Anomaly Detection Method, Apparatus, Device, and Storage Medium

By constructing a connected graph set and calculating the flow rate, the problem of low accuracy when detecting sparse graphs in the prior art is solved, and efficient abnormal detection of false transactions and malicious reviews is achieved.

CN110490598BActive Publication Date: 2025-05-27BEIJING SANKUAI ONLINE TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN201910782984.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2019-08-23
Publication Date
2025-05-27
Estimated Expiration
2039-08-23

AI Technical Summary

Technical Problem

When the prior art conducts abnormal detection of false transactions and malicious reviews, it is necessary to establish a topological relationship diagram containing a large amount of label data, and any connected graph needs to contain a large amount of label data, resulting in a low accuracy rate when abnormal detection of sparse graphs with less label data.

Method used

By constructing a collection of connected graphs, several collections of graphs are generated, and the flow of each connected graph is calculated, and horizontal comparison is performed to determine the abnormal connection graph, thereby determining the abnormal user and/or abnormal merchant.

Benefits of technology

This method does not require the establishment of a topological relationship diagram of a large number of label data, nor does any connected graph need to contain a large number of label data. It can effectively detect abnormalities on sparse graphs with fewer label data, which has high accuracy, is simple and efficient, has strong practicality and applicability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN110490598B_ABST
    Figure CN110490598B_ABST
Patent Text Reader

Abstract

The present application provides an anomaly detection method, apparatus, device and storage medium, relating to the fields of computer and Internet technologies. The method includes: by constructing a set of connected graphs, generating g sets of graphs according to n connected graphs. For the i-th set of graphs among the g sets of graphs, calculate the throughput of each connected graph in the i-th set of graphs. According to the throughput of each connected graph in the i-th set of graphs, determine the abnormal connected graphs in the i-th set of graphs. According to the abnormal connected graphs, determine abnormal users and / or abnormal merchants. The embodiments of the present application can effectively perform anomaly detection on sparse graphs with less labeled data, with high accuracy, being simple and efficient, and having strong practicability and applicability.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Embodiments of the present application relate to the fields of computer and Internet technologies, and particularly to an anomaly detection method, apparatus, device, and storage medium. Background Art

[0002] With the progress of network technologies, e-commerce platforms and online payment platforms are also developing rapidly, and a large number of transaction behaviors and evaluation behaviors occur every day. Therefore, it is necessary to perform anomaly detection on false transactions and malicious reviews among them.

[0003] Taking the anomaly detection of false transactions as an example, in the related art, users and merchants involved in false transactions are called fraudsters. A topological relationship graph is constructed based on a large amount of acquired labeled data (such as data on the flow of funds, associated information of trading parties, etc.), and the pagerank (web page ranking) algorithm is used for iterative update to rapidly accumulate the scores of fraudsters. When the score of a fraudster is higher than a preset value, the fraudster can be discovered. Summary of the Invention

[0004] The present application provides an anomaly detection method, apparatus, device, and storage medium. The technical solution includes:

[0005] On the one hand, an embodiment of the present application provides an anomaly detection method, and the method includes:

[0006] Construct a set of connected graphs, where the set of connected graphs includes n connected graphs, each connected graph includes at least one user node and at least one merchant node. Among them, the edge connecting the user node and the merchant node is used to represent that there is an association relationship between the user corresponding to the user node and the merchant corresponding to the merchant node, and n is an integer greater than 1;

[0007] Generate g sets of graphs according to the n connected graphs, and each set of graphs includes multiple connected graphs whose number of nodes meets a preset condition, and g is a positive integer;

[0008] For the i-th set of graphs in the g sets of graphs, calculate the throughput of each connected graph in the i-th set of graphs, where the throughput is used to indicate the frequency of interaction between users and merchants in the connected graph, and i is a positive integer less than or equal to g;

[0009] Determine the abnormal connected graphs in the i-th set of graphs according to the throughput of each connected graph in the i-th set of graphs;

[0010] Determine abnormal users and / or abnormal merchants according to the abnormal connected graphs.

[0011] On the other hand, an embodiment of the present application provides an anomaly detection apparatus, and the apparatus includes:

[0012] A connected graph construction module for constructing a set of connected graphs, the set of connected graphs including n connected graphs, each connected graph including at least one user node and at least one merchant node, wherein an edge connecting the user node and the merchant node is used to represent an association relationship between the user corresponding to the user node and the merchant corresponding to the merchant node, and n is an integer greater than 1;

[0013] A graph set generation module for generating g graph sets according to the n connected graphs, each graph set including a plurality of connected graphs whose number of nodes meets a preset condition, and g is a positive integer;

[0014] A throughput calculation module for calculating the throughput of each connected graph in the i-th graph set among the g graph sets, the throughput being used to indicate the frequency of interaction between users and merchants in the connected graph, and i being a positive integer less than or equal to g;

[0015] An abnormal graph determination module for determining an abnormal connected graph in the i-th graph set according to the throughput of each connected graph in the i-th graph set;

[0016] An abnormal person determination module for determining abnormal users and / or abnormal merchants according to the abnormal connected graph.

[0017] In another aspect, an embodiment of the present application provides a computer device, which includes a processor and a memory, and a computer program is stored in the memory, and the computer program is loaded and executed by the processor to implement the above abnormal detection method.

[0018] In still another aspect, an embodiment of the present application provides a computer-readable storage medium, in which a computer program is stored, and the computer program is loaded and executed by a processor to implement the above abnormal detection method.

[0019] The technical solution provided by the embodiment of the present application can bring the following beneficial effects:

[0020] By constructing a set of connected graphs, several graph sets are generated according to each connected graph included in the set of connected graphs. For any one graph set, by calculating the throughput of each connected graph in the graph set, a horizontal comparison is made on each connected graph accordingly, and an abnormal connected graph is determined therefrom. Furthermore, an abnormal user and / or an abnormal merchant are determined based on the abnormal connected graph. Since the technical solution provided by the embodiments of the present application performs anomaly detection through horizontal comparison of multiple connected graphs, there is no need to establish a topological relationship graph containing a large amount of labeled data, and any connected graph does not need to contain a large amount of labeled data either. It can effectively perform anomaly detection on sparse graphs with less labeled data, with high accuracy, being simple and efficient, and having strong practicability and applicability. BRIEF DESCRIPTION OF THE DRAWINGS

[0021] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the following drawings are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.

[0022] Figure 1 is a flowchart of an anomaly detection method shown in an exemplary embodiment of the present application;

[0023] Figure 2 is a schematic diagram of graph set generation shown in an exemplary embodiment of the present application;

[0024] Figure 3 is a schematic diagram of target connected graph division shown in an exemplary embodiment of the present application;

[0025] Figure 4 is a block diagram of an anomaly detection device provided in an exemplary embodiment of the present application;

[0026] Figure 5 is a block diagram of an anomaly detection device provided in another exemplary embodiment of the present application;

[0027] Figure 6 is a block diagram of the structure of a computer device provided in an exemplary embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0028] Here, the exemplary embodiments will be described in detail, and the examples are shown in the drawings. When the following description refers to the drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with the present application. On the contrary, they are only examples of methods consistent with some aspects of the present application as detailed in the appended claims.

[0029] Figure 1 It is a flowchart of an anomaly detection method shown according to an exemplary embodiment of the present application. This method can be applied to a computer device, which can be any electronic device with computing and storage capabilities, such as a PC (Personal Computer), a server, etc. Combining Figure 1 , the method may include the following steps:

[0030] Step 101, construct a set of connected graphs. The set of connected graphs includes n connected graphs, where n is an integer greater than 1.

[0031] Each connected graph includes at least one user node and at least one merchant node. Among them, the edge connecting the user node and the merchant node is used to represent the association relationship between the user corresponding to the user node and the merchant corresponding to the merchant node. Each connected graph includes nodes and edges connecting the nodes. The nodes include user nodes and merchant nodes. Each user node corresponds to a user, and each merchant node corresponds to a merchant.

[0032] The set of connected graphs can be constructed according to the association relationship between users and merchants. The above-mentioned association relationship can be a direct association relationship. That is, for each edge, the association relationship it represents is determined only by one user and one merchant corresponding to this edge, without being determined by other users or other merchants other than this one user and this one merchant.

[0033] Step 102, generate g sets of graphs according to the n connected graphs. Each set of graphs includes multiple connected graphs whose number of nodes meets a preset condition, where g is a positive integer.

[0034] Each connected graph belongs to at most one set of graphs, and one set of graphs includes at least two connected graphs.

[0035] Optionally, the preset condition refers to a condition preset for dividing the set of graphs. For example, the preset condition can be that the number of nodes is the same, or the number of nodes is similar.

[0036] Optionally, two connected graphs with the same number of nodes mean that the total number of nodes in these two connected graphs is the same. The number of nodes in a connected graph refers to the sum of the number of user nodes and the number of merchant nodes included in the connected graph. For example, there are 5 user nodes and 3 merchant nodes in connected graph A, and 4 user nodes and 4 merchant nodes in connected graph B. The sum of the number of user nodes and the number of merchant nodes in connected graph A and connected graph B is 8. Then, the number of nodes in connected graph A and connected graph B is the same, and these two connected graphs can belong to the same set of graphs.

[0037] Optionally, two connected graphs with similar numbers of nodes refer to the case where the difference in the numbers of nodes between the two connected graphs is less than or equal to a preset difference. For example, if the preset difference is set to 2, in connected graph C, there are 2 user nodes and 2 merchant nodes, and in connected graph D, there are 3 user nodes and 2 merchant nodes. The number of nodes in connected graph C is 4, and the number of nodes in connected graph D is 5. The difference in the numbers of nodes between these two connected graphs is 1, which is less than the preset difference of 2. This indicates that the numbers of nodes in connected graph C and connected graph D are similar, and these two connected graphs can belong to the same graph set.

[0038] Exemplarily, assume that the connected graph set includes 22 connected graphs, and their numbers of nodes are respectively: 3, 4, 5, 5, 6, 6, 6, 7, 7, 7, 8, 8, 8, 8, 8, 9, 9, 9, 9, 10, 10, 11. The above preset difference is 2. Then, 3 connected graphs with 6 nodes generate graph set A, 3 connected graphs with 7 nodes generate graph set B, 5 connected graphs with 8 nodes generate graph set C, 4 connected graphs with 9 nodes generate graph set D, 4 connected graphs with 3, 4, and 5 nodes generate graph set E, and 3 connected graphs with 10 and 11 nodes generate graph set F. That is, a total of 6 graph sets are generated.

[0039] Step 103, for the i-th graph set among the g graph sets, calculate the throughput of each connected graph in the i-th graph set, where i is a positive integer less than or equal to g.

[0040] The throughput is used to indicate the frequency of interaction between users and merchants in a connected graph.

[0041] Optionally, for the anomaly detection of fraudulent transactions, the interaction between users and merchants can be represented as the transaction behavior between users and merchants; for the anomaly detection of malicious review brushing, the interaction between users and merchants can be represented as the evaluation behavior between users and merchants.

[0042] Among them, for a certain connected graph in the i-th graph set, the greater the difference between the throughput of this connected graph and the throughputs of other connected graphs in the i-th graph set, the more frequent the interaction between users and merchants in this connected graph is compared to other connected graphs in the i-th graph set. For example, when there is a positive correlation between the throughput of a connected graph and the frequency of interaction between users and merchants in the connected graph, for a certain connected graph in the i-th graph set, the greater the throughput of this connected graph compared to the throughputs of other connected graphs in the i-th graph set, the more frequent the interaction between users and merchants in this connected graph is compared to other connected graphs in the i-th graph set.

[0043] The throughput can be determined by weights. For example, the sum of the weights of all edges in a connected graph can be used as the throughput of the connected graph. The weights can be determined by the transaction behaviors between users and merchants, or by the evaluation behaviors between users and merchants.

[0044] In an exemplary embodiment, step 103 above may include: for the j-th connected graph in the i-th graph set, calculate the sum of the weights corresponding to each edge of the j-th connected graph to obtain the throughput of the j-th connected graph, where j is a positive integer. Among them, the weights are used to indicate the frequency of interaction between users and merchants with an association relationship. In the above manner, a method for calculating the throughput of a connected graph is provided, which is simple and efficient.

[0045] Step 104, determine the abnormal connected graphs in the i-th graph set according to the throughputs of the respective connected graphs in the i-th graph set.

[0046] For a certain connected graph in the i-th graph set, the greater the difference between the throughput of this connected graph and the throughputs of other connected graphs in the i-th graph set, the more frequent the interaction between users and merchants in this connected graph compared to other connected graphs in the i-th graph set. Therefore, for the connected graphs in the i-th graph set, if its throughput is too large compared to the throughputs of other connected graphs, it means that the interaction between users and merchants in this connected graph is too frequent, and then this connected graph can be regarded as an abnormal connected graph.

[0047] Step 105, determine abnormal users and / or abnormal merchants according to the abnormal connected graphs.

[0048] Optionally, the users corresponding to each user node included in the abnormal connected graph are used as abnormal users, and the merchants corresponding to each merchant node included in the abnormal connected graph are used as abnormal merchants.

[0049] Optionally, find out the users and merchants corresponding to each user node and merchant node included in the abnormal connected graph, and further screen out the abnormal users and abnormal merchants among them. Optionally, the method for further screening abnormal users and abnormal merchants can be automatic screening through a set algorithm or manual screening, and the embodiments of the present application do not limit this.

[0050] It should be noted that in this embodiment, mainly taking the i-th graph set as an example, the process of determining the abnormal graph set from the i-th graph set and determining abnormal users and / or abnormal merchants is introduced. The i-th graph set can be any one of the above g graph sets, that is, for any one of the above g graph sets, the method process introduced in the above embodiments can be used to determine abnormal users and / or abnormal merchants.

[0051] In summary, in the technical solution provided by the embodiments of the present application, by constructing a set of connected graphs, several graph sets are generated according to each connected graph included in the set of connected graphs. For any graph set, by calculating the throughput of each connected graph in the graph set, a horizontal comparison is made on each connected graph accordingly, and an abnormal connected graph is determined therefrom, and then an abnormal user and / or an abnormal merchant are determined according to the abnormal connected graph. Since the technical solution provided by the embodiments of the present application performs anomaly detection through horizontal comparison of multiple connected graphs with the same or similar number of nodes, any connected graph does not need to include a large amount of label data, and can effectively perform anomaly detection on sparse graphs with less label data, with high accuracy, simplicity and efficiency, and strong practicability and applicability.

[0052] As introduced above, the technical solution provided by the embodiments of the present application can detect abnormal transactions and can also perform anomaly detection on malicious brushing of reviews.

[0053] In an exemplary embodiment, if it is to detect abnormal transactions, then in step 101 above, a set of connected graphs can be constructed according to the transaction data between users and merchants, and step 101 can include the following sub-steps:

[0054] 1. Obtain multiple pieces of transaction data, and each piece of transaction data is used to represent a transaction behavior between a user and a merchant;

[0055] 2. Construct a set of connected graphs according to the multiple pieces of transaction data.

[0056] Optionally, the transaction data includes but is not limited to at least one of the following: transaction amount, number of transactions, and number of natural days of transactions. Among them, for users and merchants with transaction behaviors, an edge is established between the user node corresponding to the user and the merchant node corresponding to the merchant, and the weight corresponding to the edge is used to indicate the frequency of transactions between the user and the merchant with transaction behaviors.

[0057] Optionally, the weight can be determined by at least one of the transaction amount, number of transactions, and number of natural days of transactions between the user and the merchant. For example, the transaction amount between the user and the merchant with transaction behaviors can be used as the weight corresponding to the edge; or, the number of transactions between the user and the merchant with transaction behaviors can also be used as the weight corresponding to the edge; or, the number of natural days of transactions between the user and the merchant with transaction behaviors can also be used as the weight corresponding to the edge; or, the transaction frequency between the user and the merchant with transaction behaviors can also be obtained according to the number of transactions and the number of natural days of transactions, so that this transaction frequency can be used as the weight corresponding to the edge, and so on.

[0058] In the above manner, a set of connected graphs is constructed based on the transaction data between users and merchants, so that the set of connected graphs can be further processed and analyzed to find users and merchants with abnormal transactions.

[0059] In an exemplary embodiment, if malicious review brushing is detected, the set of connected graphs can be constructed according to the review data between users and merchants in step 101 above. Step 101 may include the following sub-steps:

[0060] 1. Obtain multiple pieces of review data, each piece of review data being used to represent a review behavior between a user and a merchant;

[0061] 2. Construct a set of connected graphs according to the multiple pieces of review data.

[0062] Optionally, the review data includes, but is not limited to, at least one of the following: the number of review characters, the number of reviews, and the number of natural days of reviews. Among them, for users and merchants with review behaviors, an edge is established between the user node corresponding to the user and the merchant node corresponding to the merchant, and the weight corresponding to the edge is used to indicate the frequency of reviews between the user and the merchant with review behaviors.

[0063] Optionally, the weight can be determined by at least one of the number of review characters, the number of reviews, and the number of natural days of reviews between the user and the merchant. For example, the number of review characters between the user and the merchant with review behaviors can be used as the weight corresponding to the edge; or, the number of reviews between the user and the merchant with review behaviors can also be used as the weight corresponding to the edge; or, the number of natural days of reviews between the user and the merchant with review behaviors can also be used as the weight corresponding to the edge; or, the review frequency between the user and the merchant with review behaviors can also be obtained according to the number of reviews and the number of natural days of reviews, so that the review frequency can be used as the weight corresponding to the edge, and so on.

[0064] In the above manner, a set of connected graphs is constructed based on the review data between users and merchants, so that the set of connected graphs can be further processed and analyzed to find users and merchants with malicious review brushing.

[0065] In an exemplary embodiment, step 102 above may include: generating at least one first type of graph set according to n connected graphs, where the number of nodes in each connected graph included in each first type of graph set is the same, and the number of connected graphs included in each first type of graph set is greater than a first threshold; and / or generating at least one second type of graph set according to n connected graphs, where the number of nodes in each connected graph included in each second type of graph set is similar, and the number of connected graphs included in each second type of graph set is greater than a second threshold.

[0066] Among them, the set of graphs of the first type can be called the set of identical graphs. In the set of graphs of the first type, the number of nodes of any two connected graphs is the same; the set of graphs of the second type can be called the set of similar graphs. In the set of graphs of the second type, there are at least two connected graphs with similar numbers of nodes.

[0067] Optionally, generating at least one set of graphs of the first type may include the following sub-steps:

[0068] 1. Find a connected graphs with the same number of nodes from n connected graphs, where a is a positive integer less than or equal to n;

[0069] 2. Set a first threshold, compare the size of a and the first threshold. If a is greater than the first threshold, generate a set of graphs of the first type including these a connected graphs;

[0070] 3. Repeat the above steps 1-2 until no new set of graphs of the first type can be generated.

[0071] When there are multiple sets of graphs of the first type, in each set of graphs of the first type, the number of connected graphs included can be the same or different, and the embodiments of the present application do not limit this.

[0072] It should be noted that the above first threshold can be set by those skilled in the art according to actual usage requirements. Exemplarily, the first threshold can be 10, 11, 12, 13, 14, 15, etc., and this embodiment does not limit this.

[0073] For the connected graphs that cannot be used to generate the above-mentioned sets of graphs of the first type, they can be used to generate at least one set of graphs of the second type, and correspondingly include the following sub-steps:

[0074] 1. Find the connected graphs with a unique number of nodes and the connected graphs with the same number of nodes whose number of connected graphs is less than or equal to the first threshold among the n connected graphs, and arrange the found connected graphs in order of the number of nodes;

[0075] 2. Set a second threshold, and successively take the first z numbers of nodes, and generate a set of graphs of the second type from the corresponding connected graphs. The sum of the number of connected graphs corresponding to these z numbers of nodes is greater than the second threshold, and z is a positive integer;

[0076] 3. Repeat the previous step until no new set of graphs of the second type can be generated.

[0077] It should be noted that the above second threshold can be set by those skilled in the art according to actual usage requirements. Exemplarily, the second threshold can be 10, 11, 12, 13, 14, 15, and this embodiment does not limit this.

[0078] Please refer to Figure 2, in this embodiment, g graph sets 202 are generated according to n connected graphs 201. The g graph sets may include a first type of graph set 203 and a second type of graph set 204. In each graph set, an abnormal connected graph 205 is found, and based on the abnormal connected graph 205, abnormal users and abnormal merchants 206 can be determined.

[0079] In some other possible implementation manners, generating g graph sets according to n connected graphs can also be implemented by the following steps:

[0080] 1. Arrange the n connected graphs in ascending or descending order of the number of nodes;

[0081] 2. Set a preset value L, where the number of connected graphs in any graph set is greater than or equal to L, and L is a positive integer;

[0082] 3. Take the first L connected graphs in the arranged order to generate graph set 1, then take the first L connected graphs from the remaining connected graphs to generate graph set 2, and so on.

[0083] Through the above method, g graph sets are generated from n connected graphs, the n connected graphs are classified, and the connected graphs with the same and / or similar number of nodes are grouped into the same graph set, which is convenient for horizontal comparison of the connected graphs in the following steps.

[0084] In addition, by adopting the method of preferentially generating the first type of graph set and then generating the second type of graph set, the number of nodes of the connected graphs in each graph set is made as the same or similar as possible, making the connected graphs in each graph set more comparable and referenceable to each other.

[0085] In an exemplary embodiment, step 104 may include the following sub-steps:

[0086] 1. Determine the median median(x) of the traffic volumes of the connected graphs in the i-th graph set.

[0087] Optionally, the method for obtaining the median median(x) may be: arrange the connected graphs in the i-th graph set in ascending or descending order of the traffic volume. Let the number of connected graphs in the i-th graph set be h. If h is odd, then median(x) is the traffic volume of the [(h + 1) / 2]-th connected graph; if h is even, then median(x) is the average of the traffic volumes of the (h / 2)-th and the (h / 2 + 1)-th connected graphs.

[0088] 2. Calculate the absolute differences corresponding to the connected graphs in the i-th graph set respectively. The absolute difference refers to the absolute value of the difference between the traffic volume of the connected graph and the median of the traffic volumes.

[0089] Optionally, the throughput of the j-th connected graph in the i-th set of graphs is x j , then the absolute difference y corresponding to the j-th connected graph j can be expressed as:

[0090] y j = |x j - median(x)|;

[0091] 3. Determine the median of the absolute differences corresponding to each connected graph in the i-th set of graphs. This median m can be expressed as median(y j ).

[0092] 4. According to the median of the absolute differences and the absolute differences corresponding to each connected graph in the i-th set of graphs, calculate the scores of each connected graph in the i-th set of graphs. This score is used to indicate the degree of difference between the throughput of the target connected graph and the overall throughput of each connected graph in the i-th set of graphs.

[0093] Optionally, the score s of the j-th connected graph is calculated using the following formula j :

[0094] s j = f × y j / m;

[0095] where f is a preset constant. For example, f can be 0.675 or other values. This application does not make any limitations in this regard.

[0096] 5. Determine the connected graphs with scores greater than the preset score as abnormal connected graphs.

[0097] This preset score can be set by relevant technicians during actual application. This application embodiment does not make any limitations in this regard.

[0098] In the above implementation, by calculating the scores of each connected graph, the degree of difference between each connected graph and other connected graphs in its set of graphs is obtained, which has universality. Through the degree of difference, abnormal connected graphs can be easily found; a preset score is set when looking for abnormal connected graphs, which avoids misidentifying normal connected graphs as abnormal connected graphs and improves the accuracy of detection.

[0099] In an exemplary embodiment, after the above step 101, the following steps can also be executed to implement the division of large-scale connected graphs: Select the target connected graph in the set of connected graphs and divide the target connected graph into multiple connected graphs.

[0100] The target connected graph refers to a connected graph with the number of nodes greater than or equal to the preset quantity.

[0101] It should be noted that the above preset quantity can be set by relevant technical personnel according to the number of nodes in the actual connected graph. Exemplarily, the preset quantity can be 20, 21, 22, 25, 30, 40, and this embodiment does not limit it.

[0102] Optionally, the target connected graph can be divided into multiple connected graphs based on the louvian algorithm. This method may include the following steps:

[0103] 1. Number the preset communities of the target connected graph.

[0104] The numbers of each preset community are different. Each node in the target connected graph can be located in any one of the preset communities, and the number of preset communities is equal to the number of nodes in the target connected graph.

[0105] 2. Establish a modularity formula for the target connected graph.

[0106] Exemplarily, the modularity formula can be as follows:

[0107]

[0108]

[0109] Among them, Q represents the modularity of the target connected graph, m represents the sum of the weights of each edge in the target connected graph, A de represents the weight between nodes d and e in the target connected graph, k d represents the sum of the weights of the edges connected to node d in the target connected graph, k e represents the sum of the weights of the edges connected to node d in the target connected graph, c d represents the community where node d in the target connected graph is located, and represents the community where node e in the target connected graph is located.

[0110] Among them, if c d = c e , then δ = 0; if c d ≠ c e , then δ = 1.

[0111] 3. Find out various combination methods of the communities where each node in the target connected graph is located, and calculate the modularity corresponding to each combination method according to the modularity formula.

[0112] Substitute the required data of various combination methods of the communities where each node in the target connected graph is located into the above formula one, and calculate the Q values corresponding to each combination method.

[0113] 4. Find the maximum value of the modularity corresponding to each combination method, and determine the community where each node in the target connected graph is located according to the combination method corresponding to the maximum value.

[0114] The values of each δ when the maximum value of Q is obtained indicate whether the nodes of the target connected graph are in the same community.

[0115] Optionally, if Q has more than one maximum value, any one of the maximum values of Q can be selected to perform this step.

[0116] 5. Disconnect the edges between two nodes that are not in the same community according to the communities where the nodes of the target connected graph corresponding to the maximum value of Q are located, and obtain multiple connected graphs.

[0117] In some other possible implementation manners, the method for dividing the target connected graph into multiple connected graphs based on the louvian algorithm may further include the following steps:

[0118] 1. Establish a modularity formula for the target connected graph.

[0119] Exemplarily, the modularity formula may be as follows:

[0120]

[0121]

[0122] Where Q represents the modularity of the target connected graph, m represents the sum of the weights of each edge in the target connected graph, A de represents the weight between nodes d and e in the target connected graph, k d represents the sum of the weights of the edges connected to node d in the target connected graph, k e represents the sum of the weights of the edges connected to node d in the target connected graph. Where δ is used to represent whether the two nodes connected by each edge in the target connected graph are in the same community. When node d and node e are in the same community, δ = 1; when node d and node e are not in the same community, δ = 0.

[0123] 2. Find out all possible combinations of whether each edge in the target connected graph is disconnected.

[0124] For each edge in the target connected graph, there are two possibilities: being disconnected and not being disconnected. That is, for any two connected nodes in the target connected graph, there are two possibilities: being in the same community and not being in the same community. Exemplarily, if the edge between nodes d and e is not disconnected, that is, nodes d and e are in the same community, then δ = 1; if the edge between nodes d and e is disconnected, that is, nodes d and e are not in the same community, then δ = 0.

[0125] Optionally, use the exhaustive method to find out all possible combinations of the states of each edge in the target connected graph.

[0126] 3. Substitute each combination of possibilities of the states of all edges in the target connected graph into the above modularity formula until the states of all edges in the target connected graph that minimize the modularity Q value are found. If δ is 1, it means that node d and node e are in the same community; if δ is 0, it means that node d and node e are not in the same community.

[0127] 4. Disconnect the edges between two nodes that are not partitioned into the same community to obtain multiple connected graphs.

[0128] Please refer to Figure 3 , Figure 3 which is a schematic diagram of the partitioning of the target connected graph shown in an exemplary embodiment of the present application. Using the above method, as Figure 3 shown, the connected graph 31 can be partitioned into the connected graph 32 and the connected graph 33.

[0129] Since the target connected graph has a large number of nodes and the number of connected graphs with the same or similar number of nodes is small, it is difficult to perform anomaly detection by directly generating the first type of graph set or the second type of graph set, and thus it is difficult to detect some abnormal nodes hidden in the target connected graph. In the above implementation manner, by partitioning the target connected graph with a large number of nodes into more connected graphs, the above problem is solved, thereby improving the comprehensiveness of anomaly detection and minimizing omissions as much as possible.

[0130] In an exemplary embodiment, the abnormal nodes in the target connected graph can also be detected in the following manner, including the following steps:

[0131] 1. For the target connected graph in the connected graph set, generate the edge set corresponding to the target connected graph, where the target connected graph refers to a connected graph with the number of nodes greater than or equal to a preset number.

[0132] Optionally, the corresponding edge set of the target connected graph can be generated from each edge included in the target connected graph, and each edge in the edge set exists independently in the edge set and is not connected to other edges.

[0133] 2. Calculate the throughput of each edge in the edge set.

[0134] Optionally, the weight of the edge is used as the throughput of the edge.

[0135] 3. Determine the abnormal edges in the edge set according to the throughput of each edge in the edge set.

[0136] The method for determining abnormal edges according to the throughput of edges is similar to the method for determining abnormal connected graphs according to the throughput of connected graphs introduced in the above embodiments. For details, please refer to the description in the above embodiments and will not be elaborated here.

[0137] 4. Determine the abnormal users and / or abnormal merchants based on the abnormal edges.

[0138] Optionally, enumerate each node connected by the abnormal edge as an abnormal point, and use the user or merchant corresponding to each abnormal node as an abnormal user or abnormal merchant.

[0139] In the above implementation, by horizontally comparing the traffic volume of each edge of the target connected graph with the traffic volume of other edges in the connected graph, the abnormal edges can be determined, thereby determining the abnormal users or abnormal merchants, and solving the problem that it is difficult to perform abnormal detection on the target connected graph.

[0140] The following is an embodiment of the apparatus of the present application, which can be used to execute the method embodiment of the present application. For details not disclosed in the embodiment of the apparatus of the present application, please refer to the method embodiment of the present application.

[0141] Please refer to Figure 4 , which shows a block diagram of an abnormal detection apparatus provided by an embodiment of the present application. The apparatus has the functions of implementing the above method example, and the functions can be implemented by hardware or by hardware executing corresponding software. The apparatus can be the computer device introduced above, or can be set in the computer device. As Figure 4 shown, the apparatus 400 may include: a connected graph construction module 410, a graph set generation module 420, a traffic volume calculation module 430, an abnormal graph determination module 440, and an abnormal person determination module 450.

[0142] The connected graph construction module 410 is configured to construct a connected graph set, the connected graph set includes n connected graphs, each connected graph includes at least one user node and at least one merchant node, wherein the edge connecting the user node and the merchant node is used to represent that there is an association relationship between the user corresponding to the user node and the merchant corresponding to the merchant node, and n is an integer greater than 1.

[0143] The graph set generation module 420 is configured to generate g graph sets according to the n connected graphs, and each graph set includes multiple connected graphs whose number of nodes meets a preset condition, and g is a positive integer.

[0144] The traffic volume calculation module 430 is configured to calculate the traffic volume of each connected graph in the i-th graph set among the g graph sets, and the traffic volume is used to indicate the frequency of interaction between users and merchants in the connected graph, and i is a positive integer less than or equal to g.

[0145] The abnormal graph determination module 440 is configured to determine the abnormal connected graphs in the i-th graph set according to the traffic volume of each connected graph in the i-th graph set.

[0146] The abnormal person determination module 450 is configured to determine the abnormal users and / or abnormal merchants according to the abnormal connected graphs.

[0147] In summary, in the technical solution provided by the embodiments of the present application, by constructing a set of connected graphs, several sets of graphs are generated according to each connected graph included in the set of connected graphs. For any set of graphs, by calculating the throughput of each connected graph in the set of graphs, a horizontal comparison is made among the connected graphs accordingly, and an abnormal connected graph is determined therefrom. Furthermore, an abnormal user and / or an abnormal merchant are determined according to the abnormal connected graph. Since the technical solution provided by the embodiments of the present application performs anomaly detection through horizontal comparison of multiple connected graphs with the same or similar number of nodes, any connected graph does not need to include a large amount of label data, and can effectively perform anomaly detection on sparse graphs with less label data, with high accuracy, simplicity and efficiency, and strong practicability and applicability.

[0148] In an exemplary embodiment, as Figure 5 shown, the abnormal graph determination module 440 includes: a score calculation sub-module 441 and an abnormal graph determination sub-module 442.

[0149] The score calculation sub-module 441 is configured to calculate the scores of each connected graph in the i-th set of graphs according to the throughput of each connected graph in the i-th set of graphs, where the score of the target connected graph in the i-th set of graphs is used to indicate the degree of difference between the throughput of the target connected graph and the overall throughput of each connected graph in the i-th set of graphs.

[0150] The abnormal graph determination sub-module 442 is configured to determine the connected graphs with scores greater than a preset score as abnormal connected graphs.

[0151] In an exemplary embodiment, as Figure 5 shown, the score calculation sub-module 441 is configured to:

[0152] Determine the median of the throughput of each connected graph in the i-th set of graphs;

[0153] Calculate the absolute difference corresponding to each connected graph in the i-th set of graphs respectively, where the absolute difference refers to the absolute value of the difference between the throughput of the connected graph and the median of the throughput;

[0154] Determine the median of the absolute differences corresponding to each connected graph in the i-th set of graphs;

[0155] Calculate the scores of each connected graph in the i-th set of graphs according to the median of the absolute differences and the absolute differences corresponding to each connected graph in the i-th set of graphs.

[0156] In an exemplary embodiment, as Figure 5 shown, the graph set generation module 420 includes: a first graph set generation module and / or a second graph set generation module.

[0157] The first graph set generation module is used to generate at least one graph set of the first type. Each graph set of the first type includes connected graphs with the same number of nodes, and the number of connected graphs included in each graph set of the first type is greater than the first threshold.

[0158] The second graph set generation module is used to generate at least one graph set of the second type. Each graph set of the second type includes connected graphs with approximately the same number of nodes, and the number of connected graphs included in each graph set of the second type is greater than the second threshold.

[0159] In an exemplary embodiment, the first graph set generation module is used for:

[0160] Find a connected graphs with the same number of nodes from n connected graphs, where a is a positive integer less than or equal to n;

[0161] Set the first threshold, compare the size of a with the first threshold. If a is greater than the first threshold, generate a graph set of the first type including the a connected graphs;

[0162] Repeat the above steps until no new graph set of the first type can be generated.

[0163] In an exemplary embodiment, the second graph set generation module is used for:

[0164] Find the connected graphs with a unique number of nodes and the connected graphs with the same number of nodes whose number of connected graphs is less than or equal to the first threshold among the n connected graphs, and arrange the found connected graphs in order of the number of nodes;

[0165] Set the second threshold, and successively take the first z numbers of nodes, and generate a graph set of the second type for the corresponding connected graphs. The sum of the number of connected graphs corresponding to the z numbers of nodes is greater than the second threshold, where z is a positive integer;

[0166] Repeat the previous step until no new graph set of the second type can be generated.

[0167] In an exemplary embodiment, as Figure 5 shown, the throughput calculation module 430 is used for:

[0168] For the jth connected graph in the ith graph set, calculate the sum of the weights corresponding to each edge of the jth connected graph to obtain the throughput of the jth connected graph, where j is a positive integer;

[0169] Among them, the weight is used to indicate the frequency of interaction between users and merchants with an association relationship.

[0170] In an exemplary embodiment, as Figure 5 shown, the connected graph construction module 410 is used for:

[0171] Obtain multiple transaction data, where each piece of transaction data is used to represent a transaction behavior between a user and a merchant;

[0172] Construct a set of connected graphs based on the multiple transaction data;

[0173] Among them, for users and merchants with transaction behaviors, an edge is established between the user node corresponding to the user and the merchant node corresponding to the merchant, and the weight corresponding to the edge is used to indicate the frequency of transactions between the user and the merchant with transaction behaviors.

[0174] In an exemplary embodiment, as Figure 5 shown, the connected graph construction module 410 is used for:

[0175] Obtain multiple evaluation data, where each piece of evaluation data is used to represent an evaluation behavior between a user and a merchant;

[0176] Construct a set of connected graphs based on the multiple evaluation data;

[0177] Among them, for users and merchants with evaluation behaviors, an edge is established between the user node corresponding to the user and the merchant node corresponding to the merchant, and the weight corresponding to the edge is used to indicate the frequency of evaluations between the user and the merchant with evaluation behaviors.

[0178] In an exemplary embodiment, as Figure 5 shown, the apparatus 400 further includes: a connected graph selection module 411 and a connected graph partitioning module 412.

[0179] The connected graph selection module 411 is used to select a target connected graph from the set of connected graphs, and the target connected graph refers to a connected graph whose number of nodes is greater than or equal to a preset number.

[0180] The connected graph partitioning module 412 is used to partition the target connected graph into multiple connected graphs.

[0181] In an exemplary embodiment, as Figure 5 shown, the connected graph partitioning module 412 is used for:

[0182] Number the preset communities of the target connected graph;

[0183] Establish a modularity formula for the target connected graph;

[0184] Find out various combination ways of the communities where each node of the target connected graph is located, and calculate the modularity corresponding to various combination ways according to the modularity formula;

[0185] Find out the maximum value of the modularity corresponding to various combination ways;

[0186] Determine the communities to which the nodes of the target connected graph belong according to the combination mode corresponding to the maximum value;

[0187] According to the communities to which the nodes of the target connected graph belong, disconnect the edges between two nodes that are not partitioned into the same community to obtain multiple connected graphs.

[0188] In an exemplary embodiment, the apparatus 400 further includes: an edge set generation module (not shown in the figure).

[0189] The edge set generation module is configured to generate an edge set corresponding to the target connected graph for the target connected graph in the connected graph set, where the target connected graph refers to a connected graph with the number of nodes greater than or equal to a preset quantity.

[0190] The throughput calculation module 430 is further configured to calculate the throughput of each edge in the edge set.

[0191] The abnormal graph determination module 440 is further configured to determine the abnormal edges in the edge set according to the throughput of each edge in the edge set.

[0192] The abnormal person determination module 450 is further configured to determine the abnormal users and / or abnormal merchants according to the abnormal edges.

[0193] It should be noted that for the apparatus provided in the above embodiments, when implementing its functions, only the above-mentioned division of each functional module is used for illustration. In actual applications, the above functions can be allocated to different functional modules according to needs, that is, the internal structure of the device is divided into different functional modules to complete all or part of the functions described above. In addition, the apparatus provided in the above embodiments and the method embodiments belong to the same concept, and the specific implementation process is detailed in the method embodiments and will not be repeated here.

[0194] Please refer to Figure 6 , which shows a structural block diagram of a computer device provided in an embodiment of the present application. This computer device is used to implement the abnormal detection method provided in the above embodiments. Specifically:

[0195] The computer device 600 includes a central processing unit (CPU) 601, a system memory 604 including a random access memory (RAM) 602 and a read-only memory (ROM) 603, and a system bus 605 connecting the system memory 604 and the central processing unit 601. The computer device 600 further includes a basic input / output system (I / O system) 606 for facilitating the transmission of information between various components within the computer, and a mass storage device 607 for storing an operating system 613, application programs 614, and other program modules 612.

[0196] The basic input / output system 606 includes a display 608 for displaying information and input devices 609 such as a mouse, keyboard, etc. for user input of information. Both the display 608 and the input devices 609 are connected to the central processing unit 601 through an input / output controller 610 connected to the system bus 605. The basic input / output system 606 may also include an input / output controller 610 for receiving and processing inputs from multiple other devices such as a keyboard, mouse, or electronic stylus. Similarly, the input / output controller 610 also provides output to a display screen, printer, or other types of output devices.

[0197] The mass storage device 607 is connected to the central processing unit 601 through a mass storage controller (not shown) connected to the system bus 605. The mass storage device 607 and its associated computer-readable medium provide non-volatile storage for the computer device 600. That is, the mass storage device 607 may include a computer-readable medium (not shown) such as a hard disk or a CD-ROM drive.

[0198] Without loss of generality, computer-readable media can include computer storage media and communication media. Computer storage media includes volatile and non-volatile, removable and non-removable media implemented by any method or technology for storing information such as computer-readable instructions, data structures, program modules, or other data. Computer storage media includes RAM, ROM, EPROM, EEPROM, flash memory or other solid-state storage technologies, CD-ROM, DVD or other optical storage, magnetic tape cartridges, tapes, disk storage or other magnetic storage devices. Of course, those skilled in the art will know that computer storage media is not limited to the above several types. The above system memory 604 and mass storage device 607 can be collectively referred to as memory.

[0199] According to various embodiments of the present application, the computer device 600 can also be connected to a remote computer on the network through a network such as the Internet. That is, the computer device 600 can be connected to the network 612 through a network interface unit 66 connected to the system bus 605, or rather, can also use the network interface unit 611 to connect to other types of networks or remote computer systems (not shown).

[0200] The memory further includes a computer program, which is stored in the memory and is configured to be executed by one or more processors to implement the above-mentioned anomaly detection method.

[0201] In an exemplary embodiment, there is also provided a computer-readable storage medium, in which a computer program is stored, and the computer program, when executed by a processor, is used to implement the above-mentioned anomaly detection method.

[0202] In an exemplary embodiment, a computer program product is further provided, which is used to implement the above-mentioned anomaly detection method when executed by a processor.

[0203] It should be understood that the term "a plurality of" as mentioned herein refers to two or more. "And / or" describes the association relationship of associated objects and indicates that there can be three relationships. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone. The character " / " generally represents an "or" relationship between the associated objects before and after. In addition, the step numbers described herein only exemplarily show a possible execution sequence between steps. In some other embodiments, the above steps may not be executed in the order of the numbers. For example, two steps with different numbers can be executed simultaneously, or two steps with different numbers can be executed in the reverse order of the illustration. The embodiments of the present application do not limit this.

[0204] The above are only exemplary embodiments of the present application and are not intended to limit the present application. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present application shall be included within the protection scope of the present application.

Claims

1. An anomaly detection method, characterized in that, the method includes: Constructing a set of connected graphs, the set of connected graphs includes n connected graphs, each connected graph includes at least one user node and at least one merchant node, wherein, the edge connecting the user node and the merchant node is used to represent that there is an association relationship between the user corresponding to the user node and the merchant corresponding to the merchant node, and n is an integer greater than 1; Generating g sets of graphs according to the n connected graphs, each set of graphs includes multiple connected graphs whose number of nodes meets a preset condition, and g is a positive integer; For the i-th set of graphs among the g sets of graphs, calculating the throughput of each connected graph in the i-th set of graphs, the throughput is used to indicate the frequency of interaction between users and merchants in the connected graph, and i is a positive integer less than or equal to g; Determining the abnormal connected graphs in the i-th set of graphs according to the throughput of each connected graph in the i-th set of graphs; Determining abnormal users and / or abnormal merchants according to the abnormal connected graphs; The determining the abnormal connected graphs in the i-th set of graphs according to the throughput of each connected graph in the i-th set of graphs includes: Calculating the scores of each connected graph in the i-th set of graphs according to the throughput of each connected graph in the i-th set of graphs, wherein the score of the target connected graph in the i-th set of graphs is used to indicate the difference degree between the throughput of the target connected graph and the overall throughput of each connected graph in the i-th set of graphs; Determining the connected graphs with scores greater than a preset score as the abnormal connected graphs; The calculating the scores of each connected graph in the i-th set of graphs according to the throughput of each connected graph in the i-th set of graphs includes: Determining the median of the throughput of each connected graph in the i-th set of graphs; Respectively calculating the absolute difference corresponding to each connected graph in the i-th set of graphs, the absolute difference refers to the absolute value of the difference between the throughput of the connected graph and the median of the throughput; Determining the median of the absolute differences corresponding to each connected graph in the i-th set of graphs; Calculating the scores of each connected graph in the i-th set of graphs according to the median of the absolute differences and the absolute differences corresponding to each connected graph in the i-th set of graphs.

2. The method according to claim 1, characterized in that, the generating g sets of graphs according to the n connected graphs includes: Generating at least one set of graphs of the first type, the number of nodes of each connected graph included in each set of graphs of the first type is the same, and the number of connected graphs included in each set of graphs of the first type is greater than a first threshold; and / or, Generating at least one set of graphs of the second type, the number of nodes of each connected graph included in each set of graphs of the second type is similar, and the number of connected graphs included in each set of graphs of the second type is greater than a second threshold.

3. The method according to claim 2, characterized in that, the generating at least one set of graphs of the second type includes: Find out the connected graphs with a unique number of nodes among the n connected graphs, and the connected graphs with the same number of nodes whose number of connected graphs is less than or equal to the first threshold, and arrange the found connected graphs in ascending order of the number of nodes; Set a second threshold, and successively take the first z numbers of nodes, and generate a set of graphs of the second type from the connected graphs corresponding to them. The sum of the number of connected graphs corresponding to the z numbers of nodes is greater than the second threshold, and z is a positive integer; Repeat the previous step until no new set of graphs of the second type can be generated.

4. The method according to claim 1, wherein, Calculating the throughput of each connected graph in the i-th set of graphs includes: For the j-th connected graph in the i-th set of graphs, calculate the sum of the weights corresponding to each edge of the j-th connected graph to obtain the throughput of the j-th connected graph, where j is a positive integer; wherein, the weight is used to indicate the frequency of interaction between the user and the merchant having the association relationship.

5. The method according to any one of claims 1 to 4, wherein, Constructing the set of connected graphs includes: Obtain a plurality of transaction data, and each piece of transaction data is used to represent a transaction behavior between a user and a merchant; Construct the set of connected graphs according to the plurality of transaction data; wherein, for the user and the merchant with the transaction behavior, an edge is established between the user node corresponding to the user and the merchant node corresponding to the merchant, and the weight corresponding to the edge is used to indicate the frequency of transactions between the user and the merchant having the transaction behavior.

6. The method according to any one of claims 1 to 4, wherein, Constructing the set of connected graphs includes: Obtain a plurality of evaluation data, and each piece of evaluation data is used to represent an evaluation behavior between a user and a merchant; Construct the set of connected graphs according to the plurality of evaluation data; wherein, for the user and the merchant with the evaluation behavior, an edge is established between the user node corresponding to the user and the merchant node corresponding to the merchant, and the weight corresponding to the edge is used to indicate the frequency of evaluation between the user and the merchant having the evaluation behavior.

7. The method according to any one of claims 1 to 4, wherein, After constructing the set of connected graphs, it further includes: Select a target connected graph from the set of connected graphs, where the target connected graph refers to a connected graph whose number of nodes is greater than or equal to a preset number; Divide the target connected graph into multiple connected graphs.

8. The method according to claim 7, wherein, Dividing the target connected graph into multiple connected graphs includes: Number the preset communities of the target connected graph; Establish a modularity formula for the target connected graph; Find out various combination ways of the communities where each node of the target connected graph is located, and calculate the modularity corresponding to each combination way according to the modularity formula; Find the maximum value of the modularity corresponding to the various combination ways; Determine the communities where each node of the target connected graph is located according to the combination way corresponding to the maximum value; Disconnect the edges between two nodes that are not assigned to the same community according to the communities where the nodes of the target connected graph are located, to obtain multiple connected graphs.

9. The method according to any one of claims 1 to 4, characterized in that, after constructing the set of connected graphs, it further includes: For the target connected graph in the set of connected graphs, generate an edge set corresponding to the target connected graph, where the target connected graph refers to a connected graph with the number of nodes greater than or equal to a preset quantity; Calculate the throughput of each edge in the edge set; Determine the abnormal edges in the edge set according to the throughput of each edge in the edge set; Determine the abnormal user and / or the abnormal merchant according to the abnormal edges.

10. An anomaly detection device, characterized in that, the device includes: A connected graph construction module, configured to construct a set of connected graphs, where the set of connected graphs includes n connected graphs, each connected graph includes at least one user node and at least one merchant node, and among them, the edge connecting the user node and the merchant node is used to represent that there is an association relationship between the user corresponding to the user node and the merchant corresponding to the merchant node, and n is an integer greater than 1; A graph set generation module, configured to generate g graph sets according to the n connected graphs, and each graph set includes multiple connected graphs whose number of nodes meets a preset condition, and g is a positive integer; A throughput calculation module, configured to calculate the throughput of each connected graph in the i-th graph set among the g graph sets, where the throughput is used to indicate the frequency of interaction between users and merchants in the connected graph, and i is a positive integer less than or equal to g; An abnormal graph determination module, configured to determine the abnormal connected graphs in the i-th graph set according to the throughput of each connected graph in the i-th graph set; The abnormal graph determination module includes a score calculation sub-module and an abnormal graph determination sub-module; the score calculation sub-module is configured to calculate the scores of each connected graph in the i-th graph set according to the throughput of each connected graph in the i-th graph set, where the score of the target connected graph in the i-th graph set is used to indicate the difference degree between the throughput of the target connected graph and the overall throughput of each connected graph in the i-th graph set; the abnormal graph determination sub-module is configured to determine the connected graphs with scores greater than a preset score as the abnormal connected graphs; The score calculation sub-module is configured to determine the median of the throughput of each connected graph in the i-th graph set, calculate the absolute difference corresponding to each connected graph in the i-th graph set respectively, where the absolute difference refers to the absolute value of the difference between the throughput of the connected graph and the median of the throughput; determine the median of the absolute differences corresponding to each connected graph in the i-th graph set; calculate the scores of each connected graph in the i-th graph set according to the median of the absolute differences and the absolute differences corresponding to each connected graph in the i-th graph set; An abnormal person determination module, configured to determine abnormal users and / or abnormal merchants according to the abnormal connected graphs.

11. A computer device, characterized in that, the computer device comprises a processor and a memory, and a computer program is stored in the memory, and the computer program is loaded and executed by the processor to implement the anomaly detection method according to any one of claims 1 to 9.

12. A computer-readable storage medium, characterized in that, a computer program is stored in the storage medium, and the computer program is loaded and executed by a processor to implement the anomaly detection method according to any one of claims 1 to 9.

Citation Information

Patent Citations

  • Method and device for determining abnormal interactive account

    CN108295476A

  • Ordering detection method and device, storage medium and electronic equipment

    CN109598563A