In plain words: An AI agent learns to move and click the mouse to earn a high reCAPTCHA v3 score, stepping across a grid of cells; splitting the path into small chunks works at any grid size. It passed 97.4% of attempts; big steps toward the goal did worse.
Abstract · Hacking Google reCAPTCHA v3 using Reinforcement Learning
We present a Reinforcement Learning (RL) methodology to bypass Google reCAPTCHA v3. We formulate the problem as a grid world where the agent learns how to move the mouse and click on the reCAPTCHA button to receive a high score. We study the performance of the agent when we vary the cell size of the grid world and show that the performance drops when the agent takes big steps toward the goal. Finally, we used a divide and conquer strategy to defeat the reCAPTCHA system for any grid resolution. Our proposed method achieves a success rate of 97.4% on a 100x100 grid and 96.7% on a 1000x1000 screen resolution.
Ismail Akrout, Amal Feriani, Mohamed Akrout
arXiv:1903.01003 · cs.LG, cs.AI · submitted Mar 3, 2019 · updated Apr 18, 2019
abstract · pdf · html · Accepted for the Conference on Reinforcement Learning and Decision Making (RLDM) 2019
The problem they're solving with RL isn't the "click the tiles with the stop sign" its the "click the checkbox to prove you're a human". The token score is mainly derived from your env (medium impact on score), google cookies (high impact on score), and IP quality (high impact on score). Mouse movement is barely factored in at all, and can be ignored for botting purposes.
So for now, there's no added value here over the status-quo real-world solution. That said, for future systems which use more behavioral analysis, this research might be helpful.