Fraudulent transaction identification method and device
By obtaining and analyzing the characteristic information of customer transactions, calculating the timing correlation score, and entering the fraud transaction identification model, the problem of difficult to identify high-risk fraud transactions in the existing technology is solved, and accurate identification and effective prevention of fraud transactions are achieved.
Patent Information
- Application Number
- CN202110851085.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-07-27
- Publication Date
- 2025-05-09
- Estimated Expiration
- 2041-07-27
AI Technical Summary
It is difficult to accurately and effectively identify high-risk fraudulent transactions, especially when fraudulent transactions are conducted after biometric information is stolen.
By obtaining the transaction characteristic information of the customer's transaction, including input feature information, background noise information, login IP information and login location information, the timing correlation score of each transaction characteristic information and the corresponding time series data set is calculated, and these data are input into the preset fraud transaction identification model to obtain the fraud transaction identification results of the transaction.
It has achieved accurate and effective identification of high-risk fraudulent transactions, and improved the transaction security of banks and other financial institutions.
Smart Images

Figure CN113506109B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of biometric identification anti-attack technology, and in particular to a fraudulent transaction identification method and device. Background Art
[0002] For banks, the security of customer transactions is of vital importance. Currently, criminals can steal the biometric information (face, iris, fingerprint, vein and other image information) cached to local devices after successful transactions through Trojans, sniffing, social engineering or other means, and then conduct fraudulent transactions based on the customer's biometric information. Existing technologies make it difficult to accurately and effectively identify these fraudulent transactions.
[0003] Therefore, how to accurately and effectively determine whether a transaction is a high-risk fraudulent transaction is a problem that the existing technology urgently needs to solve. Summary of the invention
[0004] In order to solve the technical problems in the above-mentioned background technology, the present invention proposes a fraudulent transaction identification method and device.
[0005] In order to achieve the above object, according to one aspect of the present invention, a fraudulent transaction identification method is provided, the method comprising:
[0006] Acquire transaction feature information of the customer's current transaction, the transaction feature information including: input feature information, background noise information, login IP information, and login location information, wherein the input feature information and the background noise information are extracted from the customer's biometric feature information collected during the current transaction;
[0007] Acquire a time series data set corresponding to each of the transaction feature information, wherein the time series data set is determined from the transaction feature information of each transaction of the customer in history;
[0008] Calculate the time series correlation score between each transaction feature information of this transaction and the corresponding time series data set respectively;
[0009] The time series correlation score corresponding to each transaction feature information of this transaction, the cumulative rejection rate of the customer, and the transaction frequency per unit time of the customer are input into the preset fraud transaction identification model to obtain the fraud transaction identification result of this transaction, wherein the fraud transaction identification model is obtained by training a preset machine learning model using training samples, and the training samples include: the time series correlation score corresponding to each transaction feature information, the cumulative rejection rate, and the transaction frequency per unit time, and the training samples are marked with the fraud transaction identification result.
[0010] Optionally, respectively calculating the time series correlation scores between each transaction feature information of the transaction and the corresponding time series data set specifically includes:
[0011] Calculate the similarity between each transaction feature information of this transaction and each data in the corresponding time series data set;
[0012] According to the similarity between each transaction feature information of this transaction and each data in the corresponding time series data set, the time series correlation score corresponding to each transaction feature information of this transaction is calculated.
[0013] Optionally, the calculating of the time series correlation score corresponding to each transaction feature information of the transaction according to the similarity between each transaction feature information of the transaction and each data in the corresponding time series data set specifically includes:
[0014] For the two transaction feature information, input feature information and background noise information, if the similarity with at least one data in the time series data set is equal to 1, the time series correlation score is determined to be 1. If the similarity with each data in the time series data set is not 1, the average value of the similarity with each data in the time series data set is used as the time series correlation score.
[0015] Optionally, the calculating of the time series correlation score corresponding to each transaction feature information of the transaction according to the similarity between each transaction feature information of the transaction and each data in the corresponding time series data set specifically includes:
[0016] For the two transaction feature information, login IP information and login location information, the average value of the similarity with each data in the time series data set is taken as the time series relevance score.
[0017] Optionally, the time series correlation score corresponding to each transaction feature information of the transaction, the cumulative rejection rate of the customer, and the transaction frequency per unit time of the customer are input into a preset fraudulent transaction identification model to obtain a fraudulent transaction identification result of the transaction, specifically including:
[0018] If at least one of the time series correlation score corresponding to the input feature information of this transaction and the time series correlation score corresponding to the background noise information is 1, then the fraudulent transaction identification result of this transaction is directly determined to be a high-risk fraudulent transaction;
[0019] If the timing correlation score corresponding to the input feature information of this transaction and the timing correlation score corresponding to the background noise information are both not 1, then the timing correlation score corresponding to each transaction feature information of this transaction, the cumulative rejection rate of the customer and the transaction frequency per unit time of the customer are input into the preset fraud transaction identification model to obtain the fraud transaction identification result of this transaction.
[0020] Optionally, the fraudulent transaction identification method further includes:
[0021] Obtaining a training sample, wherein the training sample includes: a time series correlation score, a cumulative rejection rate, and a transaction frequency per unit time corresponding to each of the transaction feature information, and the training sample is marked with a fraudulent transaction identification result;
[0022] The preset deep learning network is trained according to the training samples to obtain the fraudulent transaction identification model.
[0023] Optionally, the fraudulent transaction identification result includes: high-risk fraudulent transactions, medium-risk suspicious transactions, and low-risk credible transactions;
[0024] The fraudulent transaction identification method further includes:
[0025] If the fraudulent transaction identification result of this transaction is a high-risk fraudulent transaction, the transaction will be rejected, the customer and the device associated with the customer will be marked as high-risk, and the transaction rights of the customer will be frozen;
[0026] If the fraudulent transaction identification result of this transaction is a medium-risk suspicious transaction, the transaction will be rejected and the customer will be included in the suspicious transaction monitoring;
[0027] If the fraudulent transaction identification result of this transaction is a low-risk and trustworthy transaction, it will not be processed.
[0028] In order to achieve the above object, according to another aspect of the present invention, a fraudulent transaction identification device is provided, the device comprising:
[0029] A transaction feature information acquisition module is used to acquire the transaction feature information of the customer's current transaction, wherein the transaction feature information includes: input feature information, background noise information, login IP information, and login location information, wherein the input feature information and the background noise information are extracted from the customer's biometric feature information collected during the current transaction;
[0030] A time series data set acquisition module, used to acquire a time series data set corresponding to each of the transaction feature information, wherein the time series data set is determined from the transaction feature information of each transaction of the customer in history;
[0031] A time series correlation score calculation module is used to calculate the time series correlation score between each transaction feature information of this transaction and the corresponding time series data set;
[0032] A fraudulent transaction identification module is used to input the time series correlation score corresponding to each transaction feature information of this transaction, the cumulative rejection rate of the customer, and the transaction frequency per unit time of the customer into a preset fraud transaction identification model to obtain a fraudulent transaction identification result of this transaction, wherein the fraudulent transaction identification model is obtained by training a preset machine learning model using training samples, and the training samples include: the time series correlation score corresponding to each transaction feature information, the cumulative rejection rate, and the transaction frequency per unit time, and the training samples are marked with fraudulent transaction identification results.
[0033] In order to achieve the above-mentioned purpose, according to another aspect of the present invention, a computer device is further provided, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the steps in the above-mentioned fraudulent transaction identification method when executing the computer program.
[0034] In order to achieve the above objective, according to another aspect of the present invention, a computer-readable storage medium is provided, wherein the computer-readable storage medium stores a computer program, and when the computer program is executed in a computer processor, the steps in the above fraudulent transaction identification method are implemented.
[0035] The beneficial effects of the present invention are:
[0036] The embodiment of the present invention trains a fraudulent transaction identification model through training samples, and then uses the trained fraudulent transaction identification model to identify the fraudulent transaction identification result of the current transaction according to the transaction feature information of the current transaction, thereby achieving the beneficial effect of accurately and effectively identifying high-risk fraudulent transactions. BRIEF DESCRIPTION OF THE DRAWINGS
[0037] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the prior art descriptions. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work. In the drawings:
[0038] Figure 1 is a flow chart of a fraudulent transaction identification method according to an embodiment of the present invention;
[0039] Figure 2 is a first flow chart of calculating a temporal correlation score according to an embodiment of the present invention;
[0040] Figure 3 is a second flow chart of calculating a temporal correlation score according to an embodiment of the present invention;
[0041] Figure 4is a specific flow chart of fraudulent transaction identification according to an embodiment of the present invention;
[0042] Figure 5 is a training flow chart of a fraudulent transaction identification model according to an embodiment of the present invention;
[0043] Figure 6 is a structural block diagram of a fraudulent transaction identification device according to an embodiment of the present invention;
[0044] Figure 7 is a structural block diagram of a temporal correlation score calculation module according to an embodiment of the present invention;
[0045] Figure 8 is a structural block diagram of a fraudulent transaction identification module according to an embodiment of the present invention;
[0046] Fig. 9 It is a schematic diagram of a computer device according to an embodiment of the present invention. DETAILED DESCRIPTION
[0047] In order to enable those skilled in the art to better understand the scheme of the present invention, the technical scheme in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work should fall within the scope of protection of the present invention.
[0048] Those skilled in the art will appreciate that embodiments of the present invention may be provided as methods, systems, or computer program products. Therefore, the present invention may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Moreover, the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0049] It should be noted that the terms "including" and "having" and any variations thereof in the specification and claims of the present invention and the above-mentioned drawings are intended to cover non-exclusive inclusions. For example, a process, method, system, product or apparatus comprising a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or apparatus.
[0050] It should be noted that, in the absence of conflict, the embodiments of the present invention and the features in the embodiments can be combined with each other. The present invention will be described in detail below with reference to the accompanying drawings and in combination with the embodiments.
[0051] It should be noted that the fraudulent transaction identification method and device of the present invention can be used in the financial field, and can also be applied to other technical fields.
[0052] The present invention provides a fraudulent transaction identification method based on time series data. The present invention identifies the replay risk of the current transaction by performing correlation analysis and abnormality scoring on the biometric information, historical transaction records and other information in the transaction, and improves the ability to defend against injection attacks and database collision attacks. At the same time, suspicious persons and devices are included in the blacklist management to prevent attacks from the user and device levels.
[0053] Figure 1 is a flow chart of a fraudulent transaction identification method according to an embodiment of the present invention. Figure 1 As shown, in one embodiment of the present invention, the fraudulent transaction identification method of the present invention includes steps S101 to S104.
[0054] Step S101, obtaining transaction feature information of the customer's transaction, the transaction feature information including: input feature information, background noise information, login IP information and login location information, wherein the input feature information and the background noise information are extracted from the customer's biometric information collected during the transaction.
[0055] In the present invention, the customer initiates a transaction on the terminal device, and during the transaction, the terminal device collects the customer's biometric information for customer identity verification. In an optional embodiment of the present invention, the biometric information can be a picture (face picture, iris picture, fingerprint picture, vein picture), audio (voiceprint) or video (person action video).
[0056] In the embodiment of the present invention, the present invention divides the biometric information into input feature information and background noise information, wherein the input feature information is the biometric part of the biometric information, and the background noise information is the background part of the biometric information. For example, for a face picture, the input feature information is the face image of the person, and the background noise information is the part of the picture other than the face of the person.
[0057] In the embodiments of the present invention, different types of biometric information are segmented into input feature information and background noise information in different ways, and the same type of biometric information can also be segmented in different ways. For example, for face images, the Haar classifier and watershed algorithm in opencv can be used to segment the background, face portrait, collar and clothing of the image; or the particle swarm detection method can be used to accurately detect and segment the face. For vein images, the directional field distribution rate can be used to segment the vein pattern and background.
[0058] In the embodiment of the present invention, the login IP information and login location information of this transaction can be obtained from the transaction log of this transaction. The transaction log is stored in a structured database in the form of records, generally including fields such as transaction time, transaction account number, transaction device model, login IP information, login location, service success / failure flag, error code, etc.
[0059] Step S102, obtaining a time series data set corresponding to each of the transaction feature information, wherein the time series data set is determined from the transaction feature information of each transaction of the customer in history.
[0060] In the embodiment of the present invention, the present invention obtains the transaction log of each transaction in the history of the customer and the biometric information of the customer collected in each transaction in the history of the customer. Then the biometric information of each transaction in the history is divided into input feature information and background noise information. And the login IP information and login location information of each transaction are extracted from the transaction log of each transaction in the history. Then, according to these historical information, a time series data set corresponding to each of the transaction feature information is established.
[0061] The time series data sets corresponding to each of the transaction feature information specifically include: a time series data set corresponding to the input feature information, a time series data set corresponding to the background noise information, a time series data set corresponding to the login IP information, and a time series data set corresponding to the login location information. Each time series data set contains multiple data.
[0062] Step S103, respectively calculating the time series correlation scores between each transaction feature information of this transaction and the corresponding time series data set.
[0063] In the present invention, according to certain transaction feature information A (A is one of input feature information, background noise information, login IP information, and login location information) and the time series data set {A0, A1, A2, ..., A n}, calculate the temporal correlation score Score(A) of the transaction feature information A.
[0064] Specifically, the present invention combines the transaction feature information A0 of this transaction and the elements (A1, A2, ..., A n ) are compared one by one. The transaction feature information A is converted into a multidimensional vector a, and the absolute value is calculated using the cosine similarity algorithm to obtain A0 and A i Similarity score sim(Ai) (range [0,1]).
[0065] In one embodiment of the present invention, when the transaction feature information A is the input feature information and the background noise information, if the similarity is 1 in any comparison, the temporal correlation score of the transaction feature information A is set to the full score of 1; otherwise, the weighted average method is used to calculate the temporal correlation score of the transaction feature information A.
[0066] In one embodiment of the present invention, when the transaction feature information A is login IP information and login location information, the present invention uses a weighted average method to calculate the temporal correlation score of the transaction feature information A for the similarity obtained from each comparison.
[0067] In one embodiment of the present invention, the multidimensional vector conversion rule of the present invention may specifically be:
[0068] Input feature information a=(x,y), where x and y are coordinates;
[0069] Background noise information a=(x,y), where x and y are coordinates;
[0070] Login IP information a = (p1, p2, p3, p4), p1, p2, p3, p4 are four segments of IP;
[0071] Login location information a = (province, area), split the login location into two parts: province + area, and replace them with digital numbers. The first part of the binary is the digital number of the province, and the second part is the digital number of the area;
[0072] In one embodiment of the present invention, the calculation formula of similarity may be specifically as follows:
[0073]
[0074] In one embodiment of the present invention, the calculation formula of the temporal correlation score of the transaction feature information A may be specifically as follows:
[0075] (1) For input feature information and background noise information
[0076]
[0077] (2) Login IP information and login location information
[0078]
[0079] For example, calculate the time series correlation score of login location information: Assume that there were 4 transactions in history, and the login locations were Guangzhou, Guangdong, Guangzhou, Guangdong, Shenzhen, Guangdong, and Guangzhou, Guangdong. The current transaction login location is Zhuhai, Guangdong. The first step is to convert the login location into a multi-dimensional vector (the numbering rule in this example is arbitrary), Guangzhou, Guangdong = (1,1), Shenzhen, Guangdong = (1,2), Zhuhai, Guangdong = (1,3). The second step is to calculate the similarity between the current login location Zhuhai, Guangdong = (1,3) and the historical login location time series data set {(1,1), (1,1), (1,2), (1,1)}, and the calculated similarities are Then, the time series correlation score of the login location information is calculated by weighted average:
[0080] Step S104, inputting the time series correlation score corresponding to each transaction feature information of this transaction, the cumulative rejection rate of the customer and the transaction frequency per unit time of the customer into a preset fraudulent transaction identification model to obtain a fraudulent transaction identification result of this transaction.
[0081] Among them, the fraud transaction identification model is obtained by training a preset machine learning model using training samples, and the training samples include: the time series correlation score, cumulative rejection rate and transaction frequency per unit time corresponding to each of the transaction feature information, and the training samples are marked with fraud transaction identification results.
[0082] In the present invention, the transaction log of each transaction contains fields such as transaction time, transaction account number, transaction device model, login IP information, login location, service success / failure flag, error code, etc. The present invention obtains the transaction log of each transaction in the history of the customer, and then determines the customer's cumulative rejection rate and the customer's transaction frequency per unit time according to the information in the transaction log of each transaction in the history of the customer.
[0083] In one embodiment of the present invention, the cumulative account rejection rate = total number of service failures / total number of historical transactions, the total number of service failures is obtained by adding up the number of times the service failure mark appears, and the total number of historical transactions is the sum of the transaction logs associated with the customer.
[0084] In one embodiment of the present invention, the transaction frequency per unit time can be understood as the number of transactions per unit time, for example, 30 transactions occurred within 1 minute. If a normal user retries after a failure, the number of retries within 1 minute is generally 1-5, which is used to prevent database collision attacks.
[0085] It can be seen that the embodiment of the present invention trains a fraudulent transaction identification model through training samples, and then uses the trained fraudulent transaction identification model to identify the fraudulent transaction identification result of the current transaction according to the transaction feature information of the current transaction, thereby achieving the beneficial effect of accurately and effectively identifying high-risk fraudulent transactions.
[0086] Figure 2 is a first flow chart of calculating the time series correlation score according to an embodiment of the present invention, such as Figure 2 As shown, in one embodiment of the present invention, the above step S103 of respectively calculating the time series correlation score between each transaction feature information of the transaction and the corresponding time series data set specifically includes step S201 and step S202.
[0087] Step S201, respectively calculating the similarity between each transaction feature information of this transaction and each data in the corresponding time series data set.
[0088] In the embodiment of the present invention, the present invention calculates the transaction feature information A0 of this transaction and the corresponding time series data set (A1, A2, ..., A n ) The similarity of each data in the set. Specifically, the present invention first converts the transaction feature information A into a multidimensional vector a, and then uses the cosine similarity algorithm to calculate and take the absolute value to obtain A0 and A i Similarity score sim(Ai) (range [0,1]).
[0089] Step S202, according to the similarity between each transaction feature information of this transaction and each data in the corresponding time series data set, calculate the time series correlation score corresponding to each transaction feature information of this transaction.
[0090] Figure 3 is a second flow chart of calculating the time series correlation score according to an embodiment of the present invention, such as Figure 3 As shown, in one embodiment of the present invention, the above step S202 of calculating the time series correlation score between each transaction feature information of the transaction and the corresponding time series data set specifically includes step S301 and step S302.
[0091] Step S301, for the two transaction feature information, input feature information and background noise information, if the similarity with at least one data in the time series data set is equal to 1, then the time series correlation score is determined to be 1; if the similarity with each data in the time series data set is not 1, then the average value of the similarity with each data in the time series data set is used as the time series correlation score.
[0092] In one embodiment of the present invention, when the transaction feature information A is the input feature information and the background noise information, if the similarity is 1 in any comparison, the temporal correlation score of the transaction feature information A is set to the full score of 1; otherwise, the weighted average method is used to calculate the temporal correlation score of the transaction feature information A.
[0093] Step S302: For the two transaction feature information, login IP information and login location information, the average value of the similarity with each data in the time series data set is used as the time series relevance score.
[0094] Figure 4 is a specific flow chart of fraudulent transaction identification according to an embodiment of the present invention, such as Figure 4 As shown, in one embodiment of the present invention, the fraudulent transaction identification process of step S104 specifically includes step S401 and step S402.
[0095] Step S401: If at least one of the time series correlation score corresponding to the input feature information of this transaction and the time series correlation score corresponding to the background noise information is 1, then the fraudulent transaction identification result of this transaction is directly determined to be a high-risk fraudulent transaction.
[0096] In general, even if the same user performs multiple operations in a short time interval, the shooting angle of the device and the user's interactive actions cannot be completely consistent every time. If they are completely consistent, the possibility of being attacked is extremely high. Therefore, the present invention first screens significant attack features through expert rules. Device direction, shooting angle, customer behavior, etc. will all have an impact on input features, background noise, etc. There may be correlation between key points of biometric features with time context relationships, but the background noise information in different transactions cannot be completely consistent. If there is a situation where any unstructured data in the input feature information and background noise information meets the full correlation score (that is, the time series correlation score is 1), it can be reasonably inferred that there is biometric splicing or reuse, and the attack characteristics are significant. According to the rules, it is directly determined to be a high-risk fraud transaction; otherwise, the fraud transaction recognition model pre-trained by the present invention is used to identify fraudulent transactions.
[0097] Step S402: If the timing correlation score corresponding to the input feature information of this transaction and the timing correlation score corresponding to the background noise information are not 1, then the timing correlation score corresponding to each transaction feature information of this transaction, the cumulative rejection rate of the customer and the transaction frequency per unit time of the customer are input into the preset fraud transaction identification model to obtain the fraud transaction identification result of this transaction.
[0098] Figure 5 is a training flow chart of a fraudulent transaction identification model according to an embodiment of the present invention, such as Figure 5As shown, in one embodiment of the present invention, the specific training process of the fraudulent transaction identification model in step S104 includes step S501 and step S502.
[0099] Step S501, obtaining training samples, wherein the training samples include: the time series correlation score, cumulative rejection rate and transaction frequency per unit time corresponding to each of the transaction feature information, and the training samples are marked with fraudulent transaction identification results.
[0100] In one embodiment of the present invention, the training samples are comprehensively derived from the identification of various characteristic factors of biometrics and business data of various scenarios. Data labeling is achieved by manually labeling positive and negative samples of fraudulent transactions. The verification samples are derived from the identification of various characteristic factors of biometrics and business data of various scenarios.
[0101] Step S502: training a preset deep learning network according to the training samples to obtain the fraudulent transaction identification model.
[0102] In one embodiment of the present invention, the input of the fraud transaction identification model of the present invention is: the temporal correlation score of input feature information, background noise information, login IP information and login location information, the cumulative rejection rate and transaction frequency per unit time, and the output is the fraud transaction identification result.
[0103] In one embodiment of the present invention, the fraudulent transaction identification results of the present invention include: high-risk fraudulent transactions, medium-risk suspicious transactions, and low-risk credible transactions.
[0104] In one embodiment of the present invention, after the fraudulent transaction identification result of the transaction is identified in the above step S104, the fraudulent transaction identification method of the present invention further includes:
[0105] If the fraudulent transaction identification result of this transaction is a high-risk fraudulent transaction, the transaction will be rejected, the customer and the device associated with the customer will be marked as high-risk, and the transaction rights of the customer will be frozen;
[0106] If the fraudulent transaction identification result of this transaction is a medium-risk suspicious transaction, the transaction will be rejected and the customer will be included in the suspicious transaction monitoring;
[0107] If the fraudulent transaction identification result of this transaction is a low-risk and trustworthy transaction, it will not be processed.
[0108] It can be seen from the above embodiments that the present invention can fully utilize the spatiotemporal context information to identify and prevent attacks such as repeated attempts, malicious database collisions, and replays. At the same time, it can mine user behavior anomalies from the spatiotemporal context information and enhance the ability of the biometric recognition system to resist unknown attack behaviors.
[0109] It should be noted that the steps shown in the flowcharts of the accompanying drawings can be executed in a computer system such as a set of computer executable instructions, and that, although a logical order is shown in the flowcharts, in some cases, the steps shown or described can be executed in an order different from that shown here.
[0110] Based on the same inventive concept, an embodiment of the present invention further provides a fraudulent transaction identification device, which can be used to implement the fraudulent transaction identification method described in the above embodiment, as described in the following embodiment. Since the principle of solving the problem by the fraudulent transaction identification device is similar to that of the fraudulent transaction identification method, the embodiment of the fraudulent transaction identification device can refer to the embodiment of the fraudulent transaction identification method, and the repeated parts are not repeated. As used below, the term "unit" or "module" can be a combination of software and / or hardware that implements a predetermined function. Although the device described in the following embodiment is preferably implemented in software, the implementation of hardware, or a combination of software and hardware, is also possible and conceivable.
[0111] Figure 6 is a structural block diagram of a fraudulent transaction identification device according to an embodiment of the present invention. Figure 6 As shown, in one embodiment of the present invention, the fraudulent transaction identification device of the present invention includes:
[0112] Transaction feature information acquisition module 1, used to acquire transaction feature information of the customer's current transaction, the transaction feature information includes: input feature information, background noise information, login IP information and login location information, wherein the input feature information and the background noise information are extracted from the customer's biometric feature information collected during the current transaction;
[0113] A time series data set acquisition module 2 is used to acquire a time series data set corresponding to each of the transaction feature information, wherein the time series data set is determined from the transaction feature information of each transaction of the customer in history;
[0114] The time series correlation score calculation module 3 is used to calculate the time series correlation score between each transaction feature information of this transaction and the corresponding time series data set;
[0115] The fraudulent transaction identification module 4 is used to input the time series correlation score corresponding to each transaction feature information of this transaction, the cumulative rejection rate of the customer, and the transaction frequency per unit time of the customer into a preset fraud transaction identification model to obtain a fraud transaction identification result of this transaction, wherein the fraud transaction identification model is obtained by training a preset machine learning model using training samples, and the training samples include: the time series correlation score corresponding to each transaction feature information, the cumulative rejection rate, and the transaction frequency per unit time, and the training samples are marked with fraud transaction identification results.
[0116] Figure 7 is a structural block diagram of a temporal correlation score calculation module according to an embodiment of the present invention. Figure 7 As shown, in one embodiment of the present invention, the temporal correlation score calculation module 3 specifically includes:
[0117] A similarity calculation unit 301 is used to calculate the similarity between each transaction feature information of this transaction and each data in the corresponding time series data set;
[0118] The time series relevance score determination unit 302 is used to calculate the time series relevance score corresponding to each transaction feature information of this transaction according to the similarity between each transaction feature information of this transaction and each data in the corresponding time series data set.
[0119] In one embodiment of the present invention, the time series correlation score determination unit 302 is specifically used to determine the time series correlation score as 1 for two transaction feature information, namely, input feature information and background noise information, if the similarity with at least one data in the time series data set is equal to 1; if the similarity with each data in the time series data set is not 1, then the average value of the similarity with each data in the time series data set is used as the time series correlation score.
[0120] In one embodiment of the present invention, the time series correlation score determination unit 302 is further used to use the average value of the similarity with each data in the time series data set as the time series correlation score for the two transaction feature information, namely, the login IP information and the login location information.
[0121] Figure 8 is a structural block diagram of a fraudulent transaction identification module according to an embodiment of the present invention. Figure 8 As shown, in one embodiment of the present invention, the fraudulent transaction identification module 4 specifically includes:
[0122] The first fraudulent transaction identification unit 401 is configured to directly determine that the fraudulent transaction identification result of the transaction is a high-risk fraudulent transaction if at least one of the time series correlation score corresponding to the input feature information of the transaction and the time series correlation score corresponding to the background noise information is 1;
[0123] The second fraudulent transaction identification unit 402 is used to input the timing correlation score corresponding to each transaction feature information of this transaction, the cumulative rejection rate of the customer, and the transaction frequency per unit time of the customer into a preset fraudulent transaction identification model if the timing correlation score corresponding to the input feature information of this transaction and the timing correlation score corresponding to the background noise information are both not 1, so as to obtain a fraudulent transaction identification result of this transaction.
[0124] In one embodiment of the present invention, the fraudulent transaction identification device of the present invention comprises:
[0125] A training sample acquisition module, used to acquire training samples, wherein the training samples include: the time series correlation score, the cumulative rejection rate and the transaction frequency per unit time corresponding to each of the transaction feature information, and the training samples are marked with fraudulent transaction identification results;
[0126] The model training module is used to train a preset deep learning network according to the training samples to obtain the fraudulent transaction identification model.
[0127] In one embodiment of the present invention, the fraudulent transaction identification device of the present invention includes: a risk management module, which is specifically used to: if the fraudulent transaction identification result of the current transaction is a high-risk fraudulent transaction, then reject the transaction, mark the customer and the equipment associated with the customer as high-risk, and freeze the customer's transaction rights; if the fraudulent transaction identification result of the current transaction is a medium-risk suspicious transaction, then reject the transaction and include the customer in the suspicious transaction monitoring; if the fraudulent transaction identification result of the current transaction is a low-risk trustworthy transaction, then no processing is performed.
[0128] In order to achieve the above object, according to another aspect of the present application, a computer device is also provided. Fig. 9 As shown, the computer device includes a memory, a processor, a communication interface and a communication bus. A computer program that can be executed on the processor is stored in the memory. When the processor executes the computer program, the steps in the above-mentioned embodiment method are implemented.
[0129] The processor may be a central processing unit (CPU). The processor may also be other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field-programmable gate arrays (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, or a combination of the above chips.
[0130] The memory, as a non-transitory computer-readable storage medium, can be used to store non-transitory software programs, non-transitory computer executable programs and units, such as the corresponding program units in the above method embodiments of the present invention. The processor executes various functional applications of the processor and works data processing by running the non-transitory software programs, instructions and modules stored in the memory, that is, implementing the method in the above method embodiments.
[0131] The memory may include a program storage area and a data storage area, wherein the program storage area may store an operating system, an application required for at least one function; the data storage area may store data created by the processor, etc. In addition, the memory may include a high-speed random access memory, and may also include a non-volatile memory, such as at least one disk storage device, a flash memory device, or other non-volatile solid-state storage device. In some embodiments, the memory may optionally include a memory remotely arranged relative to the processor, and these remote memories may be connected to the processor via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.
[0132] The one or more units are stored in the memory, and when executed by the processor, the method in the above embodiment is performed.
[0133] The specific details of the above-mentioned computer device can be understood by referring to the corresponding related descriptions and effects in the above-mentioned embodiments, and will not be repeated here.
[0134] In order to achieve the above purpose, according to another aspect of the present application, a computer-readable storage medium is also provided, wherein the computer-readable storage medium stores a computer program, and the computer program implements the steps in the above-mentioned fraudulent transaction identification method when executed in a computer processor. Those skilled in the art can understand that the implementation of all or part of the processes in the above-mentioned embodiment method can be completed by instructing the relevant hardware through a computer program, and the program can be stored in a computer-readable storage medium, and the program can include the processes of the embodiments of the above-mentioned methods when executed. Among them, the storage medium can be a disk, an optical disk, a read-only memory (ROM), a random access memory (RAM), a flash memory (Flash Memory), a hard disk (Hard Disk Drive, abbreviated: HDD) or a solid-state drive (SSD), etc.; the storage medium can also include a combination of the above-mentioned types of memory.
[0135] Obviously, those skilled in the art should understand that the above modules or steps of the present invention can be implemented by a general computing device, they can be concentrated on a single computing device, or distributed on a network composed of multiple computing devices, and optionally, they can be implemented by a program code executable by a computing device, so that they can be stored in a storage device and executed by the computing device, or they can be made into individual integrated circuit modules, or multiple modules or steps therein can be made into a single integrated circuit module for implementation. Thus, the present invention is not limited to any specific combination of hardware and software.
[0136] The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. For those skilled in the art, the present invention may have various modifications and variations. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present invention shall be included in the protection scope of the present invention.
Claims
1. A fraudulent transaction identification method, characterized in that: include: Acquire transaction feature information of the customer's current transaction, the transaction feature information including: input feature information, background noise information, login IP information and login location information, wherein the input feature information and the background noise information are extracted from the customer's biometric feature information collected during the current transaction, the input feature information is the biometric feature part of the biometric feature information, and the background noise information is the background part of the biometric feature information; Obtaining a time series data set corresponding to each of the transaction feature information, wherein the time series data set is determined from the transaction feature information of each transaction in the history of the customer; obtaining a transaction log of each transaction in the history of the customer and the biometric information of the customer collected for each transaction in the history of the customer, and then dividing the biometric information of each transaction in the history into input feature information and background noise information, and extracting the login IP information and login location information of each transaction from the transaction log of each transaction in the history, and then establishing a time series data set corresponding to each of the transaction feature information according to these historical information; Calculate the time series correlation score between each transaction feature information of this transaction and the corresponding time series data set respectively; Input the time series correlation score corresponding to each transaction feature information of this transaction, the cumulative rejection rate of the customer, and the transaction frequency per unit time of the customer into a preset fraudulent transaction identification model to obtain a fraudulent transaction identification result of this transaction, wherein the fraudulent transaction identification model is obtained by training a preset machine learning model using training samples, and the training samples include: the time series correlation score corresponding to each transaction feature information, the cumulative rejection rate, and the transaction frequency per unit time, and the training samples are marked with the fraudulent transaction identification result; The calculating of the time series correlation scores of each transaction feature information of the transaction and the corresponding time series data set respectively specifically includes: Calculate the similarity between each transaction feature information of this transaction and each data in the corresponding time series data set; According to the similarity between each transaction feature information of this transaction and each data in the corresponding time series data set, the time series correlation score corresponding to each transaction feature information of this transaction is calculated.
2. The fraudulent transaction identification method according to claim 1, characterized in that: The calculating of the time series correlation score corresponding to each transaction feature information of the transaction according to the similarity between each transaction feature information of the transaction and each data in the corresponding time series data set specifically includes: For the two transaction feature information, input feature information and background noise information, if the similarity with at least one data in the time series data set is equal to 1, the time series correlation score is determined to be 1. If the similarity with each data in the time series data set is not 1, the average value of the similarity with each data in the time series data set is used as the time series correlation score.
3. The fraudulent transaction identification method according to claim 1, characterized in that: The calculating of the time series correlation score corresponding to each transaction feature information of the transaction according to the similarity between each transaction feature information of the transaction and each data in the corresponding time series data set specifically includes: For the two transaction feature information, login IP information and login location information, the average value of the similarity with each data in the time series data set is taken as the time series relevance score.
4. The fraudulent transaction identification method according to claim 2, characterized in that: The time series correlation score corresponding to each transaction feature information of this transaction, the cumulative rejection rate of the customer and the transaction frequency per unit time of the customer are input into the preset fraudulent transaction identification model to obtain the fraudulent transaction identification result of this transaction, which specifically includes: If at least one of the time series correlation score corresponding to the input feature information of this transaction and the time series correlation score corresponding to the background noise information is 1, then the fraudulent transaction identification result of this transaction is directly determined to be a high-risk fraudulent transaction; If the timing correlation score corresponding to the input feature information of this transaction and the timing correlation score corresponding to the background noise information are both not 1, then the timing correlation score corresponding to each transaction feature information of this transaction, the cumulative rejection rate of the customer and the transaction frequency per unit time of the customer are input into the preset fraud transaction identification model to obtain the fraud transaction identification result of this transaction.
5. The fraudulent transaction identification method according to claim 1, characterized in that: Also includes: Obtaining a training sample, wherein the training sample includes: a time series correlation score, a cumulative rejection rate, and a transaction frequency per unit time corresponding to each of the transaction feature information, and the training sample is marked with a fraudulent transaction identification result; The preset deep learning network is trained according to the training samples to obtain the fraudulent transaction identification model.
6. The fraudulent transaction identification method according to claim 1, characterized in that: The fraudulent transaction identification results include: high-risk fraudulent transactions, medium-risk suspicious transactions, and low-risk credible transactions; The fraudulent transaction identification method further includes: If the fraudulent transaction identification result of this transaction is a high-risk fraudulent transaction, the transaction will be rejected, the customer and the device associated with the customer will be marked as high-risk, and the transaction rights of the customer will be frozen; If the fraudulent transaction identification result of this transaction is a medium-risk suspicious transaction, the transaction will be rejected and the customer will be included in the suspicious transaction monitoring; If the fraudulent transaction identification result of this transaction is a low-risk and trustworthy transaction, it will not be processed.
7. A fraudulent transaction identification device, characterized in that: include: A transaction feature information acquisition module is used to acquire the transaction feature information of the customer's current transaction, wherein the transaction feature information includes: input feature information, background noise information, login IP information, and login location information, wherein the input feature information and the background noise information are extracted from the customer's biometric feature information collected during the current transaction, the input feature information is the biometric feature part of the biometric feature information, and the background noise information is the background part of the biometric feature information; A time series data set acquisition module is used to acquire a time series data set corresponding to each of the transaction feature information, wherein the time series data set is determined from the transaction feature information of each transaction in the history of the customer; acquire a transaction log of each transaction in the history of the customer and the biometric information of the customer collected for each transaction in the history of the customer, and then segment the biometric information of each transaction in the history into input feature information and background noise information, and extract the login IP information and login location information of each transaction from the transaction log of each transaction in the history, and then establish a time series data set corresponding to each of the transaction feature information according to these historical information; A time series correlation score calculation module is used to calculate the time series correlation score between each transaction feature information of this transaction and the corresponding time series data set; A fraudulent transaction identification module, for inputting the time series correlation score corresponding to each transaction feature information of this transaction, the cumulative rejection rate of the customer, and the transaction frequency per unit time of the customer into a preset fraudulent transaction identification model, and obtaining a fraudulent transaction identification result of this transaction, wherein the fraudulent transaction identification model is obtained by training a preset machine learning model using training samples, and the training samples include: the time series correlation score corresponding to each transaction feature information, the cumulative rejection rate, and the transaction frequency per unit time, and the training samples are marked with the fraudulent transaction identification result; The temporal correlation score calculation module specifically includes: A similarity calculation unit, used to respectively calculate the similarity between each transaction feature information of this transaction and each data in the corresponding time series data set; The time series relevance score determination unit is used to calculate the time series relevance score corresponding to each transaction feature information of this transaction according to the similarity between each transaction feature information of this transaction and each data in the corresponding time series data set.
8. The fraudulent transaction identification device according to claim 7, characterized in that: The time series correlation score determination unit is specifically used to determine the time series correlation score as 1 for two transaction feature information, namely, input feature information and background noise information, if the similarity with at least one data in the time series data set is equal to 1; if the similarity with each data in the time series data set is not 1, then the average value of the similarity with each data in the time series data set is used as the time series correlation score.
9. The fraudulent transaction identification device according to claim 8, characterized in that: The fraudulent transaction identification module specifically includes: A first fraudulent transaction identification unit, configured to directly determine that a fraudulent transaction identification result of the transaction is a high-risk fraudulent transaction if at least one of a time series correlation score corresponding to the input feature information of the transaction and a time series correlation score corresponding to the background noise information is 1; The second fraudulent transaction identification unit is used to input the timing correlation score corresponding to each transaction feature information of this transaction, the cumulative rejection rate of the customer, and the transaction frequency per unit time of the customer into a preset fraudulent transaction identification model if the timing correlation score corresponding to the input feature information of this transaction and the timing correlation score corresponding to the background noise information are both not 1, so as to obtain a fraudulent transaction identification result of this transaction.
10. A computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the computer program, the method according to any one of claims 1 to 6 is implemented.
11. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed in a computer processor, the computer program implements the method according to any one of claims 1 to 6.
Citation Information
Patent Citations
Detection method and device for fraudulent transaction
CN112967053A