Verification code generation method and device and readable storage medium
By constructing a covariance matrix and iteratively optimizing the adversarial samples, the generated verification code can effectively resist attacks from artificial intelligence models, improving the security and user experience of the verification code.
Patent Information
- Application Number
- CN202510258663.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-05
- Publication Date
- 2025-06-06
AI Technical Summary
When dealing with attacks on artificial intelligence models, existing verification code technologies have problems such as being prone to cracking and insufficient user-friendliness.
By generating initial adversarial samples based on the original verification code samples, analyzing their input and output relationships in the target black box model, constructing a covariance matrix, and iteratively optimizing the initial adversarial samples based on the covariance matrix, generating optimized adversarial samples as the final verification code.
It improves the anti-aggressiveness of verification codes, makes it difficult for automated programs and deep learning models to correctly identify verification code content, enhances the security of verification codes, and takes into account the user experience.
Smart Images

Figure CN120105384A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of Internet technology, and in particular to a verification code generation method, device and readable storage medium. Background Art
[0002] With the rapid development of the Internet, verification codes (CAPTCHA, Completely Automated Public Turing test to tell Computers and Humans Apart) play an important role in protecting network security and preventing automated programs from abusing network services.
[0003] CAPTCHAs verify user identities by designing tasks that are easy for humans to identify but difficult for machines to identify. They are widely used in scenarios such as preventing malicious registration, spam posting, and large-scale crawling. In the CAPTCHA system, the roles of attackers and defenders are clear and opposing, including:
[0004] Attacker: A malicious party who attempts to crack the CAPTCHA system, usually by using automated programs (such as robots) or machine learning models to bypass the CAPTCHA verification mechanism to gain unauthorized access or perform malicious actions.
[0005] Defender: A developer or system administrator who designs and maintains a captcha system. His goal is to protect the system from being cracked by attackers through various means (such as increasing the complexity of the captcha, introducing behavioral verification or adversarial sample technology).
[0006] However, existing verification code technology has problems such as being easy to crack and not user-friendly enough when dealing with attacks from artificial intelligence models. Summary of the invention
[0007] The technical problem to be solved by the present application is to provide a verification code generation method, device and readable storage medium to solve the problems existing in the prior art in view of the above-mentioned deficiencies in the prior art.
[0008] In a first aspect, the present application provides a verification code generation method, the method comprising:
[0009] S1. Generate initial adversarial samples based on the original verification code samples;
[0010] S2, analyze the input-output relationship between the original verification code sample and the initial adversarial sample in the target black box model, and construct a covariance matrix;
[0011] S3. Iteratively optimize the initial adversarial sample according to the covariance matrix to obtain an optimized adversarial sample;
[0012] S4. Determine the optimized adversarial sample as the final generated verification code.
[0013] In some embodiments, S1 includes:
[0014] Apply preliminary perturbations to the original CAPTCHA samples to generate preliminary adversarial samples.
[0015] In some embodiments, applying a preliminary perturbation to the original verification code sample to generate a preliminary adversarial sample includes:
[0016] Input the original verification code sample into the white-box substitution model to obtain the loss function gradient;
[0017] According to the gradient of the loss function, preliminary adversarial samples are generated by the fast gradient sign method FGSM.
[0018] In some embodiments, S2 includes:
[0019] Input the original verification code sample and the initial adversarial sample into the target black box model to obtain the model output;
[0020] Construct an input feature matrix based on the model input, and construct an output result matrix based on the model output;
[0021] The covariance matrix is obtained based on the input feature matrix and the output result matrix.
[0022] In some embodiments, according to the input feature matrix and the output result matrix, the covariance matrix is obtained by the following formula:
[0023] C=(1 / (n-1))(X-μ X ) T (Y-μ Y )
[0024] Among them, C represents the covariance matrix, n represents the number of samples, X represents the input feature matrix, Y represents the output result matrix, μ X Represents the mean vector of the input feature matrix, μ Y Represents the mean vector of the output result matrix.
[0025] In some embodiments, S3 includes:
[0026] The perturbation direction and amplitude of the initial adversarial sample are iteratively adjusted according to the covariance matrix to obtain the optimized adversarial sample.
[0027] In some embodiments, the perturbation direction and amplitude of the initial adversarial sample are iteratively adjusted according to the covariance matrix to obtain an optimized adversarial sample, including:
[0028] Determine the perturbation adjustment direction and amplitude of the initial adversarial sample according to the covariance matrix;
[0029] Adjust the sample according to the disturbance adjustment direction and amplitude to obtain the adjusted adversarial sample;
[0030] Input the adjusted adversarial sample into the target black box model, obtain the model output, and obtain the misjudgment rate of the adjusted adversarial sample;
[0031] Determine whether the iteration stop condition is met. If not, reconstruct the covariance matrix according to the adjusted adversarial sample, and repeat the steps of sample adjustment and obtaining the adjusted sample misclassification rate according to the reconstructed covariance matrix until the iteration stop condition is met.
[0032] In some embodiments, the iteration stop condition includes:
[0033] The misclassification rate of the adjusted sample reaches the preset threshold; or
[0034] The disturbance amplitude reaches the preset range.
[0035] In a second aspect, the present application provides a verification code generating device, the device comprising:
[0036] An initial adversarial sample generation module, which is configured to generate an initial adversarial sample based on the original verification code sample;
[0037] A target model feature extraction module is configured to analyze the input-output relationship between the original verification code sample and the initial adversarial sample in the target black box model and construct a covariance matrix;
[0038] A model filter optimization module, which is configured to iteratively optimize the initial adversarial sample according to the covariance matrix to obtain an optimized adversarial sample;
[0039] A verification code generation module is configured to determine the optimized adversarial sample as a final generated verification code.
[0040] In a third aspect, the present application provides a verification code generation device, including a memory and a processor, wherein the memory stores a computer program, and the processor is configured to run the computer program to implement the verification code generation method described in the first aspect above.
[0041] In a fourth aspect, the present application provides a computer-readable storage medium having a computer program stored thereon, and when the computer program is executed by a processor, the verification code generation method described in the first aspect is implemented.
[0042] The verification code generation method, device and readable storage medium provided by the present application include: generating an initial adversarial sample based on the original verification code sample; analyzing the input-output relationship between the original verification code sample and the initial adversarial sample in the target black box model to construct a covariance matrix; iteratively optimizing the initial adversarial sample according to the covariance matrix to obtain an optimized adversarial sample; and determining the optimized adversarial sample as the final generated verification code. The present application extracts the target black box model features based on the covariance matrix, and generates adversarial samples in combination with model filtering optimization, so that users can easily identify verification codes, while increasing the recognition difficulty of the artificial intelligence cracking model, taking into account both security and user experience. BRIEF DESCRIPTION OF THE DRAWINGS
[0043] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the present application and, together with the description, serve to explain the principles of the present application.
[0044] Figure 1 A flowchart of a verification code generation method provided in an embodiment of the present application;
[0045] Figure 2 A schematic diagram of an embodiment of the present application providing an optimized adversarial sample obtained by iteratively optimizing the initial adversarial sample according to the covariance matrix;
[0046] Figure 3 An example diagram of image verification code protection provided in an embodiment of the present application;
[0047] Figure 4 A schematic diagram of the structure of a verification code generating device provided in an embodiment of the present application;
[0048] Figure 5 A schematic diagram of the structure of another verification code generating device provided in an embodiment of the present application;
[0049] Figure 6 A schematic diagram of the structure of another verification code generating device provided in an embodiment of the present application.
[0050] The above drawings have shown clear embodiments of the present application, which will be described in more detail later. These drawings and text descriptions are not intended to limit the scope of the present application in any way, but to illustrate the concept of the present application to those skilled in the art by referring to specific embodiments. DETAILED DESCRIPTION
[0051] In order to enable those skilled in the art to better understand the technical solution of the present application, the implementation mode of the present application will be further described in detail below with reference to the accompanying drawings.
[0052] It should be understood that the specific embodiments and drawings described herein are only used to explain the present application, rather than to limit the present application.
[0053] It can be understood that, in the absence of conflict, the various embodiments in the present application and the various features in the embodiments can be combined with each other.
[0054] It can be understood that, for the convenience of description, the drawings of the present application only show the parts related to the present application, while the parts unrelated to the present application are not shown in the drawings.
[0055] It can be understood that each unit and module involved in the embodiments of the present application may correspond to only one physical structure, or may be composed of multiple physical structures, or multiple units and modules may be integrated into one physical structure.
[0056] It can be understood that the terms "first", "second", etc. in the embodiments of the present application are used to distinguish different objects, or to distinguish different processing of the same object, rather than to describe a specific order of objects.
[0057] It is understandable that, in the absence of conflict, the functions and steps marked in the flowcharts and block diagrams of the present application may occur in an order different from that marked in the drawings.
[0058] It is understood that the flowcharts and block diagrams of the present application illustrate the possible architectures, functions, and operations of the systems, devices, equipment, and methods according to the various embodiments of the present application. Among them, each box in the flowchart or block diagram may represent a unit, module, program segment, code, which contains executable instructions for implementing the specified functions. Moreover, each box or combination of boxes in the block diagram and flowchart may be implemented by a hardware-based system that implements the specified functions, or by a combination of hardware and computer instructions.
[0059] It can be understood that the units and modules involved in the embodiments of the present application can be implemented by software or hardware, for example, the units and modules can be located in a processor.
[0060] Existing verification code technologies and their implementation solutions mainly include the following categories:
[0061] 1. Graphic verification code based on distorted text
[0062] The most traditional and common form of CAPTCHA is the distorted text CAPTCHA, which distorts, deforms, rotates, adds noise to characters, and makes it difficult for machines to accurately recognize them, while humans can visually recognize the correct character combination. However, studies have shown that models based on deep learning, especially convolutional neural networks (CNNs), can already recognize such CAPTCHAs with high accuracy.
[0063] 2. Captcha based on image recognition
[0064] In order to improve security, the design of CAPTCHA has gradually evolved from traditional distorted text CAPTCHA to CAPTCHA based on image recognition. This type of CAPTCHA usually requires users to select a picture containing a specific object from a set of pictures. For example, Google's reCAPTCHA v2 is a classic example of this type of CAPTCHA.
[0065] The specific mechanism of reCAPTCHA v2 includes the following features:
[0066] (1) Task type: Users need to complete a visual recognition task, such as selecting images containing specific targets (such as buses, store windows, or traffic signs) from a grid of images.
[0067] (2) Combined with behavioral data: By analyzing the user's mouse clicking behavior (such as click speed, click location distribution, etc.), determine whether the user is a human operator.
[0068] (3) Dynamic image update: If the user fails to complete the task correctly, the image will be dynamically refreshed, asking the user to try again.
[0069] Although reCAPTCHA v2 significantly improved the security of verification codes when it was first launched, with the rapid development of computer vision technology, deep learning models (such as object detection models based on convolutional neural networks) have been able to reach or even surpass human levels in such image recognition tasks. Research shows that attackers can use pre-trained models (such as YOLO and Faster R-CNN) to accurately identify target objects in images and thus crack such verification codes.
[0070] To address the above challenges, Google launched reCAPTCHA v3 based on reCAPTCHA v2, further enhancing the security and user experience of the verification code.
[0071] Key features of reCAPTCHA v3 include:
[0072] (1) No user interaction: Unlike v2, reCAPTCHA v3 no longer requires users to complete the image selection task, but instead determines the user's identity through implicit verification.
[0073] (2) Risk scoring mechanism: Generate a risk score by analyzing user behavior data (such as mouse movement trajectory, click frequency, page dwell time, etc.). The risk score ranges from 0 to 1, and the lower the score, the more likely the user is a robot.
[0074] (3) Dynamic Adaptation: Based on the risk score, the system can adopt different response strategies. For example, for low-risk users, they are directly allowed to pass the verification; for high-risk users, additional verification is triggered (such as the image selection task of reCAPTCHA v2).
[0075] Through the above improvements, reCAPTCHA v3 not only eliminates the user's interactive burden, but also improves verification efficiency and user experience. However, its risk scoring mechanism still has certain limitations: attackers can bypass the risk scoring mechanism by simulating the behavior of normal users; for specific high-risk scenarios, reCAPTCHA v3 may need to be combined with other security measures (such as multi-factor authentication) to further improve protection capabilities.
[0076] 3. Behavioral verification code
[0077] Behavioral CAPTCHAs detect user interaction behaviors to distinguish between human operations and automated programs. For example, a sliding puzzle CAPTCHA requires users to drag the slider to make the puzzle fit together, which takes advantage of human understanding of images and hand-eye coordination. However, researchers have developed automated programs that can simulate human operation behaviors and successfully crack such CAPTCHAs by simulating parameters such as trajectory and speed.
[0078] 4. Verification code based on user's physiological and cognitive characteristics
[0079] This type of verification code uses the differences in human physiological characteristics (such as touch screen pressure) or cognitive characteristics (such as understanding complex problems) to design verification methods that are difficult for machines to imitate. For example, verification codes based on brain waves (Electroencephalogram, EEG) have not yet been widely used due to problems such as implementation cost and user experience.
[0080] 5. Captcha based on adversarial examples
[0081] Adversarial examples refer to samples that slightly perturb the input data, causing the machine learning model to misjudge, while these perturbations have little impact on human perception. Using adversarial examples, we can design verification codes that are easy for humans to identify but difficult for machine models to classify. However, such methods need to target specific attack models and have poor versatility.
[0082] Adversarial samples are a special type of input in the field of deep learning. They cause machine learning models to misjudge perception by slightly perturbing the original data. For example, a "panda" image with a slight perturbation can still be clearly identified as a "panda" by humans, but the machine learning model may misjudge it as a "dog" or other categories. This perturbation is usually imperceptible to humans, but it is enough to significantly change the model's decision. The core idea of adversarial samples is to exploit the vulnerability of deep learning models on the decision boundary and deceive the model through carefully designed input perturbations to make it output incorrect classification results.
[0083] Common adversarial sample generation methods mainly include the following categories:
[0084] (1) Gradient-based perturbation method
[0085] ①Fast Gradient Sign Method (FGSM)
[0086] FGSM is a classic adversarial sample generation method that calculates the gradient of the model loss function with respect to the input data and performs a one-time perturbation on the input data along the gradient direction. The formula is as follows:
[0087]
[0088] Where x is the original sample; ε is the perturbation amplitude; Represents the gradient of the loss function J with respect to the input x. The advantage of FGSM is its high computational efficiency and suitability for white-box attack scenarios, but the generated adversarial samples may not be misleading enough to the model.
[0089] ② Projected Gradient Descent (PGD)
[0090] PGD is an improved version of FGSM, which optimizes the perturbation direction through multiple iterations and limits the perturbation to a specified range (such as L ∞ The adversarial samples generated by the PGD method are more robust and suitable for simulating more complex attack scenarios, but the computational cost is high.
[0091] (2) Optimization-based perturbation method
[0092] ①C&W attack method
[0093] The Carlini&Wagner method generates adversarial samples by optimizing the objective function, which aims to minimize the perturbation amount while maximizing the misleading effect. The optimization objective is:
[0094] min||x adv-x||+c*L(x adv ,t)
[0095] Among them, ||x adv -x|| represents the perturbation amount of the original sample; L(x adv ,t) represents the confidence loss of the model for target category t; c is the weight parameter. The adversarial samples generated by the C&W method are highly concealed and suitable for high-security scenarios, but the computational overhead is large.
[0096] (3) Adversarial Sample Generation Based on Generative Adversarial Networks (GAN)
[0097] GAN is a deep learning framework consisting of a generator and a discriminator, which is used to generate realistic adversarial samples: the generator is responsible for learning the data distribution and generating adversarial samples close to real samples; the discriminator is used to distinguish between real samples and generated samples. GAN can generate complex perturbation patterns and is suitable for multimodal data. However, the training process of GAN requires a large amount of data and computing resources, which is not suitable for offline generation of adversarial samples.
[0098] (4) Adversarial Sample Generation Based on Black-Box Query
[0099] In a black box environment, the attacker cannot directly access the internal structure and parameter information of the target black box model. In this case, the sample can be gradually optimized by inputting query data into the target black box model (and recording the output results). For example, by using evolutionary algorithms or particle swarm optimization methods, a highly misleading adversarial sample can be generated by querying the target black box model multiple times.
[0100] However, with the rapid development of artificial intelligence and deep learning technology, traditional verification code technology faces severe challenges and has the following main shortcomings:
[0101] 1. Easy to be cracked by deep learning models: Graphic CAPTCHAs based on distorted text, image recognition CAPTCHAs, and behavioral CAPTCHAs have been successfully cracked by deep learning models because their feature patterns are relatively fixed. For example, convolutional neural networks (CNNs) can recognize distorted text CAPTCHAs with high accuracy, and generative adversarial networks (GANs) can simulate and crack complex CAPTCHA images, which greatly reduces the security of traditional CAPTCHAs.
[0102] 2. Insufficient versatility of adversarial samples: Existing CAPTCHA designs based on adversarial samples are usually generated for specific attack models and are highly dependent on model structure and parameters. When attackers use different models or fine-tune the models, the defensive effects of these adversarial CAPTCHAs will be significantly reduced, and they lack sufficient transferability.
[0103] 3. High generation complexity and low efficiency: Generating adversarial samples with strong transferability and versatility requires a lot of computing resources, high computational complexity, and long time consumption. This results in the inability to update the verification code in a timely manner, limiting its feasibility in practical applications.
[0104] 4. Poor user experience: In order to improve security, some verification code designs increase the difficulty of human recognition. For example, overly distorted text, complex image tasks, etc. may cause difficulty for users to recognize, increase the user's usage burden, and reduce the user experience.
[0105] 5. Weak defense against black box models: In a black box attack environment, the attacker's model structure and parameters are unknown. Existing verification code defense methods are difficult to obtain information about the attack model in a timely manner and cannot effectively generate defense strategies, making verification codes easy to break. When defenders deal with black box attacks, existing technologies still have the following deficiencies:
[0106] (1) Lack of effective extraction of input and output features
[0107] Existing defense methods (such as adversarial training and gradient masking) usually rely on the internal structure or gradient information of the model, which is not available in a black-box environment. It is difficult for defenders to build effective defense strategies based on input and output features.
[0108] (2) Insufficient transferability of adversarial examples
[0109] Existing defense methods are usually optimized for specific attack models and lack the ability to defend against multiple attack models. For example, a verification code designed by the defender may be effective against CNN attacks, but cannot defend against attacks based on GAN or other complex models.
[0110] (3) High computational overhead
[0111] Black-box defense methods require statistical analysis of input and output features, which has high computational complexity and may lead to performance bottlenecks in high-concurrency scenarios of captcha systems.
[0112] (4) Lack of adaptability
[0113] Existing defense methods are optimized for known attack strategies, but lack sufficient adaptability to new types of attacks (such as hybrid attacks and multimodal attacks).
[0114] In view of the shortcomings of the above-mentioned prior art, this application proposes a fully automatic Turing test to distinguish computers from humans (CAPTCHA) method based on adversarial sample generation, which aims to effectively prevent artificial intelligence tools from attacking the verification code system. The purpose of this application is to:
[0115] 1. Improve the anti-attack ability of verification codes: By designing a novel verification code generation method, it is difficult for automated programs and deep learning models to correctly identify the verification code content, thereby enhancing the security of the verification code and preventing it from being easily cracked.
[0116] 2. Enhance the versatility and transferability of adversarial samples: This application aims to develop a method that can generate adversarial samples with strong transferability in a black-box environment, so that the generated verification code has good defense effect against different attack models and reduces dependence on the attacker's model structure and parameters.
[0117] 3. Reduce generation complexity and improve efficiency: By optimizing the generation algorithm of adversarial samples, the computational complexity is reduced, the generation efficiency is improved, and the verification code can be updated in a timely manner to meet the needs of practical applications.
[0118] 4. Improve user experience: Under the premise of ensuring security, design verification codes that are easy for human users to identify, reduce the difficulty of user identification, reduce the user's usage burden, and improve user experience.
[0119] 5. Enhanced defense capabilities against black box models: This application extracts the feature information of the target black box model in a black box environment, constructs a covariance matrix, and optimizes adversarial sample generation, so that the verification code can still maintain high defense performance under unknown attack models.
[0120] The technical solution of the present application and how the technical solution of the present application solves the above-mentioned technical problems are described in detail below with specific embodiments. The following specific embodiments can be combined with each other, and the same or similar concepts or processes may not be repeated in some embodiments. The embodiments of the present application will be described below in conjunction with the accompanying drawings.
[0121] The present application provides a verification code generation method, the working process of which can be implemented by electronic devices, such as computers, handheld smart terminals, etc. For ease of explanation, the embodiments of the present application are described with the method execution subject being a computer.
[0122] Figure 1 A schematic diagram of a verification code generation method provided in an embodiment of the present application, such as Figure 1 As shown, the present application provides a verification code generation method, the method comprising steps S1-S4, which are as follows:
[0123] S1. Generate initial adversarial samples based on the original verification code samples;
[0124] Among them, the original verification code samples (such as images) can be stored by constructing an original verification code sample library. The original verification code sample library plays a fundamental role in the verification code generation system of the present application, and the diversity of its samples is of key significance for improving the protection capability against adversarial samples.
[0125] When constructing the original verification code sample library, the original verification code samples include image verification codes, and the image content can involve a variety of categories, such as various animals, plants, means of transportation, daily necessities, scenery, etc., to meet different application scenarios and situations that the target black box model may encounter. By constructing such a highly diverse original verification code sample library, a rich material basis can be provided for the subsequent generation of adversarial samples. In the process of generating adversarial samples, the model can learn effective perturbation strategies for various verification codes, thereby improving the adaptability and protection capabilities of the generated adversarial samples against different attack methods and models. For complex models of image recognition, it is possible to generate adversarial samples with strong misleading and defensiveness based on a diverse sample basis, effectively ensuring the security of the verification code system while taking into account the recognizability of human users, and better achieving the purpose of this application.
[0126] After obtaining the original verification code sample, generate the initial adversarial sample.
[0127] In some embodiments, S1 includes: applying preliminary perturbations to the original verification code sample to generate an initial adversarial sample.
[0128] In some embodiments, applying a preliminary perturbation to the original verification code sample to generate an initial adversarial sample includes:
[0129] Input the original verification code sample into the white-box substitution model to obtain the loss function gradient;
[0130] According to the gradient of the loss function, the initial adversarial sample is generated by the fast gradient sign method FGSM.
[0131] Specifically, the original verification code sample x is input into the white box substitution model and the loss function gradient is calculated
[0132] Where θ represents the parameters of the white-box substitution model; x represents the input sample; y represents the true label; and J represents the loss function of the substitution model. The white-box substitution model generates a neural network model for the initial adversarial sample, which is used to approximately simulate the behavior of the target black-box model. By training a neural network model with a known structure, it is convenient to calculate the gradient information to generate adversarial samples.
[0133] When training a white-box substitution model, the size of the training data needs to be determined based on many factors. On the one hand, the data must be sufficiently diverse, covering various types of original CAPTCHA samples, such as images of different themes (such as animals, vehicles, and daily necessities for image CAPTCHA scenarios). Usually, the amount of training data ranges from thousands to tens of thousands, depending on the complexity of the CAPTCHA application scenario and the desired adversarial sample generation effect.
[0134] For example, for a common website login verification code protection scenario, we may collect image verification code samples containing different image contents, with a total of about 5,000 to 10,000. This will allow the white-box substitution model to fully learn the characteristics of different samples and provide a rich data foundation for the subsequent generation of adversarial samples.
[0135] In this application, the white-box substitution model can be constructed using a simple convolutional neural network (CNN) structure, which roughly includes the following main parts:
[0136] (1) Input layer: Determine the input dimension based on the form of the verification code sample. For image verification codes, the input dimension is the pixel dimension of the image (for example, a common RGB image is width × height × 3);
[0137] (2) Convolutional layer: Set up several convolutional layers and extract local features of the verification code samples through convolution kernels of different sizes (such as 3×3, 5×5, etc.). For example, when processing image verification codes, the convolutional layer can extract features such as textures and edges in different areas of the image. As the number of layers increases, more abstract and representative high-level features can be gradually extracted. Each convolution layer is usually followed by an activation function (such as the ReLU function) to increase the nonlinear expression ability of the network.
[0138] (3) Pooling layer: A pooling layer (such as maximum pooling or average pooling) is appropriately inserted between convolutional layers. Its function is to reduce the dimension of the feature map, reduce the amount of data while retaining key features, help improve the computational efficiency of the model and prevent overfitting.
[0139] (4) Fully connected layer: After multiple convolutional and pooling layers, the extracted features are integrated through a fully connected layer and mapped to the corresponding output dimension. The number of nodes in the output layer corresponds to the number of categories of the verification code classification (for example, for an image verification code to determine whether it is a certain type of object, the number of nodes in the output layer is the number of object categories).
[0140] Optionally, a fully connected neural network can also be used to build a white box substitution model, but its effect may be slightly weaker than CNN when processing verification code samples with spatial structure information such as images. The fully connected neural network mainly transmits the input verification code sample feature vector (such as the pixel vector after the image is flattened) through multiple layers of neurons, learns the pattern in the data by adjusting the connection weights between each neuron, and finally outputs the corresponding prediction results.
[0141] In this application, the white-box substitution model is trained based on known structures and available data, and its purpose is to simulate the behavior of the target black-box model. During the training process, by inputting a large number of original verification code samples and corresponding real labels (such as the correct category corresponding to the image in the image verification code), the white-box substitution model learns the mapping relationship between the verification code sample features and the correct output. Since the internal structure and parameters of the target black-box model are invisible when processing the verification code, this application assumes that when facing the same or similar verification code samples, there is a certain similarity between the black-box model and the white-box substitution model in the approximate relationship between the input and output.
[0142] For example, for some common image verification code classification tasks, the influence trend of different image features learned by the white-box substitution model on the classification results may be similar to that of the black-box model. In practical applications, the white-box substitution model can be adjusted continuously using newly collected verification code samples and verification result feedback to make it closer to the actual behavior of the target black-box model.
[0143] In this application, the training effect of the white-box substitution model plays a key role in the quality of adversarial sample generation. If the training effect is good, it means that the model can accurately capture the characteristics of the verification code sample and the correlation with the correct output, then when generating adversarial samples. First, the calculated gradient of the loss function will be more accurate. For example, when using the fast gradient sign method (FGSM) to generate the initial adversarial sample, accurate gradient information can guide the addition of perturbations in a more appropriate direction, making the generated adversarial sample more likely to mislead the target black box model and increase the aggressiveness of the adversarial sample to the target black box model. Secondly, the initial adversarial sample generated by the well-trained white-box substitution model can provide a more reliable basis for feature extraction and optimization in the subsequent optimization process based on the covariance matrix. Because the adversarial samples initially generated already have a certain degree of rationality and misleadingness, on this basis, by analyzing the input-output relationship of the target black box model on these samples (constructing covariance matrices and other operations) to further optimize the adversarial samples, the optimization direction will be more accurate, and the adversarial samples finally generated will be of higher quality. They can effectively interfere with the target black box model to make it misjudge, and ensure that the impact on the recognizability of human users is small, thereby better achieving the purpose of improving the anti-attack ability of the verification code and taking into account the user experience in this application.
[0144] On the contrary, if the white-box alternative model is not well trained, such as overfitting (performing well on the training data but having poor adaptability to new verification code samples) or underfitting (failing to fully learn the characteristics of the verification code samples), the generated adversarial samples may not be able to effectively target the characteristics of the target black-box model. They may be insufficiently misleading to the target black-box model and easily detected, or they may be excessively disturbed, making it difficult for human users to identify, affecting the user experience and failing to achieve the expected verification code protection effect.
[0145] When calculating the loss function gradient Finally, use FGSM to generate the initial adversarial sample:
[0146]
[0147] Among them, x is the original sample, x adv is the initial adversarial sample; ε is the perturbation amplitude, which ensures that the adversarial sample has little impact on the recognizability of human users; Represents the gradient of the loss function J with respect to the input x.
[0148] In this application, the selection of the perturbation amplitude ε of FGSM is crucial for generating effective adversarial samples. Although the range of ε∈[0,0.1] is set, the determination of the specific appropriate value needs to be determined by considering many factors and through experiments.
[0149] First, in order to improve the misjudgment rate of adversarial samples for the target black box model, it is necessary to increase the perturbation amplitude to a certain extent. A series of experiments can be conducted to gradually increase the value of ε, while inputting the generated adversarial samples into the target black box model for testing and observing the changes in the misjudgment rate.
[0150] For example, starting from a smaller ε value (such as 0.01), each time the amplitude is increased by 0.01, and the misjudgment rate of the target black box model for a large number of adversarial samples under different ε values is recorded. When the misjudgment rate begins to stabilize or grow slowly, it means that continuing to increase the perturbation amplitude within this range has no obvious effect on improving the misjudgment rate.
[0151] Secondly, we need to maintain the user's recognizability. During the experiment, we show adversarial samples generated with different ε values to a large number of real users and collect the user's recognition accuracy data. When the user recognition accuracy drops below an acceptable threshold (for example, 90%), it means that the disturbance amplitude has had a significant impact on the user's recognizability.
[0152] By comprehensively analyzing the false positive rate and user identifiability data, an ε value range is determined as the best selection range, which can not only make the false positive rate of the target black box model reach a high level (such as above 80%), but also ensure that the user recognition accuracy is within an acceptable range (such as above 95%).
[0153] For example, experiments may reveal that for a specific type of verification code, when ε is between 0.03 and 0.08, it can effectively mislead the target black box model while ensuring that human users can more easily identify the content of the verification code.
[0154] In addition, the characteristics of different types of CAPTCHAs and target black box models need to be considered. CAPTCHAs with complex images and rich features may be able to withstand relatively large disturbances without affecting user recognition. At the same time, different target black box models have different sensitivities to disturbances. Some models may misjudge even small disturbances, while others may only be affected by large disturbances.
[0155] Therefore, when determining the ε value, it is necessary to conduct targeted experiments and analysis on the specific verification code type and target black box model to find the most appropriate disturbance amplitude range, so as to better achieve the purpose of this application to improve the verification code's anti-attack ability and take into account the user experience.
[0156] S2, analyze the input-output relationship between the original verification code sample and the initial adversarial sample in the target black box model, and construct a covariance matrix;
[0157] In some embodiments, S2 includes:
[0158] Input the original verification code sample and the initial adversarial sample into the target black box model to obtain the model output;
[0159] Construct an input feature matrix based on the model input, and construct an output result matrix based on the model output;
[0160] The covariance matrix is obtained based on the input feature matrix and the output result matrix.
[0161] Specifically, the initial adversarial sample x adv The original sample x is input into the target black box model, and the output of the model (such as classification label and confidence) is recorded. Then, the input feature matrix X and the output result matrix Y are constructed.
[0162] Among them, the input feature matrix X represents the flattened pixel vector of each image, with a size of n×d, where n is the number of samples and d is the total number of pixels; the output result matrix Y represents the output result of the target black box model (such as classification probability distribution), with a size of n×m, where m is the output dimension.
[0163] In some embodiments, according to the input feature matrix and the output result matrix, the covariance matrix is obtained by the following formula:
[0164] C=(1 / (n-1))(X-μ X ) T (Y-μ Y )
[0165] Among them, C represents the covariance matrix, the size of C is d×m, which represents the correlation between each input feature and each output dimension, n represents the number of samples, X represents the input feature matrix, Y represents the output result matrix, μ XRepresents the mean vector of the input feature matrix, μ Y Represents the mean vector of the output result matrix.
[0166] In this application, the covariance matrix is used to measure the correlation between the input features and the target black box model output. The larger the absolute value of the covariance matrix, the greater the impact of the input feature on the model output.
[0167] S3. Iteratively optimize the initial adversarial sample according to the covariance matrix to obtain an optimized adversarial sample;
[0168] In some embodiments, S3 includes: iteratively adjusting the perturbation direction and amplitude of the initial adversarial sample according to the covariance matrix to obtain an optimized adversarial sample.
[0169] In some embodiments, the perturbation direction and amplitude of the initial adversarial sample are iteratively adjusted according to the covariance matrix to obtain an optimized adversarial sample, including:
[0170] Determine the perturbation adjustment direction and amplitude of the initial adversarial sample according to the covariance matrix;
[0171] Adjust the sample according to the disturbance adjustment direction and amplitude to obtain the adjusted adversarial sample;
[0172] Input the adjusted adversarial sample into the target black box model, obtain the model output, and obtain the misjudgment rate of the adjusted adversarial sample;
[0173] Determine whether the iteration stop condition is met. If not, reconstruct the covariance matrix according to the adjusted adversarial sample, and repeat the steps of sample adjustment and obtaining the adjusted sample misclassification rate according to the reconstructed covariance matrix until the iteration stop condition is met.
[0174] In some embodiments, the iteration stopping condition includes: the misjudgment rate of the adjusted samples reaches a preset threshold (eg, above 80%); or the disturbance amplitude reaches a preset range (eg, ε≤0.1).
[0175] Figure 2 A schematic diagram of an optimized adversarial sample obtained by iteratively optimizing the initial adversarial sample according to the covariance matrix provided in an embodiment of the present application, such as Figure 2 As shown, first, this application analyzes the sensitivity of the target black box model to the input features based on the covariance matrix results, among which high-correlation features (larger covariance values) have a significant impact on the model output and are preferentially perturbed. In addition, low-correlation features (smaller covariance values) have a small impact on the model output and reduce perturbations.
[0176] Then, the perturbation direction and amplitude of the initial adversarial sample are adjusted:
[0177] xadv [i] = x adv [i]+α*C[i][j]
[0178] Among them, x adv [i] is the optimized value of the i-th pixel; C[i][j] is the correlation between the i-th pixel and the j-th output dimension in the covariance matrix; α is the optimization step size, which is used to control the speed of disturbance adjustment.
[0179] This application gradually approaches the decision boundary of the target black box model through multiple iterative optimizations.
[0180] Specifically, this application performs the following operations in each iteration:
[0181] (1) According to the current initial adversarial sample and the constructed covariance matrix, determine the perturbation adjustment direction and amplitude of each pixel. For example, according to the formula x adv [i] = x adv [i]+α*C[i][j], where x adv [i] is the optimized value of the i-th pixel, C[i][j] is the correlation between the i-th pixel and the j-th output dimension in the covariance matrix, and α is the optimization step size. The covariance matrix is used to analyze the sensitivity of the target black box model to the input features, and stronger perturbations are preferentially applied to high-correlation features (larger covariance values), while reducing perturbations to low-correlation features (smaller covariance values).
[0182] (2) Input the adjusted adversarial sample into the target black box model to obtain its output results, including classification labels, confidence levels and other information.
[0183] (3) Based on the output of the target black box model, calculate the misclassification rate of the current adversarial sample. The misclassification rate is calculated by counting the ratio of the number of misclassified adversarial samples to the total number of adversarial samples tested. For example, if 100 adversarial samples are tested and 30 of them are misclassified, the misclassification rate is 30%.
[0184] In this application, the convergence of the optimization process is mainly judged based on the following two conditions:
[0185] (1) The misjudgment rate reaches the set threshold:
[0186] Set a false positive rate threshold, such as 80%. When the calculated false positive rate of adversarial samples reaches or exceeds the threshold, the optimization is considered to have achieved a good effect and the optimization process can be stopped. This means that the generated adversarial samples can effectively mislead the target black box model, causing it to make wrong judgments in most cases, thereby achieving the purpose of improving the anti-attack capability of the verification code.
[0187] (2) The disturbance amplitude reaches the limit range:
[0188] At the same time, consider the limit of the perturbation amplitude and set a limit condition such as ε≤0.1. When the perturbation amplitude of the adversarial sample has reached or is close to this limit during the iteration process, the optimization needs to be stopped even if the misjudgment rate has not reached the threshold. This is to ensure that the generated adversarial sample is misleading to the target black box model, but will not be unrecognizable to human users due to excessive perturbation, thus taking into account the user experience.
[0189] In addition, in this application, when the misjudgment rate does not reach the set threshold, the following process is followed to return to the previous stage to re-extract the target black box model features:
[0190] First, record the current number of iterations and the corresponding adversarial sample features, misjudgment rate and other information to facilitate subsequent analysis of the effects and trends of the optimization process.
[0191] Then, the adversarial samples that do not meet the requirements and the related user interaction data (such as user recognition results, response time, etc.) are fed back to the target black box model feature extraction module. In the target black box model feature extraction module, these data are re-analyzed to construct a new input feature matrix X and output result matrix Y. Specifically, the adversarial samples that do not meet the requirements are regarded as new input samples, and their corresponding user recognition results and target black box model outputs are used as output results to recalculate the covariance matrix. For example, if the previous covariance matrix calculation was based on 500 samples, now add the new 100 adversarial samples that do not meet the requirements, and construct a new matrix containing 600 samples to recalculate the covariance matrix, thereby updating the representation of the sensitivity to the target black box model features.
[0192] Finally, based on the new covariance matrix, the model filter optimization module is entered again for a new round of iterative optimization, and the above iterative steps are repeated until the optimization convergence criteria are met.
[0193] S4. Determine the optimized adversarial sample as the final generated verification code.
[0194] Optionally, it also includes: after obtaining the final generated verification code, displaying it in a user-visible display form to perform user verification.
[0195] Specifically, by displaying the verification code, the user is required to enter the verification code content; judging whether the user input is consistent with the real label: if the user input is correct, the verification passes; if the user input is incorrect, the verification fails.
[0196] In this application, the evaluation of user experience is crucial to the effectiveness and practicality of the verification code system of this application. The following is a detailed description of the evaluation method of user experience.
[0197] 1) False positive rate: As one of the key performance indicators, the false positive rate directly reflects the interference effect of adversarial samples on the target black box model. During the experimental evaluation process, a large number of generated adversarial samples are input into the target black box model for classification prediction. For example, for adversarial samples generated for image verification codes, the target black box model may be an image recognition model based on deep learning, such as a convolutional neural network (CNN). By testing thousands or even tens of thousands of adversarial sample images, the statistical model calculates the proportion of images that are misclassified. If the false positive rate can reach a high level, such as more than 80%, it means that the generated adversarial samples have successfully misled the target black box model, making it difficult to correctly identify the content of the verification code, thereby effectively resisting attacks by automated programs or malicious models, and verifying the effectiveness of this application in improving the anti-attack resistance of the verification code.
[0198] 2) User accuracy rate: The user accuracy rate reflects the performance of this application in terms of taking into account user experience. A representative group of real users is selected, and they are shown the optimized verification code (i.e., the verification code style converted from the adversarial sample generated based on the technology of this application), and the users are required to identify and record their answers. By performing statistical analysis on the recognition data of a large number of users, the proportion of users who correctly identify the verification code is calculated. For example, if after testing hundreds of users from different backgrounds and age groups, the user accuracy rate can be maintained at a high level, such as above 95%, this means that while enhancing the security of the verification code, it does not cause greater recognition difficulties for human users, ensuring that users can successfully complete the verification process, thereby verifying the effectiveness of this application in improving user experience.
[0199] 3) Efficiency: The efficiency index mainly measures whether the time cost of adversarial sample generation meets the needs of actual application scenarios. In actual verification code system applications, such as user login verification of large websites, registration verification of online service platforms and other scenarios, it is usually necessary to generate effective adversarial samples in a short time. Record the time consumed from the input of the original verification code sample to the generation of the final optimized adversarial sample, including the total processing time of each link such as the initial adversarial sample generation module, the target black box model feature extraction module, and the model filtering optimization module. If under common hardware configurations (such as server configurations, GPU resources, etc.), the generation of adversarial samples can be completed in a few seconds or even shorter, for example, the average generation time is within 3 seconds, which shows that the adversarial sample generation algorithm of this application has high efficiency, and can meet the actual application needs of rapid update and verification of verification codes in high-concurrency scenarios, ensuring the smooth operation of the system and the efficient experience of users.
[0200] Through comprehensive consideration and experimental measurement of the three performance evaluation indicators of false positive rate, user accuracy rate and efficiency, the implementation effect of the verification code technical solution of this application can be comprehensively and accurately evaluated, providing strong data support and decision-making basis for its promotion and optimization in practical applications.
[0201] The following is a specific example of image verification code protection using the technical solution of this application:
[0202] Phase 1: Preliminary generation of adversarial samples
[0203] 1. Enter the original verification code sample:
[0204] A sample is randomly selected from the original verification code sample library.
[0205] For example, Figure 3 This is an example diagram of image verification code protection provided by the embodiment of the present application, such as Figure 3 As shown, the sample is a picture of a "panda" with a size of W×H, and the feature value of each pixel is RGB (or grayscale value).
[0206] 2. Generate initial adversarial samples using a white-box substitution model:
[0207] Input the original sample x into the white-box substitution model and calculate its loss function gradient Where θ is the parameter of the white-box substitution model. x is the input sample (panda picture). y is the true label (such as "panda"). J is the loss function of the substitution model. The initial adversarial sample x generated using the Fast Gradient Sign Method (FGSM) adv It is a perturbed image with the same size as the original image. Controlling the perturbation amplitude ensures that the adversarial sample has little impact on the recognizability of human users while being somewhat misleading.
[0208] 3. Display the initial adversarial sample:
[0209] The generated initial adversarial sample x adv Show it to the user to simulate a normal verification code interaction scenario. Collect the user's input and verification results, including correct / incorrect marks (whether the user correctly identified the verification code) and response time (the time interval between users entering the verification code).
[0210] Phase 2: Target Black Box Model Feature Extraction
[0211] 1. Record user input results:
[0212] The user input data collected in the first phase is sorted out, and the following contents are recorded: whether the verification code is correctly recognized, the recognition differences of the same verification code by different users, and the distribution of users' response times.
[0213] 2. Indirectly extract target black box model features:
[0214] Perform correlation analysis between the user's input data and the initial adversarial sample to identify the sensitivity of the target black box model (black box model) to different image features. The impact of changes in the perturbation amplitude on the user input results. Construct the input feature matrix X and the output result matrix Y.
[0215] The input matrix is each verification code image flattened into a vector, with a size of n×d, where n is the number of samples and d=W×H is the total number of pixels. The output matrix is the user's input result for each verification code (such as correct / wrong label), with a size of n×m, where m is the dimension of the model output (such as the number of classification categories). The covariance matrix is calculated according to the following formula:
[0216] C=(1 / (n-1))(X-μ X ) T (Y-μ Y )
[0217] The size of C is d×m, which represents the correlation between each pixel and the output of the target black box model. X and μ Y are the mean vectors of input features and output results respectively.
[0218] 3. Analyze the covariance matrix:
[0219] The absolute value of the covariance matrix reflects the sensitivity of different pixels to the output of the target black box model. Highly correlated pixels have a greater impact on the classification results, and these areas are optimized first. Low-correlation pixels have a smaller impact on the classification results and can reduce disturbances.
[0220] Phase 3: Optimizing adversarial examples
[0221] 1. Optimize adversarial samples based on the covariance matrix:
[0222] According to the analysis results of the covariance matrix, adjust the perturbation direction and amplitude of the adversarial sample. Apply stronger perturbations to highly sensitive features. Reduce perturbations to less sensitive features to reduce interference to human users. The optimization process is as follows:
[0223] x adv [i] = x adv [i]+α*C[i][j]
[0224] where x adv [i] is the optimized value of the i-th pixel; C[i][j] is the correlation between the i-th pixel and the j-th output dimension in the covariance matrix; α is the optimization step size, which is used to control the speed of disturbance adjustment.
[0225] 2. Generate optimized adversarial samples:
[0226] Use the optimized adversarial sample for verification code display. For example, refer to Figure 3 , the panda after adding disturbance can still be identified as a panda from the perspective of human users, but artificial intelligence will identify it as a gibbon.
[0227] 3. Verify the optimization effect:
[0228] Show the optimized adversarial sample to the user again and record the following data:
[0229] False positive rate: Whether the misclassification rate of the verification code by the malicious model reaches the set threshold (such as 80%).
[0230] User experience: Whether the recognizability of the optimized verification code by normal users remains at a high level (such as a recognition rate of more than 95%).
[0231] If the misjudgment rate does not meet the requirement, return to the second stage to further optimize the covariance matrix and perturbation strategy.
[0232] This application has the following beneficial effects:
[0233] 1. Target black box model feature extraction based on covariance matrix
[0234] This application proposes a method for constructing a covariance matrix using the input and output features of a target black box model, and indirectly obtains the feature distribution of the target black box model by analyzing the correlation between the feature changes of the input samples and the output results of the target black box model. This feature extraction method does not require understanding the internal structure of the target black box model, and can efficiently capture the feature sensitivity of the model in a black box environment, providing a basis for the optimization of adversarial samples.
[0235] 2. Model filtering optimization to generate adversarial samples
[0236] This application designs an iterative optimization mechanism based on model filtering by guiding the optimization direction of the perturbation through the covariance matrix. This mechanism can make fine adjustments on the specific feature dimensions of adversarial samples, improve the misleading and transferability of adversarial samples, and thus enable the generated adversarial samples to show a high misjudgment rate in multiple cracking models.
[0237] 3. Combination of initial adversarial sample generation and optimization
[0238] This application combines a fast method for generating initial adversarial samples with a white-box substitution model. A batch of initial adversarial samples are first generated through a classic algorithm (such as FGSM), and then combined with target black-box model feature extraction and filtering optimization technology to generate more efficient target adversarial samples. This phased approach not only reduces the computational overhead of adversarial sample generation, but also improves the effectiveness of adversarial samples.
[0239] 4. Improved transferability of adversarial examples
[0240] This application significantly improves the transfer performance of adversarial samples through specific optimization design, so that the generated samples can effectively deceive a variety of different cracking models, rather than being limited to a single target black box model. This feature enhances the security and practicality of the verification code.
[0241] 5. Captcha user-friendliness
[0242] When generating adversarial samples, this application ensures that the perturbation operation does not affect the normal identification of the verification code content by the human eye, allowing users to easily identify the verification code, while increasing the recognition difficulty of the artificial intelligence cracking model, taking into account both security and user experience.
[0243] In some embodiments, when extracting the target black box model features, the following method may be used instead of constructing and using the covariance matrix:
[0244] 1. Principal Components Analysis (PCA)
[0245] Instead of using the feature extraction method of the covariance matrix, the PCA algorithm is used to reduce the dimension and extract features of the input and output data of the target black box model. PCA selects the key feature dimensions that affect the output of the target black box model by analyzing the main change direction of the input samples in the high-dimensional space, and then guides the perturbation optimization of the adversarial samples.
[0246] Advantages of substitution points: PCA can effectively reduce the data dimension and improve the computational efficiency of the adversarial sample generation process.
[0247] 2. Mutual Information Analysis
[0248] By calculating the mutual information value between the input sample features and the target black box model output, the correlation between the feature dimension and the model output is extracted. The feature dimension with a higher mutual information value can significantly affect the decision-making process of the target black box model and can be used as the focus of perturbation optimization.
[0249] Advantages of substitution points: Mutual information analysis can more directly quantify the correlation between features and outputs, and is suitable for multi-dimensional feature optimization of complex verification codes.
[0250] In some embodiments, an alternative initial adversarial sample generation method is as follows:
[0251] 1.PGD algorithm replaces FGSM algorithm
[0252] The Projected Gradient Descent (PGD) algorithm is used to replace the Fast Gradient Sign Method (FGSM) to generate the initial adversarial sample. PGD is a multi-step optimization algorithm that calculates the exact perturbation direction at each iteration and limits the perturbation to a certain range.
[0253] Alternative point advantage: The PGD algorithm can generate more robust initial adversarial samples and is suitable for scenarios that require higher destructive capabilities.
[0254] 2. Generate adversarial samples based on GAN
[0255] Generative adversarial networks (GANs) are used to replace white-box substitution models to generate initial adversarial samples. GANs directly generate realistic adversarial samples through adversarial training between the generator and the discriminator, without relying on white-box models.
[0256] Alternative point advantage: GAN can generate more complex and higher quality adversarial samples, and is also suitable for image verification codes.
[0257] Another alternative is to use generative adversarial networks (GANs) to generate adversarial samples. GANs can directly generate highly misleading samples through adversarial training between the generator and the discriminator.
[0258] In some embodiments, the surrogate model filter optimization mechanism is as follows:
[0259] 1. Genetic algorithm optimization
[0260] The alternative model filtering optimization mechanism uses a genetic algorithm to optimize the initial adversarial samples. By simulating the biological evolution process, adversarial samples are selected, crossed, and mutated to generate more adaptable samples.
[0261] Advantages of substitution points: Genetic algorithms have global search capabilities, can avoid falling into local optimal solutions, and are suitable for highly complex target black box models.
[0262] 2. Particle Swarm Optimization (PSO)
[0263] The particle swarm optimization algorithm is used to replace the model filtering optimization mechanism. PSO simulates the movement of particle swarms in the search space to find the disturbance direction that can maximize the misjudgment rate of the target black box model.
[0264] Advantages of alternative points: PSO has low computational overhead and can quickly generate effective adversarial samples.
[0265] It should be understood that, although the various steps in the flowcharts in the above-described embodiments are sequentially displayed according to the indications of the arrows, these steps are not necessarily executed sequentially in the order indicated by the arrows. Unless there is a clear description in this article, the execution of these steps is not strictly limited in order, and they can be executed in other orders. Moreover, at least a portion of the steps in the figure may include a plurality of sub-steps or a plurality of stages, and these sub-steps or stages are not necessarily executed at the same time, but can be executed at different times, and their execution order is not necessarily to be carried out sequentially, but can be executed in turn or alternately with other steps or at least a portion of the sub-steps or stages of other steps.
[0266] Figure 4 A schematic diagram of a verification code generating device provided in an embodiment of the present application, such as Figure 4 As shown, the present application provides a verification code generating device, the device comprising:
[0267] An initial adversarial sample generation module 11, which is configured to generate an initial adversarial sample based on an original verification code sample;
[0268] A target black box model feature extraction module 12, which is configured to analyze the input-output relationship between the original verification code sample and the initial adversarial sample in the target black box model and construct a covariance matrix;
[0269] A model filtering optimization module 13, which is configured to iteratively optimize the initial adversarial sample according to the covariance matrix to obtain an optimized adversarial sample;
[0270] The verification code generation module 14 is configured to determine the optimized adversarial sample as the final generated verification code.
[0271] Figure 5 Another schematic diagram of the verification code generating device provided in the embodiment of the present application is as follows Figure 5 As shown, the present application provides a verification code generation device, the device also includes: a user verification module, the specific description of the content in the figure is as follows:
[0272] (1) Original verification code sample library
[0273] The original verification code sample library is the basic data source of the entire verification code generation system. Its main function is to store various original verification code samples, which can be in the form of images, characters or other forms, to provide initial materials for the subsequent generation of adversarial samples. The module itself does not require external input of specific information as input (only as a source of data storage), but it will output the original verification code sample and pass it to the subsequent initial adversarial sample generation module to start the entire adversarial sample generation and verification code verification process.
[0274] (2) Initial adversarial sample generation module
[0275] The core task of the initial adversarial sample generation module is to use a specific algorithm to generate preliminary adversarial samples based on the received original verification code samples. Its input is clearly the original verification code samples obtained from the original verification code sample library. Inside the module, it will use white-box substitution models and related technical means such as the classic fast gradient sign method (FGSM) to calculate the gradient of the loss function and apply preliminary perturbations to the original samples according to the gradient direction and the set perturbation amplitude, thereby generating initial adversarial samples. Finally, the module will output these initial adversarial samples to provide basic data for the subsequent optimization of adversarial samples, and pass them to the target black-box model feature extraction module for the next step of processing.
[0276] (3) Target black box model feature extraction module
[0277] The target black box model feature extraction module plays a key role in connecting the previous and the next. It receives the initial adversarial samples output by the initial adversarial sample generation module and the original samples in the original verification code sample library. By inputting these samples into the target black box model and conducting an in-depth analysis of its input-output relationship, a covariance matrix that can characterize the feature sensitivity of the target black box model is constructed. Specifically, the input feature matrix is constructed based on the flattened pixel vector of the input sample, and the output result matrix is constructed in combination with the output results of the target black box model (such as classification labels, confidence, etc.), and then the covariance matrix is obtained through a specific calculation formula. The covariance matrix can reflect the correlation between each input feature and the output dimension of the target black box model. The output covariance matrix will be sent to the model filter optimization module to guide the subsequent optimization of adversarial samples.
[0278] (4) Model filtering optimization module
[0279] The model filter optimization module performs iterative optimization based on the covariance matrix obtained from the target black box model feature extraction module and the initial adversarial sample from the initial adversarial sample generation module. It will fine-tune the perturbation direction and amplitude of the initial adversarial sample based on the feature correlation information reflected in the covariance matrix. During the iteration process, stronger perturbations are preferentially applied to features with high correlation with the target black box model output (i.e., features with larger covariance values), while reducing perturbations to features with low correlation. Through multiple such iterative optimizations, the decision boundary of the target black box model is gradually approached, making the generated adversarial sample more misleading. Finally, the optimized adversarial sample is output and passed to the verification code generation module to generate the verification code that can be finally displayed to the user.
[0280] (5) Verification code generation module
[0281] The verification code generation module converts the received optimized adversarial samples into a verification code style that can be recognized and verified by users, completing the conversion from adversarial samples to intuitive and recognizable verification code presentation. For example, for image adversarial samples, they will be processed into a clear, appropriately sized, and user-friendly image verification code presentation. The final verification code output by this module will be input into the user verification module for users to perform verification operations.
[0282] (6) User Authentication Module
[0283] The user verification module is the key link for the entire system to directly interact with the user and complete the verification judgment. The user verification module receives the final verification code output by the verification code generation module and the verification code content entered by the user, and judges whether the user input is consistent with the pre-set correct verification code content (real label). If the content entered by the user matches the real label, the result of verification passing is output; if not, the result of verification failure is output, so as to determine whether the user identity verification is successful and complete the entire verification code verification process.
[0284] Through the above-mentioned complete system architecture and the coordinated cooperation between various modules, this application can generate a verification code with high anti-attack capabilities and user experience based on the original verification code sample, and complete effective verification of the user's identity. At the same time, it can cope with the cracking attack challenges brought by artificial intelligence tools, etc., to ensure system security.
[0285] Regarding the limitation on the verification code generating device, reference may be made to the limitation on the verification code generating method in the above embodiments of the present application, which will not be elaborated in this embodiment.
[0286] Figure 6 Another schematic diagram of the verification code generating device provided in the embodiment of the present application is as follows Figure 6 As shown, the device includes a memory 22 and a processor 21, the memory stores a computer program, and the processor is configured to run the computer program to execute the methods in the above embodiments of the present application.
[0287] The memory is connected to the processor, the memory may be a flash memory or a read-only memory or other memory, and the processor may be a central processing unit or a single-chip microcomputer.
[0288] In some embodiments, the present application provides a computer-readable storage medium having a computer program stored thereon. When the computer program is executed by a processor, the methods in the above embodiments of the present application are implemented.
[0289] The computer-readable storage medium includes volatile or non-volatile, removable or non-removable media implemented in any method or technology for storing information (such as computer-readable instructions, data structures, computer program modules or other data). Computer-readable storage media include, but are not limited to, RAM (Random Access Memory), ROM (Read-Only Memory), EEPROM (Electrically Erasable Programmable read only memory), flash memory or other memory technology, CD-ROM (Compact Disc Read-Only Memory), digital versatile disk (DVD) or other optical disk storage, magnetic cassettes, magnetic tapes, magnetic disk storage or other magnetic storage devices, or any other medium that can be used to store the desired information and can be accessed by a computer.
[0290] It is to be understood that the above embodiments are merely exemplary embodiments used to illustrate the principles of the present application, but the present application is not limited thereto. For those skilled in the art, various modifications and improvements can be made without departing from the spirit and substance of the present application, and these modifications and improvements are also considered to be within the scope of protection of the present application.
Claims
1. A verification code generation method, characterized in that: The method comprises: S1. Generate initial adversarial samples based on the original verification code samples; S2, analyze the input-output relationship between the original verification code sample and the initial adversarial sample in the target black box model, and construct a covariance matrix; S3. Iteratively optimize the initial adversarial sample according to the covariance matrix to obtain an optimized adversarial sample; S4. Determine the optimized adversarial sample as the final generated verification code.
2. The verification code generation method according to claim 1, characterized in that: S1, including: Apply preliminary perturbations to the original CAPTCHA samples to generate preliminary adversarial samples.
3. The verification code generation method according to claim 2, characterized in that: Apply preliminary perturbations to the original verification code sample to generate preliminary adversarial samples, including: Input the original verification code sample into the white-box substitution model to obtain the loss function gradient; According to the gradient of the loss function, preliminary adversarial samples are generated by the fast gradient sign method FGSM.
4. The verification code generation method according to claim 1, characterized in that: S2, including: Input the original verification code sample and the initial adversarial sample into the target black box model to obtain the model output; Construct an input feature matrix based on the model input, and construct an output result matrix based on the model output; The covariance matrix is obtained based on the input feature matrix and the output result matrix.
5. The verification code generation method according to claim 4, characterized in that: According to the input feature matrix and the output result matrix, the covariance matrix is obtained by the following formula: C=(1 / (n-1))(X-μ) X ) T (Y-μ Y ) Among them, C represents the covariance matrix, n represents the number of samples, X represents the input feature matrix, Y represents the output result matrix, μ X Represents the mean vector of the input feature matrix, μ Y Represents the mean vector of the output result matrix.
6. The verification code generation method according to claim 1, characterized in that: S3, including: The perturbation direction and amplitude of the initial adversarial sample are iteratively adjusted according to the covariance matrix to obtain the optimized adversarial sample.
7. The verification code generation method according to claim 6, characterized in that: The perturbation direction and amplitude of the initial adversarial sample are iteratively adjusted according to the covariance matrix to obtain the optimized adversarial sample, including: Determine the perturbation adjustment direction and amplitude of the initial adversarial sample according to the covariance matrix; Adjust the sample according to the disturbance adjustment direction and amplitude to obtain the adjusted adversarial sample; Input the adjusted adversarial sample into the target black box model, obtain the model output, and obtain the misjudgment rate of the adjusted adversarial sample; Determine whether the iteration stop condition is met. If not, reconstruct the covariance matrix according to the adjusted adversarial sample, and repeat the steps of sample adjustment and obtaining the adjusted sample misclassification rate according to the reconstructed covariance matrix until the iteration stop condition is met.
8. The verification code generation method according to claim 7, characterized in that: The iteration stop condition includes: The misclassification rate of the adjusted sample reaches the preset threshold; or The disturbance amplitude reaches the preset range.
9. A verification code generating device, characterized in that: The device comprises: An initial adversarial sample generation module, which is configured to generate an initial adversarial sample based on the original verification code sample; A target model feature extraction module is configured to analyze the input-output relationship between the original verification code sample and the initial adversarial sample in the target black box model and construct a covariance matrix; A model filter optimization module, which is configured to iteratively optimize the initial adversarial sample according to the covariance matrix to obtain an optimized adversarial sample; A verification code generation module is configured to determine the optimized adversarial sample as a final generated verification code.
10. A verification code generating device, characterized in that: The method comprises a memory and a processor, wherein the memory stores a computer program, and the processor is configured to run the computer program to implement the verification code generation method according to any one of claims 1 to 8.
11. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the verification code generation method according to any one of claims 1 to 8 is implemented.