Equipment leasing-oriented full-life-cycle monitoring and risk early warning system
By building a full life cycle monitoring and risk warning system for equipment leasing, the problem of identifying illegal subleases in equipment leasing has been solved, accurate identification and risk warning of abnormal transfers of control rights have been achieved, and the compliance management capabilities of equipment leasing have been improved.
Patent Information
- Application Number
- CN202510765734.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-10
- Publication Date
- 2025-09-19
AI Technical Summary
Existing equipment leasing management platforms struggle to identify and monitor illegal subleases, leaving equipment unmonitored, responsibilities unclear, and compliance risks compounded. This is especially true in scenarios such as engineering construction and agricultural collaboration, where existing methods struggle to detect illegal transfers of equipment control.
Build a full-life cycle monitoring and risk warning system for equipment leasing. Through the account binding module, graph construction module, control mutation identification module, control offset screening module and risk warning module, it can achieve accurate identification of abnormal transfer of control rights during the equipment leasing process and risk warning.
By building operation maps and behavioral analysis, we can identify abnormal transfer of control rights during the equipment leasing process, implement risk warnings at the lease contract cycle level, and improve compliance management capabilities and risk control accuracy throughout the entire life cycle of equipment leasing.
Smart Images

Figure CN120672438A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of equipment leasing supervision, and more specifically, to a full life cycle monitoring and risk early warning system for equipment leasing. Background Art
[0002] In current equipment leasing management practices, platforms typically rely on contract terms, identity authentication, and location information to constrain and track leasing relationships. However, these approaches are fundamentally ineffective when addressing illegal subleases. In practice, particularly in scenarios such as construction, agricultural collaboration, and energy equipment rotation, equipment subleases frequently occur between existing users to save costs. This behavior circumvents platform oversight processes, resulting in unregistered and unauthorized changes in control, leaving equipment unmonitored, unclear responsibilities, and compounding compliance risks. Specifically, because there is no obvious change in geographic location, existing identification methods relying on GPS or user IDs struggle to detect these subleases. While the platform may still record the equipment as being within the "legal lease period," actual control has already transferred. Existing leasing management platforms struggle to effectively identify and monitor these illegal subleases, resulting in financial losses for leasing providers and ineffective accountability for leasing. Summary of the Invention
[0003] In order to overcome the above-mentioned defects of the prior art, an embodiment of the present invention provides a full life cycle monitoring and risk warning system for equipment leasing to solve the problems raised in the above-mentioned background technology.
[0004] To achieve the above object, the present invention provides the following technical solutions:
[0005] A full-lifecycle monitoring and risk warning system for equipment leasing, including an account binding module, a graph construction module, a control mutation identification module, a control deviation screening module, and a risk warning module, wherein:
[0006] The account binding module extracts the identity information, equipment number, and valid lease period registered in the equipment leasing contract and constructs a contract-bound account set;
[0007] The graph construction module extracts the control instruction sequence from the control terminal log during the device operation period and generates an operation behavior record table, and constructs an operation graph based on the control instruction sequence of each bound account;
[0008] The control mutation identification module constructs a behavior sequence graph structure based on the account operation graph and identifies behavioral style break segments as control mutation candidate segments;
[0009] The control shift screening module performs structured behavioral regression matching analysis on the control mutation candidate segments of each bound account tag to screen out irregressive control path shift segments;
[0010] The risk warning module counts the irregressive control path deviation segments of bound accounts within several cumulative periods, constructs a control jump distribution sequence, and issues risk warning marks for the rental period corresponding to the jump distribution density peak.
[0011] In a preferred embodiment, the account binding module extracts the identity information, device number, and valid lease period registered in the equipment lease contract, and constructs a contract-bound account set, specifically including:
[0012] Parse the lease contract text records in the database and extract the lease identity information, equipment number, and lease start and end time fields;
[0013] Perform a two-way binding mapping between the operator account and the device number, and divide the binding mapping relationship into valid and invalid lease periods based on the lease start and end time fields;
[0014] Eliminate the associated records within the non-valid period of the lease, retain the records where the current operating time of the device coincides with the lease period, and build a contract-bound account set.
[0015] In a preferred embodiment, the graph construction module extracts the control instruction sequence in the control terminal log during the device operation period and generates an operation behavior record table. Constructing the operation graph based on the control instruction sequence of each bound account specifically includes:
[0016] Filter the log data from the control end log records that match the device number in the contract binding account set, and extract the original log entry set containing the binding account, control command and timestamp;
[0017] Format the bound account, control instruction, and corresponding timestamp in each log into triples and mark them as structured control behavior units.
[0018] Sort the structured control behavior units in ascending order by timestamp, generate the account-level control instruction time series, and establish an operation behavior record table;
[0019] Perform behavioral rhythm analysis on the control instruction sequence of each bound account, and construct an operation map based on the average interval between instructions, function call sequence, and cycle stability.
[0020] In a preferred embodiment, the behavioral rhythm analysis of the control instruction sequence of each bound account and the construction of an operation map based on the average interval between instructions, function call sequence and cycle stability specifically include:
[0021] Extract the control instruction sequence corresponding to the bound account from the operation behavior record table, and calculate the time interval difference sequence between any two adjacent instructions;
[0022] The interval difference sequence is used as a rhythm parameter group, and the mean and standard deviation of the rhythm parameter group are calculated as the time distribution of the operation interval, and output as the bound account control rhythm vector;
[0023] Setting a control instruction sequence of a function label, mapping the operation trajectory of the continuous control instruction to a standard control instruction sequence corresponding to a predefined function label in the control instruction coding space, and obtaining a function label arrangement;
[0024] Identify recurring functional tag arrangements and extract duplicate segments using a sequence similarity matching method based on the longest common prefix;
[0025] The interval period of repeated segments is counted, and a period stability index is constructed based on the mean value of the interval offset of each occurrence position on the time axis;
[0026] The rhythm vector, function label arrangement and period stability index of the account dimension are integrated into combined features, and the operation graph of bound accounts is constructed based on the combined features as the graph node structure unit.
[0027] In a preferred embodiment, the control mutation identification module constructs a behavior sequence diagram structure according to the account operation graph, and identifies behavioral style break segments as control mutation candidate segments, specifically including:
[0028] During the set rental monitoring period, the operation graph of the bound account is divided into set continuous control segments according to the time series to generate the account behavior graph node set;
[0029] In each account behavior map node set, a structural difference matrix is constructed based on the rhythm feature change rate and functional path deviation between adjacent nodes, and a structural break score sequence is generated;
[0030] Extract the corresponding control segments whose score increase exceeds the set threshold from the structural fracture score sequence, and mark the behavioral style fracture segments;
[0031] Summarize the style break fragment indexes corresponding to all bound accounts within the set rental monitoring period and establish a set of control mutation candidate segments.
[0032] In a preferred embodiment, the functional path deviation refers to mapping the operation trajectory composed of continuous control instructions in each control segment to a standard control instruction sequence corresponding to a predefined functional label in the control instruction encoding space, and counting the proportion of instructions that were not hit during the mapping process.
[0033] In a preferred embodiment, the control deviation screening module performs structured behavioral regression matching analysis on each control mutation candidate segment of each bound account tag, and screening for irregressive control path deviation segments specifically includes:
[0034] Extract the set of marked style break segments for each account within the set rental monitoring period and parse them into the functional label sequence and rhythm feature vector of the control segment;
[0035] Extract stable control period behavior segments from the account's historical operation logs and construct a set of behavior templates consisting of function label sequences and rhythm features.
[0036] Compare each style break segment with the behavior template set in turn, calculate the rhythm feature change rate and functional path deviation between the current style break segment and the matching template, and form the behavior regression offset;
[0037] The fragment segments whose regression offset exceeds the set threshold are filtered and marked as non-regressive control path offset segments.
[0038] In a preferred embodiment, the risk warning module counts the irregressive control path deviation segments of the bound account within a number of cumulative periods, constructs a control jump distribution sequence, and performs risk warning marking on the rental period corresponding to the jump distribution density peak. Specifically, the following steps are included:
[0039] Extract all irreversible control path offset segments marked by the bound account within several consecutive set rental monitoring periods and generate a sequence of abnormal control records with timestamps;
[0040] The abnormal control record sequence is statistically analyzed in a time window sliding manner, the number of non-regressive segments in each window is calculated, and the behavior jump distribution density curve is constructed;
[0041] Identify the density peak area in the behavior jump distribution density curve, align the density peak area with the rental life cycle corresponding to the bound account, and mark the illegal sublease risk warning mark in the database.
[0042] The technical effects and advantages of the present invention's full life cycle monitoring and risk warning system for equipment leasing are as follows:
[0043] By constructing an operation graph behavior structure based on account numbers and combining it with a control instruction timing and path matching mechanism, the accurate identification of abnormal transfer of control rights during the equipment leasing process can be achieved. Compared with the traditional identification method that relies on account comparison or equipment abnormality log triggering, the solution does not need to rely on multi-account comparison or external abnormality annotation information. It can complete the identification of style mutations and structural irregression based solely on the control behavior trajectory of a single account within the operation cycle, and effectively adapt to the implicit control behavior characteristics of the operator impersonating the original account in illegal sublease. In addition, through cross-cycle behavior jump distribution density analysis, the solution can capture risk trends with periodic and centralized control replacement characteristics, and realize risk warning annotation at the lease contract cycle level. The overall solution has the advantages of fine-grained behavior analysis, strong concealment of abnormality capture, and adaptability to actual business constraints, significantly improving the compliance management capabilities and risk control accuracy throughout the life cycle of equipment leasing. BRIEF DESCRIPTION OF THE DRAWINGS
[0044] Figure 1 This is a structural diagram of a full life cycle monitoring and risk warning system for equipment leasing according to the present invention. DETAILED DESCRIPTION
[0045] The following will provide a clear and complete description of the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. All other embodiments obtained by ordinary technicians in this field based on the embodiments of the present invention without making any creative efforts shall fall within the scope of protection of the present invention.
[0046] Example 1
[0047] Figure 1 The present invention provides a full life cycle monitoring and risk warning system for equipment leasing, which includes the following steps:
[0048] A full-lifecycle monitoring and risk warning system for equipment leasing, including an account binding module, a graph construction module, a control mutation identification module, a control deviation screening module, and a risk warning module, wherein:
[0049] The account binding module extracts the identity information, equipment number, and valid lease period registered in the equipment leasing contract and constructs a contract-bound account set;
[0050] The graph construction module extracts the control instruction sequence from the control terminal log during the device operation period and generates an operation behavior record table, and constructs an operation graph based on the control instruction sequence of each bound account;
[0051] The control mutation identification module constructs a behavior sequence graph structure based on the account operation graph and identifies behavioral style break segments as control mutation candidate segments;
[0052] The control shift screening module performs structured behavioral regression matching analysis on the control mutation candidate segments of each bound account tag to screen out irregressive control path shift segments;
[0053] The risk warning module counts the irregressive control path deviation segments of bound accounts within several cumulative periods, constructs a control jump distribution sequence, and issues risk warning marks for the rental period corresponding to the jump distribution density peak.
[0054] The account binding module extracts the identity information, equipment number and valid lease period registered in the equipment lease contract and constructs a contract-bound account set.
[0055] In the system's operating environment, the platform database maintains lease contract information and equipment control log data in a structured format. The lease contract data table includes fields such as "Contract Number," "Lessee Account Number," "Equipment Number," "Lease Start Time," and "Lease End Time." The control log data table includes standardized fields such as "Operator Account Number," "Operation Equipment Number," and "Operation Timestamp."
[0056] The system uses a database interface to batch read all historical contract records from the lease contract data table. It then extracts three key pieces of information from each record based on field names: the lessee's registered account number (the contract registration account field), the device number corresponding to the contract (the device number field), and the contract's lease start and end times (the lease start and end time fields). These fields, acting as constraints for binding identities, are written to the system's intermediate cache, forming an initial identity binding data table with the "account-device-lease period" triple as the primary key.
[0057] The system matches records in the control log data table by the "Device Number" field, filtering out all operation records that have executed control actions on the target device. For each record, the system extracts its "Operator Account" field and "Operation Timestamp" field, and matches its device number field with the device number field in the contract data to establish a collection of account-device binding action records. After completing the initial matching, the system performs a lease validity check on each operation record based on the lease start and end times extracted from the contract. For each account-device binding record, if its operation timestamp falls within the lease period defined in the corresponding contract (i.e., the operation time is no earlier than the lease start time and no later than the lease end time), the record is determined to be a "control action within the contract validity period." Conversely, if the operation time is before the start or end of the contract, the record is marked as "non-valid lease action" and is discarded from subsequent processing.
[0058] Finally, the system aggregates all account-device control behavior records that meet the lease validity conditions, indexed by the contract number, and extracts the set of operator accounts that performed control operations on the equipment during the contract validity period. This set constitutes the "contract-bound account set" corresponding to the lease contract and serves as the basic data input for subsequent operation map construction, control style analysis, and jump behavior identification modules.
[0059] The graph construction module extracts the control instruction sequence in the control terminal log during the device operation period and generates an operation behavior record table, and constructs an operation graph based on the control instruction sequence of each bound account.
[0060] In the backend log parsing service for leased equipment, we perform a targeted device control behavior screening operation on the large-scale device control log records generated during the contract period. The system first uses the contract-bound account set as a qualifier for filtering control logs. This set contains two-way binding records for account numbers and device numbers generated by the lease contract parsing module. Each binding entry clearly identifies the legal control rights that an account has over a particular device during the specified lease period.
[0061] Control-side logs are recorded in a standardized structure, with fields including "Operator Account," "Device Number," "Control Command Text," and "Operation Timestamp." To avoid inefficient processing, the system performs preliminary filtering during log reading, loading only records where the device number field matches the contracted device number. Matching is performed using field key-value comparisons, and fuzzy matching is supported to accommodate differences in abbreviations or mapping formats for device number fields in some systems.
[0062] After device number screening is complete, the system performs a second phase of field extraction, retaining the "Operator Account," "Control Command," and "Operation Timestamp" fields from each log entry. The operator account field is then re-verified against the contract-bound account set. This ensures that even if the device number matches, if the operator account is not in the legally bound account set, it will not be included in the subsequent processing. This comparison utilizes a hash index mechanism to perform fast searches within the account set, optimizing the efficiency of large-scale log screening.
[0063] For log records that meet the requirements, the system constructs a unified set of raw log entries. Each entry is organized into a structured data block containing "account number - command - time" and is tagged with the corresponding device number and the log record's unique ID, facilitating rapid recall and structured merging in the subsequent behavior graph construction phase.
[0064] The system traverses the original set of log entries and extracts key fields from each record. Specifically, the extracted fields include the operator account, control command content, and operation timestamp. The operator account identifies the contracting party responsible for the control action. The control command field typically appears as a structured control command identifier, which can be text, a number, a function code, or other formats. The operation timestamp field records the actual time the command was triggered, accurate to the second or millisecond level. After field extraction, the system constructs a triplet data unit based on the three fields: "account-command-time." Each triplet represents a single control action executed by a specific account on a specific device at a specific point in time. To ensure data consistency, the system performs standardization on the control command field, such as mapping function codes across multiple platforms and translating device-specific commands into synonyms, ensuring that the same control action is consolidated across different encoding standards. Furthermore, the timestamp field is uniformly converted to UTC time to avoid time misalignment caused by different time zones at the log source. To clarify the structural attributes of triples during graph construction, the system assigns the semantic label "structured control behavior unit" to each formatted triple. Specifically, this unit not only contains the triple's value itself, but also includes structural attribute identifiers, including device number tags, log record numbers, account lease status (in-lease or out-of-lease), instruction type classification, and other metadata.
[0065] Structured control action unit sets are logically grouped by the "Operator Account" field. Each account's corresponding control unit set is processed as an independent action sequence. During the grouping process, the system appends the account binding information and contract number to the group identifier, ensuring accurate segmentation of account control data even in scenarios with multiple contracts or multiple devices running concurrently.
[0066] After completing the grouping, the system performs an ascending sorting operation on the "timestamp field" for each group of structured control behavior units. The sorting mechanism uses a stable time-based sorting algorithm with the operation time accuracy (seconds or milliseconds) as the primary key to ensure that multiple instructions issued at the same time can still maintain the original log record order to prevent the behavior chain from breaking or rhythm dislocation. During the sorting process, the system also records the interval time between adjacent control behaviors for subsequent rhythm analysis module calls. After the sorting is completed, the system organizes and stores each sorted account control behavior set in an "account-time series" structure to form an account-level control instruction time series. Each time series record consists of structured control units arranged in ascending time order, and has engineering characteristics such as continuity, traceability, and consistency with the original operation log.
[0067] The control instruction sequence of each bound account is subjected to behavioral rhythm analysis, and an operation map is constructed based on the average interval between instructions, function call sequence and cycle stability.
[0068] Based on the established operational behavior record table, the system analyzes the control behavior sequence of each contract-bound account and extracts account-level rhythm statistical features. The operational behavior record table records the chronological results of all device control actions of the account during the lease period. Each record includes the control instruction's unique identification code, execution timestamp, and the device ID. The system traverses the control instruction sequence of each account in chronological order and extracts the complete time series.
[0069] During the traversal process, the system calculates the time interval between each two adjacent control instructions—the execution time of the latter instruction minus the timestamp of the previous instruction—to form a sequence of time interval differences. This difference sequence describes the temporal distribution between instructions in the account's actual control operations, reflecting the rhythmic characteristics of its control operations. The system records this difference sequence as a rhythm parameter group and statistically processes all the time interval values within it, calculating their average and standard deviation. The average represents the overall operational rhythm of the account's control behavior, while the standard deviation measures the consistency or volatility of the operational rhythm.
[0070] To prevent abnormal conditions such as sudden interruptions or system restarts from interfering with the rhythm results, the system applies a sliding window denoising process to the time interval difference sequence, removing isolated values or peak segments that significantly deviate from the normal rhythm threshold, thereby improving the stability and discriminability of the rhythm parameters. After completing this process, the system encapsulates the average operation interval and operation rhythm standard deviation corresponding to the account in vector form to construct the control rhythm vector for that account.
[0071] Based on the device's function type, low-level control instruction codes are converted into abstract tags with functional semantics, and a mapping method is used to construct the functional tag arrangement of the account control sequence. This process is based on a predefined functional tag mapping table, which categorizes and maps all control instruction codes supported by the platform to several standard functional modules, such as "Startup Process," "Material Loading," "Operation and Maintenance," and "Shutdown." Each functional module corresponds to a set of typical control instruction code sequences.
[0072] The system reads the control instruction time series of each bound account in the operation behavior record table, extracts the encoding values of all continuous control instructions, and performs function mapping operations on them in sequence. The mapping rule adopts the longest match priority strategy: the system searches forward from the current instruction position for the longest instruction fragment that can completely match a function sequence in the function label table, and maps the fragment to the corresponding function label identifier. Once the mapping is successful, the fragment is marked as a semantically complete function call path, and the corresponding label is added to the function label arrangement sequence. The instruction pointer skips the matched fragment and continues to scan backward and match the remaining instruction sequences until the entire control sequence is processed.
[0073] After completing the function tag permutation, the system enters the behavioral periodicity identification phase. In this embodiment, the platform system analyzes the control sequence of an account for periodically recurring function call structures to determine whether the account exhibits a stable, inertial control behavior style. Periodic behavior refers to the recurrence of certain function tag permutations at a high frequency over different time periods, with a certain regularity in the relative time intervals. The system uses a sequence similarity matching algorithm based on the longest common prefix (LCP) to traverse a sliding window through the function tag permutations of each account, searching for reusable tag segments. The algorithm compares the function tag sequence within the current sliding window with all previously occurring tag substrings, calculates the longest common prefix length, and sets a similarity threshold. When the LCP length of the current segment and the previous segment reaches the similarity threshold (specified based on the instruction encoding length corresponding to the function tag) and the structural positions do not overlap, the system identifies them as repeating segments. For each group of identified identical repeating segments, the first and subsequent occurrence times on the timeline are extracted, and the time intervals between each repeating segment are calculated. The system calculates the mean and standard deviation of this time interval sequence, using the standard deviation as an indicator of cyclic stability. If the standard deviation is small, it means that the behavior has a strong cyclical pattern and the controller has a highly repetitive operating style; otherwise, it means that there are fluctuations or abnormal interventions in the control style.
[0074] The system integrates the three types of account-level feature information previously obtained - control rhythm vectors, function label arrangements and periodic stability indicators - into behavioral node attributes in the graph structure to construct an operational behavior graph. The graph is constructed based on accounts, and nodes and edges are organized in the order of the control instruction time series. Nodes represent structured behavior fragments, and edges represent the temporal and functional path relationships between previous and subsequent control behaviors. The graph node structure is defined as follows: each node corresponds to a continuous control behavior, and the time span does not exceed the set window threshold (the threshold cannot be lower than the longest instruction sequence execution length of the function label). The content includes the rhythm vector value (average interval and fluctuation value), the function label subsequence and its semantic summary, and the periodic score. The connecting edges between the graph nodes are established according to the control order, and the edge weight can represent the control connection delay or the function transfer amplitude.
[0075] The control mutation identification module constructs a behavior sequence diagram structure according to the account operation map, and identifies behavioral style break segments as control mutation candidate segments.
[0076] Based on the parameters set for the lease monitoring cycle (e.g., a 7-day, 14-day, or 30-day monitoring window), the analysis time range is determined, and the account operation graphs within this range are processed. The system sorts the nodes in the operation graph by timestamp and sets division rules based on the time intervals between consecutive control behaviors. The division rules determine control segments based on a time sliding window and a minimum duration constraint. If the time interval between any two graph nodes exceeds the set maximum control behavior gap threshold (e.g., 30 minutes), the system demarcates them as the dividing point between two consecutive control segments. Once the division is complete, the system generates several chronologically ordered behavior control segments for each account within the monitoring cycle. Each control segment is identified as a "graph behavior node." The system assigns a unique ID to each node and records metadata such as its start and end times, the number of original control instructions contained, the composition structure of the main function tags, and the average operation rhythm.
[0077] After completing the division of the account graph node set, this embodiment continues to perform the behavior structure difference analysis operation, with the goal of identifying the structural break position where the behavior style has significantly mutated at the node level, thereby extracting the mutation nodes that may exist in the control logic of the account as candidates for style break fragments. Taking the account graph node set as the input object, the structural feature change amplitude between two adjacent nodes is analyzed pair by pair according to the arrangement order of the nodes on the time axis. Between each pair of nodes, the system extracts its control rhythm vector (including the average interval and fluctuation amplitude) and functional path characteristics (path sequence composed of functional label structure), and uses the differential vector calculation formula to quantify the degree of difference between the two. The control rhythm change rate is obtained by calculating the normalized Euclidean distance of the rhythm vectors of the two nodes, reflecting the degree of mutation in the operation rhythm; and the functional path deviation is measured by calculating the miss rate of the functional labels of the two nodes in the standard functional instruction set, that is, "the proportion of functional sequences in the current path that do not belong to the previous structural path."
[0078] The difference values of the two dimensions are weighted and combined to construct a structural difference score, which is then output as a structural difference matrix in chronological order. Each cell in this matrix represents the intensity of the structural change between the current node and the previous node. The system further performs a sliding analysis on this difference matrix to form a structural break score sequence (corresponding to structural difference values), with higher scores indicating more dramatic behavioral style changes. To identify key style break locations, the system sets a structural break score rising threshold (based on the score distribution, with the default setting being the average score) as a basis for identifying behavioral mutations. When the structural break score of a node shows a sudden increase relative to the previous node, and the increase exceeds the set threshold (for example, the standardized score difference is greater than 0.5), the system identifies it as a break point where style shift may occur. The control segments corresponding to all such score segments are extracted and labeled as behavioral style break segments, forming a set of candidate mutation structures.
[0079] After marking style break segments in each account's graph, the system further aggregates style mutation information for all bound accounts within the lease monitoring period, constructing a set of candidate control mutation segments for platform-wide lease behavior monitoring. This aggregation is managed by the graph indexing system. The system first uniformly codes the marked style break control segments and creates a ternary index table consisting of account, graph segment, and break score. This index supports searches based on lease contract number, account ID, and device number, and includes the ability to aggregate by time window. Within the set monitoring period, the system extracts all graph control segments marked as "style break" on a per-account basis, with daily granularity as the minimum, and classifies them into a candidate break index pool. When constructing the candidate mutation set, the system records the occurrence time, duration, structural break score, structural differences between the preceding and following segments, and the control process stage in which each break segment occurs. The system also determines whether the break segments are concentrated in certain control modules (such as high-frequency adjustments and key linkages), providing contextual information for subsequent jump behavior identification. The final output set of control mutation candidate segments has dual indexing capabilities of time dimension and structural characteristics, and can retroactively locate the abnormal behavior location of any account within any monitoring period.
[0080] The functional path deviation is analyzed with each control segment as the unit. The granularity of the control segment comes from the graph node constructed in the previous order, which usually represents the control operations that occur continuously within a period of time. All control instructions in the segment are encoded and extracted, and spliced into an operation trajectory sequence in chronological order. This trajectory is regarded as the actual control behavior path and will be used as the calculation object of the functional path deviation. The operation trajectory is then mapped to all standard instruction sequences in the functional tag library and matched one by one. The matching method is a sliding window comparison. The sliding window on the standard path is compared with the operation trajectory to see if the instruction fragments are consistent. If there is a continuous instruction sequence in the operation trajectory that can completely match the fragment in the standard path, the system considers that the fragment has "hit" the standard path; if there is an instruction in the trajectory that fails to match any standard path content, it is judged as a "miss".
[0081] After the mapping is completed, the number of all missed instructions in the control behavior path of this segment is counted and divided by the total number of instructions in this segment to obtain the miss ratio. This ratio is defined as the "functional path deviation degree", which indicates the degree to which the control behavior of this segment deviates from the standard process at the functional path level. The higher the value, the further the segment behavior deviates from the standard operating procedure of the equipment, and there may be unconventional control behavior or changes in the user control logic. In order to enhance the robustness of the indicator, the system introduces a minimum valid instruction number threshold (such as no less than 5 instructions) in the calculation process to avoid abnormally high deviations caused by short-segment behavior. At the same time, if there are matching windows in multiple function label paths, the path with the best hit rate is selected as the benchmark matching object.
[0082] The control deviation screening module performs structured behavior regression matching analysis on the control mutation candidate segment of each bound account mark to screen out non-regressive control path deviation segments.
[0083] For each contract-bound account, within a defined rental monitoring period (e.g., 7 or 30 consecutive days), we extract the control segments marked as "style break segments" in the previous module and convert them into a standard structural feature input format for behavioral regression analysis. These style break segments are derived from node segments in the account's operation graph where the structural break score increases by more than a set threshold, already labeled in the aforementioned graph analysis phase.
[0084] First, the system retrieves the break marker indexes for all graph nodes within the account's monitoring period and performs feature analysis on each style break segment. Specifically, the system extracts the control instruction set corresponding to the break segment and, based on functional label mapping rules, maps the original control instruction encoding into a standard functional label arrangement. This arrangement forms the functional path structure of the break segment, which is used to describe the trajectory of changes in the control semantic direction. Simultaneously, based on the rhythm feature vectors (including the average control interval and the standard deviation of temporal fluctuation) carried in the node structure corresponding to the style break segment, these two types of features together form a structured behavior segment description, which serves as the input template for the break behavior regression determination. To enhance processing efficiency and consistency, the system uniformly normalizes each style break segment to ensure that all control segment features are comparable under the same time scale, label semantic space, and spacing standard. After processing, the break segment is structured and encapsulated as a "set of fragments to be regressed" and stored in a behavioral comparison buffer pool, ready for structural similarity comparison with the account's historical behavioral template.
[0085] To establish a reference model for account control style, this embodiment extracts stable, structurally continuous, and style-free control behavior segments from each account's control behavior sequence during its lease period, using these segments as a "template set" for behavioral regression comparison. These segments are typically located in graph node regions with low scores, high rhythmic consistency, and strong function call path continuity within the graph structure.
[0086] The system uses the previously constructed operational behavior record table and graph node set to select control segments that are unaffected by break markers, have a moderate duration, and cover a wide range of control types. During the extraction process, a rhythm vector is calculated for each segment, and its rhythm standard deviation is verified to not exceed a set threshold (e.g., ≤15% fluctuation). Segments that meet these stability criteria are selected into the template set. Each historical behavior template uses the same structural description as the break segment: a vector pair consisting of a sequence of functional labels and a set of rhythm parameters. The template set can include segments from multiple behavioral cycles and different work task states to fully cover the diversity of the account's operational styles under normal control. The template set is uniformly sorted and numbered, and the average path similarity and rhythm feature difference distribution between each segment within the set are calculated for subsequent selection of the optimal matching template segment. Ultimately, the template set serves as a "historical structural benchmark library" of account control styles, used to compare the behavioral consistency of the current behavior segment to be judged and determine its regressibility.
[0087] The comparison process utilizes a similarity matching algorithm in a two-dimensional feature space, using two metrics: rhythm feature change rate and functional path deviation. The rhythm feature change rate is calculated by calculating the normalized Euclidean distance between the rhythm vector of the current fragment and the rhythm vector of the candidate template. A higher value indicates a more significant deviation from the original control rhythm. The functional path deviation, based on the definition of "standard path miss rate," measures the proportion of control instructions in the fragment that do not match the template path, reflecting whether there has been a fundamental change in its semantic logic. For each fragment, the system selects the template with the highest similarity score as the comparison benchmark. The two metrics are then combined to create a weighted composite value, defined as the "behavior regression offset." This offset numerically measures the degree of interpretability between the current behavior segment and the account's historical control pattern. The system sets a set offset threshold (e.g., 0.6). When the regression offset of a behavior segment exceeds this value, the behavior characteristics are deemed no longer regressable using the existing behavior template and are marked as a "non-regressive control path deviation segment." This mark means that the current behavior segment has deviated from the account control habit and may be completed by a non-original operator, constituting behavioral evidence of an implicit transfer of control rights.
[0088] The risk warning module counts the irregressive control path deviation sections of the bound account within a number of cumulative periods, constructs a control jump distribution sequence, and performs risk warning marking on the rental period corresponding to the jump distribution density peak.
[0089] Based on the non-regressive control path deviation segments identified by the previous module, behavioral trend archiving is performed to identify trends in the stability of an account's control behavior over multiple consecutive monitoring cycles. The platform's configured lease monitoring period is typically 7, 14, or 30 days, covering all behavior records throughout the entire lease period through a fixed sliding window. The system first retrieves records for the bound account identified as "non-regressive control path deviation segments" by the structural regression matching module over the past several (at least two) lease monitoring cycles. Each control segment marked as non-regressive is given a clear time stamp, including its start and end times. A structured sequence of abnormal behavior records is then created, with each record containing at least four pieces of information: the bound account ID, the device number, the start timestamp of the abnormal control segment, and the lease contract number to which it belongs. All records are sorted in ascending timestamp order to form a trajectory of abnormal account control behavior. While creating this sequence, the system excludes duplicated record segments. That is, if a control segment is identified as abnormal in two consecutive cycles, only the record from the cycle in which it was first identified is retained to avoid statistical redundancy. This abnormal record sequence not only has clear chronological order and identity attribution information, but can also be quickly matched to the lease contract period through timestamps, supporting subsequent sliding window aggregation statistics. The system ultimately caches this sequence in a behavioral trend analysis table, providing stable input for subsequent density calculations and risk labeling.
[0090] After completing the construction of the abnormal control record sequence, we continue to conduct sliding time window statistical analysis around behavioral trend identification to determine whether there is a period of concentrated behavioral anomalies during the entire rental period of the account. The goal of this processing stage is to quantify the time domain distribution pattern of behavioral jumps through density analysis to facilitate subsequent risk trend extraction and lease period mapping. The system first sets the sliding time window parameters, such as sliding 1 day per day and setting the window width to 7 days. Throughout the rental period, using the start date of each window as an index, all abnormal record entries that fall within the start and end range of the current window are extracted from the abnormal record sequence. The statistical method is to directly calculate the number of non-regressive control fragments that appear in the time window, without setting weights or performing frequency normalization.
[0091] In order to avoid deviations in the density curve caused by short-term sporadic anomalies, the system compares the anomaly count value of the current window with the average value of the two windows before and after it after each statistics. If the value of the middle window is significantly higher than the previous and next windows, the system will smooth the curve at that point and mark it as a "trend enhancement point" to determine whether there is a trend of periodic risk outbreak. The system combines the number of anomalies in each time window with its corresponding time index into a time-density pair, and organizes the output in the form of a list or chart. Subsequently, the system constructs a behavior jump distribution density curve for the anomaly count values of all time windows through fitting methods (such as local weighted regression or linear interpolation). This curve shows the changing trend of the account's control behavior anomalies throughout the lease period, with time as the horizontal axis and the number of non-regressive segments identified in each time period as the vertical axis, to help determine whether there are segments with intensive behavioral anomalies.
[0092] After completing the construction of the behavior jump density curve, this embodiment continues to analyze the key areas in the curve, identify the peak areas where abnormal behavior density is concentrated, and map these regional time periods to the account rental life cycle to complete the automatic identification of illegal sublease risks and database warning labeling.
[0093] First, traverse the behavior jump distribution density curve and extract the areas where the continuous abnormal frequency is significantly higher than the overall mean. The extraction logic is based on dynamic threshold settings: when the number of abnormal behaviors in a certain time window exceeds twice the overall abnormal average value of the account, the system determines it to be a high-density abnormal segment. If two or more consecutive windows meet this condition at the same time, they will be merged into a "density peak area". Each density peak area has a clear start and end time, and the system aligns the time period with the lease contract period recorded in the lease management database one by one. If the density area is completely covered within a certain lease contract period, the system will add a risk warning field to the contract record with a value of "Concentrated abnormal control behavior exists", and attach additional description fields such as the time period when the abnormal behavior is concentrated and the number of jump behaviors.
[0094] If the density peak area spans multiple contract cycles, the system will mark the risks separately in all relevant contracts and establish an independent lease period abnormal trend chain at the account level for evidence collection or behavior explanation in subsequent leasing behavior audits or dispute resolution.
[0095] Risk warning information is ultimately written to the platform's leasing risk annotation database, where it is indexed alongside the contract number, account ID, and time period. The system also supports automated risk control strategies based on this annotated data, such as issuing risk alerts during contract renewals, triggering secondary identity verification, or initiating backend manual review mechanisms. This enables a closed-loop, system-wide risk identification of illegal subleases.
[0096] The above formulas are all dimensionless and numerical calculations. The formulas are obtained by collecting a large amount of data and performing software simulation to obtain the most recent real situation. The preset parameters and thresholds in the formulas are set by technicians in this field according to actual conditions.
[0097] The above embodiments can be implemented in whole or in part by software, hardware, firmware or any other combination. When implemented using software, the above embodiments can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions or computer programs. When the computer instructions or computer program are loaded or executed on a computer, the process or function described in the embodiment of the present application is generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from one website, computer, server or data center to another website, computer, server or data center via a wired (e.g., infrared, wireless, microwave, etc.) method. The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or data center that contains one or more available media sets. The available medium can be a magnetic medium (e.g., a floppy disk, a hard disk, a tape), an optical medium (e.g., a DVD), or a semiconductor medium. The semiconductor medium can be a solid-state drive.
[0098] Those skilled in the art will appreciate that the modules and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.
[0099] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and modules described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.
[0100] In the several embodiments provided in this application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are merely schematic. For example, the division of the modules is only a logical function division. In actual implementation, there may be other division methods, such as multiple modules or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or modules, which can be electrical, mechanical or other forms.
[0101] The modules described as separate components may or may not be physically separate, and the components shown as modules may or may not be physical modules, and may be located in one place or distributed across multiple network modules. Some or all of the modules may be selected to achieve the purpose of this embodiment according to actual needs.
[0102] In addition, each functional module in each embodiment of the present application may be integrated into one processing module, or each module may exist physically separately, or two or more modules may be integrated into one module.
[0103] If the functions are implemented in the form of software function modules and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art or the part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.
[0104] The above description is merely a specific embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in this application should be included in the scope of protection of this application. Therefore, the scope of protection of this application should be based on the scope of protection of the claims.
[0105] Finally: The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present invention should be included in the scope of protection of the present invention.
Claims
1. A full life cycle monitoring and risk warning system for equipment leasing, characterized by: It includes an account binding module, a graph construction module, a control mutation identification module, a control offset screening module, and a risk warning module, among which: The account binding module extracts the identity information, equipment number, and valid lease period registered in the equipment leasing contract and constructs a contract-bound account set; The graph construction module extracts the control instruction sequence from the control terminal log during the device operation period and generates an operation behavior record table, and constructs an operation graph based on the control instruction sequence of each bound account; The control mutation identification module constructs a behavior sequence graph structure based on the account operation graph and identifies behavioral style break segments as control mutation candidate segments; The control shift screening module performs structured behavioral regression matching analysis on the control mutation candidate segments of each bound account tag to screen out irregressive control path shift segments; The risk warning module counts the irregressive control path deviation segments of bound accounts within several cumulative periods, constructs a control jump distribution sequence, and issues risk warning marks for the rental period corresponding to the jump distribution density peak.
2. A full life cycle monitoring and risk warning system for equipment leasing according to claim 1, characterized in that: The account binding module extracts the identity information, device number, and valid lease period registered in the equipment lease contract and constructs a contract-bound account set, specifically including: Parse the lease contract text records in the database and extract the lease identity information, equipment number, and lease start and end time fields; Perform a two-way binding mapping between the operator account and the device number, and divide the binding mapping relationship into valid and invalid lease periods based on the lease start and end time fields; Eliminate the associated records within the non-valid period of the lease, retain the records where the current operating time of the device coincides with the lease period, and build a contract-bound account set.
3. The full life cycle monitoring and risk warning system for equipment leasing according to claim 1 is characterized in that: The graph construction module extracts the control instruction sequence in the control terminal log during the device operation period and generates an operation behavior record table. The operation graph is constructed based on the control instruction sequence of each bound account, specifically including: Filter the log data from the control end log records that match the device number in the contract binding account set, and extract the original log entry set containing the binding account, control command and timestamp; Format the bound account, control instruction, and corresponding timestamp in each log into triples and mark them as structured control behavior units. Sort the structured control behavior units in ascending order by timestamp, generate the account-level control instruction time series, and establish an operation behavior record table; Perform behavioral rhythm analysis on the control instruction sequence of each bound account, and construct an operation map based on the average interval between instructions, function call sequence, and cycle stability.
4. The full life cycle monitoring and risk warning system for equipment leasing according to claim 3 is characterized in that: The behavioral rhythm analysis of the control instruction sequence of each bound account and the construction of an operation map based on the average interval between instructions, function call sequence and cycle stability specifically include: Extract the control instruction sequence corresponding to the bound account from the operation behavior record table, and calculate the time interval difference sequence between any two adjacent instructions; The interval difference sequence is used as a rhythm parameter group, and the mean and standard deviation of the rhythm parameter group are calculated as the time distribution of the operation interval, and output as the bound account control rhythm vector; Setting a control instruction sequence of a function label, mapping the operation trajectory of the continuous control instruction to a standard control instruction sequence corresponding to a predefined function label in the control instruction coding space, and obtaining a function label arrangement; Identify recurring functional tag arrangements and extract duplicate segments using a sequence similarity matching method based on the longest common prefix; The interval period of repeated segments is counted, and a period stability index is constructed based on the mean value of the interval offset of each occurrence position on the time axis; The rhythm vector, function label arrangement and periodic stability index of the account dimension are integrated into combined features, and the operation graph of bound accounts is constructed based on the combined features as the graph node structure unit.
5. The full life cycle monitoring and risk warning system for equipment leasing according to claim 1 is characterized in that: The control mutation identification module constructs a behavior sequence diagram structure according to the account operation map and identifies behavioral style break segments as control mutation candidate segments, specifically including: During the set rental monitoring period, the operation graph of the bound account is divided into set continuous control segments according to the time series to generate the account behavior graph node set; In each account behavior map node set, a structural difference matrix is constructed based on the rhythm feature change rate and functional path deviation between adjacent nodes, and a structural break score sequence is generated; Extract the corresponding control segments whose score increase exceeds the set threshold from the structural fracture score sequence, and mark the behavioral style fracture segments; Summarize the style break fragment indexes corresponding to all bound accounts within the set rental monitoring period and establish a set of control mutation candidate segments.
6. The full life cycle monitoring and risk warning system for equipment leasing according to claim 5 is characterized in that: The functional path deviation refers to mapping the operation trajectory composed of continuous control instructions in each control segment to the standard control instruction sequence corresponding to the predefined function label in the control instruction encoding space, and counting the proportion of instructions that were not hit during the mapping process.
7. The full life cycle monitoring and risk warning system for equipment leasing according to claim 1 is characterized in that: The control deviation screening module performs structured behavioral regression matching analysis on the control mutation candidate segments of each bound account tag, and screening the irregressible control path deviation segments specifically includes: Extract the set of style-fragmented segments marked for each account within the set rental monitoring period and parse them into functional label sequences and rhythm feature vectors of the control segments; Extract stable control period behavior segments from the account's historical operation logs and construct a set of behavior templates consisting of function label sequences and rhythm features. Compare each style break segment with the behavior template set in turn, calculate the rhythm feature change rate and functional path deviation between the current style break segment and the matching template, and form the behavior regression offset; The fragment segments whose regression offset exceeds the set threshold are filtered and marked as non-regressive control path offset segments.
8. The full life cycle monitoring and risk warning system for equipment leasing according to claim 1 is characterized in that: The risk warning module counts the irregressive control path deviation segments of the bound account within a number of cumulative periods, constructs a control jump distribution sequence, and performs risk warning marking on the rental period corresponding to the jump distribution density peak. Specifically, the module includes: Extract all irreversible control path offset segments marked by the bound account within several consecutive set rental monitoring periods and generate a sequence of abnormal control records with timestamps; The abnormal control record sequence is statistically analyzed in a time window sliding manner, the number of non-regressive segments in each window is calculated, and the behavior jump distribution density curve is constructed; Identify the density peak area in the behavior jump distribution density curve, align the density peak area with the rental life cycle corresponding to the bound account, and mark the illegal sublease risk warning mark in the database.
Citation Information
Cited By
Internet of Things security management system based on behavior analysis
CN121619137A
Rental state monitoring method and equipment for operational assets, and medium
CN122089446A