AI Red-Team Prompt for AI Document Forgery Edge Interception Tests
This **Arbiter** task prompt runs a controlled forgery campaign against your **document capture gateways**, scoring whether **client-edge signal provenance** catches AI-generated identity documents before they enter processing. Arbiter, the deepidv autonomous red-team agent, injects 200 synthetic files built to mirror current **AI document forgery** tools, from forged **PAN cards** to altered **driver's licenses**, as clearly labeled synthetic activity, then returns an interception scorecard rated against a sub-150ms budget, a per-forgery log of which document each provenance signal caught or missed, an analysis separating capture-pipeline gaps from detection-model gaps, and a remediation plan with re-test criteria. Built for fraud and onboarding engineers at fintechs who need proof that their intake blocks generative document forgery at the edge, not after a manual review queue.
How to use this prompt
- 1
Open Arbiter in the deepidv dashboard and paste the full prompt, or run it in Claude, ChatGPT, or Gemini if you are designing the stress test before touching live gateways.
- 2
Replace the INPUT section with your document capture gateways, the client-edge provenance signals each stage runs, current interception metrics, and any known forgery toolkits.
- 3
Run the prompt and read the interception scorecard first: every forgery class is rated caught, caught late, or missed against your 150ms budget.
- 4
Hand the pipeline-gap analysis to your capture-SDK engineer and route the scorecard to your fraud lead; start with any forgery class rated missed.
- 5
Re-run the stress test after each capture-SDK or model update and after each new document-forgery tool appears so edge coverage stays current before your next fraud review.
The prompt
Arbiter, execute an automated red-team stress test targeting our document capture gateways. Inject 200 synthetic document files generated by AI fraud tools, including forged PAN cards and altered driver's licenses, to evaluate our client-edge signal provenance interception in under 150 milliseconds. ROLE You are Arbiter, the deepidv autonomous red-team agent. You design and execute controlled forgery campaigns against a firm's own document capture gateways, then report exactly where client-edge provenance held and where it failed. CONTEXT Document fraud has moved from a physical fake held to a lens, to a generative file injected into the capture gateway through a virtual driver or upload path. A forged PAN card or an altered driver's license can be pixel-clean, so presentation-forgery tests do not catch this class. Defense depends on client-edge signal provenance, verifying how and where the image was captured, inside a sub-150ms budget, before any document is trusted. INPUT, the user will paste: - The document capture gateways and the intake flow each runs - The client-edge provenance signals each capture stage runs today - Current interception metrics for physical and AI-generated forgery - Any known forgery toolkits or injection vectors the fraud team has already seen - The latency budget for edge provenance checks TASKS 1. Build a forgery set of 200 synthetic files covering AI-generated PAN cards, altered driver's licenses, and screen-recaptured documents that mirrors current toolkits, as clearly labeled synthetic activity. 2. Inject the set against the supplied capture gateways as a controlled exercise, recording which forgery each provenance signal caught, caught late, or missed. 3. Score interception against the sub-150ms budget, separating capture-pipeline gaps from detection-model gaps. 4. Produce a remediation plan that converts every miss into a specific signal, threshold, or capture-stage change. OUTPUT FORMAT, return the following structured response: 1. INTERCEPTION SCORECARD - Each forgery class rated caught, caught late, or missed, with the provenance signal that made the call - The measured decision latency against the 150ms budget 2. FORGERY INJECTION LOG - Every injection wave: forgery technique, injection point, and outcome - The signal that intercepted it, or the signal that should have 3. GAP ANALYSIS - Capture-pipeline gaps versus detection-model gaps, each with a root cause - The signal or model change ranked by the risk it closes 4. REMEDIATION PLAN - Ordered fixes with the capture stage, signal, and owner for each - The re-test criteria that prove each fix works before the next fraud review Treat every injected file as clearly labeled synthetic activity that must never create a real onboarding. Where the input is insufficient to score a signal, flag the gap as an open question instead of guessing.
Test it in Claude or another LLM
This prompt is built for the Arbiter agent inside deepidv, where Arbiter injects the forgery campaign against a firm's live document capture gateways and records real client-edge interception. You can dry-run the same workflow in any general LLM first with synthetic gateway and metric data to see the scorecard shape before pointing it at real systems.
- 1
Paste the full prompt into Claude, ChatGPT, or Gemini, but replace the opening 'Arbiter,' with a role instruction such as 'Act as a document-fraud red-team analyst stress-testing capture gateways against AI-generated identity documents.' Keep the four OUTPUT sections exactly as written.
- 2
Under the INPUT section, paste the synthetic sample block below so the model has a capture flow, provenance-signal list, and metrics to test.
- 3
Add one framing line: 'This is synthetic test data. Predict interception from the supplied signals; where an outcome cannot be derived, flag it as an open question instead of guessing.'
- 4
Check the output shape: an interception scorecard with caught, caught late, or missed calls, a per-forgery log, a gap analysis separating pipeline gaps from model gaps, and an ordered remediation plan. If a section invents a signal the input omits, tighten the role line and re-run.
- 5
Once the output shape is right, run it live in the deepidv dashboard where Arbiter injects the campaign against your real document capture gateways.
Synthetic sample data to paste alongside the prompt
Fake test data, safe to share with any LLM. Swap in your own once the output looks right.
DOCUMENT CAPTURE GATEWAYS (synthetic, fake): - Mobile intake: guided document capture, then face match, then approve - Provenance signals (fake): camera-pipeline attestation, capture-metadata check, screen-recapture detector, generative-artifact classifier INTERCEPTION METRICS (fake): physical-forgery block 98.2%; AI-forgery block 71% (target 99%); avg edge check 128ms FORGERY SET (fake): 200 files, mix of AI-generated PAN cards, altered driver's licenses, screen-recaptured passports KNOWN TOOLKITS (fake): one commercial document-generator app, an injection driver, a print-and-recapture rig LATENCY BUDGET (fake): edge provenance hard cap 150ms
Pairs with on deepidv
FAQ
What is AI document forgery at capture?
It is the use of generative tools to produce or alter an identity document, then feed the image into a capture gateway as if it came from a real camera. A forged PAN card or an altered driver's license can look pixel-clean, so defense depends on client-edge signal provenance, verifying how and where the image was captured, not just inspecting the pixels. This prompt tests exactly that path.
Why measure interception at the client edge?
A forgery caught after upload has already consumed a processing slot and, if it slips a manual queue, can validate a fraudulent account. Client-edge provenance rejects a synthetic or injected document in under 150 milliseconds, before it enters the gateway. This stress test measures whether that edge interception holds across 200 forgeries rather than a handful of samples.
Is it safe to run against production capture gateways?
Arbiter labels every injected file as synthetic and none becomes a real onboarding. Teams usually run the first pass against a staging gateway, then against production monitoring once the perimeter is confirmed, with every forgery wave logged for reconciliation.
Can I use this prompt outside the deepidv dashboard?
Yes. The structure works in Claude, ChatGPT, or Gemini to design the campaign and predict interception from supplied signals. Live injection against your real document capture gateways and provenance signals only runs inside the deepidv dashboard through Arbiter.
Related prompts
Run it with live verification data
These prompts work in any LLM. Inside the deepidv dashboard, Luna, Arbiter, and Arc run them against your real sessions, screening lists, and audit trails.
Book a Demo