A data processing method, device, apparatus, and storage medium

By automatically generating data processing rules and utilizing trial runs and historical data analysis, the efficiency and effectiveness issues of financial institutions in monitoring risky behaviors have been resolved. This has enabled the automation and standardization of rule development and deployment, and improved the efficiency and accuracy of data processing.

CN112837140BActive Publication Date: 2025-11-25TENCENT TECHNOLOGY (SHENZHEN) CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202110169912.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-02-02
Publication Date
2025-11-25
Estimated Expiration
2041-02-02

AI Technical Summary

Technical Problem

In existing technologies, financial institutions face inefficiencies in developing and implementing data processing rules when monitoring risky behaviors within their systems. Furthermore, these systems often suffer from logical errors and inconsistent evaluation standards, which negatively impact the effectiveness of behavior monitoring.

Method used

A data processing method is provided that automatically generates data processing rules through a parameter configuration interface, analyzes trial operation and historical black and white sample data, and automatically evaluates indicators to ensure that the rules are only launched when preset conditions are met.

Benefits of technology

It improved the efficiency of developing and deploying data processing rules, unified the evaluation standards for rule effectiveness, enhanced the hit rate and analysis results of rules, and reduced manpower consumption.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN112837140B_ABST
    Figure CN112837140B_ABST
Patent Text Reader

Abstract

The application relates to a data processing method, device and equipment and a storage medium. The method comprises the following steps: receiving a parameter configuration request, wherein the parameter configuration request carries feature data; forming a data processing rule based on the feature data; receiving a trial operation instruction for the data processing rule; obtaining a trial operation result by using feature conditions of each feature in the data processing rule and operation relationships between the feature conditions; obtaining historical black and white sample data; analyzing the trial operation result according to the historical black and white sample data to obtain a first evaluation index; and performing online processing on the data processing rule when the first evaluation index meets a preset online condition. The application can avoid complicated operations of online processing of the data processing rule, improve the online efficiency of the data processing rule, and increase the hit rate of the data processing rule.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of computer technology, and in particular to a data processing method, apparatus, device, and storage medium. Background Technology

[0002] With social development, more and more illegal activities are being carried out through the business of financial institutions, which makes it necessary for financial institutions to carry out targeted behavior monitoring services.

[0003] In existing technologies, financial institutions primarily monitor risky behaviors within their systems through processes and data processing rules. However, data processing rules are typically developed and evaluated offline, followed by initial manual sampling and approval based on individual preferences. Developing rules offline through code is time-consuming and labor-intensive, and the rules are prone to data logic errors due to developer carelessness. Furthermore, offline trial results and manual sampling verification results suffer from issues such as data retention, inconsistent rule effectiveness evaluation standards, and non-standardized approval processes. This results in unsatisfactory deployment efficiency and analytical effectiveness of data processing rules, hindering the development of monitoring operations. Summary of the Invention

[0004] This application provides a data processing method, apparatus, device, and storage medium that can avoid the cumbersome operations of deploying data processing rules and improve the efficiency and analysis effect of deploying data processing rules.

[0005] On the one hand, this application provides a data processing method, the method comprising:

[0006] Receive a parameter configuration request, the parameter configuration request carrying feature data;

[0007] Data processing rules are formed based on the aforementioned feature data;

[0008] Receive a trial run instruction for the data processing rule, and obtain the trial run result by utilizing the feature conditions of each feature in the data processing rule and the operational relationship between the feature conditions;

[0009] Obtain historical black and white sample data;

[0010] The trial operation results are analyzed based on the historical black and white sample data to obtain the first evaluation index;

[0011] When the first evaluation indicator meets the preset online conditions, the data processing rules are put into operation.

[0012] On the other hand, a data processing apparatus is provided, the apparatus comprising:

[0013] A parameter configuration request receiving module is used to receive parameter configuration requests, wherein the parameter configuration requests carry feature data;

[0014] The rule generation module is used to form data processing rules based on the feature data;

[0015] The rule trial operation module is used to receive trial operation instructions for the data processing rules, and obtain trial operation results by utilizing the feature conditions of each feature in the data processing rules and the operational relationships between the feature conditions.

[0016] The sample data acquisition module is used to acquire historical black and white sample data;

[0017] The trial operation result analysis module is used to analyze the trial operation results based on the historical black and white sample data to obtain the first evaluation index;

[0018] The online processing module is used to process the data processing rules online when the first evaluation indicator meets the preset online conditions.

[0019] On the other hand, an electronic device is provided, the device including a processor and a memory, the memory storing at least one instruction or at least one program, the at least one instruction or at least one program being loaded by the processor and executed by the data processing method described above.

[0020] On the other hand, a computer storage medium is provided, which stores at least one instruction or at least one program, the at least one instruction or the at least one program being loaded and executed by a processor to implement the data processing method described above.

[0021] This application provides users with a parameter configuration interface for rule configuration, automatically generating data processing rules. This improves the transparency and interpretability of rules, while also increasing the efficiency of rule development and deployment. Before deployment, rule trial runs are provided, improving rule testing efficiency. After trial runs, historical black-and-white sample data is used to conduct an initial evaluation of the results, providing a reference for subsequent rule effectiveness assessments. The initial evaluation is performed automatically by the system, eliminating the need for manual intervention. This ensures consistency in the rule effectiveness evaluation standards used for both offline trial results and manual sampling verification results, while reducing manpower costs. Once the initial evaluation result (i.e., the first evaluation indicator) meets the deployment criteria, the rule is deployed, increasing the hit rate of data processing rules and thus improving their analytical effectiveness. Attached Figure Description

[0022] To more clearly illustrate the technical solutions and advantages in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0023] Figure 1 This is a schematic diagram of the structure of a data processing system provided in an embodiment of this application.

[0024] Figure 2 This is a schematic diagram of the architecture of a data processing system provided in an embodiment of this application.

[0025] Figure 3 This is a schematic diagram of the structure of a distributed system applied to a blockchain system according to an embodiment of this application.

[0026] Figure 4 This is a schematic diagram of the block structure provided in the embodiments of this application.

[0027] Figure 5 This is a flowchart illustrating a data processing method provided in an embodiment of this application.

[0028] Figure 6 This is an example diagram of the parameter configuration interface provided in the embodiments of this application.

[0029] Figure 7 This is an example diagram of the basic information configuration interface provided in the embodiments of this application.

[0030] Figure 8 This is a flowchart illustrating another data processing method provided in an embodiment of this application.

[0031] Figure 9 This is a flowchart illustrating another data processing method provided in an embodiment of this application.

[0032] Figure 10 This is an example diagram of the template configuration interface provided in the embodiments of this application.

[0033] Figure 11 This is a schematic diagram of the process for forming data processing rules provided in the embodiments of this application.

[0034] Figure 12 This is a flowchart illustrating the process of determining the first evaluation index provided in an embodiment of this application.

[0035] Figure 13a This is a schematic diagram of the architecture of another data processing system provided in the embodiments of this application.

[0036] Figure 13bThis is an example diagram of the cumulative hit count provided in the embodiments of this application.

[0037] Figure 14 This is a flowchart illustrating the process of determining preset online conditions provided in an embodiment of this application.

[0038] Figure 15 This is a flowchart illustrating another data processing method provided in an embodiment of this application.

[0039] Figure 16 This is an example diagram of the sampling inspection interface provided in the embodiments of this application.

[0040] Figure 17 This is an example diagram of the verification online interface provided in the embodiments of this application.

[0041] Figure 18 This is a schematic diagram of the execution result viewing interface provided in the embodiments of this application.

[0042] Figure 19 This is an example diagram of the evaluation results provided in the embodiments of this application.

[0043] Figure 20 This is a schematic diagram of the structure of a data processing device provided in an embodiment of this application.

[0044] Figure 21 This is a schematic diagram of the hardware structure of a device for implementing the method provided in the embodiments of this application. Detailed Implementation

[0045] Cloud technology refers to a hosting technology that unifies a series of resources such as hardware, software, and networks within a wide area network or local area network to achieve data computing, storage, processing, and sharing.

[0046] Cloud technology is a general term encompassing network technology, information technology, integration technology, management platform technology, and application technology based on the cloud computing business model. It can form resource pools, providing flexible and convenient on-demand access. Cloud computing technology will become a crucial support. Backend services of technical network systems require substantial computing and storage resources, such as video websites, image websites, and many portal websites. With the rapid development and application of the internet industry, every item may have its own identification mark in the future, requiring transmission to backend systems for logical processing. Data at different levels will be processed separately, and various industry data will all require robust system support, which can only be achieved through cloud computing.

[0047] Cloud technology has been widely applied in various fields such as government, transportation, finance, and enterprises. The solution provided in this application relates to the financial application field. In the financial sector, in order to carry out targeted behavioral monitoring tasks, financial institutions mainly monitor risky behaviors within their systems through processes and data processing rules. However, data processing rules are generally developed and evaluated offline, followed by preliminary manual sampling, with decisions on whether to approve their implementation based on personal preferences. Developing rules offline through code is time-consuming and labor-intensive, and the developed rules are prone to data logic errors due to carelessness by developers. At the same time, there are problems with the retention of offline trial results and manual sampling verification results, inconsistent evaluation standards for rule effectiveness, and non-standardized approval processes, resulting in very unsatisfactory implementation efficiency and analysis effects of data processing rules, which is detrimental to the development of monitoring operations.

[0048] Based on the above description, embodiments of this application provide a data processing method to improve the efficiency of data processing rule deployment and analysis effectiveness. The embodiments of this application will be further described in detail below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of this application, and not all of them. All other embodiments obtained by those skilled in the art based on the embodiments of this application without creative effort are within the scope of protection of this application.

[0049] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of this application described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or service that includes a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or devices.

[0050] First, the relevant terms used in the embodiments of this specification are explained as follows:

[0051] Auditing: refers to the preliminary identification of suspicious risky users through models or rules.

[0052] Verification: In risk control, suspicious users who have passed the rule audit need to be manually investigated to confirm whether they are truly suspicious before being reported or not.

[0053] Features: A certain attribute of a subject, such as "height", "age", "transaction amount in the past 7 days", etc. When a user's certain features or combinations of features are different from those of a normal person, they are called suspicious features.

[0054] Testing: This refers to the need to simulate operation before the rules go live, to see the audit effect of the rules, and then to evaluate whether they meet the go-live standards.

[0055] Data processing rules: These are rules or models used to audit risky behaviors, and they are usually composed of multiple features.

[0056] Going live: This refers to the official commencement of risk assessment of users and the submission of their data to the review platform for manual review.

[0057] Online evaluation: This refers to the evaluation of whether the rules meet the online conditions when they are launched, including dimensions such as the rule's hit rate, coverage, and the importance of prevention and control for the target population.

[0058] Please see Figure 1 It shows a schematic diagram of the structure of a data processing system provided in an embodiment of this application, such as... Figure 1 As shown, the system may include at least client 01 and server 02.

[0059] Client 01 can be a device such as a smartphone, desktop computer, tablet, laptop, digital assistant, smart wearable device, monitoring device, or voice interaction device. It can also be software running on the device, such as web pages or applications provided by service providers. Specifically, Client 01 can be used to display the configuration interface for data processing rules and the results of the processing.

[0060] Server 02 can be a standalone server, a distributed server, or a server cluster composed of multiple servers. It can also be a cloud server providing basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, CDN, and big data and artificial intelligence platforms. Specifically, server 02 can receive requests from client 01 to complete processes such as configuring, testing, verifying, and deploying data processing rules.

[0061] Specific examples Figure 2 The diagram illustrates the architecture of a data processing system. Information related to the rule templates and template parameters configured on the client side is transformed into executable code, such as SQL, Python, or Java. Then, based on the data processing rules, feature indicators from the lower-level feature pool are periodically called to perform data calculations to identify high-risk users.

[0062] In some feasible implementations, the system involved in the embodiments of this application can also be a distributed system formed by connecting clients and multiple nodes (any form of computing device in the network, such as servers and user terminals) through network communication.

[0063] Taking a distributed system as an example, see blockchain system. Figure 3 , Figure 3 This is an optional structural diagram of the distributed system 100 provided in this application embodiment applied to a blockchain system. It consists of multiple nodes (any form of computing device in the network, such as servers or user terminals) and clients, forming a peer-to-peer (P2P) network. The P2P protocol is an application layer protocol running on top of the Transmission Control Protocol (TCP). In the distributed system, any machine, such as a server or terminal, can join and become a node. A node includes a hardware layer, a middleware layer, an operating system layer, and an application layer.

[0064] See Figure 3 The functions of each node in the illustrated blockchain system include: routing, a basic function of the node used to support communication between nodes; applications, which are deployed in the blockchain to implement specific business needs, record data related to the implementation of functions to form record data, carry digital signatures in the record data to indicate the source of the task data, and send the record data to other nodes in the blockchain system so that other nodes can add the record data to a temporary block when they successfully verify the source and integrity of the record data; and the blockchain, which consists of a series of blocks that are sequentially generated. Once a new block is added to the blockchain, it will not be removed. The blocks record the record data submitted by the nodes in the blockchain system.

[0065] For example, the business logic implemented by the application includes:

[0066] 1) A wallet is used to provide the function of conducting electronic currency transactions, including initiating transactions (that is, sending the transaction record of the current transaction to other nodes in the blockchain system; after other nodes verify the transaction successfully, they store the transaction record data in the temporary block of the blockchain as a response to acknowledge the validity of the transaction; of course, the wallet also supports querying the remaining electronic currency in the electronic currency address.

[0067] 2) Shared ledger, which provides functions such as storage, query and modification of ledger data. It sends the record data of the operation on the ledger data to other nodes in the blockchain system. After the other nodes verify the validity, as a response to acknowledge the validity of the ledger data, they store the record data in a temporary block. It can also send confirmation to the node that initiated the operation.

[0068] 3) Smart contracts are computerized protocols that can execute the terms of a contract. They are implemented through code deployed on a shared ledger that executes when certain conditions are met. Based on actual business needs, the code is used to complete automated transactions, such as querying the logistics status of goods purchased by a buyer and transferring the buyer's electronic money to the merchant's address after the buyer signs for the goods. Of course, smart contracts are not limited to executing contracts for transactions; they can also execute contracts for processing received information.

[0069] See Figure 4 , Figure 4 This is an optional schematic diagram of the block structure provided in this application embodiment. Each block includes the hash value of the transaction records stored in this block (the hash value of this block) and the hash value of the previous block. The blocks are connected through their hash values ​​to form a blockchain. Additionally, the block may include information such as a timestamp when it was generated. A blockchain is essentially a decentralized database, a chain of data blocks linked together using cryptographic methods. Each data block contains relevant information used to verify the validity of the information (anti-counterfeiting) and to generate the next block.

[0070] The following describes a data processing method provided by an embodiment of this application, which can be applied to... Figure 1 The server shown or applied to Figure 3 The nodes are shown. It should be noted that this specification provides the operational steps of the methods described in the embodiments or flowcharts, but based on conventional or non-inventive labor, more or fewer operational steps may be included. The order of steps listed in the embodiments is merely one possible execution order among many, and does not represent the only execution order. In actual system or server product execution, the methods shown in the embodiments or figures can be executed sequentially or in parallel (e.g., in a parallel processor or multi-threaded processing environment). Specifically, as shown... Figure 5 As shown, the method may include:

[0071] S510 receives a parameter configuration request, which carries feature data.

[0072] Users can configure the feature data of each characteristic that constitutes the data processing rule in the parameter configuration interface, so that the data processing rule can be implemented for risk prevention and control. For example Figure 6 The image shown is an example of the parameter configuration interface. One or more feature conditions can be configured in the parameter configuration interface. Therefore, the feature data must include at least the feature identifier, threshold parameter, and comparison operator parameter for each feature. If there are multiple feature conditions, the feature data also includes feature association parameters.

[0073] Among them, feature identifiers are used to uniquely identify features, such as feature ID or feature name; threshold parameters represent the threshold for comparing the feature value with the corresponding feature value, and the threshold parameter can be a specific numerical value, string, or date, etc.; comparison operator parameters are used to determine the relationship between feature value and threshold parameter, such as symbols such as ">", "<", "≥", "≤" or "=" used to compare the relationship between the size of two objects, or symbols used to determine whether two objects have an inclusion relationship, such as in or not int, etc.; feature association parameters represent the association relationship between features, such as "AND" relationship or "OR" relationship.

[0074] In practical implementation, the feature data can also include the data type, runtime parameters, and version information for each feature. The data type represents the type of the feature value, such as integer, string, or date. This allows the data type to limit the value of the threshold parameter, providing a reference for users when configuring the threshold parameter. The runtime parameters can include the runtime cycle and the first runtime. The runtime cycle represents the period during which the data processing rule runs automatically after it goes live, and the first runtime represents the time of the first run after the data processing rule goes live.

[0075] To standardize the configuration of feature data and avoid inconsistencies and logical errors among different users, rule templates can be provided to users in practical applications, and parameter configuration interfaces can be generated based on these templates. For example... Figure 7 The image shown is an example of the basic information configuration interface. In this interface, users can select fields based on risk mode, choose the rule module for the data processing rules they want to define, and the server automatically reads the template parameters to generate the parameter configuration interface based on the selected rule template.

[0076] The basic information configuration interface also allows you to configure version information for data processing rules, such as version description and version name. The version description might include, for example, the nth time a certain type of risk control measure has been verified. It's understood that the parameter configuration interface and the basic information configuration interface can be the same interface; this manual does not specify the form in which the basic information configuration interface exists.

[0077] In view of this, in some feasible implementations, such as Figure 8 As shown, before step S510 is implemented, the method may further include:

[0078] S507, Receive template read request, the template read request carries template identifier;

[0079] S508, retrieve the rule template that matches the template identifier;

[0080] S509 reads the template parameters from the rule template and sends the template parameters to the client so that the client can generate a parameter configuration interface based on the template parameters.

[0081] Template identifiers are used to uniquely identify rule templates. Rule templates can be language templates written in the target language, such as SQL, Python, or Java templates, or text templates written in a text editing tool, such as JSON, XML, or Excel templates. Template parameters correspond to feature data and can include feature association parameters, feature names for each feature, feature identifiers, comparison operator parameters, default values, and data types, etc.

[0082] Regarding rule template generation, in addition to using the target language or text editing tools, to ensure the extensibility of the rule templates and prevent standardization errors in the template parameters during creation, online creation can be provided for users. Furthermore, when creating rules online, users can directly utilize already imported features, avoiding errors in feature-related attribute configuration, such as feature type or feature value.

[0083] Based on the above description, in some feasible implementations, such as Figure 9 As shown, before step S507 is implemented, the method may further include:

[0084] S502, Receive a search feature request, which carries feature keywords.

[0085] like Figure 10 The image shown is an example of the template configuration interface. Figure 10 In the search bar, users can enter keywords to search and filter for the features they want to add. In the template configuration interface, users can add features in two ways: one is through the "Add" entry next to each feature record, and the other is through the provided "Add Conditions" entry. However, different methods have different associated relationships. For example... Figure 10 In the diagram, if a new feature is added through the "Add" entry after the first feature record (i.e., the record with serial number 1), the added feature is a parallel "OR" feature, meaning only one condition needs to be met. For example, rows 1 and 2 only need to meet one of them, and intuitively, no new serial number will be added. If a new condition entry is added, the added feature is a parallel "AND" feature, meaning every condition needs to be met. For example, rows 1 and 2, and rows 3, 4, and 5. Intuitively, a new serial number will be added.

[0086] like Figure 6The audit logic to be expressed must simultaneously meet the following three conditions: 1. The authentication field is: Y; 2. The user registration time is: less than the specified value; 3. The number of transfer partners in the last 7 days is greater than the specified value, or the transfer amount in the last 7 days is greater than the specified value.

[0087] Corresponding to adding new entries, users can also delete records based on the deletion entry following the record with a certain feature if they no longer need it.

[0088] S503: Select target feature information from the preset feature pool based on the feature keywords.

[0089] The preset feature pool stores pre-imported features that have undergone preprocessing such as cleaning. Target feature information may include feature name, feature identifier, and data type. It is understood that the preset feature pool can be a single feature pool table or multiple feature pool tables.

[0090] S504, the target feature information is sent to the client so that the client can display the target feature information in the template configuration interface.

[0091] When displaying target feature information, the client generates corresponding default value input controls based on the data type of the target feature information. For example, if the data type is integer (int), an input box control is generated; if the data type is date (datetime), a date widget control is generated, and so on. Users can enter default values ​​for the feature in the default value input controls, or they can use the default values ​​provided by the client.

[0092] Understandably, the range of default values ​​can be limited by data type. For example, when the data type represents a numeric default value, such as integer (int), any recommended numeric value can be entered; when the data type represents an enumerated value, an enumerated value can be selected through a drop-down control. Different comparison operators can also be selected for different data types. For example, numeric values ​​can choose >, =, <, ≥, and ≤, while enumerated values ​​can choose =, in, not in, etc.

[0093] S505 receives a template configuration request from the template configuration interface, which carries template parameters.

[0094] After completing each feature and its corresponding conditions, the user can trigger the completion operation using controls such as "Complete" or "Save". Upon receiving the completion operation, the client reads the feature information of each feature from the template configuration interface, generates template parameters, and encapsulates these parameters in a template configuration request before sending it to the server.

[0095] S506, generate rule templates based on template parameters.

[0096] As described in step S509 above, rule templates can have various expression methods, such as language templates and text templates, and correspondingly, they can also have various storage methods, such as file storage and database storage. For example, for SQL language templates, the resulting rule template consists of SQL code, and... Figure 10 The corresponding SQL code is shown below:

[0097] select userid

[0098] from user_base

[0099] where(amt_7day>'parameterA'or user_7day>'parameterB')

[0100] and ifcent = 'parameterC'

[0101] and createdate<'parameterD'

[0102] Wherein, `user_base` is the name of the data table to be queried; `userid` is the primary key, referring to the main user ID of the feature; `amt_7day` refers to the transfer amount of the feature in the last 7 days; `user_7day` refers to the number of counterparties in the last 7 days; `ifcent` indicates whether authentication is required; `createdate` refers to the user's registration time; `parameterA`, `parameterB`, `parameterC`, and `parameterD` are threshold parameters to be determined and filled in after the specific rules are configured. It is understood that the data table used in the above SQL code is a single data table. In actual implementation, multiple data tables can be used to generate the table through join operations; this application does not specifically limit this.

[0103] S520, data processing rules are formed based on feature data.

[0104] Since feature data includes at least the feature identifier, threshold parameter, and comparison operator parameter for each feature, and when there are multiple features, the feature data also includes feature association parameters. Therefore, in a feasible implementation, such as Figure 11 As shown, step S520 may include the following when implemented:

[0105] S521, for each feature in the feature data, generate feature conditions for the feature based on the feature identifier, threshold parameter and comparison operator parameter.

[0106] In this embodiment, the feature condition characterizes the risk pattern of the feature. If the feature value meets the feature condition, it is considered to be suspicious of risk. Specifically, the key representation of the feature in the data table is obtained through the feature identifier. Then, the key representation, threshold parameter, and comparison operator parameter are expressed according to the target language to obtain the feature condition. For example, if the target language is SQL, the key representation is amt_7day, the threshold parameter represents a threshold of 10000, and the comparison operator parameter represents a comparison operator ">", then the generated feature condition is "amt_7day>10000". Similarly, if the key representation is user_7day, the threshold parameter represents a threshold of 1000, and the comparison operator parameter represents a comparison operator ">", then the generated feature condition is "user_7day>1000".

[0107] S522, Determine the number of features in the feature data.

[0108] The feature count indicates the number of features in the feature data. If the feature count is equal to a preset feature threshold, the preset feature threshold indicates that there is only one feature, that is... Figure 6 If the interface shows only one record, then proceed to step S523; if the number of features is greater than the preset feature threshold, that is... Figure 6 If the interface shown contains multiple records, then proceed to step S524.

[0109] S523, data processing rules are formed from the characteristic conditions of the features.

[0110] For example, if we use SQL code to represent the data processing rule, assuming there is only feature 1, and the feature condition of feature 1 is "amt_7day>10000", then the data processing rule is "amt_7day>10000".

[0111] S524. Based on the feature association parameters in the feature data, determine the operational relationships between the feature conditions of each feature, and form data processing rules from the feature conditions of each feature and the operational relationships between them.

[0112] Feature association parameters characterize the relationships between features. When determining the operational relationships between various feature conditions, operator parameters are used. For example, if feature 1 and feature 2 have an "OR" relationship in the feature association parameters, then the operator parameter between the feature conditions of feature 1 and feature 2 is "or".

[0113] If we use SQL code to represent the data processing rules, assuming there are two features, feature 1 and feature 2, and the feature condition of feature 1 is "amt_7day>10000", the feature condition of feature 2 is "user_7day>1000", and the operator parameter between feature 1 and feature 2 is "or", then the data processing rule is "amt_7day>10000or user_7day>1000".

[0114] S530 receives a trial run instruction for the data processing rules, and obtains the trial run results by utilizing the feature conditions of each feature in the data processing rules and the operational relationships between the feature conditions.

[0115] In this embodiment, the trial run is also known as a test, and the trial run results mainly include each suspicious user who meets the data processing rules. The data processing rules can be presented in various forms, such as text or code. If it is code, it can be run directly; if it is text, it needs to be converted into executable code. Therefore, step S530 can specifically include: generating executable code using the feature conditions of each feature in the data processing rules and the operational relationships between these feature conditions; and calling the executable code to obtain the trial run results. Figure 6 The configuration shown, when used with SQL, generates the following executable code:

[0116] Create table online_rule_18237389as

[0117] select userid

[0118] from user_base

[0119] where(amt_7day>10000or user_7day>1000)

[0120] and ifcent = 'Y'

[0121] and createdate<'2019-01-01'

[0122] The executable statements described above can store the user ID (userid) of a suspicious user in the calculation results, which can then be accessed by the review platform for manual review, as shown in Table 1.

[0123] Table 1

[0124] User ID XXXX1 XXXX2 XXXX9

[0125] S540, acquire historical black and white sample data.

[0126] Historical black-and-white sample data represents manually labeled black and white samples from the past. Black samples refer to samples from high-risk users, and white samples refer to samples from non-risk users. Historical black-and-white sample data can include user identifiers, whether a sample was reported, and risk category. Reporting status indicates whether a sample is a black sample, and risk category indicates the type of risk. Table 2 shows an example of the acquired historical black-and-white sample data:

[0127] Table 2

[0128]

[0129]

[0130] S550, based on the analysis of historical black and white sample data, obtained the first evaluation index by analyzing the trial operation results.

[0131] The first evaluation metric includes the hit rate of risky users and the hit rate of each risk category. The hit rate of risky users represents the probability of hitting risky users among the hit users. Risky users refer to black sample users. The hit rate of risk categories represents the probability of hitting users of the risk category.

[0132] In one feasible implementation, such as Figure 12 As shown, step S550 may include the following in a specific implementation:

[0133] S551 matches historical black and white sample data with trial operation results to determine the matched users.

[0134] The trial run aims to achieve the effect of using real online data for auditing, without generating real audit tasks to push to the review platform, such as... Figure 13a As shown, this is a schematic diagram of another data processing system architecture. The audit results of online rules are pushed to the online database table. For test rules not yet deployed, the audit results are pushed to the offline rule audit table with the same structure. The format of the offline rule audit table is shown in Table 3.

[0135] Table 3

[0136] User ID Audit rule identification Audit time XXXX1 xxx1 2020-11-12 15:58:12 XXXX2 xxx2 2020-11-12 14:56:09 XXXX3 xxx3 2020-11-12 09:30:05 XXXX4 xxx4 2020-11-13 12:46:36 XXXX5 xxx4 2020-11-15 13:07:56

[0137] The process of matching the trial run results with historical black and white sample data is also the process of determining the audit results. Understandably, for the same data processing rule, multiple runs (audits) can be performed. By statistically analyzing the primary evaluation indicator of each audit, the stability of the data processing rule can be determined, such as the cumulative hit count. Table 4 shows an example of the audit results for a certain test rule, i.e., the list of hit users:

[0138] Table 4

[0139]

[0140]

[0141] S552 filters out high-risk users from the hit users.

[0142] Based on the audit time, the risky users for this trial operation can be identified, that is, the users who have been reported in the hit user list.

[0143] S553 defines the risk user hit rate as the ratio of the number of risky users to the total number of users in the historical black and white sample data.

[0144] S554 categorizes risky users by risk type, resulting in risky users corresponding to each risk type.

[0145] S555: For each risk category, the hit rate of the risk category is determined by the ratio of the number of risk users corresponding to the risk category to the total number of users corresponding to the risk category in the historical black and white samples.

[0146] For example, suppose the historical black and white sample data includes 100 users. Of these 100 users, 20 are white samples, and the black samples contain 10 users of category 1, 50 users of category 2, and 20 users of category 3. Based on the historical black and white sample data and the trial operation results, the number of matched users is 80. Among the matched users, the number of risky users is 40: 5 users of category 1, 20 users of category 2, and 15 users of category 3. Therefore, the hit rate for risky users is 40 / 100 = 0.4, the hit rate for category 1 is 5 / 10 = 0.5, the hit rate for category 2 is 20 / 50 = 0.4, and the hit rate for category 3 is 15 / 20 = 0.75.

[0147] After determining the primary evaluation indicators for the trial operation, the server can perform statistical analysis on these indicators, providing data for business personnel to conduct an overall effectiveness assessment. For example... Figure 13b As shown in the figure, it is an example of the cumulative hit count. The figure shows which time period the data processing rule is most effective.

[0148] Understandably, it is necessary to determine whether the first evaluation indicator meets the preset launch conditions. Only when the preset launch conditions are met can the data processing rules be allowed to go live. In some feasible implementations, such as... Figure 14 As shown, determining whether the first evaluation indicator meets the preset launch conditions can include the following in specific implementation:

[0149] S548, determine whether the hit rate of risk users meets the first preset launch condition, and determine whether the hit rate of each risk category meets the second preset launch condition corresponding to that risk category.

[0150] The first preset launch condition represents the standard that the hit rate for risky users needs to reach. For example, the hit rate for risky users can be compared with a first hit rate threshold. If the hit rate for risky users is greater than the first hit rate threshold, the standard is considered to have been met. Similarly, the second preset launch condition represents the standard that the hit rate for risk categories needs to reach. For example, the hit rate for a risk category can be compared with a second hit rate threshold corresponding to that risk category. If the hit rate for a risk category is greater than the second hit rate threshold corresponding to that risk category, the standard is considered to have been met.

[0151] It should be noted that each risk category can have different second preset upper limit conditions for the hit rate, i.e., different second hit rate thresholds. For example, if the hit rate of category 1 is greater than 50%, then the hit rate of category 2 meets the second preset upper limit condition corresponding to category 2; while the hit rate of category 3 needs to be greater than 80% to be considered to meet the second preset upper limit condition corresponding to category 3.

[0152] It is understandable that the first preset online conditions and the second preset online conditions corresponding to each risk category can be adjusted in real time. That is, the settings of the first hit rate threshold and the second hit rate threshold can be the same or different. This manual does not make specific restrictions.

[0153] S549, if the first preset upper limit condition is met, and the second preset upper limit condition corresponding to each risk category is met, then it is determined that the first hit indicator meets the preset upper limit condition.

[0154] It should be noted that the hit rate of risky users and the hit rate of each risk category are the core indicators of the first evaluation metric. In some implementations, the first evaluation metric may also include indicators such as the fluctuation range of audit volume, the historical audit ratio, and the historical reporting ratio. Accordingly, when determining whether the first hit metric meets the preset launch conditions, it is necessary to determine whether indicators such as the fluctuation range of audit volume, the historical audit ratio, and the historical reporting ratio meet their corresponding preset launch conditions. If all indicators meet their corresponding preset launch conditions, the first hit metric can also be determined to meet the preset launch conditions. In specific implementations, the first evaluation metric can also be adjusted according to different business situations.

[0155] S560: When the first evaluation indicator meets the preset online conditions, the data processing rules are put into operation.

[0156] If all indicators in the first evaluation index basically meet the requirements, further evaluation can proceed to manual sampling or system sampling. If the evaluation results are not satisfactory, the features, feature conditions, or threshold parameters in the data processing rules can be re-optimized, and then step S530 can be executed again for trial operation.

[0157] Therefore, in a feasible implementation, such as Figure 15 As shown, before implementing the data processing rules for online deployment, this method may further include:

[0158] S561 receives a verification processing request for data processing rules, the verification processing request carrying a second evaluation index.

[0159] If manual sampling is used, the sampling personnel will conduct spot checks on the historical operation records of the data processing rules, and then evaluate the effectiveness of indicators such as hit rate and hit type. The second evaluation indicator, in addition to including the first evaluation indicator, may also include information such as the number of auditing users and the number of sampling personnel, for example... Figure 16 The image shown is an example of the verification interface. Users can input relevant information from the second evaluation indicator into the sampling evaluation text box, such as: number of audit users: 100; number of people sampled: 90; number of people hit in the sampling: 80; sampling hit rate: 80%; sampling hit type: Category 1: 50 people, Category 2: 30 people.

[0160] S562, review the data processing rules according to the second evaluation indicator, and after the review is passed, put the data processing rules into operation.

[0161] The review process based on the second evaluation indicator can be found in step S550, which involves reviewing whether each indicator meets the corresponding preset launch conditions. If all indicators meet the preset launch conditions, the review is passed. If not, the data processing rules can be re-optimized before proceeding to step S530.

[0162] In some feasible implementations, the step of executing the online processing of data processing rules may include: receiving an online processing request carrying applicant information; creating an application process based on the applicant information; and initiating the processing of each application node in the application process. For example... Figure 17 The image shown is an example of the verification and online interface.

[0163] Since the data processing rules include runtime parameters, after the data processing rules have been deployed online, the server can also start running the data processing rules based on these parameters. The operation process for each run is similar to that for the trial run, and will not be repeated here.

[0164] In some feasible implementations, to enable users to more intuitively understand the results of this trial run, the server can send the trial run results to the client, allowing users to view the details of the results through the client. Therefore, after step S530, the method may further include:

[0165] (1) Send the execution status to the client so that the client can display the execution status on the execution result viewing interface.

[0166] like Figure 18 The image shown is a schematic diagram of the execution result viewing interface. Each time a data processing rule is run or tested, a task record corresponding to that data processing rule is added to the execution result viewing interface, such as... Figure 18 Task number 142 in the dataset is in running status. After each run or trial run of the data processing rules, the server sends the execution status to the client. The execution status indicates the result of the execution, such as success or failure.

[0167] (2) Receive a result viewing request from the execution result viewing interface, which carries at least the task number.

[0168] (3) Obtain the trial run results corresponding to the task number.

[0169] Users can view the trial run results through the details entry in the results. The server analyzes the trial run results and historical black and white sample data to obtain the first evaluation index. To allow users to view the evaluation index more intuitively, the method may further include the following after step S550:

[0170] The data processing rule is evaluated based on the first evaluation index, evaluation data is generated, and the evaluation data is sent to the client so that the client can visualize the evaluation data.

[0171] The evaluation data includes the total number of hit users, the trend of the number of hit users (if the simulation has been run multiple times periodically), the historical review data of hit users, the number of customers historically identified as high-risk, and the risk category of customers historically identified as high-risk. For example... Figure 19 As shown, this is an example graph of the evaluation results.

[0172] Through testing and verification, in terms of efficiency improvement, the data processing methods provided in the above-mentioned embodiments reduce the development efficiency of data processing rules from 2-4 weeks for pure code development to less than 1 day; the productization completion time during trial operation is reduced from 1-2 days depending on technology to less than 1 hour; in terms of compliance, all data processing rules have been measured by specific data indicators before going online, making them more reasonable, standardized, and with more unified and objective standards; moreover, sampling inspections and evaluations are all completed online, and subsequent records are verifiable; the review process is also completed online, facilitating rapid review.

[0173] As can be seen from the solutions provided in the above embodiments, this application automatically generates data processing rules by providing users with a parameter configuration interface for rule configuration. This improves the transparency and interpretability of the rules, while also increasing the efficiency of data processing rule development and deployment. Providing rule trial runs before deployment improves rule testing efficiency. After the trial runs, historical black-and-white sample data is used to conduct an initial evaluation of the trial results, providing a reference for subsequent rule effectiveness assessment. The initial evaluation is performed automatically by the system, eliminating the need for manual operation. This ensures that the rule effectiveness evaluation standards used for both offline trial results and manual sampling verification results are consistent, reducing manpower consumption. Once the initial evaluation result, i.e., the first evaluation indicator, reaches the deployment standard, the rule is deployed, increasing the hit rate of data processing rules and thus improving the analytical effect of the data processing rules.

[0174] By providing unified rule templates, users can quickly configure data processing rules, improving user experience. Utilizing pre-cleaned and imported features, users can customize combination features to control specific risks, further improving the development efficiency of data processing rules. Through features such as template configuration, rule configuration, testing, evaluation, and approval, the various processes of data processing rules are transferred from offline to online, solving the problems of time-consuming and labor-intensive code development and slow deployment of data processing rules due to non-standard offline stages, enabling rapid deployment of data processing rules.

[0175] Based on the same inventive concept as the method embodiments, this application also provides a data processing apparatus, such as... Figure 20 As shown, the device 200 may include:

[0176] The parameter configuration request receiving module 210 is used to receive parameter configuration requests, which carry feature data.

[0177] Rule generation module 220 is used to generate data processing rules based on feature data;

[0178] The rule trial operation module 230 is used to receive trial operation instructions for data processing rules, and obtain trial operation results by utilizing the feature conditions of each feature in the data processing rules and the operation relationship between each feature condition;

[0179] Sample data acquisition module 240 is used to acquire historical black and white sample data;

[0180] The trial operation result analysis module 250 is used to analyze the trial operation results based on historical black and white sample data to obtain the first evaluation index;

[0181] The online processing module 260 is used to process the data processing rules online when the first evaluation indicator meets the preset online conditions.

[0182] In some feasible implementations, the device 200 may further include: a read request receiving module for receiving a template read request, the template read request carrying a template identifier; a template acquisition module for acquiring a rule template that matches the template identifier; and a template parameter reading module for reading template parameters from the rule template and sending the template parameters to the client so that the client can generate a parameter configuration interface based on the template parameters.

[0183] In some feasible implementations, the device 200 may further include: a feature search module for receiving a feature search request, the feature search request carrying feature keywords; a feature filtering module for filtering target feature information from a preset feature pool based on the feature keywords; a feature return module for sending the target feature information to a client so that the client can display the target feature information in a template configuration interface; a template configuration request receiving module for receiving a template configuration request from the template configuration interface, the template configuration request carrying template parameters; and a rule template generation module for generating a rule template based on the template parameters.

[0184] In some feasible implementations, the rule generation module 220 may include: a logic generation unit, used to generate feature conditions for each feature in the feature data based on the feature identifier, threshold parameter, and comparison operator parameter; a feature quantity determination unit, used to determine the number of features in the feature data; a first rule generation unit, used to form data processing rules from the feature conditions when the number of features is a preset feature threshold; and a second rule generation unit, used to determine the operational relationship between the feature conditions of each feature based on the feature association parameters in the feature data when the number of features is greater than the preset feature threshold, and to form data processing rules from the feature conditions of each feature and the operational relationship between the feature conditions.

[0185] In some feasible implementations, the first evaluation metric may include the hit rate of risky users and the hit rate of each risk category; the trial operation result analysis module 250 may include: a hit user determination unit, used to match historical black and white sample data with the trial operation results to determine hit users; a risky user screening unit, used to screen out risky users from the hit users; a first calculation unit, used to determine the risky user hit rate as the ratio of the number of risky users to the total number of users in the historical black and white sample data; a risky user classification unit, used to classify risky users according to risk categories to obtain the risky users corresponding to each risk category; and a second calculation unit, used to determine the hit rate of the risk category as the ratio of the number of risky users corresponding to the risk category to the total number of users corresponding to the risk category in the historical black and white samples.

[0186] In some feasible implementations, the device 200 may further include: an online condition judgment module, used to determine whether the first evaluation index meets the preset online conditions.

[0187] Specifically, the online condition judgment module may include: a first condition judgment unit, used to determine whether the hit rate of risk users meets the first preset online condition; a second condition judgment unit, used to determine whether the hit rate of each risk category meets the second preset online condition corresponding to the risk category; and a result determination unit, used to determine that the first hit indicator meets the preset online condition when the first preset online condition is met and the second preset online condition corresponding to each risk category is met.

[0188] In some feasible implementations, the device 200 may further include: a verification processing request receiving module, configured to receive a verification processing request for a data processing rule, the verification processing request carrying a second evaluation index; and a verification module, configured to verify the data processing rule according to the second evaluation index, and after the verification is passed, execute the step of putting the data processing rule online.

[0189] It should be noted that the apparatus provided in the above embodiments is only illustrated by the division of the above functional modules when implementing its functions. In actual applications, the above functions can be assigned to different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above. In addition, the apparatus and method embodiments provided in the above embodiments belong to the same concept, and the specific implementation process can be found in the method embodiments, which will not be repeated here.

[0190] This application also provides an electronic device, which includes a processor and a memory. The memory stores at least one instruction or at least one program, which is loaded by the processor and executed to perform the data processing method provided in the above method embodiments.

[0191] Furthermore, Figure 21 A schematic diagram of a hardware structure for implementing the method provided in the embodiments of this application is shown. This device may participate in or include the apparatus or system provided in the embodiments of this application. Figure 21 As shown, device 21 may include one or more processors 2102 (shown as 2102a, 2102b, ..., 2102n in the figure) 2102 (processor 2102 may include, but is not limited to, a microprocessor MCU or a programmable logic device FPGA, etc.), a memory 2104 for storing data, and a transmission device 2106 for communication functions. In addition, it may also include: a display, an input / output interface (I / O interface), a universal serial bus (USB) port (which may be included as one of the ports of the I / O interface), a network interface, a power supply, and / or a camera. Those skilled in the art will understand that... Figure 21 The structure shown is for illustrative purposes only and does not limit the structure of the electronic device described above. For example, device 21 may also include a... Figure 21 The more or fewer components shown, or having the same Figure 21 The different configurations shown.

[0192] It should be noted that the aforementioned one or more processors 2102 and / or other data processing circuitry are generally referred to herein as "data processing circuitry". This data processing circuitry may be embodied, in whole or in part, in software, hardware, firmware, or any other combination thereof. Furthermore, the data processing circuitry may be a single, independent processing module, or may be wholly or partially integrated into any other element within device 21 (or mobile device). As involved in the embodiments of this application, this data processing circuitry serves as a processor control mechanism (e.g., selection of a variable resistor termination path connected to an interface).

[0193] The memory 2104 can be used to store software programs and modules of application software, such as the program instructions / data storage device corresponding to the method described in the embodiments of this application. The processor 2102 executes various functional applications and data processing by running the software programs and modules stored in the memory 2104, thereby implementing the aforementioned data processing method. The memory 2104 may include high-speed random access memory, and may also include non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory 2104 may further include memory remotely located relative to the processor 2102, and these remote memories can be connected to the device 21 via a network. Examples of such networks include, but are not limited to, the Internet, corporate intranets, local area networks, mobile communication networks, and combinations thereof.

[0194] The transmission device 2106 is used to receive or send data via a network. Specific examples of the network described above may include a wireless network provided by the communication provider of device 21. In one example, the transmission device 2106 includes a Network Interface Controller (NIC), which can connect to other network devices via a base station to communicate with the Internet. In another example, the transmission device 2106 may be a radio frequency (RF) module used for wireless communication with the Internet.

[0195] The display may be, for example, a touchscreen liquid crystal display (LCD) that allows the user to interact with the user interface of device 21 (or mobile device).

[0196] This application also provides a computer storage medium storing at least one instruction or at least one program, which is loaded and executed by a processor to implement the data processing method provided in the above method embodiments.

[0197] Optionally, in this embodiment, the aforementioned computer storage medium may be located at at least one of the multiple network servers in a computer network. Optionally, in this embodiment, the aforementioned storage medium may include, but is not limited to, various media capable of storing program code, such as USB flash drives, read-only memory (ROM), random access memory (RAM), portable hard drives, magnetic disks, or optical disks.

[0198] This application also provides a computer program product or computer program that includes computer instructions stored in a computer storage medium. The processor of an electronic device reads the computer instructions from the computer storage medium and executes the computer instructions, causing the electronic device to perform the data processing method provided in the above-described method embodiments.

[0199] It should be noted that the order of the embodiments described above is merely for descriptive purposes and does not represent the superiority or inferiority of the embodiments. Furthermore, specific embodiments have been described above. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps described in the claims can be performed in a different order than that shown in the embodiments and still achieve the desired result. Additionally, the processes depicted in the drawings do not necessarily require a specific or sequential order to achieve the desired result. In some embodiments, multitasking and parallel processing are also possible or may be advantageous.

[0200] The various embodiments in this specification are described in a progressive manner. Similar or identical parts between embodiments can be referred to mutually. Each embodiment focuses on describing the differences from other embodiments. In particular, the device and electronic device embodiments are basically similar to the method embodiments, so the descriptions are relatively simple; relevant parts can be referred to the descriptions of the method embodiments.

[0201] The foregoing description has fully disclosed the specific embodiments of this application. It should be noted that any modifications made by those skilled in the art to the specific embodiments of this application do not depart from the scope of the claims. Accordingly, the scope of the claims of this application is not limited to the foregoing specific embodiments.

Claims

1. A data processing method, characterized in that, The method includes: Receive a parameter configuration request, the parameter configuration request carrying feature data; For each feature in the feature data, feature conditions are generated based on the feature identifier, threshold parameter, and comparison operator parameter of the feature, and the feature conditions characterize the risk pattern of the corresponding feature; the operation relationship between each feature condition is determined based on the feature association parameter in the feature data, and executable code indicating data processing rules is generated from each feature condition and the operation relationship between each feature condition; The executable code is invoked to obtain the trial run results; Obtain historical black and white sample data; The trial operation results are analyzed based on the historical black and white sample data to obtain a first evaluation index, which includes the hit rate of risky users and the hit rate of each risk category. Determine whether the hit rate of the risky users meets the first preset limit condition, and determine whether the hit rate of each risk category meets the second preset limit condition corresponding to the risk category; If the first preset launch condition is met, and the second preset launch condition corresponding to each risk category is met, then the first evaluation indicator is determined to meet the preset launch condition. When the first evaluation indicator meets the preset online conditions, the data processing rules are put into operation.

2. The method according to claim 1, characterized in that, The analysis of the trial operation results based on the historical black and white sample data to obtain the first evaluation index includes: The historical black-and-white sample data is matched with the trial operation results to determine the matched users; Filter out high-risk users from the hit users; The risk user hit rate is determined by the ratio of the number of risky users to the total number of users in the historical black and white sample data. The risky users are classified according to the risk categories to obtain the risky users corresponding to each risk category; For each risk category, the hit rate of that risk category is determined by the ratio of the number of risky users corresponding to that risk category to the total number of users corresponding to that risk category in the historical black and white samples.

3. The method according to claim 1, characterized in that, Before receiving the parameter configuration request, the method further includes: Receive a template read request, the template read request carrying a template identifier; Obtain the rule template that matches the template identifier; The template parameters in the rule template are read and sent to the client so that the client can generate a parameter configuration interface based on the template parameters.

4. The method according to claim 3, characterized in that, Before receiving the template read request, the method further includes: Receive a search feature request, the search feature request carrying feature keywords; Target feature information is selected from a preset feature pool based on the aforementioned feature keywords; The target feature information is sent to the client so that the client displays the target feature information in the template configuration interface; Receive a template configuration request from the template configuration interface, the template configuration request carrying template parameters; A rule template is generated based on the template parameters.

5. The method according to claim 1, characterized in that, Before the data processing rules are put online, the method further includes: Receive a verification processing request for the data processing rule, the verification processing request carrying a second evaluation index; The data processing rules are validated according to the second evaluation index. After the validation is passed, the step of putting the data processing rules online is executed.

6. A data processing apparatus, characterized in that, The device includes: A parameter configuration request receiving module is used to receive parameter configuration requests, wherein the parameter configuration requests carry feature data; The rule generation module is used to generate feature conditions for each feature in the feature data based on the feature identifier, threshold parameter, and comparison operator parameter of the feature, wherein the feature conditions characterize the risk pattern of the corresponding feature; determine the operation relationship between each feature condition based on the feature association parameter in the feature data; and generate executable code indicating data processing rules from each feature condition and the operation relationship between each feature condition. The rule trial operation module is used to call the executable code and obtain the trial operation results; The sample data acquisition module is used to acquire historical black and white sample data; The trial operation result analysis module is used to analyze the trial operation results based on the historical black and white sample data to obtain a first evaluation index, which includes the hit rate of risky users and the hit rate of each risk category. The online condition judgment module is used to determine whether the hit rate of the risk users meets the first preset online condition, and to determine whether the hit rate of each risk category meets the second preset online condition corresponding to the risk category; if the first preset online condition is met, and the second preset online condition corresponding to each risk category is met, then the first evaluation indicator is determined to meet the preset online condition. The online processing module is used to process the data processing rules online when the first evaluation indicator meets the preset online conditions.

7. The apparatus according to claim 6, characterized in that, The trial operation result analysis module is used for: The historical black-and-white sample data is matched with the trial operation results to determine the matched users; Filter out high-risk users from the hit users; The risk user hit rate is determined by the ratio of the number of risky users to the total number of users in the historical black and white sample data. The risky users are classified according to the risk categories to obtain the risky users corresponding to each risk category; For each risk category, the hit rate of that risk category is determined by the ratio of the number of risky users corresponding to that risk category to the total number of users corresponding to that risk category in the historical black and white samples.

8. The apparatus according to claim 6, characterized in that, The device further includes: The read request receiving module is used to receive template read requests, which carry template identifiers. The template acquisition module is used to obtain rule templates that match the template identifier; The template parameter reading module is used to read the template parameters in the rule template and send the template parameters to the client so that the client can generate a parameter configuration interface based on the template parameters.

9. The apparatus according to claim 8, characterized in that, The device further includes: The feature search module is used to receive search feature requests, which carry feature keywords. The feature filtering module is used to filter target feature information from a preset feature pool based on feature keywords; The feature return module is used to send target feature information to the client so that the client can display the target feature information in the template configuration interface; The template configuration request receiving module is used to receive template configuration requests from the template configuration interface. The template configuration request carries template parameters. The rule template generation module is used to generate rule templates based on template parameters.

10. The apparatus according to claim 6, characterized in that, The device further includes: The verification processing request receiving module is used to receive verification processing requests based on data processing rules. The verification processing request carries a second evaluation index. The verification module is used to verify the data processing rules according to the second evaluation index. After the verification is passed, the steps of going online with the data processing rules are executed.

11. An electronic device, characterized in that, The device includes a processor and a memory, the memory storing at least one instruction or at least one program, the at least one instruction or at least one program being loaded by the processor and executed as described in any one of claims 1-5.

12. A computer storage medium, characterized in that, The computer storage medium stores at least one instruction or at least one program, which is loaded and executed by a processor to implement the data processing method as described in any one of claims 1-5.

13. A computer program product, characterized in that, The computer program product includes computer instructions stored in a computer storage medium, a processor of an electronic device reading the computer instructions from the computer storage medium, and the processor executing the computer instructions to cause the electronic device to perform the data processing method as described in any one of claims 1-5.

Citation Information

Patent Citations

  • Data processing method and device, electronic equipment and readable medium

    CN111581291A

  • Managed real-time transaction fraud analysis and decisioning

    US20100305993A1