Rendering on Real Silicon: GPU Render-Timing as a Passive, AI-Resistant CAPTCHA Signal

📅 2026-07-25
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
This work addresses the vulnerability of traditional CAPTCHAs to AI-based attacks and the privacy or cost drawbacks of existing behavioral or cryptographic verification schemes. The authors propose a passive verification mechanism that leverages client-side GPU timing behavior under controlled WebGL rendering workloads. By analyzing dynamic timing features—such as frame jitter and coefficient of variation—the method distinguishes human users from automated scripts without relying on persistent device identifiers, thereby mitigating long-term privacy risks. This approach pioneers the use of GPU rendering timing dynamics as a CAPTCHA signal and demonstrates strong efficacy in real hardware settings: software-rendered requests exhibit average execution times approximately five times longer than those on genuine GPUs, and under identical hardware and software conditions, headless browsers differ from human-driven interactions by 75–106% across key timing metrics.
📝 Abstract
Conventional CAPTCHAs pose puzzles that modern AI systems increasingly solve, while behavioral and cryptographic-attestation defenses carry privacy or enrollment costs. We investigate an orthogonal signal: the physical timing behavior of a client's GPU under a controlled WebGL rendering workload. Unlike WebGL fingerprinting, which hashes pixel output into a static device identifier, we measure render-timing dynamics to classify rather than identify, leaking no persistent identifier. We characterize the in-the-wild adversary with a 12-hour passive deployment (207 unsolicited requests; 86% automated; 85% of browser-claiming clients failed HTTP header-consistency checks). We then collect labeled GPU-timing samples through a single public endpoint exercised by real browsers (positive class, 13 distinct GPUs) and by keyed headless automation across a render-backend matrix (negative class). Software-rendered automation -- empirically the dominant real-world adversary -- separates from genuine GPUs by roughly 5x in mean render time. On a confound-controlled comparison (identical GPU family and browser engine, differing only in headless vs. interactive execution), headless automation on real hardware still exhibits a distinct timing signature, separating from human samples by 75-106% on frame jitter, timer-quantization ratio, and coefficient of variation. We report these as pilot-scale findings on a single GPU architecture and outline the cross-architecture collection required to establish generalization.
Problem

Research questions and friction points this paper is trying to address.

CAPTCHA
AI-resistant
GPU render-timing
WebGL
bot detection
Innovation

Methods, ideas, or system contributions that make the work stand out.

GPU render-timing
passive CAPTCHA
WebGL timing dynamics
headless browser detection
AI-resistant authentication
🔎 Similar Papers
No similar papers found.