Machine Learning Model Shift for Proactive CAPTCHA Defense

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Malicious entities exploit machine learning classifiers to bypass CAPTCHA systems, circumventing security measures by using VPNs to change IP addresses and evade blacklists.

Innovation Solution

A data processor induces model shift in malicious machine learning models by generating and providing transition data to cause a change in the boundary function over time, disrupting the classifier's ability to accurately differentiate between classes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If blacklists are used to block malicious computers, then security is improved, but malicious entities can circumvent by using VPNs to change IP addresses

Engineering Contradiction:
ImprovesecurityVSAvoidcircumvention capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system performs preliminary actions by proactively inducing model shifts in malicious machine learning models before they can successfully bypass security measures. Transition data is fed into the malicious model to preemptively change its classification boundary function, rendering it ineffective for CAPTCHA bypass attempts before they occur.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system converts the harmful capability of machine learning models into a beneficial defense mechanism. By exploiting the model's ability to learn from data, the system feeds it transition data that causes the model to shift its decision boundary, thereby turning the model's learning capability against the malicious entity's intent.

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

2Ease of operation

If machine learning models are used to bypass CAPTCHA, then unauthorized access is achieved, but the model's classification accuracy deteriorates when faced with transition data

Engineering Contradiction:
ImproveCAPTCHA bypass capabilityVSAvoidclassification accuracy
Core Design Contradiction:
Ease of operationVSMeasurement precision

Solution Approach 1:

The system changes the parameters of the machine learning model by inducing model shifts through transition data. The boundary function of the model is deliberately modified over time, causing it to misclassify inputs that were previously correctly identified, thereby degrading its CAPTCHA bypass capability.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The system introduces dynamics into the defense by continuously adapting the model's behavior through repeated provision of transition data. The boundary function is not static but evolves over time in response to the fed data, making the malicious model increasingly unreliable for its intended purpose.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS12361281B2Proactive defense of untrustworthy machine learning system
Publication Date: 2025.07.15 VISA INTERNATIONAL SERVICE ASSOCIATION
  • US12361281B2 patent drawing
  • US12361281B2 patent drawing
  • US12361281B2 patent drawing

AI summary

Methods and systems for inducing model shift in a malicious computer's machine learning model is disclosed. A data processor can determine that a malicious computer uses a machine learning model with a boundary function to determine outcomes. The data processor can then generate transition data intended to shift the boundary function and then provide the transition data to the malicious computer. The data processor can repeat generating and providing the transition data, thereby causing the boundary function to shift over time.