Model training method, method for predicting trading risks, device, equipment and medium

By clustering and classification models of historical transaction data sets, the problem of sample imbalance in model training is solved, and the accuracy and recall rate of transaction risk prediction are improved.

CN114462532BActive Publication Date: 2025-06-17INDUSTRIAL AND COMMERCIAL BANK OF CHINA
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210115648.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-02-07
Publication Date
2025-06-17
Estimated Expiration
2042-02-07

AI Technical Summary

Technical Problem

During the model training process, there is an imbalance in the sample data, which makes it impossible to predict transaction risks more accurately.

Method used

By obtaining the historical transaction data set generated within the preset time interval, clustering it to divide it into multiple clusters, determining a new data set from it, and using the classification model to update the transaction label, forming a training data set, and finally training a model for predicting transaction risks.

Benefits of technology

It effectively alleviates the problem of sample imbalance, narrows the proportion gap between normal trading data and abnormal trading data, and retains the distribution characteristics of normal trading data, improving the prediction accuracy and recall rate of the model.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114462532B_ABST
    Figure CN114462532B_ABST
Patent Text Reader

Abstract

The present disclosure provides a model training method, which can be applied to the field of artificial intelligence technology. The model training method includes: obtaining a first target historical transaction data set generated within a preset time interval, where the first target historical transaction data set includes a normal transaction data set and an abnormal transaction data set, and the normal transaction data set and the abnormal transaction data set carry transaction labels; clustering the normal transaction data set in the first target historical transaction data set to obtain a plurality of clusters; determining a second target historical transaction data set from the plurality of clusters; using a classification model to update the transaction labels carried by the second target historical transaction data set and the abnormal transaction data set to obtain a training data set; and training a model to be trained based on the training data set to obtain a model for predicting transaction risks. The present disclosure also provides a method, apparatus, device, storage medium, and program product for predicting transaction risks.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the field of artificial intelligence, and particularly to a model training method, a method for predicting trading risks, an apparatus, a device, a medium, and a program product. Background Art

[0002] With the development of society and technology, information sharing and resource sharing are the requirements of the development of the times. As an important part of social development, Internet transactions play a crucial role. With the development of the Internet, the number of trading channels has been increasing continuously, and the trading situation has become increasingly complex and cumbersome. The business scope of transactions in various industries is getting wider and wider, and there is a possibility of fraud in each link, so it is necessary to control trading risks.

[0003] However, in the process of implementing the present disclosure, it is found that when training a model by obtaining sample data, there is an imbalance problem in the sample data, resulting in an inability to accurately predict trading risks. Summary of the Invention

[0004] In view of the above problems, the present disclosure provides a model training method, a method for predicting trading risks, an apparatus, a device, a medium, and a program product.

[0005] According to a first aspect of the present disclosure, there is provided a model training method, including: obtaining a first target historical transaction data set generated within a preset time interval, where the first target historical transaction data set includes a normal transaction data set and an abnormal transaction data set, and the normal transaction data set and the abnormal transaction data set carry transaction labels;

[0006] Clustering the normal transaction data set in the first target historical transaction data set to obtain a plurality of clusters;

[0007] Determining a second target historical transaction data set from the plurality of clusters;

[0008] Using a classification model to update the transaction labels carried by the second target historical transaction data set and the abnormal transaction data set to obtain a training data set; and

[0009] Training a model to be trained based on the training data set to obtain a model for predicting trading risks.

[0010] According to an embodiment of the present disclosure, using a classification model to update the transaction labels carried by the second target historical transaction data set and the abnormal transaction data set to obtain a training data set includes:

[0011] Inputting the second target historical transaction data set and the abnormal transaction data set into the classification model to obtain a classification result;

[0012] Using the classification result and the transaction label to determine the error rate of the classification model;

[0013] Calculate the voting weights of the classification model based on the error rate;

[0014] Based on the voting weights, update the transaction labels to obtain the training data set.

[0015] According to an embodiment of the present disclosure, determining the second target historical transaction data set from multiple clusters includes:

[0016] Screen the data in each cluster respectively to obtain the second target historical transaction data set, where the screening includes screening centered on each cluster.

[0017] According to an embodiment of the present disclosure, obtaining the first target historical transaction data set generated within a preset time interval includes:

[0018] Obtain the normal transaction data set and the abnormal transaction data set generated within the preset time interval to obtain the initial historical data;

[0019] Preprocess the initial historical data to obtain the first target historical transaction data set.

[0020] According to an embodiment of the present disclosure, the normal transaction data set and the abnormal transaction data set further include: transaction basic information and transaction account information.

[0021] According to an embodiment of the present disclosure, training the model to be trained based on the training data set to obtain a model for predicting transaction risks includes:

[0022] Input the training data set into the model to be trained and output the training result;

[0023] Based on the training result and the updated transaction labels, adjust the parameters of the model to be trained to obtain a trained model for predicting transaction risks.

[0024] According to an embodiment of the present disclosure, before obtaining the first target historical transaction data set generated within a preset time interval, it further includes:

[0025] Obtain the authorization of the user for the first target historical transaction data set;

[0026] Obtain the first target historical transaction data set after obtaining the authorization.

[0027] A second aspect of the present disclosure provides a method for predicting transaction risks, including:

[0028] Obtain the target prediction data associated with the time interval to be predicted;

[0029] Input the target prediction data into the model for predicting transaction risks; and

[0030] Output the prediction result;

[0031] Among them, the model for predicting transaction risks is trained according to the above model training method.

[0032] The third aspect of the present disclosure provides a model training device, including:

[0033] A first acquisition module, configured to acquire a first target historical transaction data set generated within a preset time interval, where the first target historical transaction data set includes a normal transaction data set and an abnormal transaction data set, and the normal transaction data set and the abnormal transaction data set carry transaction labels;

[0034] A determination module, configured to determine a second target historical transaction data set from the normal transaction data set in the first target historical transaction data set by using a preset method;

[0035] An update module, configured to update the transaction labels carried by the second target historical transaction data set and the abnormal transaction data set by using a classification model to obtain a training data set; and

[0036] A training module, configured to train a model to be trained based on the training data set to obtain a model for predicting transaction risks.

[0037] The fourth aspect of the present disclosure provides a device for predicting transaction risks, including:

[0038] A second acquisition module, configured to acquire target prediction data associated with a time interval to be predicted;

[0039] An input module, configured to input the target prediction data into the model for predicting transaction risks; and

[0040] An output module, configured to output a prediction result;

[0041] Among them, the model for predicting transaction risks is trained according to the above model training method.

[0042] The fifth aspect of the present disclosure provides an electronic device, including: one or more processors; a memory for storing one or more programs, where when the one or more programs are executed by the one or more processors, the one or more processors are caused to execute the above model training method and the method for predicting transaction risks.

[0043] The sixth aspect of the present disclosure further provides a computer-readable storage medium, on which executable instructions are stored, and when the instructions are executed by a processor, the processor is caused to execute the above model training method and the method for predicting transaction risks.

[0044] The seventh aspect of the present disclosure further provides a computer program product, including a computer program, and when the computer program is executed by a processor, the above model training method and the method for predicting transaction risks are implemented.

[0045] According to the embodiments of the present disclosure, the normal transaction data of the training samples are divided into multiple clusters through a clustering method, and then a new normal transaction data set is determined from the multiple clusters; the obtained new normal transaction data set and abnormal transaction data set are re-adjusted through the classification model to obtain a reconstructed data set after the label enhancement data; the reconstructed data set is used to retrain to obtain a model for predicting transaction risks. The sample imbalance problem in model training is effectively alleviated, and the ratio gap between normal transaction data and abnormal transaction data in the sample is narrowed. At the same time, the distribution characteristics of the samples in the normal transaction data set are retained as much as possible, so that the effect of the trained model is not affected by the change in the number of samples. Moreover, the results predicted by the trained model for predicting transaction risks can more accurately predict the fraud risks in transactions in terms of precision, recall and comprehensive evaluation values. BRIEF DESCRIPTION OF THE DRAWINGS

[0046] The above contents and other objects, features and advantages of the present disclosure will become more apparent through the following description of the embodiments of the present disclosure with reference to the accompanying drawings, in which:

[0047] Figure 1 A diagram schematically illustrates an application scenario of a model training method, a method, an apparatus, a device, a medium, and a program product for predicting transaction risks according to an embodiment of the present disclosure;

[0048] Figure 2 A flowchart of a model training method according to an embodiment of the present disclosure is schematically shown;

[0049] Figure 3 A schematic diagram of a method for clustering a normal transaction data set in a first target historical transaction data set to obtain multiple clusters according to an embodiment of the present disclosure is schematically shown;

[0050] Figure 4 A flowchart of a method for obtaining a training data set by using a classification model to update transaction labels of a second target historical transaction data set and an abnormal transaction data set according to an embodiment of the present disclosure is schematically shown;

[0051] Figure 5 A flowchart schematically shows a method for predicting transaction risks according to an embodiment of the present disclosure;

[0052] Figure 6 The structure block diagram of the model training device according to the embodiment of the present disclosure is schematically shown;

[0053] Figure 7 A block diagram schematically shows a structure of a device for predicting transaction risk according to an embodiment of the present disclosure; and

[0054] Figure 8A block diagram of an electronic device suitable for implementing a model training method and a method for predicting trading risks according to an embodiment of the present disclosure is schematically shown. Detailed implementation manners

[0055] Hereinafter, embodiments of the present disclosure will be described with reference to the accompanying drawings. However, it should be understood that these descriptions are merely exemplary and are not intended to limit the scope of the present disclosure. In the following detailed description, for the sake of explanation, many specific details are set forth to provide a thorough understanding of the embodiments of the present disclosure. However, it is obvious that one or more embodiments can also be implemented without these specific details. In addition, in the following description, descriptions of well-known structures and technologies are omitted to avoid unnecessarily obscuring the concepts of the present disclosure.

[0056] The terms used herein are merely for describing specific embodiments and are not intended to limit the present disclosure. The terms "including", "comprising", etc. used herein indicate the presence of the described features, steps, operations, and / or components, but do not exclude the presence or addition of one or more other features, steps, operations, or components.

[0057] All terms used herein (including technical and scientific terms) have the meanings commonly understood by those skilled in the art, unless otherwise defined. It should be noted that the terms used herein should be interpreted as having a meaning consistent with the context of this specification and should not be interpreted in an idealized or overly rigid manner.

[0058] In the case of using expressions such as "at least one of A, B, and C", generally, it should be interpreted according to the meaning commonly understood by those skilled in the art (for example, "a system having at least one of A, B, and C" should include, but is not limited to, a system having only A, only B, only C, having A and B, having A and C, having B and C, and / or having A, B, and C).

[0059] In the technical solution of the present disclosure, the processing of the collection, storage, use, processing, transmission, provision, disclosure, and application of the user's personal information involved all comply with the provisions of relevant laws and regulations, necessary confidentiality measures are taken, and public order and good customs are not violated.

[0060] In the technical solution of the present disclosure, before obtaining or collecting the user's personal information, the authorization or consent of the user is obtained.

[0061] In the anti-fraud scenario, machine learning and deep learning technologies can be used for modeling to control the fraud risks existing in transactions. During the modeling process, one of the most encountered technical problems is the problem of sample imbalance. It can be understood that in the dataset obtained through transaction services, the vast majority of samples should be normal samples, that is, non-fraud samples, and only a very small number of samples are negative samples, that is, fraud samples.

[0062] There are two methods to solve the problem of sample imbalance: oversampling and undersampling. Each of these two methods has its drawbacks. Oversampling essentially means repeatedly using the minority samples in the dataset, which will inevitably lead to overfitting of the trained model and affect the generalization ability in the final application. Undersampling actually randomly discards some normal samples, but this often leads to the loss of some useful information, resulting in a low accuracy of the trained model. Therefore, the embodiments of the present disclosure provide a new method for processing sample imbalance to avoid the problems described above.

[0063] The embodiments of the present disclosure provide a model training method, including: obtaining a first target historical transaction dataset generated within a preset time interval, where the first target historical transaction dataset includes a normal transaction dataset and an abnormal transaction dataset, and the normal transaction dataset and the abnormal transaction dataset carry transaction labels; clustering the normal transaction dataset in the first target historical transaction dataset to obtain multiple clusters; determining a second target historical transaction dataset from the multiple clusters; using a classification model to update the transaction labels carried by the second target historical transaction dataset and the abnormal transaction dataset to obtain a training dataset; and training a model to be trained based on the training dataset to obtain a model for predicting transaction risks.

[0064] Figure 1 The application scenario diagrams of the model training method, the method for predicting transaction risks, the device, the device, the medium, and the program product according to the embodiments of the present disclosure are schematically shown.

[0065] As Figure 1 shown, the application scenario 100 according to this embodiment may include terminal devices 101, 102, 103, a network 104, and a server 105. The network 104 is used to provide a medium for communication links between the terminal devices 101, 102, 103 and the server 105. The network 104 may include various connection types, such as wired, wireless communication links, or fiber optic cables, etc.

[0066] Users can use terminal devices 101, 102, and 103 to interact with server 105 via network 104 to receive or send messages, etc. Various communication client applications can be installed on terminal devices 101, 102, and 103, such as financial product applications, shopping applications, web browser applications, search applications, instant messaging tools, email clients, social platform software, etc. (for example only).

[0067] Terminal devices 101, 102, and 103 can be various electronic devices with a display screen and supporting web browsing, including but not limited to smartphones, tablets, laptop computers, desktop computers, and so on.

[0068] Server 105 can be a server providing various services, such as a background management server that supports the websites browsed by users using terminal devices 101, 102, and 103 (for example only). The background management server can analyze and process data such as received user requests, and feedback the processing results (such as web pages, information, or data obtained or generated according to user requests) to the terminal devices.

[0069] It should be noted that the model training method and the method for predicting trading risks provided by the embodiments of the present disclosure can generally be executed by server 105. Correspondingly, the model training device and the device for predicting trading risks provided by the embodiments of the present disclosure can generally be set in server 105. The model training method and the method for predicting trading risks provided by the embodiments of the present disclosure can also be executed by a server or a server cluster different from server 105 and capable of communicating with terminal devices 101, 102, 103 and / or server 105. Correspondingly, the model training device and the device for predicting trading risks provided by the embodiments of the present disclosure can also be set in a server or a server cluster different from server 105 and capable of communicating with terminal devices 101, 102, 103 and / or server 105.

[0070] It should be understood that Figure 1 the numbers of terminal devices, networks, and servers in

[0071] are merely illustrative. According to the implementation requirements, there can be any number of terminal devices, networks, and servers. Figure 1 the scenario described below, through Figures 2 to 5 the model training method of the disclosed embodiments will be described in detail.

[0072] Figure 2 Schematically shows a flowchart of the model training method according to an embodiment of the present disclosure.

[0073] As Figure 2As shown, the model training method 200 of this embodiment includes operations S201 to S204.

[0074] In operation S201, a first target historical transaction data set generated within a preset time interval is obtained. The first target historical transaction data set includes a normal transaction data set and an abnormal transaction data set, and the normal transaction data set and the abnormal transaction data set carry transaction labels.

[0075] According to an embodiment of the present disclosure, the preset time interval can be a past period of time selected according to actual prediction needs. Both the normal transaction data set and the abnormal transaction data set include transaction basic information and transaction account information. The transaction labels can be positive labels and negative labels. For example, the preset time interval can be, but is not limited to: the past two months, the past four months, the past six months, the past year, etc., such as from March 1, 2019 to July 31, 2019. The transaction basic information can be, for example, but is not limited to: the time of the transaction, the transaction frequency, the transaction amount, etc. The transaction account information can be, for example, the account information of each of the two parties to the transaction. The normal transaction data can carry positive labels, and the abnormal transaction data can carry negative labels.

[0076] It should be noted that before operation S201, it also includes: obtaining the user's authorization for the first target historical transaction data set; and obtaining the first target historical transaction data set after obtaining the authorization.

[0077] In operation S202, the normal transaction data set in the first target historical transaction data set is clustered to obtain a plurality of clusters.

[0078] According to an embodiment of the present disclosure, the clustering method can include, for example, the K-medoids clustering method. This clustering method replaces the commonly used K-means algorithm because the K-means algorithm has drawbacks, that is, the size difference of each category generated by the algorithm is not very large and it is very sensitive to abnormal data. Therefore, after using the K-medoids clustering method to classify the normal transaction data set, the generated clusters are closer to the classification of transaction categories in reality.

[0079] Figure 3 Schematically shows a schematic diagram of a method for clustering the normal transaction data set in the first target historical transaction data set according to an embodiment of the present disclosure to obtain a plurality of clusters.

[0080] As Figure 3 shown, by clustering the normal transaction data set in the first target historical transaction data set, a plurality of clusters are obtained.

[0081] In operation S203, a second target historical transaction data set is determined from the plurality of clusters.

[0082] According to an embodiment of the present disclosure, determining a second target historical transaction data set from multiple clusters may include: selecting a predetermined number of data from each cluster respectively to form the second target historical transaction data set. The predetermined number may be selected according to the accuracy of the actual training model, for example, it may be 1%. As Figure 3 shown, the black dots represent the second target historical transaction data, and the gray dots represent the normal transaction data other than the second target historical transaction data. It may be to select the second target historical transaction data represented by the black dots from multiple clusters to form the second target historical transaction data set.

[0083] In operation S204, using the classification model, update the transaction labels carried by the second target historical transaction data set and the abnormal transaction data set to obtain a training data set.

[0084] According to an embodiment of the present disclosure, it may be to input the second target historical transaction data set and the abnormal transaction data set into the classification model, and re-determine the transaction labels carried by the second target historical transaction data set and the abnormal transaction data set according to the classification results output by the classification model. The classification model may use the C4.5 decision tree algorithm for classification.

[0085] In operation S205, based on the training data set, train the model to be trained to obtain a model for predicting transaction risks.

[0086] According to an embodiment of the present disclosure, the training data set may be input into the model to be trained, and the training result is output. According to the output training result and the transaction labels carried by the training data set, determine the model parameters of the model to be trained. It is also possible to determine the model parameters of the training model according to the number of iterations.

[0087] For example, the output training result may include the training classification results, such as normal transaction data and abnormal transaction data. According to the transaction labels carried by the training data set, the accuracy rate of the model can be determined. If the accuracy rate is high, for example, more than 95%, then the model parameters at this time are used as the parameters of the model for predicting transaction risks; otherwise, re-adjust the model parameters and train again.

[0088] According to the disclosed embodiment, the normal transaction data of the training samples are divided into multiple clusters by a clustering method, and then a new normal transaction data set is determined from the multiple clusters; the obtained new normal transaction data set and abnormal transaction data set are re-adjusted through the classification model to obtain a reconstructed data set after the label enhancement data; the reconstructed data set is used to retrain to obtain a model for predicting transaction risks. The sample imbalance problem in model training is effectively alleviated, and the ratio gap between normal transaction data and abnormal transaction data in the sample is narrowed. At the same time, the distribution characteristics of the samples in the normal transaction data set are retained as much as possible, so that the effect of the trained model is not affected by the change in the number of samples. Moreover, the results predicted by the trained model for predicting transaction risks can more accurately predict the fraud risks in transactions in terms of precision, recall and comprehensive evaluation values.

[0089] Figure 4 The flowchart schematically shows a method for obtaining a training data set by using a classification model to update transaction labels of a second target historical transaction data set and an abnormal transaction data set according to an embodiment of the present disclosure.

[0090] like Figure 4 As shown, the method 400 of this embodiment for using a classification model to update the transaction labels of a second target historical transaction dataset and an abnormal transaction dataset to obtain a training dataset includes operations S401 to S404.

[0091] In operation S401, the second target historical transaction data set and the abnormal transaction data set are input into a classification model to obtain a classification result.

[0092] According to the embodiment of the present disclosure, the classification model can use the C4.5 decision tree algorithm for classification, and a decision tree M can be obtained. i .

[0093] According to an embodiment of the present disclosure, each data sample in the normal transaction data set in the first target historical transaction data set is assigned an initial weight of 1 / d, where d represents the number of each data sample in the normal transaction data set in the first target historical transaction data set. Then, an iteration of a preset number of iterations is started. At the beginning of each iteration, a clustering method is used. The preset number of iterations is determined according to the classification of the second target historical transaction data set and the abnormal transaction data set.

[0094] In operation S402, the error rate of the classification model is determined using the classification results and the transaction labels.

[0095] According to the embodiment of the present disclosure, the classification result obtained can be calculated by formula (1) to obtain M i The error rate error(M i ):

[0096]

[0097] w i refers to the weight assigned to each data sample x in the second target historical transaction data set and the abnormal transaction data set. i err(x i ) is used to indicate whether each x i is correctly classified. If a data sample x i is misclassified by the decision tree M i , then err(x i ) is equal to 1. If a data sample x i is correctly classified by the decision tree M i , then err(x i ) is equal to 0.

[0098] Based on the comparison between the calculated error(M i ) and the preset threshold, the number of iterations is determined.

[0099] For example, when the preset threshold is 0.5, if error(M i ) is less than or equal to 0.5, the above operation S202 can be returned to start the next round of iteration. If error(M i ) is greater than 0.5, the coefficient of each correctly classified data sample needs to be multiplied by error(M i ) / (1 - error(M i )) and finally all the coefficients are normalized (normalization is also known as normalization), and the iteration ends.

[0100] In operation S403, the voting weight of the classification model is calculated according to the error rate.

[0101] According to the embodiments of the present disclosure, according to the error rate error(Mi) determined in the above operation S402, the voting weight v of the classification model is calculated according to formula (2): i :

[0102]

[0103] In operation S404, based on the voting weight, the transaction label is updated to obtain the training data set.

[0104] According to an embodiment of the present disclosure, the voting weights obtained according to the above operation S403 are added to the categories assigned to each second target historical transaction dataset and abnormal transaction dataset by the decision tree. After all the decision trees for the preset number of iterations have finished classifying, the category with the highest weight value in each second target historical transaction dataset and abnormal transaction dataset is used as the category finally assigned to this data sample, thereby updating the transaction label. The second target historical transaction dataset and abnormal transaction dataset with the new transaction label can be used as the training dataset.

[0105] According to an embodiment of the present disclosure, through the classification model, the transaction labels carried by the second target historical transaction dataset and abnormal transaction dataset are updated and used as the training dataset. The prediction results of the model obtained by training are more accurate in predicting the fraud risks existing in transactions in terms of precision, recall rate, and comprehensive evaluation value than the model obtained by training with the unprocessed data.

[0106] According to an embodiment of the present disclosure, determining the second target historical transaction dataset from multiple clusters includes:

[0107] Screen the data in each cluster respectively to obtain the second target historical transaction dataset.

[0108] According to an embodiment of the present disclosure, a predetermined number of data can be screened from each cluster respectively, and then the second target historical transaction dataset can be formed. The predetermined number can be selected according to the accuracy of the actual training model, for example, it can be 1%. The distribution characteristics of the samples in the normal transaction dataset are retained as much as possible. Among them, the screening includes screening centered on each cluster. As an alternative embodiment, the screening can also include screening from the spatially dense areas of each cluster, and the spatially dense areas can be understood as the areas where the distances between the normal transaction data are relatively small.

[0109] According to an embodiment of the present disclosure, obtaining the first target historical transaction dataset generated within a preset time interval includes:

[0110] Obtain the normal transaction dataset and abnormal transaction dataset generated within the preset time interval to obtain the initial historical data;

[0111] Preprocess the initial historical data to obtain the first target historical transaction dataset.

[0112] According to an embodiment of the present disclosure, the preset time interval can be a period of time in the past, for example, it can be the past 6 months, 12 months, etc. The normal transaction dataset and abnormal transaction dataset can include transaction basic information and transaction account information. The preprocessing can include filling in missing values.

[0113] For example, the data tables involved in the initial historical data from January 1, 2021 to September 30, 2021 can be determined according to the categories of transaction basic information and transaction account information. Then, observe the data columns related to transaction basic information and the account information of both parties in different tables. The data columns include the relevant proportions of transaction frequency, the relevant proportions of transaction amount, the relevant proportions of the number of transaction accounts, and other data columns. Concatenate the relevant data columns in different tables according to the transaction ID to form the original features. For columns with missing values, fill them according to certain rules. The certain rules can be: except for the relevant proportions of transaction frequency, the relevant proportions of transaction amount, and the relevant proportions of the number of transaction accounts, fill the null values of the data in these three types of data columns with the maximum value, and fill the null values of other data columns with 0 values.

[0114] According to an embodiment of the present disclosure, training a model to be trained based on a training data set to obtain a model for predicting transaction risks includes:

[0115] Input the training data set into the model to be trained and output the training result;

[0116] Based on the training result and the updated transaction labels, adjust the parameters of the model to be trained to obtain a trained model for predicting transaction risks.

[0117] According to an embodiment of the present disclosure, the training result can be classifying the data in each training data set into normal transaction data and abnormal transaction data. The accuracy rate of the training model can be determined according to the training result and the updated transaction labels. If the accuracy rate is lower than the expected accuracy rate, the training model can be re - parameter - adjusted and then trained again; if the accuracy rate reaches the expected accuracy rate, a trained model for predicting transaction risks can be obtained; where the expected accuracy rate can be determined according to the accuracy rate that the model needs to reach in actual training.

[0118] According to an embodiment of the present disclosure, before obtaining the first target historical transaction data set generated within a preset time interval, it further includes:

[0119] Obtain the user's authorization for the first target historical transaction data set;

[0120] After obtaining the authorization, obtain the first target historical transaction data set.

[0121] Based on the above model training method, the present disclosure also provides a method for predicting transaction risks, which will be described in detail below.

[0122] Figure 5 Schematically shows a flowchart of a method for predicting transaction risks according to an embodiment of the present disclosure

[0123] As Figure 5 shown, the method 500 for predicting transaction risks includes operations S501 - S503.

[0124] In operation S501, obtain target prediction data associated with the time interval to be predicted.

[0125] According to an embodiment of the present disclosure, the time interval to be predicted can be a period during which a transaction has not occurred. The target prediction data can be data for which a transaction is to be carried out, such as account data of the two parties to the transaction, transaction amount, etc.

[0126] In operation S502, input the target prediction data into a model for predicting transaction risks.

[0127] According to an embodiment of the present disclosure, data for which a transaction is to be carried out can be input into a model for predicting transaction risks.

[0128] In operation S503, output a prediction result.

[0129] According to an embodiment of the present disclosure, a prediction result of normal transaction or abnormal transaction can be output.

[0130] According to an embodiment of the present disclosure, corresponding processing can be performed on the transaction according to the prediction result, avoiding the occurrence of fraudulent transactions and reducing the losses caused by fraudulent transactions to transaction users.

[0131] Based on the above model training method, the present disclosure also provides a model training device. The following will be combined with Figure 6 Describe this device in detail.

[0132] Figure 6 Schematically shows a structural block diagram of a model training device according to an embodiment of the present disclosure.

[0133] As Figure 6 shown, the model training device 600 of this embodiment includes a first acquisition module 610, a clustering module 620, a determination module 630, an update module 640, and a training module 650.

[0134] The first acquisition module 610 is used to acquire a first target historical transaction data set generated within a preset time interval, wherein the first target historical transaction data set includes a normal transaction data set and an abnormal transaction data set, and the normal transaction data set and the abnormal transaction data set carry transaction labels. In one embodiment, the first acquisition module 610 can be used to execute operation S201 described above, which will not be elaborated here.

[0135] The clustering module 620 is used to cluster the normal transaction data set in the first target historical transaction data set to obtain a plurality of clusters. In one embodiment, the clustering module 620 can be used to execute operation S202 described above, which will not be elaborated here.

[0136] The determination module 630 is used to determine a second target historical transaction dataset from the multiple clusters. In one embodiment, the determination module 630 can be used to perform the operation S203 described above, which will not be elaborated here.

[0137] The update module 640 is used to update the transaction labels carried by the second target historical transaction dataset and the abnormal transaction dataset by using a classification model, so as to obtain a training dataset. In one embodiment, the update module 640 can be used to perform the operation S204 described above, which will not be elaborated here.

[0138] The training module 650 is used to train a model to be trained based on the training dataset, and obtain a model for predicting transaction risks. In one embodiment, the training module 650 can be used to perform the operation S205 described above, which will not be elaborated here.

[0139] According to an embodiment of the present disclosure, the first acquisition module 610 includes an acquisition subunit and a processing unit.

[0140] The acquisition subunit is used to acquire a normal transaction dataset and an abnormal transaction dataset generated within a preset time interval, so as to obtain initial historical data.

[0141] The processing unit is used to preprocess the initial historical data to obtain a first target historical transaction dataset.

[0142] According to an embodiment of the present disclosure, the update module 640 includes a classification unit, a first determination subunit, a calculation unit, and a second determination subunit.

[0143] The classification unit is used to input the second target historical transaction dataset and the abnormal transaction dataset into a classification model to obtain a classification result.

[0144] The first determination subunit is used to determine the error rate of the classification model by using the classification result and the transaction label.

[0145] The calculation unit is used to calculate the voting weight of the classification model according to the error rate.

[0146] The second determination subunit is used to update the transaction label based on the voting weight to obtain a training dataset.

[0147] According to embodiments of the present disclosure, any plurality of modules among the first acquisition module 610, the clustering module 620, the determination module 630, the update module 640, and the training module 650 may be combined and implemented in one module, or any one of them may be split into multiple modules. Alternatively, at least part of the functions of one or more of these modules may be combined with at least part of the functions of other modules and implemented in one module. According to embodiments of the present disclosure, at least one of the first acquisition module 610, the clustering module 620, the determination module 630, the update module 640, and the training module 650 may be at least partially implemented as a hardware circuit, such as a field programmable gate array (FPGA), a programmable logic array (PLA), a system on a chip, a system on a substrate, a system on a package, an application specific integrated circuit (ASIC), or may be implemented by any other reasonable means such as hardware or firmware through circuit integration or packaging, or may be implemented in any one of the three implementation manners of software, hardware, and firmware or in any suitable combination of several of them. Alternatively, at least one of the first acquisition module 610, the clustering module 620, the determination module 630, the update module 640, and the training module 650 may be at least partially implemented as a computer program module, and when the computer program module is run, the corresponding functions may be executed.

[0148] Based on the above model prediction method, the present disclosure also provides a device for predicting transaction risks. The following will be combined with Figure 7 to describe this device in detail.

[0149] Figure 7 Schematically shows a structural block diagram of a device for predicting transaction risks according to an embodiment of the present disclosure.

[0150] As Figure 7 shown, the device 700 for predicting transaction risks in this embodiment includes a second acquisition module 710, an input module 720, and an output module 730.

[0151] The second acquisition module 710 is configured to acquire target prediction data associated with a time interval to be predicted. In one embodiment, the second acquisition module 710 may be configured to perform the operation S1 described above, which will not be elaborated here.

[0152] The input module 720 is configured to input the target prediction data into a model for predicting transaction risks. In one embodiment, the input module 720 may be configured to perform the operation S2 described above, which will not be elaborated here.

[0153] The output module 730 is configured to output a prediction result. In one embodiment, the output module 730 may be configured to perform the operation S3 described above, which will not be elaborated here.

[0154] According to an embodiment of the present disclosure, any multiple of the third acquisition module 710, the input module 720, and the output module 730 may be combined and implemented in one module, or any one of them may be split into multiple modules. Alternatively, at least part of the functions of one or more of these modules may be combined with at least part of the functions of other modules and implemented in one module. According to an embodiment of the present disclosure, at least one of the third acquisition module 710, the input module 720, and the output module 730 may be at least partially implemented as a hardware circuit, such as a field programmable gate array (FPGA), a programmable logic array (PLA), a system on chip, a system on substrate, a system on package, an application specific integrated circuit (ASIC), or any other reasonable manner that can be achieved by integrating or packaging circuits, etc., in hardware or firmware, or implemented in any one of the three implementation manners of software, hardware, and firmware, or in an appropriate combination of any several of them. Alternatively, at least one of the third acquisition module 710, the input module 720, and the output module 730 may be at least partially implemented as a computer program module, and when the computer program module is run, it can perform corresponding functions.

[0155] Figure 8 Schematically shows a block diagram of an electronic device suitable for implementing the model training method and the model prediction method according to an embodiment of the present disclosure.

[0156] As Figure 8 shown, the electronic device 800 according to an embodiment of the present disclosure includes a processor 801, which can perform various appropriate actions and processes according to the program stored in the read only memory (ROM) 802 or the program loaded from the storage part 908 into the random access memory (RAM) 803. The processor 801 may include, for example, a general microprocessor (such as a CPU), an instruction set processor, and / or a related chipset, and / or a dedicated microprocessor (such as an application specific integrated circuit (ASIC)), etc. The processor 801 may also include on board memory for caching purposes. The processor 801 may include a single processing unit or multiple processing units for performing different actions of the method flow according to an embodiment of the present disclosure.

[0157] In the RAM 803, various programs and data required for the operation of the electronic device 800 are stored. The processor 801, the ROM 802, and the RAM 803 are connected to each other via a bus 804. The processor 801 performs various operations of the method flow according to the embodiments of the present disclosure by executing the programs in the ROM 802 and / or the RAM 803. It should be noted that the programs may also be stored in one or more memories other than the ROM 802 and the RAM 803. The processor 801 may also perform various operations of the method flow according to the embodiments of the present disclosure by executing the programs stored in the one or more memories.

[0158] According to an embodiment of the present disclosure, the electronic device 800 may further include an input / output (I / O) interface 805, and the input / output (I / O) interface 805 is also connected to the bus 804. The electronic device 800 may further include one or more of the following components connected to the I / O interface 805: an input part 806 including a keyboard, a mouse, etc.; an output part 807 including a cathode ray tube (CRT), a liquid crystal display (LCD), etc. and a speaker, etc.; a storage part 808 including a hard disk, etc.; and a communication part 809 including a network interface card such as a LAN card, a modem, etc. The communication part 809 performs communication processing via a network such as the Internet. A drive 810 is also connected to the I / O interface 805 as needed. A removable medium 811, such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, etc., is installed on the drive 810 as needed, and a computer program read from it is installed into the storage part 808 as needed.

[0159] The present disclosure also provides a computer-readable storage medium, which may be included in the device / apparatus / system described in the above embodiments; or may exist separately without being assembled into the device / apparatus / system. The above computer-readable storage medium carries one or more programs, and when the one or more programs are executed, the method according to the embodiments of the present disclosure is implemented.

[0160] According to an embodiment of the present disclosure, the computer-readable storage medium may be a non-volatile computer-readable storage medium, which may include, for example, but not limited to: portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the above. In the present disclosure, the computer-readable storage medium may be any tangible medium that contains or stores a program, and this program may be used by or in combination with an instruction execution system, apparatus, or device. For example, according to an embodiment of the present disclosure, the computer-readable storage medium may include one or more memories other than the ROM 802 and / or RAM 803 and / or ROM 802 and RAM 803 described above.

[0161] An embodiment of the present disclosure further includes a computer program product, which includes a computer program that contains program code for executing the method shown in the flowchart. When the computer program product runs in a computer system, the program code is used to enable the computer system to implement the model training method and the method for predicting trading risks provided by the embodiments of the present disclosure.

[0162] When the computer program is executed by the processor 801, it executes the above functions defined in the system / apparatus of the embodiments of the present disclosure. According to an embodiment of the present disclosure, the above-described systems, apparatuses, modules, units, etc. may be implemented by computer program modules.

[0163] In one embodiment, the computer program may rely on tangible storage media such as optical storage devices and magnetic storage devices. In another embodiment, the computer program may also be transmitted and distributed in the form of a signal on a network medium, and be downloaded and installed through the communication part 809, and / or be installed from the removable medium 811. The program code contained in the computer program may be transmitted by any suitable network medium, including but not limited to: wireless, wired, etc., or any suitable combination of the above.

[0164] In such an embodiment, the computer program may be downloaded and installed from the network through the communication part 809, and / or be installed from the removable medium 811. When the computer program is executed by the processor 801, it executes the above functions defined in the system of the embodiments of the present disclosure. According to an embodiment of the present disclosure, the above-described systems, devices, apparatuses, modules, units, etc. may be implemented by computer program modules.

[0165] According to embodiments of the present disclosure, program code for executing the computer programs provided by the embodiments of the present disclosure can be written in any combination of one or more programming languages. Specifically, these computing programs can be implemented using high-level procedural and / or object-oriented programming languages, and / or assembly / machine languages. The programming languages include, but are not limited to, such as Java, C++, Python, the "C" language, or similar programming languages. The program code can be executed entirely on the user computing device, partially on the user device, partially on a remote computing device, or entirely on a remote computing device or server. In cases involving a remote computing device, the remote computing device can be connected to the user computing device through any type of network, including a local area network (LAN) or a wide area network (WAN), or it can be connected to an external computing device (e.g., by using an Internet service provider to connect through the Internet).

[0166] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of the present disclosure. In this regard, each block in the flowchart or block diagram can represent a module, a program segment, or a part of code that contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than marked in the accompanying drawings. For example, two consecutive blocks shown may actually be executed substantially in parallel, and they can sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram or flowchart, and combinations of blocks in the block diagram or flowchart, can be implemented by a dedicated hardware-based system for performing the specified functions or operations, or can be implemented by a combination of dedicated hardware and computer instructions.

[0167] Those skilled in the art can understand that the features recited in the various embodiments and / or claims of the present disclosure can be combined or combined in various ways, even if such combinations or combinations are not explicitly recited in the present disclosure. In particular, without departing from the spirit and teachings of the present disclosure, the features recited in the various embodiments and / or claims of the present disclosure can be combined and combined in various ways. All such combinations and / or combinations fall within the scope of the present disclosure.

[0168] The embodiments of the present disclosure have been described above. However, these embodiments are for illustrative purposes only and are not intended to limit the scope of the present disclosure. Although the embodiments have been described separately above, this does not mean that the measures in each embodiment cannot be used advantageously in combination. The scope of the present disclosure is defined by the appended claims and their equivalents. Without departing from the scope of the present disclosure, those skilled in the art can make various substitutions and modifications, and all such substitutions and modifications should fall within the scope of the present disclosure.

Claims

1. A model training method, comprising: Obtain a first target historical transaction data set generated within a preset time interval, where the first target historical transaction data set includes a normal transaction data set and an abnormal transaction data set, and the normal transaction data set and the abnormal transaction data set carry transaction labels; Cluster the normal transaction data set in the first target historical transaction data set to obtain a plurality of clusters; Determine a second target historical transaction data set from the plurality of clusters; Use a classification model to update the transaction labels carried by the second target historical transaction data set and the abnormal transaction data set to obtain a training data set, where the update is iterated according to a preset number of iterations, and at the beginning of each iteration, the clustering is performed; and Train a model to be trained based on the training data set to obtain a model for predicting transaction risks; The using a classification model to update the transaction labels carried by the second target historical transaction data set and the abnormal transaction data set to obtain a training data set includes: Input the second target historical transaction data set and the abnormal transaction data set into the classification model to obtain a classification result; Use the classification result and the transaction label to determine the error rate of the classification model; Calculate the voting weight of the classification model according to the error rate; Based on the voting weight, update the transaction label to obtain the training data set.

2. The method according to claim 1, wherein The determining a second target historical transaction data set from the plurality of clusters includes: Screen the data in each cluster respectively to obtain the second target historical transaction data set, where the screening includes screening with each cluster as the center.

3. The method according to claim 1, wherein The obtaining a first target historical transaction data set generated within a preset time interval includes: Obtain the normal transaction data set and the abnormal transaction data set generated within the preset time interval to obtain initial historical data; Preprocess the initial historical data to obtain the first target historical transaction data set.

4. The method according to claim 1, wherein The normal transaction data set and the abnormal transaction data set further include: transaction basic information and transaction account information.

5. The method according to claim 1, wherein The training a model to be trained based on the training data set to obtain a model for predicting transaction risks includes: Input the training data set into the model to be trained and output a training result; Based on the training result and the updated transaction label, adjust the parameters of the model to be trained to obtain the trained model for predicting transaction risks.

6. The method according to claim 1, further comprising, before obtaining the first target historical transaction data set generated within a preset time interval: Obtain the authorization of the user for the first target historical transaction data set; Obtain the first target historical transaction data set after obtaining the authorization.

7. A method for predicting transaction risks, comprising: Obtain target prediction data associated with a time interval to be predicted; Input the target prediction data into the model for predicting transaction risks; And Output a prediction result; Wherein, the model for predicting transaction risks is trained according to the method according to any one of claims 1 to 6.

8. A model training apparatus, comprising: A first acquisition module, configured to obtain a first target historical transaction data set generated within a preset time interval, where the first target historical transaction data set includes a normal transaction data set and an abnormal transaction data set, and the normal transaction data set and the abnormal transaction data set carry transaction labels; A clustering module for clustering the normal transaction data set in the first target historical transaction data set to obtain a plurality of clusters; A determination module for determining a second target historical transaction data set from the plurality of clusters; An update module for updating the transaction labels carried by the second target historical transaction data set and the abnormal transaction data set by using a classification model to obtain a training data set, wherein the update is iterated according to a preset number of iterations, and at the beginning of each iteration, the clustering is performed; and A training module for training a model to be trained based on the training data set to obtain a model for predicting transaction risks; The step of updating the transaction labels carried by the second target historical transaction data set and the abnormal transaction data set by using a classification model to obtain a training data set includes: Inputting the second target historical transaction data set and the abnormal transaction data set into the classification model to obtain a classification result; Determining the error rate of the classification model by using the classification result and the transaction labels; Calculating the voting weight of the classification model according to the error rate; Updating the transaction labels based on the voting weight to obtain the training data set.

9. An apparatus for predicting trading risks, comprising: A second acquisition module for acquiring target prediction data associated with a time interval to be predicted; An input module for inputting the target prediction data into a model for predicting transaction risks; And An output module for outputting a prediction result; Wherein, the model for predicting transaction risks is trained according to the method described in any one of claims 1 to 6.

10. An electronic device, comprising: One or more processors; A storage device for storing one or more programs, Wherein, when the one or more programs are executed by the one or more processors, the one or more processors are caused to execute the method described in any one of claims 1 to 7.

11. A computer-readable storage medium, having stored thereon executable instructions that, when executed by a processor, cause the processor to execute the method according to any one of claims 1 to 7.

12. A computer program product, comprising a computer program that, when executed by a processor, implements the method according to any one of claims 1 to 7.

Citation Information

Patent Citations

  • Unbalanced data classification method based on unbalanced classification indexes and integrated learning

    CN104951809A

  • Fraudulent trading detection method based on sample clustering

    CN105787743A