The Granular Gambit: Checkmating Behavior-based CAPTCHAs
Abstract
Behavior-based CAPTCHAs such as Google reCAPTCHA v3 enable frictionless verification by assigning risk scores from fine-grained user interaction traces. Prior studies, however, largely rely on coarse-grained analyses and fail to capture the atomic behavioral signals underlying v3’s scoring mechanism. This work examines whether agentic AI can synthesize human-like low-level interactions to obtain high trust scores and bypass reCAPTCHA v3. The problem is formulated as sequential decision-making over atomic behaviors, and Seqion, an LLM-driven agentic framework for fine-grained web interaction execution, is introduced. Experiments on a controlled reCAPTCHA v3 testbed, including registration, forum posting, and content reading tasks, show that agentic AI can consistently increase trust scores and achieve up to a 90% bypass success rate, even without domain-specific knowledge. Furthermore, evaluations on an external, real-world website reveal that Seqion achieves a mean trust score of 0.60, significantly outperforming the state-of-the-art baseline of 0.34 and closely approximating the genuine human average of 0.69. These results expose fundamental limitations of frictionless CAPTCHA systems under rapidly advancing agentic AI.
Then back it, or bet against it.
Related papers
Open the market on this paper to see 7 more related papers.