The only unbeatable test is one machines have never seen before.
The "human-proof test" behind CAPTCHA never really existed. Arkose Labs founder and CEO Kevin Gosschalk explains why economic disruption, not unsolvable puzzles, is what actually stops both human-driven and AI-powered attacks.
About the speaker
The concept of a CAPTCHA is meant to be something machines can't solve, which I think that concept is not achievable. Like anything a human can do, you can train the machine to do.
What we focus on is economic disruption. So if we can make the effort and cost of what they're trying to achieve higher than their profit reward, that is the entire strategy we take at Arkose.
We have challenge mechanisms, which are designed to be expensive to spend time, human labor attacks or machine vision attacks. There are no agentic AI systems that can get through everything that they've never seen before.
It doesn't conceptualize. And so if you present something to it that it's got no concept of, it doesn't know how to actually reason. It will try and brute force and things like that, but that's worse than basic attacks we see from attackers that build ML models and stuff.
The biggest irony, I think, is that the concept of a CAPTCHA is meant to be something machines can't solve, and I don't think that concept is achievable. Anything a human can do, you can train a machine to do. Even text CAPTCHAs, you can always train a machine to solve them. What we focus on instead is economic disruption — if we can make the effort and cost of what an attacker is trying to achieve higher than their profit reward, that's the entire strategy we take at Arkose. They'll go after the lower-hanging fruit, or ideally go get a real job instead.
We have challenge mechanisms which are designed to be expensive in terms of time, human labor attacks, or machine vision attacks. There are no agentic AI systems that can get through everything they've never seen before. The biggest solution to defeating a large multimodal model is to show it something novel that it hasn't been trained on — it doesn't know what to do with that.
At the end of the day, yes, we're highly emphasizing that it's AI, but really it's predictive text modeling. It's not intelligent, it doesn't conceptualize. So if you present something to it that it has no concept of, it doesn't know how to actually reason. It will try to brute force it, but that's worse than the basic attacks we see from attackers who build their own ML models. I think it's going to be that way for quite a while.