Abnormal object processing method, device, equipment and medium
By clustering to determine abnormal objects among financial risk users, monitoring and verifying their transaction information, the problems of slow data updates and long processing time in the existing technology are solved, timely screening and isolation of risk users are achieved, and the risk of capital loss is reduced.
Patent Information
- Application Number
- CN202210345341.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-03-31
- Publication Date
- 2025-06-27
- Estimated Expiration
- 2042-03-31
AI Technical Summary
When handling financial risks, the blacklist data is updated slowly and cannot predict the abnormal behavior of risk users in a timely manner. Supervised learning requires a lot of data and time, so risk users cannot be processed in a timely manner, resulting in fund losses.
Through clustering, M abnormal objects are determined based on multiple risk users, their transaction information is monitored, the risk status is verified, and when the result is verified, the abnormal objects are recorded in the prohibited transaction database to prevent the occurrence of abnormal behavior.
It has achieved early screening and isolation of risky users, reduced the risk of capital loss, and improved the timeliness and accuracy of risk treatment.
Smart Images

Figure CN114971897B_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the field of machine learning, and more particularly to a method, apparatus, device, medium, and program product for processing abnormal objects. Background Art
[0002] Risk implementation means are constantly updated with the advancement of technology, from the previous single-risk implementation form to the current group-risk implementation form. The update of risk implementation means also brings the risk of capital loss to financial enterprises.
[0003] The main risk processing means in the field of fintech include blacklists and supervised learning. Among them, the blacklist is the most primitive risk processing method, similar to a "filter", but the data in the blacklist is updated relatively slowly, and it is impossible to predict in a timely manner the abnormal behaviors of risk users that are occurring. By the time an abnormal behavior is detected, the abnormal behavior has already ended. The blacklist belongs to passive defense; supervised learning requires a large amount of data and time to train the model, and the time is relatively long, making it impossible to process risk users in a timely manner and resulting in capital losses for users. Summary of the Invention
[0004] In view of the above problems, the present disclosure provides a method, apparatus, device, medium, and program product for processing abnormal objects, which are used to screen, isolate, and monitor abnormal users in advance to prevent the generation of abnormal behaviors from the source.
[0005] According to a first aspect of the present disclosure, there is provided a method for processing abnormal objects, including: determining M abnormal objects based on multiple risk users through clustering, where the M abnormal objects have similar characteristics, and M is an integer greater than 2; when recording the M abnormal objects in a first preset area of a monitoring database, monitoring the transaction information of the M abnormal objects, where the monitoring database includes a first preset area and a second preset area; when determining that there is new transaction information for N abnormal objects among the M abnormal objects, recording the N abnormal objects in the second preset area, where N is an integer greater than or equal to 1, and M is greater than or equal to N; verifying the risk status of the N abnormal objects to determine N verification results corresponding to the N abnormal objects; and when one of the N verification results is a true risk, recording the abnormal object corresponding to the verification result in a prohibited transaction database.
[0006] According to an embodiment of the present disclosure, the method further includes, when one of the N verification results is a true risk: determining a sub-abnormal object group corresponding to the abnormal object according to the abnormal object corresponding to the verification result; determining multiple associated objects having transaction records with the abnormal object according to the sub-abnormal object group; and recording the multiple associated objects in the prohibited transaction database.
[0007] According to an embodiment of the present disclosure, the method further includes: freezing all transaction funds when determining all transaction funds between an abnormal object and multiple associated objects.
[0008] According to an embodiment of the present disclosure, wherein the risk status includes true risk and false risk; verifying the risk status of N abnormal objects and determining N verification results corresponding to the N abnormal objects includes: for one abnormal object among the N abnormal objects, determining the verification result of the abnormal object includes: receiving a first return request from a user terminal and a second return request from a verification terminal, the first return request includes a verification result from a user, and the second return request includes a verification result from a verification personnel; when the first return request is a true risk and / or the second return request is a true risk, determining that the verification result of the abnormal object is a true risk; and when the first return request is a false risk and the second return request is a false risk, determining that the verification result of the abnormal object is a false risk.
[0009] According to an embodiment of the present disclosure, the method further includes: sending a first prompt message to the user terminal and sending a second prompt message to the verification terminal, the first prompt message is displayed in a first display area of the user terminal; the second prompt message is displayed in a second display area of the verification terminal; and in response to an operation from a user, determining the first return request; in response to an operation from a verification personnel, determining the second return request.
[0010] According to an embodiment of the present disclosure, wherein determining M abnormal objects based on multiple risk users by clustering includes: determining characteristic label information of the multiple risk users; based on the characteristic label information, determining user portraits of the multiple risk users by clustering; and according to the user portraits, determining M abnormal objects.
[0011] A second aspect of the present disclosure provides an abnormal object processing apparatus, including: a determination module, configured to determine M abnormal objects based on multiple risk users by clustering, the M abnormal objects include similar characteristics, wherein M is an integer greater than 2; a monitoring module, configured to monitor transaction information of the M abnormal objects when recording the M abnormal objects in a first preset area of a monitoring database, the monitoring database includes a first preset area and a second preset area; a recording module, configured to record N abnormal objects in the second preset area when determining that there is new transaction information for N abnormal objects among the M abnormal objects, wherein N is an integer greater than or equal to 1, and M is greater than or equal to N; a verification module, configured to verify the risk status of the N abnormal objects to obtain N verification results of the N abnormal objects; and a processing module, configured to record the abnormal object corresponding to the verification result in a prohibited transaction database when one of the N verification results is a true risk.
[0012] A third aspect of the present disclosure provides an electronic device, including: one or more processors; a memory for storing one or more programs, wherein when the one or more programs are executed by the one or more processors, the one or more processors are caused to execute the above-mentioned abnormal object processing method.
[0013] A fourth aspect of the present disclosure further provides a computer-readable storage medium, on which executable instructions are stored, and when the instructions are executed by a processor, the processor is caused to execute the above-mentioned abnormal object processing method.
[0014] A fifth aspect of the present disclosure further provides a computer program product, including a computer program, and when the computer program is executed by a processor, the above-mentioned abnormal object processing method is implemented. Description of the Drawings
[0015] Through the following description of the embodiments of the present disclosure with reference to the drawings, the above-mentioned content and other objects, features and advantages of the present disclosure will become clearer. In the drawings:
[0016] Figure 1 Schematically shows an application scenario diagram of an abnormal object processing method, apparatus, device, medium and program product according to an embodiment of the present disclosure;
[0017] Figure 2 Schematically shows a flowchart of an abnormal object processing method according to an embodiment of the present disclosure;
[0018] Figure 3 Schematically shows a flowchart of a processing method in a true risk situation according to an embodiment of the present disclosure;
[0019] Figure 4 Schematically shows a flowchart of a method for verifying a risk situation according to an embodiment of the present disclosure;
[0020] Figure 5 Schematically shows a flowchart of a method for obtaining a return request according to an embodiment of the present disclosure;
[0021] Figure 6 Schematically shows a flowchart of a method for determining a plurality of abnormal objects according to an embodiment of the present disclosure;
[0022] Figure 7 Schematically shows a structural block diagram of an abnormal object processing apparatus according to an embodiment of the present disclosure; and
[0023] Figure 8 Schematically shows a block diagram of an electronic device suitable for implementing an abnormal object processing method according to an embodiment of the present disclosure. Detailed Embodiments
[0024] Hereinafter, embodiments of the present disclosure will be described with reference to the accompanying drawings. However, it should be understood that these descriptions are merely exemplary and are not intended to limit the scope of the present disclosure. In the following detailed description, for the sake of explanation, numerous specific details are set forth to provide a comprehensive understanding of the embodiments of the present disclosure. However, evidently, one or more embodiments can also be implemented without these specific details. In addition, in the following description, descriptions of well-known structures and technologies are omitted to avoid unnecessarily obscuring the concepts of the present disclosure.
[0025] The terms used herein are merely for describing specific embodiments and are not intended to limit the present disclosure. The terms "including", "comprising", etc. used herein indicate the presence of the described features, steps, operations, and / or components, but do not exclude the presence or addition of one or more other features, steps, operations, or components.
[0026] All terms used herein (including technical and scientific terms) have the meanings commonly understood by those skilled in the art, unless otherwise defined. It should be noted that the terms used herein should be interpreted as having a meaning consistent with the context of this specification and should not be interpreted in an idealized or overly rigid manner.
[0027] In the case of using expressions such as "at least one of A, B, and C, etc.", generally, it should be interpreted according to the meaning commonly understood by those skilled in the art (for example, "a system having at least one of A, B, and C" should include, but not be limited to, a system having only A, only B, only C, having A and B, having A and C, having B and C, and / or having A, B, and C, etc.).
[0028] Embodiments of the present disclosure provide a method for processing abnormal objects, including: determining M abnormal objects based on multiple risk users through clustering, where the M abnormal objects have similar characteristics, and M is an integer greater than 2; when recording the M abnormal objects in a first preset area of a monitoring database, monitoring the transaction information of the M abnormal objects, and the monitoring database includes a first preset area and a second preset area; when determining that there is new transaction information for N abnormal objects among the M abnormal objects, recording the N abnormal objects in the second preset area, where N is an integer greater than or equal to 1, and M is greater than or equal to N; verifying the risk status of the N abnormal objects to determine N verification results corresponding to the N abnormal objects; and when one of the N verification results is a true risk, recording the abnormal object corresponding to the verification result in a prohibited transaction database.
[0029] Figure 1 Schematically shows an application scenario diagram of a method, device, equipment, medium, and program product for processing abnormal objects according to an embodiment of the present disclosure.
[0030] As Figure 1 shown, the application scenario 100 according to this embodiment may include terminal devices 101, 102, 103, a network 104, and a server 105. The network 104 is used to provide a medium for communication links between the terminal devices 101, 102, 103 and the server 105. The network 104 may include various connection types, such as wired, wireless communication links, or fiber optic cables, etc.
[0031] Users can use the terminal devices 101, 102, 103 to interact with the server 105 through the network 104 to receive or send messages, etc. Various communication client applications may be installed on the terminal devices 101, 102, 103, such as shopping applications, web browser applications, search applications, instant messaging tools, email clients, social platform software, etc. (only as examples).
[0032] The terminal devices 101, 102, 103 may be various electronic devices with a display screen and supporting web browsing, including but not limited to smart phones, tablet computers, laptop portable computers, and desktop computers, etc.
[0033] The server 105 may be a server providing various services, such as a background management server that supports the websites browsed by users using the terminal devices 101, 102, 103 (only as an example). The background management server may analyze and process data such as received user requests, and feedback the processing results (such as web pages, information, or data obtained or generated according to user requests) to the terminal devices.
[0034] It should be noted that the method for processing abnormal objects provided in the embodiments of the present disclosure can generally be executed by the server 105. Correspondingly, the device for processing abnormal objects provided in the embodiments of the present disclosure can generally be set in the server 105. The method for processing abnormal objects provided in the embodiments of the present disclosure can also be executed by a server or a server cluster different from the server 105 and capable of communicating with the terminal devices 101, 102, 103 and / or the server 105. Correspondingly, the device for processing abnormal objects provided in the embodiments of the present disclosure can also be set in a server or a server cluster different from the server 105 and capable of communicating with the terminal devices 101, 102, 103 and / or the server 105.
[0035] It should be understood that Figure 1 the numbers of terminal devices, networks, and servers in [[ ]] are merely illustrative. According to the implementation requirements, there may be any number of terminal devices, networks, and servers.
[0036] The following will be based on Figure 1 the described scenario, through Figures 2 to 6A method for processing abnormal objects in public embodiments is described in detail.
[0037] In the technical solution of the present disclosure, the processing of the user's personal information involved in collection, storage, use, processing, transmission, provision, disclosure, and application, etc., all comply with the provisions of relevant laws and regulations, take necessary confidentiality measures, and do not violate public order and good customs.
[0038] In the technical solution of the present disclosure, before obtaining or collecting the user's personal information, the user's authorization or consent has been obtained.
[0039] Figure 2 A flowchart of an abnormal object processing method according to an embodiment of the present disclosure is schematically shown.
[0040] As Figure 2 shown, this embodiment includes operations S210 to S250.
[0041] In operation S210, M abnormal objects are determined based on multiple risk users through clustering, and the M abnormal objects contain similar features.
[0042] According to an embodiment of the present disclosure, a risk user is a user who may have abnormal risks in actual applications. Specifically, it may be a user with fraud risks, a user with abnormal operations, etc. The sources of risk users include risk users registered in the social credit system, risk users registered by third-party enterprises, and risk information databases from the system.
[0043] According to an embodiment of the present disclosure, determining M abnormal objects based on multiple risk users through clustering includes determining according to the risk information of the risk users, and M is an integer greater than 2. The multiple risk users include but are not limited to the M abnormal objects. The risk information includes the registration information registered by the risk user itself and the account information of the users with transaction records with the risk user through the front end. The acquisition of risk information also includes information input through forms such as mobile banking apps and web browsers.
[0044] According to an embodiment of the present disclosure, when determining M abnormal objects based on risk users through clustering, multiple risk users can be divided into M abnormal objects under multiple features according to one or more similar features of the risk users. For example, risk user A contains the features of "default" and "loan", risk user B contains "default", and risk users C and D also at least contain the feature of "loan". At this time, risk users A, B, and C can be divided into abnormal objects under the "default" feature, and risk users A, C, and D can be divided into abnormal objects under the "loan" feature.
[0045] According to an embodiment of the present disclosure, M abnormal objects are determined based on risk users through clustering, and further, abnormal objects are determined from risk users according to the similarity of features. Specifically, for risk users A, B, and C, when the feature similarity between risk users A and B exceeds a preset threshold, or the number of similar features of A and B exceeds a preset number, risk users A and B are determined as abnormal objects from risk users A, B, and C.
[0046] According to an embodiment of the present disclosure, the analysis of a single abnormal object may not be able to analyze abnormal behaviors. However, when each of multiple abnormal objects meets one or more features, the group behavior of these multiple abnormal objects is very suspicious. Screening out M abnormal objects with similar features from risk users and conducting key monitoring helps to monitor abnormal objects with a high degree of suspicion in real time and improve the detection efficiency.
[0047] In operation S220, when the M abnormal objects are recorded in the first preset area of the monitoring database, the transaction information of the M abnormal objects is monitored.
[0048] According to an embodiment of the present disclosure, when M abnormal objects are screened out, the M abnormal objects are recorded in the first preset area of the monitoring database for monitoring the above-mentioned M abnormal objects. Specifically, the monitoring database includes a first preset area and a second preset area. The first preset area is used to monitor the transaction information of the M abnormal objects. The monitoring database can be set as a gray list database, and the first preset area is set as a yellow area, which belongs to a warning area, indicating that the abnormal objects in this area have a very high suspicion of abnormal risk but no new transaction records have occurred yet.
[0049] In operation S230, when it is determined that N abnormal objects among the M abnormal objects have new transaction information, the N abnormal objects are recorded in the second preset area.
[0050] According to an embodiment of the present disclosure, the N abnormal objects are the currently processed abnormal objects, N is an integer greater than or equal to 1, and M is greater than or equal to N. Both the first preset area and the second preset area are located in the monitoring database, and information can be transmitted between the two preset areas. Specifically, when it is determined that the N abnormal objects have new transaction information, the user information of the N abnormal objects that generate new transaction information in the first preset area is transmitted to the second preset area, and the second preset area records the information of the N abnormal objects with new transaction information, that is, the information of the objects that perform new transaction operations among the key monitored abnormal objects, so as to perform accurate risk verification operations later. Specifically, the second preset area of the monitoring database can be set as a temporary area, such as a red area.
[0051] According to an embodiment of the present disclosure, the new transaction information in which N abnormal objects exist includes transaction records with normal users, transaction records with users whose risks are not monitored, and transaction information of users involved in the transaction fund flow. For example, when there is a large amount of fund flow for a certain abnormal object, or there are multiple small amounts of fund flows to the abnormal object, it is determined that there is a new transaction record for the abnormal object, and further, N abnormal objects with new transaction information are determined.
[0052] According to an embodiment of the present disclosure, when recording N abnormal objects from a first preset area to a second preset area, the first preset area still retains the user information of the N abnormal objects for subsequent operations according to the verification results.
[0053] In operation S240, verify the risk status of the N abnormal objects to determine N verification results corresponding to the N abnormal objects.
[0054] According to an embodiment of the present disclosure, after recording the N abnormal objects in the second preset area, it is necessary to verify the N abnormal objects to obtain the risk verification results of the N abnormal objects.
[0055] According to an embodiment of the present disclosure, verifying the risk status of the N abnormal objects can be done by sending a verification request to the user and determining the verification result according to the user's verification operation; it can also be done by sending the user information of the N abnormal objects to the verification end, and having the verification personnel at the verification end perform manual verification operations to determine the verification result; it can also combine user verification and verification personnel verification to determine the verification result.
[0056] In operation S250, when one of the N verification results is a true risk, record the abnormal object corresponding to the verification result in the prohibited transaction database.
[0057] According to an embodiment of the present disclosure, determine the risk situation of the N abnormal objects according to the obtained verification results. When one of the N verification results is a true risk, send the user information of the abnormal object corresponding to the verification result to the prohibited transaction database, and record the abnormal object in the prohibited transaction database.
[0058] According to an embodiment of the present disclosure, when recording the abnormal object corresponding to the true risk verification result in the prohibited transaction database, delete the abnormal object recorded in the first preset area and the second preset area in the monitoring database to reduce the monitoring workload and verification workload of the monitoring database.
[0059] The present disclosure first screens out multiple abnormal objects from multiple risky users through clustering. In the first step, key monitoring objects are screened out, achieving precise monitoring while reducing the monitoring workload. Then, objects with abnormal operations among the key monitoring objects are verified, further achieving precise verification while precisely monitoring. In the case where the verification result is a true risk, the abnormal object corresponding to the verification result is recorded in the prohibited transaction library. Therefore, the technical solution of the present disclosure can screen potential risky users in advance, isolate and focus on monitoring abnormal objects using the detection database, avoid the generation of abnormal behaviors from the source, and protect the fund safety of users.
[0060] According to an embodiment of the present disclosure, M abnormal objects are determined through clustering. Specifically, the hierarchical clustering algorithm is used to determine M abnormal objects. Hierarchical clustering is to perform clustering layer by layer. Hierarchical clustering includes the divisive method and the agglomerative method. The divisive method is to divide large categories (clusters) from top to bottom. Specifically, initially, all samples are grouped into a single cluster c. The distance between two samples in the same cluster is calculated. In this clustering, the two samples a and b with the farthest distance are determined. Then, samples a and b are assigned to different clusters c1 and c2 for hierarchical splitting. The distances between the remaining samples in the original cluster c and samples a and b are calculated again. Samples closer to a are assigned to cluster c1, and samples closer to b are assigned to cluster c2. This process continues until a preset condition is met or the set number of classifications is reached, obtaining multiple groups of abnormal objects. Each group of abnormal objects includes multiple abnormal objects with similar characteristics, and these abnormal objects are the screened-out M abnormal objects. In addition, due to the existence of multiple ways to divide similar characteristics, the same abnormal object may be assigned to multiple groups of abnormal objects according to different division rules.
[0061] The agglomerative method is to aggregate small categories from bottom to top. Specifically, initially, each sample point is regarded as a cluster, that is, the size of the original cluster is equal to the number of sample points. Then, the distances between every two clusters are calculated, and the two samples e and f with the smallest distance, and their corresponding two clusters c3 and c4 are found. The clusters c3 and c4 corresponding to samples e and f are merged into a single cluster d1. The distances between other samples and samples e and f are calculated again, and the cluster c5 to which the sample closest to sample e or f belongs is merged into cluster d1 until a preset condition is met or the set number of classifications is reached.
[0062] The present disclosure uses the method of hierarchical clustering, which does not require specifying a specific k value and the cluster center value, improving the accuracy of determining abnormal objects from risky users.
[0063] Figure 3 Schematically shows a flowchart of the processing method in the case of true risk according to an embodiment of the present disclosure. Among them, Figure 3It includes operations S351 to S353, which can be a specific implementation of operation S250.
[0064] According to an embodiment of the present disclosure, after operation S250 determines an abnormal object corresponding to a true risk of verification result, the abnormal object is processed. Since the abnormal object corresponding to the true risk is obtained from multiple abnormal objects including similar features, when the risk situation of the abnormal object is a true risk, the abnormal objects having similar features to the abnormal object may also have a relatively high risk. Therefore, as a specific embodiment, it further includes recording multiple abnormal objects associated with the abnormal object in a prohibited transaction database.
[0065] According to an embodiment of the present disclosure, operations S351 to S353 occur after operation S250, or can be performed simultaneously with operation S250.
[0066] As Figure 3 shown, this embodiment includes operations S351 to S353.
[0067] In operation S351, according to the abnormal object corresponding to the true risk of verification result, a sub - abnormal object group corresponding to the abnormal object is determined.
[0068] According to an embodiment of the present disclosure, according to the abnormal object corresponding to the true risk of verification result, a sub - abnormal object group having similar features to the abnormal object is determined from a first preset area.
[0069] In operation S352, according to the sub - abnormal object group, multiple associated objects having transaction records with the abnormal object are determined.
[0070] According to an embodiment of the present disclosure, after determining the sub - abnormal object group corresponding to the abnormal object, multiple associated objects having transaction records with the abnormal object are screened out from the sub - abnormal object group.
[0071] In operation S353, the multiple associated objects are recorded in a prohibited transaction database.
[0072] According to an embodiment of the present disclosure, according to the abnormal object corresponding to the true risk of verification result, first a sub - abnormal object group having similar features to the abnormal object is determined, and then multiple associated objects having transaction records with the abnormal object are screened out from the multiple abnormal objects in the sub - abnormal object group. Since the abnormal object has been determined to be a true risk, the multiple determined associated objects have a high correlation with the abnormal object. The multiple associated objects are determined as high - risk and recorded in a prohibited transaction database, such as a blacklist database.
[0073] According to an embodiment of the present disclosure, during the clustering process, it has been determined that the abnormal object A, the abnormal object B, and the abnormal object C have similar characteristics. In the case where the abnormal object corresponding to the true risk of the verification result is the abnormal object A, then the group where the abnormal object A, the abnormal object B, and the abnormal object C are located is determined as a sub-abnormal object group. In the case where there is a transaction record between the abnormal object B and the abnormal object A, both the abnormal object A and the abnormal object B are recorded in the prohibited transaction database.
[0074] According to an embodiment of the present disclosure, in the case of determining all the transaction funds between the abnormal object corresponding to the true risk of the verification result and multiple associated objects, all the transaction funds are frozen. Still taking the abnormal object A, the abnormal object B, and the abnormal object C determined during the clustering process as an example, the abnormal object corresponding to the true risk of the verification result is the abnormal object A. There is a transaction record between the abnormal object B and the abnormal object A. At this time, according to this transaction record, it is determined that there are multiple small transfers between the abnormal object B and the abnormal object A, then the transaction funds involved in the multiple small transfers are frozen.
[0075] Figure 4 The flowchart of the method for verifying the risk status according to an embodiment of the present disclosure is schematically shown. Among them, Figure 4 It includes operation S441 to operation S443, and can be a specific implementation manner of operation S240.
[0076] According to an embodiment of the present disclosure, operation S240 is to verify N abnormal objects to obtain a verification result. In the case where the user is affected by other external factors, the operation behavior of the user itself is not abnormal. For example, the user believes that there is no current transaction risk and performs a risk-free verification operation, but in the actual judgment, the current behavior has a transaction risk, but the user is affected by external factors resulting in a misjudgment, and the operation itself is not abnormal. Therefore, as a specific embodiment, the present disclosure jointly verifies the current risk status through the user terminal and the verification terminal.
[0077] According to an embodiment of the present disclosure, for one abnormal object among the N abnormal objects, the verification result of the abnormal object is determined, and then the N verification results of the N abnormal objects are determined in the same way.
[0078] As Figure 4 shown, this embodiment includes operation S441 to operation S443.
[0079] In operation S441, receive a first return request from the user terminal and a second return request from the verification terminal.
[0080] According to an embodiment of the present disclosure, verifying the risk status of an abnormal object among N abnormal objects includes verifying the risk status from the user side and the risk status from the verification side. Specifically, it is achieved by receiving a first return request from the user side and a second return request from the verification side.
[0081] In operation S442, when the first return request is a true risk and / or the second return request is a true risk, determine that the verification result of the abnormal object is a true risk.
[0082] According to an embodiment of the present disclosure, for the first return request and the second return request, when the verification result of one of them is a true risk, it indicates that there is a true risk for the currently verified abnormal object. Therefore, when the first return request is a true risk and / or the second return request is a true risk, determine that the verification result of the currently verified abnormal object is a true risk. Since the first return request from the user side may be a request returned by the user under a deceived situation, the verification side needs to perform verification and return the second return request.
[0083] In operation S443, when the first return request is a false risk and the second return request is a false risk, determine that the verification result of the abnormal object is a false risk.
[0084] According to an embodiment of the present disclosure, when the return requests from both the user side and the verification side are false risks, determine that the verification result of the currently verified abnormal object is a false risk. By performing dual - end determination of the risk status through the user side and the client side, it is possible to avoid inaccurate verification results caused by user operation errors or external influences.
[0085] According to an embodiment of the present disclosure, when the verification result indicates that the risk situation of the currently verified abnormal object is a false risk, send the user information of the verified abnormal object in the second preset area back to the first preset area and record this verification record. Delete the abnormal object from the second preset area.
[0086] Figure 5 Schematically shows a flowchart of a method for obtaining a return request according to an embodiment of the present disclosure. Among them, Figure 5 It includes operation S541 to operation S542 as Figure 4 a further description of operation S441 to operation S443 in
[0087] According to an embodiment of the present disclosure, before performing operation S441, it is also possible to send a verification request to the user through operation S541 to operation S542. As Figure 5 shown, this embodiment includes operation S541 to operation S542.
[0088] In operation S541, a first prompt message is sent to the user side, and a second prompt message is sent to the verification side.
[0089] According to an embodiment of the present disclosure, verifying the risk status of the currently verified abnormal object can be achieved by sending a first prompt message to the user side and a second prompt message to the verification side. Specifically, when verifying the risk status of the user side, sending the first prompt message to the user side can be implemented by setting a security verification button. For example, when sending the first prompt message to the user side, after the user side device receives the first prompt message, a security verification button is displayed to the user, and the user needs to perform an operation to conduct a risk verification. When verifying the risk status of the verification side, it can be implemented by setting a manual verification service. For example, when sending the second prompt message to the verification side, after the verification side device receives the second prompt message, the information of the object to be verified is displayed to the verification personnel, and the verification personnel conduct the verification after making a phone call.
[0090] According to an embodiment of the present disclosure, the first prompt message sent to the user side can be displayed between the user's transaction operation confirmation operations. For example, it is achieved by displaying "The other party's account is an insecure account and is under bank monitoring" on the user side interface.
[0091] According to an embodiment of the present disclosure, when sending the second prompt message to the verification side, a third prompt message can also be sent to the user side to prompt the user that the verification personnel are conducting the verification. For example, a prompt message such as "The other party's account is abnormal. Please wait for further operations by the verification personnel" is sent.
[0092] In operation S542, in response to an operation from the user, a first return request is determined; in response to an operation from the verification personnel, a second return request is determined.
[0093] According to an embodiment of the present disclosure, the user side device determines the first return request in response to the user's operation on the first prompt message; the verification side device determines the second return request in response to an operation from the verification personnel. For example, the user side device determines the first return request as "true risk" or "false risk" in response to the user's click operation on the security verification button; the verification side device determines the first return request as "true risk" or "false risk" in response to an input operation from the verification personnel.
[0094] Figure 6 Schematically shows a flowchart of a method for determining multiple abnormal objects according to an embodiment of the present disclosure. Among them, Figure 6 including operation S611 to operation S613, can be used as Figure 2 a specific embodiment of operation S210 in
[0095] As Figure 6 shown, this embodiment includes operation S611 to operation S613.
[0096] In operation S611, the characteristic tag information of multiple risk users is determined.
[0097] According to an embodiment of the present disclosure, in the process of determining M abnormal objects based on multiple risk users by clustering in operation S210, the characteristic tag information of multiple risk users can be determined first, and then a user portrait of multiple risk users can be formed, so as to determine M abnormal objects according to the user portrait.
[0098] Specifically, the characteristic tags of risk users include the basic attributes of users, behavior characteristics, user relationships, user interest characteristics, user risk information, user marketing information, user value, etc. The characteristic tag information is the characteristic value corresponding to the characteristic tag. The characteristic tag information of users can be obtained through the information filled in by users during registration or the operation logs of users. For example, when the characteristic tag is the user relationship, according to the operation log, "user A transfers 500 yuan to user B" is obtained, then the characteristic tag information corresponding to the user relationship tag of A can be "user B".
[0099] According to an embodiment of the present disclosure, the basic attributes include the demographic statistics of users, life information, location information, hardware and software information at the time of registration, custom information, etc.; the behavior characteristics include the daily activity level of users, the frequency of deposits and withdrawals, etc.; the user relationships include life relationships, financial association relationships, social network association relationships. The user interest characteristics include the financial product preferences of users, the internal operation channel preferences, the behavior channel preferences, etc.; the user risk information includes the user risk evaluation, the blacklist; the user marketing information includes the recent demand information of users, the marketing activity information; the user value includes the self-value of users, the asset contribution.
[0100] In operation S612, based on the characteristic tag information, a user portrait of multiple risk users is determined by clustering.
[0101] According to an embodiment of the present disclosure, using the characteristic tag information, the specific information of users is divided into different characteristics by clustering. According to the divided characteristics, the specific descriptions corresponding to the characteristics can be determined, and then a user portrait is formed according to the specific descriptions of multiple characteristics of users.
[0102] In operation S613, M abnormal objects are determined according to the user portrait.
[0103] According to an embodiment of the present disclosure, due to the setting according to actual needs, there are differences in the descriptions of user portraits with similar characteristics, so risk users with similar characteristics may have different user portraits. Determining M abnormal objects according to the specific user portrait ensures the accuracy of the divided characteristics.
[0104] For example, the transaction amount, transaction time, transaction person relationship, transaction frequency, etc. of risk user A are obtained from the transaction record storage database, that is, the feature label information. It is found through clustering that risk user A and risk user B have similar transaction amounts at similar transaction times. For example, the transaction time of risk user A is on March 31st, and the transaction time of risk user B is on April 1st. Although the transaction times are similar, the above features are described differently in the user portraits of risk users. For example, "transaction time on March 31st" is described as "the first quarter", and "transaction time on April 1st" is described as "the second quarter". According to the specific descriptions in the user portraits, risk user A and risk user B are determined as abnormal objects with similar transaction amounts, rather than abnormal objects with similar transaction times.
[0105] According to an embodiment of the present disclosure, the user portrait is stored in the user portrait database so that the bank can adjust the marketing or monitoring strategy for the user through the user portrait, such as restricting the re-application for a credit card, etc.
[0106] Based on the above method for processing abnormal objects, the present disclosure also provides a device for processing abnormal objects. The following will be combined with Figure 7 to describe this device in detail.
[0107] Figure 7 The structural block diagram of the abnormal object processing device according to an embodiment of the present disclosure is schematically shown.
[0108] As Figure 7 shown, the abnormal object processing device 700 of this embodiment includes a determination module 710, a monitoring module 720, a recording module 730, a verification module 740, and a processing module 705.
[0109] The determination module 710 is used to determine M abnormal objects based on multiple risk users through clustering. The M abnormal objects include similar features, where M is an integer greater than 2. In one embodiment, the determination module 710 can be used to perform the operation S210 described above, which will not be elaborated here.
[0110] The monitoring module 720 is used to monitor the transaction information of the M abnormal objects when the M abnormal objects are recorded in the first preset area of the monitoring database. In one embodiment, the monitoring module 720 can be used to perform the operation S220 described above, which will not be elaborated here.
[0111] The recording module 730 is used to record N abnormal objects in the second preset area when it is determined that the N abnormal objects have new transaction information. In one embodiment, the recording module 730 can be used to perform the operation S230 described above, which will not be elaborated here.
[0112] A verification module 740 is configured to verify the risk status of N abnormal objects and determine N verification results corresponding to the N abnormal objects. In one embodiment, the verification module 740 may be configured to perform the operation S240 described above, which will not be elaborated herein.
[0113] A processing module 750 is configured to record the abnormal object corresponding to the verification result in a prohibited transaction database when one of the N verification results is a true risk. In one embodiment, the processing module 750 may be configured to perform the operation S250 described above, which will not be elaborated herein.
[0114] According to an embodiment of the present disclosure, the processing module 750 further includes a first determination unit, a second determination unit, and a recording unit.
[0115] The first determination unit is configured to determine a sub-abnormal object group corresponding to the abnormal object according to the abnormal object corresponding to the true risk of the verification result. In one embodiment, the first determination unit may be configured to perform the operation S351 described above, which will not be elaborated herein.
[0116] The second determination unit is configured to determine a plurality of associated objects having transaction records with the abnormal object according to the sub-abnormal object group. In one embodiment, the second determination unit may be configured to perform the operation S352 described above, which will not be elaborated herein.
[0117] The recording unit is configured to record the plurality of associated objects in the prohibited transaction database. In one embodiment, the recording unit may be configured to perform the operation S353 described above, which will not be elaborated herein.
[0118] According to an embodiment of the present disclosure, the apparatus further includes a freezing module configured to freeze all transaction funds when it is determined all transaction funds between the abnormal object and the plurality of associated objects.
[0119] According to an embodiment of the present disclosure, the verification module 740 further includes a third determination unit, a fourth determination unit, and a fifth unit.
[0120] The third determination unit is configured to receive a first return request from a user terminal and a second return request from a verification terminal. In one embodiment, the third determination unit may be configured to perform the operation S441 described above, which will not be elaborated herein.
[0121] The fourth determination unit is configured to determine that the verification result of the abnormal object is a true risk when the first return request is a true risk and / or the second return request is a true risk. In one embodiment, the fourth determination unit may be configured to perform the operation S442 described above, which will not be elaborated herein.
[0122] The fifth unit is configured to determine that the verification result of the abnormal object is at risk of being false in the case where the first return request is at risk of being false and the second return request is at risk of being false. In one embodiment, the fifth determination unit may be configured to perform the operation S443 described above, which will not be elaborated here.
[0123] According to an embodiment of the present disclosure, the verification module 740 further includes a first sending unit and a first response unit.
[0124] The first sending unit is configured to send a first prompt message to the user terminal and send a second prompt message to the verification terminal. In one embodiment, the first sending unit may be configured to perform the operation S541 described above, which will not be elaborated here.
[0125] The first response unit is configured to determine a first return request in response to an operation from the user; and determine the second return request in response to an operation from the verification personnel. In one embodiment, the first response unit may be configured to perform the operation S542 described above, which will not be elaborated here.
[0126] According to an embodiment of the present disclosure, the determination module 710 further includes a feature determination unit, a portrait determination unit, and an abnormal object determination unit.
[0127] The feature determination unit is configured to determine the feature tag information of multiple risk users. In one embodiment, the feature determination unit may be configured to perform the operation S611 described above, which will not be elaborated here.
[0128] The portrait determination unit is configured to determine the user portraits of multiple risk users by clustering based on the feature tag information. In one embodiment, the portrait determination unit may be configured to perform the operation S612 described above, which will not be elaborated here.
[0129] The abnormal object determination unit is configured to determine M abnormal objects according to the user portraits. In one embodiment, the abnormal object determination unit may be configured to perform the operation S613 described above, which will not be elaborated here.
[0130] According to embodiments of the present disclosure, any multiple of the determination module 710, the monitoring module 720, the recording module 730, the verification module 740, and the processing module 750 may be combined and implemented in one module, or any one of them may be split into multiple modules. Alternatively, at least part of the functions of one or more of these modules may be combined with at least part of the functions of other modules and implemented in one module. According to embodiments of the present disclosure, at least one of the determination module 710, the monitoring module 720, the recording module 730, the verification module 740, and the processing module 750 may be at least partially implemented as a hardware circuit, such as a field programmable gate array (FPGA), a programmable logic array (PLA), a system on chip, a system on substrate, a system on package, an application specific integrated circuit (ASIC), or any other reasonable way of integrating or packaging circuits, etc., implemented by hardware or firmware, or implemented in any one of the three implementation manners of software, hardware, and firmware, or in an appropriate combination of any several of them. Alternatively, at least one of the determination module 710, the monitoring module 720, the recording module 730, the verification module 740, and the processing module 750 may be at least partially implemented as a computer program module, and when the computer program module is run, corresponding functions may be executed.
[0131] Figure 8 A block diagram of an electronic device suitable for implementing an abnormal object processing method according to an embodiment of the present disclosure is schematically shown.
[0132] As Figure 8 shown, the electronic device 800 according to an embodiment of the present disclosure includes a processor 801, which may perform various appropriate actions and processes according to a program stored in a read only memory (ROM) 802 or a program loaded from a storage section 808 into a random access memory (RAM) 803. The processor 801 may include, for example, a general microprocessor (such as a CPU), an instruction set processor, and / or a related chipset, and / or a dedicated microprocessor (such as an application specific integrated circuit (ASIC)), etc. The processor 801 may also include on-board memory for caching purposes. The processor 801 may include a single processing unit or multiple processing units for performing different actions of the method flow according to an embodiment of the present disclosure.
[0133] In the RAM 803, various programs and data required for the operation of the electronic device 800 are stored. The processor 801, the ROM 802, and the RAM 803 are connected to each other via a bus 804. The processor 801 performs various operations of the method flow according to the embodiments of the present disclosure by executing the programs in the ROM 802 and / or the RAM 803. It should be noted that the programs may also be stored in one or more memories other than the ROM 802 and the RAM 803. The processor 801 may also perform various operations of the method flow according to the embodiments of the present disclosure by executing the programs stored in the one or more memories.
[0134] According to an embodiment of the present disclosure, the electronic device 800 may further include an input / output (I / O) interface 805, and the input / output (I / O) interface 805 is also connected to the bus 804. The electronic device 800 may further include one or more of the following components connected to the I / O interface 805: an input portion 806 including a keyboard, a mouse, etc.; an output portion 807 including, for example, a cathode ray tube (CRT), a liquid crystal display (LCD), etc., and a speaker, etc.; a storage portion 808 including a hard disk, etc.; and a communication portion 809 including a network interface card such as a LAN card, a modem, etc. The communication portion 809 performs communication processing via a network such as the Internet. A drive 810 is also connected to the I / O interface 805 as needed. A removable medium 811, such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, etc., is installed on the drive 810 as needed so that a computer program read from it can be installed into the storage portion 808 as needed.
[0135] The present disclosure also provides a computer-readable storage medium, which may be included in the device / apparatus / system described in the above embodiments; or may exist separately without being assembled into the device / apparatus / system. The above computer-readable storage medium carries one or more programs, and when the one or more programs are executed, the method according to the embodiments of the present disclosure is implemented.
[0136] According to an embodiment of the present disclosure, the computer-readable storage medium may be a non-volatile computer-readable storage medium, for example, it may include but is not limited to: portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the above. In the present disclosure, the computer-readable storage medium may be any tangible medium that contains or stores a program, and this program can be used by or in combination with an instruction execution system, apparatus, or device. For example, according to an embodiment of the present disclosure, the computer-readable storage medium may include one or more memories other than the ROM 802 and / or RAM 803 described above and / or the ROM 802 and RAM 803.
[0137] An embodiment of the present disclosure also includes a computer program product, which includes a computer program that contains program code for executing the method shown in the flowchart. When the computer program product runs in a computer system, the program code is used to enable the computer system to implement the exception object processing method provided by the embodiment of the present disclosure.
[0138] When the computer program is executed by the processor 801, it executes the above functions defined in the system / apparatus of the embodiment of the present disclosure. According to an embodiment of the present disclosure, the above-described systems, apparatuses, modules, units, etc. can be implemented by computer program modules.
[0139] In one embodiment, the computer program can rely on tangible storage media such as optical storage devices and magnetic storage devices. In another embodiment, the computer program can also be transmitted and distributed in the form of a signal on a network medium, and is downloaded and installed through the communication part 809, and / or installed from the removable medium 811. The program code contained in the computer program can be transmitted by any suitable network medium, including but not limited to: wireless, wired, etc., or any suitable combination of the above.
[0140] In such an embodiment, the computer program can be downloaded and installed from the network through the communication part 809, and / or installed from the removable medium 811. When the computer program is executed by the processor 801, it executes the above functions defined in the system of the embodiment of the present disclosure. According to an embodiment of the present disclosure, the above-described systems, devices, apparatuses, modules, units, etc. can be implemented by computer program modules.
[0141] In accordance with embodiments of the present disclosure, program code for executing the computer programs provided by the embodiments of the present disclosure may be written in any combination of one or more programming languages. Specifically, these computing programs may be implemented using high-level procedural and / or object-oriented programming languages, and / or assembly / machine languages. Programming languages include, but are not limited to, such as Java, C++, Python, the "C" language, or similar programming languages. The program code may be executed entirely on the user's computing device, partially on the user's device, partially on a remote computing device, or entirely on a remote computing device or server. In cases involving a remote computing device, the remote computing device may be connected to the user's computing device through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computing device (e.g., by connecting through the Internet using an Internet service provider).
[0142] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of the present disclosure. In this regard, each block in the flowchart or block diagram may represent a module, a program segment, or a part of code that contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than that marked in the accompanying drawings. For example, two consecutive blocks shown may actually be executed substantially in parallel, and they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram or flowchart, and combinations of blocks in the block diagram or flowchart, may be implemented by a dedicated hardware-based system for performing the specified functions or operations, or may be implemented by a combination of dedicated hardware and computer instructions.
[0143] Those skilled in the art can understand that the features described in the various embodiments of the present disclosure can be combined and / or combined in various ways, even if such combinations or combinations are not explicitly described in the present disclosure. In particular, without departing from the spirit and teachings of the present disclosure, the features described in the various embodiments of the present disclosure can be combined and / or combined in various ways. All such combinations and / or combinations fall within the scope of the present disclosure.
[0144] The above describes the embodiments of the present disclosure. However, these embodiments are for illustrative purposes only and are not intended to limit the scope of the present disclosure. Although the embodiments are described separately above, this does not mean that the measures in the various embodiments cannot be used advantageously in combination. Without departing from the scope of the present disclosure, those skilled in the art can make various substitutions and modifications, and all such substitutions and modifications should fall within the scope of the present disclosure.
[0145] The specific embodiments described above further elaborate on the purpose, technical solutions, and beneficial effects of the present disclosure. It should be understood that the above are only specific embodiments of the present disclosure and are not used to limit the present disclosure. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present disclosure shall be included within the protection scope of the present disclosure.
Claims
1. An abnormal object processing method, comprising: Determining M abnormal objects based on multiple risk users through clustering, where the M abnormal objects are multiple objects belonging to the same cluster determined by the hierarchical clustering method, and M is an integer greater than 2; When recording the M abnormal objects in the first preset area of the monitoring database, monitoring the transaction information of the M abnormal objects, where the monitoring database includes a first preset area and a second preset area; When determining that N abnormal objects among the M abnormal objects have new transaction information, recording the N abnormal objects in the second preset area, where N is an integer greater than or equal to 1, and M is greater than or equal to N; Verifying the risk status of the N abnormal objects to determine N verification results corresponding to the N abnormal objects; the risk status includes true risk and false risk; When one of the N verification results is a true risk, recording the abnormal object corresponding to the verification result in the prohibited transaction database and deleting the abnormal object from the first preset area and the second preset area of the monitoring database; The verifying the risk status of the N abnormal objects to determine N verification results corresponding to the N abnormal objects includes: For one abnormal object among the N abnormal objects, Receiving a first return request from the user side and a second return request from the verification side, where the first return request includes a verification result from the user, and the second return request includes a verification result from the verification personnel; When the first return request is a true risk and / or the second return request is a true risk, determining that the verification result of the abnormal object is a true risk; When the first return request is a false risk and the second return request is a false risk, determining that the verification result of the abnormal object is a false risk.
2. The method according to claim 1, further comprising, when one of the N verification results is a true risk: Determining a sub-abnormal object group corresponding to the abnormal object according to the abnormal object corresponding to the verification result; Determining multiple associated objects having transaction records with the abnormal object according to the sub-abnormal object group; Recording the multiple associated objects in the prohibited transaction database.
3. The method according to claim 2 further comprises: When determining all the transaction funds between the abnormal object and the multiple associated objects, freezing all the transaction funds.
4. The method according to claim 1, further comprising: Sending a first prompt message to the user side and a second prompt message to the verification side, where the first prompt message is displayed in the first display area of the user side; The second prompt message is displayed in the second display area of the verification side; And Responding to an operation from the user to determine the first return request; Responding to an operation from the verification personnel to determine the second return request.
5. The method according to claim 1, wherein The determining M abnormal objects based on multiple risk users through clustering includes: Determining the characteristic label information of the multiple risk users; Based on the characteristic label information, determining the user portraits of the multiple risk users through clustering; and Determine M abnormal objects according to the user profile.
6. An abnormal object processing device, comprising: A determination module, configured to determine M abnormal objects based on multiple risk users through clustering. The M abnormal objects are multiple objects belonging to the same cluster determined by the hierarchical clustering method, where M is an integer greater than 2; A monitoring module, configured to monitor the transaction information of the M abnormal objects when the M abnormal objects are recorded in a first preset area of a monitoring database. The monitoring database includes a first preset area and a second preset area; A recording module, configured to record the N abnormal objects in the second preset area when it is determined that there is new transaction information for N abnormal objects among the M abnormal objects, where N is an integer greater than or equal to 1, and M is greater than or equal to N; A verification module, configured to verify the risk status of the N abnormal objects to obtain N verification results of the N abnormal objects; the risk status includes true risk and false risk; A processing module, configured to record the abnormal object corresponding to the verification result in a prohibited transaction database and delete the abnormal object from the first preset area and the second preset area of the monitoring database when one of the N verification results is a true risk; The verification module is further configured to: for one abnormal object among the N abnormal objects, Receive a first return request from a user terminal and a second return request from a verification terminal. The first return request includes a verification result from a user, and the second return request includes a verification result from a verification personnel; Determine that the verification result of the abnormal object is a true risk when the first return request is a true risk and / or the second return request is a true risk; Determine that the verification result of the abnormal object is a false risk when the first return request is a false risk and the second return request is a false risk.
7. An electronic device, comprising: One or more processors; A storage device, configured to store one or more programs, wherein, when the one or more programs are executed by the one or more processors, the one or more processors are caused to execute the method according to any one of claims 1 to 5.
8. A computer-readable storage medium, having executable instructions stored thereon, which when executed by a processor cause the processor to execute the method according to any one of claims 1 to 5.
9. A computer program product, comprising a computer program, which when executed by a processor implements the method according to any one of claims 1 to 5.
Citation Information
Patent Citations
A method and a device for identifying an abnormal user
CN108985553A