A risk identification and control method and device
By updating meta-network instances and extracting instance characteristics, identifying and controlling dispersed and group risk behaviors in Internet business enterprises or platforms, the problem of difficult to effectively identify and control these risks in the prior art is solved, and the risk identification and control capabilities are improved.
Patent Information
- Application Number
- CN202111056848.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-09-09
- Publication Date
- 2025-05-27
- Estimated Expiration
- 2041-09-09
AI Technical Summary
It is difficult for the existing technology to effectively identify and control the dispersed and group risk behaviors present in Internet business enterprises or platforms, resulting in an increase in risk prevention and control challenges.
By obtaining multiple business objects and their business relationships involved in business activities, updating meta-network instances, extracting instance characteristics, and determining risk types and levels based on the characteristics to determine the control actions for business objects and business behavior.
It improves the ability to identify and control dispersed and group risk behaviors, and reduces the losses caused by these risk behaviors.
Smart Images

Figure CN113724073B_ABST
Abstract
Description
Technical Field
[0001] One or more embodiments of this specification relate to the fields of digital security and risk prevention and control, and in particular, to a risk identification and control method and device. Background Art
[0002] In recent years, the business activities of many Internet business enterprises or platforms rely on the association and interaction events between users or between users and organizations / institutions. For example, recommendations between users, payment events between users and merchants, coupon redemption events, and so on. However, while these business activities provide services to users, they also provide a breeding ground for illegal industries to obtain illegal income through non-compliant means, resulting in the impact on users' services and the decline in the stability of business platforms. Facing this problem, some enterprises and platforms have enabled technical means to identify and prevent such illegal / non-compliant activities. However, in the process of the confrontation between enterprises and illegal industries, the illegal industrial chain has also been continuously upgraded to a certain extent, and its means show a trend of developing from individual means to group means, and from aggregated explicit methods to dispersed implicit methods, which brings huge challenges to the risk prevention and control of enterprises and platforms.
[0003] Therefore, a new risk identification and control method is needed. Summary of the Invention
[0004] The embodiments in this specification aim to provide a more effective method for identifying and controlling risk factors in business activities, and solve the deficiencies in the prior art.
[0005] According to a first aspect, a risk identification and control method is provided, including:
[0006] Obtain a plurality of business objects involved in a first network activity, and the business relationships between the business objects;
[0007] Update a first meta-network instance according to the business objects and the business relationships, where the first meta-network instance is generated according to a first meta-structure template among a plurality of predetermined meta-structure templates;
[0008] Extract instance features of the first meta-network instance;
[0009] Determine the risk type of the first meta-network instance at least according to the instance features.
[0010] In one embodiment, the method further includes, before updating the first meta-network instance according to the business objects and the business relationships,
[0011] Determine a first meta-structure template from the plurality of predetermined meta-structure templates according to the first activity pattern of the first network activity, where the first meta-structure template supports a plurality of activity patterns, and the plurality of activity patterns includes the first activity pattern;
[0012] Generate a first meta-network instance according to the first meta-structure template.
[0013] In one embodiment, the method further includes,
[0014] Determine control actions for the business object and / or its business behavior according to the risk type.
[0015] In one embodiment, the network node types in the first meta-structure template include: group nodes and member nodes;
[0016] The relationships between network nodes include: one or more of group-to-member within a group, member-to-group within a group, member-to-member between groups, member-to-group between groups, and group-to-group.
[0017] In one embodiment, the instance features include the number of network nodes and the risk features of each node. The risk features include the risk labels corresponding to the individual risk types that the node has among a preset variety of individual risk types.
[0018] In one embodiment, updating the first meta-network instance includes at least one of the following:
[0019] Add nodes to the first meta-network instance according to the plurality of business objects;
[0020] Update the connection edges in the first meta-network instance according to the business relationships;
[0021] Update the risk features of the nodes in the first meta-network instance.
[0022] In one embodiment, the instance features further include risk consistency, where the risk consistency is used to indicate the proportion of nodes with a specific risk label among all nodes in the first meta-network instance.
[0023] In one embodiment, the risk consistency includes single-risk consistency and / or multi-risk consistency. The single-risk consistency is used to indicate the proportion of nodes with a single risk label among all nodes in the first meta-network instance, and the multi-risk consistency is used to indicate the proportion of nodes with a specified plurality of risk labels among all nodes in the first meta-network instance.
[0024] In one embodiment, determining the risk type of the first meta-network instance based at least on the instance features includes: determining the risk type of the first meta-network instance according to the nodes and connection edges in the first meta-network instance and the instance features.
[0025] In one embodiment, determining the risk type of the first meta-network includes:
[0026] Determining the risk type of the first meta-network instance based on a pre-trained risk detection model.
[0027] In one embodiment, determining the risk type of the first meta-network instance includes determining the probability distribution of the first meta-network instance for a preset variety of alternative risk types.
[0028] In one embodiment, the method further includes
[0029] Determining the risk level of the first meta-network instance based at least on the instance features;
[0030] Determining a control action for the business object and / or its business behavior according to the risk type and risk level of the first meta-network instance.
[0031] In one embodiment, determining the risk level of the first meta-network instance based at least on the instance features includes:
[0032] Determining the index value of a predetermined judgment index based at least on the instance features;
[0033] Determining the risk level of the first meta-network instance according to the index value.
[0034] In one embodiment, the instance features include the number of network nodes and the risk features of each node, and the risk features include the risk labels corresponding to the individual risk types that the node has among a preset variety of individual risk types;
[0035] The predetermined judgment index includes at least one of the following: network scale, risk concentration, risk consistency;
[0036] Determining the index value of the predetermined judgment index based at least on the instance features includes at least one of the following:
[0037] Determining the network scale of the first meta-network instance according to the number of network nodes;
[0038] Determining the proportion of the nodes with a specified risk label in all nodes in the first meta-network instance according to the number of network nodes and the risk features of each node, and further determining the risk concentration of the first meta-network instance;
[0039] According to the number of network nodes and the risk characteristics of each node, determine the proportion of nodes with a single risk label and / or specified multiple risk labels in all nodes in the first meta-network instance, and then determine the single-risk consistency and / or multi-risk consistency, and classify them into the risk consistency.
[0040] According to a second aspect, there is provided a risk identification and control device, the device comprising:
[0041] A service object acquisition unit, configured to acquire a plurality of service objects involved in a first network activity and the service relationships between the service objects;
[0042] A network instance update unit, configured to update a first meta-network instance according to the service objects and the service relationships, wherein the first meta-network instance is generated according to a first meta-structure template among a plurality of predetermined meta-structure templates;
[0043] A feature extraction unit, configured to extract instance features of the first meta-network instance;
[0044] A risk type determination unit, configured to determine the risk type of the first meta-network instance at least according to the instance features.
[0045] In one embodiment, the device further comprises
[0046] A template determination unit, configured to determine a first meta-structure template from the plurality of predetermined meta-structure templates according to a first activity pattern of the first network activity, the first meta-structure template supporting a plurality of activity patterns, and the plurality of activity patterns including the first activity pattern;
[0047] A network instance generation unit, configured to generate a first meta-network instance according to the first meta-structure template.
[0048] In one embodiment, the risk type determination unit is further configured to determine the risk type of the first meta-network instance according to the nodes and connection edges in the first meta-network instance and the instance features.
[0049] In one embodiment, the risk type determination unit is further configured to determine the risk type of the first meta-network instance based on a pre-trained risk detection model.
[0050] In one embodiment, the device further comprises
[0051] A risk level determination unit, configured to determine the risk level of the first meta-network instance at least according to the instance features;
[0052] The control action determination unit is configured to determine control actions for the business object and / or its business behaviors according to the risk type and risk level of the first meta-network instance.
[0053] In one embodiment, the risk level determination unit is further configured to:
[0054] Determine the index value of a predetermined judgment index based on at least the instance characteristics;
[0055] Determine the risk level of the first meta-network instance according to the index value.
[0056] In one embodiment, the instance characteristics include the number of network nodes and the risk characteristics of each node. The risk characteristics include the risk labels corresponding to the individual risk types that the node has among a preset variety of individual risk types;
[0057] The predetermined judgment index includes at least one of the following: network scale, risk concentration, risk consistency;
[0058] The determining the index value of the predetermined judgment index based on at least the instance characteristics includes at least one of the following:
[0059] Determine the network scale of the first meta-network instance according to the number of network nodes;
[0060] Determine the proportion of nodes with a specified risk label in all nodes in the first meta-network instance according to the number of network nodes and the risk characteristics of each node, and then determine the risk concentration of the first meta-network instance;
[0061] Determine the proportion of nodes with a single risk label and / or specified multiple risk labels in all nodes in the first meta-network instance according to the number of network nodes and the risk characteristics of each node, and then determine the single-risk consistency and / or multi-risk consistency, which are classified into the risk consistency.
[0062] According to a third aspect, there is provided a computer-readable storage medium, on which a computer program is stored. When the computer program is executed on a computer, the computer is made to execute the method described in the first aspect.
[0063] According to a fourth aspect, there is provided a computing device, including a memory and a processor. An executable code is stored in the memory. When the processor executes the executable code, the method described in the first aspect is implemented.
[0064] By using one or more of the methods, apparatuses, computing devices, and storage media in the above aspects, the ability to identify dispersed and group risk behaviors existing in business activities can be effectively improved, as well as the ability to control such risk behaviors, and the losses caused by such risk behaviors can be reduced. BRIEF DESCRIPTION OF THE DRAWINGS
[0065] To more clearly illustrate the technical solutions of the embodiments of the present invention, the accompanying drawings required for the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0066] Figure 1 Schematic diagram showing the principle of a risk identification and control method according to an embodiment of this specification;
[0067] Figure 2 Flowchart showing a risk identification and control method according to an embodiment of this specification;
[0068] Figure 3 Schematic diagram showing the network structure corresponding to the first template according to an embodiment of this specification;
[0069] Figure 4 Schematic diagram showing the network structures corresponding to the second and third templates according to an embodiment of this specification;
[0070] Figure 5 Structure diagram showing a risk identification and control apparatus according to an embodiment of this specification. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0071] The solutions provided in this specification will be described below in conjunction with the accompanying drawings.
[0072] In recent years, many Internet enterprises or platforms have invested marketing funds to carry out various platform marketing activities aimed at, for example, expanding the user base and promoting user activity. While these activities have promoted business development, they have also provided a natural breeding ground for illegal industries to carry out illegal activities. At the same time, in the process of the confrontation between enterprises and illegal industries, the illegal industrial chain has also been upgraded. Its activity mode has developed from participating in an individual mode to participating in a group mode, its illegal means have developed from amateur means to professional means with clear division of labor and each performing its own duties, and from concentrated and obvious means to dispersed and hidden means. This has brought huge challenges to the risk prevention and control of enterprises / platforms, resulting in the marketing funds of enterprises flowing into the hands of illegal industries and being unable to fully play their roles. It may also lead to enterprises being forced to launch more marketing activities passively, or lowering the user access threshold, but this has provided more room for illegal activities.
[0073] To address this issue, some enterprises have made more innovations in the operation methods of marketing activities and continuously launched a large number of marketing activities with different operation methods. To monitor these marketing activities and identify the risks of illegal behaviors that may occur, some existing technical solutions mainly generate relationship networks based on general relationships between business objects such as financial relationships and media relationships, and identify possible groups of illegal objects from them. Since general relationships such as financial relationships and media relationships relied on by such solutions generally exist widely in all business activities, these solutions have strong generality, and their corresponding identification systems have the advantage of being able to be constructed once and used multiple times and in multiple places. However, such solutions also have the following problems. In addition to their generally high construction costs (such as storage costs and computing costs) and long construction cycles, more importantly, the types of general relationships relied on by general solutions are few and lack flexibility, making it difficult to meet the diverse needs of different businesses. Or rather, general solutions lack business pertinence. Their identification effects that are divorced from business rules and solely rely on general relationship data are poor, and the interpretability of their identification results is usually also relatively poor.
[0074] Another type of technical solution mainly generates relationship networks based on the business relationships and data of different specific business activities, and identifies possible groups of illegal objects from them. Compared with the previous type of technical solution, since this type of solution constructs relationship networks according to the specific business activity rules of different activities, it has good matching with the corresponding business activities and is convenient for identifying illegal groups from the relationship networks of specific business activities. However, the relationship networks in this type of solution are customized according to specific business activities, so their generality is very poor and they have no adaptability to other business activities. As a result, the identification network for a certain business activity becomes worthless after the business activity ends, thus causing a waste of construction costs. Moreover, the cumulative time and labor costs for targeted construction of each business activity are also increasing continuously. More importantly, since business activities usually have strong timeliness, the urgency of targeted construction for each business activity is often relatively high, putting relatively great pressure on the construction personnel. During the limited online period of business activities, the window period caused by the time necessarily consumed by targeted construction may affect the timely monitoring of business activities.
[0075] The embodiments of this specification provide a risk identification and control method. Through the research on the implementation methods of various business activities, the inventors believe that although the specific implementation methods of various business activities vary widely, some common operation ideas can still be abstracted from them, such as team formation mode, person-to-person transmission mode, etc. For these abstract modes, different meta-network structure templates can be defined respectively, and the network structure characteristics of an abstract network mode are defined correspondingly in each meta-network structure template. Thus, each meta-network structure template can be used to identify the risks of multiple different business promotion activities, as long as the network formed by the business objects and relationships in these business promotion activities can match the characteristic definition of the meta-network structure template.
[0076] The meta-network structure template is also called a semi-structured network template in this specification. This template is not defined completely for the business objects and their relationships of each specific business promotion activity as in the above second type of solution. Instead, a more generalized network structure is abstracted and defined based on multiple business activities, and then the risks of multiple business activities are identified according to this network structure. Therefore, compared with the above second type of solution, this solution can handle multiple business activities, and its generality and processing timeliness are better; moreover, this meta-network structure template can be used multiple times, reducing the construction cost of the risk identification system. Compared with the above first type of solution, since this network meta-structure template comes from the abstraction of the commonalities of the business objects and their relationships of multiple business activities, it can not only adapt to multiple business activities, but also includes network features related to the real business activity rules, rather than completely ignoring the rule factors of specific business activities as in the above first type of solution. Therefore, the risk identification based on this meta-network structure template has a better identification effect for the business activities it adapts to than the above first type of solution.
[0077] Figure 1 Show a schematic diagram of the principle of a risk identification and control method according to an embodiment of this specification. As Figure 1 shown, first, for example, M meta-network structure templates can be abstracted and defined in advance according to a large number of business activities, which are the first to the Mth templates respectively. When various business activities need to be processed, for a specific business activity, a meta-network structure template can be matched for it according to its specific activity rules or activity patterns. For example, the first template is included in the M meta-network structure templates, which is also called the battle team template in this specification. This template can be used to construct a business network for business activities whose business rules have the following properties, that is, there are one or more types of group participants in these business activities, and member participants associated with these group participants, and different specific relationships can exist between these groups and members, groups and groups, and members and members. Figure 3 Show a schematic diagram of the network structure corresponding to the first template according to an embodiment of this specification. InFigure 3 As shown, in the first template, different types of group nodes such as type A and type B groups are defined, as well as member nodes such as type C, and two types of node relationships, namely intra-group relationships and inter-group relationships. The intra-group relationship specifically includes the relationship of group node → member node as shown by edge ① (in different embodiments, it can correspond to different business relationships in different business activities. For example, in a family interaction activity, the relationship between a family node and family members, or in different activities, the relationship between a merchant node and a customer node, etc.). The relationship of member node → group node as shown by edge ② (for example, corresponding to the relationship where a customer uses a consumption voucher of a specific merchant). The inter-group relationship specifically includes the relationship of inter-group member node → member node as shown by edge ③ (for example, corresponding to the relationship where members of different families visit each other and give red envelopes). The relationship of member node → multiple group nodes as shown by edge ④ (for example, corresponding to the relationship where in a government consumption voucher activity, a user redeems consumption vouchers at multiple merchants). The relationship of group node → group node as shown by edge ⑤ (for example, corresponding to the relationship where multiple participating merchants transfer funds to each other in a government consumption voucher activity).
[0078] From the above description, it can be known that the definition of nodes and their relationships in the first template is generalizable, and the first template can be used to construct business networks for different business activities. For example, in one embodiment, the activity mode of a business activity (Activity 1) is specifically a family interaction activity, and the rule of this activity is that family members of multiple families can interact, such as visiting each other and giving red envelopes. Therefore, the business relationship network corresponding to this business activity can be considered to have the following characteristics: it has group nodes (families), member nodes (family members), there is an association relationship between group nodes and member nodes (the act of forming a family), and there can be an association relationship between member nodes of different group nodes (for example, the act of visiting each other and giving red envelopes). Therefore, the first template can be used to establish a business relationship network that matches the rules of Activity 1. Also, for example, in another embodiment, the activity mode of a business activity (Activity 2) is specifically a government consumption voucher activity. In this activity, customers can receive consumption vouchers issued by the government and consume at multiple merchants, and the transfer of funds between participating merchants is highly sensitive. According to the same reasoning logic as in the previous embodiment, the first template can also be used to establish a business relationship network that matches the rules of Activity 2. Therefore, the same template can support multiple activity modes with common characteristics, and specific business activities can be carried out under each activity mode.
[0079] However, the adaptation ability of the first template has limitations and cannot match all types of business activities. For example, in one embodiment, a business activity is a QR code forwarding activity (Activity 3), and its activity pattern is that a small number of forwarders forward the QR code to more forwarders, gradually spreading the QR code to more people through forwarding. Therefore, its business network presents a tree-like divergent pattern composed of multiple levels of participants and their forwarding relationships. For this structural characteristic of the business network, there is no suitable corresponding definition in the first model. Therefore, in one embodiment, another meta-network structure template, such as the second template, can be matched for Activity 3, which is also referred to as the person-to-person template in this specification. Figure 4 FIG. shows a schematic diagram of the network structure corresponding to the second and third templates according to an embodiment of the present specification. As Figure 4 (a) shows, the network structure defined by the second template has the characteristic that its member nodes form a tree-like structure. In a specific embodiment, in the second template, for example, the definition of the network structure can be achieved by classifying the nodes into types such as root nodes, intermediate nodes, and leaf nodes, and defining the parent node attributes of the intermediate nodes and leaf nodes. Figure 4 (b) also shows the third template, which is also referred to as the service provider commission-back template in this specification. Its network structure characteristic is that the service provider node as the root node, the merchant node as the intermediate node, and the user node as the leaf node form a tree-like structure, where the service provider node and the merchant node can be group nodes. In different embodiments, the meta-network structure template can also have other specific types and corresponding network structures, and this specification does not limit this. In different embodiments, there can also be different specific definition methods for the network structure, and this specification does not limit this either.
[0080] Next, after determining the meta-network structure template matched by the network activity according to the business rules of the network activity, a corresponding meta-network instance can be generated according to the matched template. In one embodiment, in the first meta-network embodiment generated according to the first template, the types of its various nodes and relationships can be various node types and relationship types defined in the first model.
[0081] Then, the first meta-network instance can be updated according to, for example, the associated data of the first network activity collected in real time. The associated data of the first network activity can be, in different embodiments, each account participating in the activity, the activity groups established among these accounts, and the business behaviors related to the first network activity among these accounts and groups. Specifically, in one example, network nodes corresponding to the accounts and groups can be generated according to the continuously participating accounts and the established groups. According to the business behaviors among the accounts and groups, the relationships between the nodes (also referred to as the edges between the nodes) can be generated. The corresponding attributes of the corresponding nodes can also be filled according to the specific information of the accounts. For example, according to the ID, age, and name information of the accounts, they can be filled into the values of the corresponding ID, age, and name attributes of the nodes. In one example, the ID, age, and name attributes of the nodes can be defined as node attributes in the meta-structure template.
[0082] After filling the first meta-network instance based on the actual activity data of the first network activity, the instance features of the meta-network instance can be extracted. Then, for example, the instance features can be saved into the first meta-network instance, and then the current copy of the first meta-network instance can be sent to a pre-trained risk type recognition model to obtain the risk type of the first meta-network instance. In different embodiments, the instance features can include predetermined statistical features for the meta-network instance, and the predetermined statistical features can be generated according to the nodes, relationships, and their attributes in the first meta-network instance. The instance features can also include node-level risk features for the meta-network instance, that is, the risk features of its respective nodes. Specifically, the risk feature of a node refers to, in this specification, the risk label corresponding to the individual risk type that the node has among a preset variety of individual risk types. Since the meta-network structure template in the embodiments of this specification has generalization, it can be adapted to different business activities, such as different business activities occurring at different times. Therefore, its risk type recognition model can also be trained using sample data obtained from other business activities, which not only makes the risk type recognition model universal but also improves the response speed of risk recognition processing.
[0083] After obtaining the risk type of the first meta-network instance, the risk level of the first meta-network instance can also be determined according to the features of the first meta-network instance based on a predetermined discrimination index. In one embodiment, the discrimination index can include, for example, network scale, network risk concentration, and network risk consistency. Among them, the network scale can be determined according to the number of nodes, the network risk concentration can be determined according to the proportion of risk nodes among all nodes, and the network risk consistency can be determined according to the proportion of nodes with different risk features among all nodes. In one embodiment, the risk level of the first meta-network instance can be determined to be one of high, medium, and low by combining the above indexes.
[0084] After obtaining the risk type and risk level of the first meta-network instance, the corresponding risk control method can be determined based on the risk type and risk level. In different embodiments, for example, the specific corresponding risk control means can be determined according to different combination methods of the risk type and risk level.
[0085] The risk identification and risk control method has the following advantages: By constructing a semi-structured meta-network, the activity rules are naturally integrated with the fund relationship, medium relationship, etc. as the basis for risk identification, thereby improving the risk identification ability for low-concentration batch non-compliance behaviors under complex network conditions, and the interpretability of the identification results is strong. By constructing a semi-structured meta-network, the identification system based on this network achieves a good balance in terms of construction cycle, adaptability, and effectiveness. By combining the risk approach (type) and risk level to determine the control means, a multi-dimensional hierarchical control scheme is provided, improving the control accuracy.
[0086] The detailed process of this method is further elaborated below. Figure 2 The flowchart showing a risk identification and control method according to an embodiment of the present specification is as follows Figure 2 As described above, the method at least includes the following steps:
[0087] Step 21, obtaining a plurality of business objects involved in the first network activity and the business relationships between the business objects;
[0088] Step 22, updating the first meta-network instance according to the business objects and business relationships, where the first meta-network instance is generated according to the first meta-structure template among a plurality of predetermined meta-structure templates;
[0089] Step 23, extracting the instance features of the first meta-network instance;
[0090] Step 24, determining the risk type of the first meta-network instance at least according to the instance features.
[0091] First, in step 11, obtain multiple business objects involved in the first network activity and the business relationships between the business objects. In different embodiments, the first network activity can be various types of network activities initiated by an enterprise, a merchant, or a platform and involving multiple participating objects (business objects). For example, in one embodiment, the first network activity can be a marketing activity initiated by an enterprise or a merchant. In another embodiment, the first network activity can be a promotion activity or a customer activity improvement activity for a certain business initiated by a business platform, etc. In different embodiments, the business objects can be accounts, customers, participating users involved in the first network activity, or other identifiers corresponding to the activity participants. The business relationship can be a relationship generated by any behavior related to the first network activity between the business objects. For example, in a red envelope activity, the business relationship constituted by the red envelope sending behavior between different accounts and users, and in a team-based group buying activity, the business relationship constituted by the team formation behavior and the order placement behavior between different accounts and users. In some embodiments, the business relationship can also be the default relationship between the business objects in the first network activity.
[0092] Then, in step 12, update the first meta-network instance according to the business objects and the business relationships.
[0093] In this step, the first meta-network instance is generated according to the first meta-structure template among a plurality of predetermined meta-structure templates. Therefore, in one embodiment, before updating the first meta-network instance, according to the first activity pattern of the first network activity, determine the first meta-structure template from the plurality of predetermined meta-structure templates. The first meta-structure template supports a plurality of activity patterns, and the plurality of activity patterns includes the first activity pattern; generate the first meta-network instance according to the first meta-structure template.
[0094] The activity pattern of the first network activity, that is, the first activity pattern, can be different in different embodiments. For example, it can be a family interaction activity, a government consumption voucher activity, etc. Furthermore, in different embodiments, the first meta-structure template determined according to its specific activity model can also be different. In one embodiment, the definition of the network structure by the first meta-structure template can be shown as follows: the network node types in the first structure template can include: group nodes and member nodes, and the relationships between the network nodes in the first structure template can include: group-to-member within a group, member-to-group within a group, member-to-member between groups, member-to-group between groups, group-to-group. In one embodiment, the network node types can be further subdivided. For example, the group nodes can be further subdivided into type A group nodes and type B group nodes.
[0095] In one embodiment, the first meta-network instance can be updated according to the collected business objects and their business relationships. Specifically, in different embodiments, for example, one or more of the following operations can be performed: nodes can be added to the first meta-network instance according to multiple business objects; the connection edges in the first meta-network instance can be updated according to the business relationships; and the risk characteristics of the nodes in the first meta-network instance can be updated.
[0096] Next, in step 13, the instance characteristics of the first meta-network instance are extracted.
[0097] In this step, the instance characteristics of the first meta-network instance are extracted. In different embodiments, the specifically extracted instance characteristics can be different. In one embodiment, the instance characteristics may include the number of network nodes and the risk characteristics of each node. In a specific embodiment, the number of network nodes can be, for example, the total number of all types of nodes in the network. As described above, the risk characteristic of a certain node refers to the risk label corresponding to the individual risk type that the node has among the preset multiple individual risk types. For example, in some network activities of embodiments, the age of the participant is risk-sensitive. Among the preset multiple individual risk types, for example, there may be an 'elderly risk type'. For example, when the age of the participant is greater than a certain predetermined value (for example, greater than 65 years old), the node generated according to this participant can have an 'elderly risk label'. Another example is that in some other network activities of embodiments, the abnormal refund of the participant is risk-sensitive. Among the preset multiple individual risk types, for example, there may be an abnormal refund risk type. When the participant has an abnormal refund action, the node generated according to this participant can have an 'abnormal refund risk label'. In different embodiments, different individual risk types can be preset, and this specification does not limit this.
[0098] In one embodiment, the implementation feature may further include risk consistency, where the risk consistency is used to indicate the proportion of nodes with specific risk labels among all nodes in the first meta-network instance. In a specific embodiment, the risk consistency may further include single-risk consistency and / or multi-risk consistency. The multi-risk consistency is used to indicate the proportion of nodes with a single risk label among all nodes, and the multi-risk consistency is used to indicate the proportion of nodes with a specified multiple risk labels among all nodes in the first meta-network instance. In an example, for all nodes (c1, c2,..., cm) in the network and all preset risk labels (f1, f2,..., fn), where m is the number of nodes and n is the number of label types. The proportion of nodes with each risk label among all nodes (a total of n) is determined in sequence, and then n single-risk consistency values for each type of risk label are obtained. In another example, for all nodes (c1, c2,..., cm) in the network and a target label set, the proportion of members with at least x of the labels among all members is determined, so as to obtain the multi-risk consistency of the entire network. In a specific example, the target label set may be all preset risk labels (f1, f2,..., fn) or a predetermined part of the all risk labels.
[0099] Thereafter, in step 14, determine the risk type of the first meta-network instance based at least on the instance feature.
[0100] In this step, the risk type of the first meta-network instance may be determined according to the instance feature of the first meta-network instance. Determining the risk type may be based on a pre-trained neural network model. In one embodiment, the risk type of the first meta-network instance may also be determined according to the nodes and connection edges in the first meta-network instance and the instance feature. Specifically, in one embodiment, the nodes, connection edges, and instance feature may be input into a pre-trained risk detection model to obtain the risk type of the first meta-network instance. In different embodiments, the samples used to pre-train the neural network model may be obtained based on the first meta-network instance or based on the accumulated data of other meta-network instances, and the other network instances are generated according to the first meta-structure template.
[0101] The risk types output by the risk detection model can be in continuous or discrete forms. For example, they can be manifested as specific risk types or probability distributions of multiple alternative risk types. Therefore, in one embodiment, the probability distributions of the first meta-network instance for a preset variety of alternative risk types can be determined. In one embodiment, the alternative risk types can have further sub-types, and the probability distributions of the alternative risk types and their sub-types can be determined respectively. In one example, in the risk type of 'impersonation risk', for example, it can include two sub-types: 'elderly-impersonation' and 'non-elderly-impersonation'. In a specific example, the determined probability distributions of multiple alternative risk types can be, for example, the probability of 'device risk' is 0.11, the probability of 'impersonation risk' is 0.72, the probability of 'false transaction risk' is 0.16, and the probability of 'brush order risk' is 0.01. And under the 'impersonation risk', the probability of 'elderly-impersonation' is 0.98, and the probability of 'non-elderly-impersonation' is 0.02.
[0102] After obtaining the risk types, according to one implementation manner, control actions for the business object and / or business behavior can be determined based on the risk types. According to another implementation manner, the risk level of the first meta-network instance can also be determined according to the instance characteristics; according to the risk type and risk level of the first meta-network instance, control actions for the business object and / or its business behavior can be determined.
[0103] Specifically, a predetermined judgment index can be used to determine the risk level. Therefore, in one embodiment, the index value of the predetermined judgment index can be determined at least according to the instance characteristics; according to the index value, the risk level of the first meta-network instance can be determined.
[0104] In a specific embodiment, the instance characteristics specifically include, for example, the number of network nodes and the risk characteristics of each node. The predetermined judgment index includes, for example, one or more of network scale, risk concentration, and risk consistency. In this embodiment, for example, the index values of each predetermined judgment index can be determined through the following steps:
[0105] According to the number of network nodes, determine the network scale of the first meta-network instance; according to the number of network nodes and the risk characteristics of each node, determine the proportion of nodes with a specified risk label in all nodes in the first meta-network instance, and further determine the risk concentration of the first meta-network instance;
[0106] According to the number of network nodes and the risk characteristics of each node, determine the proportion of nodes with a single risk label and / or specified multiple risk labels in all nodes in the first meta-network instance, and further determine single-risk consistency and / or multi-risk consistency, which are classified into the risk consistency.
[0107] In this embodiment, after obtaining each index value, for example, the risk level of the first meta-network instance can also be determined by combining the index values of network scale, risk concentration, and risk consistency.
[0108] In a specific embodiment, the determined index value of the network scale can be, for example, any one of large, medium, or small network scale; the index value of the risk concentration can be, for example, any one of high, medium, or low risk concentration; and the index value of the risk consistency can be, for example, high, medium, or low single / multiple feature consistency. In different examples, the index value of the risk consistency can be determined based on different single / multiple risk labels among all risk labels. This specification does not limit this.
[0109] In one example, the risk level of the first meta-network instance can be determined, for example, in the following specific manner: when it is determined that the network scale is small, the risk concentration is low, and the multi-feature consistency is high, the risk level of the first meta-network instance is a high risk; when it is determined that the network scale is medium, the risk concentration is medium, and the single-feature consistency is medium, then the risk level of the first meta-network instance is a medium risk; when the network scale is low, the risk concentration is low, and the single-feature consistency is low, then the risk level is a low risk.
[0110] In other embodiments, there can be other specific ways to determine the risk level of the first meta-network instance, and this specification does not limit this.
[0111] As described above, in one embodiment, the control actions for the business object or business relationship can be determined by combining the risk type and the risk level. Table 1 shows the control actions determined according to the risk type and the risk level in one embodiment.
[0112] Equipment Risk Impersonation - Elderly Impersonation - Non - Elderly Offline Risk High Risk No Prize Return Face + Card Binding Outbound Interactive Q&A High - Risk Q&A Medium Risk No Prize Return Face Outbound Risk Warning Confirmation Medium - Risk Q&A Low Risk Reduced Prize Return Card Binding Delayed Face Verification Low - Risk Module
[0113] Table 1 Correspondence Table of Risk Level, Risk Type, and Control Actions
[0114] As described in Table 1, the leftmost column represents the risk level, and the top row represents the risk type. Based on the risk level and risk type, the corresponding control actions can be determined. For example, when it is determined that the risk type of the current active network is 'equipment risk', if the risk level of the current active network is 'high risk' or'medium risk', the corresponding control action is not to return the bonus or prize. If the risk level of the current active network is 'low risk', the corresponding control action is also not to return the bonus or prize. In different embodiments, since even in a high-risk active network, not all nodes / relationships necessarily need to be the objects of control implementation. Therefore, in a specific example, the specific objects to which the control action is to be implemented can also be determined first. For example, certain business objects or business relationships targeted by the control action can be determined, and then the control action can be implemented on them. For example, in one example, for high-risk - equipment risk, the specific risk equipment can be determined first, and then the current prize return can be intercepted. In one example, for medium-risk - identity theft risk, the specific risk account can be determined first, and verification can be performed through face verification. If the verification passes, the prize will be returned normally; otherwise, no prize will be returned. In yet another example, for high identity theft - elderly risk, questions such as whether the elderly person understands the participated activity and what the scene was like at that time can also be asked through an interactive robot question-and-answer method to determine whether there are non-compliant behaviors. In yet another example, for the risk of merchants soliciting users offline for non-compliant behaviors, through a crowdsourcing interactive questionnaire method, such as asking users whether they are visiting the store for the first time, the types of goods purchased, etc., to comprehensively determine whether the merchant has non-compliant behaviors, and further control actions can also be determined based on the judgment result. The specific method for determining the implementation objects of control is not limited in this specification.
[0115] According to an embodiment of another aspect, a risk identification and control method and apparatus are also provided. Figure 5 The structural diagram of a risk identification and control apparatus according to an embodiment of this specification is shown. As Figure 5 shown, the apparatus 500 includes:
[0116] A business object acquisition unit 51, configured to acquire a plurality of business objects involved in a first network activity and the business relationships between the business objects;
[0117] A network instance update unit 52, configured to update a first meta-network instance according to the business objects and the business relationships, where the first meta-network instance is generated according to a first meta-structure template among a plurality of predetermined meta-structure templates;
[0118] A feature extraction unit 53, configured to extract the instance features of the first meta-network instance;
[0119] A risk type determination unit 54, configured to determine the risk type of the first meta-network instance based at least on the instance features.
[0120] In one embodiment, the apparatus may further include
[0121] A template determination unit, configured to determine a first meta-structure template from a plurality of predetermined meta-structure templates according to the first activity pattern of the first network activity, where the first meta-structure template supports a plurality of activity patterns, and the plurality of activity patterns includes the first activity pattern;
[0122] A network instance generation unit, configured to generate a first meta-network instance according to the first meta-structure template.
[0123] In one embodiment, the risk type determination unit may be further configured to determine the risk type of the first meta-network instance according to the nodes and connection edges in the first meta-network instance and the instance features.
[0124] In one embodiment, the risk type determination unit may be further configured to determine the risk type of the first meta-network instance based on a pre-trained risk detection model.
[0125] In one embodiment, the apparatus may further include
[0126] A risk level determination unit, configured to determine the risk level of the first meta-network instance based at least on the instance features;
[0127] A control action determination unit, configured to determine a control action for the business object and / or its business behavior according to the risk type and risk level of the first meta-network instance.
[0128] In one embodiment, the risk level determination unit may be further configured to:
[0129] Determine the index value of a predetermined judgment index based at least on the instance features;
[0130] Determine the risk level of the first meta-network instance according to the index value.
[0131] In one embodiment, the instance features may include the number of network nodes and the risk features of each node. The risk features may include, among a plurality of preset individual risk types, the risk labels corresponding to the individual risk types possessed by the node;
[0132] The predetermined judgment index may include at least one of the following: network scale, risk concentration, risk consistency;
[0133] Determining the value of a predetermined judgment metric based on at least the instance features may include at least one of the following:
[0134] Determining the network scale of the first meta-network instance according to the number of network nodes;
[0135] Determining the proportion of nodes with a specified risk label in all nodes in the first meta-network instance according to the number of network nodes and the risk features of each node, and further determining the risk concentration of the first meta-network instance;
[0136] Determining the proportion of nodes with a single risk label and / or specified multiple risk labels in all nodes in the first meta-network instance according to the number of network nodes and the risk features of each node, and further determining the single-risk consistency and / or multi-risk consistency, which are classified into the risk consistency.
[0137] Another aspect of this specification provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed on a computer, the computer is made to execute any one of the above methods.
[0138] Another aspect of this specification provides a computing device, including a memory and a processor. An executable code is stored in the memory. When the processor executes the executable code, any one of the above methods is implemented.
[0139] It should be understood that the descriptions such as "first" and "second" in this article are only used to distinguish similar concepts for the sake of simple description and do not have other limiting effects.
[0140] Those skilled in the art should be able to realize that in one or more of the above examples, the functions described in the present invention can be implemented by hardware, software, firmware, or any combination thereof. When implemented using software, these functions can be stored in a computer-readable medium or transmitted as one or more instructions or codes on a computer-readable medium.
[0141] The above specific implementation manners further elaborate on the purpose, technical solution, and beneficial effects of the present invention. It should be understood that the above is only the specific implementation manners of the present invention and is not used to limit the protection scope of the present invention. Any modifications, equivalent replacements, improvements, etc. made on the basis of the technical solution of the present invention shall be included in the protection scope of the present invention.
Claims
1. A risk identification and control method, comprising: Obtaining a plurality of business objects involved in a first network activity, and business relationships between the business objects ; Determining a first meta-structure template from a plurality of predetermined meta-structure templates according to a first activity pattern of the first network activity, the first meta-structure template supporting the first activity pattern; Generating a first meta-network instance according to the first meta-structure template; Updating the first meta-network instance according to the business objects and the business relationships, wherein the first meta-network instance is generated according to the first meta-structure template among a plurality of predetermined meta-structure templates; the types of network nodes in the first meta-structure template include: group nodes and member nodes; the relationships between network nodes include: one or more of group-to-member within a group, member-to-group within a group, member-to-member between groups, member-to-group between groups, and group-to-group; Extracting instance features of the first meta-network instance, the instance features including the number of network nodes and the risk features of each node; determining the risk type of the first meta-network instance at least according to the instance features.
2. The method according to claim 1, wherein, The first meta-structure template supports a plurality of activity patterns, and the plurality of activity patterns include the first activity pattern.
3. The method according to claim 1, further comprising, Determining control actions for the business objects and / or their business behaviors according to the risk type.
4. The method according to claim 1, wherein, The risk features include, Risk labels corresponding to the individual risk types of the nodes among a plurality of preset individual risk types.
5. The method according to claim 4, wherein, Updating the first meta-network instance includes at least one of the following: Adding nodes to the first meta-network instance according to the plurality of business objects; Updating the connection edges in the first meta-network instance according to the business relationships; Updating the risk features of the nodes in the first meta-network instance.
6. The method according to claim 4, wherein, The instance features further include risk consistency, and the risk consistency is used to indicate the proportion of nodes with a specific risk label among all nodes in the first meta-network instance.
7. The method according to claim 6, wherein, The risk consistency includes single-risk consistency and / or multi-risk consistency, wherein the single-risk consistency is used to indicate the proportion of nodes with a single risk label among all nodes in the first meta-network instance, and the multi-risk consistency is used to indicate the proportion of nodes with a specified plurality of risk labels among all nodes in the first meta-network instance.
8. The method according to claim 1, wherein, Determining the risk type of the first meta-network instance at least according to the instance features includes: determining the risk type of the first meta-network instance according to the nodes and connection edges in the first meta-network instance and the instance features.
9. The method according to claim 1, wherein, Determining the risk type of the first meta-network includes: Determining the risk type of the first meta-network instance based on a pre-trained risk detection model.
10. The method according to claim 9, wherein, determining the risk type of the first meta-network instance includes determining the probability distribution of the first meta-network instance for a plurality of preset alternative risk types.
11. The method according to claim 1, further comprising, determining the risk level of the first meta-network instance at least according to the instance features; determining control actions for the business object and / or its business behavior according to the risk type and risk level of the first meta-network instance.
12. The method according to claim 11, wherein, determining the risk level of the first meta-network instance at least according to the instance features includes: determining the index value of a predetermined judgment index at least according to the instance features; determining the risk level of the first meta-network instance according to the index value.
13. The method according to claim 12, wherein, the instance features include the number of network nodes and the risk features of each node, and the risk features include risk labels corresponding to the individual risk types that the node has among a plurality of preset individual risk types; the predetermined judgment index includes at least one of the following: network scale, risk concentration, risk consistency; determining the index value of the predetermined judgment index at least according to the instance features includes at least one of the following: determining the network scale of the first meta-network instance according to the number of network nodes; determining the proportion of nodes with a specified risk label in all nodes of the first meta-network instance according to the number of network nodes and the risk features of each node, and further determining the risk concentration of the first meta-network instance; determining the proportion of nodes with a single risk label and / or a specified plurality of risk labels in all nodes of the first meta-network instance according to the number of network nodes and the risk features of each node, and further determining single-risk consistency and / or multi-risk consistency, and classifying them into the risk consistency.
14. A risk identification and control device, the device includes: a business object acquisition unit configured to acquire a plurality of business objects involved in a first network activity and the business relationships between the business objects ; determining a first meta-structure template from a plurality of predetermined meta-structure templates according to the first activity mode of the first network activity, the first meta-structure template supporting the first activity mode; generating a first meta-network instance according to the first meta-structure template; a network instance update unit configured to update the first meta-network instance according to the business object and the business relationship, wherein the first meta-network instance is generated according to the first meta-structure template among a plurality of predetermined meta-structure templates; the types of network nodes in the first meta-structure template include: group nodes and member nodes; the relationships between network nodes include: one or more of group-to-member within a group, member-to-group within a group, member-to-member between groups, member-to-group between groups, group-to-group; a feature extraction unit configured to extract instance features of the first meta-network instance, the instance features including the number of network nodes and the risk features of each node; A risk type determination unit, configured to determine the risk type of the first meta-network instance based on at least the instance features.
15. The apparatus according to claim 14, wherein, the first meta-structure template supports a plurality of activity modes, and the plurality of activity modes include the first activity mode.
16. The apparatus according to claim 14, wherein, the risk type determination unit is further configured to determine the risk type of the first meta-network instance according to the nodes and connection edges in the first meta-network instance and the instance features.
17. The apparatus according to claim 14, wherein, the risk type determination unit is further configured to determine the risk type of the first meta-network instance based on a pre-trained risk detection model.
18. The apparatus according to claim 14, further comprising, a risk level determination unit, configured to determine the risk level of the first meta-network instance based on at least the instance features; a control action determination unit, configured to determine a control action for the service object and / or its service behavior according to the risk type and risk level of the first meta-network instance.
19. The apparatus according to claim 18, wherein, the risk level determination unit is further configured to: determine at least the index value of a predetermined judgment index based on the instance features; determine the risk level of the first meta-network instance according to the index value.
20. The apparatus according to claim 19, wherein, the instance features include the number of network nodes and the risk features of each node, and the risk features include risk labels corresponding to the individual risk types that the node has among a plurality of preset individual risk types; the predetermined judgment index includes at least one of the following: network scale, risk concentration, risk consistency; the determining at least the index value of a predetermined judgment index based on the instance features includes at least one of the following: determine the network scale of the first meta-network instance according to the number of network nodes; determine the proportion of nodes with a specified risk label in all nodes in the first meta-network instance according to the number of network nodes and the risk features of each node, and then determine the risk concentration of the first meta-network instance; determine the proportion of nodes with a single risk label and / or specified multiple risk labels in all nodes in the first meta-network instance according to the number of network nodes and the risk features of each node, and then determine single-risk consistency and / or multi-risk consistency, and classify them into the risk consistency.
21. A computer-readable storage medium, on which a computer program is stored, and when the computer program is executed in a computer, the computer is made to execute the method according to any one of claims 1-13.
22. A computing device, including a memory and a processor, where an executable code is stored in the memory, and when the processor executes the executable code, the method according to any one of claims 1-13 is implemented.
Citation Information
Patent Citations
Fraud identification method and device, electronic equipment and computer readable storage medium
CN110765117A