Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

Instead of replacing a CAPTCHA’s classifier with a larger model, Shiva Mani kept the existing Random Forest and added a memory layer that can bring prior security experiences into later decisions. The project, SwipeCHA, asks a user to slide a handle along a track and evaluates movement behavior. It is an implementation account and architectural proposal—not evidence that memory improves CAPTCHA accuracy.

What changes when a CAPTCHA can remember?

A conventional classifier evaluates the evidence from the interaction in front of it. Mani’s design adds a second question: “What does this swipe look like, and does it fit the security experiences I’ve already seen?” The Random Forest handles the current behavioral signal; Hindsight supplies recalled context; a Security Agent interprets that combination; and a decision policy determines what to do.

The distinction is between making the classifier itself more capable and changing the context in which its output is used. As Mani puts it, “The Random Forest didn’t suddenly become a better classifier. The decision became contextual.”

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How SwipeCHA evaluates a swipe

Ten behavioral features feed the existing classifier

While a person moves the slider, the browser records pointer movement and timing. The project describes deriving ten features for the Random Forest:

  • Average mouse speed
  • Mouse-path entropy
  • Click delay
  • Task-completion time
  • Idle time
  • Micro-jitter variance
  • Acceleration curve
  • Curvature variance
  • Overshoot-correction ratio
  • Timing entropy

These are behavioral observations about an interaction, not proof of who made it. The author’s stated boundary is direct: “Behavioral signals are not identity.”

Memory adds context; policy chooses an action

Mani describes Hindsight as the memory layer and the Security Agent as the component that interprets retrieved experiences alongside the current classifier result. The decision policy can allow the interaction, block it, or challenge the user again. For obvious automation, the design also describes a deterministic hard-rule path rather than relying on historical recall for every decision.

The components have different responsibilities: the classifier evaluates current features, memory retrieves relevant past security experiences, the agent interprets the combined information, and policy controls the resulting action. Hindsight’s official project documentation describes its core operations as retain, recall, and reflect: https://github.com/vectorize-io/hindsight. That documentation explains the memory layer’s general capabilities; it does not verify this integration or its security outcomes.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What gets remembered—and when

The system is intended to begin without fabricated history. On the first interaction, it makes a decision using current evidence; the resulting security experience can then be retained for possible use in a later interaction. Mani describes storing distilled security context rather than a dump of raw pointer coordinates and timestamps. A simplified example includes a prediction, confidence, risk level, reason codes, and recommended action.

This separation matters: retaining a compact account of a prior decision is not the same as retaining every movement measurement. However, the article does not provide a privacy impact assessment or specify a retention and deletion policy, so it does not establish how long stored information persists or how users can request its removal.

What the implementation account reports

Mani reports running a sequence of interactions, restarting the application, and then seeing historical memories recalled on later turns. The described development and staging setup used the official Hindsight client with a local Hindsight-compatible deployment; the account does not claim a verified Hindsight Cloud deployment. This is the author’s report, not an independently replicated test.

The article also describes fallback to the Random Forest path if Hindsight or the agent layer is unavailable or times out, with a circuit breaker intended to limit repeated latency from service failures. These are reported implementation features, not independently verified reliability results.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What the project does—and does not—show

The contribution is an architecture and implementation account: keep the model that evaluates live behavioral features, then add historical context and a controlled policy around its output. Mani explicitly says the notable result was not a new model-accuracy number.

The article gives no sample size, benchmark, baseline comparison, false-accept or false-reject rate, or measured improvement in accuracy. Its example confidence value of 0.98 is an illustrative system output, not a study result. It therefore does not establish that memory makes the CAPTCHA more accurate or secure.

Nor does consistency with prior behavior establish legitimacy. Mani cautions, “Historical consistency is not proof that an interaction is legitimate.” The account also does not provide a bias analysis, threat model, production audit, or quantitative security evaluation. Those omissions limit what can be concluded about real-world performance; they do not negate the architectural idea.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Why add memory rather than simply enlarge the model?

The proposal targets a different limitation from model capacity. A larger classifier could change how the system evaluates the current swipe; memory instead lets a later decision take prior security experiences into account. That can make the decision process contextual without claiming that the underlying Random Forest has become a better classifier.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The trade-off is an additional dependency and interpretation layer. Mani describes a fallback path when memory or the agent is unavailable, but the published account supplies no comparative latency, reliability, or security measurements. The design is therefore best understood as a way to structure contextual decisions—not as demonstrated evidence that this approach outperforms a larger model.

Source and scope

The project description and implementation claims are from Shiva Mani’s DEV Community article, published September 29, 2026: “I Gave a CAPTCHA Memory Instead of Making the Model Bigger.” Hindsight’s official documentation is available at the Vectorize Hindsight project. The account should be read as a description of one implementation, not an independent CAPTCHA evaluation.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.