Haichang Gao

dblp:81/7020 · DBLP profile ↗
← Back
44ranked-venue papers
12as first author
25since 2021 · last 2026
0000-0002-4969-5718ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 21 · 9 first-author · 8 since 2021Artificial intelligence and machine learning · 13 · 1 first-author · 12 since 2021Graphics, computer vision, multimedia, augmented reality and games · 7 · 2 first-author · 4 since 2021Human-computer interaction and ubiquitous computing · 2 · 2 first-authorApplied, interdisciplinary, general and emerging computing · 2 · 1 since 2021Systems, architecture and hardware · 1 · 1 since 2021Computer networks · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021
YearPublicationVenuePosition
2026 HumorReject: Decoupling LLM Safety from Refusal Prefix via a Little Humor
abstract
Large Language Models (LLMs) commonly rely on explicit refusal prefixes for safety, making them vulnerable to prefix injection attacks. We introduce HumorReject, a novel data-driven approach that reimagines LLM safety by decoupling it from refusal prefixes through humor as an indirect refusal strategy. Rather than explicitly rejecting harmful instructions, HumorReject responds with contextually appropriate humor that naturally defuses potentially dangerous requests. Our approach effectively addresses common "over-defense" issues while demonstrating superior robustness against various attack vectors. Our findings suggest that improvements in training data design can be as important as the alignment algorithm itself in achieving effective LLM safety.
Zihui Wu, Haichang Gao, Jiacheng Luo, Zhaoxiang Liu
AAAI2
2026 GlitchMiner: Mining Glitch Tokens in Large Language Models via Gradient-based Discrete Optimization
abstract
Glitch tokens—inputs that trigger unpredictable or anomalous behavior in Large Language Models (LLMs)—pose significant challenges to model reliability and safety. Existing detection methods primarily rely on heuristic embedding patterns or statistical anomalies within internal representations, limiting their generalizability across different model architectures and potentially missing anomalies that deviate from observed patterns. We introduce GlitchMiner, an behavior-driven framework designed to identify glitch tokens by maximizing predictive entropy. Leveraging a gradient-guided local search strategy, GlitchMiner efficiently explores the discrete token space without relying on model-specific heuristics or large-batch sampling. Extensive experiments across ten LLMs from five major model families demonstrate that GlitchMiner consistently outperforms existing approaches in detection accuracy and query efficiency, providing a generalizable and scalable solution for effective glitch token discovery.
Zihui Wu, Haichang Gao, Ping Wang 0003, Shudong Zhang, Zhaoxiang Liu, Shiguo Lian
AAAI2
2026 Shadow model-guided class-label distribution inference and privacy assessment in personalized federated learning
abstract
Personalized federated learning (PFL) enables collaborative model training under heterogeneous client data by separating shared model components from personalized ones, but the uploaded shared-model updates may still reveal implicit knowledge about clients’ private data distributions. In this work, we study class-label distribution inference as a distributional knowledge reconstruction problem in PFL. We observe that updates of the shared model component encode label distribution information through their directional alignment with class-specific optimization trajectories, even when personalized parameters remain local. Based on this observation, we propose the S hadow M odel-guided class-label distribution I nference and privacy A ssessment ( SMIA ), a shadow model-guided geometric inference framework for assessing distributional privacy risks in personalized federated learning. Instead of relying on magnitude-sensitive parameter variations, SMIA characterizes the directional relationships between target-client shared updates and class-wise reference updates obtained from shadow models. These relationships are then organized into a Gram-matrix-induced geometric reconstruction system, where the client label distribution can be efficiently estimated through a closed-form solution. Extensive experiments on multiple vision and text datasets under diverse data distribution settings demonstrate that SMIA consistently outperforms prior methods across personalized federated learning scenarios. The results reveal that shared-model update directions can carry substantial distributional knowledge, highlighting the need to consider directional leakage when evaluating privacy risks in personalized federated learning systems.
Zhixuan Ma, Haichang Gao, Junxiang Huang, Ping Wang 0027
Neurocomputing2
2025 The Dark Side of Function Calling: Pathways to Jailbreaking Large Language Models
abstract
Large language models (LLMs) have demonstrated remarkable capabilities, but their power comes with significant security considerations. While extensive research has been conducted on the safety of LLMs in chat mode, the security implications of their function calling feature have been largely overlooked. This paper uncovers a critical vulnerability in the function calling process of LLMs, introducing a novel “jailbreak function” attack method that exploits alignment discrepancies, user coercion, and the absence of rigorous safety filters. Our empirical study, conducted on six state-of-the-art LLMs including GPT-4o, Claude-3.5-Sonnet, and Gemini-1.5-pro, reveals an alarming average success rate of over 90% for this attack. We provide a comprehensive analysis of why function calls are susceptible to such attacks and propose defensive strategies, including the use of defensive prompts. Our findings highlight the urgent need for enhanced security measures in the function calling capabilities of LLMs, contributing to the field of AI safety by identifying a previously unexplored risk, designing an effective attack method, and suggesting practical defensive measures
Zihui Wu, Haichang Gao, Jianping He 0008, Ping Wang 0027
COLING2
2025 DBBA: Diffusion-Based Backdoor Attacks on Open-Set Face Recognition Models
Fuqi Qi, Haichang Gao, Boling Li, Guangyu He, Jiacheng Luo
ESORICS (1)2
2025 Towards Aligned Data Forgetting via Twin Machine Unlearning
abstract
Modern privacy regulations have spurred the evolution of machine unlearning, a technique enabling a trained model to efficiently forget specific training data. In prior unlearning methods, the concept of “data forgetting” is often interpreted and implemented as achieving zero classification accuracy on such data. Nevertheless, the authentic aim of machine unlearning is to achieve alignment between the unlearned model and the gold model, i.e., encouraging them to have identical classification accuracy. On the other hand, the gold model often exhibits non-zero classification accuracy due to its generalization ability. To achieve aligned data forgetting, we propose a Twin Machine Unlearning (TMU) approach, where a twin unlearning problem is defined corresponding to the original unlearning problem. Consequently, the generalization-label predictor trained on the twin problem can be transferred to the original problem, facilitating aligned data forgetting. Comprehensive empirical experiments illustrate that our approach significantly enhances the alignment between the unlearned model and the gold model.
Haoxuan Ji, Yuyao Sun, Fei Gao 0006, Haichang Gao, Zhenxing Niu
ICME6
2025 BadLogo: A Physically Realizable Adversarial Sticker for Evaluating the Robustness of Face Recognition Models
abstract
Deep learning-based face recognition systems are increasingly deployed in security-critical applications, yet remain vulnerable to adversarial attacks. Existing physical attacks often lack stealth or realism, limiting their utility for evaluating realworld robustness. To address this, we propose BadLogo, a physically realizable, sticker-based perturbation that balances attack effectiveness and visual plausibility. We also introduce PLOF-GAN, an attack model employing a two-stage pretraining strategy to progressively transform benign logos into high-quality adversarial patches. An improved 3D mapping algorithm ensures precise alignment with facial geometry, enhancing the realism of physical deployment. To quantitatively assess stealthiness and visual plausibility, we design a new metric, BROI, which measures both region occlusion and semantic coherence. Whether in evasion or impersonation attack scenarios, extensive experiments on identity verification and identification tasks demonstrate that BadLogo achieves high attack success rates with superior stealthiness compared to existing methods. Notably, our approach exhibits strong transferability across multiple face recognition models and generalizes to object detection scenarios. By leveraging adversarial stickers, this work reveals critical vulnerabilities in face recognition systems under physical-world conditions and offers new perspectives for developing more robust models.
Fuqi Qi, Haichang Gao, Boling Li, Shiping Guo, Yuming Zheng, Bingqian Zhou
RAID2
2024 Enhancing Data-Free Model Stealing Attack on Robust Models
abstract
Machine Learning Model Deployment as a Service (MLaaS) has surged in popularity, offering substantial business value. However, the significant resources and costs required to train models have raised concerns about Model Stealing Attacks (MSAs), where attackers create a clone model to replicate the knowledge of a victim model without access to its parameters. In data-free MSA, attackers also lack access to the training data for the victim model. In this setting, existing MSA methods rely on Generative Adversarial Networks (GANs) to generate images to query the victim model. However, GANs are known to suffer from model collapse, resulting in limited diversity in generated images. The lack of diversity in generated images will significantly impact the accuracy of the clone model, especially in stealing robust models trained with adversarial training. Recent studies have demonstrated that Denoising Diffusion Probabilistic Models (DDPMs) outperform GANs in generating images with greater diversity. In our data-free MSA framework, using DDPM as the generator to steal robust models significantly increases the effectiveness, improving the accuracy of the clone model from 21.34% to 60.23% compared to the GANs-based approach DFME, and requires fewer queries. We further use denoise diffusion GANs to address the problem of low sampling speed of DDPM, while retaining the advantage of its high sample diversity and obtaining better results.
Jianping He 0008, Haichang Gao, Yunyi Zhou
IJCNN2
2024 A Transferable Adversarial Attack against Object Detection Networks
abstract
Deep neural networks are widely used in tasks such as autonomous driving and computer vision. Previous studies have shown that it is susceptible to adversarial attacks, resulting in erroneous outputs. However, adversarial attacks against object detection networks are difficult to implement due to the high complexity of the object detection algorithm itself. We propose a transferable adversarial attack method for object detection networks, and collect a large number of real car images for model training and testing. We design a classification probability loss function based on inter-class probability distribution and an IoU loss function based on the predicted bounding box to train the generation of adversarial perturbations. The perturbation is covered on the hood of the car so that the vehicle can successfully escape the object detection model. At the same time, we place the printed adversarial patch on real-world cars and use methods such as perspective transformation and affine transformation to enhance the robustness of adversarial attacks in various complex physical environments. The experimental results in indoor and outdoor scenes show that the adversarial perturbation jointly trained by the above two loss functions can successfully attack the YOLOv3 detector, reducing the number of cars detected by the detector by 91.2% and 90.7% respectively. The proposed attack method performs well in both the digital and physical domains and can be transferred between different detection models.
Yier Wei, Haichang Gao, Xingyi Quan, Guotu Luo
IJCNN2
2024 The robustness of behavior-verification-based slider CAPTCHAs
Guoqin Chang, Haichang Gao, Ge Pei, Sainan Luo, Qianwen Guo
J. Inf. Secur. Appl.2
2024 Black-box Bayesian adversarial attack with transferable priors
Shudong Zhang, Haichang Gao, Chao Shu, Xiwen Cao, Yunyi Zhou, Jianping He 0008
Mach. Learn.2
2024 Improving the Security of Audio CAPTCHAs With Adversarial Examples
abstract
CAPTCHAs (completely automated public Turing tests to tell computers and humans apart) have been the main protection against malicious attacks on public systems for many years. Audio CAPTCHAs, as one of the most important CAPTCHA forms, provide an effective test for visually impaired users. However, in recent years, most of the existing audio CAPTCHAs have been successfully attacked by machine learning-based audio recognition algorithms, showing their insecurity. In this article, a generative adversarial network (GAN)-based method is proposed to generate adversarial audio CAPTCHAs. This method is implemented by using a generator to synthesize noise, a discriminator to make it similar to the target and a threshold function to limit the size of the perturbation; then, the synthetic perturbation is combined with the original audio to generate the adversarial audio CAPTCHA. The experimental results demonstrate that the addition of adversarial examples can greatly reduce the recognition accuracy of automatic models and improve the robustness of different types of audio CAPTCHAs. We also explore ensemble learning strategies to improve the transferability of the proposed adversarial audio CAPTCHA methods. To investigate the effect of adversarial CAPTCHAs on human users, a user study is also conducted.
Ping Wang 0027, Haichang Gao, Zhongni Yuan, Jiawei Nian
IEEE Trans. Dependable Secur. Comput.2
2024 A Stability-Enhanced Dynamic Backdoor Defense in Federated Learning for IIoT
abstract
Federated learning (FL) systems enable collaborative model training among industrial Internet of Things (IIoT) devices but face significant security challenges, particularly in backdoor attacks, due to the nonindependent and identically distributed (non-IID) nature of data. To address this challenge, we propose a stability-enhanced dynamic backdoor defense approach in FL for IIoT, which maintains primary task accuracy while strengthening defenses in non-IID environments. Leveraging the similarity between data distribution and model updates, we segment non-IID scenarios into multiple quasi-IID environments. Our approach includes a dynamic client matching module, a malicious filtering module, and robust personalized aggregation to reduce the success rate of backdoor attacks while augmenting the resilience and precision of the aggregated model. The effectiveness of our strategy has been validated through analyses on the Modified National Institute of Standards and Technology database (MNIST), Canadian Institute for Advanced Research, 10 classes (CIFAR-10), Internet of Things (IoT)-23, and Washington University in St. Louis (WUSTL)-IIOT datasets in both IID and non-IID scenarios. Notably, on the IoT-23 and WUSTL-IIOT, the success rate of backdoor attacks was significantly reduced to 3.46%.
Zhixuan Ma, Haichang Gao, Shangwen Li, Ping Wang 0027
IEEE Trans. Ind. Informatics2
2023 TransNoise: Transferable Universal Adversarial Noise for Adversarial Attack
Yier Wei, Haichang Gao, Yipeng Gao, Sainan Luo, Qianwen Guo
ICANN (5)2
2023 TextGuise: Adaptive adversarial example attacks on text classification model
Guoqin Chang, Haichang Gao, Zhou Yao, Haoquan Xiong
Neurocomputing2
2023 A lightweight backdoor defense framework based on image inpainting
Yier Wei, Haichang Gao, Yipeng Gao
Neurocomputing2
2023 Manto: A Practical and Secure Inference Service of Convolutional Neural Networks for IoT
abstract
As convolutional neural networks (CNNs) exhibit remarkable performance in various inference tasks, it is increasingly important to enable Internet of Things (IoT) devices to perform CNN-based applications. Many companies provide their carefully trained neural networks as inference services for resource-constrained clients (e.g., IoT devices). However, the use of CNN inference in many IoT applications raises privacy concerns. Cryptographic inference services provide a way to perform neural inference efficiently and, at the same time, preserve both the privacy of the client’s input data and the server’s proprietary model. Unfortunately, the existing solutions incur severe latency costs, stemming mostly from nonlinear activations such as ReLUs, which make them still unsuitable for deployment in real IoT devices. In this article, we propose Manto, a secure inference system of CNNs for IoT. Manto makes the following two specific efforts by combining the insights of machine learning and cryptography. First, we customize different quadratic activation functions to replace specific ReLU layers and further propose a sliding-window-based fine-tuning method to produce CNN models involving no or few ReLUs. These techniques allow us to speedup cryptographic inference and guarantee inference accuracy. Second, we develop a series of cryptographic protocols that support ReLU activations and its approximation variants (i.e., polynomial activations), which purely rely on the lightweight secret sharing techniques in the online execution and can well cope with the above-mentioned optimized CNN models in the ciphertext domain. Our experimental results show Manto obtains state-of-the-art performance, reducing online inference latency by$66.2\%\sim 87.7\%$over prior works on CIFAR-100 and TinyImageNet data sets.
Ke Cheng 0001, Jiaxuan Fu, Yulong Shen 0001, Haichang Gao, Ning Xi 0002, Zhiwei Zhang 0004
IEEE Internet Things J.4
2023 Private Inference for Deep Neural Networks: A Secure, Adaptive, and Efficient Realization
abstract
The advances in deep neural networks (DNNs) have driven many companies to offer their carefully-trained DNNs as inference services for clients’ private data. The privacy concerns have increasingly motivated the need for private inference (PI), where DNN inferences are performed directly on encrypted data without revealing the client's private inputs to the server or revealing the server's proprietary DNN weights to the client. However, existing cryptographic protocols for PI suffer from impractically high latency, stemming mostly from non-linear operators like ReLU activations. In this paper, we propose PAPI, a Practical and Adaptive Private Inference framework. First, we develop an accuracy-adaptive neural architecture search (NAS) approach to generate DNN models tailored for high-efficiency ciphertext computation. Specifically, our NAS automatically generates the DNNs with fewer ReLUs while keeping the accuracy above a user-defined target. Second, we propose secure online/offline protocols for ReLU activation and its approximation variants (i.e., polynomial activations), which purely rely on the lightweight secret sharing techniques in the online execution and can well cope with our optimized DNNs in the ciphertext domain. Experimental results show that PAPI reduces online inference latency on the CIFAR-10/100 and ImageNet datasets by 2.7${\times}$$\sim$7.8${\times}$over the state-of-the-art.
Ke Cheng 0001, Ning Xi 0002, Ximeng Liu, Haichang Gao, Zhiwei Zhang 0004, Yulong Shen 0001
IEEE Trans. Computers5
2023 Extended Research on the Security of Visual Reasoning CAPTCHA
abstract
CAPTCHA is an effective mechanism for protecting computers from malicious bots. With the development of deep learning techniques, current mainstream text-based and traditional image-based CAPTCHAs have been proven to be insecure. Therefore, a major effort has been directed toward developing new CAPTCHAs by utilizing some other hard Artificial Intelligence (AI) problems. Recently, some commercial companies (Tencent, NetEase, Geetest, etc.) have begun deploying a new type of CAPTCHA based on visual reasoning to defend against bots. As a newly proposed CAPTCHA, it is therefore natural to ask a fundamental question: are visual reasoning CAPTCHAs as secure as their designers expect? This paper explores the security of visual reasoning CAPTCHAs. We proposed a modular attack and evaluated it on six different real-world visual reasoning CAPTCHAs, which achieved overall success rates ranging from 79.2% to 98.6%. The results show that visual reasoning CAPTCHAs are not as secure as anticipated; this latest effort to use novel, hard AI problems for CAPTCHAs has not yet succeeded. Then, we summarize some guidelines for designing better visual-based CAPTCHAs, and based on the lessons we learned from our attacks, we propose a new CAPTCHA based on commonsense knowledge (CsCAPTCHA) and show its security and usability experimentally.
Ping Wang 0027, Haichang Gao, Chenxuan Xiao, Yipeng Gao, Yang Zi
IEEE Trans. Dependable Secur. Comput.2
2022 Consistency Regularization Helps Mitigate Robust Overfitting in Adversarial Training
Shudong Zhang, Haichang Gao, Yunyi Zhou, Zihui Wu
KSEM (3)2
2022 A deep learning-based attack on text CAPTCHAs by using object detection techniques
abstract
Abstract Text‐based CAPTCHAs have been widely deployed by many popular websites, and many have been attacked. However, most previous cracks were based on classification algorithms that typically rely on a series of preprocessing operations or on many training samples, thus making such attacks complicated and costly. In this study, a simple, generic, fast and end‐to‐end attack based on advanced object detection technologies is introduced. The proposed attack combines a feature extraction module, a character location and recognition module and a coordinate matching module. The experiments show that the attack can break a wide range of real‐world text CAPTCHAs deployed by the 50 most popular websites on Alexa.com and that the method achieves a high attack accuracy with only 2000 samples at an attack speed of less than 0.10 s. The attack was also evaluated on four click‐based CAPTCHAs that cannot be attacked in the end‐to‐end manner used by previous attacks, and the results demonstrated that within one step, the proposed approach achieves high success rates on both click‐based CAPTCHAs and schemes based on large‐scale character sets, such as Chinese character sets.
Jiawei Nian, Ping Wang 0027, Haichang Gao
IET Inf. Secur.3
2021 Research on the Security of Visual Reasoning CAPTCHA
Yipeng Gao, Haichang Gao, Sainan Luo, Yang Zi, Shudong Zhang, Ping Wang 0003, Jeff Yan
USENIX Security Symposium2
2021 Universal Optimization Strategies for Object Detection Networks
abstract
With the development of deep learning technologies, object detection algorithms have made significant progress in terms of detection speed and detection performance. However, the detection speed of current detection networks still does not meet the requirements of real-world applications in some scenarios. In this paper, we propose a faster non-maximum suppression (FNMS) algorithm that reduces the processing time by a large margin while achieving the same detection precision compared with the traditional non-maximum suppression (NMS) algorithm. Moreover, an attempt is made to adopt additional lightweight network structures to improve the speed of the detection network. By combining our FNMS algorithm with other network optimization strategies, we are able to improve the detection speed of YOLO v3 on the DOTA dataset by 165%.
Ziyu Shi, Haichang Gao, Shuai Kang
Int. J. Pattern Recognit. Artif. Intell.2
2021 A Security Analysis of Captchas With Large Character Sets
abstract
Captcha, which can prevent computer programs from attacking websites, has been the most important security technology for many years. The most popularly deployed Captcha is the text-based scheme. The vast majority of the existing text Captchas are designed with English letters and Arabic numerals. Recently, text Captchas with large character sets are being increasingly popular. From the perspective of attackers, larger character set means greater solution space and better theoretical security. However, the security of Captchas with large character sets in real world has never been studied comprehensively. In this article, we introduce a simple, fast, and effective deep learning method to attack these newly emerging Captchas. Taking 11 Chinese Captchas as representatives, we ran our experimental attack on each of them. Our attack achieved high success rates, ranging from 34.7 to 86.9 percent at an average speed of 0.175 seconds on these schemes. All of the results show that the Chinese text Captcha can be easily broken, demonstrating that text Captchas with large character sets are also insecure in existing forms. As a substitute, we proposed a 3D image-based scheme combining semantic comprehension and dragging action. The preliminary experimental results show that it is more robust than current text-based schemes.
Ping Wang 0027, Haichang Gao, Qingxun Rao, Sainan Luo, Zhongni Yuan, Ziyu Shi
IEEE Trans. Dependable Secur. Comput.2
2021 Defense Against Adversarial Attacks by Reconstructing Images
abstract
Convolutional neural networks (CNNs) are vulnerable to being deceived by adversarial examples generated by adding small, human-imperceptible perturbations to a clean image. In this paper, we propose an image reconstruction network that reconstructs an input adversarial example into a clean output image to defend against such adversarial attacks. Due to the powerful learning capabilities of the residual block structure, our model can learn a precise mapping from adversarial examples to reconstructed examples. The use of a perceptual loss greatly suppresses the error amplification effect and improves the performance of our reconstruction network. In addition, by adding randomization layers to the end of the network, the effects of additional noise are further suppressed, especially for iterative attacks. Our model has the following four advantages. 1) It greatly reduces the impact of adversarial perturbations while having little influence on the prediction performance of clean images. 2) During inference phase, it performs better than most existing model-agnostic defense methods. 3) It has better generalization capability. 4) It can be flexibly combined with other methods, such as adversarially trained models.
Shudong Zhang, Haichang Gao, Qingxun Rao
IEEE Trans. Image Process.2
2020 An End-to-End Attack on Text CAPTCHAs
abstract
Text-based CAPTCHAs are the most widely used CAPTCHA scheme. Most text-based CAPTCHAs have been cracked. However, previous works have mostly relied on a series of preprocessing steps to attack text CAPTCHAs, which was complicated and inefficient. In this paper, we introduce a simple, generic, and effective end-to-end attack on text CAPTCHAs without any preprocessing. Through a convolutional neural network and an attention-based recurrent neural network, our attack broke a wide range of real-world text CAPTCHAs that are deployed by the top 50 most popular websites ranked by Alexa.com. In addition, this paper comprehensively analyzed the security of most resistance mechanisms of text-based CAPTCHAs through experiments. Experimental results prove that the anti-segmentation principle can be completely broken under deep learning attacks without any segmentation or preprocessing steps in contrast to commonly held beliefs.
Yang Zi, Haichang Gao, Zhouhang Cheng, Yi Liu 0042
IEEE Trans. Inf. Forensics Secur.2
2019 Image-based CAPTCHAs based on neural style transfer
abstract
Over the last few years, completely automated public turing test to tell computers and humans apart (CAPTCHA) has been used as an effective method to prevent websites from malicious attacks, however, CAPTCHA designers failed to reach a balance between good usability and high security. In this study, the authors apply neural style transfer to enhance the security for CAPTCHA design. Two image‐based CAPTCHAs, Grid‐CAPTCHA and Font‐CAPTCHA, based on neural style transfer are proposed. Grid‐CAPTCHA offers nine stylized images to users and requires users to select all corresponding images according to a short description, and Font‐CAPTCHA asks users to click Chinese characters presented in the image in sequence according to the description. To evaluate the effectiveness of this techniques on enhancing CAPTCHA security, they conducted a comprehensive field study and compared them to similar mechanisms. The comparison results demonstrated that the neural style transfer decreased the success rate of automated attacks. Human beings have achieved a successful solving rate of 75.04 and 84.49% on the Grid‐CAPTCHA and Font‐CAPTCHA schemes, respectively, indicating good usability. The results prove deep learning can have a positive effect on enhancing CAPTCHA security and provides a promising direction for future CAPTCHA study.
Zhouhang Cheng, Haichang Gao, Zhongyu Liu, Huaxi Wu, Yang Zi, Ge Pei
IET Inf. Secur.2
2018 Research on Deep Learning Techniques in Breaking Text-Based Captchas and Designing Image-Based Captcha
abstract
The ability of hackers to infiltrate computer systems using computer attack programs and bots led to the development of Captchas or Completely Automated Public Turing Tests to Tell Computers and Humans Apart. The text Captcha is the most popular Captcha scheme given its ease of construction and user friendliness. However, the next generation of hackers and programmers has decreased the expected security of these mechanisms, leaving websites open to attack. Text Captchas are still widely used, because it is believed that the attack speeds are slow, typically two to five seconds per image, and this is not seen as a critical threat. In this paper, we introduce a simple, generic, and fast attack on text Captchas that effectively challenges that supposition. With deep learning techniques, our attack demonstrates a high success rate in breaking the Roman-character-based text Captchas deployed by the top 50 most popular international websites and three Chinese Captchas that use a larger character set. These targeted schemes cover almost all existing resistance mechanisms, demonstrating that our attack techniques are also applicable to other existing Captchas. Does this work then spell the beginning of the end for text-based Captcha? We believe so. A novel image-based Captcha named Style Area Captcha (SACaptcha) is proposed in this paper, which is based on semantic information understanding, pixel-level segmentation, and deep learning techniques. Having demonstrated that text Captchas are no longer secure, we hope that our proposal shows promise in the development of image-based Captchas using deep learning techniques.
Mengyun Tang, Haichang Gao, Yi Liu 0042, Ping Wang 0027
IEEE Trans. Inf. Forensics Secur.2
2017 Research on the Security of Microsoft's Two-Layer Captcha
abstract
Captcha is a security mechanism designed to differentiate between computers and humans, and is used to defend against malicious bot programs. Text-based Captchas are the most widely deployed differentiation mechanism, and almost all text-based Captchas are single layered. Numerous successful attacks on the single-layer text-based Captchas deployed by Google, Yahoo!, and Amazon have been reported. In 2015, Microsoft deployed a new two-layer Captcha scheme. This appears to be the first application of two-layer Captchas. It is, therefore, natural to ask a fundamental question: is the two-layer Captcha as secure as its designers expected? Intrigued by this question, we have for the first time systematically analyzed the security of the two-layer Captcha in this paper. We propose a simple but an effective method to attack the two-layer Captcha deployed by Microsoft, and achieve a success rate of 44.6% with an average speed of 9.05 s on a standard desktop computer (with a 3.3-GHz Intel Core i3 CPU and 2-GB RAM), thus demonstrating clear security issues. We also discuss the originality and applicability of our attack, and offer guidelines for designing Captchas with better security and usability.
Haichang Gao, Mengyun Tang, Yi Liu 0042
IEEE Trans. Inf. Forensics Secur.1
2016 A Simple Generic Attack on Text Captchas
Haichang Gao, Jeff Yan, Zhengya Zhang, Mengyun Tang, Xuqin Wang
NDSS1
2016 Robustness of text-based completely automated public turing test to tell computers and humans apart
abstract
Text‐based completely automated public turing tests to tell computers and humans apart (CAPTCHAs) have been widely deployed across the Internet to defend against undesirable or malicious bot programmes. In this study, the authors provide a systematic analysis of text‐based CAPTCHAs and innovatively improve their earlier attack on hollow CAPTCHAs to expand applicability to attack all the text CAPTCHAs. With this improved attack, they have successfully broken the CAPTCHA schemes adopted by 19 out of the top 20 web sites in Alexa including two versions of the famous ReCAPTCHA. With success rates ranging from 12 to 88.8% (note that the success rate for Yandex CAPTCHA is 0%), they demonstrate the effectiveness of their attack method. It is not only applicable to hollow CAPTCHAs, but also to non‐hollow ones. As their attack casts serious doubt on the viability of current designs, they offer lessons and guidelines for designing better text‐based CAPTCHAs.
Haichang Gao, Xuqin Wang, Zhengya Zhang, Jiao Qi
IET Inf. Secur.1
2013 The robustness of hollow CAPTCHAs
abstract
CAPTCHA is now a standard security technology for differentiating between computers and humans, and the most widely deployed schemes are text-based. While many text schemes have been broken, hollow CAPTCHAs have emerged as one of the latest designs, and they have been deployed by major companies such as Yahoo!, Tencent, Sina, China Mobile and Baidu. A main feature of such schemes is to use contour lines to form connected hollow characters with the aim of improving security and usability simultaneously, as it is hard for standard techniques to segment and recognize such connected characters, which are however easy to human eyes. In this paper, we provide the first analysis of hollow CAPTCHAs' robustness. We show that with a simple but novel attack, we can successfully break a whole family of hollow CAPTCHAs, including those deployed by all the major companies. While our attack casts serious doubt on the viability of current designs, we offer lessons and guidelines for designing better hollow CAPTCHAs.
Haichang Gao, Jiao Qi, Xuqin Wang, Jeff Yan
CCS1
2012 Divide and Conquer: An Efficient Attack on Yahoo! CAPTCHA
abstract
CAPTCHA is now almost a standard security technology to tell computers and humans apart. The most widely deployed CAPTCHAs are text-based schemes. In this paper, we document how we have broken such text-based scheme used by Yahoo!. Using "connecting characters together" principle, Yahoo! CAPTCHA is effectively resistant to segmentation and recognition in the early attacks. In contrast to early works that recognized the text after segmentation, we combined the recognition with segmentation to divide and conquer the CAPTCHA. In another word, we segment the text by extracting the recognized characters. The experiments show that our extraction and segmentation attack on Yahoo! CAPTCHA achieved a success rate of about 78% and an overall (individual character recognition with OCR) success rate of 54.7%.
Haichang Gao
TrustCom1
2012 Multiple password interference in graphical passwords
abstract
Considerable studies verified that people are vulnerable to multiple passwords interference in alphanumeric passwords but few studies in graphical passwords. We conducted a study on multiple password interference in graphical passwords and examined the effects on users’ behaviour and performance. DAS, PassPoints and PassFaces, three canonical graphical passwords, represent the three main memory categories: recall, cued-recall and recognition. PassPoints were divided into PassPoints-I and PassPoints-II, corresponding to associated and unassociated cued-recall memory respectively. The study results indicate that the multiple password interference exercises strong impacts in PassFaces and is significant in DAS and PassPoints-II only in the long-term memory, while has no impact in PassPoints-I. From psychological analysis, it is clear that recall-based, recognition-based and associated cued-recall-based schemes are all susceptible to multiple password interference to some extent, while unassociated cued-recall based is not subject to memory password interference.
Haichang Gao, Licheng Ma
Int. J. Inf. Comput. Secur.1
2011 A Novel Cued-recall Graphical Password Scheme
abstract
Graphical passwords have been proposed as an alternative to alphanumeric passwords with their advantages in usability and security. However, most of these alternate schemes have their own disadvantages. For example, cued-recall graphical password schemes are vulnerable to shoulder-surfing and cannot prevent intersection analysis attack. A novel cued-recall graphical password scheme CBFG (Click Buttons according to Figures in Grids) is proposed in this paper. Inheriting the way of setting password in traditional cued-recall scheme, this scheme is also added the ideology of image identification. CBFG helps users tend to set their passwords more complex. Simultaneously, it has the capability against shoulder surfing attack and intersection analysis attack. Experiments illustrate that CBFG has better performance in usability, especially in security.
Jinhua Qiu, Licheng Ma, Haichang Gao, Zhongjie Ren
ICIG4
2011 Exploration of a hand-based graphical password scheme
abstract
Graphical passwords have been proposed as an alternative to alphanumeric passwords with their advantages in usability and security. However, most of these alternate schemes have their own problems about memorability. Biometrics schemes are not widely adopted though they need no remembrance and provide the highest level of security, owing to their great cost both in device and time. In this paper, we explore the feasibility of introducing hand-based biometrics into the realm of graphical passwords with a simplified scheme named PassHands. PassHands has similar authentication form with Passfaces and has the advantages of unnecessary to remember the password and unpredictable of user choice. Some primary experiments are conducted and the results illustrate the performance of PassHands.
Haichang Gao, Licheng Ma, Jinhua Qiu
SIN1
2011 An Enhanced Drawing Reproduction Graphical Password Strategy
Haichang Gao, Xiuling Chang
J. Comput. Sci. Technol.2
2010 Against Spyware Using CAPTCHA in Graphical Password Scheme
abstract
Text-based password schemes have inherent security and usability problems, leading to the development of graphical password schemes. However, most of these alternate schemes are vulnerable to spyware attacks. We propose a new scheme, using CAPTCHA (Completely Automated Public Turing tests to tell Computers and Humans Apart) that retaining the advantages of graphical password schemes, while simultaneously raising the cost of adversaries by orders of magnitude. Furthermore, some primary experiments are conducted and the results indicate that the usability should be improved in the future work.
Xiuling Chang, Zhongjie Ren, Haichang Gao, Uwe Aickelin
AINA4
2010 A New Graphical Password Scheme Resistant to Shoulder-Surfing
abstract
Shoulder-surfing is a known risk where an attacker can capture a password by direct observation or by recording the authentication session. Due to the visual interface, this problem has become exacerbated in graphical passwords. There have been some graphical schemes resistant or immune to shoulder-surfing, but they have significant usability drawbacks, usually in the time and effort to log in. In this paper, we propose and evaluate a new shoulder-surfing resistant scheme which has a desirable usability for PDAs. Our inspiration comes from the drawing input method in DAS and the association mnemonics in Story for sequence retrieval. The new scheme requires users to draw a curve across their password images orderly rather than click directly on them. The drawing input trick along with the complementary measures, such as erasing the drawing trace, displaying degraded images, and starting and ending with randomly designated images provide a good resistance to shoulder-surfing. A preliminary user study showed that users were able to enter their passwords accurately and to remember them over time.
Haichang Gao, Zhongjie Ren, Xiuling Chang, Uwe Aickelin
CW1
2009 Web Service Selection Algorithm Based on Particle Swarm Optimization
abstract
A novel multi-objective optimization based particle swarm optimization algorithm is presented to solve the global optimization problem for based services selecting in Web services composition technology. This algorithm takes Web services selection as a multi-objective constrained optimization problem with constraints. It introduces multi-objective PSO intelligent theory to optimize multi parameters simultaneously, and produces a set of constraints to meet the Pareto optimal solution. The experiments show that the algorithm is a feasible and efficient method for Web services selection.
Hong Xia, Zengzhi Li, Haichang Gao, Yanping Chen 0006
DASC4
2009 Analysis and Evaluation of the ColorLogin Graphical Password Scheme
abstract
It is believed that graphical passwords are more memorable than traditional textual passwords, but usually seen as complex and time-consuming for users. Furthermore, most of the existing graphical password schemes are vulnerable to spyware and shoulder surfing. ColorLogin uses color, a method not previously considered, to decrease login time. Multiple colors are used to confuse the peepers, while not burdening the legitimate users. Meanwhile, the scheme is resistant to shoulder surfing and intersection attack to a certain extent. This paper analyzes and evaluates the ColorLogin scheme using some experiments.
Haichang Gao, Ruyi Dai, Sidong Wang, Xiuling Chang
ICIG1
2009 A new graphical password scheme against spyware by using CAPTCHA
abstract
No abstract available.
Haichang Gao
SOUPS1
2008 YAGP: Yet Another Graphical Password Strategy
abstract
Alphanumeric passwords are widely used in computer and network authentication to protect users' privacy. However, it is well known that long, text-based passwords are hard for people to remember, while shorter ones are susceptible to attack. Graphical password is a promising solution to this problem. Draw-A-Secret (DAS) is a typical implementation based on the user drawing on a grid canvas. Currently, too many constraints result in reduction in user experience and prevent its popularity. A novel graphical password strategy Yet Another Graphical Password (YAGP) inspired by DAS is proposed in this paper. The proposal has the advantages of free drawing positions, strong shoulder surfing resistance and large password space. Experiments illustrate the effectiveness of YAGP.
Haichang Gao, Xuewu Guo
ACSAC1
2006 Training RBF Neural Network with Hybrid Particle Swarm Optimization
Haichang Gao, Boqin Feng
ISNN (1)1