Test method, optimization method and device for certificate anti-counterfeiting model
By using reinforcement learning to generate image acquisition strategies and combining lighting and angle adjustments, the document anti-counterfeiting model is optimized, solving the testing challenges of document anti-counterfeiting systems in different environments and improving the system's defense capabilities and recognition accuracy.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- ANT BLOCKCHAIN TECHNOLOGY (SHANGHAI) CO LTD
- Filing Date
- 2023-08-18
- Publication Date
- 2026-04-21
AI Technical Summary
Existing document anti-counterfeiting systems are difficult to effectively test their anti-attack capabilities under different environmental conditions, and manual testing is difficult to simulate all data collection conditions, leading to the continuous breach of the system by counterfeit document attack methods.
An image acquisition strategy is generated using a reinforcement learning-based policy model. Images of counterfeit documents are acquired by adjusting lighting and angle. An attack strategy is constructed and the document anti-counterfeiting model is optimized. A quality detection model is used to ensure image quality. The policy model is updated by the attack rate and the stimulus signal.
Effective testing and optimization of the anti-counterfeiting model of the document can improve its anti-counterfeiting capabilities and accuracy, and enhance its ability to identify different fake documents.
Smart Images

Figure CN117078909B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of computer technology, and in particular to a testing method, optimization method, and apparatus for an anti-counterfeiting model of identification documents. Background Technology
[0002] The purpose of document anti-counterfeiting is to ensure that the documents submitted by users during electronic identity authentication are genuine and in accordance with the identity of the user. However, cybercriminals use various fake document attack methods, such as screen capture, color printing of documents, high-quality counterfeit documents, and adding headshots to photos, to attempt to bypass the document anti-counterfeiting system and steal user data or even funds. These attack methods are constantly evolving. The same fake document may bypass the entire anti-counterfeiting system under different lighting conditions, angles, and other environmental conditions. Therefore, document anti-counterfeiting systems must undergo rigorous testing before going live. Manual testing of document anti-counterfeiting capabilities cannot simulate all environmental conditions, and even after a fake document is bypassed, it is not easy to generate a large number of fake documents under the same conditions. Summary of the Invention
[0003] One of the objectives of this invention is to provide a testing method for document anti-counterfeiting models. This method can traverse different acquisition strategies to construct sufficient counterfeit document images to effectively test the anti-attack capability of the document anti-counterfeiting model.
[0004] In accordance with the aforementioned objective, this specification provides a method for testing a document anti-counterfeiting model, comprising at least one round of attack on the document anti-counterfeiting model; wherein each round of attack includes:
[0005] Obtain the image acquisition strategy output by the strategy model;
[0006] Based on the image acquisition strategy, images of the target counterfeit document are acquired to obtain at least one target image;
[0007] Input the at least one target image into the document anti-counterfeiting model to obtain the recognition result;
[0008] Based on the identification results, the success rate of this attack is determined;
[0009] Based on the aforementioned breakthrough rate, an excitation signal is determined;
[0010] The excitation signal and the image acquisition environment are input into the policy model so that the policy model updates the image acquisition policy using reinforcement learning.
[0011] The testing method for the document anti-counterfeiting model proposed in the embodiments of this specification attacks the document anti-counterfeiting model by collecting images of the target counterfeit document. Based on the attack rate under the image acquisition strategy and the image acquisition environment, reinforcement learning is used to enable the strategy model to generate attack strategies with wider attack coverage and stronger attack power, thereby effectively testing the anti-attack capability of the document anti-counterfeiting model and improving the defense capability of the document anti-counterfeiting model.
[0012] Furthermore, in some embodiments, the image acquisition strategy includes a lighting adjustment strategy; and the image acquisition of the target counterfeit document based on the image acquisition strategy specifically includes:
[0013] Based on the light adjustment strategy, at least one of the angle and intensity of the light illuminating the target counterfeit document is adjusted to obtain the target light environment;
[0014] Under the target lighting conditions, images of the target counterfeit document are captured.
[0015] Furthermore, in some embodiments, the image acquisition strategy includes an angle adjustment strategy; image acquisition of the target counterfeit document based on the image acquisition strategy specifically includes:
[0016] The image acquisition device is grasped by a robotic arm and adjusted to a preset first position;
[0017] At the first position, the image acquisition device acquires an image of the target area to obtain a first image;
[0018] In response to the presence of the target counterfeit document in the first image, a second location of the target counterfeit document is determined;
[0019] Based on the first position, the second position, and the angle adjustment strategy, control commands are generated;
[0020] The robotic arm executes the control commands to adjust the image acquisition device to the target angle specified by the angle adjustment strategy, and acquires an image of the target counterfeit document at the target angle.
[0021] Furthermore, in some embodiments, determining the second location of the target counterfeit document in response to the presence of the target counterfeit document in the first image specifically includes:
[0022] Determine the corner positions of the four corner points of the target counterfeit document in the first image;
[0023] Based on the corner positions of the four corner points, the second position of the target counterfeit document is determined.
[0024] Furthermore, in some embodiments, determining the excitation signal based on the breakthrough rate specifically includes:
[0025] For each round of attack, a positive excitation signal is determined if the breakthrough rate of the current round of attack is higher than that of the previous round of attack; a negative excitation signal is determined if the breakthrough rate of the current round of attack is lower than that of the previous round of attack.
[0026] Furthermore, in some embodiments, the testing method for the document anti-counterfeiting model further includes:
[0027] After capturing images of the target counterfeit document, the captured document images are input into the quality detection model;
[0028] The target image is determined based on the detection results of the quality detection model.
[0029] The present invention also aims to provide an optimization method for document anti-counterfeiting models, which can optimize document anti-counterfeiting models based on attack data.
[0030] In accordance with the aforementioned objective, this specification provides an optimization method for an anti-counterfeiting model of an identification document, comprising continuously optimizing the anti-counterfeiting model for at least one round until an anti-counterfeiting model that meets preset conditions is obtained; wherein each round of optimization includes:
[0031] At least one round of attack is performed on the document anti-counterfeiting model using any of the above-mentioned testing methods;
[0032] For each round of attack, if the breakthrough rate of the attack is higher than the preset breakthrough rate threshold, then the target forged document will be captured in the image acquisition environment corresponding to the attack to obtain at least one sample image.
[0033] Add negative sample labels to the sample images;
[0034] The document anti-counterfeiting model is trained based on the sample images and the negative sample labels.
[0035] This specification also provides a testing device for an anti-counterfeiting model of an identification document, used to perform at least one round of attacks on the anti-counterfeiting model of the identification document. The device includes:
[0036] The strategy generation module is configured to generate an image acquisition strategy based on a strategy model; and to determine the attack rate of each round of attack based on the recognition result of the target image by the document anti-counterfeiting model in each round of attack, determine an excitation signal based on the attack rate, and input the excitation signal into the strategy model so that the strategy model updates the image acquisition strategy using reinforcement learning.
[0037] An image acquisition device is configured to acquire images of a target counterfeit document based on the image acquisition strategy, thereby obtaining at least one target image.
[0038] Furthermore, in some embodiments, the image acquisition strategy includes a light adjustment strategy; the device further includes an environment adjustment module, which is used to adjust at least one of the angle and intensity of the light illuminating the target counterfeit document based on the light adjustment strategy.
[0039] Furthermore, in some embodiments, the image acquisition strategy includes an angle adjustment strategy; the device also includes a robotic arm and a robotic arm control module;
[0040] The robotic arm is used to grasp the image acquisition device and adjust the image acquisition device to a preset first position; and in response to a control command, adjust the image acquisition device to a target angle specified by the angle adjustment strategy;
[0041] The image acquisition device is further configured to acquire an image of the target area at the first location to obtain a first image; and in response to the presence of the target counterfeit document in the first image, determine the second location of the target counterfeit document.
[0042] The robotic arm control module is used to generate the control commands based on the first position, the second position, and the angle adjustment strategy.
[0043] Furthermore, in some embodiments, the device further includes a quality detection module; the quality detection module is used to input the document image acquired by the image acquisition device into a quality detection model, and determine the target image based on the detection results of the quality detection model.
[0044] This specification also provides an optimization device for a document anti-counterfeiting model, including: a testing device, an identification module, a data acquisition module, and an optimization module as described in any of the above embodiments;
[0045] The identification module identifies the target image input into the test device in each round of attack using the deployed document anti-counterfeiting model, and outputs the identification result.
[0046] The data acquisition module is configured to determine the breakthrough rate of the document anti-counterfeiting model in the current round of attack based on the recognition result; when the breakthrough rate is greater than the preset breakthrough rate threshold, to perform image acquisition on the target counterfeit document in the image acquisition environment corresponding to the current round of attack, to obtain at least one sample image, and to add negative sample labels to the sample image.
[0047] The optimization module is configured to train the document anti-counterfeiting model based on the sample images and the negative sample labels.
[0048] This specification also provides a computer-readable storage medium storing a computer program thereon, which, when executed by a processor, performs at least one round of attack on the anti-counterfeiting model of the document; wherein each round of attack includes:
[0049] Obtain the image acquisition strategy output by the strategy model;
[0050] Based on the image acquisition strategy, images of the target counterfeit document are acquired to obtain at least one target image;
[0051] Input the at least one target image into the document anti-counterfeiting model to obtain the recognition result;
[0052] Based on the identification results, the success rate of this attack is determined;
[0053] Based on the aforementioned breakthrough rate, an excitation signal is determined;
[0054] The excitation signal is input into the policy model so that the policy model updates the image acquisition policy using reinforcement learning.
[0055] This specification also provides an electronic device, including:
[0056] One or more processors; and a memory associated with the one or more processors, the memory storing program instructions that, when read and executed by the one or more processors, enable the one or more processors to perform at least one round of attack on the document anti-counterfeiting model; wherein each round of attack includes:
[0057] Obtain the image acquisition strategy output by the strategy model;
[0058] Based on the image acquisition strategy, images of the target counterfeit document are acquired to obtain at least one target image;
[0059] Input the at least one target image into the document anti-counterfeiting model to obtain the recognition result;
[0060] Based on the identification results, the success rate of this attack is determined;
[0061] Based on the aforementioned breakthrough rate, an excitation signal is determined;
[0062] The excitation signal is input into the policy model so that the policy model updates the image acquisition policy using reinforcement learning.
[0063] This specification also provides a computer-readable storage medium storing a computer program thereon. When executed by a processor, the computer program performs at least one round of optimization on a document anti-counterfeiting model until a document anti-counterfeiting model that meets preset conditions is obtained; wherein each round of optimization includes:
[0064] At least one round of attack is performed on the document anti-counterfeiting model using any of the above-mentioned testing methods;
[0065] For each round of attack, if the breakthrough rate of the attack is higher than the preset breakthrough rate threshold, then the target forged document will be captured in the image acquisition environment corresponding to the attack to obtain at least one sample image.
[0066] Add negative sample labels to the sample images;
[0067] The document anti-counterfeiting model is trained based on the sample images and the negative sample labels.
[0068] This specification also provides an electronic device, including:
[0069] One or more processors; and a memory associated with the one or more processors, the memory storing program instructions that, when read and executed by the one or more processors, cause the one or more processors to perform at least one round of optimization on the document anti-counterfeiting model until a document anti-counterfeiting model that meets preset conditions is obtained; wherein each round of optimization includes:
[0070] At least one round of attack is performed on the document anti-counterfeiting model using any of the above-mentioned testing methods;
[0071] For each round of attack, if the breakthrough rate of the attack is higher than the preset breakthrough rate threshold, then the target forged document will be captured in the image acquisition environment corresponding to the attack to obtain at least one sample image.
[0072] Add negative sample labels to the sample images;
[0073] The document anti-counterfeiting model is trained based on the sample images and the negative sample labels.
[0074] The beneficial effect of the testing method for the document anti-counterfeiting model described in the embodiments of this specification is that it uses a reinforcement learning-based policy model to generate image acquisition strategies, thereby constructing sufficient target images to attack the document anti-counterfeiting model and effectively testing the anti-counterfeiting model's resistance to attacks. Furthermore, effective attack samples can be used to optimize the document anti-counterfeiting model, thereby improving its defense capabilities and anti-counterfeiting accuracy.
[0075] The testing and optimization devices for the document anti-counterfeiting model described in the embodiments of this specification also have the aforementioned beneficial effects. Attached Figure Description
[0076] To more clearly illustrate the technical solutions in the embodiments or prior art of this specification, the drawings used in the description of the embodiments or prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of this specification. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0077] Figure 1 An exemplary flowchart of a testing method for an anti-counterfeiting model of a document as described in an embodiment of this specification is shown in one implementation.
[0078] Figure 2 A schematic flowchart of a document collection method described in one or more embodiments of this specification is shown as an example.
[0079] Figure 3 An exemplary flowchart of one implementation of the method for optimizing the document anti-counterfeiting model described in the embodiments of this specification is shown.
[0080] Figure 4 An exemplary block diagram of the testing apparatus for the document anti-counterfeiting model described in the embodiments of this specification is shown in one implementation.
[0081] Figure 5 An exemplary block diagram of the optimization device for the document anti-counterfeiting model described in the embodiments of this specification is shown in one implementation.
[0082] Figure 6 A schematic diagram of a test system for an anti-counterfeiting model of a document, as described in an embodiment of this specification, is shown as an example.
[0083] Figure 7 An exemplary structural diagram of an electronic device provided in an embodiment of this specification is shown. Detailed Implementation
[0084] First, it should be noted that the terminology used in the embodiments of this invention is for the purpose of describing specific embodiments only and is not intended to limit the invention. The singular forms “a,” “the,” and “the” used in the embodiments of this invention and the appended claims are also intended to include the plural forms, unless the context clearly indicates otherwise.
[0085] To enable those skilled in the art to better understand the technical solutions in this specification, the technical solutions in the embodiments of this specification will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments in this specification, and not all of the embodiments. Therefore, those skilled in the art should recognize that various changes and modifications can be made to the embodiments described herein without departing from the scope and spirit of the invention. Similarly, for clarity and conciseness, descriptions of well-known functions and structures are omitted in the following description.
[0086] It should be noted that the steps of the corresponding methods are not necessarily performed in the order shown and described in this specification in other embodiments. In some other embodiments, the methods may include more or fewer steps than described in this specification. Furthermore, a single step described in this specification may be broken down into multiple steps in other embodiments; and multiple steps described in this specification may be combined into a single step in other embodiments.
[0087] In the ongoing promotion of the digital economy, digital identity has been widely adopted. As credentials authorizing merchants to use real-name information, the security of documents identifying users' digital identities is paramount. The core of digital identity commercialization lies in document anti-counterfeiting models. Faced with various fake document attacks, such as screen capture, color-printed documents, high-quality counterfeit documents, and photoshopped images, the document anti-counterfeiting system deploys corresponding anti-counterfeiting models for identification. The purpose of the system is to ensure that the documents submitted by users during online identity authentication are genuine and belong to the user, preventing black market actors from using these fake document attacks to bypass the system for profit or even steal user funds. Furthermore, the attack methods of black market actors are constantly evolving. The same fake document may breach the entire document anti-counterfeiting system under different lighting conditions, angles, and other sampling environments. Therefore, document anti-counterfeiting models require rigorous testing before deployment. Manual testing of the anti-counterfeiting capabilities of document anti-counterfeiting models is difficult to simulate all document sampling conditions, and even after a fake document is breached, it is not easy to launch a large-scale fake document attack while maintaining the same sampling conditions.
[0088] Therefore, we hope to obtain a document anti-counterfeiting model testing scheme that can collect data on counterfeit documents attacking the document anti-counterfeiting model under different environments and angles, so as to promote the optimization of the document anti-counterfeiting model.
[0089] The following will provide a more detailed description of the testing method, optimization method, and apparatus for the document anti-counterfeiting model described in the embodiments of this specification, in conjunction with the accompanying drawings and specific examples. However, this detailed description does not constitute a limitation on the embodiments of this specification.
[0090] In one embodiment of this specification, a testing method for an anti-counterfeiting model of an identification document is proposed. Figure 1 An exemplary flowchart of a testing method for an anti-counterfeiting model of a document as described in an embodiment of this specification is shown in one implementation.
[0091] like Figure 1 As shown, the method includes at least one round of attack on the document anti-counterfeiting model; wherein each round of attack includes:
[0092] S100: Image acquisition strategy output by the acquisition strategy model.
[0093] The policy model takes environmental information as input and outputs a corresponding image acquisition policy through a multi-classification task, thereby determining the relevant parameters involved in the image acquisition process based on the image acquisition policy. In some embodiments, the policy model can be built based on a neural network structure, such as a multilayer perceptron (MLP) model.
[0094] Image acquisition strategies include at least one of lighting adjustment strategies and angle adjustment strategies. The parameters that need to be determined include, but are not limited to, the light intensity and lighting angle in the lighting adjustment strategy, or the document pose data in the angle adjustment strategy. Target images of counterfeit documents acquired through different image acquisition strategies exhibit certain differences in their features, which can affect the recognition results of the document anti-counterfeiting model, thus resulting in different attack effects. Therefore, adjusting the image acquisition strategy can achieve better attack effects, allowing for rapid and effective testing of the anti-counterfeiting capabilities of the document anti-counterfeiting model.
[0095] S102: Based on the image acquisition strategy, acquire images of the target counterfeit document to obtain at least one target image.
[0096] Optionally, mobile terminal devices such as smartphones, tablets, and wearable devices can be used as image acquisition devices to capture images of the target counterfeit documents in the environment or posture specified by the image acquisition strategy. Target counterfeit documents include, but are not limited to, color-printed documents, high-quality counterfeit documents, documents photographed from a screen, and documents counterfeited by pasting a portrait onto a photograph. Depending on the counterfeiting method, different image acquisition strategies can be used to specifically highlight the document's image features, thereby facilitating the differentiation between counterfeit and genuine documents. At least one target image must be captured; multiple target images can also be captured to ensure the integrity of the document's image features.
[0097] In some embodiments, after capturing images of the target counterfeit document, the captured document images can be input into a quality detection model for quality detection, so as to eliminate images that do not meet the quality requirements.
[0098] The initially collected target document images may suffer from quality issues such as blurriness, incompleteness, or obstruction due to limitations in the collection environment or equipment, as well as some accidental factors. For example, key information on the document may be reflected light, damaged, or the edges may be obscured by fingers. Performing anti-counterfeiting identification on these substandard images will affect the accuracy of the results. Therefore, quality inspection is necessary to ensure that the document images entering the anti-counterfeiting stage meet quality requirements and improve anti-counterfeiting efficiency. If the quality inspection result is satisfactory, the collected document image is determined as the target image; otherwise, the reason for the substandard document quality is fed back to the user, and the user is guided to adjust and re-collect the document image through an interactive page.
[0099] Specifically, the quality detection model can be implemented based on a CNN network, such as ResNet. The acquired document image is input into the CNN network for image feature extraction. The quality of the document image is scored by analyzing the image features. If the quality score of the document image is greater than a preset threshold, the quality detection is qualified; otherwise, the quality detection is unqualified.
[0100] S104: Input at least one target image into the document anti-counterfeiting model to obtain the recognition result.
[0101] Counterfeit documents can be attacked in various ways, and different types of counterfeit documents require different anti-counterfeiting models for defense. These include, but are not limited to, counterfeit documents created by photographing images of other documents, high-quality counterfeits, color-printed documents, and documents with photo stickers. In response to the type of counterfeit document detected, the corresponding anti-counterfeiting model will perform anti-counterfeiting identification and return the identification result, indicating whether the model input is a counterfeit document or a genuine document.
[0102] In some embodiments, the document anti-counterfeiting model is pre-trained in the following manner:
[0103] Obtain images of real identification documents as positive samples and add positive sample labels;
[0104] Obtain images of forged documents as negative samples and add negative sample labels;
[0105] The document anti-counterfeiting model is trained using training samples containing both positive and negative samples until a document anti-counterfeiting model that meets the preset conditions is obtained.
[0106] During model training, the difference between the recognition result obtained after inputting training samples into the document anti-counterfeiting model and the corresponding sample label is calculated, and the document anti-counterfeiting model is trained with the goal of minimizing this difference, so that the trained document anti-counterfeiting model can stably and accurately distinguish between genuine and counterfeit documents.
[0107] In some more specific embodiments, the document anti-counterfeiting model can be built on a CNN network structure, such as ResNet, or on an RNN network or Transformer network structure.
[0108] S106: Based on the identification results, determine the success rate of this round of attack.
[0109] The breach rate can be calculated as the ratio of the number of times the document anti-counterfeiting model is breached to the total number of attacks within a certain period. A breach of the document anti-counterfeiting model means that it identifies a counterfeit document as a genuine one. In each round of attacks, a higher breach rate indicates a lower anti-counterfeiting capability score for the document anti-counterfeiting model, and a greater need for optimization.
[0110] S108: Determine the excitation signal based on the breakthrough rate.
[0111] In some embodiments, determining the excitation signal based on the breakthrough rate specifically includes:
[0112] For each round of attack, a positive excitation signal is determined if the breakthrough rate of the current round of attack is higher than that of the previous round of attack; a negative excitation signal is determined if the breakthrough rate of the current round of attack is lower than that of the previous round of attack.
[0113] By using positive and negative excitation signals, the strategy model can be updated with the goal of increasing the breakthrough rate, so as to fully discover the weaknesses of the document anti-counterfeiting model.
[0114] S110: Input the excitation signal and image acquisition environment into the policy model so that the policy model can use reinforcement learning to update the image acquisition policy.
[0115] The policy model employs reinforcement learning for policy updates. The image acquisition policy can be at least one of an environment policy or an angle policy. The environment policy can be a light intensity adjustment policy, a light angle adjustment policy, etc. The angle policy refers to the adjustment strategy for the relative angle between the image acquisition device and the target counterfeit document.
[0116] In each round of attack, the strategy model first generates an image acquisition strategy. Based on the current image acquisition strategy, it acquires the target counterfeit document, thereby obtaining the target image, which is then input into the document anti-counterfeiting model for attack. The breakthrough rate and stimulus signal are determined based on the recognition results of the document anti-counterfeiting model. The breakthrough rate reflects the offensive strength of the counterfeit document under the current image acquisition strategy. The strategy model employs reinforcement learning, updating the image acquisition strategy based on the returned stimulus signal. It learns and updates round after round with the goal of increasing the breakthrough rate, ultimately ensuring that the image acquisition strategy generated by the strategy model can reliably break through the document anti-counterfeiting model.
[0117] In some embodiments, if the image acquisition strategy includes a lighting adjustment strategy, then the testing method for the document anti-counterfeiting model includes:
[0118] S200: Image acquisition strategy output by the acquisition strategy model.
[0119] Image acquisition strategies include lighting adjustment strategies, which determine the environmental parameters involved when using image acquisition equipment to capture images of counterfeit documents. Maintaining a consistent acquisition angle is crucial, as the completeness and clarity of information presented on the document will vary under different lighting conditions. For example, the clarity of information on the document can be guaranteed under appropriate lighting conditions, while reflective anti-counterfeiting marks on the document can only be accurately captured under flash photography.
[0120] S202: Based on the light adjustment strategy in the image acquisition strategy, perform image acquisition on the target forged document to obtain at least one target image.
[0121] Specifically, image acquisition of the target counterfeit document based on the lighting adjustment strategy includes:
[0122] Based on a light adjustment strategy, at least one of the angle and intensity of the light illuminating the target counterfeit document is adjusted to obtain the target light environment;
[0123] Under the target lighting conditions, images of the counterfeit documents are captured.
[0124] Different lighting angles result in varying reflectivity on documents. For documents with reflective anti-counterfeiting features, adjusting the lighting angle helps in observing whether the anti-counterfeiting features are present, and the clarity and accuracy of those features, making it easier to distinguish high-quality counterfeit documents from fakes. Light intensity, on the other hand, affects the clarity and completeness of the captured image. Furthermore, different lighting conditions can reveal differences in document materials, thus facilitating the differentiation of counterfeit documents, such as color-printed documents.
[0125] More specifically, a target lighting environment can be created using a flash on an image acquisition device, and the angle and / or intensity of the flash hitting the target forged document can be controlled by adjusting the relative position between the image acquisition device and the target forged document.
[0126] Of course, in other implementations, the target lighting environment can also be constructed using peripheral lighting equipment, thereby allowing for more flexible adjustment of the intensity and / or angle of the light to obtain a sufficient target image to attack the document anti-counterfeiting model.
[0127] Optionally, after adjusting the lighting and capturing the image of the target counterfeit document, the captured document image is input into the quality detection model; based on the detection results of the quality detection model, the target image is determined.
[0128] S204: Input at least one target image into the document anti-counterfeiting model to obtain the recognition result.
[0129] In response to the type of forgery detected in the target counterfeit document, the corresponding document anti-counterfeiting model will perform anti-counterfeiting identification and return the identification result, i.e., whether the model input is a counterfeit document or a genuine document. The training method for the document anti-counterfeiting model can be found in [reference needed]. Figure 1 The embodiments shown will not be described again here.
[0130] S206: Based on the identification results, determine the breakthrough rate of this round of attack; based on the breakthrough rate, determine the excitation signal; input the excitation signal and the image acquisition environment into the policy model so that the policy model can use reinforcement learning to update the image acquisition strategy.
[0131] The strategy model uses reinforcement learning to update the image acquisition environment based on the returned stimulus signals and generate new lighting adjustment strategies. It learns and updates round after round with the increase in the breakthrough rate as a positive incentive, so that the lighting adjustment strategy generated by the strategy model can stably break through the document anti-counterfeiting model.
[0132] In other embodiments, the image acquisition strategy includes an angle adjustment strategy, then the testing method for the document anti-counterfeiting model includes:
[0133] S300: Image acquisition strategy output by the acquisition strategy model.
[0134] Image acquisition strategies include angle adjustment strategies. The acquisition angle can also affect the anti-counterfeiting effect of documents. Information captured from a frontal or side angle will differ. For example, under the same lighting conditions, the materials of counterfeit and genuine documents will appear different at different angles, and some special anti-counterfeiting marks can only be identified when the document is captured from the side. The acquisition angle can be reflected by the posture data of the target counterfeit document, such as its angle.
[0135] S302: Based on the angle adjustment strategy in the image acquisition strategy, perform image acquisition on the target forged document to obtain at least one target image.
[0136] Specifically, image acquisition of the target counterfeit document based on the angle adjustment strategy includes:
[0137] The robotic arm grasps the image acquisition device and adjusts it to a preset first position.
[0138] At the first position, an image is acquired of the target area using an image acquisition device to obtain a first image;
[0139] In response to the presence of a target counterfeit document in the first image, a second location of the target counterfeit document is determined;
[0140] Based on the first position, the second position, and the angle adjustment strategy, control commands are generated.
[0141] The robotic arm executes control commands to adjust the image acquisition device to the target angle specified by the angle adjustment strategy, and then acquires images of the forged document at the target angle.
[0142] First, the image acquisition device is adjusted to a preset first position so that the target counterfeit document to be acquired enters the acquisition range; then, the valid part of the target counterfeit document is determined by detecting the first image to determine whether it falls within the acquisition range of the image acquisition device. If the target counterfeit document is detected within the acquisition range, the position information of the target counterfeit document is obtained to determine the second position.
[0143] The angle adjustment strategy is generated by a strategy model, which includes the target angle to be adjusted. Based on the first position of the image acquisition device and the second position of the target counterfeit document, the relative position information between the image acquisition device and the document can be determined. Based on the second position of the target counterfeit document, the current posture of the document can be calculated, thus obtaining the current angle of the document. By comparing the current angle of the document with the target angle, and based on the relative position between the image acquisition device and the document, the adjustment requirements of the image acquisition device can be determined, and control commands for controlling the robotic arm can be generated. Preferably, the robotic arm can be used to automatically traverse different acquisition angles, thereby obtaining more diverse attack samples.
[0144] Specifically, in response to the presence of a target counterfeit document in the first image, determining the second location of the target counterfeit document includes:
[0145] Determine the corner positions of the four corner points of the target counterfeit document in the first image;
[0146] Based on the corner positions of the four corner points, the second position of the target forged document is determined.
[0147] Optionally, a regression-based corner detection algorithm, such as the SIFT algorithm, can be used to extract the corner positions of the four corners of the target counterfeit document in the first image.
[0148] Optionally, after adjusting the acquisition angle to acquire an image of the target counterfeit document, the acquired document image is input into the quality detection model; based on the detection results of the quality detection model, the target image is determined.
[0149] Preferably, taking a smartphone as an example, when capturing an image of a counterfeit document, a client for image capture is launched on the phone, and a box appears on the screen to prompt the user to place the document into the box. For example... Figure 2 As shown, Figure 2An exemplary flowchart of a document collection method described in one or more embodiments of this specification is shown, specifically including the following steps:
[0150] S400: The robotic arm adjusts the mobile phone to a preset first position to place the target counterfeit document into the capture box on the screen, and captures the image with a range slightly larger than the actual box to obtain the first image.
[0151] S402: Input the first image into the first-level CNN network. If no document is detected, return to S400 to re-acquire; otherwise, continue to execute S404.
[0152] S404: If the first-level CNN network detects the existence of the document, it obtains the corner position information of the document and determines the second position of the target forged document.
[0153] S406: Based on the angle adjustment strategy in the image acquisition strategy and the first position and the second position, control the robotic arm to adjust the mobile phone to the target angle, and capture the image of the document in a range slightly larger than the corner point range of the document to obtain the second image.
[0154] S408: The second-level CNN network detects whether the type and quality of the forged document in the second image meet the requirements. If it does not meet the requirements, the user is given feedback on the reasons and suggestions for modification through the interactive window, such as the angle being too large or the image being unclear.
[0155] S410: If the type and quality of the target forged document meet the requirements, select the image with the best quality within the specified time as the target image.
[0156] It should be noted that the first-level CNN network and the second-level CNN network can be the same network or different networks.
[0157] The quality detection in this embodiment includes document type detection and document quality detection. The second-level CNN network performs document type detection by checking whether the positions of various information items in the document image match the corresponding document type; for example, it detects the position of a face in the document image. Optionally, an image of the reverse side of the document can be captured and input into the second-level CNN network for more accurate determination of whether the document type meets the requirements. Document quality detection mainly assesses whether the clarity, completeness, and tilt angle of the document image ensure that valid information representing the user's identity can be identified from the target image.
[0158] S304: Input at least one target image into the document anti-counterfeiting model to obtain the recognition result.
[0159] In response to the type of forgery detected in the target counterfeit document, the corresponding document anti-counterfeiting model will perform anti-counterfeiting identification and return the identification result, i.e., whether the model input is a counterfeit document or a genuine document. The training method for the document anti-counterfeiting model can be found in [reference needed]. Figure 1 The embodiments shown will not be described again here.
[0160] S306: Based on the identification results, determine the breakthrough rate of this attack; based on the breakthrough rate, determine the excitation signal; input the excitation signal and the image acquisition environment into the policy model so that the policy model can use reinforcement learning to update the image acquisition strategy.
[0161] The strategy model uses reinforcement learning to update the image acquisition environment based on the returned stimulus signals and generate new angle adjustment strategies. It learns and updates round after round with the increase in the breakthrough rate as a positive incentive, so that the angle adjustment strategy generated by the strategy model can stably break the document anti-counterfeiting model.
[0162] Preferably, in some embodiments, the image acquisition strategy includes a lighting adjustment strategy and an angle adjustment strategy, then the testing method for the document anti-counterfeiting model includes:
[0163] S500: Image acquisition strategy output by the acquisition strategy model.
[0164] S502: Based on the light adjustment strategy and the angle adjustment strategy, the target forged document is image acquired to obtain at least one target image.
[0165] S504: Input at least one target image into the document anti-counterfeiting model to obtain the recognition result.
[0166] S506: Based on the identification results, determine the breakthrough rate of this round of attack; based on the breakthrough rate, determine the excitation signal; input the excitation signal and the image acquisition environment into the policy model so that the policy model can use reinforcement learning to update the image acquisition strategy.
[0167] The image acquisition strategy includes a lighting adjustment strategy and an angle adjustment strategy, generated by a strategy model. The image acquisition strategy determines the environmental and motion parameters involved when acquiring counterfeit documents using the target terminal, including but not limited to the light intensity and angle in the lighting adjustment strategy, and the document pose data in the angle adjustment strategy. By simultaneously executing the lighting and angle adjustment strategies, adjusting both the lighting environment and the acquisition angle of the counterfeit document, feature information at different locations on the document can be acquired more effectively, improving the accuracy and efficiency of document anti-counterfeiting.
[0168] In some embodiments of this specification, an optimization method for a document anti-counterfeiting model is also proposed, such as... Figure 3As shown, this includes continuously optimizing the document anti-counterfeiting model for at least one round until a document anti-counterfeiting model that meets preset conditions is obtained; wherein, each round of optimization includes:
[0169] S600: At least one round of attack is performed on the document anti-counterfeiting model using any of the above-mentioned test methods.
[0170] S602: For each round of attack, if the breakthrough rate of the attack is higher than the preset breakthrough rate threshold, then the target forged document is captured in the image acquisition environment corresponding to the attack, and at least one sample image is obtained.
[0171] S604: Add negative sample labels to the sample images.
[0172] S606: Train an anti-counterfeiting model for identification documents based on sample images and negative sample labels.
[0173] The optimization method described in this embodiment utilizes any of the above-mentioned testing methods for document anti-counterfeiting models to find an attack strategy capable of reliably breaking through the document anti-counterfeiting model. This attack strategy includes the aforementioned image acquisition strategy. Therefore, for the found attack strategy, counterfeit documents are collected as training samples in the corresponding image acquisition environment, and the document anti-counterfeiting model is trained and optimized under supervision. Specifically, after inputting the sample images into the document anti-counterfeiting model, the recognition result is obtained. The difference between the recognition result and the negative sample label is calculated, and the document anti-counterfeiting model is optimized with the goal of minimizing this difference until a document anti-counterfeiting model capable of reliably identifying counterfeit documents is obtained.
[0174] In some embodiments of this specification, a testing device 70 for a document anti-counterfeiting model is also provided, such as... Figure 4 As shown, the attack used to conduct at least one round of attacks on the anti-counterfeiting model of the document includes:
[0175] The strategy generation module 72 is configured to generate an image acquisition strategy based on a strategy model; and to determine the attack rate of each attack based on the recognition result of the target image by the document anti-counterfeiting model in each round of attack, determine the excitation signal based on the attack rate, and input the excitation signal into the strategy model so that the strategy model can use reinforcement learning to update the image acquisition strategy.
[0176] Image acquisition device 74 is configured to acquire images of the target counterfeit document based on an image acquisition strategy, and obtain at least one target image.
[0177] Image acquisition strategies determine the environmental or action parameters involved when acquiring counterfeit documents using a target terminal. Image acquisition strategies include at least one of lighting adjustment strategies and angle adjustment strategies. The parameters to be determined include, but are not limited to, the light intensity and angle in the lighting adjustment strategy, or the document pose data in the angle adjustment strategy. Target images of counterfeit documents acquired through different image acquisition strategies exhibit certain differences in their features, which can affect the recognition results of the document anti-counterfeiting model, thus resulting in different attack effects. Therefore, adjusting the image acquisition strategy can yield better attack results, allowing for rapid and effective testing of the anti-counterfeiting capabilities of the document anti-counterfeiting model.
[0178] In some embodiments, the image acquisition strategy includes a light adjustment strategy; the device further includes an environment adjustment module, which is used to adjust at least one of the angle and intensity of the light illuminating the target counterfeit document based on the light adjustment strategy.
[0179] In some embodiments, the image acquisition strategy includes an angle adjustment strategy; the device further includes a robotic arm and a robotic arm control module;
[0180] The robotic arm is used to grasp an image acquisition device and adjust the image acquisition device to a preset first position; and in response to control commands, adjust the image acquisition device to a target angle specified by an angle adjustment strategy;
[0181] The image acquisition device is also used to acquire an image of the target area at a first location to obtain a first image; and in response to the presence of a target counterfeit document in the first image, to determine a second location of the target counterfeit document;
[0182] The robotic arm control module is used to generate control commands based on the first position, the second position, and the angle adjustment strategy.
[0183] Specifically, the image acquisition device is also used to determine the corner positions of the four corner points of the target counterfeit document in the first image; based on the corner positions of the four corner points, the second position of the target counterfeit document is determined.
[0184] In some embodiments, the apparatus further includes a quality detection module; the quality detection module is used to input the document image acquired by the image acquisition device into the quality detection model, and determine the target image based on the detection result of the quality detection model.
[0185] The quality inspection module ensures that the document images entering the anti-counterfeiting process meet quality requirements, improving anti-counterfeiting efficiency. If the quality inspection result is satisfactory, the captured document image is designated as the target image; otherwise, the reason for the document's substandard quality is fed back to the user, and the user is guided to adjust and recapture the document image through an interactive page.
[0186] The strategy generation module responds to the forgery type of the target counterfeit document by inputting the target image captured by the image acquisition device into the corresponding document anti-counterfeiting model for anti-counterfeiting identification, obtaining the identification result, i.e., whether the model input is a counterfeit document or a genuine document. The strategy generation module determines the breach rate of the current attack by calculating the ratio of the number of times the document anti-counterfeiting model is compromised to the total number of attacks within a certain period of time. Under each round of attacks, a higher breach rate indicates a lower anti-counterfeiting capability score for the document anti-counterfeiting model, and a greater need for optimization.
[0187] In some embodiments, the strategy generation module determines the incentive signal based on the breakthrough rate, specifically including:
[0188] For each round of attack, a positive excitation signal is determined if the breakthrough rate of the current round of attack is higher than that of the previous round of attack; a negative excitation signal is determined if the breakthrough rate of the current round of attack is lower than that of the previous round of attack.
[0189] In each round of attack, the strategy generation module first generates an image acquisition strategy. Based on the current image acquisition strategy, it controls the image acquisition device to acquire the target counterfeit document. The strategy generation module obtains the target image and inputs it into the document anti-counterfeiting model for attack. Based on the recognition results of the document anti-counterfeiting model, it determines the breakthrough rate and the incentive signal. The breakthrough rate reflects the attack strength of the counterfeit document in the current image acquisition environment. The strategy generation module uses reinforcement learning to update the image acquisition environment based on the returned incentive signal and generate a new image acquisition strategy. With the increase in the breakthrough rate as a positive incentive, it performs rounds of learning and updating, ultimately enabling the image acquisition strategy generated by the updated strategy model to stably break the document anti-counterfeiting model.
[0190] In some embodiments of this specification, an optimization device 80 for a document anti-counterfeiting model is also proposed, such as... Figure 5 As shown, it includes: the testing device 70 as described in any of the above, the identification module 82, the data acquisition module 84, and the optimization module 86;
[0191] The identification module 82 identifies the target image input into the test device 70 in each round of attack using the deployed document anti-counterfeiting model, and outputs the identification result;
[0192] The data acquisition module 84 is configured to determine the breakthrough rate of the document anti-counterfeiting model in the current round of attack based on the recognition results; when the breakthrough rate is greater than the preset breakthrough rate threshold, the target counterfeit document is image acquired in the image acquisition environment corresponding to the current round of attack to obtain at least one sample image and add negative sample labels to the sample image.
[0193] The optimization module 86 is configured to train the document anti-counterfeiting model based on sample images and negative sample labels.
[0194] The testing device was used to find attack strategies that could reliably break through the document anti-counterfeiting model. These strategies included image acquisition techniques. Therefore, the data acquisition module collected counterfeit documents as training samples in the corresponding image acquisition environment, based on the found attack strategies. The optimization module then performed supervised training and optimization of the document anti-counterfeiting model. Specifically, the optimization module input the sample images obtained by the data acquisition module into the document anti-counterfeiting model to obtain the recognition results, calculated the difference between the recognition results and the negative sample labels, and optimized the document anti-counterfeiting model with the goal of minimizing this difference until a document anti-counterfeiting model that could reliably identify counterfeit documents was obtained.
[0195] One embodiment of this specification also provides a computer-readable storage medium storing a computer program thereon, which, when executed by a processor, performs at least one round of attack on the anti-counterfeiting model of the document; wherein each round of attack includes:
[0196] Obtain the image acquisition strategy output by the strategy model;
[0197] Based on the image acquisition strategy, images of the target counterfeit document are acquired to obtain at least one target image;
[0198] Input the at least one target image into the document anti-counterfeiting model to obtain the recognition result;
[0199] Based on the identification results, the success rate of this attack is determined;
[0200] Based on the aforementioned breakthrough rate, an excitation signal is determined;
[0201] The excitation signal is input into the policy model so that the policy model updates the image acquisition policy using reinforcement learning.
[0202] This specification also provides an electronic device, including:
[0203] One or more processors; and a memory associated with the one or more processors, the memory storing program instructions that, when read and executed by the one or more processors, enable the one or more processors to perform at least one round of attack on the document anti-counterfeiting model; wherein each round of attack includes:
[0204] Obtain the image acquisition strategy output by the strategy model;
[0205] Based on the image acquisition strategy, images of the target counterfeit document are acquired to obtain at least one target image;
[0206] Input the at least one target image into the document anti-counterfeiting model to obtain the recognition result;
[0207] Based on the identification results, the success rate of this attack is determined;
[0208] Based on the aforementioned breakthrough rate, an excitation signal is determined;
[0209] The excitation signal is input into the policy model so that the policy model updates the image acquisition policy using reinforcement learning.
[0210] This specification also provides a computer-readable storage medium storing a computer program thereon. When executed by a processor, the computer program performs at least one round of optimization on a document anti-counterfeiting model until a document anti-counterfeiting model that meets preset conditions is obtained; wherein each round of optimization includes:
[0211] At least one round of attack is performed on the document anti-counterfeiting model using any of the above-mentioned testing methods;
[0212] For each round of attack, if the breakthrough rate of the attack is higher than the preset breakthrough rate threshold, then the target forged document will be captured in the image acquisition environment corresponding to the attack to obtain at least one sample image.
[0213] Add negative sample labels to the sample images;
[0214] The document anti-counterfeiting model is trained based on the sample images and the negative sample labels.
[0215] This specification also provides an electronic device, including:
[0216] One or more processors; and a memory associated with the one or more processors, the memory storing program instructions that, when read and executed by the one or more processors, cause the one or more processors to perform at least one round of optimization on the document anti-counterfeiting model until a document anti-counterfeiting model that meets preset conditions is obtained; wherein each round of optimization includes:
[0217] At least one round of attack is performed on the document anti-counterfeiting model using any of the above-mentioned testing methods;
[0218] For each round of attack, if the breakthrough rate of the attack is higher than the preset breakthrough rate threshold, then the target forged document will be captured in the image acquisition environment corresponding to the attack to obtain at least one sample image.
[0219] Add negative sample labels to the sample images;
[0220] The document anti-counterfeiting model is trained based on the sample images and the negative sample labels.
[0221] It should be noted that the testing and optimization devices for the aforementioned document anti-counterfeiting model can be deployed in the same terminal device or in different terminal devices. Furthermore, the modules within the testing and optimization devices can also be deployed in the same terminal device or in different terminal devices. Different terminal devices are connected via communication links, which can be wired or wireless networks. For example, different terminal devices can establish communication connections using methods such as Wi-Fi, Bluetooth, or infrared. Alternatively, different terminal devices can also establish communication connections through mobile networks, where the mobile network standard can be any one of 2G (GSM), 2.5G (GPRS), 3G (WCDMA, TD-SCDMA, CDMA2000, UTMS), 4G (LTE), 4G+ (LTE+), WiMax, etc.
[0222] Preferably, a robotic arm can be introduced to grasp the image acquisition device for image acquisition, and the corresponding testing system for the document anti-counterfeiting model is as follows: Figure 6 As shown, it should be noted that the testing method for the document anti-counterfeiting model described in one or more embodiments of this specification can be implemented using the testing system for the document anti-counterfeiting model, but is not limited to the testing system for the document anti-counterfeiting model.
[0223] Please refer to Figure 6 The testing system for the document anti-counterfeiting model includes a target terminal, a robotic arm, and a control terminal.
[0224] Target terminals include mobile devices such as smartphones, laptops, and iPads. Each target terminal has a front-end app installed with document image capture capabilities. This app, through its built-in capture SDK, can perform a series of operations, including document detection, tracking, and quality checks, to obtain target images of acceptable quality. Additionally, the target terminals deploy various types of document anti-counterfeiting models for identification based on the type of counterfeit document, including but not limited to screen captures, color-printed documents, high-quality counterfeit documents, and documents with attached portraits.
[0225] Under the control of the control terminal, the robotic arm executes the image acquisition strategy, grabs the target terminal and acquires target images in different acquisition environments for anti-counterfeiting identification, and adjusts the acquisition environment of the target terminal based on the strategy update results returned by the control terminal.
[0226] The control unit can be deployed inside the robotic arm or separately outside the robotic arm. It is used to generate image acquisition strategies based on the strategy model and control the robotic arm to execute the image acquisition strategies. This control unit can be any device, equipment, platform, or equipment cluster with computing and processing capabilities.
[0227] The strategy model within the control terminal generates image acquisition strategies based on different lighting conditions and / or different acquisition angles. The control terminal then controls a robotic arm to simulate the corresponding acquisition environment to capture the target image from the target terminal and attack the corresponding type of document anti-counterfeiting model. The control terminal collects the attack results and image acquisition environment data to update the strategy model and generate a new image acquisition strategy for a new round of attacks. During this process, the document anti-counterfeiting model is optimized based on the attack data, thereby improving its anti-counterfeiting capabilities and efficiency.
[0228] Specifically, when executing an image acquisition strategy using a robotic arm, the acquisition angle of the robotic arm grasping the image acquisition device can be adjusted according to the angle adjustment strategy, including:
[0229] First, the robotic arm is controlled to adjust the image acquisition device to a preset first position so that the target counterfeit document to be acquired enters the acquisition range. Then, by detecting the first image, it is determined whether the valid part of the target counterfeit document falls within the acquisition range of the image acquisition device. If the target counterfeit document is detected within the acquisition range, the coordinates of the four corner points of the target counterfeit document in the first image are determined. The angle annotation information of the target counterfeit document is calculated based on the coordinates of the corner points. For example, after calculating the side length of the document, the angle annotation information is determined by calculating the ratio between each pair of side lengths. Then, the angle annotation information is learned by regression to obtain the current attitude angle of the target counterfeit document in each direction. Regression learning is continued to be used to obtain the angle data generated by the document's rotation around the x-axis, y-axis, and z-axis based on the attitude angle, including pitch, yaw, and roll angles, thereby obtaining the current angle of the target counterfeit document and determining the second position. The control unit determines the adjustment angle and generates control commands based on the comparison between the current angle of the target counterfeit document and the target angle. The robotic arm adjusts the relative position between the image acquisition device and the target counterfeit document based on the control commands until the target angle is reached, and then performs image acquisition on the target counterfeit document at the target angle.
[0230] Figure 7 An exemplary structural diagram of an electronic device provided in an embodiment of this specification is shown, illustrating a structural schematic diagram of a computer system 900 suitable for implementing a terminal device or server of the present invention. Figure 7 The terminal device or server shown is merely an example and should not impose any limitation on the functionality and scope of use of the embodiments of the present invention.
[0231] In a typical configuration, computer 900 includes one or more processors (CPU) 902, input interface 904, output interface 906, network interface 908, and memory 910.
[0232] The memory 910 may include non-persistent memory in the form of computer-readable media, random access memory (RAM), and / or non-volatile memory, such as read-only memory (ROM) or flash RAM. Memory is an example of computer-readable media.
[0233] Computer-readable media, including both permanent and non-permanent, removable and non-removable media, can store information using any method or technology. Information can be computer-readable instructions, data structures, modules of programs, or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, CD-ROM, digital versatile optical disc (DVD) or other optical storage, magnetic tape, disk storage, quantum memory, graphene-based storage media or other magnetic storage devices, or any other non-transferable medium that can be used to store information accessible by a computing device. As defined herein, computer-readable media does not include transient computer-readable media, such as modulated data signals and carrier waves.
[0234] The foregoing has described specific embodiments of this specification. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims may be performed in a different order than that shown in the embodiments and may still achieve the desired result. Furthermore, the processes depicted in the drawings do not necessarily require the specific or sequential order shown to achieve the desired result. In some embodiments, multitasking and parallel processing are possible or may be advantageous.
[0235] It should be understood that although the terms first, second, third, etc., may be used to describe various information in one or more embodiments of this specification, such information should not be limited to these terms. These terms are only used to distinguish information of the same type from one another. For example, first information may also be referred to as second information without departing from the scope of one or more embodiments of this specification, and similarly, second information may also be referred to as first information. Depending on the context, the word "if" as used herein may be interpreted as "when," "in response to a determination," or "when," or "in the event of a determination."
[0236] It should be noted that the above examples are merely specific embodiments of the present invention, and the present invention is obviously not limited to the above embodiments, with many similar variations. All modifications that can be directly derived or conceived by those skilled in the art from the content disclosed in this invention should fall within the protection scope of this invention.
Claims
1. A testing method for an anti-counterfeiting model of an identification document, comprising performing at least one round of attacks on the anti-counterfeiting model; wherein, Each round of attacks includes: The image acquisition strategy output by the strategy model is obtained. The image acquisition strategy is used to adjust at least one of the light intensity, light angle and document posture data when acquiring counterfeit documents, so that the features presented by the acquired image have differences that can affect the recognition results of the document anti-counterfeiting model, thereby having different attack effects. Based on the image acquisition strategy, images of the target counterfeit document are acquired to obtain at least one target image; The at least one target image is input into the document anti-counterfeiting model to attack the document anti-counterfeiting model and obtain the recognition result; Based on the identification results, the success rate of this attack is determined; Based on the aforementioned breakthrough rate, an excitation signal is determined; The excitation signal and the image acquisition environment are input into the policy model, which employs a reinforcement learning method to update the image acquisition policy in the direction of increasing the breakthrough rate.
2. The method as described in claim 1, wherein the image acquisition strategy includes a lighting adjustment strategy; and the image acquisition of the target counterfeit document based on the image acquisition strategy specifically includes: Based on the light adjustment strategy, at least one of the angle and intensity of the light illuminating the target counterfeit document is adjusted to obtain the target light environment; Under the target lighting conditions, images of the target counterfeit document are captured.
3. The method as described in claim 1, wherein the image acquisition strategy includes an angle adjustment strategy; and image acquisition of the target counterfeit document based on the image acquisition strategy specifically includes: The image acquisition device is grasped by a robotic arm and adjusted to a preset first position; At the first position, the image acquisition device acquires an image of the target area to obtain a first image; In response to the presence of the target counterfeit document in the first image, a second location of the target counterfeit document is determined; Based on the first position, the second position, and the angle adjustment strategy, control commands are generated; The robotic arm executes the control commands to adjust the image acquisition device to the target angle specified by the angle adjustment strategy, and acquires an image of the target counterfeit document at the target angle.
4. The method of claim 3, wherein determining the second location of the target counterfeit document in response to the presence of the target counterfeit document in the first image specifically includes: Determine the corner positions of the four corner points of the target counterfeit document in the first image; Based on the corner positions of the four corner points, the second position of the target counterfeit document is determined.
5. The method as described in claim 1, wherein determining the excitation signal based on the breakthrough rate specifically includes: For each round of attack, a positive excitation signal is determined in response to the higher breakthrough rate of the current round of attack compared to the breakthrough rate of the previous round of attack. A negative incentive signal is identified in response to the lower breakthrough rate of this round of attacks compared to the previous round.
6. The method of claim 1, further comprising: After capturing images of the target counterfeit document, the captured document images are input into the quality detection model; The target image is determined based on the detection results of the quality detection model.
7. A method for optimizing a document anti-counterfeiting model, comprising continuously optimizing the document anti-counterfeiting model for at least one round until a document anti-counterfeiting model that meets preset conditions is obtained; wherein, Each round of optimization includes: At least one round of attack is carried out on the document anti-counterfeiting model using the method described in any one of claims 1 to 6; For each round of attack, if the breakthrough rate of the attack is higher than the preset breakthrough rate threshold, then the target forged document will be captured in the image acquisition environment corresponding to the attack to obtain at least one sample image. Add negative sample labels to the sample images; The document anti-counterfeiting model is trained based on the sample images and the negative sample labels.
8. A testing device for an anti-counterfeiting model of an identification document, used to perform at least one round of attacks on the anti-counterfeiting model of the identification document, the device comprising: The strategy generation module is configured to generate an image acquisition strategy based on a strategy model. This image acquisition strategy adjusts at least one of the following when acquiring data on the light intensity, light angle, and document pose of a counterfeit document: the acquired image exhibits features that influence the recognition results of the document anti-counterfeiting model, thus achieving different attack effects. Furthermore, based on the document anti-counterfeiting model's recognition results of the target image in each attack round, the module determines the attack success rate for each round, determines an excitation signal based on the success rate, and inputs the excitation signal and the image acquisition environment into the strategy model. The strategy model employs reinforcement learning to update the image acquisition strategy in the direction of increasing the success rate. An image acquisition device is configured to acquire images of a target counterfeit document based on the image acquisition strategy, thereby obtaining at least one target image.
9. The apparatus of claim 8, wherein the image acquisition strategy includes a light adjustment strategy; the apparatus further includes an environment adjustment module, the environment adjustment module being configured to adjust at least one of the angle and intensity of the light illuminating the target counterfeit document based on the light adjustment strategy.
10. The apparatus of claim 8, wherein the image acquisition strategy includes an angle adjustment strategy; the apparatus further includes a robotic arm and a robotic arm control module; The robotic arm is used to grasp the image acquisition device and adjust the image acquisition device to a preset first position; and in response to a control command, adjust the image acquisition device to a target angle specified by the angle adjustment strategy; The image acquisition device is also used to acquire an image of the target area at the first position to obtain a first image; And in response to the presence of the target counterfeit document in the first image, determine the second location of the target counterfeit document; The robotic arm control module is used to generate the control commands based on the first position, the second position, and the angle adjustment strategy.
11. The apparatus of claim 8, further comprising a quality detection module; the quality detection module is configured to input the document image acquired by the image acquisition device into a quality detection model, and determine the target image based on the detection result of the quality detection model.
12. An optimization device for an anti-counterfeiting model of an identification document, comprising: The testing apparatus, identification module, data acquisition module, and optimization module as described in any one of claims 8 to 11; The identification module identifies the target image input into the test device in each round of attack using the deployed document anti-counterfeiting model, and outputs the identification result. The data acquisition module is configured to determine the breakthrough rate of the document anti-counterfeiting model in the current round of attack based on the recognition result; when the breakthrough rate is greater than the preset breakthrough rate threshold, to perform image acquisition on the target counterfeit document in the image acquisition environment corresponding to the current round of attack, to obtain at least one sample image, and to add negative sample labels to the sample image. The optimization module is configured to train the document anti-counterfeiting model based on the sample images and the negative sample labels.
13. A computer-readable storage medium having a computer program stored thereon, the computer program, when executed by a processor, implementing at least one round of attack on an anti-counterfeiting model of an identification document; wherein, Each round of attacks includes: The image acquisition strategy output by the strategy model is obtained. The image acquisition strategy is used to adjust at least one of the light intensity, light angle and document posture data when acquiring counterfeit documents, so that the features presented by the acquired image have differences that can affect the recognition results of the document anti-counterfeiting model, thereby having different attack effects. Based on the image acquisition strategy, images of the target counterfeit document are acquired to obtain at least one target image; The at least one target image is input into the document anti-counterfeiting model to attack the document anti-counterfeiting model and obtain the recognition result; Based on the identification results, the success rate of this attack is determined; Based on the aforementioned breakthrough rate, an excitation signal is determined; The excitation signal and the image acquisition environment are input into the policy model, which employs a reinforcement learning method to update the image acquisition policy in the direction of increasing the breakthrough rate.
14. An electronic device comprising: One or more processors; and a memory associated with the one or more processors, the memory storing program instructions that, when read and executed by the one or more processors, enable the one or more processors to perform at least one round of attack on the document anti-counterfeiting model; wherein each round of attack includes: The image acquisition strategy output by the strategy model is obtained. The image acquisition strategy is used to adjust at least one of the light intensity, light angle and document posture data when acquiring counterfeit documents, so that the features presented by the acquired image have differences that can affect the recognition results of the document anti-counterfeiting model, thereby having different attack effects. Based on the image acquisition strategy, images of the target counterfeit document are acquired to obtain at least one target image; The at least one target image is input into the document anti-counterfeiting model to attack the document anti-counterfeiting model and obtain the recognition result; Based on the identification results, the success rate of this attack is determined; Based on the aforementioned breakthrough rate, an excitation signal is determined; The excitation signal and the image acquisition environment are input into the policy model, which employs a reinforcement learning method to update the image acquisition policy in the direction of increasing the breakthrough rate.
15. A computer-readable storage medium storing a computer program thereon, wherein the computer program, when executed by a processor, performs at least one round of optimization on an anti-counterfeiting model of an identification document until an anti-counterfeiting model of the identification document that satisfies preset conditions is obtained; wherein, Each round of optimization includes: At least one round of attack is carried out on the document anti-counterfeiting model using the method described in any one of claims 1 to 6; For each round of attack, if the breakthrough rate of the attack is higher than the preset breakthrough rate threshold, then the target forged document will be captured in the image acquisition environment corresponding to the attack to obtain at least one sample image. Add negative sample labels to the sample images; The document anti-counterfeiting model is trained based on the sample images and the negative sample labels.
16. An electronic device comprising: One or more processors; and a memory associated with the one or more processors, the memory storing program instructions, which, when read and executed by the one or more processors, cause the one or more processors to perform at least one round of optimization on the document anti-counterfeiting model until a document anti-counterfeiting model that meets preset conditions is obtained; wherein each round of optimization includes: At least one round of attack is carried out on the document anti-counterfeiting model using the method described in any one of claims 1 to 6; For each round of attack, if the breakthrough rate of the attack is higher than the preset breakthrough rate threshold, then the target forged document will be captured in the image acquisition environment corresponding to the attack to obtain at least one sample image. Add negative sample labels to the sample images; The document anti-counterfeiting model is trained based on the sample images and the negative sample labels.
Citation Information
Patent Citations
Adversarial sample generation method and device, terminal and readable storage medium
CN111461226A
Power transmission line defect identification method and system based on edge computing
WO2023005100A1