IP Library Granted Patent US 12,737,486
Granted Patent B2
US 12,737,486 · App. 18/930,923 · Granted Sep 15, 2026

Automated fraudulent document detection

Inventors: Anton Mobley (Lehi, UT); Jixin Li (Lehi, UT); Nickolaus Mueller (Lehi, UT)
Assignee: Lendingclub Bank, National Association
G06F21/6209G06F16/93G06Q30/0185
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,737,486
App. No.
18/930,923
Granted
Sep 15, 2026
Kind
B2
Abstract

Techniques are disclosed for determining the authenticity of a digital-origin document based, at least in part, on the code of the document. By determining authenticity based on the code of the document, authentication may take into account several features that are not detectable on the rendered image of a digital-origin document. The document class of a target document is initially determined. Anomalies are then detected in the code using various detectors, including but not limited to metadata-based detectors and content-based detectors. The output of the detectors may be combined to generate a document anomaly score that indicates likelihood that the document is not authentic.

Claims (82)

1 . A method comprising:

receiving, at a document authentication system, a captured-image that includes a region that depicts a target document;

wherein the document authentication system includes a set of one or more detectors;

wherein the set of one or more detectors includes a common-surrounding-content detector;

identifying, by the document authentication system, target surrounding-content corresponding to the captured-image, wherein the target surrounding-content is content that corresponds to the captured-image;

using the common-surrounding-content detector, the document authentication system performing a comparison of the target surrounding-content to previously stored surrounding-content data; and

based at least in part on the comparison, the document authentication system generating a document anomaly score for the target document that indicates a likelihood that the target document is authentic;

wherein the method is performed by one or more computing devices.

2 . The method of claim 1 wherein generating the document anomaly score includes:

the common-surrounding-content detector generating a feature-specific anomaly score that reflects a degree of deviation between the target surrounding-content in the captured-image and the surrounding-content extracted from a population of captured-images of documents; and

generating the document anomaly score based at least in part on the feature-specific anomaly score.

3 . The method of claim 2 wherein the feature-specific anomaly score increases with an increase in a number of captured-images that have surrounding-content that matches the target surrounding-content.

4 . The method of claim 2 wherein the feature-specific anomaly score increases with an increase in how closely the target surrounding-content matches surrounding-content in the population of captured-images.

5 . The method of claim 2 further comprising:

based on the document anomaly score, the document authentication system performing at least one of:

indicating that the target document is authentic responsive to the document anomaly score falling below a first threshold, or

indicating that the target document is not authentic responsive to the document anomaly score exceeding a second threshold.

6 . The method of claim 2 wherein:

the feature-specific anomaly score is a first feature-specific anomaly score upon which the document anomaly score is based;

the set of one or more detectors includes a stripped-metadata detector; and

generating the document anomaly score is based, at least in part, on a second feature-specific anomaly score generated by the stripped-metadata detector.

7 . The method of claim 2 wherein:

the feature-specific anomaly score is a first feature-specific anomaly score upon which the document anomaly score is based;

the set of one or more detectors includes a suspicious-software detector; and

generating the document anomaly score is based, at least in part, on a second feature-specific anomaly score generated by the suspicious-software detector.

8 . The method of claim 2 wherein:

the feature-specific anomaly score is a first feature-specific anomaly score upon which the document anomaly score is based;

the set of one or more detectors includes a date-mismatch detector; and

generating the document anomaly score is based, at least in part, on a second feature-specific anomaly score generated by the date-mismatch detector.

9 . The method of claim 2 wherein:

the feature-specific anomaly score is a first feature-specific anomaly score upon which the document anomaly score is based;

the set of one or more detectors includes a suspicious-metadata-type detector; and

generating the document anomaly score is based, at least in part, on a second feature-specific anomaly score generated by the suspicious-metadata-type detector.

10 . The method of claim 2 wherein:

the feature-specific anomaly score is a first feature-specific anomaly score upon which the document anomaly score is based;

the set of one or more detectors includes a metadata-anomaly detector; and

generating the document anomaly score is based, at least in part, on a second feature-specific anomaly score generated by the metadata-anomaly detector.

11 . The method of claim 2 wherein:

the feature-specific anomaly score is a first feature-specific anomaly score upon which the document anomaly score is based;

the set of one or more detectors includes an editing-tags detector; and

generating the document anomaly score is based, at least in part, on a second feature-specific anomaly score generated by the editing-tags detector.

12 . The method of claim 2 wherein:

the feature-specific anomaly score is a first feature-specific anomaly score upon which the document anomaly score is based;

the set of one or more detectors includes a mask-overlap detector; and

generating the document anomaly score is based, at least in part, on a second feature-specific anomaly score generated by the mask-overlap detector.

13 . The method of claim 2 wherein:

the feature-specific anomaly score is a first feature-specific anomaly score upon which the document anomaly score is based;

the set of one or more detectors includes a fonts-embedded-types detector; and

generating the document anomaly score is based, at least in part, on a second feature-specific anomaly score generated by the fonts-embedded-types detector.

14 . The method of claim 2 wherein:

the feature-specific anomaly score is a first feature-specific anomaly score upon which the document anomaly score is based;

the set of one or more detectors includes a multiple-fonts-types-within-element detector; and

generating the document anomaly score is based, at least in part, on a second feature-specific anomaly score generated by the multiple-fonts-types-within-element detector.

15 . The method of claim 2 wherein:

the feature-specific anomaly score is a first feature-specific anomaly score upon which the document anomaly score is based;

the set of one or more detectors includes an annotation-masks detector; and

generating the document anomaly score is based, at least in part, on a second feature-specific anomaly score generated by the annotation-masks detector.

16 . The method of claim 2 wherein:

the feature-specific anomaly score is a first feature-specific anomaly score upon which the document anomaly score is based;

the set of one or more detectors includes a previous-version-hidden detector; and

generating the document anomaly score is based, at least in part, on a second feature-specific anomaly score generated by the previous-version-hidden detector.

17 . The method of claim 2 wherein:

the feature-specific anomaly score is a first feature-specific anomaly score upon which the document anomaly score is based;

the set of one or more detectors includes an in-class-code-anomaly detector; and

generating the document anomaly score is based, at least in part, on a second feature-specific anomaly score generated by the in-class-code-anomaly detector.

18 . One or more non-transitory computer-readable media comprising instructions that, when executed by one or more hardware processors, cause performance of operations comprising:

receiving, at a document authentication system, a captured-image that includes a region that depicts a target document;

wherein the document authentication system includes a set of one or more detectors;

wherein the set of one or more detectors includes a common-surrounding-content detector;

identifying, by the document authentication system, target surrounding-content corresponding to the captured-image, wherein the target surrounding-content is content that corresponds to the captured-image;

using the common-surrounding-content detector, the document authentication system performing a comparison of the target surrounding-content to previously stored surrounding-content data; and

based at least in part on the comparison, the document authentication system generating a document anomaly score for the target document that indicates a likelihood that the target document is authentic.

19 . A system comprising:

one or more hardware processors;

one or more non-transitory computer-readable media; and

program instructions stored on the one or more non-transitory computer-readable media which, when executed by the one or more hardware processors, cause the system to perform operations comprising:

receiving, at a document authentication system, a captured-image that includes a region that depicts a target document;

wherein the document authentication system includes a set of one or more detectors;

wherein the set of one or more detectors includes a common-surrounding-content detector;

identifying, by the document authentication system, target surrounding-content corresponding to the captured-image, wherein the target surrounding-content is content that corresponds to the captured-image;

using the common-surrounding-content detector, the document authentication system performing a comparison of the target surrounding-content to previously stored surrounding-content data; and

based at least in part on the comparison, the document authentication system generating a document anomaly score for the target document that indicates a likelihood that the target document is authentic.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 7, 2024
From: MOBLEY, ANTON; LI, JIXIN; MUELLER, NICKOLAUS
To: LENDINGCLUB BANK, NATIONAL ASSOCIATION
Reel/Frame 069189/0440 →
Continuity (3)
Continuation 18143042 · May 3, 2023
Continuation 17680260 · Feb 24, 2022
Related Publication 20250053673A1 · Feb 13, 2025
References Cited (71)
US 6718535B1 · Underwood · 2004 [cited by examiner]
US 6850252B1 · Hoffberg · 2005 [cited by examiner]
US 7054461B2 · Zeller · 2006 [cited by examiner]
US 7630520B2 · Visan · 2009 [cited by examiner]
US 7813822B1 · Hoffberg · 2010 [cited by examiner]
US 7920714B2 · O'Neil · 2011 [cited by examiner]
US 7974714B2 · Hoffberg · 2011 [cited by examiner]
US 8359271B2 · Peckover · 2013 [cited by examiner]
US 8428332B1 · Csulits · 2013 [cited by examiner]
US 8430301B2 · Tian · 2013 [cited by examiner]
US 8433123B1 · Csulits · 2013 [cited by examiner]
US 8437530B1 · Mennie · 2013 [cited by examiner]
US 8600830B2 · Hoffberg · 2013 [cited by examiner]
US 8799770B2 · Morris · 2014 [cited by examiner]
US 8874477B2 · Hoffberg · 2014 [cited by examiner]
US 9225519B1 · Fraccaroli · 2015 [cited by examiner]
US 9311670B2 · Hoffberg · 2016 [cited by examiner]
US 9444645B2 · Blot-Lefevre · 2016 [cited by examiner]
US 9483629B2 · Krawczyk · 2016 [cited by examiner]
US 9818136B1 · Hoffberg · 2017 [cited by examiner]
US 10262272B2 · Chickering · 2019 [cited by examiner]
US 10636040B2 · Peckover · 2020 [cited by examiner]
US 10693872B1 · Larson · 2020 [cited by examiner]
US 11354435B2 · Brannon · 2022 [cited by examiner]
US 11380115B2 · Wu · 2022 [cited by examiner]
US 11405189B1 · Bennison · 2022 [cited by examiner]
US 20040158724A1 · Carr · 2004 [cited by examiner]
US 20060202468A1 · Phillips · 2006 [cited by examiner]
US 20070053513A1 · Hoffberg · 2007 [cited by examiner]
US 20070087756A1 · Hoffberg · 2007 [cited by examiner]
US 20080025555A1 · Visan · 2008 [cited by examiner]
US 20080025556A1 · Visan · 2008 [cited by examiner]
US 20080030798A1 · O'Neil · 2008 [cited by examiner]
US 20080267448A1 · Phillips · 2008 [cited by examiner]
US 20090152357A1 · Lei · 2009 [cited by examiner]
US 20100037059A1 · Sun · 2010 [cited by examiner]
US 20100235285A1 · Hoffberg · 2010 [cited by examiner]
US 20110038012A1 · Massicot · 2011 [cited by examiner]
US 20110121066A1 · Tian · 2011 [cited by examiner]
US 20120072859A1 · Wang · 2012 [cited by examiner]
US 20120327450A1 · Sagan · 2012 [cited by examiner]
US 20140046954A1 · MacLean · 2014 [cited by examiner]
US 20140119615A1 · Mercolino · 2014 [cited by examiner]
US 20140259157A1 · Toma · 2014 [cited by examiner]
US 20160110826A1 · Morimoto · 2016 [cited by examiner]
US 20170214701A1 · Hasan · 2017 [cited by examiner]
US 20170250855A1 · Patil · 2017 [cited by examiner]
US 20170264640A1 · Narayanaswamy · 2017 [cited by examiner]
US 20180033020A1 · Viens · 2018 [cited by examiner]
US 20180075138A1 · Perram · 2018 [cited by examiner]
US 20180268015A1 · Sugaberry · 2018 [cited by examiner]
US 20180349693A1 · Watanabe · 2018 [cited by examiner]
US 20200301979A1 · Alexiades · 2020 [cited by examiner]
US 20200366671A1 · Larson · 2020 [cited by examiner]
US 20210110037A1 · Hunt · 2021 [cited by examiner]
US 20210124919A1 · Balakrishnan · 2021 [cited by examiner]
US 20210133498A1 · Zhang · 2021 [cited by examiner]
US 20210279212A1 · Kazmi · 2021 [cited by examiner]
US 20210295103A1 · Tanniru · 2021 [cited by examiner]
US 20220358583A1 · Sliwka · 2022 [cited by examiner]
EP 1662699A1 · 2006 [cited by examiner]
JP 2006157914A · 2006 [cited by examiner]
JP 2007318732A · 2007 [cited by examiner]
WO WO2008014590A1 · 2008 [cited by examiner]
Muda et al. “Computational Intelligence in Digital Forensics: Forensic Investigation and Applications.” (2014). Retrieved online Jul. 18, 2022. https://link.springer.com/content/pdf/10.1007%2F978-3-319-05885-6.pdf (Year… [cited by examiner]
How Its Done. “A Simplified Guide To Forensic Document Examination.” (Aug. 11, 2012). Retrieved online Jul. 18, 2022. https://www.forensicsciencesimplified.org/docs/how.html (Year: 2012). [cited by examiner]
Talib M. Jawad Abbas. “Studying the Documentation Process in Digital Forensic Investigation Frameworks/ Models.” (2015). Retrieved online Jul. 18, 2022. https://www.iasj.net/iasj/download/6e2dd4cac5720eb3 (Year: 2015). [cited by examiner]
Clifford Lynch. “Authenticity and Integrity in the Digital Environment: An Exploratory Analysis of the Central Role of Trust.” (2009) Retrieved online Jul. 18, 2022. https://www.clir.org/pubs/reports/pub92/lynch/ (Year:… [cited by examiner]
Exploringtheinvisible.org. “Behind the Data: Investigating metadata.” (Nov. 30, 2017). Retrieved online Jul. 18, 2022. https://exposingtheinvisible.org/en/guides/behind-the-data-metadata-investigations/ (Year: 2017). [cited by examiner]
Kindson Munonye et al. “Machine learning approach to vulnerability detection in OAuth 2.0 authentication and authorization flow.” (May 13, 2021). Retrieved online Dec. 20, 2022. https://link.springer.com/article/10.1007… [cited by examiner]
K. A. Apoorva et al. “Deep neural network and model-based clustering technique for forensic electronic mail author attribution.” (Feb. 18, 2021). Retrieved online Dec. 20, 2022. https://link.springer.com/article/10.1007… [cited by examiner]