I’ve used this technique before in a project; to put it simply, it’s quite straightforward: perform data augmentation during testing to enhance the overall system’s robustness.

Additionally, hCAPTCHA’s recent update involves adding noise to images, which is essentially a relatively simple model attack. However, what piques my curiosity is: what is the actual utility of performing a model attack in this specific scenario?

I believe most model attacks and defenses occur in real-world scenarios, since it’s difficult to specifically alter real-world objects. But in this scenario… I simply don’t get it.

I just need to apply a perturbation to the noise you added, or perform a simple denoising operation—just one line of img = cv2.fastNlMeansDenoisingColored(img, None, 10, 10, 7, 21). At the very least, if I add a filter img = cv2.GaussianBlur(img, (5, 5), 0), it seems your noise-adding operation becomes useless.

After all, my model’s input isn’t determined by you, so your attack on my model is nearly 0% effective.

So, I truly don’t understand this noise-adding operation. Is it meant to thwart humans? To make humans’ eyes blur while robots make correct judgments, so that only robots pass and humans fail? That’s just too hilarious 8, haha.

@hCAPTCHA, please come up with more interesting challenges; lately, everything feels boring. Bring on something difficult!

I believe the ultimate form of CAPTCHAs will not be image-based ones, but rather some form of environmental monitoring that makes the CAPTCHA invisible to users. This might be the true future form of CAPTCHAs, just as the ultimate goal of distributed systems is to be invisible.