Malicious account identification method and device, storage medium and electronic equipment
By acquiring historical resource transfer event data of application accounts and using user account prediction neural networks to calculate recognition confidence, the problem of inaccurate identification of malicious accounts in existing technologies is solved, achieving higher identification accuracy and blocking effect.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- TENCENT TECHNOLOGY (SHENZHEN) CO LTD
- Filing Date
- 2021-05-13
- Publication Date
- 2026-07-21
AI Technical Summary
In existing technologies, identifying malicious accounts based on resource transfer events between users and accounts is not accurate enough.
By acquiring historical resource transfer event data of application accounts, feature data of reference user accounts are extracted, and user account prediction neural networks are used to calculate identification confidence and determine malicious user accounts.
It improves the accuracy of identifying malicious accounts, enabling more accurate identification and blocking of malicious user accounts, and reduces the false identification rate.
Smart Images

Figure CN115345620B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of computers, and more specifically, to a method and apparatus for identifying malicious accounts, a storage medium, and an electronic device. Background Technology
[0002] In existing technologies, account identification typically relies on resource transfer events between the user and the account to determine whether an account is malicious. However, since resource transfer events between users and accounts often include both normal and abnormal events, using these events to identify malicious accounts is inaccurate.
[0003] There is currently no effective solution to the above problems. Summary of the Invention
[0004] This invention provides a method, apparatus, storage medium, and electronic device for identifying malicious accounts, in order to at least solve the technical problem of inaccurate identification of malicious accounts.
[0005] According to one aspect of the present invention, a method for identifying malicious accounts is provided, comprising: acquiring a resource transfer event to be identified, wherein the resource transfer event carries an application account and a user account with an association relationship, and in response to a click operation on an access link in the application account, performing a resource transfer operation between the application account and the user account; acquiring event data of a first historical resource transfer event corresponding to the application account, wherein the first historical resource transfer event is a resource transfer event in which the application account participated within a first target time period prior to triggering the resource transfer event; extracting feature data corresponding to each reference user account participating in the first historical resource transfer event from the event data of the first historical resource transfer event; acquiring a first identification confidence level corresponding to each reference user account based on the feature data of each reference user account; and identifying the reference user account whose first identification confidence level reaches a first threshold as a malicious user account.
[0006] According to another aspect of the present invention, a malicious account identification device is also provided, comprising: a first acquisition unit, configured to acquire a resource transfer event to be identified, wherein the resource transfer event carries an application account and a user account with an association relationship, and in response to a click operation on an access link in the application account, execute a resource transfer operation between the application account and the user account; a second acquisition unit, configured to acquire event data of a first historical resource transfer event corresponding to the application account, wherein the first historical resource transfer event is a resource transfer event in which the application account participated within a first target time period before the resource transfer event was triggered; an extraction unit, configured to extract feature data corresponding to each reference user account participating in the first historical resource transfer event from the event data of the first historical resource transfer event; a third acquisition unit, configured to acquire a first identification confidence level corresponding to each of the reference user accounts based on the feature data of each of the reference user accounts; and a determination unit, configured to determine the reference user accounts whose first identification confidence level reaches a first threshold as malicious user accounts.
[0007] As an optional example, the above apparatus further includes at least one of the following units: a blocking unit, configured to block the usage rights of the malicious user account after the reference user account whose first identification confidence level reaches the first threshold is determined to be a malicious user account; and an interception unit, configured to intercept the resource transfer event triggered by the malicious user account after the reference user account whose first identification confidence level reaches the first threshold is determined to be a malicious user account.
[0008] According to another aspect of the present invention, a computer-readable storage medium is also provided, wherein a computer program is stored in the computer program, wherein the computer program is configured to execute the above-described method for identifying malicious accounts when it is run.
[0009] According to another aspect of the present invention, an electronic device is also provided, including a memory and a processor, wherein the memory stores a computer program and the processor is configured to execute the above-described method for identifying malicious accounts through the computer program.
[0010] In this embodiment of the invention, a method is employed to acquire resource transfer events to be identified, wherein the resource transfer events carry related application accounts and user accounts, and in response to a click operation on an access link in the application account, a resource transfer operation between the application account and the user account is executed; event data of a first historical resource transfer event corresponding to the application account is acquired, wherein the first historical resource transfer event is a resource transfer event in which the application account participated within a first target time period before the resource transfer event was triggered; feature data corresponding to each reference user account participating in the first historical resource transfer event is extracted from the event data of the first historical resource transfer event; a first identification confidence level is acquired for each reference user account based on the feature data of each reference user account; and reference user accounts whose first identification confidence level reaches a first threshold are identified as malicious user accounts. Since the above method identifies whether an account is malicious based on the feature data of the reference user accounts related to the application account, it is not necessary to use resource transfer data between the user and the account to determine whether the account is malicious, thus improving the accuracy of identifying whether an account is malicious and solving the technical problem of inaccurate identification of malicious accounts. Attached Figure Description
[0011] The accompanying drawings, which are included to provide a further understanding of the invention and form part of this application, illustrate exemplary embodiments of the invention and, together with their description, serve to explain the invention and do not constitute an undue limitation thereof. In the drawings:
[0012] Figure 1 This is a schematic diagram of an application environment for an optional malicious account identification method according to an embodiment of the present invention;
[0013] Figure 2 This is a flowchart of an optional method for identifying malicious accounts according to an embodiment of the present invention;
[0014] Figure 3 This is a schematic diagram illustrating the correspondence between application accounts and user accounts in an optional malicious account identification method according to an embodiment of the present invention.
[0015] Figure 4 This is a schematic diagram of a redirect payment method for an optional malicious account identification method according to an embodiment of the present invention;
[0016] Figure 5 This is a schematic diagram of model training for an optional malicious account identification method according to an embodiment of the present invention;
[0017] Figure 6This is a schematic diagram of appid identification, which is an optional method for identifying malicious accounts according to an embodiment of the present invention.
[0018] Figure 7 This is a schematic diagram illustrating a merchant-targeting method for an optional malicious account identification method according to an embodiment of the present invention;
[0019] Figure 8 This is a schematic diagram of the structure of an optional malicious account identification device according to an embodiment of the present invention;
[0020] Figure 9 This is a schematic diagram of the structure of an optional electronic device according to an embodiment of the present invention. Detailed Implementation
[0021] To enable those skilled in the art to better understand the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present invention.
[0022] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this invention are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of the invention described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover a non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.
[0023] According to one aspect of the present invention, a method for identifying malicious accounts is provided. Optionally, as an optional implementation, the above-described method for identifying malicious accounts may be applied to, but is not limited to, [examples of other methods]. Figure 1 In the environment shown.
[0024] like Figure 1As shown, terminal device 102 includes a memory 104 for storing various data generated during its operation, a processor 106 for processing and calculating the aforementioned data, and a display 108 for displaying the recognition results. Terminal device 102 can interact with server 112 via network 110. Server 112 includes a database 114 for storing various data and a processing engine 116 for processing the aforementioned data. Data interaction is possible between terminal device 102 and server 112. For example, clicking an access link on the terminal redirects to the user's account, sending a request to the server to retrieve the user's account data, and displaying it on the terminal device. Terminal device can execute resource transfer events and send data to the server. Through steps S102 to S104, server 112 can obtain the resource transfer event to be identified, then obtain the event data of the first historical resource transfer event, extract the feature data corresponding to each reference user account participating in the first historical resource transfer event from the event data of the first historical resource transfer event, obtain the first identification confidence level corresponding to each reference user account based on the feature data of each reference user account, and identify the reference user account whose first identification confidence level reaches the first threshold as a malicious user account, thereby realizing the identification of the account.
[0025] As another example, the aforementioned malicious account identification method can be executed by the terminal device 102. The terminal device 102 obtains the resource transfer event to be identified, obtains the event data of the first historical resource transfer event, extracts the feature data corresponding to each reference user account participating in the first historical resource transfer event from the event data of the first historical resource transfer event, obtains the first identification confidence level corresponding to each reference user account based on the feature data of each reference user account, and identifies the reference user account whose first identification confidence level reaches the first threshold as a malicious user account, thereby realizing account identification.
[0026] Optionally, in this embodiment, the terminal device can be a terminal device configured with a target client, which may include, but is not limited to, at least one of the following: mobile phone (such as Android phone, iOS phone, etc.), laptop computer, tablet computer, PDA, MID (Mobile Internet Devices), PAD, desktop computer, smart TV, etc. The target client may be a video client, instant messaging client, browser client, educational client, etc. The network may include, but is not limited to, wired network and wireless network, wherein the wired network includes: local area network, metropolitan area network and wide area network, and the wireless network includes: Bluetooth, WIFI and other networks that enable wireless communication. The server may be a single server, a server cluster composed of multiple servers, or a cloud server. The above is only an example, and no limitation is made in this embodiment.
[0027] Optionally, the aforementioned method for identifying malicious accounts can be applied to blockchain nodes. In this embodiment, the blockchain represents a novel application model of computer technologies such as distributed data storage, peer-to-peer transmission, consensus mechanisms, and encryption algorithms. Essentially, a blockchain is a decentralized database, a chain of data blocks linked using cryptographic methods. Each data block contains information about a batch of network transactions, used to verify the validity of the information (anti-counterfeiting) and generate the next block. A blockchain can include a blockchain underlying platform, a platform product service layer, and an application service layer.
[0028] The underlying blockchain platform can include processing modules such as user management, basic services, smart contracts, and operational monitoring. The user management module is responsible for managing the identity information of all blockchain participants, including maintaining public and private key generation (account management), key management, and maintaining the correspondence between user real identities and blockchain addresses (access management). Furthermore, under authorization, it monitors and audits transactions of certain real identities and provides risk control rule configuration (risk control audit). The basic services module is deployed on all blockchain node devices to verify the validity of business requests. After consensus is reached on valid requests, they are recorded in storage. For a new business request, the basic services first perform interface adaptation parsing and authentication (interface adaptation), and then encrypt the business information through a consensus algorithm (consensus management). After encryption, the data is transmitted completely and consistently to the shared ledger (network communication) and recorded and stored. The smart contract module is responsible for contract registration, issuance, triggering, and execution. Developers can define contract logic using a programming language and publish it to the blockchain (contract registration). According to the contract terms, the key or other events are invoked to trigger execution and complete the contract logic. It also provides functions for contract upgrades and cancellations. The operation monitoring module is mainly responsible for deployment, configuration modification, contract settings, cloud adaptation, and real-time status visualization output during product release, such as alarms, monitoring network conditions, and monitoring the health status of node devices.
[0029] The platform's product service layer provides the basic capabilities and implementation frameworks for typical applications. Developers can leverage these basic capabilities, along with the specific characteristics of their business needs, to implement blockchain-based business logic. The application service layer provides blockchain-based application services to business stakeholders.
[0030] Alternatively, as an alternative implementation method, such as Figure 2 As shown, the methods for identifying the aforementioned malicious accounts include:
[0031] S202, Obtain the resource transfer event to be identified, wherein the resource transfer event carries an application account and a user account with an association relationship, and in response to the click operation of the access link in the application account, perform a resource transfer operation between the application account and the user account.
[0032] S204, obtain the event data of the first historical resource transfer event corresponding to the application account, wherein the first historical resource transfer event is the resource transfer event in which the application account participated within the first target time period before the resource transfer event was triggered;
[0033] S206, Extract the feature data corresponding to each reference user account that participated in the first historical resource transfer event from the event data of the first historical resource transfer event;
[0034] S208, Based on the feature data of each reference user account, obtain the first identification confidence level corresponding to each reference user account;
[0035] S210, the reference user account whose first identification confidence level reaches the first threshold is identified as a malicious user account.
[0036] Optionally, in this embodiment, the method for identifying malicious accounts described above can be applied, but is not limited to, the process of identifying network accounts. A network account can be an account capable of executing resource transfer events. These resource transfer events can be the transfer of virtual resources from one account to another. Resource transfer events can be resource transfers between accounts within the same application or between accounts in different applications. For example, for resource transfers between accounts in different applications, the transfer can be performed between accounts on different applications through an inter-application interface.
[0037] The aforementioned application account can be an account that displays an access link. Clicking the access link redirects the user to their account, where the resource transfer operation can be completed. For example, user 1 accesses the application account, clicks the access link on the application account, is redirected to their user account, and completes the resource transfer event on their user account.
[0038] Optionally, in this embodiment, the relationship between application accounts and user accounts can be many-to-many. For example, one application account can correspond to multiple user accounts, and one user account can correspond to multiple application accounts. Figure 3 As shown, Figure 3 This is a diagram illustrating the mapping between an optional application account and a user account. Figure 3 In this example, application account 1 corresponds to user accounts 1-4, application accounts 2 and 3 correspond to user accounts 1-2, and application account 4 corresponds to user accounts 2-4. This correspondence means that access links on application accounts can redirect to user accounts. For example, if application account 1 includes access links to user accounts 1-4, these links can redirect to any one of user accounts 1-4, thus completing a resource transfer event. Optionally, the reference user account in this embodiment can be an account that can be accessed through the application account. For example, if an application account includes 10 links, then all 10 user accounts corresponding to those 10 links can be used as reference user accounts. A reference application account is an application account that includes access links to a reference user account. Access links are redirected to reference user accounts through the reference application account. For example, if one reference user account has access links in three application accounts, then all three application accounts are reference application accounts for that reference user account. Figure 3 All user accounts in this document can be reference user accounts. Figure 3The application accounts in the text can all be reference application accounts.
[0039] In this embodiment, when a user jumps from an application account to a user account and completes a resource transfer event, all reference user accounts corresponding to the application account can be obtained. Based on the characteristic data of each reference user account, the first identification confidence level corresponding to each reference user account can be obtained. If the first identification confidence level is higher than the first threshold, then the reference user account is a malicious user account.
[0040] In this embodiment, malicious merchants can be merchants with specific labels, such as merchants that provide illegal services such as pornography, violence, gambling, and drug use. The method in this embodiment can automatically identify and monitor them, improving the accuracy of identifying malicious merchants.
[0041] In this embodiment, after the application account is redirected to the user account, the feature data of the reference user account in the first historical resource transfer event of the application account is used to identify the first identification confidence of the reference user account, thereby identifying whether the reference user account is a malicious user account, which improves the accuracy of identifying malicious user accounts.
[0042] Let's illustrate this with a concrete example. For instance, let's apply the aforementioned malicious account identification method to the process of identifying whether a user account capable of performing resource transfer operations is malicious. The application account mentioned above can be any application client account, either a login account or an identifier account. For example, a login account can be the account information used to log in, and an identifier account can be the name set for the user's account. The application account can also be a public account, a mini-program, etc. The user account mentioned above can be a merchant, where the resource transfer operation can be completed. The application account or reference application account mentioned above can be the application's unique identifier (Application Identification, or appid for short). The user, through the appid, clicks a message link, enters the merchant's website, selects a video, and then makes a payment. This process can be viewed as the user being redirected to the merchant through the appid, and then completing the resource transfer event on the merchant's website. For example... Figure 4 As shown, Figure 4 In the application account interface, an access link (402) and a jump button (404) are displayed. Users can also jump via QR code scanning, leading to different merchants. For example, clicking a link might redirect to a merchant on a late-night video website offering paid services, with payment made via a pop-up window (406). As an optional example, payment methods can include various options such as QR code payment, facial recognition payment, fingerprint recognition payment, or even password-free payment. The purpose of this embodiment is to identify whether the "late-night video website" merchant is a malicious merchant.
[0043] As an optional implementation, obtaining the first identification confidence level for each reference user account based on its respective feature data includes:
[0044] The feature data of each reference user account is input into the user account prediction neural network. The user account prediction neural network is a neural network obtained by training multiple times based on the feature data of the sample user accounts associated with the tagged application account. It is used to determine the confidence level of a user account as a malicious user account. The tagged application account is the application account that provides access links to malicious user accounts.
[0045] In the user account prediction neural network, the feature data of each reference user account are calculated to obtain the first recognition confidence level corresponding to each reference user account.
[0046] Optionally, the user account prediction neural network model in this embodiment can be a pre-trained model. For each reference user account, feature data related to the reference user account is obtained, and the user account prediction neural network model performs calculations and identifications to obtain a first confidence level.
[0047] During training, the user account prediction neural network model can be trained using sample user accounts associated with tagged application accounts. The tagged application accounts can be one or more of the reference application accounts.
[0048] The feature data of the reference user account in this embodiment may include the account information of the application account corresponding to the user account, including the account's unique identifier, account name, gender, level, preferences, etc., as well as whether it is a malicious application account, the proportion of malicious application accounts, and the user account's account information, such as the account's unique identifier, account name, gender, level, preferences, etc.
[0049] For example, for a reference user account, which includes three corresponding application accounts, the account information of all three application accounts can be used as information in the feature data.
[0050] By acquiring the feature data corresponding to each user account and inputting the feature data into the user account prediction neural network to obtain the first recognition confidence, the accuracy of the first recognition confidence is improved.
[0051] As an optional example, before feeding the feature data of each reference user account into the user account prediction neural network, the following is also included:
[0052] Obtain sample user accounts associated with the tag application account. These sample user accounts include positive and negative sample user accounts. Positive sample user accounts are malicious user accounts, while negative sample user accounts are trusted user accounts.
[0053] The feature data of the sample user accounts are processed to obtain the multidimensional feature vector of the sample user accounts;
[0054] The multidimensional feature vectors of sample user accounts and the event data of sample resource transfer events in which the sample user accounts participate are sequentially input into the initial user account prediction neural network, and cross-validation is used to train the neural network to obtain the user account prediction neural network.
[0055] In this embodiment, the sample user accounts can include positive sample user accounts and negative sample user accounts. Positive sample user accounts are malicious user accounts, and negative sample user accounts are trusted user accounts. The tag application accounts include corresponding tags. For example, the tags can be malicious tags, such as pornography, violence, gambling, etc. When the sample user accounts and tag application accounts are used as sample data to train the initial user account prediction neural network, cross-validation can be used for training to obtain the user account prediction neural network. This embodiment achieves the effect of improving the recognition accuracy of the user account prediction neural network.
[0056] As an optional example, before feeding the feature data of each reference user account into the user account prediction neural network, the following is also included:
[0057] Obtain event data for the second historical resource transfer event corresponding to the target user account that has been identified as a malicious user account. The second historical resource transfer event is a resource transfer event in which the target user account participated within the second target time period before the resource transfer event was triggered.
[0058] Extract the characteristic data corresponding to each reference application account that participated in the second historical resource transfer event from the event data;
[0059] Based on the characteristic data of each reference application account, obtain the second identification confidence level corresponding to each reference application account;
[0060] Reference application accounts whose second identification confidence level reaches the second threshold are identified as tag application accounts.
[0061] Optionally, in this embodiment, the tags of the aforementioned tag application account can also be tags identified using an application account prediction neural network.
[0062] Optionally, in this embodiment, all user accounts associated with the reference application account can be obtained. These user accounts may include both malicious and trusted user accounts. For the reference application account, the following information is obtained: the account information of the reference application account, such as its unique identifier, name, gender, level, and preferences; and the account information of each user account corresponding to the reference application account, such as its unique identifier, name, gender, level, and preferences, as well as whether the user account is malicious and the percentage of malicious user accounts. The aforementioned feature data is used to determine the tagged application accounts.
[0063] As an optional example, before obtaining the second identification confidence score corresponding to each reference application account based on its respective feature data, the following steps are also included:
[0064] The feature data of each reference application account is input into the application account prediction neural network. The application account prediction neural network is a neural network obtained by training multiple times based on the feature data of the labeled sample application accounts. It is used to determine the confidence level of the application account as associated with the malicious user account.
[0065] In the application account prediction neural network, the feature data of each reference application account are calculated to obtain the second recognition confidence level corresponding to each reference application account.
[0066] Tag application accounts can be identified using an application account prediction neural network to recognize the unique features of the aforementioned reference application accounts. This involves obtaining the account information of the reference application account, such as its unique identifier, name, gender, level, and preferences, as well as the account information of each corresponding user account, including its unique identifier, name, gender, level, and preferences, and determining whether the user account is malicious and the percentage of malicious user accounts. The application account prediction neural network can then be used to identify these features, thereby determining whether the reference application account is a tag application account.
[0067] As an optional example, before obtaining the second identification confidence score corresponding to each reference application account based on its respective feature data, the following steps are also included:
[0068] Obtain multiple original sample application accounts;
[0069] Denoising was performed on multiple original sample application accounts to obtain multiple sample application accounts;
[0070] Multiple sample application accounts were labeled to obtain positive sample application accounts and negative sample application accounts;
[0071] The feature data of the sample application accounts are processed to obtain the multidimensional feature vector of the sample application accounts;
[0072] The multidimensional feature vectors of the sample application accounts and the event data of the sample resource transfer events in which the sample application accounts participate are sequentially input into the initial application account prediction neural network, and cross-validation is used to train the application account prediction neural network.
[0073] In this embodiment, the application account prediction neural network is a pre-trained neural network model. Sample application accounts can be obtained, each corresponding to multiple user accounts. These user accounts are labeled with either malicious or trusted tags. An initial application account prediction neural network is trained using these sample application accounts, employing cross-validation to further refine the neural network and obtain the final application account prediction neural network.
[0074] The noise reduction process in this embodiment can first filter out a portion of noisy samples from all samples. This filtering process can be based on sample labels or time periods, such as filtering samples within a fixed time period, thus removing inaccurate samples. This embodiment improves the accuracy of the samples and further enhances the recognition accuracy of the application account prediction neural network.
[0075] As an optional example, after identifying a reference user account whose first identification confidence level reaches a first threshold as a malicious user account, the method further includes at least one of the following steps:
[0076] Ban the access privileges of malicious user accounts;
[0077] Intercept resource transfer events triggered by malicious user accounts.
[0078] In this embodiment, if a user account is identified as a malicious user account, the user account will be banned, or the user account will no longer be able to execute resource transfer events. For example, the user will no longer be able to redirect to the user account, or after redirecting to the user account, the user will no longer be able to execute resource transfer events.
[0079] Of course, this embodiment can also block malicious application accounts and prohibit users from accessing them.
[0080] This will be illustrated with a specific example. Taking redirection to a merchant via appid for payment as an example, this embodiment needs to identify whether the appid and merchant are malicious after the user is redirected to the merchant for payment, in order to determine whether to ban them. The relationship between appid and merchant is not one-to-one, but many-to-many. Entering from the same appid entry point may correspond to different merchants. The merchant can be the payee, and different appids may pay the same merchant; the relationship between merchant and appid can be a direct binding relationship or a cross-account referral relationship.
[0081] During identification, this embodiment can use a user account prediction neural network to identify whether a merchant is malicious, and an application account prediction neural network to identify whether an appid is malicious. The training of the two neural networks is as follows:
[0082] First, determine the appid tag and locate the appid that provides a malicious transaction entry point and tag it.
[0083] Based on past identification and crackdowns, a batch of known malicious merchant seeds can be obtained. By obtaining the transaction records of these malicious merchants for the previous N days, the transaction-related appids can be obtained. These appids and merchants can be used as the full sample.
[0084] To maximize the coverage of the identification, both appids directly associated with merchants and those associated across different accounts can be considered. Malicious merchants often associate with legitimate appids; for example, some malicious merchants might use platform-type appids to drive users to their own accounts for transactions. Therefore, some noisy data can be removed before modeling appids. Based on experience or tags, simple rule-based filtering can be performed using features such as appid nicknames and the number of associated merchants. For example, appids with nicknames in the whitelist can be removed, or appids with associated merchants below a certain value can be deleted. This can eliminate some legitimate appids. However, to accurately identify malicious appids, machine learning modeling is needed in the next step to predict the probability of a malicious appid. Using merchant and appid transaction data and information data, effective features such as transaction scenario proportions are processed, and an eXtreme Gradient Boosting (xgboost) model is used to train the appid attributes for multi-class classification. The XGBoost model comprises multiple decision trees, and the predictions from each tree are summed to form the final prediction. Extracted features can include: merchant tags, whether the merchant is a blacklisted merchant (a blacklisted merchant is one whose account has been shut down), complaint information, text information, payment scenario information, different payment methods, the proportion of malicious public accounts associated with the merchant, merchant tags, merchant rating, proportion of malicious merchants, and high-risk scenarios.
[0085] Typically, most appid samples are unlabeled, especially lacking negative sample labels. Therefore, besides labeling appids that will be banned as positive samples, appids deemed malicious by humans can also be labeled as positive samples, and appids deemed trustworthy by humans can be labeled as negative samples. Unlike user labels, which are difficult to determine, pornographic and normal appids are relatively easy to identify. However, relying solely on manual labeling is too costly. Pseudo-labeling techniques from semi-supervised learning can partially address the lack of labels. Pseudo-labeling encourages the classifier to confidently predict unknown samples, grouping adjacent points into the same class, thus making the decision boundary clearer and effectively improving the model's generalization ability. When the initial classifier performs well, pseudo-labeling has a significant impact on improving model performance.
[0086] A diagram illustrating pseudo-label learning is shown below. Figure 5 As shown, the steps are as follows:
[0087] a) Based on experience or label data, reduce noise in the samples and remove platform-related appids;
[0088] b) Label positive and negative samples based on definitions and expert experience;
[0089] c) Process the relevant data of the samples to form several dimensional features that can be input into the model;
[0090] d) Train the model using the k-fold cross-validation method to obtain the trained model 1;
[0091] e) Use the trained model 1 to predict unknown samples, select those with a prediction probability value >= 0.99 as positive samples, and those with a prediction probability value <= 0.01 as negative samples. These high-confidence samples are pseudo-labeled samples.
[0092] f) Merge the pseudo-labeled samples and labeled samples, retrain, and obtain the optimized model 2;
[0093] g) Use Model 2 to predict unknown samples, select those with a predicted probability value >= 0.99 as positive samples, and those with a predicted probability value <= 0.01 as negative samples. These high-confidence samples are pseudo-labeled samples.
[0094] h) Merge the pseudo-labeled samples from steps e and g with the labeled samples, retrain, and obtain the optimized model 3;
[0095] i) Deploy the final Model 3 as an application account prediction neural network on a near real-time platform.
[0096] The pseudo-label learning method performs well after 1-2 iterations. In this embodiment, it is repeated 2 times to obtain the optimized model 3. This embodiment reduces the labeling cost and improves the labeling efficiency.
[0097] After training the application account prediction neural network, it is deployed to a near real-time policy engine. This platform, equipped with Python and relevant data dependency components, can acquire and process relevant data, call the model for prediction, and return results. Due to the short operating cycle of pornography-related crimes, the prediction and labeling of appids can be configured to run hourly. The specific process is as follows:
[0098] a) When each commercial payment transaction occurs, the protocol triggers a write to the key-value database in the near real-time system: using the merchant number as the key and the appid as the value, to record and store the merchant-appid transaction relationship;
[0099] b) Obtain the appid transaction information of all seed black market merchants in the previous hour once per hour;
[0100] c) Process the feature data of the relevant appid;
[0101] d) Use the pre-deployed model to predict these appids, and define the appids with a probability value >= 0.7 as the predicted positive appids, which are the label appids in this paper;
[0102] e) Using appid as the key, store the predicted probability value of appid in a key-value pair, and then retrieve and use it in the subsequent malicious merchant identification stage. Figure 6 This is a diagram illustrating the prediction of appid.
[0103] Figure 7 This is a diagram illustrating how to identify malicious merchants.
[0104] Predict the probability of merchant malicious activity based on the appid tag.
[0105] Based on the obtained tag appid, the corresponding appid-merchant transaction flow network is retrieved. The identification of pornographic merchants based on tag appid shows similar performance across different models, with relatively high accuracy. Merchants can be directly shut down as a penalty; therefore, the simpler and more interpretable logistic regression model is chosen.
[0106] Merchants whose appids were linked to in the previous N days and whose accounts have been closed or penalized are used as positive samples. Merchants whose accounts were approved after normal review or whose accounts were closed but were subsequently appealed and approved are used as negative samples. Combining merchant transaction characteristics, static characteristics and other data, logistic regression is used after feature engineering to predict the probability that a merchant is malicious.
[0107] The steps for model training and practical application are as follows:
[0108] a) Label positive and negative samples according to the definition. In this embodiment, the number of merchants associated in the previous N days that have been shut down or penalized may not be too large, meaning the number of positive samples will be small. Since pornographic merchants are easy to identify, in this embodiment, unlabeled samples can be covered by expert judgment. Merchants judged suspicious by human judgment are labeled as positive samples, and merchants judged trustworthy by human judgment are labeled as negative samples, thereby increasing the number of positive and negative samples.
[0109] b) Process the relevant data of the labeled samples to form several dimensional features that can be input into the model;
[0110] c) Train the model using the k-fold cross-validation method;
[0111] d) Deploy the trained model as a user account prediction neural network on a near real-time platform.
[0112] After obtaining the user account prediction neural network, it is deployed on a near real-time strategy platform. This platform can store and retrieve merchant-appid transaction relationship data and other data, call the model for prediction, and return results. The returned results are written into the real-time strategy system, which can then invoke different risk control measures to intercept transactions or automatically penalize payment capabilities based on the merchant's nature and probability values. The specific steps are as follows:
[0113] a) When each commercial payment transaction occurs, the protocol triggers a write to the key-value database in the near real-time system: using appid as the key and merchant number as the value, to record and store the appid-merchant transaction relationship;
[0114] b) Obtain the predicted malicious probability value of the appid once per hour, and obtain the full set of tag appids and the corresponding merchant data with transactions in the previous hour;
[0115] c) Process the characteristic data of relevant merchants;
[0116] d) Use the pre-deployed model to make predictions about these merchants and obtain their predicted probability values;
[0117] d) Using the merchant ID as the key, store the predicted probability value of the merchant in the key-value pair of the near real-time engine, and also write it into the key-value pair of the real-time strategy engine;
[0118] e) Trigger the real-time strategy engine to invoke risk control measures and call the automatic penalty interface for merchants with high malicious probability values.
[0119] In practical application, this embodiment can cover up to 60% of the total number of pornographic businesses, with an online automatic penalty accuracy rate of up to 99%. Approximately 50% of pornographic businesses are quickly located and dealt with on the first day of their illegal activities, and the strategy is not easily rendered ineffective by changes in the methods of black market operators, effectively curbing the expansion of such black market activities. At the same time, this method is also very effective in combating black market activities that are difficult to locate, such as pyramid schemes and multi-level marketing schemes.
[0120] In this embodiment, the tagging period for appids and the merchant prediction period are on the hourly level. This is because the malicious activity cycle of pornography-related black market activities is relatively short. To identify pornography-related appids and merchants more quickly, a shorter period can be selected if resources permit. For merchants with longer malicious activity cycles, such as gambling, a daily or even longer period can be used to balance machine resources and coverage speed. Additionally, this embodiment includes two model training steps, using the XGBoost model and the logistic regression model respectively. These two models perform well in the application of financial risk control data, but they can also be replaced by other models such as the Gradient Boosting Decision Tree (GBDT).
[0121] It should be noted that, for the sake of simplicity, the foregoing method embodiments are all described as a series of actions. However, those skilled in the art should understand that the present invention is not limited to the described order of actions, because according to the present invention, some steps can be performed in other orders or simultaneously. Furthermore, those skilled in the art should also understand that the embodiments described in the specification are preferred embodiments, and the actions and modules involved are not necessarily essential to the present invention.
[0122] According to another aspect of the present invention, a malicious account identification device for implementing the above-described malicious account identification method is also provided. For example... Figure 8 As shown, the device includes:
[0123] The first acquisition unit 802 is used to acquire the resource transfer event to be identified, wherein the resource transfer event carries an application account and a user account that are related, and in response to the click operation of the access link in the application account, the resource transfer operation between the application account and the user account is executed.
[0124] The second acquisition unit 804 is used to acquire event data of the first historical resource transfer event corresponding to the application account, wherein the first historical resource transfer event is the resource transfer event in which the application account participated within a first target time period before the resource transfer event was triggered.
[0125] Extraction unit 806 is used to extract feature data corresponding to each reference user account participating in the first historical resource transfer event from the event data of the first historical resource transfer event;
[0126] The third acquisition unit 808 is used to acquire the first identification confidence level corresponding to each of the reference user accounts based on the feature data of each of the reference user accounts.
[0127] The determining unit 810 is used to determine a reference user account whose first identification confidence level reaches a first threshold as a malicious user account.
[0128] Optionally, in this embodiment, the aforementioned malicious account identification device may be applied, but is not limited to, the process of identifying network accounts. A network account can be an account capable of executing resource transfer events. These resource transfer events can be the transfer of virtual resources from one account to another; they can be resource transfers between accounts within the same application or between accounts in different applications. For example, resource transfers between accounts in different applications can be performed through an inter-application interface between accounts on different applications.
[0129] The aforementioned application account can be an account that displays an access link. Clicking the access link redirects the user to their account, where the resource transfer operation can be completed. For example, user 1 accesses the application account, clicks the access link on the application account, is redirected to their user account, and completes the resource transfer event on their user account.
[0130] Optionally, in this embodiment, the relationship between application accounts and user accounts can be many-to-many. For example, one application account can correspond to multiple user accounts, and one user account can correspond to multiple application accounts.
[0131] The above correspondence means that accessing the user's account can be redirected through the access link on the application account.
[0132] In this embodiment, when a user jumps from an application account to a user account and completes a resource transfer event, all reference user accounts corresponding to the application account can be obtained. Based on the characteristic data of each reference user account, the first identification confidence level corresponding to each reference user account can be obtained. If the first identification confidence level is higher than the first threshold, then the reference user account is a malicious user account.
[0133] In this embodiment, malicious merchants can be merchants with specific labels, such as merchants that provide illegal services such as pornography, violence, gambling, and drug use. The method in this embodiment can automatically identify and monitor them, improving the accuracy of identifying malicious merchants.
[0134] In this embodiment, after the application account is redirected to the user account, the feature data of the reference user account in the first historical resource transfer event of the application account is used to identify the first identification confidence of the reference user account, thereby identifying whether the reference user account is a malicious user account, which improves the accuracy of identifying malicious user accounts.
[0135] For other examples of this embodiment, please refer to the examples above, which will not be repeated here.
[0136] According to another aspect of the present invention, an electronic device for implementing the above-described method for identifying malicious accounts is also provided. This electronic device may be... Figure 9 The terminal device or server shown. This embodiment uses the electronic device as a server as an example for illustration. Figure 9 As shown, the electronic device includes a memory 902 and a processor 904. The memory 902 stores a computer program, and the processor 904 is configured to execute the steps of any of the above method embodiments through the computer program.
[0137] Optionally, in this embodiment, the aforementioned electronic device may be located in at least one of a plurality of network devices in a computer network.
[0138] Optionally, in this embodiment, the processor can be configured to perform the following steps via a computer program:
[0139] Obtain the resource transfer event to be identified, wherein the resource transfer event carries an application account and a user account with an association relationship, and in response to the click operation of the access link in the application account, perform a resource transfer operation between the application account and the user account.
[0140] Obtain event data for the first historical resource transfer event corresponding to the application account, wherein the first historical resource transfer event is the resource transfer event in which the application account participated within the first target time period before the resource transfer event was triggered;
[0141] Extract the feature data corresponding to each reference user account that participated in the first historical resource transfer event from the event data;
[0142] Based on the feature data of each reference user account, obtain the first identification confidence level for each reference user account;
[0143] Reference user accounts whose first identification confidence level reaches the first threshold are identified as malicious user accounts.
[0144] Alternatively, as those skilled in the art will understand, Figure 9 The structure shown is for illustrative purposes only. Electronic devices can also be smartphones (such as Android phones, iOS phones, etc.), tablets, PDAs, mobile internet devices (MIDs), PADs, and other terminal devices. Figure 9 This does not limit the structure of the aforementioned electronic devices or electronic equipment. For example, electronic devices or electronic equipment may also include components that are more... Figure 9 The more or fewer components shown (such as network interfaces, etc.), or having the same Figure 9 The different configurations shown.
[0145] The memory 902 can be used to store software programs and modules, such as the program instructions / modules corresponding to the malicious account identification method and device in this embodiment of the invention. The processor 904 executes various functional applications and data processing by running the software programs and modules stored in the memory 902, thereby realizing the aforementioned malicious account identification method. The memory 902 may include high-speed random access memory, and may also include non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory 902 may further include memory remotely located relative to the processor 904, and these remote memories can be connected to the terminal via a network. Examples of such networks include, but are not limited to, the Internet, corporate intranets, local area networks, mobile communication networks, and combinations thereof. Specifically, the memory 902 may be used, but is not limited to, to store information such as user accounts and application accounts. As an example, such as... Figure 9 As shown, the memory 902 may include, but is not limited to, the first acquisition unit 802, the second acquisition unit 804, the extraction unit 806, the third acquisition unit 808, and the determination unit 810 in the malicious account identification device. Furthermore, it may include, but is not limited to, other module units in the malicious account identification device, which will not be elaborated upon in this example.
[0146] Optionally, the transmission device 906 described above is used to receive or send data via a network. Specific examples of the network described above may include wired networks and wireless networks. In one example, the transmission device 906 includes a Network Interface Controller (NIC), which can be connected to other network devices and a router via a network cable to communicate with the Internet or a local area network. In one example, the transmission device 906 is a Radio Frequency (RF) module used for wireless communication.
[0147] In addition, the aforementioned electronic device also includes a connection bus 908 for connecting various module components in the aforementioned electronic device.
[0148] In other embodiments, the aforementioned terminal device or server can be a node in a distributed system, wherein the distributed system can be a blockchain system, which is a distributed system formed by connecting multiple nodes through network communication. The nodes can form a peer-to-peer (P2P) network, and any form of computing device, such as a server, terminal, or other electronic device, can become a node in the blockchain system by joining this peer-to-peer network.
[0149] According to another aspect of the present invention, a computer-readable storage medium is also provided, wherein a computer program is stored therein, wherein the computer program is configured to perform the steps in any of the above method embodiments when it is run.
[0150] Optionally, in this embodiment, the computer-readable storage medium described above may be configured to store a computer program for performing the following steps:
[0151] Obtain the resource transfer event to be identified, wherein the resource transfer event carries an application account and a user account with an association relationship, and in response to the click operation of the access link in the application account, perform a resource transfer operation between the application account and the user account.
[0152] Obtain event data for the first historical resource transfer event corresponding to the application account, wherein the first historical resource transfer event is the resource transfer event in which the application account participated within the first target time period before the resource transfer event was triggered;
[0153] Extract the feature data corresponding to each reference user account that participated in the first historical resource transfer event from the event data;
[0154] Based on the feature data of each reference user account, obtain the first identification confidence level for each reference user account;
[0155] Reference user accounts whose first identification confidence level reaches the first threshold are identified as malicious user accounts.
[0156] Optionally, in this embodiment, those skilled in the art will understand that all or part of the steps in the various methods of the above embodiments can be implemented by a program instructing the hardware related to the terminal device. The program can be stored in a computer-readable storage medium, which may include: flash drive, read-only memory (ROM), random access memory (RAM), disk or optical disk, etc.
[0157] The sequence numbers of the above embodiments of the present invention are for descriptive purposes only and do not represent the superiority or inferiority of the embodiments.
[0158] If the integrated units in the above embodiments are implemented as software functional units and sold or used as independent products, they can be stored in the aforementioned computer-readable storage medium. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause one or more computer devices (which may be personal computers, servers, or network devices, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present invention.
[0159] In the above embodiments of the present invention, the descriptions of each embodiment have different focuses. For parts not described in detail in a certain embodiment, please refer to the relevant descriptions of other embodiments.
[0160] In the several embodiments provided in this application, it should be understood that the disclosed client can be implemented in other ways. The device embodiments described above are merely illustrative; for example, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces, indirect coupling or communication connection between units or modules, and may be electrical or other forms.
[0161] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0162] Furthermore, the functional units in the various embodiments of the present invention can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.
[0163] The above description is only a preferred embodiment of the present invention. It should be noted that for those skilled in the art, several improvements and modifications can be made without departing from the principle of the present invention, and these improvements and modifications should also be considered within the scope of protection of the present invention.
Claims
1. A method for identifying malicious accounts, characterized in that, include: Obtain the resource transfer event to be identified, wherein the resource transfer event carries an application account and a user account that are associated, and the resource transfer event is used to indicate a resource transfer operation between the user account and the application account when an access link in the application account is clicked. Obtain event data of the first historical resource transfer event corresponding to the application account, wherein the first historical resource transfer event is a resource transfer event in which the application account participated within a first target time period before the resource transfer event was triggered; Extract the feature data corresponding to each reference user account that participated in the first historical resource transfer event from the event data of the first historical resource transfer event; Based on the feature data of each of the reference user accounts, obtain the first identification confidence level corresponding to each of the reference user accounts; The reference user accounts whose first identification confidence level reaches the first threshold are identified as malicious user accounts.
2. The method according to claim 1, characterized in that, The step of obtaining the first identification confidence level corresponding to each of the reference user accounts based on their respective feature data includes: The feature data of each of the reference user accounts is input into the user account prediction neural network. The user account prediction neural network is a neural network obtained by training multiple times based on the feature data of the sample user accounts associated with the tag application account. It is used to determine the confidence level of a user account as a malicious user account. The tag application account is an application account that provides access links to malicious user accounts. The feature data of each of the reference user accounts are calculated in the user account prediction neural network to obtain the first identification confidence level corresponding to each of the reference user accounts.
3. The method according to claim 2, characterized in that, Before inputting the feature data of each of the reference user accounts into the user account prediction neural network, the method further includes: Obtain the sample user accounts associated with the tag application account, wherein the sample user accounts include positive sample user accounts and negative sample user accounts, the positive sample user accounts are malicious user accounts, and the negative sample user accounts are trusted user accounts; The feature data of the sample user accounts are processed to obtain the multidimensional feature vector of the sample user accounts; The multidimensional feature vectors of the sample user accounts and the event data of the sample resource transfer events in which the sample user accounts participated are sequentially input into the initial user account prediction neural network, and the network is trained using cross-validation to obtain the user account prediction neural network.
4. The method according to claim 2, characterized in that, Before inputting the feature data of each of the reference user accounts into the user account prediction neural network, the method further includes: Obtain event data of the second historical resource transfer event corresponding to the target user account that has been identified as a malicious user account, wherein the second historical resource transfer event is a resource transfer event in which the target user account participated within a second target time period before the resource transfer event was triggered; Extract the feature data corresponding to each reference application account that participated in the second historical resource transfer event from the event data of the second historical resource transfer event; Based on the feature data of each of the reference application accounts, obtain the second identification confidence level corresponding to each of the reference application accounts; The reference application account whose second identification confidence level reaches the second threshold is identified as the tag application account.
5. The method according to claim 4, characterized in that, Before obtaining the second identification confidence level corresponding to each of the reference application accounts based on their respective feature data, the method further includes: The feature data of each of the reference application accounts is input into the application account prediction neural network, wherein the application account prediction neural network is a neural network obtained by training multiple times based on the feature data of the sample application accounts, and is used to determine the confidence level of the application account as associated with the malicious user account. The feature data of each of the reference application accounts are calculated in the application account prediction neural network to obtain the second identification confidence level corresponding to each of the reference application accounts.
6. The method according to claim 5, characterized in that, Before obtaining the second identification confidence level corresponding to each of the reference application accounts based on their respective feature data, the method further includes: Obtain multiple original sample application accounts; The multiple original sample application accounts are subjected to noise reduction processing to obtain multiple sample application accounts; The multiple sample application accounts are labeled to obtain positive sample application accounts and negative sample application accounts; The feature data of the sample application account is processed to obtain the multidimensional feature vector of the sample application account; The multidimensional feature vector of the sample application account and the event data of the sample resource transfer events in which the sample application account participated are sequentially input into the initial application account prediction neural network, and the application account prediction neural network is trained using the cross-validation method to obtain the application account prediction neural network.
7. The method according to any one of claims 1 to 6, characterized in that, After determining the reference user account whose first identification confidence level reaches the first threshold as a malicious user account, the method further includes at least one of the following steps: The malicious user accounts will have their access privileges revoked. Intercept the resource transfer event triggered by the malicious user account.
8. A device for identifying malicious accounts, characterized in that, include: The first acquisition unit is used to acquire a resource transfer event to be identified, wherein the resource transfer event carries an application account and a user account that are associated, and the resource transfer event is used to indicate a resource transfer operation between the user account and the application account when an access link in the application account is clicked. The second acquisition unit is used to acquire event data of the first historical resource transfer event corresponding to the application account, wherein the first historical resource transfer event is a resource transfer event in which the application account participated within a first target time period before the resource transfer event was triggered. The extraction unit is used to extract feature data corresponding to each reference user account participating in the first historical resource transfer event from the event data of the first historical resource transfer event. The third acquisition unit is used to acquire the first identification confidence level corresponding to each of the reference user accounts based on the feature data of each of the reference user accounts. The determining unit is used to determine the reference user account whose first identification confidence level reaches a first threshold as a malicious user account.
9. The apparatus according to claim 8, characterized in that, The third acquisition unit includes: The first input module is used to input the feature data of each of the reference user accounts into the user account prediction neural network. The user account prediction neural network is a neural network obtained by training multiple times based on the feature data of the sample user accounts associated with the tag application account. It is used to determine the confidence level of a user account as a malicious user account. The tag application account is an application account that provides access links to malicious user accounts. The calculation module is used to calculate the feature data of each of the reference user accounts in the user account prediction neural network to obtain the first identification confidence level corresponding to each of the reference user accounts.
10. The apparatus according to claim 9, characterized in that, The third acquisition unit further includes: The first acquisition module is used to acquire the sample user accounts associated with the tag application account before inputting the feature data of each of the reference user accounts into the user account prediction neural network. The sample user accounts include positive sample user accounts and negative sample user accounts. The positive sample user accounts are malicious user accounts, and the negative sample user accounts are trusted user accounts. The processing module is used to process the feature data of the sample user accounts to obtain the multidimensional feature vector of the sample user accounts. The second input module is used to sequentially input the multidimensional feature vector of the sample user account and the event data of the sample resource transfer events in which the sample user account participates into the initial user account prediction neural network, and train it using the cross-validation method to obtain the user account prediction neural network.
11. The apparatus according to claim 9, characterized in that, The third acquisition unit further includes: The second acquisition module is used to acquire event data of the second historical resource transfer event corresponding to the target user account that has been identified as a malicious user account before inputting the feature data of each of the reference user accounts into the user account prediction neural network. The second historical resource transfer event is a resource transfer event in which the target user account participated within a second target time period before the resource transfer event was triggered. The extraction module is used to extract the feature data corresponding to each reference application account that participated in the second historical resource transfer event from the event data of the second historical resource transfer event; The third acquisition module is used to acquire the second identification confidence level corresponding to each of the reference application accounts based on the feature data of each of the reference application accounts. The determination module is used to determine the reference application account whose second identification confidence level reaches the second threshold as the tag application account.
12. The apparatus according to claim 11, characterized in that, The third acquisition module further includes: The first acquisition submodule is used to input the feature data of each reference application account into the application account prediction neural network before acquiring the second identification confidence level corresponding to each reference application account based on the feature data of each reference application account. The application account prediction neural network is a neural network obtained by training multiple times based on the feature data of the sample application accounts, and is used to determine the confidence level of the application account as associated with the malicious user account. The calculation submodule is used to calculate the feature data of each of the reference application accounts in the application account prediction neural network to obtain the second identification confidence level corresponding to each of the reference application accounts.
13. The apparatus according to claim 12, characterized in that, The third acquisition module further includes: The second acquisition submodule is used to acquire multiple original sample application accounts before acquiring the second identification confidence level corresponding to each of the reference application accounts based on their respective feature data. The noise reduction submodule is used to perform noise reduction processing on the multiple original sample application accounts to obtain multiple sample application accounts; The annotation submodule is used to annotate multiple sample application accounts to obtain positive sample application accounts and negative sample application accounts; The processing submodule is used to process the feature data of the sample application account to obtain the multidimensional feature vector of the sample application account. The input submodule is used to sequentially input the multidimensional feature vector of the sample application account and the event data of the sample resource transfer events in which the sample application account participates into the initial application account prediction neural network, and train it using the cross-validation method to obtain the application account prediction neural network.
14. A computer-readable storage medium storing a computer program, characterized in that, The computer program executes the method described in any one of claims 1 to 7 when it runs.
15. An electronic device comprising a memory and a processor, characterized in that, The memory stores a computer program, and the processor is configured to execute the method described in any one of claims 1 to 7 through the computer program.