A three-stage examination cheating risk control method and device and a storage medium
By employing a three-stage approach, a candidate relationship graph is constructed and answering behavior is analyzed. Combining graph neural networks and clustering algorithms, this approach solves the problem of existing technologies being unable to detect cheating behavior in a timely manner, and achieves comprehensive identification and accurate control of exam risks.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- 人力资源和社会保障部人事考试中心
- Filing Date
- 2026-04-29
- Publication Date
- 2026-05-29
AI Technical Summary
Current technologies cannot detect cheating in exams in a timely manner, resulting in reduced efficiency and accuracy in risk identification.
A three-stage approach is adopted: before the exam, a candidate relationship graph structure is constructed; during the exam, spectral clustering algorithm is used to analyze answering behavior; and after the exam, density clustering algorithm is used to identify abnormal groups. Combined with graph neural network and community detection algorithm, the relationships and answering behaviors among candidates are identified.
It improves the accuracy and efficiency of exam risk identification, and can comprehensively identify at-risk candidate groups before, during and after the exam.
Smart Images

Figure CN122115172A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of risk identification technology for examinations, and in particular to a three-stage method, apparatus and storage medium for controlling examination cheating risks. Background Technology
[0002] With the continuous advancement of information technology, various examinations currently face certain risks. For example, there is the possibility of risky groups organizing collective cheating during examinations. Therefore, relevant technical personnel are constantly researching how to better identify or mitigate the risks associated with examinations.
[0003] In existing technologies, monitoring for risky behaviors during exams is typically done manually. For example, organizers manage each stage of the exam and use tools to monitor test-takers and prevent cheating. However, this method may not be able to detect risky behaviors (such as cheating) in a timely manner, thus reducing the efficiency and accuracy of identifying exam-related risks.
[0004] There is currently no effective solution to the technical problem that existing technologies may not be able to detect risky behaviors (such as cheating) in exams in a timely manner, thus reducing the efficiency and accuracy of identifying exam-related risky behaviors. Summary of the Invention
[0005] The embodiments of this disclosure provide a three-stage exam cheating risk control method to at least address the technical problem in the prior art that risky behaviors (such as cheating) in exams may not be detected in a timely manner, thereby reducing the efficiency and accuracy of identifying exam-related risky behaviors.
[0006] According to one aspect of the present disclosure, a three-stage method for controlling exam cheating risk is provided, comprising: in the pre-exam stage, constructing a candidate relationship graph structure to represent the relationships between candidates, and classifying candidates into community or non-community individuals based on the candidate relationship graph structure, performing message passing based on the candidate relationship graph structure, generating embedded representations corresponding to candidates, and determining pre-exam risk candidate groups based on the embedded representations; during the exam, constructing an exam answer graph structure based on the candidates' answer results, wherein nodes in the exam answer graph structure represent candidates, and the weight of the edges is the similarity of the representation vectors of two candidates; the representation vectors are constructed based on the answer content and answer order of each candidate, and a spectral clustering algorithm is used to determine the answer content based on the exam answer graph structure. For groups of candidates with similar content, based on the overlap in the order and timing of their answers, candidates exhibiting follow-up answering behavior are identified, resulting in a group of candidates at risk during the exam. In the post-exam phase, a density clustering algorithm is used to identify first anomalous groups among multiple candidates. Based on the intra-cluster similarity evaluation index corresponding to each first anomalous group, and the similarity evaluation index corresponding to any two candidates within each first anomalous group, second anomalous groups are selected from each first anomalous group, resulting in a group of candidates at risk after the exam. The similarity evaluation index indicates the proportion of questions on which any two candidates answer incorrectly and have the same wrong answer, relative to the total number of questions on which any two candidates have the same wrong answer.
[0007] According to another aspect of the present disclosure, a storage medium is also provided, the storage medium including a stored program, wherein, when the program is executed, a processor performs any of the methods described above.
[0008] According to another aspect of the present disclosure, a three-stage examination cheating risk control device is also provided, comprising: a pre-examination risk identification module, used to construct a candidate relationship graph structure representing the relationships between candidates in the pre-examination stage, and to classify candidates into community or non-community individuals based on the candidate relationship graph structure, to perform message passing based on the candidate relationship graph structure, to generate an embedded representation corresponding to the candidate, and to determine the pre-examination risk candidate group based on the embedded representation; and an in-examination risk identification module, used to construct an examination answer graph structure based on the candidates' answer results during the examination, wherein the nodes in the examination answer graph structure represent candidates, and the weight of the edge is the similarity of the representation vectors of two candidates; the representation vector is constructed based on the answer content and answer order of each candidate. The system is structured based on the exam answer graph and uses spectral clustering to identify groups of candidates with similar answers. Based on the overlap in the order and timing of answers within the same candidate group, it identifies candidates exhibiting follow-up answering behavior, thus creating a group of candidates at risk during the exam. A post-exam risk identification module is also included. In the post-exam phase, density clustering is used to identify first anomalous groups among multiple candidates. Based on the intra-cluster similarity evaluation index corresponding to each first anomalous group, and by filtering out second anomalous groups from these groups, a group of candidates at risk after the exam is obtained. The similarity evaluation index indicates the proportion of questions on which two candidates answer incorrectly and have the same wrong answer, relative to the total number of questions on which two candidates answer incorrectly.
[0009] According to another aspect of the present disclosure, a three-stage exam cheating risk control device is also provided, comprising: a processor; and a memory connected to the processor, for providing the processor with instructions to process the following steps: In the pre-exam stage, constructing a candidate relationship graph structure to represent the relationships between candidates, and classifying candidates into community or non-community individuals based on the candidate relationship graph structure, performing message passing based on the candidate relationship graph structure, generating embedded representations corresponding to candidates, and determining pre-exam risk candidate groups based on the embedded representations; During the exam, constructing an exam answer graph structure based on the candidates' answer results, wherein nodes in the exam answer graph structure represent candidates, and the weight of an edge is the similarity of the representation vectors of two candidates; the representation vector is based on each... The exam process constructs a database of candidates' answers and their order of responses. Based on the exam answer graph structure, a spectral clustering algorithm is used to identify groups of candidates with similar answers. Within the same candidate group, the order and timing of their answers are compared to identify candidates exhibiting follow-up behavior, thus creating a group of candidates at risk during the exam. In the post-exam phase, a density clustering algorithm is used to identify first anomalous groups among multiple candidates. Based on the intra-cluster similarity evaluation index corresponding to each first anomalous group, and by filtering out second anomalous groups from these groups, a post-exam risk group is obtained. The similarity evaluation index indicates the proportion of questions on which two candidates answer incorrectly and have identical incorrect answers, relative to the total number of questions on which two candidates answer incorrectly.
[0010] In this embodiment, the identification of exam-related risk behaviors is divided into three stages: before the exam, during the exam, and after the exam. Risk groups are identified in each stage. Before the exam, a candidate relationship graph is constructed to represent the relationships between candidates, determining the embedded representation of each candidate and thus identifying risk groups (pre-exam risk candidate groups). During the exam, an exam answer graph is constructed based on the candidates' answers to represent the correlation between answers in terms of content and order. Candidates exhibiting follow-up answering behavior are identified based on this graph, resulting in a mid-exam risk candidate group. In the post-exam stage, similarity evaluation indicators are determined between pairs of candidates, and density clustering is used to identify a first abnormal group. Based on the similarity evaluation indicators between pairs of candidates in the first abnormal group and the intra-cluster similarity evaluation indicators of the first abnormal group, a second abnormal group is further selected, resulting in a post-exam risk candidate group. Therefore, this method can comprehensively identify risk groups before, during, and after the exam, improving the accuracy of exam risk identification. Attached Figure Description
[0011] The accompanying drawings, which are included to provide a further understanding of this disclosure and form part of this application, illustrate exemplary embodiments of this disclosure and are used to explain this disclosure, but do not constitute an undue limitation of this disclosure. In the drawings: Figure 1 This is a hardware structure block diagram of a computing device for implementing the method according to Embodiment 1 of this disclosure; Figure 2 This is a flowchart illustrating the three-stage exam cheating risk control method according to the first aspect of Embodiment 1 of this disclosure; Figure 3 This is a schematic diagram of a dyeing process provided in Embodiment 1 of this disclosure; Figure 4 This is a schematic diagram of the disordered order of computer-based test questions according to Embodiment 1 of this application; Figure 5 This is a flowchart illustrating the follow-up response discovery process using a spectral clustering algorithm based on the exam response graph structure as described in Embodiment 1 of this application. Figure 6 This is a schematic diagram of the positive and negative sample pair contrast learning mechanism according to Embodiment 1 of this application; Figure 7 This is a statistical chart of the distribution of abnormal groups in City S as described in Embodiment 1 of this application; Figure 8 This is a schematic diagram of a typical abnormal group response result segment according to Embodiment 1 of this application; Figure 9 It is a heatmap of similarity among 5 candidates as described in Embodiment 1 of this application; Figure 10 This is a schematic diagram of a typical high-risk group according to Embodiment 1 of this application; Figure 11 It is a line graph of Case 1, which describes the same examination room in City S following the answer trajectory, according to Embodiment 1 of this application; Figure 12 This is a schematic diagram of the answer results corresponding to Case 1 of the same examination room in City S, as described in Embodiment 1 of this application; Figure 13 It is a line graph of Case 2, which describes the same examination room in City S following the answer trajectory, according to Embodiment 1 of this application; Figure 14 This is a schematic diagram of the answer results corresponding to Case 2 of the same examination room in City S, as described in Embodiment 1 of this application; Figure 15 This is a line graph of Case 1, which describes the cross-examination room following the answer trajectory at the same test center in City S, according to Embodiment 1 of this application; Figure 16This is a schematic diagram of the answering results corresponding to Case 1, which describes the cross-examination room following the answering trajectory at the same test center in City S, according to Embodiment 1 of this application; Figure 17 This is a line graph of Case 2, which describes the cross-examination room following the answer trajectory at the same test center in City S, according to Embodiment 1 of this application; Figure 18 This is a schematic diagram of the answering results corresponding to Case 2, which describes the cross-examination room following the answering trajectory at the same test center in City S, according to Embodiment 1 of this application; Figure 19 It is a typical attack response trajectory diagram according to Embodiment 1 of this application. Detailed Implementation
[0012] To enable those skilled in the art to better understand the technical solutions of this disclosure, the technical solutions of the embodiments of this disclosure will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are merely some embodiments of this disclosure, and not all embodiments. Based on the embodiments of this disclosure, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of this disclosure.
[0013] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this disclosure are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of this disclosure described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.
[0014] Example 1
[0015] According to this embodiment, a three-stage method for controlling exam cheating risk is provided. It should be noted that the steps shown in the flowchart in the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. Also, although a logical order is shown in the flowchart, in some cases, the steps shown or described may be executed in a different order than that shown here.
[0016] The method embodiments provided in this example can be executed on mobile terminals, computer terminals, servers, or similar computing devices. Figure 1 A hardware block diagram of a computing device for implementing a three-stage exam cheating risk control method is shown. Figure 1 As shown, a computing device may include one or more processors (processors may include, but are not limited to, microprocessors such as MCUs or programmable logic devices such as FPGAs), a memory for storing data, a transmission device for communication functions, and an input / output interface. The memory, transmission device, and input / output interface are connected to the processor via a bus. In addition, it may also include a display, keyboard, and cursor control device connected to the input / output interface. Those skilled in the art will understand that... Figure 1 The structure shown is for illustrative purposes only and does not limit the structure of the aforementioned electronic device. For example, a computing device may also include... Figure 1 The more or fewer components shown, or having the same Figure 1 The different configurations shown.
[0017] It should be noted that the aforementioned one or more processors and / or other data processing circuits are generally referred to herein as "data processing circuits". These data processing circuits may be embodied, in whole or in part, in software, hardware, firmware, or any other combination thereof. Furthermore, the data processing circuits may be a single, independent processing module, or may be integrated, in whole or in part, into any other element in a computing device. As involved in the embodiments of this disclosure, the data processing circuits serve as processor control (e.g., selection of a variable resistor termination path connected to an interface).
[0018] The memory can be used to store software programs and modules of application software, such as the program instructions / data storage device corresponding to the three-stage exam cheating risk control method in this embodiment of the present disclosure. The processor executes various functional applications and data processing by running the software programs and modules stored in the memory, thereby realizing the three-stage exam cheating risk control method of the aforementioned application. The memory may include high-speed random access memory, and may also include non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory may further include memory remotely located relative to the processor, and these remote memories can be connected to the computing device via a network. Examples of the aforementioned networks include, but are not limited to, the Internet, corporate intranets, local area networks, mobile communication networks, and combinations thereof.
[0019] The transmission device is used to receive or send data via a network. Specific examples of the network described above may include a wireless network provided by the computing device's communication provider. In one example, the transmission device includes a Network Interface Controller (NIC), which can connect to other network devices via a base station to communicate with the Internet. In another example, the transmission device may be a Radio Frequency (RF) module used for wireless communication with the Internet.
[0020] The display can be, for example, a touchscreen liquid crystal display (LCD), which allows users to interact with the user interface of the computing device.
[0021] It should be noted here that, in some optional embodiments, the above... Figure 1 The computing device shown may include hardware elements (including circuitry), software elements (including computer code stored on a computer-readable medium), or a combination of both hardware and software elements. It should be noted that... Figure 1 This is only one instance of a specific particular instance, and is intended to illustrate the types of components that may exist in the aforementioned computing devices.
[0022] Under the aforementioned operating environment, according to the first aspect of this embodiment, a three-stage examination cheating risk control method is provided. This method can be implemented by... Figure 1 The computing device implementation is shown. Figure 2 A flowchart illustrating the method is shown below. (Refer to...) Figure 2 As shown, the method includes: S202: In the pre-exam stage, construct a candidate relationship graph structure to represent the relationships between candidates, and classify candidates into community or non-community individuals based on the candidate relationship graph structure, perform message passing based on the candidate relationship graph structure, generate embedded representations corresponding to candidates, and determine the pre-exam risk candidate groups based on the embedded representations; S204: During the examination, based on the candidates' answers, an examination answer graph structure is constructed. Nodes in the answer graph represent candidates, and the weights of the edges are the similarity of the representation vectors of two candidates. The representation vectors are constructed based on each candidate's answer content and order. Based on the examination answer graph structure, a spectral clustering algorithm is used to determine groups of candidates with similar answer content. Based on the overlap in the order and timing of answers within the same candidate group, candidates exhibiting follow-up answering behavior are identified, resulting in a group of candidates at risk of failing the exam. S206: In the post-exam stage, density clustering algorithm is used to determine each first abnormal group among multiple candidates. Based on the intra-cluster similarity evaluation index corresponding to each first abnormal group and the similarity evaluation index corresponding to any two candidates in the first abnormal group, a second abnormal group is selected from each first abnormal group to obtain the post-exam risk candidate group. The similarity evaluation index is used to indicate the proportion of the number of questions in which any two candidates answer the same question incorrectly and have the same wrong answer to the total number of questions in which any two candidates have the same wrong answer.
[0023] First, in the pre-exam stage, the computing device can construct a candidate relationship graph structure to represent the relationships between candidates, and classify candidates into community or non-community individuals based on the candidate relationship graph structure, perform message passing based on the candidate relationship graph structure, generate embedded representations corresponding to candidates, and determine the pre-exam risk candidate groups based on the embedded representations (202).
[0024] In this candidate relationship graph structure, nodes represent candidates, and edges are weighted undirected edges created based on candidate feature similarity. Communities indicate potentially organized groups of candidates who have registered abnormally. Each node can possess several attribute information (i.e., the corresponding candidate's attribute information), such as registration IP address, password, mailing address, workplace, and security questions. This attribute information forms the basis for analyzing candidate relationships. Connections between candidates can be established based on attribute information to create edges in the candidate relationship graph structure. Candidates can then be categorized into community or non-community individuals.
[0025] Then, the computing device can perform message passing based on the candidate relationship graph structure, generate embedded representations corresponding to each candidate, and determine the pre-exam high-risk candidate group based on the embedded representations corresponding to each candidate. The specific methods for generating the embedded representations corresponding to each candidate and for determining the pre-exam high-risk candidate group based on these embedded representations will be explained in detail below.
[0026] During the examination, the computing device can construct an examination answer graph structure based on the examinees' answers. In this graph, nodes represent examinees, and the weight of an edge is the similarity of the representation vectors of two examinees. The representation vectors are constructed based on each examinee's answer content and answering order. Based on the examination answer graph structure, a spectral clustering algorithm is used to determine groups of examinees with similar answer content. Based on the overlap of the answering order and answering time among examinees in the same group, examinees with follow-up answering behavior are identified, resulting in a group of examinees at risk of failing the exam (S204).
[0027] In other words, risk identification during the examination process primarily focuses on the similarity of answers among candidates. This similarity stems not only from the specific content of the candidates' answers (such as answer accuracy and option distribution) but also from the order in which they answer a set of questions (such as the sequence of question solutions and the pace of answering). First, an examination answer graph structure representing the correlation between candidates' answering behaviors is constructed. Then, using a spectral clustering algorithm, based on this examination answer graph structure, candidates exhibiting follow-up answering behaviors are identified, resulting in a group of candidates at risk during the examination.
[0028] In the post-exam phase, the computing device uses a density clustering algorithm to identify each first abnormal group among multiple candidates. Based on the intra-cluster similarity evaluation index corresponding to each first abnormal group and the similarity evaluation index corresponding to any two candidates in the first abnormal group, a second abnormal group is selected from each first abnormal group to obtain the post-exam risk candidate group. The similarity evaluation index is used to indicate the proportion of questions in which any two candidates answer the same question incorrectly and have the same wrong answer to the proportion of questions in which any two candidates have the same wrong answer (S206).
[0029] In other words, in the post-exam phase, we can first preliminarily cluster out a group of candidates who are expected to have a certain risk (the first abnormal group). Since we know the correct and incorrect answers of the candidates after the exam, we can further filter out the second abnormal group by analyzing the incorrect answers between pairs of candidates in the first abnormal group (represented by a similarity evaluation index) and the average number of incorrect answers among candidates in the first abnormal group (represented by an intra-cluster similarity evaluation index), thereby extracting a more accurate group of candidates with risk.
[0030] As described in the background section, in existing technologies, monitoring for risky behaviors during examinations is typically done manually. For example, organizers manage each stage of the examination and use tools to monitor examinees and prevent cheating. However, this approach using existing technologies may not be able to detect risky behaviors (such as cheating) in a timely manner, thus reducing the efficiency and accuracy of identifying exam-related risks.
[0031] In view of this, this method identifies corresponding risk candidate groups by developing different methods according to the different characteristics of the pre-exam, during-exam, and post-exam stages (pre-exam mainly uses the attributes of candidates registering before the exam, during the exam mainly uses the attributes of candidates' behavior during the exam, and post-exam mainly uses the attributes of candidates' answering of questions after the exam, to identify risks respectively), thereby comprehensively identifying risk candidate groups during the exam, before the exam, and after the exam, thus improving the efficiency and accuracy of predicting and controlling exam-related risks.
[0032] The following section provides a detailed explanation of the pre-exam phase. The computing device can first utilize the Neo4j database to construct a graph structure representing the relationships between candidates, and based on this graph structure, classify candidates into community or non-community individuals. Each node possesses several attribute information (i.e., the corresponding candidate's attribute information), such as registration IP address, password, mailing address, workplace, and security questions. This attribute information forms the basis for analyzing candidate relationships. Connections between candidates can be established based on this attribute information, forming edges in the graph structure.
[0033] Then, test takers can be categorized into community or non-community individuals. This can be achieved using a community partitioning algorithm, such as Louvain's algorithm, to divide the nodes in the test taker graph into nodes within the community and nodes outside the community (i.e., non-community individuals). A community represents a group with pre-exam risk.
[0034] Constructing a candidate relationship graph and community segmentation plays three key roles in identifying high-risk candidate groups: First, it provides a more focused path for subsequent in-depth analysis, excluding individual candidate samples outside the group, significantly reducing the complexity of subsequent calculations, and thus greatly improving the overall efficiency of the detection process. Second, it can more effectively capture the characteristics of candidates who violate regulations, more accurately identify cheating behavior and its participants, and form a common feature identification of high-risk groups. Third, the application of the Louvain community segmentation algorithm further improves the accuracy of community detection.
[0035] After completing the graph structure construction and community division, the computing device can use a pre-defined graph neural network to perform message passing based on the candidate relationship graph structure, generating embedded representations for each node as embedded representations corresponding to the respective candidates. Then, based on the embedded representations of the respective candidates, the computing device can determine the confidence level of each candidate corresponding to a pre-defined label, and generate a risk score for each candidate based on the confidence level. The pre-defined label is used to indicate that the candidate poses a risk. The specific method for generating risk scores for candidates will be described below. Based on the risk scores corresponding to candidates, the computing device can determine the characteristics of high-risk candidates, and mark the nodes corresponding to candidates with high-risk candidate characteristics as high-risk candidate nodes, performing a coloring operation in the Neo4j database.
[0036] The high-risk candidate characteristics mentioned here refer to the common features of candidates identified through statistical methods as having a relatively high risk profile. For example, if an IP address is associated with multiple high-risk candidates, then that IP address may be a centralized registration point for a risky organization related to the exam.
[0037] Therefore, by identifying the characteristics of high-risk candidates, the nodes corresponding to candidates with risks (high-risk candidate nodes) can be determined. These nodes can then be marked, and coloring operations can be performed in the Neo4j database to clearly and obviously visualize the candidates with risks.
[0038] Since risky behaviors related to exams in reality are usually organized group actions, after identifying high-risk candidate nodes, the associated groups can be determined based on these nodes within the candidate relationship graph structure. Therefore, computing devices can propagate high-risk labels based on the candidate relationship graph structure to identify risky candidate groups associated with high-risk candidate nodes. The specific method of high-risk label propagation will be described below.
[0039] In other words, in the candidate relationship graph structure, the edge weight between any two nodes can be determined by the common attribute information and corresponding weights that exist between the corresponding candidates. The edge weight can be determined by the following formula:
[0040] Among them, W ij Let w be the edge weight between the i-th node and the j-th node, and k be the number of attribute information. kThe preset weight for the k-th attribute can be set based on experience. For example, passwords and security questions have relatively high weights, while IP addresses have relatively low weights. This is because, under normal circumstances, it's almost impossible for candidates to have the same password or security question. However, due to the widespread use of NAT technology, people in the same school or organization may share a single IP address. k (i, j) is an indicator function used to represent the condition where the k-th attribute information of the i-th node and the j-th node are the same. k (i, j) is 1, otherwise it is 0.
[0041] Of course, the computing device can first construct a multigraph, with each graph corresponding to a type of attribute information. When two nodes share the same attribute information, an edge can be constructed between them. Then, after weighted summation using the above method, the original graph is transformed from a multigraph into a simple graph, resulting in the aforementioned candidate relationship graph structure. There is at most one edge between nodes, representing the comprehensive similarity between the two candidates. The more shared features, the greater the edge weight, meaning a closer connection between the two candidates. The construction of the simple graph also facilitates subsequent community partitioning algorithms, reducing complexity. For example, if two candidates have used the same IP address and the same communication address, two edges will be constructed between the two nodes. After constructing relationship edges for various features, the edges between all candidate nodes are weighted and summarized to form a total relationship edge. Secondly, regarding community partitioning, the Louvain community partitioning algorithm automatically identifies closely related subgraphs, i.e., communities, by calculating the comprehensive similarity between each pair of candidates. The Louvain algorithm is a greedy algorithm based on maximizing modularity. For a given modular partitioning scheme in a network, its modularity is defined as:
[0042] Among them, e c Let represent the sum of weights of community c, and m represent the sum of weights of all edges in the graph. This represents the sum of the weights of the edges connected to nodes within community c. The modularity ranges from 1 / 2 to 1. A higher modularity indicates a more reasonable community division, while a negative modularity indicates a low degree of rationality in the current community division, suggesting that each node should be considered as a separate community.
[0043] For nodes in the network, by trying to place them into different candidate groups and evaluating the improvement in overall network modularity, the most ideal community for each node can be found. After multiple iterations, if the overall modularity no longer improves, the current partitioning is output as the community discovery result. After community partitioning, the modularity is as high as 0.7, indicating that there is a very high probability of high-risk groups among the test takers.
[0044] To further identify high-risk candidates within the defined communities, nodes not belonging to a community can be considered as nodes unrelated to other nodes. Alternatively, during subsequent message passing via graph neural networks, feature extraction can be performed only on nodes within the communities, thus allowing for risk prediction only on those nodes.
[0045] The goal of this stage is to further consolidate the characteristics of high-risk candidates within the communities segmented in the previous step. Since it's impossible to capture all violations during actual invigilation, whether a candidate has violated regulations should be considered a missing label field. This method leverages the advantages of graph neural network models, combining node features with the graph structure information of the candidate relationship graph for deep analysis to handle complex correlation data between candidates. Specifically, this method employs a semi-supervised graph neural network (Graph-based joint model with Nonignorable Missingness, GNM). In the GNM model, for each observed node, the GNM weights it according to the probability of the node being observed, thus inversely weighting the observed data to reduce bias caused by non-random missing values. For missing nodes, the GNM predicts the latent labels of these nodes, and then predicts the missing labels based on these representations.
[0046] Specifically, it is necessary to perform detailed segmented coding of the candidates' relevant information. This information can include the aforementioned attribute information. For example, based on the number of times an IP address is repeated, or the degree of password repetition, a high coding value may indicate proxy registration behavior; based on the number of times an address is repeated, a high coding value may indicate concentrated registration; based on the degree of repetition by organization, a high coding value may mean unified organized registration. This coding method divides features into different intervals based on their degree of repetition and assigns corresponding coding values. Through this segmented coding method based on repetition, all features are transformed into multi-level coding values, which not only allows for a more flexible representation of feature repetition but also helps the model better capture the similarities between candidates, thereby enhancing the ability to identify potential organized proxy registration behavior.
[0047] Thus, the encoded value corresponding to each node can be obtained through the above method, thereby obtaining the initial node features. Then, through message passing via the GNM model, the node features of each node can be updated and iterated continuously, ultimately obtaining the embedded representation of each node.
[0048] The GNM model captures the features of each node within its network structure. In this process, each node gathers information from its neighbors, aggregates and updates this information with its own features, forming a new node representation. In this mechanism, node features are continuously updated with each iteration, eventually incorporating information from neighbors, thus capturing both global and local relationships within the graph. After receiving messages from neighboring nodes, a weighted sum of features within the node's neighborhood is performed using graph convolution operations. Let h be the feature of node i in the l-th iteration. i (l) Then, after one convolution operation, its new features can be obtained by the following calculation:
[0049] Where, N (i) Let k be the set of neighbors of node i. i k j W represents the degree of nodes i and j. (l) It is a weight matrix. (i) is the activation function, typically the ReLU function. The GNM model iteratively updates the features of each node through message passing and graph convolution operations, ultimately obtaining the embedded representation of each node.
[0050] After determining the embedded representation of each examinee, the computing device can determine the confidence level corresponding to the pre-defined label for each examinee, and generate a risk score for each examinee based on the confidence level. The pre-defined label indicates that the examinee is at risk. In other words, GNM can predict whether an examinee is at risk based on the examinee's embedded representation. GNM can output the predicted confidence level during prediction, where only the confidence level corresponding to the pre-defined label can be obtained; that is, the probability that GNM considers a particular examinee to be at risk.
[0051] This stage focuses only on candidates with a predicted label of 0 (i.e., the preset label), collecting their probabilities and calculating their mean and standard deviation. The second step, based on the concept of z-scores, calculates a risk score between 0 and 100 for each candidate, effectively ranking and normalizing their risk probabilities. Candidates with lower z-scores are considered to have higher risk. For example, candidates can be categorized as high-risk, medium-risk, and low-risk. High-risk candidates (0-40 points): These candidates are considered to have a higher risk of cheating and should be given priority for attention and monitoring.
[0052] Medium-risk candidates (41-69 points): These candidates are considered to have a potential risk of cheating and should be closely monitored to prevent possible cheating.
[0053] Low-risk candidates (70-100 points): These candidates are considered low-risk and generally do not require special attention.
[0054] In other words, we can statistically identify features that appear frequently among high-risk candidates and observe which features are repeated among these high-risk candidates. For example, if an IP address is associated with multiple high-risk candidates, then this IP may be a centralized registration point for cheating organizations. Specifically, we set a scoring threshold and select the set V of nodes representing all high-risk candidates with scores below a certain threshold. high For all v i ∈V high Examine the frequency of occurrence of each feature in the feature set F:
[0055] Among them, I(v) i F k ) is the indicator function, node v i With characteristic F k At that time, I(v) i F k ) = 1, otherwise I(v) i F k =0. Set the threshold for the frequency of feature occurrence (i.e., the first preset threshold mentioned above) θ. f , with frequencies higher than θ f The features are labeled as "high-risk candidate features", and the high-risk feature set F is obtained. high .
[0056] In the above, a GNM model was used to generate a predicted probability of cheating risk for each examinee, and these predicted probabilities were quantified into easily understandable scores using a scoring card. Based on this, feature pattern recognition was used to analyze examinees with lower scores and identify patterns of certain high-frequency features, such as frequently shared IP addresses or communication addresses. The purpose of feature analysis and label propagation is to identify which features are predominantly present among high-risk examinees, thereby identifying key characteristics of organized cheating.
[0057] After identifying the characteristics of high-risk candidates, the nodes corresponding to these candidates can be designated as high-risk candidate nodes. These nodes are then labeled as high-risk, and a coloring operation is used to highlight them, facilitating subsequent label propagation. The label propagation algorithm identifies potential groups posing a test-taking risk (e.g., cheating rings) by propagating risk labels through the candidate relationship graph structure.
[0058] Further, the Neo4j graph database is used for coloring operations, specifically for high-risk candidate nodes v. i ∈V highInitialize its coloring in the graph and mark it as "high risk", that is, let v i .color=red. For any node v j ∈V, if it possesses feature F k ∈F high Then update the node's attributes, making v j .color=red.
[0059] In other words, after initially identifying each high-risk candidate node, the high-risk label can be propagated to a subset of nodes within a certain neighborhood of the high-risk candidate node by leveraging the relationships between nodes in the candidate relationship graph structure. The method for propagating the high-risk label can be determined iteratively. In each iteration, the propagation strength of each node is calculated to determine whether the high-risk label can be propagated to the corresponding node. After continuous iteration, if the label propagation to each node no longer changes (i.e., the propagation strength of each node tends to converge), the iteration can end. Therefore, each high-risk candidate node can potentially propagate its high-risk label to nodes within a certain range. Thus, this method can identify groups at risk, rather than just discrete high-risk candidate nodes.
[0060] The label propagation algorithm uses a greedy strategy, iteratively labeling each colored node with its directly associated nodes. A propagation strength *s* is introduced to describe the propagation effect on the examinee. First, the initial strength of each node can be set:
[0061] Set a threshold γ for the propagation intensity; if the propagation intensity v of a certain node... j If s > γ, then v j It will also be considered as being stained, i.e., marked v. j .color=red, and v j Add to set V high In the middle, each iteration starts from v i ∈V high , for v i neighbor node v n Propagation occurs, satisfying the following condition in the l-th iteration: v n .s=v n .s+v i .s·α l ·w' in .
[0062] Where α∈(0,1) is the update rate, w' in For node v i With node v nAfter multiple iterations of propagation, the normalized weights (i.e., edge weights) between nodes will tend to converge, and the number of colored nodes will also tend to stabilize, at which point the label propagation process ends. The overall coloring and label propagation process is as follows: Figure 3 As shown.
[0063] Figure 3 This is a schematic diagram of a dyeing process provided in Embodiment 1 of this disclosure.
[0064] exist Figure 3 The diagram illustrates the original graph structure (the newly constructed candidate relationship graph structure) and the three-round label propagation process based on this original graph structure. First, in the original graph structure, each node represents a candidate, and the edges between nodes represent the edge weights determined in step S202. Since nodes 1 and 3 are the initially determined candidate nodes, the initial coloring sets these two nodes to 1, and the propagation strength of the remaining nodes to 0. In the first round of propagation, the propagation strengths of the other three nodes are updated, but do not exceed the set second preset threshold. In the second round of propagation, the updated propagation strength of node 2 exceeds the second preset threshold (in the context of the relationship between the candidate and the node). Figure 3 In the corresponding example, the second preset threshold can be set to 0.7, so node 2 is colored. In the third round of propagation, the update magnitude of the propagation intensity of the uncolored nodes is relatively small and does not exceed the second preset threshold. Therefore, no new nodes are colored in the third round of propagation, and the propagation intensity has converged, stopping the iteration of label propagation.
[0065] Finally, the computing device can visualize the high-risk candidate groups (pre-exam high-risk candidate groups) and the identification criteria. Through Neo4j's graph database, the relationships between candidates can be visualized, allowing administrators to more intuitively understand the structure and scale of the cheating network. This visualization helps administrators better understand the complexity of cheating behavior, thereby developing more effective preventative measures.
[0066] The risk identification during the examination stage will then be described in detail in the embodiments of this application.
[0067] In this embodiment, considering that paperless exams (computer-based exams) typically employ a shuffled question order, meaning that within the same set of questions, the question order for each candidate is randomized to ensure that each candidate has a unique question number on their exam paper, corresponding to the standard question number on the original exam paper. Under independent answering conditions, the probability of two candidates answering the same question at the same time is low. The possibility of two or more candidates answering multiple questions simultaneously is even more extremely low. This is the fundamental basis for the exam data analysis in this embodiment. The computer-based exam system shuffles the question order as follows: Figure 4 As shown.
[0068] Furthermore, the disordered nature of questions in computer-based exams provides a basis for detecting asynchronous follow-up responses in this embodiment. For example, in an exam room, a cheater might first record the answers of the person being copied, and then answer all at once. In this case, the answering times of the two candidates for each question may be far apart, but the order of their answers will still be highly similar. Considering a natural scenario, when two benign candidates answer questions in their own order, the probability that the order of their answers for several questions happens to be exactly the same is extremely low. For example... Figure 4 If candidates 1 and 2 answer the questions in their own order, they will have at most four questions answered in the same order. In fact, the probability of this happening is only 4%. As the number of questions increases, the probability of two candidates answering multiple questions in the same order decreases exponentially. The probability P of two candidates answering k questions in the same order when there are a total of n questions is calculated using the following formula: ; Where n is the total number of questions, and k is the number of questions in which the two candidates answered in the same order.
[0069] When n (i.e., the total number of questions in the exam) is 100, the probability that any two candidates will answer 10 questions in the same order when the order of the questions is randomly shuffled is negligible, as shown in the table below.
[0070]
[0071] Therefore, in this embodiment, during the examination, the answers of each examinee are first collected in real time, including the answer content and answer time sequence for each question. Through a rationally designed feature extraction algorithm, a unique representation vector is constructed for each examinee. This vector simultaneously contains features of the answer content (such as answer accuracy and option distribution) and features of the answer sequence (such as question answer sequence and answering rhythm). Subsequently, the similarity between pairs of examinees is calculated based on the representation vectors, forming an examination answer graph structure. Nodes in the graph structure represent individual examinees, and edge weights precisely quantify the degree of similarity between examinees' answers, providing a structured data foundation for subsequent analysis.
[0072] Then, to fully utilize the crucial information of the candidates' answering order, this embodiment applies a spectral clustering algorithm based on the constructed exam answer graph structure. Through cluster analysis, it quickly identifies groups of candidates with similar answer content (i.e., highly similar answer trajectories). Specifically, candidates whose answer content similarity exceeds a first preset threshold are grouped into the same candidate group. Spectral clustering can detect similarity between data in a multi-dimensional space, providing an effective means for plagiarism detection on large-scale data. This allows for in-depth analysis of candidates' answer trajectories, thereby identifying potential cheating behaviors. During the spectral clustering process, a preset first threshold controls the minimum similarity requirement within a group, ensuring high consistency in the answer trajectories of candidates within the same group. This accurately identifies candidate groups potentially involved in collaborative cheating, providing target objects for abnormal behavior detection.
[0073] Next, for each group of test-takers, an in-depth analysis was conducted on the order in which they answered questions and the overlap in their answering times. By calculating the correlation coefficient of answering order and the degree of overlap in time windows among test-takers, combined with a preset time difference threshold, pairs of test-takers exhibiting real-time following behavior (synchronous cheating) were accurately identified. Simultaneously, by analyzing the characteristics of answering time distribution and the degree of order anomalies, test-takers exhibiting a memorization-then-answering pattern (asynchronous cheating) were detected. This achieved full coverage detection of the two main cheating patterns, effectively capturing test-takers with following behavior, thus identifying high-risk test-taker groups.
[0074] Finally, the answers and answer trajectories of candidates exhibiting follow-up behavior are output through a visual interface. For example, but not limited to, generating a spatiotemporal heatmap containing the answer trajectories of candidates exhibiting follow-up behavior, clearly showing the answer propagation path and overlapping time intervals; simultaneously providing an interactive follow-path map, allowing invigilators to focus on specific time periods or candidates for detailed verification. By visually presenting the dynamic propagation process of cheating, invigilators are provided with an intuitive and traceable chain of behavioral evidence, significantly improving the efficiency of cheating identification and the accuracy of handling.
[0075] In this embodiment, during the examination, an examination answer graph structure is first constructed based on the candidates' answers, providing a topological foundation for subsequent dynamic behavior association modeling. Nodes in this graph structure represent candidate entities, and edge weights are the similarity of the representation vectors of two candidates. These representation vectors are constructed based on each candidate's answer content and answering order. Then, based on the examination answer graph structure, a spectral clustering algorithm is used to group candidates whose answer content similarity exceeds a preset first threshold into the same candidate group, providing a core criterion for accurately identifying suspected collaborative cheating groups. Through spectral embedding analysis of the graph structure using spectral clustering, accidental similarity and organized cheating are effectively distinguished. Secondly, based on the overlap in the order and timing of answers among candidates within the same candidate group, candidates exhibiting follow-up answering behavior are identified, achieving dual-mode detection of synchronous follow-up cheating (real-time copying) and asynchronous cheating (memorizing before answering). Finally, the answers and trajectories of candidates exhibiting follow-up behavior are visualized, for example, by generating interactive heatmaps and follow-up path maps of cheating behavior and presenting them visually, providing invigilators with a traceable chain of behavioral evidence. This achieves high-precision, multimodal, and traceable detection of group follow-up cheating. It addresses the technical problems of existing cheating detection schemes, such as low accuracy in identifying group follow-up cheating, lack of dynamic behavior analysis, and incomplete coverage of cheating patterns.
[0076] Specifically, in constructing the exam answer graph structure, this embodiment of the invention first extracts answer content features (such as the distribution of multiple-choice options and the keyword matching degree of subjective questions) and answer sequence features (such as the sequence of answering questions and the time interval between answers to adjacent questions). These two types of features are then concatenated and fused to form a high-dimensional representation vector. Based on these representation vectors, the cosine similarity between each pair of examinees is calculated to accurately quantify the degree of similarity in their answers. Finally, an exam answer graph structure is constructed with examinees as nodes and similarity values as edge weights. Larger edge weights indicate more similar answer patterns among examinees, providing a structured data foundation for subsequent group behavior analysis. This graph structure can simultaneously carry content similarity (answer matching) and temporal logic (problem-solving path), providing a structured data foundation for subsequent abnormal behavior detection.
[0077] In this embodiment of the invention, a fine-grained attribute graph clustering method is referenced. This method integrates the feature and structural information of nodes to construct a high-quality similarity graph. Based on this, a shallow, interpretable high-order relationship clustering method is proposed, thereby more accurately reflecting the subtle relationships between data during the clustering process. Therefore, this embodiment introduces a graph structure learning algorithm before performing spectral clustering analysis to better uncover hidden relationships in the data, thus providing a more comprehensive perspective on candidate behavior similarity. This method allows for preprocessing of candidate answer data before the clustering stage, strengthening the potential behavioral similarities between candidates and providing high-quality graph structure support for subsequent follow-up answer detection. This graph structure can be viewed as a mapping of the self-expressive attributes of the original data, where each data sample is expressed by a linear combination of other samples within the same group, helping to detect implicit relationships between samples.
[0078] Combination Figure 5 As shown, after constructing the exam answer graph structure, the relation matrix is initialized; wherein, the expression of the relation matrix is: ; in, It is a trajectory feature matrix, where each row of the trajectory feature matrix represents a candidate's representation vector. This refers to the structure of the exam answer diagram; This is the regularization strength coefficient. The first term of the expression indicates that the original information of the data can be approximated by a relation matrix, where each data point can express itself through its relationship with other data points. The second term represents the regularization term introduced to keep this relation matrix as simple and stable as possible, thus preventing overfitting. Looking at the relationship between the two terms, when the first term is considered alone, its optimal exam answer graph structure S is the identity matrix, that is, let... = At this point, the value of the first term is 0; considering the second term alone, its optimal exam answer graph structure S is a zero matrix, and the value of the second term is 0. The two optimization terms are determined by parameters. By adjusting the graph, a better graphical representation can be obtained.
[0079] Furthermore, this embodiment also references a simple contrastive graph clustering method, which proposes a graph clustering method combining low-frequency filtering, a lightweight network structure, and a contrastive loss based on neighborhood consistency. This significantly improves the efficiency and accuracy of graph clustering and enhances the discriminative power of data representations. Following this approach, this embodiment optimizes the above method by replacing the higher-order regularization terms in the relation matrix with contrastive learning regularization terms. This improves the discriminative power of graph structure learning, enabling the learned graph structure to more accurately capture subtle differences in test-takers' answering behaviors during the clustering process. In this way, test-takers with similar graph structures can be accurately clustered together, achieving more detailed trajectory similarity analysis, helping to identify potential plagiarism, and providing support for real-time cheating detection in large-scale examination environments with limited equipment.
[0080] To improve the distinguishability of the graph, this embodiment introduces a contrastive learning mechanism. By bringing similar samples closer together and pushing dissimilar samples further apart, it enhances the model's ability to identify follow-up responses. Specifically, each node's k neighboring nodes are considered positive samples, and the relationships between them reflect the similarity of the nodes. Other nodes in the graph structure are considered negative samples, representing dissimilar relationships. The loss function is designed to further strengthen this contrastive mechanism, maximizing the similarity of positive sample pairs while minimizing the similarity of negative sample pairs, thereby improving the quality of the graph structure. In this way, the model can more accurately capture the true relationships between nodes, making similar nodes closer in the representation space, while effectively distinguishing dissimilar nodes. Figure 6 As shown.
[0081] Thus, the loss function for the graph structure learning algorithm is obtained, ensuring the high discriminative power of the graph structure, which helps to identify potential cheating behaviors and improve the model's recognition accuracy. The expression for the loss function is: ; in, For the number of nodes, Indicates the first All nearest neighbors of each node, Indicates the first The similarity between the representation vector of a node and the representation vector of its j-th neighbor node. Indicates the first The similarity between the representation vector of a node and the representation vector of the p-th node in the exam answer graph structure; These are the weight coefficients of the contrastive learning regularization term.
[0082] To achieve the optimization objective of the graph structure learning algorithm, gradient descent is used to optimize the graph structure, ensuring that the reconstruction error between nodes is minimized. Furthermore, a comparison regularizer is used to further improve the graph quality. Specifically, to achieve this optimization objective, gradient descent is used to optimize the exam answer graph structure, ensuring that the reconstruction error between nodes is minimized. A comparison regularizer is then used to further improve the graph quality.
[0083] After multiple iterations, the exam response graph structure S will tend to converge. Since the selection of neighboring nodes is not symmetric, the S matrix may not be a symmetric matrix, meaning S represents a directed graph. Generally, spectral clustering is based on undirected graphs. Therefore, by symmetrizing the converged exam response graph structure, we obtain the undirected graph structure C. Finally, the clustering result is obtained by performing spectral clustering on the undirected graph structure C.
[0084] Optionally, the convergent exam response graph structure can be symmetrically processed using the following formula: ; Where S is the convergent exam answer graph structure, and C is the undirected graph structure obtained by symmetry processing.
[0085] Optionally, the gradient of the gradient descent method used is expressed as: ; ; ; ; in, It reconstructs the gradient components of the loss; It compares the gradient components of the loss. It is the standardized trajectory feature matrix; It is the element in the i-th row and j-th column of the covariance matrix, representing the dot product of the standardized representation vectors of candidate i and candidate j; It is the element in the i-th row and j-th column of the product of the covariance matrix and the similarity matrix at step t-1. It is the similarity weight between node i and node j at the (t-1)th iteration. These are the weight coefficients of the contrastive learning regularization term. It is the similarity weight between node i and node p at the (t-1)th iteration. For the number of nodes, Indicates the first All the nearest neighbors of a node.
[0086] After obtaining the clustering results, this invention considers both synchronous and asynchronous cheating. Synchronous cheating refers to directly copying from a neighbor or following the same source when answering questions. Asynchronous cheating refers to the cheater memorizing the answers first and then writing them on the corresponding question at the end. For synchronous cheating, two indicators will be used: textual correlation and temporal correlation. Behavioral correlation refers to combining behavioral clustering results to detect whether candidates with highly similar answers have similar behavioral patterns.
[0087] Specifically, for the suspected group identified through spectral clustering, a behavioral association graph structure is first constructed within the group: using each examinee as a node, a weighted directed graph network is formed by calculating the correlation coefficient of the answering order (such as the Spearman rank correlation coefficient) and the overlap of answering time between each pair of examinees. This behavioral association graph structure accurately quantifies the strength of the correlation between the behavioral patterns of examinees, where edges with weights greater than a preset correlation threshold indicate significant behavioral synchronicity between examinees.
[0088] Then, for these highly correlated pairs of test takers, their abnormal following behavior is further analyzed: when the similarity of two test takers' answers to a specific question exceeds a preset second threshold, the time difference between their submissions of that answer is precisely calculated. If the time difference is greater than a preset time threshold (e.g., 60 seconds), it is determined that there is following behavior, indicating that the test taker who answers later may have delayed answering after observing the former's answer, and the test taker is marked as suspected of synchronous cheating. This mechanism can effectively identify the "observe first, then answer" cheating pattern.
[0089] Simultaneously, the answering behavior of all candidates within the same group is analyzed: by calculating the abnormality of each candidate's answering order (such as the question skipping index) and the characteristics of the answering time distribution (such as the concentration of answers at the end), when a candidate's abnormality of the answering order exceeds the corresponding preset threshold or the proportion of answers at the end exceeds the corresponding preset threshold, the candidate is marked as suspected of asynchronous cheating. This mechanism can effectively identify the cheating pattern of "memorizing first and then answering in batches".
[0090] Through the aforementioned dual-path detection mechanism, both real-time following behavior (high correlation + large time difference) and delayed cheating behavior (abnormal sequence / distribution) are captured, achieving multi-dimensional and accurate identification of abnormal following and answering behaviors.
[0091] Optionally, the method proposed in this application further includes: when the number of candidates with abnormal answering order and / or abnormal answering time distribution within the same candidate group is greater than a preset third threshold, comparing the answers of candidates with abnormal answering order and / or abnormal answering time distribution to determine the similarity of answers among candidates.
[0092] In this embodiment of the invention, after detecting abnormal follow-up answering behavior, a group-level verification mechanism is added: when the number of candidates in the same candidate group marked as having abnormal answering order and / or abnormal answering time distribution exceeds a preset third threshold, a deep answer comparison analysis is automatically triggered. This mechanism first extracts detailed answer records of these abnormal candidates and uses a multi-dimensional similarity algorithm (including option matching degree, semantic similarity of subjective questions, consistency of incorrect answers, etc.) to calculate the answer similarity score between pairs of candidates for each question. If more than a certain percentage of abnormal candidate pairs (e.g., >75%) have answer similarities significantly higher than the group average, it is confirmed as organized cheating behavior. This verification mechanism can effectively distinguish between genuine cheating groups and individuals with occasional abnormal behavior, significantly reducing the false positive rate and ensuring the reliability of the detection results.
[0093] In this embodiment of the invention, an analysis of the economics exams in City S was conducted, and good results were achieved. The results of the analysis are as follows: A total of 144 abnormal groups were found in City S, including 115 abnormal groups in the same examination room and 29 abnormal groups in different examination rooms, with a total of 895 people. The largest group had 20 people. Figure 7 This is a statistics chart of the abnormal groups in City S. Among them, the number of abnormal people in the same examination room in session 7 is the largest, reaching 128 people, while the number of abnormal people in different examination rooms in session 4 is the largest, reaching 100 people.
[0094] The main characteristic of abnormal groups in the test is that the answers are highly similar. Figure 7 The presentation showed a sample of the answers from a typical group of 5 people with unusual behavior, and included 30 of the 70 questions.
[0095] Figure 8 These five test takers had identical answers to 38 questions, a rate of 54%. Figure 9 This is a heatmap showing the similarity of these five candidates.
[0096] These five test takers formed a typical high-risk group centered around test taker 2, with their answers showing a high degree of similarity. Figure 10 As shown.
[0097] In this embodiment of the invention, two pairs of typical cases from the same examination room were selected for visual presentation of the answer trajectory. The cases from the same examination room are as follows: Figure 11 As shown. Figure 11 In the diagram, the two lines represent two candidates, the horizontal axis represents the standard question number, and the vertical axis represents the time (in seconds) after the start of the exam.
[0098] In Case Study 1, the two candidates in the same examination room had 100% similarity in their answers to these 30 questions, and a cosine similarity of their answer trajectories (an index that measures the similarity between two curves) of 99.1%, showing typical characteristics of following each other in answering questions. Figure 12These are their answers.
[0099] Case 2 in the same examination room Figure 13 As shown, in Case 2 of the same examination room, the two candidates had 100% similarity in their answers to these 30 questions, and the cosine similarity of their answer trajectories was 99.8%, demonstrating typical follow-up answering characteristics. Figure 14 These are their answers.
[0100] Below are two typical examples of cross-exam-site case studies: Cross-exam case 1: The two candidates' answers to these 30 questions were 100% similar, and the cosine similarity of their answer trajectories was 99.2%. Figure 15 and Figure 16 This is the answer trajectory and answer result for Case 1, which involves cross-examination rooms.
[0101] Cross-exam room case 2: The two candidates had 100% similarity in their answers to these 30 questions, and the cosine similarity of their answer trajectories was 99.2%. Figure 17 and Figure 18 This is the answer trajectory and answer result for Case 2, which involves cross-examination rooms.
[0102] In City S, a total of 40 candidates were found to have rushed to answer the questions. Figure 19 This is a typical example of a sudden, unexpected response. For example... Figure 19 As shown, the candidate answered only 10 questions in the first 2700 seconds and 75 questions in the last 2200 seconds, which is a clear case of rushed answering.
[0103] To verify the ability of the technical solution proposed in this application to detect and block abnormal candidates in a timely manner during the examination, the embodiments of this invention conducted two data analyses at half an hour and one hour after the start of the examination. The results showed that a total of 45 abnormal candidates were detected, proving that the technical solution has a certain ability to detect and block abnormal candidates during the examination.
[0104] Furthermore, through verification using examination data from City S, this embodiment of the invention identified high-risk groups with the following characteristics: First, similar answer results. This is the core characteristic of high-risk groups. Second, convergent answering order. In high-risk groups, multiple pairs of candidates showed convergent answering orders. Third, similar answering times. The similarity in answering times further verifies that the aforementioned candidates did not answer independently. Simultaneously, this technical solution can detect candidates who rush to answer questions and has the ability to disrupt the examination process. Therefore, the abnormal following answer group detection scheme based on spectral clustering algorithm proposed in this application has good results.
[0105] In summary, risk identification during the exam phase focuses on analyzing candidates' answer trajectories, particularly when question numbers are shuffled, effectively identifying and analyzing their answering behavior. This characteristic gives risk identification during the exam phase the following advantages: 1) Analysis at any time point: It can perform trajectory analysis at any time point, adapting to various exam formats. This flexibility ensures its applicability in different scenarios, whether monitoring real-time answering behavior or analyzing candidates' answering strategies afterward. 2) Revealing potential cheating behavior: Through in-depth analysis of candidates' trajectories, it is possible to identify similar answering patterns among candidates, especially when multiple candidates are answering simultaneously. For example, if two candidates choose similar questions within the same time period and answer in a similar order, this may indicate a risk of information sharing or plagiarism.
[0106] The following is a detailed explanation of risk identification in the post-exam phase.
[0107] Specifically, firstly, users can upload completed exam papers from multiple candidates to a computing device via their terminal devices. Upon receiving the exam papers from multiple candidates, the computing device treats the answers of any two candidates on the same exam paper as clustering results of two different clustering models on the same set, and uses the rand index to measure the similarity between the two candidates' answers. Then, after determining the error-similarity rate between any two candidates, the computing device constructs a similarity evaluation index based on the rand index and the error-similarity rate. This similarity evaluation index indicates the proportion of questions on which two candidates answer incorrectly and have identical incorrect answers, out of the total number of questions on which both candidates have incorrect answers.
[0108] Before using density clustering to identify the first outlier groups among multiple candidates, the method further includes: determining the error-sameness ratio between any two candidates and constructing a similarity evaluation index based on the error-sameness ratio. Specifically, the operation of the computing device constructing the similarity evaluation index based on the error-sameness ratio includes: first, determining the number of first-question questions where any two candidates answer the same question incorrectly, and their incorrect answers are identical; then, determining the number of second-question questions where any two candidates answer the same question incorrectly, and their incorrect answers are different; further, determining the number of third-question questions where any two candidates answer the same question incorrectly, and one candidate answers correctly; finally, calculating the proportion of the number of first-question questions to the total number of first-question questions, second-question questions, and third-question questions, and determining this proportion as the similarity evaluation index corresponding to the aforementioned any two candidates. The above will be described in detail later, and therefore will not be repeated here.
[0109] Then, the computing device uses a density clustering algorithm to identify the first anomalous group among multiple candidates. This first anomalous group is used to indicate potential cheating groups. The operation of the computing device using the density clustering algorithm to identify the first anomalous group among multiple candidates includes: First, the computing device analyzes the distance distribution among candidates based on a grid search method and pre-sets a minimum similarity threshold for determining the similarity between candidates. Then, based on the minimum similarity threshold, the computing device determines the search range of the neighborhood radius corresponding to the density clustering algorithm. Further, based on the search range of the neighborhood radius, the computing device traverses parameter combinations including the neighborhood radius and the minimum number of samples, and selects the target parameter combination that optimizes the clustering effect of the density clustering algorithm. Finally, the computing device uses the density clustering algorithm and the target parameter combination to identify the first anomalous group among multiple candidates. The above will be described in detail later, so it will not be repeated here.
[0110] Furthermore, the computing device determines the intra-cluster similarity evaluation index corresponding to each first abnormal group. The intra-cluster similarity evaluation index indicates the average of multiple similarity evaluation indices corresponding to any two candidates within the first abnormal group. Referring to the above description, since the computing device has already determined the similarity evaluation indices corresponding to any two candidates in the above process, once the computing device has determined the first abnormal group, it can determine the similarity evaluation index between any two candidates within the first abnormal group.
[0111] For example, the computing device identified multiple candidates. And further identified multiple candidates ~ Similarity evaluation index between any two candidates ~ Among them, similarity evaluation indicators With the candidates and test takers Correspondingly, similarity evaluation metrics With the candidates and test takers Correspondingly, ..., similarity evaluation metrics With the candidates and test takers correspond.
[0112] The computing device then identified several first anomaly groups. ~ And the first abnormal group This includes multiple candidates. ~ Then the computing device can determine the examinee. With the candidates Similarity evaluation metrics between Candidates With the candidates Similarity evaluation metrics between and test takers and test takers Similarity evaluation metrics between .
[0113] Thus, it is related to the first abnormal group. Corresponding intra-cluster similarity evaluation index It can be calculated based on the following formula:
[0114] Similarly, based on the same operations described above, the computing device can identify multiple first anomaly groups. ~ Corresponding intra-cluster similarity evaluation index ~ .
[0115] Finally, the computing device uses the intra-cluster similarity evaluation index corresponding to each first abnormal group, and the similarity evaluation index corresponding to any two candidates in each first abnormal group, to filter out second abnormal groups from each first abnormal group. The confidence level of the second abnormal group is greater than that of the first abnormal group. Specifically, the computing device determines the first similarity evaluation index corresponding to the first and second candidates, the second similarity evaluation index corresponding to the second and third candidates, and the third similarity evaluation index corresponding to the first and third candidates in each first abnormal group. Here, the first, second, and third candidates represent any one of the multiple candidates. Furthermore, if the first similarity evaluation index is greater than the corresponding intra-cluster similarity evaluation index, the second similarity evaluation index is greater than the intra-cluster similarity evaluation index, and the third similarity evaluation index is less than the intra-cluster similarity evaluation index, the first abnormal group is removed, and the second abnormal group is obtained.
[0116] The computing device can analyze the clustering results (i.e., the first abnormal group) by combining the intra-cluster similarity evaluation index corresponding to each first abnormal group, and exclude the cases in the first abnormal group where the first candidate and the second candidate are similar, the second candidate and the third candidate are similar, but the first candidate and the third candidate are not similar, thereby selecting the second abnormal group with higher confidence and outputting it.
[0117] As described above, this application selects the rand index, based on the error-similarity rate, as the similarity evaluation metric, thus providing a more rigorous similarity judgment and being suitable for anomaly group detection in large-scale data. That is, it not only considers the consistency of answers on incorrect questions but also integrates various error scenarios, making the detection results more reliable and accurate, and reducing interference from randomness. Therefore, through these improvements, the density clustering algorithm can more effectively identify potential abnormal cheating groups, making it more suitable for complex examination scenarios.
[0118] Furthermore, since this application does not merely analyze the individual behavior of test takers, but rather identifies abnormal cheating groups among them, the solution provided by this application is not limited to the examination room itself, but can also effectively analyze cheating across examination rooms, thereby further ensuring the fairness of the examination.
[0119] Therefore, this application achieves the technical effect of reliably and accurately determining whether there is a potential abnormal cheating group among multiple candidates, and ensuring the fairness of the examination. This solves the technical problem that existing cheating detection methods cannot accurately identify whether there is a potential abnormal cheating group among a large number of candidates, thus failing to guarantee the fairness of the examination.
[0120] Optionally, the operation of selecting second abnormal groups from each first abnormal group based on the intra-cluster similarity evaluation index corresponding to each first abnormal group and the similarity evaluation index corresponding to any two candidates in each first abnormal group includes: determining, respectively, the first similarity evaluation index corresponding to the first candidate and the second candidate, the second similarity evaluation index corresponding to the second candidate and the third candidate, and the third similarity evaluation index corresponding to the first candidate and the third candidate in each first abnormal group, wherein the first candidate, the second candidate, and the third candidate represent any one of the multiple candidates; and removing the first abnormal group and obtaining the second abnormal group if the first similarity evaluation index is greater than the corresponding intra-cluster similarity evaluation index, the second similarity evaluation index is greater than the corresponding intra-cluster similarity evaluation index, and the third similarity evaluation index is less than the corresponding intra-cluster similarity evaluation index.
[0121] Specifically, with the first abnormal group For example, firstly, the computing devices determine the first abnormal group. Internal test takers (That is, the first examinee) and examinees Similarity evaluation metrics between (i.e., the second candidate) Candidates (That is, the first examinee) and examinees Similarity evaluation index among (i.e., the third candidate) and test takers (i.e., the second candidate) and the candidate Similarity evaluation index among (i.e., the third candidate) .
[0122] And the computing device identifies the first abnormal group. Similarity evaluation index between pairs of test takers ~ In this case, the computing device will be connected with the examinee With the candidates The corresponding similarity evaluation index is regarded as the first similarity evaluation index. Will with the candidates With the candidates The corresponding similarity evaluation metric is regarded as the second similarity evaluation metric. Will with the candidates With the candidates The corresponding similarity evaluation index is regarded as the third similarity evaluation index. .
[0123] The computing device then applies the first similarity evaluation index. Second similarity evaluation index and the third similarity evaluation index Respectively with the first abnormal group Corresponding intra-cluster similarity evaluation index A comparison was performed. And based on the first similarity evaluation metric... Greater than intra-cluster similarity evaluation index Second similarity evaluation index Greater than intra-cluster similarity evaluation index However, the third similarity evaluation index Smaller than intra-cluster similarity evaluation index In this case, it indicates the first abnormal group The confidence level is low, thus classifying the first abnormal group as [a group with low confidence]. Remove.
[0124] For example, the first abnormal group Includes candidates ~ Therefore, the computing devices first determine the first abnormal group. Internal test takers (That is, the first examinee) and examinees Similarity evaluation metrics between (i.e., the second candidate) Candidates (That is, the first examinee) and examinees Similarity evaluation index among (i.e., the third candidate) and test takers (i.e., the second candidate) and the candidate Similarity evaluation index among (i.e., the third candidate) .
[0125] And the computing device identifies the first abnormal group. Similarity evaluation index between pairs of test takers ~ In this case, processor 200 will interact with the examinee With the candidates The corresponding similarity evaluation index is regarded as the first similarity evaluation index. Will with the candidates With the candidates The corresponding similarity evaluation metric is regarded as the second similarity evaluation metric. Will with the candidates With the candidates The corresponding similarity evaluation index is regarded as the third similarity evaluation index. .
[0126] The computing device then applies the first similarity evaluation index. Second similarity evaluation index and the third similarity evaluation index Respectively with the first abnormal group Corresponding intra-cluster similarity evaluation index A comparison was performed. And based on the first similarity evaluation metric... Second similarity evaluation index and the third similarity evaluation index Similarity evaluation metrics within clusters If the size relationship between them does not meet the above conditions, it means that it is not necessary to remove the first abnormal group. .
[0127] Furthermore, the processor 200 analysis and test takers (i.e., the first examinee), examinee (i.e., the second candidate) and the candidates (That is, the similarity evaluation index corresponding to the third candidate) ~ With the first abnormal group Intra-cluster similarity evaluation metrics Does the size relationship between them satisfy the above conditions? If it does, then the first abnormal group needs to be removed. The confidence level is low, and the first abnormal group needs to be removed. If the above conditions are not met, it means that it is not necessary to remove the first abnormal group. .
[0128] Similarly, processor 200 analyzes the first anomaly group. In other cases (i.e., candidates) As the first examinee, examinee As the second candidate, the candidate For the third candidate, or, candidate As the first examinee, examinee As the second candidate, the candidate Does the third candidate meet the above conditions? If so, it means the first abnormal group needs to be removed. The confidence level is low, and the first abnormal group needs to be removed. If the above conditions are not met, it means that it is not necessary to remove the first abnormal group. .
[0129] Thus, the processor 200 is able to identify the first abnormal group through the above method. ~ The confidence level, and the first outlier group with lower confidence level. ~ The abnormal groups are then eliminated, thus obtaining the second abnormal group.
[0130] Therefore, the clustered candidate groups obtained using density clustering analysis (i.e., the first abnormal group) are further evaluated using intra-cluster similarity evaluation metrics to ultimately determine the post-exam risk candidate group (i.e., the second abnormal group). This more stringent similarity measurement further filters out the second abnormal group, which exhibits a high degree of similarity in overall answer patterns.
[0131] Optionally, the operation of identifying the first anomalous group among multiple candidates using a density clustering algorithm includes: analyzing the distance distribution among candidates based on a grid search method, and pre-setting a minimum similarity threshold for determining the similarity between candidates; determining the search range of the neighborhood radius corresponding to the density clustering algorithm based on the minimum similarity threshold; traversing various parameter combinations according to the search range of the neighborhood radius, and selecting the target parameter combination that makes the clustering effect of the density clustering algorithm optimal, wherein the parameter combination includes the neighborhood radius and the minimum number of samples; and identifying the first anomalous group among multiple candidates using the density clustering algorithm and according to the target parameter combination.
[0132] Specifically, since cheating candidates typically constitute only a minority of the overall test-taker population, while the majority of legitimate candidates represent noise, the data corresponding to legitimate candidates deviates from the characteristic patterns of the cheating group. This makes traditional clustering methods susceptible to interference from noise points (i.e., legitimate candidates), resulting in unclear cluster boundaries and affecting detection accuracy. Therefore, this application selects density clustering as the clustering analysis algorithm.
[0133] When using density clustering algorithms to identify the first anomalous group, the key lies in setting two hyperparameters appropriately: the neighborhood radius (i.e., eps) and the minimum sample size (i.e., min-samples). The neighborhood radius represents the maximum interval at which candidates are considered to be of the same category. In the cheating group detection of this application, a smaller neighborhood radius is typically chosen to ensure that candidates are clustered only when they are highly similar. The minimum sample size reflects the minimum number of individuals required to identify a group as anomalous. Considering the indicative role of small clusters in anomaly detection, setting a lower minimum sample size helps identify small-scale anomalous groups without overlooking large-scale anomalous groups, and also filters out candidates who answered correctly.
[0134] Therefore, in order to select the optimal neighborhood radius and minimum sample size, the computing device uses a grid search method to analyze each examinee. ~ Based on the distance distribution between them and combined with the empirical analysis of multiple data runs, a minimum similarity threshold for the eps search space is pre-set, and the search range of the neighborhood radius corresponding to the density clustering algorithm is determined.
[0135] Then, the computing device systematically traverses each parameter combination (i.e., neighborhood radius and minimum number of samples) using a grid search method to select the target parameter combination that makes the density clustering algorithm achieve the best clustering effect, so as to achieve accurate anomaly detection.
[0136] Furthermore, given a determined combination of target parameters, the computing device uses a density clustering algorithm to cluster the candidate data, thereby identifying potential first outlier groups. The operation of identifying potential first outlier groups using the density clustering algorithm includes: the computing device processing data from multiple candidate data... ~ Starting from any candidate in the list, determine the number of first similar candidates around that candidate to check based on the set neighborhood radius.
[0137] Furthermore, if the number of similar candidates is greater than or equal to a predetermined minimum sample size, that candidate is identified as a core candidate. Starting with the core candidates, the computing device continuously searches for density-connected candidates using a density-based clustering algorithm, grouping connected candidates into a cluster until all candidates have been included. The resulting clusters represent potential cheating groups (i.e., the first anomalous group), while candidates without sufficient similar neighbors are marked as noise points and excluded from the cheating group. Thus, density-based clustering can effectively aggregate highly similar candidate groups and isolate independent candidate data that does not belong to any group.
[0138] Therefore, this application reasonably sets the neighborhood radius (i.e., eps) and minimum number of samples (i.e., min-samples) in the density clustering algorithm, which directly determines which candidate among multiple candidates is identified as a potential anomalous group (i.e., the first anomalous group). This enables the density clustering algorithm to effectively aggregate highly similar candidate groups and isolate independent candidate data that do not belong to any group.
[0139] Specifically, first, the computing device identifies multiple candidates. ~ The number of questions in the first section where any two candidates answer the same question incorrectly at the same time, and their incorrect answers are identical. Where j = 1 to n. For example, Indicates to the test taker and test takers The corresponding number of questions in the first section. Indicates to the test taker and test takers The corresponding number of questions in the first round. And so on.
[0140] Then, the computing device identifies multiple candidates. ~ The number of second questions in which any two candidates answer the same question incorrectly, but with different incorrect answers. .For example, Indicates to the test taker and test takers The corresponding number of questions in the first section. Indicates to the test taker and test takers The corresponding number of questions in the first round. And so on.
[0141] Furthermore, the computing device identifies multiple candidates. ~ The number of third questions in which any two candidates answer the same question incorrectly and the other answers correctly. .For example, Indicates to the test taker and test takers The corresponding number of questions in the first section. Indicates to the test taker and test takers The corresponding number of questions in the first round. And so on.
[0142] The computing device then calculates the similarity evaluation index for any two candidates according to the following formula:
[0143] in, In order to meet with the candidates and test takers The corresponding similarity evaluation metrics, In order to meet with the candidates and test takers Corresponding similarity evaluation metrics, etc.
[0144] Thus, by using the rand index based on the error rate to evaluate the similarity of answers between any two candidates, the aforementioned operation achieves the technical effect of providing necessary support for subsequent use of density clustering algorithms to discover potential abnormal cheating groups.
[0145] Specifically, after the computing device uses a density clustering algorithm to identify the first anomalous group among multiple candidates, the number of identical incorrect answers within each first anomalous group is further determined. The number of identical incorrect answers within each cluster indicates the number of questions in which candidates within the first anomalous group have answered the same question incorrectly and have the same answer. For example, the first anomalous group... Including test takers ~ And in the first abnormal group Junior high school students Candidates and test takers The number of questions on the same test paper where both parties answered the same question incorrectly and had the same answer is: .
[0146] Therefore, the computing device can determine the first abnormal group based on the same operation as described above. ~ Corresponding intra-cluster mismatch number ~ The specific steps will not be elaborated here.
[0147] Thus, the computing device identifies the first abnormal group. ~ Corresponding intra-cluster mismatch number ~ In this case, it can be based on each first abnormal group ~ Corresponding intra-cluster mismatch number ~ Each of the two households is in its first abnormal group ~ The consistency of incorrect answers among all test takers within the group provides insights into the first abnormal group. ~ A direct measure of internal abnormal structures.
[0148] This technology enables reliable and accurate determination of whether there are potential cheating groups among multiple candidates, thus ensuring the fairness of the examination.
[0149] In addition, refer to Figure 1 As shown, according to a second aspect of this embodiment, a storage medium is provided. The storage medium includes a stored program, wherein, when the program is executed, a processor performs any of the methods described above.
[0150] According to this embodiment, (1) before the exam, nodes with a high probability of cheating are marked, and then the coloring operation is performed on the candidate relationship graph structure. After that, the label propagation is performed to find the risk candidate group associated with the high-risk candidate node. The candidate group with the risk of cheating is locked in advance before the exam. Through the coloring operation, nodes with the characteristics of high-risk candidates can be marked significantly to facilitate the subsequent label propagation operation; the label propagation algorithm can identify potential cheating groups by propagating risk labels in the candidate relationship graph structure. (2) Through in-depth analysis of the candidates' trajectories during the exam, the system can identify similar answering patterns among candidates. Especially when multiple candidates answer at the same time, it can more accurately find organized cheating behavior. For example, if two candidates choose similar questions in the same time period and answer in a similar order, it may indicate that there is a risk of information transmission or plagiarism. (3) After the exam, the clustered candidate groups obtained by cluster analysis are further evaluated using the intra-cluster error rate index to determine the final risk candidate group. The number of identical errors within a cluster describes the absolute number of questions that candidates within a cluster answered incorrectly together. It can quantify the consistency of candidates within a group in terms of incorrect answers and provide a direct measure of abnormal structures within the group. Through this more rigorous similarity metric, the high similarity of the overall answering patterns of group members can be further confirmed.
[0151] It should be noted that, for the sake of simplicity, the foregoing method embodiments are all described as a series of actions. However, those skilled in the art should understand that the present invention is not limited to the described order of actions, because according to the present invention, some steps can be performed in other orders or simultaneously. Furthermore, those skilled in the art should also understand that the embodiments described in the specification are preferred embodiments, and the actions and modules involved are not necessarily essential to the present invention.
[0152] Through the above description of the embodiments, those skilled in the art can clearly understand that the methods according to the above embodiments can be implemented by means of software plus necessary general-purpose hardware platforms. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) and includes several instructions to cause a terminal device (which may be a mobile phone, computer, server, or network device, etc.) to execute the methods described in the various embodiments of the present invention.
[0153] This manual also provides a device corresponding to the above-described three-stage exam cheating risk control method. For details, please refer to the description of the three-stage exam cheating risk control method.
[0154] The sequence numbers of the above embodiments of the present invention are for descriptive purposes only and do not represent the superiority or inferiority of the embodiments.
[0155] In the above embodiments of the present invention, the descriptions of each embodiment have different focuses. For parts not described in detail in a certain embodiment, please refer to the relevant descriptions of other embodiments.
[0156] In the several embodiments provided in this application, it should be understood that the disclosed technical content can be implemented in other ways. The device embodiments described above are merely illustrative; for example, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the displayed or discussed mutual coupling, direct coupling, or communication connection may be through some interfaces; the indirect coupling or communication connection between units or modules may be electrical or other forms.
[0157] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0158] Furthermore, the functional units in the various embodiments of the present invention can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.
[0159] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, read-only memory (ROM), random access memory (RAM), portable hard drives, magnetic disks, or optical disks.
[0160] The above description is only a preferred embodiment of the present invention. It should be noted that for those skilled in the art, several improvements and modifications can be made without departing from the principle of the present invention, and these improvements and modifications should also be considered within the scope of protection of the present invention.
Claims
1. A three-stage method for controlling exam cheating risks, characterized in that, include: In the pre-exam stage, a candidate relationship graph structure is constructed to represent the relationships between candidates, and candidates are divided into community or non-community individuals based on the candidate relationship graph structure. Message passing is performed based on the candidate relationship graph structure to generate embedded representations corresponding to candidates. Based on the embedded representations, pre-exam risk candidate groups are determined. During the examination, an examination answer graph structure is constructed based on the candidates' answers. Nodes in this graph represent candidates, and the weights of the edges are the similarity of the representation vectors of two candidates. These representation vectors are constructed based on each candidate's answer content and order. Based on this examination answer graph structure, a spectral clustering algorithm is used to determine groups of candidates with similar answer content. Based on the overlap in the order and timing of answers within the same candidate group, candidates exhibiting follow-up answering behavior are identified, resulting in a group of candidates at risk of failing the exam. In the post-exam phase, density clustering algorithm is used to identify each first abnormal group among multiple candidates. Based on the intra-cluster similarity evaluation index corresponding to each first abnormal group and the similarity evaluation index corresponding to any two candidates in the first abnormal group, a second abnormal group is selected from each first abnormal group to obtain the post-exam risk candidate group. The similarity evaluation index is used to indicate the proportion of questions in which any two candidates answer the same question incorrectly and have the same wrong answer to the total number of questions in which any two candidates have the same wrong answer.
2. The method according to claim 1, characterized in that, The operation of identifying pre-exam risk candidate groups based on the embedded representation includes: Based on the embedded representation of the corresponding candidate, the confidence level of the corresponding candidate and the preset label is determined, and a risk score is generated for the corresponding candidate based on the confidence level, wherein the preset label is used to indicate that the candidate has a risk. Based on the risk scores of the examinees, the characteristics of high-risk examinees are determined, and the nodes corresponding to examinees with high-risk examinee characteristics are marked as high-risk examinee nodes and then colored in the Neo4j database; and Based on the candidate relationship graph structure, the high-risk label is propagated to identify the risk candidate group associated with the high-risk candidate node.
3. The method according to claim 1, characterized in that, In the candidate relationship graph structure, nodes refer to candidates, edges in the candidate relationship graph structure are weighted undirected edges created based on candidate feature similarity, and communities are used to indicate potentially organized groups of candidates who have registered abnormally. The operations for constructing a candidate relationship graph structure to represent the relationships between candidates include: Determine the candidate's attribute information, which includes at least one of the following: registration IP address, password, mailing address, work unit, and security questions; Construct the nodes corresponding to the candidates; For two candidates, determine the common attribute information that exists between the two candidates, and determine the preset weights corresponding to the common attribute information that exists between the two candidates; Based on the preset weights corresponding to the shared attribute information between the two candidates, the edge weights between them are determined; and Based on the edge weights between the two candidates, an edge is constructed between the two candidates to obtain the candidate relationship graph structure; and wherein... The operation of message passing based on the candidate relationship graph structure and generating an embedded representation corresponding to the candidate includes: Based on the degree of repetition of candidate characteristics, the relevant information of the candidates is divided into different intervals and assigned corresponding coding values; A semi-supervised graph neural network with non-random missing values is used to perform message passing on the candidate relationship graph structure. By combining node features and the topological information of the candidate relationship graph structure, an embedded representation of each node is generated as the embedded representation corresponding to the corresponding candidate.
4. The method according to claim 1, characterized in that, Based on the overlap in the order and timing of answers among candidates within the same group, the actions of candidates exhibiting follow-up behavior are identified, including: Using social network analysis, a behavioral correlation graph of candidates within the same candidate group is constructed to detect behavioral correlations among candidates. For candidate pairs with behavioral correlations greater than a preset correlation threshold, the difference in answer time between candidates whose answer similarity exceeds a preset second threshold is determined to be greater than a preset time threshold. Candidate pairs with answer similarity exceeding the preset time threshold are identified as candidates exhibiting follow-up answering behavior. The analysis examines the order in which candidates within the same group answer questions and the distribution of their answering time. Candidates exhibiting abnormal answering order or abnormal answering time distribution are identified as exhibiting follow-up answering behavior. Also includes: When the number of candidates with abnormal answer order and / or abnormal answer time distribution within the same candidate group exceeds a preset third threshold, the answers of candidates with abnormal answer order and / or abnormal answer time distribution are compared to determine the similarity of answers among candidates.
5. The method according to claim 1, characterized in that, Based on the aforementioned exam answer graph structure, the operation of using spectral clustering algorithm to determine groups of candidates with similar answer content includes: Based on the aforementioned exam answer graph structure, initialize the relation matrix; wherein, the expression of the relation matrix is: ; in, It is a trajectory feature matrix, where each row of the trajectory feature matrix represents a candidate's representation vector. This refers to the structure of the exam answer diagram; It is the regularization intensity coefficient; Calculate the trajectory feature matrix Nearest neighbor data, and according to the Nearest neighbor data, which will be used to store the data of each node. Neighboring nodes are considered positive samples, and other nodes in the exam answer graph structure are considered negative samples. A loss function considering contrastive learning regularization is constructed based on the initialized relation matrix; wherein, the expression of the loss function is: ; in, For the number of nodes, Indicates the first All nearest neighbors of each node, Indicates the first The similarity between the representation vector of a node and the representation vector of its j-th neighbor node. Indicates the first The similarity between the representation vector of a node and the representation vector of the p-th node in the exam answer graph structure; These are the weight coefficients of the contrastive learning regularization term; Based on the loss function, the gradient descent method is used to iteratively optimize the exam answer graph structure until the exam answer graph structure converges. Symmetricizing the convergent exam response graph structure yields an undirected graph structure; and Spectral clustering is performed on the undirected graph structure to obtain multiple candidate groups; among them, the similarity of the answers of candidates within the same candidate group is greater than a preset first threshold.
6. The method according to claim 1, characterized in that, The intra-cluster similarity evaluation index is used to indicate the average value of multiple similarity evaluation indices corresponding to any two candidates within the first abnormal group; The operation of selecting a second abnormal group from the first abnormal groups based on the intra-cluster similarity evaluation index corresponding to each of the first abnormal groups and the similarity evaluation index corresponding to any two candidates in the first abnormal groups includes: In each of the first abnormal groups, a first similarity evaluation index corresponding to the first candidate and the second candidate, a second similarity evaluation index corresponding to the second candidate and the third candidate, and a third similarity evaluation index corresponding to the first candidate and the third candidate are determined respectively, wherein the first candidate, the second candidate, and the third candidate represent any one of the plurality of candidates; If the first similarity evaluation index is greater than the corresponding intra-cluster similarity evaluation index, the second similarity evaluation index is greater than the corresponding intra-cluster similarity evaluation index, and the third similarity evaluation index is less than the corresponding intra-cluster similarity evaluation index, the first abnormal group is removed, and the second abnormal group is obtained by filtering.
7. The method according to claim 1, characterized in that, Before using density clustering algorithm to determine the first outlier groups among multiple candidates, the method further includes: Determine the similarity error rate between any two candidates from a pool of candidates, and construct a similarity evaluation index based on the similarity error rate, wherein... The operation of constructing a similarity evaluation index based on the error rate includes: Determine the number of first questions in which any two candidates among the plurality of candidates answer the same question incorrectly at the same time, and the incorrect answers are identical; Determine the number of second questions in which any two candidates among the plurality of candidates answer the same question incorrectly at the same time, and the incorrect answers are different; Determine the number of third questions in which any two candidates among the plurality of candidates answer the same question incorrectly and the other candidate answers correctly. Calculate the ratio of the number of the first question to the total number of the first question, the second question, and the third question, and determine the ratio as the similarity evaluation index corresponding to any two candidates.
8. A storage medium, characterized in that, The storage medium includes a stored program, wherein the method described in any one of claims 1 to 7 is generated and executed by a processor when the program is run.
9. A three-stage examination cheating risk control device, characterized in that, include: The pre-exam risk identification module is used to construct a candidate relationship graph structure to represent the relationships between candidates in the pre-exam stage, and to divide candidates into community or non-community individuals based on the candidate relationship graph structure, to perform message passing based on the candidate relationship graph structure, to generate embedded representations corresponding to candidates, and to determine the pre-exam risk candidate groups based on the embedded representations. The exam risk identification module is used to construct an exam answer graph structure based on the candidates' answers during the exam. In this graph, nodes represent candidates, and the weights of edges are the similarity of the representation vectors of two candidates. These representation vectors are constructed based on each candidate's answer content and order. Based on the exam answer graph structure, a spectral clustering algorithm is used to identify groups of candidates with similar answer content. Based on the overlap in the order and timing of answers within the same candidate group, candidates exhibiting follow-the-leader behavior are identified, resulting in a group of candidates at exam risk. The post-exam risk identification module is used to identify first abnormal groups among multiple candidates in the post-exam stage using a density clustering algorithm. Based on the intra-cluster similarity evaluation index corresponding to each first abnormal group and the similarity evaluation index corresponding to any two candidates in the first abnormal group, a second abnormal group is selected from each first abnormal group to obtain the post-exam risk candidate group. The similarity evaluation index is used to indicate the proportion of questions in which any two candidates answer the same question incorrectly and have the same wrong answer to the total number of questions in which any two candidates have the same wrong answer.
10. A three-stage examination cheating risk control device, characterized in that, include: processor; as well as A memory, connected to the processor, for providing the processor with instructions to perform the following processing steps: In the pre-exam stage, a candidate relationship graph structure is constructed to represent the relationships between candidates, and candidates are divided into community or non-community individuals based on the candidate relationship graph structure. Message passing is performed based on the candidate relationship graph structure to generate embedded representations corresponding to candidates. Based on the embedded representations, pre-exam risk candidate groups are determined. During the examination, an examination answer graph structure is constructed based on the candidates' answers. Nodes in this graph represent candidates, and the weights of the edges are the similarity of the representation vectors of two candidates. These representation vectors are constructed based on each candidate's answer content and order. Based on this examination answer graph structure, a spectral clustering algorithm is used to determine groups of candidates with similar answer content. Based on the overlap in the order and timing of answers within the same candidate group, candidates exhibiting follow-up answering behavior are identified, resulting in a group of candidates at risk of failing the exam. In the post-exam phase, density clustering algorithm is used to identify each first abnormal group among multiple candidates. Based on the intra-cluster similarity evaluation index corresponding to each first abnormal group and the similarity evaluation index corresponding to any two candidates in the first abnormal group, a second abnormal group is selected from each first abnormal group to obtain the post-exam risk candidate group. The similarity evaluation index is used to indicate the proportion of questions in which any two candidates answer the same question incorrectly and have the same wrong answer to the total number of questions in which any two candidates have the same wrong answer.