Abnormal user identification method and apparatus

By combining data from banks and telecom operators and using a joint neural network model to identify abnormal users, the problem of identifying telecom fraud users in the banking system has been solved, achieving more efficient and accurate user identification.

CN115271930BActive Publication Date: 2026-02-03INDUSTRIAL AND COMMERCIAL BANK OF CHINA
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202210991550.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-08-18
Publication Date
2026-02-03
Estimated Expiration
2042-08-18

AI Technical Summary

Technical Problem

The existing banking system struggles to efficiently and accurately identify users involved in telecom fraud, primarily due to the limited availability of data within banks, resulting in poor identification outcomes.

Method used

By combining data from the bank and the operator, a joint neural network model is used for user identification. This model acquires and matches data features and identification information from both the bank and the operator to generate a joint neural network model that identifies whether a user is an abnormal user.

Benefits of technology

While ensuring data privacy and security, it can more efficiently and accurately identify abnormal users, improving the accuracy and efficiency of identification.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115271930B_ABST
    Figure CN115271930B_ABST
Patent Text Reader

Abstract

Embodiments of the present application provide a non-normal user identification method and device. The non-normal user identification device comprises a first acquisition unit, a matching unit, a second acquisition unit, a generation unit and an identification unit. Thus, based on the first data of the bank-side user and the second data of the operator-side user, i.e. multi-party data, and in the case of ensuring the privacy and security of the data of each party, the bank-side logged-in user can be more efficiently and accurately identified as a non-normal user.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of computer, in particular to a non-normal user identification method and device. BACKGROUND

[0002] At present, in order to improve user experience and business efficiency, users usually log in to the bank system by using mobile banking. Mobile banking refers to a channel mode in which the bank uses a smart phone as a carrier to enable users to use bank services on the terminal. With the progress of communication and Internet technology, the business functions of mobile banking are constantly updated and improved. By connecting the mobile phone of the customer to the bank through the mobile communication network, the customer can directly complete various financial businesses such as account inquiry and account transfer through the mobile phone interface. That is, the bank uses a mobile phone as a carrier, relies on a mobile GSM wireless network, uses mobile short message resources, and sends short messages to operate the bank account through the mobile phone to realize functions such as mobile "financial management" and "electronic wallet".

[0003] However, in the existing bank system, many telecom fraud users tend to use mobile banking to perform account transfer and other operations. Therefore, in order to protect the property safety and privacy of users, it is necessary to efficiently and accurately identify telecom fraud users.

[0004] It should be noted that the above introduction to the technical background is only for the convenience of clearly and completely describing the technical solutions of the present application, and for the convenience of understanding by those skilled in the art. The above technical solutions cannot be considered as known to those skilled in the art only because they are described in the background section of the present application. SUMMARY

[0005] At present, the existing technology usually only identifies users based on bank internal data. However, due to the single nature of the bank internal data, it is not possible to efficiently and accurately identify fraud users, i.e., non-normal users.

[0006] In order to solve at least one of the above problems, the embodiments of the present application provide a non-normal user identification method and device. Thus, the non-normal users can be more efficiently and accurately identified based on more comprehensive data and under the condition of ensuring the privacy and security of the data of all parties.

[0007] According to an aspect of the embodiments of the present application, a non-normal user identification method is provided, which comprises:

[0008] obtaining first data of a bank-side user and second data of an operator-side user, the first data comprising first identification information and first features, and the second data comprising second identification information and second features;

[0009] match and align the first data and the second data based on the first identification information and the second identification information;

[0010] obtain first parameters of a first neural network model on a bank side and second parameters of a second neural network model on an operator side;

[0011] generate a neural network joint model using the first parameters and the second parameters;

[0012] identify whether a user logging in on the bank side is an abnormal user using the neural network joint model.

[0013] In some embodiments, the first parameters are obtained by training the first neural network model based on the first features, and the second parameters are obtained by training the second neural network model based on the second features.

[0014] In some embodiments, the first features include at least one of the following information: user label information; transaction record information; or login area information.

[0015] In some embodiments, the second features include at least one of the following information: call type information; short message type information; traffic type information; or owner information.

[0016] In some embodiments, the first identification information and the second identification information include a user phone number.

[0017] In some embodiments, the first data and the second data are matched and aligned when the user phone number of the first identification information and the user phone number of the second identification information belong to the same user.

[0018] According to an aspect of an embodiment of the present application, a non-normal user identification device is provided, and the device includes:

[0019] a first obtaining unit that obtains first data of a user on a bank side and second data of a user on an operator side, the first data including first identification information and first features, and the second data including second identification information and second features;

[0020] a matching unit that matches and aligns the first data and the second data based on the first identification information and the second identification information;

[0021] a second obtaining unit that obtains first parameters of a first neural network model on a bank side and second parameters of a second neural network model on an operator side;

[0022] a generating unit that generates a neural network joint model using the first parameters and the second parameters; and

[0023] The identification unit uses the neural network joint model to identify whether the bank-side login user is an abnormal user.

[0024] According to one aspect of the embodiments of this application, a computer device is provided, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the aforementioned abnormal user identification method.

[0025] According to one aspect of the embodiments of this application, a computer-readable storage medium is provided, the computer-readable storage medium storing the aforementioned abnormal user identification method.

[0026] According to one aspect of the embodiments of this application, a computer program product is provided, the computer program product including a computer program, which, when executed by a processor, implements the aforementioned abnormal user identification method.

[0027] One of the beneficial effects of this application's embodiments is that it can identify abnormal users more efficiently and accurately based on more comprehensive data and while ensuring the data privacy and security of all parties.

[0028] Specific embodiments of this application are disclosed in detail with reference to the following description and accompanying drawings, indicating how the principles of this application can be adopted. It should be understood that the embodiments of this application are not limited in scope. Within the spirit and scope of the appended claims, embodiments of this application include many changes, modifications, and equivalents.

[0029] The feature information described and illustrated for one embodiment may be used in the same or similar manner in one or more other embodiments, combined with feature information in other embodiments, or substituted for feature information in other embodiments.

[0030] It should be emphasized that the term "including / comprises" as used herein refers to the presence of a feature, whole, step, or component, but does not exclude the presence or addition of one or more other features, wholes, steps, or components. Attached Figure Description

[0031] Many aspects of this application can be better understood by referring to the following accompanying drawings. The components in the drawings are not drawn to scale, but are only intended to illustrate the principles of this application. Corresponding portions in the drawings may be enlarged or reduced for ease of illustration and description of certain parts of this application. Elements and features described in one drawing or embodiment of this application may be combined with elements and features shown in one or more other drawings or embodiments. Furthermore, similar reference numerals in the drawings denote corresponding components in several drawings and can be used to indicate corresponding components used in more than one embodiment.

[0032] In the attached diagram:

[0033] Figure 1 This is a schematic diagram of an abnormal user identification device;

[0034] Figure 2 This is a schematic diagram of the network architecture according to an embodiment of this application;

[0035] Figure 3 This is a flowchart of an abnormal user identification method according to an embodiment of this application;

[0036] Figure 4 This is a schematic diagram of an abnormal user identification method according to an embodiment of this application;

[0037] Figure 5 This is a schematic diagram of a computer device in an embodiment of this application. Detailed Implementation

[0038] Referring to the accompanying drawings, the foregoing and other features of this application will become apparent from the following description. Specific embodiments of this application are specifically disclosed in the description and drawings, illustrating partial implementations in which the principles of this application may be employed. It should be understood that this application is not limited to the described embodiments; rather, it includes all modifications, variations, and equivalents falling within the scope of the appended claims.

[0039] In the embodiments of this application, the terms "first," "second," etc., are used to distinguish different elements by name, but do not indicate the spatial arrangement or chronological order of these elements, and these elements should not be limited by these terms. The term "and / or" includes any one or more of the terms listed in association and all combinations thereof. The terms "comprising," "including," "having," etc., refer to the presence of the stated features, elements, components, or assemblies, but do not exclude the presence or addition of one or more other features, elements, components, or assemblies.

[0040] In the embodiments of this application, the singular forms "a," "the," etc., including the plural forms, should be broadly understood as "a kind" or "a class" rather than limited to the meaning of "an." Furthermore, the term "the" should be understood to include both the singular and plural forms, unless the context explicitly indicates otherwise. Additionally, the term "according to" should be understood as "at least partially based on…," and the term "based on" should be understood as "at least partially based on…," unless the context explicitly indicates otherwise.

[0041] To address the aforementioned problems, various embodiments of this application will be described below with reference to the accompanying drawings. These embodiments are merely exemplary and are not intended to limit the scope of this application.

[0042] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the embodiments of this application will be further described in detail below with reference to the accompanying drawings. Here, the illustrative embodiments and descriptions of this application are used to explain this application, but are not intended to limit this application.

[0043] First aspect of the embodiments

[0044] This application provides an abnormal user identification device.

[0045] Figure 1 This is a structural diagram of a malicious program classification device according to an embodiment of this application. Figure 1 As shown, the abnormal user identification device 100 includes:

[0046] The first acquisition unit 110 acquires first data of bank-side users and second data of operator-side users. The first data includes first identification information and first feature, and the second data includes second identification information and second feature.

[0047] The matching unit 120 matches and aligns the first data and the second data based on the first identification information and the second identification information.

[0048] The second acquisition unit 130 acquires the first parameters of the first neural network model on the bank side and the second parameters of the second neural network model on the operator side.

[0049] Generation unit 140 uses the first parameter and the second parameter to generate a joint neural network model; and

[0050] The identification unit 150 uses a joint neural network model to identify whether a user logging in on the bank side is an abnormal user.

[0051] Therefore, based on the first data of bank-side users and the second data of operator-side users, i.e., multi-party data, and while ensuring the privacy and security of all parties' data, it is possible to more efficiently and accurately identify whether users logging in from the bank side are abnormal users.

[0052] In some implementations, the bank and / or operator can periodically and proactively report the first data and / or the second data to the abnormal user identification device 100. Optionally, the bank can also proactively report the first data to the abnormal user identification device 100, and the abnormal user identification device 100 can obtain the second data from the operator based on the bank's reporting request. For example, after the bank triggers abnormal user identification, for example, on the current date, the bank can proactively report the first data to the abnormal user identification device 100. Furthermore, the abnormal user identification device 100 notifies the operator to report the second data from the day before the current date or within a predetermined period before the current date. Thus, the abnormal user identification device 100 can more accurately obtain the first data of the bank's users and the second data of the operator's users.

[0053] In some implementations, the first feature includes at least one of the following: user tag information; transaction record information; or login area information.

[0054] For example, user tagging information can classify users as abnormal users, such as setting high, medium, and low tags to represent decreasing likelihood of abnormal users; transaction record information can include: mobile banking operation code transaction records, number of days of mobile banking operation code transactions, and mobile banking operation code transaction ratio; login region information can include: whether there are overseas login records (mobile banking), number of overseas login countries (mobile banking), whether there are domestic login records (mobile banking), whether domestic and foreign IPs coexist (mobile banking), whether overseas login countries are high-risk regions or countries (mobile banking), number of overseas logins to high-risk countries (mobile banking), whether there are login records from high-risk regions within China (mobile banking), number of provinces within China that are high-risk regions (mobile banking), whether there are login records from high-risk IP ranges (mobile banking), whether there are online banking redirects (login records from 2 or more provinces within one day) (mobile banking), and the number of online banking redirects (mobile banking). This allows for accurate acquisition of primary user data from the bank's side.

[0055] In some implementations, the second feature includes at least one of the following: call type information; SMS type information; data traffic type information; or, owner information.

[0056] For example, the call type information includes whether the current user frequently makes international calls; the SMS type information includes whether the current user has activated international SMS roaming; the data traffic type information includes whether the user uses international data; and the owner information is the owner's location information to obtain the owner's geographical location. This allows for the accurate acquisition of the operator's second-hand user data.

[0057] The first and second features mentioned above are merely illustrative examples. For instance, the first and second features may include features of hundreds of dimensions, which will not be listed one by one in the embodiments of this application.

[0058] In some implementations, the first identification information and the second identification information include a user's phone number. For example, when the user's phone number in the first identification information and the user's phone number in the second identification information belong to the same user, the first data and the second data are matched. Thus, user data from different systems can be matched based solely on the first and second identification information, without requiring data from other users within each system, thereby better protecting user privacy.

[0059] In some implementations, the bank can encrypt the first data, and the operator can encrypt the second data. The encryption process can employ existing technologies, and this application does not impose any limitations on it. This further protects the privacy of user data across different systems.

[0060] In some embodiments, the second acquisition unit 130 acquires the first parameters of the first neural network model on the bank side and the second parameters of the second neural network model on the operator side. In some embodiments, the first parameters are obtained by training the first neural network model based on the first feature, and the second parameters are obtained by training the second neural network model based on the second feature. For example, the first neural network model and the second neural network model can use existing neural network models, and this application does not limit them. In some embodiments, the first parameters and the second parameters include model gradients, loss functions, and cut point parameters of the decision tree model. For example, when training the first neural network model based on the first feature, the user label information in the first feature can be used as the output of the first neural network model, and other features and the first recognition information can be used as the input of the first neural network model to train the first neural network model. The first neural network model learns the relationships between the features to obtain the first parameters, such as the cut point parameters of the decision tree model of the first neural network model. The acquisition method of the second parameters is similar and will not be described in detail here.

[0061] In some implementations, the first feature can form a first feature table, and the second feature can form a second feature table. A first neural network model is trained based on the first feature table, and a second neural network model is trained based on the second feature table. That is, after acquiring the first and second features, the first or second feature can be statistically analyzed within predetermined dimensions (e.g., time, location) to form a first or second feature table. For example, the content of the first feature table might include statistical features such as the number of transfers in seven days or the transaction amount in 30 days. This data can be retrieved from the ICBC system's data lake for processing, thereby improving the recognition performance of the trained model.

[0062] In some implementations, the generation unit 140 uses the first parameter and the second parameter to generate a joint neural network model; and the identification unit uses the joint neural network model to identify whether a bank-side login user is an abnormal user. Specifically, the first neural network model and the second neural network model can exchange their first and second parameters. That is, the first neural network model obtains the second parameters of the operator-side second neural network model and uses the second and first parameters to continue training and updating the first neural network model; the second neural network model obtains the first parameters of the bank-side first neural network model and uses the first and second parameters to continue training and updating the second neural network model, and so on, continuously exchanging the updated model parameters and iteratively training the model until the model converges, resulting in the joint neural network model. In other words, the generation unit 140 trains and learns the first and second neural network models by exchanging parameters until the first and second neural network models converge to the joint neural network model.

[0063] For example, this neural network joint model is a federated model. The federated parties exchange intermediate computation results in encrypted form to complete the model's learning and convergence. Furthermore, the federated model process ensures that gradients cannot be reverse-engineered, and the original sample data cannot be reverse-engineered. Therefore, it can further guarantee user data privacy beyond simply identifying whether a user logging in on the bank's side is an abnormal user.

[0064] In some embodiments, the identification unit 150 uses the neural network joint model to identify whether the user who logs in on the bank side is an abnormal user. That is, when a user logs in on the bank side, the first identification information and the first feature of the user are obtained, and the first identification information and the first feature of the user are input into the neural network joint model to obtain the output result as the user's label information, that is, whether the user is an abnormal user.

[0065] The following explains the process of identifying whether a user logging in from the bank is an abnormal user.

[0066] Figure 2 This is a schematic diagram of the network architecture according to an embodiment of this application. Figure 2 As shown,

[0067] 201: The bank obtains the first internal data and outputs the first data to the abnormal user identification device 100;

[0068] 202: The operator obtains internal second data and outputs first data to the abnormal user identification device 100;

[0069] 203: Abnormal user identification device 100 acquires the first feature table;

[0070] 204: Abnormal user identification device 100 acquires the second feature table;

[0071] 205: The abnormal user identification device 100 matches and aligns the first data and the second data based on the first identification information and the second identification information; for example, banks and operators may have the same users but different data, which can enable vertical matching and alignment of data between banks and operators; for example, matching the phone numbers of users on the bank side with all users on the operator side, the matching result is the users shared by both parties. Thus, it ensures that the sample identifier outside the intersection of the two parties is not leaked.

[0072] 206: The abnormal user identification device 100 obtains the first parameter based on the first neural network model on the bank side;

[0073] 207: The abnormal user identification device 100 obtains the second parameter based on the operator's second neural network model;

[0074] 208: The abnormal user identification device 100 uses the first parameter and the second parameter to generate a joint neural network model;

[0075] 209: The abnormal user identification device 100 uses the neural network joint model to identify whether the bank-side login user is an abnormal user and obtains the identification result.

[0076] For example, when a user logs in using a mobile banking app, the backend obtains the user's first identification information, such as their phone number and associated first features. The bank then notifies the operator of this first identification information (either individually or in batches). The operator obtains the corresponding second features of the user. The bank then obtains multiple first parameters based on a first neural network model. If these parameters satisfy the decision tree's cutting conditions, the operator obtains multiple second parameters based on the user's second features and its own second neural network model. If these second parameters satisfy the decision tree's cutting conditions, the updated parameters are repeatedly exchanged to obtain a joint neural network model. The abnormal user identification device 100 then uses this joint neural network model to identify whether the bank's login user is an abnormal user. For example, if the first and second parameters exceed a specific threshold and satisfy the decision tree cutting conditions, the user is identified as an abnormal user. For instance, if there are 100 first and second parameters in total, and more than 90 satisfy the decision tree cutting conditions, the user is identified as an abnormal user. For example, the first parameter is the transaction frequency of the user on the bank side. The decision tree cut-off condition is that the number of transactions within 24 hours is greater than 10. If this condition is met, the operator side obtains the second parameter, such as the user's overseas call records. The decision tree cut-off condition is that the number of overseas call records of the user within 24 hours is greater than 10. For example, if both of the above conditions are met, the user is identified as an abnormal user.

[0077] Therefore, it can not only efficiently and accurately identify whether users logging in from the bank are abnormal users; but also ensure that sample data is not leaked during the 205 matching and alignment process and the 208 generating neural network joint model process, thus better protecting user privacy.

[0078] The following explanation is based on the data interaction process of the banking system.

[0079] Figure 3 This is a flowchart illustrating the application of an abnormal user identification method in a banking system, according to an embodiment of this application. Figure 3 As shown,

[0080] Step 301: Begin identifying abnormal users in the banking system;

[0081] Step 302: REAF (Real-Time Enterprise Anti-fraud System, ICBC Anti-fraud Application) performs data scheduling through BDSP (Big Data Service Platform, ICBC Unified Scheduling and Management Platform), batch scheduling the Turing Machine Learning Lab's data preprocessing tasks. Specifically, it generates preprocessed data bin files using public scripts within the ICBC system. These bin files contain the first feature of the first data. The bin files are stored in the ICBC data lake. Furthermore, the bin files are transferred to a file path registered with GTP using public scripts within BDSP. GTP is an internal file transfer platform within ICBC, which sends the files from the BDSP server path to the federated server path where the abnormal user identification device 100 is located. This ensures that the federated server where the abnormal user identification device 100 is located is not directly connected to the ICBC internal data lake, further guaranteeing the security of user data within the bank system.

[0082] Step 303: Transfer the bin file in the data lake to the abnormal user identification device 100; the script deployed by the abnormal user identification device 100 polls the file to find the corresponding path, that is, after the federated server where the abnormal user identification device 100 is located receives the path of the bin file, it starts the prediction task to identify abnormal users.

[0083] Step 304: In the ICBC network isolation zone (DMZ, demilitarized zone), the abnormal user identification device 100 requests the operator to input second data to the abnormal user identification device 100, for example, to obtain the second data related file from the operator the previous day;

[0084] Step 305: The abnormal user identification device 100 identifies users in the ICBC's network isolation zone (DMZ) based on the second data from the operator side and the above identification method;

[0085] Step 306: The abnormal user identification device 100 generates an identification result based on the aforementioned abnormal user identification method, updates the bin file based on the identification result, and incorporates the updated bin file into the data lake.

[0086] Therefore, after completing the non-user identification, it can also update the first data of the bank system, and more efficiently and accurately identify whether the user logging in on the bank side is an abnormal user.

[0087] The table below is a comparison between the abnormal user identification method based on the embodiments of this application and the abnormal user identification method not based on the embodiments of this application.

[0088] Table 1: Comparison of Abnormal User Identification Methods Based on Embodiments of this Application and Abnormal User Identification Methods Not Adopted in Embodiments of this Application

[0089]

[0090] As shown in Table 1, `top_n` represents the ranking of the scores; for example, `top_n` of 100 represents the top 100 abnormal users (the higher the ranking, the higher the risk). "Segmented hit" refers to the number of black samples hit in the current segment. "Cumulative hit" refers to the cumulative number of black samples hit. For example, black samples are confirmed abnormal users, while the abnormal user identification method of this application identifies potential abnormal users. Taking the row `top_n = 50` in the implementation of this application as an example, "segmented hit" means that 17 out of the predicted top 50 potential abnormal users are actually confirmed abnormal users.

[0091] For example, in the row of Table 1 where top_n = 200, the number of abnormal user samples identified by the abnormal user identification method according to the present application is greater than that of the abnormal user identification method without the present application (for each column of the third row: 10 > 9, 32 > 27). Therefore, the abnormal user identification method according to the present application has higher identification efficiency. Thus, the abnormal user identification method based on the present application can more accurately identify abnormal users.

[0092] It should be noted that the hardware structure in the above example may also include devices not shown in the figure. For details, please refer to the prior art. This application embodiment is not intended to limit the hardware structure. Alternatively, the hardware structure may not necessarily include all the components shown in the figure. These will not be listed here.

[0093] For simplicity, the figures only illustrate the connection relationships or signal flows between the various components or modules, but those skilled in the art should understand that such connections can employ various related technologies such as electrical connections. The embodiments of this application do not limit this.

[0094] The above embodiments are merely illustrative examples of embodiments of this application, but this application is not limited thereto, and appropriate modifications can be made based on the above embodiments. For example, the above embodiments can be used alone, or one or more of the above embodiments can be combined.

[0095] This application can identify whether a user logging in from the bank is an abnormal user more efficiently and accurately, based on the first data of the bank-side user and the second data of the operator-side user, i.e., multi-party data, while ensuring the privacy and security of all parties' data.

[0096] Second aspect of the embodiments

[0097] This application provides a method for identifying abnormal users.

[0098] This method corresponds to the abnormal user identification device in the foregoing embodiments. Embodiments of this method can be found in the foregoing embodiments; repeated details will not be described again.

[0099] Figure 4 This is a schematic diagram of a malicious program classification method according to an embodiment of this application; as shown Figure 4 As shown, the method includes:

[0100] Step 401: Obtain first data of bank-side users and second data of operator-side users. The first data includes first identification information and first feature, and the second data includes second identification information and second feature.

[0101] Step 402: Based on the first identification information and the second identification information, match and align the first data and the second data;

[0102] Step 403: Obtain the first parameters of the first neural network model on the bank side and the second parameters of the second neural network model on the operator side;

[0103] Step 404: Use the first parameter and the second parameter to generate a joint neural network model;

[0104] Step 405: Use the joint neural network model to identify whether the bank-side login user is an abnormal user.

[0105] The execution of each of the above steps and their specific details can be found in the descriptions of the functions and structures of the relevant components in the foregoing embodiments, and will not be repeated here.

[0106] Therefore, based on the first data of bank-side users and the second data of operator-side users, i.e., multi-party data, and while ensuring the privacy and security of all parties' data, it is possible to more efficiently and accurately identify whether users logging in from the bank side are abnormal users.

[0107] Embodiments of this application also provide a computer device. Figure 5 This is a schematic diagram of the computer device 500 in an embodiment of this application. The computer device 500 is capable of implementing all the steps in the program extension method in the above embodiments. The computer device 500 specifically includes the following:

[0108] Processor 501, memory 502, communications interface 503, and communication bus 5604;

[0109] The processor 501, memory 502, and communication interface 503 communicate with each other through the communication bus 504; the communication interface 503 is used to realize information transmission between server-side devices, detection devices, and user-side devices and other related devices.

[0110] The processor 501 is used to call the computer program in the memory 502. When the processor executes the computer program, it implements all the steps in the abnormal user identification in the above embodiments.

[0111] Embodiments of this application also provide a computer-readable storage medium capable of implementing all steps in the malicious program classification described in the above embodiments. The computer-readable storage medium stores a computer program that, when executed by a processor, implements all steps of abnormal user identification described in the above embodiments.

[0112] Embodiments of this application also provide a computer program product, which includes a computer program that, when executed by a processor, implements the abnormal user identification described in the above embodiments.

[0113] While this invention provides the method operation steps as described in the embodiments or flowcharts, more or fewer operation steps may be included based on conventional or non-inventive labor. The order of steps listed in the embodiments is merely one possible execution order among many and does not represent the only possible execution order. In actual device or client product execution, the methods shown in the embodiments or drawings can be executed sequentially or in parallel (e.g., in a parallel processor or multi-threaded processing environment).

[0114] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0115] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart... Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0116] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0117] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.

[0118] The present application has been described above with reference to specific embodiments. However, those skilled in the art should understand that these descriptions are exemplary and not intended to limit the scope of protection of the present application. Those skilled in the art can make various modifications and variations to the present application based on its spirit and principles, and these modifications and variations are also within the scope of the present application.

Claims

1. A method for identifying abnormal users, characterized in that, The method includes: Acquire first data of bank-side users and second data of operator-side users. The first data includes first identification information and first feature, and the second data includes second identification information and second feature. The first feature includes at least one of the following: user tag information; transaction record information; or login area information. The second feature includes at least one of the following: call type information; SMS type information; data traffic type information; or, account holder information. Based on the first identification information and the second identification information, the first data and the second data are matched and aligned; the first identification information and the second identification information include user phone numbers; when the user phone number of the first identification information and the user phone number of the second identification information belong to the same user, the first data and the second data are matched and aligned. Obtain the first parameters of the first neural network model on the bank side and the second parameters of the second neural network model on the operator side; Generate a joint neural network model using the first parameter and the second parameter; The aforementioned neural network joint model is used to identify whether bank-side login users are abnormal users. The first neural network model is trained based on the first feature to obtain the first parameters, and the second neural network model is trained based on the second feature to obtain the second parameters; the first parameters and the second parameters include the model gradient, loss function, and cut point parameters of the decision tree model; The method of training the first neural network model based on the first feature to obtain the first parameters includes: using the user label information in the first feature as the output of the first neural network model, using other features and the first recognition information as the input of the first neural network model, training the first neural network model, and obtaining the cut point parameters of the decision tree model of the first neural network model by learning the relationship between each feature. The method of generating a joint neural network model using the first parameter and the second parameter includes: the first neural network model obtaining the second parameter of the second neural network model on the operator side, and using the second parameter and the first parameter to continue training and updating the first neural network model; the second neural network model obtaining the first parameter of the first neural network model on the bank side, and using the first parameter and the second parameter to continue training and updating the second neural network model; and so on, iteratively training the model until the model converges to obtain the joint neural network model.

2. An abnormal user identification device, characterized in that, The device includes: The first acquisition unit acquires first data of bank-side users and second data of operator-side users. The first data includes first identification information and first feature, and the second data includes second identification information and second feature. The first feature includes at least one of the following: user tag information; transaction record information; or login area information. The second feature includes at least one of the following: call type information; SMS type information; data traffic type information; or, device owner information. A matching unit matches and aligns the first data and the second data based on the first identification information and the second identification information; the first identification information and the second identification information include user phone numbers; when the user phone number in the first identification information and the user phone number in the second identification information belong to the same user, the first data and the second data are matched and aligned. The second acquisition unit acquires the first parameters of the first neural network model on the bank side and the second parameters of the second neural network model on the operator side. A generation unit that uses the first parameter and the second parameter to generate a joint neural network model; and The identification unit uses the neural network joint model to identify whether a bank-side login user is an abnormal user. The first neural network model is trained based on the first feature to obtain the first parameters, and the second neural network model is trained based on the second feature to obtain the second parameters; the first parameters and the second parameters include the model gradient, loss function, and cut point parameters of the decision tree model; The method of training the first neural network model based on the first feature to obtain the first parameters includes: using the user label information in the first feature as the output of the first neural network model, using other features and the first recognition information as the input of the first neural network model, training the first neural network model, and obtaining the cut point parameters of the decision tree model of the first neural network model by learning the relationship between each feature. The method of generating a joint neural network model using the first parameter and the second parameter includes: the first neural network model obtaining the second parameter of the second neural network model on the operator side, and using the second parameter and the first parameter to continue training and updating the first neural network model; the second neural network model obtaining the first parameter of the first neural network model on the bank side, and using the first parameter and the second parameter to continue training and updating the second neural network model; and so on, iteratively training the model until the model converges to obtain the joint neural network model.

3. A computer device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements the method of claim 1.

4. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program that performs the method of claim 1.

5. A computer program product, characterized in that, The computer program product includes a computer program that, when executed by a processor, implements the method of claim 1.

Citation Information

Patent Citations

  • Abnormal bank account identification method and system, electronic equipment and storage medium

    CN113902037A