Anyone who has been surfing the web for a while is probably used to clicking through a CAPTCHA grid of street images, identifying everyday objects to prove that they’re a human and not an automated bot. Now, though, new research claims that locally run bots using specially trained image-recognition models can match human-level performance in this style of CAPTCHA, achieving a 100 percent success rate despite being decidedly not human.

ETH Zurich PhD student Andreas Plesner and his colleagues’ new research, available as a pre-print paper, focuses on Google’s ReCAPTCHA v2, which challenges users to identify which street images in a grid contain items like bicycles, crosswalks, mountains, stairs, or traffic lights. Google began phasing that system out years ago in favor of an “invisible” reCAPTCHA v3 that analyzes user interactions rather than offering an explicit challenge.

Despite this, the older reCAPTCHA v2 is still used by millions of websites. And even sites that use the updated reCAPTCHA v3 will sometimes use reCAPTCHA v2 as a fallback when the updated system gives a user a low “human” confidence rating.

  • mosiacmango@lemm.ee
    link
    fedilink
    English
    arrow-up
    71
    arrow-down
    4
    ·
    edit-2
    3 months ago

    This is actually a good sign for self driving. Google was using this data as a training set for Waymo. If AI is accurately identifying vehicles and traffic markings, it should be able to process interactions with them easier.

    • iAmTheTot@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      45
      ·
      3 months ago

      As I understand it, the point of those captchas was never really “bots can’t identify these things” (though you’re right on that it was used to train). They use cursor movement, clicks, and other behaviours while you’re solving it to detect if you are a bot or not.

      • Takumidesh@lemmy.world
        link
        fedilink
        English
        arrow-up
        9
        ·
        edit-2
        3 months ago

        It’s a combination.

        Most captchas goals generally aren’t 100% prevention, it’s to put a workload in front, this makes spamming the site cost money, a bankrolled attempt could just as easily outsource the captchas to real humans.

      • Mushroomm@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        6
        ·
        3 months ago

        Since I started getting good at yosu and that fishing mini game in farmrpg I’ve been failing more captchas. I wonder if they’re related knowing this

    • grue@lemmy.world
      link
      fedilink
      English
      arrow-up
      22
      arrow-down
      1
      ·
      3 months ago

      The annoying thing is that they held us hostage for our free labor, but the results are proprietary for Google’s benefit only.

      That training data ought to be forced to be made freely available to the public, since we’re the ones who actually created it.

    • crusa187@lemmy.ml
      link
      fedilink
      English
      arrow-up
      4
      arrow-down
      1
      ·
      3 months ago

      Afaik this is precisely what the captcha data was intended for - training AI models. Originally leveraged machine learning. LLMs are a slightly different paradigm but same purpose and results here.

      • mosiacmango@lemm.ee
        link
        fedilink
        English
        arrow-up
        9
        ·
        edit-2
        3 months ago

        Its never been confirmed by Google, so I may be wrong. It still tracks that the data harvesting company with a AI self driving car project would use free human labor to identify road hazards.

        • Arthur Besse@lemmy.ml
          link
          fedilink
          English
          arrow-up
          3
          arrow-down
          9
          ·
          edit-2
          3 months ago

          I was referring to the “This is actually a good sign for self driving” part of their comment.

          The captcha circumvention arms race has been going on for over two decades, and every new type of captcha has and will continue to be broken as soon as it’s widely deployed enough that someone is motivated to spend the time to.

          So, the notion that an academic paper about breaking the current generation of traffic-related captchas (something which the captcha solving industry has been doing for years with a pretty high success rate already) is “good news” for the autonomous vehicle industry (who has also been able to identify such objects well enough to continue existing and getting more regulatory approval for years now) is…

          fry not sure meme template, no text

          • mosiacmango@lemm.ee
            link
            fedilink
            English
            arrow-up
            10
            ·
            edit-2
            3 months ago

            Not really. I’m not even sure what you’re disagreeing with based on the above comment.

            My point is that if bog standard AI can accurately identify all of the road information from pictures, that is good news for self driving.

            What was once a nearly impossible task for computers is now mundane, and can be used to improve safety/utility for self driving, especially for FOSS projects like comma.ai

  • communism@lemmy.ml
    link
    fedilink
    English
    arrow-up
    49
    ·
    3 months ago

    And yet I can’t beat the CAPTCHAs because reCAPTCHA doesn’t like VPNs lol

    • Draconic NEO@lemmy.world
      link
      fedilink
      English
      arrow-up
      13
      ·
      3 months ago

      Captcha these days isn’t even really a CAPTCHA in the traditional sense since most of the work it does is based on filtering of IP and browser fingerprinting, with a certain level of gamification because the goal is not just to keep out the people they fight against, but to waste their time, would work great if it didn’t waste normal people’s time, while real bad actors have easy ways to get around it.

    • unconsciousvoidling@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      8
      ·
      3 months ago

      I was going to say I’ve straight up just left whatever website I was trying to access because I was stuck in some endless loop of clicking on street crossings, buses, bikes, and street lights.

    • SSJMarx@lemm.ee
      link
      fedilink
      English
      arrow-up
      2
      ·
      2 months ago

      The capchas getting really bad on Mullvad almost made me give up on using a VPN. But then I learned about Buster.

      This is my third post in a row shilling for this browser extension lol, it’s so good.

  • pixxelkick@lemmy.world
    link
    fedilink
    English
    arrow-up
    35
    arrow-down
    2
    ·
    3 months ago

    Well yeah, I’d hope so, that’s the entire point.

    Catcha’s data collection always was with the intent for training ai on these skills. That’s “the point” of them.

    It’s reasonable to expect that the older version of captchas can now be beaten by modern ai, because they’re often literally trained on that exact data to beat it.

    Captcha effectively is free to use on websites as a tool because the data collection is the “payment”, they then license that data out to people like OpenAI to train with for stuff like image recognition.

    It’s why ai is progressing so fast, captchas are one of humanity’s long term collected data silos that are very full now.

    We are going to have to keep progressing the complexity of catches as it will be the only way to catch modern AIs, and in turn it will collect more data to improve it.

    • MIDItheKID@lemmy.world
      link
      fedilink
      English
      arrow-up
      8
      ·
      3 months ago

      Yeah, my understanding is that these capchas were made to harvest data to use for AI/Autopilot driven cars. That’s why they are always having you identify motorcycles, bycicles, crosswalks, stoplights, busses, etc. It’s all stuff that automatic driving cars have had a hard time identifying.

    • UltraGiGaGigantic@lemmy.ml
      link
      fedilink
      English
      arrow-up
      3
      arrow-down
      1
      ·
      edit-2
      3 months ago

      We are going to have to keep progressing the complexity of catches as it will be the only way to catch modern AIs, and in turn it will collect more data to improve it.

      I wanted to use 4chan alot before I came here, but FUCK that slider capcha. I bailed after the first time I didn’t pass.

      • Riccosuave@lemmy.world
        link
        fedilink
        English
        arrow-up
        6
        ·
        3 months ago

        I wanted to use 4chan

        I am relatively confident that you are one of the first people to ever type that sentence out.

    • pyre@lemmy.world
      link
      fedilink
      English
      arrow-up
      16
      ·
      3 months ago

      it’s super ableist. if someone has poor vision or colorblindness chances are they’re going to miss things.

      • Dozzi92@lemmy.world
        link
        fedilink
        English
        arrow-up
        17
        ·
        3 months ago

        I have regular everything and I still fuck them up. “click the ones with a fire hydrant”. But a tiny piece of fire hydrant is spilling into another box. Does it count? Does it not count? Good luck!!

        I had one the other day that was deep fried jpegs to the max. Like, what the fuck am I supposed to do.

        • scottywh@lemmy.world
          link
          fedilink
          English
          arrow-up
          1
          ·
          2 months ago

          Spillovers into other boxes definitely count…

          I don’t want to do this next part but I can’t resist…

          Just ask my girlfriend…

          Ba dum tiss

    • SSJMarx@lemm.ee
      link
      fedilink
      English
      arrow-up
      4
      ·
      2 months ago

      Same. That’s why Buster is my most recent must-have browser extension, alongside such greats as ublock and sponsorblock.

  • GoofSchmoofer@lemmy.world
    link
    fedilink
    English
    arrow-up
    13
    arrow-down
    1
    ·
    3 months ago

    I can see a future where the Internet is completely run by bots and AI to the point where no human actually uses the Internet anymore.

    It’s like an island that gets overrun with rats - there are just too many to deal with so you leave.

    • SynopsisTantilize@lemm.ee
      link
      fedilink
      English
      arrow-up
      5
      ·
      3 months ago

      I’m already doing that now. If Lemmy starts showing signs of fuckery I’m out. I’ll switch back to magazines.

      • nexusband@lemmy.world
        link
        fedilink
        English
        arrow-up
        2
        ·
        3 months ago

        I already did… There’s some subscription stuff where you can read pretty much all available magazines and papers, it’s been a long time since I’ve been reading that much “news” and reports

    • yamanii@lemmy.world
      link
      fedilink
      English
      arrow-up
      2
      ·
      2 months ago

      Basically Cyberpunk, people only interact with the night city intranet because the global internet has been taken over by AIs.

    • nikaaa@lemmy.world
      link
      fedilink
      English
      arrow-up
      2
      ·
      2 months ago

      Yeah, I predict that in the future, you can’t expect that content on the internet is written by humans. If you go to the internet, then it will probably not be to connect to other humans. Maybe you want to know something that a bot can tell you or you have some administrative task to fulfill, like filing a form.

  • Yer Ma@lemm.ee
    link
    fedilink
    English
    arrow-up
    11
    ·
    3 months ago

    But, I cannot pass those 50% of the time… what does that mean?

  • TommySoda@lemmy.world
    link
    fedilink
    English
    arrow-up
    9
    ·
    3 months ago

    I mean, we literally train them by completing the CAPTCHAs. Why do you think you were picking things like bikes, traffic lights, cars, and busses? The only question now is what’s next…

  • blattrules@lemmy.world
    link
    fedilink
    English
    arrow-up
    8
    ·
    3 months ago

    I never get the first one and rarely the second one. If it says to click all the squares with motorcycles and it’s just the one big picture, am I supposed to click stuff like the tire and mirrors? I always do and never get it right. Then most of the time they ask me to identify motorcycles, they show me motor scooters and what am I supposed to do then? I think I just need to get one of these bots to do it for me.

    • CosmicTurtle0@lemmy.dbzer0.com
      link
      fedilink
      English
      arrow-up
      2
      ·
      3 months ago

      Fwiw they aren’t really asking about the motorcycle. I mean they are but they are washing your mouse movements and how fast you click through the images. It’s okay to get a few images wrong.

      • pixxelkick@lemmy.world
        link
        fedilink
        English
        arrow-up
        6
        ·
        3 months ago

        Not quite.

        It’s mostly wisdom of the crowd, as it always has been.

        As long as you mostly click the same squares most other people click, you pass.

        You often at random get 2-3 images because 2 of them are actual checks, but the third is a new image that you auto pass and they’re using it to gather data on what the average clicks are on it.

      • y0kai@lemmy.dbzer0.com
        link
        fedilink
        English
        arrow-up
        1
        ·
        3 months ago

        Not everywhere.

        Where I am, you need a special license to drive a motorcycle, classified as having an engine of 51ccs or more, whereas a scooter is any motorcycle with a less than 51ccs and doesn’t require a special license.

          • y0kai@lemmy.dbzer0.com
            link
            fedilink
            English
            arrow-up
            1
            arrow-down
            1
            ·
            2 months ago

            Mopeds are similar but have pedals and can be used as a bicycle. The name itself, Mo-Ped" is a portmanteau for motor and pedal.

            Motor scooters are different in that they have a cut out for the rider’s legs/ feet so they don’t have to straddle it the same way they would with a motorcycle. Both mopeds and motor scooters do not require a license endorsement here, while motorcycles, as defined in my original comment, do.

              • y0kai@lemmy.dbzer0.com
                link
                fedilink
                English
                arrow-up
                1
                arrow-down
                1
                ·
                2 months ago

                So a moped with a 49cc engine, astep-through design, and no pedals is a moped but a scooter with a step-through design and 49cc engine is a motorcycle?

                That’s confusing as fuck lol

                • Ilovethebomb@lemm.ee
                  link
                  fedilink
                  English
                  arrow-up
                  1
                  ·
                  2 months ago

                  Not really, both your examples are a moped. The definition of a moped in most places has nothing to do with the style of bike.

  • Draconic NEO@lemmy.world
    link
    fedilink
    English
    arrow-up
    8
    arrow-down
    1
    ·
    edit-2
    2 months ago

    CAPTCHA doesn’t stop bots, and let us be honest, it never really did. It frustrated the hell out of people though, and caused people to waste time doing these challenges. Meanwhile even before AI bad actors and bots could get past it simply by using captcha solver services run by exploited humans solving captchas for the service.

    It’s a display of security theater meant to make normies feel safe but in reality doesn’t stop most bad actors.

  • finitebanjo@lemmy.world
    link
    fedilink
    English
    arrow-up
    7
    ·
    2 months ago

    Technically the “correct” answer is set by the highest percentage of people choosing it. EG: 19 people select Box A and 1 selects Box B, then the machine decides Box A is in fact correct.

    That means these AI could be selecting the wrong answers for all anybody knows, if enough of them are answering the prompts, and still passing.

    • systemglitch@lemmy.world
      link
      fedilink
      English
      arrow-up
      3
      arrow-down
      1
      ·
      3 months ago

      In use an add-on that does 90% of these for me already on Firefox. I would tell you what it’s called but I’m not at my PC.

      Which (on a side note) I’d totally go downstairs and check for you, but I just sprained my ankle real bad, and am dreading stairs. Sorry :(

      • communism@lemmy.ml
        link
        fedilink
        English
        arrow-up
        3
        ·
        3 months ago

        Sorry to hear about your ankle. When you’re able to, I’d also like to know what the add-on is

    • SynopsisTantilize@lemm.ee
      link
      fedilink
      English
      arrow-up
      1
      ·
      2 months ago

      If I see the newer ones pop up at all I just skip what ever the task is that was requiring me to bother with it.

      • KillingTimeItself@lemmy.dbzer0.com
        link
        fedilink
        English
        arrow-up
        1
        ·
        2 months ago

        i love when websites (twitter is a really bad example) hit me with like 8 captchas, and then if i get my username/password wrong i have to do another 8. It’s just so obviously gaming for training data on shit lmao.