PoW-GeoCAPTCHA: A novel human-bot verification scheme integrating proof-of-work and geometric recognition
Widely deployed CAPTCHAs face a growing security-usability trade-off, worsened by deep learning bots defeating mainstream methods with high success rates. We propose PoW-GeoCAPTCHA, a two-factor human-bot verification scheme. Departing from conventional circular and elliptical ring-counting designs whose stable curvature and closed contours are increasingly exploitable by deep learning attacks, we propose a triangle-counting geometric CAPTCHA. This geometric primitive resists automated solvers via occlusion-prone contours and unstable global features, and integrates with a lightweight Proof-of-Work (PoW) mechanism. Unlike prior works concatenating independent modules, our design achieves deep synergy via background-transparent PoW execution and request-aware dynamic difficulty linkage. The geometric CAPTCHA resists attacks via randomized triangle overlays and dynamic HSV color modulation creating visually indistinguishable regions, while PoW difficulty adjusts based on request context. In controlled attack experiments, single-challenge success rates reached only 1.00% (contour-based), 22% (CNN), 38.10% (YOLOv8), 40.20% (Faster R-CNN), and 18.00%, 24.70%, and 28.60% against attacks from representative multimodal large language models (MLLMs, vision-augmented LLM variants) Qwen3-VL-Plus, ChatGPT-series gpt-4o-mini, and Google Gemini-series gemini-3.5-flash, respectively, verifying reliable defense against LLM-derived visual cracking. When two consecutive geometric challenges are required, these rates drop exponentially to 0.01%, 4.84%, 14.52%, 16.16%, and to 3.24%, 6.10%, and 8.18% for the three multimodal large-model attacks, respectively. A user study on the dual geometric CAPTCHA (without PoW) showed a 90.20% human pass rate. The full system adds negligible PoW overhead ( < 10 ms) and maintains high usability. This lightweight solution suits login, transaction, and API protection, validated under realistic threat models.
Authors
- Lixin Jiang
- Zhanshan Li (ORCID: https://orcid.org/0000-0003-1648-8138)
- Shuhui Zhang (ORCID: https://orcid.org/0000-0001-5017-3207)
- Lu Wang (ORCID: https://orcid.org/0009-0004-3933-6852)
- Jiayi Chen (ORCID: https://orcid.org/0009-0005-6384-1813)
Institutions
- Jilin University (CN)
Publication Details
- Journal
- Journal of Information Security and Applications
- Published
- 2026-10-07
- DOI
- https://doi.org/10.1016/j.jisa.2026.104668
- Primary Topic
- User Authentication and Security Systems
- Type
- article
- Field-Weighted Citation Impact
- 0.00