Fraud early warning method and device based on telecommunication network fraud early warning model

By extracting features from transaction data of fraudulent accounts and performing dynamic evaluation using fuzzy comprehensive methods, a telecom fraud early warning model was trained, solving the problem of identifying fund transfers and flows in telecom fraud crimes and achieving effective early warning and interception of abnormal accounts.

CN121616293APending Publication Date: 2026-03-06HENAN POLICE ACAD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511757203.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-11-27
Publication Date
2026-03-06

AI Technical Summary

Technical Problem

Existing technologies are insufficient to effectively identify and provide early warning of the transfer and flow of funds involved in telecommunications and online fraud, making interception and control extremely difficult.

Method used

By extracting features from the transaction data of fraudulent accounts, generating historical transaction feature groups, performing fuzzy comprehensive dynamic evaluation, training a Bayesian regularized neural network model, generating real-time early warning levels, and realizing the identification and early warning of abnormal accounts.

Benefits of technology

Effective identification and early warning of abnormal fraudulent accounts have improved the efficiency of intercepting and controlling telecommunications and online fraud crimes.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121616293A_ABST
    Figure CN121616293A_ABST
Patent Text Reader

Abstract

The embodiment of the invention discloses a fraud early warning method and device based on a telecommunication network fraud early warning model. A specific embodiment of the method comprises the steps of performing feature extraction on each piece of historical transaction data in a historical transaction data sequence; generating a candidate risk level group corresponding to the historical transaction feature group; performing fuzzy comprehensive dynamic evaluation according to the historical transaction feature group sequence and the obtained candidate risk level group sequence; according to the historical transaction feature group sequence and the candidate early warning level sequence, carrying out model training on an untrained telecommunication network fraud early warning model; performing feature extraction on the real-time transaction data to generate real-time transaction features; and according to the real-time transaction characteristics and the telecommunication network fraud early warning model, generating a real-time early warning level for the candidate account. According to the embodiment, the abnormal fraud-related account number can be effectively identified and early warned.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments disclosed herein relate to the field of computer technology, and specifically to a fraud early warning method and apparatus based on a telecommunications network fraud early warning model. Background Technology

[0002] Based on the practical experience of public security organs in combating and governing telecommunications and online fraud crimes, the key factors and links involved in the cases are mainly the transfer and flow of fraudulent funds. Among them, whether it is a transfer, cash withdrawal or online third-party payment, bank accounts are involved. Therefore, it is necessary to give full play to the role of monitoring bank accounts as the "master gate" to effectively intercept, suppress and control the occurrence of telecommunications and online fraud crimes. Summary of the Invention

[0003] The summary portion of this disclosure is intended to provide a brief overview of the concepts, which will be described in detail in the detailed description portion. This summary portion is not intended to identify key or essential features of the claimed technical solutions, nor is it intended to limit the scope of the claimed technical solutions.

[0004] Some embodiments of this disclosure propose a fraud early warning method and apparatus based on a telecommunications network fraud early warning model to solve the technical problems mentioned in the background section above.

[0005] In a first aspect, some embodiments of this disclosure provide a fraud early warning method based on a telecommunications network fraud early warning model. The method includes: extracting features from each historical transaction data in a historical transaction data sequence to generate a historical transaction feature group, resulting in a historical transaction feature group sequence. The historical transaction data sequence comprises transaction data corresponding to multiple fraudulent accounts. The historical transaction feature group includes: first transfer interval, consecutive transfer interval, account balance, query frequency, vertical transfer level, and cross-transfer count. For each historical transaction feature group in the historical transaction feature group sequence, a candidate risk level group is generated corresponding to the historical transaction feature group. Fuzzy comprehensive dynamic evaluation is performed based on the historical transaction feature group sequence and the obtained candidate risk level group sequence to obtain a candidate early warning level sequence corresponding to the historical transaction feature group sequence. Based on the historical transaction feature group sequence and the candidate early warning level sequence, an untrained telecommunications network fraud early warning model is trained to obtain a telecommunications network fraud early warning model. Features are extracted from real-time transaction data to generate real-time transaction features. Based on the real-time transaction features and the telecommunications network fraud early warning model, a real-time early warning level is generated for the candidate accounts.

[0006] Secondly, some embodiments of this disclosure provide a fraud early warning device based on a telecommunications network fraud early warning model. The device includes: a first feature extraction unit configured to extract features from each historical transaction data in a historical transaction data sequence to generate historical transaction feature groups, resulting in a historical transaction feature group sequence. The historical transaction data sequence consists of transaction data corresponding to multiple fraudulent accounts, and the historical transaction feature groups include: first transfer interval, consecutive transfer interval, account balance, query frequency, vertical transfer level, and cross-transfer count. A first generation unit configured to generate a candidate risk level corresponding to each historical transaction feature group in the historical transaction feature group sequence. The system comprises the following components: a fuzzy comprehensive dynamic evaluation unit, configured to perform fuzzy comprehensive dynamic evaluation based on the historical transaction feature group sequence and the obtained candidate risk level group sequence, to obtain the candidate warning level sequence corresponding to the historical transaction feature group sequence; a model training unit, configured to train an untrained telecommunications network fraud warning model based on the historical transaction feature group sequence and the candidate warning level sequence, to obtain the telecommunications network fraud warning model; a second feature extraction unit, configured to extract features from real-time transaction data to generate real-time transaction features; and a second generation unit, configured to generate real-time warning levels for candidate accounts based on the real-time transaction features and the telecommunications network fraud warning model.

[0007] Thirdly, some embodiments of this disclosure provide an electronic device, including: one or more processors; and a storage device having one or more programs stored thereon, wherein when the one or more programs are executed by the one or more processors, the one or more processors implement the method described in any implementation of the first aspect above.

[0008] Fourthly, some embodiments of this disclosure provide a computer-readable medium having a computer program stored thereon, wherein the program, when executed by a processor, implements the method described in any of the implementations of the first aspect above.

[0009] The embodiments disclosed above have the following beneficial effects: by extracting features from the transaction data of fraudulent accounts corresponding to fraud gangs and classifying risks, a telecommunications network fraud early warning model is trained based on this. Experiments have shown that the telecommunications network fraud early warning model trained in this way can effectively identify and warn of abnormal fraudulent accounts. Attached Figure Description

[0010] The above and other features, advantages, and aspects of the embodiments of this disclosure will become more apparent from the accompanying drawings and the following detailed description. Throughout the drawings, the same or similar reference numerals denote the same or similar elements. It should be understood that the drawings are schematic, and elements are not necessarily drawn to scale.

[0011] Figure 1 This is a flowchart of some embodiments of the fraud early warning method based on the telecommunications network fraud early warning model according to this disclosure; Figure 2 It is the training error histogram corresponding to the sample data; Figure 3 Scatter plot of target values ​​corresponding to sample data and output values ​​corresponding to the telecom network fraud early warning model; Figure 4 This is a schematic diagram of the structure of some embodiments of the fraud warning device based on the telecommunications network fraud warning model according to the present disclosure; Figure 5 This is a schematic diagram of the structure of an electronic device suitable for implementing some embodiments of the present disclosure. Detailed Implementation

[0012] Embodiments of this disclosure will now be described in more detail with reference to the accompanying drawings. While some embodiments of this disclosure are shown in the drawings, it should be understood that this disclosure can be implemented in various forms and should not be construed as limited to the embodiments set forth herein. Rather, these embodiments are provided to provide a more thorough and complete understanding of this disclosure. It should be understood that the accompanying drawings and embodiments of this disclosure are for illustrative purposes only and are not intended to limit the scope of protection of this disclosure.

[0013] It should also be noted that, for ease of description, only the parts relevant to the invention are shown in the accompanying drawings. Unless otherwise specified, the embodiments and features described in this disclosure can be combined with each other.

[0014] It should be noted that the concepts of "first" and "second" mentioned in this disclosure are used only to distinguish different devices, modules or units, and are not used to limit the order of functions performed by these devices, modules or units or their interdependencies.

[0015] It should be noted that the terms "a" and "a plurality of" used in this disclosure are illustrative rather than restrictive, and those skilled in the art should understand that, unless otherwise expressly indicated in the context, they should be understood as "one or more".

[0016] The names of messages or information exchanged between multiple devices in the embodiments of this disclosure are for illustrative purposes only and are not intended to limit the scope of such messages or information.

[0017] This disclosure will now be described in detail with reference to the accompanying drawings and embodiments.

[0018] refer to Figure 1The flowchart 100 illustrates some embodiments of a fraud warning method based on a telecommunications network fraud warning model according to this disclosure. This fraud warning method based on a telecommunications network fraud warning model includes the following steps: Step 101: Extract features from each historical transaction data in the historical transaction data sequence to generate a historical transaction feature group, thus obtaining a historical transaction feature group sequence.

[0019] In some embodiments, the execution entity (e.g., a computing device) of the fraud warning method based on the telecommunications network fraud warning model can extract features from each historical transaction data in the historical transaction data sequence to generate a historical transaction feature group and obtain a historical transaction feature group sequence.

[0020] The historical transaction data sequence comprises transaction data corresponding to multiple fraudulent accounts. Specifically, the historical transaction data sequence can be transaction data corresponding to fraudulent accounts involved in telecommunications network fraud. Historical transaction feature groups include: first transfer interval, consecutive transfer interval, account balance, query frequency, vertical transfer level, and cross-regional transfer count. The first transfer interval represents the time interval between the arrival of fraudulent funds and the first fund transfer. The consecutive transfer interval represents the time interval between consecutive fund transfers. The account balance represents the balance within the corresponding bank account. The query frequency represents the frequency of balance inquiries for the bank account. The vertical transfer level represents the transfer level between different bank accounts. The cross-regional transfer count represents the number of transfers involving cross-regional or cross-domain transactions by the bank account.

[0021] In practice, through analysis of the transaction behavior of fraudulent accounts involved in telecommunications network fraud, the following main characteristics were found: (1) To prevent the defrauded funds from being traced or the fraudulent account from being frozen, the defrauded funds will be quickly transferred or cashed out after they are received; (2) To increase the difficulty of recovering the defrauded funds, the defrauded funds will be transferred out in a dispersed manner after they are received; (3) The fraudulent account is mainly a tool used by fraudsters to transfer defrauded funds, and generally there will not be a lot of funds (account balance) in the fraudulent account; (4) Before and after the defrauded funds are received, the fraudsters will frequently check the account balance; (5) Fraudsters often conduct multi-level transactions through multiple different bank accounts to mix illegal defrauded funds with legal funds in order to cover up the defrauded money; (6) Defrauded funds are often transferred across regions and domains multiple times to achieve the purpose of concealing their whereabouts. Based on this, this disclosure describes the transaction characteristics from six feature dimensions: first transfer interval, consecutive transfer interval, account balance, query frequency, vertical transfer level and cross-transfer number.

[0022] It should be noted that the aforementioned computing devices can be either hardware or software. When the computing device is hardware, it can be implemented as a distributed cluster consisting of multiple servers or terminal devices, or as a single server or a single terminal device. When the computing device is software, it can be installed on the hardware devices listed above. It can be implemented as, for example, multiple software programs or software modules used to provide distributed services, or as a single software program or software module. No specific limitations are made here.

[0023] In some optional implementations of certain embodiments, the aforementioned execution entity extracts features from each historical transaction in the historical transaction data sequence to generate a historical transaction feature group, including: Step S1: Extract the time interval from the arrival of funds to the first fund transfer in the historical transaction data, and use it as the first transfer interval included in the historical transaction feature group corresponding to the historical transaction data.

[0024] Step S2: Extract the time interval from the arrival of funds to the continuous transfer of funds in the historical transaction data, and use it as the continuous transfer interval included in the historical transaction feature group corresponding to the historical transaction data.

[0025] Step S3: Extract the account balance corresponding to the historical transaction data, and use it as the account balance included in the historical transaction feature group corresponding to the historical transaction data.

[0026] Step S4: Extract the account balance query frequency corresponding to the historical transaction data, and use it as the query frequency included in the historical transaction feature group corresponding to the historical transaction data.

[0027] Step S5: Determine the circulation level corresponding to the historical transaction data, which is the vertical circulation level included in the historical transaction feature group corresponding to the historical transaction data.

[0028] Step S6: Extract the number of cross-bank and cross-domain fund transfers from the historical transaction data, and use them as the cross-transfer counts included in the historical transaction feature group corresponding to the historical transaction data.

[0029] Step 102: For each historical transaction feature group in the historical transaction feature group sequence, generate a candidate risk level group corresponding to the historical transaction feature group.

[0030] In some embodiments, the aforementioned executing entity may generate a candidate risk level group for each historical transaction feature group in the historical transaction feature group sequence.

[0031] Among them, the candidate risk level represents the behavioral risk level corresponding to historical transaction characteristics. Specifically, the historical transaction characteristic group includes the first transfer interval, consecutive transfer interval, account balance, query frequency, vertical transfer level, and cross-transfer number. Therefore, the corresponding candidate risk level group includes 6 candidate risk levels. The candidate risk levels can be divided into five levels: I, II, III, IV, and V.

[0032] In practice, the relationship between historical transaction characteristics and corresponding candidate risk levels can be seen in Table 1 below: Table 1

[0033] Step 103: Perform fuzzy comprehensive dynamic evaluation based on the historical transaction feature group sequence and the obtained candidate risk level group sequence to obtain the candidate early warning level sequence corresponding to the historical transaction feature group sequence.

[0034] In some embodiments, the aforementioned executing entity may perform fuzzy comprehensive evaluation (FCES) based on the historical transaction feature group sequence and the obtained candidate risk level group sequence to obtain the candidate early warning level sequence corresponding to the historical transaction feature group sequence.

[0035] Among them, the candidate warning level is the account warning level for fraudulent accounts corresponding to historical transaction feature groups.

[0036] In some optional implementations of certain embodiments, the aforementioned execution entity performs fuzzy comprehensive dynamic evaluation based on the historical transaction feature group sequence and the obtained candidate risk level group sequence to obtain a candidate early warning level sequence corresponding to the historical transaction feature group sequence, including: Step S1: Determine the single-factor weighting reorganization using the following formula: , in, Indicates the serial number. are positive integers and The range of values ​​is , The single-factor weights corresponding to the first rotation interval. The single-factor weights corresponding to the continuous rotation intervals, The single-factor weight corresponding to the account balance. The single-factor weight corresponding to the query frequency. The single-factor weights corresponding to the vertical transition levels. The single-factor weights corresponding to the number of transitions. This indicates the number of fraudulent accounts corresponding to a historical transaction data sequence. Indicates the serial number. Represents the first in the sequence of historical transaction feature groups The first historical transaction feature group includes the first Historical transaction characteristics.

[0037] Step S2: For each historical transaction feature group in the historical transaction feature group sequence, perform the following processing steps: Step S21: Determine the first-level warning membership group, second-level warning membership group, third-level warning membership group, fourth-level warning membership group, and fifth-level warning membership group corresponding to the historical transaction feature group.

[0038] Among them, for the first in the historical transaction feature group sequence The first historical transaction feature group includes the first Historical transaction characteristics : when hour, ; when hour, ; when hour, ; when hour, ; when hour, , in, For (V) level 5 warning membership degree, (IV) Level 4 Warning Membership For (III) Level 3 early warning membership, For (II) Level 2 warning membership, (I) Level 1 Early Warning Membership The threshold for Level V alarms. The threshold for Level IV emergency response is [missing information]. The threshold for Level III emergency response is [not specified]. This is the threshold for Level II emergency situations.

[0039] Step S22: Based on the single-factor weighted reorganization and the primary warning membership group, determine the primary warning evaluation value using the following formula: , in, Indicates the serial number. This indicates the level 1 emergency response rating. This indicates the first-level early warning membership group corresponding to the historical transaction feature group. In single-factor weighted reorganization, the first factor is represented by the second factor. Individual factor weights.

[0040] Step S23: Based on the single-factor weighted reorganization and the secondary warning membership group, determine the secondary warning evaluation value using the following formula: , in, Indicates the serial number. This indicates the level 2 police incident assessment value. This indicates the secondary early warning membership group corresponding to the historical transaction feature group. In single-factor weighted reorganization, the first factor is represented by the second factor. Individual factor weights.

[0041] Step S24: Based on the single-factor weighted reorganization and the three-level early warning membership group, determine the three-level alarm evaluation value using the following formula: , in, Indicates the serial number. This indicates the level three emergency response rating. This indicates the three-level early warning membership group corresponding to the historical transaction feature group. In single-factor weighted reorganization, the first factor is represented by the second factor. Individual factor weights.

[0042] Step S25: Based on the single-factor weighted reorganization and the four-level early warning membership group, determine the level four alarm evaluation value using the following formula: , in, Indicates the serial number. This indicates the level four police incident assessment value. This represents the four-level early warning membership group corresponding to the historical transaction feature group. In single-factor weighted reorganization, the first factor is represented by the second factor. Individual factor weights.

[0043] Step S26: Based on the single-factor weighted reorganization and the five-level early warning membership group, determine the five-level alarm evaluation value using the following formula: , in, Indicates the serial number. This indicates the five-level emergency response rating. This indicates the five-level early warning membership group corresponding to the historical transaction feature group. In single-factor weighted reorganization, the first factor is represented by the second factor. Individual factor weights.

[0044] Step S27: Based on the Level 1, Level 2, Level 3, Level 4, and Level 5 alert evaluation values, determine the candidate warning level corresponding to the historical transaction feature group using the following formula: , in, This indicates the candidate warning level corresponding to the historical transaction feature group, where is the sequence number. Indicates the serial number. In single-factor weighted reorganization, the first factor is represented by the second factor. Each single-factor weight, where... Indicates the first The historical transaction characteristics corresponding to each single-factor weight are the corresponding crime evaluation values ​​in the first-level, second-level, third-level, fourth-level, and fifth-level crime evaluation values.

[0045] Step 104: Based on the historical transaction feature group sequence and the candidate warning level sequence, train the untrained telecommunications network fraud warning model to obtain the telecommunications network fraud warning model.

[0046] In some embodiments, the aforementioned executing entity may train an untrained telecommunications network fraud early warning model based on a sequence of historical transaction feature groups and a sequence of candidate early warning levels, thereby obtaining a telecommunications network fraud early warning model.

[0047] Among them, the telecommunications network fraud early warning model adopts a Bayesian Regularization Neural Network (BRNN).

[0048] In some optional implementations of some embodiments, the aforementioned executing entity trains an untrained telecommunications network fraud early warning model based on a historical transaction feature group sequence and a candidate early warning level sequence to obtain a telecommunications network fraud early warning model, including: Step S1: Initialize the model parameters corresponding to the untrained telecommunications network fraud early warning model.

[0049] In practice, the initialization of an untrained telecom network fraud early warning model corresponds to regularization optimization parameters (α, β) and network weight parameters.

[0050] Step S2: In response to the completion of model parameter initialization, the untrained telecommunications network fraud early warning model is trained using the historical transaction feature group in the historical transaction feature group sequence as training samples and the candidate early warning level corresponding to the historical transaction feature group in the candidate early warning level sequence as sample labels, to obtain the telecommunications network fraud early warning model.

[0051] In practice, the sum of squares of the network weight coefficients can be calculated. Sum of squared training errors and neural network error performance ,in: , in, Indicates the serial number. This represents the number of weight coefficients in the neural network. Indicates the first Each neural network weight coefficient.

[0052] in: , in, Indicates the serial number. This represents the number of weight coefficients in the neural network. Indicates the first The training error corresponding to each neural network weight coefficient.

[0053] in: , in, Represents the sum of squares of network weight coefficients The corresponding weights Represents the sum of squared training errors The corresponding weights.

[0054] Furthermore, the Hessian matrix is ​​approximated using the Gauss-Newton method to obtain the minimum point. Hessian matrix at time And further solve for the number of effective parameters. and optimal Bayesian regularization parameters , For the detailed solution process, please refer to the following formula: .

[0055] Step 105: Extract features from real-time transaction data to generate real-time transaction features.

[0056] In some embodiments, the aforementioned execution entity may extract features from real-time transaction data to generate real-time transaction features.

[0057] Real-time transaction data can be transaction data corresponding to suspicious bank accounts (candidate accounts). Real-time transaction characteristics include: first transfer interval, consecutive transfer interval, account balance, query frequency, vertical transfer level, and number of cross-transfers.

[0058] In practice, the generation of real-time transaction features can be found in step 101, which involves extracting features from historical transaction data to generate historical transaction feature groups. This will not be elaborated further here.

[0059] Step 106: Based on real-time transaction characteristics and the telecommunications network fraud early warning model, generate a real-time early warning level for candidate accounts.

[0060] In some embodiments, the aforementioned implementing entity may generate a real-time warning level for candidate accounts based on real-time transaction characteristics and a telecommunications network fraud early warning model.

[0061] In practice, the aforementioned implementing entities can input real-time transaction characteristics into the telecommunications network fraud early warning model to generate real-time early warning levels for candidate accounts.

[0062] The embodiments disclosed above have the following beneficial effects: by extracting features from the transaction data of fraudulent accounts corresponding to fraud gangs and classifying risks, a telecommunications network fraud early warning model is trained based on this. Experiments have shown that the telecommunications network fraud early warning model trained in this way can effectively identify and warn of abnormal fraudulent accounts.

[0063] Experimental simulation The experimental data (sample data) was based on transaction data (historical transaction data) from 50 telecommunications fraud cases involving fraudulent accounts. Risk warnings were also issued using transaction data (real-time transaction data) from 20 suspicious bank accounts.

[0064] The alarm thresholds corresponding to different warning levels are shown in Table 2 below: Table 2

[0065] The risk values ​​and warning levels of the fraudulent accounts involved in the above 50 telecommunications fraud cases are shown in Table 3 below: Table 3

[0066] The feature values ​​constructed from 50 sample data are used as input, and the warning level corresponding to the sample data is used as output. The optimal regularization parameters and neural network weight coefficients are approximated by the Gauss-Newton method, so that the telecom network fraud warning model can reach the optimal state. The number of hidden layers in the telecom network fraud warning model is set to 12, and the ratio between training data, validation data and test data is 7:1.5:1.5, with a total of 788 iterations.

[0067] First, see Figure 2 The training error histogram shown corresponds to the sample data. The horizontal axis of the training error histogram represents the training error "Errors", which is calculated as "Target - Output". The vertical axis "Instances" represents the amount of training and test data corresponding to each error interval.

[0068] Secondly, see Figure 3 The scatter plot shown represents the target value corresponding to the sample data and the output value corresponding to the telecommunications network fraud early warning model. The horizontal axis of the scatter plot corresponds to the target value "Target," and the vertical axis corresponds to the output value "Output." . Figure 3 The dashed line corresponds to the fitted line where the target value equals the output value; the red line corresponds to the fitted line formed by the data points corresponding to "target value - output value"; and the circles correspond to the data points corresponding to "target value - output value". The overall regression value R = 0.94521. Furthermore, the regression value R for the training data is 0.95232, and the regression value R for the test data is 0.92939.

[0069] The training results show that the errors between the training data, test data and the true values ​​are close to 0, and the regression coefficients R of the training data, test data and (overall) sample data are all greater than 0.9, indicating that the system's predicted values ​​are highly correlated with the actual output.

[0070] Using the feature values ​​constructed from the transaction data (real-time transaction data) corresponding to 20 suspected bank accounts (candidate accounts) as input, the warning level corresponding to the 20 suspected bank accounts is predicted through the telecommunications network fraud early warning model. The specific results are shown in Table 4 below: Table 4

[0071] Analysis revealed that the early warning results showed one suspected bank account each corresponding to Level I and II warnings, nine suspected bank accounts corresponding to Level III, and nine suspected bank accounts corresponding to Level IV. Specifically, for Level I and II warnings, the public security organs can coordinate with the banking system to freeze the accounts and initiate investigations; for Level III, the public security organs can collaborate with banks, telecommunications, and internet companies to promptly issue warnings to the suspected account holders and block the remittance channels; and for Level IV, the public security organs should strengthen monitoring of suspicious accounts and take corresponding preventative measures based on changing trends in the reports.

[0072] Further reference Figure 4 As an implementation of the methods shown in the above figures, this disclosure provides some embodiments of a fraud early warning device based on a telecommunications network fraud early warning model. These device embodiments are similar to... Figure 1 Corresponding to the method embodiments shown, this fraud warning device based on the telecommunications network fraud warning model can be specifically applied to various electronic devices.

[0073] like Figure 4As shown, a fraud early warning device 400 based on a telecommunications network fraud early warning model in some embodiments includes: a first feature extraction unit 401, a first generation unit 402, a fuzzy comprehensive dynamic evaluation unit 403, a model training unit 404, a second feature extraction unit 405, and a second generation unit 406. The first feature extraction unit 401 is configured to extract features from each historical transaction data in the historical transaction data sequence to generate a historical transaction feature group, resulting in a historical transaction feature group sequence. The historical transaction data sequence consists of transaction data corresponding to multiple fraudulent accounts. The historical transaction feature group includes: first transfer interval, consecutive transfer interval, account balance, query frequency, vertical transfer level, and cross-transfer number. The first generation unit 402 is configured to perform feature extraction on each historical transaction feature group sequence... The system comprises: a historical transaction feature group, generating candidate risk level groups corresponding to the historical transaction feature group; a fuzzy comprehensive dynamic evaluation unit 403, configured to perform fuzzy comprehensive dynamic evaluation based on the historical transaction feature group sequence and the obtained candidate risk level group sequence, to obtain a candidate warning level sequence corresponding to the historical transaction feature group sequence; a model training unit 404, configured to train an untrained telecommunications network fraud warning model based on the historical transaction feature group sequence and the candidate warning level sequence, to obtain a telecommunications network fraud warning model; a second feature extraction unit 405, configured to extract features from real-time transaction data to generate real-time transaction features; and a second generation unit 406, configured to generate real-time warning levels for candidate accounts based on real-time transaction features and the telecommunications network fraud warning model.

[0074] It is understandable that the various units recorded in the fraud early warning device 400 based on the telecommunications network fraud early warning model are related to the reference... Figure 1 The steps in the described method correspond to each other. Therefore, the operations, features, and beneficial effects described above for the method also apply to the fraud early warning device 400 based on the telecommunications network fraud early warning model and the units contained therein, and will not be repeated here.

[0075] The following is for reference. Figure 5 It shows a schematic diagram of the structure of an electronic device (e.g., a computing device) 500 suitable for implementing some embodiments of the present disclosure. Figure 5 The electronic device shown is merely an example and should not be construed as limiting the functionality and scope of the embodiments of this disclosure.

[0076] like Figure 5As shown, the electronic device 500 may include a processing unit (e.g., a central processing unit, a graphics processing unit, etc.) 501, which can perform various appropriate actions and processes according to a program stored in a read-only memory 502 or a program loaded from a storage device 508 into a random access memory 503. The random access memory 503 also stores various programs and data required for the operation of the electronic device 500. The processing unit 501, the read-only memory 502, and the random access memory 503 are interconnected via a bus 504. An input / output interface 505 is also connected to the bus 504.

[0077] Typically, the following devices can be connected to the input / output interface 505: input devices 506 including, for example, a touchscreen, touchpad, keyboard, mouse, camera, microphone, accelerometer, gyroscope, etc.; output devices 507 including, for example, a liquid crystal display (LCD), speaker, vibrator, etc.; storage devices 508 including, for example, magnetic tape, hard disk, etc.; and communication devices 509. Communication device 509 allows electronic device 500 to communicate wirelessly or wiredly with other devices to exchange data. Although Figure 5 An electronic device 500 with various devices is shown; however, it should be understood that it is not required to implement or possess all of the devices shown. More or fewer devices may be implemented or possessed alternatively. Figure 5 Each box shown can represent a device or multiple devices as needed.

[0078] In particular, according to some embodiments of this disclosure, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, some embodiments of this disclosure include a computer program product comprising a computer program carried on a computer-readable medium, the computer program containing program code for performing the methods shown in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network via a communication device 509, or installed from a storage device 508, or installed from a read-only memory 502. When the computer program is executed by the processing device 501, it performs the functions defined above in the methods of some embodiments of this disclosure.

[0079] It should be noted that, in some embodiments of this disclosure, the computer-readable medium may be a computer-readable signal medium or a computer-readable storage medium, or any combination thereof. A computer-readable storage medium may be, for example,—but not limited to—an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples of a computer-readable storage medium may include, but are not limited to: an electrical connection having one or more wires, a portable computer disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage device, magnetic storage device, or any suitable combination thereof. In some embodiments of this disclosure, a computer-readable storage medium may be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. In some embodiments of this disclosure, a computer-readable signal medium may include a data signal propagated in baseband or as part of a carrier wave, carrying computer-readable program code. Such propagated data signals may take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. A computer-readable signal medium can be any computer-readable medium other than a computer-readable storage medium, which can send, propagate, or transmit a program for use by or in connection with an instruction execution system, apparatus, or device. The program code contained on the computer-readable medium can be transmitted using any suitable medium, including but not limited to: wires, optical fibers, RF (radio frequency), etc., or any suitable combination thereof.

[0080] In some implementations, clients and servers can communicate using any currently known or future-developed network protocol such as HTTP (Hypertext Transfer Protocol) and can interconnect with digital data communication (e.g., communication networks) of any form or medium. Examples of communication networks include local area networks (“LANs”), wide area networks (“WANs”), the Internet (e.g., the Internet of Things), and peer-to-peer networks (e.g., ad hoc peer-to-peer networks), as well as any currently known or future-developed networks.

[0081] The aforementioned computer-readable medium may be included in the aforementioned electronic device; or it may exist independently and not assembled into the electronic device. The aforementioned computer-readable medium carries one or more programs that, when executed by the electronic device, cause the electronic device to: extract features from each historical transaction data in the historical transaction data sequence to generate historical transaction feature groups, resulting in a historical transaction feature group sequence, wherein the historical transaction data sequence consists of transaction data corresponding to multiple fraudulent accounts, and the historical transaction feature groups include: first transfer interval, consecutive transfer interval, account balance, query frequency, vertical transfer level, and cross-transfer number; for each historical transaction feature group in the historical transaction feature group sequence, generate a candidate risk level group corresponding to the historical transaction feature group; perform fuzzy comprehensive dynamic evaluation based on the historical transaction feature group sequence and the obtained candidate risk level group sequence to obtain a candidate early warning level sequence corresponding to the historical transaction feature group sequence; train an untrained telecommunications network fraud early warning model based on the historical transaction feature group sequence and the candidate early warning level sequence to obtain a telecommunications network fraud early warning model; extract features from real-time transaction data to generate real-time transaction features; and generate real-time early warning levels for candidate accounts based on the real-time transaction features and the telecommunications network fraud early warning model.

[0082] Computer program code for performing operations of some embodiments of this disclosure can be written in one or more programming languages ​​or a combination thereof, including object-oriented programming languages ​​such as Java, Smalltalk, and C++, and conventional procedural programming languages ​​such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving remote computers, the remote computer can be connected to the user's computer via any type of network—including a local area network (LAN) or a wide area network (WAN)—or can be connected to an external computer (e.g., via the Internet using an Internet service provider).

[0083] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of this disclosure. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, can be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.

[0084] The functions described above in this document can be performed at least in part by one or more hardware logic components. For example, exemplary types of hardware logic components that can be used, without limitation, include: field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), system-on-a-chip (SoCs), complex programmable logic devices (CPLDs), and so on.

[0085] The above description is merely a selection of preferred embodiments of this disclosure and an explanation of the technical principles employed. Those skilled in the art should understand that the scope of the invention involved in the embodiments of this disclosure is not limited to technical solutions formed by specific combinations of the above-described technical features, but should also cover other technical solutions formed by arbitrary combinations of the above-described technical features or their equivalents without departing from the above-described inventive concept. For example, technical solutions formed by substituting the above-described features with (but not limited to) technical features with similar functions disclosed in the embodiments of this disclosure.

Claims

1.A fraud early warning method based on a fraud early warning model of a telecommunications network, characterized by, The method comprises the following steps: feature extraction is performed on each historical transaction data in a historical transaction data sequence to generate a historical transaction feature group, thereby obtaining a historical transaction feature group sequence, wherein the historical transaction data sequence is transaction data corresponding to a plurality of fraudulent accounts, and the historical transaction feature group comprises a first transfer interval, a continuous transfer interval, an account balance, an inquiry frequency, a vertical transfer level, and a cross-transfer number; for each historical transaction feature group in the historical transaction feature group sequence, a candidate risk level group corresponding to the historical transaction feature group is generated; fuzzy comprehensive dynamic evaluation is performed on the historical transaction feature group sequence and the obtained candidate risk level group sequence, thereby obtaining a candidate early warning level sequence corresponding to the historical transaction feature group sequence; a telecommunication network fraud early warning model is trained based on the historical transaction feature group sequence and the candidate early warning level sequence, thereby obtaining the telecommunication network fraud early warning model; feature extraction is performed on real-time transaction data to generate real-time transaction features; a real-time early warning level for a candidate account is generated based on the real-time transaction features and the telecommunication network fraud early warning model. 2.The fraud alerting method based on the fraud alerting model of a telecom network fraud according to claim 1, characterized in that, The feature extraction performed on each historical transaction data in the historical transaction data sequence to generate the historical transaction feature group comprises: extracting a time interval from a fund arrival to a first fund transfer in the historical transaction data as the first transfer interval included in the historical transaction feature group corresponding to the historical transaction data; extracting a time interval from a fund arrival to a continuous fund transfer in the historical transaction data as the continuous transfer interval included in the historical transaction feature group corresponding to the historical transaction data; extracting an account balance corresponding to the historical transaction data as the account balance included in the historical transaction feature group corresponding to the historical transaction data; extracting an account balance inquiry frequency corresponding to the historical transaction data as the inquiry frequency included in the historical transaction feature group corresponding to the historical transaction data; determining a transfer level corresponding to the historical transaction data as the vertical transfer level included in the historical transaction feature group corresponding to the historical transaction data; extracting a cross-bank and cross-domain fund transfer number in the historical transaction data as the cross-transfer number included in the historical transaction feature group corresponding to the historical transaction data. 3.The fraud alerting method based on the fraud alerting model of a telecom network fraud according to claim 2, characterized in that, The fuzzy comprehensive dynamic evaluation performed on the historical transaction feature group sequence and the obtained candidate risk level group sequence to obtain the candidate early warning level sequence corresponding to the historical transaction feature group sequence comprises: a single-factor weight group is determined through the following formula: , wherein, denotes a serial number, is a positive integer and the value range of , is a single-factor weight corresponding to a first transfer interval, is a single-factor weight corresponding to a continuous transfer interval, is a single-factor weight corresponding to an account balance, is a single-factor weight corresponding to a query frequency, is a single-factor weight corresponding to a vertical transfer level, is a single-factor weight corresponding to a cross-transfer number, denotes a number of fraudulent accounts corresponding to a historical transaction data sequence, denotes a serial number, denotes a th historical transaction feature included in a th historical transaction feature group in a historical transaction feature group sequence. 4.The fraud alerting method based on the fraud alerting model of a telecom network fraud according to claim 3, characterized in that, The fuzzy comprehensive dynamic evaluation performed on the historical transaction feature group sequence and the obtained candidate risk level group sequence to obtain the candidate early warning level sequence corresponding to the historical transaction feature group sequence further comprises: for each historical transaction feature group in the historical transaction feature group sequence, the following processing steps are performed: a first-level early warning membership degree group, a second-level early warning membership degree group, a third-level early warning membership degree group, a fourth-level early warning membership degree group, and a fifth-level early warning membership degree group corresponding to the historical transaction feature group are determined; a first-level warning situation evaluation value is determined through the following formula based on the single-factor weight group and the first-level early warning membership degree group: , in, Indicates the serial number. This indicates the level 1 emergency response rating. This indicates the first-level early warning membership group corresponding to the historical transaction feature group. In single-factor weighted reorganization, the first factor is represented by the second factor. Individual factor weights; a second-level warning situation evaluation value is determined through the following formula based on the single-factor weight group and the second-level early warning membership degree group: , in, Indicates the serial number. This indicates the level 2 police incident assessment value. This indicates the secondary early warning membership group corresponding to the historical transaction feature group. In single-factor weighted reorganization, the first factor is represented by the second factor. Individual factor weights; a third-level warning situation evaluation value is determined through the following formula based on the single-factor weight group and the third-level early warning membership degree group: , in, Indicates the serial number. This indicates the level three emergency response rating. This indicates the three-level early warning membership group corresponding to the historical transaction feature group. In single-factor weighted reorganization, the first factor is represented by the second factor. Individual factor weights; According to the single factor weight group and the four-level early warning membership group, the four-level alarm evaluation value is determined through the following formula: , in, Indicates the serial number. This indicates the level four police incident assessment value. This represents the four-level early warning membership group corresponding to the historical transaction feature group. In single-factor weighted reorganization, the first factor is represented by the second factor. Individual factor weights; According to the single factor weight group and the five-level early warning membership group, the five-level alarm evaluation value is determined through the following formula: , wherein, denotes a serial number, denotes a five-level police situation evaluation value, denotes a five-level early warning membership group corresponding to a historical transaction feature group, denotes a single factor weight in a single factor weight group. denotes a single factor weight in a single factor weight group. 5.The fraud alerting method based on the fraud alerting model of a telecom network fraud according to claim 4, characterized in that, The fuzzy comprehensive dynamic evaluation unit is configured to perform fuzzy comprehensive dynamic evaluation according to the historical transaction feature group sequence and the obtained candidate risk level group sequence, to obtain a candidate early warning level sequence corresponding to the historical transaction feature group sequence. According to the first-level alarm evaluation value, the second-level alarm evaluation value, the third-level alarm evaluation value, the fourth-level alarm evaluation value, and the fifth-level alarm evaluation value, the candidate early warning level corresponding to the historical transaction feature group is determined through the following formula: , wherein, represents the candidate early warning level corresponding to the historical transaction feature group, represents the serial number, represents the serial number, represents the th single factor weight in the single factor weight group, wherein, represents the th historical transaction feature corresponding to the single factor weight, the alarm evaluation value corresponding to the first-level alarm evaluation value, the second-level alarm evaluation value, the third-level alarm evaluation value, the fourth-level alarm evaluation value, and the fifth-level alarm evaluation value. 6.The fraud alerting method based on the fraud alerting model of a telecom network fraud according to claim 5, characterized in that, The model training unit is configured to perform model training on the untrained telecom network fraud early warning model according to the historical transaction feature group sequence and the candidate early warning level sequence, to obtain the telecom network fraud early warning model. The model parameter corresponding to the untrained telecom network fraud early warning model is initialized; In response to the model parameter initialization being completed, the historical transaction feature group in the historical transaction feature group sequence is taken as a training sample, and the candidate early warning level corresponding to the historical transaction feature group in the candidate early warning level sequence is taken as a sample label, to perform model training on the untrained telecom network fraud early warning model, to obtain the telecom network fraud early warning model. 7.The fraud alerting method based on the fraud alerting model of a telecom network fraud according to claim 6, characterized in that, The model parameter corresponding to the untrained telecom network fraud early warning model is initialized; The model parameter corresponding to the untrained telecom network fraud early warning model is initialized; 8.A fraud early warning device based on a fraud early warning model of a telecommunications network, characterized by, The first feature extraction unit is configured to perform feature extraction on each historical transaction data in the historical transaction data sequence to generate a historical transaction feature group, to obtain a historical transaction feature group sequence, wherein the historical transaction data sequence is transaction data corresponding to a plurality of fraud accounts, and the historical transaction feature group includes a first transfer interval, a continuous transfer interval, an account balance, a query frequency, a vertical transfer level, and a cross transfer number; The first generation unit is configured to generate, for each historical transaction feature group in the historical transaction feature group sequence, a candidate risk level group corresponding to the historical transaction feature group; The fuzzy comprehensive dynamic evaluation unit is configured to perform fuzzy comprehensive dynamic evaluation according to the historical transaction feature group sequence and the obtained candidate risk level group sequence, to obtain a candidate early warning level sequence corresponding to the historical transaction feature group sequence; The model training unit is configured to perform model training on the untrained telecom network fraud early warning model according to the historical transaction feature group sequence and the candidate early warning level sequence, to obtain the telecom network fraud early warning model; The second feature extraction unit is configured to perform feature extraction on real-time transaction data to generate real-time transaction features; The second generation unit is configured to generate a real-time early warning level for a candidate account according to the real-time transaction features and the telecom network fraud early warning model. One or more processors; 9. An electronic device, comprising: A storage device having one or more programs stored thereon; When the one or more programs are executed by the one or more processors, the one or more processors implement the method of any one of claims 1 to 7. A computer program is stored thereon, wherein the computer program is executed by a processor to implement the method of any one of claims 1 to 7. ​ 10. A computer readable medium characterized by ​