论文标题
Aaecaptcha:音频对抗验证码的设计和实现
aaeCAPTCHA: The Design and Implementation of Audio Adversarial CAPTCHA
论文作者
论文摘要
验证码旨在防止恶意机器人程序滥用网站。大多数在线服务提供商部署音频验证码作为视觉障碍用户的文本和图像验证码的替代方案。但是,事先研究了音频验证码的安全性的研究发现,使用自动语音识别(ASR)系统非常容易受到自动攻击的影响。为了提高音频验证码对自动滥用的鲁棒性,我们在本文中介绍了音频对抗验证码(AAECAPTCHA)系统的设计和实现。 AAECAPTCHA系统利用音频对抗示例作为验证码,以防止ASR系统自动求解它们。此外,我们对我们的新音频验证码设计进行了严格的安全评估,该设计针对五个最先进的DNN ASR系统和三个商业语音到文本(STT)服务。我们的实验评估表明,即使攻击者完全了解当前针对音频对抗性示例的攻击,AAECAPTCHA对这些语音识别技术也很安全。我们还对AAECAPTCHA计划的概念验证实施进行了可用性评估。我们的结果表明,与普通音频验证码相比,它以适度的可用性成本实现了高鲁棒性。最后,我们广泛的分析强调,Aaecaptcha可以显着提高传统音频验证码系统的安全性和鲁棒性,同时保持相似的可用性。
CAPTCHAs are designed to prevent malicious bot programs from abusing websites. Most online service providers deploy audio CAPTCHAs as an alternative to text and image CAPTCHAs for visually impaired users. However, prior research investigating the security of audio CAPTCHAs found them highly vulnerable to automated attacks using Automatic Speech Recognition (ASR) systems. To improve the robustness of audio CAPTCHAs against automated abuses, we present the design and implementation of an audio adversarial CAPTCHA (aaeCAPTCHA) system in this paper. The aaeCAPTCHA system exploits audio adversarial examples as CAPTCHAs to prevent the ASR systems from automatically solving them. Furthermore, we conducted a rigorous security evaluation of our new audio CAPTCHA design against five state-of-the-art DNN-based ASR systems and three commercial Speech-to-Text (STT) services. Our experimental evaluations demonstrate that aaeCAPTCHA is highly secure against these speech recognition technologies, even when the attacker has complete knowledge of the current attacks against audio adversarial examples. We also conducted a usability evaluation of the proof-of-concept implementation of the aaeCAPTCHA scheme. Our results show that it achieves high robustness at a moderate usability cost compared to normal audio CAPTCHAs. Finally, our extensive analysis highlights that aaeCAPTCHA can significantly enhance the security and robustness of traditional audio CAPTCHA systems while maintaining similar usability.