Method, device, electronic device and storage medium for identifying abnormal account
By constructing an account network structure and identifying partially collapsed networks, and by using account relationships and fund flows to calculate weight ratios, the problem of high misjudgment rate in small account identification is solved, achieving more accurate identification of abnormal accounts and reducing management burden and reputational damage.
Patent Information
- Application Number
- CN202110252154.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-03-08
- Publication Date
- 2026-02-03
- Estimated Expiration
- 2041-03-08
AI Technical Summary
Existing technologies have a high false positive rate when identifying auxiliary business accounts (small accounts), which increases the burden of account management and negatively impacts the reputation of platforms and merchants.
An account network structure is constructed. By identifying partially collapsed network structures, abnormal accounts are determined. Weight ratios are calculated using the relationships between accounts and the flow of funds to identify abnormal accounts.
It reduced the false alarm rate, decreased the management burden, and protected the reputation of the platform and merchants.
Smart Images

Figure CN115049396B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of computer technology, and in particular to a method, apparatus, electronic device, and storage medium for identifying abnormal accounts. Background Technology
[0002] With the rapid development of the internet, using electronic devices for activities such as playing games, shopping, and socializing has become an indispensable part of people's daily leisure and entertainment. Due to the need to conceal one's true identity, for the same activity, in addition to a primary account, people often apply for auxiliary accounts, which can be called "smurf accounts." However, when businesses conduct online promotional activities such as distributing red envelopes or coupons, individuals frequently manipulate a large number of these smurf accounts to participate in the activities and profit from them, causing businesses to suffer losses because the promotional effects are not achieved.
[0003] Currently, these types of fake accounts are typically identified based on attributes such as information during account registration, registration duration, account operation frequency, and transaction behavior characteristics.
[0004] However, during the identification process, the misjudgment rate is relatively high for some infrequently used real accounts or a small number of legitimately existing secondary accounts, resulting in incorrect account handling, affecting the normal use of accounts, increasing the burden of account management, and negatively impacting the reputation of the platform and merchants. Summary of the Invention
[0005] Based on the aforementioned technical issues, this application provides a method for identifying abnormal accounts, in order to identify accounts with collapsed financial relationships, reduce the false judgment rate and the management burden caused by false judgments, and at the same time avoid negative impacts on the reputation of the platform and merchants.
[0006] Other features and advantages of this application will become apparent from the following detailed description, or may be learned in part from practice of this application.
[0007] According to one aspect of the embodiments of this application, a method for identifying abnormal accounts is provided, comprising:
[0008] By using accounts as nodes and the relationships between two accounts as edges, an account network structure is constructed, consisting of multiple accounts.
[0009] Based on the relationships between accounts, a partially collapsed network structure is identified in the account network structure. In the partially collapsed network structure, there are first-degree accounts that are associated with the central account and second-degree accounts that are associated with the first-degree accounts. The account association status corresponding to the central account first expands with the first-degree accounts and then collapses with the second-degree accounts.
[0010] The first-degree accounts contained in the partially collapsed network are identified as abnormal accounts.
[0011] According to one aspect of the embodiments of this application, an abnormal account identification device is provided, comprising:
[0012] The building module is used to construct an account network structure consisting of multiple accounts, with accounts as nodes and the relationships between two accounts as edges.
[0013] The identification module is used to identify a partially collapsed network structure in the account network structure based on the relationship between accounts. In the partially collapsed network structure, there is a first-degree account that is associated with the central account and a second-degree account that is associated with the first-degree account. The account association status corresponding to the central account first expands with the first-degree account and then collapses with the second-degree account.
[0014] The determination module is used to identify the first-degree accounts contained in the locally collapsed network as abnormal accounts.
[0015] In the embodiments of this application, based on the above technical solution, the identification module 1302 may include:
[0016] The acquisition submodule is used to take each account in the account network structure as a central account, acquire first-degree accounts that are associated with the central account from the account network structure, and acquire second-degree accounts that are associated with the first-degree accounts.
[0017] The calculation submodule is used to calculate the collapse index of the local network structure formed by the central account, the first-degree account, and the second-degree account based on the association relationship between the first-degree account and the central account, and the association relationship between the second-degree account and the first-degree account.
[0018] The identification submodule is used to identify local network structures with collapse indices less than the account risk threshold as locally collapsed network structures.
[0019] In the embodiments of this application, based on the above technical solution, the acquisition sub-module includes:
[0020] The calculation unit is used to calculate the first-level weight of the central account based on the fund flow relationship between the central account and the first-level account;
[0021] The calculation unit is also used to calculate the second-degree weight of the central account based on the first-degree weight of the first-degree account, wherein the first-degree weight of the first-degree account is determined by using the first-degree account as the central account.
[0022] The calculation unit is also used to calculate the ratio between the second-degree weight and the first-degree weight of the central account, and to obtain the collapse index of the central account.
[0023] In the embodiments of this application, based on the above technical solution, the computing unit may include:
[0024] The quantity acquisition subunit is used to acquire the number of first-level accounts that transfer funds into the central account and the number of first-level accounts that receive funds transferred out of the central account.
[0025] The weighted sum calculation subunit is used to calculate the weighted sum of the number of first-level accounts and the number of first-level accounts receiving payments, so as to obtain the first-level weight of the central account.
[0026] In the embodiments of this application, based on the above technical solution, the computing unit may include:
[0027] The first-degree weight and calculation subunit is used to calculate the sum of the first-degree weights of all first-degree accounts, and obtain the sum of the first-degree weights of all first-degree accounts associated with the central account;
[0028] The second-degree weighting determines the sub-unit and is used to determine the second-degree weight of the central account based on the first-degree weight.
[0029] In the embodiments of this application, based on the above technical solution, the abnormal account identification device may further include:
[0030] The calculation unit is also used to calculate the first-level weight of the central account based on the fund flow relationship and non-fund relationship between the central account and the first-level account.
[0031] In the embodiments of this application, based on the above technical solution, the computing unit may include:
[0032] The quantity acquisition subunit is also used to acquire the number of first-level accounts that transfer funds into the central account, the number of first-level accounts that receive funds transferred out of the central account, and the number of special first-level accounts that have no financial relationship with the central account.
[0033] It is also used in conjunction with the calculation sub-unit to calculate the weighted sum between the number of first-level accounts, the number of first-level accounts receiving payments, and the number of special first-level accounts, in order to obtain the first-level weight of the central account.
[0034] In the embodiments of this application, based on the above technical solution, the abnormal account identification device may further include:
[0035] The determination module is also used to determine the mean and standard deviation of the collapse index based on the collapse index corresponding to all accounts in the account network structure.
[0036] The calculation module is used to calculate the account risk threshold based on the mean of the collapse index and the standard deviation of the weight ratio.
[0037] In the embodiments of this application, based on the above technical solution, the abnormal account identification device may further include:
[0038] The determination module is also used to determine the transfer frequency between the primary account and the primary account based on the time of fund transfer between the primary account and the primary account contained in the local network structure.
[0039] The identification module is also used to identify a local network structure as a partially collapsed network structure if the collapse index of the local network structure is less than the account risk threshold, the number of first-degree accounts is greater than a preset number threshold, and the transfer frequency between first-degree accounts and the central account is greater than a preset frequency threshold.
[0040] In the embodiments of this application, based on the above technical solution, the abnormal account identification device may further include:
[0041] The alarm module is used to handle alarms for abnormal accounts and to prohibit the execution of transfer operations related to abnormal accounts.
[0042] According to one aspect of the embodiments of this application, an electronic device is provided, the electronic device comprising: a processor; and a memory for storing executable instructions of the processor; wherein the processor is configured to perform an abnormal account identification method as described above by executing the executable instructions.
[0043] According to one aspect of the embodiments of this application, a computer-readable storage medium is provided, on which a computer program is stored, which, when executed by a processor, implements the method for abnormal account identification as described above.
[0044] According to one aspect of the embodiments of this application, a computer program product or computer program is provided, which includes computer instructions stored in a computer-readable storage medium. A processor of a computer device reads the computer instructions from the computer-readable storage medium and executes the computer instructions, causing the computer device to perform the method for abnormal account identification provided in the various optional implementations described above.
[0045] In the embodiments of this application, the weight ratio between accounts is determined based on the fund flow relationship between the central account and related accounts. Then, a risk threshold is determined based on the weight ratio between all accounts and related accounts. Finally, it is determined whether the related account is an abnormal account based on the risk threshold. Since the fund flow relationship between accounts itself constitutes a network structure, and the fund relationship of a small account is usually only related to a small number of accounts, including the main account, the weight ratio determined based on the fund flow relationship can identify the collapse scene of the account relationship, thereby identifying the small account with a collapsed fund relationship, reducing the false judgment rate and the management burden caused by false judgment, while avoiding negative impacts on the reputation of the platform and merchants.
[0046] It should be understood that the above general description and the following detailed description are exemplary and explanatory only, and do not limit this application. Attached Figure Description
[0047] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application. It is obvious that the drawings described below are merely some embodiments of this application, and those skilled in the art can obtain other drawings based on these drawings without any inventive effort. In the drawings:
[0048] Figure 1 This is a schematic diagram of the component architecture for an application scenario to which this application applies;
[0049] Figure 2 This is a flowchart illustrating an abnormal account identification method according to an embodiment of this application;
[0050] Figure 3 This is a schematic diagram of a locally collapsed network in an embodiment of this application;
[0051] Figure 4 This is a flowchart illustrating an abnormal account identification method according to an embodiment of this application;
[0052] Figure 5 This is a flowchart illustrating an abnormal account identification method according to an embodiment of this application;
[0053] Figure 6 This is a flowchart illustrating an abnormal account identification method according to an embodiment of this application;
[0054] Figure 7 This is a flowchart illustrating an abnormal account identification method according to an embodiment of this application;
[0055] Figure 8 This is a flowchart illustrating an abnormal account identification method according to an embodiment of this application;
[0056] Figure 9 This is a flowchart illustrating an abnormal account identification method according to an embodiment of this application;
[0057] Figure 10 This is a flowchart illustrating an abnormal account identification method according to an embodiment of this application;
[0058] Figure 11 This is a flowchart illustrating an abnormal account identification method according to an embodiment of this application;
[0059] Figure 12 This is a flowchart illustrating an abnormal account identification method according to an embodiment of this application;
[0060] Figure 13 A schematic block diagram illustrating the components of the abnormal account identification device in an embodiment of this application is shown.
[0061] Figure 14 A schematic diagram of the structure of a computer system suitable for implementing the electronic device of the present application is shown. Detailed Implementation
[0062] Exemplary embodiments will now be described more fully with reference to the accompanying drawings. However, these exemplary embodiments can be implemented in many forms and should not be construed as limited to the examples set forth herein; rather, these embodiments are provided to make this application more comprehensive and complete, and to fully convey the concept of the exemplary embodiments to those skilled in the art.
[0063] Furthermore, the described features, structures, or characteristics can be combined in any suitable manner in one or more embodiments. Numerous specific details are provided in the following description to give a thorough understanding of embodiments of this application. However, those skilled in the art will recognize that the technical solutions of this application can be practiced without one or more of the specific details, or other methods, components, apparatuses, steps, etc., can be employed. In other instances, well-known methods, apparatuses, implementations, or operations are not shown or described in detail to avoid obscuring various aspects of this application.
[0064] The block diagrams shown in the accompanying drawings are merely functional entities and do not necessarily correspond to physically independent entities. That is, these functional entities can be implemented in software, in one or more hardware modules or integrated circuits, or in different network and / or processor devices and / or microcontroller devices.
[0065] The flowcharts shown in the accompanying drawings are merely illustrative and do not necessarily include all content and operations / steps, nor do they necessarily have to be performed in the described order. For example, some operations / steps can be broken down, while others can be combined or partially combined; therefore, the actual execution order may change depending on the specific circumstances.
[0066] It should be understood that, in this application, an abnormal account can be a secondary account or a fraudulent account registered through cheating. A secondary account refers to an auxiliary business account registered in addition to the primary business account used by the account.
[0067] The proposed solution can be applied to various online services or applications, such as online games, e-commerce, payment applications, and online video platforms. For example, in online games, abnormal accounts can be secondary game accounts, i.e., game accounts used by players in addition to their main game account. Detecting these secondary accounts can help identify anomalies in virtual assets such as game resources distributed during game promotions or events, preventing individuals from using secondary accounts to acquire large amounts of virtual assets for profit. In e-commerce applications, abnormal accounts can be fake accounts, i.e., accounts specifically used for purposes such as deliberately leaving negative reviews, receiving red envelopes, and creating fake transaction volumes. Identifying such accounts can prevent the use of secondary accounts to disrupt the trading environment and engage in fraudulent activities, thus maintaining a fair environment on e-commerce platforms.
[0068] For ease of understanding, the scheme of this application is described below with reference to the accompanying drawings. Please refer to... Figure 1 , Figure 1 This is a schematic diagram of the system architecture of an abnormal account identification method provided in an embodiment of the present invention. The system may include at least one terminal 110, a data storage server 120, and a small account identification server 130.
[0069] At least one terminal 110 may run a business client 111 that implements specific business functions, such as Figure 1 The client application shown can be, but is not limited to, an online payment application. The terminal can be a smartphone, desktop computer, tablet, laptop, or other device with various operating systems.
[0070] The data storage server 120 can connect and communicate with the terminal 110 to provide business data storage services for the terminal 110. For example, it can collect and store relevant data information of the online payment program, which may include account information (e.g., account tags, personal information, outgoing amount, incoming amount, transaction records, and account social relationships).
[0071] The small account identification server 130 is responsible for identifying abnormal accounts. It can identify abnormal accounts (e.g., small accounts) based on the account information stored in the data storage server 120. The small account identification server 130 can also store the identification results and perform subsequent management operations (e.g., freezing, banning accounts, prohibiting transaction operations, etc.).
[0072] It should be noted that the solution of this application can be applied to personal computers, servers, or server systems composed of multiple servers. In order to improve the computing and storage capabilities for abnormal account identification, this application can also be applied to cloud platforms, cloud storage, or other computing systems.
[0073] Figure 1 For ease of understanding, this application is used as an example in online payment procedures. When using a single computing device, cloud platform, or server cluster for abnormal account identification, it is only necessary to... Figure 1 The servers in the shown scenario can be replaced with corresponding devices or server clusters, as the scenarios are similar and will not be elaborated upon here.
[0074] Cloud computing is a computing model that distributes computing tasks across a large pool of computers, enabling various application systems to access computing power, storage space, and information services as needed. The network providing these resources is called the "cloud." From the user's perspective, resources in the "cloud" appear infinitely scalable, readily available, on-demand, and expandable, with payment based on usage.
[0075] As a provider of fundamental cloud computing capabilities, a cloud resource pool (referred to as a cloud platform, generally called an IaaS (Infrastructure as a Service) platform) is established. Various types of virtual resources are deployed in the resource pool for external customers to choose from. The cloud resource pool mainly includes: computing devices (virtualized machines containing operating systems), storage devices, and network devices.
[0076] Based on logical function, a PaaS (Platform as a Service) layer can be deployed on top of the IaaS (Infrastructure as a Service) layer, and a SaaS (Software as a Service) layer can be deployed on top of the PaaS layer. Alternatively, SaaS can be deployed directly on top of IaaS. PaaS is a platform for running software, such as databases and web containers. SaaS refers to various types of business software, such as web portals and bulk SMS senders. Generally speaking, SaaS and PaaS are upper layers compared to IaaS.
[0077] The technical solution provided in this application will be described in detail below with reference to specific embodiments.
[0078] Please see Figure 2 , Figure 2 This is a flowchart illustrating an abnormal account identification method provided in an embodiment of the present invention. This method can be applied to... Figure 1 The small-sized identification server in the middle. It should be noted that this specification provides method operation steps as shown in the embodiments or flowcharts, but based on conventional or non-inventive labor, more or fewer operation steps may be included. The order of steps listed in the embodiments is only one of many possible execution orders and does not represent the only execution order. In actual system or product execution, the method can be executed sequentially according to the embodiments or drawings or in parallel (e.g., in a parallel processor or multi-threaded processing environment). Specifically, as shown in the figures... Figure 2 As shown, the method may include the following steps S201 to S203:
[0079] Step S201: Using accounts as nodes and the relationships between two accounts as edges, construct an account network structure consisting of multiple accounts.
[0080] Specifically, the account network structure can be an undirected graph, and it can be a connected graph. Understandably, starting from any point in the account network structure, a radial or tree-like structure can be formed. Within this radial or tree-like structure, as the hierarchy increases, the number of associated nodes will grow explosively due to the complex and diverse nature of real-world interpersonal relationships.
[0081] Step S202: Based on the relationship between accounts, identify a partially collapsed network in the account network structure. In the partially collapsed network, there are first-degree accounts that are related to the central account and second-degree accounts that are related to the first-degree accounts. The account relationship status corresponding to the central account first expands with the first-degree accounts and then collapses with the second-degree accounts.
[0082] Specifically, a partially collapsed network is part of an account network structure, and it is a tree-like or radial structure starting from a central account. A first-degree account is the account corresponding to a node in the account network structure that is connected to the central account by an edge, while a second-degree account is the account corresponding to a node that is connected to a first-degree account by an edge, and so on, thus identifying accounts at each level associated with the central account. Account association state refers to the number of accounts at each level that are associated in the association network centered on the central account. It is understandable that when a first-degree account is an abnormal account or a low-level account, its association with other second-degree accounts is relatively simpler than the actual association. Therefore, in a partially collapsed network, the account association state corresponding to the central account first expands with the expansion of first-degree accounts, and then collapses with the expansion of second-degree accounts.
[0083] Specifically, please refer to Figure 3 , Figure 3 This is a schematic diagram of a partially collapsed network in an embodiment of this application. Account A is the central account, accounts B1 to B12 are first-degree accounts, and accounts C1 and C2 are second-degree accounts. It can be seen that the account association state corresponding to the central account A expands with the first-degree accounts B1 to B12, and finally collapses with the second-degree accounts C1 and C2. Therefore, the central account A and the first-degree accounts B1 to B12 can be identified as a partially collapsed network, and the first-degree accounts B1 to B12 are identified as anomalous accounts.
[0084] Step S203: Identify the first-degree accounts contained in the locally collapsed network as abnormal accounts.
[0085] Specifically, in the identified partially collapsed network, it can be determined that the association relationship of its first-degree accounts does not conform to the real social relationship state, that is, the first-degree accounts in the partially collapsed network can be identified as abnormal accounts.
[0086] In the embodiments of this application, accounts are used as nodes, and the relationships between accounts are used as edges to construct an account network structure. Then, locally collapsed networks are identified from the account network structure, and first-degree accounts within these locally collapsed networks are identified as abnormal accounts. Since the relationships between accounts constitute the network structure, and the financial relationships of smaller accounts are usually only related to a small number of accounts, including the main account, the collapse phenomenon in account relationships can be identified based on these relationships. This allows for the identification of smaller accounts with collapse within the account network structure, reducing the false positive rate and the management burden caused by false positives, while also avoiding negative impacts on the reputation of the platform and merchants.
[0087] In one embodiment, to identify locally collapsed networks, specifically as follows: Figure 4As shown, step S202 above, which identifies the partially collapsed network structure in the account network structure based on the relationship between accounts, may include the following steps S401 to S403:
[0088] Step S401: Take each account in the account network structure as the central account, obtain the first-degree accounts that are related to the central account from the account network structure, and obtain the second-degree accounts that are related to the first-degree accounts.
[0089] The accounts in the account network structure can be the total set of all accounts involved in the application or platform used in this application, and the account network structure includes account information. The account network structure can be stored in a data storage server. The account information includes information on transactions that have occurred between related accounts. Related relationships refer to financial relationships where funds have been transferred to or from the central account, or various relationships such as friendships in social relationships. For example, if the solution of this application is applied to a game application or a payment application, the account network structure includes all registered accounts of that game application or payment application, and the account information includes virtual asset transaction information or financial transaction information between registered accounts. The central account can be any account in the account network structure. First-degree accounts are obtained from the account network structure that have a direct connection to the central account, and second-degree accounts are obtained from accounts that have a direct connection to the first-degree accounts.
[0090] For clarity, please refer to Table 1, which provides an example of account information:
[0091]
[0092] Table 1
[0093] In this context, Related Account 1 and Related Account 2 are the two accounts involved in the related relationship. Fund outflow refers to the total funds flowing from Related Account 1 to Related Account 2, while fund inflow refers to the total funds flowing from Related Account 2 to Related Account 1. Based on this account information, if Account A is the central account, then Accounts B, C, and D are first-degree accounts, and Account E is a second-degree account.
[0094] In embodiments of this application, the account identification server retrieves account information for a specific range of accounts from the data storage server. The specific range can be determined based on the account's own attributes, such as the account's registration time, most recent login time, or the time of its most recent transaction. The account information can also be filtered according to predetermined conditions, such as information where transactions occurred within a preset time range. Specifically, for example, the content of an account's information could be a summary of all transactions that occurred between the central account and associated accounts within the last three months.
[0095] It is understood that, in one embodiment, the account number identification server and the data storage server may be the same device, in which case the account number identification server can obtain the required account information from the stored information.
[0096] Step S402: Based on the relationship between the first-degree account and the central account, and the relationship between the second-degree account and the first-degree account, calculate the collapse index of the local network structure formed by the central account, the first-degree account, and the second-degree account.
[0097] The collapse index can be used to determine whether a relationship network consisting of a central account, first-degree accounts, and second-degree accounts is a collapsed network. Specifically, the local network structure is determined based on the relationships between the central account and first-degree accounts, as well as the relationships between the central account and second-degree accounts. Based on these relationships, starting with the central account, the number of associated accounts explodes as the number of intermediate accounts in the relationship increases. For example, if the number of accounts associated with the central account is 100, the number of second-degree accounts associated with the first-degree account may reach tens of thousands, and the number of third-degree accounts associated with tens of thousands of second-degree accounts may reach hundreds of thousands or even millions. However, for smaller accounts, since they lack social relationships, the number of associated accounts in the relationship network decreases sharply, thus forming a locally collapsed network.
[0098] Step S403: Identify local network structures with collapse indices less than the account risk threshold as locally collapsed network structures.
[0099] The account risk threshold can be determined based on the relationships between all accounts in the account network structure. It primarily indicates the degree to which a local network structure belongs to a collapsed network structure. The account risk threshold can be determined in advance based on all account information within the threshold, or it can be determined based on account information from historical data over a period of time. The account risk threshold is used to measure whether an account is a small or abnormal account. A local network structure with a collapse index below the account risk threshold indicates that there is a phenomenon of first-degree account expansion and second-degree account collapse within that local network structure; therefore, it can be identified as a locally collapsed network structure.
[0100] In the embodiments of this application, the collapse index of the local network structure is calculated through the association relationship between the central account, the first-degree account, and the second-degree account, and the local collapsed network structure is identified based on the collapse index. This can quantify the association relationship between the various accounts and fully consider the association relationship between the accounts in the process of identifying abnormal accounts, thereby improving the accuracy of abnormal account identification.
[0101] In one embodiment, the relationship includes fund transfer relationships. To calculate the collapse metric, it can be specifically as follows: Figure 5 As shown, step S402 above, which calculates the collapse index of the local network structure formed by the central account, the first-degree account, and the second-degree account based on the relationship between the first-degree account and the central account, and the relationship between the second-degree account and the first-degree account, may include the following steps S501 to S503:
[0102] Step S501: Calculate the first-degree weight of the central account based on the fund transfer relationship between the central account and the first-degree account;
[0103] Step S502: Calculate the second-degree weight of the central account based on the first-degree weight of the first-degree account, wherein the first-degree weight of the first-degree account is determined by using the first-degree account as the central account.
[0104] Step S503: Calculate the ratio between the second-degree weight and the first-degree weight of the central account to obtain the collapse index of the central account.
[0105] Specifically, fund transfer relationships refer to situations where funds are transferred out or in between accounts. The first-degree weight of a central account is determined based on the relationship between the central account and its first-degree accounts. Therefore, it can be understood that the first-degree weight of a central account represents the degree of correlation between the central account and its first-degree accounts. The first-degree weight of a first-degree account is determined with the first-degree account acting as the central account. It can be understood that when a first-degree account acts as the central account, its second-degree accounts can be either the original central account itself or its second-degree accounts. For clarity, please refer to [link to relevant documentation]. Figure 2 When account A is the central account, the first-degree weight of account A is determined based on the first-degree accounts B1 to B12. The first-degree weight of first-degree account B6 is determined based on account A and second-degree account C1 (both are first-degree accounts relative to account B6).
[0106] The collapse metric for a central account is calculated based on the ratio between its second-degree weight and its first-degree weight. For example, for central account A, it can be calculated using the following formula:
[0107]
[0108] Wherein, weight S A F is the collapse indicator for central account A. A2 For the second-degree weighting of the central account, F A1 The first-degree weight of the central account is used for the collapse indicator. Understandably, for the collapse indicator, without considering the direction of fund inflows or outflows, and only considering the existence of fund transfer relationships, the account itself is the counterparty of the counterparty account, so the collapse indicator is usually greater than or equal to 1. However, if only the unidirectional flow of funds inflows or outflows is considered, and the funds between the central account, first-degree account, and second-degree account are all unidirectional, S may be less than 1 or even 0. A larger S value indicates normal and rapid network expansion, while a smaller S value indicates rapid network collapse after first-degree expansion, with a higher risk of the first-degree counterparty being an abnormal account.
[0109] In the embodiments of this application, the first-degree weight and second-degree weight of the central account are determined based on the fund flow relationship between the central account and the first-degree account. Then, the ratio between the first-degree account and the second-degree account is calculated as the collapse index. A specific method for determining the collapse index is proposed, which improves the feasibility of the scheme.
[0110] In one embodiment, to calculate the first-degree weight of the central account, it can be specifically as follows: Figure 6 As shown, step S501 above, which calculates the first-degree weight of the central account based on the fund flow relationship between the central account and the first-degree account, may include the following steps S601 to S602:
[0111] Step S601: Obtain the number of first-level accounts that transfer funds to the central account and the number of first-level accounts that receive funds transferred out of the central account.
[0112] Step S602: Calculate the weighted sum of the number of first-level accounts and the number of first-level accounts to obtain the first-level weight of the central account.
[0113] Specifically, the calculation of the first-degree weight mainly depends on the fund flow relationship between the central account and the first account, and the first-degree weight can be calculated according to the following formula:
[0114]
[0115] in, This indicates the number of accounts that have been billed at one time, while The table shows the number of first-level accounts receiving funds, F1 as the first-level weight, N as the total number of first-level accounts sending funds, M as the total number of first-level accounts receiving funds, FLOWout as the first-level account receiving transfers from the central account, FLOWin as the first-level account sending transfers to the central account, P as the outgoing weighting value, and Q as the incoming weighting value. The outgoing and incoming weighting values represent the importance of outgoing and incoming funds within the first-level weight. The values of P and Q can be determined based on the specific implementation. For example, in cash withdrawal scenarios, there might be a large number of smaller accounts receiving funds and then transferring them to the central account, while the central account would not transfer funds to these smaller accounts. Therefore, the incoming weighting value could be appropriately increased.
[0116] In the embodiments of this application, a weighted sum is calculated as the first-degree weight of the central account based on the number of funds deposited into and into the first-degree accounts between the central account and the first-degree accounts. This can fully reflect the fund relationship between the accounts. Furthermore, by using a weighted sum, the different effects of outflow and inflow funds on the first-degree accounts can be considered in different scenarios, making the determination of the first-degree weight more flexible.
[0117] In one embodiment, to calculate the first-degree weight of the central account, it can be specifically as follows: Figure 7 As shown, step S502 above, which calculates the second-degree weight of the central account based on the first-degree weight of the first-degree account, may include the following steps S701 to S702:
[0118] Step S701: Calculate the sum of the first-degree weights of all first-degree accounts to obtain the sum of the first-degree weights of all first-degree accounts associated with the central account;
[0119] Step S702: Determine the second-degree weight of the central account based on the first-degree weight.
[0120] Specifically, as mentioned above, the first-degree weight of a first-degree account is calculated by using the first-degree account as the central account. That is, the first-degree weight of a first-degree account can be determined based on the central account, second-degree accounts, and possibly other first-degree accounts. After calculating the weights of all first-degree accounts, they are summed to obtain the sum of the first-degree weights. This can be calculated using the following formula:
[0121]
[0122] Where F2 is the second-degree weight of the central account, F1 is the first-degree weight of the first-degree account, and N is the number of first-degree accounts.
[0123] In one embodiment, the first-degree weights can be directly identified as the second-degree weights of the central account. However, in another embodiment, the second-degree weights can be the result of the first-degree weights after appropriate weighting and processing. For example, in a first-degree account set, some accounts may have normal relationships, and the first-degree weights of these accounts can be removed from the first-degree weights. Alternatively, the second-degree weights can be implemented in other ways, such as the average of the first-degree weights of the first-degree accounts.
[0124] In the embodiments of this application, the second-degree weight of the central account is calculated by summing the first-degree weights of the first-degree accounts, thereby reflecting the relationship between the central account and the second-degree accounts. This helps to demonstrate the collapse phenomenon of the locally collapsing network after expansion and improves the accuracy of the algorithm.
[0125] In one embodiment, the relationship also includes non-financial relationships, specifically such as... Figure 8 As shown, the method may further include the following step S801:
[0126] Step S801: Calculate the first-degree weight of the central account based on the fund transfer relationship and non-fund relationship between the central account and the first-degree account.
[0127] Non-funding relationships refer to relationships between two accounts other than fund transfers, such as friendship, communication, and virtual relationships. For example, in games, non-funding relationships could mean that the accounts belong to the same game group or share the same login information.
[0128] In this embodiment, the small account identification server calculates the first-degree weight of the central account based on the fund flow relationship and non-fund flow relationship between the central account and the first-degree account. Specifically, there can be various non-fund flow relationships between the central account and the first-degree account. Each different non-fund flow relationship can correspond to a different preset calculation value, so that the first-degree weight can be calculated together based on the results calculated from the fund flow relationship. For example, there can be a friend relationship between the central account and the first-degree account, so when calculating the first-degree weight, the preset calculation value corresponding to the friend relationship can also be used. It can be understood that the preset calculation value can be determined according to the order of magnitude of the fund flow relationship between the central account and the first-degree account. For example, if the fund flow relationship mainly occurs on the order of thousands of yuan, the preset calculation value can also be set on the order of thousands. This can avoid the non-fund flow relationship having too large or too small an impact on the first-degree weight.
[0129] In the embodiments of this application, the first-degree weight of the central account is calculated based on the fund flow relationship and non-fund relationship between the central account and the first-degree account. This introduces non-fund relationship into the calculation of the first-degree weight, making the first-degree weight more reflective of the relationship between the central account and the first-degree account, thereby improving the accuracy of judging abnormal accounts.
[0130] In one embodiment, to calculate the first-degree weight of the central account, it can be specifically as follows: Figure 9 As shown, step S801 above, which calculates the first-degree weight of the central account based on the fund transfer relationship and non-fund relationship between the central account and the first-degree account, may include the following steps S901 to S902:
[0131] Step S901: Obtain the number of first-level accounts that transfer funds to the central account, the number of first-level accounts that receive funds transferred out of the central account, and the number of special first-level accounts that have no financial relationship with the central account.
[0132] Step S902: Calculate the weighted sum among the number of first-level accounts, the number of first-level accounts receiving payments, and the number of special first-level accounts to obtain the first-level weight of the central account.
[0133] The definitions of the number of accounts with outgoing funds and the number of accounts with incoming funds are the same as those described in step S601 in the above embodiments, and will not be repeated here.
[0134] The number of special first-level accounts is determined based on the number of first-level accounts that have non-funding relationships with the central account. Specifically, there may be one or more non-funding relationships between the central account and first-level accounts, or there may be no corresponding relationship. When there is one non-funding relationship, the number of special first-level accounts can be directly determined based on the special first-level accounts corresponding to that non-funding relationship. When there are multiple non-funding relationships, the number of special first-level accounts can be the sum of the number of special first-level accounts corresponding to each non-funding relationship. Alternatively, the number of non-funding relationships can be disregarded, and only the existence of non-funding relationships can be considered. In this case, the number of special first-level accounts is the total number of first-level accounts that have one or more non-funding relationships with the central account.
[0135] After obtaining the number of special first-degree accounts, the account recognition server can calculate the weighted sum of the number of first-degree accounts credited, the number of first-degree accounts credited, and the number of special first-degree accounts to obtain the first-degree weight of the central account. Specifically, it can be calculated using the following formula:
[0136]
[0137] in, To account for the number of transactions, and To record the number of first-level accounts, Here, F1 represents the first-degree account weight, N represents the number of first-degree accounts sending funds, M represents the number of first-degree accounts receiving funds, FLOWout represents first-degree accounts receiving transfers from the central account, and FLOWin represents first-degree accounts transferring funds to the central account. P is the outgoing weighting value, Q is the incoming weighting value, W is the special weighting value, T represents the type of non-funding relationship between the central account and first-degree accounts, and UNflow represents first-degree accounts with non-funding relationships to the central account. The special weighting value W can be determined based on the importance of non-funding relationships to the first-degree weight and the specific implementation environment. For example, in payment scenarios, since the importance of friend relationships for abnormal account identification in payment applications is usually low, the special weighting value W can be appropriately reduced.
[0138] In the embodiments of this application, a weighted sum is calculated as the first-degree weight of the central account based on the number of first-degree accounts receiving funds, the number of first-degree accounts receiving funds, and the number of special first-degree accounts between the central account and the first-degree accounts. This can fully take into account the contribution of various relationships other than financial relationships to the first-degree weight. Furthermore, by using a weighted sum, the different importance of non-financial relationships to the first-degree account can be considered when facing different scenarios, making the confirmation of the first-degree weight more flexible.
[0139] In one embodiment, to calculate the account risk threshold, specifically as follows: Figure 10 As shown, the method for identifying abnormal accounts in this application embodiment may further include the following steps S1001 to S1002:
[0140] Step S1001: Determine the mean and standard deviation of the collapse index based on the collapse index corresponding to all accounts in the account network structure.
[0141] Step S1002: Calculate the account risk threshold based on the mean of the collapse index and the standard deviation of the weight ratio.
[0142] In this structure, the collapse indices for all accounts in the account network can be pre-calculated and stored results. The mean of the collapse indices is the average of the collapse indices for all accounts, and the standard deviation of the collapse indices is the standard deviation of the collapse indices for all accounts. The meaning of the standard deviation is the same as the conventional definition of standard deviation.
[0143] After determining the mean and standard deviation of the collapse index, the account risk identification server calculates the account risk threshold based on the mean of the collapse index and the standard deviation of the weight ratio. Specifically, the account risk threshold can be the difference between the mean of the collapse index and the standard deviation of the weight ratio, and can be calculated as follows: S` = S 均值 -3S 标准差Where S' is the account risk threshold, S 均值 S is the mean of the collapse index. 标准差 Given the standard deviation of the collapse index, it can be seen that the account risk threshold is the mean of the collapse index minus three times the standard deviation of the collapse index.
[0144] It is understood that the above calculation methods for the mean and standard deviation of the collapse index are only examples. In specific implementations, other standard deviation multiples can also be used. This application does not show the specific calculation methods.
[0145] In one embodiment, the relationship includes fund transfer relationships, specifically as follows: Figure 11 As shown, the method for identifying abnormal accounts in this application embodiment may further include the following steps S1101 to S1102:
[0146] Step S1101: Determine the transfer frequency between the primary account and the primary account based on the time of fund transfer between the primary account and the primary account contained in the local network structure.
[0147] Step S1102: If the collapse index of the local network structure is less than the account risk threshold, the number of first-degree accounts is greater than the preset number threshold, and the transfer frequency between first-degree accounts and the central account is greater than the preset frequency threshold, then the local network structure is identified as a locally collapsed network structure.
[0148] The time frame for fund transfers can be either the time of each individual transfer or the time of the most recent transfer. Specifically, the secondary account identification server can determine the transfer frequency between each secondary account and the central account based on the fund transfer history between the central account and each primary account. This transfer frequency helps identify secondary accounts that frequently transfer funds to the central account, thus allowing for more targeted identification of accounts specifically used for grabbing resources such as red envelopes.
[0149] In this embodiment, the number of first-degree accounts is also considered when identifying the local collapse network structure. In practical applications, it is reasonable for a user to have multiple accounts in many cases, such as in gaming applications where users often register multiple accounts. Therefore, by setting the frequency of first-degree accounts, the existence of a small number of secondary accounts can be allowed, while only identifying cases with a large number of secondary accounts.
[0150] Therefore, when the small account identification server identifies that the collapse index of the local network structure is less than the account risk threshold, it also determines that the number of first-degree accounts in the local network structure is greater than the preset number threshold, and the transfer frequency between the first-degree accounts and the central account is greater than the preset frequency threshold. Only then is the local network structure identified as a partially collapsed network structure.
[0151] In the embodiments of this application, when identifying a partially collapsed network structure, the transfer frequency is determined based on the time of fund transfers between the central account and the primary accounts. Then, the partially collapsed network structure is identified based on the collapse index of the local network structure, the number of primary accounts, and the transfer frequency. By taking into account the number of primary accounts and the transfer frequency, a small number of smaller accounts can be identified while a large number of smaller accounts are identified, thus avoiding the identification of a user's reasonably existing small number of smaller accounts as abnormal accounts and improving the accuracy of identification.
[0152] In one embodiment, it can be specifically as follows: Figure 12 As shown, after identifying the first-degree accounts contained in the local collapse network as abnormal accounts in step S203 above, the abnormal account identification method in this embodiment of the application may further include the following step S1201:
[0153] Step S1201: Alarm processing is performed for abnormal accounts, and risk control processing is performed for transfer operations related to the abnormal accounts.
[0154] Alarm processing for abnormal accounts may include sending a notification message to the abnormal account within the application to which the solution described in this application is applied. When the abnormal account logs into the application, or when the abnormal account performs user operations such as fund transfers, the notification message is displayed through the application to inform the user of the abnormal status. For abnormal accounts, the account identification server can perform risk control processing on fund transfers related to the abnormal account. Specifically, this includes prohibiting transfers to and from the abnormal account, or delaying transfers involving the abnormal account, or requiring additional confirmation, verification, or human-computer interaction to make it difficult to perform automatic batch processing on abnormal accounts.
[0155] In one embodiment, the account identification server can also store the identified abnormal accounts in a database. When other servers of the application perform account-related operations, they can first query the database to see if the account involved in the operation is an abnormal account, and then perform operations such as pausing, adding confirmation, issuing alarms, or directly terminating operations involving abnormal accounts.
[0156] In the embodiments of this application, alarm processing and prohibition of transfer operations are performed for abnormal accounts. Since manual management of abnormal accounts is avoided, the management efficiency of abnormal accounts can be improved.
[0157] It should be noted that although the steps of the method in this application are described in a specific order in the accompanying drawings, this does not require or imply that the steps must be performed in that specific order, or that all the steps shown must be performed to achieve the desired result. Additional or alternative steps may be omitted, multiple steps may be combined into one step, and / or one step may be broken down into multiple steps.
[0158] The following describes the implementation of the apparatus of this application, which can be used to perform the abnormal account identification method in the above embodiments of this application. Figure 13 A schematic block diagram illustrating the components of an abnormal account identification device in an embodiment of this application is shown. Figure 13 As shown, the abnormal account identification device 1300 mainly includes:
[0159] Module 1301 is used to construct an account network structure consisting of multiple accounts, with accounts as nodes and the relationships between two accounts as edges.
[0160] The identification module 1302 is used to identify a partially collapsed network structure in the account network structure based on the relationship between accounts. In the partially collapsed network structure, there is a first-degree account that is associated with the central account and a second-degree account that is associated with the first-degree account. The account association status corresponding to the central account first expands with the first-degree account and then collapses with the second-degree account.
[0161] The determination module 1303 is used to determine the first-degree account contained in the local collapse network as an abnormal account.
[0162] In the embodiments of this application, based on the above technical solution, the identification module 1302 may include:
[0163] The acquisition submodule is used to take each account in the account network structure as a central account, acquire first-degree accounts that are associated with the central account from the account network structure, and acquire second-degree accounts that are associated with the first-degree accounts.
[0164] The calculation submodule is used to calculate the collapse index of the local network structure formed by the central account, the first-degree account, and the second-degree account based on the association relationship between the first-degree account and the central account, and the association relationship between the second-degree account and the first-degree account.
[0165] The identification submodule is used to identify local network structures with collapse indices less than the account risk threshold as locally collapsed network structures.
[0166] In the embodiments of this application, based on the above technical solution, the acquisition sub-module includes:
[0167] The calculation unit is used to calculate the first-level weight of the central account based on the fund flow relationship between the central account and the first-level account;
[0168] The calculation unit is also used to calculate the second-degree weight of the central account based on the first-degree weight of the first-degree account, wherein the first-degree weight of the first-degree account is determined by using the first-degree account as the central account.
[0169] The calculation unit is also used to calculate the ratio between the second-degree weight and the first-degree weight of the central account, and to obtain the collapse index of the central account.
[0170] In the embodiments of this application, based on the above technical solution, the computing unit may include:
[0171] The quantity acquisition subunit is used to acquire the number of first-level accounts that transfer funds into the central account and the number of first-level accounts that receive funds transferred out of the central account.
[0172] The weighted sum calculation subunit is used to calculate the weighted sum of the number of first-level accounts and the number of first-level accounts receiving payments, so as to obtain the first-level weight of the central account.
[0173] In the embodiments of this application, based on the above technical solution, the computing unit may include:
[0174] The first-degree weight and calculation subunit is used to calculate the sum of the first-degree weights of all first-degree accounts, and obtain the sum of the first-degree weights of all first-degree accounts associated with the central account;
[0175] The second-degree weighting determines the sub-unit and is used to determine the second-degree weight of the central account based on the first-degree weight.
[0176] In the embodiments of this application, based on the above technical solution, the abnormal account identification device 1300 may further include:
[0177] The calculation unit is also used to calculate the first-level weight of the central account based on the fund flow relationship and non-fund relationship between the central account and the first-level account.
[0178] In the embodiments of this application, based on the above technical solution, the computing unit may include:
[0179] The quantity acquisition subunit is also used to acquire the number of first-level accounts that transfer funds into the central account, the number of first-level accounts that receive funds transferred out of the central account, and the number of special first-level accounts that have no financial relationship with the central account.
[0180] It is also used in conjunction with the calculation sub-unit to calculate the weighted sum between the number of first-level accounts, the number of first-level accounts receiving payments, and the number of special first-level accounts, in order to obtain the first-level weight of the central account.
[0181] In the embodiments of this application, based on the above technical solution, the abnormal account identification device 1300 may further include:
[0182] The determination module 1303 is also used to determine the mean and standard deviation of the collapse index based on the collapse index corresponding to all accounts in the account network structure.
[0183] The calculation module is used to calculate the account risk threshold based on the mean of the collapse index and the standard deviation of the weight ratio.
[0184] In the embodiments of this application, based on the above technical solution, the abnormal account identification device 1300 may further include:
[0185] The determination module 1303 is also used to determine the transfer frequency between the primary account and the primary account based on the time of fund transfer between the primary account and the primary account contained in the local network structure.
[0186] The identification module 1302 is also used to identify the local network structure as a locally collapsed network structure if the collapse index of the local network structure is less than the account risk threshold, the number of first-degree accounts is greater than the preset number threshold, and the transfer frequency between first-degree accounts and the central account is greater than the preset frequency threshold.
[0187] In the embodiments of this application, based on the above technical solution, the abnormal account identification device 1300 may further include:
[0188] The alarm module is used to handle alarms for abnormal accounts and to prohibit the execution of transfer operations related to abnormal accounts.
[0189] It should be noted that the apparatus provided in the above embodiments and the method provided in the above embodiments belong to the same concept, and the specific way in which each module performs the operation has been described in detail in the method embodiments, and will not be repeated here.
[0190] Figure 14 A schematic diagram of the structure of a computer system suitable for implementing the electronic device of the present application is shown.
[0191] It should be noted that, Figure 14 The computer system 1400 of the electronic device shown is merely an example and should not impose any limitation on the functionality and scope of use of the embodiments of this application.
[0192] like Figure 14As shown, the computer system 1400 includes a Central Processing Unit (CPU) 1401, which can perform various appropriate actions and processes based on programs stored in Read-Only Memory (ROM) 1402 or programs loaded from Storage Unit 1408 into Random Access Memory (RAM) 1403. The RAM 1403 also stores various programs and data required for system operation. The CPU 1401, ROM 1402, and RAM 1403 are interconnected via a bus 1404. An Input / Output (I / O) interface 1405 is also connected to the bus 1404.
[0193] The following components are connected to I / O interface 1405: an input section 1406 including a keyboard, mouse, etc.; an output section 1407 including a cathode ray tube (CRT), liquid crystal display (LCD), etc., and speakers, etc.; a storage section 1408 including a hard disk, etc.; and a communication section 1409 including a network interface card such as a LAN (Local Area Network) card, modem, etc. The communication section 1409 performs communication processing via a network such as the Internet. A drive 1410 is also connected to I / O interface 1405 as needed. Removable media 1411, such as a disk, optical disk, magneto-optical disk, semiconductor memory, etc., are installed on drive 1410 as needed so that computer programs read from them can be installed into storage section 1408 as needed.
[0194] Specifically, according to embodiments of this application, the processes described in the various method flowcharts can be implemented as computer software programs. For example, embodiments of this application include a computer program product comprising a computer program carried on a computer-readable medium, the computer program containing program code for performing the methods shown in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network via communication section 1409, and / or installed from removable medium 1411. When the computer program is executed by central processing unit (CPU) 1401, it performs various functions defined in the system of this application.
[0195] It should be noted that the computer-readable medium shown in the embodiments of this application can be a computer-readable signal medium, a computer-readable storage medium, or any combination of the two. A computer-readable storage medium can be, for example,—but not limited to—an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples of a computer-readable storage medium may include, but are not limited to: an electrical connection having one or more wires, a portable computer disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM), flash memory, optical fiber, portable compact disc read-only memory (CD-ROM), optical storage device, magnetic storage device, or any suitable combination thereof. In this application, a computer-readable storage medium can be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. In this application, a computer-readable signal medium can include a data signal propagated in baseband or as part of a carrier wave, carrying computer-readable program code. Such transmitted data signals can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. The computer-readable signal medium can also be any computer-readable medium other than a computer-readable storage medium, which can send, propagate, or transmit a program for use by or in connection with an instruction execution system, apparatus, or device. The program code contained on the computer-readable medium can be transmitted using any suitable medium, including but not limited to wireless, wired, etc., or any suitable combination thereof.
[0196] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of this application. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in a block diagram or flowchart, and combinations of blocks in a block diagram or flowchart, may be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.
[0197] It should be noted that although several modules or units for the device used to perform actions have been mentioned in the detailed description above, this division is not mandatory. In fact, according to the embodiments of this application, the features and functions of two or more modules or units described above can be embodied in one module or unit. Conversely, the features and functions of one module or unit described above can be further divided and embodied by multiple modules or units.
[0198] Through the above description of the embodiments, those skilled in the art will readily understand that the exemplary embodiments described herein can be implemented by software or by combining software with necessary hardware. Therefore, the technical solutions according to the embodiments of this application can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (such as a CD-ROM, USB flash drive, external hard drive, etc.) or on a network, including several instructions to cause a computing device (such as a personal computer, server, touch terminal, or network device, etc.) to execute the methods according to the embodiments of this application.
[0199] Other embodiments of this application will readily occur to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. This application is intended to cover any variations, uses, or adaptations of this application that follow the general principles of this application and include common knowledge or customary techniques in the art not disclosed herein.
[0200] It should be understood that this application is not limited to the precise structure described above and shown in the accompanying drawings, and various modifications and changes can be made without departing from its scope. The scope of this application is limited only by the appended claims.
Claims
1. A method for identifying abnormal accounts, characterized in that, include: By using accounts as nodes and the relationships between two accounts as edges, an account network structure is constructed, consisting of multiple accounts. Based on the relationships between accounts, a partially collapsed network structure is identified in the account network structure. In the partially collapsed network structure, there are first-degree accounts that are associated with the central account, and there are second-degree accounts that are associated with the first-degree accounts. The first-degree account refers to the account corresponding to the node that is connected to the central account in the account network structure by an edge. The second-degree account is the account corresponding to the node that is connected to the first-degree account by an edge. The association state of the account corresponding to the central account first expands with the first-degree account and then collapses with the second-degree account. The first-degree accounts contained in the partially collapsed network structure are identified as abnormal accounts.
2. The method according to claim 1, characterized in that, The step of identifying partially collapsed network structures in the account network structure based on the relationships between accounts includes: Each account in the account network structure is taken as a central account. First-degree accounts that are associated with the central account are obtained from the account network structure, and second-degree accounts that are associated with the first-degree accounts are obtained. Based on the association between the first-degree account and the central account, and the association between the second-degree account and the first-degree account, calculate the collapse index of the local network structure formed by the central account, the first-degree account, and the second-degree account; Local network structures with collapse indices below the account risk threshold are identified as locally collapsed network structures.
3. The method according to claim 2, characterized in that, The relationships include fund transfer relationships; the calculation of the collapse index of the local network structure formed by the central account, the first-degree account, and the second-degree account, based on the relationships between the first-degree account and the central account, and the relationships between the second-degree account and the first-degree account, includes: Calculate the first-degree weight of the central account based on the fund flow relationship between the central account and the first-degree account; The second-degree weight of the central account is calculated based on the first-degree weight of the first-degree account, wherein the first-degree weight of the first-degree account is determined with the first-degree account as the central account. The ratio between the second-degree weight and the first-degree weight of the central account is calculated to obtain the collapse index of the central account.
4. The method according to claim 3, characterized in that, The step of calculating the first-degree weight of the central account based on the fund flow relationship between the central account and the first-degree account includes: Obtain the number of first-level accounts that transfer funds to the central account and the number of first-level accounts that receive funds transferred out of the central account. Calculate the weighted sum of the number of first-level accounts that issue funds and the number of first-level accounts that receive funds to obtain the first-level weight of the central account.
5. The method according to claim 3, characterized in that, The step of calculating the second-degree weight of the central account based on the first-degree weight of the first-degree account includes: Calculate the sum of the first-degree weights of all the first-degree accounts to obtain the sum of the first-degree weights of all the first-degree accounts associated with the central account; The second-degree weight of the central account is determined based on the first-degree weight.
6. The method according to claim 3, characterized in that, The relationship also includes non-financial relationships; the method further includes: The first-degree weight of the central account is calculated based on the fund transfer relationship and non-fund relationship between the central account and the first-degree account.
7. The method according to claim 6, characterized in that, The step of calculating the first-degree weight of the central account based on the fund flow relationship and non-fund relationship between the central account and the first-degree account includes: The system obtains the number of first-level accounts that transfer funds to the central account, the number of first-level accounts that receive funds transferred out of the central account, and the number of special first-level accounts that have no financial relationship with the central account. Calculate the weighted sum among the number of first-level accounts for outgoing payments, the number of first-level accounts for incoming payments, and the number of special first-level accounts to obtain the first-level weight of the central account.
8. The method according to claim 2, characterized in that, The method further includes: Based on the collapse index corresponding to all accounts in the account network structure, determine the mean and standard deviation of the collapse index. The account risk threshold is calculated based on the mean and standard deviation of the collapse index.
9. The method according to claim 2, characterized in that, The relationship includes fund transfer relationships; the method further includes: The transfer frequency between the primary account and the primary account is determined based on the time of fund transfer between the primary account and the primary account contained in the local network structure. If the collapse index of the local network structure is less than the account risk threshold, the number of first-degree accounts is greater than a preset number threshold, and the transfer frequency between the first-degree accounts and the central account is greater than a preset frequency threshold, then the local network structure is identified as a locally collapsed network structure.
10. The method according to any one of claims 1-9, characterized in that, After identifying the first-degree accounts contained in the locally collapsed network structure as anomalous accounts, the method further includes: Alarms are issued for the abnormal accounts, and risk control measures are implemented for transfer operations related to the abnormal accounts.
11. An abnormal account identification device, characterized in that, include: The building module is used to construct an account network structure consisting of multiple accounts, with accounts as nodes and the relationships between two accounts as edges. The identification module is used to identify a partially collapsed network structure in the account network structure based on the relationship between accounts. In the partially collapsed network structure, there are first-degree accounts that are associated with the central account and second-degree accounts that are associated with the first-degree accounts. The first-degree account refers to the account corresponding to the node that is connected to the central account in the account network structure by an edge. The second-degree account is the account corresponding to the node that is connected to the first-degree account by an edge. The association state of the account corresponding to the central account first expands with the first-degree account and then collapses with the second-degree account. The determination module is used to identify the first-degree accounts contained in the local collapse network structure as abnormal accounts.
12. The abnormal account identification device according to claim 11, characterized in that, The identification module includes: The acquisition submodule is used to take each account in the account network structure as a central account, acquire first-degree accounts that are associated with the central account from the account network structure, and acquire second-degree accounts that are associated with the first-degree accounts. The calculation submodule is used to calculate the collapse index of the local network structure formed by the central account, the first-degree account, and the second-degree account based on the association relationship between the first-degree account and the central account, and the association relationship between the second-degree account and the first-degree account. The identification submodule is used to identify local network structures with collapse indices less than the account risk threshold as locally collapsed network structures.
13. The abnormal account identification device according to claim 12, characterized in that, The acquisition submodule includes: The calculation unit is used to calculate the first-degree weight of the central account based on the fund flow relationship between the central account and the first-degree account; The calculation unit is further configured to calculate the second-degree weight of the central account based on the first-degree weight of the first-degree account, wherein the first-degree weight of the first-degree account is determined with the first-degree account as the central account. The calculation unit is also used to calculate the ratio between the second-degree weight and the first-degree weight of the central account to obtain the collapse index of the central account.
14. An electronic device, characterized in that, include: processor; Memory for storing the executable instructions of the processor; The processor is configured to perform the method for identifying abnormal accounts according to any one of claims 1 to 10 by executing the executable instructions.
15. A computer-readable medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the method for identifying abnormal accounts as described in any one of claims 1 to 10.
16. A computer program product, characterized in that, The computer program product includes computer instructions stored in a computer-readable storage medium, a processor of a computer device reading the computer instructions from the computer-readable storage medium, and the processor executing the computer instructions to cause the computer device to perform the method for identifying abnormal accounts as described in any one of claims 1 to 10.
Citation Information
Patent Citations
Method and device for computer to identify batch accounts
CN105812195A
System for anomaly detection and remediation based on dynamic directed graph network flow analysis
US20200167786A1