Examination cheating identification method, device and equipment and storage medium

By constructing standard and individual answer trajectories, calculating trajectory offsets, and performing fusion analysis, the problems of low efficiency and inaccurate identification results in existing cheating detection methods are solved, achieving efficient and accurate identification of cheating candidates.

CN121958797APending Publication Date: 2026-05-01MINISTRY OF FINANCE ACCOUNTING & FINANCIAL EVALUATION CENTER +1
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-11-21
Publication Date
2026-05-01

AI Technical Summary

Technical Problem

Existing methods for identifying cheating in exams are inefficient and lack accuracy. Especially when dealing with large-scale test centers and a large number of test takers, manual inspection and verification are inefficient, and analysis based on a single data dimension is prone to misjudgment. The accuracy rate is significantly reduced, especially for exams with a high proportion of subjective questions.

Method used

By obtaining the original data of candidates authorized by the examination system, standard answer trajectories and individual candidate answer trajectories within a preset test center range are constructed. Trajectory offset is calculated, abnormal candidate data is screened, and fusion analysis is performed. The trajectory offset and abnormal candidate data are combined for dual verification to improve the accuracy of cheating detection.

Benefits of technology

This improved the accuracy of identifying cheating by test takers, reduced the workload of manual verification, increased efficiency, avoided the one-sidedness of single-dimensional analysis, and enhanced the credibility of the judgment results.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121958797A_ABST
    Figure CN121958797A_ABST
Patent Text Reader

Abstract

The invention relates to a computer examination security technology, and discloses an examination cheating identification method and device, electronic equipment and a storage medium, and the method comprises the steps: obtaining the original data of an examinee authorized by an examination system, and constructing a standard answer track corresponding to a preset examination point range and an individual examinee answer track according to the original data of the examinee; performing offset calculation on the answer track of the individual examinee and the standard answer track to obtain a track offset; screening abnormal examinee data in the original examinee data according to the track offset; and carrying out fusion analysis on the track offset and the abnormal examinee data to obtain an examinee cheating identification result. Through the offset calculation of the individual trajectory and the standard trajectory, the trajectory offset and the abnormal examinee data are combined, the dual verification of the data trend and the specific behavior is realized, and the accuracy of judging the examinee cheating recognition result is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of computer examination security technology, and in particular to a method, apparatus, device, and storage medium for identifying cheating during examinations. Background Technology

[0002] National high-stakes examinations are the core vehicle for talent selection and professional competence certification. Their results are directly related to the fairness of talent evaluation and the rigor of professional entry. Therefore, they have much stricter requirements than ordinary examinations regarding the fairness of the examination process and the traceability of the examination results.

[0003] Currently, traditional methods for identifying cheating in exams still have many shortcomings. On the one hand, some methods rely mainly on manual invigilation and post-exam spot checks. However, when faced with large-scale test centers and a large number of candidates, manual inspection and verification are inefficient and prone to missed detections. On the other hand, some methods extract objective question answer data from the exam system, group them by "exam room," "seat area," or "admission ticket number range," and use algorithms to calculate the degree of overlap in answers within the group to determine the cheating result. However, this method only performs simple filtering and comparison on a single data dimension, which is prone to misjudgment. Moreover, for exams with a high proportion of subjective questions, the accuracy rate is greatly reduced.

[0004] Therefore, in the face of the growing demand for exam cheating detection, current exam cheating detection methods urgently need to be improved to solve the problems of low efficiency and insufficient accuracy of existing methods. Summary of the Invention

[0005] This invention provides a method, apparatus, device, and storage medium for identifying cheating in examinations, with the main objective of solving the problem of low accuracy in identifying cheating results.

[0006] To achieve the above objectives, the present invention provides a method for identifying cheating in examinations, comprising: Obtain the original data of candidates authorized by the examination system, and construct the standard answer trajectory and individual candidate answer trajectory corresponding to the preset test center range based on the original data of candidates; The offset between the individual candidate's answer trajectory and the standard answer trajectory is calculated to obtain the trajectory offset. Filter out abnormal candidate data from the original candidate data based on trajectory offset; By fusing and analyzing the trajectory offset with abnormal candidate data, the results of candidate cheating identification are obtained.

[0007] The present invention also provides an examination cheating detection device, the device comprising: The acquisition module is used to obtain the original data of candidates authorized by the examination system, and to construct the standard answer trajectory and individual candidate answer trajectory corresponding to the preset test center range based on the original data of candidates; The offset calculation module is used to calculate the offset between the individual candidate's answer trajectory and the standard answer trajectory, and obtain the trajectory offset. The filtering module is used to filter out abnormal candidate data from the original candidate data based on the trajectory offset. The fusion analysis module is used to fuse and analyze trajectory offset and abnormal candidate data to obtain the results of candidate cheating identification.

[0008] The present invention also provides an electronic device, the electronic device comprising: At least one processor; and, A memory that is communicatively connected to at least one processor; wherein, The memory stores a computer program that can be executed by at least one processor, which enables the at least one processor to perform the above-described method for detecting cheating in examinations.

[0009] The present invention also provides a computer-readable storage medium storing at least one computer program, which is executed by a processor in an electronic device to implement the above-described method for detecting cheating in examinations.

[0010] This invention directly obtains authorized raw data from the examination system, ensuring data authenticity and integrity. It constructs a standard answer trajectory, providing an objective benchmark for judging normal answer patterns and avoiding reliance on subjective experience to define anomalies. It also constructs individual answer trajectories, accurately capturing the unique answering patterns of each examinee, laying the foundation for subsequent targeted analysis of individual anomalies. The differences between individual trajectories and standard trajectories are transformed into concrete numerical values, converting abstract anomalies into comparable and rankable quantitative indicators, accurately locating systemic deviations potentially related to cheating. It filters abnormal examinee data, avoiding indiscriminate analysis of all examinees, significantly reducing the workload of subsequent manual verification or in-depth analysis, and improving efficiency. Combining trajectory offset and abnormal examinee data achieves dual verification of data trends and specific behaviors, greatly improving the credibility of cheating determination, reducing the one-sidedness of single-dimensional analysis, and improving the accuracy of examinee cheating identification results. Therefore, the examination cheating identification method, device, equipment, and storage medium proposed in this invention can solve the problem of low accuracy in identifying examinee cheating results. Attached Figure Description

[0011] Figure 1 A flowchart illustrating an embodiment of the exam cheating detection method provided by the present invention; Figure 2This is a flowchart illustrating the process of calculating the offset between an individual examinee's answer trajectory and a standard answer trajectory, provided in an embodiment of the present invention. Figure 3 This is a flowchart illustrating the process of filtering abnormal candidate data from the original candidate data based on trajectory offset, according to an embodiment of the present invention. Figure 4 A functional block diagram of an exam cheating detection device provided in an embodiment of the present invention; Figure 5 This is a schematic diagram of the structure of an electronic device that implements a method for identifying cheating in examinations, according to an embodiment of the present invention.

[0012] The realization of the objective, functional features and advantages of the present invention will be further explained in conjunction with the embodiments and with reference to the accompanying drawings. Detailed Implementation

[0013] It should be understood that the specific embodiments described herein are merely illustrative of the invention and are not intended to limit the invention.

[0014] To address the problems of low efficiency in manual invigilation and post-exam spot checks, and insufficient accuracy in identification results due to simple screening and comparison of only a single data dimension, an embodiment of this application provides an examination cheating identification method. This method is a novel examination cheating identification method based on the offset calculation of individual trajectories and standard trajectories, combined with trajectory offset and abnormal candidate data, to achieve dual verification of data trends and specific behaviors.

[0015] Reference Figure 1 The diagram shown is a flowchart illustrating an exam cheating detection method according to an embodiment of this application. In this embodiment, the exam cheating detection method includes: S1. Obtain the original data of candidates authorized by the examination system, and construct the standard answer trajectory and individual candidate answer trajectory corresponding to the preset test center range based on the original data of candidates.

[0016] In this embodiment of the invention, constructing the answer trajectory refers to the process of transforming the scattered original data into a "standard answer trajectory" and an "individual candidate answer trajectory" that can be used for comparative analysis, based on the candidate's original data. The standard answer trajectory refers to the overall trend line of the answer scores of all candidates within a specified range (such as a province or test center). This trend line represents the typical answer pattern of candidates within that range and reflects the average change pattern of scores as the questions progress. The individual candidate answer trajectory refers to the personal trend line of the answer scores of a single candidate. Based on the candidate's own question score sequence, a linear fitting method is used to fit the score and the question number into a straight line. This straight line represents the change pattern of the individual candidate's score as the questions progress during the exam and reflects the candidate's personal answer characteristics.

[0017] Specifically, the candidate's original data includes candidate information data and candidate answer trajectory data. The candidate information data includes data such as province code, city code, test center / examination room code, admission ticket number, candidate name, seat number, test paper code, and examination time. The candidate answer trajectory data includes data such as admission ticket number, candidate name, answer question number, answer time, browsing time, modification time, and answer.

[0018] In this embodiment of the invention, constructing a standard answer trajectory corresponding to a preset test center range based on the candidate's original data includes: performing data normalization processing on the candidate's original data to obtain standard candidate data; filtering out range-summarized candidate data from the standard candidate data according to the preset test center range; calculating the median score of each question based on the score of each question in the range-summarized candidate data to obtain the median score sequence corresponding to the question sequence; and performing a linear function fitting between the median score sequence and the question numbers in the range-summarized candidate data to obtain the standard answer trajectory corresponding to the preset test center range.

[0019] In this embodiment of the invention, linear function fitting refers to using a linear relationship to summarize the overall trend of changes in the candidate data.

[0020] Specifically, the raw candidate data undergoes data standardization processing, including cleaning (removing invalid data such as those submitted by absentees or duplicates), time alignment (converting the timestamps of different candidates' answers to "minutes after the start of the exam"), outlier handling (deleting abnormal data where the score of a single question exceeds the range of 0 to full marks), and standardization (converting indicators such as the score of each question and the time taken to answer to a unified unit, such as "score rate" or "seconds / question"), to obtain standardized candidate data with a unified format and valid data.

[0021] Furthermore, based on the preset test center scope (such as by province or by individual test center), the data aggregation granularity is determined. From the standard test center data, all test center data belonging to the target scope (such as "all test centers in Jiangsu Province" or "test center No. 3 in XX City") are selected, and the data of these test centers, such as "question number-score" and "question number-answering time", are classified and integrated according to the question number.

[0022] Furthermore, when calculating the median score for each question based on the scores of each question in the aggregated candidate data, the aggregated candidate data is processed sequentially according to the question number. For each question, the scores of all candidates for that question are extracted, and the scores are sorted from low to high. The median value is then taken (if the number of candidates is even, the average of the two median values ​​is taken) to obtain the median score for that question. The median scores of each question are then arranged sequentially according to the question number from question 1 to question T to obtain the median score sequence corresponding to the question sequence.

[0023] Furthermore, when performing a linear function fit on the median score sequence and the question numbers in the range summary candidate data, the output median score sequence is used as the y-axis (representing the group average score for each question), and the question numbers in the range summary candidate data (from 1 to T, representing the order of answering questions) are used as the x-axis. T discrete data points (1,), (2,), ..., (T, m_T) are constructed in the coordinate system. The least squares method is used to perform a linear function fit on these discrete data points. By calculating the slope a and intercept b, the line y = ... The function that minimizes the sum of squared vertical distances from all data points is the fitted linear function (ŷ(x) = ...). This serves as the standard answer trajectory for the pre-set test point range.

[0024] In this embodiment of the invention, constructing an individual candidate's answer trajectory based on the candidate's original data includes: extracting the score data of a single candidate on each question from the candidate's original data; arranging the score data in order according to the question number to obtain the score sequence of a single candidate; and performing a linear function fitting based on the score sequence and the question number to obtain the individual candidate's answer trajectory.

[0025] Specifically, when extracting the question score sequence for each candidate from the original candidate data, the data is split using the "admission ticket number" in the standard candidate data after processing the original candidate data as a unique identifier to distinguish the independent data entries for each candidate. In each candidate's data entry, the "question sequence and score for each question" field is located, and the specific score for each question is extracted. The extracted scores are arranged sequentially according to the question number from question 1 to the last question, forming an ordered sequence of "question number 1 - score, question number 2 - score... question number T - score", thereby outputting the question score sequence for each candidate.

[0026] Furthermore, using the output "question score sequence for each candidate" and the "question number" from the standard candidate data as input, the coordinate system dimensions are determined: the "question number" is used as the horizontal axis (x-axis, representing the order of answering questions, with values ​​of 1, 2, ..., T), and the "question score" is used as the vertical axis (y-axis, representing the candidate's score on the corresponding question). For each candidate, the "question number" and "corresponding score" in their question score sequence are mapped one-to-one, and discrete data points are marked in the coordinate system. These discrete data points are then connected sequentially with line segments according to the question number order to form a curve that reflects the candidate's "score changes as the questions progress." This curve is associated with the candidate's admission ticket number and key information (such as answering time characteristics), and finally, the "individual answer trajectory for each candidate" is output.

[0027] S2. Calculate the offset between the individual candidate's answer trajectory and the standard answer trajectory to obtain the trajectory offset.

[0028] In this embodiment of the invention, offset calculation refers to the process of comprehensively measuring the degree of deviation between the "individual candidate's answer trajectory" and the "standard answer trajectory" by quantitatively comparing the differences between the two.

[0029] like Figure 2 As shown, in this embodiment of the invention, the offset calculation of the individual candidate's answer trajectory and the standard answer trajectory to obtain the trajectory offset includes: extracting individual key parameters from the individual candidate's answer trajectory; extracting standard parameters from the standard answer trajectory based on the individual key parameters; performing difference analysis on the individual key parameters and the standard parameters to obtain the individual parameter offset; calculating the root mean square of the residuals on the individual original data in the individual candidate's answer trajectory and the standard original data in the standard answer trajectory to obtain the root mean square of the residuals; obtaining the distribution scale data of the test point range, and performing a weighted summation of the individual parameter offset and the root mean square of the residuals based on preset weights and distribution scale data to obtain the trajectory offset.

[0030] In this embodiment of the invention, individual key parameters refer to feature parameters extracted from the answer trajectory of an individual examinee that can reflect the core pattern of answering questions, such as score trend parameters (e.g., the slope of the individual answer trajectory: reflecting the overall rate of increase or decrease in score as the questions progress, and the intercept: reflecting the basic score level corresponding to the initial questions), and rhythm feature parameters (e.g., the average answering time per question and the fluctuation coefficient of the overall answering rhythm: reflecting the stability of answering speed). Distribution scale data refers to the overall dispersion data of all examinees within the preset test center range on the "individual key parameters" and "root mean square of residuals", which is used to eliminate the scale differences of different parameters.

[0031] Specifically, when extracting individual key parameters from an individual candidate's answer trajectory, for the score dimension, the slope of the trajectory is extracted through linear fitting, such as the average change in score for each increase of 1 in question number, and the intercept (the theoretical score when the question number is 0). For the time dimension, the average answering time per question (total time / number of questions) and the rhythm fluctuation coefficient (standard deviation of answering time for each question / average time) are calculated. These features are then summarized to form the individual key parameters for the i-th candidate (e.g., slope). ,intercept Average duration Volatility coefficient }).

[0032] Furthermore, using the extracted individual key parameters as a reference, the corresponding parameter types in the standard answer trajectory are located. From the standard answer trajectory, standard parameters that correspond one-to-one with the individual key parameters are extracted to form a set of standard parameters (such as {slope}). ,intercept Average duration Volatility coefficient }). Furthermore, using individual key parameters and corresponding standard parameters as input, the difference is calculated one by one according to parameter type, for example: score trend slope offset: (The same applies to intercept offset and average duration offset). Take the absolute value of the difference to form a set of individual parameter offsets.

[0033] Furthermore, the root mean square residuals are calculated for the individual raw data in the individual test taker's answer trajectory and the standard raw data in the standard answer trajectory. First, the correspondence between the individual raw data and the standard raw data is determined: the individual raw data is "the actual score / time for each question" (e.g., the score for question 1). Score for question 2 …), the standard raw data is the theoretical value of the standard trajectory on the corresponding question (such as the standard score of question 1 ŷ_s1, the standard score of question 2 ŷ_s2, etc.). The difference (residual) of the corresponding data is calculated point by point. Finally, the sum of squares of all residuals is calculated. The sum of squares is divided by the total number of questions to get the average value. The square root of the average value is then taken to get the root mean square of the residual.

[0034] Furthermore, when acquiring the distribution scale data of the test site area, the individual key parameter offsets and root mean square residuals of all candidates within the preset test site area are collected, and the corresponding distribution scale (such as the standard deviation of the individual key parameter offsets) is calculated. , Standard deviation of root mean square of residuals To eliminate scale differences, the individual parameter offset and the root mean square of the residual are divided by the corresponding distribution scale.

[0035] For example, normalized slope offset: Normalized intercept offset: Normalized root mean square residual: root mean square residual / According to the preset weights ( , , The normalized index is weighted and calculated as follows: Trajectory Offset = That is, the trajectory deviation of an individual examinee, where the preset weight is determined after verification of historical abnormal data and optimization of statistical models (such as regression analysis).

[0036] S3. Filter out abnormal candidate data in the original candidate data based on the trajectory offset.

[0037] like Figure 3 As shown, in this embodiment of the invention, filtering abnormal candidate data in the candidate's original data based on trajectory offset includes: performing a quantile threshold lookup on the trajectory offset to obtain a quantile threshold; filtering preliminary abnormal candidate data in the candidate's original data based on the quantile threshold; and performing behavioral data verification on the preliminary abnormal candidate data to obtain abnormal candidate data.

[0038] In this embodiment of the invention, threshold lookup refers to the process of determining a critical value based on the trajectory offset distribution.

[0039] Specifically, when performing quantile threshold lookup on trajectory offset, first summarize the trajectory offsets of all candidates, arrange the trajectory offsets of all candidates in descending order to form an ordered sequence, and calculate the corresponding position according to the preset quantile ratio (such as P95, P99). If the total number of candidates is N, the position corresponding to the 95th quantile is N×(1-95%)=N×5% (rounded up), and the position corresponding to the 99th quantile is N×1% (rounded up).

[0040] The preset quantile ratio is determined based on empirical judgment of the "normal trajectory deviation range", the strictness of the examination scenario (such as the level of anti-cheating requirements) or the distribution characteristics of abnormal behavior in historical data.

[0041] For example, with 1000 candidates, the 95th percentile is 1000×5%=50 (i.e., the 50th value after sorting), and the 99th percentile is 1000×1%=10 (i.e., the 10th value after sorting). Find the trajectory offset value of the corresponding position in the sorted sequence. This value is the percentile threshold (e.g., if the 50th value is 10.1, then the P95 threshold is 10.1).

[0042] Furthermore, the trajectory offset of each candidate is checked one by one, and candidates with "offset ≥ percentile threshold" are selected. The complete information of the selected candidates is extracted from the candidate's original data, including answer score, answer time, operation log, IP address, etc., to form a "preliminary abnormal candidate data set".

[0043] Furthermore, for the output preliminary abnormal candidate data set (initial list of abnormal candidates), the original behavioral data of the corresponding candidates is retrieved, such as answering time, modification records, question jump order, submission time, etc.; check for any behavioral anomalies related to trajectory deviation (such as completing the questions in a very short time, a sudden and significant increase in accuracy, frequent modification of answers across questions, etc.); if the behavioral anomalies and trajectory deviation characteristics corroborate each other (such as the trajectory showing an abnormal score trend, and the presence of frequent answer modification behavior), then the candidate is confirmed as an abnormal candidate, and finally the final abnormal candidate data verified by behavioral data is obtained.

[0044] S4. Perform a fusion analysis of the trajectory offset and abnormal candidate data to obtain the candidate cheating identification results.

[0045] In this embodiment of the invention, fusion analysis refers to the process of combining trajectory offset with abnormal candidate data, and then determining whether a candidate has cheated through correlation verification and comprehensive judgment.

[0046] In this embodiment of the invention, the trajectory offset and abnormal candidate data are fused and analyzed to obtain the candidate cheating identification result, including: extracting the answer behavior features of the abnormal candidate data; extracting the abnormal candidate trajectory offset from the trajectory offset based on the abnormal candidate data; comprehensively weighting the answer behavior features and the abnormal candidate trajectory offset according to the preset evidence contribution weight to obtain the auxiliary evidence score; performing evidence correlation analysis on the auxiliary evidence score to obtain the associated evidence record; and generating the candidate cheating identification result by combining the auxiliary evidence score and the associated evidence record.

[0047] In this embodiment of the invention, extracting answer behavior features refers to extracting concrete information from abnormal candidate data that reflects the pattern of answering operations or abnormal performance, and evidence association analysis refers to the process of binding and matching the auxiliary evidence score with the original supporting data that generated the score.

[0048] Specifically, when extracting the answering behavior characteristics of abnormal candidates, the data is broken down into independent data entries for each abnormal candidate based on their "admission ticket number." Key fields are located, such as extracting single-question duration and overall rhythm data from "answer timestamp / stay time" to filter out features like "extremely short answer" and "abrupt rhythm"; extracting operation records from "click / page turning / modification logs" to filter out features like "frequent modifications" and "abnormal jumps"; and extracting environmental data from "IP address / station number" to filter out features like "out-of-location IP" and "multiple operation traces." The features are then categorized and organized according to the "time-operation-environment" dimension to form the "answering behavior characteristics" for each abnormal candidate.

[0049] Further, retrieve the trajectory offset dataset of all candidates calculated in step S2, and filter out the trajectory offset data corresponding to abnormal candidates (matched by admission ticket number), including the specific value of the offset (e.g., 12.5), the offset type (parameter offset / residual offset), the range of questions in the offset set (e.g., questions 5-10), and whether it exceeds the preset percentile threshold (e.g., exceeding the P99 threshold).

[0050] Furthermore, when comprehensively weighting the answer behavior characteristics and the trajectory deviation of abnormal candidates according to the preset evidence contribution weight, the answer behavior characteristics and the trajectory deviation of abnormal candidates are first assigned values ​​respectively. For example, the behavior characteristics are scored according to the severity of the abnormality (e.g., "IP location change + frequent modification" gets 40 points, "only very short answer" gets 20 points), and the trajectory deviation is scored according to the degree of deviation (e.g., exceeding the P99 threshold gets 50 points, exceeding the P95 threshold gets 30 points). The preset evidence contribution weight is then called (e.g., behavior characteristics weight 0.4, trajectory deviation weight 0.6). The auxiliary evidence score = (behavior characteristics score × 0.4) + (trajectory deviation score × 0.6) (e.g., candidate A: 40 × 0.4 + 50 × 0.6 = 46 points).

[0051] The assignment of values ​​to answer behavior characteristics and abnormal candidate trajectory deviations, as well as the preset evidence contribution weights, are all determined based on historical data and empirical statistics.

[0052] Furthermore, the auxiliary evidence scores are linked with the "answer behavior characteristics" and "trajectory offset details table" (both of which are extracted in the above steps), and the related data are integrated and organized according to the "score-behavioral characteristics-trajectory offset" structure, such as "Candidate A, auxiliary evidence score 46 points, corresponding behavioral characteristics: answer question 3 in 8 seconds, modified 6 times for a single question; corresponding trajectory offset: offset 12.5, exceeding the P99 threshold by 2.3 times, the offset is concentrated in questions 5-10", and the "auxiliary evidence score-related evidence record table" is output, which is the related evidence record.

[0053] Furthermore, when generating the cheating identification result based on the combination of auxiliary evidence scores and related evidence records, a cheating judgment threshold is preset (determined through historical data experience) (e.g., a score ≥80 is "highly suspected of cheating", 60-79 is "moderately suspected of cheating", and <60 is "lowly suspected / normal"). The auxiliary evidence score of each candidate is compared with the cheating judgment threshold to initially determine the level of suspicion (e.g., candidate B with 82 points → highly suspected of cheating, candidate A with 46 points → lowly suspected). The completeness of the evidence chain is checked based on the auxiliary evidence score-related evidence record table (e.g., "highly suspected of cheating" requires both "significantly abnormal behavioral characteristics + excessive trajectory deviation"), data errors (e.g., abnormal behavior recorded by mistake) are excluded. Combining the threshold level and the validity of the evidence chain, the final cheating identification result of the candidate is output.

[0054] In addition, the system integrates "offset evidence" and "behavioral / trajectory evidence" by linking them through the examination admission ticket number and displays them in a visual interface (such as tables, timelines, and trajectory comparison charts). For example, the left side displays the candidate's trajectory offset data and a comparison curve with the standard trajectory, while the right side simultaneously lists the corresponding abnormal behavior records (including timestamps, screenshots of operation logs, etc.), forming a linked view of "quantitative data + concrete behavior". This allows reviewers to intuitively see "why the trajectory offset was judged as abnormal" and "the specific abnormal behavior associated with it". By cross-validating the correlation between the two, it can confirm whether the abnormality is caused by cheating or data error, thus improving the accuracy and efficiency of manual judgment.

[0055] In this embodiment of the invention, the answer behavior characteristics and the trajectory deviation of abnormal candidates are comprehensively weighted according to the preset evidence contribution weight to obtain the auxiliary evidence score. This includes: performing rule engine matching on the answer behavior characteristics and the trajectory deviation of abnormal candidates to obtain the behavior trajectory correlation matching degree; performing statistical testing on the behavior trajectory correlation matching degree to obtain the test support degree; and weighting and fusing the behavior trajectory correlation matching degree and the test support degree according to the preset evidence contribution weight to obtain the auxiliary evidence score.

[0056] In this embodiment of the invention, rule engine matching refers to using a preset abnormal behavior-trajectory association rule base to compare the combination patterns of the candidate's answer behavior characteristics and trajectory offset, calculate the degree of match between the actual pattern and the typical cheating patterns in the rule base, and statistical testing refers to verifying the significance of the "behavior-trajectory association pattern" through statistical methods (such as chi-square test, correlation analysis), determining whether the pattern is an accidental occurrence or a statistically significant anomaly, and outputting the test support.

[0057] Specifically, when performing rule engine matching on answer behavior characteristics and abnormal candidate trajectory deviations, a preset rule base is retrieved. The rule base contains multiple cheating pattern rules (each rule defines a combination of "behavioral characteristics + trajectory deviation", such as rule 1: "single question duration < 10 seconds (behavior) + trajectory deviation exceeding P99 (trajectory) → weight 0.8"). The candidate's answer behavior characteristics (such as "single question duration 8 seconds") and trajectory deviations (such as "deviation exceeding P99") are combined and extracted to form an actual association pattern. The actual pattern is compared with each rule in the rule base to calculate the matching degree (if it fully matches rule 1, the matching degree is 0.8; if it partially matches, it is calculated according to the overlap condition ratio, such as if it matches 60%, the matching degree is 0.8 × 60% = 0.48). The highest matching degree among all rules is taken as the candidate's "behavioral trajectory association matching degree".

[0058] Furthermore, when conducting statistical tests on the correlation matching degree of behavioral trajectories, the test object is determined. For example, the correlation pattern of "extremely short answer + high trajectory deviation" is taken as the test object. Reference group data (such as the behavioral-trajectory correlation data of all normal candidates at the test center) is selected. The significance of the difference between the candidate's correlation pattern and the normal group is calculated by statistical methods (such as t-test, which is an existing technology and will not be elaborated here). The support is expressed by the P value (significance level). For example, P=0.005 (extremely significant difference) corresponds to a test support of 0.9; P=0.03 (significant difference) corresponds to 0.7; P=0.1 (no significant difference) corresponds to 0.3, thus obtaining the test support of the candidate.

[0059] Furthermore, the behavioral trajectory correlation matching degree (e.g., 0.48) and the test support degree (e.g., 0.9) are weighted according to the preset evidence contribution weight (based on the score example above): Auxiliary evidence score = (0.48 × 0.6) + (0.9 × 0.4) = 0.288 + 0.36 = 0.648 (64.8 points).

[0060] like Figure 4 The diagram shown is a functional block diagram of an exam cheating detection device provided in an embodiment of the present invention.

[0061] The exam cheating detection device 100 of this invention can be installed in an electronic device. Depending on the functions implemented, the exam cheating detection device 100 may include an acquisition and construction module 101, an offset calculation module 102, a filtering module 103, and a fusion analysis module 104. A module of this invention can also be referred to as a unit, which refers to a series of computer program segments that can be executed by the processor of an electronic device and can perform a fixed function, and which are stored in the memory of the electronic device.

[0062] In this embodiment, the functions of each module / unit are as follows: The acquisition and construction module 101 is used to acquire the original data of candidates authorized by the examination system, and construct the standard answer trajectory and individual candidate answer trajectory corresponding to the preset test center range based on the original data of candidates; The offset calculation module 102 is used to calculate the offset between the individual candidate's answer trajectory and the standard answer trajectory to obtain the trajectory offset. The filtering module 103 is used to filter abnormal candidate data in the candidate's original data based on the trajectory offset. The fusion analysis module 104 is used to perform fusion analysis on trajectory offset and abnormal candidate data to obtain the candidate cheating identification result.

[0063] In detail, each module in the exam cheating identification device 100 of this embodiment of the invention uses the same technical means as the exam cheating identification method in the accompanying drawings and can produce the same technical effect, which will not be repeated here.

[0064] like Figure 5 The diagram shown is a structural schematic of an electronic device for implementing an exam cheating detection method according to an embodiment of the present invention.

[0065] Electronic device 1 may include processor 10, memory 11, communication bus 12 and communication interface 13, and may also include computer programs stored in memory 11 and capable of running on processor 10, such as exam cheating detection programs.

[0066] In some embodiments, the processor 10 may be composed of integrated circuits, such as a single packaged integrated circuit or multiple integrated circuits with the same or different functions, including combinations of one or more central processing units (CPUs), microprocessors, digital processing chips, graphics processors, and various control chips. The processor 10 is the control unit of the electronic device, connecting various components of the entire electronic device through various interfaces and lines. It executes programs or modules stored in the memory 11 (e.g., executing a cheating detection program) and calls data stored in the memory 11 to perform various functions and process data within the electronic device.

[0067] The memory 11 includes at least one type of readable storage medium, including flash memory, portable hard drive, multimedia card, card-type memory (e.g., SD or DX memory), magnetic memory, magnetic disk, optical disk, etc. In some embodiments, the memory 11 can be an internal storage unit of an electronic device, such as a portable hard drive. In other embodiments, the memory 11 can be an external storage device of the electronic device, such as a plug-in portable hard drive, Smart Media Card (SMC), Secure Digital (SD) card, Flash Card, etc. Furthermore, the memory 11 can include both internal and external storage units of the electronic device. The memory 11 can be used not only to store application software and various types of data installed on the electronic device, such as the code of an exam cheating detection program, but also to temporarily store data that has been output or will be output.

[0068] The communication bus 12 can be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, etc. This bus can be divided into an address bus, a data bus, a control bus, etc. The bus is configured to enable communication between the memory 11 and at least one processor 10, etc.

[0069] Communication interface 13 is used for communication between the aforementioned electronic device and other devices, including a network interface and a user interface. Optionally, the network interface may include a wired interface and / or a wireless interface (such as a Wi-Fi interface, Bluetooth interface, etc.), typically used to establish communication connections between the electronic device and other electronic devices. The user interface may be a display, an input unit (such as a keyboard), and optionally, a standard wired or wireless interface. Optionally, in some embodiments, the display may be an LED display, a liquid crystal display, a touch-sensitive liquid crystal display, or an OLED (Organic Light-Emitting Diode) touchscreen, etc. The display may also be appropriately referred to as a screen or display unit, used to display information processed in the electronic device and to display a visual user interface.

[0070] Figure 5 Only electronic devices with components are shown; it will be understood by those skilled in the art that... Figure 5 The structure shown does not constitute a limitation on the electronic device 1, and may include fewer or more components than shown, or combine certain components, or have different component arrangements.

[0071] For example, although not shown, the electronic device may also include a power supply (such as a battery) to power various components. Preferably, the power supply can be logically connected to at least one processor 10 via a power management device, thereby enabling functions such as charging management, discharging management, and power consumption management. The power supply may also include one or more DC or AC power sources, recharging devices, power fault detection circuits, power converters or inverters, power status indicators, and other arbitrary components. The electronic device may also include various sensors, Bluetooth modules, Wi-Fi modules, etc., which will not be described in detail here.

[0072] It should be understood that the embodiments are for illustrative purposes only and are not limited to this structure in the scope of the patent application.

[0073] Specifically, the processor 10's specific implementation method of the above instructions can be found in the description of the relevant steps in the corresponding embodiments of the accompanying drawings, and will not be repeated here.

[0074] Furthermore, if the modules / units integrated in electronic device 1 are implemented as software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. The computer-readable storage medium can be volatile or non-volatile. For example, a computer-readable medium may include: any entity or device capable of carrying computer program code, a recording medium, a USB flash drive, a portable hard drive, a magnetic disk, an optical disk, a computer memory, or a read-only memory (ROM).

[0075] The present invention also provides a computer-readable storage medium storing a computer program, which, when executed by a processor, can implement an examination cheating detection method according to any of the above embodiments. It should be noted that the computer-readable storage medium can be volatile or non-volatile. For example, a computer-readable medium may include: any entity or device capable of carrying computer program code, a recording medium, a USB flash drive, a portable hard disk, a magnetic disk, an optical disk, a computer memory, or a read-only memory (ROM).

[0076] In the several embodiments provided by this invention, it should be understood that the disclosed devices, apparatuses, and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of modules is only a logical functional division, and other division methods may be used in actual implementation.

[0077] The modules described as separate components may or may not be physically separate. The components shown as modules may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs.

[0078] Furthermore, the functional modules in the various embodiments of the present invention can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or in the form of hardware plus software functional modules.

[0079] It will be apparent to those skilled in the art that the present invention is not limited to the details of the exemplary embodiments described above, and that the present invention can be implemented in other specific forms without departing from the spirit or essential characteristics of the present invention.

[0080] Therefore, the embodiments should be considered exemplary and non-limiting in all respects, and the scope of the invention is defined by the appended claims rather than the foregoing description. Thus, all variations falling within the meaning and scope of equivalents of the claims are intended to be embraced within the invention. No appended diagram markings in the claims should be construed as limiting the scope of the claims.

[0081] Furthermore, it is clear that the word "comprising" does not exclude other units or steps, and the singular does not exclude the plural. Multiple units or devices recited in a system claim may also be implemented by a single unit or device through software or hardware. The terms "first," "second," etc., are used to indicate names and do not indicate any specific order.

[0082] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit it. Although the present invention has been described in detail with reference to preferred embodiments, those skilled in the art should understand that modifications or equivalent substitutions can be made to the technical solutions of the present invention without departing from the spirit and scope of the technical solutions of the present invention.

Claims

1. A method for identifying cheating in examinations, characterized in that, The method includes: Obtain the original candidate data authorized by the examination system, and construct the standard answer trajectory and individual candidate answer trajectory corresponding to the preset test center range based on the original candidate data; The offset between the individual candidate's answer trajectory and the standard answer trajectory is calculated to obtain the trajectory offset. Filter out abnormal candidate data from the original candidate data based on the trajectory offset; The trajectory offset and the abnormal candidate data are fused and analyzed to obtain the candidate cheating identification result.

2. The exam cheating detection method as described in claim 1, characterized in that, The step of constructing a standard answer trajectory corresponding to a preset test center range based on the candidate's original data includes: The original candidate data is subjected to data normalization processing to obtain standard candidate data; According to the preset test center range, the range of test takers data is filtered out from the standard test taker data and the test taker data is summarized. The median score for each question is calculated based on the scores of each question in the aggregated candidate data within the specified range, to obtain the median score sequence corresponding to the question sequence. By performing a linear function fit on the median score sequence and the question numbers in the range summary candidate data, the standard answer trajectory corresponding to the preset test point range is obtained.

3. The exam cheating detection method as described in claim 1, characterized in that, The step of constructing an individual candidate's answer trajectory based on the candidate's original data includes: Extract the score data of each candidate on each question from the original candidate data; The score data is arranged sequentially according to the question number to obtain the score sequence of a single candidate; By performing a linear function fit based on the score sequence and the question number, the individual candidate's answer trajectory can be obtained.

4. The exam cheating detection method as described in claim 1, characterized in that, The calculation of the offset between the individual candidate's answer trajectory and the standard answer trajectory to obtain the trajectory offset includes: Extract key individual parameters from the individual test taker's answer trajectory; Standard parameters are extracted from the standard answer trajectory based on the individual key parameters; The individual key parameters are compared with the standard parameters to obtain the individual parameter offset. The root mean square of the residuals is calculated by comparing the individual raw data in the individual candidate's answer trajectory with the standard raw data in the standard answer trajectory. Obtain the distribution scale data of the test point range, and perform a weighted summation of the individual parameter offset and the root mean square of the residual based on the preset weight and the distribution scale data to obtain the trajectory offset.

5. The exam cheating detection method as described in claim 1, characterized in that, The step of filtering abnormal candidate data from the original candidate data based on the trajectory offset includes: The quantile threshold is obtained by performing a quantile threshold lookup on the trajectory offset. Preliminary abnormal candidate data in the candidate's original data are filtered according to the quantile threshold. Behavioral data verification was performed on the preliminary abnormal candidate data to obtain abnormal candidate data.

6. The exam cheating detection method as described in claim 1, characterized in that, The process of fusing and analyzing the trajectory offset with the abnormal candidate data to obtain the candidate cheating identification result includes: Extract the behavioral characteristics of the abnormal test takers; Extract the trajectory offset of abnormal candidates from the trajectory offset based on the abnormal candidate data; The answering behavior characteristics and the abnormal candidate trajectory deviation are comprehensively weighted according to the preset evidence contribution weight to obtain the auxiliary evidence score; Evidence correlation analysis is performed on the scores of the auxiliary evidence to obtain the records of related evidence; The cheating identification result is generated based on the combination of the auxiliary evidence score and the associated evidence record.

7. The exam cheating detection method as described in claim 6, characterized in that, The auxiliary evidence score is obtained by comprehensively weighting the answering behavior characteristics and the abnormal candidate trajectory deviation according to the preset evidence contribution weight, including: The answering behavior characteristics and the trajectory offset of the abnormal examinee are matched by a rule engine to obtain the behavior trajectory correlation matching degree; The correlation and matching degree of the behavioral trajectory is statistically tested to obtain the test support. The behavioral trajectory correlation matching degree and the test support degree are weighted and fused according to the preset evidence contribution weight to obtain the auxiliary evidence score.

8. A device for detecting cheating in examinations, characterized in that, The device includes: The acquisition module is used to acquire the original data of candidates authorized by the examination system, and to construct the standard answer trajectory and individual candidate answer trajectory corresponding to the preset test center range based on the original data of candidates; The offset calculation module is used to calculate the offset between the individual candidate's answer trajectory and the standard answer trajectory to obtain the trajectory offset. The filtering module is used to filter abnormal candidate data in the candidate's original data based on the trajectory offset. The fusion analysis module is used to perform fusion analysis on the trajectory offset and the abnormal candidate data to obtain the candidate cheating identification result.

9. An electronic device, characterized in that, The electronic device includes: At least one processor; and, A memory communicatively connected to the at least one processor; wherein, The memory stores a computer program that can be executed by the at least one processor, the computer program being executed by the at least one processor to enable the at least one processor to perform the exam cheating detection method as described in any one of claims 1 to 7.

10. A computer-readable storage medium storing a computer program, characterized in that, When the computer program is executed by the processor, it implements the exam cheating detection method as described in any one of claims 1 to 7.