHA increasingly favors reputation-based verification, visual challenge-based fallback persists as a safety net that, paradoxically, has become the weakest link in the defense chain, suggesting that challenge-based visual CAPTCHAs may have reached the end of their useful life.

CommentsAccepted for publication in the Proceedings of the 29th Information Security Conference (ISC 2026)

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑