A multi-modal anti-counterfeiting verification method and terminal based on microstructure cross-spectrum scattering stability and trusted computing
By establishing hardware isolation links and cross-spectral spatial alignment within a secure execution environment, and combining microstructural features and illumination consistency judgment, the attack defense and forgery identification problems of multimodal verification technology are solved, achieving highly reliable anti-counterfeiting verification.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- 深圳市元明科技股份有限公司
- Filing Date
- 2026-04-01
- Publication Date
- 2026-07-03
AI Technical Summary
Existing multimodal verification technologies cannot defend against low-level video stream injection attacks from virtual cameras, have difficulty identifying realistic images generated by AIGC but lacking physical reflection characteristics, and have difficulty distinguishing between high-definition screen re-enactments and high-precision model material forgery methods.
By establishing a hardware-isolated control link within a secure execution environment, the thermal pixel distribution of dark frames is directly written into the image sensor register. Cross-spectral spatial alignment is performed by combining visible light and lidar data to extract microstructural features, and a comprehensive judgment is made using normalized mutual information and illumination consistency determination functions.
It achieves resistance to low-level attacks, can identify realistic forged images, maintains high credibility in complex environments, and possesses rigorous mathematical interpretability and robustness.
Smart Images

Figure CN122336449A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the fields of computer vision forensics, multimodal anti-counterfeiting, and trusted computing technologies, specifically to a multimodal anti-counterfeiting verification method and terminal based on microstructure transspectral scattering stability and trusted computing. Background Technology
[0002] With the development of financial lending and asset digitization, remote asset verification has become a crucial business process. However, existing verification technologies primarily rely on single-mode image acquisition and two-dimensional visual feature determination, which have the following technical shortcomings in practical applications:
[0003] Vulnerable to low-level data stream injection attacks: Existing systems typically call standard operating system APIs to obtain video streams. Attackers can hijack the data stream at the driver or framework layer using virtual cameras or hooking techniques, injecting pre-made fake videos, causing the verification data received by the application layer to not come from real physical sensors.
[0004] Deep forgeries generated by generative artificial intelligence (AIGC) are difficult to detect: With the development of generative models, AIGC-generated images have become close to real photos in terms of high-frequency texture and low-frequency semantics in two-dimensional pixel space. These images are essentially fittings of pixel statistical regularities and do not possess the material reflection properties and three-dimensional lighting regularities of real physical space. However, existing anti-forgery algorithms based on image statistical features have difficulty effectively distinguishing them.
[0005] Insufficient depth of multimodal fusion: Some existing technologies attempt to introduce depth cameras or lidar for auxiliary defense, but they are mostly limited to macroscopic 3D shape stitching or simple depth threshold determination. They lack the strict spatial alignment of heterogeneous sensors at the micro-pixel level and the deep fusion of cross-spectral physical scattering mechanisms, making them easy to bypass by physical forgery methods such as high-precision physical models or high-definition screen re-photographing. Summary of the Invention
[0006] The technical problem to be solved by this invention is to address the following deficiencies in existing multimodal verification technologies:
[0007] 1. Unable to defend against low-level video stream injection attacks based on virtual camera (Hook);
[0008] 2. It is difficult to identify AIGC deepfake images with extremely realistic visual textures but lacking physical reflection properties;
[0009] 3. It is difficult to distinguish between physical material forgery methods such as high-definition screen re-photographing and high-precision model painting. Therefore, a multimodal anti-counterfeiting verification method and terminal based on microstructure transspectral scattering stability and reliable calculation is provided.
[0010] The technical solution adopted by the present invention to solve the above-mentioned technical problems is as follows:
[0011] On the one hand, this invention provides a multimodal anti-counterfeiting verification method based on the transspectral scattering stability and reliable calculation of microstructure, comprising the following steps:
[0012] Step S1, Establishing a Hardware Physical Anchor: A hardware-isolated control link directly connecting to the image sensor is established within the Secure Execution Environment (TEE), and the physical addressing path of the ordinary operating system is cut off by configuring TZASC. During verification startup, the TEE generates register instructions containing extreme exposure parameters of less than 1 microsecond and a maximum analog gain of greater than 24dB, which are directly written to the image sensor register via a secure I2C channel; the dark frames output by the image sensor under the extreme parameters, without being processed by the operating system, are captured, and the thermal pixel distribution of the dark frames is extracted as the measured hardware physical fingerprint of dark current fixed mode noise (DSNU).
[0013] Step S2, cross-spectral spatial alignment: Simultaneously acquire visible light image data and lidar point cloud data of the target surface; based on the pre-calibrated intrinsic parameter matrix K of the visible light image sensor and the extrinsic parameter matrix [R|T] between the sensor and the lidar, project the three-dimensional laser point cloud onto the two-dimensional pixel coordinate system of the visible light image using the reprojection matrix formula, and use bilinear interpolation to generate a dense infrared reflectivity distribution field corresponding to the pixel level of the visible light image; thereby generating a cross-spectral data source with strict alignment between depth and echo intensity.
[0014] Step S3, extract transspectral micro features: use the Scharr edge detection operator to extract the high-frequency brightness components of the aligned visible light image to generate a visible light texture gradient field; calculate the standard deviation of the aligned infrared reflectance distribution field within a local sliding window to generate an infrared intensity physical texture.
[0015] Step S4, calculate physical scattering invariant: Within a local sliding window of a preset size, extract the joint grayscale histogram distribution of the visible light texture gradient field and the infrared intensity physical texture, and calculate the normalized mutual information (NMI) of the two; use the normalized mutual information value as the transspectral scattering invariant characterizing the physical stability of the target material's microstructure.
[0016] Step S5, Macroscopic Illumination Consistency Estimation: Based on the aligned local point cloud data, perform least squares surface fitting to calculate the physical normal vector field of the target surface; input the visible light image into a lightweight convolutional neural network with MobileNetV3 as the backbone and pre-trained based on the joint loss function, regress and extract the first 3 spherical harmonic illumination coefficients of the scene, and extract the main light source direction vector analytically; calculate the illumination residual between the theoretical illumination distribution and the actual visible light image brightness according to Lambert's law of reflection.
[0017] Step S6, Physical Consistency Comprehensive Determination: Constructing a Joint Trustworthy Determination Function The function is defined as follows:
[0018]
[0019] in, The hardware physical fingerprint crossover score in step S1, The values of the transspectral scattering invariants in step S4 are... To obtain the macroscopic geometric consistency score based on the illumination residual mapping in step S5, an adaptive quantization attenuation and compensation function based on ambient illuminance and IMU angular velocity is introduced to dynamically update the score. If and only if When the value exceeds the preset physical confidence threshold, a trusted digital signature containing a physical evidence chain is generated.
[0020] Furthermore, the dynamic adjustment logic for the environmental adaptive weight coefficient is as follows: when the environmental perception sensor detects that the ambient light intensity is lower than a preset threshold, the system automatically reduces the weight of the microstructure coupling term. Enable the synchronized flash and simultaneously increase the weight of the physical fingerprint sensor. When the inertial measurement unit (IMU) detects that the instantaneous angular velocity of the acquisition device exceeds a preset value, the high-frequency data from the IMU is used to perform reverse motion compensation on the acquisition sequence to realign the point cloud and the image, and to increase the weight of the macroscopic illumination geometric constraint term. Furthermore, the present invention also provides a multimodal anti-counterfeiting verification terminal, comprising: a multimodal physical sensor group: integrating a visible light image sensor and a lidar, configured to synchronously trigger acquisition under a unified hardware clock domain; a secure execution environment (TEE) module: configured to take over the control bus of the sensors at the physical layer and independently execute the active sensor challenge in step S1; and a physical consistency calculation processor: whose memory is pre-loaded with intrinsic and extrinsic parameter spatial calibration parameters and a layered material transspectral scattering model library; configured to execute the above steps S2 to S6 and output a trusted digital signature.
[0021] The beneficial effects of this invention are as follows:
[0022] 1. Physical-level anti-injection capability: By actively exciting and verifying semiconductor lattice defect noise, "atomic-level" locking of the acquisition link is achieved, making software-level attacks (such as Hook and Replay) completely ineffective.
[0023] 2. Cross-modal material penetration: It does not rely on the "experience judgment" of AI black boxes, but is based on the physical axiom that "microstructure determines scattering characteristics". No matter how the counterfeiting methods are updated (such as 4K screens, 8K screens, oil paintings, 3D printing), as long as its microscopic physical structure does not match the real material, it will be detected by the cross-spectral invariant algorithm.
[0024] 3. Robustness across all scenarios: Combined with environmental adaptive weight adjustment, it can maintain high reliability even in harsh industrial environments such as low light and vibration, solving the problem of the stringent environmental requirements of traditional optical anti-counterfeiting technology.
[0025] 4. Algorithm white-boxing and adaptive quantization: This invention discloses the topology and joint loss function of deep learning networks and introduces a secondary decay and compensation function based on physical environment variables (illuminance, angular velocity), which overcomes the defects of subjective weight configuration in traditional multimodal fusion and has strict mathematical interpretability and robustness under complex working conditions. Attached Figure Description
[0026] Figure 1 This is a schematic diagram of the terminal hardware architecture and hardware isolation control link provided in an embodiment of the present invention;
[0027] Figure 2 This is a full-process verification logic diagram for cross-spectral spatial alignment and physical consistency determination provided in an embodiment of the present invention;
[0028] Figure 3 This is a schematic diagram illustrating the calculation principle of microstructure transspectral scattering invariants and normalized mutual information provided in an embodiment of the present invention.
[0029] Figure 4 This is a schematic diagram illustrating the principle of macroscopic illumination-normal geometric residual and anti-generative forgery determination provided in an embodiment of the present invention.
[0030] Figure 5 A timing interaction diagram for active sensor challenge and underlying register instruction verification provided in an embodiment of the present invention;
[0031] Figure 6 This is a structural block diagram of the multimodal anti-counterfeiting verification terminal module provided in an embodiment of the present invention.
[0032] Figure 7 A flowchart illustrating the lightweight convolutional neural network topology and loss function training process provided in this embodiment of the invention;
[0033] Figure 8 The weight adaptive quantization adjustment curve is provided for an embodiment of the present invention. Detailed Implementation
[0034] To enable those skilled in the art to better understand the present invention, the present invention will be further described in detail below with reference to the accompanying drawings and specific embodiments.
[0035] Example 1:
[0036] Underlying hardware proactive challenge and DSNU fingerprint verification:
[0037] This embodiment provides a link verification method based on hardware physical characteristics, which is suitable for business terminals that require high-security anti-counterfeiting verification to resist the injection of virtual data streams in the driver layer.
[0038] The verification terminal includes a main control chip and enables a Secure Execution Environment (TEE). During system startup verification, the TEE suspends the camera hardware abstraction layer service of the ordinary operating system domain, gaining independent control of the image sensor communication bus. This embodiment employs the ARM TrustZone architecture to acquire independent control. Specifically, the system configures an address space controller (TZASC) during the bootloader stage, locking the I2C / SPI physical bus address range of the image sensor to be readable and writable only by the Secure World. When the verification application initiates a request at the REE, it must switch to the TEE via the SMC instruction. This purely hardware-level memory barrier ensures that even if the operating system kernel is rooted or hooked by a hacker, it cannot forge or intercept register instructions sent to the sensor.
[0039] 2. Active Limit Parameter Injection: The TEE randomly generates register instructions containing limit exposure parameters and writes them directly into the image sensor's control register via the aforementioned secure I2C channel. An extremely short exposure instruction is written to the integration time register (in this embodiment, the integration time is configured as follows). And write the maximum analog gain instruction to the analog gain register (configured as follows in this embodiment). Under these imaging conditions, due to the extremely short exposure time, the RAW format image stream output by the sensor mainly consists of dark current fixed mode noise (DSNU), which reflects semiconductor lattice defects.
[0040] 3. Physical fingerprint feature extraction: The algorithm unit receives the dark frame image. Then, a filtering operation is performed to extract the high-frequency dark current noise matrix: Select a preset region of the image and calculate its row mean and variance. Sum of column mean and variance And extract pixel values that exceed the preset standard deviation (e.g. The set of hot pixel spatial coordinates .
[0041] 4. Comparison and Judgment: The extracted hot pixel set The set of reference thermal pixels pre-stored in the TEE secure storage area when the device leaves the factory Perform the intersection-over-union (IoU) calculation: ;
[0042] If the score is greater than the preset baseline threshold (e.g., 0.85), it is confirmed that the current data stream originates from the specified real physical sensor, thereby blocking the injection of virtual data at the underlying link.
[0043] Example 2: Microstructure Consistency Verification Based on Cross-Spectral Spatial Alignment
[0044] This embodiment describes the specific process of calculating transspectral scattering invariants, which is used to determine whether the target surface has true physical roughness.
[0045] 1. Spatial Alignment of Cross-Spectral Heterogeneous Signals: To eliminate differences in viewing angle and resolution between multimodal sensors, the terminal pre-calibrates the intrinsic parameter matrix K of the visible light image sensor, and the extrinsic parameter rotation matrix R and translation vector T between the lidar and the visible light sensor using a calibration algorithm. Let a point in the 3D point cloud data acquired by the lidar be... Reproject it onto the coordinates of the visible light two-dimensional pixel plane. The calculation formula is: ;
[0046] in This represents the depth value of the point in the camera coordinate system. Through the aforementioned reprojection, combined with a bilinear interpolation algorithm, a dense infrared reflectance distribution field is generated that is strictly aligned to the pixel level of the visible light image. .
[0047] 2. Microscopic Feature Extraction: Acquire visible light RGB images and extract their luminance components (e.g., the Y component in the YCbCr color space). Use the Scharr edge detection operator to extract their gradient magnitudes, generating a visible light texture gradient field. : ;
[0048] Simultaneously, the standard deviation of the aligned infrared reflectance distribution field is calculated within a local window and used as the physical intensity texture.
[0049] 3. Transspectral scattering invariant calculation (NMI): Calculation of spatially aligned invariants. and Divide the area into local sliding patches of a preset size (e.g., 64×64), and calculate the joint grayscale probability distribution of the two. Normalized mutual information (NMI) is derived: ;
[0050] Scene determination logic: For physically rough materials (such as metal rust), their microscopic geometric roughness simultaneously affects the texture of visible light diffuse reflection and the scattering intensity of infrared laser light, as shown in the data. High value area and The areas of change highly overlap, and the NMI values show a high correlation. For flat panel display screens (such as photocopying media), although the screen pixels display high-frequency textures ( (The changes are significant), but when the laser strikes the flat glass cover of the screen, Fresnel reflection or uniform transmission occurs, and the infrared echo intensity distribution is smooth. (The rate of change is close to 0), and its NMI value is significantly lower than that of the real material, which is why it is judged to be a planar forgery.
[0051] Example 3: Illumination-Normal Geometric Constraints Against Generative Forgery
[0052] This embodiment is designed to perform anti-counterfeiting verification on generative forged images that are pixel-realistic but violate the logic of physical space lighting.
[0053] 1. Physical Normal Field Reconstruction: Based on the aligned laser point cloud data in Example 2, local K-nearest neighbor points are selected, and spatial surface fitting is performed using the least squares method to calculate the physical normal vector corresponding to the target surface. .
[0054] 2. Main Light Source Inference and Pre-training: A lightweight convolutional neural network is pre-configured to extract the spherical harmonic illumination coefficients of the scene from the visible light image. The specific construction and training process of the aforementioned lightweight convolutional neural network is as follows:
[0055] (1) Dataset construction: A synthetic dataset containing various multimodalities is rendered using a 3D engine. The direction and intensity of the light source are randomly sampled in the hemispherical space to generate 100,000 RGB images with accurate first 3 orders (9 in total) spherical harmonic illumination coefficients (Ground Truth) labels.
[0056] (2) Network topology: The backbone network uses MobileNetV3-Small, which has low computational complexity, to adapt to the NPU computing power of terminal devices. The tail fully connected classification layer is removed, and its regression head is composed of Linear(1024, 512), ReLU activation layer, and Linear(512, 9) connected in sequence.
[0057] (3) Loss Function: During the offline training phase, a joint loss function is used for supervised training, and the formula is as follows: To ensure the convergence stability of the lightweight network under complex lighting conditions, the photometric consistency loss (the second term) employs the L1 norm to enhance robustness to abnormal pixels such as specular highlights. For training hyperparameter settings, the Adam optimizer is used initially, with the learning rate set to [value missing]. When the epoch reaches 50, a cosine annealing learning rate decay strategy is introduced. In this embodiment, to balance regression accuracy and rendering fidelity, a learning rate decay strategy is set... .
[0058] During the online verification phase, the target visible light image is input into the pre-trained network, which can regress the top 3 (out of 9) spherical harmonic illumination coefficients of the output scene and extract the direction vector of the main light source with the highest energy. .
[0059] 3. Physical consistency calculation: Construct the illumination residual equation based on Lambert's law of reflection: ;
[0060] in This is an estimate of the albedo. If the illumination residual diagram... If the proportion of pixel areas exceeding the set error threshold exceeds a preset ratio (e.g., 20%), the target image is determined to have physical and logical anomalies in dimensions such as shadow projection or ambient light occlusion, and is therefore a generated forged image.
[0061] Example 4: Active supplementary lighting and highlight consistency verification in low light environment. This example is applicable to anti-counterfeiting supplementary verification in low light environment.
[0062] When the terminal's ambient light sensor detects extremely low illumination, it triggers the terminal to activate the synchronous flash for active illumination. For a real smooth surface, point light source illumination will produce specular reflection. The verification module detects the coordinates of overexposed highlight pixels in the visible light image and checks the corresponding LiDAR point cloud data. If the corresponding point cloud data does not exhibit specular reflection characteristics (such as the absence of high-intensity saturation or receiving dead zone holes caused by non-coaxial structures), but instead shows ordinary diffuse reflection intensity, it indicates that the bright spots in the image are emitted by a fake light source, and the image is determined to be a forged medium.
[0063] Example 5: IMU-assisted motion compensation in motion-blurred scenarios. This example is applicable to scenarios where motion blur occurs due to shaking during handheld device acquisition.
[0064] When the inertial measurement unit (IMU) detects that the instantaneous angular velocity exceeds a preset threshold, the system uses the high-frequency data from the IMU to perform reverse motion compensation on each sampling point of the lidar within the scanning cycle, correcting it to the same coordinate reference frame at the same moment. Simultaneously, based on the motion vector (PSF) calculated from the IMU data, Wiener filtering is used to perform deblurring and deconvolution operations on the visible light image. After compensation is complete, the aforementioned spatial projection alignment and texture extraction are performed to prevent abnormally low NMI values caused by pixel misalignment due to motion distortion.
[0065] Example 6: Reflectivity benchmark verification of high-precision 3D models against forgery attacks on 3D models with high-precision 3D printed and sprayed surfaces.
[0066] The system determines the theoretical material classification of the target device (e.g., "wear-resistant steel") based on the preliminary semantic recognition results of the visible light image, and loads the corresponding infrared wavelength theoretical reflectivity range. The output of the radiometrically calibrated lidar is the actual measured reflectance value. If the measured average absolute reflectance of the point cloud is significantly lower than the lower limit of the theoretical range... (For example, if the detected material is PLA plastic substrate or low reflectivity of ordinary spray paint), the verification will be blocked directly and the material will be judged as inconsistent.
[0067] Example 7: Joint Trustworthiness Decision Function Computation and dynamic decision making
[0068] This embodiment integrates the verification results from the above dimensions into a unified decision. The terminal processor defines a joint trustworthiness determination function: ;
[0069] in, The hardware fingerprint similarity score output in Example 1 is shown below. The value of transspectral microscopic mutual information calculated in Example 2. The macroscopic geometric consistency score calculated for Example 3; These are the corresponding weighting coefficients. If If the value is below the safety threshold, the circuit breaker will be automatically tripped. = 0.
[0070] Adaptive Weight Adjustment: In industrial field verification, lighting conditions or equipment vibration can affect the confidence level of data in different modalities. Therefore, this embodiment constructs a rigorous mathematical mapping model for dynamic weight allocation. Let the initial baseline weight of the system be... .
[0071] Illumination Adaptation: The calculation of transspectral mutual information (NMI) depends on the high-frequency gradient of the visible light image. When the illuminance measured by the illuminance meter of the environment perception module is lower than a set threshold (e.g., ...), ... When the visible light image signal-to-noise ratio decreases, the system uses a quadratic attenuation function to smoothly reduce the weights of the microstructure coupling terms. Meanwhile, since the extraction of the underlying dark current noise (DSNU) does not depend on external illumination, the system will compensate for the reduced weights to... ,Right now .
[0072] Motion Adaptation: When instantaneous angular velocity is detected by the inertial measurement unit (IMU) Exceeding the preset image stabilization threshold At times, the accuracy of micro-pixel alignment may decrease. The system adjusts the weight of macro-level lighting geometry constraints, which are unaffected by local pixel offsets, according to a compensation function: Where k is the preset compensation sensitivity coefficient, and is proportionally reduced. and This ensures that the total weight sum is 1. The above continuous mathematical mapping based on physical environment variables guarantees the robustness of the joint decision function under extreme conditions.
[0073] Output trusted credentials: if and only if the final calculated credential is... When the physical confidence threshold is exceeded, a verification pass marker is generated. This result will be encapsulated into a trusted digital signature containing a chain of evidence including collection time, geographic coordinates, and signal hash digest, and will be encrypted and output using the hardware private key of the TEE module to ensure that the verification result cannot be tampered with.
[0074] Example 8: Simulation Testing and Effect Verification
[0075] To verify the effectiveness of the present invention, anti-counterfeiting verification tests were conducted on a closed test set containing 10,000 samples. The positive samples included 3,000 real physical devices, and the negative samples included 5,000 AIGC deepfake image injection attack samples and 2,000 high-precision screen capture samples.
[0076] Test results show that:
[0077] (1) The DSNU hardware fingerprint extraction mechanism based on TEE and TZASC isolation achieves a 100% interception rate for low-level injection attacks at the operating system layer;
[0078] (2) When the NMI judgment threshold is set to 0.5, the accuracy of the present invention in recognizing AIGC-generated forged images and screen re-photographing media reaches 98.7%;
[0079] (3) Compared with traditional anti-counterfeiting algorithms that rely solely on visible light two-dimensional texture features, under the interference of drastic changes in ambient illumination (such as a sudden change from 500 Lux to 50 Lux), thanks to the introduction of transspectral scattering invariants and adaptive weights, the false recognition rate of this method is significantly reduced by 82.4%, which fully verifies the strong robustness and high physical interpretability of this invention in complex physical environments.
[0080] The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of the present invention should be included within the protection scope of the present invention.
Claims
1. A multimodal anti-counterfeiting verification method based on microstructure transspectral scattering stability and reliable computation, comprising the steps of simultaneously acquiring visible light image data and laser point cloud data of the target surface and performing consistency determination; characterized in that, The method further includes: Establish hardware physical anchors: Establish a hardware-isolated control link through the image sensor within the Secure Execution Environment (TEE) to acquire the raw photoelectric signal that has not been processed by the operating system, and extract the dark current fixed mode noise (DSNU) of the sensor as a hardware physical fingerprint. Cross-spectral spatial alignment: Based on the pre-calibrated intrinsic parameter matrix of the image sensor and the extrinsic parameter matrix between it and the lidar, the three-dimensional laser point cloud is projected onto the two-dimensional pixel coordinate system of the visible light image to generate a cross-spectral data source that is aligned with the depth and echo intensity. Extracting transspectral micro-features: The aligned visible light image and lidar intensity map are mapped to visible light texture gradient field and infrared reflectivity distribution field, respectively; Calculate the physical scattering invariants: Within a local sliding window, calculate the normalized mutual information (NMI) between the visible light texture gradient field and the infrared reflectivity distribution field, and derive the transspectral scattering invariants that characterize the stability of the material's microstructure. Extracting macroscopic illumination consistency features: Based on the laser point cloud data, extract the normal information of the target surface, and process the visible light image data through a pre-trained convolutional neural network model to infer the direction of the main light source. Calculate the macroscopic illumination residual between the observed illumination and the estimated illumination of the visible light image according to the law of physical reflection. Physical consistency determination: A joint trust determination function is constructed, which includes a weighted sum of hardware physical fingerprint constraints, microstructure constraints, and macroscopic geometric constraints. The weight coefficients in the joint trust determination function have adaptive quantitative adjustment characteristics based on environmental perception data: when the ambient light intensity is lower than a preset threshold, the weight of the microstructure constraint is reduced according to a preset quadratic attenuation function, and weight compensation is applied to the hardware physical fingerprint constraint; when the instantaneous angular velocity detected by the inertial measurement unit exceeds a preset anti-shake threshold, the weight of the macroscopic geometric constraint is increased, and the weights of the other two items are reduced proportionally; a verification pass signature is generated only when the value of the joint trust determination function exceeds a preset physical confidence threshold.
2. The method according to claim 1, characterized in that, The step of establishing hardware physical anchors includes an active sensor challenge, specifically: When the Secure Execution Environment (TEE) starts, the physical base address of the I2C bus controller of the image sensor is configured to be exclusively accessed by the Secure World by configuring the TrustZone address space controller (TZASC), thus cutting off the physical addressing path of the ordinary operating system (REE). The TEE generates register instructions containing the limit exposure parameters and the maximum analog gain, wherein the integration time of the limit exposure parameters is configured to be less than 1 microsecond and the maximum analog gain is configured to be greater than 24dB, and writes them to the sensor register through the secure I2C channel. The dark frame output by the capture sensor under the extreme parameters is mainly composed of dark current fixed mode noise (DSNU) reflecting semiconductor lattice defects due to the extremely short exposure time. Calculate the intersection-over-union ratio (IoU) between the hot pixel distribution of the dark frame and the pre-stored DSNU physical fingerprint. If the IoU exceeds a preset benchmark value of 0.85, it is confirmed as a real physical device.
3. The method according to claim 1, characterized in that, The specific calculation process for the cross-spectral spatial alignment and microscopic feature extraction is as follows: Let the three-dimensional coordinates of the laser point cloud be... The corresponding coordinates are obtained by projecting the pre-calibrated extrinsic matrix [R|T] and intrinsic matrix K onto the pixel system. A dense-intensity infrared reflectivity distribution field is generated using bilinear interpolation. The luminance component of the visible light image is extracted using the Scharr operator to generate a visible light texture gradient field. .
4. The method according to claim 1, characterized in that, The joint trust determination function is defined as follows: ; in, Let be the numerical value of the transspectral scattering invariant. The score is based on macroscopic geometric consistency. The similarity score is calculated based on the physical fingerprint of the hardware. These are the environmental adaptive weighting coefficients.
5. The method according to claim 1, characterized in that, The logic for determining generative forged images is included in the macroscopic geometric constraints, specifically including: The physical normal vector field of the target surface is calculated based on least-squares surface fitting of local point cloud data. The visible light image is input into a pre-trained lightweight convolutional neural network. The network employs a lightweight feature extraction backbone network containing a depthwise separable convolutional structure, removes the tail fully connected classification layer, and connects a two-layer fully connected regression head containing 512 and 9 neurons respectively. The network is trained offline under supervision using a synthetic illumination dataset, and its loss function is defined as the weighted sum of the mean square error (MSE) loss between the predicted spherical harmonics and the true spherical harmonics, and the loss from rendering the image reconstruction. The network regresses the first three orders of the scene, totaling nine spherical harmonic illumination coefficients, and then analyzes the main light source direction vector based on the principle of maximizing energy. ; The illumination residual equation for calculating the theoretical illumination distribution versus the actual image brightness is calculated based on Lambert's law of reflection: ,in Surface albedo; If the residual map If the proportion of pixels exceeding the error threshold is greater than the preset ratio, it is determined to be a generative forged image that violates the laws of physical lighting.
6. The method according to claim 1, characterized in that, When the instantaneous angular velocity detected by the inertial measurement unit exceeds the preset anti-shake threshold, before performing the step of increasing the weight of the macroscopic geometric constraint term, the method further includes a step of using high-frequency inertial data for transient motion compensation, specifically including: Using the high-frequency attitude data of the inertial measurement unit, reverse motion compensation is performed on each three-dimensional sampling point of the laser point cloud data within the scanning cycle, and its spatial pose is corrected to a coordinate reference system with a unified timestamp. Simultaneously, the motion blur point spread function (PSF) vector is calculated based on the high-frequency attitude data, and Wiener filtering is used to perform deblurring and deconvolution operations on the visible light image data; After completing the dual transient compensation of the point cloud and the image, the cross-spectral spatial alignment step of projecting the three-dimensional laser point cloud onto the visible light image is then performed to eliminate pixel-level misalignment caused by high-frequency jitter of physical equipment.
7. A multimodal anti-counterfeiting verification terminal based on microstructure transspectral scattering stability and reliable computation, characterized in that, include: Multimodal physical sensor array: integrates a visible light image sensor and a lidar, and is configured to synchronously acquire target data in a unified clock domain; Secure Execution Environment (TEE) module: configured to take over the control bus of the sensor in hardware isolation, and perform active sensor challenge and hardware fingerprint verification; Physical consistency solver processor: pre-stored sensor spatial calibration parameters, configured to perform the method as described in any one of claims 1-6.
8. The method according to claim 1, characterized in that, Before calculating the physical scattering invariant, the method further includes: classifying and identifying the target material based on the preliminary semantic features of the visible light image to determine the theoretical material classification of the target device; and then adaptively adjusting the judgment strategy based on the theoretical material classification. For metals, a specular reflection coupling model is loaded to verify the transspectral phase consistency between the visible light specular region and the infrared intensity. For the rough or rusted categories, a diffuse reflection coupling model is loaded to verify the spatial co-occurrence of visible light texture gradient and infrared reflectance; For screen planar media, the criteria are set to determine whether the visible light texture gradient change rate is higher than a threshold and the infrared reflectance distribution variance is lower than a threshold.
9. The terminal according to claim 7, characterized in that, It also includes an environmental perception and active lighting module: When the environmental perception module detects that the ambient light intensity is lower than a preset threshold, it triggers the active supplementary lighting module to emit a synchronous flash and performs a high-light and blind-spot consistency detection: that is, it checks whether the coordinates of overexposed highlight pixels in the visible light image correspond to data holes or preset high-intensity reflection anomalies in the laser point cloud data. If they do not correspond, it is determined to be a non-real physical specular reflection.
10. The terminal according to claim 7, characterized in that, The verification result generated by the terminal is a trusted digital signature containing a chain of physical evidence. The physical evidence chain encapsulates the satellite timing at the time of acquisition, satellite positioning coordinates, hash digest of the original photoelectric signal, and the value of the transspectral scattering invariant; the trusted digital signature is generated by encryption using the terminal hardware private key within the secure execution environment (TEE).