Live data from Hacker News

CAPTCHAs can still detect AI agents

research.roundtable.ai

71–76 of 76 posts

Re: CAPTCHAs can still detect AI agents

#71
post #67
post #63

Earlier quoted context omitted.

Exactly, nowadays, the main usage of "capcha" is more about to force down on user the whatng cartel web engines more than anything else. It is like windows kernel anti-cheat which are more to please microsoft at making games not running on linux based OS... and kernel anti-cheat seems to be actively exploited by hackers. Put up a human team tracking the IPs of those bots and work with network operators. The hard part…

Kernel anti-cheat (KMAC) is an effective tool when used effectively and invested in (see Vanguard), but it only works when you are consistent and the team working on it are interested and capable. Creating terrible KMAC happens all the time, and gets treated as a one-and-done thing which will always be defeated. You have to continually watch the cheat market and work actively against it. It works, and Valorant with V…

You are very mistaken: what "works" (see below) here is an invested and permanent team, not a kernel anti-cheat.

Effectiveness, yes, at giving hackers easy kernel an...access.

And trying to spot cheaters using external AI based hardware: you may have a chance with data collection on servers (no need of kernel access).

It is so much obvious, I am even wondering all that is made-up to give easy kernel access to some "services", seriously.

And it seems such games are still rid of cheaters.

Re: CAPTCHAs can still detect AI agents

#72

I actually saw a pretty decent captcha the other day on a Chinese website (I think Taobao? I forget.) anyway the cool thing they did was that the text wasn’t in an image it was a looping video, but the text in any one frame was incomplete (only parts of the Chinese characters). And each frame different parts of the characters were visible, with a lot of noise in other parts of the frame where parts of characters woul…

I wonder if it could be made stronger by having the word move around the captcha...

Like the dvd logo screensaver

Re: CAPTCHAs can still detect AI agents

#73
Thanks all for the discussion! Would like to highlight two parts that maybe didn't come fully through, and we'll work on making this clearer:

1. CAPTCHAs can still detect AI agents...if you know where to look. Most commercial CAPTCHAs are not doing the cognitive process tracing you see in our paper. Nor are they really doing 'behavioral biometrics' (but that is slightly tangential here). Our CAPTCHA example here is about repurposing the current paradigm with a new methodology (cognitive process tracing) in a way that is able to combat human/machine discrimination in a way that's independent on frontier AI progress.

2. There are lots of concerns about adversarial robustness, which are very fair, and we reported some fine-tuning tests in the paper. Generally, there are two mental models for me that work, both framing fraud as an economic game.

First, compare AI spoofability concerns to something like a passport or a fingerprint. The cost to mimic continuous cognitive and behavioral patterns over time seems more computationally complex. In other words, sure this method is not bulletproof with infinite resources, but nothing is. We rely on defeasible mechanisms everyday, and our job is to make that significantly securer.

Along these lines, there's a common line of criticism that suggests once fraudsters know the game, they will solve the game. The CAPTCHA presence in the 2000s didn't mobilize massive deep learning / image recognition advances from the fraud community. Nor are these same bot farms solving quantum computing despite there being immense incentives to. If anything, the real threats are stuff like JavaScript injections, not really fully simulating human cognition

Re: CAPTCHAs can still detect AI agents

#74

Earlier quoted context omitted.

How does this relate to the article? They weren't collecting bits until they identified a specific individual so I feel like I'm missing something.

The appendix lists what they were collecting, and the amount of samples needed for not just mathematically significant, but also practically useful distinguishing power implies collecting enough for a stable yet unique fingerprint. In that case you could just add a login form.. and still be less hostile than the increasing number of websites that will not let me browse (maybe my mouse movement does not match other hu…

> In that case you could just add a login form

This is the product insight. We're not going to deploy Stroop tasks for authentication :)

Re: CAPTCHAs can still detect AI agents

#75
post #71
post #67

Earlier quoted context omitted.

Kernel anti-cheat (KMAC) is an effective tool when used effectively and invested in (see Vanguard), but it only works when you are consistent and the team working on it are interested and capable. Creating terrible KMAC happens all the time, and gets treated as a one-and-done thing which will always be defeated. You have to continually watch the cheat market and work actively against it. It works, and Valorant with V…

You are very mistaken: what "works" (see below) here is an invested and permanent team, not a kernel anti-cheat. Effectiveness, yes, at giving hackers easy kernel an...access. And trying to spot cheaters using external AI based hardware: you may have a chance with data collection on servers (no need of kernel access). It is so much obvious, I am even wondering all that is made-up to give easy kernel access to some "s…

Valorant reports ~1% of games having a cheater. Apex Legends self-reported over 10x that.

Re: CAPTCHAs can still detect AI agents

#76
post #75
post #71

Earlier quoted context omitted.

You are very mistaken: what "works" (see below) here is an invested and permanent team, not a kernel anti-cheat. Effectiveness, yes, at giving hackers easy kernel an...access. And trying to spot cheaters using external AI based hardware: you may have a chance with data collection on servers (no need of kernel access). It is so much obvious, I am even wondering all that is made-up to give easy kernel access to some "s…

Valorant reports ~1% of games having a cheater. Apex Legends self-reported over 10x that.

It is not related to th kernel anti-cheat: it is to have permanet and dedicated team to deal with that.

My english is so bad?

Post reply on HN