Defensive Adversarial CAPTCHA: A Semantics-Driven Framework for Natural Adversarial Example Generation
作者:Xia Du, X. Liu, Jizhe Zhou, Zheng Lin, Chi‐Man Pun, Cong Wu, Tao Li, Zhe Chen, Wei Ni, Jun Luo · 发表于:IEEE Transactions on Dependable and Secure Computing · 年份:2025 · DOI:10.1109/tdsc.2025.3636741 · 被引用次数:8 · 研究领域:Adversarial Robustness in Machine Learning、Ethics and Social Impacts of AI、Generative Adversarial Networks and Image Synthesis
Traditional CAPTCHA (Completely Automated Public Turing Test to Tell Computers and Humans Apart) schemes are increasingly vulnerable to automated attacks powered by deep neural networks (DNNs). Existing adversarial attack methods often rely on the original image characteristics, resulting in distortions that hinder human interpretation and limit their applicability in scenarios where no initial input images are available. To address these challenges, we propose the Unsourced Adversarial CAPTCHA (DAC), a novel framework that generates high-fidelity adversarial examples guided by attacker-specified semantics information. Leveraging a Large Language Model (LLM), DAC enhances CAPTCHA diversity and enriches the semantic information. To address various application scenarios, we examine the white-box targeted attack scenario and the black-box untargeted attack scenario. For target attacks, we introduce two latent noise variables that are alternately guided in the diffusion step to achieve robust inversion. The synergy between gradient guidance and latent variable optimization achieved in this way ensures that the generated adversarial examples not only accurately align with the target conditions but also achieve optimal performance in terms of distributional consistency and attack effectiveness. In untargeted attacks, especially for black-box scenarios, we introduce bi-path unsourced adversarial CAPTCHA (BP-DAC), a two-step optimization strategy employing multimodal gradients and bi...