Method, device and computer equipment for analyzing alarm information
By comparing and analyzing the comprehensive scores of the alarm information from the bank's customer identity recognition system, false alarm information is screened out, solving the problem of low efficiency in manual review and achieving efficient alarm information processing.
Patent Information
- Application Number
- CN202111639482.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-12-29
- Publication Date
- 2025-09-23
- Estimated Expiration
- 2041-12-29
AI Technical Summary
In existing bank customer identity recognition systems, manual review of alarm information is labor-intensive and inefficient. In addition, existing technologies have problems such as high cost of labeling sample data, model complexity, and difficulty in interpretation when reducing false alarm rates.
By comparing the comprehensive score of the alarm information with the threshold, the type of abnormal alarm information is determined, and in-depth analysis is performed based on the alarm elements and trigger types, including customer feature expansion and the application of Gaussian mixture models, to screen out false alarm information.
It reduces the workload of manual review, improves work efficiency, reduces false positive rates, and reduces dependence on the experience of business experts.
Smart Images

Figure CN114298563B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of data analysis, and in particular to an analysis method, device and computer equipment for alarm information. Background Art
[0002] Currently, bank customer identification systems maintain lists of various types of "prohibited" customers to form a risk database and establish a customer identification monitoring system. During bank transactions, customer identity information is fed into the identification engine through various technical methods, including the list database, risk database, search engine, risk relationship map, and third-party risk identification interface. Various customer information elements are matched with risk data, and alerts are issued for close, similar, or related customer information. These information then enters the manual approval process, where it is further manually reviewed and confirmed by review specialists. To avoid missing any "prohibited" customers, existing identification systems use fuzzy matching technology to perform highly sensitive matching of numerous elements, including customer name, ID number, region, country, and address. Fuzzy matching is characterized by randomness, high sensitivity, and a high detection rate. Consequently, a large number of alerts are fed into the manual review process, leading to complex reviews and low efficiency. Summary of the Invention
[0003] The present invention provides an alarm information analysis method, device and computer equipment, which are used to solve the problems of heavy workload and low work efficiency in the prior art of manual review of alarm information.
[0004] In a first aspect, an embodiment of the present invention provides a method for analyzing alarm information, the method comprising:
[0005] Comparing the comprehensive score of the alarm information with a first threshold, and determining whether the alarm information is first abnormal alarm information or second abnormal alarm information based on the comparison result and the risk type of the alarm information;
[0006] If the alarm information is the first abnormal alarm information, determining that the first abnormal alarm information is false alarm information according to the alarm element and the alarm trigger type of the first abnormal alarm information;
[0007] If the alarm information is the second abnormal alarm information, the customer characteristics of the second alarm information are expanded, and the expanded customer characteristics are deeply analyzed to determine that the second abnormal alarm information is false alarm information, wherein the customer characteristics include basic characteristics and / or behavioral characteristics.
[0008] In a possible implementation, comparing the comprehensive score of the alarm information with a first threshold, and determining, based on the comparison result and the risk type of the alarm information, whether the alarm information is first abnormal alarm information or second abnormal alarm information, includes:
[0009] Determining that the comprehensive score is greater than or equal to the first threshold and the warning information of the risk type being the first risk type is the first abnormal warning information;
[0010] It is determined that the comprehensive score is less than the first threshold, and the alarm information that the risk type is the second risk type is the second abnormal alarm information.
[0011] In a possible implementation, determining, based on the alarm element and the alarm trigger type of the first abnormal alarm information, that the first abnormal alarm information is false alarm information includes:
[0012] If the alarm element is a single element, and the alarm trigger type corresponding to the alarm element completely matches the alarm trigger type corresponding to the element of the historical false alarm information, then determining that the first abnormal alarm information is false alarm information;
[0013] If the alarm element is multiple elements, a similar hash value is calculated according to the alarm trigger type corresponding to each alarm element and the alarm trigger type of historical false alarm information, and the first abnormal alarm information is determined to be false alarm information according to the similar hash value.
[0014] In a possible implementation, determining, according to the similar hash value, that the first abnormality alarm information is false alarm information includes:
[0015] If the similar hash value is greater than or equal to a second threshold, determining that the first abnormal alarm information is false alarm information;
[0016] If the similar hash value is less than the second threshold, the first abnormal alarm information is determined to be false alarm information based on the feature score of each alarm element, the normal alarm trigger type and the customer feature corresponding to the first abnormal alarm information.
[0017] In a possible implementation, determining that the first abnormal alarm information is false alarm information based on the feature score of each alarm element, the normal alarm trigger type, and the customer feature corresponding to the first abnormal alarm information includes:
[0018] If the feature score of any alarm element in each of the alarm elements is higher than the third threshold, and the alarm trigger type corresponding to any alarm element in each of the alarm elements does not belong to the normal alarm trigger type, then an in-depth analysis is performed on the customer characteristics of the first abnormal alarm information to determine that the first abnormal alarm information is false alarm information.
[0019] In one possible implementation, the method further includes:
[0020] After in-depth analysis of the customer characteristics, perform Expectation Maximization (EM) parameter estimation;
[0021] The EM parameter estimation results are input into the Gaussian mixture model to obtain the false probability value;
[0022] Determine the first abnormal alarm information or the second abnormal alarm information whose false probability value is less than a fourth threshold as the false alarm information.
[0023] In a second aspect, an embodiment of the present invention provides an alarm information analysis device, the device comprising:
[0024] a first determination module, comparing the comprehensive score of the alarm information with a first threshold, and determining whether the alarm information is first abnormal alarm information or second abnormal alarm information based on the comparison result and the risk type of the alarm information;
[0025] a second determining module, configured to, if the alarm information is the first abnormal alarm information, determine, based on the alarm elements and the alarm trigger type of the first abnormal alarm information, that the first abnormal alarm information is false alarm information;
[0026] The third determination module is used to expand the customer characteristics of the second alarm information if the alarm information is the second abnormal alarm information, and conduct an in-depth analysis of the expanded customer characteristics to determine that the second abnormal alarm information is false alarm information, wherein the customer characteristics include basic characteristics and / or behavioral characteristics.
[0027] In a possible implementation, the first determining module includes:
[0028] A first determining submodule is configured to determine that the comprehensive score is greater than or equal to the first threshold, and the warning information of the risk type being the first risk type is the first abnormal warning information;
[0029] The second determining submodule is configured to determine that the comprehensive score is less than the first threshold value, and the alarm information of the risk type being the second risk type is the second abnormal alarm information.
[0030] In a possible implementation, the second determining module includes:
[0031] a single element determination module, configured to determine that the first abnormal alarm information is false alarm information if the alarm element is a single element and the alarm trigger type corresponding to the alarm element completely matches the alarm trigger type corresponding to the element of the historical false alarm information;
[0032] A multi-factor determination module is used to calculate a similar hash value based on the alarm trigger type corresponding to each alarm factor and the alarm trigger type of historical false alarm information if the alarm factor is multi-factor, and determine that the first abnormal alarm information is false alarm information based on the similar hash value.
[0033] In a possible implementation, the multi-factor determination module includes:
[0034] a first multi-factor determination submodule, configured to determine that the first abnormal alarm information is false alarm information if the similarity hash value is greater than or equal to a second threshold;
[0035] The second multi-factor determination submodule is used to determine that the first abnormal alarm information is false alarm information based on the feature score of each alarm element, the normal alarm trigger type and the customer characteristics corresponding to the first abnormal alarm information if the similar hash value is less than the second threshold.
[0036] In a possible implementation manner, the second multi-factor determination submodule includes:
[0037] The second multi-factor determination sub-unit is used to conduct an in-depth analysis of the customer characteristics of the first abnormal alarm information if the feature score of any alarm element in each of the alarm elements is higher than a third threshold, and the alarm trigger type corresponding to any alarm element in each of the alarm elements does not belong to the normal alarm trigger type, and determine that the first abnormal alarm information is false alarm information.
[0038] In one possible implementation, the device further includes:
[0039] A parameter estimation module is used to perform expectation maximization (EM) parameter estimation after in-depth analysis of the customer characteristics;
[0040] The probability calculation module is used to input the EM parameter estimation results into the Gaussian mixture model to obtain the false probability value;
[0041] The fourth determining module is configured to determine that the first abnormal alarm information or the second abnormal alarm information whose false probability value is less than a fourth threshold is the false alarm information.
[0042] In a third aspect, an embodiment of the present invention provides a computer device, including: a memory, a transceiver, and a processor;
[0043] The memory is used to store computer instructions;
[0044] The transceiver is used to send and receive data under the control of the processor;
[0045] The processor is configured to read the computer program in the memory and execute the following steps:
[0046] Comparing the comprehensive score of the alarm information with a first threshold, and determining whether the alarm information is first abnormal alarm information or second abnormal alarm information based on the comparison result and the risk type of the alarm information;
[0047] If the alarm information is the first abnormal alarm information, determining that the first abnormal alarm information is false alarm information according to the alarm element and the alarm trigger type of the first abnormal alarm information;
[0048] If the alarm information is the second abnormal alarm information, the customer characteristics of the second alarm information are expanded, and the expanded customer characteristics are deeply analyzed to determine that the second abnormal alarm information is false alarm information, wherein the customer characteristics include basic characteristics and / or behavioral characteristics.
[0049] In a fourth aspect, an embodiment of the present invention provides a computer-readable storage medium, wherein the storage medium stores computer instructions, and when the computer instructions are executed by the processor, the method as described in any one of the first aspects is implemented.
[0050] In a fifth aspect, an embodiment of the present invention provides a computer program product comprising computer-executable instructions, wherein the computer-executable instructions are used to enable a computer to execute the method as described in any one of the first aspects.
[0051] The beneficial effects of the present invention are as follows:
[0052] The present invention discloses a method, device and computer equipment for analyzing alarm information. First, the comprehensive score of the alarm information is compared with a first threshold value. According to the comparison result and the risk type of the alarm information, the alarm information is determined to be the first abnormal alarm information or the second abnormal alarm information. Then, if the alarm information is the first abnormal alarm information, the first abnormal alarm information is determined to be a false alarm information according to the alarm elements and alarm trigger type of the first abnormal alarm information. If the alarm information is the second abnormal alarm information, the second alarm information is expanded with customer characteristics, and the expanded customer characteristics are deeply analyzed to determine that the second abnormal alarm information is a false alarm information, wherein the customer characteristics include basic characteristics and / or behavioral characteristics. By the above method, the alarm information issued by the system is further filtered out to obtain abnormal alarm information, and false alarm information is filtered out from the abnormal alarm information, thereby reducing the workload of manual review and improving work efficiency. BRIEF DESCRIPTION OF THE DRAWINGS
[0053] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0054] Figure 1 A flowchart of a method for analyzing alarm information provided by an embodiment of the present invention;
[0055] Figure 2 A schematic diagram of a specific process of an alarm information analysis method provided by an embodiment of the present invention;
[0056] Figure 3a A schematic diagram of modeling of alarm information provided by an embodiment of the present invention;
[0057] Figure 3b A schematic diagram of an alarm information probability value provided by an embodiment of the present invention;
[0058] Figure 4 A schematic diagram of the structure of an alarm information analysis device provided by an embodiment of the present invention;
[0059] Figure 5 A schematic diagram of the specific structure of an alarm information analysis device provided by an embodiment of the present invention;
[0060] Figure 6 A schematic structural diagram of a computer device provided in an embodiment of the present invention. DETAILED DESCRIPTION
[0061] To make the objectives, technical solutions, and advantages of the present invention more apparent, the present invention will be further described in detail below with reference to the accompanying drawings. It should be understood that the embodiments described herein are merely some, rather than all, of the present invention. All other embodiments derived by persons of ordinary skill in the art based on the embodiments of the present invention without inventive effort are intended to fall within the scope of protection of the present invention.
[0062] Currently, during the transaction process, the bank's customer identity identification system feeds customer identity information into the identity identification engine through technical means such as the list database, risk database, search engine, risk relationship map, and third-party risk identification interface. It matches various customer information elements with risk data, issues alerts for close, similar, and related customer information, and enters the manual approval process, where the audit specialist further manually approves and confirms whether the alert information is false.
[0063] To improve the recognition capability of the identity recognition system, technical personnel have enhanced the effectiveness and accuracy of risk data, improved the recognition capability of the identity recognition system, connected to more functional departments and third-party identity recognition interfaces, combined multiple systems for identification, and made comprehensive judgments on alarm records, thereby reducing alarms to a certain extent. However, they still face the problems of numerous abnormal indicators, inability to unify indicator weights, and a large amount of weak alarm information that makes it difficult for auditors to distinguish.
[0064] To address the problem of excessive alerts in customer identity verification systems and reduce false alarm rates, currently widely used methods include supervised random forests and multi-layer neural networks. These methods label alert samples, fit the sample data, and then classify newly generated alert records as true or false. These false alarm reduction methods face challenges such as requiring large amounts of labeled sample data, high labeling and maintenance costs, high risk of overfitting, overly complex models that make predictions difficult to interpret, and an inability to identify unknown anomaly alerts.
[0065] In view of the above problems, embodiments of the present invention provide a method, apparatus and computer device for analyzing alarm information, which are used to solve the problem of heavy workload and low efficiency in the prior art of manually reviewing alarm information.
[0066] The following describes the alarm information analysis method, device and computer equipment provided by the exemplary embodiment of the present application in combination with the application scenarios described above and with reference to the accompanying drawings. It should be noted that the above application scenarios are only shown to facilitate understanding of the spirit and principles of the present application, and the implementation methods of the present application are not limited in this respect.
[0067] like Figure 1 FIG. 1 is a flow chart of a method for analyzing alarm information provided by an embodiment of the present invention, the method comprising:
[0068] Step 101: Compare the comprehensive score of the alarm information with a first threshold, and determine whether the alarm information is the first abnormal alarm information or the second abnormal alarm information based on the comparison result and the risk type of the alarm information;
[0069] Step 102: If the alarm information is the first abnormal alarm information, determine that the first abnormal alarm information is false alarm information according to the alarm elements and alarm trigger type of the first abnormal alarm information;
[0070] Step 103: If the alarm information is the second abnormal alarm information, the customer characteristics of the second alarm information are expanded, and the expanded customer characteristics are deeply analyzed to determine that the second abnormal alarm information is false alarm information, wherein the customer characteristics include basic characteristics and / or behavioral characteristics.
[0071] The present invention discloses a method for analyzing alarm information. First, the comprehensive score of the alarm information is compared with a first threshold value. According to the comparison result and the risk type of the alarm information, the alarm information is determined to be the first abnormal alarm information or the second abnormal alarm information. Then, if the alarm information is the first abnormal alarm information, the first abnormal alarm information is determined to be a false alarm information according to the alarm elements and alarm trigger type of the first abnormal alarm information. If the alarm information is the second abnormal alarm information, the second alarm information is expanded with customer characteristics, and the expanded customer characteristics are deeply analyzed to determine that the second abnormal alarm information is a false alarm information, wherein the customer characteristics include basic characteristics and / or behavioral characteristics. By the above method, the alarm information issued by the system is further filtered out to obtain abnormal alarm information, and false alarm information is filtered out from the abnormal alarm information, thereby reducing the workload of manual review and improving work efficiency.
[0072] like Figure 2 FIG. 1 is a schematic diagram of a specific process of an alarm information analysis method provided by an embodiment of the present invention, the method comprising:
[0073] Step 201: Obtain alarm information;
[0074] Specifically, the alarm information may include alarm elements, alarm characteristics, alarm trigger type, comprehensive score, characteristic score, risk type and other information.
[0075] Among them, risk types may include high risk, medium-high risk, medium risk, medium-low risk and low risk.
[0076] Step 202: determine whether the comprehensive score of the warning information is greater than or equal to a first threshold. If so, execute step 203; if not, execute step 204;
[0077] Step 203: Determine that the warning information of the first risk type is the first abnormal warning information, and execute step 205;
[0078] Specifically, the first risk type may include high / medium-high / medium risk. If the comprehensive score of the alarm information is greater than or equal to the first threshold and the risk type is the first risk type, the alarm information is determined to be first abnormal alarm information, that is, alarm information with a potential false alarm risk;
[0079] Step 204: Determine that the warning information of the second risk type is the second abnormal warning information, and execute step 211;
[0080] Specifically, the second risk type may include medium-low / low risk. If the comprehensive score of the alarm information is less than the first threshold and the risk type is the second risk type, the alarm information is determined to be second abnormal alarm information, that is, alarm information with a hidden danger of underreporting;
[0081] Step 205: Determine whether the first abnormal alarm information is a single-factor alarm information or a multi-factor alarm information. If it is a single-factor alarm information, execute step 206; if it is a multi-factor alarm information, execute step 207.
[0082] Specifically, as shown in Table 1, the alarm elements may include the legal name, social unified credit code, name of the legal representative, ID number of the legal representative, name of the actual controller (natural person), ID number of the actual controller (natural person), name of the actual controlling shareholder enterprise, social unified credit code of the actual controlling shareholder enterprise, name of the beneficiary, ID number of the beneficiary, name of the authorized representative, ID number of the authorized representative, etc., among which, if the alarm information includes only one alarm element, the alarm information is single-element alarm information; if the alarm information includes two or more alarm elements, the alarm information is multi-element alarm information.
[0083]
[0084]
[0085]
[0086] Table 1
[0087] Step 206: determine whether the alarm trigger type corresponding to the alarm element completely matches the alarm trigger type corresponding to the element of the historical false alarm information. If so, execute step 214; if not, execute step 211;
[0088] Step 207: Calculate a similar hash value based on the alarm trigger type corresponding to each alarm element and the alarm trigger type of historical false alarm information, and then execute step 208;
[0089] It should be noted that in the above embodiment, if there is a single element in the alarm information that completely matches the alarm element in the historical false alarm information, but the alarm trigger type is an unknown trigger type, for example, the alarm information to be analyzed contains a social unified credit code, and the trigger type is the first 9-17 digits or 1-18 digits of the social unified credit code, which is not within the range of known alarm trigger types shown in Table 1, the alarm information analysis will no longer be continued for this alarm information, and it will be determined that the alarm information is a real alarm.
[0090] Step 208, determining whether the similar hash value is less than a second threshold, if so, executing step 209, if not, executing step 216;
[0091] In a specific implementation, the second threshold can be determined according to actual conditions, for example, it can be 0.95;
[0092] It should be noted that the above embodiment calculates a similar hash value according to the alarm trigger type corresponding to each alarm element and the alarm trigger type of historical false alarm information through the similar hash SimHash algorithm.
[0093] Step 209: determine whether the feature score of each alarm element in the alarm information is lower than the third threshold. If so, execute step 210; if not, execute step 216;
[0094] In a specific implementation, only key alarm factors may be selected first, and then a determination may be made as to whether the characteristic score of each key alarm factor is below a third threshold. For example, key alarm factors may include the characteristic score of a social unified credit code. The selection of key alarm factors may be based on a preset key alarm factor table. Specifically, the alarm factors in the multi-factor alarm information are selected from the alarm factors in the key alarm factor table as the key alarm factors corresponding to the alarm information.
[0095] Step 210: determine whether the alarm trigger type corresponding to each alarm element in the alarm information is a determined normal alarm trigger type. If so, execute step 215; if not, execute step 211;
[0096] It should be noted that the normal alarm trigger type in the embodiment of the present invention may be an alarm whitelist, which may include normal behaviors, legal programs, and other contents, as well as trigger types that have been confirmed to be ignorable.
[0097] Step 211, expand the customer characteristics of the alarm information and execute step 212;
[0098] Specifically, customer characteristics may include basic characteristics and real-time behavioral characteristics. The basic characteristics of a customer may include the customer's industry, the location of the customer's ID number, age, account opening location, registered capital, account opening method, etc. Such customer static characteristics are calculated by an offline computing engine.
[0099] Customer real-time behavioral characteristics may include the alarm time period, Internet Protocol (IP) city, IP country, location information, transaction type, transaction method, counterparty city, etc. Such dynamic characteristics are used to analyze customer activity intensity and geographical distribution.
[0100] It should be noted that the second abnormality alarm information in the embodiment of the present invention is an alarm information with relatively few customer features, so it is necessary to expand the customer features. When expanding the customer features, they can be obtained from a third party. Specifically, the acquisition method can be to send a request corresponding to the identifier of the second abnormality alarm information to the third-party server. After receiving the request, the third-party server searches for the customer features corresponding to the identifier based on the identifier carried in the request and returns the found customer features.
[0101] Step 212: Perform an in-depth analysis of the customer characteristics of the alarm information and output a false probability value, and then proceed to step 213;
[0102] Specifically, the in-depth analysis of customer characteristics of the alarm information can be performed based on the distribution of alarms, including alarm characteristics, basic customer characteristics, and real-time customer characteristics. The alarm information is analyzed and features are extracted, and then combined. Principal Component Analysis (PCA) is used to reduce the dimensionality of high-dimensional data, extracting the main characteristic components of the data. These numerous features are then orthogonally transformed to transform them into linearly uncorrelated components while preserving the original characteristic information to the greatest extent possible. The characteristic vectors of the leading main dimensions are then determined as the characteristic parameters of the clustering model.
[0103] The process of calculating the false probability value can be as follows: after an in-depth analysis of the customer characteristics, perform expectation maximization (EM) parameter estimation, perform parameter estimation on each Gaussian component of the Gaussian Mixed Model (GMM), set two clustering target categories for true and false alarms, and specify parameters such as the stopping threshold and the number of iterations. Calculate the expected value of the hidden variable of each alarm record, and solve the maximum likelihood estimate to obtain the mean and variance after convergence to obtain the GMM. The specific process refers to (Formula 1-3). The largest training result in (Formula 1-2) is used as the model parameter, and the alarm features of the alarm record are processed by dimensionality reduction and normalization, and then imported into the GMM model to obtain the labels and corresponding probability values of the true alarms and false alarms of each record, and compare them with the set threshold to obtain true alarms and false alarms. The true and false alarm modeling results are as follows: Figure 3a As shown, the probability values of true and false alarms can be obtained at the same time, such as Figure 3b shown.
[0104] It should be noted that the GMM used in the embodiment of the present invention is a multivariate distribution function. By weighting any number of Gaussian models, the probability density distribution of samples of any distribution is estimated. One or more Gaussian models represent a class. It can not only provide a smooth fit for a given distribution, but also provide the parameters and weights of each Gaussian model. The Gaussian mixture model uses multiple Gaussian density functions to fit the actual data, maps the data in the alarm sample onto each Gaussian distribution, derives the probability of each class, and selects the class with the highest probability as the class of the sample. Assuming there are M Gaussian distributions in total, the Gaussian mixture distribution model is:
[0105]
[0106] Among them, M is the number of Gaussian distributions, α j is the weight coefficient of the jth Gaussian distribution, x j For each identity recognition abnormality alarm record, μ j is the mean, ∑ i is the covariance matrix, N j (x j ;μ j ,∑ j ) is the j-th Gaussian distribution:
[0107]
[0108] j represents the order of the Gaussian mixture model, Γ represents the training feature dimension, (x-μ j ) represents the probability density function of the j-th Gaussian distribution,
[0109] For solving the weight coefficient α of Gaussian distribution j , mean μ j , covariance matrix ∑ i , all parameters of GMM are estimated through the sample data set x. The total probability of N alarm data can be expressed as the product of the probability of each alarm data, which is the likelihood function. Thus, the likelihood function is constructed for the alarm sample X:
[0110]
[0111] Where N is the number of alarm samples, and the probability density function is used to indicate whether a monitoring parameter has undergone a substantial change. Since Equation (1-2) cannot be solved analytically using maximum likelihood estimation, it can only be solved using an iterative method. Here, the EM algorithm is used for parameter estimation.
[0112] In addition, the EM algorithm in the embodiment of the present invention first obtains the expected result through expectation estimation, and then solves the parameter value by maximizing the expectation. The specific process is as follows:
[0113] (1) Initialization: The covariance matrix ∑0 is set to the identity matrix, and the prior probability of each model proportion is The mean υ0 is set to a random number.
[0114] (2) Expected estimation step: Let α j The posterior probability is:
[0115]
[0116] (3) Expectation maximization step:
[0117] Construct Lagrange multipliers:
[0118]
[0119] Update the blending weights:
[0120] Update the mean:
[0121] Update the covariance matrix:
[0122] (4) Convergence conditions:
[0123] Check the convergence of the likelihood function of formula (1-2), repeatedly iterate the above steps (2) and (3), and repeatedly update the weight α j , mean μ j , covariance matrix Σ j, until the convergence criterion p(X|Φ)-p(X|Φ)′<ε is met, which is the value calculated after the parameter update. The iteration is terminated when the difference between the results of the previous and next two iterations is less than a certain value.
[0124] The Gaussian mixture model transforms density estimation into a maximum likelihood estimation problem by assuming that the distribution to be estimated comes from a Gaussian mixture distribution with a fixed number of fractions, thus reducing the parameters of the model and the space complexity.
[0125] This method analyzes the alarm records of the identity recognition system to mine their characteristics. Combining these characteristics with static basic features and real-time behavioral characteristics, it normalizes and reduces the dimensionality of these multidimensional features, constructs a Gaussian mixture model, and performs further identification and learning. This significantly reduces alarm records, approval errors, and labor costs without increasing the false alarm rate. Furthermore, this method eliminates the need to mark true and false alarm records and does not rely excessively on the personal experience of business experts.
[0126] Step 213 , determining whether the false probability value is less than a fourth threshold value, if so, executing step 215 , if not, executing step 216 .
[0127] Step 214 , determining whether the feature score of each alarm element in the alarm information is lower than the fifth threshold; if so, executing step 211 ; if not, executing step 216 .
[0128] Step 215, determining that the warning information is a false warning information;
[0129] Specifically, after determining that the alarm information is false alarm information, it is manually confirmed and recorded in the false alarm information database as historical false alarm information.
[0130] Step 216, determining that the warning information is real warning information;
[0131] Specifically, after determining that the alarm information is real alarm information, the alarm information is manually reviewed.
[0132] The various thresholds in the embodiments of the present invention are preset thresholds and can be determined according to actual conditions.
[0133] In addition, the collection, dissemination, and use of data in the technical solution of this application comply with relevant national laws and regulations.
[0134] Based on the same inventive concept, an embodiment of the present invention also provides an analysis device for alarm information. Figure 4 FIG. 1 is a schematic diagram of a structure of an alarm information analysis device provided by an embodiment of the present invention, the device comprising:
[0135] A first determination module 401 compares the comprehensive score of the alarm information with a first threshold, and determines whether the alarm information is first abnormal alarm information or second abnormal alarm information based on the comparison result and the risk type of the alarm information;
[0136] A second determining module 402 is configured to, if the alarm information is the first abnormal alarm information, determine, based on the alarm elements and alarm trigger type of the first abnormal alarm information, that the first abnormal alarm information is false alarm information;
[0137] The third determination module 403 is used to expand the customer characteristics of the second alarm information if the alarm information is the second abnormal alarm information, and conduct an in-depth analysis of the expanded customer characteristics to determine that the second abnormal alarm information is false alarm information, wherein the customer characteristics include basic characteristics and / or behavioral characteristics.
[0138] like Figure 5 , which is a schematic diagram of a specific structure of an alarm information analysis device provided by an embodiment of the present invention, the device includes: a first determination module 401 , a second determination module 402 and a third determination module 403 .
[0139] Optionally, the first determining module 401 includes:
[0140] A first determining submodule 501 is configured to determine that the comprehensive score is greater than or equal to the first threshold, and the warning information of the risk type being the first risk type is the first abnormal warning information;
[0141] The second determining submodule 502 is configured to determine that the comprehensive score is less than the first threshold, and the alarm information of the risk type being the second risk type is the second abnormal alarm information.
[0142] Optionally, the second determining module 402 includes:
[0143] a single element determination module 503 configured to determine that the first abnormal alarm information is false alarm information if the alarm element is a single element and the alarm trigger type corresponding to the alarm element completely matches the alarm trigger type corresponding to the element of the historical false alarm information;
[0144] The multi-factor determination module 504 is used to calculate a similar hash value according to the alarm trigger type corresponding to each alarm factor and the alarm trigger type of historical false alarm information if the alarm factor is multi-factor, and determine that the first abnormal alarm information is false alarm information according to the similar hash value.
[0145] Optionally, the multi-factor determination module 504 includes:
[0146] A first multi-factor determination submodule 5041 is configured to determine that the first abnormality alarm information is false alarm information if the similarity hash value is greater than or equal to a second threshold;
[0147] The second multi-factor determination submodule 5042 is used to determine that the first abnormal alarm information is false alarm information based on the feature score of each alarm factor, the normal alarm trigger type and the customer characteristics corresponding to the first abnormal alarm information if the similar hash value is less than the second threshold.
[0148] Optionally, the second multi-factor determination submodule 5042 includes:
[0149] The second multi-factor determination sub-unit 50421 is used to conduct an in-depth analysis of the customer characteristics of the first abnormal alarm information and determine that the first abnormal alarm information is false alarm information if the feature score of any alarm element in each alarm element is higher than the third threshold and the alarm trigger type corresponding to any alarm element in each alarm element does not belong to the normal alarm trigger type.
[0150] Optionally, the device further includes:
[0151] Parameter estimation module 505, used to perform expectation maximization (EM) parameter estimation after in-depth analysis of customer characteristics;
[0152] The probability calculation module 506 is used to input the EM parameter estimation results into the Gaussian mixture model to obtain a false probability value;
[0153] The fourth determining module 507 is configured to determine whether the first abnormal alarm information or the second abnormal alarm information having a false probability value less than a fourth threshold is false alarm information.
[0154] Based on the same inventive concept, an embodiment of the present invention further provides a computer device. The computer device can implement the above-mentioned embodiment. Figure 1 The flow of the method being executed.
[0155] like Figure 6 6 is a schematic diagram of the structure of a computer device provided in an embodiment of the present invention, wherein the computer device includes a processor 601, a memory 602, and a transceiver 603;
[0156] The processor 601 is responsible for managing the bus architecture and general processing, and the memory 602 can store data used by the processor 601 when performing operations. The transceiver 603 is used to receive and send data under the control of the processor 601.
[0157] The bus architecture can include any number of interconnected buses and bridges, specifically linking various circuits such as one or more processors represented by processor 601 and memory represented by memory 602. The bus architecture can also link various other circuits such as peripherals, voltage regulators, and power management circuits, all of which are well known in the art and are not further described herein. Bus interface 604 provides the interface. Processor 601 is responsible for managing the bus architecture and general processing, while memory 602 can store data used by processor 601 when performing operations.
[0158] The processes disclosed in the embodiments of this application can be applied to or implemented by processor 601. During implementation, each step of the signal processing process can be completed by hardware integrated logic circuits or software instructions in processor 601. Processor 601 can be a general-purpose processor, a digital signal processor, an application-specific integrated circuit, a field-programmable gate array or other programmable logic device, a discrete gate or transistor logic device, or a discrete hardware component, and can implement or execute the various methods, steps, and logic block diagrams disclosed in the embodiments of this application. A general-purpose processor can be a microprocessor or any conventional processor. The steps of the methods disclosed in the embodiments of this application can be directly implemented and executed by a hardware processor, or by a combination of hardware and software modules in the processor. The software modules can be located in a storage medium well-known in the art, such as random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, registers, etc. The storage medium is located in memory 602, and processor 601 reads the information in memory 602 and, in conjunction with its hardware, completes the steps of the signal processing process.
[0159] Specifically, the processor 601 is configured to read the program in the memory 602 and execute:
[0160] Comparing the comprehensive score of the alarm information with a first threshold, and determining whether the alarm information is first abnormal alarm information or second abnormal alarm information based on the comparison result and the risk type of the alarm information;
[0161] If the alarm information is the first abnormal alarm information, determining that the first abnormal alarm information is false alarm information according to the alarm element and the alarm trigger type of the first abnormal alarm information;
[0162] If the alarm information is the second abnormal alarm information, the customer characteristics of the second alarm information are expanded, and the expanded customer characteristics are deeply analyzed to determine that the second abnormal alarm information is false alarm information, wherein the customer characteristics include basic characteristics and / or behavioral characteristics.
[0163] Optionally, the processor 601 is specifically configured to:
[0164] Determining that the comprehensive score is greater than or equal to the first threshold and the warning information of the risk type being the first risk type is the first abnormal warning information;
[0165] It is determined that the comprehensive score is less than the first threshold, and the alarm information that the risk type is the second risk type is the second abnormal alarm information.
[0166] Optionally, the processor 601 is specifically configured to:
[0167] If the alarm element is a single element, and the alarm trigger type corresponding to the alarm element completely matches the alarm trigger type corresponding to the element of the historical false alarm information, then determining that the first abnormal alarm information is false alarm information;
[0168] If the alarm element is multiple elements, a similar hash value is calculated according to the alarm trigger type corresponding to each alarm element and the alarm trigger type of historical false alarm information, and the first abnormal alarm information is determined to be false alarm information according to the similar hash value.
[0169] Optionally, the processor 601 is specifically configured to:
[0170] If the similar hash value is greater than or equal to a second threshold, determining that the first abnormal alarm information is false alarm information;
[0171] If the similar hash value is less than the second threshold, the first abnormal alarm information is determined to be false alarm information based on the feature score of each alarm element, the normal alarm trigger type and the customer feature corresponding to the first abnormal alarm information.
[0172] Optionally, the processor 601 is specifically configured to:
[0173] If the feature score of any alarm element in each of the alarm elements is higher than the third threshold, and the alarm trigger type corresponding to any alarm element in each of the alarm elements does not belong to the normal alarm trigger type, then an in-depth analysis is performed on the customer characteristics of the first abnormal alarm information to determine that the first abnormal alarm information is false alarm information.
[0174] Optionally, the processor 601 is further configured to:
[0175] After in-depth analysis of the customer characteristics, perform Expectation Maximization (EM) parameter estimation;
[0176] The EM parameter estimation results are input into the Gaussian mixture model to obtain the false probability value;
[0177] Determine the first abnormal alarm information or the second abnormal alarm information whose false probability value is less than a fourth threshold as the false alarm information.
[0178] The present embodiment of the present application also provides a computer-readable storage medium for the alarm information analysis method, i.e., the content is not lost after a power outage. The storage medium stores a software program, including program code. When the program code is executed on a computing device, the software program, when read and executed by one or more processors, can implement any of the above-mentioned alarm information analysis methods of the present embodiment.
[0179] In some possible implementations, various aspects of the alarm information analysis method provided in the present application can also be implemented in the form of a program product, which includes program code. When the program product is run on a computer device, the program code is used to enable the computer device to execute the steps of the alarm information analysis method according to various exemplary embodiments of the present application described above in this specification.
[0180] The present invention discloses a method, apparatus, and computer device for analyzing alarm information. First, the comprehensive score of the alarm information is compared with a first threshold value. Alarm information with a comprehensive score greater than or equal to the first threshold value and a risk type of the first risk type is determined to be first abnormal alarm information, i.e., alarm information with a hidden danger of false alarm. Alarm information with a comprehensive score less than the first threshold value and a risk type of the second risk type is determined to be second abnormal alarm information, i.e., alarm information with a hidden danger of missed alarm.
[0181] For the first abnormal alarm information, if its alarm element is a single element, and the alarm trigger type corresponding to the alarm element completely matches the alarm trigger type corresponding to the element of the historical false alarm information, then the first abnormal alarm information is determined to be false alarm information; if its alarm element is multiple elements, then according to the alarm trigger type corresponding to each alarm element and the alarm trigger type of the historical false alarm information, a similarity hash value is calculated, and the first abnormal alarm information is determined to be false alarm information based on the similarity hash value. If the similarity hash value is greater than or equal to the second threshold, then the first abnormal alarm information is determined to be false alarm information; if the similarity hash value is less than the second threshold, and the feature score of any alarm element is higher than the third threshold, and the alarm trigger type corresponding to any alarm element does not belong to the normal alarm trigger type, then an in-depth analysis of the customer characteristics of the first abnormal alarm information is performed;
[0182] Expanding customer characteristics for the second abnormal alarm information and conducting in-depth analysis on the expanded customer characteristics;
[0183] After conducting an in-depth analysis of the customer characteristics of the first or second abnormal alarm information, EM parameter estimation is performed; the EM parameter estimation results are input into a Gaussian mixture model to obtain a false probability value; and the first or second abnormal alarm information with a false probability value less than a fourth threshold is determined to be a false alarm information. This method repeatedly confirms and analyzes the alarm information issued by the system, distinguishing false alarm information from the alarm information, thereby reducing the false alarm rate.
[0184] The present application is described above with reference to block diagrams and / or flow charts illustrating methods, apparatus (systems) and / or computer program products according to embodiments of the present application. It should be understood that a block of a block diagram and / or flow chart, as well as a combination of blocks of a block diagram and / or flow chart, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer and / or other programmable data processing device to produce a machine such that instructions executed by the computer processor and / or other programmable data processing device create a method for implementing the functions / actions specified in the block diagram and / or flow chart block.
[0185] Accordingly, the present application may also be implemented using hardware and / or software (including firmware, resident software, microcode, etc.). Furthermore, the present application may take the form of a computer program product on a computer-usable or computer-readable storage medium having computer-usable or computer-readable program code embodied in the medium for use by or in conjunction with an instruction execution system. In the context of the present application, a computer-usable or computer-readable medium may be any medium that can contain, store, communicate, transmit, or convey a program for use by or in conjunction with an instruction execution system, apparatus, or device.
[0186] Obviously, those skilled in the art may make various changes and modifications to the present invention without departing from the spirit and scope of the present invention. Thus, if such changes and modifications fall within the scope of the claims and their equivalents, the present invention is intended to include such changes and modifications.
Claims
1. A method for analyzing alarm information, characterized in that: The method includes: Comparing the comprehensive score of the alarm information with a first threshold, and determining whether the alarm information is first abnormal alarm information or second abnormal alarm information based on the comparison result and the risk type of the alarm information; If the alarm information is the first abnormal alarm information, determining that the first abnormal alarm information is false alarm information according to the alarm element and the alarm trigger type of the first abnormal alarm information; If the alarm information is the second abnormal alarm information, expanding the second abnormal alarm information with customer characteristics, and performing in-depth analysis on the expanded customer characteristics to determine that the second abnormal alarm information is false alarm information, wherein the customer characteristics include basic characteristics and / or behavioral characteristics; After in-depth analysis of the customer characteristics, perform expectation maximization (EM) parameter estimation; The EM parameter estimation results are input into the Gaussian mixture model to obtain the false probability value; The first abnormal alarm information or the second abnormal alarm information whose false probability value is less than a fourth threshold is determined to be the false alarm information.
2. The method according to claim 1, wherein The comparing the comprehensive score of the alarm information with the first threshold, and determining whether the alarm information is the first abnormal alarm information or the second abnormal alarm information according to the comparison result and the risk type of the alarm information, includes: Determining that the comprehensive score is greater than or equal to the first threshold and the warning information of the risk type being the first risk type is the first abnormal warning information; It is determined that the comprehensive score is less than the first threshold and the alarm information that the risk type is the second risk type is the second abnormal alarm information.
3. The method according to claim 1, wherein The determining, based on the alarm element and the alarm trigger type of the first abnormal alarm information, that the first abnormal alarm information is false alarm information includes: If the alarm element is a single element, and the alarm trigger type corresponding to the alarm element completely matches the alarm trigger type corresponding to the element of the historical false alarm information, then determining that the first abnormal alarm information is false alarm information; If the alarm element is multiple elements, a similar hash value is calculated according to the alarm trigger type corresponding to each alarm element and the alarm trigger type of historical false alarm information, and the first abnormal alarm information is determined to be false alarm information according to the similar hash value.
4. The method according to claim 3, wherein The determining, according to the similar hash value, that the first abnormality alarm information is false alarm information includes: If the similar hash value is greater than or equal to a second threshold, determining that the first abnormal alarm information is false alarm information; If the similar hash value is less than the second threshold, the first abnormal alarm information is determined to be false alarm information based on the feature score of each alarm element, the normal alarm trigger type and the customer feature corresponding to the first abnormal alarm information.
5. The method according to claim 4, wherein The determining that the first abnormal alarm information is false alarm information according to the feature score of each alarm element, the normal alarm trigger type, and the customer feature corresponding to the first abnormal alarm information includes: If the feature score of any alarm element in each of the alarm elements is higher than the third threshold, and the alarm trigger type corresponding to any alarm element in each of the alarm elements does not belong to the normal alarm trigger type, then an in-depth analysis is performed on the customer characteristics of the first abnormal alarm information to determine that the first abnormal alarm information is false alarm information.
6. An analysis device for alarm information, characterized in that: The device includes: a first determination module, comparing the comprehensive score of the alarm information with a first threshold, and determining whether the alarm information is first abnormal alarm information or second abnormal alarm information based on the comparison result and the risk type of the alarm information; a second determining module, configured to, if the alarm information is the first abnormal alarm information, determine, based on the alarm elements and the alarm trigger type of the first abnormal alarm information, that the first abnormal alarm information is false alarm information; a third determination module, configured to, if the alarm information is the second abnormal alarm information, expand the second abnormal alarm information with customer characteristics, and perform in-depth analysis on the expanded customer characteristics to determine that the second abnormal alarm information is false alarm information, wherein the customer characteristics include basic characteristics and / or behavioral characteristics; A parameter estimation module is used to perform expectation maximization (EM) parameter estimation after in-depth analysis of the customer characteristics; The probability calculation module is used to input the EM parameter estimation results into the Gaussian mixture model to obtain the false probability value; The fourth determining module is configured to determine that the first abnormal alarm information or the second abnormal alarm information whose false probability value is less than a fourth threshold is the false alarm information.
7. The device according to claim 6, characterized in that The first determining module includes: A first determining submodule is configured to determine that the comprehensive score is greater than or equal to the first threshold, and the warning information of the risk type being the first risk type is the first abnormal warning information; The second determining submodule is configured to determine that the comprehensive score is less than the first threshold value, and the alarm information of the risk type being the second risk type is the second abnormal alarm information.
8. The device according to claim 6, wherein The second determining module includes: a single element determination module, configured to determine that the first abnormal alarm information is false alarm information if the alarm element is a single element and the alarm trigger type corresponding to the alarm element completely matches the alarm trigger type corresponding to the element of the historical false alarm information; A multi-factor determination module is used to calculate a similar hash value based on the alarm trigger type corresponding to each alarm factor and the alarm trigger type of historical false alarm information if the alarm factor is multi-factor, and determine that the first abnormal alarm information is false alarm information based on the similar hash value.
9. The device according to claim 8, wherein The multi-factor determination module includes: a first multi-factor determination submodule, configured to determine that the first abnormal alarm information is false alarm information if the similarity hash value is greater than or equal to a second threshold; The second multi-factor determination submodule is used to determine that the first abnormal alarm information is false alarm information based on the feature score of each alarm element, the normal alarm trigger type and the customer characteristics corresponding to the first abnormal alarm information if the similar hash value is less than the second threshold.
10. The device according to claim 9, wherein The second multi-factor determination submodule includes: The second multi-factor determination sub-unit is used to conduct an in-depth analysis of the customer characteristics of the first abnormal alarm information if the feature score of any alarm element in each of the alarm elements is higher than a third threshold, and the alarm trigger type corresponding to any alarm element in each of the alarm elements does not belong to the normal alarm trigger type, and determine that the first abnormal alarm information is false alarm information.
11. A computer device, characterized in that: include: memory, transceivers, and processors; The memory is used to store computer instructions; The transceiver is used to send and receive data under the control of the processor; The processor is configured to read the computer program in the memory and execute the following steps: Comparing the comprehensive score of the alarm information with a first threshold, and determining whether the alarm information is first abnormal alarm information or second abnormal alarm information based on the comparison result and the risk type of the alarm information; If the alarm information is the first abnormal alarm information, determining that the first abnormal alarm information is false alarm information according to the alarm element and the alarm trigger type of the first abnormal alarm information; If the alarm information is the second abnormal alarm information, expanding the second abnormal alarm information with customer characteristics, and performing in-depth analysis on the expanded customer characteristics to determine that the second abnormal alarm information is false alarm information, wherein the customer characteristics include basic characteristics and / or behavioral characteristics; After in-depth analysis of the customer characteristics, perform expectation maximization (EM) parameter estimation; The EM parameter estimation results are input into the Gaussian mixture model to obtain the false probability value; The first abnormal alarm information or the second abnormal alarm information whose false probability value is less than a fourth threshold is determined to be the false alarm information.
12. A computer-readable storage medium, characterized in that The storage medium stores computer instructions, and when the computer instructions are executed by a processor, the method according to any one of claims 1 to 5 is implemented.
13. A computer program product, characterized in that The method comprises computer-executable instructions for causing a computer to execute the method according to any one of claims 1 to 5.
Citation Information
Patent Citations
False alarm information identification method and device, storage medium and electronic terminal
CN109379228A
Analysis method, system and equipment for gross profit abnormity reason of order, and storage medium
CN110503477A