Risk assessment method and system based on customer key data

The customer risk assessment method based on multi-terminal data cleaning and multi-dimensional feature analysis solves the problems of singleness and lack of adaptability of traditional assessment methods, realizes real-time dynamic monitoring of customer behavior and accurate identification of fraud risks, and ensures transaction security.

CN120765248APending Publication Date: 2025-10-10CHENGZHISHU TECH (SHENZHEN) CO LTD
View PDF 0 Cites 3 Cited by

Patent Information

Application Number
CN202510740948.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-05
Publication Date
2025-10-10

AI Technical Summary

Technical Problem

Traditional customer risk assessment methods are based on single-dimensional data and are unable to fully capture the complex characteristics and potential risk factors of customer behavior. They also lack flexibility and adaptability, making it difficult to cope with complex and changing transaction environments and new fraud methods.

Method used

By obtaining customers' multi-terminal identity authentication data, multi-platform transaction behavior data and device interaction logs, we perform data cleaning and feature extraction, build multi-dimensional behavioral feature parameters, use multi-channel data association technology for real-time verification and anomaly assessment, and generate behavioral anomaly indicators to determine fraud risks.

Benefits of technology

It has achieved improvements in the accuracy, real-time nature and comprehensiveness of customer risk assessment, enabling timely detection of potential fraud risks and ensuring transaction security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120765248A_ABST
    Figure CN120765248A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of customer risk assessment, and discloses a risk assessment method and system based on customer key data, and the method comprises the steps: obtaining and cleaning customer identity verification, transaction behaviors and equipment interaction log data; analyzing the cleaned data to generate multi-dimensional behavior characteristic parameters, and constructing a risk assessment reference model; performing real-time verification on customer behavior data according to the model, and quantitatively evaluating abnormal matching of an operation instruction and a transaction record; and generating a behavior anomaly index according to a verification result, and judging a fraud risk. The system comprises a multi-source data integration module, a feature modeling module, a behavior verification module and a risk judgment module, and comprehensive risk assessment of customer transaction behaviors is realized. According to the invention, multi-source data can be comprehensively integrated, risks can be accurately assessed in real time, and transaction security is effectively guaranteed.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of customer risk assessment, in particular to a risk assessment method and system based on customer key data. BACKGROUND

[0002] In the current rapid development of digital economy, various types of transaction activities are increasingly frequent and transaction forms are becoming more diversified, and customer transaction risk assessment has become a key link to ensure the safe and stable operation of financial institutions, enterprises and transaction platforms. Traditional customer risk assessment methods are mostly based on single-dimensional data or simple rules for judgment, such as relying only on customer credit history records or transaction amount to assess risk. This approach has obvious limitations and cannot fully capture the complex characteristics and potential risk factors of customer behavior.

[0003] On the one hand, single-dimensional data cannot reflect the full picture of customer behavior. For example, credit history records only reflect the customer's past performance in credit, but cannot cover the dynamic changes in customer's current transaction behavior patterns, device usage, and transaction environment. When a customer's transaction behavior is affected by external factors and shows abnormal fluctuations, an assessment method that relies solely on credit history records cannot detect risks in a timely manner, leading to misjudgment. On the other hand, the assessment method based on simple rules lacks flexibility and adaptability. Market conditions are constantly changing, and customers' transaction habits and fraud methods are also evolving, making it difficult for fixed assessment rules to cope with complex and changing risk scenarios. For example, when faced with new types of online fraud, traditional rules may not be able to identify abnormal characteristics, making risk assessment ineffective.

[0004] With the development of big data and artificial intelligence technologies, although some enterprises have begun to try to use multi-source data for risk assessment, there are still many problems in actual application. Existing technologies are not fine enough in data processing, integration and cleaning of multi-source data. Different sources of data formats, quality is uneven, if the missing values, noise and sensitive information in the data cannot be effectively processed, it will lead to deviation of the subsequent analysis results. In the feature extraction link, the potential features in the data cannot be fully mined, and the evaluation model reflecting the risk of customer behavior cannot be accurately constructed. Moreover, the existing risk assessment model performs poorly in real-time and dynamic adaptability, making it difficult to monitor and dynamically assess customer behavior in real time, and unable to timely detect and warn potential fraud risks. Therefore, there is an urgent need for a method and system that can fully integrate multi-source data, deeply analyze customer behavior characteristics, and achieve real-time and accurate risk assessment to meet the risk prevention and control needs in the current complex and changing transaction environment. SUMMARY

[0005] The present application aims to provide a risk assessment method and system based on customer key data to solve the problems raised in the background.

[0006] To achieve the above object, the application provides the following technical scheme: a risk assessment method and system based on customer key data, the method comprising:

[0007] S1: obtaining identity verification data, transaction behavior data and device interaction logs of a customer, and performing data cleaning on the identity verification data, transaction behavior data and device interaction logs;

[0008] S2: analyzing the cleaned data to generate multi-dimensional behavior feature parameters, selecting features according to the multi-dimensional behavior feature parameters to form a feature vector set, and constructing a risk assessment benchmark model according to the feature vector set;

[0009] S3: verifying the customer behavior data in real time according to the risk assessment benchmark model, identifying the time sequence correlation between operation instructions and transaction records by using multi-channel data correlation technology, and quantitatively evaluating the abnormal matching of operation instructions and transaction records;

[0010] S4: generating a behavior abnormality index according to the verification result of the risk assessment benchmark model, and determining whether there is a fraud risk according to the behavior abnormality index.

[0011] Preferably, in S1, the system is preset with a collection frequency, and the multi-terminal identity verification data, multi-platform transaction behavior data and device interaction logs of the customer in a preset time period are obtained; the identity verification data includes biometric recognition records and password verification frequency; the transaction behavior data includes transaction amount distribution and payment channel switching frequency; the device interaction log includes device geographic location offset and operation response delay; the identity verification data, transaction behavior data and device interaction log are subjected to data cleaning, which includes data desensitization, missing value filling, noise filtering and standardization processing; the identity verification data is cleaned to generate an identity verification feature sequence, and the transaction behavior data is cleaned to generate a transaction feature sequence; the identity verification feature sequence and the transaction feature sequence of different terminals are spatiotemporally associated to form a multi-source behavior feature set.

[0012] Preferably, in S2, the following steps are included:

[0013] S201: extracting time sequence feature parameters from the cleaned identity verification feature sequence, transaction feature sequence and device interaction log, respectively, the time sequence feature parameters including transaction frequency coefficient of variation, IP address variation rate and operation dispersion, and combining each time sequence feature parameter according to a preset priority to generate multi-dimensional behavior feature parameters;

[0014] S202: setting an adaptive threshold for the multi-dimensional behavior feature parameters in the multi-source behavior feature set, screening feature parameters meeting the threshold range to form an initial feature vector set, and excluding feature parameters exceeding the threshold range;

[0015] S203: Cross-terminal correlation analysis is performed on each feature parameter in the initial feature vector set, deviation degrees of the feature parameters in different terminals in the same event period are extracted, standard deviations of the deviation degrees are calculated, and are marked as inter-terminal difference parameters;

[0016] S204: The inter-terminal difference parameters are compared with a preset difference threshold, feature parameters exceeding the difference threshold are screened and added to a risk assessment benchmark model, and operation response delay mutation features are supplemented to the risk assessment benchmark model according to the device interaction log.

[0017] Preferably, in S3, the quantitative assessment on the abnormal matching of the operation instruction and the transaction record comprises the following steps:

[0018] S301: The operation instruction timestamp of the client terminal and the transaction record generation timestamp are captured in real time, the time interval difference between the two is calculated, and if the time interval difference exceeds a preset reasonable range, it is determined as an abnormal timing event;

[0019] S302: The number of abnormal timing events in a preset period is counted and recorded as N, and the operation response delay fluctuation amplitude in the device interaction log is synchronously obtained and recorded as ΔT;

[0020] S303: According to the correlation between the number of abnormal timing events N and the operation response delay fluctuation amplitude ΔT, a timing abnormality index is generated by using a nonlinear function mapping, wherein the product component and the ratio component of N and ΔT are generated by superposition operation to generate a comprehensive evaluation value;

[0021] If the timing abnormality index exceeds a preset risk threshold, a fraud suspicion mark is triggered.

[0022] Preferably, in S4, the verification results of the risk assessment benchmark model in the same customer historical behavior data are extracted, the deviation values of each benchmark model are weighted and accumulated to generate a behavior abnormality index, and if the behavior abnormality index continuously exceeds a preset trigger number, it is determined that there is a fraud risk.

[0023] Preferably, the application also includes a risk assessment system based on customer key data, which is applied to the risk assessment method based on customer key data described above, and the system comprises a multi-source data integration module, a feature modeling module, a behavior verification module and a risk judgment module.

[0024] The multi-source data integration module is used to obtain the identity verification data, transaction behavior data and device interaction log of the customer and perform data cleaning;

[0025] The feature modeling module is used to analyze the cleaned data to generate multi-dimensional behavior feature parameters and construct a risk assessment benchmark model;

[0026] The behavior verification module is used for real-time verification of the customer behavior data according to a risk assessment benchmark model, and abnormal matching of the operation instruction and the transaction record is evaluated.

[0027] The risk judgment module is used for generating a behavior abnormality index and judging a fraud risk.

[0028] Preferably, the multi-source data integration module comprises an identity collection unit and a transaction collection unit.

[0029] The identity collection unit is used for collecting multi-terminal biological feature recognition records and password verification data of the customer.

[0030] The transaction collection unit is used for acquiring multi-platform transaction amount distribution data and payment channel switching records.

[0031] Preferably, the feature modeling module comprises a feature calculation unit and a model construction unit.

[0032] The feature calculation unit is used for extracting transaction frequency variation coefficient, IP address variation rate and time sequence dispersion feature parameters from the cleaned data.

[0033] The model construction unit is used for screening feature parameters meeting a threshold range and supplementing operation response delay mutation features to the risk assessment benchmark model.

[0034] Preferably, the behavior verification module comprises a time sequence monitoring unit and an abnormality calculation unit.

[0035] The time sequence monitoring unit is used for detecting time interval difference values of the operation instruction and the transaction record and identifying abnormal time sequence events.

[0036] The abnormality calculation unit is used for calculating a time sequence abnormality index in combination with operation response delay fluctuation amplitude.

[0037] Preferably, the risk judgment module comprises an abnormality degree generation unit and a judgment unit.

[0038] The abnormality degree generation unit is used for weighted accumulation of deviation values of the risk assessment benchmark model.

[0039] The judgment unit is used for judging a fraud risk according to a continuous over-limit number of the abnormality index.

[0040] Compared with the prior art, the present application has the following beneficial effects:

[0041] The risk assessment method and system based on customer key data provided by the application effectively improve the accuracy, real-time performance and comprehensiveness of customer risk assessment from multiple aspects. In data collection and processing, the system pre-set acquisition frequency to obtain customer multi-terminal identity verification data, multi-platform transaction behavior data and device interaction logs. Through a comprehensive and detailed data cleaning process, including data desensitization, missing value filling, noise filtering and standardization processing, the safety and integrity of the data are guaranteed, and different sources of data can be unified and standardized, laying a solid foundation for subsequent analysis. The identity verification feature sequence and transaction feature sequence of different terminals are spatiotemporally associated to form a multi-source behavior feature set, which fully integrates multi-dimensional data information. Compared with the traditional single data source evaluation method, the customer behavior characteristics can be more comprehensively presented.

[0042] In the feature analysis and model construction aspect, a plurality of time sequence feature parameters are extracted from the cleaned data, and a plurality of dimensional behavior feature parameters are formed by combination according to a preset priority, and then a risk assessment benchmark model is accurately constructed through adaptive threshold screening and cross-terminal association analysis. This method fully excavates the potential risk characteristics in the data, so that the model can more accurately reflect the normal behavior pattern of the customer, and compared with the model constructed by traditional simple rules or limited features, the abnormal changes of the customer behavior can be more sensitively captured, and the accuracy of risk assessment is greatly improved.

[0043] In the real-time verification and risk determination link, the time stamps of the customer terminal operation instructions and the transaction record generation time stamps are monitored in real time, combined with the operation response delay fluctuation amplitude in the device interaction log, and a time sequence anomaly index is generated by using a nonlinear function mapping, so that the real-time dynamic monitoring of the customer behavior is realized. When the behavior abnormality degree index continuously exceeds the preset trigger number of times, it is determined that there is a fraud risk. This risk determination method based on multi-dimensional data association analysis and dynamic index calculation can timely discover potential fraud risks, and compared with the traditional lag or single index risk determination method, the real-time performance and accuracy are significantly improved. At the same time, the risk assessment system constructed by the application has clear division of labor and close cooperation from data collection and integration to risk determination to form a complete closed loop, which provides an efficient and reliable solution for customer risk assessment, can effectively reduce transaction risks and protect transaction safety, and has high practical value and application prospect. BRIEF DESCRIPTION OF DRAWINGS

[0044] Fig. 1 The working principle diagram of the risk assessment method and system based on customer key data described in the application;

[0045] Fig. 2 The design diagram of the multi-source data integration module;

[0046] Fig. 3 The design diagram of the feature modeling module. DETAILED DESCRIPTION

[0047] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.

[0048] See also Figs. 1-3 The present invention relates to a risk assessment method and system based on customer key data, and the specific implementation steps are as follows:

[0049] Step S1: Based on a preset collection frequency, obtain the customer's multi-terminal identity authentication data, multi-platform transaction behavior data, and device interaction logs within a preset time period. Identity authentication data includes biometric identification records and password verification frequency, transaction behavior data includes transaction amount distribution and payment channel switching frequency, and device interaction logs include device geographic location offset and operation response delay. After acquiring the data, it undergoes data cleaning, which includes data desensitization, missing value filling, noise filtering, and standardization. After cleaning, identity authentication data generates an identity authentication feature sequence, and transaction behavior data generates a transaction feature sequence. The identity authentication feature sequences and transaction feature sequences of different terminals are then temporally and spatially correlated to form a multi-source behavior feature set.

[0050] Step S2: Extract time series feature parameters, such as transaction frequency coefficient of variation, IP address change rate, and operation discreteness, from the cleaned authentication feature sequence, transaction feature sequence, and device interaction log. Combine each time series feature parameter according to the preset priority to generate multi-dimensional behavioral feature parameters. Set an adaptive threshold for the multi-dimensional behavioral feature parameters in the multi-source behavioral feature set, filter out feature parameters that meet the threshold range, form an initial feature vector set, and exclude feature parameters that exceed the threshold range. Perform cross-terminal correlation analysis on each feature parameter in the initial feature vector set, extract the deviation of feature parameters in different terminals within the same event cycle, calculate the standard deviation of the deviation, and mark it as the inter-terminal difference parameter. Compare the inter-terminal difference parameter with the preset difference threshold, filter out feature parameters that exceed the difference threshold and add them to the risk assessment benchmark model. Supplement the operation response delay mutation feature to the risk assessment benchmark model based on the device interaction log.

[0051] Step S3: Real-time verification of customer behavior data according to the constructed risk assessment benchmark model. Capture the timestamp of the customer terminal operation instruction and the timestamp of the transaction record generation in real time, calculate the time interval difference between the two, and if the time interval difference exceeds the pre-set reasonable range, it is determined as an abnormal timing event. Count the number of abnormal timing events in the pre-set period as N, and simultaneously obtain the operation response delay fluctuation amplitude in the device interaction log as AT. According to the correlation between the number of abnormal timing events N and the operation response delay fluctuation amplitude AT, a non-linear function mapping is used to generate a timing anomaly index, wherein the product component and the ratio component of N and AT are generated by superposition operation to generate a comprehensive evaluation value, and if the timing anomaly index exceeds the pre-set risk threshold, a fraud suspicion flag is triggered.

[0052] Step S4: Extract the verification results of the risk assessment benchmark model in the same customer historical behavior data, and generate a behavior anomaly index by weighted accumulation of the deviation value of each benchmark model. If the behavior anomaly index continuously exceeds the pre-set trigger number, it is determined that there is a fraud risk.

[0053] The application will be further described in conjunction with Examples 1 to 5:

[0054] Example 1:

[0055] In the data collection and cleaning link, first, according to the pre-set collection frequency, the customer data is continuously and comprehensively acquired. The setting of the collection frequency is based on the comprehensive consideration of the customer's transaction behavior and operation habit, to ensure that effective data can be captured in time, and at the same time, the system burden or the interference to the customer caused by too frequent collection is avoided. For example, for high-frequency trading customers, the collection frequency can be set to once every 5 minutes, and for low-frequency trading customers, the collection frequency can be set to once every 30 minutes.

[0056] In the aspect of multi-terminal identity verification data collection, through the establishment of a secure data transmission channel with multiple terminal devices, the customer's biological feature recognition record and password verification frequency are obtained. For biological feature recognition records, different terminal devices may support different biological recognition technologies, such as smart phones may support fingerprint recognition, facial recognition, while computer devices may support fingerprint recognition or iris recognition. The system will call the corresponding biological recognition interface according to the type of terminal device, real-time acquire the biological feature data of the customer when performing identity verification, and record the time, location, etc. information of each identification. The collection of password verification frequency is through monitoring the customer's operation of inputting password for identity verification on each terminal, recording the number of password input, the time interval of each input, etc. information. At the same time, the system will preliminarily format the data to ensure the consistency of the data in subsequent processing.

[0057] The collection of multi-platform transaction behavior data involves interfacing with multiple transaction platforms. By signing a data interface agreement with each transaction platform, the system obtains data such as transaction amount distribution and payment channel switching frequency according to the agreed data format and transmission rules. When obtaining transaction amount distribution data, the system receives the transaction amount information of each transaction sent by the transaction platform in real time and stores it in chronological order. For payment channel switching frequency data, the system monitors the customer's operation of switching from one payment channel to another during the transaction process, records the number of switches, the types of payment channels before and after the switch, and the time points of the switch, etc. To ensure the accuracy and integrity of the data, the system checks the collected transaction behavior data, such as whether the transaction amount is within the normal numerical range and whether the payment channel switching operation complies with the rules of the transaction platform.

[0058] The collection of device interaction logs mainly relies on the lightweight data collection program installed on the customer's terminal device. This program records information such as device geographic position offset and operation response delay in real time without affecting the customer's normal use of the device. The device geographic position offset is obtained through the positioning function of the terminal device, such as GPS or base station positioning. The program periodically obtains the device's geographic position coordinates and compares them with the last obtained coordinates to calculate the offset. The operation response delay is recorded by recording the time when the operation instruction is sent and the time when the system returns the response. The time difference between the two is the operation response delay. The collection program encrypts these device interaction log data and uploads them to the system's data storage center regularly.

[0059] After completing data collection, the system enters the data cleaning phase. Data desensitization is an important step to protect customer information security. The system uses various desensitization techniques to process sensitive information in identity verification data. For biometric recognition records, the original biometric data can be replaced with feature values generated by hash operation; for password verification data, the password field is directly encrypted to ensure that even if the data is leaked, others cannot obtain the real password information.

[0060] For missing value filling, the system uses different filling strategies based on the type and characteristics of the data. For time series data, such as transaction amount data over time, if there are missing values, linear interpolation can be used to estimate the size of the missing values based on the transaction amounts at adjacent time points; for categorical data, such as payment channel types, if there are missing values, the mode filling method can be used to fill the missing values with the payment channel type that appears most frequently in the field.

[0061] Noise filtering removes the interference information in the data by setting reasonable threshold and filtering rules. For example, for the device geographic location offset data, if the offset at a certain moment exceeds the normal movement range (such as a large offset of the device geographic location across the city in a short time), it is judged that the data is noise data, which is rejected; for the transaction amount data, if a transaction amount deviates significantly from the normal transaction amount range of the customer, it will also be treated as noise data for processing.

[0062] Standardization processing is mainly to normalize the data of different dimensions and value ranges, so that the data is comparable. For numerical data, such as operation response delay, the minimum-maximum standardization method can be used to map the data to the interval [0, 1]; for non-numerical data, such as payment channel type, unique coding method can be used to convert it into numerical vector form. After the above data cleaning operation, the identity verification data is processed into identity verification feature sequence, and the transaction behavior data is processed into transaction feature sequence. The system further associates the identity verification feature sequence and the transaction feature sequence of different terminals based on time stamp and device identifier and other information, integrates the related data generated at the same time and on the same device, and constructs a complete multi-source behavior feature set, which lays a solid data foundation for subsequent feature analysis and risk assessment model construction based on these data.

[0063] Embodiment 2:

[0064] In the feature parameter processing and model construction link, based on the identity verification feature sequence, transaction feature sequence and device interaction log which have been cleaned, the extraction and analysis of feature parameters are carried out. First, professional data mining algorithms are used to deeply analyze various types of data. In extracting the transaction frequency variation coefficient, according to the transaction time information recorded in the transaction feature sequence, the transaction frequency in each time window is counted according to a fixed time window (for example, one day as a time window). Then, for the transaction frequency data of continuous multiple time windows, the fluctuation is analyzed to measure the degree of change of transaction frequency. For example, if a customer's transaction frequency is stable for the first three days in a week, and the transaction frequency starts to fluctuate greatly from the fourth day, the system can analyze the transaction frequency data to obtain the corresponding transaction frequency variation coefficient, and capture the abnormal change trend of the customer's transaction frequency.

[0065] For the calculation of IP address variation rate, the system continuously tracks the IP address information used by the customer when performing transaction or identity verification operations. Each time the customer performs an operation, the system records the IP address corresponding to the operation and compares it with the IP address used in the previous operation. According to a certain time period (such as one month), the number of different IP addresses used by the customer in that period is counted, combined with the total number of operations performed by the customer in that period, and the IP address variation rate is determined through a specific calculation method to reflect the variation of the customer's use of network addresses. If the customer frequently changes IP addresses in different regions within a short period of time to perform transaction operations, a higher IP address variation rate can reflect this abnormal network address usage behavior.

[0066] In terms of determining operation dispersion, the system analyzes the customer's operation behavior based on the operation time, operation type, and other information recorded in the device interaction log. All operations of the customer within a period of time are classified by operation type, and then the distribution of each type of operation in time and space is calculated. For example, for a certain type of transaction operation, the frequency of occurrence at different time periods within a day and the distribution on different device terminals are analyzed to obtain the operation dispersion, which reflects the degree of dispersion of the customer's operation behavior. If the customer is accustomed to performing a specific operation at a fixed time period and on a fixed device, and suddenly there is a significant change in operation time and device, the change in operation dispersion can reflect the change in this operation behavior pattern.

[0067] After extracting the time series characteristic parameters such as transaction frequency variation coefficient, IP address variation rate, and operation dispersion, the system combines these characteristic parameters according to the pre-set priority. The priority is set based on the evaluation of the importance of each type of characteristic parameter in reflecting the customer's risk behavior. For example, in some business scenarios, the transaction frequency variation coefficient may be more critical for identifying fraud risk, so it is given a higher priority; while in other scenarios, the IP address variation rate may be more important, and accordingly it is given a higher weight. Through this priority combination method, multi-dimensional behavior characteristic parameters are formed to comprehensively and comprehensively describe the customer's behavior characteristics.

[0068] For multi-dimensional behavior characteristic parameters in the multi-source behavior characteristic set, the system sets an adaptive threshold. The threshold is not fixed, but is dynamically adjusted according to the overall distribution of the data and business requirements. Through analysis of a large amount of historical data, the system learns the distribution range of the normal customer behavior characteristic parameters, and sets an initial threshold based on this. In the subsequent running process, as new data is continuously accumulated, the system will monitor the changes of the characteristic parameters in real time, and automatically adjust the threshold when significant changes in data distribution are found. Through the adaptive threshold, the system selects the characteristic parameters that meet the requirements to construct an initial feature vector set, and excludes the characteristic parameters that exceed the threshold range, preliminarily filtering out those that obviously do not conform to the normal behavior pattern.

[0069] The system conducts cross-terminal correlation analysis on each characteristic parameter in the initial feature vector set. Taking the same event period (such as a complete transaction process, from the customer initiating a transaction request to the completion of the transaction) as the time range, the characteristic parameter performance of the customer on different terminals (such as mobile phones, computers, tablets, etc.) is compared and analyzed. For example, for the transaction frequency coefficient of variation characteristic parameter, the numerical difference of the parameter of the customer on the mobile phone terminal and the computer terminal is analyzed, and the difference is extracted as the deviation. For the deviation data of each characteristic parameter on different terminals, the standard deviation is calculated to obtain the terminal difference parameter. This parameter can quantify the dispersion degree of the characteristic parameter on different terminals, and reflect the consistency or difference of the customer's behavior performance on different devices.

[0070] Finally, the system compares the terminal difference parameter with the preset difference threshold. The preset difference threshold is also set based on historical data and business experience, and is used to judge whether the difference of the characteristic parameter on different terminals is within the normal range. When the terminal difference parameter exceeds the preset difference threshold, it indicates that the performance of the characteristic parameter on different terminals is significantly abnormal, and the system will include it in the risk assessment benchmark model. In addition, the system will also check the operation response delay data according to the device interaction log, and if it finds that there is an operation response delay mutation, i.e. the operation response delay changes significantly in a short period of time, the system will supplement this operation response delay mutation feature to the risk assessment benchmark model. Through the above series of steps, the risk assessment benchmark model is continuously improved, so that it can more accurately and comprehensively reflect the customer behavior characteristics, and provide a reliable model basis for subsequent accurate assessment of customer transaction risk.

[0071] Embodiment 3:

[0072] In the real-time verification process of customer behavior, the system builds a complete and rigorous monitoring and evaluation system. First, the system will establish an efficient data transmission channel between the customer terminal and the transaction processing system to ensure that the customer terminal operation instruction timestamp and transaction record generation timestamp can be obtained in real time and accurately. These timestamp information is the basic data of the entire verification process, which accurately records the specific time of customer operation behavior and transaction behavior.

[0073] Specifically, when the customer initiates an operation instruction such as payment, transfer, etc. on the terminal device, the terminal device will obtain the current system time at the moment of instruction generation and send it as the operation instruction timestamp to the system monitoring module through a secure data transmission protocol. At the same time, when the transaction processing system receives the operation instruction and completes the relevant processing to generate the transaction record, it will also record the system time at that moment to form the transaction record generation timestamp. The monitoring module of the system continuously monitors the transmission of these two types of timestamp data, and once the data is obtained, it will be immediately processed.

[0074] The system accurately calculates the time interval difference between the operation instruction timestamp and the transaction record generation timestamp, sets the operation instruction timestamp as t1 and the transaction record generation timestamp as t2, and the time interval difference as Δt, then Δt = |t2-t1|. Here, t1 represents the specific time when the customer issues the operation instruction on the terminal device, t2 represents the specific time when the transaction processing system generates the corresponding transaction record, and Δt reflects the length of time from the customer's operation to the generation of the transaction record. The system sets a reasonable time interval range in advance according to the statistical analysis of a large number of normal transaction data combined with the characteristics of different business scenarios. Once the calculated time interval difference Δt exceeds the pre-set reasonable range, the system immediately determines it as an abnormal timing event. For example, in the normal small payment scenario, the time interval from the customer's submission of the payment instruction to the generation of the transaction record is usually within a few seconds, and if the time interval difference of a certain transaction far exceeds this normal range, it will be identified as abnormal.

[0075] The system sets a preset period, which can be flexibly adjusted according to business needs, such as in minutes, hours, or days. Within this preset period, the system continuously monitors and counts the number of abnormal timing events, denoted as N. At the same time, the system obtains the operation response delay fluctuation amplitude from the device interaction log, denoted as ΔT. The device interaction log records in detail the time information from the operation instruction to the system response during each operation of the customer. By analyzing these time information, the system calculates the fluctuation of the operation response delay within the preset period, and thus obtains the operation response delay fluctuation amplitude ΔT. For example, the system can count the response delay of each operation within the preset period, find the maximum and minimum values, and the difference between the two is a simple operation response delay fluctuation amplitude calculation method.

[0076] Based on the correlation between the number of abnormal timing events N and the operation response delay fluctuation amplitude ΔT, the system uses a nonlinear function mapping method to generate a timing anomaly index. Let the timing anomaly index be I, the value of I is determined by the superposition operation of the product component and the ratio component of N and ΔT, and its calculation method can be represented as where f represents a specific nonlinear function relationship. Here, N×ΔT reflects the comprehensive influence degree of the number of abnormal timing events and the operation response delay fluctuation amplitude, the more the number and the greater the fluctuation amplitude, the greater the value of this product component; which reflects the relative relationship between the two from another angle, and is used to more comprehensively characterize abnormal situations. Through this nonlinear function mapping, N and ΔT are converted into a comprehensive evaluation index, the timing anomaly index I.

[0077] The system pre-sets a risk threshold, which is determined comprehensively according to business risk tolerance, the distribution of normal and abnormal situations in historical data, and other factors. When the calculated timing anomaly index I exceeds the preset risk threshold, the system automatically triggers a fraud suspicion mark. Once the mark is triggered, the system will immediately take a series of subsequent measures, such as further manual review of related transactions, suspension of the customer's operation permission for part of the high-risk business, and recording of related abnormal information in the system log for subsequent detailed analysis and tracing. The whole process realizes the timely monitoring and early warning of customer behavior abnormal situations, can timely discover and take measures in the early stage of transaction risk, and effectively safeguards the safety and reliability of transactions.

[0078] Embodiment 4:

[0079] In the behavior abnormality degree index calculation and risk judgment stage, the system is based on the customer historical behavior data, combined with the verification result of the risk assessment benchmark model, to build a dynamic risk judgment mechanism. The following will elaborate the implementation method of this process through specific examples.

[0080] Suppose there is a customer A, who has generated multiple transaction behavior data in the past period of time. The system first retrieves the historical behavior data of customer A from the database, which covers the identity verification data, transaction behavior data and device interaction logs in the previous multiple time periods, and these data have been verified by the risk assessment benchmark model before.

[0081] For the risk assessment benchmark model, it contains evaluation dimensions constructed by various characteristic parameters such as transaction frequency coefficient of variation, IP address change rate, operation dispersion, etc. For each historical verification, the system calculates the deviation value of the actual behavior data of customer A from the corresponding characteristic parameters in the benchmark model. For example, in a certain transaction, the benchmark model sets the normal transaction frequency coefficient of variation to be within the range of 0.1-0.3, while the transaction frequency coefficient of variation of customer A in this transaction is calculated as 0.5, so the deviation value of this characteristic parameter is the difference between 0.5 and the upper limit of the normal range 0.3, i.e. 0.2. Similarly, for IP address change rate, operation dispersion and other characteristic parameters, the deviation value is calculated in a similar manner.

[0082] Next, the system assigns corresponding weights to each benchmark model characteristic parameter according to its importance. In different business scenarios, the importance of each characteristic parameter to risk assessment is different. In a high-risk transaction scenario, the transaction amount distribution characteristic parameter may be more critical, and the system will assign it a higher weight, such as 0.4; while the IP address change rate is relatively less important in this scenario, and is assigned a weight of 0.2; the operation dispersion is assigned a weight of 0.3; the remaining 0.1 weight is allocated to other secondary characteristic parameters.

[0083] Then, the system uses a weighted cumulative method to aggregate these deviation values to generate a behavior anomaly degree index. Continuing with the example of customer A, suppose that in a certain transaction behavior verification, the transaction amount distribution deviation value is 0.1, the IP address change rate deviation value is 0.05, the operation dispersion deviation value is 0.08, and the sum of the deviation values of other secondary characteristic parameters is 0.02. According to the above weight distribution, the behavior anomaly degree index calculation process is as follows: multiply the transaction amount distribution deviation value by its weight 0.4 to get 0.04; multiply the IP address change rate deviation value by the weight 0.2 to get 0.01; multiply the operation dispersion deviation value by the weight 0.3 to get 0.024; multiply the sum of the deviation values of other secondary characteristic parameters by the weight 0.1 to get 0.002. Finally, add these results together, 0.04+0.01+0.024+0.002=0.076, which is the behavior anomaly degree index value of customer A in this transaction behavior.

[0084] The system will continuously monitor the behavior anomaly index of customer A. A trigger number is set in advance, such as 3 times. In subsequent transaction behavior, if the behavior anomaly index of customer A continuously exceeds the pre-set normal range (for example, the normal range is set to within 0.05), and the number of exceedances reaches or exceeds 3 times, the system will determine that customer A has a high probability of fraud risk.

[0085] When the system determines that customer A has a fraud risk, a series of preventive measures will be taken in time. First, the transaction currently being conducted by customer A is intercepted, and the transaction process is suspended to prevent the completion of fraudulent transactions. At the same time, warning information is sent to risk management personnel, including customer A's basic information, transaction details involving risk, behavior anomaly index data, etc., so that risk management personnel can manually review. In addition, the system will also limit customer A's high-risk transaction rights within a certain period of time, such as large amount transfers, payments to unknown accounts, etc., to reduce potential risks. And record the relevant data of this risk determination to the system log, including transaction time, involved feature parameter deviation value, behavior anomaly index calculation process, determination result, etc., to facilitate subsequent risk analysis and traceability, and continuously optimize the risk assessment model and determination strategy.

[0086] For other customers, the system also calculates the behavior anomaly index and determines the risk according to the same process. Through continuous analysis and monitoring of the historical behavior data of each customer, combined with dynamic adjustment of weight distribution and strict determination rules, the system can identify potential fraud risk customers in time, effectively protect transaction security, and maintain transaction order.

[0087] Example 5:

[0088] In the implementation process of the risk assessment system based on customer key data, the multi-source data integration module serves as the basic data acquisition and processing unit of the system. It builds a complete data acquisition system through the identity acquisition unit and the transaction acquisition unit. The identity acquisition unit establishes a secure data transmission channel with various terminal devices used by customers, including but not limited to smartphones, tablets, personal computers, etc. According to the biometric identification technologies supported by different terminal devices, the identity acquisition unit develops corresponding adaptive interfaces. On the smartphone side, it supports fingerprint recognition and facial recognition functions. When the customer uses fingerprint or facial recognition for identity verification, the identity acquisition unit will acquire relevant data in real time during the identification process, such as fingerprint image feature points, facial recognition key point coordinates, etc. At the same time, it records the time, number of attempts, and identification result (success or failure) of each identification. On the personal computer side, if fingerprint recognition or iris recognition is supported, the identity acquisition unit will also follow the established standard process to acquire and record the corresponding biometric identification data. For password verification data, the identity acquisition unit will record the time of password input, the number of password inputs, and the result of password verification. Through detailed recording of these data, a complete set of customer identity verification data is formed.

[0089] The transaction acquisition unit establishes data interface with multiple transaction platforms, including online payment platforms, e-commerce platforms, financial service platforms, etc. Through cooperation with various transaction platforms, the transaction acquisition unit regularly acquires transaction amount distribution data and payment channel switching records according to the agreed time interval and data format. For transaction amount distribution data, the transaction acquisition unit will acquire the specific amount of each transaction, transaction time, transaction type, etc. and classify and organize them according to different time dimensions (such as day, week, month) and transaction types. For payment channel switching records, the transaction acquisition unit will record the switching of payment channels during the transaction process in detail, including the time point of switching, the original payment channel type, the target payment channel type, and the number of switching, etc. After the identity acquisition unit and the transaction acquisition unit acquire the original data, the multi-source data integration module will perform unified cleaning and integration processing on these data, including data desensitization, missing value filling, noise filtering, and standardization processing, etc. to ensure the quality and consistency of the data.

[0090] The feature modeling module undertakes the important task of extracting key features from the cleaned data and constructing a risk assessment benchmark model throughout the system. The feature calculation unit uses a variety of professional data mining algorithms to conduct in-depth analysis on the cleaned identity verification feature sequence, transaction feature sequence, and device interaction log. When extracting the transaction frequency coefficient of variation, the feature calculation unit first divides the transaction data according to the time window, then counts the number of transactions in each time window, and calculates the transaction frequency coefficient of variation by analyzing the fluctuation of transaction frequency between different time windows, to measure the degree of change in customer transaction frequency. For the calculation of IP address change rate, the feature calculation unit tracks the IP address used by the customer each time, records the change of IP address, and calculates the IP address change rate combined with the transaction frequency, reflecting the stability of the customer's use of network address. The calculation of operation dispersion is based on the operation behavior data of the customer on different devices, analyzing the distribution of operation time, operation type and other factors, to obtain the operation dispersion, reflecting the dispersion degree of customer operation behavior.

[0091] The model construction unit further processes the multi-dimensional behavior feature parameters after the feature calculation unit extracts various time series feature parameters. The model construction unit sets an adaptive threshold for each feature parameter, which is not fixed but dynamically adjusted according to the distribution of data and business requirements. Through this adaptive threshold, the model construction unit filters out the required feature parameters, constructs an initial feature vector set, and excludes feature parameters that exceed the threshold range. The model construction unit also conducts cross-terminal correlation analysis on each feature parameter in the initial feature vector set, extracts the deviation degree by comparing the performance of feature parameters in different terminals within the same event period, and calculates the standard deviation of the deviation degree to obtain the inter-terminal difference parameter. Compare the inter-terminal difference parameter with the preset difference threshold, and include the feature parameters that exceed the difference threshold in the risk assessment benchmark model. The model construction unit will supplement the operation response delay mutation feature according to the device interaction log, and perfect the risk assessment benchmark model, so that it can more accurately reflect the customer behavior characteristics.

[0092] The behavior verification module is a key link for the system to realize real-time risk monitoring, and works in cooperation with the time sequence monitoring unit and the abnormality calculation unit. The time sequence monitoring unit keeps real-time data interaction with the client terminal and the transaction processing system, and captures the time stamp of the operation instruction of the client terminal and the time stamp of the generation of the transaction record in real time. By accurately calculating the time interval difference between the two time stamps, the time sequence monitoring unit can timely discover abnormal time sequence events. The time interval difference outside the preset reasonable time range will be determined by the time sequence monitoring unit as an abnormal time sequence event, and will be recorded and counted. After the time sequence monitoring unit counts the number of abnormal time sequence events N in the preset period, the abnormality calculation unit synchronously obtains the operation response delay fluctuation amplitude ΔT from the device interaction log. Based on the correlation between the two parameters, the abnormality calculation unit generates a time sequence abnormality index by using a nonlinear function mapping method. In this process, the abnormality calculation unit will comprehensively consider the product component and the ratio component of N and ΔT, and obtain a comprehensive evaluation value through superposition operation to determine the time sequence abnormality index. When the calculated time sequence abnormality index exceeds the preset risk threshold, the abnormality calculation unit will automatically trigger a fraud suspicion mark to provide a basis for subsequent risk processing.

[0093] The risk judgment module, as the final decision unit of the system, realizes accurate judgment of fraud risk through the abnormality degree generation unit and the judgment unit. The abnormality degree generation unit extracts the verification results of the risk assessment benchmark model in the historical behavior data of the same client, and according to the deviation value of each benchmark model, gives a corresponding weight according to its importance. The abnormality degree generation unit will add up the weighted deviation values to generate a behavior abnormality degree index. This behavior abnormality degree index comprehensively reflects the deviation degree of the current behavior of the client from the historical behavior pattern. The judgment unit will continuously monitor the behavior abnormality degree index, and when the index exceeds the preset trigger number continuously, the judgment unit will consider that the behavior of the client has a high abnormal probability, and thus determine that there is a fraud risk. Once it is determined that there is a fraud risk, the system will immediately start the corresponding preventive measures, such as limiting the transaction rights of the client, conducting manual review, etc., to ensure the safety of the transaction. Through the close cooperation and data flow between the modules, the entire risk assessment system realizes comprehensive, real-time and accurate risk assessment of the transaction behavior of the client.

[0094] It should be noted that, in this text, relational terms such as first and second are used merely to distinguish one entity or action from another, and do not necessarily require or imply that there is any such actual relationship or order between these entities or actions. Moreover, the terms "include", "contain" or any other variant thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements, but also includes other elements not explicitly listed or inherent to such process, method, article or device.

[0095] While embodiments of the application have been shown and described, it is to be understood that the application is not limited to the details of the embodiments described, since numerous changes, modifications, substitutions and alterations can be made thereto without departing from the spirit and scope of the application as defined by the appended claims and their equivalents.

Claims

1. A risk assessment method based on customer key data, characterized in that: The method comprises the following steps: S1: Obtain the customer's identity authentication data, transaction behavior data, and device interaction logs, and perform data cleansing on the identity authentication data, transaction behavior data, and device interaction logs; S2: Analyze the cleaned data to generate multi-dimensional behavioral characteristic parameters, perform feature selection based on the multi-dimensional behavioral characteristic parameters to form a feature vector set, and build a risk assessment benchmark model based on the feature vector set; S3: Validate customer behavior data in real time based on a risk assessment benchmark model, utilize multi-channel data association technology to identify the temporal correlation between operation instructions and transaction records, and perform quantitative assessments of abnormal matches between operation instructions and transaction records. S4: Generate a behavior abnormality index based on the verification results of the risk assessment benchmark model, and determine whether there is a fraud risk based on the behavior abnormality index.

2. The risk assessment method based on customer key data according to claim 1, characterized in that: In S1, the system presets the collection frequency and obtains the customer's multi-terminal identity authentication data, multi-platform transaction behavior data and device interaction logs within a preset time period; the identity authentication data includes biometric identification records and password verification frequency; the transaction behavior data includes transaction amount distribution and payment channel switching frequency; the device interaction log includes device geographic location offset and operation response delay; the identity authentication data, transaction behavior data and device interaction log are cleaned, and the data cleaning includes data desensitization, missing value filling, noise filtering and standardization processing; After the identity authentication data is cleaned, an identity authentication feature sequence is generated. After the transaction behavior data is cleaned, a transaction feature sequence is generated. The identity authentication feature sequences and transaction feature sequences of different terminals are temporally and spatially associated to form a multi-source behavior feature set.

3. The risk assessment method based on customer key data according to claim 2, characterized in that: In S2, the following steps are included: S201: Extracting time series feature parameters from the cleaned identity authentication feature sequence, transaction feature sequence, and device interaction log. The time series feature parameters include transaction frequency variation coefficient, IP address change rate, and operation dispersion. Each time series feature parameter is combined according to a preset priority to generate a multi-dimensional behavior feature parameter. S202: Setting an adaptive threshold for the multi-dimensional behavior feature parameters in the multi-source behavior feature set, screening feature parameters that meet the threshold range to form an initial feature vector set, and excluding feature parameters that exceed the threshold range; S203: Perform cross-terminal correlation analysis on each characteristic parameter in the initial characteristic vector set, extract the deviation of the characteristic parameters in different terminals within the same event period, calculate the standard deviation of the deviation and mark it as the inter-terminal difference parameter; S204: Compare the difference parameters between the terminals with a preset difference threshold, select characteristic parameters that exceed the difference threshold and add them to the risk assessment benchmark model, and supplement the operation response delay mutation characteristics to the risk assessment benchmark model based on the device interaction log.

4. The risk assessment method based on customer key data according to claim 3, characterized in that: In S3, quantitative evaluation of abnormal matching between operation instructions and transaction records includes the following steps: S301: Capture the timestamp of the client terminal operation instruction and the timestamp of the transaction record generation in real time, calculate the time interval difference between the two, and determine it as an abnormal time series event if the time interval difference exceeds a preset reasonable range; S302: Count the number of abnormal time series events within a preset period, record it as N, and synchronously obtain the fluctuation amplitude of the operation response delay in the device interaction log, record it as ΔT; S303: Based on the correlation between the number of abnormal timing events N and the fluctuation amplitude of the operation response delay ΔT, a timing anomaly index is generated using a nonlinear function mapping, wherein the product component and the ratio component of N and ΔT are superimposed to generate a comprehensive evaluation value; If the time series anomaly index exceeds the preset risk threshold, a fraud suspicion flag is triggered.

5. The risk assessment method based on customer key data according to claim 4, characterized in that: In S4, the verification results of the risk assessment benchmark model in the historical behavior data of the same customer are extracted, and the deviation values ​​of each benchmark model are weighted and accumulated to generate a behavior abnormality index. If the behavior abnormality index exceeds the preset trigger times continuously, it is determined that there is a fraud risk.

6. A risk assessment system based on customer key data, wherein the system is applied to implement a risk assessment method based on customer key data according to any one of claims 1 to 5, characterized in that: The system includes a multi-source data integration module, a feature modeling module, a behavior verification module, and a risk determination module; The multi-source data integration module is used to obtain customer authentication data, transaction behavior data, and device interaction logs and perform data cleaning; The feature modeling module is used to analyze the cleaned data to generate multi-dimensional behavioral feature parameters and build a risk assessment benchmark model; The behavior verification module is used to verify customer behavior data in real time according to the risk assessment benchmark model and evaluate abnormal matching between operation instructions and transaction records; The risk determination module is used to generate a behavior abnormality index and determine fraud risk.

7. A risk assessment system based on customer key data according to claim 6, characterized in that: The multi-source data integration module includes an identity collection unit and a transaction collection unit; The identity collection unit is used to collect the customer's multi-terminal biometric identification records and password verification data; The transaction collection unit is used to obtain transaction amount distribution data and payment channel switching records of multiple platforms.

8. The risk assessment system based on customer key data according to claim 6, characterized in that: The feature modeling module includes a feature calculation unit and a model building unit; The feature calculation unit is used to extract the transaction frequency variation coefficient, IP address change rate and time series dispersion feature parameters from the cleaned data; The model building unit is used to screen characteristic parameters that meet the threshold range and supplement the operation response delay mutation characteristics to the risk assessment benchmark model.

9. The risk assessment system based on customer key data according to claim 6, characterized in that: The behavior verification module includes a timing monitoring unit and an abnormality calculation unit; The timing monitoring unit is used to detect the time interval difference between the operation instruction and the transaction record and identify abnormal timing events; The anomaly calculation unit is used to calculate the timing anomaly index in combination with the operation response delay fluctuation amplitude.

10. The risk assessment system based on customer key data according to claim 6, characterized in that: The risk determination module includes an abnormality generation unit and a determination unit; The abnormality generation unit is used to perform weighted accumulation on the deviation values ​​of the risk assessment benchmark model; The determination unit is used to determine the fraud risk according to the number of consecutive times that the abnormality index exceeds the limit.

Citation Information

Cited By

  • Terminal security assessment method, system and equipment based on nonlinear mapping technology, and medium

    CN121441645A

  • Personal insurance customer fraud risk assessment method and device based on machine learning correction

    CN121639375A

  • Abnormal behavior identification method based on multi-dimensional data, medium and equipment

    CN122020499A