Machine Learning Model Shift for Proactive CAPTCHA Defense
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Malicious entities exploit machine learning classifiers to bypass CAPTCHA systems, circumventing security measures by using VPNs to change IP addresses and evade blacklists.
Innovation Solution
A data processor induces model shift in malicious machine learning models by generating and providing transition data to cause a change in the boundary function over time, disrupting the classifier's ability to accurately differentiate between classes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If blacklists are used to block malicious computers, then security is improved, but malicious entities can circumvent by using VPNs to change IP addresses
Solution Approach 1:
The system performs preliminary actions by proactively inducing model shifts in malicious machine learning models before they can successfully bypass security measures. Transition data is fed into the malicious model to preemptively change its classification boundary function, rendering it ineffective for CAPTCHA bypass attempts before they occur.
Solution Approach 2:
The system converts the harmful capability of machine learning models into a beneficial defense mechanism. By exploiting the model's ability to learn from data, the system feeds it transition data that causes the model to shift its decision boundary, thereby turning the model's learning capability against the malicious entity's intent.
2Ease of operation
If machine learning models are used to bypass CAPTCHA, then unauthorized access is achieved, but the model's classification accuracy deteriorates when faced with transition data
Solution Approach 1:
The system changes the parameters of the machine learning model by inducing model shifts through transition data. The boundary function of the model is deliberately modified over time, causing it to misclassify inputs that were previously correctly identified, thereby degrading its CAPTCHA bypass capability.
Solution Approach 2:
The system introduces dynamics into the defense by continuously adapting the model's behavior through repeated provision of transition data. The boundary function is not static but evolves over time in response to the fed data, making the malicious model increasingly unreliable for its intended purpose.
Data Source
AI summary
Methods and systems for inducing model shift in a malicious computer's machine learning model is disclosed. A data processor can determine that a malicious computer uses a machine learning model with a boundary function to determine outcomes. The data processor can then generate transition data intended to shift the boundary function and then provide the transition data to the malicious computer. The data processor can repeat generating and providing the transition data, thereby causing the boundary function to shift over time.


