AAMAS Conference 2026 Conference Paper
Cleaner Adversarial CAPTCHAs: Intelligent Targets and Precise Noise for Usable Security
- Meir Litman
- Chen Hajaj
TraditionalCAPTCHAsareincreasinglyvulnerabletodeeplearningbasedsolversthatdecodetextandimageswithhighaccuracy. Inthis work, we propose methods to strengthen adversarial CAPTCHAs without compromising human usability. First, we introduce a Precise Gradient Method (PGM) that preserves gradient magnitude (rather than discarding it via a sign operator), producing adversarial perturbations with significantly lower perceptual noise. Second, we develop intelligent target class selection, using either dataset-level confusion structure (Class Relations Network) or image-specific softmax probabilities (Distance-Based Target), to steer adversarial perturbations more efficiently. Across multiple modern architectures (MobileNets, EfficientNets, ResNet, and Vision Transformer), our framework achieves faster convergence (fewer iterations), reduced visual distortion, and notably greater robustness under iterative adversarial retraining. Experiments show that our methods consistentlyreduceiterationcountsandperceptualdistortionwhile significantly increasing the difficulty for automated attacks. Our results offer a practical, scalable path toward the next generation of CAPTCHA systems and contribute new insights to the adversarial machine learning landscape focused on security and usability.