Rule generation method and device and electronic equipment
By obtaining transaction data and determining the validity information of illegal operation rules, iterative processing is used to generate rules for the next cycle. This solves the problem of low rule accuracy and optimization efficiency caused by reliance on business personnel's experience, and achieves accurate optimization and efficient generation of rules.
Patent Information
- Application Number
- CN202510692803.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-27
- Publication Date
- 2025-09-05
AI Technical Summary
In the existing technology, the setting of financial transaction rules relies on the experience of business personnel, resulting in low rule operation accuracy and optimization efficiency, which affects normal financial transactions.
By obtaining transaction data, the validity information of the illegal operation rules in use is determined, and based on this information, iterative processing is performed to generate the illegal operation rules for the next cycle, thereby achieving accurate optimization of the rules.
The efficiency of rule generation and operation accuracy have been improved. Rules can be continuously adjusted and improved based on real-time feedback, which significantly improves the efficiency and accuracy of rule optimization.
Smart Images

Figure CN120598657A_ABST
Abstract
Description
Technical Field
[0001] The embodiments of the present disclosure relate to the field of data processing technology, and in particular to a rule generation method, device, and electronic device. Background Art
[0002] With the rise and rapid development of internet finance, non-compliant operations are becoming increasingly common. To identify accounts with non-compliant operations, it is necessary to analyze and process massive daily financial transactions. If an account meets the rules set by business personnel, the account will be subject to risk management.
[0003] Currently, rules are set by business personnel themselves. Once set, they are immediately operational and revised based on the complaint rates of non-compliant accounts and customers identified by public security and industry peers. The current rule-setting method relies heavily on the experience of business personnel, requiring extensive iteration and refinement. This results in low accuracy and optimization efficiency, impacting normal financial transactions. Summary of the Invention
[0004] The embodiments of the present disclosure provide a rule generation method, device, and electronic device to determine the illegal operation rules to be combined based on the illegal operation rules in use, and to iteratively process the illegal operation rules to be combined, thereby improving the efficiency of rule generation. The iterative processing mechanism enables the rules to be continuously adjusted and improved according to real-time feedback, thereby achieving accurate optimization of the rules and significantly improving the rule optimization efficiency and the rule operation accuracy.
[0005] In a first aspect, an embodiment of the present disclosure provides a rule generation method, the method comprising:
[0006] Get the transaction data of at least one trading account in the current period;
[0007] For at least one in-use illegal operation rule associated with the current cycle, determining validity information of the in-use illegal operation rule based on the transaction data and the in-use illegal operation rule;
[0008] Based on the validity information, determining the illegal operation rule to be combined; wherein the illegal operation rule to be combined is a rule in the at least one illegal operation rule in use;
[0009] The illegal operation rules to be combined are iteratively processed to obtain the illegal operation rules in use corresponding to the next cycle.
[0010] In a second aspect, an embodiment of the present invention further provides a rule generation device, the device comprising:
[0011] A transaction data acquisition module is used to obtain transaction data of at least one transaction account in the current period;
[0012] a validity information determination module, configured to determine, for at least one in-use illegal operation rule associated with the current period, validity information of the in-use illegal operation rule based on the transaction data and the in-use illegal operation rule;
[0013] a module for determining a rule of illegal operation to be combined, configured to determine a rule of illegal operation to be combined based on the validity information; wherein the rule of illegal operation to be combined is a rule in the at least one illegal operation rule in use;
[0014] The iterative processing module is used to obtain the in-use illegal operation rules corresponding to the next cycle by iteratively processing the illegal operation rules to be combined.
[0015] In a third aspect, an embodiment of the present invention further provides an electronic device, comprising:
[0016] one or more processors;
[0017] a storage device for storing one or more programs,
[0018] When the one or more programs are executed by the one or more processors, the one or more processors implement the rule generation method as described in any one of the embodiments of the present invention.
[0019] In a fourth aspect, an embodiment of the present invention further provides a storage medium comprising computer-executable instructions, wherein the computer-executable instructions, when executed by a computer processor, are used to execute the rule generation method as described in any one of the embodiments of the present invention.
[0020] In a fifth aspect, an embodiment of the present invention further provides a computer program product, including a computer program, which, when executed by a processor, implements the rule generation method as described in any one of the embodiments of the present invention.
[0021] The technical solution of the embodiment of the present disclosure obtains the transaction data of at least one transaction account in the current cycle. Then, for at least one in-use violation operation rule associated with the current cycle, the validity information of the in-use violation operation rule is determined based on the transaction data and the in-use violation operation rule. Further, based on the validity information, the violation operation rule to be combined is determined. Finally, by iteratively processing the violation operation rule to be combined, the in-use violation operation rule corresponding to the next cycle is obtained. This solves the problem that the current reliance on business personnel to set rules to determine violation operations, the low rule operation accuracy and rule optimization efficiency, and the impact on normal financial transactions. The embodiment of the present disclosure realizes the determination of the violation operation rule to be combined based on the in-use violation operation rule, and iteratively processes the violation operation rule to be combined, thereby improving the rule generation efficiency. The iterative processing mechanism enables the rules to be continuously adjusted and improved according to real-time feedback, so as to achieve accurate optimization of the rules, significantly improving the rule optimization efficiency and the rule operation accuracy. BRIEF DESCRIPTION OF THE DRAWINGS
[0022] To more clearly illustrate the technical solutions of the exemplary embodiments of the present invention, the following briefly introduces the drawings required for describing the embodiments. Obviously, the drawings introduced here only illustrate some of the embodiments to be described by the present invention, and are not exhaustive. A person skilled in the art can derive other drawings based on these drawings without inventive effort.
[0023] Figure 1 is a flowchart of the rule generation method provided by an embodiment of the present disclosure;
[0024] Figure 2 is a schematic diagram of the rule generation process provided by an embodiment of the present disclosure;
[0025] Figure 3 is a schematic diagram of rule verification provided by an embodiment of the present disclosure;
[0026] Figure 4 is a structural diagram of a rule generation device provided by an embodiment of the present disclosure;
[0027] Figure 5 It is a structural diagram of an electronic device provided by an embodiment of the present disclosure. DETAILED DESCRIPTION
[0028] The present invention will be further described in detail below with reference to the accompanying drawings and examples. It will be understood that the specific embodiments described herein are intended only to illustrate the present invention and are not intended to limit the present invention. It should also be noted that, for ease of description, the accompanying drawings only illustrate portions relevant to the present invention, not all structures.
[0029] Before introducing the technical solutions provided by the embodiments of the present disclosure, an exemplary application scenario can be first described. The technical solutions provided by the embodiments of the present disclosure can be applied in scenarios where new rules for in-use violations are generated. For example, in the business scenarios of financial institutions, in-use violation rules associated with the current cycle can be used to iteratively process the violation rules to generate new in-use violation rules.
[0030] It should be noted that when the current cycle is the first regulatory cycle, the violation rules in use are single rules. Each single rule is based on a specific indicator. An indicator refers to an index, specification, or standard generated based on a customer's financial transaction activities using business line characteristics and statistical methods. Indicators are generally represented by data, such as the number of off-site account logins during the regulatory cycle, the total number of account logins during the regulatory cycle, the total value of account transfers during the regulatory cycle, or the total value of account resource financing during the regulatory cycle. Based on the business line, a single rule refers to the conditions and restrictions set under each indicator for a customer's financial transaction activities. If the conditions and restrictions are met for a specific indicator, the account is considered to have a certain level of non-compliance risk under that single rule. For example, Rule A may define the number of off-site account logins exceeding 100 during the regulatory cycle; Rule B may define the number of total account logins exceeding 200 during the regulatory cycle; and Rule C may define the total value of account transfers exceeding a value M during the regulatory cycle. For Rule A, if the number of off-site account logins exceeds 100 during the regulatory cycle, the account is considered to have a certain level of non-compliance risk under that single rule.
[0031] It should also be noted that when the platform detects that an account has a non-compliance risk, it will take certain measures or actions. The behavior of taking certain measures or actions to control an account is called a control method. There are many control methods, for example, face recognition, SMS verification, fingerprint verification, blocking financial transactions or releasing financial transactions, etc. Based on the technical solution of the embodiment of the present disclosure, it is realized that the illegal operation rules to be combined are determined based on the illegal operation rules in use, and the illegal operation rules to be combined are iteratively processed to improve the efficiency of rule generation. The iterative processing mechanism enables the rules to be continuously adjusted and improved according to real-time feedback, so as to achieve accurate optimization of the rules, which significantly improves the rule optimization efficiency and the rule operation accuracy.
[0032] Example 1
[0033] Figure 1This is a flow chart of the rule generation method provided by the embodiment of the present disclosure. The embodiment of the present disclosure is applicable to situations where new rules for illegal operations in use are generated. The method can be executed by a rule generation device, which can be implemented in the form of software and / or hardware. The hardware can be a mobile electronic device, which can execute the rule generation method provided by this technical solution.
[0034] like Figure 1 As shown, the method includes:
[0035] S110: Acquire transaction data of at least one transaction account in the current period.
[0036] A "cycle" is a specified timeframe. Different business scenarios and requirements may correspond to different cycles. For example, a cycle could be one month or one quarter. The "current cycle" is an ongoing timeframe. The current cycle includes the first regulatory cycle and any subsequent regulatory cycles, i.e., non-first regulatory cycles. A "trading account" refers to an account opened at a financial institution for transactions and other activities. For example, a trading account can be a financial institution account, a securities account, or an electronic account. Transaction data can include data under various indicators, such as the number of remote account logins, the total number of account logins, the total value of account transfers, or the total value of account resource financing.
[0037] It should also be noted that after obtaining transaction data for at least one trading account within the current period, the transaction data can be statistically analyzed and extracted. From this transaction data, indicators such as the number of remote account logins within the regulatory period, the total number of account logins within the regulatory period, the total value of account transfers within the regulatory period, or the total value of resource financing within the regulatory period can be calculated.
[0038] Specifically, the trading data of a trading account is obtained during the current cycle. Then, by filtering, comparing, and calculating various logs and recorded data in the trading system, multiple indicators of the account during the current cycle can be statistically analyzed and extracted. Obtaining these indicators is crucial for account security monitoring, trading behavior analysis, and risk management.
[0039] S120: For at least one in-use illegal operation rule associated with the current cycle, determine validity information of the in-use illegal operation rule based on the transaction data and the in-use illegal operation rule.
[0040] Active rule violations are rules currently in use during the current cycle and are used to identify and detect accounts that violate transactions. During the current cycle, these active rule violations continuously monitor transaction data to identify potential violations.
[0041] Optionally, the in-use violation operation rules are used to detect anomalies in transaction data.
[0042] It should be noted that effectiveness information is a quantitative assessment of the performance and accuracy of an active rule within the current cycle. This effectiveness information is quantified by analyzing the application results of at least one active rule in actual transaction data. By quantitatively assessing the effectiveness information of active rules, the accuracy and reliability of at least one active rule can be ensured within the current cycle, providing data support for future rule optimization.
[0043] Optionally, the current cycle is the first supervision cycle, and the illegal operation rules in use are single rules. Determine the number of illegal accounts corresponding to the illegal operation rules in use, the total number of warnings triggered, and the number of controls for each control method after the warning; for each control method, determine the control information based on the control number and corresponding weight of the control method; determine the validity information of the illegal operation rules in use by calculating the control information, the number of illegal accounts, the total number of warnings, and the number of confirmed illegal accounts received in the current cycle.
[0044] In financial regulation, the first regulatory cycle refers to the first regulatory cycle following the implementation of a single rule. During this first regulatory cycle, historical trading data for trading accounts can be collected to assess the implementation of the single rule. A single rule refers to a regulatory rule that relies solely on a single core indicator. For example, when using a single rule to monitor non-compliant accounts, a single threshold can be used to identify non-compliant accounts. For example, if an account has more than 200 total logins during the regulatory cycle, it can be considered a non-compliant account.
[0045] It should be noted that during the first regulatory cycle, the number of non-compliant accounts refers to the number of non-compliant accounts determined by a single rule based on transaction data. For each single rule, there is a corresponding number of non-compliant accounts. The total number of warnings refers to the total number of warning signals issued during the regulatory cycle due to account violations detected according to a single rule. For example, if the single rule is that the total number of account logins exceeds 200 during the regulatory cycle, then during the first regulatory cycle, a total of 100 cases of accounts with total logins exceeding 200 during the regulatory cycle were detected, resulting in a total of 100 warnings triggered. It should also be noted that if account A has a total login count exceeding 200 during the first regulatory cycle, then account A contributes 3 times to the total number of warnings. This indicates that an account may trigger warnings multiple times, and the total number of warnings triggered should not be less than the number of non-compliant accounts.
[0046] Each control method after an early warning refers to the specific management or control measures implemented after the early warning. These control methods can include account restrictions, information verification, and administrative penalties. The number of controls implemented for each control method after an early warning refers to the number of times each control method was actually implemented during the first regulatory cycle. For a given account, multiple control methods may be used to control the account after an early warning is triggered. The corresponding weight refers to the relative importance coefficient assigned to different control methods in the regulatory rules, which quantifies the priority or impact of each control method in the overall regulatory framework. Typically, the sum of the weights of all control methods is 1, and the weights of each control method can be adjusted dynamically based on regulatory objectives or changes in risk. Control information refers to a quantitative indicator of the regulatory effectiveness of a control method, calculated by multiplying the number of controls implemented for a control method by its corresponding weight. The number of confirmed non-compliant accounts received during the current cycle refers to the number of accounts confirmed by regulatory authorities or relevant agencies through monitoring, review, and investigation during the current cycle (i.e., the first regulatory cycle). These accounts are considered to have actually violated regulations or rules during the regulatory cycle and have been formally recorded and confirmed.
[0047] For example, the formula for determining the validity information of the in-use illegal operation rules based on the control information, the number of illegal accounts, the total number of warnings, and the number of confirmed illegal accounts received in the current cycle can be:
[0048] C=e / E*(N1*a1+N2*a2+…+N n *a n ) / N;
[0049] Among them, C is the validity information of a certain illegal operation rule in use in the first supervision cycle; N1*a1 to N n *a n For control information; N1 to N n is the number of control times for each control method; a1 to a n is the weight of each control method; e is the number of violating accounts corresponding to a particular active violation rule; E is the number of confirmed violating accounts received during the current cycle; and N is the total number of warnings. It should be noted that for each individual rule, the validity information of the active violation rule can be determined based on the number of control methods, the corresponding weight of the control method, the number of violating accounts, the total number of warnings, and the number of confirmed violating accounts received during the current cycle.
[0050] In this embodiment, the current cycle is not the first regulatory cycle, and the in-use violation operation rule is a rule obtained by combining at least one single rule. The rule accuracy and rule misjudgment rate are determined based on the confirmed violation accounts received in the current cycle and the detected violation accounts determined based on at least one in-use violation operation rule; the violation cost information corresponding to the detected violation accounts is determined; and the validity information of the in-use violation operation rule is determined based on the violation accuracy, rule misjudgment rate and violation cost information.
[0051] When the current cycle is not the first regulatory cycle, the in-use violation rules are constructed by combining single rules to form more complex violation rules to accommodate diverse regulatory scenarios. For example, when the current cycle is not the first regulatory cycle, at least one single rule can be combined using the logical operators AND and OR to form the in-use violation rules. A non-first regulatory cycle refers to a subsequent cycle following the implementation of a single rule and at least one complete monitoring and evaluation cycle. During a non-first regulatory cycle, regulators continue to apply established rules and policies for monitoring and compliance checks.
[0052] It should be noted that if the current cycle is not the first regulatory cycle, the in-use violation rules are generated for the first time and have not yet been executed. Therefore, there is no transaction data for the relevant trading accounts, and therefore the validity information of the in-use violation rules cannot be calculated. Therefore, after the in-use violation rules are generated, in order to obtain the number of violating accounts corresponding to the in-use violation rules and the number of confirmed violating accounts received in the current cycle, these in-use violation rules must be executed in the implementation environment for at least one regulatory cycle. The purpose of the execution is to enable the system to begin monitoring and recording account data that meets the conditions of the in-use violation rules.
[0053] It should be noted that for a specific active violation rule, the rule accuracy rate refers to the proportion of true violating accounts detected by the active violation rule, calculated based on the confirmed violating accounts received during the current cycle and the violating accounts detected by the active violation rule. The rule accuracy rate can be expressed as the ratio of the number of true violating accounts to the number of violating accounts detected by the active violation rule. The number of true violating accounts refers to the number of violating accounts detected by the active violation rule that were actually detected. The number of violating accounts detected by the active violation rule includes all accounts detected by the active violation rule, regardless of whether they were ultimately confirmed as violating accounts. The rule false positive rate refers to the ratio of accounts incorrectly marked as violating by the active violation rule to accounts that were violating but were not marked. The rule false positive rate can be expressed as the sum of the number of incorrectly marked and missed violating accounts divided by the total number of detected violating accounts. The number of incorrectly marked violating accounts refers to the number of accounts that were detected as violating but were not actually violating after confirmation. The number of accounts that were missed as violating rules refers to the number of accounts that were detected as not violating rules but were later confirmed to be violating rules. The number of all detected violating accounts refers to the number of accounts detected by the rules that were used for the violation, regardless of whether these accounts were ultimately confirmed as violating rules.
[0054] It should also be noted that when the current cycle is not the first regulatory cycle, and the transaction data of at least one trading account is monitored using an ongoing violation rule, each triggered alert for an ongoing violation rule can trigger at least one control method. For example, ongoing violation rule Q could be that the total number of account logins exceeds 200 during the regulatory cycle, or the total account transfer value exceeds a value M during the regulatory cycle. If the total account transfer value of an account exceeds M during a non-first regulatory cycle, an alert is triggered. In this case, the relevant control method is implemented for the triggered alert. Each control method is associated with a corresponding violation cost information. In this embodiment of the present invention, the violation cost information corresponding to each control method refers to the labor cost associated with each control method, and these violation cost information for each control method can be quantified. The violation cost information refers to the sum of the violation cost information for all triggered control methods during a non-first regulatory cycle. For example, if a total of 200 control measures are triggered during the second regulatory cycle, 30 control methods are involved. The steps for calculating the violation cost information at this point are: first, determine the labor costs corresponding to the 30 control methods involved, then count the number of times each control method is triggered. Finally, add up the total labor costs calculated for each control method to obtain the violation cost information corresponding to the detected violating account.
[0055] For example, the formula for determining the validity information of the illegal operation rules in use by using the violation accuracy rate, rule misjudgment rate, and violation cost information can be:
[0056] β=accur*(1-err) / human;
[0057] Here, β refers to the effectiveness of a specific violation rule in use during a non-first regulatory cycle; accur refers to the violation accuracy rate; err refers to the rule false positive rate; and human refers to the violation cost information. It should be noted that for each violation rule in use, effectiveness information can be determined using the violation accuracy rate, rule false positive rate, and violation cost information. It should also be noted that the violation accuracy rate and rule false positive rate are typically expressed as percentages, ranging from 0% to 100%. Violation cost information is typically expressed in monetary units, so its numerical range may be larger and inconsistent with the numerical ranges of the violation accuracy rate and rule false positive rate. Therefore, the violation cost information can be normalized to facilitate calculation.
[0058] Optionally, when the current cycle is not the first regulatory cycle, for the same in-use violation operation rule used in multiple cycles, if the validity information of the in-use violation operation rule in the current cycle and the validity information of the previous cycle meet the preset conditions, the validity information of the in-use violation operation rule in the next cycle will no longer be determined.
[0059] It should be noted that the validity information of the current cycle and the validity information of the previous cycle for the in-use illegal operation rule satisfying the preset conditions means that the validity information of the in-use illegal operation rule in the current cycle is lower than the validity information of the in-use illegal operation rule in the previous cycle. For the same in-use illegal operation rule used in multiple cycles, if the validity information in the current cycle is lower than that in the previous cycle, the in-use illegal operation rule may be eliminated.
[0060] Specifically, in the first supervision cycle and the non-first supervision cycle, for at least one in-use illegal operation rule associated with the current cycle, the validity information of the in-use illegal operation rule is determined respectively according to the transaction data and the in-use illegal operation rule.
[0061] S130: Determine the illegal operation rules to be combined based on the validity information.
[0062] The illegal operation rule to be combined is a rule in at least one illegal operation rule in use.
[0063] Optionally, the in-use illegal operation rules whose validity information is higher than a preset threshold are retained, and the in-use illegal operation rules are used as the illegal operation rules to be combined.
[0064] Optionally, by combining and processing the combined illegal operation rules, in-use illegal operation rules used in the next cycle are obtained.
[0065] Specifically, after first collecting the validity information of each in-use violation operation rule, the in-use violation operation rules are screened based on a predetermined validity information threshold, that is, a preset threshold. When the validity information exceeds the preset threshold, the corresponding in-use violation operation rule can be retained, and when the validity information is lower than the threshold, the corresponding in-use violation operation rule can be discarded. All retained in-use violation operation rules are the violation operation rules to be combined. After determining the violation operation rules to be combined, a single rule in the violation operation rules to be combined can be used as the in-use violation operation rule to be used in the next cycle, and the single rules in the violation operation rules to be combined can also be combined to obtain the in-use violation operation rule to be used in the next cycle.
[0066] S140 , obtaining the in-use illegal operation rules corresponding to the next cycle by iteratively processing the combined illegal operation rules.
[0067] In this embodiment, if the cycle number corresponding to the current cycle is the same as the preset number, the in-use illegal operation rule corresponding to the next cycle will no longer be determined.
[0068] Specifically, for rule-based illegal operation rules whose validity information exceeds a preset threshold, they can be retained and their frequency of use may be increased. Through this systematic, iterative process, the illegal operation rules in use can be continuously optimized to ensure their adaptability and effectiveness, thereby better addressing compliance challenges and risks.
[0069] The technical solution of the embodiment of the present disclosure obtains the transaction data of at least one transaction account in the current cycle. Then, for at least one in-use violation operation rule associated with the current cycle, the validity information of the in-use violation operation rule is determined based on the transaction data and the in-use violation operation rule. Further, based on the validity information, the violation operation rule to be combined is determined. Finally, by iteratively processing the violation operation rule to be combined, the in-use violation operation rule corresponding to the next cycle is obtained. This solves the problem that the current reliance on business personnel to set rules to determine violation operations, the low rule operation accuracy and rule optimization efficiency, and the impact on normal financial transactions. The embodiment of the present disclosure realizes the determination of the violation operation rule to be combined based on the in-use violation operation rule, and iteratively processes the violation operation rule to be combined, thereby improving the rule generation efficiency. The iterative processing mechanism enables the rules to be continuously adjusted and improved according to real-time feedback, so as to achieve accurate optimization of the rules, significantly improving the rule optimization efficiency and the rule operation accuracy.
[0070] Example 2
[0071] As an optional embodiment of the above embodiment, this technical solution is introduced below using an example.
[0072] See also Figure 2 , obtain transaction data for at least one transaction account in the current period, and extract and compile indicator data. The transaction data obtained for at least one transaction account in the current period includes data obtained from financial institutions, the Ministry of Public Security, third-party credit rating agencies, and the People's Financial Institutions.
[0073] After obtaining the indicator data, if the current cycle is the first regulatory cycle, the validity information of the rule can be determined based on a simple rule, that is, a single rule. Figure 3 In a non-first regulatory cycle, the data and the database of the regulatory department, namely the transaction data of the trading account and the number of confirmed violation accounts received in the current cycle, can be used to determine the validity information of the rule based on the rule operation accuracy rate, namely the violation accuracy rate, the rule operation misjudgment rate, namely the rule misjudgment rate, and the rule operation labor cost, namely the violation cost information.
[0074] After the illegal operation rules to be combined are determined based on the validity information, the illegal operation rules to be combined may be verified, and the illegal operation rules to be combined may be iteratively processed to obtain the illegal operation rules in use corresponding to the next cycle.
[0075] See also Figure 3 If the number of cycles corresponding to the current cycle is the same as the preset number, the rules for determining the in-use illegal operation corresponding to the next cycle will not be executed. Figure 2 After obtaining the final rules, the final rules will be put online for operation.
[0076] The technical solution of the embodiment of the present disclosure determines the illegal operation rules to be combined based on the illegal operation rules in use, iteratively processes the illegal operation rules to be combined, improves the efficiency of rule generation, achieves accurate optimization of the rules, and significantly improves the rule optimization efficiency and the accuracy of rule operation.
[0077] Example 3
[0078] Figure 4 is a schematic diagram of the structure of the rule generation device provided by the embodiment of the present disclosure, such as Figure 4 As shown, the apparatus includes: a transaction data acquisition module 210 , a validity information determination module 220 , a to-be-combined illegal operation rule determination module 230 , and an iterative processing module 240 .
[0079] A transaction data acquisition module is configured to acquire transaction data of at least one transaction account within a current cycle; a validity information determination module is configured to determine, for at least one in-use violation operation rule associated with the current cycle, the validity information of the in-use violation operation rule based on the transaction data and the in-use violation operation rule; a module is configured to determine the violation operation rule to be combined based on the validity information; wherein the violation operation rule to be combined is a rule in the at least one in-use violation operation rule; and an iterative processing module is configured to obtain the in-use violation operation rule corresponding to the next cycle by iteratively processing the violation operation rule to be combined.
[0080] The technical solution of the embodiment of the present disclosure obtains the transaction data of at least one transaction account in the current cycle. Then, for at least one in-use violation operation rule associated with the current cycle, the validity information of the in-use violation operation rule is determined based on the transaction data and the in-use violation operation rule. Further, based on the validity information, the violation operation rule to be combined is determined. Finally, by iteratively processing the violation operation rule to be combined, the in-use violation operation rule corresponding to the next cycle is obtained. This solves the problem that the current reliance on business personnel to set rules to determine violation operations, the low rule operation accuracy and rule optimization efficiency, and the impact on normal financial transactions. The embodiment of the present disclosure realizes the determination of the violation operation rule to be combined based on the in-use violation operation rule, and iteratively processes the violation operation rule to be combined, thereby improving the rule generation efficiency. The iterative processing mechanism enables the rules to be continuously adjusted and improved according to real-time feedback, so as to achieve accurate optimization of the rules, significantly improving the rule optimization efficiency and the rule operation accuracy.
[0081] Based on the above technical solutions, the current cycle is the first supervision cycle, the illegal operation rules in use are single rules, and the validity information determination module 220 includes: a control number determination submodule, a control information determination submodule and a validity information determination submodule.
[0082] A control times determination submodule is used to determine the number of illegal accounts corresponding to the illegal operation rules in use, the total number of warnings triggered, and the number of control times for each control method after the warning;
[0083] A control information determination submodule is used to determine control information for each control method according to the control times and corresponding weights of the control method;
[0084] The validity information determination submodule is used to determine the validity information of the illegal operation rules in use by calculating the control information, the number of illegal accounts, the total number of warnings, and the number of confirmed illegal accounts received in the current cycle.
[0085] Based on the above technical solutions, the current cycle is not the first supervision cycle, the illegal operation rules in use are rules obtained by combining at least one single rule, and the validity information determination module 220 includes: a rule accuracy determination submodule, a violation cost information determination submodule and a validity information determination submodule.
[0086] a rule accuracy determination submodule, configured to determine a rule accuracy and a rule misjudgment rate based on confirmed violation accounts received in a current cycle and detected violation accounts determined based on the at least one violation operation rule in use;
[0087] A violation cost information determination submodule, configured to determine the violation cost information corresponding to the detected violation account;
[0088] The validity information determination submodule is used to determine the validity information of the illegal operation rule in use according to the violation accuracy rate, the rule misjudgment rate and the violation cost information.
[0089] On the basis of the above technical solutions, the module for determining the illegal operation rules to be combined 230 includes: a sub-module for determining the illegal operation rules to be combined.
[0090] The submodule for determining illegal operation rules to be combined is configured to retain the illegal operation rules in use whose validity information is higher than a preset threshold, and use the illegal operation rules in use as the illegal operation rules to be combined.
[0091] On the basis of the above technical solutions, the iterative processing module 240 includes: a submodule for determining illegal operation rules during use.
[0092] The in-use illegal operation rule determination submodule is used to obtain the in-use illegal operation rules used in the next cycle by combining and processing the illegal operation rules to be combined.
[0093] On the basis of the above technical solutions, the current cycle is not the first supervision cycle, and the device further includes: a validity information uncertainty module.
[0094] The validity information uncertainty module is used to determine, for the same in-use violation operation rule used in multiple cycles, the validity information of the in-use violation operation rule in the next cycle will no longer be determined if the validity information of the in-use violation operation rule in the current cycle and the validity information of the previous cycle meet the preset conditions.
[0095] On the basis of the above technical solutions, the device further comprises: a module for not executing illegal operation rules during use.
[0096] The module for not executing the in-use illegal operation rule is configured to not execute the in-use illegal operation rule corresponding to the next cycle if the number of cycles corresponding to the current cycle is the same as the preset number of cycles.
[0097] On the basis of the above technical solutions, the in-use illegal operation rules are used to detect anomalies in the transaction data.
[0098] The rule generation device provided by the embodiments of the present disclosure can execute the rule generation method provided by any embodiment of the present disclosure, and has the corresponding functional modules and beneficial effects of the execution method.
[0099] It is worth noting that the various units and modules included in the above-mentioned device are only divided according to functional logic, but are not limited to the above-mentioned division, as long as the corresponding functions can be achieved; in addition, the specific names of the functional units are only for the convenience of distinguishing each other, and are not used to limit the protection scope of the embodiments of the present disclosure.
[0100] Example 4
[0101] Figure 5 This is a schematic diagram of the structure of an electronic device provided by an embodiment of the present disclosure. Figure 5 , which shows an electronic device (eg Figure 5 The terminal device in the embodiments of the present disclosure may include, but is not limited to, a mobile terminal such as a mobile phone, a laptop computer, a digital broadcast receiver, a PDA (personal digital assistant), a PAD (tablet computer), a PMP (portable multimedia player), an in-vehicle terminal (such as an in-vehicle navigation terminal), and the like. Figure 5The electronic device shown is only an example and should not limit the functions and scope of use of the embodiments of the present disclosure.
[0102] like Figure 5 As shown, the electronic device 500 may include a processing device (e.g., a central processing unit, a graphics processing unit, etc.) 501, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 502 or a program loaded from a storage device 508 into a random access memory (RAM) 503. Various programs and data required for the operation of the electronic device 500 are also stored in the RAM 503. The processing device 501, the ROM 502, and the RAM 503 are connected to each other via a bus 504. An edit / output (I / O) interface 505 is also connected to the bus 504.
[0103] Typically, the following devices may be connected to the I / O interface 505: an input device 506 including, for example, a touch screen, a touchpad, a keyboard, a mouse, a camera, a microphone, an accelerometer, a gyroscope, etc.; an output device 507 including, for example, a liquid crystal display (LCD), a speaker, a vibrator, etc.; a storage device 508 including, for example, a magnetic tape, a hard disk, etc.; and a communication device 509. The communication device 509 may allow the electronic device 500 to communicate with other devices wirelessly or by wire to exchange data. Although Figure 5 The electronic device 500 is shown with various devices, but it should be understood that it is not required to implement or possess all of the devices shown. More or fewer devices may be implemented or possessed instead.
[0104] In particular, according to an embodiment of the present disclosure, the process described above with reference to the flowchart can be implemented as a computer software program. For example, an embodiment of the present disclosure includes a computer program product, which includes a computer program carried on a non-transitory computer-readable medium, and the computer program includes a program code for executing the method shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from the network through the communication device 509, or installed from the storage device 508, or installed from the ROM 502. When the computer program is executed by the processing device 501, the above-mentioned functions defined in the method of the embodiment of the present disclosure are performed.
[0105] The names of the messages or information exchanged between multiple devices in the embodiments of the present disclosure are only used for illustrative purposes and are not used to limit the scope of these messages or information.
[0106] The electronic device provided by the embodiment of the present disclosure and the rule generation method provided by the above embodiment belong to the same inventive concept. For technical details not fully described in this embodiment, please refer to the above embodiment, and this embodiment has the same beneficial effects as the above embodiment.
[0107] Example 5
[0108] An embodiment of the present disclosure provides a computer storage medium having a computer program stored thereon. When the program is executed by a processor, the rule generation method provided in the above embodiment is implemented.
[0109] It should be noted that the computer-readable medium mentioned above in the present disclosure may be a computer-readable signal medium or a computer-readable storage medium, or any combination of the two. A computer-readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, device, or component, or any combination of the above. More specific examples of computer-readable storage media may include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present disclosure, a computer-readable storage medium may be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, device, or component. In the present disclosure, a computer-readable signal medium may include a data signal propagated in baseband or as part of a carrier wave, which carries computer-readable program code. Such a propagated data signal may take a variety of forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. A computer-readable signal medium may also be any computer-readable medium other than a computer-readable storage medium that can transmit, propagate, or transport a program for use by or in conjunction with an instruction execution system, apparatus, or device. The program code contained on the computer-readable medium may be transmitted using any suitable medium, including but not limited to wires, optical cables, RF (radio frequency), etc., or any suitable combination thereof.
[0110] In some embodiments, the server can communicate using any currently known or later developed network protocol, such as HTTP (HyperText Transfer Protocol), and can be interconnected with any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include a local area network ("LAN"), a wide area network ("WAN"), an internet (e.g., the Internet), and a peer-to-peer network (e.g., an ad hoc peer-to-peer network), as well as any currently known or later developed network.
[0111] The computer-readable medium may be included in the electronic device, or may exist independently without being incorporated into the electronic device.
[0112] The computer-readable medium carries one or more programs. When the one or more programs are executed by the electronic device, the electronic device:
[0113] Get the transaction data of at least one trading account in the current period;
[0114] For at least one in-use illegal operation rule associated with the current cycle, determining validity information of the in-use illegal operation rule based on the transaction data and the in-use illegal operation rule;
[0115] Based on the validity information, determining the illegal operation rule to be combined; wherein the illegal operation rule to be combined is a rule in the at least one illegal operation rule in use;
[0116] The illegal operation rules to be combined are iteratively processed to obtain the illegal operation rules in use corresponding to the next cycle.
[0117] Computer program code for performing the operations of the present disclosure may be written in one or more programming languages, or a combination thereof, including, but not limited to, object-oriented programming languages such as Java, Smalltalk, C++, and conventional procedural programming languages such as "C" or similar programming languages. The program code may be executed entirely on the user's computer, partially on the user's computer, as a stand-alone software package, partially on the user's computer and partially on a remote computer, or entirely on the remote computer or server. In cases involving a remote computer, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., through the Internet using an Internet service provider).
[0118] The flowcharts and block diagrams in the accompanying drawings illustrate the possible implementation architecture, functions and operations of the systems, methods and computer program products according to various embodiments of the present disclosure. In this regard, each box in the flowchart or block diagram can represent a module, program segment, or a part of code, and the module, program segment, or a part of code contains one or more executable instructions for realizing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in a different order than that marked in the accompanying drawings. For example, two boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram and / or flowchart, and the combination of the boxes in the block diagram and / or flowchart, can be implemented with a dedicated hardware-based system that performs the specified function or operation, or can be implemented with a combination of dedicated hardware and computer instructions.
[0119] The units involved in the embodiments described in this disclosure may be implemented in software or hardware, wherein the name of a unit does not necessarily limit the unit itself.
[0120] The functions described above herein may be performed, at least in part, by one or more hardware logic components. For example, and without limitation, exemplary types of hardware logic components that may be used include: field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), systems on chip (SOCs), complex programmable logic devices (CPLDs), and the like.
[0121] In the context of the present disclosure, a machine-readable medium can be a tangible medium that can contain or store a program for use by or in conjunction with an instruction execution system, device or equipment. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can include, but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, device or equipment, or any suitable combination of the foregoing. A more specific example of a machine-readable storage medium can include an electrical connection based on one or more lines, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0122] The above description is merely a preferred embodiment of the present disclosure and an illustration of the technical principles employed. Those skilled in the art should understand that the scope of disclosure involved in the present disclosure is not limited to the technical solutions formed by the specific combination of the above-mentioned technical features, but also includes other technical solutions formed by any combination of the above-mentioned technical features or their equivalents without departing from the above-mentioned disclosed concepts. For example, a technical solution formed by replacing the above-mentioned features with (but not limited to) technical features with similar functions disclosed in this disclosure.
[0123] In addition, although each operation is described in a specific order, this should not be understood as requiring these operations to be performed in the specific order shown or in a sequential order. Under certain circumstances, multitasking and parallel processing may be advantageous. Similarly, although some specific implementation details have been included in the above discussion, these should not be interpreted as limiting the scope of the present disclosure. Some features described in the context of a separate embodiment can also be implemented in a single embodiment in combination. On the contrary, the various features described in the context of a single embodiment can also be implemented in multiple embodiments individually or in any suitable sub-combination mode.
[0124] Although the subject matter has been described in language specific to structural features and / or methodological logical acts, it should be understood that the subject matter defined in the appended claims is not necessarily limited to the specific features or acts described above. Rather, the specific features and acts described above are merely example forms of implementing the claims.
Claims
1. A rule generation method, characterized in that: The method comprises: Get the transaction data of at least one trading account in the current period; For at least one in-use illegal operation rule associated with the current cycle, determining validity information of the in-use illegal operation rule based on the transaction data and the in-use illegal operation rule; Based on the validity information, determining the illegal operation rule to be combined; wherein the illegal operation rule to be combined is a rule in the at least one illegal operation rule in use; The illegal operation rules to be combined are iteratively processed to obtain the illegal operation rules in use corresponding to the next cycle.
2. The method according to claim 1, characterized in that The current cycle is the first regulatory cycle, the in-use illegal operation rule is a single rule, and determining the validity information of the in-use illegal operation rule based on the transaction data and the in-use illegal operation rule includes: Determine the number of violating accounts corresponding to the illegal operation rules in use, the total number of warnings triggered, and the number of control methods for each control method after the warning; For each control method, control information is determined based on the control times and corresponding weight of the control method; The validity information of the in-use illegal operation rules is determined by calculating the control information, the number of illegal accounts, the total number of warnings, and the number of confirmed illegal accounts received in the current cycle.
3. The method according to claim 1, characterized in that The current cycle is not the first regulatory cycle, the in-use illegal operation rule is a rule obtained by combining at least one single rule, and determining the validity information of the in-use illegal operation rule based on the transaction data and the in-use illegal operation rule includes: Determining a rule accuracy rate and a rule misjudgment rate based on confirmed violation accounts received in a current period and detected violation accounts determined based on the at least one in-use violation operation rule; Determining violation cost information corresponding to the detected violation account; The validity information of the illegal operation rule in use is determined according to the violation accuracy rate, the rule misjudgment rate and the violation cost information.
4. The method according to claim 1, wherein The determining of the illegal operation rules to be combined based on the validity information includes: The in-use illegal operation rules whose validity information is higher than a preset threshold are retained, and the in-use illegal operation rules are used as the illegal operation rules to be combined.
5. The method according to claim 1, characterized in that The iterative processing of the illegal operation rules to be combined to obtain the illegal operation rules in use corresponding to the next cycle includes: By combining and processing the illegal operation rules to be combined, the illegal operation rules in use used in the next cycle are obtained.
6. The method according to claim 1, characterized in that The current cycle is not the first regulatory cycle, and the method further includes: For the same in-use illegal operation rule used in multiple cycles, if the validity information of the in-use illegal operation rule in the current cycle and the validity information of the previous cycle meet the preset conditions, the validity information of the in-use illegal operation rule in the next cycle will no longer be determined.
7. The method according to claim 1, characterized in that The method further comprises: If the number of cycles corresponding to the current cycle is the same as the preset number of cycles, the rule for determining the illegal operation in use corresponding to the next cycle will no longer be executed.
8. The method according to any one of claims 1 to 7, characterized in that: The in-use illegal operation rules are used to detect anomalies in the transaction data.
9. A rule generating device, characterized in that: include: A transaction data acquisition module is used to obtain transaction data of at least one transaction account in the current period; a validity information determination module, configured to determine, for at least one in-use illegal operation rule associated with the current period, validity information of the in-use illegal operation rule based on the transaction data and the in-use illegal operation rule; a module for determining a rule of illegal operation to be combined, configured to determine a rule of illegal operation to be combined based on the validity information; wherein the rule of illegal operation to be combined is a rule in the at least one illegal operation rule in use; The iterative processing module is used to obtain the in-use illegal operation rules corresponding to the next cycle by iteratively processing the illegal operation rules to be combined.
10. An electronic device, characterized in that: The electronic device comprises: one or more processors; a storage device for storing one or more programs, When one or more programs are executed by one or more processors, the one or more processors implement the rule generation method according to any one of claims 1 to 8.