Risk prevention method, device, equipment, medium and program product

By obtaining historical risk records and risk behavior sets, extracting association rules, establishing a risk evaluation algorithm, and calculating the risk score of credit card cash-out behavior, the limitations and high cost problems of manually identifying cash-out behavior are solved, and more efficient risk prevention is achieved.

CN114757759BActive Publication Date: 2025-07-18INDUSTRIAL AND COMMERCIAL BANK OF CHINA
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210308420.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-03-24
Publication Date
2025-07-18
Estimated Expiration
2042-03-24

AI Technical Summary

Technical Problem

In the prior art, manual identification of credit card cash-out behavior has limitations and high costs, and it cannot effectively improve the comprehensiveness and accuracy of identification.

Method used

By obtaining historical risk records and risk behavior sets, extracting association rules, establishing a risk assessment algorithm, calculating the risk scores to be evaluated, and risk prevention and treatment is carried out.

Benefits of technology

It improves the comprehensiveness and accuracy of identifying cash-out risk behaviors, reduces the consumption of human and material resources, and improves the effectiveness and objectivity of risk prevention.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114757759B_ABST
    Figure CN114757759B_ABST
Patent Text Reader

Abstract

The present disclosure provides a risk prevention method, which can be applied to the field of big data technology or the financial field. The risk prevention method includes: obtaining historical risk records and a set of risk behaviors, where the set of risk behaviors includes a set of consumption behavior types associated with cash-out behaviors; extracting risk behavior association rules based on the historical risk records and the set of risk behaviors; establishing a risk degree evaluation algorithm based on the risk behavior association rules; calculating a risk degree score of a record to be evaluated based on the risk degree evaluation algorithm to obtain a record risk degree rating; and performing risk prevention processing based on the record risk degree rating. The present disclosure also provides a risk prevention device, equipment, storage medium and program product.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the field of big data technology or the financial field, and particularly relates to a risk prevention method, device, equipment, medium and program product. Background Art

[0002] Cash-out is a relatively common financial risk. Credit card cash-out is the most common method of cash-out, which refers to violating national regulations and using methods such as point-of-sale terminal devices to directly pay cash to credit card holders in ways such as fictitious transactions, inflated prices, and cash refunds. Credit card cash-out poses a great hidden danger to the safety of bank funds. To avoid this problem, it is necessary to identify credit card cash-out behaviors in a timely manner. Currently, for cash-out behaviors, it is usually checked through simple manual experience. For example, when abnormal characteristic data of a certain merchant or card is found, its transaction ledger can be further verified and related behaviors can be traced to identify credit card cash-out behaviors. In the process of implementing the concept of the present disclosure, the inventors found that there are at least the following problems in the prior art:

[0003] Manual identification usually has many limitations, and the consumption of human and material resources is relatively large. The comprehensiveness and accuracy of identifying cash-out risk behaviors need to be improved. Summary of the Invention

[0004] In view of the above problems, embodiments of the present disclosure provide a risk prevention method, device, equipment, medium and program product.

[0005] According to a first aspect of the present disclosure, there is provided a risk prevention method, including: obtaining historical risk records and a risk behavior set, where the risk behavior set includes a set of consumption behavior types associated with cash-out behaviors; extracting risk behavior association rules based on the historical risk records and the risk behavior set; establishing a risk degree evaluation algorithm based on the risk behavior association rules; calculating a risk degree score of a record to be evaluated based on the risk degree evaluation algorithm to obtain a record risk degree rating; and performing risk prevention processing based on the record risk degree rating.

[0006] According to an embodiment of the present disclosure, the extracting risk behavior association rules based on the historical risk records and the risk behavior set includes: calculating the support degree of each risk behavior in the risk behavior set and the confidence degree between risk behaviors based on the historical risk records; and calculating the interaction degree between risk behaviors based on the support degree of each risk behavior and the confidence degree between risk behaviors.

[0007] According to an embodiment of the present disclosure, the risk degree evaluation algorithm established based on the risk behavior association rule includes: obtaining a risk behavior frequency and a risk coefficient, wherein the risk behavior frequency is obtained based on an associated risk behavior set of a record to be evaluated and historical risk records, and the risk coefficient is obtained based on an interaction degree between risk behaviors of risk-unrelated behaviors; and establishing a risk degree evaluation algorithm based on the risk behavior frequency and the risk coefficient, wherein the risk degree evaluation algorithm is used to calculate a risk degree score of the record to be evaluated.

[0008] According to an embodiment of the present disclosure, the frequency of the i-th risk behavior is obtained by calculating the proportion of the number of occurrences of the i-th risk behavior in the historical risk records in the total number of occurrences of risk behaviors, wherein the i-th risk behavior is an element in the associated risk behavior set of the record to be evaluated, and i is an integer greater than or equal to 1.

[0009] According to an embodiment of the present disclosure, the obtaining of the risk coefficient includes the following steps: screening risk behaviors not appearing in the record to be evaluated and marking them as risk-unrelated behaviors; obtaining an interaction degree between risk behaviors associated with the risk-unrelated behaviors and marking it as an irrelevant risk interaction degree; screening the irrelevant risk interaction degree based on a preset threshold to obtain an effective irrelevant risk interaction degree; and obtaining the risk coefficient based on the effective irrelevant risk interaction degree.

[0010] According to an embodiment of the present disclosure, the risk prevention processing based on the record risk degree rating includes: pre-establishing a mapping relationship between the risk degree score and the risk degree rating, and a mapping relationship between the record risk degree rating and the risk prevention processing method; and finding a corresponding risk prevention processing method based on the record risk degree rating of the record to be evaluated to perform risk processing.

[0011] According to an embodiment of the present disclosure, the risk behavior set includes that the account consumption amount is a positive integer multiple of 100, the account consumption amount exceeds the merchant preset threshold, the account consumption amount exceeds the empirical multiple of the average consumption amount of the same type of accounts, and at least three of the account consumption counterparts are merchants under the account subject name.

[0012] A second aspect of the present disclosure provides a risk prevention device, including: an obtaining module configured to obtain historical risk records and a risk behavior set, wherein the risk behavior set includes a set of consumption behavior types associated with cash-out behaviors; a first processing module configured to extract risk behavior association rules based on the historical risk records and the risk behavior set; a second processing module configured to establish a risk degree evaluation algorithm based on the risk behavior association rules; a third processing module configured to calculate a risk degree score of a record of a risk to be evaluated based on the risk degree evaluation algorithm to obtain a record risk degree rating; and a fourth processing module configured to perform risk prevention processing based on the record risk degree rating.

[0013] The third aspect of the present disclosure provides an electronic device, including: one or more processors; a memory for storing one or more programs, wherein when the one or more programs are executed by the one or more processors, the one or more processors are caused to execute the above-mentioned risk prevention method.

[0014] The fourth aspect of the present disclosure further provides a computer-readable storage medium, on which executable instructions are stored, and when the instructions are executed by a processor, the processor is caused to execute the above-mentioned risk prevention method.

[0015] The fifth aspect of the present disclosure further provides a computer program product, including a computer program, and when the computer program is executed by a processor, the above-mentioned risk prevention method is implemented.

[0016] The method provided by the embodiments of the present disclosure can improve the comprehensiveness and accuracy of identifying cash-out risk behaviors, can enhance the processing mechanism for suspicious cash-out behaviors, and effectively reduce the financial risks of financial institutions. BRIEF DESCRIPTION OF THE DRAWINGS

[0017] Through the following description of the embodiments of the present disclosure with reference to the drawings, the above-mentioned content and other objects, features and advantages of the present disclosure will become clearer. In the drawings:

[0018] Figure 1 Schematically shows an application scenario diagram of a risk prevention method, device, equipment, medium and program product according to an embodiment of the present disclosure.

[0019] Figure 2 Schematically shows a flowchart of a risk prevention method according to an embodiment of the present disclosure.

[0020] Figure 3 Schematically shows a flowchart of a risk prevention method according to an embodiment of the present disclosure.

[0021] Figure 4 Schematically shows a flowchart of a risk prevention method according to an embodiment of the present disclosure.

[0022] Figure 5 Schematically shows a flowchart of a method for obtaining a risk coefficient according to an embodiment of the present disclosure.

[0023] Figure 6 Schematically shows a flowchart of a method for risk prevention processing based on a recorded risk degree rating according to an embodiment of the present disclosure.

[0024] Figure 7 Schematically shows a structural block diagram of a risk prevention device according to an embodiment of the present disclosure.

[0025] Figure 8A block diagram of an electronic device suitable for implementing the above risk prevention and control method according to an embodiment of the present disclosure is schematically shown. Detailed implementation manners

[0026] Hereinafter, embodiments of the present disclosure will be described with reference to the accompanying drawings. However, it should be understood that these descriptions are merely exemplary and are not intended to limit the scope of the present disclosure. In the following detailed description, for the sake of explanation, many specific details are set forth to provide a comprehensive understanding of the embodiments of the present disclosure. However, obviously, one or more embodiments may also be implemented without these specific details. In addition, in the following description, descriptions of well-known structures and technologies are omitted to avoid unnecessarily confusing the concepts of the present disclosure.

[0027] The terms used herein are merely for describing specific embodiments and are not intended to limit the present disclosure. The terms "including", "comprising", etc. used herein indicate the presence of the described features, steps, operations, and / or components, but do not exclude the presence or addition of one or more other features, steps, operations, or components.

[0028] All terms used herein (including technical and scientific terms) have the meanings commonly understood by those skilled in the art, unless otherwise defined. It should be noted that the terms used herein should be interpreted as having a meaning consistent with the context of this specification and should not be interpreted in an idealized or overly rigid manner.

[0029] In the case of using expressions such as "at least one of A, B, and C, etc.", generally, it should be interpreted according to the meaning commonly understood by those skilled in the art (for example, "a system having at least one of A, B, and C" should include, but is not limited to, a system having only A, only B, only C, having A and B, having A and C, having B and C, and / or having A, B, and C, etc.).

[0030] Cash-out is a relatively common financial risk in financial activities. Among them, credit card cash-out is the most common. Credit card cash-out refers to violating national laws and regulations and using methods such as point-of-sale terminal devices to directly pay cash to credit card holders in ways such as fictitious transactions, inflated prices, and cash returns. Credit card cash-out poses a great hidden danger to the safety of bank funds. To avoid this problem, it is necessary to promptly identify credit card cash-out behaviors. Currently, for cash-out behaviors, it is usually checked through simple manual experience. For example, when it is found that the characteristic data of a certain merchant or card is abnormal, its transaction ledger can be further verified and related behaviors can be traced to identify credit card cash-out behaviors. However, traditional manual identification methods usually have many limitations, cannot accurately check cash-out risks, consume a large amount of human and material resources, and the comprehensiveness and accuracy of identifying cash-out risk behaviors need to be improved.

[0031] Association rules are a major mining technique in data mining. They can reflect the interdependence and relevance between one thing and other things, and can mine the correlation relationships between valuable data items from a large amount of data. In the process of conceiving the embodiments of the present disclosure, the inventors of the present disclosure realized that when cashing behavior occurs, some high-risk behaviors accompany it, and there may be a certain degree of correlation between different high-risk behaviors. To achieve the purpose of intelligently identifying the risk of cashing behavior, the association rules between different risk behaviors can be mined to discover the associations between different risk behaviors, and further a risk degree evaluation algorithm can be established. After a risk record to be evaluated appears, the risk degree evaluation algorithm can be used to evaluate the risk degree of the risk record to be evaluated, so as to carry out effective prevention.

[0032] Embodiments of the present disclosure provide a risk prevention method, including: obtaining historical risk records and a set of risk behaviors, where the set of risk behaviors includes a set of consumption behavior types associated with cashing behavior. Extracting risk behavior association rules based on the historical risk records and the set of risk behaviors. Establishing a risk degree evaluation algorithm based on the risk behavior association rules. Calculating a risk degree score of a record to be evaluated based on the risk degree evaluation algorithm to obtain a risk degree rating of the record. And performing risk prevention processing based on the risk degree rating of the record.

[0033] It should be noted that the risk prevention method, device, equipment, medium and program product provided by the embodiments of the present disclosure can be used in aspects related to risk prevention and control in big data technology, and can also be used in various fields other than big data technology, such as the financial field, etc. The application fields of the risk prevention method, device, equipment, medium and program product provided by the embodiments of the present disclosure are not limited.

[0034] The above operations for achieving at least one object of the present disclosure will be described below in conjunction with the accompanying drawings and their explanatory texts.

[0035] Figure 1 A schematic diagram shows an application scenario diagram of a risk prevention method, device, equipment, medium and program product according to an embodiment of the present disclosure.

[0036] As Figure 1 shown, the application scenario 100 according to this embodiment may include terminal devices 101, 102, 103, a network 104, and a server 105. The network 104 is used to provide a medium for communication links between the terminal devices 101, 102, 103 and the server 105. The network 104 may include various connection types, such as wired, wireless communication links, or fiber optic cables, etc.

[0037] Users can use terminal devices 101, 102, and 103 to interact with server 105 via network 104 to receive or send data, etc. Terminal devices 101, 102, and 103 can have functions of fund payment and collection, and various transaction-related applications can be installed thereon. For example, they can include consumption support, pre-authorization, balance inquiry, and transfer applications, etc. (only as examples). Terminal devices 101, 102, and 103 can also install shopping applications, web browser applications, search applications, instant messaging tools, email clients, social platform software, etc. (only as examples).

[0038] Terminal devices 101, 102, and 103 can include, but are not limited to, multimedia self-service terminals, POS machines, smart phones, tablets, laptop computers, and desktop computers with functions of transfer and consumption support, and so on.

[0039] Server 105 can be a server that provides various services. For example, it can be a background management server that supports the websites browsed by users using terminal devices 101, 102, and 103 (only as an example). The background management server can analyze and process data such as user requests received, and feedback the processing results (such as web pages, information, or data obtained or generated according to user requests) to the terminal devices.

[0040] It should be noted that the risk prevention method provided by the embodiments of the present disclosure can generally be executed by server 105. Correspondingly, the risk prevention device provided by the embodiments of the present disclosure can generally be set in server 105. The risk prevention method provided by the embodiments of the present disclosure can also be executed by a server or a server cluster different from server 105 and capable of communicating with terminal devices 101, 102, 103 and / or server 105. Correspondingly, the risk prevention device provided by the embodiments of the present disclosure can also be set in a server or a server cluster different from server 105 and capable of communicating with terminal devices 101, 102, 103 and / or server 105.

[0041] It should be understood that Figure 1 the numbers of terminal devices, networks, and servers in

[0042] are merely illustrative. According to actual needs, there can be any number of terminal devices, networks, and servers. Figure 1 Based on the scenario described below Figures 2 to 6 the risk prevention method of the disclosed embodiments will be described in detail through

[0043] Figure 2 Schematically shows a flowchart of the risk prevention method according to an embodiment of the present disclosure.

[0044] As shown in Figure 2As shown, the risk prevention method of this embodiment includes operations S210 to S250. This transaction processing method can be executed by a processor or any electronic device including a processor.

[0045] In operation S210, obtain historical risk records and a set of risk behaviors.

[0046] In operation S220, extract risk behavior association rules based on the historical risk records and the set of risk behaviors.

[0047] In operation S230, establish a risk degree evaluation algorithm based on the risk behavior association rules.

[0048] In operation S240, calculate the risk degree score of the record to be evaluated based on the risk degree evaluation algorithm to obtain the record risk degree rating.

[0049] In operation S250, perform risk prevention processing based on the record risk degree rating.

[0050] According to an embodiment of the present disclosure, through big data technology, a risk degree evaluation algorithm for intelligently identifying cash - out risks is constructed. After identifying the risk behaviors of the transaction records to be evaluated and calculating the risk degree, the risk degree can be rated, and corresponding risk prevention measures can be taken for different risk degree levels. Among them, the risk behavior set includes a set of consumption behavior types associated with cash - out behavior, which can be preset based on manual experience or obtained by collecting risk behaviors in historical cash - out records. The historical risk records can be used as sample data to construct the risk degree evaluation algorithm. Among them, the historical risk records can be historical transaction records containing one or more risk behaviors, which can be obtained from transaction terminal devices, such as multimedia self - service terminals with consumption support and transfer functions, POS machines, smart phones, tablets, laptop computers, and desktop computers with transfer and consumption support functions. Through the historical risk records and the risk behavior set, risk behavior association rules can be extracted. Among them, the association rule is a main mining technology in data mining, which can reflect the interdependence and relevance between one thing and other things, and can mine the correlation relationship between valuable data items from a large amount of data. In the embodiment of the present disclosure, by mining the association rules between different risk behaviors, the association between different risk behaviors can be found, and further a risk degree evaluation algorithm can be established. After the risk record to be evaluated appears, the risk degree evaluation algorithm can be used to evaluate the risk degree of the risk record to be evaluated, so as to carry out effective prevention. Specifically, a risk degree evaluation algorithm model can be established first, and further, the risk degree score calculation can be carried out based on the data associated with the actual record to be evaluated. After calculating the risk degree score, its risk degree level can be determined, and risk prevention measures can be carried out in a hierarchical and classified manner, so as to effectively improve the cash - out behavior processing mechanism. In this process, historical data is fully utilized for association rule mining, greatly reducing the intervention of manual experience, improving the effectiveness, objectivity, and comprehensiveness of risk judgment, and reducing the dissipation of human resource costs.

[0051] In some specific embodiments, the risk behavior set includes that the account consumption amount is a positive integer multiple of 100, the account consumption amount exceeds the merchant - preset threshold, the account consumption amount exceeds the average experience multiple of the consumption amount of the same - type accounts, and the consumption counterpart of the account is at least 3 types among the merchants under the account subject. The inventors of the embodiments of the present disclosure found through analyzing a large number of cash - out records that the above - mentioned consumption behaviors appear frequently in cash - out records, and the data availability is relatively high, which is conducive to the establishment of the risk degree evaluation algorithm and makes the algorithm have high accuracy and practicality. It can be understood that the consumption behavior types in the above - mentioned risk behavior set are only examples, and other various risk behaviors that can be used as judgment bases can also be used to construct the risk degree evaluation algorithm of the embodiments of the present disclosure.

[0052] Figure 3A flowchart of a risk prevention method according to an embodiment of the present disclosure is schematically shown.

[0053] As Figure 3 shown, the risk prevention method of this embodiment includes operation S310 to operation S320.

[0054] In operation S310, based on the historical risk records, the support degrees of each risk behavior in the risk behavior set and the confidence degrees between risk behaviors are calculated.

[0055] In operation S320, based on the support degrees of each risk behavior and the confidence degrees between risk behaviors, the interaction degrees between risk behaviors are calculated.

[0056] According to an embodiment of the present disclosure, support degree, confidence degree, and interaction degree are important concepts in association rules. Among them, support degree (Support) represents the frequency of occurrence of a rule or item set in all things. Such as P(A), P(B), or P(AB). Among them, P(A) represents the frequency of occurrence of rule A or item set A, P(B) represents the frequency of occurrence of rule B or item set B, and P(AB) represents the frequency of occurrence of rule A or item set A and rule B or item set B at the same time. P(AB) can be calculated by formula (1):

[0057] P(AB) = P(A∩B) Formula (1)

[0058] Confidence degree represents the frequency of occurrence of rule B or item set B when rule A or item set A appears. In other words, the confidence degree refers to the ratio of the number of transactions containing both item A and item B to the number of transactions containing item A. The confidence degree can be denoted as confidence(A→B), that is, P(B|A), and is calculated by formula (2):

[0059]

[0060] Lift represents the frequency of occurrence of item A and item B together, and at the same time, the respective frequencies of occurrence of these two items need to be considered. It can be used to measure the influence of the association rule on the frequency of occurrence of the rule or item set, and reflects the correlation between A and B in the association rule. The lift can be denoted as lift(A→B), that is, P(B|A) / P(B), and is calculated by formula (3):

[0061]

[0062] It should be noted that generally, lift > 1 and the higher it is, the higher the positive correlation; 0 < lift < 1 and the lower it is, the higher the negative correlation; lift = 1 indicates no correlation, and the two are independent of each other. When lift < 0, it means that there is a mutually exclusive effect between A and B.

[0063] According to an embodiment of the present disclosure, by mining the association rules between risk behaviors, the correlation between risk behaviors can be mined to improve the accuracy of the risk degree evaluation algorithm.

[0064] Figure 4 FIG. schematically shows a flowchart of a risk prevention method according to an embodiment of the present disclosure.

[0065] As Figure 4 shown, the risk prevention method of this embodiment includes operations S410 to S420.

[0066] In operation S410, obtain the risk behavior frequency and the risk coefficient.

[0067] In operation S420, establish a risk degree evaluation algorithm based on the risk behavior frequency and the risk coefficient.

[0068] According to an embodiment of the present disclosure, the risk degree evaluation algorithm is used to calculate the risk degree score of a record to be evaluated. Among them, the risk behavior frequency is obtained based on the associated risk behavior set of the record to be evaluated and the historical risk records. The associated risk behaviors of the record to be evaluated are the set of risk behavior types associated with the record to be evaluated. The frequency of the risk behavior types included in the record to be evaluated can be statistically obtained through historical risk records. It can be understood that the higher the risk behavior frequency, the greater the probability that the record to be evaluated is a cash-out record. However, only relying on the risk behavior frequency to evaluate the risk degree of the record to be evaluated may have a large error. In the embodiment of the present disclosure, the above error is corrected by the risk coefficient. Specifically, the risk coefficient can be obtained based on the interaction degree between risk behaviors of risk-unrelated behaviors. The establishment concept of the risk degree evaluation algorithm in the embodiment of the present disclosure is to use the association rules of risk-unrelated behaviors to correct the risk behavior frequency. Since not all risk behavior types may appear in a record to be evaluated, the interaction degree of risk behaviors unrelated to the record to be evaluated can be used to correct the overestimation of risk by the simple frequency calculation, thereby improving the accuracy and objectivity of the algorithm.

[0069] In some specific embodiments, the frequency of the i-th risk behavior is obtained by calculating the proportion of the number of occurrences of the i-th risk behavior in the historical risk records in the total number of occurrences of risk behaviors. Among them, the i-th risk behavior is an element in the associated risk behavior set of the record to be evaluated, and i is an integer greater than or equal to 1. It can be understood that the associated risk behavior set of the record to be evaluated includes all risk behaviors that appear in the record to be evaluated.

[0070] Figure 5 FIG. schematically shows a flowchart of a method for obtaining a risk coefficient according to an embodiment of the present disclosure.

[0071] As Figure 5As shown, the method for obtaining the risk coefficient of this embodiment includes operations S510 to S540.

[0072] In operation S510, screen for risk behaviors that do not appear in the records to be evaluated, and mark them as risk-unrelated behaviors.

[0073] In operation S520, obtain the interaction degree between risk behaviors associated with the risk-unrelated behaviors, and mark it as the unrelated risk interaction degree.

[0074] In operation S530, screen the unrelated risk interaction degree based on a preset threshold to obtain the effective unrelated risk interaction degree.

[0075] In operation S540, obtain the risk coefficient based on the effective unrelated risk interaction degree.

[0076] According to an embodiment of the present disclosure, when obtaining the risk coefficient, risk behaviors that do not appear in the records to be evaluated can be screened first and used as risk-unrelated behaviors. Further, the interaction degree between risk behaviors associated with the risk-unrelated behaviors is the unrelated risk interaction degree. For example, in a record to be evaluated, risk behavior one, risk behavior two, and risk behavior three appear, but risk behavior four does not appear. Thus, the unrelated risk interaction degree is the interaction degree associated with risk behavior four, such as lift(behavior one → behavior four), lift(behavior two → behavior four), lift(behavior three → behavior four). Among them, the unrelated risk interaction degree can be screened based on a preset threshold to obtain the effective unrelated risk interaction degree. It can be understood that if the unrelated risk interaction degree of a certain risk behavior is negative, or when 0 < unrelated risk interaction degree < 1, this risk behavior has a negative correlation with other risk behaviors, and it is not an effective factor that can correct the frequency of risk behaviors. Therefore, the preset threshold should be a value that can indicate a positive correlation between risk-unrelated behaviors and risk-related behaviors. In some specific embodiments, the preset threshold can be 1, or a value greater than 1, and can be adjusted based on the model test results. In some specific embodiments, when there are multiple effective unrelated risk interaction degrees, they can be comprehensively considered. For example, they can be associated in ways such as multiplication and summation, and the reciprocal of the effective unrelated risk interaction degree is used as the risk coefficient.

[0077] Figure 6 Schematically shows a flowchart of a method for risk prevention and control based on record risk degree rating according to an embodiment of the present disclosure.

[0078] As Figure 6 shown, the method for obtaining the risk coefficient of this embodiment includes operations S610 to S620.

[0079] In operation S610, a mapping relationship between a risk degree score and a risk degree rating is established in advance, and a mapping relationship between the risk degree rating and a risk prevention and handling method is recorded.

[0080] In operation S620, a corresponding risk prevention and handling method is searched based on the recorded risk degree rating of the record to be evaluated for risk handling.

[0081] According to an embodiment of the present disclosure, in order to quickly search for a risk prevention and handling method at a corresponding level, a mapping relationship between a risk degree score and a risk degree rating can be established in advance, and a mapping relationship between the risk degree rating and a risk prevention and handling method is recorded. Among them, the above two mapping relationships can be established based on expert experience and can be adjusted in real time based on the actual operating conditions of financial institutions.

[0082] The risk prevention method of the embodiment of the present disclosure will be described below in combination with an application scenario example. It should be noted that the specific data and values in this example are only illustrative descriptions of the method principle, do not constitute a limitation to the method of the present disclosure, nor are they used as the data volume and data types of the data used when actually constructing the algorithm.

[0083] S1. Obtain historical risk records and construct a risk behavior set.

[0084] Among them, the risk behavior set includes {Behavior One, Behavior Two, Behavior Three, Behavior Four}. Among them, Behavior One: The last two digits of the credit card consumption amount are integers of 0. Behavior Two: The credit card consumption amount is not within the normal collection amount range of the receiving merchant. Behavior Three: The credit card payment amount value is not within the normal range of a single consumption of this type of credit card (for example, within 2 times the average value). Behavior Four: The payee is a merchant under the credit card holder.

[0085] As shown in Table 1, 10 historical risk records are obtained (any risk behavior is regarded as suspicious cash-out). It should be understood that this example only describes the algorithm construction principle with 10 records as an example. In the actual establishment process of the algorithm, the required number of records can be obtained based on big data technology to construct an effective risk degree evaluation algorithm in the real scenario.

[0086] Behavior 1 Behavior 2 Behavior 3 Behavior 4 Record 1 1 0 0 1 Record 2 0 1 0 1 Record 3 1 0 0 1 Record 4 1 1 1 0 Record 5 0 1 0 0 Record 6 1 0 1 0 Record 7 0 1 1 0 Record 8 1 0 0 1 Record 9 1 1 1 0 Record 10 0 0 0 1

[0087] Table 1

[0088] S2. Extract risk behavior association rules based on historical risk records and the risk behavior set

[0089] S2.1. Calculate the support degree of each behavior

[0090] In some cases, in order to reduce data processing overhead and meet the requirements of algorithm accuracy, only the pairwise association rules of risk behaviors can be calculated. It can be understood that the accuracy of the algorithm can be further improved after comprehensively calculating the association rules of multiple item sets.

[0091] Support(Risk Behavior One): P(Risk Behavior One) = 6 / 10 = 60%

[0092] Support(Risk Behavior Two): P(Risk Behavior Two) = 5 / 10 = 50%

[0093] Support(Risk Behavior Three): P(Risk Behavior Three) = 4 / 10 = 40%

[0094] Support(Risk Behavior Four): P(Risk Behavior Four) = 5 / 10 = 50%

[0095] Support(Risk Behavior One + Risk Behavior Two): P(Risk Behavior One ∩ Risk Behavior Two) = 2 / 10 = 20%

[0096] Support(Risk Behavior One + Risk Behavior Three): P(Risk Behavior One ∩ Risk Behavior Three) = 3 / 10 = 30%

[0097] Support(Risk Behavior One + Risk Behavior Four): P(Risk Behavior One ∩ Risk Behavior Four) = 3 / 10 = 30%

[0098] Support(Risk Behavior Two + Risk Behavior Three): P(Risk Behavior Two ∩ Risk Behavior Three) = 3 / 10 = 30%

[0099] Support(Risk Behavior Two + Risk Behavior Four): P(Risk Behavior Two ∩ Risk Behavior Four) = 1 / 10 = 10%

[0100] Support(Risk Behavior Three + Risk Behavior Four): P(Risk Behavior Three ∩ Risk Behavior Four) = 0 / 10 = 0%

[0101] S2.2. Calculate the confidence between behaviors

[0102] Confidence(Risk Behavior One → Risk Behavior Two): P(Risk Behavior Two | Risk Behavior One) = P(Risk Behavior One ∩ Risk Behavior Two) / P(Risk Behavior One) = 20% / 60% = 1 / 3

[0103] Confidence(Risk Behavior One → Risk Behavior Three): P(Risk Behavior Three | Risk Behavior One) = P(Risk Behavior One ∩ Risk Behavior Three) / P(Risk Behavior One) = 30% / 60% = 1 / 2 = 50%

[0104] Confidence(Risk Behavior One → Risk Behavior Four): P(Risk Behavior Four | Risk Behavior One) = P(Risk Behavior One ∩ Risk Behavior Four) / P(Risk Behavior One) = 30% / 60% = 1 / 2 = 50%

[0105] Confidence(Action 2 → Action 3): P(Action 3|Action 2) = P(Action 2 ∩ Action 3) / P(Action 2) = 30% / 50% = 3 / 5 = 60%

[0106] Confidence(Action 2 → Action 4): P(Action 4|Action 2) = P(Action 2 ∩ Action 4) / P(Action 2) = 10% / 50% = 1 / 5 = 20%

[0107] Confidence(Action 3 → Action 4): P(Action 4|Action 3) = P(Action 3 ∩ Action 4) / P(Action 3) = 0% / 50% = 0

[0108] S2.3. Calculate the lift of the influence between actions

[0109] lift(Action 1 → Action 2) = P(Action 2|Action 1) / P(Action 2) × P(Action 1) = (1 / 3) / (5 / 10) = 2 / 3 = 60%

[0110] lift(Action 1 → Action 3) = P(Action 3|Action 1) / P(Action 3) × P(Action 1) = 50% / 40% = 125%

[0111] lift(Action 1 → Action 4) = P(Action 4|Action 1) / P(Action 4) × P(Action 1) = 50% / 50% = 100%

[0112] lift(Action 2 → Action 3) = P(Action 3|Action 2) / P(Action 3) × P(Action 2) = 60% / 40% = 150%

[0113] lift(Action 2 → Action 4) = P(Action 4|Action 2) / P(Action 4) × P(Action 2) = 20% / 50% = 40%

[0114] lift(Action 3 → Action 4) = P(Action 4|Action 3) / P(Action 4) × P(Action 3) = 0 / 50% = 0

[0115] S2.4. Establish a risk degree evaluation algorithm and calculate the risk degree score

[0116] S2.4.1. Through the historical risk records in Table 1, the number of occurrences of each risk action among all possible risk actions can be calculated, that is, the risk action frequency

[0117] The total number of occurrences of risk actions in the records is 6 + 5 + 4 + 5 = 20

[0118] P(Frequency of Action 1): 6 / 20 = 0.3

[0119] P(Frequency of Behavior Two): 5 / 20 = 0.25

[0120] P(Frequency of Behavior Three): 4 / 20 = 0.2

[0121] P(Frequency of Behavior Four): 5 / 20 = 0.25

[0122] S2.4.2. Analyze the association rules that do not exist in the records to be evaluated. For example, if risk behaviors one, two, and four are satisfied, then there is no association rule related to risk behavior three, that is, the association rules of behavior one → behavior three, behavior two → behavior three, and behavior three → behavior four do not exist.

[0123] S2.4.3. Determine whether the interaction degree between risk behaviors related to risk behavior three calculated in S2.3 is greater than 1 (with 1 as the preset threshold). If it is greater than 1, it is recorded as P(Irrelevant Risk Interaction Degree). If there is no interaction degree between risk behaviors greater than 1, it is recorded as 1. It can be understood that in this example, the irrelevant risk interaction degrees of behavior one → behavior three and behavior two → behavior three are 1.25 and 1.5 respectively.

[0124] S2.4.3. Calculate the risk degree score

[0125] ① Assume that the records to be evaluated contain full risk behaviors one, two, and four:

[0126] Then

[0127] ② Assume that the records to be evaluated contain full risk behaviors two, three, and four:

[0128] Then

[0129] ③ Assume that the records to be evaluated contain full risk behaviors one, two, three, and four:

[0130] Then the risk degree score == 100%

[0131] S2.5. Obtain the record risk degree rating and perform risk prevention and control processing based on the record risk degree rating.

[0132] S2.5.1. Pre - establish mapping relation table 2 between risk degree scores and risk degree ratings, and mapping relation table 3 between record risk degree ratings and risk prevention and control processing methods.

[0133] Risk score Risk rating 0~20% 1 20~40% 2 40~60% 3 60~80% 4 80~100% 5

[0134] Table 2

[0135]

[0136] Table 3

[0137] S2.5.2 Look up the corresponding risk rating in Table 2 according to the risk score calculated in S2.4.3. Further, look up the risk prevention and handling methods corresponding to the risk rating in Table 3 to perform risk prevention and handling. For example, for the to-be-evaluated records ① and ②, their risk scores are 43% and 56% respectively, and the corresponding risk rating is 3. Further determine that the risk prevention and handling methods for the to-be-evaluated records ① and ② are to reduce the credit card limit and send text messages and make phone calls for warnings. For the to-be-evaluated record ③, its risk score is 100%, and the corresponding risk rating is 5. Further determine that its risk prevention and handling method is to lock the credit card so that it cannot be consumed, and notify the user to go to the relevant network institutions for identity verification and information verification.

[0138] Based on the above risk prevention method, the present disclosure also provides a risk prevention device. The following will be combined with Figure 7 to describe the device in detail.

[0139] Figure 7 The structural block diagram of the risk prevention device according to an embodiment of the present disclosure is schematically shown.

[0140] As Figure 7 shown, the risk prevention device 700 of this embodiment includes an acquisition module 710, a first processing module 720, a second processing module 730, a third processing module 740, and a fourth processing module 750.

[0141] The acquisition module 710 is configured to acquire historical risk records and a set of risk behaviors, where the set of risk behaviors includes a set of consumption behavior types associated with cash-out behaviors.

[0142] The first processing module 720 is configured to extract risk behavior association rules based on the historical risk records and the set of risk behaviors.

[0143] The second processing module 730 is configured to establish a risk degree evaluation algorithm based on the risk behavior association rules.

[0144] The third processing module 740 is configured to calculate the risk score of the to-be-evaluated risk record based on the risk degree evaluation algorithm to obtain the record risk rating.

[0145] The fourth processing module 750 is configured to perform risk prevention and handling based on the record risk rating.

[0146] According to an embodiment of the present disclosure, any plurality of modules among the acquisition module 710, the first processing module 720, the second processing module 730, the third processing module 740, and the fourth processing module 750 may be combined and implemented in one module, or any one of them may be split into multiple modules. Alternatively, at least part of the functions of one or more of these modules may be combined with at least part of the functions of other modules and implemented in one module. According to an embodiment of the present disclosure, at least one of the acquisition module 710, the first processing module 720, the second processing module 730, the third processing module 740, and the fourth processing module 750 may be at least partially implemented as a hardware circuit, such as a field programmable gate array (FPGA), a programmable logic array (PLA), a system on chip, a system on a substrate, a system on a package, an application specific integrated circuit (ASIC), or any other reasonable way of integrating or packaging circuits, etc., implemented by hardware or firmware, or implemented in any one or a suitable combination of the three implementation manners of software, hardware, and firmware. Alternatively, at least one of the acquisition module 710, the first processing module 720, the second processing module 730, the third processing module 740, and the fourth processing module 750 may be at least partially implemented as a computer program module, and when the computer program module is run, corresponding functions may be executed.

[0147] Figure 8 A block diagram of an electronic device suitable for implementing the above risk prevention and control method according to an embodiment of the present disclosure is schematically shown.

[0148] As Figure 8 shown, the electronic device 900 according to an embodiment of the present disclosure includes a processor 901, which may perform various appropriate actions and processes according to a program stored in a read only memory (ROM) 902 or a program loaded from a storage section 908 into a random access memory (RAM) 903. The processor 901 may include, for example, a general microprocessor (such as a CPU), an instruction set processor, and / or a related chipset, and / or a dedicated microprocessor (such as an application specific integrated circuit (ASIC)), etc. The processor 901 may also include on-board memory for caching purposes. The processor 901 may include a single processing unit or multiple processing units for performing different actions of the method flow according to an embodiment of the present disclosure.

[0149] In the RAM 903, various programs and data required for the operation of the electronic device 900 are stored. The processor 901, the ROM 902, and the RAM 903 are connected to each other via a bus 904. The processor 901 performs various operations of the method flow according to the embodiments of the present disclosure by executing the programs in the ROM 902 and / or the RAM 903. It should be noted that the programs can also be stored in one or more memories other than the ROM 902 and the RAM 903. The processor 901 can also perform various operations of the method flow according to the embodiments of the present disclosure by executing the programs stored in the one or more memories.

[0150] According to an embodiment of the present disclosure, the electronic device 900 may further include an input / output (I / O) interface 905, and the input / output (I / O) interface 905 is also connected to the bus 904. The electronic device 900 may further include one or more of the following components connected to the I / O interface 905: an input portion 906 including a keyboard, a mouse, etc.; an output portion 907 including a cathode ray tube (CRT), a liquid crystal display (LCD), etc. and a speaker, etc.; a storage portion 908 including a hard disk, etc.; and a communication portion 909 including a network interface card such as a LAN card, a modem, etc. The communication portion 909 performs communication processing via a network such as the Internet. A drive 910 is also connected to the I / O interface 905 as needed. A removable medium 911, such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, etc., is mounted on the drive 910 as needed so that a computer program read from it can be installed into the storage portion 908 as needed.

[0151] The present disclosure also provides a computer-readable storage medium, which may be included in the device / apparatus / system described in the above embodiments; or may exist separately without being assembled into the device / apparatus / system. The above computer-readable storage medium carries one or more programs, and when the one or more programs are executed, the methods according to the embodiments of the present disclosure are implemented.

[0152] According to an embodiment of the present disclosure, the computer-readable storage medium may be a non-volatile computer-readable storage medium, for example, it may include but is not limited to: portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the above. In the present disclosure, the computer-readable storage medium may be any tangible medium that contains or stores a program, and this program can be used by or in combination with an instruction execution system, device, or component. For example, according to an embodiment of the present disclosure, the computer-readable storage medium may include one or more memories other than the above-described ROM 902 and / or RAM 903 and / or ROM 902 and RAM 903.

[0153] An embodiment of the present disclosure also includes a computer program product, which includes a computer program that contains program code for executing the method shown in the flowchart. When the computer program product runs in a computer system, the program code is used to enable the computer system to implement the method provided by the embodiment of the present disclosure.

[0154] When the computer program is executed by the processor 901, it executes the above functions defined in the system / device of the embodiment of the present disclosure. According to an embodiment of the present disclosure, the above-described systems, devices, modules, units, etc. can be implemented by computer program modules.

[0155] In one embodiment, the computer program can rely on tangible storage media such as optical storage devices and magnetic storage devices. In another embodiment, the computer program can also be transmitted and distributed in the form of a signal on a network medium, and be downloaded and installed through the communication part 909, and / or be installed from the removable medium 911. The program code included in the computer program can be transmitted using any suitable network medium, including but not limited to: wireless, wired, etc., or any suitable combination of the above.

[0156] In such an embodiment, the computer program can be downloaded and installed from the network through the communication part 909, and / or be installed from the removable medium 911. When the computer program is executed by the processor 901, it executes the above functions defined in the system of the embodiment of the present disclosure. According to an embodiment of the present disclosure, the above-described systems, devices, apparatuses, modules, units, etc. can be implemented by computer program modules.

[0157] According to embodiments of the present disclosure, program code for executing the computer programs provided by the embodiments of the present disclosure may be written in any combination of one or more programming languages. Specifically, these computing programs may be implemented using high-level procedural and / or object-oriented programming languages, and / or assembly / machine languages. The programming languages include, but are not limited to, programming languages such as Java, C++, Python, the "C" language, or similar programming languages. The program code may be executed entirely on the user's computing device, partially on the user's device, partially on a remote computing device, or entirely on a remote computing device or server. In cases involving a remote computing device, the remote computing device may be connected to the user's computing device through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computing device (e.g., by connecting through the Internet using an Internet service provider).

[0158] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of the present disclosure. In this regard, each block in the flowchart or block diagram may represent a module, a program segment, or a portion of code that contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than marked in the accompanying drawings. For example, two consecutive blocks shown may actually be executed substantially in parallel, and they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram or flowchart, and combinations of blocks in the block diagram or flowchart, may be implemented by a dedicated hardware-based system for performing the specified functions or operations, or may be implemented by a combination of dedicated hardware and computer instructions.

[0159] Those skilled in the art can understand that the features recited in the various embodiments and / or claims of the present disclosure can be combined or / and combined in various ways, even if such combinations or combinations are not explicitly recited in the present disclosure. In particular, without departing from the spirit and teachings of the present disclosure, the features recited in the various embodiments and / or claims of the present disclosure can be combined and / or combined in various ways. All such combinations and / or combinations fall within the scope of the present disclosure.

[0160] The embodiments of the present disclosure have been described above. However, these embodiments are for illustrative purposes only and are not intended to limit the scope of the present disclosure. Although the embodiments have been described separately above, this does not mean that the measures in each embodiment cannot be used advantageously in combination. The scope of the present disclosure is defined by the appended claims and their equivalents. Without departing from the scope of the present disclosure, those skilled in the art can make various substitutions and modifications, and these substitutions and modifications should all fall within the scope of the present disclosure.

Claims

1. A risk prevention method, characterized in that, Including: Obtain historical risk records and a risk behavior set, where the risk behavior set contains a set of consumption behavior types associated with cash - out behavior; Calculate the support of each risk behavior in the risk behavior set and the confidence between risk behaviors based on the historical risk records; Calculate the interaction degree between risk behaviors based on the support of each risk behavior and the confidence between risk behaviors; Obtain the risk behavior frequency and risk coefficient, where the risk behavior frequency is obtained based on the associated risk behavior set of the record to be evaluated and the historical risk records, and the risk coefficient is obtained based on the interaction degree between risk behaviors of risk - irrelevant behaviors; The obtaining of the risk coefficient includes the following steps: Based on the risk behavior set, screen out the risk behaviors that do not appear in the record to be evaluated and mark them as risk - irrelevant behaviors; Obtain the interaction degree between risk behaviors associated with the risk - irrelevant behaviors and mark it as the irrelevant risk interaction degree; Screen the irrelevant risk interaction degree based on a preset threshold to obtain the effective irrelevant risk interaction degree; Take the reciprocal of the product of multiple effective irrelevant risk interaction degrees to determine the risk coefficient; Establish a risk degree evaluation algorithm, which is used to calculate the risk degree score of the record to be evaluated. The risk degree score is obtained by multiplying the sum of the risk behavior frequencies corresponding to the risk behavior types included in the record to be evaluated by the risk coefficient; Calculate the risk degree score of the record to be evaluated based on the risk degree evaluation algorithm to obtain the record risk degree rating; and Perform risk prevention processing based on the record risk degree rating.

2. A method according to claim 1, wherein, The frequency of the i - th risk behavior is obtained by calculating the proportion of the number of occurrences of the i - th risk behavior in the historical risk records in the total number of occurrences of risk behaviors, where the i - th risk behavior is an element in the associated risk behavior set of the record to be evaluated, and i is an integer greater than or equal to 1.

3. A method according to claim 1, wherein The performing risk prevention processing based on the record risk degree rating includes: Pre - establish a mapping relationship between the risk degree score and the risk degree rating, and a mapping relationship between the record risk degree rating and the risk prevention processing method; and Find the corresponding risk prevention processing method based on the record risk degree rating of the record to be evaluated to perform risk processing.

4. A method according to claim 1, wherein, The risk behavior set includes that the account consumption amount is a positive integer multiple of 100, the account consumption amount exceeds the merchant - preset threshold, the account consumption amount exceeds the average multiple of the consumption amount of the same - type accounts, and the counterparty of the account consumption is at least 3 of the merchants under the account subject.

5. A risk prevention device, including: An acquisition module configured to obtain historical risk records and a risk behavior set, where the risk behavior set contains a set of consumption behavior types associated with cash - out behavior; A first processing module configured to extract risk behavior association rules based on the historical risk records and the risk behavior set, The extracting risk behavior association rules based on the historical risk records and the risk behavior set includes: Calculate the support of each risk behavior in the risk behavior set and the confidence between risk behaviors based on the historical risk records; Calculate the interaction degree between risk behaviors based on the support of each risk behavior and the confidence between risk behaviors; A second processing module, configured to establish a risk degree evaluation algorithm based on the risk behavior association rule The establishment of the risk degree evaluation algorithm based on the risk behavior association rule includes: Obtaining the risk behavior frequency and the risk coefficient, wherein the risk behavior frequency is obtained based on the associated risk behavior set of the record to be evaluated and the historical risk records, and the risk coefficient is obtained based on the interaction degree between risk behaviors of risk - irrelevant behaviors The obtaining of the risk coefficient includes the following steps: Based on the risk behavior set, screening out the risk behaviors that do not appear in the record to be evaluated, and marking them as risk - irrelevant behaviors; Obtaining the interaction degree between risk behaviors associated with the risk - irrelevant behaviors, and marking it as the irrelevant risk interaction degree; Screening the irrelevant risk interaction degree based on a preset threshold to obtain the effective irrelevant risk interaction degree; Taking the reciprocal of the product of multiple effective irrelevant risk interaction degrees to determine the risk coefficient; Establishing a risk degree evaluation algorithm, which is used to calculate the risk degree score of the record to be evaluated, and the risk degree score is obtained by multiplying the sum of the risk behavior frequencies corresponding to the risk behavior types included in the record to be evaluated by the risk coefficient; A third processing module, configured to calculate the risk degree score of the risk record to be evaluated based on the risk degree evaluation algorithm to obtain the record risk degree rating; and A fourth processing module, configured to perform risk prevention processing based on the record risk degree rating.

6. An electronic device, comprising: One or more processors; A storage device for storing one or more programs, wherein, when the one or more programs are executed by the one or more processors, the one or more processors are caused to execute the method according to any one of claims 1 - 4.

7. A computer - readable storage medium, on which executable instructions are stored, and when the instructions are executed by a processor, the processor is caused to execute the method according to any one of claims 1 - 4.

8. A computer program product, comprising a computer program, and when the computer program is executed by a processor, the method according to any one of claims 1 - 4 is implemented.

Citation Information

Patent Citations

  • Enterprise fraud behavior determination method, apparatus and device, and storage medium

    CN111275338A

  • Transaction information auditing method and device

    CN118297705A