Speed is not a good idea. I can be very fast to write something

(300 char/min + 10% of defects lol)
With a special number of <tab> characters, we could use autoit to spam a database... Too easy to perform...
Nevertheless, you can generate random fields...
Fields' names are stored in the database, a key is created in a session's array ($key, $image_name). After usage, database and session are cleaned up.
Random fields can be used only one time by one client...
But that would not block a bot which submits correctly the form... (just use autoit to discover how easy it is to do it)