<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta>
      <journal-title-group>
        <journal-title>GDPR - Automated individual decision-making, including profiling. General Data Protection
Regulation (GDPR).
 (March</journal-title>
      </journal-title-group>
    </journal-meta>
    <article-meta>
      <title-group>
        <article-title>The Reverse Turing Test: Being Human (is) enough in the Age of AI</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Fatemeh Alizadeh</string-name>
          <email>Fatemeh.alizadeh@uni-siegen.de</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Aikaterini Mniestri</string-name>
          <email>Aikaterini.Mniestri@student.uni-siegen.de</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Gunnar Stevens</string-name>
          <email>Gunnar.stevens@uni-</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>University of Siegen</institution>
          ,
          <addr-line>Siegen</addr-line>
          ,
          <country country="DE">Germany</country>
        </aff>
      </contrib-group>
      <pub-date>
        <year>2022</year>
      </pub-date>
      <volume>27</volume>
      <issue>2022</issue>
      <fpage>49</fpage>
      <lpage>54</lpage>
      <abstract>
        <p>Disposing of bad actors on social media is a daunting task, particularly in the face of “engineered social tampering” [4]. That is what Ferrara et al. [6] have labeled the rise of social bots, and large platform owners are struggling to mitigate the harmful effects caused by such malicious software. Therefore, it is no surprise that platform owners like META are fastening their security controls and that the popular press has tracked the efficacy of these measures. Specifically, META has been implementing what Forbes' Lance Eliot named the 'Upside Down Turing Test.' [26]. Unlike the original Turing test, which tasked a human participant with distinguishing a human from a digital speech correspondent, this version is designed to use a software program to distinguish non-human activity on the platform. In this work, we discuss the complications introduced by this reversal taking the human user's perspective. On the one hand, we recognize the necessity for fraud detection and defense against webautomated attacks. On the other hand, we find it necessary to uplift the voices of users who are wrongfully made victims as a result, in minor or major ways. At the same time, we offer alternatives to these invisible Reverse Turing Tests (RTTs) that expand the scope for distinguishing between human and non-human actors, while keeping humanity at the forefront of this inquiry.</p>
      </abstract>
      <kwd-group>
        <kwd>1 Reverse Turing Test</kwd>
        <kwd>CAPTCHA</kwd>
        <kwd>Bot detection</kwd>
        <kwd>User-centered design</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>1. Introduction</title>
      <p>
        The advent of the age of computers set forth a new horizon of exploration for artificial intelligence (AI).
Ever since, researchers and industry have dedicated ample resources to investigate the question: Can
machines think? Famously, the Turing Test, originated in 1950 by Alan Turing, was meant to assess
the extent to which a digital computer could ‘pass’ as human through a knock off of the three-person
party pastime, the "imitation game.” [27]. In Turing’s version, a human evaluator is meant to judge
natural language conversations between a human and a machine developed to generate human-like
responses. To be clear, Turing does not claim to answer the original question of whether machines are
indeed, capable of thinking. Instead, he asks: can machines do what we (as thinking entities) can do?
Thus, he not only does he distinguish between the physical and intellectual capacities of a man, as he
proposed, but also sets the precedent for this workshop paper by emphasizing that machinic 'thought'
ultimately serves a purpose for human users. That is to say, when the tables turn and computers are
tasked with recognizing human from non-human behavior, humanity itself should be a part of this
equation in all of its diversity and complexity. In this workshop paper, we pay respect to the evolving
discourse around the Reverse Turing Test (RTT) [
        <xref ref-type="bibr" rid="ref1 ref4">1, 4</xref>
        ], the concept that a machine is capable of
recognizing human behavior in digital systems, to critique recent attempts to distinguish users from
social bots on Instagram. For the purpose of this paper, social bots refer to computer algorithms that
automatically produce content and interact with human actors on social media, trying to emulate and
possibly alter their behavior [
        <xref ref-type="bibr" rid="ref4">4</xref>
        ]. Social bots have populated social media platforms for the past few
years. We seek to understand the arguments for reverse Turing tests (RTT) in the current social media
landscape, particularly in relation to the invisible bot detection algorithms referred to by Google as
reCAPTCHA (Completely Automated Public Turing Tests to Tell Computers and Humans Apart), and
we counter them with academic literature that centers on users’ negative experiences with these
algorithms. As a result, we rely on literature from New Media and Human Computer Interaction (HCI)
to propose alternatives to standardized reCAPTCHAs that are more inclusive and user-centric.
      </p>
      <p>This paper comes together in five sections. To begin with, we briefly provide some historical context
by presenting an abbreviated history of the RTT. We then go into more detail about reCAPTCHAs and
practices of invisible user tracking, and then specifically address the RTT algorithms enforced by
Instagram. This leads us to the following section, which explores the user perspective on these security
practices. We focus on users' gripes with these algorithms, which show that Instagram's fight against
non-human interaction has real consequences for human users. As a result, we offer a series of
alternatives, delineated in recent literature from the fields of HCI and New Media positioning ourselves
firmly on the side of the user while also still acknowledging the need to maintain social media free of
bad actors.
1.1.</p>
    </sec>
    <sec id="sec-2">
      <title>History of the Reverse Turing Test</title>
      <p>
        The idea of repurposing the Turing test for curbing undesirable online interactions, was first proposed
in an unpublished draft by Naor, who outlined a solution to the growing problem of online spam
clogging free services such as email [
        <xref ref-type="bibr" rid="ref20">20</xref>
        ]. Naor suggested that users requesting access should first be
given content identification tasks, such as "gender recognition" or "nudity detection" in images, to
distinguish them from malicious actors. In the late 1990s, these tasks could easily confuse the relatively
unsophisticated bots, but were "unambiguous" to humans [
        <xref ref-type="bibr" rid="ref19">19</xref>
        ]. A year later, the first practical example
of a CAPTCHA scheme was developed to safeguard an online poll in advance of an upcoming
presidential election [
        <xref ref-type="bibr" rid="ref11">11</xref>
        ]. The goal of CAPTCHA was to prevent the manipulation of election results
by creating distorted texts and distinguishing humans from machines [
        <xref ref-type="bibr" rid="ref15">15</xref>
        ]. Building upon this, Baird et
al. introduced RTT, a test in which “a program challenges the user with one synthetically generated
image of a text and the user must type the text correctly to pass”[
        <xref ref-type="bibr" rid="ref3">3</xref>
        ]. This definition of RRT is based
on the premise that text recognition tasks can overwhelm sophisticated bots and distinguish them from
human users. However, in light of new advanced bots that solve even the most difficult traditional
CAPTCHAs with a 99.8% hit rate [
        <xref ref-type="bibr" rid="ref10">10</xref>
        ], this premise is no longer tenable.
      </p>
      <p>
        To address this issue, Google introduced the No CAPTCHA reCAPTCHA system, which is based
on an advanced risk analysis engine that takes into account how users interact with CAPTCHA
verifications [
        <xref ref-type="bibr" rid="ref12">12</xref>
        ]. Users only need to check the "I'm not a robot" box and will be verified without having
to solve a CAPTCHA, if the risk analysis engine determines that the user is human. Otherwise, they are
presented with an image-based challenge or a traditional text-based CAPTCHA to verify their identity.
Previously, researchers have pointed out the shortcomings of this system (e.g., [
        <xref ref-type="bibr" rid="ref2 ref24">2, 24</xref>
        ]). For example,
such a system can easily be tricked into thinking a program is human, or can become ineffective when
Google web cookies are deleted or JavaScript is disabled [
        <xref ref-type="bibr" rid="ref2">2</xref>
        ]. Therefore, Google has recently improved
this mechanism and made it completely invisible. The new "Invisible reCAPTCHA" service is based
on the same technology as "No CAPTCHA reCAPTCHA", only without the “I’m not a robot”
checkbox. Instead, Google “invisibly analyzes the way users navigate through a website and assigns
them a risk score based on how malicious their behavior is” [
        <xref ref-type="bibr" rid="ref12">12</xref>
        ]. Invisible reCAPTCHAs eliminate the
disruption caused by challenging CAPTCHAs, creating a more positive experience for users. As a
result, more and more organizations are deploying invisible audits of activity on their platform.
      </p>
      <p>
        Therefore, with this evolution of bots and AI technology, the construct of RTTs has also evolved
from simple text recognition CAPTCHAs to complicated AI-invisible behavior tracking and
discrepancy assessment between human and machine behavior [
        <xref ref-type="bibr" rid="ref9">9</xref>
        ]. In the following section, we take a
closer look at these new forms of invisible RTTs to detect non-human activities on social media
platforms and their consequences.
1.2.
      </p>
    </sec>
    <sec id="sec-3">
      <title>New forms of the Reverse Turing Test</title>
      <p>
        Social bots populate social media platforms (Facebook, Twitter, Instagram etc.) en masse [
        <xref ref-type="bibr" rid="ref1">1</xref>
        ].
According to a 2018 study by Ghost Data, nearly 95 million Instagram accounts are automated [
        <xref ref-type="bibr" rid="ref13">13</xref>
        ]. In
2016, bots produced more internet traffic than humans [
        <xref ref-type="bibr" rid="ref5">5</xref>
        ]. Social bots have been used to undermine
political discourse, manipulate the stock market, steal personal data, and spread fake news [
        <xref ref-type="bibr" rid="ref6">6</xref>
        ].
Therefore, detecting social bots is an important research goal. But social bots are becoming more skilled
by the day, and the line between human-like and bot-like behavior is becoming more blurred [
        <xref ref-type="bibr" rid="ref1 ref13">1, 13</xref>
        ].
Today, they engage in more complicated types of interactions, whether discussing with other humans,
commenting on their posts, or responding to their questions [
        <xref ref-type="bibr" rid="ref6">6</xref>
        ]. What makes the problem worse is that
fake engagement is not only caused by bots, but also by fake accounts. Unlike bots, fake accounts do
not improve their own metrics but those of other users, creating an unhealthy and inorganic environment
[
        <xref ref-type="bibr" rid="ref1">1</xref>
        ]. Because of the increasing number of bots on Instagram, the company is accused of not doing enough
to detect them [
        <xref ref-type="bibr" rid="ref13">13</xref>
        ].
      </p>
      <p>
        To address these challenges, Instagram uses automated bot detection systems [
        <xref ref-type="bibr" rid="ref18 ref22">18, 22</xref>
        ] or "automated
technologies" that help "ensure the functionality and integrity of the service," as stated in Instagram's
Terms of Use [25]. Although the company does not disclose the inner workings of such bot detection
systems, ostensibly to protect the systems from malicious actors, these mechanisms have been shown
to use AI-based technologies (also referred to as reCAPTCHA) to invisibly track user interactions and
apply necessary authenticity measures when a pattern of potentially inauthentic behavior is detected
[
        <xref ref-type="bibr" rid="ref18">18</xref>
        ]. Authenticity measures on Instagram range from asking users to confirm their accounts, to
temporarily blocking their actions, to permanently disabling accounts [
        <xref ref-type="bibr" rid="ref14">14</xref>
        ]. As useful and necessary as
these mechanisms are, they are not without cost. Previous studies have shown that in some cases human
users are blocked due to an error in these mechanisms (the so-called false positive error)[
        <xref ref-type="bibr" rid="ref22">22</xref>
        ], with no
way to challenge or change the algorithmic decision. Considering that social media echo systems are
already pointing in the direction of environments where interaction between machines is the norm and
humans are navigating a world that is predominantly populated by them, the application of such bot
detection mechanisms raises several concerns about the potential consequences of such control for users
and society at large, as well as the redefinition of the term human as opposed to machine in future social
media environments.
1.3.
      </p>
    </sec>
    <sec id="sec-4">
      <title>The risks and consequences of the invisible RTT</title>
      <p>
        Judging by the statements of major platform owners, the new generation of bot detection and
suppression algorithms does not compromise the usability of social media platforms. Google introduces
its latest associated product, reCAPTCHA Enterprise, with the advertisement that it is “a frictionless
user experience, where fraud protection is easily extended across websites” [
        <xref ref-type="bibr" rid="ref23">23</xref>
        ]. However, despite
their effectiveness, these seamless and invisible mechanisms still raise a number of issues under the
General Data Protection Regulation (GDPR). Mainly because they collect loads of personal data from
users without proper notification and consent [
        <xref ref-type="bibr" rid="ref8">8</xref>
        ].
      </p>
      <p>
        Introducing new measures to counter coordinated inauthentic behavior, Instagram users are also
led to believe that the transition to reCAPTCHA is only to bring benefits for them both in terms of
security and usability [
        <xref ref-type="bibr" rid="ref14">14</xref>
        ]. Nevertheless, as time goes by, it seems like this promise has not been
fulfilled on two levels. Firstly, users still struggle with the automatic bot detection mechanism, and
secondly, there are bad actors causing friction associated with the authentication processes within
platforms after the fact: on Instagram, the uphill battle begins once a user loses access to their account.
Once the algorithm has flagged their content, users, especially those who entrepreneurialise through the
platform in the form of promotions and sponsorship deals, are approached by ‘dealers.’ These dealers
offer creators an opportunity to recover their accounts for a price. Whereas some of them are merely
scammers, others inexplicably have enough access in Instagram’s moderation infrastructure to restore
one’s account and ‘right’ any algorithmically decided wrongs [28].
      </p>
      <p>
        Last but not least, Simone Natale asserts that AI scientists “have incorporated knowledge about
users into their efforts to build meaningful and effective interactions between humans and
machines.”[
        <xref ref-type="bibr" rid="ref21">21</xref>
        ]. That is to say, the author implores for us to understand deception as an integral part of
AI technologies. So, if we reverse the roles, in an RTT the computer is also encouraged to assume
deception, to always be suspicious that there is no human end user on the other side but rather, another
software, and malicious software at that. This is a sentiment that is built into the authentication systems
of dominant social media platforms like Instagram. Their 2020 statement on authentication reads:“If
we see signs of potential inauthentic activity, we will require the account holder to confirm who they
are, and once an account holder verifies their information, their account will function as usual unless
we have reason to investigate further.” [
        <xref ref-type="bibr" rid="ref14">14</xref>
        ]
      </p>
      <p>
        This incriminates the user and puts the onus on them to prove that they are not guilty. Only, in this
case, not being guilty means that they must prove their own humanity. Similarly, Myers West argues
that “automatic bans presume that users both intended to break the rules and are thus unable to learn
how to do better” [
        <xref ref-type="bibr" rid="ref18">18</xref>
        ]. She points out that the appeals process on Instagram fails to educate users on
the reason for their misconduct and deprives them of the opportunity to reclaim their agency. In fact,
users experience a range of negative emotions when they challenge the bot detection algorithm's
decision, including anger, frustration, and, more importantly, dehumanization.
1.4.
      </p>
    </sec>
    <sec id="sec-5">
      <title>The alternatives to invisible reCAPTCHA bot detection</title>
      <p>As mentioned above, the invisibility and seamlessness of reCAPTCHA and bot detection algorithms
raise serious doubts when it comes to the fairness, transparency and accountability of such systems, as
well as users’ rights and control over the data being collected. In this section, we review some potential
alternative approaches from the literature that have been introduced to address the challenges posed by
the invisibility of reCAPTCHAs.</p>
      <p>
        Frischmann [
        <xref ref-type="bibr" rid="ref7">7</xref>
        ] proposed a first set of human-focused RTT to investigate different aspects of
intelligence and distinguish humans from bots. He refers to common sense, and rationality as human
characteristics that can be used for generating RTT based on the notions of what it means to be human.
He argued that a common sense (rational) test “could employ a structure similar to the conventional
Turing test, and the observer could ask questions that would require the skillful use of common sense
(rationality).” By addressing human bias and judgement errors, especially when there is not one "right"
answer, he touches on a similar idea as using humans' perception capabilities for generating distorted
text CAPTCHAs.
      </p>
      <p>
        In a similar vein, Massey [
        <xref ref-type="bibr" rid="ref17">17</xref>
        ] argues for an approach to AI tests that is based on the discipline of
aesthetics rather than technology. In his work, he proposes the ‘metaphor to nonsense’ transition. He
proposes that the human mind can read metaphorical meaning into what is essentially a nonsensical
phrase. He then argues that, even if a computer is trained to recognize metaphors, it will not be able to
make the transition to viewing a particular metaphor as nonsense, at will. There is no logical transition
from the metaphor to nonsense, which means that the AI would be faced with an insurmountable
adversarial object. This paper does not merely center the user, but the humanity of the user.
      </p>
      <p>However, despite the aforementioned promising proposals for human-focused RTTs and the
concerns raised by the new forms of RTTs, research on alternative RTTs has so far remained at a
conceptual level. In the following section, we look at this challenge through an HCI lens to see how
these concepts can be operationalized in practice.
1.5.</p>
    </sec>
    <sec id="sec-6">
      <title>Towards a user-centered RTT</title>
      <p>
        If the question raised by RTTs is how AI can be up to the task of distinguishing human activity from
non-human activity on the Internet in a user-friendly manner, then the main idea of invisible
reCAPTCHA and bot detection algorithms as a solution is to eliminate the question rather than provide
an effective answer. Mainly because users, as the main affected parties of algorithmic decision making,
have the right to be aware that they are being evaluated by an algorithm[29]. Therefore, the current
invisible RTT mechanisms does not meet the requirement of transparency and are also not in
compliance with the GDPR. As an alternative, we propose to apply the HCI method by involving users
in a user-centered design (UCD) cycle. As “a multidisciplinary design approach based on the active
involvement of users to improve the understanding of user and task requirements” [
        <xref ref-type="bibr" rid="ref16">16</xref>
        ], UCD allows
users not only to be aware of the test, but also to play an active and participatory role in the testing
process. As we saw in Section 1.4, the human essence of users can inspire new creative ways to
approach the RTT design process that leverage the aesthetic, intellectual capabilities of humans. We
therefore propose the application of UCD to these techniques in order to put them into practice and
create new forms of testing that are as diverse as they are potentially fun.
      </p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          [1]
          <string-name>
            <surname>Akyon</surname>
            ,
            <given-names>F.C.</given-names>
          </string-name>
          and
          <string-name>
            <surname>Kalfaoglu</surname>
            ,
            <given-names>M.E.</given-names>
          </string-name>
          <year>2019</year>
          .
          <article-title>Instagram fake</article-title>
          and
          <source>automated account detection</source>
          .
          <source>2019 Innovations in Intelligent Systems and Applications Conference (ASYU)</source>
          (
          <year>2019</year>
          ),
          <fpage>1</fpage>
          -
          <lpage>7</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          [2]
          <string-name>
            <surname>Al-Fannah</surname>
            ,
            <given-names>N.M.</given-names>
          </string-name>
          <year>2019</year>
          .
          <article-title>Using Aesthetic Judgements to Distinguish between Humans and Computers</article-title>
          . arXiv:
          <volume>1704</volume>
          .02972 [cs].
          <source>(Jul</source>
          .
          <year>2019</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          [3]
          <string-name>
            <surname>Baird</surname>
            ,
            <given-names>H.S.</given-names>
          </string-name>
          et al.
          <year>2003</year>
          .
          <article-title>Pessimalprint: a reverse turing test</article-title>
          .
          <source>International Journal on Document Analysis and Recognition. 5</source>
          ,
          <issue>2</issue>
          (
          <year>2003</year>
          ),
          <fpage>158</fpage>
          -
          <lpage>163</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          [4]
          <string-name>
            <surname>Boshmaf</surname>
            ,
            <given-names>Y.</given-names>
          </string-name>
          et al.
          <year>2013</year>
          .
          <article-title>Design and analysis of a social botnet</article-title>
          .
          <source>Computer Networks</source>
          .
          <volume>57</volume>
          ,
          <issue>2</issue>
          (
          <year>2013</year>
          ),
          <fpage>556</fpage>
          -
          <lpage>578</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          [5]
          <string-name>
            <surname>Efthimion</surname>
            ,
            <given-names>P.G.</given-names>
          </string-name>
          et al.
          <year>2018</year>
          .
          <article-title>Supervised machine learning bot detection techniques to identify social twitter bots</article-title>
          .
          <source>SMU Data Science Review. 1</source>
          ,
          <issue>2</issue>
          (
          <year>2018</year>
          ),
          <fpage>5</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          [6]
          <string-name>
            <surname>Ferrara</surname>
            ,
            <given-names>E.</given-names>
          </string-name>
          et al.
          <year>2016</year>
          .
          <article-title>The rise of social bots</article-title>
          .
          <source>Communications of the ACM. 59</source>
          ,
          <issue>7</issue>
          (
          <year>2016</year>
          ),
          <fpage>96</fpage>
          -
          <lpage>104</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          [7]
          <string-name>
            <surname>Frischmann</surname>
            ,
            <given-names>B.M.</given-names>
          </string-name>
          <year>2014</year>
          .
          <article-title>Human-focused Turing tests: A framework for judging nudging and techno-social engineering of human beings</article-title>
          .
          <source>Cardozo Legal Studies Research Paper</source>
          .
          <volume>441</volume>
          (
          <year>2014</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          [8]
          <string-name>
            <surname>GDPR</surname>
          </string-name>
          &amp;
          <article-title>Recaptcha: How to stay compliant with GDPR: 2021</article-title>
          . https://measuredcollective.com/gdprrecaptcha-how
          <article-title>-to-stay-compliant-with-gdpr/</article-title>
          . Accessed:
          <fpage>2022</fpage>
          -03-27.
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          [9]
          <string-name>
            <surname>Gonzalez</surname>
            ,
            <given-names>A.V.</given-names>
          </string-name>
          and
          <string-name>
            <surname>Søgaard</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          <year>2020</year>
          .
          <article-title>The reverse turing test for evaluating interpretability methods on unknown tasks</article-title>
          .
          <source>NeurIPS Workshop on Human And Machine in-the-Loop Evaluation and Learning Strategies</source>
          (
          <year>2020</year>
          ),
          <fpage>62</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          [10]
          <string-name>
            <surname>Goodfellow</surname>
            ,
            <given-names>I.J.</given-names>
          </string-name>
          et al.
          <year>2014</year>
          .
          <article-title>Multi-digit Number Recognition from Street View Imagery using Deep Convolutional Neural Networks</article-title>
          .
          <source>arXiv:1312</source>
          .6082 [cs].
          <source>(Apr</source>
          .
          <year>2014</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          [11]
          <string-name>
            <surname>Guerar</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          et al.
          <year>2021</year>
          .
          <article-title>Gotta CAPTCHA'Em all: a survey of 20 Years of the human-or-computer Dilemma</article-title>
          .
          <source>ACM Computing Surveys (CSUR)</source>
          .
          <volume>54</volume>
          ,
          <issue>9</issue>
          (
          <year>2021</year>
          ),
          <fpage>1</fpage>
          -
          <lpage>33</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          [12]
          <string-name>
            <surname>Guerar</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          et al.
          <year>2018</year>
          .
          <article-title>Invisible CAPPCHA: A usable mechanism to distinguish between malware and humans on the mobile IoT</article-title>
          .
          <source>computers &amp; security. 78</source>
          , (
          <year>2018</year>
          ),
          <fpage>255</fpage>
          -
          <lpage>266</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          [13]
          <string-name>
            <surname>Instagram's Growing</surname>
          </string-name>
          Bot Problem: https://www.theinformation.com/articles/instagrams-growing-botproblem.
          <source>Accessed: 2022-03-26.</source>
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          [14] Introducing New Authenticity Measures on Instagram: https://about.instagram.com/blog/announcements/introducing
          <article-title>-new-authenticity-measures-on-instagram</article-title>
          .
          <source>Accessed: 2022-03-26.</source>
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          [15]
          <string-name>
            <surname>Kochanski</surname>
            ,
            <given-names>G.</given-names>
          </string-name>
          et al.
          <year>2002</year>
          .
          <article-title>A reverse turing test using speech</article-title>
          . (
          <year>2002</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          [16]
          <string-name>
            <surname>Mao</surname>
          </string-name>
          , J.-Y. et al.
          <year>2005</year>
          .
          <article-title>The state of user-centered design practice</article-title>
          .
          <source>Communications of the ACM. 48</source>
          ,
          <issue>3</issue>
          (
          <year>2005</year>
          ),
          <fpage>105</fpage>
          -
          <lpage>109</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref17">
        <mixed-citation>
          [17]
          <string-name>
            <surname>Massey</surname>
            ,
            <given-names>I.</given-names>
          </string-name>
          <year>2021</year>
          .
          <article-title>A new Turing test: metaphor vs</article-title>
          . nonsense.
          <source>AI &amp; SOCIETY. 36</source>
          ,
          <issue>3</issue>
          (Sep.
          <year>2021</year>
          ),
          <fpage>677</fpage>
          -
          <lpage>684</lpage>
          . DOI:https://doi.org/10.1007/s00146-021-01242-9.
        </mixed-citation>
      </ref>
      <ref id="ref18">
        <mixed-citation>
          [18]
          <string-name>
            <given-names>Myers</given-names>
            <surname>West</surname>
          </string-name>
          ,
          <string-name>
            <surname>S.</surname>
          </string-name>
          <year>2018</year>
          .
          <article-title>Censored, suspended, shadowbanned: User interpretations of content moderation on social media platforms</article-title>
          .
          <source>New Media &amp; Society</source>
          .
          <volume>20</volume>
          ,
          <issue>11</issue>
          (
          <year>2018</year>
          ),
          <fpage>4366</fpage>
          -
          <lpage>4383</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref19">
        <mixed-citation>
          [19]
          <string-name>
            <surname>Naor</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          <year>1996</year>
          .
          <article-title>Verification of a human in the loop or Identification via the Turing Test</article-title>
          . Unpublished draft from http://www. wisdom. weizmann. ac. il/∼ naor/PAPERS/human abs. html. (
          <year>1996</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref20">
        <mixed-citation>
          [20]
          <string-name>
            <surname>Naor</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          and
          <string-name>
            <surname>Shamir</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          <year>1995</year>
          .
          <article-title>Visual cryptography</article-title>
          .
          <source>Advances in Cryptology - EUROCRYPT'94</source>
          (Berlin, Heidelberg,
          <year>1995</year>
          ),
          <fpage>1</fpage>
          -
          <lpage>12</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref21">
        <mixed-citation>
          [21]
          <string-name>
            <surname>Natale</surname>
            , S.L. in C. and
            <given-names>M.S.S.</given-names>
          </string-name>
          and
          <string-name>
            <surname>Natale</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          <year>2021</year>
          .
          <article-title>Deceitful Media: Artificial Intelligence and Social Life After the Turing Test</article-title>
          . Oxford University Press.
        </mixed-citation>
      </ref>
      <ref id="ref22">
        <mixed-citation>
          [22]
          <string-name>
            <surname>Rauchfleisch</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          and
          <string-name>
            <surname>Kaiser</surname>
            ,
            <given-names>J.</given-names>
          </string-name>
          <year>2020</year>
          .
          <article-title>The false positive problem of automatic bot detection in social science research</article-title>
          .
          <source>PloS one</source>
          .
          <volume>15</volume>
          ,
          <issue>10</issue>
          (
          <year>2020</year>
          ),
          <year>e0241045</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref23">
        <mixed-citation>
          [23] reCAPTCHA: https://www.google.com/recaptcha/about/. Accessed:
          <fpage>2022</fpage>
          -03-27.
        </mixed-citation>
      </ref>
      <ref id="ref24">
        <mixed-citation>
          [24]
          <string-name>
            <surname>Sivakorn</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          et al.
          <article-title>Sivakorn: I'm not a human: Breaking the Google reCAPTCHA</article-title>
          .
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>