{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,14]],"date-time":"2026-03-14T18:00:18Z","timestamp":1773511218174,"version":"3.50.1"},"reference-count":53,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"11","license":[{"start":{"date-parts":[[2017,11,1]],"date-time":"2017-11-01T00:00:00Z","timestamp":1509494400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/3.0\/legalcode"}],"funder":[{"DOI":"10.13039\/501100000266","name":"U.K. Engineering and Physical Sciences Research Council","doi-asserted-by":"publisher","award":["EP\/M013375\/1"],"award-info":[{"award-number":["EP\/M013375\/1"]}],"id":[{"id":"10.13039\/501100000266","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100003711","name":"Israeli Ministry of Science and Technology","doi-asserted-by":"publisher","award":["3-11858"],"award-info":[{"award-number":["3-11858"]}],"id":[{"id":"10.13039\/501100003711","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans.Inform.Forensic Secur."],"published-print":{"date-parts":[[2017,11]]},"DOI":"10.1109\/tifs.2017.2718479","type":"journal-article","created":{"date-parts":[[2017,6,21]],"date-time":"2017-06-21T18:36:37Z","timestamp":1498070197000},"page":"2640-2653","source":"Crossref","is-referenced-by-count":146,"title":["No Bot Expects the DeepCAPTCHA! Introducing Immutable Adversarial Examples, With Applications to CAPTCHA Generation"],"prefix":"10.1109","volume":"12","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-5480-5099","authenticated-orcid":false,"given":"Margarita","family":"Osadchy","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Julio","family":"Hernandez-Castro","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Stuart","family":"Gibson","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Orr","family":"Dunkelman","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Daniel","family":"Perez-Cabo","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref39","article-title":"OverFeat: Integrated recognition, localization and detection using convolutional networks","author":"sermanet","year":"2013"},{"key":"ref38","article-title":"Adversarial manipulation of deep representations","author":"sabour","year":"2015"},{"key":"ref33","article-title":"Transferability in machine learning: From phenomena to black-box attacks using adversarial samples","author":"papernot","year":"2016"},{"key":"ref32","year":"2016","journal-title":"NuCaptcha & Traditional Captcha"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2015.7298640"},{"key":"ref30","author":"naor","year":"0","journal-title":"Verification of a human in the loop or Identification via the Turing Test"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1007\/s11263-015-0816-y"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2016.41"},{"key":"ref35","article-title":"Practical black-box attacks against machine learning","author":"papernot","year":"2016"},{"key":"ref34","article-title":"The limitations of deep learning in adversarial settings","author":"papernot","year":"2015"},{"key":"ref28","first-page":"195","article-title":"Three-way dissection of a game-CAPTCHA: Automated attacks, relay attacks, and usability","author":"mohamed","year":"2014","journal-title":"Proc 9th Symp Inf Comput Commun Secur (ASIA)"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1038\/nature14236"},{"key":"ref29","article-title":"Understanding captcha-solving services in an economic context","volume":"10","author":"motoyama","year":"2010","journal-title":"Proc Usenix Security"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2005.38"},{"key":"ref1","year":"2016","journal-title":"Are You a Human"},{"key":"ref20","article-title":"Adversarial examples in the physical world","author":"kurakin","year":"2016"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1162\/neco.1989.1.4.541"},{"key":"ref21","article-title":"Adversarial machine learning at scale","author":"kurakin","year":"2016"},{"key":"ref24","article-title":"Delving into transferable adversarial examples and black-box attacks","author":"liu","year":"2016"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1109\/5.726791"},{"key":"ref26","first-page":"1","article-title":"Distributional smoothing with virtual adversarial training","author":"miyato","year":"2016","journal-title":"Proc ICLR"},{"key":"ref25","first-page":"3253","article-title":"Spatially adaptive statistical modeling of wavelet image coefficients and its application to denoising","author":"mih\u00e7ak","year":"1999","journal-title":"Proc IEEE Int Conf Acoust Speech Signal Process"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.1109\/ACSAC.2007.47"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.1145\/1408664.1408671"},{"key":"ref53","doi-asserted-by":"publisher","DOI":"10.1145\/1866307.1866329"},{"key":"ref52","first-page":"818","article-title":"Visualizing and understanding convolutional networks","author":"zeiler","year":"2014","journal-title":"Proc Eur Conf Comp Vis (ECCV)"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1145\/1101149.1101218"},{"key":"ref11","first-page":"366","article-title":"Asirra: A CAPTCHA that exploits interest-aligned manual image categorization","author":"elson","year":"2007","journal-title":"Proc 14th ACM Conf Comput Commun Secur"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978392"},{"key":"ref12","article-title":"Analysis of classifiers&#x2019; robustness to adversarial perturbations","author":"fawzi","year":"2015"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1145\/1455770.1455838"},{"key":"ref14","article-title":"Multi-digit number recognition from street view imagery using deep convolutional neural networks","author":"goodfellow","year":"2013"},{"key":"ref15","article-title":"Explaining and harnessing adversarial examples","author":"goodfellow","year":"2014"},{"key":"ref16","author":"gu","year":"2014","journal-title":"Towards deep neural network architectures robust to adversarial examples"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1109\/MIC.2015.127"},{"key":"ref18","article-title":"Learning with a strong adversary","author":"huang","year":"2015"},{"key":"ref19","first-page":"1106","article-title":"ImageNet classification with deep convolutional neural networks","author":"krizhevsky","year":"2012","journal-title":"Proc Adv Neural Inf Process Syst"},{"key":"ref4","first-page":"1","article-title":"The end is nigh: Generic solving of text-based CAPTCHAs","author":"bursztein","year":"2014","journal-title":"Proc 8th USENIX Conf Offensive Technol"},{"key":"ref3","author":"bursztein","year":"2016","journal-title":"How we Broke the NuCaptcha Video Scheme and What we Proposed to Fix it"},{"key":"ref6","first-page":"513","article-title":"Hidden voice commands","author":"carlini","year":"2016","journal-title":"Proceedings of the 16th USENIX Security Symp (Security)"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2010.31"},{"key":"ref8","first-page":"711","article-title":"Designing human friendly human interaction proofs (HIPs)","author":"chellapilla","year":"2005","journal-title":"Proc SIGCHI Conf Human Factors Comput Syst"},{"key":"ref7","article-title":"Return of the devil in the details: Delving deep into convolutional nets","author":"chatfield","year":"2014","journal-title":"Proc Brit Mach Vis Conf"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2013.52"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1145\/1014052.1014066"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1126\/science.1160379"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1145\/966389.966390"},{"key":"ref48","first-page":"15","article-title":"Automatically evading classifiers: A case study on PDF malware classifiers","author":"xu","year":"2016","journal-title":"Proc 23nd Annu Netw Distrib Syst Secur Symp"},{"key":"ref47","article-title":"Adversarial perturbations of deep neural networks","author":"warde-farley","year":"2016","journal-title":"Advanced Structured Prediction"},{"key":"ref42","article-title":"Intriguing properties of neural networks","author":"szegedy","year":"2013"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2016.37"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1145\/2733373.2807412"},{"key":"ref43","doi-asserted-by":"crossref","first-page":"16","DOI":"10.1007\/978-3-319-30447-2_2","article-title":"Robustness of deep convolutional neural networks for image recognition","author":"ulicn\u00fd","year":"2016","journal-title":"Proc Int Symp Intell Comput Syst"}],"container-title":["IEEE Transactions on Information Forensics and Security"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/10206\/7990663\/07954632.pdf?arnumber=7954632","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,1,12]],"date-time":"2022-01-12T16:26:15Z","timestamp":1642004775000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/7954632\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2017,11]]},"references-count":53,"journal-issue":{"issue":"11"},"URL":"https:\/\/doi.org\/10.1109\/tifs.2017.2718479","relation":{},"ISSN":["1556-6013","1556-6021"],"issn-type":[{"value":"1556-6013","type":"print"},{"value":"1556-6021","type":"electronic"}],"subject":[],"published":{"date-parts":[[2017,11]]}}}