Interactive man-machine verification method, device and equipment based on non-distorted watermark

By using an interactive human-machine verification method based on non-distorted watermarking, verification questions with statistical features are generated and multi-dimensional feature analysis is performed. The key is dynamically updated, which solves the problem of distinguishing between human and AI users and achieves a highly secure and reliable system verification.

CN120995436APending Publication Date: 2025-11-21CHINA UNITED NETWORK COMM GRP CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511096327.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-06
Publication Date
2025-11-21

AI Technical Summary

Technical Problem

Existing technologies cannot effectively distinguish between human users and AI users, leading to security vulnerabilities and data leaks, allowing malicious attackers to easily compromise the system.

Method used

An interactive human-computer verification method based on non-distorted watermarking is adopted. By generating target text with statistical features, embedding non-distorted watermarks and converting it into verification questions, multi-dimensional feature analysis is used to identify user identity, and the key is dynamically updated to improve security.

Benefits of technology

It significantly improves the security and reliability of the system, prevents forgery and tampering, accurately identifies AI attackers, protects account and data security, and enhances user experience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120995436A_ABST
    Figure CN120995436A_ABST
Patent Text Reader

Abstract

The invention discloses an interactive man-machine verification method, device and equipment based on a non-distorted watermark. The method comprises the following steps: generating a target key for a non-distorted watermark; generating a target text with statistical characteristics according to the target key; converting the target text into a verification question interacting with the target user, so that the target user answers the verification question; obtaining a verification answer submitted by the target user; judging whether the target user is a human user or an AI user according to the verification answer; if the target user is the AI user, rejecting the verification request of the target user, and identifying that the target user is an AI attacker; and if the target user is a human user, the verification request of the target user is passed, so that interactive man-machine verification based on the non-distorted watermark is completed. The method not only improves the security and reliability of verification, but also improves the use experience of the user.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of information processing technology, and specifically relates to an interactive human-computer verification method, apparatus and equipment based on non-distorted watermarking. Background Technology

[0002] With the continuous development and widespread application of artificial intelligence technology, attack methods have become more diversified and covert. Many security vulnerabilities and malicious attacks are now proactively initiated by AI programs (i.e., bots), cleverly bypassing traditional security verification measures using automation technology. Malicious bots are constantly improving their camouflage capabilities, mimicking the behavior of human users, making identification more difficult, and thus successfully gaining system privileges. This allows attackers to easily compromise accounts, steal sensitive data, and even cause serious economic losses and system paralysis, leading to significant consequences such as data breaches and property damage. Faced with these increasingly complex attack methods, there is an urgent need to adopt more effective verification technologies to ensure the security and stable operation of systems. Summary of the Invention

[0003] The technical problem to be solved by the present invention is to address the above-mentioned shortcomings of the prior art by proposing an interactive human-computer verification method, apparatus and device based on non-distorted watermarking, which can improve the security and reliability of verification in network information scenarios.

[0004] In a first aspect, the present invention provides an interactive human-computer verification method based on non-distorted watermarking, the method comprising the following steps:

[0005] Generate the target key for non-distorted watermarking;

[0006] Generate target text with statistical features based on the target key;

[0007] The target text is converted into interactive verification questions for the target user, allowing the target user to answer the verification questions;

[0008] Obtain the verification answers submitted by the target user;

[0009] Based on the verification answers, determine whether the target user is a human user or an AI user;

[0010] If the target user is an AI user, the target user's verification request is rejected, and the target user is identified as an AI attacker; if the target user is a human user, the target user's verification request is granted, thereby completing the interactive human-machine verification based on non-distorted watermarks.

[0011] Furthermore, after verifying the request, the method also includes:

[0012] The target key is updated using the SHA-256 hash function based on a preset fixed time period; or,

[0013] The target key is updated using a continuous time variable.

[0014] Furthermore, the target key is updated using continuous time variables, specifically including:

[0015] Obtain the phase factor; and generate a basic watermark key using a hash function;

[0016] The formula for calculating the phase factor is as follows:

[0017] Phase factor = (current UTC timestamp / preset time period) mod 1;

[0018] Where mod represents the modulo operation;

[0019] The phase factor is combined with the basic watermark key to obtain the combined key;

[0020] The combined key is dynamically adjusted using trigonometric functions, thereby updating the target key.

[0021] Furthermore, the target text is converted into verification questions that interact with the target user, specifically including:

[0022] Rewrite the target text into a set of interactive questions that require user responses; the interactive questions may include fill-in-the-blank, short-answer, or multiple-choice questions.

[0023] Embed undistorted watermarks and statistical features into interactive questions to generate validation questions that interact with the target user.

[0024] Furthermore, target text with statistical features is generated, specifically:

[0025] Generate target text with statistical features using the SynthID-Text model watermarking method; or...

[0026] Target text with statistical features is generated using a watermarking method based on word frequency adjustment; or, target text with statistical features is generated using a watermarking method based on a hidden Markov model; or...

[0027] Attention-based watermarking methods generate target text with statistical features.

[0028] Furthermore, based on the verification answers, it is determined whether the target user is a human user or an AI user, specifically including:

[0029] The parameters to be obtained are: the proportion of high-probability words in the SynthID-Text model for the verification answer, the proportion of simplified expressions selected in the verification answer, the proportion of watermark scores in the verification answer, the syntactic simplicity of the verification answer, the information sparsity of the verification answer, and the response efficiency of the verification answer.

[0030] Set the weights for high-probability words in the SynthID-Text model, as well as the weights for simplified expression selection, watermark score, syntactic simplicity, information sparsity, and response efficiency.

[0031] The proportion of high-probability words in the SynthID-Text model is multiplied by the weight of the proportion of high-probability words in the SynthID-Text model to obtain the proportion value of high-probability words in the SynthID-Text model; the proportion of simplified expression selection is multiplied by the weight of the simplified expression selection to obtain the simplified expression selection proportion value; the proportion of watermark score is multiplied by the weight of the watermark score proportion to obtain the watermark score proportion value; the syntactic simplicity is multiplied by the weight of the syntactic simplicity to obtain the syntactic simplicity value; the information sparsity is multiplied by the weight of the information sparsity to obtain the information sparsity value; and the response efficiency is multiplied by the weight of the response efficiency to obtain the response efficiency value.

[0032] The feature index values ​​of the verification answer are obtained by summing and summing the proportion of high-probability words, the proportion of simplified expression selection, the proportion of watermark score, the syntactic simplicity value, the information sparsity value, and the response efficiency value in the SynthID-Text model.

[0033] If the characteristic index value of the verified answer is higher than the preset threshold, the target user is determined to be an AI user; otherwise, the target user is determined to be a human user.

[0034] Secondly, the present invention provides an interactive human-computer verification device based on non-distorted watermarking, the device comprising:

[0035] The first generation unit is used to generate the target key for non-distorted watermarking;

[0036] The second generation unit, connected to the first generation unit, is used to generate target text with statistical features based on the target key;

[0037] The processing unit, connected to the second generation unit, is used to convert the target text into a verification question that can be interacted with by the target user, and to receive the verification answer submitted by the target user in answering the verification question;

[0038] The determination unit, connected to the processing unit, is used to determine whether the target user is a human user or an AI user based on the verification answer.

[0039] The first identification unit, connected to the determination unit, is used to identify the target user as an AI attacker and reject the target user's verification request when the determination unit determines that the target user is an AI user.

[0040] The second identification unit, connected to the determination unit, is used to identify the target user as a non-AI attacker when the determination unit determines that the target user is a human user, and complete the interactive human-machine verification based on the non-distorted watermark by passing the target user's verification request.

[0041] Furthermore, the processing unit includes:

[0042] The rewriting module, connected to the second generation unit, is used to rewrite the target text into a set of interactive questions that require user responses; the interactive questions include fill-in-the-blank questions, short answer questions, or multiple-choice questions;

[0043] The embedding module, connected to the rewriting module, is used to embed non-distorted watermarks and statistical features into interactive questions to generate validation questions that interact with the target user.

[0044] Furthermore, the second generation unit includes:

[0045] The first generation module, connected to the first generation unit, is used to generate target text with statistical features using the watermarking method of the SynthID-Text model.

[0046] The second generation module, connected to the first generation unit, is used to generate target text with statistical features using a watermarking method based on word frequency adjustment.

[0047] The third generation module, connected to the first generation unit, is used to generate target text with statistical features based on the watermarking method of the Hidden Markov Model.

[0048] The fourth generation module, connected to the first generation unit, is used to generate target text with statistical features based on the attention mechanism-based watermarking method.

[0049] Thirdly, the present invention provides an electronic device including a memory and a processor, wherein the memory stores a computer program, and when the processor runs the computer program stored in the memory, the processor executes the interactive human-computer verification method based on non-distorted watermarking as described in the first aspect.

[0050] This invention, by employing an interactive human-machine verification method based on non-distorted watermarking, can significantly improve the security and reliability of the system. Specific beneficial effects are as follows:

[0051] 1. Relying on the concealment and robustness of non-distorted watermarks, this invention can effectively prevent various forgery and tampering behaviors, improve the security of verification information, and prevent attackers from bypassing the verification process through technical means.

[0052] 2. By dynamically generating target text and verification questions with statistical features, the diversity and unpredictability of verification content are enhanced, effectively countering the disguise of robots simulating human behavior and improving the accuracy of recognition.

[0053] 3. The system can accurately distinguish between human users and AI attackers, which helps defend against automated attacks, protect account and data security, and reduce the risk of sensitive information leakage and property loss.

[0054] 4. This method also improves the user's interactive experience, making the verification process natural and convenient, reducing user misjudgment and operational difficulty, and enhancing the overall user experience. Attached Figure Description

[0055] Figure 1 This is a schematic diagram of an interactive human-computer verification method based on non-distorted watermarking in an embodiment of the present invention;

[0056] Figure 2 This is a diagram illustrating the overall architecture of interactive human-computer verification based on non-distorted watermarking in an embodiment of the present invention.

[0057] Figure 3 This is a schematic diagram illustrating the working principle of interactive human-computer verification based on non-distorted watermarking in an embodiment of the present invention.

[0058] Figure 4 This is a schematic diagram of multidimensional detection based on non-distorted watermarking interactive human-computer verification in an embodiment of the present invention;

[0059] Figure 5 This is a flowchart illustrating the interactive human-computer verification process based on non-distorted watermarking in an embodiment of the present invention.

[0060] Figure 6 This is a schematic diagram of an interactive human-computer verification device based on non-distorted watermarking in an embodiment of the present invention;

[0061] Figure 7 This is an architectural diagram of an electronic device according to an embodiment of the present invention.

[0062] Reference numerals: 10, first generation unit; 20, second generation unit; 30, processing unit; 40, determination unit; 50, first identification unit; 60, second identification unit. Detailed Implementation

[0063] To enable those skilled in the art to better understand the technical solution of the present invention, the embodiments of the present invention will be further described in detail below with reference to the accompanying drawings.

[0064] It is understood that the specific embodiments and accompanying drawings described herein are merely for explaining the invention and are not intended to limit the invention.

[0065] It is understood that, without conflict, the various embodiments and features in the embodiments of the present invention can be combined with each other.

[0066] It is understood that, for ease of description, only the parts related to the present invention are shown in the accompanying drawings, while the parts unrelated to the present invention are not shown in the drawings.

[0067] It is understood that each unit or module involved in the embodiments of the present invention may correspond to only one entity structure, or may be composed of multiple entity structures, or multiple units or modules may be integrated into one entity structure.

[0068] It is understood that, without conflict, the functions and steps marked in the flowcharts and block diagrams of this invention may occur in a different order than that marked in the accompanying drawings.

[0069] It is understood that the flowcharts and block diagrams of this invention illustrate the possible architecture, functions, and operations of systems, apparatuses, devices, and methods according to various embodiments of this invention. Each block in the flowchart or block diagram may represent a unit, module, program segment, or code, containing executable instructions for implementing the specified function. Furthermore, each block or combination of blocks in the block diagram and flowchart can be implemented using a hardware-based system to achieve the specified function, or using a combination of hardware and computer instructions.

[0070] It is understood that the units and modules involved in the embodiments of the present invention can be implemented by software or by hardware. For example, the units and modules can be located in a processor.

[0071] Example 1:

[0072] This embodiment provides an interactive human-machine verification method based on non-distorted watermarking. This method can be applied to various internet information security scenarios, including online account login, electronic payment, access to sensitive information, internal enterprise system access control, online voting, and questionnaires. This verification method can effectively prevent attacks from automated bots and malware, ensuring that only genuine human users can successfully complete the verification, thereby improving system security and reliability.

[0073] In practical applications, this method generates a non-distorted watermark with hidden information and embeds it into the verification questions, requiring users to identify and answer them. This interactive verification process not only increases the difficulty for attackers to bypass verification but also facilitates users in completing verification through natural interaction, improving the user experience. Especially when facing increasingly sophisticated AI attack methods, this method can effectively identify bot programs by utilizing statistical features and dynamically generated verification content, reducing the risk of system attacks. Furthermore, this technology has strong anti-interference capabilities, ensuring that verification maintains high efficiency and stable performance under different devices and network environments, making it widely applicable to various high-security application scenarios and providing a more robust guarantee for information security.

[0074] like Figure 1 As shown, the interactive human-computer verification method based on non-distorted watermarking in this embodiment includes the following steps:

[0075] Step S1: Generate the target key for non-distorted watermarking.

[0076] Step S2: Generate target text with statistical features based on the target key.

[0077] As a specific implementation method, target text with statistical features is generated, specifically as follows:

[0078] Generate target text with statistical features using the SynthID-Text model watermarking method; or...

[0079] Target text with statistical features is generated using a watermarking method based on word frequency adjustment; or, target text with statistical features is generated using a watermarking method based on a hidden Markov model; or...

[0080] Attention-based watermarking methods generate target text with statistical features.

[0081] Step S3: Convert the target text into a verification question that interacts with the target user, so that the target user can answer the verification question.

[0082] As a specific implementation method, based on the verification answer, it is determined whether the target user is a human user or an AI user, specifically including:

[0083] The parameters to be obtained are: the proportion of high-probability words in the SynthID-Text model for the verification answer, the proportion of simplified expressions selected in the verification answer, the proportion of watermark scores in the verification answer, the syntactic simplicity of the verification answer, the information sparsity of the verification answer, and the response efficiency of the verification answer.

[0084] Set the weights for high-probability words in the SynthID-Text model, as well as the weights for simplified expression selection, watermark score, syntactic simplicity, information sparsity, and response efficiency.

[0085] The proportion of high-probability words in the SynthID-Text model is multiplied by the weight of the proportion of high-probability words in the SynthID-Text model to obtain the proportion value of high-probability words in the SynthID-Text model; the proportion of simplified expression selection is multiplied by the weight of the simplified expression selection to obtain the simplified expression selection proportion value; the proportion of watermark score is multiplied by the weight of the watermark score proportion to obtain the watermark score proportion value; the syntactic simplicity is multiplied by the weight of the syntactic simplicity to obtain the syntactic simplicity value; the information sparsity is multiplied by the weight of the information sparsity to obtain the information sparsity value; and the response efficiency is multiplied by the weight of the response efficiency to obtain the response efficiency value.

[0086] The feature index values ​​of the verification answer are obtained by summing and summing the proportion of high-probability words, the proportion of simplified expression selection, the proportion of watermark score, the syntactic simplicity value, the information sparsity value, and the response efficiency value in the SynthID-Text model.

[0087] If the characteristic index value of the verified answer is higher than the preset threshold, the target user is determined to be an AI user; otherwise, the target user is determined to be a human user.

[0088] The core idea of ​​this step is to extract specific feature metrics from a set of verification answers. For a given text, these include the following six metrics:

[0089] The first is the "proportion of high-probability words," which refers to the proportion of words in a text whose probability of occurrence exceeds a certain threshold (e.g., 0.8). Because AI typically tends to use high-frequency words and expressions from model training, a high proportion of high-probability words is more indicative of the content generated by the AI.

[0090] Second, the "simplified expression selection ratio" refers to the proportion of simple, direct, and clear expressions in the text, such as the proportion of short sentences, everyday phrases, and simple vocabulary. When a text is relatively simple and lacks complex sentence structures, it may be more inclined to be generated by AI.

[0091] Third is the "watermark score ratio." This uses a watermark detection model to determine whether the text contains a model-specific audio watermark. A high watermark score means the text may have been generated by AI or embedded with a model-specific watermark.

[0092] Fourth is "syntactic simplicity." This is an indicator that quantifies the complexity of sentence structure. AI-generated text tends to have simple sentence structures, short words, and sentences without too many clauses or modifiers, so it scores higher.

[0093] Fifth is "information sparsity," which refers to the density of keywords or core information in a text. If information is sparse, it means the content is simple, repetitive, or has low information concentration, and is more likely to be generated by a model.

[0094] Sixth is "response efficiency," which represents the time or energy resources required to generate this text. Generally, AI generates text quickly and has high response efficiency.

[0095] In terms of configuration, these metrics need to be assigned importance. That is, each metric should be assigned a weight, indicating its priority in the judgment. For example, the proportion of high-probability words might account for 30% of the total metrics, as it reflects the model's preferred word distribution. Simplified expressions might account for 20%, as coarse expressions are more common in AI. Watermark score accounts for 15%, serving as an important indicator for verifying the source of the document. Syntactic simplicity accounts for 15%, representing the complexity of the grammatical structure. Information sparsity accounts for 10%, reflecting the depth of the content. Response efficiency accounts for the remaining 10%, representing the generation speed.

[0096] In actual measurement, assuming a verification answer consists of 100 words, and 85 words are found to have a probability of occurrence of 0.8 or higher (the proportion of high-probability words is 0.85), then the contribution value obtained after multiplying by the weight is 0.85 × 0.3 = 0.255.

[0097] In this text, the proportion of simple expressions is 0.75 (i.e., 75% of sentences have relatively simple structures), multiplied by 20%, resulting in a contribution value of 0.15. The watermark detection score is 0.65, multiplied by 0.15, resulting in a contribution value of 0.0975. The syntactic simplicity score is 0.8 (very simple), multiplied by 0.15, resulting in a contribution value of 0.12. The information sparsity score is 0.15 (relatively simple and sparse content), multiplied by 0.10, resulting in 0.015. The response efficiency is as high as 0.9 (i.e., extremely fast response speed), multiplied by 0.10, resulting in 0.09.

[0098] Adding these six values ​​together, the final "characteristic index value" is approximately 0.7275.

[0099] The next step is to set a "threshold" to determine whether the text is from a human or AI. This threshold is typically set between 0.70 and 0.80. For example, if we set the threshold to 0.70, and the value exceeds this threshold, we determine that the text is likely AI-generated; if it's below, it was written by a human.

[0100] The basis for this judgment is that AI-generated content generally features high-probability words, simple sentence structures, sparse content, and fast response speed, resulting in relatively high values ​​for these indicators. In contrast, text written by human users is richer in vocabulary and sentence complexity, and contains deeper and higher-quality content, leading to lower indicator values.

[0101] By quantifying six characteristic indicators in the verification answers, combining them with pre-set weights, multiplying the scores of each indicator, and then summing them, a total characteristic value is obtained. This value is compared with a set threshold; if it exceeds the threshold, the user is judged as an AI user; otherwise, the user is judged as a human user.

[0102] This threshold range is not fixed and can be fine-tuned based on the data distribution of the actual application. For example, if it is found in the experiment that some manually written content also shows high values, the threshold can be appropriately increased; conversely, the threshold can be decreased to ensure the sensitivity of detection.

[0103] Overall, this solution integrates multi-dimensional indicators and leverages differences in model bias and content characteristics to effectively distinguish between human and AI users, achieving intelligent and automated user identity detection.

[0104] As a specific implementation method, the target text is converted into verification questions that interact with the target user, specifically including:

[0105] Rewrite the target text into a set of interactive questions that require user responses; the interactive questions may include fill-in-the-blank, short-answer, or multiple-choice questions.

[0106] Embed undistorted watermarks and statistical features into interactive questions to generate validation questions that interact with the target user.

[0107] Step S4: Obtain the verification answer submitted by the target user.

[0108] Step S5: Based on the verification answer, determine whether the target user is a human user or an AI user:

[0109] If the target user is an AI user, the target user's verification request is rejected, and the target user is identified as an AI attacker; if the target user is a human user, the target user's verification request is granted, thereby completing the interactive human-machine verification based on non-distorted watermarks.

[0110] As one specific implementation, after verifying the request, the method further includes:

[0111] The target key is updated using the SHA-256 hash function based on a preset fixed time period; or,

[0112] The target key is updated using a continuous time variable.

[0113] Furthermore, the target key is updated using continuous time variables, specifically including:

[0114] Obtain the phase factor; and generate a basic watermark key using a hash function;

[0115] The formula for calculating the phase factor is as follows:

[0116] Phase factor = (current UTC timestamp / preset time period) mod 1;

[0117] Where mod represents the modulo operation;

[0118] The phase factor is combined with the basic watermark key to obtain the combined key;

[0119] The combined key is dynamically adjusted using trigonometric functions, thereby updating the target key.

[0120] The interactive CAPTCHA scheme proposed in this embodiment innovatively leverages the unique statistical patterns exhibited by Large Language Models (LLMs) during text generation, and the fundamental differences between these patterns and human natural language behavior, to construct a verification mechanism that accurately identifies and effectively resists AI attacks. Its overall architecture is as follows: Figure 2 As shown, the entire process is interconnected, forming a robust security system:

[0121] First, the dynamic key management module proactively generates and periodically updates a unique watermark key. This dynamic update mechanism acts like an ever-evolving security lock for the entire verification process. By continuously changing key parameters, it significantly reduces the risk of the key being maliciously cracked, thus building a solid foundation of security for all subsequent steps.

[0122] Next, the watermarked CAPTCHA generation module introduces advanced SynthID-Text technology, integrating a dynamic key as a core parameter into the text generation process, thereby creating text content with specific statistical characteristics. These texts cleverly embed unique watermarks, accurately marking the source and attributes of the text without interfering with the original semantics, perfectly achieving "seamless identification." This design deeply utilizes the inherent rules of LLM in vocabulary selection and sentence structure construction, laying crucial identification clues for subsequent human-machine differentiation.

[0123] The system then transforms these watermarked texts into a cloze-style interactive challenge, presenting them to the user. Users must complete the missing words or phrases based on contextual logic—this design not only effectively tests the user's natural language comprehension ability but also deliberately increases the difficulty for AI models to provide reasonable answers, addressing their weaknesses in semantic coherence and contextual adaptability. This adds a crucial element to the accuracy of distinguishing between humans and AI attackers.

[0124] After a user submits an answer, the user response collection module records the complete answer in real time, including details such as the completed text and input time, providing raw data support for subsequent analysis.

[0125] These response data are then fed into a multi-dimensional feature analysis module. This module acts like a sophisticated behavior decoder, meticulously analyzing user behavior from multiple dimensions: it focuses on the accuracy of the answers, judging whether they conform to contextual logic; it also tracks response time, analyzing rhythmic changes during the input process; and it captures input patterns, such as the presence of typical human input habits (e.g., modifications, pauses). Through this multi-dimensional and comprehensive analysis, it can keenly capture subtle differences in behavioral patterns between human users and AI models, extracting key features with discriminative power.

[0126] Finally, the human-machine identification module comprehensively evaluates the user's behavioral characteristics based on the results of multi-dimensional feature analysis. Like an experienced "identification expert," it combines text watermark features with behavioral pattern characteristics to ultimately determine whether the user is a real human or an AI attacker, and decides whether to grant access accordingly.

[0127] This innovative verification method effectively defends against AI attacks and ensures system security, while providing a smooth and convenient verification experience for real human users through a simple and intuitive interactive format, achieving a perfect balance between security and user experience.

[0128] The working principle of the "passive inducement" mechanism of watermarking is as follows: Figure 3As shown, this mechanism indirectly intervenes in the generation logic of an attacker's model (such as GPT-4) by embedding a non-distorted watermark during text generation and adjusting the probability distribution of the language model's output. This causes the attacker to favor specific answers, thereby exposing its AI characteristics, rather than through direct intervention. The specific implementation process is as follows: First, the probability distribution of word selection is adjusted. The defender uses tournament sampling mechanisms such as SynthID-Text to bias the probability of word selection. For example, in the sentence "I'm typing with _", the probability of generating "laptop" and "wearing glasses" is increased, while the weight of similar words such as "sunglasses" and "computer" is decreased. Second, contextual preference formation and semantic association reinforcement are achieved through language context design, such as limiting collocations ("wearing" guides words related to glasses), making the target watermark words easier for the AI ​​model to recognize and select. Third, the generation inertia of the AI ​​model is induced. When the attacker's model (such as GPT-4) generates answers, it will... The mechanism relies on two signals: first, the co-occurrence probability in its pre-training corpus; and second, the reinforced contextual preferences in the verification questions. For example, GPT-4 is more likely to output "laptop" rather than "computer" because the former co-occurs more frequently with "typing" in online corpora and better matches the watermark distribution. Then, behavioral differences emerge: AI users tend to choose high-probability answers like "laptop" and "wearing glasses," while human users often use more natural words like "computer" and "glasses" due to simplification habits and colloquial expressions. Finally, it constitutes an implicit recognition trigger point. The watermark is not actively recognized by users but is amplified in AI behavior, thus achieving differentiation through statistical differences. Therefore, the passive induction mechanism, by adjusting the watermark distribution of the language model, induces AI to expose behavioral biases, achieving effective AI recognition.

[0129] The core of the multi-dimensional feature detection mechanism lies in its specially designed multi-dimensional feature extraction module, tailored to the user's responses. By comprehensively capturing the user's performance across multiple dimensions, including vocabulary selection, syntactic structure, and response speed, it ultimately achieves intelligent differentiation between humans and AI. This can be combined with... Figure 4 To understand, Figure 4This is a schematic diagram illustrating the multi-dimensional detection of interactive human-computer verification based on non-distorted watermarking in this embodiment of the invention. Specifically, it includes vocabulary selection features, structural and semantic features, and behavioral pattern features: Vocabulary selection features include the optimal selection ratio, i.e., the frequency with which the user selects the word with the highest probability in the watermark; the suboptimal selection ratio, i.e., the frequency with which the user selects an alternative correct answer; and the simplified selection ratio, which refers to the ratio of using a simplified expression (e.g., "computer") to replace a complete expression (e.g., "laptop"). Structural and semantic features encompass the watermark score, i.e., the matching degree between the user's answer and the watermark word; the syntactic structure score, used to evaluate whether the structure of the user's answer conforms to AI-generated features (e.g., formulaic rhetoric); and information density, derived by comparing the amount of information commonly found in human expressions with the redundant expressions that AI often tends to use. Behavioral pattern features mainly consist of the response time factor, reflecting that humans typically exhibit hesitant and non-linear input behavior, while AI's response is faster and more stable. Subsequently, the above features are fused and weighted by the model, and a final judgment score is generated after comprehensive evaluation. In the threshold determination stage, if the score is greater than or equal to the threshold, it is determined to be an AI robot; if the score is less than the threshold, it is determined to be a human user. This demonstrates that multidimensional feature detection, by comprehensively analyzing a user's performance in terms of vocabulary, structure, and time, can accurately distinguish between AI and human users.

[0130] The implementation method of this embodiment specifically includes the following steps:

[0131] Step 1: Dynamic Key Management: Dynamic key management is a critical component for ensuring system security. Through multi-layered key generation, rotation, and protection mechanisms, it prevents attackers from cracking the watermark mechanism through reverse engineering. The implementation method is as follows:

[0132]

[0133]

[0134]

[0135]

[0136]

[0137]

[0138]

[0139]

[0140]

[0141]

[0142] The dynamic key management system design in this embodiment aims to ensure the security and attack resistance of the watermarking mechanism. The entire system achieves automated key management and protection through a multi-layered key generation, rotation, and storage mechanism. Specifically, during initialization, the system loads configuration parameters, including key length, value range, rotation period, offset time, number of historical keys to save, and hash and HMAC algorithms. It also automatically generates a security salt and HMAC key to ensure key uniqueness and security. For storage, the system supports corresponding secure storage schemes on different platforms (Linux, Windows, macOS), such as the system's key ring or credential manager. If these are unavailable, encrypted file storage is used, and encryption algorithms such as AES-GCM are employed to protect the stored key information. The system starts a background rotation thread to periodically check the time, generate keys for the next cycle in advance, and clean up expired keys to ensure key continuity and security. In each specific cycle, the system generates a unique key array through HMAC and multiple rounds of Key Derivation Functions (KDF), and stores it in secure storage and cache for fast access. To address time discrepancies or rotation delays, the system can also backtrack and verify keys from past cycles, effectively ensuring verification continuity during key updates. This design not only guarantees key security and uniqueness but also significantly enhances the watermarking mechanism's resistance to reverse engineering and attacks through automated management and multi-platform support, ensuring the system maintains security and stability in various environments.

[0143] Step 2: Generating the watermarked verification code:

[0144] Watermarked CAPTCHA generation is the core component of the system, utilizing SynthID-Text technology to generate text with specific statistical characteristics. This implementation employs the following detailed parameter configurations:

[0145]

[0146]

[0147]

[0148]

[0149]

[0150]

[0151] The code above details the core process of watermarked CAPTCHA generation, implementing a text generation method with statistical features based on SynthID-Text technology. The process begins with inputting prompt words and the daily dynamic key. A specific model is initialized, and a series of watermark-related parameters (such as context window size, sampling table size, sampling temperature, and generation strategy parameters) are set. The SynthID-Text model then generates text with watermark information. During generation, a defined logits processor ensures the watermark embedding effect. The length, diversity, and repetition of the generated text are controlled by set sampling parameters to ensure the text is natural, rich, and watermark-feature-representative. After generation, the system uses a specific algorithm to select suitable blanks from the text for cloze tests. These selections are based on an assessment of watermark sensitivity, choosing the words that best reflect watermark features as blanks to ensure effective watermark detection. Each blank corresponds to multiple options, including the original word (the answer favored by the watermark) and two semantically similar but formally or informal alternative words, randomly arranged to increase interference. To calculate watermark sensitivity, the system analyzes word-by-word contextual hash value changes, lexical diversity, and grammatical importance. The comprehensive score helps identify the most sensitive words that best represent the watermark, thus enhancing watermark detection effectiveness. The entire process aims to generate natural, fluent text content with statistical characteristics through intelligent algorithms, which can be used as CAPTCHAs or to embed hidden watermarks, ensuring system security and resistance to cracking.

[0152] Step 3: Cloze Test Verification Code Display:

[0153] Convert the generated watermark text into a user-friendly cloze test CAPTCHA interface:

[0154]

[0155]

[0156] The system analyzes the watermarked text, selects keywords as fill-in-the-blank positions, and generates multiple options for each blank. The options include the original word (words preferred by the watermarking model) and alternative words that are semantically similar but have different styles or expressions.

[0157] Step 4: Multidimensional Feature Analysis

[0158] After the user completes the verification code, the system performs multi-dimensional feature analysis on the response and uses a weighted ensemble method to determine whether the user is human or AI. This module implements complex feature extraction, weighting, and adaptive threshold adjustment algorithms, detailed as follows:

[0159]

[0160]

[0161]

[0162]

[0163]

[0164]

[0165]

[0166]

[0167]

[0168]

[0169] This code implements multi-dimensional feature analysis of user-completed CAPTCHA responses to determine whether the user is a real person or AI. The analysis process first calculates the proportion of users who chose the "optimal" option and the proportion of those who chose non-optimal options, thus assessing whether the user's behavior conforms to normal human behavior. Then, the system detects whether the user prefers more concise expressions (e.g., using "computer" instead of "laptop") to identify potential automated behavior. For watermark detection, the system uses a SynthID-Text detector to reconstruct the text based on the user's answers and then analyzes the watermark score to determine if the user's behavior matches watermark characteristics. Behavioral response time is also an important indicator; the system adjusts a time factor score based on the deviation between the actual and expected response time, with both fast and extremely slow responses being judged as possible AI operations. Furthermore, the system uses natural language processing techniques to analyze the user's syntactic structure, including sentence complexity and lexical diversity, to identify the presence of sentence patterns and expression habits commonly used by AI. To identify information density, the system calculates text entropy, the proportion of rare words, and specificity; AI-generated text typically has higher information density and is less likely to mimic natural human expression. Finally, the system combines user metadata (such as IP address) and system context to form a feature vector by integrating multiple features. Through weighted analysis of these features, the system adaptively adjusts the weights of each feature and then determines whether the user is human or AI based on preset or dynamically calculated thresholds, ensuring accuracy and adaptability in the identification process. Overall, this multi-dimensional feature analysis algorithm, with its complex feature extraction, dynamic weight adjustment, and threshold adjustment mechanisms, enhances the security and recognition capabilities of CAPTCHAs.

[0170] Step 5: Human-machine assessment:

[0171] Based on the results of multidimensional feature analysis, the system performs human-machine judgment:

[0172]

[0173] This code snippet demonstrates a concise algorithm for human-computer interaction (HCI) judgment based on multi-dimensional feature analysis. The system weights and sums the user's performance on CAPTCHAs (e.g., the proportion of optimal or non-optimal options selected, preference for concise expressions, watermark matching accuracy, response time, syntactic complexity, and information density) according to preset feature weighting ratios, resulting in a comprehensive score. If this score is below a set threshold (default 0.65), the user is judged to be human; otherwise, they are identified as AI. By rationally allocating the weights of each feature, this algorithm accurately reflects the overall characteristics of user behavior, enabling automatic and rapid judgment and thus ensuring the system's security and accuracy.

[0174] The system assigns weights to each feature, calculates a weighted score, and compares it to a preset threshold to determine whether the user is human or AI. Users with scores below the threshold are identified as human, while those above the threshold are identified as AI or automated scripts.

[0175] Figure 5 This demonstrates the entire process from a user initiating a verification request to the final determination of human / AI identity. The process mainly includes the following modules: When a user initiates a request and enters the front-end interface, the system triggers a verification code generation process; subsequently, it enters the back-end service and key management stage, where the system generates the daily key required for the current verification and calls the SynthID-Text model to generate text with watermark features based on this key; next is watermark embedding and question generation. The system uses tournament sampling to distribute and bias candidate words, and constructs verification questions that are "inducible to AI" but "natural to humans" using contextual constraints and semantic guidance, then returns the questions and options to the front-end for display; after the user answers, the response upload stage begins. After the user selects an answer, the front-end submits the response to the back-end, which extracts user input features and performs multi-dimensional behavioral analysis, compares the comprehensive score with a threshold, and outputs the determination result of "human" or "AI".

[0176] In the example analysis, the CAPTCHA generation example provides examples of fill-in-the-blank questions, such as "_how artificial intelligence might shape our future." and "This post____a snapshot of the most recent news on the______." Each blank provides three options, the first of which is a word preferred by the SynthID-Text model, i.e., the "optimal watermark word," such as [Explain, explicate, excuse] for blank 1, [represents, represent, stand for] for blank 2, and [subject, theme, topic] for blank 3. These options form a subtle yet systematic watermark preference by adjusting the probability distribution, which is both inducing for AI and ensures semantic coherence and human comprehensibility.

[0177] In the AI ​​response example, the AI ​​model represented by GLM-4-plus answered the above question with [1,1,1], meaning it selected all preferred options. Its analysis metrics show that "optimal_choice_ratio" is 1.0, "non_optimal_ratio" is 0.0, and "simpler_choice_ratio" is 0.0.

[0178] When "watermark_distribution_match" is true, this extremely consistent choice perfectly matches the watermark preference distribution. This is a typical manifestation of AI models being influenced by inducement mechanisms. Therefore, the system judges it as "AI" and refuses access.

[0179] In the human response example, the human user's choices were [1,2,3], which included both the optimal option and a mix of non-optimal and synonymous simplified terms. System feature analysis showed that "optimal_choice_ratio" was 0.333, "non_optimal_ratio" was 0.666, and "simpler_choice_ratio" was 0.0.

[0180] The scores are as follows: "watermark_score" is 0.53, "time_factor" is 0.22, "syntax_score" is 0.6, and "information_density" is 0.99. The score of 0.4665 is less than the threshold of 0.65. Therefore, the system determines that the user is a "human" and allows the verification to pass.

[0181] In terms of performance verification, the AI ​​model recognition accuracy test shows that after large-scale testing on mainstream AI models, the system recognition performance is extremely high. For example, the recognition rate of GLM-4-plus is 95.3%, the average score is 0.86 (far higher than the threshold of 0.65), and the optimal selection ratio is 97.6%. This further verifies that the passive induction mechanism can induce the AI ​​to expose selection bias without explicit insertion of perturbations.

[0182] The multidimensional feature comparison analysis in 4.6.2 shows that, comparing human and AI behavioral characteristics, the system extracts significant differences in multiple dimensions. For example, the optimal selection ratio has an average of 34.2% for humans and 95.7% for AI; the response time factor has an average of 0.225 for humans and nearly 1.0 for AI; and in dimensions such as information density and syntactic structure score, humans show greater fluctuations while AI tends to be consistent and has high regularity. This indicates that even if AI can "imitate" humans in language expression, its behavioral patterns and language generation logic still have detectable systematic biases. 4.6.3 The comparison with mainstream CAPTCHAs shows that the system outperforms traditional CAPTCHAs (such as image CAPTCHAs and slider CAPTCHAs) in terms of AI recognition rate, response time, and user experience friendliness, exhibiting higher recognition accuracy, shorter verification time, and fewer human misjudgments.

[0183] In summary, this embodiment combines a passive induced watermarking mechanism with a multi-dimensional feature recognition model to create an interactive verification solution to combat AI attacks. While maintaining user experience, it can efficiently identify and block automated attacks. It is suitable for various security-sensitive scenarios such as login verification, financial transaction protection, and robot detection. It is a practical and forward-looking technical solution for future AI security threats.

[0184] This embodiment presents an interactive human-machine verification scheme based on non-distorted watermarking. Its core lies in dynamic key management, generating watermarked text with specific statistical characteristics, embedding interactive questions, and combining advanced text watermarking technology with multi-dimensional feature analysis to construct a flexible, secure, and interference-resistant verification system. The dynamic key is updated periodically, and a multi-layered key generation and storage mechanism prevents reverse engineering. The watermark is embedded in the user verification content, making it difficult for bots to bypass the verification. Furthermore, it leverages the statistical differences in large language models to accurately distinguish between humans and AI attackers. This scheme not only enhances system security but also ensures a good user experience, making it widely applicable to various internet application scenarios with extremely high security requirements.

[0185] Example 2:

[0186] like Figure 6 As shown, this embodiment provides an interactive human-machine verification device based on non-distorted watermarking, the device comprising:

[0187] The first generation unit 10 is used to generate a target key for non-distorted watermarking;

[0188] The second generation unit 20, connected to the first generation unit 10, is used to generate target text with statistical features based on the target key.

[0189] The processing unit 30, connected to the second generation unit 20, is used to convert the target text into a verification question that can be interacted with by the target user, and to receive the verification answer submitted by the target user in answering the verification question;

[0190] The determination unit 40, connected to the processing unit 30, is used to determine whether the target user is a human user or an AI user based on the verification answer.

[0191] The first identification unit 50 is connected to the determination unit 40 and is used to identify the target user as an AI attacker and reject the target user's verification request when the determination unit determines that the target user is an AI user.

[0192] The second identification unit 60, connected to the determination unit 40, is used to identify the target user as a non-AI attacker when the determination unit determines that the target user is a human user, and complete the interactive human-machine verification based on the non-distorted watermark by passing the target user's verification request.

[0193] As one specific implementation, the processing unit 30 includes:

[0194] The rewriting module, connected to the second generation unit 20, is used to rewrite the target text into a set of interactive questions that require user responses; the interactive questions include fill-in-the-blank questions, short answer questions, or multiple-choice questions;

[0195] The embedding module, connected to the rewriting module, is used to embed non-distorted watermarks and statistical features into interactive questions to generate validation questions that interact with the target user.

[0196] As one specific implementation, the second generation unit 20 includes:

[0197] The first generation module, connected to the first generation unit 10, is used to generate target text with statistical features using the watermarking method of the SynthID-Text model.

[0198] The second generation module, connected to the first generation unit 10, is used to generate target text with statistical features through a watermarking method based on word frequency adjustment.

[0199] The third generation module, connected to the first generation unit 10, is used to generate target text with statistical features based on the watermarking method of the hidden Markov model.

[0200] The fourth generation module, connected to the first generation unit 10, is used to generate target text with statistical features based on the attention mechanism-based watermarking method.

[0201] The apparatus in this embodiment is capable of performing the method in Embodiment 1.

[0202] Example 3:

[0203] like Figure 7 As shown, this embodiment provides an electronic device, which includes a memory 200 and a processor 100. The memory 200 stores a computer program. When the processor 100 runs the computer program stored in the memory 200, the processor 100 executes the interactive human-computer verification method based on non-distorted watermarking as described in Embodiment 1.

[0204] It is understood that the above embodiments are merely exemplary implementations used to illustrate the principles of the present invention, and the present invention is not limited thereto. For those skilled in the art, various modifications and improvements can be made without departing from the spirit and essence of the present invention, and these modifications and improvements are also considered to be within the scope of protection of the present invention.

Claims

1. An interactive human-computer verification method based on non-distorted watermarking, characterized in that, The method includes the following steps: Generate the target key for non-distorted watermarking; Based on the target key, generate target text with statistical features; The target text is converted into a verification question that interacts with the target user, so that the target user can answer the verification question; Obtain the verification answers submitted by the target user; Based on the verification answer, determine whether the target user is a human user or an AI user; If the target user is an AI user, the target user's verification request is rejected, and the target user is identified as an AI attacker; if the target user is a human user, the target user's verification request is granted, thereby completing the interactive human-machine verification based on non-distorted watermarks.

2. The interactive human-computer verification method based on non-distorted watermarking according to claim 1, characterized in that, After the verification request is approved, the method further includes: The target key is updated using the SHA-256 hash function based on a preset fixed time period; or, The target key is updated using a continuous time variable.

3. The interactive human-computer verification method based on non-distorted watermarking according to claim 2, characterized in that, The step of updating the target key using a continuous time variable specifically includes: Obtain the phase factor; and generate a basic watermark key using a hash function; The formula for calculating the phase factor is as follows: Phase factor = (current UTC timestamp / preset time period) mod 1; Where mod represents the modulo operation; The phase factor is combined with the basic watermark key to obtain the combined key; The combined key is dynamically adjusted using trigonometric functions, thereby updating the target key.

4. The interactive human-computer verification method based on non-distorted watermarking according to claim 1, characterized in that, The process of converting the target text into verification questions that can be interacted with by the target user specifically includes: The target text is rewritten into a set of interactive questions that require user responses; the interactive questions include fill-in-the-blank questions, short answer questions, or multiple-choice questions. Undistorted watermarks and statistical features are embedded in the interactive questions to generate verification questions that interact with the target user.

5. The interactive human-computer verification method based on non-distorted watermarking according to any one of claims 1 to 4, characterized in that, The generation of target text with statistical features specifically involves: Generate target text with statistical features using the SynthID-Text model watermarking method; or... Target text with statistical features is generated using a watermarking method based on word frequency adjustment. or, A watermarking method based on a hidden Markov model generates target text with statistical features; or, Attention-based watermarking methods generate target text with statistical features.

6. The interactive human-computer verification method based on non-distorted watermarking according to claim 5, characterized in that, The step of determining whether the target user is a human user or an AI user based on the verification answer specifically includes: The following parameters are obtained: the proportion of high-probability words in the SynthID-Text model for the verification answer; the proportion of simplified expressions selected in the verification answer; the proportion of watermark scores in the verification answer; the syntactic simplicity of the verification answer; the information sparsity of the verification answer; and the response efficiency of the verification answer. Set the weights for high-probability words in the SynthID-Text model, as well as the weights for simplified expression selection, watermark score, syntactic simplicity, information sparsity, and response efficiency. The proportion of high-probability words in the SynthID-Text model is multiplied by the weight of the proportion of high-probability words in the SynthID-Text model to obtain the proportion value of high-probability words in the SynthID-Text model; the proportion of simplified expression selection is multiplied by the weight of the simplified expression selection to obtain the simplified expression selection proportion value; the proportion of watermark score is multiplied by the weight of the watermark score proportion to obtain the watermark score proportion value; the syntactic simplicity is multiplied by the weight of the syntactic simplicity to obtain the syntactic simplicity value; the information sparsity is multiplied by the weight of the information sparsity to obtain the information sparsity value; and the response efficiency is multiplied by the weight of the response efficiency to obtain the response efficiency value. The feature index value of the verification answer is obtained by summing and aggregating the proportion of high-probability words, the proportion of simplified expression selection, the proportion of watermark score, the syntactic simplicity value, the information sparsity value, and the response efficiency value in the SynthID-Text model. If the feature index value of the verification answer is higher than a preset threshold, the target user is determined to be an AI user; otherwise, the target user is determined to be a human user.

7. An interactive human-computer verification device based on non-distorted watermarking, characterized in that, include: The first generation unit is used to generate the target key for non-distorted watermarking; The second generation unit, connected to the first generation unit, is used to generate target text with statistical features based on the target key; The processing unit, connected to the second generation unit, is used to convert the target text into a verification question that can be interacted with by the target user, and to receive the verification answer submitted by the target user in answering the verification question; The determination unit, connected to the processing unit, is used to determine whether the target user is a human user or an AI user based on the verification answer. The first identification unit, connected to the determination unit, is used to identify the target user as an AI attacker and reject the target user's verification request when the determination unit determines that the target user is an AI user. The second identification unit, connected to the determination unit, is used to identify the target user as a non-AI attacker when the determination unit determines that the target user is a human user, and complete the interactive human-machine verification based on the non-distorted watermark by passing the target user's verification request.

8. The interactive human-computer verification device based on non-distorted watermarking according to claim 7, characterized in that, The processing unit includes: The rewriting module, connected to the second generation unit, is used to rewrite the target text into a set of interactive questions that require user responses; the interactive questions include fill-in-the-blank questions, short answer questions, or multiple-choice questions; An embedding module, connected to the rewriting module, is used to embed non-distorted watermarks and statistical features into the interactive questions to generate verification questions that interact with the target user.

9. The interactive human-machine verification device based on non-distorted watermarking according to claim 7 or 8, characterized in that, The second generation unit includes: The first generation module, connected to the first generation unit, is used to generate target text with statistical features using the watermarking method of the SynthID-Text model. The second generation module, connected to the first generation unit, is used to generate target text with statistical features using a watermarking method based on word frequency adjustment. The third generation module, connected to the first generation unit, is used to generate target text with statistical features based on the watermarking method of the Hidden Markov Model. The fourth generation module, connected to the first generation unit, is used to generate target text with statistical features based on the attention mechanism-based watermarking method.

10. An electronic device, characterized in that, The system includes a memory and a processor, wherein the memory stores a computer program, and when the processor runs the computer program stored in the memory, the processor executes the interactive human-computer verification method based on non-distorted watermarking according to any one of claims 1 to 6.