A platform new device screening method, device, medium and computer equipment

By acquiring and analyzing the characteristic information of newly added devices, and using historical data prediction and outlier analysis, the problem of low accuracy in screening fake devices on live streaming platforms has been solved, achieving efficient screening and accurate identification of newly added devices.

CN114169388BActive Publication Date: 2025-12-16WUHAN DOUYU NETWORK TECHNOLOGY CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202111222530.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-10-20
Publication Date
2025-12-16
Estimated Expiration
2041-10-20

AI Technical Summary

Technical Problem

Existing technology cannot accurately screen out fake devices among the newly added devices on live streaming platforms, resulting in low screening accuracy. Furthermore, the cost of identification is high when black market operators use real, inexpensive devices.

Method used

By acquiring the characteristic information of newly added devices, including attribute information, tracking point information and IP address information, and by using feature value aggregation and data prediction within historical time periods, the proportion of outliers and differences in distribution is determined, and new devices are screened based on suspicious values.

Benefits of technology

This improved the accuracy of screening newly added devices on the platform, accurately identified abnormal devices, ensured the data matched the actual situation, and reduced the impact of black market devices.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114169388B_ABST
    Figure CN114169388B_ABST
Patent Text Reader

Abstract

The application provides a platform new device screening method and device, medium and computer equipment, comprising: obtaining the characteristic information of the new device, determining the actual number of new devices corresponding to the characteristic information in the historical time period, and predicting the predicted number of new devices in the current collection period according to the actual number of new devices in the historical time period, for each characteristic value of each characteristic dimension, and then comparing the difference between the actual number of new devices in the current collection period and the predicted number of new devices, if the difference is large, the new device corresponding to the characteristic value has a very large suspicion value; and considering that if the new device is a black production device, it will have certain characteristics, such as the aggregation of certain characteristic information, the similarity of dot point information, and the concentration of IP address, so the above characteristic information is obtained to ensure the fit of the data with the actual situation and the screening accuracy of the platform new device.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the live broadcast platform risk control technical field, and particularly relates to a platform new device screening method and device, medium and computer equipment. BACKGROUND

[0002] In the live broadcast platform, some new devices are generated through various new user pulling every day. At present, the daily new device is mainly counted by behavior dotting basic data, so as to determine the conversion rate, activation rate and other operation decision indexes of the platform, so as to provide data support for the operation decision of the live broadcast platform.

[0003] However, the behavior dotting data is easily affected by black production (black industry chain), resulting in distorted new device data, and thus the determined operation decision index is largely deviated from the actual situation, so it is necessary to screen the new device.

[0004] In the related art, there is another way to start from the hardware device itself to dig the traces of device forgery and information tampering. However, although this way can effectively identify some false devices, the recognition cost is very high, and more and more black production adopts real cheap devices, resulting in very low efficiency of the above-mentioned way, thereby reducing the screening accuracy of the platform new device. SUMMARY

[0005] In view of the problems in the prior art, the embodiments of the present application provide a platform new device screening method, device, medium and computer equipment, which are used to solve the technical problem that the false devices in the platform new device cannot be accurately screened in the prior art, resulting in that the screening accuracy of the platform new device cannot be ensured.

[0006] The present application provides a platform new device screening method, which comprises:

[0007] Obtaining characteristic information of the new device; the characteristic information comprises attribute information, dotting point information and IP address information of the new device; each characteristic information comprises at least one characteristic dimension;

[0008] Aggregating at least one characteristic value of the characteristic dimension in a historical time period to obtain a historical actual new device quantity sequence corresponding to each characteristic value;

[0009] Based on the historical actual new device quantity sequence, the new device quantity of the current collection period is predicted to obtain a new device predicted quantity corresponding to each characteristic value;

[0010] determine a distribution abnormal value between the actual number of newly added devices and the predicted number of newly added devices in the current collection period, and determine a difference value proportion of the difference value between the actual number of newly added devices and the predicted number of newly added devices in the overall difference value;

[0011] determine a suspicious value of the newly added device corresponding to each feature value based on the distribution abnormal value and the difference value proportion;

[0012] screen the newly added devices of the platform based on the suspicious value.

[0013] Optionally, the at least one feature value of the feature dimension in the historical time period is aggregated to obtain a historical actual number of newly added devices corresponding to each feature value, including:

[0014] obtain the actual number of newly added devices of the feature value meeting the target feature value in each collection period;

[0015] obtain the historical actual number of newly added devices corresponding to each feature value in the historical time period based on the actual number of newly added devices; the historical actual number of newly added devices is wherein,

[0016] the i is the serial number of the feature dimension, the j is the jth feature value of the ith feature dimension, the s-1 is the s-1th collection period, the t is the tth collection period, the is the actual number of newly added devices of the jth feature value of the ith feature dimension meeting the target feature value in the 1th collection period, the is the actual number of newly added devices of the jth feature value of the ith feature dimension meeting the target feature value in the tth collection period, and the is the actual number of newly added devices of the jth feature value of the ith feature dimension meeting the target feature value in the s-1th collection period.

[0017] Optionally, the historical actual number of newly added devices is used to predict the number of newly added devices in the current collection period to obtain the predicted number of newly added devices corresponding to each feature value, including:

[0018] for each feature value, the trend decomposition value of the predicted number of newly added devices in the s-1th collection period is determined according to the formula

[0019] the horizontal decomposition value of the predicted number of newly added devices in the s-1th collection period is determined according to the formula the horizontal decomposition value of the predicted number of newly added devices in the s-1th collection period is determined according to the formula​

[0020] According to the formula determining the newly added equipment prediction quantity of the current collection period wherein,

[0021] The beta is the weight of the horizontal resolution value increment, and the is the horizontal resolution value of the newly added equipment prediction quantity in the s-2th collection period, and the is the trend resolution value of the newly added equipment prediction quantity in the s-2th collection period; and the current collection period is the s th collection period.

[0022] Optionally, the method further comprises:

[0023] Based on the formula determining the initial trend resolution value of the newly added equipment prediction quantity in the first collection period

[0024] Based on the formula determining the initial horizontal resolution value of the newly added equipment prediction quantity in the first collection period wherein,

[0025] The s-1 is the s-1th collection period, the s-2 is the s-2th collection period, the t is the t th collection period, and the is the actual number of newly added equipment whose j th feature value of i th feature dimension in the t th collection period meets the target feature value, and the is the actual number of newly added equipment whose j th feature value of i th feature dimension in the t+1 th collection period meets the target feature value, is the actual number of newly added equipment whose j th feature value of i th feature dimension in the first collection period meets the target feature value.

[0026] Optionally, the method further comprises:

[0027] According to the formula determining the first intermediate variable x t ;

[0028] According to the formula determining the second intermediate variable y t ;

[0029] According to the formula determining the weight of the horizontal resolution value increment; wherein,

[0030] The s-1 is the s-1th collection period, the t-2 is the t-2th collection period, the i is the serial number of the feature dimension, the j is the j th feature value of the i th feature dimension, and the The horizontal decomposition value of the predicted number of new devices in the (t-1)th collection period, wherein The horizontal decomposition value of the predicted number of new devices in the (t-2)th acquisition period is the value of the predicted number of new devices. The trend decomposition value of the predicted number of new devices in the (t-1)th collection period is the value of the [missing information]. This is the trend decomposition value of the predicted number of new devices during the (t-2)th collection period.

[0031] Optionally, determining the distribution outliers between the actual number of newly added devices and the predicted number of newly added devices includes:

[0032] According to the formula Determine the percentage (q) of the actual number of newly added devices whose j-th feature value in the i-th feature dimension satisfies the target feature value within the s-th collection period, in the total number of newly added devices. ij ;

[0033] According to the formula The percentage p of the predicted number of new devices whose j-th feature value in the i-th feature dimension satisfies the target feature value within the s-th collection period is determined. ij ;

[0034] According to the formula Determine the distribution outlier m between the actual number of newly added equipment and the predicted number of newly added equipment. ij ;in,

[0035] The The n represents the actual number of newly added devices whose j-th feature value in the i-th feature dimension satisfies the target feature value within the s-th collection period. s The actual total number of newly added devices, the The number of newly added devices whose j-th feature value in the i-th feature dimension satisfies the target feature value within the s-th collection period, wherein f s This forecasts the total number of new devices.

[0036] Optionally, determining the suspicion value of the new device corresponding to each feature value based on the distribution outliers and the proportion of the difference values ​​includes:

[0037] According to the formula Determine the percentage e of the difference between the actual number of newly added devices and the predicted number of newly added devices in the total difference value. ij ;

[0038] Based on formula a ij =|e ij m ij | Determine the suspicion value a of the newly added device corresponding to each feature value.ij ; wherein,

[0039] the m ij is a distribution anomaly value between the actual number of newly added devices and the predicted number of newly added devices of the i-th feature dimension j-th feature value meeting the target feature value, the actual number of newly added devices is the actual number of newly added devices of the i-th feature dimension j-th feature value meeting the target feature value in the s-th collection cycle, and the actual number of newly added devices s is the actual total number of newly added devices, and the actual number of newly added devices is the predicted number of newly added devices of the i-th feature dimension j-th feature value meeting the target feature value in the s-th collection cycle, and the predicted number of newly added devices s is the predicted total number of newly added devices.

[0040] The application further provides a screening device for platform newly added devices, which comprises:

[0041] an acquisition unit, configured to acquire feature information of newly added devices; the feature information comprises attribute information, dotting point information and IP address information of the newly added devices; each feature information comprises at least one feature dimension; at least one feature value of the feature dimension is aggregated in a historical time period to obtain a historical actual number sequence of newly added devices corresponding to each feature value;

[0042] a prediction unit, configured to predict the number of newly added devices in a current collection cycle based on the historical actual number sequence of newly added devices to obtain a predicted number of newly added devices corresponding to each feature value;

[0043] a determination unit, configured to, for each feature dimension, determine a distribution anomaly value between the actual number of newly added devices and the predicted number of newly added devices in the current collection cycle, and determine a difference value proportion of the difference value between the actual number of newly added devices and the predicted number of newly added devices in the overall difference value; and determine a suspicion value of the newly added devices corresponding to each feature value based on the distribution anomaly value and the difference value proportion;

[0044] a screening unit, configured to screen platform newly added devices based on the suspicion value.

[0045] The application further provides a computer readable storage medium, which stores a computer program, and the program is executed by a processor to implement the method of any one of the above.

[0046] The application further provides a computer device, which comprises a memory, a processor and a computer program stored in the memory and executable on the processor, and the processor implements the method of any one of the above when executing the program.

[0047] The application provides a platform new device screening method, device, medium and computer equipment, the method comprises the following steps: obtaining characteristic information of a new device; the characteristic information comprises attribute information, dotting point information and IP address information of the new device; each characteristic information comprises at least one characteristic dimension; at least one characteristic value of the characteristic dimension is aggregated in a historical time period to obtain a historical actual new device quantity sequence corresponding to each characteristic value; the actual new device quantity in the current collection period is predicted based on the historical actual new device quantity sequence to obtain a new device predicted quantity corresponding to each characteristic value; for each characteristic dimension, based on the actual new device quantity and the new device predicted quantity in the current collection period, the distribution abnormal value between the actual new device quantity and the new device predicted quantity is determined, and the difference value ratio of the difference value between the actual new device quantity and the new device predicted quantity in the overall difference value is determined; the suspicious value of the new device corresponding to each characteristic value is determined based on the distribution abnormal value and the difference value ratio; the platform new device is screened based on the suspicious value; in this way, if the new device is a black production device, it will have certain characteristics, such as the aggregation of some characteristic information, the similarity of dotting point information and the concentration of IP address, so the application obtains the above characteristic information to ensure the fitting degree of data and actual situation and ensure the screening precision; and the actual new device quantity in the historical time period is used to predict the new device predicted quantity in the current collection period, and for each characteristic value of each characteristic dimension, the difference between the actual new device quantity and the new device predicted quantity in the current collection period is compared, if the difference is large, it means that the new device corresponding to the characteristic value has a very large suspicious value, which means that the new device is abnormal, so that the abnormal new device can be accurately screened, and the screening precision of the platform new device is ensured. BRIEF DESCRIPTION OF DRAWINGS

[0048] Various other advantages and benefits will become apparent to those of ordinary skill in the art upon reading the following detailed description of the preferred embodiments. The accompanying drawings are included to provide a description of preferred embodiments, and are not intended to limit the scope of the application. Moreover, the same reference numerals are used throughout the same figures. In the drawings:

[0049] Figure 1 A platform new device screening method flowchart is provided for the embodiments of the application;

[0050] Figure 2 A platform new device screening device structure diagram is provided for the embodiments of the application;

[0051] Figure 3 A computer equipment structure diagram is provided for the embodiments of the application;

[0052] Figure 4 The computer readable storage medium structure schematic diagram provided for the embodiment of the application is shown. DETAILED DESCRIPTION

[0053] In order to solve the technical problem that the false device in the newly added device of the platform cannot be accurately screened in the prior art, resulting in that the screening accuracy of the newly added device of the platform cannot be ensured, the application provides a screening method, device, medium and computer equipment for the newly added device of the platform.

[0054] In order to better understand the above technical solution, the technical solution of the embodiment of the present application will be described in detail below through the drawings and specific embodiments. It should be understood that the specific features in the embodiments of the present application and the embodiments are detailed descriptions of the technical solution of the embodiments of the present application, and are not limitations of the technical solution of the present application. In the case of no conflict, the technical features in the embodiments of the present application and the embodiments can be combined with each other.

[0055] The embodiment provides a screening method for the newly added device of the platform, as shown in the method, the method comprises the steps of: Figure 1

[0056] S110, acquiring characteristic information of the newly added device; the characteristic information comprises attribute information, dotting point position information and IP address information of the newly added device; each characteristic information comprises at least one characteristic dimension;

[0057] Suppose that the newly added device is a black production device, the black production device has some similar characteristic information in the platform, such as using the same device to brush multiple tasks, such as concentrated IP address, etc. Therefore, the embodiment is combined with the actual scene to acquire the characteristic information of the newly added device; the characteristic information comprises attribute information, dotting point position information and IP address information of the newly added device. Each characteristic information comprises at least one characteristic dimension.

[0058] The attribute information comprises device unique serial number (device ID), device type and device brand information, etc. The dotting point position information comprises behavior events of the newly added device in the live broadcast platform, such as behavior events of browsing a certain page and behavior events of clicking a certain live broadcast room, etc.

[0059] This step acquires data with high actual scene fitting degree combined with the actual scene, so as to ensure the accuracy of the basic data.

[0060] S111, aggregating at least one characteristic value of the characteristic dimension in a historical time period to obtain a historical actual newly added device quantity sequence corresponding to each characteristic value;

[0061] ​After the feature information is determined, since each feature information has at least one feature dimension, at least one feature value of each feature dimension is aggregated in the historical time period to obtain a historical actual newly added device quantity sequence corresponding to each feature value.

[0062] In an optional implementation, aggregating at least one feature value of the feature dimension in the historical time period to obtain a historical actual newly added device quantity sequence corresponding to each feature value includes:

[0063] obtaining actual quantities of newly added devices whose feature values meet the target feature value in each collection period of the historical time period;

[0064] obtaining a historical actual newly added device quantity sequence corresponding to each feature value in the historical time period based on the actual quantities of newly added devices; the historical actual newly added device quantity sequence is wherein,

[0065] i is a serial number of the feature dimension, j is a jth feature value of an ith feature dimension, s-1 is an s-1th collection period, t is a tth collection period, is an actual quantity of newly added devices whose jth feature value of the ith feature dimension meets the target feature value in the 1st collection period, is an actual quantity of newly added devices whose jth feature value of the ith feature dimension meets the target feature value in the tth collection period, is an actual quantity of newly added devices whose jth feature value of the ith feature dimension meets the target feature value in the s-1th collection period.

[0066] Taking feature information as attribute information as an example, as described above, if the attribute information includes three feature dimensions, namely, device ID, device type and device brand, then i=1, 2, 3. Assuming that the third feature dimension is device brand, if the device brand includes three feature values, namely, brand A, brand B and brand C, then j=1, 2, 3, and the corresponding target feature values are v 31 , v 32 and v 33 , respectively.

[0067] When aggregating the device brand as brand A, the following is implemented: in the first collection period, the actual quantity of newly added devices whose device brand is v 31 is recorded as in the second collection period, the actual quantity of newly added devices whose device brand is v 31 is recorded as Similarly, until the last collection period is counted. The actual number of newly added devices in all collection periods is aggregated to generate the historical actual number of newly added devices sequence of feature dimension brand A in the historical time period. That is, the historical actual number of newly added devices sequence of feature dimension brand A is

[0068] According to the same method as described above, the historical actual number of newly added devices sequence corresponding to all feature values in the historical time period can be obtained.

[0069] Here, the historical time period can be 1 month, and the collection period can be 1 day. The historical time period and the collection period can also be set according to the actual application scenario, which is not limited here.

[0070] In this step, the actual number of newly added devices sequence corresponding to all feature values in the historical time period is counted, which lays a historical data foundation for subsequent determination of the predicted number of newly added devices in the current collection period.

[0071] S112, based on the historical actual number of newly added devices sequence, the number of newly added devices in the current collection period is predicted to obtain the predicted number of newly added devices corresponding to each feature value;

[0072] It can be understood that the sequence value contained in the historical actual number of newly added devices sequence is the actual number of newly added devices in the previous s-1 collection periods, so this step can predict the predicted number of newly added devices in the current collection period (the s-th collection period) according to the actual number of newly added devices in the previous s-1 collection periods.

[0073] Specifically, for each feature dimension, the predicted number of newly added devices in the s-1th collection period is determined according to the formula trend decomposition value of the predicted number of newly added devices in the s-1th collection period

[0074] The horizontal decomposition value of the predicted number of newly added devices in the s-1th collection period is determined according to the formula

[0075] The predicted number of newly added devices in the current collection period is determined according to the formula wherein,

[0076] β is the weight of the horizontal decomposition value increment, is the horizontal decomposition value of the predicted number of newly added devices in the s-2th collection period, trend decomposition value of the predicted number of newly added devices in the s-2th collection period; the current collection period is the s-th collection period.

[0077] ​​The principle behind the above formula is as follows: the historical sequence of actual new equipment numbers can be understood as a sequence formed in chronological order. This formula divides the sequence into two components: the horizontal decomposition value represents the baseline of the predicted number of new equipment, while the trend decomposition value represents the changing trend of the predicted number of new equipment. The predicted number of new equipment in the s-th collection period... The horizontal decomposition values ​​within the s-1 acquisition period can be obtained. and trend decomposition value Horizontal decomposition values ​​within the s-1 acquisition period The number of new devices can be predicted directly using the data collection period s-1. Calculations are performed, and the trend decomposition value... It can be written as the trend decomposition value within the s-2 acquisition period. and level decomposition value increment The weighted sum.

[0078] In an optional implementation, the initial level decomposition value and the initial trend decomposition value of the predicted amount of new equipment in the first collection period in the above formula are determined as follows:

[0079] Based on formula Determine the initial trend decomposition value for the predicted number of new devices in the first data collection period.

[0080] Based on formula Determine the initial level decomposition values ​​for the predicted number of new devices in the first data collection period. in,

[0081] s-1 represents the (s-1)th acquisition cycle, s-2 represents the (s-2)th acquisition cycle, and t represents the tth acquisition cycle. This represents the actual number of newly added devices whose j-th feature value in the i-th feature dimension satisfies the target feature value during the t-th collection period. This represents the actual number of newly added devices whose j-th feature value in the i-th feature dimension satisfies the target feature value during the (t+1)-th collection period. The actual number of newly added devices whose j-th feature value in the i-th feature dimension satisfies the target feature value during the first collection period.

[0082] The principle behind the above formula is as follows: For the initial level decomposition value, the initial level decomposition value can be consistent with the actual number of new devices in the first collection period in the historical actual number of new devices sequence; for the initial trend decomposition value, the average of the actual number of new devices with a collection period interval of 1 can be used for estimation.

[0083] In one optional implementation, the weight β of the level decomposition value increment in this embodiment is determined as follows:

[0084] According to the formula The first intermediate variable x is determined t ;

[0085] According to the formula The second intermediate variable y is determined t ;

[0086] According to the formula The weight β of the horizontal decomposition value increment is determined; wherein,

[0087] s-1 is the s-1th acquisition cycle, t-2 is the t-2th acquisition cycle, i is the serial number of the feature dimension, j is the jth feature value of the ith feature dimension, is the horizontal decomposition value of the newly added equipment prediction quantity in the t-1th acquisition cycle, is the horizontal decomposition value of the newly added equipment prediction quantity in the t-2th acquisition cycle, is the trend decomposition value of the newly added equipment prediction quantity in the t-1th acquisition cycle, is the trend decomposition value of the newly added equipment prediction quantity in the t-2th acquisition cycle.

[0088] The principle of the above formula is that According to the basic principle of the least square method, the function is y=a+βx, and the estimated value is Wherein is any x minus the mean value of x, is any y minus the mean value of all y; therefore in , it is equivalent to Therefore is brought into the formula of the estimated value, and the weight β can be obtained.

[0089] In this step, the newly added equipment prediction quantity in the current acquisition cycle is predicted, and the newly added equipment prediction quantity can be used as a reference value to determine the suspicion degree of the actual newly added equipment in the current acquisition cycle. Since the newly added equipment prediction quantity is determined according to historical data, it is more consistent with the real situation of the live broadcast platform, thereby improving the screening accuracy.

[0090] S113, based on the actual number of newly added equipment in the current acquisition cycle and the newly added equipment prediction quantity, determining the distribution abnormal value between the actual number of newly added equipment and the newly added equipment prediction quantity, and determining the difference value ratio of the difference value of the actual number of newly added equipment and the newly added equipment prediction quantity in the total difference value;

[0091] In this step, for each feature value, the distribution abnormal value between the actual number of new devices and the predicted number of new devices needs to be determined based on the actual number of new devices and the predicted number of new devices in the current collection period, and the difference value of the difference value between the actual number of new devices and the predicted number of new devices in the overall difference value is determined.

[0092] Specifically, the distribution abnormal value between the actual number of new devices and the predicted number of new devices is determined, including:

[0093] According to the formula determining the proportion q of the actual number of new devices of the jth feature value of the ith feature dimension in the s th collection period that meets the target feature value in the total number of actual new devices ij ;

[0094] According to the formula determining the proportion p of the predicted number of new devices of the jth feature value of the ith feature dimension in the s th collection period that meets the target feature value in the total number of predicted new devices ij ;

[0095] According to the formula determining the distribution abnormal value m between the actual number of new devices and the predicted number of new devices ij ; wherein,

[0096] The current collection period is the s th collection period, is the actual number of new devices of the jth feature value of the ith feature dimension in the s th collection period that meets the target feature value, n s is the total number of actual new devices, which can be understood as the actual number of new devices of all feature values of all feature dimensions in the s th collection period that meet the corresponding target feature value, is the predicted number of new devices of the jth feature value of the ith feature dimension in the s th collection period that meets the target feature value, f s is the total number of predicted new devices, which can be understood as the predicted number of new devices of all feature values of all feature dimensions in the s th collection period that meet the corresponding target feature value.

[0097] The determination principle of the above distribution abnormal value m ij is to determine the difference between the actual number of new devices distribution q ij and the predicted number of new devices distribution predicted feature value distribution p ij , if the difference is larger, it means that the actual number and the predicted number have changed greatly, which means that the actual number has been abnormal. The above distribution abnormality is determined by p ij and the distribution mean The relative entropy between To measure the difference in distribution between these two, the metric should obviously be symmetric, therefore it can be constructed. The mean of the two terms is then calculated to obtain the outliers of the distribution.

[0098] In one optional implementation, determining the proportion of the difference between the actual number of newly added equipment and the predicted number of newly added equipment in the total difference value includes:

[0099] According to the formula Determine the percentage e of the difference between the actual number of newly added equipment and the predicted number of newly added equipment in the total difference value. ij

[0100] The above determines the proportion of the difference value e ij The formula works as follows: the ratio of the difference between the actual number of newly added devices and the predicted number of newly added devices to the total difference. This takes into account the overall difference and excludes changes in the actual number of newly added devices caused by factors related to the live streaming platform as a whole. Therefore, a higher percentage of the difference indicates a larger difference between the actual number of newly added devices and the predicted number of newly added devices relative to the overall difference, and thus a greater likelihood that the actual number of newly added devices is abnormal.

[0101] In this step, the distribution of outliers between the actual number of newly added devices and the predicted number of newly added devices, as well as the proportion of the difference between the actual number of newly added devices and the predicted number of newly added devices in the total difference value, are used to determine whether the actual number of newly added devices is abnormal. This fully considers the various differences between the two and excludes the changes in the actual number of devices due to reasons of the live streaming platform as a whole (its own reasons), thus ensuring the accuracy of the screening.

[0102] S114, Based on the distribution outliers and the proportion of the difference values, determine the suspicion value of the new device corresponding to each feature value;

[0103] This step determines the suspected value of the new device corresponding to each feature value based on the proportion of outliers and differences in the distribution.

[0104] Specifically, it can be based on formula a ij =|e ij m ij | Determine the suspicion value a of the newly added device corresponding to each feature value. ij Among them, m ij e represents an outlier in the distribution between the actual number of new devices and the predicted number of new devices, where the j-th feature value in the i-th feature dimension satisfies the target feature value. ijThe difference value between the actual number of newly added devices and the predicted number of newly added devices accounts for the difference value in the overall difference value.

[0105] This step determines the suspicion value of the newly added device corresponding to each feature value by distributing the abnormal value and the difference value proportion. Finally, it can be determined whether the newly added device corresponding to the feature value is an abnormal device through the suspicion value.

[0106] S115, screening the platform newly added device based on the suspicion value.

[0107] After determining the suspicion value of the newly added device corresponding to each feature value, the platform newly added device is screened based on the suspicion value.

[0108] Specifically, if it is determined that the suspicion value of the newly added device corresponding to a certain feature value is greater than the suspicion value threshold, it means that the newly added device corresponding to the feature value is an abnormal device. At this time, these newly added devices can be screened out in the live broadcast platform, and these newly added devices are cleaned up, such as punishment, account ban and other operations.

[0109] For example, assuming that a certain feature dimension i includes two feature values (j = 1, 2), the predicted number of newly added devices in the current collection period, the predicted total number of newly added devices in the current collection period, the actual total number, the distribution abnormal value and the difference value proportion corresponding to the two feature values are as follows:

[0110]

[0111]

[0112] n s = 2000, f s = 2100;

[0113]

[0114]

[0115] Then,

[0116]

[0117]

[0118]

[0119]

[0120] The finally determined suspicion value is as follows:

[0121] a i1 = 4 * 0.0163 = 0.0652;

[0122] a i2 = 0.1 * 0.0084 = 0.00084;

[0123] If the suspicion value threshold is 0.01, at this time, the suspicion value of the newly added device corresponding to the first feature value of the feature dimension i is greater than 0.01, and the suspicion value of the newly added device corresponding to the second feature value of the feature dimension i is less than 0.01, at this time, the newly added device corresponding to the first feature value of the feature dimension i is screened out, so as to clean the newly added device corresponding to the first feature value of the feature dimension i.

[0124] This step determines whether the newly added device is an abnormal device by determining the suspicion value of the newly added device corresponding to each feature value, which can effectively determine whether the newly added device is an abnormal device and ensure the screening accuracy of abnormal devices.

[0125] Based on the same inventive concept, the application also provides a device for platform newly added device, as shown in Figure 2 The device comprises:

[0126] An acquisition unit 21 is configured to acquire feature information of a newly added device, wherein the feature information comprises attribute information, dotting point information and IP address information of the newly added device, each feature information comprises at least one feature dimension, and at least one feature value of the feature dimension is aggregated in a historical time period to obtain a historical actual newly added device quantity sequence corresponding to each feature value.

[0127] A prediction unit 22 is configured to predict the quantity of newly added devices in a current collection period based on the historical actual newly added device quantity sequence to obtain a predicted quantity of newly added devices corresponding to each feature value.

[0128] A determination unit 23 is configured to, for each feature dimension, determine a distribution abnormal value between an actual quantity of newly added devices and a predicted quantity of newly added devices in the current collection period and a difference value proportion of a difference value between the actual quantity of newly added devices and the predicted quantity of newly added devices in a total difference value based on the actual quantity of newly added devices and the predicted quantity of newly added devices, and determine a suspicion value of the newly added device corresponding to each feature value based on the distribution abnormal value and the difference value proportion.

[0129] A screening unit 24 is configured to screen platform newly added devices based on the suspicion value.

[0130] The specific functions of the above units can be referred to the corresponding description in the method embodiments, which will not be repeated here. Since the device introduced in the embodiments of the present application is the device used to implement the method of the embodiments of the present application, the specific structure and deformation of the device can be understood by the person skilled in the art based on the method introduced in the embodiments of the present application, so it will not be repeated here. Any device used by the method of the embodiments of the present application belongs to the scope of the present application.

[0131] The platform new device screening method and device provided by the present application can bring at least the following beneficial effects:

[0132] The present application provides a kind of platform new device screening method, device, medium and computer equipment, method includes: the characteristic information of new equipment is acquired;The characteristic information includes: the attribute information of the new equipment, dot point position information and IP address information;Each characteristic information includes at least one characteristic dimension;At least one characteristic value of the characteristic dimension is aggregated in historical time period, and the historical actual new equipment quantity sequence corresponding to each characteristic value is obtained;Based on the historical actual new equipment quantity sequence, the new equipment quantity of current acquisition period is predicted, and the new equipment predicted quantity corresponding to each characteristic value is obtained;For each characteristic dimension, based on the actual number of new equipment in current acquisition period and new equipment predicted quantity, the distribution abnormal value between the actual number of new equipment and the new equipment predicted quantity is determined, and the difference value of the actual number of new equipment and the new equipment predicted quantity in the difference value of overall difference value is determined.The proportion of difference value;Determine the suspect value of new equipment corresponding to each characteristic value based on the distribution abnormal value and the difference value proportion;The platform new equipment is screened based on the suspect value;In this way, if the new equipment is black production equipment, it will have certain characteristics, such as the aggregation of some characteristic information, the dot point position information will be similar, and the IP address will be concentrated, so the present application acquires the above characteristic information, ensures the fitting degree of data and actual situation, and ensures the screening precision;And according to the actual number of new equipment in historical time period, the new equipment predicted quantity in current acquisition period is predicted, for each characteristic value of each characteristic dimension, and then by comparing the difference between the actual number of new equipment in current acquisition period and the new equipment predicted quantity, if the difference is large, it means that the new equipment corresponding to the characteristic value has very large suspect value, which means that the new equipment is abnormal, so that the abnormal new equipment can be accurately screened, and the screening precision of platform new equipment is ensured.

[0133] Based on the same inventive concept as the foregoing embodiments, the present application also provides a computer device, such as Figure 3As shown, it comprises a memory 310, a processor 320, and a computer program 311 stored in the memory 310 and executable on the processor 320, and the processor 320 implements the following steps when executing the computer program 311:

[0134] Obtain feature information of the newly added device; the feature information comprises attribute information, dotting point information and IP address information of the newly added device; each feature information comprises at least one feature dimension;

[0135] Aggregate at least one feature value of the feature dimension in a historical time period to obtain a historical actual newly added device quantity sequence corresponding to each feature value;

[0136] Based on the historical actual newly added device quantity sequence, predict the newly added device quantity of a current collection period to obtain a newly added device predicted quantity corresponding to each feature value;

[0137] Based on the actual newly added device quantity and the newly added device predicted quantity in the current collection period, determine a distribution abnormal value between the actual newly added device quantity and the newly added device predicted quantity, and determine a difference value proportion of the difference value between the actual newly added device quantity and the newly added device predicted quantity in the overall difference value;

[0138] Determine a suspicion value of the newly added device corresponding to each feature value based on the distribution abnormal value and the difference value proportion;

[0139] Based on the suspicion value, screen the platform newly added device.

[0140] In the specific implementation process, when the processor 320 executes the computer program 311, any embodiment in the above-mentioned embodiments can be implemented.

[0141] Since the computer device introduced in the embodiment is the device used to implement the platform newly added device screening method in the foregoing embodiments of the application, the specific implementation mode of the computer device of the embodiment and its various forms can be understood by those skilled in the art based on the method introduced in the foregoing embodiments of the application, so the server how to implement the method in the embodiments of the application will not be introduced in detail. As long as the device used to implement the method in the embodiments of the application is implemented by those skilled in the art, it belongs to the scope of the application.

[0142] Based on the same inventive concept as the foregoing embodiments, the embodiment provides a computer readable storage medium 400, as shown in the figure, which stores a computer program 411, and the computer program 411 is executed by a processor to implement the following steps: Figure 4

[0143] ​Obtaining feature information of the new device; the feature information includes attribute information, dotting point information and IP address information of the new device; each feature information includes at least one feature dimension;

[0144] Aggregating at least one feature value of the feature dimension in a historical time period to obtain a historical actual new device quantity sequence corresponding to each feature value;

[0145] Based on the historical actual new device quantity sequence, predicting the new device quantity of a current collection period to obtain a new device prediction quantity corresponding to each feature value;

[0146] Based on the actual new device quantity and the new device prediction quantity in the current collection period, determining a distribution abnormal value between the actual new device quantity and the new device prediction quantity, and determining a difference value ratio of the difference value between the actual new device quantity and the new device prediction quantity in the overall difference value;

[0147] Based on the distribution abnormal value and the difference value ratio, determining a suspicious value of the new device corresponding to each feature value;

[0148] Based on the suspicious value, screening the platform new device.

[0149] In the implementation process, the computer program 411 is executed by the processor, and any of the above embodiments can be implemented.

[0150] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system or a computer program product. Therefore, the present application can be in the form of a complete hardware embodiment, a complete software embodiment or an embodiment combining software and hardware aspects. Moreover, the present application can be in the form of a computer program product implemented on one or more computer usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer usable program code.

[0151] The present application is described with reference to flowcharts and / or block diagrams according to the method, device (system) and computer program product of the embodiments of the present application. It should be understood that each flow and / or block in the flowchart and / or block diagram, and the combination of the flows and / or blocks in the flowchart and / or block diagram can be realized by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device produce a device that implements the functions specified in the flowchart and / or block diagram. Figure 1 The function specified in one flow or multiple flows and / or blocks Figure 1 The device for implementing the function specified in one block or multiple blocks.

[0152] These computer program instructions can also be stored in a computer readable memory that can direct a computer or other programmable data processing apparatus to function in a particular manner, such that the instructions stored in the computer readable memory produce an article of manufacture including instructions which implement the Figure 1 function specified in the flow or flows and / or blocks Figure 1 of the block or blocks.

[0153] These computer program instructions can also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer implemented process such that the instructions that are executed on the computer or other programmable apparatus provide steps for implementing the Figure 1 function specified in the flow or flows and / or blocks Figure 1 of the block or blocks.

[0154] Although preferred embodiments of the application have been described herein, changes and modifications can be suggested to one skilled in the art, and it is intended that the scope of the application be limited only by the appended claims.

[0155] The above descriptions are only the preferred embodiments of the present application, not intended to limit the protection scope of the present application, and any modification, equivalent replacement and improvement made within the spirit and principle of the present application shall be included in the protection scope of the present application.

Claims

1. A method for screening of new devices for a platform, characterized in that, The method comprises: obtaining feature information of the new device; the feature information comprises attribute information, dot point information and IP address information of the new device; each feature information comprises at least one feature dimension; aggregating at least one feature value of the feature dimension in a historical time period to obtain a historical actual new device quantity sequence corresponding to each feature value; predicting the number of new devices in a current collection period based on the historical actual new device quantity sequence to obtain a predicted number of new devices corresponding to each feature value; based on the actual number of new devices in the current collection period and the predicted number of new devices, determining a distribution anomaly value between the actual number of new devices and the predicted number of new devices, and determining a difference value ratio of the difference value between the actual number of new devices and the predicted number of new devices in the overall difference value; determining the suspicious value of the new device corresponding to each feature value based on the distribution anomaly value and the difference value ratio; screening the platform new device based on the suspicious value; wherein the distribution anomaly value is used to represent the difference between the actual number of new devices and the predicted number of new devices, and if the difference is greater, it means that the actual number and the predicted number have changed greatly, indicating that the actual number is abnormal; the overall difference value is used to represent the change of the actual number of new devices caused by the overall reason of the live broadcast platform, and the higher the difference value ratio is, the greater the difference value between the actual number of new devices and the predicted number of new devices is relative to the overall difference value, and the greater the possibility of abnormality of the actual number of new devices is.

2. The method of claim 1, wherein, The aggregation of at least one feature value of the feature dimension in a historical time period to obtain a historical actual new device quantity sequence corresponding to each feature value comprises: obtaining the actual number of new devices of the feature value meeting the target feature value in each collection period; Based on the actual number of each of the new devices, a historical actual number of new devices sequence corresponding to each feature value in the historical time period is obtained; the historical actual number of new devices sequence is wherein, The i is the serial number of the feature dimension, the j is the jth feature value of the ith feature dimension, the s-1 is the s-1th acquisition cycle, the t is the tth acquisition cycle, and the The s-1 is the s-1th acquisition cycle, the t is the tth acquisition cycle, the i is the serial number of the feature dimension, the j is the jth feature value of the ith feature dimension, and the The s-1 is the s-1th acquisition cycle, the t is the tth acquisition cycle, the i is the serial number of the feature dimension, the j is the jth feature value of the ith feature dimension, and the The s-1 is the s-1th acquisition cycle, the t is the tth acquisition cycle, the i is the serial number of the feature dimension, the j is the jth feature value of the ith feature dimension, and the 3. The method of claim 1, wherein, The prediction of the number of new devices in a current collection period based on the historical actual new device quantity sequence to obtain a predicted number of new devices corresponding to each feature value comprises: For each of the feature values, according to the formula determines the trend decomposition value of the predicted number of new devices in the s-1th acquisition cycle According to the formula determining the level decomposition value of the predicted number of newly added devices in the s-1th collection cycle According to the formula determining the predicted number of new devices for the current collection cycle wherein, The β is a weight of a horizontal resolution value increment, and the is a horizontal resolution value of a predicted number of newly added devices in an s-2th collection cycle, and the is a trend resolution value of a predicted number of newly added devices in an s-2th collection cycle; the current collection cycle is an s th collection cycle; the horizontal resolution value represents a baseline of the predicted number of newly added devices, and the trend resolution value represents a change trend of the predicted number of newly added devices.

4. The method of claim 3, wherein, The method further comprises: Based on the formula determining an initial trend decomposition value of the predicted number of newly added devices in the first collection period Based on the formula determining the initial level decomposition value of the predicted number of newly added devices in the first collection cycle wherein, The s-1 is the s-1th acquisition cycle, the s-2 is the s-2th acquisition cycle, the t is the tth acquisition cycle, and the The s-1 is the s-1th acquisition cycle, the s-2 is the s-2th acquisition cycle, the t is the tth acquisition cycle, and the The s-1 is the s-1th acquisition cycle, the s-2 is the s-2th acquisition cycle, the t is the tth acquisition cycle, and the The s-1 is the s-1th acquisition cycle, the s-2 is the s-2th acquisition cycle, the t is the tth acquisition cycle, and the 5. The method of claim 3, wherein, The method further comprises: According to the formula determining a first intermediate variable x t ; According to the formula determining a second intermediate variable y t ; According to the formula determining a weight of the level decomposition value increment; wherein, The s-1 is the s-1th acquisition cycle, the t-2 is the t-2th acquisition cycle, the i is the serial number of the feature dimension, the j is the jth feature value of the ith feature dimension, and the The is a horizontal decomposition value of the predicted number of new devices in the t-1th acquisition cycle, the is a horizontal decomposition value of the predicted number of new devices in the t-2th acquisition cycle, the is a trend decomposition value of the predicted number of new devices in the t-1th acquisition cycle, and the is a trend decomposition value of the predicted number of new devices in the t-2th acquisition cycle. The is a horizontal decomposition value of the predicted number of new devices in the t-1th acquisition cycle, the is a horizontal decomposition value of the predicted number of new devices in the t-2th acquisition cycle, the is a trend decomposition value of the predicted number of new devices in the t-1th acquisition cycle, and the is a trend decomposition value of the predicted number of new devices in the t-2th acquisition cycle. The is a horizontal decomposition value of the predicted number of new devices in the t-1th acquisition cycle, the is a horizontal decomposition value of the predicted number of new devices in the t-2th acquisition cycle, the is a trend decomposition value of the predicted number of new devices in the t-1th acquisition cycle, and the is a trend decomposition value of the predicted number of new devices in the t-2th acquisition cycle. The is a horizontal decomposition value of the predicted number of new devices in the t-1th acquisition cycle, the is a horizontal decomposition value of the predicted number of new devices in the t-2th 6. The method of claim 1, wherein, The determination of the distribution anomaly value between the actual number of new devices and the predicted number of new devices comprises: According to the formula The proportion q of the actual number of newly added devices that meet the target feature value in the actual total number of newly added devices in the jth feature value of the ith feature dimension in the sth acquisition cycle ij ; According to the formula The proportion p of the predicted number of new devices in the total predicted number of new devices that satisfy the target feature value in the jth feature value of the ith feature dimension in the sth acquisition cycle ij ; According to the formula determining a distribution abnormal value m between the actual number of the added devices and the predicted number of the added devices ij ; wherein, The is the actual number of newly added devices whose jth feature value of the ith feature dimension in the s th collection cycle meets the target feature value, and the n s is the total number of newly added devices, and the n is the predicted number of newly added devices whose jth feature value of the ith feature dimension in the s th collection cycle meets the target feature value, and the f s is the total number of newly added devices.

7. The method of claim 1, wherein, The determination of the suspicious value of the new device corresponding to each feature value based on the distribution anomaly value and the difference value ratio comprises: According to the formula determining a difference value proportion e of the difference value between the actual number of the added devices and the predicted number of the added devices in the overall difference value ij ; Based on the formula a ij = |e ij m ij Determine the value of each feature corresponding to the new device of the suspect value a ij ; wherein, The m ij The distribution anomaly value between the actual number of newly added devices and the predicted number of newly added devices for the i-th feature dimension j-th feature value meeting the target feature value in the s-th collection cycle, wherein the n The actual number of newly added devices for the i-th feature dimension j-th feature value meeting the target feature value in the s-th collection cycle, wherein the n s The actual total number of newly added devices, wherein the n The predicted number of newly added devices for the i-th feature dimension j-th feature value meeting the target feature value in the s-th collection cycle, wherein the f s The predicted total number of newly added devices.

8. A computer-readable storage medium having stored thereon a computer program, characterized in that, The program is executed by the processor to realize the method of any one of claims 1 to 7.

9. A computer device comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, characterized in that, The processor executes the program to realize the method of any one of claims 1 to 7.

Citation Information

Patent Citations

  • Fan prediction management method and device, electronic device and storage medium

    CN110276491A

  • Abnormity detection method and device, computer equipment and storage medium

    CN112685273A