A method and computing device for constructing a counterfeit card identification model and for counterfeit card identification.

CN115423464BActive Publication Date: 2026-09-01UNIONPAY ZHICE CONSULTING (SHANGHAI) CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210936101.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-08-05
Publication Date
2026-09-01
Estimated Expiration
2042-08-05

AI Technical Summary

Technical Problem

[0003]但是,依靠POS机应答码进行判断,会出现误判的情况,如由于在POS机安装时候测试卡出错导致在实际的交易中POS机应答码误判,因此无法准确判断出此卡是否为一张伪冒卡或有作弊嫌疑的卡

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115423464B_ABST
    Figure CN115423464B_ABST
Patent Text Reader

Abstract

This application provides a method and computing device for constructing a counterfeit card identification model and for counterfeit card identification. The main method includes: constructing a first initial model and a second initial model; acquiring transaction data of each counterfeit card under different time-duration standards as samples; training the first initial model with samples under the same time-duration standard to obtain a first model under the specified time-duration standard; obtaining second values ​​of each input feature by passing samples under at least one time-duration standard through the second initial model; and determining a counterfeit card identification model whose counterfeit card identification effect meets the set requirements by using the second values ​​of each input feature and the first models under different time-duration standards. By constructing a counterfeit card identification model and a counterfeit card identification method in the above manner, the risk probability of counterfeit cards can be determined, and merchants with counterfeit card risk can be identified.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments of the present invention relate to the field of information technology, and in particular to a method and computing device for constructing a counterfeit card identification model and for counterfeit card identification. Background Technology

[0002] In UnionPay transaction data, the standard technical method for identifying terminal operations is through the POS machine's response code. Counterfeit card fraud will generate two types of response codes, which can be used to determine whether the card is counterfeit or suspected of being used for fraud.

[0003] However, relying on POS machine response codes for judgment can lead to misjudgments. For example, if the test card is faulty during POS machine installation, the POS machine may misjudge the response code during the actual transaction, making it impossible to accurately determine whether the card is counterfeit or suspected of being used for fraud. Summary of the Invention

[0004] This application provides a method for constructing a counterfeit card identification model and identifying counterfeit cards. Based on the counterfeit card response code, it can more accurately determine the risk probability of a counterfeit card and identify cards suspected of being fraudulently used by analyzing transaction habits.

[0005] In a first aspect, embodiments of this application provide a method for constructing a counterfeit card identification model, the method comprising:

[0006] Construct a first initial model and a second initial model; the first initial model and the second initial model have the same input features but different processing logic;

[0007] Transaction data of each counterfeit card under different time standards is obtained as a sample; any time period is selected based on the time points of the first and last counterfeit card transactions.

[0008] For samples under the same duration standard, the first initial model is trained using samples under the same duration standard to obtain a first model under the same duration standard; wherein, the first model has the first value of each input feature after training;

[0009] The second value of each input feature is obtained by passing at least one sample under a time standard through the second initial model.

[0010] By using the second values ​​of each input feature and the first models under different time duration standards, a counterfeit card recognition model that meets the set requirements is determined.

[0011] This application embodiment improves the recognition effect of the final counterfeit card recognition model by using two models with the same input features but different processing logics. At the same time, taking the time points of the first and last response codes of the transaction as the benchmark, transaction data under different time standards are used as samples to construct the counterfeit card recognition model through transaction data, which no longer relies solely on POS machine response codes for judgment, thus improving the accuracy of counterfeit card recognition.

[0012] Optionally, by using the second values ​​of each input feature and each first model under different time duration standards, a counterfeit card recognition model that meets the set requirements is determined, including:

[0013] For a first model under any time standard, the first value in the first model is updated by the second value of each input feature to obtain a corrected model;

[0014] Based on the various correction models under different time-duration standards, the correction model that satisfies the set requirements for counterfeit card recognition effect is determined as the counterfeit card recognition model.

[0015] For the first model under different time standards, the second value of each input feature is used to adjust the corresponding first value in the first model. The adjusted model is used as the corrected model, so that the corrected model integrates the training results of the first model and the second model. Furthermore, the corrected model that meets the set requirements is selected from each corrected model as the fake card recognition model. Furthermore, the time standard that is better for fake card recognition is determined under different time standards.

[0016] Optionally, from various correction models under different time-duration standards, the correction model that meets the set requirements for counterfeit card recognition performance is determined as the counterfeit card recognition model, including:

[0017] For any time-based standard, the modified model is input into the modified model to obtain the predicted pseudo-card result of the sample; based on the predicted pseudo-card result of each sample, the pseudo-card recognition effect of the modified model is determined.

[0018] The modified model with the best counterfeit card recognition performance is used as the counterfeit card recognition model.

[0019] Input any sample into each correction model, and compare the predicted sample results of each correction model with the actual sample results. For example, the model with the smallest deviation between the predicted value and the actual value is taken as the final fake card identification model. The fake card identification model is selected by means of samples.

[0020] Optionally, the first initial model is a logistic regression model; the second initial model is a Naive Bayes model.

[0021] By using the second values ​​of each input feature and the first models under different time duration standards, a counterfeit card recognition model that meets the set requirements is determined, including:

[0022] From the first models under different time-duration standards, the first model with the best counterfeit card recognition performance was determined;

[0023] The counterfeit card identification model is determined by using the second values ​​of each input feature and the first values ​​of each input feature in the first model with the best counterfeit card identification effect.

[0024] The above scheme determines the first model with the best counterfeit card identification effect from each first model. The time standard corresponding to this first model is used as the basis for transaction data for counterfeit card identification. Further, the second value of each input feature obtained by the second model is applied to this model, and the first value and the second value are combined to obtain the final counterfeit card identification model that meets the set requirements.

[0025] Secondly, embodiments of this application provide a method for identifying counterfeit cards, including:

[0026] Identify a suspected card with a transaction response code indicating a counterfeit card;

[0027] Acquire the first transaction data of the suspected card within a set time period, based on the time points of the first and last occurrences of the response codes in the transaction.

[0028] Based on the first transaction data, determine the first input feature value corresponding to each input feature;

[0029] Each first input feature is input into the counterfeit card identification model to determine the probability that the card is a counterfeit card; the counterfeit card identification model is obtained through the method described in the first aspect above.

[0030] In the above method, suspected cards with transaction response codes indicating counterfeit cards are further analyzed using a counterfeit card identification model. Using the times of the first and last occurrence of the response code as benchmarks, transaction data for this card is obtained within a set timeframe corresponding to the counterfeit card identification model, thereby determining transaction characteristics. These characteristics are then input into the counterfeit card identification model to determine whether the card is counterfeit. This two-layer approach—using the transaction response code indicating a counterfeit card and the counterfeit card identification model utilizing transaction data—improves the accuracy of counterfeit card identification.

[0031] Optional, also includes:

[0032] For any normal card, obtain the second transaction data of the card within the set time period;

[0033] Based on the second transaction data, determine the second input feature corresponding to each input feature;

[0034] Each second input feature is input into the counterfeit card identification model to determine the probability that the card is a counterfeit card.

[0035] The aforementioned normal card refers to any card that has not received a transaction response code indicating a counterfeit card. Based on the card's transaction data, its transaction characteristics are determined and input into the counterfeit card identification model to determine whether the card is normal. In this way, normal cards with the potential to be counterfeit cards can be identified based on transaction data, allowing for focused tracking of these cards before a counterfeit card response code is received.

[0036] Optionally, after determining the probability that the card is counterfeit, the method further includes:

[0037] For any given merchant, determine the statistical information of each counterfeit card used for transactions at that merchant; based on the statistical information, construct a dimension vector for the merchant in different dimensions.

[0038] Cluster the dimensional vectors of each merchant to determine the merchant counterfeit card risk for each merchant.

[0039] The above method further evaluates merchants based on the identified counterfeit cards. Different dimensional vectors are used in the risk assessment of merchants, and a clustering algorithm is applied to the dimensional vectors of each merchant to determine the counterfeit card risk level. This method, by analyzing the spending patterns of counterfeit cards at merchants, further identifies merchants suspected of using counterfeit cards, which can further reduce the occurrence of subsequent counterfeit card transactions.

[0040] Optionally, determine the statistical information of each counterfeit card used for transactions at the merchant, including:

[0041] For any counterfeit card used for purchases at the merchant, determine the risk level of the counterfeit card; based on the number of counterfeit cards at each risk level, determine the counterfeit card distribution information of the merchant.

[0042] Determine the percentage of counterfeit card spending for each counterfeit card under the aforementioned merchant;

[0043] Based on the statistical information, construct the dimensional vectors of the merchants under different dimensions, including:

[0044] The distribution information of counterfeit cards of merchants, the proportion of counterfeit card consumption of merchants, and whether a merchant has multiple accounts on one device are determined as the dimension vectors of the merchants in different dimensions.

[0045] Based on transaction data of counterfeit cards used at merchants, three labels are summarized as characteristics to judge whether a merchant is a risky merchant.

[0046] Thirdly, embodiments of this application provide a computing device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement the steps of any of the methods described in the first and second aspects.

[0047] Fourthly, embodiments of this application provide a computer-readable storage medium storing a computer program executable by a computer device, which, when run on the computer device, causes the computer device to perform the steps of any of the methods described in the first and second aspects. Attached Figure Description

[0048] To more clearly illustrate the technical solutions in the embodiments of this application, the drawings used in the embodiments of this application will be briefly introduced below. Obviously, the drawings below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0049] Figure 1 This application provides a flowchart for constructing a counterfeit card identification model.

[0050] Figure 2 This application provides a process for generating a counterfeit card identification model.

[0051] Figure 3 This application provides a specific process for model training in its embodiments;

[0052] Figure 4 This application provides a method for identifying counterfeit cards.

[0053] Figure 5 A process for identifying merchant risk levels is provided in the embodiments of this application;

[0054] Figure 6 This application provides a method for determining a merchant's risk level.

[0055] Figure 7 This application provides an important indicator for identifying the risk level of merchants.

[0056] Figure 8 This is a schematic diagram of the structure of a computing device provided in an embodiment of this application. Detailed Implementation

[0057] In existing technologies, counterfeit card identification methods typically rely on the two counterfeit card response codes displayed by the POS terminal to determine whether a card is counterfeit or suspected of fraud. Errors during POS terminal installation testing can lead to misinterpretations of the response codes, resulting in inaccurate identification. Furthermore, counterfeit card fraud rings often collaborate with merchants, and relying solely on POS terminal response codes to prevent counterfeit card fraud cannot address the root cause of the problem. This application provides a counterfeit card identification model that can more accurately assess the probability of counterfeit card fraud and identify merchants at risk of such fraud based on the risk level of the counterfeit card, thus addressing the problem at its source.

[0058] The following describes the generation process of the counterfeit card identification model, such as... Figure 1 As shown:

[0059] S101. Construct a first initial model and a second initial model; the first initial model and the second initial model have the same input features but different processing logic;

[0060] A model can be considered an expression of an algorithm that can search for patterns or make predictions by analyzing massive amounts of data. The processing logic of a model can be diverse; for example, linear models can be used to predict the relationship between variables, graphical models use graphs to represent probabilities, and convolutional neural network models are commonly used in computer vision, etc.

[0061] The input features and processing logic of the model are closely related. Typically, it involves filtering out meaningful features—those that can differentiate the target—from a vast amount of data. In this embodiment, the input features selected based on specific transaction data may include one or more of the following:

[0062] 1. Balance Inquiry Features: Check if there are any balance inquiry actions in card transactions;

[0063] 2. Password Attempt Characteristics: Check for any incorrect password transactions on the card.

[0064] 3. Multi-location transaction characteristics: For offline transactions, check whether card transactions occurred at more than three merchants within the same hour;

[0065] 4. Multi-merchant transaction characteristics: For offline transactions, check whether the same transaction amount occurs at more than two merchants within the same hour;

[0066] 5. Identity verification features: Check whether the card transaction has undergone identity verification;

[0067] 6. Characteristics of cross-border transactions: Check whether the card transaction was made overseas;

[0068] 7. Characteristics of large transactions: Check if there are any large-amount transactions on the card;

[0069] 8. Whole Amount Transaction Characteristics: Check if there are whole amount transactions on the card;

[0070] 9. Midnight Transaction Characteristics: Check if any card transactions were made at midnight;

[0071] 10. Similarity of transaction amounts: Check the coefficient of variation of each transaction amount on the card.

[0072] The first initial model and the second initial model have the same sample data and the same input features. In this embodiment, the chi-square binning algorithm is applied to determine the threshold for the large transaction feature. The transaction amounts of cards suspected of being counterfeit are binned to obtain the large transaction threshold.

[0073]

[0074] Among them, A ij Let E be the number of instances of class j in interval i. ij For A ij of N is the total number of samples, N i C is the number of samples in the i-th group. j It is the proportion of the j-th type of sample in the whole.

[0075] Find the smallest chi-square value from the calculated values ​​and merge the corresponding two bins. Repeat the above steps until the bins are divided into two bins. The threshold value is the threshold for determining whether a transaction is large.

[0076] S102. Obtain transaction data of each counterfeit card under different time standards as samples; any time period is selected based on the time points of the first and last counterfeit card transactions.

[0077] This application embodiment uses card transaction data for counterfeit card identification; therefore, the amount and timing of the selected transaction data are crucial for counterfeit card identification. This application embodiment selects different time periods, i.e., different durations of transaction data, based on the time attributes of the transaction data for counterfeit card identification.

[0078] Specifically, the timeframes can be divided based on the first and last occurrences of the counterfeit card transaction response code: one week, two weeks, three weeks, one month, two months, three months, six months, and one year before the first occurrence of the counterfeit card response code. Similarly, the timeframes can be divided based on the last occurrence of the counterfeit card transaction response code: one week, two weeks, three weeks, one month, two months, three months, six months, and one year after the last occurrence of the counterfeit card transaction response code. This results in 16 timeframes.

[0079] S103. For samples under the same duration standard, train the first initial model using samples under the same duration standard to obtain the first model under the duration standard; wherein, the first model has the first value of each input feature after training;

[0080] For sample data within the same time period, the weights of each input feature under that time period standard are obtained by training the first model, and are denoted as the first value. For example, the first model is trained on samples from the week preceding the occurrence of the counterfeit card transaction response code, and the weights of the aforementioned 10 input features are obtained. The weights of these 10 input features in the first model are the first values.

[0081] S104. Take samples under at least one time duration standard and use the second initial model to obtain the second values ​​of each input feature;

[0082] By training the second model, the probability of each input feature is obtained, which is denoted as the second value.

[0083] S105. Using the second values ​​of each input feature and the first models under different time length standards, determine the fake card recognition model that meets the set requirements.

[0084] For the first model under different time standards, the second value of each input feature is used to adjust the corresponding first value in the first model. The adjusted model is used as the corrected model, so that the corrected model integrates the training results of the first model and the second model. Furthermore, the corrected model that meets the set requirements is selected from each corrected model as the fake card recognition model. Furthermore, the time standard that is better for fake card recognition is determined under different time standards.

[0085] This application further provides how to combine the first value and the second value to derive a counterfeit card identification model.

[0086] Method 1: such as Figure 2 As shown, by using the second values ​​of each input feature and the first models under different time duration standards, a counterfeit card recognition model that meets the set requirements is determined, including:

[0087] S201. For the first model under any time standard, update the corresponding first value in the first model with the second value of each input feature to obtain the corrected model;

[0088] In this step, each first model is adjusted using the second value of each input feature to obtain a corrected model corresponding to each first model. Specifically, the 16 first models trained under the 16 different duration standards are adjusted to obtain 16 corrected models.

[0089] There are various ways to adjust the first value based on the second value. One feasible way is to sum the first and second values ​​and assign the summation result to different scores, i.e., the score corresponding to each input feature. Another feasible way is to use weighted summation and use the result as the weight of each input feature. The weight setting can be based on the difference in recognition performance between the first model and the second model.

[0090] S202. From the various correction models under different time length standards, determine the correction model that meets the set requirements for the counterfeit card recognition effect as the counterfeit card recognition model.

[0091] After obtaining each modified model, the counterfeit card recognition performance of the modified model can be determined through individual samples; alternatively, in practical applications, the performance of each modified model can be used as the counterfeit card recognition performance, and the model that meets the set requirements can be used as the counterfeit card recognition model. The set requirements here can be the optimal counterfeit card recognition performance, or multiple models with relatively good recognition performance. The specific requirements depend on the actual application needs.

[0092] The following is an implementation method to determine the counterfeit card recognition effect: For any time standard, input any sample of the time standard into the correction model to obtain the predicted counterfeit card result of the sample; determine the counterfeit card recognition effect of the correction model based on the predicted counterfeit card result of each sample; and take the correction model with the best counterfeit card recognition effect as the counterfeit card recognition model.

[0093] Arbitrary samples are input into each modified model, and the predicted sample results of each modified model are compared with the actual sample results. For example, the model with the smallest deviation between the predicted value and the actual value is selected as the final fake card identification model. The optimal model is confirmed by calculating the predicted value IV. IV, or Information Value, is used to represent the degree of contribution of a feature to the target prediction, that is, the predictive ability of the feature. Generally speaking, the higher the IV value, the stronger the predictive ability of the feature and the higher the degree of information contribution.

[0094]

[0095] Among them, #y i This refers to the number of predicted cards identified as counterfeit, #n i The predicted number of cards identified as normal is #y T This represents the total number of suspected counterfeit cards in the sample, #n T It represents the total number of all suspected counterfeit cards in the sample.

[0096] The optimal modified model is determined by the magnitude of the IV value; the model with the largest IV value is the optimal modified model.

[0097] Method 2, such as Figure 3As shown in the embodiment of this application, a specific process for model training is provided. The two models used are a logistic regression model and a Naive Bayes model. By using the second values ​​of each input feature and the first models under different time length standards, a counterfeit card recognition model that meets the set requirements is determined, including:

[0098] S301. From the first models under different time length standards, determine the first model with the best counterfeit card recognition effect;

[0099] In this embodiment of the application, when training the two models, the logistic regression model is first trained on the sample data. Under 16 time-duration standards, 16 logistic regression models with different first values ​​are obtained. Then, the IV value is calculated for each of the 16 logistic regression models. The model with the largest IV value is the first model with the best counterfeit card recognition effect.

[0100] S302. The counterfeit card identification model is determined by the second value of each input feature and the first value of each input feature in the first model with the best counterfeit card identification effect.

[0101] After determining the first model with the best counterfeit card recognition effect, the second model is used on this model. The second value obtained from the second model is used to adjust the first value of the first model. The final result is the counterfeit card recognition model.

[0102] The specific process of the Bayesian model is as follows:

[0103] 1. We can learn the prior distribution of Naive Bayes (Y is the independent variable, is there any suspicion of a fake card? Xi is the dependent variable, consisting of 10 input features):

[0104] P(Y=C k Formula 3 (k = 1, 2)

[0105] 2. Next, we will learn about conditional probability distributions:

[0106]

[0107] The joint distribution P(X,Y) of X and Y can be obtained using Bayes' theorem. The joint distribution is defined as P(X,Y):

[0108]

[0109] Since we made the assumption that the variables are conditionally independent of each other, we can conclude that:

[0110]

[0111] This involves calculating the probability of a counterfeit card for each variable using frequency counts. Combining the counterfeit card probability with the logistic regression weights, we can determine the degree to which each label aligns with counterfeit card skimming habits. The higher the overall percentage, the more important that label is in identifying counterfeit card skimming behavior.

[0112] Method 3: For each sample under the same time standard, train the first initial model and the second initial model using each sample to obtain the first model and the second model; for the same input variable, obtain the final value of the input variable based on the first value of the input variable in the first model and the second value of the input variable in the second model; obtain the corrected model based on the final values ​​of each input variable.

[0113] From the various correction models under different time-duration standards, the correction model that meets the set requirements for counterfeit card recognition effect is determined as the counterfeit card recognition model.

[0114] The various fusion methods provided above enable the final counterfeit card identification model to identify counterfeit cards based on transaction data.

[0115] This application also provides a method for identifying counterfeit cards, such as... Figure 4 As shown, it includes:

[0116] S4011. Identify a suspected card with a transaction response code indicating a counterfeit card;

[0117] When a card is swiped at a POS terminal, a counterfeit card will generate two types of response codes. This embodiment uses these two response codes to initially determine whether the card is counterfeit or suspected of being used for fraud. Based on these two response codes, preliminary filtering is performed to identify cards that have been involved in counterfeit card transactions.

[0118] S4012. Obtain the first transaction data of the suspect card within a set time period based on the time point of occurrence of the transaction response code;

[0119] If a card suspected of being counterfeit is obtained based on the response code, the transaction data within the set time period corresponding to the first and last counterfeit card response codes of this card is used as the reference point. This data is recorded as the first transaction data. For example, if the set time period corresponding to the counterfeit card identification model is one week before and after, then the first transaction data obtained will be the data within that week. The first transaction data is used to distinguish it from the subsequent second transaction data.

[0120] S4013. Based on the first transaction data, determine the first input feature value corresponding to each input feature;

[0121] Based on the first transaction data of this card, determine whether the above 10 features exist, and calculate the feature value of each input feature, which is recorded as the first input feature value.

[0122] S4014. Input each of the first input features into the counterfeit card identification model to determine the risk probability of the counterfeit card.

[0123] Furthermore, the output of the counterfeit card identification model can be the counterfeit card probability, and the corresponding score can be determined based on the counterfeit card probability, or it can be directly divided into 5 counterfeit card levels based on the counterfeit card probability, namely low risk, low-medium risk, medium risk, medium-high risk, and high risk.

[0124] The above implementation method is for suspected cards. That is, when a transaction response code indicating a counterfeit card is issued, such as during a transaction at a POS machine, the POS initially determines that there is a suspected counterfeit card. Then, the above implementation method is activated to further judge the transaction data of this card within a set time period and finally output whether it is a counterfeit card. Alternatively, at a certain point in time after the transaction response code indicating a counterfeit card is issued, the transaction data of this card within a set time period is further judged to finally give an accurate conclusion on whether it is a counterfeit card.

[0125] Furthermore, this application's embodiments can also detect counterfeit cards even with normal cards, such as... Figure 4 As shown:

[0126] S4021. For any normal card, obtain the second transaction data of the card during the set time period;

[0127] A normal card is one that has never received a counterfeit card response code. If transaction data for a normal card is obtained, the transaction duration division of this card is consistent with that of a counterfeit card. The second transaction data is the transaction data of this normal card, and is different from the first transaction data.

[0128] S4022. Based on the second transaction data, determine the second input feature corresponding to each input feature;

[0129] The feature values ​​of the 10 input features of the normal card are determined and denoted as the second input feature.

[0130] S4023. Input each of the second input features into the counterfeit card identification model to determine the risk probability of the counterfeit card.

[0131] The second input feature of the normal card is input into the counterfeit card identification model to determine the risk probability of the counterfeit card. This step allows for some prediction, enabling focused monitoring of normal cards with a high probability of being counterfeited.

[0132] After determining the risk level of a counterfeit card, this application embodiment also provides a process for identifying the risk level of a merchant, and assessing the merchant's risk level. For example... Figure 5 As shown:

[0133] S501. For any merchant, determine the statistical information of each counterfeit card consumed at the merchant; based on the statistical information, construct the dimension vector of the merchant in different dimensions;

[0134] All merchants whose transactions occurred using counterfeit cards were extracted to form a counterfeit card transaction merchant dataset. To accurately identify the risk level of merchants using counterfeit cards, three labels were summarized as criteria for risk level identification by observing the transaction data of each merchant suspected of using counterfeit cards: the distribution of the number of risky cards, the proportion of counterfeit card transactions, and whether it is a single device with multiple accounts.

[0135] S502. Cluster the dimension vectors of each merchant to determine the merchant counterfeit card risk of each merchant.

[0136] In determining the risk level of merchants, since there is no objective variable, unsupervised learning is used for prediction. Initially, K-means clustering is chosen as the prediction model, but because the risk levels are ordered, K-means++ is used for optimization. For example... Figure 6 As shown:

[0137] S5021. Based on expert experience, select three initial cluster centers from the sample merchants and define them as high, medium and low risk levels, respectively.

[0138] S5022. For each point in the sample, calculate its Euclidean distance to the nearest cluster center among the selected cluster centers.

[0139] S5023. In each iteration, the mean of the Euclidean distance is used to update the centroids of the three clusters.

[0140] S5024. After iteratively updating the three cluster centers using the second and third steps, if the change in location points is less than the set threshold, it is considered to have reached a stable state, and the iteration ends, thus realizing the classification of merchants into three risk levels: high, medium, and low.

[0141] The statistical information of each counterfeit card used for transactions at the merchant, as described in this application embodiment, is as follows: Figure 7 As shown, it includes:

[0142] S701. For any counterfeit card used for a transaction at the merchant, determine the risk level of the counterfeit card; based on the number of counterfeit cards at each risk level, determine the counterfeit card distribution information of the merchant.

[0143] Based on the number and distribution of risk cards: calculate the number of each risk level of all counterfeit cards occurring at this merchant, and complete the preliminary classification of merchant counterfeit card risk levels by observing the distribution of the number of risk levels across all merchants.

[0144] S702. Determine the percentage of counterfeit card consumption for each counterfeit card under the merchant.

[0145] Based on the percentage of counterfeit cards that occurred to the total number of cards: Calculate the ratio of all counterfeit cards that occurred at this merchant to all consumer cards that occurred at this merchant. The size of the ratio can determine whether this merchant is a merchant favored by counterfeit cards, thereby assessing the merchant's counterfeit card risk.

[0146] S703. Based on the statistical information, construct the dimensional vector of the merchant under different dimensions, including:

[0147] The distribution information of counterfeit cards of merchants, the proportion of counterfeit card consumption of merchants, and whether a merchant has multiple accounts on one device are determined as the dimension vectors of the merchants in different dimensions.

[0148] Based on the logic of one machine for multiple accounts: By regulating the phenomenon of one machine for multiple codes and one machine for multiple accounts through the People's Bank of China, POS machines with multiple merchants on a single terminal have identified a group of fake merchants. By observing the number of merchants sharing the same terminal, the risk of counterfeit cards by merchants can be judged.

[0149] Based on the same technical concept, embodiments of this application provide a computing device, which may be a terminal or a server, such as... Figure 8 As shown, it includes at least one processor 801 and a memory 802 connected to at least one processor. In this embodiment, the specific connection medium between the processor 801 and the memory 802 is not limited. Figure 8 Taking the connection between the processor 801 and the memory 802 via a bus as an example, the bus can be divided into address bus, data bus, control bus, etc.

[0150] In this embodiment of the application, the memory 802 stores instructions that can be executed by at least one processor 801. By executing the instructions stored in the memory 802, at least one processor 801 can perform the steps included in the traffic flow tracing method described above.

[0151] The processor 801 is the control center of the computing device, capable of connecting various parts of the computer device via various interfaces and lines. It performs traffic flow tracing by running or executing instructions stored in the memory 802 and accessing data stored in the memory 802. Optionally, the processor 801 may include one or more processing units. The processor 801 may integrate an application processor and a modem processor. The application processor primarily handles the operating system, user interface, and applications, while the modem processor primarily handles wireless communication. It is understood that the modem processor may not be integrated into the processor 801. In some embodiments, the processor 801 and the memory 802 may be implemented on the same chip; in other embodiments, they may be implemented on separate chips.

[0152] The processor 801 can be a general-purpose processor, such as a central processing unit (CPU), digital signal processor, application-specific integrated circuit (ASIC), field-programmable gate array (FPGA), or other programmable logic device, discrete gate or transistor logic device, or discrete hardware component, capable of implementing or executing the methods, steps, and logic block diagrams disclosed in the embodiments of this application. The general-purpose processor can be a microprocessor or any conventional processor. The steps of the methods disclosed in the embodiments of this application can be directly manifested as being executed by a hardware processor, or executed by a combination of hardware and software modules within the processor.

[0153] Memory 802, as a non-volatile computer-readable storage medium, can be used to store non-volatile software programs, non-volatile computer-executable programs, and modules. Memory 802 may include at least one type of storage medium, such as flash memory, hard disk, multimedia card, card-type memory, random access memory (RAM), static random access memory (SRAM), programmable read-only memory (PROM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), magnetic storage, magnetic disk, optical disk, etc. Memory 802 can be any other medium capable of carrying or storing desired program code in the form of instructions or data structures that can be accessed by a computer, but is not limited thereto. In the embodiments of this application, memory 802 can also be a circuit or any other device capable of implementing storage functions for storing program instructions and / or data.

[0154] Based on the same inventive concept, embodiments of this application provide a computer-readable storage medium storing a computer program executable by a computer device, which, when run on the computer device, causes the computer device to perform the steps of the traffic flow tracing method described above.

[0155] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0156] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to this application. It should be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart illustrations. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0157] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0158] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.

[0159] Obviously, those skilled in the art can make various modifications and variations to this application without departing from the spirit and scope of this application. Therefore, if such modifications and variations fall within the scope of the claims of this application and their equivalents, this application also intends to include such modifications and variations.

Claims

1. A method for constructing a counterfeit card identification model, characterized in that, The method includes: Construct a first initial model and a second initial model; the first initial model and the second initial model have the same input features but different processing logic; Transaction data of each counterfeit card under different time standards is obtained as a sample; any time period is selected based on the time points of the first and last counterfeit card transactions. For samples under the same duration standard, the first initial model is trained using samples under the same duration standard to obtain a first model under the same duration standard; wherein, the first model has a first value for each input feature after training, and the first value is the weight of each input feature under the same duration standard obtained by training the first model for samples under the same duration standard; The second value of each input feature is obtained by using a second model to obtain samples under at least one time duration standard. The second model is obtained by training the second initial model with the samples. The second value is the probability of obtaining each input feature by training the second model. For a first model under any time standard, the first value in the first model is updated by the second value of each input feature to obtain a corrected model; Based on the various correction models under different time-duration standards, the correction model that satisfies the set requirements for counterfeit card recognition effect is determined as the counterfeit card recognition model.

2. The method according to claim 1, characterized in that, From various correction models under different time-duration standards, the correction model that meets the set requirements for counterfeit card recognition performance is identified as the counterfeit card recognition model, including: For any time-based standard, the modified model is input into the modified model to obtain the predicted pseudo-card result of the sample; based on the predicted pseudo-card result of each sample, the pseudo-card recognition effect of the modified model is determined. The modified model with the best counterfeit card recognition performance is used as the counterfeit card recognition model.

3. The method according to claim 1, characterized in that, The first initial model is a logistic regression model; the second initial model is a Naive Bayes model. The counterfeit card identification model is determined through the following methods: From the first models under different time-duration standards, the first model with the best counterfeit card recognition performance was determined; The counterfeit card identification model is determined by using the second values ​​of each input feature and the first values ​​of each input feature in the first model with the best counterfeit card identification effect.

4. A method for identifying counterfeit cards, characterized in that, include: Identify a suspected card with a transaction response code indicating a counterfeit card; Acquire the first transaction data of the suspected card within a set time period, based on the time points of the first and last occurrences of the response codes in the transaction. Based on the first transaction data, determine the first input feature value corresponding to each input feature; Each first input feature value is input into the counterfeit card identification model to determine the probability that the card is a counterfeit card. The counterfeit card identification model is obtained by the method described in any one of claims 1 to 3.

5. The method according to claim 4, characterized in that, Also includes: For any normal card, obtain the second transaction data of the normal card within the set time period; Based on the second transaction data, determine the second input feature corresponding to each input feature; Each second input feature is input into the counterfeit card identification model to determine the probability that the card is a counterfeit card.

6. The method according to claim 4 or 5, characterized in that, After assessing the probability of counterfeit cards, the following is also included: For any given merchant, determine the statistical information of each counterfeit card used for transactions at that merchant; based on the statistical information, construct a dimension vector for the merchant in different dimensions. Cluster the dimensional vectors of each merchant to determine the merchant counterfeit card risk for each merchant.

7. The method according to claim 6, characterized in that, Statistical information on each counterfeit card used at the merchant was determined, including: For any counterfeit card used for purchases at the merchant, determine the risk level of the counterfeit card; based on the number of counterfeit cards at each risk level, determine the counterfeit card distribution information of the merchant. Determine the percentage of counterfeit card spending for each counterfeit card under the aforementioned merchant; Based on the statistical information, construct the dimensional vectors of the merchants under different dimensions, including: The distribution information of counterfeit cards of merchants, the proportion of counterfeit card consumption of merchants, and whether a merchant has multiple accounts on one device are determined as the dimension vectors of the merchants in different dimensions.

8. A computing device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the program, it implements the steps of the method according to any one of claims 1 to 7.

9. A computer-readable storage medium, characterized in that, It stores a computer program executable by a computer device, which, when run on the computer device, causes the computer device to perform the steps of any one of claims 1 to 7.

Citation Information

Patent Citations

  • Merchant fraud risk monitoring system and data mining method

    CN111612606A

  • Methods and systems for generating rules for unseen fraud and credit risks using artificial intelligence

    US20210374756A1