With the development of text-based CAPTCHA, many adversarial example generation methods for text-based CAPTCHA have been proposed. However, the perturbation factors generated by the existing methods are simple and easy to be attacked. In this paper, we present a framework for meta perturbation text-based CAPTCHA generation (denoted as MAPFN), which enhances the security of text-based CAPTCHA and makes the perturbed images friendly for humans. More specifically, we propose a meta perturbation generation network (MPGN) to construct rich and effective perturbation factors. To this end, we devise a perturbation feature fusion module (PFFM) to fuse the perturbation factors generated by MPGN into a new perturbation factor, which can be applied to the CAPTCHA image to make it similar to the origin while being effectively against the attacker models. Extensive experiments on 8 real website CAPTCHA datasets show the excellent performance of the proposed MAPFN. (e.g., attack accuracy falls from 93.99% to 0.98% on the NSFC dataset).

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Meta Perturbation Generation Network for Text-Based CAPTCHA

  • Zhuoting Wu,
  • Zhiwei Guo,
  • Jiuxiang You,
  • Zhenguo Yang,
  • Qing Li,
  • Wenyin Liu

摘要

With the development of text-based CAPTCHA, many adversarial example generation methods for text-based CAPTCHA have been proposed. However, the perturbation factors generated by the existing methods are simple and easy to be attacked. In this paper, we present a framework for meta perturbation text-based CAPTCHA generation (denoted as MAPFN), which enhances the security of text-based CAPTCHA and makes the perturbed images friendly for humans. More specifically, we propose a meta perturbation generation network (MPGN) to construct rich and effective perturbation factors. To this end, we devise a perturbation feature fusion module (PFFM) to fuse the perturbation factors generated by MPGN into a new perturbation factor, which can be applied to the CAPTCHA image to make it similar to the origin while being effectively against the attacker models. Extensive experiments on 8 real website CAPTCHA datasets show the excellent performance of the proposed MAPFN. (e.g., attack accuracy falls from 93.99% to 0.98% on the NSFC dataset).