AI-powered forensics platforms, methods, and electronic devices for automatically processing non-forensic content

By using the evidence collection anomaly handling model of the AI ​​evidence collection platform, non-evidence content can be identified and processed in real time, solving the problems of incomplete manual operation and easy failure of fixed code in traditional evidence collection, and realizing the integrity of recorded videos and improving the credibility of evidence.

CN121462786BActive Publication Date: 2026-05-26BEIJING UNITED TRUST TECH SERVICE CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
BEIJING UNITED TRUST TECH SERVICE CO LTD
Filing Date
2026-01-06
Publication Date
2026-05-26

Smart Images

  • Figure CN121462786B_ABST
    Figure CN121462786B_ABST
Patent Text Reader

Abstract

This application discloses an AI forensics platform, method, and electronic device for automatically processing non-evidence-collecting content. The AI ​​forensics platform performs the following processing: receiving video data of the evidence-collecting object recorded in real time by the forensics device; inputting the video data into an evidence-collecting anomaly handling model, which performs the following processing: parsing the video data of the current frame to determine whether the currently recorded screen is an abnormal evidence-collecting screen; if it is an abnormal evidence-collecting screen, identifying the type of content in the abnormal evidence-collecting screen; if it is a direct-close type, outputting a processing strategy to directly close the content; if it is a parsing processing type, generating a processing strategy corresponding to the parsing result of the content; calling the API interface of the operating system of the forensics device and sending a request to the operating system to execute the processing strategy to restore normal recording of the evidence-collecting object. This application can automatically process non-evidence-collecting content during screen recording forensics, achieving automatic forensics.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of forensics technology, and in particular to an AI forensics platform, method and electronic device for automatically processing non-forensic content. Background Technology

[0002] In today's digital age, electronic data is increasingly used in various fields. Whether in business activities, legal affairs or daily life, it is often necessary to collect evidence of specific infringing goods or operating processes as a basis for subsequent dispute resolution or compliance review.

[0003] However, traditional evidence collection methods typically rely on manual operation of the equipment, which has several drawbacks. Firstly, manual operation can easily lead to the omission of crucial information, resulting in incomplete evidence. For example, during prolonged operation, operators may fail to capture important scenes or details due to fatigue or negligence. Secondly, during recording, electronic devices may be subject to interference from various non-evidence-gathering elements. These elements can disrupt the recording's continuity and obscure key scenes, preventing the recorded video data from accurately and completely reflecting the true situation of the subject, thus affecting the validity and credibility of the evidence. Furthermore, ensuring the authenticity, completeness, and accurate time recording of the data obtained after evidence collection is also a pressing issue that needs to be addressed.

[0004] In conclusion, current forensic technologies are significantly inadequate in dealing with interference from non-forensic content and cannot meet the growing demand for digital forensics. Summary of the Invention

[0005] In view of this, embodiments of this application provide an AI forensics platform, method, and electronic device for automatically processing non-forensic content, which can automatically handle message notification interference during screen recording forensics, and achieve automatic forensics and authentication.

[0006] In a first aspect, embodiments of this application provide an AI forensics platform for automatically processing non-evidence-collecting content. The AI ​​forensics platform is equipped with a pre-trained forensics anomaly handling model. After the AI ​​forensics platform is started, it performs the following processing: receiving video data of the evidence-collecting object recorded in real time by the forensics device; inputting the video data into the forensics anomaly handling model, which performs the following processing: parsing the video data of the current frame and determining whether the current recording screen is an abnormal evidence-collecting screen based on the video parsing result; when it is an abnormal evidence-collecting screen, identifying the type of content in the abnormal evidence-collecting screen; if the content type is the direct-close type, outputting a processing strategy for directly closing the content; if the content type is the parsing processing type, further parsing the content and generating a processing strategy corresponding to the content parsing result; calling the API interface of the operating system of the forensics device and sending a request to the operating system to execute the processing strategy, so that the operating system processes the content in the current recording screen of the forensics device according to the processing strategy and restores normal recording of the evidence-collecting object.

[0007] According to some embodiments of this application, optionally, the content in the abnormal evidence collection screen includes message notifications, and the evidence collection anomaly handling model is further used to perform the following processing: before identifying the type of content in the abnormal evidence collection screen, identifying and determining whether the message notification is evidence collection content related to the evidence collection object, and evidence collection content related to the evidence collection object includes at least one of the evidence collection object's transaction information, promotional information, and proof information; if yes, then outputting a processing strategy of not closing the message notification and continuing recording; if no, then identifying the type of content in the abnormal evidence collection screen.

[0008] According to some embodiments of this application, optionally, transaction information includes at least one of a purchase link pop-up, payment code, order confirmation prompt, and payment success prompt; promotional information includes at least one of an exclusive coupon, limited-time discount code, and group purchase success prompt; and certification information includes at least one of an official platform certificate, product qualification certificate, entity identity certificate, and genuine product and anti-counterfeiting information.

[0009] According to some embodiments of this application, optionally, the message notification type includes system notification, application message, and permission request type; if the content type is the direct close type, then the processing strategy for directly closing the content is output, including: if the message notification type is system notification or application message, then the processing strategy for directly closing the message notification is output; if the content type is the parsing processing type, then the content is further parsed, and a processing strategy corresponding to the content parsing result is generated, including: if the message notification type is the permission request type, then the permission requirements in the message notification are parsed, and based on the parsed permission type to be enabled and the preset security policy, it is determined whether the permission type can be authorized; if it is determined to be authorized, then a processing strategy for enabling the corresponding permission is generated; if it is determined to be unauthorized, then a processing strategy for recording the event and prompting the user is generated.

[0010] According to some embodiments of this application, optionally, the objects of evidence collection include goods, online meetings, software operation processes, online transaction processes, or electronic contract signing processes; system notifications include at least one of caller ID, alarm clock reminders, system update prompts, and low battery reminders; application messages include at least one of instant messaging software messages, shopping platform notifications, and application update reminders; and permission requests include permission request pop-ups.

[0011] According to some embodiments of this application, optionally, after the AI ​​forensics platform is started, it also performs the following processing: before screen recording forensics, it receives the image of the object to be recorded uploaded by the forensics device and uploads the image of the object to the forensics anomaly handling model; or, after screen recording forensics is started, it receives the image of the object to be recorded selected by the user in the recording screen uploaded by the forensics device and uploads the image of the object to the forensics anomaly handling model; the forensics anomaly handling model is also used to perform the following processing: based on image recognition and target tracking technology, it monitors whether the object to be recorded in the recording screen leaves the preset monitoring area or disappears, and records the duration of the object leaving the preset monitoring area or disappearing. When the duration reaches the preset duration, it generates a processing strategy that instructs the forensics device to close the screen recording forensics.

[0012] According to some embodiments of this application, optionally, the user's operation of selecting the evidence object includes double-clicking the evidence object, long-pressing the evidence object, or selecting the evidence object by drawing a box in the recording screen.

[0013] According to some embodiments of this application, optionally, the evidence collection anomaly handling model is also used to perform the following processing: monitoring the smoothness of the recorded screen based on video data; when the smoothness of the recorded screen is detected to be inconsistent with the preset recording requirements, obtaining the network connection parameters of the evidence collection device, and determining whether the network of the evidence collection device is normal based on the network connection parameters of the evidence collection device; if abnormal, generating a processing strategy that instructs the evidence collection object to dynamically adjust the network settings of the evidence collection device and / or dynamically adjust the recording parameters of the evidence collection object, wherein the recording parameters include at least one of resolution, image quality and frame rate.

[0014] According to some embodiments of this application, optionally, the evidence collection anomaly handling model is specifically used to perform frame rate analysis, screen content change analysis, and / or video bitstream analysis on video data in real time during screen recording evidence collection; screen content change analysis includes: calculating the image similarity or pixel difference between consecutive video frames, and determining that the screen content change is abnormal when the similarity is continuously higher than a first threshold or the difference is continuously lower than a second threshold; if the screen content change is determined to be abnormal, or the frame rate or video bitstream of the video data is less than a preset threshold, or video frames are lost, then the smoothness of the recorded screen does not meet the preset recording requirements.

[0015] According to some embodiments of this application, optionally, dynamically adjusting the network settings of the evidence collection device includes switching the network connection of the evidence collection device from a first wireless network to a first mobile data network, from the first wireless network to a second wireless network, or from the first mobile data network to the first wireless network, from the first mobile data network to the second mobile data network, or attempting to reconnect to the current network.

[0016] According to some embodiments of this application, optionally, the evidence collection anomaly handling model is also used to perform the following processing: if it is determined that the network of the evidence collection device is abnormal, the following processing strategy is output for the AI ​​evidence collection platform and the evidence collection device to perform: suspend the recording of the evidence collection object, cache the recorded video segments, and overlay a watermark indicating network abnormality and pause status on the screen during the recording pause; resume recording after adjusting the network settings of the evidence collection device and the network returns to normal.

[0017] According to some embodiments of this application, optionally, the AI ​​forensics platform communicates with a preset timestamp authentication service system. After the AI ​​forensics platform is started, it also performs the following processing: after the screen recording forensics is completed, the recorded video data is sent to the timestamp authentication service system so that the timestamp authentication service system can perform timestamp authentication on the video data.

[0018] Secondly, embodiments of this application provide an AI forensics method for automatically processing non-evidence-collecting content. This method is implemented based on the AI ​​forensics platform for automatically processing non-evidence-collecting content provided in the first aspect, and includes: receiving video data of the evidence-collecting object recorded in real time by an evidence-collecting device; inputting the video data into an evidence-collecting anomaly processing model, and performing the following processing through the evidence-collecting anomaly processing model: parsing the video data of the current frame, and determining whether the current recording screen is an abnormal evidence-collecting screen based on the video parsing result; when it is an abnormal evidence-collecting screen, identifying the type of content in the abnormal evidence-collecting screen; if the content type is a direct-close type, outputting a processing strategy for directly closing the content; if the content type is a parsing processing type, further parsing the content and generating a processing strategy corresponding to the content parsing result; calling the API interface of the operating system of the evidence-collecting device, and sending a request to the operating system to execute the processing strategy, so that the operating system processes the content in the current recording screen of the evidence-collecting device according to the processing strategy, and restores the normal recording of the evidence-collecting object.

[0019] Thirdly, embodiments of this application provide an electronic device that is equipped with an AI forensics platform for automatically processing non-forensic content, as provided in any of the above embodiments.

[0020] The AI-powered forensic platform, method, and electronic device for automatically processing non-evidence-collecting content provided by the embodiments of this application address two main issues. Firstly, traditional forensic methods typically require constant manual monitoring and handling of interference. This application automatically identifies abnormal forensic scenes (such as message notifications) using a model and generates processing strategies, which are then automatically executed by calling system APIs without human intervention. This avoids interruptions in forensic collection due to operator delays or errors, saving time and costs associated with manual waiting. Secondly, the forensic anomaly processing model can analyze video data in real time. When the currently recorded scene is an abnormal forensic scene, it can accurately distinguish the type of content within the abnormal scene, i.e., directly closing or parsing / processing. For directly closing content, the forensic device is instructed to automatically close the content, preventing it from continuously interrupting recording continuity and obscuring key scenes. This ensures that the recorded video data reflects the true situation of the forensic object more completely and accurately, improving the validity and credibility of the evidence. For parsing / processing content, the forensic anomaly processing model performs deep analysis and automatically generates processing strategies corresponding to the content analysis results, achieving automatic processing of parsing / processing content.

[0021] Furthermore, compared to writing fixed program code for abnormal evidence processing, this application utilizes an evidence abnormality processing model, which has the following advantages in terms of environmental cleanliness, evidence collection process cleanliness, and evidence cleanliness: Firstly, the evidence abnormality processing model has strong environmental adaptability and generalization capabilities, and can dynamically identify and process various unknown or changing message notifications, overcoming the limitations of high maintenance costs and easy failure of fixed program code; secondly, it achieves intelligent identification of evidence and noise, such as distinguishing and retaining transaction vouchers and prompts that are crucial to the core of evidence collection, avoiding the loss of key evidence caused by the "brutal deletion" of traditional code; and thirdly, the refined operation strategy generated by the deep analysis of the evidence abnormality processing model makes the evidence collection intervention behavior more natural and precise, reduces mechanical operation traces, enhances the coherence and credibility of the final recorded evidence, and ensures the cleanliness of the evidence chain from the source. Attached Figure Description

[0022] To more clearly illustrate the technical solutions of the embodiments of this application, the accompanying drawings of the embodiments of this application will be briefly described below.

[0023] Figure 1 This is a schematic diagram of a system architecture for an AI forensics platform that automatically processes non-forensic content, as provided in an embodiment of this application.

[0024] Figure 2 This is a schematic diagram of the execution flow of an AI forensics platform that automatically processes non-forensic content, as provided in an embodiment of this application.

[0025] Figure 3 This is a schematic diagram of a screen display when receiving an incoming call during screen recording for evidence collection.

[0026] Figure 4 This is a screenshot of a permission request pop-up window received during screen recording for evidence collection.

[0027] Figure 5 This is a schematic diagram of another execution flow of the AI ​​forensics platform for automatically processing non-forensic content provided in the embodiments of this application.

[0028] Figure 6 This document illustrates various operations a user can perform to select an object for evidence collection during the recording process. Detailed Implementation

[0029] The features and exemplary embodiments of various aspects of this application will be described in detail below. To make the objectives, technical solutions, and advantages of this application clearer, the application will be further described in detail below with reference to the accompanying drawings and specific embodiments. It should be understood that the specific embodiments described herein are only intended to explain this application and not to limit it. For those skilled in the art, this application can be implemented without some of these specific details. The following description of the embodiments is merely to provide a better understanding of this application by illustrating examples.

[0030] It should be noted that, in this document, relational terms such as "first" and "second" are used merely to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising..." does not exclude the presence of additional identical elements in the process, method, article, or apparatus that includes said element.

[0031] It should be understood that the term "and / or" used in this article is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, and B existing alone. Additionally, the character " / " in this article generally indicates that the preceding and following related objects have an "or" relationship.

[0032] Various modifications and variations can be made to this application without departing from its spirit or scope, which will be apparent to those skilled in the art. Therefore, this application is intended to cover modifications and variations falling within the scope of the corresponding claims (the claimed technical solutions) and their equivalents. It should be noted that the implementation methods provided in the embodiments of this application can be combined with each other without contradiction.

[0033] Before describing the technical solutions provided in the embodiments of this application, in order to facilitate understanding of the embodiments of this application, this application first specifically explains the problems existing in the related technologies:

[0034] In today's digital age, electronic data is increasingly used in various fields. Whether in business activities, legal affairs or daily life, it is often necessary to collect evidence of specific infringing goods or operating processes as a basis for subsequent dispute resolution or compliance review.

[0035] However, traditional evidence collection methods typically rely on manual operation of the equipment, which has several drawbacks. Firstly, manual operation can easily lead to the omission of crucial information, resulting in incomplete evidence. For example, during prolonged operation, operators may fail to capture important scenes or details due to fatigue or negligence. Secondly, during recording, electronic devices may be interfered with by various non-evidence-gathering content (such as message notifications). This non-evidence-gathering content not only disrupts the continuity of the recording but may also obscure key scenes being recorded, making the recorded video data unable to accurately and completely reflect the true situation of the subject, thus affecting the validity and credibility of the evidence. Furthermore, ensuring the authenticity, completeness, and accurate time recording of the data obtained after evidence collection is also a pressing issue that needs to be addressed.

[0036] To alleviate the burden of manual operations, some solutions attempt to automate the handling of abnormal content by writing fixed program code (scripts). These scripts typically use preset rules (such as recognizing window titles or clicking at fixed coordinates) to automatically close advertisements and other distractions. However, this method of writing fixed program code has poor environmental adaptability. For example, once the software interface is updated, the message notification style changes, or new types of interference appear, the preset rules will become invalid, requiring constant manual maintenance, which is costly and has downtime. More importantly, the processing logic of the written fixed program code is blind, making it difficult to distinguish whether a message notification is an irrelevant advertisement or a transaction certificate, risk warning, or authorization certificate that is crucial for evidence collection. This one-size-fits-all, crude removal can easily lead to the accidental deletion of key evidence, directly damaging the integrity of the evidence chain, and may even render the evidence invalid due to tampering with key information, bringing serious legal risks. In addition, the mechanical operation trajectory can easily leave unnatural traces in the recorded video, which may raise questions about the authenticity and originality of the evidence.

[0037] To address the technical problems existing in related technologies, this application provides an AI forensics platform, method, and electronic device for automatically processing non-evidence-collecting content. It can automatically process non-evidence-collecting content interference during screen recording forensics by using an evidence anomaly processing model, so that the recorded video data can reflect the real situation of the evidence-collecting object more completely and accurately, and is conducive to improving the cleanliness of the evidence-collecting environment, the cleanliness of the evidence-collecting process, and the cleanliness of the evidence.

[0038] The AI ​​forensics platform for automatically processing non-forensic content provided in the embodiments of this application will be introduced first.

[0039] Figure 1 This is a schematic diagram of a system architecture for an AI forensics platform that automatically processes non-forensic content, as provided in an embodiment of this application. Figure 1As shown, the system may include at least an evidence-gathering device 11 and a server 12. An AI evidence-gathering platform 100, which automatically processes non-evidence-gathering content, may be deployed on the server 12. The evidence-gathering device 11 may have a client installed, such as an evidence-gathering client. This client may be a client specifically designed to perform a particular function (such as an application app), or a client embedded with multiple application applets (with different functions), or a client logged in via a browser; this application does not limit the scope of this application. The evidence-gathering device 11 may be a smartphone, tablet, laptop, desktop computer, smart TV, various wearable devices, augmented reality (AR) devices, or virtual reality (VR) devices, etc.; this application does not limit the scope of this application.

[0040] like Figure 1 As shown, in some embodiments, the AI ​​forensics platform 100 can communicate with a timestamp authentication service system 13, which can be a system specifically designed to provide time stamping and authentication functions for data. After the AI ​​forensics platform 100 completes screen recording for evidence collection, the timestamp authentication service system 13 can add a precise timestamp to the recorded video data. This timestamp is similar to a "birth certificate" for the evidence, recording the exact time the evidence was generated. In this way, the authenticity, completeness, and timeliness of the evidence can be ensured, enhancing its legal credibility and validity.

[0041] Figure 2 This is a schematic diagram illustrating the execution flow of an AI forensics platform for automatically processing non-forensic content, as provided in an embodiment of this application. Figure 2 As shown, after the AI ​​forensics platform is started, it will execute the following steps S201 to S203.

[0042] S201: Receive video data of the evidence-collecting object recorded in real time by the evidence-collecting device.

[0043] Specifically, combined Figure 1 and Figure 2 As shown, users can input screen recording commands on the evidence collection client in the evidence collection device 11, such as clicking the "Start Screen Recording" button, using language input, or using shortcut keys. The evidence collection device 11 can respond to the user's screen recording command, start the screen recording function, and begin screen recording of the evidence collection object. The AI ​​evidence collection platform 100 can receive the video data of the evidence collection object recorded in real time by the evidence collection device 11.

[0044] S202: Input the video data into the evidence collection anomaly processing model. The evidence collection anomaly processing model is used to perform the following processing: parse the video data of the current frame and determine whether the current recorded screen is an abnormal evidence collection screen based on the video parsing result; when it is an abnormal evidence collection screen, identify the type of content in the abnormal evidence collection screen; if the content type is the direct closure type, output the processing strategy for directly closing the content; if the content type is the parsing processing type, further parse the content and generate a processing strategy corresponding to the content parsing result.

[0045] The AI ​​forensics platform 100 is equipped with a pre-trained forensics anomaly handling model. This model can be a pre-trained AI model, machine learning model, or intelligent recognition and control model, etc. The AI ​​model includes, but is not limited to, large AI models; this application does not limit this. In some embodiments, the forensics anomaly handling model can be obtained by training or fine-tuning an AI model, machine learning model, or intelligent recognition and control model. Specifically, a large amount of sample video data containing various non-forensic content can be collected as training data. The training data can cover different types of non-forensic content (such as directly closing content and parsing / processing content), as well as different device screen images, etc. Simultaneously, the training data can be labeled, such as annotating the location and type of non-forensic content in the video, and the correct handling method to be adopted.

[0046] Then, these labeled training data are used to train or fine-tune AI models, machine learning models, or intelligent recognition and control models. Through training or fine-tuning, the model's ability and accuracy in judging whether the currently recorded footage is abnormal evidence collection footage, identifying the type of content in abnormal evidence collection footage, and issuing correct processing instructions are improved, resulting in an evidence collection anomaly handling model.

[0047] In S202, the AI ​​forensics platform 100 can input the real-time recorded video data of the object to be forensic examination into the forensics anomaly processing model. The forensics anomaly processing model can be used to parse the video data of the current frame and determine whether the current recording screen is an abnormal forensics screen, i.e., a screen containing non-forensic content, based on the video parsing results. For example, when non-forensic content, such as a message notification window, suddenly pops up in the recording screen, and this non-forensic content covers at least part of the original recording screen, the forensics anomaly processing model determines that the current recording screen is an abnormal forensics screen.

[0048] When the current recorded screen is determined to be an abnormal evidence collection screen, the evidence collection anomaly handling model can identify the type of content in the abnormal evidence collection screen. If the type of content in the abnormal evidence collection screen is identified as the direct closure type, the processing strategy for directly closing the content is output; if the type of content in the abnormal evidence collection screen is identified as the parsing processing type, the content in the abnormal evidence collection screen is further parsed, and a processing strategy corresponding to the content parsing result is generated.

[0049] S203: Call the API interface of the operating system of the evidence collection device and send a request to the operating system to execute the processing policy, so that the operating system processes the content of the current recording screen of the evidence collection device according to the processing policy and restores the normal recording of the evidence collection object.

[0050] The purpose of S203 is to transform the processing strategy generated by the evidence collection anomaly handling model into specific operation instructions that the operating system of the evidence collection device can understand and execute, thereby automatically and accurately eliminating abnormal evidence collection footage and restoring normal recording of the evidence collection object.

[0051] In S203, the AI ​​forensics platform 100 can send a request to execute a processing strategy by calling the standard application programming interface (API) provided by the operating system of the forensics device 11. Upon receiving the request from the AI ​​forensics platform 100, the operating system of the forensics device 11 will treat it as a legitimate user operation or system command and execute it. After execution, the operating system of the forensics device 11 updates the graphical user interface, specifically by the disappearance of non-forensic content in the currently recorded screen. At this point, the previously obscured forensic object is once again fully and without interference displayed on the screen.

[0052] The AI-powered forensics platform for automatically processing non-evidence-gathering content provided in this application addresses two main issues. Firstly, traditional forensics typically requires constant manual monitoring and intervention to handle interference. This application automatically identifies abnormal forensics scenes (such as message notifications) using a model and generates processing strategies, which are then executed automatically via system API calls. This eliminates the need for manual intervention, preventing interruptions due to operator delays or errors and saving time and costs associated with manual waiting. Secondly, the forensics anomaly processing model can analyze video data in real time. When the current recording screen is an abnormal forensics scene, it accurately distinguishes the type of content within it—either directly closed or parsed and processed. For directly closed content, the forensics device is instructed to automatically close the content, preventing continuous interruption of recording continuity and obscuring key scenes. This ensures that the recorded video data accurately and completely reflects the true situation of the evidence, enhancing its validity and credibility. For parsed and processed content, the forensics anomaly processing model performs deep analysis, automatically generating processing strategies corresponding to the analysis results, thus achieving automatic processing of parsed and processed content.

[0053] Furthermore, compared to writing fixed program code for abnormal evidence processing, this application utilizes an evidence abnormality processing model, which has the following advantages in terms of environmental cleanliness, evidence collection process cleanliness, and evidence cleanliness: Firstly, the evidence abnormality processing model has strong environmental adaptability and generalization capabilities, and can dynamically identify and process various unknown or changing message notifications, overcoming the limitations of high maintenance costs and easy failure of fixed program code; secondly, it achieves intelligent identification of evidence and noise, such as distinguishing and retaining transaction vouchers and prompts that are crucial to the core of evidence collection, avoiding the loss of key evidence caused by the "brutal deletion" of traditional code; and thirdly, the refined operation strategy generated by the deep analysis of the evidence abnormality processing model makes the evidence collection intervention behavior more natural and precise, reduces mechanical operation traces, enhances the coherence and credibility of the final recorded evidence, and ensures the cleanliness of the evidence chain from the source.

[0054] According to some embodiments of this application, optionally, the content in the abnormal evidence collection screen includes message notifications, and the evidence collection anomaly handling model is further used to perform the following processing: before identifying the type of content in the abnormal evidence collection screen, identifying and determining whether the message notification is evidence collection content related to the evidence collection object, and the evidence collection content related to the evidence collection object includes at least one of the evidence collection object's transaction information, promotional information and proof information.

[0055] If the message notification is evidence-gathering content related to the evidence-gathering object, then the processing strategy of not closing the message notification and continuing recording is output; if the message notification is not evidence-gathering content related to the evidence-gathering object, then the type of content in the abnormal evidence-gathering screen is identified.

[0056] Specifically, when the evidence collection anomaly handling model determines that the current recording screen is an abnormal evidence collection screen (e.g., pop-ups, floating notifications, etc.), it first parses the message notification in the current recording screen to extract visual features, text information, control elements, and contextual semantics. Then, the evidence collection anomaly handling model performs correlation analysis between the extracted message notification information and the evidence collection object to determine whether the message notification belongs to the evidence collection content related to the evidence collection object. Evidence collection content related to the evidence collection object includes, but is not limited to, at least one of the evidence collection object's transaction information, promotional information, and proof information. If the message notification is evidence collection content related to the evidence collection object, the evidence collection anomaly handling model outputs a processing strategy of not closing the message notification and continuing recording. That is, it will not perform any closing or minimization operation on the message notification, but will ensure that it is fully and clearly recorded in the evidence collection video stream and preserved as part of the core evidence. If the message notification is not related to the evidence collection object, the evidence collection anomaly handling model will determine the message notification as a distractor, thereby triggering the subsequent general anomaly handling process, which involves identifying its specific type and generating a corresponding handling strategy to eliminate its interference with the recording.

[0057] In this way, the evidence collection anomaly handling model can intelligently identify the evidence that needs to be retained and the noise that needs to be removed, so that electronic traces related to the evidence collection object (such as payment vouchers and risk disclosures) can be automatically identified and completely fixed, reducing the risk of losing key evidence due to misoperation, ensuring the integrity of the evidence chain, and fundamentally solving the defects of blind removal by traditional automated scripts.

[0058] In addition, the evidence collection anomaly processing model intelligently identifies the evidence that needs to be retained and the noise that needs to be removed. This avoids interference from irrelevant information (such as advertisements) while retaining key information related to the evidence subject. As a result, the evidence can more clearly and powerfully restore the whole picture of the facts. Its formation process is also more credible due to its reasonable logic, and it can play a stronger evidentiary role in judicial review or dispute resolution.

[0059] In some specific embodiments, transaction information may optionally include at least one of the following: a purchase link pop-up, a payment code, an order confirmation prompt, and a payment success prompt. Promotional information may include at least one of the following: exclusive coupons, limited-time discount codes, and group-buying success prompts. Supporting information may include at least one of the following: official platform credentials, product qualification certificates, entity identity verification, and genuine product and anti-counterfeiting information. For example, official platform credentials may include, but are not limited to, transaction risk warnings and consumer rights protection notices sent by the platform. Product qualification certificates may include, but are not limited to, authorization certificates of the certified entity, quality inspection reports, patent certificates, and production licenses. Entity identity verification may include, but are not limited to, a merchant's business license and brand trademark registration information. Genuine product and anti-counterfeiting information may include, but are not limited to, official genuine product certification marks, anti-counterfeiting query code entry points, and brand traceability code prompts.

[0060] Thus, this application breaks through the traditional crude model of closing pop-up windows upon seeing them in evidence collection. By clearly defining and identifying transaction information such as purchase links, payment codes, and order confirmations, it can accurately capture the core electronic traces of contract formation and performance. By identifying promotional information such as exclusive coupons and limited-time discount codes, it can fully record key facts affecting transaction prices and consumer decisions. By capturing supporting information such as platform risk warnings, quality inspection reports, business licenses, and genuine product labels, it can construct an evidence chain proving the legality of the transaction environment, the compliance of goods, and the qualifications of the entities involved, thereby enhancing the probative value of recorded evidence in judicial review or dispute resolution.

[0061] According to some embodiments of this application, optionally, the content in the abnormal evidence collection screen may include message notifications, and the types of message notifications include, but are not limited to, system notifications, application messages, and permission requests.

[0062] Accordingly, if the content in the abnormal evidence collection screen is of the direct-close type, the processing strategy for directly closing the content will be output, which may include the following steps:

[0063] If the message notification type is a system notification or an application message, output the handling strategy of directly disabling message notifications.

[0064] If the content in the abnormal evidence collection screen is of the parsing and processing type, then the content is further parsed, and a processing strategy corresponding to the content parsing result is generated, which may include the following steps:

[0065] If the message notification type is a permission request type, the permission request in the message notification is parsed, and the required permission type and the preset security policy are used to determine whether the permission type can be authorized. If it is determined to be authorized, a processing policy to enable the corresponding permission is generated; if it is determined to be unauthorized, a processing policy to record the event and prompt the user is generated.

[0066] Specifically, for example, when a message notification appears in the current recording screen, the forensic anomaly processing model can determine that the current recording screen is an abnormal forensic screen. Next, the forensic anomaly processing model can perform text recognition on the message notification in the current recording screen (i.e., the abnormal forensic screen) and determine the type of message notification based on the recognition result. In some embodiments, message notifications can be divided into multiple types, such as system notifications, application messages, or permission requests. For example, system notifications can include at least one of caller ID, alarm reminders, system update notifications, and low battery reminders. Application messages can include at least one of instant messaging software messages, shopping platform notifications, and application update notifications. Permission request types can include permission request pop-ups.

[0067] Figure 3 This is a schematic diagram of a screen display when receiving an incoming call during screen recording for evidence collection. Figure 4 This is a screenshot illustrating a permission request pop-up window received during screen recording for evidence collection. Figure 3 As shown, for example, with caller ID, if an incoming call occurs while screen recording is in progress, the screen will typically switch to caller ID, interrupting the display of the recorded evidence. Another example is instant messaging messages. If a message is received during screen recording, a notification window may pop up, potentially completely or partially obscuring the recorded evidence. Yet another example... Figure 4 As shown, taking a permission request pop-up as an example, when collecting evidence from the screen content of a certain application, a permission request pop-up may appear, such as requesting camera permission, storage permission, or account login. This permission request pop-up may completely or partially obscure the content of the evidence collection screen that is being recorded.

[0068] If the message notification is determined to be a system notification or application message, the forensic anomaly handling model can output a strategy to directly disable the message notification. If the message notification is determined to be a permission request, the forensic anomaly handling model can parse the permission requirements in the message notification, extract keywords such as "camera," "microphone," and "storage," determine the specific permission type, and judge whether the required permission type can be authorized based on the parsed permission type and the preset security policy. If the required permission type is determined to be authorized, a strategy to enable the corresponding permission is generated; if the required permission type (such as high-risk permissions involving user privacy or payment) is determined to be unauthorized, a strategy to record the event and prompt the user is generated.

[0069] During screen recording for evidence collection, automatically granting all permissions (such as reading SMS messages, accessing location, and using the camera) may infringe on user privacy and could even be exploited by malware, leading to data leaks or illegal payments. This violates the principles of legality and security in evidence collection. Conversely, automatically denying all permissions may cause critical applications being recorded to malfunction, crash, or fail to load data, thereby interrupting the evidence collection process and compromising the integrity of the evidence.

[0070] To address this issue, the forensic anomaly handling model in this application introduces an intelligent judgment mechanism based on permission type and preset security policies. This aims to automate the authorization of necessary permissions while avoiding and alerting users to high-risk permissions, ensuring the continuity of the forensic process while guaranteeing operational security and compliance. For permission request notification messages, the forensic anomaly handling model compares the parsed required permission type with preset security policies. If the permission can be automatically authorized according to the security policy, a processing policy for enabling the corresponding permission is generated; if the permission cannot be automatically authorized according to the security policy, a processing policy is generated to record the event and prompt the user. Automatically authorizable permissions are typically functional permissions that do not affect user privacy and data security and are necessary for the normal operation of the application, such as storage permissions and network access permissions. Permissions that cannot be automatically authorized are typically permissions involving core user privacy, property security, or sensitive data, such as SMS / call log reading permissions and payment-related permissions.

[0071] Thus, by setting up an intelligent judgment mechanism based on permission type and preset security policies, the improper authorization of sensitive user data during unattended automated forensics can be avoided, complying with data privacy protection regulations. At the same time, allowing low-risk permissions ensures the normal progress of forensics.

[0072] Accordingly, in S203, after obtaining the processing strategy of the forensic anomaly handling model, for system notifications or application message notifications, the AI ​​forensic platform can call the API interface of the operating system of the forensic device or the API interface of the target application in the forensic device to send a request to the operating system or the target application to disable message notifications, thereby disabling message notifications. The target application is the application that sent the message notification.

[0073] For permission request notifications, if the AI ​​forensics platform determines that the required permission type can be granted, it can call the operating system's API interface of the forensic device to send a request to the operating system to grant the corresponding permission. If the platform determines that the required permission type (such as high-risk permissions involving user privacy or payment) cannot be granted, it will record the event and notify the user.

[0074] Thus, for system notifications and application messages, the forensic anomaly handling model can automatically disable notifications to prevent them from continuously interrupting the recording flow and obscuring key footage, ensuring that the recorded video data fully and accurately reflects the true situation of the subject being investigated. For permission request notifications, the forensic anomaly handling model's intelligent judgment mechanism based on permission type and preset security policies can prevent the improper authorization of sensitive user data during unattended automated forensics, complying with data privacy protection regulations. Simultaneously, allowing low-risk permissions to be enabled ensures that the recording process is not interrupted due to insufficient low-risk permissions, further ensuring that the recorded video data fully and accurately reflects the true situation of the subject being investigated.

[0075] Figure 5 This is a schematic diagram illustrating another execution flow of the AI ​​forensics platform for automatically processing non-forensic content provided in an embodiment of this application. For example... Figure 5 As shown, after the AI ​​forensics platform is started, the following steps S204 can also be performed.

[0076] S204: After the screen recording evidence collection is completed, the recorded video data is sent to the timestamp authentication service system so that the timestamp authentication service system can perform timestamp authentication on the video data.

[0077] Combination Figure 1 and Figure 5 As shown, after the screen recording evidence collection is completed, the AI ​​evidence collection platform 100 can send the recorded video data to the timestamp authentication service system 13. The timestamp authentication service system 13 can add a timestamp to the received video data to record the accurate time when the video data was generated.

[0078] In this way, after the screen recording is completed, the AI ​​evidence collection platform sends the recorded video data to the timestamp authentication service system to add a timestamp, thereby proving the time when the evidence was generated, effectively preventing the evidence from being tampered with or forged, and enhancing the legal credibility and validity of the evidence.

[0079] According to some embodiments of this application, optionally, in S202, the forensic anomaly handling model can be used to perform the following processes:

[0080] When a message notification is detected in the current recording frame, an image region containing the message notification is extracted from the current video frame; the extracted message notification image is then processed using optical character recognition (OCR) technology to recognize the text, and the recognized text is converted into computer-readable text information; semantic analysis and keyword matching are performed on the text information to determine the type of message notification.

[0081] Specifically, when the forensic anomaly handling model detects a message notification in the currently recorded video frame, it analyzes the current video frame and extracts the image region containing the message notification. For the extracted message notification image, the forensic anomaly handling model uses Optical Character Recognition (OCR) technology to extract and analyze the features of the text in the image, thereby recognizing the text. The recognized text can be converted into computer-readable text information. After obtaining the text information, the forensic anomaly handling model uses natural language processing technology to analyze the grammatical structure, lexical meaning, and contextual relationships of the text to understand its semantics. To improve recognition accuracy, the forensic anomaly handling model can also match the recognized text with pre-defined keywords and determine the type of message notification based on the matching results. For example, is it a system notification, an application message, or a permission request?

[0082] For example, keywords can be flexibly adjusted according to actual circumstances, and this application does not limit them. For instance, in some examples, keywords may include at least one of the following: caller ID, alarm clock reminder, system update notification (such as system update or system upgrade), low battery reminder, instant messaging software message (such as friend message, friend request, group announcement or group invitation), shopping platform notification (such as new product launch, limited-time sale or discount), application update reminder, and permission request.

[0083] According to some embodiments of this application, optionally, the objects of evidence collection may include goods, online meetings, software operation processes, online transaction processes, or electronic contract signing processes, etc. Among them, goods may include goods that infringe on the user's intellectual property rights (i.e., infringing goods) or goods that may infringe on the user's intellectual property rights (i.e., potentially infringing goods), and this application does not limit this.

[0084] That is, the AI ​​evidence collection platform can be used to record and collect evidence of goods sold on shopping platforms (or e-commerce platforms), as well as online meetings in conferencing software, and can also be used to record and collect evidence of online transaction processes or electronic contract signing processes, etc. This application does not limit it in this regard.

[0085] Optionally, according to some embodiments of this application, the AI ​​forensics platform may also perform the following processing after startup:

[0086] Before screen recording for evidence collection, the system receives images of the evidence-collecting object uploaded by the evidence collection device and uploads these images to the evidence collection anomaly handling model. Alternatively, after screen recording for evidence collection is started, the system receives images of the evidence-collecting object selected by the user in the recording screen and uploads these images to the evidence collection anomaly handling model. The evidence collection anomaly handling model also performs the following processing: based on image recognition and target tracking technology, it monitors whether the evidence-collecting object in the recording screen leaves a preset monitoring area or disappears, and records the duration for which the evidence-collecting object leaves the preset monitoring area or disappears. When the preset duration is reached, it generates a processing strategy instructing the evidence collection device to shut down screen recording for evidence collection. The evidence collection device automatically shuts down screen recording for evidence collection in response to the request to execute the shutdown processing strategy. The preset duration can be flexibly adjusted according to actual conditions, and this application does not limit it.

[0087] Specifically, before starting screen recording for evidence collection, users can upload images of the subject to the AI ​​evidence collection platform using their evidence collection device. The AI ​​evidence collection platform can then input the uploaded images of the subject into an evidence collection anomaly handling model.

[0088] Alternatively, in some embodiments, after screen recording for evidence collection is enabled, the forensic device can monitor user operations in real time. When the user selects an object for evidence collection in the recording screen, the forensic device can automatically capture this operation, capture an image of the selected object, and upload the captured image to the AI ​​forensic platform. The AI ​​forensic platform can then input the captured image of the object for evidence collection into the evidence collection anomaly processing model.

[0089] After receiving an image or picture of the object to be examined, the evidence collection anomaly handling model can perform format verification and parsing on the image or picture of the object to be examined, and convert the image or picture of the object to be examined into a processable feature vector of the object to be examined.

[0090] During screen recording for evidence collection, the evidence collection anomaly handling model can analyze each frame of the received video data based on image recognition and target tracking technology. It compares the object features in each frame with the feature vector of the evidence collection target, and determines whether the evidence collection target exists in each frame and / or whether the target has left the preset monitoring area. Once it is determined that the evidence collection target has disappeared or left the preset monitoring area, the evidence collection anomaly handling model starts timing, recording the duration of the disappearance. During timing, the model continuously monitors subsequent frames. If the evidence collection target reappears or re-enters the preset monitoring area before the preset duration has elapsed, the timing is reset. If the evidence collection target still has not reappeared or has left the preset monitoring area after the preset duration has elapsed, the evidence collection anomaly handling model generates a processing strategy that instructs the evidence collection device to stop screen recording. After receiving the screen recording shutdown command, the AI ​​forensics platform sends a request to the forensics device to disable its screen recording function and end the screen recording forensics operation.

[0091] In this way, when the evidence collection anomaly handling model detects that the evidence collection object has left the preset monitoring area or has been missing for a preset duration, it will automatically shut down the screen recording evidence collection. This can effectively avoid meaningless screen recording when the evidence collection object has already disappeared or left the preset monitoring area, reduce unnecessary video data storage, and save storage space.

[0092] According to some embodiments of this application, optionally, the user's operation of selecting the target product includes double-clicking the evidence object, long-pressing the evidence object, or selecting the evidence object by drawing a box in the recording screen, thereby completing the operation of selecting the evidence object.

[0093] Figure 6 This section illustrates various operations a user can perform to select an object for evidence collection during recording. For example... Figure 6 As shown, the evidence-gathering device can monitor the user's input in real time during screen recording. When the user double-clicks or long-presses the object being recorded, the device can capture this event. Then, based on the coordinates of the mouse or touch operation, combined with the screen recording's resolution and coordinate system, the device determines the corresponding area on the screen, thus selecting the object. Alternatively, when the user begins a selection operation on the recording screen, the device can record the starting and ending coordinates of the selection, thereby determining the selected area and selecting the object.

[0094] In this way, during the screen recording and evidence collection process, users can select the evidence collection object at any time. Relying on the evidence collection anomaly handling model, when the evidence collection object is detected to have left the preset monitoring area or disappeared for a preset duration, the screen recording and evidence collection will be automatically closed, without requiring the user to wait for the screen recording and evidence collection to be completed and then close the screen recording manually, thus improving the flexibility and convenience of the operation.

[0095] In some embodiments, the evidence-gathering device may also respond to the user's command to turn off screen recording, thereby turning off the screen recording function of the electronic device and ending the screen recording evidence-gathering operation. This application does not limit this.

[0096] According to some embodiments of this application, optionally, the evidence collection anomaly handling model can also be used to perform the following processing: monitoring the smoothness of the recorded screen based on video data; when the smoothness of the recorded screen is detected to be inconsistent with the preset recording requirements, obtaining the network connection parameters of the evidence collection device, and determining whether the network of the evidence collection device is normal based on the network connection parameters of the evidence collection device; if abnormal, generating a processing strategy that instructs the evidence collection object to dynamically adjust the network settings of the evidence collection device and / or dynamically adjust the recording parameters of the evidence collection object, wherein the recording parameters include at least one of resolution, image quality and frame rate.

[0097] Specifically, the evidence collection anomaly handling model can monitor the smoothness of the recorded screen based on video data, such as whether the screen stutters or freezes. For example, in some embodiments, the evidence collection anomaly handling model can be used to perform real-time frame rate analysis, screen content change analysis, and / or video bitrate analysis on video data during screen recording for evidence collection. Screen content change analysis includes: calculating the image similarity or pixel difference between consecutive video frames, and determining that the screen content change is abnormal when the image similarity is consistently higher than a first threshold or the pixel difference is consistently lower than a second threshold. If the screen content change is determined to be abnormal, or the frame rate or video bitrate of the video data is less than a preset threshold, or video frames are lost, then the smoothness of the recorded screen is determined to not meet the preset recording requirements. The values ​​of the first threshold, the second threshold, and the preset threshold can be flexibly set according to actual conditions, and this application does not limit them.

[0098] When the smoothness of the recorded footage does not meet the preset recording requirements, the evidence collection anomaly handling model can obtain the network connection parameters of the evidence collection device and determine whether the network of the evidence collection device is normal based on the network connection parameters. For example, network connection parameters include, but are not limited to, network signal strength, network latency, and / or packet loss rate. If the network signal strength is weak, the network latency is too high, and / or the packet loss rate is large, then the network of the evidence collection device is determined to be abnormal.

[0099] If the network of the forensic device is determined to be abnormal, the forensic anomaly handling model can generate a processing strategy that instructs the forensic subject to dynamically adjust the network settings of the forensic device and / or dynamically adjust the recording parameters of the forensic subject. After receiving the processing strategy for dynamically adjusting the network settings of the forensic device and / or dynamically adjusting the recording parameters of the forensic subject, the AI ​​forensic platform sends a request to the forensic device to enable it to dynamically adjust its network settings and / or dynamically adjust the recording parameters of the forensic subject.

[0100] In some embodiments, dynamically adjusting the network settings of the forensic device may include switching the network connection of the forensic device from a first wireless network to a first mobile data network, from the first wireless network to a second wireless network, or from the first mobile data network to the first wireless network and from the first mobile data network to the second mobile data network, or attempting to reconnect to the current network to restore a stable network connection. Here, the first wireless network and the second wireless network are different wireless networks (WiFi), and the first mobile data network and the second mobile data network are different mobile data networks.

[0101] Taking switching the network connection of the forensic device from the first wireless network to the first mobile data network as an example, the AI ​​forensic platform can send a command to the operating system of the forensic device to switch the network connection by calling the API interface of the operating system of the forensic device. After receiving the command, the operating system of the forensic device can switch the network connection of the forensic device, such as disconnecting from the first wireless network, turning off the WiFi function, and connecting to the first mobile data network.

[0102] In some embodiments, dynamically adjusting the recording parameters of the evidence-gathering object may include dynamically adjusting at least one of the resolution, image quality, and frame rate of the recorded video. For example, when it is detected that the smoothness of the recorded video does not meet the preset recording requirements, the resolution of the recorded video may be reduced from 1080p to 720p, and / or the image quality of the recorded video may be reduced from "high" to "medium" or "low", and / or the frame rate of the recorded video may be reduced from 60fps to 30fps. The above are merely examples and do not constitute a limitation of this application.

[0103] If the smoothness of the recorded footage does not meet the preset recording requirements, it will directly affect the completeness and clarity of the evidence. Therefore, by using an evidence anomaly handling model to monitor whether the smoothness of the recorded footage meets the preset recording requirements, and to make timely adjustments when the smoothness of the recorded footage does not meet the preset recording requirements, it is beneficial to ensure that the recorded video data is smooth and coherent, thereby improving the credibility and effectiveness of the video data.

[0104] Furthermore, when the smoothness of the recorded footage does not meet the preset recording requirements, the network settings of the forensic equipment are dynamically adjusted through the processing strategy output by the forensic anomaly handling model. This includes switching network types or reconnecting to the network, which improves data transmission and provides a stable network environment for recording, ensuring uninterrupted recording. Dynamically adjusting recording parameters such as resolution, image quality, and frame rate when the smoothness of the recorded footage does not meet the preset requirements helps ensure continuous recording, preventing interruptions due to device resource depletion and guaranteeing the continuity of the forensic work.

[0105] According to some embodiments of this application, optionally, the evidence collection anomaly handling model is also used to perform the following processing: if it is determined that the network of the evidence collection device is abnormal, or after the network settings of the evidence collection device have been adjusted and / or the recording parameters of the evidence object have been adjusted to the preset minimum recording parameters, but the network of the evidence collection device still has not returned to normal, then the following processing strategy is output for the automatic evidence collection platform and the evidence collection device to execute: suspend the recording of the evidence object, cache the recorded video segments, and during the recording pause, overlay a watermark indicating network abnormality and pause status on the screen; after the network settings of the evidence collection device are adjusted and the network returns to normal, resume recording. The minimum recording parameters can be flexibly adjusted according to the actual situation. Its setting is intended to ensure that even when network bandwidth is limited, the recorded video screen can still meet the minimum clarity and recognizability requirements required for evidence review, avoiding the loss of probative value due to the blurry electronic evidence screen and the inability to identify key information caused by the recording parameters being too low, thereby maintaining the continuity of the evidence collection process while effectively ensuring the usability and legal validity of each frame of evidence material.

[0106] Specifically, continuing recording under network conditions may result in lost, corrupted, or incomplete recording data. For example, network interruptions may prevent some data from being uploaded successfully to cloud storage. Continuing recording under network conditions may also cause stuttering or freeze-up footage in the recorded video. Therefore, if the network of the forensic device is determined to be abnormal, or if the network is still abnormal after adjusting network settings and / or adjusting the recording parameters of the forensic subject to the preset minimum recording parameters, the forensic anomaly handling model can notify the AI ​​forensic platform and the forensic device to pause recording of the forensic subject, cache the already recorded video segments, and overlay a watermark indicating network anomaly and pause status on the screen during the recording pause. After adjusting the network settings of the forensic device and restoring normal network access, the forensic anomaly handling model can notify the AI ​​forensic platform and the forensic device to resume recording of the forensic subject.

[0107] Thus, pausing recording when the evidence-gathering equipment experiences network anomalies helps ensure smooth and complete recording of the final video data. It also reduces the risk of recording failures or data corruption due to network issues, saving time, manpower, and material costs. Furthermore, caching recorded video segments is the technical guarantee for implementing the pause-resume function. Adding a watermark clearly records the reason and time of the interruption at the evidentiary level, ensuring the integrity and interpretability of the entire video evidence chain.

[0108] Based on the AI ​​forensics platform 100 for automatically processing non-forensic content provided in the above embodiments, this application also provides an AI forensics method for automatically processing non-forensic content. This AI forensics method can be implemented based on the AI ​​forensics platform 100 for automatically processing non-forensic content provided in any of the above embodiments. The AI ​​forensics method for automatically processing non-forensic content may include the following steps one to three:

[0109] Step 1: Receive video data of the evidence-collecting object recorded in real time by the evidence-collecting device;

[0110] Step 2: Input the video data into the evidence collection anomaly handling model, and perform the following processing through the evidence collection anomaly handling model: parse the video data of the current frame, and determine whether the current recorded screen is an abnormal evidence collection screen based on the video parsing results; if it is an abnormal evidence collection screen, identify the type of content in the abnormal evidence collection screen; if the content type is the direct closure type, output the processing strategy for directly closing the content; if the content type is the parsing processing type, further parse the content, and generate a processing strategy corresponding to the content parsing results;

[0111] Step 3: Call the API interface of the operating system of the evidence collection device and send a request to the operating system to execute the processing policy, so that the operating system can process the content of the current recording screen of the evidence collection device according to the processing policy and restore the normal recording of the evidence collection object.

[0112] The specific processes of steps one to three above have been described in detail above. Please refer to steps S201 to S203 for details, which will not be repeated here.

[0113] The AI-based forensic method for automatically processing non-evidence-gathering content provided by the embodiments of this application addresses two main issues. Firstly, traditional forensic methods typically require constant manual monitoring and intervention to handle interference. This application automatically identifies abnormal forensic scenes (such as message notifications) using a model and generates processing strategies, which are then automatically executed via system API calls. This eliminates the need for manual intervention, preventing interruptions due to operator delays or errors and saving time and costs associated with manual waiting. Secondly, the forensic anomaly processing model can analyze video data in real time. When the currently recorded scene is an abnormal forensic scene, it can accurately distinguish the type of content within it—either directly closed or parsed and processed. For directly closed content, the forensic device is instructed to automatically close the content, preventing continuous interruption of recording continuity and obscuring key scenes. This ensures that the recorded video data accurately and completely reflects the true situation of the evidence, enhancing its validity and credibility. For parsed and processed content, the forensic anomaly processing model performs deep analysis and automatically generates processing strategies corresponding to the analysis results, achieving automatic processing of parsed and processed content.

[0114] Furthermore, compared to writing fixed program code for abnormal evidence processing, this application utilizes an evidence abnormality processing model, which has the following advantages in terms of environmental cleanliness, evidence collection process cleanliness, and evidence cleanliness: Firstly, the evidence abnormality processing model has strong environmental adaptability and generalization capabilities, and can dynamically identify and process various unknown or changing message notifications, overcoming the limitations of high maintenance costs and easy failure of fixed program code; secondly, it achieves intelligent identification of evidence and noise, such as distinguishing and retaining transaction vouchers and prompts that are crucial to the core of evidence collection, avoiding the loss of key evidence caused by the "brutal deletion" of traditional code; and thirdly, the refined operation strategy generated by the deep analysis of the evidence abnormality processing model makes the evidence collection intervention behavior more natural and precise, reduces mechanical operation traces, enhances the coherence and credibility of the final recorded evidence, and ensures the cleanliness of the evidence chain from the source.

[0115] The AI ​​forensics method for automatically processing non-forensic content provided in the embodiments of this application has the same or corresponding technical features as the AI ​​forensics platform 100 for automatically processing non-forensic content, and can achieve the same or corresponding technical effects. For the sake of brevity, it will not be described in detail here.

[0116] Based on the AI ​​forensics platform 100 for automatically processing non-forensic content provided in the above-described method embodiments, this application also provides an electronic device that can be deployed with the AI ​​forensics platform 100 for automatically processing non-forensic content provided in any of the above embodiments. Exemplarily, the electronic device includes, but is not limited to, a server.

[0117] It should be understood that each block or combination thereof in a flowchart and / or block diagram may be implemented by computer program instructions, by special-purpose hardware performing the specified function or action, or by a combination of special-purpose hardware and computer instructions. For example, these computer program instructions may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device to form a machine that enables the implementation of the function / action specified in each block or combination thereof in the flowchart and / or block diagram, as executed by such processor. Such processor may be a general-purpose processor, a special-purpose processor, a special application processor, or a field-programmable logic circuit.

[0118] The functional blocks shown in the structural block diagrams of this application can be implemented as hardware, software, firmware, or a combination thereof. When implemented in hardware, they can be, for example, electronic circuits, application-specific integrated circuits (ASICs), appropriate firmware, plug-ins, function cards, etc.; when implemented in software, they are programs or code segments used to perform the required tasks. Programs or code segments can be stored in memory or transmitted over a transmission medium or communication link via data signals carried on a carrier wave. Code segments can be downloaded via computer networks such as the Internet or intranets.

[0119] It should be noted that this application is not limited to the specific configurations and processes described above or shown in the figures. The above descriptions are merely specific embodiments of this application. Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working processes of the described systems, devices, modules, or units can be referred to the corresponding processes in the method embodiments, and need not be repeated here. It should be understood that the scope of protection of this application is not limited thereto. Any person skilled in the art can conceive of various equivalent modifications or substitutions within the scope of the technology disclosed in this application, and these modifications or substitutions should all be covered within the scope of protection of this application.

Claims

1. An AI-powered forensics platform that automatically processes non-forensic content, characterized in that, The AI ​​forensics platform is equipped with a pre-trained forensics anomaly handling model. After the AI ​​forensics platform is started, it performs the following processes: Receive video data of the evidence-collecting object recorded in real time by the evidence-collecting device; The video data is input into the evidence collection anomaly processing model, which is used to perform the following processing: parse the video data of the current frame, and determine whether the current recording screen is an abnormal evidence collection screen based on the video parsing result; When the screen is an abnormal evidence collection screen, identify the type of content in the abnormal evidence collection screen; if the type of the content is the direct closure type, output the processing strategy of directly closing the content; if the type of the content is the parsing processing type, further parse the content and generate a processing strategy corresponding to the content parsing result. The API interface of the operating system of the evidence collection device is invoked, and a request to execute the processing strategy is sent to the operating system so that the operating system processes the content in the current recording screen of the evidence collection device according to the processing strategy and restores the normal recording of the evidence collection object. The method of determining whether the current recording screen is an abnormal evidence collection screen based on the video analysis results includes: when non-evidence collection content appears in the current recording screen and the non-evidence collection content covers at least part of the current recording screen, the evidence collection anomaly handling model determines that the current recording screen is an abnormal evidence collection screen; the non-evidence collection content includes message notifications, and the message notifications include pop-up windows or floating notifications.

2. The AI-based forensics platform according to claim 1, characterized in that, The evidence collection anomaly handling model is also used to perform the following processing: before identifying the type of content in the abnormal evidence collection screen, identify and determine whether the message notification is evidence collection content related to the evidence collection object, wherein the evidence collection content related to the evidence collection object includes at least one of the evidence collection object's transaction information, promotional information and proof information; If yes, output a processing strategy that does not close the message notification and continues recording; if no, identify the type of content in the abnormal evidence collection screen.

3. The AI-based forensics platform according to claim 2, characterized in that, The transaction information includes at least one of the following: a purchase link pop-up, a payment code, an order confirmation prompt, and a payment success prompt; The promotional information includes at least one of the following: exclusive coupons, limited-time discount codes, and group-buying success notifications; The supporting information includes at least one of the following: official platform credentials, product qualification certificates, entity identity verification, and genuine product and anti-counterfeiting information.

4. The AI ​​forensics platform according to claim 2 or 3, characterized in that, The types of message notifications include system notifications, application messages, and permission requests. If the content type is "directly close", then output the processing strategy for directly closing the content, including: If the message notification is of the system notification type or the application message type, then output the processing strategy of directly disabling the message notification; If the content type is parsing processing, then the content is further parsed, and a processing strategy corresponding to the content parsing result is generated, including: If the message notification is a permission request, the permission request in the message notification is parsed, and the permission type to be granted is determined based on the parsed permission type and the preset security policy. If the permission type is granted, a processing policy to grant the corresponding permission is generated; if the permission is not granted, a processing policy to record the message notification and prompt the user is generated.

5. The AI ​​forensics platform according to claim 4, characterized in that, The evidence collected includes goods, online meetings, software operation processes, online transaction processes, or electronic contract signing processes; System notifications include at least one of the following: caller ID, alarm reminders, system update notifications, and low battery reminders; application messages include at least one of the following: instant messaging software messages, shopping platform notifications, and application update notifications; and permission requests include permission request pop-ups.

6. The AI-based forensics platform according to claim 1, characterized in that, After the AI-based forensics platform is started, it also performs the following processes: Before screen recording for evidence collection, receive the image of the evidence collection object uploaded by the evidence collection device and upload the image of the evidence collection object to the evidence collection anomaly handling model; or, after screen recording for evidence collection is started, receive the image of the evidence collection object selected by the user in the recording screen uploaded by the evidence collection device and upload the image of the evidence collection object to the evidence collection anomaly handling model. The evidence collection anomaly handling model is also used to perform the following processing: based on image recognition and target tracking technology, it monitors whether the evidence collection object in the recorded screen has left the preset monitoring area or disappeared, and records the duration of the evidence collection object leaving the preset monitoring area or disappearing. When the duration reaches the preset duration, it generates a processing strategy that instructs the evidence collection device to turn off screen recording.

7. The AI ​​forensics platform according to claim 6, characterized in that, Users can select evidence objects by double-clicking the object in the recording screen, long-pressing the object, or selecting the object by drawing a box.

8. The AI-based forensics platform according to claim 1, characterized in that, The evidence collection anomaly handling model is also used to perform the following processes: The smoothness of the recorded footage is monitored based on video data. When the smoothness of the recorded footage does not meet the preset recording requirements, the network connection parameters of the evidence collection device are obtained, and the network connection parameters of the evidence collection device are used to determine whether the network of the evidence collection device is normal. If an anomaly is detected, a processing strategy is generated that instructs the evidence-collecting object to dynamically adjust the network settings of the evidence-collecting device and / or dynamically adjust the recording parameters of the evidence-collecting object. The recording parameters include at least one of resolution, image quality, and frame rate.

9. The AI ​​forensics platform according to claim 8, characterized in that, The evidence collection anomaly handling model is specifically used to perform real-time frame rate analysis, screen content change analysis, and / or video bitstream analysis on video data during screen recording evidence collection. The screen content change analysis includes: calculating the image similarity or pixel difference between consecutive video frames, and determining that the screen content change is abnormal when the similarity is continuously higher than a first threshold or the difference is continuously lower than a second threshold. If the screen content change is determined to be abnormal, or the frame rate or video bitstream of the video data is less than a preset threshold, or video frames are lost, then the smoothness of the recorded screen does not meet the preset recording requirements.

10. The AI ​​forensics platform according to claim 8, characterized in that, Dynamically adjusting the network settings of the evidence collection device includes switching the network connection of the evidence collection device from a first wireless network to a first mobile data network, from a first wireless network to a second wireless network, or from a first mobile data network to a first wireless network, from a first mobile data network to a second mobile data network, or attempting to reconnect to the current network.

11. The AI ​​forensics platform according to any one of claims 8-10, characterized in that, The evidence collection anomaly handling model is also used to perform the following processing: If the network of the evidence collection device is determined to be abnormal, or after the network settings of the evidence collection device have been adjusted and / or the recording parameters of the evidence collection object have been adjusted to the preset minimum recording parameters, but the network of the evidence collection device still has not returned to normal, the following processing strategy is output for the AI ​​evidence collection platform and the evidence collection device to execute: pause the recording of the evidence collection object, cache the recorded video segments, and overlay a watermark indicating network abnormality and pause status on the screen during the recording pause; resume recording after the network settings of the evidence collection device are adjusted and the network returns to normal.

12. The AI ​​forensics platform according to claim 1, characterized in that, The AI ​​forensics platform communicates with a pre-set timestamp authentication service system. After the AI ​​forensics platform is started, it also performs the following processes: After the screen recording evidence collection is completed, the recorded video data is sent to the timestamp authentication service system so that the timestamp authentication service system can perform timestamp authentication on the video data.

13. An AI-based forensics method for automatically processing non-forensic content, characterized in that, The method is implemented based on an AI forensics platform for automatically processing non-forensic content as described in any one of claims 1-12, and includes: Receive video data of the evidence-collecting object recorded in real time by the evidence-collecting device; The video data is input into the evidence collection anomaly processing model, and the following processing is performed by the evidence collection anomaly processing model: The video data of the current frame is parsed, and the video parsing results are used to determine whether the current recorded screen is an abnormal evidence collection screen. When it is an abnormal evidence collection screen, the type of content in the abnormal evidence collection screen is identified. If the type of the content is the direct closure type, the processing strategy of directly closing the content is output. If the type of the content is the parsing processing type, the content is further parsed, and a processing strategy corresponding to the content parsing result is generated. The API interface of the operating system of the evidence collection device is invoked, and a request to execute the processing strategy is sent to the operating system so that the operating system processes the content in the current recording screen of the evidence collection device according to the processing strategy and restores the normal recording of the evidence collection object. The method of determining whether the current recording screen is an abnormal evidence collection screen based on the video analysis results includes: when non-evidence collection content appears in the current recording screen and the non-evidence collection content covers at least part of the current recording screen, the evidence collection anomaly handling model determines that the current recording screen is an abnormal evidence collection screen; the non-evidence collection content includes message notifications, and the message notifications include pop-up windows or floating notifications.

14. An electronic device, characterized in that, The electronic device is equipped with an AI forensics platform that automatically processes non-forensic content as described in any one of claims 1-12.