PoW-GeoCAPTCHA: A novel human-bot verification scheme integrating proof-of-work and geometric recognition

Widely deployed CAPTCHAs face a growing security-usability trade-off, worsened by deep learning bots defeating mainstream methods with high success rates. We propose PoW-GeoCAPTCHA, a two-factor human-bot verification scheme. Departing from conventional circular and elliptical ring-counting designs whose stable curvature and closed contours are increasingly exploitable by deep learning attacks, we propose a triangle-counting geometric CAPTCHA. This geometric primitive resists automated solvers via occlusion-prone contours and unstable global features, and integrates with a lightweight Proof-of-Work (PoW) mechanism. Unlike prior works concatenating independent modules, our design achieves deep synergy via background-transparent PoW execution and request-aware dynamic difficulty linkage. The geometric CAPTCHA resists attacks via randomized triangle overlays and dynamic HSV color modulation creating visually indistinguishable regions, while PoW difficulty adjusts based on request context. In controlled attack experiments, single-challenge success rates reached only 1.00% (contour-based), 22% (CNN), 38.10% (YOLOv8), 40.20% (Faster R-CNN), and 18.00%, 24.70%, and 28.60% against attacks from representative multimodal large language models (MLLMs, vision-augmented LLM variants) Qwen3-VL-Plus, ChatGPT-series gpt-4o-mini, and Google Gemini-series gemini-3.5-flash, respectively, verifying reliable defense against LLM-derived visual cracking. When two consecutive geometric challenges are required, these rates drop exponentially to 0.01%, 4.84%, 14.52%, 16.16%, and to 3.24%, 6.10%, and 8.18% for the three multimodal large-model attacks, respectively. A user study on the dual geometric CAPTCHA (without PoW) showed a 90.20% human pass rate. The full system adds negligible PoW overhead ( < 10 ms) and maintains high usability. This lightweight solution suits login, transaction, and API protection, validated under realistic threat models.

Authors

Institutions

Publication Details

Journal
Journal of Information Security and Applications
Published
2026-10-07
DOI
https://doi.org/10.1016/j.jisa.2026.104668
Primary Topic
User Authentication and Security Systems
Type
article
Field-Weighted Citation Impact
0.00
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
OCT
article

PoW-GeoCAPTCHA: A novel human-bot verification scheme integrating proof-of-work and geometric recognition

Lixin Jiang, Zhanshan Li, Shuhui Zhang, Lu Wang et al.
Journal of Information Security and Applications
User Authentication and Security Systems
article

PoW-GeoCAPTCHA: A novel human-bot verification scheme integrating proof-of-work and geometric recognition

Lixin Jiang, Zhanshan Li, Shuhui Zhang, Lu Wang, Jiayi Chen
article en

Abstract

Widely deployed CAPTCHAs face a growing security-usability trade-off, worsened by deep learning bots defeating mainstream methods with high success rates. We propose PoW-GeoCAPTCHA, a two-factor human-bot verification scheme. Departing from conventional circular and elliptical ring-counting designs whose stable curvature and closed contours are increasingly exploitable by deep learning attacks, we propose a triangle-counting geometric CAPTCHA. This geometric primitive resists automated solvers via occlusion-prone contours and unstable global features, and integrates with a lightweight Proof-of-Work (PoW) mechanism. Unlike prior works concatenating independent modules, our design achieves deep synergy via background-transparent PoW execution and request-aware dynamic difficulty linkage. The geometric CAPTCHA resists attacks via randomized triangle overlays and dynamic HSV color modulation creating visually indistinguishable regions, while PoW difficulty adjusts based on request context. In controlled attack experiments, single-challenge success rates reached only 1.00% (contour-based), 22% (CNN), 38.10% (YOLOv8), 40.20% (Faster R-CNN), and 18.00%, 24.70%, and 28.60% against attacks from representative multimodal large language models (MLLMs, vision-augmented LLM variants) Qwen3-VL-Plus, ChatGPT-series gpt-4o-mini, and Google Gemini-series gemini-3.5-flash, respectively, verifying reliable defense against LLM-derived visual cracking. When two consecutive geometric challenges are required, these rates drop exponentially to 0.01%, 4.84%, 14.52%, 16.16%, and to 3.24%, 6.10%, and 8.18% for the three multimodal large-model attacks, respectively. A user study on the dual geometric CAPTCHA (without PoW) showed a 90.20% human pass rate. The full system adds negligible PoW overhead ( < 10 ms) and maintains high usability. This lightweight solution suits login, transaction, and API protection, validated under realistic threat models.

Journal of Information Security and ApplicationsVol. 103
Jilin University (CN)
Openalex Percentile: Top 5%
User Authentication and Security Systems
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.