Data exception monitoring method and device, computer equipment and storage medium
By constructing a graph model and using cluster analysis, the problem of low accuracy in existing insurance fraud detection methods in scenarios with wide distribution and multiple parties involved is solved, enabling automatic identification of abnormal claims and improving the accuracy of insurance fraud detection.
Patent Information
- Application Number
- CN202510845895.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-20
- Publication Date
- 2025-10-31
AI Technical Summary
Existing insurance fraud detection methods have low accuracy when faced with scenarios involving a wide range of claims and multiple parties involved in fraud, making it difficult to accurately distinguish between legitimate claims and fraudulent activities, resulting in a high rate of false positives.
By constructing a graph model, extracting graph features and merging data, cluster analysis is performed based on time series splitting and target clustering algorithms. Preset indicators are used to determine abnormal claim groups and alarm processing is executed.
It enables automatic and accurate identification of duplicate claims, improves the accuracy of fraud risk identification, and enhances the insurance company's prevention capabilities.
Smart Images

Figure CN120873642A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of artificial intelligence technology and can be applied to the fields of fintech and healthcare insurance, particularly to data anomaly monitoring methods, devices, computer equipment, and storage media. Background Technology
[0002] In the insurance industry, duplicate insurance and claims have become a common and covert form of fraud, severely damaging the economic interests of insurance companies and disrupting market order. Currently, the industry's commonly used methods for detecting duplicate claims primarily rely on preset rules. These rules compare currently entered claim information with key fields such as location and amount of historical claims to trigger duplicate claim alerts. However, this rule-based detection method's limitations are becoming increasingly apparent when dealing with specific types of insurance programs.
[0003] Specifically, in scenarios where the insured projects involve a wide range of objects (such as vending machines), traditional rule matching methods often struggle to accurately distinguish between legitimate claims and fraudulent activities due to the dispersed locations of claims, the high similarity of accident causes, and the generally low claim amounts. This leads to a significant increase in the false positive rate. Furthermore, in fraud scenarios involving multiple parties and complex methods, single rule matching is even less capable of comprehensively capturing the characteristics of fraudulent behavior, further reducing the accuracy of detection.
[0004] Therefore, there is an urgent need to develop a new method for detecting insurance fraud to overcome the limitations of existing rule-based detection technologies, improve the accuracy of identifying duplicate insurance and claims, and thus effectively prevent insurance fraud risks and protect the legitimate rights and interests of insurance companies. Summary of the Invention
[0005] The purpose of this application is to provide a data anomaly monitoring method, apparatus, computer equipment, and storage medium to solve the technical problem of low identification accuracy in existing insurance fraud detection methods.
[0006] Firstly, a data anomaly monitoring method is provided, including:
[0007] Obtain claims data within a preset time period;
[0008] Construct a corresponding graph model based on the claims data;
[0009] Feature extraction is performed on the graph model to obtain the corresponding graph features, and the graph features are merged with the compensation case data to obtain the corresponding merged data;
[0010] The merged data is split based on a preset time series to obtain the corresponding target data;
[0011] The target data is clustered based on a preset target clustering algorithm to obtain multiple corresponding cluster groups;
[0012] Based on preset target indicators, index analysis is performed on all the cluster groups to determine whether there are any abnormal claim groups among all the cluster groups;
[0013] If so, execute the alarm processing corresponding to the abnormal claim group.
[0014] Secondly, a data anomaly monitoring device is provided, comprising:
[0015] The acquisition module is used to acquire claims data within a preset time period;
[0016] The construction module is used to build a corresponding graph model based on the compensation case data;
[0017] The processing module is used to extract features from the graph model to obtain corresponding graph features, and to merge the graph features with the compensation case data to obtain corresponding merged data;
[0018] The splitting module is used to split the merged data based on a preset time series to obtain the corresponding target data;
[0019] The clustering module is used to perform cluster analysis on the target data based on a preset target clustering algorithm to obtain multiple corresponding cluster groups;
[0020] The analysis module is used to perform indicator analysis on all the cluster groups based on preset target indicators, and to determine whether there are any abnormal claim groups among all the cluster groups;
[0021] The execution module is used to execute the alarm processing corresponding to the abnormal claim group if the case is found to be abnormal.
[0022] Thirdly, a computer device is provided, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the steps of the above-described data anomaly monitoring method.
[0023] Fourthly, a computer-readable storage medium is provided, which stores a computer program that, when executed by a processor, implements the steps of the above-described data anomaly monitoring method.
[0024] In the above-mentioned data anomaly monitoring method, device, computer equipment, and storage medium, the following steps are taken: First, claim data within a preset time period is acquired; a corresponding graph model is constructed based on the claim data; then, feature extraction is performed on the graph model to obtain corresponding graph features, and the graph features are merged with the claim data to obtain corresponding merged data; subsequently, the merged data is split based on a preset time series to obtain corresponding target data; further, cluster analysis is performed on the target data based on a preset target clustering algorithm to obtain multiple corresponding cluster groups; subsequently, indicator analysis is performed on all cluster groups based on preset target indicators, and it is determined whether there are abnormal claim groups among all cluster groups; if so, alarm processing corresponding to the abnormal claim group is executed. Based on the above processing flow, this application utilizes artificial intelligence technology to identify the acquired claim data to construct a graph model, integrates graph features for cluster analysis, and then analyzes and processes the cluster groups generated by cluster analysis based on the use of target indicators. This enables the automatic and accurate identification of abnormal duplicate claims, effectively improving the accuracy of identifying duplicate claims that may have fraud risks. Attached Figure Description
[0025] To more clearly illustrate the solutions in this application, the accompanying drawings used in the description of the embodiments of this application will be briefly introduced below. Obviously, the accompanying drawings described below are some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0026] Figure 1 This is an exemplary system architecture diagram to which this application can be applied;
[0027] Figure 2 This is a flowchart of an embodiment of the data anomaly monitoring method according to this application;
[0028] Figure 3 This is a schematic diagram of the structure of one embodiment of the data anomaly monitoring device according to this application;
[0029] Figure 4 This is a schematic diagram of the structure of one embodiment of the computer device according to this application. Detailed Implementation
[0030] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this application pertains; the terminology used herein in the specification of the application is for the purpose of describing particular embodiments only and is not intended to be limiting of the application; the terms "comprising" and "having," and any variations thereof, in the specification, claims, and foregoing drawings of this application, are intended to cover non-exclusive inclusion. The terms "first," "second," etc., in the specification, claims, or foregoing drawings of this application are used to distinguish different objects, not to describe a particular order.
[0031] In this document, the term "embodiment" means that a particular feature, structure, or characteristic described in connection with an embodiment may be included in at least one embodiment of this application. The appearance of this phrase in various places throughout the specification does not necessarily refer to the same embodiment, nor is it a separate or alternative embodiment mutually exclusive with other embodiments. It will be explicitly and implicitly understood by those skilled in the art that the embodiments described herein can be combined with other embodiments.
[0032] To enable those skilled in the art to better understand the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings.
[0033] like Figure 1 As shown, system architecture 100 may include terminal device 101, network 102, and server 103. Terminal device 101 may be a laptop 1011, tablet 1012, or mobile phone 1013. Network 102 is used as a medium to provide a communication link between terminal device 101 and server 103. Network 102 may include various connection types, such as wired, wireless communication links, or fiber optic cables, etc.
[0034] Users can use terminal device 101 to interact with server 103 via network 102 to receive or send messages, etc. Various communication client applications can be installed on terminal device 101, such as web browser applications, shopping applications, search applications, instant messaging tools, email clients, social media platform software, etc.
[0035] Terminal device 101 can be various electronic devices with a display screen and support web browsing. In addition to laptops 1011, tablets 1012, or mobile phones 1013, terminal device 101 can also be an e-book reader, an MP3 player (Moving Picture Experts Group Audio Layer III), an MP4 player (Moving Picture Experts Group Audio Layer IV), a laptop computer, and a desktop computer, etc.
[0036] Server 103 can be a server that provides various services, such as a backend server that provides support for the pages displayed on terminal device 101.
[0037] It should be noted that the data anomaly monitoring method provided in this application embodiment is generally executed by a server / terminal device, and correspondingly, the data anomaly monitoring device is generally installed in the server / terminal device.
[0038] It should be understood that Figure 1 The number of terminal devices, networks, and servers shown is merely illustrative. Depending on implementation needs, any number of terminal devices, networks, and servers can be included.
[0039] Continue to refer to Figure 2 A flowchart illustrating an embodiment of the data anomaly monitoring method according to this application is shown. The order of steps in the flowchart can be changed, and some steps can be omitted, depending on different needs. The data anomaly monitoring method provided in this application embodiment can be applied to any scenario requiring data anomaly monitoring, and thus can be applied to products in these scenarios, such as case anomaly monitoring scenarios in the fintech and healthcare insurance fields. The data anomaly monitoring method includes the following steps:
[0040] Step S201: Obtain claim data within a preset time period.
[0041] In this embodiment, the data anomaly monitoring method operates on an electronic device (e.g., Figure 1The server / terminal device shown can obtain claims data within a preset time period via wired or wireless connection. It should be noted that the aforementioned wireless connection methods may include, but are not limited to, 3G / 4G / 5G connections, WiFi connections, Bluetooth connections, WiMAX connections, Zigbee connections, UWB (ultra-wideband) connections, and other currently known or future-developed wireless connection methods. The implementing entity of this application is specifically a data anomaly monitoring system, which can be simply referred to as the system. The selection of the aforementioned preset time period is not specifically limited and can be determined according to actual business needs; for example, it can be set to the past three years. Furthermore, claims data from the past three years can be extracted from the insurance company's historical database, including policyholder information, beneficiary information, claim amount, accident description, and claim settlement time.
[0042] Furthermore, this application can be applied to anomaly monitoring scenarios in the fintech and healthcare insurance sectors. A claim case refers to a series of events involving the insured or beneficiary submitting a claim to the insurance company after an insured event occurs as stipulated in the insurance contract, and the insurance company reviewing, investigating, assessing, and deciding whether to provide compensation or pay insurance benefits according to the contract. Simply put, it is a single event corresponding to a series of operations surrounding insurance payouts.
[0043] For example, in the fintech sector, the aforementioned claims data could be data related to auto insurance claims. In the healthcare insurance sector, the aforementioned claims data could be data related to medical claims. Medical claims also follow the general claims process, including reporting the incident, submitting claim documents (such as medical records, invoices, expense lists, etc.), insurance company review, investigation (if necessary), claims decision (payment or rejection), and payment of compensation. Medical claims can include claims related to medical insurance, critical illness insurance, disability income loss insurance, long-term care insurance, accident insurance, and other healthcare insurance.
[0044] Step S202: Construct a corresponding graph model based on the compensation case data.
[0045] In this embodiment, the specific implementation process of constructing the corresponding graph model based on the compensation case data will be further described in detail in subsequent specific embodiments of this application, and will not be elaborated on here.
[0046] Step S203: Extract features from the graph model to obtain corresponding graph features, and merge the graph features with the compensation case data to obtain corresponding merged data.
[0047] In this embodiment, node features and edge features can be extracted from the graph model. For example, features of the policyholder node include: number of policy purchases, number of associated beneficiaries, average claim amount, etc. Features of the beneficiary node include: number of associated policyholders, claim frequency, etc. Edge features include: number of associations between policyholders and beneficiaries, association time intervals, etc. Then, the extracted node and edge features are integrated into a structured tabular form (such as a DataFrame), where each row represents a claim and each column represents a feature, to obtain graph features. Furthermore, the extracted graph features are merged with the original claim data to form a complete dataset, which serves as the aforementioned merged data.
[0048] Step S204: The merged data is split based on a preset time series to obtain the corresponding target data.
[0049] In this embodiment, the merged data can be split based on a time series predetermined by actual needs, and the split data can be used as the target data. For example: data from the past three years: used to analyze long-term trends and patterns; data from the past three months: used to analyze the concentration of recent claims; data from the past three weeks: used to analyze abnormal fluctuations in the short term. This splitting method helps to analyze claims patterns in different time periods and identify potential duplicate claims.
[0050] Step S205: Perform cluster analysis on the target data based on a preset target clustering algorithm to obtain multiple corresponding cluster groups.
[0051] In this embodiment, the specific implementation process of performing cluster analysis on the target data based on the preset target clustering algorithm to obtain multiple corresponding cluster groups will be further described in detail in subsequent specific embodiments of this application, and will not be elaborated on here.
[0052] Step S206: Perform index analysis on all the cluster groups based on preset target indicators, and determine whether there are any abnormal claim groups among all the cluster groups.
[0053] In this embodiment, the specific implementation process of performing index analysis on all the cluster groups based on preset target indicators and determining whether there are abnormal claim groups in all the cluster groups will be further described in detail in subsequent specific embodiments of this application, and will not be elaborated on here.
[0054] Step S207: If yes, execute the alarm processing corresponding to the abnormal claim group.
[0055] In this embodiment, the specific implementation process of performing the alarm processing corresponding to the abnormal claim group will be further described in detail in subsequent specific embodiments of this application, and will not be elaborated on here.
[0056] This application first acquires claims data within a preset time period; then constructs a corresponding graph model based on the claims data; next, it extracts features from the graph model to obtain corresponding graph features, and merges the graph features with the claims data to obtain corresponding merged data; then, it splits the merged data based on a preset time series to obtain corresponding target data; further, it performs cluster analysis on the target data based on a preset target clustering algorithm to obtain multiple corresponding cluster groups; subsequently, it performs indicator analysis on all cluster groups based on preset target indicators and determines whether there are abnormal claims groups among all cluster groups; if so, it executes alarm processing corresponding to the abnormal claims group. Based on the above processing flow, this application uses artificial intelligence technology to identify the acquired claims data to construct a graph model, integrates graph features for cluster analysis, and then analyzes and processes the cluster groups generated by cluster analysis based on the use of target indicators. This enables the automatic and accurate identification of abnormal duplicate claims, effectively improving the accuracy of identifying duplicate claims that may have fraud risks.
[0057] In some alternative implementations, step S202 includes the following steps:
[0058] The policyholder of each claim case contained in the claims data is taken as the central node.
[0059] In this embodiment, the policyholder of each claim case in the above-mentioned claims data can be used as the central node (i.e., the policyholder node) to represent the initiator of the claim.
[0060] Identify the associated nodes corresponding to the central node from the claims data.
[0061] In this embodiment, by adding associated nodes, beneficiary information is treated as a node associated with the policyholder node, representing the beneficiary of the claim. Claim information (such as accident type, claim amount, etc.) is also treated as a node and connected to the policyholder node, representing the specific details of the claim.
[0062] The corresponding graph structure is obtained by connecting the central node and the associated nodes through the edges.
[0063] In this embodiment, the policyholder node, beneficiary node, and claim information node are connected by edges (i.e., relationships) to form a graph structure. The edges can represent the relationship between the policyholder and beneficiary (such as relatives, friends, etc.) or the specific attributes of a claim.
[0064] The graph structure is extended by a preset expansion strategy to obtain the processed target graph structure.
[0065] In this embodiment, the above-mentioned expansion strategy includes the following: if the policyholder also appears as a beneficiary in other claims, then these related nodes are further connected to form a network of policyholder relationships. This connection can reveal potential connections or fraud patterns among policyholders. Specifically, the graph structure can be expanded based on the above-mentioned expansion strategy to create a network, and the resulting processed target graph structure can be used as the required graph model.
[0066] The target graph structure is used as the graph model.
[0067] In this embodiment, the constructed graph model is stored in a graph database for subsequent feature extraction and analysis. The graph database can efficiently store and query complex relationships.
[0068] This application uses the policyholder of each claim case in the claims data as the central node; then, it identifies the associated nodes corresponding to the central node from the claims data; subsequently, it connects the central node and the associated nodes through edge processing to obtain the corresponding graph structure; next, it expands the graph structure based on a preset expansion strategy to obtain the processed target graph structure; finally, it uses the target graph structure as the graph model. Through the above processing flow, this application can efficiently and accurately construct a graph model, linking related data in the claims data, which is beneficial for providing accurate data structure support for subsequent graph feature merging and clustering analysis.
[0069] In some optional implementations of this embodiment, step S205 includes the following steps:
[0070] The target data is preprocessed to obtain the corresponding processed data.
[0071] In this embodiment, the preprocessing includes standardization / normalization, missing value handling, and outlier handling. Specifically, standardization / normalization includes standardizing or normalizing the data to eliminate dimensional differences between different features. For example, Z-score standardization or Min-Max normalization methods are used to ensure that the values of each feature are within the same range, avoiding excessive influence of some features on the clustering results due to excessively large values. Missing value handling includes checking whether there are missing values in the data and filling or deleting them as appropriate. Commonly used methods include mean imputation, median imputation, or imputation based on predictions of other features. Outlier handling includes identifying and processing outliers in the data to prevent them from interfering with the clustering results. Outliers can be identified through statistical methods (such as Z-score) or visualization methods (such as box plots), and whether to retain or adjust them is determined according to business logic.
[0072] Invokes multiple preset clustering algorithms.
[0073] In this embodiment, the clustering algorithm mentioned above may include at least K-means, DBSCAN, hierarchical clustering, and other algorithms.
[0074] The target clustering algorithm is selected from all the clustering algorithms based on a preset screening strategy.
[0075] In this embodiment, the DBSCAN algorithm can be selected as the target clustering algorithm. The specific implementation process of selecting the target clustering algorithm from all the clustering algorithms based on the preset screening strategy will be further described in detail in the subsequent specific embodiments of this application, and will not be elaborated on here.
[0076] The parameters of the target clustering algorithm are adjusted to obtain the adjusted target clustering algorithm.
[0077] In this embodiment, for the selected DBSCAN algorithm, appropriate neighborhood radius (eps) and minimum number of samples (min_samples) parameters can be determined by methods such as k-distance graphs to identify dense regions and noise points, and to ensure the accuracy and stability of the clustering results.
[0078] Based on the adjusted target clustering algorithm, cluster analysis is performed on the target data to obtain multiple corresponding cluster groups.
[0079] In this embodiment, the preprocessed data can be used to train the adjusted target clustering algorithm described above, grouping claims with similar characteristics into the same group. This adjusted target clustering algorithm automatically groups claims based on the similarity between features, without needing to know the number of groups or labels in advance, thus obtaining multiple cluster groups after cluster analysis.
[0080] This application preprocesses the target data to obtain corresponding processed data; then it calls multiple preset clustering algorithms; subsequently, based on a preset screening strategy, it selects a target clustering algorithm from all the clustering algorithms; next, it adjusts the parameters of the target clustering algorithm to obtain an adjusted target clustering algorithm; finally, it performs cluster analysis on the target data based on the adjusted target clustering algorithm to obtain multiple corresponding cluster groups. Based on the above processing flow, this application uses the selected and parameter-adjusted target clustering algorithm to perform cluster analysis on target data, which can efficiently and accurately identify groups of claims with similar characteristics, ensuring the accuracy of the obtained cluster groups, and providing accurate data support for subsequent abnormal group judgment.
[0081] In some optional implementations, the selection of the target clustering algorithm from all the clustering algorithms based on a preset screening strategy includes the following steps:
[0082] Data analysis was performed on the compensation case data to obtain the corresponding data characteristics.
[0083] In this embodiment, the above-mentioned data analysis refers to data distribution analysis, including: first, conducting exploratory data analysis (EDA) on the merged claims data to understand the distribution characteristics of the data; then checking whether the data has an obvious cluster structure, or whether the data distribution is complex (such as multimodal, non-spherical, etc.); and then identifying noise points and outliers in the data and evaluating their impact on the clustering results.
[0084] Specifically, taking the processing of an insurance company's claims dataset, with the goal of identifying potentially fraudulent claims groups as an example, the dataset contains features such as policyholder information, claim amounts, claim intervals, and accident descriptions. The corresponding data analysis process includes: 1. Noise and Outliers: The dataset may contain some anomalous claims, such as extremely low claim amounts occurring frequently, or abnormally high claim amounts with vague accident descriptions. These claims may be due to fraudulent activity or noise caused by data entry errors. 2. Cluster Shape and Distribution: The distribution of claims may be irregular because fraudulent activity often lacks a fixed pattern. For example, some fraudsters may evade scrutiny by making multiple small claims, while others may profit quickly through large single claims. 3. Data Scale: The dataset may contain tens or even hundreds of thousands of claims records, requiring an algorithm capable of efficiently processing large-scale data.
[0085] The performance of the various clustering algorithms was evaluated, and the corresponding performance evaluation results were obtained.
[0086] In this embodiment, the clustering algorithms mentioned above include K-means, DBSCAN, hierarchical clustering, etc. The process of evaluating the performance of various clustering algorithms and obtaining the evaluation results includes: 1. K-means: Advantages: High computational efficiency, suitable for large-scale datasets; can quickly converge to local optima. Disadvantages: Sensitive to noise and outliers; requires pre-specifying the number of clusters; assumes clusters are spherical and of similar size, may not be suitable for irregularly distributed data. 2. DBSCAN: Advantages: Can automatically identify noise points; does not require pre-specifying the number of clusters; can discover clusters of arbitrary shapes. Disadvantages: Sensitive to parameters (eps and min_samples); relatively high computational complexity, but can still handle large-scale data with reasonable parameter settings. 3. Hierarchical clustering: Advantages: Provides hierarchical structure information of data; good visualization effect. Disadvantages: High computational complexity, unsuitable for large-scale datasets; sensitive to the choice of distance metrics and linking methods.
[0087] Obtain the business requirements corresponding to the claims data.
[0088] In this embodiment, the business requirements corresponding to the claims data include: Fraud detection: The business objective is to identify claims groups that may involve fraudulent activities, thus requiring an algorithm capable of handling noisy and irregularly distributed data. Real-time requirements: Although real-time performance is not the primary consideration, the algorithm's processing speed still needs to be within an acceptable range to respond promptly to potential fraudulent activities.
[0089] Based on the data characteristics, the performance evaluation results, and the business requirements, all the clustering algorithms are screened to obtain the specified clustering algorithm that meets the requirements.
[0090] In this embodiment, the most suitable clustering algorithm is selected based on the characteristics of the obtained data, performance evaluation results, and business requirements. Specifically, since there is noise and outliers in the claims data, DBSCAN can automatically identify and eliminate these noise points, improving the accuracy of clustering. Furthermore, the distribution of claims may be irregular, and DBSCAN can discover clusters of arbitrary shapes, better reflecting the diversity of fraudulent behavior. In addition, although DBSCAN has relatively high computational complexity, with reasonable parameter settings, it can still handle large-scale datasets and meet business needs. Therefore, DBSCAN is ultimately selected as the most suitable clustering algorithm, i.e., used as the final target clustering algorithm.
[0091] The specified clustering algorithm is used as the target clustering algorithm.
[0092] This application analyzes the claims data to obtain corresponding data characteristics; then evaluates the performance of various clustering algorithms to obtain corresponding performance evaluation results; next, it obtains the business requirements corresponding to the claims data; subsequently, based on the data characteristics, the performance evaluation results, and the business requirements, it filters all the clustering algorithms to obtain a specified clustering algorithm that meets the requirements; finally, it uses the specified clustering algorithm as the target clustering algorithm. Based on the above processing flow, this application, through analysis based on multiple data dimensions such as data characteristics, performance evaluation results, and business requirements, can intelligently and accurately select the most suitable target clustering algorithm from multiple clustering algorithms to ensure the accuracy and adaptability of the obtained target clustering algorithm. This enables the subsequent use of the target clustering algorithm to effectively identify claims groups that may involve fraudulent behavior, thereby providing strong support for the insurance company's risk control and anti-fraud work.
[0093] In some alternative implementations, step S206 includes the following steps:
[0094] Obtain target metrics associated with anomaly assessments of claims data.
[0095] In this embodiment, the aforementioned target indicators may include at least the claim start and end time and the claim amount. The claim start and end time includes defining the time interval from policy issuance to claim settlement as a metric to reflect the timeliness of the claim. For example, calculating the difference in days between the policy issuance date and the claim settlement date. The claim amount includes defining the amount of each claim as another key indicator to identify claims with abnormal amounts. Additionally, based on actual business needs, other auxiliary indicators can be defined, such as claim frequency and beneficiary change frequency, to comprehensively assess the anomalies of claims.
[0096] Based on the target indicators, statistical analysis is performed on each cluster group to obtain corresponding multiple indicator data.
[0097] In this embodiment, the statistical analysis of the above indicators includes statistical analysis and inter-group comparison. Specifically, the statistical analysis includes: performing statistical analysis on the indicators of each cluster group, such as: calculating the average claim amount, median claim amount, and range of claim amount distribution within the group; calculating the average claim time interval, shortest and longest claim time interval, etc., within the group. Inter-group comparison includes: comparing the indicators between different groups to identify whether the indicators of a certain group deviate significantly from those of other groups. For example: comparing the average claim amount of different groups to identify whether the amount of a certain group is significantly lower or higher than that of other groups; comparing the average claim time interval of different groups to identify whether the time interval of a certain group is significantly shorter than that of other groups.
[0098] Based on the aforementioned indicator data, a preset anomaly detection strategy is used to identify anomalies in all the cluster groups to obtain corresponding anomaly detection results.
[0099] In this embodiment, the above-mentioned anomaly detection strategy includes: feature identification, comprehensive evaluation, and anomaly labeling. Specifically, 1. Feature identification includes: if a group of claims is found to have the following characteristics, there may be a risk of fraud: 1) High-frequency claims: The same policyholder has multiple claims in a relatively short period of time, indicating that there may be deliberate accident-making or duplicate claims. 2) Small-amount, high-frequency claims: The claim amount for each claim is small, but the frequency is significantly higher than other groups, indicating that there may be behavior of circumventing review by making multiple small claims. 2. Comprehensive evaluation includes: combining multiple indicators for comprehensive evaluation to avoid misjudgment based on a single indicator. For example, a group may not have obvious anomalies in the claim amount, but the claim interval is significantly shorter, which still needs attention. 3. Anomaly labeling includes: labeling the groups determined to be abnormal, recording their key features and abnormal indicators, and providing a basis for subsequent alarms and manual verification.
[0100] Specifically, based on the above-mentioned anomaly detection strategy, the aforementioned indicator data can be used to identify anomalies in all cluster groups and generate corresponding anomaly detection results. If there are groups determined to be anomalous, the generated content will be an anomaly detection result indicating the presence of anomalies; otherwise, if there are no groups determined to be anomalous, the generated content will be an anomaly detection result indicating the absence of anomalies.
[0101] If the anomaly identification result indicates the presence of an anomaly, then it is determined that there is an abnormal claims group among all the cluster groups; otherwise, it is determined that there is no abnormal claims group among all the cluster groups.
[0102] In this embodiment, if the anomaly identification result indicates that an anomaly exists, it is determined that there is an abnormal claims group among all the cluster groups; and if the anomaly identification result indicates that no anomaly exists, it is determined that there is no abnormal claims group among all the cluster groups.
[0103] This application obtains target indicators associated with anomaly assessment of claims data; then, based on the target indicators, performs statistical analysis on each cluster group to obtain corresponding multiple indicator data; subsequently, based on the indicator data, uses a preset anomaly detection strategy to identify anomalies in all cluster groups to obtain corresponding anomaly detection results; if the anomaly detection result indicates the presence of anomalies, it is determined that there are abnormal claims groups among all cluster groups; otherwise, it is determined that there are no abnormal claims groups among all cluster groups. Based on the above processing flow, this application performs statistical analysis on each cluster group based on target indicators associated with anomaly assessment of claims data, and uses a preset anomaly detection strategy to identify anomalies in all cluster groups based on the obtained indicator data, thereby achieving efficient and accurate identification of abnormal claims groups, effectively improving the processing efficiency of anomaly identification, and ensuring the accuracy of the obtained abnormal claims groups.
[0104] In some optional implementations of this embodiment, step S207 includes the following steps:
[0105] Obtain the key features corresponding to the abnormal claims group.
[0106] In this embodiment, the aforementioned key features may include at least the policyholder information, the time of the claim, abnormal indicators, and other relevant evidence. The policyholder information includes: name, ID number, and contact information. The time of the claim includes: the specific time range of the abnormal claim. Abnormal indicators include: abnormal data such as claim amount, claim interval, and incident frequency. Other relevant evidence includes: the relationships shown in the model, historical claim records, etc.
[0107] Based on the key features, alarm information corresponding to the abnormal claim group is constructed.
[0108] In this embodiment, all the acquired key features can be integrated, and the resulting integrated features can be used as the alarm information corresponding to the abnormal claim group.
[0109] Invoke the preset target alarm method.
[0110] In this embodiment, the selection method for the aforementioned target alarm format is not specifically limited and can be determined according to actual business needs. Preferably, an alarm window containing alarm information can pop up through the system's front end (such as a web interface or mobile application). The alarm window can be designed as a high-priority notification to ensure that operators can notice it in a timely manner.
[0111] The alarm information is displayed and processed based on the target alarm method.
[0112] In this embodiment, the display processing of the above alarm information can be performed according to the selected target alarm method.
[0113] This application obtains key features corresponding to the abnormal claim group; then constructs alarm information corresponding to the abnormal claim group based on the key features; subsequently, it calls a preset target alarm method; and finally, it displays the alarm information based on the target alarm method. Based on the above processing flow, this application can automatically construct alarm information according to the obtained key features corresponding to the abnormal claim group, effectively improving the generation efficiency of alarm information. Furthermore, it intelligently displays the alarm information based on the use of the target alarm method, improving the intelligence of alarm information display. Moreover, the use of alarm information can serve as a reminder to operators, thereby improving their work efficiency and user experience.
[0114] In some optional implementations of this embodiment, after displaying the alarm information based on the target alarm method, the following steps may also be performed:
[0115] Receive the verification results corresponding to the alarm information returned by the preset operators.
[0116] In this embodiment, after logging into the system, the operator will immediately receive a fraud alarm notification and can view detailed alarm information. The operator will then perform corresponding verification processing based on the alarm information and return the corresponding verification results to the system. Specifically, the verification processing includes: the operator can contact the policyholder or beneficiary by phone, email, or other means to verify the authenticity of the accident. For example, inquiring about the specific details of the accident, the injuries, or the property damage; investigating whether there are any abnormalities in the relationship between the policyholder and the beneficiary, such as whether they are relatives, friends, or other close relationships, and whether there is any possibility of transfer of benefits; reviewing the policyholder and beneficiary's historical claims records to analyze whether there are any instances of duplicate claims, fraudulent claims, or other misconduct.
[0117] Obtain the target case handling strategy corresponding to the verification results.
[0118] In this embodiment, a mapping relationship between appropriate results and corresponding target case handling strategies is pre-set according to actual needs. Specifically, this includes: Denying claims: If fraud is confirmed, claims can be denied and the fraud case recorded. Marking high-risk customers: Policyholders or beneficiaries involved in fraud are marked as high-risk customers for more rigorous future review of their claims. Legal action: For serious fraud, the case can be transferred to the legal department for handling and legal action. Based on the content of the above verification results, case handling strategies matching the verification results can be selected to obtain the aforementioned target case handling strategy.
[0119] Based on the target case handling strategy, the abnormal claims groups are processed accordingly to obtain the corresponding processing results.
[0120] In this embodiment, the above-mentioned abnormal claims groups can be processed according to the selected target case processing strategy, and corresponding processing results can be generated.
[0121] The verification results and the processing results are stored.
[0122] In this embodiment, a complete closed-loop process can be formed by recording the processing and verification results of alarms, facilitating subsequent auditing and optimization. The storage method for the verification and processing results is not specifically limited; for example, it can be stored in a local database, on a disk, on a cloud server, or on a blockchain.
[0123] This application receives verification results corresponding to alarm information returned by pre-set operators; then obtains the target case handling strategy corresponding to the verification results; subsequently, it processes the abnormal claim group according to the target case handling strategy to obtain the corresponding processing results; and finally, it stores the verification results and the processing results. Based on the above processing flow, after receiving the verification results corresponding to alarm information returned by operators, this application automatically processes the abnormal claim group according to the target case handling strategy corresponding to the verification results, ensuring the accuracy and fairness of handling fraudulent behavior in abnormal claim groups. In addition, it intelligently stores the generated verification results and processing results, thereby ensuring the data security of the verification results and processing results and facilitating subsequent auditing and optimization.
[0124] In some alternative implementations, the user information obtained is subject to user consent and complies with relevant laws and policies.
[0125] Furthermore, any software tools or components not belonging to our company that appear in the embodiments of this application are merely illustrative examples and do not represent actual use.
[0126] Furthermore, the duplicate claim detection method based on graph feature fusion clustering algorithm proposed in this application focuses on related claim scenarios. Technically, it adds relationship information and graph prediction features to the machine learning pipeline to improve model performance. In terms of business scenarios, it has a better recognition effect on scenarios involving multiple parties in fraudulent activities, such as scenarios where the insured and the accident handling unit jointly commit insurance fraud. It can extract the relationship for identification, providing a reference for the success rate of duplicate claim verification.
[0127] It should be understood that the sequence number of each step in the above embodiments does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present invention.
[0128] It should be emphasized that, in order to further ensure the privacy and security of the aforementioned abnormal claims groups, these abnormal claims groups can also be stored in a blockchain node.
[0129] The blockchain referred to in this application is a novel application model of computer technologies such as distributed data storage, peer-to-peer transmission, consensus mechanisms, and encryption algorithms. Essentially, a blockchain is a decentralized database, a chain of data blocks linked together using cryptographic methods. Each data block contains information about a batch of network transactions, used to verify the validity of the information (anti-counterfeiting) and generate the next block. A blockchain can include an underlying blockchain platform, a platform product service layer, and an application service layer.
[0130] The embodiments of this application can acquire and process relevant data based on artificial intelligence technology. Artificial intelligence (AI) is the theory, method, technology, and application system that uses digital computers or machines controlled by digital computers to simulate, extend, and expand human intelligence, perceive the environment, acquire knowledge, and use that knowledge to obtain optimal results.
[0131] Foundational technologies for artificial intelligence generally include sensors, dedicated AI chips, cloud computing, distributed storage, big data processing, operating / interactive systems, and mechatronics. AI software technologies mainly encompass computer vision, robotics, biometrics, speech processing, natural language processing, and machine learning / deep learning.
[0132] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by instructing related hardware through computer-readable instructions. These computer-readable instructions can be stored in a computer-readable storage medium. When the program is executed, it can include the processes of the embodiments of the methods described above. The aforementioned storage medium can be a non-volatile storage medium such as a magnetic disk, optical disk, or read-only memory (ROM), or random access memory (RAM).
[0133] It should be understood that although the steps in the flowcharts of the accompanying figures are shown sequentially as indicated by the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the flowcharts of the accompanying figures may include multiple sub-steps or multiple stages. These sub-steps or stages are not necessarily completed at the same time, but can be executed at different times, and their execution order is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the sub-steps or stages of other steps.
[0134] Further reference Figure 3 As a response to the above Figure 2 The implementation of the method shown in this application provides an embodiment of a data anomaly monitoring device, which is similar to... Figure 2 Corresponding to the method embodiments shown, this device can be specifically applied to various electronic devices.
[0135] like Figure 3 As shown, the data anomaly monitoring device 300 described in this embodiment includes: an acquisition module 301, a construction module 302, a processing module 303, a splitting module 304, a clustering module 305, an analysis module 306, and an execution module 307. Wherein:
[0136] The acquisition module 301 is used to acquire claims data within a preset time period;
[0137] Construction module 302 is used to construct a corresponding graph model based on the compensation case data;
[0138] Processing module 303 is used to extract features from the graph model to obtain corresponding graph features, and merge the graph features with the compensation case data to obtain corresponding merged data;
[0139] The splitting module 304 is used to split the merged data based on a preset time series to obtain the corresponding target data;
[0140] Clustering module 305 is used to perform cluster analysis on the target data based on a preset target clustering algorithm to obtain multiple corresponding cluster groups;
[0141] The analysis module 306 is used to perform indicator analysis on all the cluster groups based on preset target indicators, and to determine whether there are any abnormal claim groups among all the cluster groups;
[0142] The execution module 307 is used to execute the alarm processing corresponding to the abnormal claim group if the case is so.
[0143] In this embodiment, the operations performed by the above modules or units correspond one-to-one with the steps of the data anomaly monitoring method in the aforementioned embodiments, and will not be repeated here.
[0144] In some optional implementations of this embodiment, the construction module 302 includes:
[0145] The first processing submodule is used to take the policyholder of each claim case contained in the claims data as the central node;
[0146] The first determining submodule is used to determine the associated nodes corresponding to the central node from the claims data;
[0147] The connection submodule is used to connect the central node and the associated nodes through the edges to obtain the corresponding graph structure;
[0148] The second processing submodule is used to expand the graph structure into a relational network based on a preset expansion strategy to obtain the processed target graph structure.
[0149] The second determining submodule is used to use the target graph structure as the graph model.
[0150] In this embodiment, the operations performed by the above modules or units correspond one-to-one with the steps of the data anomaly monitoring method in the aforementioned embodiments, and will not be repeated here.
[0151] In some optional implementations of this embodiment, the clustering module 305 includes:
[0152] The preprocessing submodule is used to preprocess the target data to obtain the corresponding processed data;
[0153] The first calling submodule is used to call various preset clustering algorithms;
[0154] The filtering submodule is used to filter out the target clustering algorithm from all the clustering algorithms based on a preset filtering strategy;
[0155] The adjustment submodule is used to adjust the parameters of the target clustering algorithm to obtain the adjusted target clustering algorithm;
[0156] The analysis submodule is used to perform cluster analysis on the target data based on the adjusted target clustering algorithm to obtain multiple corresponding cluster groups.
[0157] In this embodiment, the operations performed by the above modules or units correspond one-to-one with the steps of the data anomaly monitoring method in the aforementioned embodiments, and will not be repeated here.
[0158] In some optional implementations of this embodiment, the filtering submodule includes:
[0159] The analysis unit is used to perform data analysis on the claims data to obtain corresponding data characteristics;
[0160] An evaluation unit is used to evaluate the performance of various clustering algorithms and obtain corresponding performance evaluation results.
[0161] The acquisition unit is used to acquire business requirements corresponding to the claims data;
[0162] The filtering unit is used to filter all the clustering algorithms based on the data characteristics, the performance evaluation results and the business requirements, so as to obtain the specified clustering algorithm that meets the requirements.
[0163] A determining unit is used to select the specified clustering algorithm as the target clustering algorithm.
[0164] In this embodiment, the operations performed by the above modules or units correspond one-to-one with the steps of the data anomaly monitoring method in the aforementioned embodiments, and will not be repeated here.
[0165] In some optional implementations of this embodiment, the analysis module 306 includes:
[0166] The first acquisition submodule is used to acquire target indicators associated with the anomaly assessment of claims data;
[0167] The statistics submodule is used to perform statistical analysis on each cluster group based on the target indicator to obtain multiple corresponding indicator data.
[0168] The identification submodule is used to identify anomalies in all the cluster groups based on the indicator data using a preset anomaly detection strategy to obtain the corresponding anomaly identification results.
[0169] The determination submodule is used to determine that if the anomaly identification result indicates the existence of an anomaly, then there is an abnormal claim group among all the cluster groups; otherwise, it determines that there is no abnormal claim group among all the cluster groups.
[0170] In this embodiment, the operations performed by the above modules or units correspond one-to-one with the steps of the data anomaly monitoring method in the aforementioned embodiments, and will not be repeated here.
[0171] In some optional implementations of this embodiment, the execution module 307 includes:
[0172] The second acquisition submodule is used to acquire key features corresponding to the abnormal claim group;
[0173] A submodule is constructed to generate alarm information corresponding to the abnormal claims group based on the key features;
[0174] The second submodule is used to invoke the preset target alarm method;
[0175] The display submodule is used to display and process the alarm information based on the target alarm method.
[0176] In this embodiment, the operations performed by the above modules or units correspond one-to-one with the steps of the data anomaly monitoring method in the aforementioned embodiments, and will not be repeated here.
[0177] In some optional implementations of this embodiment, the execution module 307 further includes:
[0178] The receiving submodule is used to receive the verification results corresponding to the alarm information returned by the preset operators;
[0179] The third acquisition submodule is used to acquire the target case handling strategy corresponding to the verification result;
[0180] The third processing submodule is used to process the abnormal claims group according to the target case processing strategy and obtain the corresponding processing result.
[0181] The storage submodule is used to store the verification results and the processing results.
[0182] In this embodiment, the operations performed by the above modules or units correspond one-to-one with the steps of the data anomaly monitoring method in the aforementioned embodiments, and will not be repeated here.
[0183] To address the aforementioned technical problems, embodiments of this application also provide a computer device. Please refer to [link / reference needed]. Figure 4 , Figure 4 This is a basic structural block diagram of the computer device in this embodiment.
[0184] The computer device 4 includes a memory 41, a processor 42, and a network interface 43 that are interconnected via a system bus. It should be noted that only the computer device 4 with components 41-43 is shown in the figure; however, it should be understood that it is not required to implement all the shown components, and more or fewer components can be implemented alternatively. Those skilled in the art will understand that the computer device described here is a device capable of automatically performing numerical calculations and / or information processing according to pre-set or stored instructions, and its hardware includes, but is not limited to, microprocessors, application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), digital signal processors (DSPs), embedded devices, etc.
[0185] The computer device can be a desktop computer, laptop, handheld computer, or cloud server, etc. The computer device can interact with the user via a keyboard, mouse, remote control, touchpad, or voice control.
[0186] The memory 41 includes at least one type of readable storage medium, including flash memory, hard disk, multimedia card, card-type memory (e.g., SD or DX memory), random access memory (RAM), static random access memory (SRAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), programmable read-only memory (PROM), magnetic memory, magnetic disk, optical disk, etc. In some embodiments, the memory 41 may be an internal storage unit of the computer device 4, such as the hard disk or memory of the computer device 4. In other embodiments, the memory 41 may also be an external storage device of the computer device 4, such as a plug-in hard disk, smart media card (SMC), secure digital (SD) card, flash card, etc., equipped on the computer device 4. Of course, the memory 41 may also include both the internal storage unit and its external storage device of the computer device 4. In this embodiment, the memory 41 is typically used to store the operating system and various application software installed on the computer device 4, such as computer-readable instructions for data anomaly monitoring methods. In addition, the memory 41 can also be used to temporarily store various types of data that have been output or will be output.
[0187] In some embodiments, the processor 42 may be a central processing unit (CPU), a controller, a microcontroller, a microprocessor, or other data processing chip. The processor 42 is typically used to control the overall operation of the computer device 4. In this embodiment, the processor 42 is used to execute computer-readable instructions stored in the memory 41 or to process data, for example, to execute computer-readable instructions for the data anomaly monitoring method.
[0188] The network interface 43 may include a wireless network interface or a wired network interface, which is typically used to establish communication connections between the computer device 4 and other electronic devices.
[0189] Compared with the prior art, the embodiments of this application have the following beneficial effects:
[0190] In this embodiment, firstly, claim data within a preset time period is acquired; and a corresponding graph model is constructed based on the claim data; then, feature extraction is performed on the graph model to obtain corresponding graph features, and the graph features are merged with the claim data to obtain corresponding merged data; subsequently, the merged data is split based on a preset time series to obtain corresponding target data; further, cluster analysis is performed on the target data based on a preset target clustering algorithm to obtain multiple corresponding cluster groups; subsequently, indicator analysis is performed on all cluster groups based on preset target indicators, and it is determined whether there are abnormal claim groups in all cluster groups; if so, alarm processing corresponding to the abnormal claim group is executed. Based on the above processing flow, this application uses artificial intelligence technology to identify the acquired claim data to construct a graph model, integrates graph features with cluster analysis, and then analyzes and processes the cluster groups generated by cluster analysis based on the use of target indicators, thereby automatically and accurately identifying abnormal duplicate claims, effectively improving the accuracy of identifying duplicate claims that may have fraud risks.
[0191] This application also provides another embodiment, namely, providing a computer-readable storage medium storing computer-readable instructions that can be executed by at least one processor to cause the at least one processor to perform the steps of the data anomaly monitoring method described above.
[0192] Compared with the prior art, the embodiments of this application have the following main advantages:
[0193] In this embodiment, firstly, claim data within a preset time period is acquired; and a corresponding graph model is constructed based on the claim data; then, feature extraction is performed on the graph model to obtain corresponding graph features, and the graph features are merged with the claim data to obtain corresponding merged data; subsequently, the merged data is split based on a preset time series to obtain corresponding target data; further, cluster analysis is performed on the target data based on a preset target clustering algorithm to obtain multiple corresponding cluster groups; subsequently, indicator analysis is performed on all cluster groups based on preset target indicators, and it is determined whether there are abnormal claim groups in all cluster groups; if so, alarm processing corresponding to the abnormal claim group is executed. Based on the above processing flow, this application uses artificial intelligence technology to identify the acquired claim data to construct a graph model, integrates graph features with cluster analysis, and then analyzes and processes the cluster groups generated by cluster analysis based on the use of target indicators, thereby automatically and accurately identifying abnormal duplicate claims, effectively improving the accuracy of identifying duplicate claims that may have fraud risks.
[0194] Through the above description of the embodiments, those skilled in the art can clearly understand that the methods of the above embodiments can be implemented by means of software plus necessary general-purpose hardware platforms. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk), and includes several instructions to cause a terminal device (which may be a mobile phone, computer, server, air conditioner, or network device, etc.) to execute the methods described in the various embodiments of this application.
[0195] Obviously, the embodiments described above are only some embodiments of this application, not all embodiments. The accompanying drawings show preferred embodiments of this application, but do not limit the patent scope of this application. This application can be implemented in many different forms; rather, the purpose of providing these embodiments is to provide a more thorough and comprehensive understanding of the disclosure of this application. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art can still modify the technical solutions described in the foregoing specific embodiments, or make equivalent substitutions for some of the technical features. Any equivalent structures made using the content of this application's specification and drawings, directly or indirectly applied to other related technical fields, are similarly within the scope of patent protection of this application.
Claims
1. A method for monitoring data anomalies, characterized in that, Includes the following steps: Obtain claims data within a preset time period; Construct a corresponding graph model based on the claims data; Feature extraction is performed on the graph model to obtain the corresponding graph features, and the graph features are merged with the compensation case data to obtain the corresponding merged data; The merged data is split based on a preset time series to obtain the corresponding target data; The target data is clustered based on a preset target clustering algorithm to obtain multiple corresponding cluster groups; Based on preset target indicators, index analysis is performed on all the cluster groups to determine whether there are any abnormal claim groups among all the cluster groups; If so, execute the alarm processing corresponding to the abnormal claim group.
2. The data anomaly monitoring method according to claim 1, characterized in that, The step of constructing the corresponding graph model based on the claims data specifically includes: The policyholder of each claim case contained in the claims data is taken as the central node; Identify the associated nodes corresponding to the central node from the claims data; The corresponding graph structure is obtained by connecting the central node and the associated nodes through the edges; The graph structure is extended by a preset expansion strategy to obtain the processed target graph structure. The target graph structure is used as the graph model.
3. The data anomaly monitoring method according to claim 1, characterized in that, The step of performing cluster analysis on the target data based on a preset target clustering algorithm to obtain multiple corresponding cluster groups specifically includes: The target data is preprocessed to obtain the corresponding processed data; Invoke multiple preset clustering algorithms; The target clustering algorithm is selected from all the clustering algorithms based on a preset screening strategy; The parameters of the target clustering algorithm are adjusted to obtain the adjusted target clustering algorithm; Based on the adjusted target clustering algorithm, cluster analysis is performed on the target data to obtain multiple corresponding cluster groups.
4. The data anomaly monitoring method according to claim 3, characterized in that, The step of selecting the target clustering algorithm from all the clustering algorithms based on a preset screening strategy specifically includes: Data analysis was performed on the claims data to obtain the corresponding data characteristics; The performance of the various clustering algorithms is evaluated, and the corresponding performance evaluation results are obtained. Obtain the business requirements corresponding to the claims data; Based on the data characteristics, the performance evaluation results, and the business requirements, all the clustering algorithms are screened to obtain the specified clustering algorithm that meets the requirements. The specified clustering algorithm is used as the target clustering algorithm.
5. The data anomaly monitoring method according to claim 1, characterized in that, The step of performing index analysis on all cluster groups based on preset target indicators and determining whether there are abnormal claim groups among all cluster groups specifically includes: Obtain target metrics associated with anomaly assessments of claims data; Based on the target indicators, statistical analysis is performed on each cluster group to obtain multiple corresponding indicator data. Based on the aforementioned indicator data, a preset anomaly detection strategy is used to identify anomalies in all the cluster groups to obtain corresponding anomaly detection results. If the anomaly identification result indicates the presence of an anomaly, then it is determined that there is an abnormal claims group among all the cluster groups; otherwise, it is determined that there is no abnormal claims group among all the cluster groups.
6. The data anomaly monitoring method according to claim 1, characterized in that, The steps for executing the alarm processing corresponding to the abnormal claims group specifically include: Obtain the key features corresponding to the abnormal claims group; Based on the key features, alarm information corresponding to the abnormal claims group is constructed; Invoke the preset target alarm method; The alarm information is displayed and processed based on the target alarm method.
7. The data anomaly monitoring method according to claim 6, characterized in that, After the step of displaying the alarm information based on the target alarm method, the method further includes: Receive the verification results corresponding to the alarm information returned by the preset operators; Obtain the target case handling strategy corresponding to the verification result; Based on the target case handling strategy, the abnormal claims group is processed accordingly to obtain the corresponding processing results; The verification results and the processing results are stored.
8. A data anomaly monitoring device, characterized in that, include: The acquisition module is used to acquire claims data within a preset time period; The construction module is used to build a corresponding graph model based on the compensation case data; The processing module is used to extract features from the graph model to obtain corresponding graph features, and to merge the graph features with the compensation case data to obtain corresponding merged data; The splitting module is used to split the merged data based on a preset time series to obtain the corresponding target data; The clustering module is used to perform cluster analysis on the target data based on a preset target clustering algorithm to obtain multiple corresponding cluster groups; The analysis module is used to perform indicator analysis on all the cluster groups based on preset target indicators, and to determine whether there are any abnormal claim groups among all the cluster groups; The execution module is used to execute the alarm processing corresponding to the abnormal claim group if the case is found to be abnormal.
9. A computer device, characterized in that, The method includes a memory and a processor, wherein the memory stores computer-readable instructions, and the processor executes the computer-readable instructions to implement the steps of the data anomaly monitoring method as described in any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer-readable instructions, which, when executed by a processor, implement the steps of the data anomaly monitoring method as described in any one of claims 1 to 7.