Dynamic Mutation Bot Detection via Semantic Challenges

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing CAPTCHA and reCAPTCHA systems are vulnerable to machine learning-based malicious systems, which can predict correct answers with high accuracy, leading to ineffective access control and potential automated bot access to secured resources.

Innovation Solution

An automated testing mechanism that uses a combination of natural language understanding, logical reasoning, and common sense reasoning through a backend database of structured data objects with dynamic mutation transformations, generating challenges that are difficult for machine learning models to predict while remaining manageable for human users.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If traditional CAPTCHA or reCAPTCHA systems are used for access control, then the system is easy to implement and understand, but the system becomes vulnerable to machine learning-based malicious systems that can predict correct answers with high accuracy

Engineering Contradiction:
Improveease of implementationVSAvoideffectiveness against bots
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The system dynamically changes the parameters of challenges by introducing mutations to questions, answers, and contextual information. This transforms static CAPTCHA challenges into dynamic ones where the same underlying concept can be presented in infinitely varied forms, preventing machine learning models from memorizing patterns while maintaining human understandability

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The challenge system transitions from static to dynamic by continuously mutating challenge parameters. The system adapts challenges in real-time based on user responses and system state, creating a living defense mechanism that evolves against automated attacks while remaining consistent for human users

Inventive Principle:
Principle #15Dynamics

2Reliability

If the challenge difficulty is increased to counter machine learning attacks, then the effectiveness against bots improves, but the burden on human users increases and may become too difficult

Engineering Contradiction:
Improveeffectiveness against botsVSAvoiduser burden
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system applies partial mutation to challenges - not all parameters are mutated, and mutation intensity is controlled. This creates sufficient complexity to defeat bot detection while maintaining core recognizability for human users, achieving the right balance between security and usability

Inventive Principle:
Principle #16Partial or excessive action

3Measurement precision

If static question/answer pairs are used for training machine learning models, then the models can achieve high prediction accuracy, but the system becomes vulnerable to automated attacks

Engineering Contradiction:
Improveprediction accuracyVSAvoidvulnerability to attacks
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

The system preemptively counters machine learning training by mutating challenges before they can be collected and analyzed. By continuously transforming the challenge space, the system prevents adversaries from gathering sufficient training data to build accurate prediction models, addressing the vulnerability before it can be exploited

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentUS11755749B2System and method for reverse-Turing bot detection
Publication Date: 2023.09.12 ROYAL BANK OF CANADA
  • US11755749B2 patent drawing
  • US11755749B2 patent drawing
  • US11755749B2 patent drawing

AI summary

A system for controlling access to hosted services using computer generated question answer sets is described. The question answer sets are generated and include relationships which are designed to distinguish between human and automated system interpretation through the inclusion of a dynamically established transformation of characteristics in relation to objects described in the question answer sets. The dynamically established transformation provides an additional defense against malicious neural networks used to overcome mechanisms for distinguishing between humans and automated systems. Corresponding methods and devices are contemplated. In an additional embodiment, a decoy set of answer sets are also established to maintain a blacklisted set of suspected automated systems.