A method for generating a transaction event, a related device, equipment and a storage medium

By reporting event information through clue submission channels and conducting background evaluations, suspicious transaction events are generated, which solves the problem of the lag in identification of existing transaction monitoring models and enables more timely discovery and effective early warning of suspicious transaction events.

CN115482099BActive Publication Date: 2026-04-07TENPAY PAID TECH
View PDF 3 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-05-31
Publication Date
2026-04-07

AI Technical Summary

Technical Problem

Existing transaction monitoring models are unable to identify suspicious transaction events in a timely manner, resulting in a significant lag in the determination of suspicious transaction events.

Method used

Event information is reported through the tip-off channels. The backend assesses the authenticity and importance of the event information and determines the value level of the tip based on the authenticity and importance of the event. If the conditions are met, a suspicious transaction event is generated.

Benefits of technology

This enables more timely detection of suspicious transactions and improves the effectiveness of early warnings and alerts.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115482099B_ABST
    Figure CN115482099B_ABST
Patent Text Reader

Abstract

This application discloses a method for generating transaction events, including: responding to an event reporting request, obtaining event information, which includes the name of the target object, a description of the target clue, and the type of the target event; determining the authenticity and importance of the clue based on the event information, where the authenticity of the clue indicates the credibility of the event information, and the importance of the event indicates the degree of correlation between the transaction event and sensitive content; determining the value level of the clue based on the authenticity and importance of the clue; and generating a target transaction event if the value level of the clue meets the event generation conditions. This application also discloses a device, equipment, and medium. In this application, users can report event information through clue submission channels, and the backend evaluates the event information. If the evaluation is successful, a suspicious transaction event is directly generated. Therefore, suspicious transaction events can be detected more promptly, thus achieving a better early warning and alert function.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of data processing, and in particular to a transaction event generation method, related device, equipment and storage medium. BACKGROUND

[0002] In the digital economy era, with the rapid development of cloud computing, artificial intelligence and blockchain technology, illegal transaction methods are constantly updated, and their concealment and destructiveness are constantly enhanced. The potential illegal transaction risks in the field of financial technology are worth attention. How to effectively curb illegal transactions and maintain financial security is a problem that relevant departments and industries are increasingly concerned about.

[0003] Currently, the generation of suspicious transaction events basically depends on the identification of transaction monitoring models. Specifically, first, data modeling is performed according to the characteristics of different illegal transactions, and multiple types of transaction monitoring models are established in the system. Then, the transaction monitoring model preliminarily screens out suspicious transaction events that hit the model rules. Finally, the suspicious transaction events are manually reviewed and reported by the review side.

[0004] However, since the method of identifying transaction characteristics by using a transaction monitoring model requires collecting a certain amount of transaction characteristics (for example, transaction characteristics within several months), it is difficult to discover suspicious transaction events in a timely manner, resulting in a large lag in determining suspicious transaction events. SUMMARY

[0005] The embodiments of the present application provide a transaction event generation method, related device, equipment and storage medium. Users can report event information through a clue delivery channel, and the background evaluates the event information. Therefore, suspicious transaction events can be discovered more timely, thereby achieving better early warning and prompting effects.

[0006] Therefore, the present application provides a transaction event generation method, comprising:

[0007] In response to an event reporting request, event information is obtained, wherein the event information includes a target object name, a target clue description text and a target event type;

[0008] The clue authenticity and the event importance are determined according to the event information, wherein the clue authenticity represents the credibility of the event information, and the event importance represents the association degree between the transaction event and the sensitive content;

[0009] The clue value level is determined according to the clue authenticity and the event importance;

[0010] If the clue value level meets the event generation condition, a target transaction event is generated, wherein the target transaction event includes the target object name, the target event type and the clue value level.

[0011] Another aspect of the present application provides a transaction event generation apparatus, comprising:

[0012] an acquisition module, configured to acquire event information in response to an event reporting request, wherein the event information comprises a target object name, a target clue description text and a target event type;

[0013] a determination module, configured to determine a clue authenticity and an event importance according to the event information, wherein the clue authenticity represents a credibility of the event information, and the event importance represents an association degree between the transaction event and sensitive content;

[0014] the determination module is further configured to determine a clue value level according to the clue authenticity and the event importance;

[0015] a generation module, configured to generate a target transaction event if the clue value level meets an event generation condition, wherein the target transaction event comprises the target object name, the target event type and the clue value level.

[0016] In a possible design, in another implementation of another aspect of the embodiment of the present application, the transaction event generation apparatus further comprises a processing module and an execution module;

[0017] the processing module is configured to perform word segmentation processing on the target clue description text to obtain M words, wherein M is an integer greater than or equal to 1;

[0018] the execution module is configured to perform the step of determining the clue authenticity and the event importance according to the event information if at least one word in the M words matches a word in a word library corresponding to the target event type successfully;

[0019] the determination module is specifically configured to determine the event importance according to the target clue description text and the target event type;

[0020] the clue authenticity is determined according to at least one of the target object name, the target event type and a target transaction amount, wherein the target transaction amount is derived from the event information, or the target transaction amount is determined according to a historical transaction amount.

[0021] In a possible design, in another implementation of another aspect of the embodiment of the present application,

[0022] the determination module is specifically configured to acquire a sensitive word matching relationship corresponding to the target event type, wherein the sensitive word matching relationship comprises K sensitive words and a rating score corresponding to each sensitive word, and K is an integer greater than or equal to 1;

[0023] determine N sensitive words from the target clue description text according to the K sensitive words included in the sensitive word matching relationship, where N is an integer greater than or equal to 1 and less than or equal to M;

[0024] determine the sensitive word coverage according to the proportion of the N sensitive words in the M words;

[0025] determine the average rating score corresponding to the N sensitive words according to the rating score corresponding to each sensitive word included in the sensitive word matching relationship;

[0026] determine the event importance according to the sensitive word coverage and the average rating score.

[0027] In a possible design, in another implementation manner of another aspect of the embodiment of the present application,

[0028] The determining module is further configured to obtain a historical sample data set, where the historical sample data set includes C groups of historical sample data, each group of historical sample data corresponds to a labeled score, a historical sensitive word coverage, and a historical average rating score, and C is an integer greater than 1;

[0029] generate a first data matrix according to the labeled score included in each group of historical sample data;

[0030] generate a second data matrix according to the historical sensitive word coverage and the historical average rating score included in each group of historical sample data;

[0031] determine a first coefficient and a second coefficient according to the first data matrix and the second data matrix;

[0032] The determining module is specifically configured to determine the event importance according to the sensitive word coverage, the first coefficient corresponding to the sensitive word coverage, the average rating score, and the second coefficient corresponding to the average rating score.

[0033] In a possible design, in another implementation manner of another aspect of the embodiment of the present application,

[0034] The determining module is specifically configured to obtain a historical event information set in a preset period, where the historical event information set includes at least one historical event information, and each historical event information includes an object name;

[0035] statistically determine a target occurrence frequency of the target object name according to the historical event information set;

[0036] determine a target frequency coefficient corresponding to the target occurrence frequency according to a mapping relationship between the object name occurrence frequency and the frequency coefficient, and take the target frequency coefficient as the clue authenticity.

[0037] In a possible design, in another implementation manner of another aspect of the embodiment of the present application,

[0038] The determining module is specifically configured to determine a target type coefficient corresponding to the target event type according to a mapping relationship between event types and type coefficients, and take the target type coefficient as the lead real degree.

[0039] In a possible design, in another implementation manner of another aspect of the embodiment of the present application,

[0040] The determining module is specifically configured to determine a target amount coefficient corresponding to the target transaction amount according to a mapping relationship between transaction amounts and amount coefficients, and take the target amount coefficient as the lead real degree.

[0041] In a possible design, in another implementation manner of another aspect of the embodiment of the present application,

[0042] The determining module is specifically configured to obtain a historical event information set in a preset period, wherein the historical event information set includes at least one historical event information, and each historical event information includes an object name.

[0043] According to the historical event information set, a target occurrence frequency of the target object name is counted.

[0044] According to a mapping relationship between the object name occurrence frequency and a frequency coefficient, a target frequency coefficient corresponding to the target occurrence frequency is determined.

[0045] According to a mapping relationship between event types and type coefficients, a target type coefficient corresponding to the target event type is determined.

[0046] According to a mapping relationship between transaction amounts and amount coefficients, a target amount coefficient corresponding to the target transaction amount is determined.

[0047] According to the target frequency coefficient, the target type coefficient and the target amount coefficient, a lead real degree is determined.

[0048] In a possible design, in another implementation manner of another aspect of the embodiment of the present application,

[0049] The determining module is specifically configured to determine a target lead real degree according to a product of the lead real degree and a first weight value.

[0050] According to a product of the event importance degree and a second weight value, a target event importance degree is determined.

[0051] According to the target lead real degree and the target event importance degree, a lead value level is determined.

[0052] In one possible design, in another implementation of another aspect of the embodiments of this application,

[0053] The acquisition module is specifically used to receive event reporting requests sent by the first terminal device and acquire event information. The first terminal device is used to provide a clue delivery interface, which displays an object name input area, a clue description input area, and an event type input area.

[0054] In one possible design, in another implementation of another aspect of the embodiments of this application, the transaction event generation device further includes a sending module;

[0055] The sending module is used to send the target transaction event to the second terminal device, wherein the second terminal device is used to provide an event generation interface, which displays at least one transaction event, and the at least one transaction event includes the target transaction event.

[0056] In one possible design, in another implementation of another aspect of the embodiments of this application, the transaction event generation device further includes a receiving module;

[0057] The receiving module is used to receive an event filtering request sent by the second terminal device, wherein the event filtering request carries at least one of the following: the type of object to be filtered, the type of event to be filtered, the value level of the clue to be filtered, and the time event to be filtered.

[0058] The sending module is also used to send the event filtering result to the second terminal device according to the event filtering request, so that the second terminal device can display the event filtering result.

[0059] This application also provides a computer device, including: a memory, a processor, and a bus system;

[0060] The memory is used to store programs;

[0061] The processor is used to execute programs in memory, and the processor is used to execute the methods mentioned above according to the instructions in the program code;

[0062] Bus systems are used to connect memory and processor to enable communication between them.

[0063] Another aspect of this application provides a computer-readable storage medium storing instructions that, when executed on a computer, cause the computer to perform the methods described above.

[0064] Another aspect of this application provides a computer program product or computer program including computer instructions stored in a computer-readable storage medium. A processor of a computer device reads the computer instructions from the computer-readable storage medium and executes the computer instructions, causing the computer device to perform the methods provided in the above aspects.

[0065] As can be seen from the above technical solutions, the embodiments of this application have the following advantages:

[0066] This application provides a method for generating transaction events. First, in response to an event reporting request, event information is obtained. This information includes the target object name, a description of the target clue, and the target event type. Based on this information, the authenticity and importance of the clue are determined. Then, the value level of the clue is determined based on these factors. If the value level is greater than or equal to a threshold, a target transaction event is generated; this target transaction event is a suspicious transaction event. Through this method, after opening a clue submission channel, users can report event information through this channel, which is then evaluated by the backend. If the evaluation passes, a suspicious transaction event is directly generated. Therefore, suspicious transaction events can be detected more promptly, resulting in better early warning and alerting capabilities. Attached Figure Description

[0067] Figure 1 This is a schematic diagram of an environment for the transaction event generation system in this application embodiment;

[0068] Figure 2 This is a schematic diagram of a process for pushing suspicious transaction events in an embodiment of this application;

[0069] Figure 3 This is a schematic diagram of one embodiment of the transaction event generation method in this application;

[0070] Figure 4 This is a flowchart illustrating natural language processing in an embodiment of this application;

[0071] Figure 5 This is a schematic diagram of the clue delivery interface in an embodiment of this application;

[0072] Figure 6 This is a schematic diagram of the event generation interface in an embodiment of this application;

[0073] Figure 7 This is a schematic diagram of the event filtering interface in an embodiment of this application;

[0074] Figure 8 This is a schematic diagram of a transaction event generation device in an embodiment of this application;

[0075] Figure 9 This is a schematic diagram of the server structure in an embodiment of this application;

[0076] Figure 10 This is a schematic diagram of the structure of a terminal device in an embodiment of this application. Detailed Implementation

[0077] This application provides a method for generating transaction events, related devices, equipment, and storage media. Users can report event information through clue submission channels, and the background will evaluate the event information. Therefore, suspicious transaction events can be detected more promptly, thereby achieving a better early warning and alert function.

[0078] The terms “first,” “second,” “third,” “fourth,” etc. (if present) in the specification, claims, and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a particular order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of this application described herein can be implemented, for example, in orders other than those illustrated or described herein. Furthermore, the terms “comprising” and “corresponding to,” and any variations thereof, are intended to cover a non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.

[0079] The emergence of new businesses and new business models has led to increasingly complex methods and types of illegal transactions. Combating illegal transactions faces severe challenges due to the numerous scenarios, wide scope, and scattered distribution of these activities. Illegal transactions include the act of concealing the source and nature of illegal proceeds and their profits through various means, making them appear legitimate. Illegal transactions undoubtedly harm the interests of the public. Therefore, to more efficiently and accurately identify suspicious transaction events, this application provides a method for generating transaction events. This method involves constructing a search and placement platform, opening up tip-off channels to individual users and company employees, and using a data platform to aggregate and filter reported tips. High-value tips from individual users and company employees are then generated as suspicious transaction events. Professional staff conduct focused analysis of these suspicious transaction events, identifying those deemed to pose a risk of illegal transactions and reporting them according to the type of illegality involved, thereby achieving the goal of "universal reporting."

[0080] Based on this, this application proposes a method for generating transaction events, which is applied to... Figure 1 Please refer to the transaction event generation system shown.Figure 1 , Figure 1 This is a schematic diagram of an environment for the transaction event generation system in this application embodiment. As shown in the figure, the transaction event generation system includes a server and terminal devices, with the client deployed on the terminal devices. The client can run on the terminal devices via a browser or as a standalone application (APP). The specific form of the client is not limited here. The server involved in this application can be an independent physical server, a server cluster composed of multiple physical servers, or a distributed system. It can also be a cloud server providing basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, content delivery networks (CDNs), and big data and artificial intelligence platforms. The terminal devices can be smartphones, tablets, laptops, PDAs, personal computers, smart TVs, smartwatches, in-vehicle devices, wearable devices, etc., but are not limited to these. The terminal devices and the server can be directly or indirectly connected via wired or wireless communication, which is not limited here. The number of servers and terminal devices is also not limited.

[0081] For example, the terminal devices include a first terminal device and a second terminal device. The first terminal device provides a tip-off reporting platform, through which users input event information and submit it to the server. The server analyzes the event information to determine the tip value level. If the tip value level is greater than or equal to a threshold, a suspicious transaction event is generated. The server then pushes this suspicious transaction event to the second terminal device, which provides a platform for displaying suspicious transaction events. Professional staff can view these events on the platform, and further, the suspicious transaction event can be pushed to relevant departments for appropriate handling.

[0082] based on Figure 1 The transaction event generation system shown below will be combined with... Figure 2 For a description of the process of pushing suspicious transaction events, please refer to [link / reference]. Figure 2 , Figure 2 This is a flowchart illustrating the process of pushing suspicious transaction events in an embodiment of this application, as shown in the figure. Specifically:

[0083] In step S1, the user triggers an event reporting request to report event information, that is, to provide evidence of suspicious illegal transaction content.

[0084] In step S2, after the user reports the event information, the transaction event generation system will perform a preliminary judgment on the submitted event information, that is, determine whether the event information reported by the user passes the preliminary screening. If the content of the event information is complete, then step S3 is executed. If the content of the event information is incomplete, then step S1 is executed, that is, the incomplete event information is returned to the user. The user can choose to continue to supplement and improve the event information. After completion, the user can choose to resubmit the event information or directly abandon the submission of the event information.

[0085] In step S3, if the event information is complete, Natural Language Processing (NLP) technology within Artificial Intelligence (AI) is used to preprocess the target clue description text in the event information. The target clue description text is then matched against the target event type entered by the user. If a match is found, step S4 is executed. Conversely, if a match fails, step S1 is executed, which returns the mismatched event information to the user. The user can choose to verify and correct the event information. After completion, the user can choose to resubmit the event information or simply discard the submission.

[0086] In step S4, after filtering out noise in the target clue description text, the target clue description text is confirmed to be valuable information. Based on this, the clue value level of the event is determined according to indicators such as the frequency of clues being placed for the same object, the degree of illegality, and the transaction scale.

[0087] In step S5, if the clue value level is greater than or equal to the level threshold, a target transaction event is generated, which is a suspicious transaction event.

[0088] In step S6, the target transaction event is pushed to the anti-illegal transaction review department for review and reporting.

[0089] Based on the above introduction, the method for generating transaction events in this application will be described below. Please refer to [link / reference]. Figure 3 One embodiment of the transaction event generation method in this application includes:

[0090] 101. In response to an event reporting request, obtain event information, including the target object name, target clue description text, and target event type;

[0091] In one or more embodiments, the transaction event generation device responds to an event reporting request triggered by a user, thereby obtaining event information reported by the user. The event information includes at least the target object name, a target clue description text, and a target event type. The target object name represents the name of the entity suspected of illegal transactions, such as "Zhang San" (for individuals) or "XXX Co., Ltd." (for organizations). The target clue description text represents the user's description of the suspected illegal transaction clue, such as "XXX Co., Ltd. is conducting a large-scale virtual currency exchange activity at XXX Entertainment City." The target event type represents the relevant type of the suspected illegal transaction, such as "illegal business operation" or "telecom fraud," etc.

[0092] It should be noted that the transaction event generation device can be deployed on a server, on a terminal device, or in a system consisting of a server and a terminal device; this application does not impose any limitations on this.

[0093] For example, a user triggers an event reporting request through a first terminal device. The first terminal device then sends the event reporting request to the server, which retrieves the event information corresponding to the request. Based on this, the server filters, selects, and evaluates the event information, and then sends the suspicious transaction event to a second terminal device, which displays the suspicious transaction event. It is understood that the second terminal device and the first terminal device can be the same device, or they can be two different devices. The first terminal device provides the lead submission interface, while the second terminal device provides the event generation interface.

[0094] For example, a user triggers an event reporting request through a first terminal device, thereby directly obtaining the event information input by the user. Based on this, the first terminal device filters, selects, and evaluates the event information, generating a suspicious transaction event, which is then displayed by the first terminal device. It can be understood that the first terminal device is used to provide a lead submission interface, through which the event reporting request is triggered. The first terminal device is also used to provide an event generation interface, through which the suspicious transaction event is displayed.

[0095] It is important to emphasize that users (i.e., the public) report event information through the tip submission interface, while professional staff view suspicious transaction events through the event generation interface. The two types of interfaces are for different audiences.

[0096] 102. Determine the authenticity of clues and the importance of events based on event information. The authenticity of clues indicates the credibility of event information, and the importance of events indicates the degree of relevance between the transaction event and sensitive content.

[0097] In one or more embodiments, the transaction event generation device calculates the authenticity of the clues and the importance of the event based on the event information reported by the user. Specifically, in the process of evaluating the value of an event, this application can use a combination of qualitative and quantitative analysis. The authenticity of the clues is obtained after qualitative analysis, and the importance of the event is obtained after quantitative analysis. That is to say, the authenticity of the clues represents the credibility of the event information, and the importance of the event represents the degree of correlation between the transaction event and sensitive content.

[0098] Understandably, sensitive content indicates information that may involve illegal transactions, including but not limited to terms like "ranking up," "bookmakers," and "casinos."

[0099] 103. Determine the value level of clues based on their authenticity and the importance of the event;

[0100] In one or more embodiments, the transaction event generation device calculates the value level of a clue based on its authenticity and the importance of the event. For example, a clue can be calculated in the following manner:

[0101] Z = A * I;

[0102] Here, Z represents the value of the clue, A represents the authenticity of the clue, and I represents the importance of the event. Therefore, the value of a clue is positively correlated with its authenticity, and also positively correlated with its importance. Furthermore, the corresponding clue value level can be determined based on the clue value.

[0103] In one implementation, the greater the value of a clue, the higher its corresponding clue value level, meaning the greater the value of the event information reported by the user. For example, if the clue value level is 5, it means the event information reported by the user has high potential for further investigation, while if the clue value level is 1, it means the event information reported by the user has no potential for further investigation.

[0104] In another implementation, the greater the value of a clue, the lower its corresponding clue value level, meaning the more valuable the event information reported by the user. For example, a clue value level of 1 indicates that the event information reported by the user has high potential for further investigation, while a clue value level of 5 indicates that the event information reported by the user has no potential for further investigation.

[0105] 104. If the value level of the clue meets the event generation conditions, a target transaction event is generated. The target transaction event includes the name of the target object, the type of the target event, and the value level of the clue.

[0106] In one or more embodiments, if the value level of a clue meets the conditions for generating a suspicious event, the event information is considered to have the value of being pushed. Based on this, the transaction event generation device generates a target transaction event according to the event information, wherein the target transaction event is a suspicious transaction event.

[0107] In one implementation, it is assumed that the value level of a clue is divided into 5 levels, where level 1 is the highest level and level 5 is the lowest level. Based on this, clues with a value level less than or equal to a level threshold are considered to have high value. For example, the level threshold can be level 4.

[0108] In another implementation, it is assumed that the value level of a clue is divided into 5 levels, where level 5 is the highest level and level 1 is the lowest level. Based on this, a clue is considered to have high value if its value level is greater than or equal to a level threshold, for example, level 1.

[0109] Therefore, the conditions for generating suspicious events are related to the method of classifying the value level of clues. Specifically, after a target transaction event is generated, it can be pushed to professional staff. Thus, a target transaction event must at least include the name of the target object, the type of the target event, and the value level of the clue. Based on the value level of the clue, professional staff can then further choose whether to push the target transaction event to the relevant review department for further review and processing.

[0110] This application provides a method for generating transaction events. Through this method, after opening a lead submission channel, users can report event information through the channel, which is then evaluated by the backend. If the evaluation passes, a suspicious transaction event is directly generated. Therefore, suspicious transaction events can be detected more promptly, thus achieving a better early warning and alerting effect.

[0111] Optionally, in the above Figure 3 In addition to one or more corresponding embodiments, another optional embodiment provided in this application may further include:

[0112] The target clue description text is segmented into M words, where M is an integer greater than or equal to 1;

[0113] If at least one of the M words matches a word in the vocabulary corresponding to the target event type, then proceed with the steps of determining the authenticity of the clues and the importance of the event based on the event information.

[0114] Determining the authenticity of clues and the importance of the event based on event information can specifically include:

[0115] Determine the importance of an event based on the target clue description text and the target event type;

[0116] The authenticity of a lead is determined based on at least one of the following: the name of the target object, the type of the target event, and the target transaction amount, wherein the target transaction amount is derived from event information or is determined based on historical transaction amounts.

[0117] In one or more embodiments, a method for determining the authenticity of clues and the importance of events by combining event information is described. After obtaining event information, the transaction event generation device needs to filter the event information. That is, if the target clue description text included in the event information does not match the thesaurus corresponding to the target event type, the event information reported by the user is considered not worth further testing, and therefore, the event information can be directly filtered.

[0118] The following will combine Figure 4 This describes the preprocessing methods used for the target cue description text. For better understanding, please refer to [link to relevant documentation]. Figure 4 , Figure 4 This is a flowchart illustrating a natural language processing implementation in an embodiment of this application, as shown in the figure. Specifically:

[0119] In step A1, the original text is obtained, which is the target clue description text.

[0120] In step A2, the target clue description text is segmented. Taking Chinese segmentation as an example, a segmentation method based on string matching (e.g., forward maximum matching, backward maximum matching, minimum segmentation, or bidirectional maximum matching) can be used, or a segmentation method based on statistics (e.g., N-gram model, Hidden Markov model, maximum entropy model, or Conditional Random Field model) can be used, or a segmentation method based on understanding (e.g., Jieba segmentation).

[0121] In step A3, the segmented results are cleaned, that is, useless information, special text, and stop words are removed.

[0122] In step A4, after cleaning, M words are obtained and then standardized, which involves stemming and part-of-speech tagging.

[0123] In step A5, feature extraction is performed on each word to obtain the word vector for each word.

[0124] Combined with the above process, in one implementation, the corresponding lexicon can be obtained according to the target event type first. The lexicon includes at least one sensitive word. Based on this, each of the M words is directly compared with each sensitive word in the lexicon. Suppose there is a sensitive word "score points" in the lexicon, and one of the M words is also "score points", which means the match is successful. Therefore, the event information can be further analyzed.

[0125] Combined with the above process, in another implementation, the corresponding lexicon can be obtained according to the target event type first. The lexicon includes at least one sensitive word. Based on this, the similarity between the word vectors of each of the M words and the word vectors of each sensitive word in the lexicon is calculated. If the similarity is greater than or equal to the similarity threshold, it means the match is successful. Therefore, the event information can be further analyzed.

[0126] After the trading event generation device determines to continue analyzing the event information, it is necessary to determine the event importance according to the target clue description text and the target event type, and determine the clue authenticity according to at least one of the target object name, the target event type, and the target transaction amount. Then, the trading event generation device calculates the clue value level according to the event importance and the clue authenticity.

[0127] Secondly, in the embodiments of the present application, a method for determining the clue authenticity and the event importance in combination with the event information is provided. Through the above method, it is necessary to first conduct a preliminary test on the target clue description text reported by the user to filter out the event information irrelevant to the suspicious transaction. On the one hand, this can effectively reduce the interference of the noise information on the subsequent detection. On the other hand, there is no need to further detect the noise information, thereby improving the detection efficiency.

[0128] Optionally, based on one or more corresponding Figure 3 embodiments above, in another optional embodiment provided by the embodiments of the present application, determining the event importance according to the target clue description text and the target event type may specifically include:

[0129] Obtain the sensitive word matching relationship corresponding to the target event type, where the sensitive word matching relationship includes K sensitive words and the rating score corresponding to each sensitive word, and K is an integer greater than or equal to 1;

[0130] Determine N sensitive words from the target clue description text according to the K sensitive words included in the sensitive word matching relationship, where N is an integer greater than or equal to 1 and less than or equal to M;

[0131] Determine the sensitive word coverage rate according to the proportion of the N sensitive words in the M words;

[0132] Based on the rating score corresponding to each sensitive word included in the sensitive word matching relationship, determine the average rating score corresponding to N sensitive words;

[0133] The importance of an event is determined based on the coverage rate of sensitive words and the average rating score.

[0134] In one or more embodiments, a method for determining event importance based on target cue description text is described. As can be seen from the foregoing embodiments, event importance is the result of "quantitative analysis," and the higher the event importance, the deeper the connection between the event information and sensitive content.

[0135] Specifically, firstly, the transaction event generation device determines the corresponding sensitive word matching relationship based on the target event type included in the event information. Different event types often correspond to different sensitive word matching relationships. For example, the target event type is "telecom fraud." For easier understanding, please refer to Table 1, which illustrates the sensitive word matching relationship corresponding to the target event type.

[0136] Table 1

[0137]

[0138] Table 1 shows that the sensitive word matching relationship corresponding to this target event type includes 9 sensitive words (i.e., K is 9) and the rating score corresponding to each sensitive word. Based on this, after segmenting the target clue description text, the resulting M words are matched against the sensitive words included in the sensitive word matching relationship. Assuming that N words (N less than or equal to M) in the target clue description text match the sensitive words in the sensitive word matching relationship corresponding to the target event type, the sensitive word coverage rate is calculated as follows:

[0139] Q = N / M;

[0140] Where Q represents the sensitive word coverage rate, N represents the number of words in the target clue description text that successfully match the sensitive words, and M represents the total number of words in the target clue description text after word segmentation.

[0141] At the same time, based on the matching relationships of sensitive words, the rating score corresponding to each sensitive word can be determined. These rating scores are usually set based on empirical values. Based on this, the average rating score can be calculated as follows:

[0142] W=S / N;

[0143] Where W represents the average rating score, S represents the sum of the rating scores corresponding to the N words, and N represents the number of words in the target clue description text that successfully match the sensitive words. For example, assuming that the N words in the target clue description text that successfully match the sensitive words are "transfer", "download", and "receive payment", then the sum of the rating scores corresponding to the N words is 6 (i.e., 3+2+1).

[0144] Based on the coverage rate of sensitive words and the average rating score, the importance of an event can be calculated in the following way:

[0145] I = Q + W;

[0146] Where I represents the importance of the event, Q represents the coverage of sensitive words, and W represents the average rating score.

[0147] Furthermore, this application provides a method for determining the importance of an event based on the target clue description text. This method, combined with a pre-constructed sensitive word matching relationship (including sensitive words and their corresponding rating scores), determines the sensitive word coverage rate and average rating score based on the number of sensitive words the target clue description text contains. These rates are then used as standards for evaluating the authenticity of the clue. This approach considers the potential amount of sensitive content in the user-reported target clue description text and, combined with the preset rating scores, measures the depth of the sensitive content involved. In other words, it evaluates the correlation between the target clue description text and sensitive content from different dimensions, thereby improving the reliability of the event's importance.

[0148] Optionally, in the above Figure 3 In addition to one or more corresponding embodiments, another optional embodiment provided in this application may further include:

[0149] Obtain a set of historical sample data, which includes C sets of historical sample data. Each set of historical sample data corresponds to a label score, historical sensitive word coverage rate, and historical average rating score, where C is an integer greater than 1.

[0150] The first data matrix is ​​generated based on the labeled scores included in each group of historical sample data;

[0151] A second data matrix is ​​generated based on the historical sensitive word coverage and historical rating average score of each set of historical sample data;

[0152] Based on the first data matrix and the second data matrix, determine the first coefficient and the second coefficient;

[0153] The importance of an event is determined based on the coverage rate of sensitive words and the average rating score, which may include:

[0154] The importance of an event is determined based on the sensitive word coverage rate, the first coefficient corresponding to the sensitive word coverage rate, the average rating score, and the second coefficient corresponding to the average rating score.

[0155] In one or more embodiments, a method for calculating event importance is described. As seen in the foregoing embodiments, event importance is related to the coverage rate of sensitive words and the average rating score. To increase credibility, a corresponding weight value, i.e., a first coefficient, can be set for the coverage rate of sensitive words, and a corresponding weight value, i.e., a second coefficient, can be set for the average rating score. The first and second coefficients can be set based on empirical values ​​or derived from historical sample datasets. The following will explain how to derive the first and second coefficients using historical sample datasets.

[0156] Specifically, the importance of an event is calculated as follows:

[0157] I = Q*a1 + W*a2;

[0158] Where I represents the importance of the event, Q represents the coverage of sensitive words, a1 represents the first coefficient, W represents the average rating score, and a2 represents the second coefficient.

[0159] The sensitive word coverage rate is calculated as follows:

[0160] Q = N / M;

[0161] The average rating score is calculated as follows:

[0162] W=S / N;

[0163] Combining the above formulas, the method for calculating the importance of an event is as follows:

[0164] ;

[0165] in, Indicates the importance of an event. This indicates the number of words in the target clue description text that successfully match the sensitive words. This represents the total number of words in the target cue description text after word segmentation. Indicates the first coefficient. This represents the sum of the rating scores corresponding to N words. This indicates the second coefficient.

[0166] Based on this, we first obtain a historical sample data set, which consists of C groups of historical sample data. Each group of historical sample data corresponds to a labeled score obtained through manual review and evaluation. The labeled score can range from 1 to 100. Therefore, based on the labeled scores included in each group of historical sample data, we generate a first data matrix Y. The first data matrix Y can be represented as:

[0167] ;

[0168] Where Y represents the first data matrix, C represents the total number of historical sample data sets in the historical sample data set, and C is an integer greater than 1.

[0169] By combining the historical sensitive word coverage and historical average rating scores of each set of historical sample data, a second data matrix X is generated. The second data matrix X can be represented as:

[0170] ;

[0171] Where X represents the second data matrix, This represents the coverage rate of historical sensitive words in the first set of historical sample data. This represents the historical average rating score in the first set of historical sample data. This indicates the coverage rate of historical sensitive words in the second set of historical sample data. This represents the average historical rating score in the second group of historical sample data. Similarly, the second data matrix consists of the historical sensitive word coverage rate and the average historical rating score of group C.

[0172] Therefore, based on the first data matrix and the second data matrix, the following formula is obtained:

[0173] ;

[0174] in, Indicates the first coefficient. This represents the first coefficient. Let represent the matrix to be solved. The matrix to be solved can be represented as:

[0175] ;

[0176] in, Let Y represent the matrix to be solved, Y represent the first data matrix, and X represent the second data matrix. Based on this, the first coefficient is solved using multiple linear regression. Second coefficient The value of the first coefficient. Second coefficient Substituting these values ​​into the formula for calculating event importance yields the event importance score.

[0177] Furthermore, in this embodiment of the application, a method for calculating the importance of an event is provided. By using the above method, relevant data in the historical sample dataset is used to derive a reasonable first coefficient and a second coefficient. The event importance calculated by combining the first coefficient and the second coefficient has higher reliability.

[0178] Optionally, in the above Figure 3 Based on one or more corresponding embodiments, in another optional embodiment provided by this application, the authenticity of the clue is determined according to at least one of the target object name, target event type, and target transaction amount, which may specifically include:

[0179] Obtain a set of historical event information within a preset period, wherein the set of historical event information includes at least one historical event information, and each historical event information includes an object name;

[0180] Based on the historical event information set, count the frequency of target object names appearing in the target object name;

[0181] Based on the mapping relationship between the frequency of object name occurrence and the frequency coefficient, the target frequency coefficient corresponding to the target occurrence frequency is determined, and the target frequency coefficient is used as the authenticity of the clue.

[0182] In one or more embodiments, a method for determining the authenticity of clues based on the frequency of occurrence of target object names is described. As can be seen from the foregoing embodiments, the authenticity of clues is the result of "qualitative analysis," and the higher the authenticity of clues, the higher the credibility of the event information.

[0183] Specifically, the transaction event generation device first acquires a set of historical event information within a preset period. This preset period can be a specific time frame, such as within one year or six months, and is not limited here. The historical event information set includes at least one historical event, and all historical event information in the set is valid. Each historical event includes an object name. The frequency of occurrence of the target object name in the historical event information set is then calculated. For example, if the target object name is "XXX Co., Ltd.", and the historical event information set includes 200 historical event entries, with 4 entries containing the object name "XXX Co., Ltd.", the target frequency is 4.

[0184] Based on this, the target frequency coefficient corresponding to the target occurrence frequency can be determined according to the mapping relationship between the frequency of object name occurrence and the frequency coefficient. For ease of understanding, please refer to Table 2, which is an illustration of the mapping relationship between the frequency of object name occurrence and the frequency coefficient.

[0185] Table 2

[0186]

[0187] It should be noted that the mapping relationship between the frequency of object names and the frequency coefficient shown in Table 2 is only an illustration and should not be construed as a limitation of this application. For example, assuming the target appears 4 times, based on the mapping relationship shown in Table 2, the corresponding target frequency coefficient can be determined to be 0.625. Therefore, the target frequency coefficient can be used as the clue authenticity, that is, the clue authenticity is 0.625.

[0188] Understandably, organizations can adjust the mapping relationship between the frequency of occurrence of the same object name and the frequency coefficient according to their own business situation. For example, if object A is reported, the frequency coefficient corresponding to the frequency of occurrence of object A can be increased in the following period.

[0189] Optionally, in the process of counting the frequency of occurrence of the target object name, the target event type can also be considered, and historical event information consistent with the target event type can be filtered from the historical event information set. Then, the number of times the target object name appears in this part of the historical event information is determined, thus obtaining the target occurrence frequency.

[0190] Furthermore, in this embodiment of the application, a method for determining the authenticity of clues based on the frequency of occurrence of the target object name is provided. By combining the above method with the mapping relationship between the frequency of occurrence of the object name and the frequency coefficient, the target frequency coefficient corresponding to the frequency of occurrence of the target can be determined. Based on this, the target frequency coefficient is used as the authenticity of the clue. Thus, the influence of the frequency of occurrence of the object name on the credibility of the event information can be better reflected, thereby improving the reliability of the authenticity of the clue.

[0191] Optionally, in the above Figure 3 Based on one or more corresponding embodiments, in another optional embodiment provided by this application, the authenticity of the clue is determined according to at least one of the target object name, target event type, and target transaction amount, which may specifically include:

[0192] Based on the mapping relationship between event type and type coefficient, the target type coefficient corresponding to the target event type is determined, and the target type coefficient is used as the clue authenticity.

[0193] In one or more embodiments, a method for determining the authenticity of clues based on the type of target event is described. As can be seen from the foregoing embodiments, the authenticity of a clue is the result of "qualitative analysis," and the higher the authenticity of a clue, the more credible the event information is.

[0194] Specifically, first, the transaction event generation device obtains the target event type from the event information, for example, the target event type is "telecom fraud". Based on this, the target type coefficient corresponding to the target event type can be determined according to the mapping relationship between event types and type coefficients. For ease of understanding, please refer to Table 3, which is a schematic diagram of the mapping relationship between event types and type coefficients.

[0195] Table 3

[0196]

[0197] It should be noted that the mapping relationship between event types and type coefficients shown in Table 3 is merely illustrative and should not be construed as a limitation of this application. For example, assuming the target event type is "telecom fraud," based on the mapping relationship shown in Table 3, the corresponding target type coefficient can be determined to be 3. Therefore, the target type coefficient can be used as the authenticity of the clue, i.e., the authenticity of the clue is 3.

[0198] It is understandable that the mapping relationship between event type and type coefficient is relatively fixed. The type coefficient values ​​shown in Table 3 are 1, 2 or 3. In practical applications, other type coefficient value ranges can also be set, which are not limited here.

[0199] Furthermore, in this embodiment of the application, a method for determining the authenticity of clues based on target event types is provided. By combining the mapping relationship between event types and type coefficients, the target type coefficient corresponding to the target event type can be determined. Based on this, the target type coefficient is used as the authenticity of the clues. Thus, the influence of event types on the credibility of event information can be better reflected, thereby improving the reliability of the authenticity of clues.

[0200] Optionally, in the above Figure 3 Based on one or more corresponding embodiments, in another optional embodiment provided by this application, the authenticity of the clue is determined according to at least one of the target object name, target event type, and target transaction amount, which may specifically include:

[0201] Based on the mapping relationship between transaction amount and amount coefficient, the target amount coefficient corresponding to the target transaction amount is determined, and the target amount coefficient is used as the authenticity of the clue.

[0202] In one or more embodiments, a method for determining the authenticity of a lead based on the target transaction amount is described. As can be seen from the foregoing embodiments, the authenticity of a lead is the result of "qualitative analysis," and the higher the authenticity of a lead, the more credible the event information.

[0203] Specifically, first, the transaction event generation device obtains the target transaction amount, for example, "800,000 yuan". In one case, the user can directly report the target transaction amount, i.e., the event information carries the user-inputted target transaction amount. In another case, the device obtains the corresponding historical transaction amount based on the target object name, then calculates the average of the historical transaction amounts, and uses this average as the target transaction amount. Based on this, the mapping relationship between the tradable amount and the amount coefficient is established to determine the target amount coefficient corresponding to the target transaction amount. For easier understanding, please refer to Table 4, which illustrates the mapping relationship between transaction amount and amount coefficient.

[0204] Table 4

[0205]

[0206] It should be noted that the mapping relationship between transaction amount and amount coefficient shown in Table 4 is only illustrative and should not be construed as a limitation of this application. For example, assuming the target transaction amount is "800,000 yuan", based on the mapping relationship shown in Table 4, the corresponding target amount coefficient can be determined to be 2. Therefore, the target amount coefficient can be used as the authenticity of the clue, that is, the authenticity of the clue is 2.

[0207] It is understandable that the mapping relationship between transaction amount and amount coefficient is relatively fixed. The amount coefficient values ​​shown in Table 4 are 1, 1.5, 2, 2.5 and 3. In practical applications, other types of coefficient value ranges can also be set, which are not limited here.

[0208] Furthermore, in this embodiment of the application, a method for determining the authenticity of clues based on the target transaction amount is provided. By combining the above method with the mapping relationship between the transaction amount and the amount coefficient, the target amount coefficient corresponding to the target transaction amount can be determined. Based on this, the target amount coefficient is used as the authenticity of the clue. Thus, the influence of the amount coefficient on the credibility of the event information can be better reflected, thereby improving the reliability of the authenticity of the clue.

[0209] Optionally, in the above Figure 3 Based on one or more corresponding embodiments, in another optional embodiment provided by this application, the authenticity of the clue is determined according to at least one of the target object name, target event type, and target transaction amount, which may specifically include:

[0210] Obtain a set of historical event information within a preset period, wherein the set of historical event information includes at least one historical event information, and each historical event information includes an object name;

[0211] Based on the historical event information set, count the frequency of target object names appearing in the target object name;

[0212] Based on the mapping relationship between the frequency of object name occurrence and the frequency coefficient, determine the target frequency coefficient corresponding to the target occurrence frequency;

[0213] Based on the mapping relationship between event type and type coefficient, determine the target type coefficient corresponding to the target event type;

[0214] Based on the mapping relationship between transaction amount and amount coefficient, determine the target amount coefficient corresponding to the target transaction amount;

[0215] The authenticity of clues is determined based on the target frequency coefficient, target type coefficient, and target amount coefficient.

[0216] In one or more embodiments, a method is described to determine the authenticity of clues based on the frequency of occurrence of the target object name, the type of the target event, and the amount of the target transaction.

[0217] Specifically, as described in the foregoing embodiments, the transaction event generation device acquires a set of historical event information within a preset period, and then counts the number of times the target object name appears in the historical event information set, thus obtaining the target occurrence frequency. Combined with the mapping relationship between object name occurrence frequency and frequency coefficient shown in Table 2, the target frequency coefficient is obtained. The transaction event generation device obtains the target event type from the event information. Based on this, it can determine the target type coefficient corresponding to the target event type according to the mapping relationship between event type and type coefficient. The transaction event generation device also needs to acquire the target transaction amount. Based on this, it can determine the target amount coefficient corresponding to the target transaction amount by using the mapping relationship between transaction amount and amount coefficient.

[0218] Finally, based on the target frequency coefficient, target type coefficient, and target amount coefficient, the authenticity of the clues can be calculated as follows:

[0219] A = k * t * p;

[0220] Where A represents the authenticity of the lead, k represents the target frequency coefficient, t represents the target type coefficient, and p represents the target amount coefficient. Taking the coefficients shown in Tables 2, 3, and 4 as examples, the value range of the lead authenticity is 0.5 to 9. It is understood that the range of the lead authenticity value can also vary depending on the coefficients; this is merely an illustration and should not be construed as a limitation of this application. The lead authenticity is positively correlated with the target frequency coefficient, target type coefficient, and target amount coefficient.

[0221] Furthermore, this application provides a method for determining the authenticity of clues based on the target occurrence frequency of the target object name, the target event type, and the target transaction amount. By combining the mapping relationship between the object name occurrence frequency and the frequency coefficient, the target frequency coefficient corresponding to the target occurrence frequency can be determined; by combining the mapping relationship between the event type and the type coefficient, the target type coefficient corresponding to the target event type can be determined; and by combining the mapping relationship between the transaction amount and the amount coefficient, the target amount coefficient corresponding to the target transaction amount can be determined. Therefore, the target frequency coefficient, the target type coefficient, and the target amount coefficient jointly serve as the basis for influencing the authenticity of clues. This better reflects the impact of different dimensional features on determining the credibility of event information, thereby improving the reliability of clue authenticity.

[0222] Optionally, in the above Figure 3 Based on one or more corresponding embodiments, in another optional embodiment provided by this application, the value level of a clue is determined according to the authenticity of the clue and the importance of the event, which may specifically include:

[0223] The authenticity of the target clue is determined by multiplying the authenticity of the clue by the first weight value.

[0224] The importance of the target event is determined by multiplying the event importance by the second weight value;

[0225] The value level of clues is determined based on their authenticity and the importance of the target event.

[0226] In one or more embodiments, a method for determining the value level of a clue based on the authenticity of the target clue and the importance of the target event is described. As can be seen from the foregoing embodiments, after obtaining the authenticity of the clue and the importance of the event, the authenticity of the target clue and the importance of the target event can be further calculated according to their assigned weight values.

[0227] Specifically, the transaction event generation device can calculate the value of a lead in the following way:

[0228] Z = α*A + β*I;

[0229] Where Z represents the clue value, A represents the clue authenticity, I represents the event importance, α represents the first weight value, β represents the second weight value, α*A represents the target clue authenticity, and β*I represents the target event importance. Based on this, the clue value level is positively correlated with the target clue authenticity, and the clue value level is also positively correlated with the target event importance. For example, if α is greater than β (e.g., α=0.7, β=0.3), it indicates a greater focus on the influence of clue authenticity. Similarly, if β is greater than α (e.g., β=0.7, α=0.3), it indicates a greater focus on the influence of event importance.

[0230] Therefore, the transaction event generation device can further determine the corresponding clue value level based on the clue value. If the clue value is less than b0 (b0 is a constant), the event information is judged as "false event information," meaning the target clue description text is invalid. If the clue value is greater than or equal to b0, the event information is judged as "true event information," meaning the target clue description text is valid. Based on this, the clue value level can be determined according to the specific value of the clue.

[0231] In one implementation, the greater the value of a clue, the higher its corresponding clue value level, meaning the greater the value of the event information reported by the user. For easier understanding, please refer to Table 5, which illustrates the mapping relationship between clue value and clue value level.

[0232] Table 5

[0233]

[0234] It should be noted that the mapping relationship between clue value and clue value level shown in Table 5 is only for illustration and should not be construed as a limitation of this application. If the clue value level is greater than or equal to the level threshold, a corresponding target transaction event (i.e., a suspicious transaction event) is generated. It is understood that the level threshold can be set to level 1, or it can be set according to the actual situation, and no limitation is made here.

[0235] In another implementation, the greater the value of a clue, the lower its corresponding clue value level, meaning the higher the value of the event information reported by the user. For easier understanding, please refer to Table 6, which provides another illustration of the mapping relationship between clue value and clue value level.

[0236] Table 6

[0237]

[0238] It should be noted that the mapping relationship between clue value and clue value level shown in Table 6 is only for illustration and should not be construed as a limitation of this application. If the clue value level is less than or equal to the level threshold, a corresponding target transaction event (i.e., a suspicious transaction event) is generated. It is understood that the level threshold can be set to level 4, or it can be set according to the actual situation, and no limitation is made here.

[0239] Secondly, this application provides a method for determining the value level of a clue based on the authenticity of the target clue and the importance of the target event. This method utilizes the authenticity of the target clue and its corresponding first weight value, as well as the importance of the target event and its corresponding second weight value, to calculate a clue value level, thereby improving the feasibility and operability of the solution. Furthermore, using both clue authenticity and event importance as criteria for evaluating the clue value level increases the rationality of the clue value level. For example, a clue with high authenticity may not involve a large transaction amount or high level of regulatory attention; or a clue with high event importance may lack sufficient supporting evidence to determine its authenticity. Therefore, a comprehensive evaluation combining clue authenticity and event importance is necessary.

[0240] Optionally, in the above Figure 3 Based on one or more corresponding embodiments, in another optional embodiment provided by this application, in response to an event reporting request, obtaining event information may specifically include:

[0241] The system receives an event reporting request sent by a first terminal device and obtains event information. The first terminal device is used to provide a clue delivery interface, which displays an object name input area, a clue description input area, and an event type input area.

[0242] In one or more embodiments, a method based on inputting time information through a lead submission interface is described. Taking a transaction event generation device deployed on a server as an example, after the transaction event generation device receives an event reporting request sent by a first terminal device, it can obtain event information based on the event reporting request. The first terminal device is a user-used terminal device; therefore, the first terminal device needs to develop a front-end interface, i.e., provide a lead submission interface, through which it receives event information reported by users. The transaction event generation device (i.e., the data platform) retrieves relevant information based on the data entered on the lead submission interface, aggregates it to form risk events, and after system detection and evaluation, filters out noise in the risk events to generate target transaction events. The review side then manually reviews and reports the target transaction events.

[0243] Specifically, for ease of understanding, please refer to Figure 5 , Figure 5This is a schematic diagram of the clue submission interface in an embodiment of this application. As shown in the figure, the clue submission interface provides multiple input areas. B1 indicates the object name input area, B2 indicates the clue description input area, B3 indicates the event type input area, and B4 indicates the "Submit" control. The user needs to enter the name of the target object suspected of illegal transaction in the object name input area indicated by B1, such as "Zhang San" or "Company A". Correspondingly, the user also needs to select the object type; for example, "Zhang San" belongs to the "Individual" type, and "Company A" belongs to the "Organization" type. The user needs to fill in the target clue description text suspected of illegal transaction in the clue description input area indicated by B2, such as "Zhang San repeatedly called to request a transfer". The user needs to select or enter the target event type suspected of illegal transaction in the event type input area indicated by B3.

[0244] In addition, users can fill in other relevant information. For example, a user can enter the identification number suspected of being involved in the illegal transaction in the "Identification Number" input area, such as an individual's ID card number or organization code. For example, a user can enter the mobile phone number suspected of being involved in the illegal transaction in the "Mobile Phone Number" input area. For example, a user can enter relevant information about the suspected illegal transaction in the "Other Information" input area, such as a company identification number. For example, a user can enter whether they have a transaction with the suspected illegal transaction party in the "Transaction Status" input area. For example, a user can enter the time of the transaction with the suspected illegal transaction party in the "Transaction Time" input area, such as "October 16, 2020, 16:46". For example, a user can enter the amount of the transaction with the suspected illegal transaction party in the "Transaction Amount" input area, such as "500,000". For example, a user can upload supporting evidence in the "Evidence Materials" input area, such as images, videos, audio, and files.

[0245] Finally, users can upload supporting materials based on their actual knowledge. After filling in the information, users can click the "Submit" control indicated by B4 to trigger an event reporting request.

[0246] It should be noted that, Figure 5The lead submission interface shown is for illustrative purposes only. In actual applications, each payment institution can adjust the lead submission interface according to its own payment business scenarios, product characteristics, and user preferences, adding new sub-items for lead collection. This allows for comprehensiveness, effectiveness, and relevance in lead collection, tailored to each institution's specific circumstances. For example, adding payment business scenarios, including but not limited to red envelopes, transfers, and QR code payments, allows users to select from all of the institution's business scenarios. Another example is adding product features, including but not limited to account nicknames, avatars, and signatures, allowing users to select from all of the institution's product features. Yet another example is adding the specific process of obtaining leads on illegal transactions. Finally, adding regions, including but not limited to national, provincial, municipal, and district levels, indicates the areas affected by illegal transactions.

[0247] Secondly, in this embodiment of the application, a method based on inputting time information on the clue delivery interface is provided. Through the above method, users can actively report event information that they consider suspicious. The reported event information includes the name of the target object, the description text of the target clue, and the type of the target event. As a result, the illegal transaction clues obtained are richer and more reliable, and the accuracy of the generated suspicious transaction events is higher. In addition, it is beneficial to cover a wider range of transaction types.

[0248] Optionally, in the above Figure 3 In addition to one or more corresponding embodiments, another optional embodiment provided in this application may further include:

[0249] Send the target transaction event to the second terminal device, wherein the second terminal device is used to provide an event generation interface, the event generation interface displays at least one transaction event, and the at least one transaction event includes the target transaction event.

[0250] In one or more embodiments, a method for displaying target transaction events based on an event generation interface is described. Taking a transaction event generation device deployed on a server as an example, after receiving an event reporting request from a first terminal device, the transaction event generation device can obtain event information based on the event reporting request. The first terminal device is a user-used terminal device that provides a lead submission interface. Therefore, event information reported by users is received through the lead submission interface. The transaction event generation device (i.e., the data platform) retrieves relevant information based on the data entered on the lead submission interface for detection and evaluation, filtering noise in risk events to generate target transaction events. Based on this, a second terminal device can request to display the target transaction events. The second terminal device is a terminal device used by professional personnel; therefore, after receiving the target transaction events, the second terminal device can display these target transaction events through the event generation interface.

[0251] Understandably, the event generation interface can also display other suspicious transaction events, not just the target transaction event. The following will combine... Figure 6 This describes at least one suspicious transaction event provided through the event generation interface, wherein the at least one suspicious transaction event may include the target transaction event.

[0252] Specifically, for ease of understanding, please refer to Figure 6 , Figure 6 This is a schematic diagram of an event generation interface in an embodiment of this application. As shown in the figure, the event generation interface provides multiple suspicious transaction events. C1 indicates a "One-Click Push" control; clicking the "One-Click Push" control will push all suspicious transaction events displayed on the event generation interface to the relevant department for review. C2 indicates an "Event Selection" control; clicking the "Event Selection" control will filter out some suspicious transaction events for viewing. C9 indicates a "Previous Page" control; clicking the "Previous Page" control will jump to the previous page. C10 indicates the current page, for example, page 2. C11 indicates a "Next Page" control; clicking the "Next Page" control will jump to the previous page.

[0253] Furthermore, C3 indicates the automatically generated event number, where each suspicious transaction event has a unique event number, such as "20210205XXX01". C4 indicates the entity name, such as "Zhang XX" or "Nanjing XX Co., Ltd." C5 indicates the entity type, such as "individual" or "organization". C6 indicates the event type, such as "illegal sales", "illegal operation", or "telecom fraud". C7 indicates the value level of the clue. C8 indicates the status, such as "pushed" or "pending", where "pushed" means it has been pushed to the relevant department for further review, and "pending" means it has not yet been pushed to the relevant department.

[0254] It should be noted that, Figure 6 The event generation interface shown is for illustrative purposes only and should not be construed as limiting this application.

[0255] Secondly, in this embodiment of the application, a method for displaying target transaction events based on an event generation interface is provided. Through the above method, after the target transaction event (i.e., suspicious transaction event) is generated, it can also be pushed to a second terminal device used by professional staff, thereby making it easier for professional staff to view the target transaction event (i.e. suspicious transaction event) and thus improving the flexibility and convenience of the solution.

[0256] Optionally, in the above Figure 3In addition to one or more corresponding embodiments, another optional embodiment provided in this application may further include:

[0257] Receive an event filtering request sent by a second terminal device, wherein the event filtering request carries at least one of the following: object type to be filtered, event type to be filtered, clue value level to be filtered, and time event to be filtered;

[0258] The event filtering result is sent to the second terminal device according to the event filtering request, so that the second terminal device can display the event filtering result.

[0259] In one or more embodiments, a method for finding relevant events based on an event filtering interface is described. Taking a transaction event generation device deployed on a server as an example, after the transaction event generation device receives an event filtering request sent by a second terminal device, it can provide the event filtering results to the second terminal device based on the event filtering request. The second terminal device is a terminal device used by professional staff, so the second terminal device will display the event filtering results upon receiving them.

[0260] Specifically, for ease of understanding, please refer to Figure 7 , Figure 7 This is a schematic diagram of an event filtering interface in an embodiment of this application. As shown in the figure, the event filtering interface provides multiple selection controls, where D1 is used to indicate the "Submit" control. Users can select the object type; for example, selecting "Individual" means the object type to be filtered is "Individual". Users can also select the event type; for example, selecting "Telecommunications Fraud" means the event type to be filtered is "Telecommunications Fraud". Users can also select the clue value level; for example, selecting "Level 3" means the clue value level to be filtered is "3". Users can also select the event time; for example, selecting "January 1, 2021" means the event time to be filtered is "January 1, 2021".

[0261] Finally, after the professional staff selects the relevant filtering criteria and clicks the "Submit" control indicated by D1, the event filtering request is triggered. Based on this, the relevant event filtering results (i.e., one or more suspicious transaction events) are pushed to the second terminal device according to the filtering criteria, so that the second terminal device can display the event filtering results (i.e., one or more suspicious transaction events).

[0262] It should be noted that, Figure 7 The event filtering interface shown is for illustrative purposes only and should not be construed as limiting this application.

[0263] Secondly, this application embodiment provides a method for finding relevant events based on an event filtering interface. Through the above method, professional staff can further filter relevant suspicious transaction events. On the one hand, it can summarize suspicious transaction events that meet the relevant filtering conditions, thereby improving the convenience of use. On the other hand, based on the displayed suspicious transaction events, professional staff can choose to push them to relevant departments for review, thereby increasing the feasibility and operability of the solution.

[0264] The transaction event generation apparatus in this application is described in detail below. Please refer to [link / reference]. Figure 8 , Figure 8 This is a schematic diagram of one embodiment of the transaction event generation device in this application. The transaction event generation device 20 includes:

[0265] The acquisition module 201 is used to acquire event information in response to an event reporting request. The event information includes the target object name, the target clue description text, and the target event type.

[0266] The determination module 202 is used to determine the authenticity of clues and the importance of events based on event information. The authenticity of clues indicates the credibility of event information, and the importance of events indicates the degree of correlation between the transaction event and sensitive content.

[0267] The determination module 202 is also used to determine the value level of clues based on their authenticity and the importance of the event;

[0268] The generation module 203 is used to generate a target transaction event if the value level of the clue meets the event generation conditions. The target transaction event includes the name of the target object, the type of the target event, and the value level of the clue.

[0269] This application provides a transaction event generation device. Using this device, after opening a lead submission channel, users can report event information through the channel, which is then evaluated by the backend. If the evaluation passes, a suspicious transaction event is directly generated. Therefore, suspicious transaction events can be detected more promptly, resulting in better early warning and alerting capabilities.

[0270] Optionally, in the above Figure 8 Based on the corresponding embodiments, in another embodiment of the transaction event generation device 20 provided in this application, the transaction event generation device 20 further includes a processing module 204 and an execution module 205;

[0271] The processing module 204 is used to perform word segmentation on the target clue description text to obtain M words, where M is an integer greater than or equal to 1;

[0272] The execution module 205 is used to perform the steps of determining the authenticity of clues and the importance of events based on event information if at least one of the M words successfully matches a word in the word library corresponding to the target event type.

[0273] Module 202 is specifically used to determine the importance of an event based on the target clue description text and the target event type.

[0274] The authenticity of a lead is determined based on at least one of the following: the name of the target object, the type of the target event, and the target transaction amount, wherein the target transaction amount is derived from event information or is determined based on historical transaction amounts.

[0275] In this application embodiment, a transaction event generation device is provided. Using the above device, it is necessary to first perform an initial test on the target clue description text reported by the user to filter out event information that is not related to the suspicious transaction. On the one hand, this can effectively reduce the interference of noise information on subsequent detection, and on the other hand, it eliminates the need for further detection of noise information, thereby improving detection efficiency.

[0276] Optionally, in the above Figure 8 Based on the corresponding embodiments, in another embodiment of the transaction event generation device 20 provided in this application,

[0277] The determination module 202 is specifically used to obtain the sensitive word matching relationship corresponding to the target event type. The sensitive word matching relationship includes K sensitive words and the rating score corresponding to each sensitive word, where K is an integer greater than or equal to 1.

[0278] Based on the K sensitive words included in the sensitive word matching relationship, determine N sensitive words from the target clue description text, where N is an integer greater than or equal to 1 and less than or equal to M;

[0279] The sensitive word coverage rate is determined based on the proportion of N sensitive words in M ​​words;

[0280] Based on the rating score corresponding to each sensitive word included in the sensitive word matching relationship, determine the average rating score corresponding to N sensitive words;

[0281] The importance of an event is determined based on the coverage rate of sensitive words and the average rating score.

[0282] In this embodiment of the application, a transaction event generation device is provided. Using the above device, combined with a pre-constructed sensitive word matching relationship, which includes sensitive words and their corresponding rating scores, the sensitive word coverage rate and the average rating score are determined according to the number of sensitive words in the target clue description text. The sensitive word coverage rate and the average rating score are used as the standard for evaluating the authenticity of the clue. On the one hand, this can take into account the amount of sensitive content that may be involved in the target clue description text reported by the user. On the other hand, combined with the preset rating score, the depth of the sensitive content involved can be measured. That is, the correlation between the target clue description text and the sensitive content is evaluated from different dimensions, thereby improving the reliability of the event importance.

[0283] Optionally, in the above Figure 8 Based on the corresponding embodiments, in another embodiment of the transaction event generation device 20 provided in this application,

[0284] The determination module 202 is also used to obtain a historical sample data set, wherein the historical sample data set includes C groups of historical sample data, each group of historical sample data corresponds to a labeling score, historical sensitive word coverage rate and historical rating average score, and C is an integer greater than 1;

[0285] The first data matrix is ​​generated based on the labeled scores included in each group of historical sample data;

[0286] A second data matrix is ​​generated based on the historical sensitive word coverage and historical rating average score of each set of historical sample data;

[0287] Based on the first data matrix and the second data matrix, determine the first coefficient and the second coefficient;

[0288] The determination module 202 is specifically used to determine the importance of an event based on the sensitive word coverage rate, the first coefficient corresponding to the sensitive word coverage rate, the average rating score, and the second coefficient corresponding to the average rating score.

[0289] In this embodiment of the application, a transaction event generation device is provided. Using the above device, relevant data in the historical sample data set is used to derive reasonable first coefficients and second coefficients. The event importance calculated by combining the first coefficients and second coefficients has higher reliability.

[0290] Optionally, in the above Figure 8 Based on the corresponding embodiments, in another embodiment of the transaction event generation device 20 provided in this application,

[0291] The determination module 202 is specifically used to obtain a set of historical event information within a preset period, wherein the set of historical event information includes at least one historical event information, and each historical event information includes an object name;

[0292] Based on the historical event information set, count the frequency of target object names appearing in the target object name;

[0293] Based on the mapping relationship between the frequency of object name occurrence and the frequency coefficient, the target frequency coefficient corresponding to the target occurrence frequency is determined, and the target frequency coefficient is used as the authenticity of the clue.

[0294] In this application embodiment, a transaction event generation device is provided. By using the above device and combining the mapping relationship between the frequency of occurrence of object names and frequency coefficients, the target frequency coefficient corresponding to the frequency of occurrence of the target can be determined. Based on this, the target frequency coefficient is used as the authenticity of the clue. Thus, the influence of the frequency of occurrence of object names on the credibility of event information can be better reflected, thereby improving the reliability of the authenticity of the clue.

[0295] Optionally, in the above Figure 8 Based on the corresponding embodiments, in another embodiment of the transaction event generation device 20 provided in this application,

[0296] The determination module 202 is specifically used to determine the target type coefficient corresponding to the target event type based on the mapping relationship between event type and type coefficient, and to use the target type coefficient as the clue authenticity.

[0297] In this application embodiment, a transaction event generation device is provided. By using the above device and combining the mapping relationship between event type and type coefficient, the target type coefficient corresponding to the target event type can be determined. Based on this, the target type coefficient is used as the authenticity of the clue. Thus, the influence of event type on the credibility of event information can be better reflected, thereby improving the reliability of the authenticity of the clue.

[0298] Optionally, in the above Figure 8 Based on the corresponding embodiments, in another embodiment of the transaction event generation device 20 provided in this application,

[0299] The determination module 202 is specifically used to determine the target amount coefficient corresponding to the target transaction amount based on the mapping relationship between the transaction amount and the amount coefficient, and to use the target amount coefficient as the authenticity of the clue.

[0300] In this embodiment of the application, a transaction event generation device is provided. By using the above device and combining the mapping relationship between transaction amount and amount coefficient, the target amount coefficient corresponding to the target transaction amount can be determined. Based on this, the target amount coefficient is used as the authenticity of the clue. Thus, the influence of the amount coefficient on the credibility of the event information can be better reflected, thereby improving the reliability of the authenticity of the clue.

[0301] Optionally, in the above Figure 8 Based on the corresponding embodiments, in another embodiment of the transaction event generation device 20 provided in this application,

[0302] The determination module 202 is specifically used to obtain a set of historical event information within a preset period, wherein the set of historical event information includes at least one historical event information, and each historical event information includes an object name;

[0303] Based on the historical event information set, count the frequency of target object names appearing in the target object name;

[0304] Based on the mapping relationship between the frequency of object name occurrence and the frequency coefficient, determine the target frequency coefficient corresponding to the target occurrence frequency;

[0305] Based on the mapping relationship between event type and type coefficient, determine the target type coefficient corresponding to the target event type;

[0306] Based on the mapping relationship between transaction amount and amount coefficient, determine the target amount coefficient corresponding to the target transaction amount;

[0307] The authenticity of clues is determined based on the target frequency coefficient, target type coefficient, and target amount coefficient.

[0308] In this application embodiment, a transaction event generation device is provided. Using the above device, by combining the mapping relationship between the frequency of occurrence of object names and frequency coefficients, the target frequency coefficient corresponding to the frequency of occurrence of the target can be determined. By combining the mapping relationship between event type and type coefficient, the target type coefficient corresponding to the target event type can be determined. By combining the mapping relationship between transaction amount and amount coefficient, the target amount coefficient corresponding to the target transaction amount can be determined. Based on this, the target frequency coefficient, target type coefficient, and target amount coefficient together serve as the basis for influencing the authenticity of clues. Thus, the influence of different dimensional features on the credibility of event information can be better reflected, thereby improving the reliability of the authenticity of clues.

[0309] Optionally, in the above Figure 8 Based on the corresponding embodiments, in another embodiment of the transaction event generation device 20 provided in this application,

[0310] The determination module 202 is specifically used to determine the authenticity of the target clue based on the product of the clue authenticity and the first weight value;

[0311] The importance of the target event is determined by multiplying the event importance by the second weight value;

[0312] The value level of clues is determined based on their authenticity and the importance of the target event.

[0313] This application provides a transaction event generation device. Using this device, a clue value level is calculated based on the authenticity of the target clue and its corresponding first weight value, as well as the importance of the target event and its corresponding second weight value, thereby improving the feasibility and operability of the solution. Furthermore, using both clue authenticity and event importance as criteria for measuring the clue value level increases the rationality of the clue value level. For example, a clue with high authenticity may not involve a large transaction amount or high level of regulatory attention; or a clue with high event importance may lack sufficient supporting evidence to determine its authenticity. Therefore, a comprehensive evaluation combining clue authenticity and event importance is necessary.

[0314] Optionally, in the above Figure 8 Based on the corresponding embodiments, in another embodiment of the transaction event generation device 20 provided in this application,

[0315] The acquisition module 201 is specifically used to receive the event reporting request sent by the first terminal device and acquire event information. The first terminal device is used to provide a clue delivery interface, which displays an object name input area, a clue description input area, and an event type input area.

[0316] In this application embodiment, a transaction event generation device is provided. Using the above device, users can actively report event information that they consider suspicious. The reported event information includes the name of the target object, the description text of the target clue, and the type of the target event. As a result, the illegal transaction clues obtained are richer and more reliable, the accuracy of the generated suspicious transaction events is higher, and it is also beneficial to cover a wider range of transaction types.

[0317] Optionally, in the above Figure 8 Based on the corresponding embodiments, in another embodiment of the transaction event generation device 20 provided in this application, the transaction event generation device 20 further includes a sending module 206;

[0318] The sending module 206 is used to send the target transaction event to the second terminal device, wherein the second terminal device is used to provide an event generation interface, which displays at least one transaction event, and the at least one transaction event includes the target transaction event.

[0319] In this application embodiment, a transaction event generation device is provided. Using the above device, after generating a target transaction event (i.e., a suspicious transaction event), it can also be pushed to a second terminal device used by professional staff, thereby facilitating professional staff to view the target transaction event (i.e., the suspicious transaction event) and improving the flexibility and convenience of the solution.

[0320] Optionally, in the above Figure 9 Based on the corresponding embodiments, in another embodiment of the transaction event generation device 20 provided in this application, the transaction event generation device 20 further includes a receiving module 207;

[0321] The receiving module 207 is used to receive an event filtering request sent by the second terminal device, wherein the event filtering request carries at least one of the following: the type of object to be filtered, the type of event to be filtered, the value level of the clue to be filtered, and the time event to be filtered.

[0322] The sending module 206 is also used to send the event filtering result to the second terminal device according to the event filtering request, so that the second terminal device can display the event filtering result.

[0323] In this application embodiment, a transaction event generation device is provided. Using the above device, professional staff can further screen relevant suspicious transaction events. On the one hand, it can summarize suspicious transaction events that meet the relevant screening conditions, thereby improving the convenience of use. On the other hand, based on the displayed suspicious transaction events, professional staff can choose to push them to relevant departments for review, thereby increasing the feasibility and operability of the solution.

[0324] Figure 9 This is a schematic diagram of a server structure provided in an embodiment of this application. The server 300 can vary significantly due to different configurations or performance. It may include one or more central processing units (CPUs) 322 (e.g., one or more processors) and memory 332, and one or more storage media 330 (e.g., one or more mass storage devices) for storing application programs 342 or data 344. The memory 332 and storage media 330 can be temporary or persistent storage. The program stored in the storage media 330 may include one or more modules (not shown in the diagram), each module may include a series of instruction operations on the server. Furthermore, the CPU 322 may be configured to communicate with the storage media 330 and execute the series of instruction operations stored in the storage media 330 on the server 300.

[0325] Server 300 may also include one or more power supplies 326, one or more wired or wireless network interfaces 350, one or more input / output interfaces 358, and / or one or more operating systems 341, such as Windows Server. TM Mac OS X TM Unix TM Linux TM FreeBSD TM etc.

[0326] In this embodiment of the application, the CPU 322 in the server is used to perform the following steps:

[0327] In response to an event reporting request, obtain event information, which includes the target object name, target clue description text, and target event type;

[0328] The authenticity of clues and the importance of events are determined based on event information. The authenticity of clues indicates the credibility of event information, while the importance of events indicates the degree of relevance between the transaction event and sensitive content.

[0329] The value level of clues is determined based on their authenticity and the importance of the event.

[0330] If the value level of a lead meets the conditions for event generation, a target transaction event is generated. The target transaction event includes the name of the target object, the type of the target event, and the value level of the lead.

[0331] Optionally, CPU 322 in the server is specifically used to perform the following steps:

[0332] The system receives an event reporting request sent by a first terminal device and obtains event information. The first terminal device is used to provide a clue delivery interface, which displays an object name input area, a clue description input area, and an event type input area.

[0333] Optionally, CPU 322 in the server is also used to perform the following steps:

[0334] Send the target transaction event to the second terminal device, wherein the second terminal device is used to provide an event generation interface, the event generation interface displays at least one transaction event, and the at least one transaction event includes the target transaction event.

[0335] Optionally, CPU 322 in the server is also used to perform the following steps:

[0336] Receive an event filtering request sent by a second terminal device, wherein the event filtering request carries at least one of the following: object type to be filtered, event type to be filtered, clue value level to be filtered, and time event to be filtered;

[0337] The event filtering result is sent to the second terminal device according to the event filtering request, so that the second terminal device can display the event filtering result.

[0338] The steps performed by the server in the above embodiments can be based on this Figure 10 The server structure shown.

[0339] This application also provides another image display control device, such as... Figure 10 As shown, for ease of explanation, only the parts related to the embodiments of this application are shown. For specific technical details not disclosed, please refer to the method section of the embodiments of this application. The terminal device can be any terminal device including mobile phones, tablets, personal digital assistants (PDAs), point-of-sale (POS) terminals, in-vehicle computers, etc. Taking a mobile phone as an example:

[0340] Figure 10 This diagram illustrates a partial structural representation of a mobile phone related to the terminal device provided in this embodiment. (Reference) Figure 10 The mobile phone includes components such as a radio frequency (RF) circuit 410, a memory 420, an input unit 430, a display unit 440, a sensor 450, an audio circuit 460, a wireless fidelity (WiFi) module 470, a processor 480, and a power supply 490. Those skilled in the art will understand that... Figure 10 The mobile phone structure shown does not constitute a limitation on the mobile phone and may include more or fewer components than shown, or combine certain components, or have different component arrangements.

[0341] The following is combined with Figure 10 A detailed introduction to each component of a mobile phone:

[0342] RF circuit 410 can be used for receiving and transmitting signals during information transmission or calls. Specifically, it receives downlink information from the base station and processes it with processor 480; additionally, it transmits uplink data to the base station. Typically, RF circuit 410 includes, but is not limited to, an antenna, at least one amplifier, a transceiver, a coupler, a low-noise amplifier (LNA), a duplexer, etc. Furthermore, RF circuit 410 can also communicate wirelessly with networks and other devices. The aforementioned wireless communication can use any communication standard or protocol, including but not limited to Global System for Mobile Communication (GSM), General Packet Radio Service (GPRS), Code Division Multiple Access (CDMA), Wideband Code Division Multiple Access (WCDMA), Long Term Evolution (LTE), email, Short Messaging Service (SMS), etc.

[0343] The memory 420 can be used to store software programs and modules. The processor 480 executes various functions and data processing of the mobile phone by running the software programs and modules stored in the memory 420. The memory 420 may mainly include a program storage area and a data storage area. The program storage area may store the operating system, applications required for at least one function (such as sound playback function, image playback function, etc.), etc.; the data storage area may store data created according to the use of the mobile phone (such as audio data, phonebook, etc.). In addition, the memory 420 may include high-speed random access memory, and may also include non-volatile memory, such as at least one disk storage device, flash memory device, or other volatile solid-state storage device.

[0344] The input unit 430 can be used to receive input numerical or character information, and to generate key signal inputs related to user settings and function control of the mobile phone. Specifically, the input unit 430 may include a touch panel 431 and other input devices 432. The touch panel 431, also known as a touch screen, can collect touch operations performed by the user on or near it (such as operations performed by the user using a finger, stylus, or any suitable object or accessory on or near the touch panel 431), and drive the corresponding connection devices according to a pre-set program. Optionally, the touch panel 431 may include two parts: a touch detection device and a touch controller. The touch detection device detects the user's touch position and the signal generated by the touch operation, and transmits the signal to the touch controller; the touch controller receives touch information from the touch detection device, converts it into touch point coordinates, sends it to the processor 480, and can receive and execute commands sent by the processor 480. In addition, the touch panel 431 can be implemented using various types such as resistive, capacitive, infrared, and surface acoustic wave. In addition to the touch panel 431, the input unit 430 may also include other input devices 432. Specifically, other input devices 432 may include, but are not limited to, one or more of the following: physical keyboard, function keys (such as volume control buttons, power buttons, etc.), trackball, mouse, joystick, etc.

[0345] Display unit 440 can be used to display information input by the user or information provided to the user, as well as various menus of the mobile phone. Display unit 440 may include display panel 441, optionally configured as a liquid crystal display (LCD), organic light-emitting diode (OLED), or similar display panel 441. Further, touch panel 431 may cover display panel 441. When touch panel 431 detects a touch operation on or near it, it transmits the information to processor 480 to determine the type of touch event. Subsequently, processor 480 provides corresponding visual output on display panel 441 based on the type of touch event. Although in Figure 10 In this embodiment, the touch panel 431 and the display panel 441 are two separate components to realize the input and output functions of the mobile phone. However, in some embodiments, the touch panel 431 and the display panel 441 can be integrated to realize the input and output functions of the mobile phone.

[0346] The mobile phone may also include at least one sensor 450, such as a light sensor, a motion sensor, and other sensors. Specifically, the light sensor may include an ambient light sensor and a proximity sensor. The ambient light sensor can adjust the brightness of the display panel 441 according to the ambient light level, and the proximity sensor can turn off the display panel 441 and / or the backlight when the phone is moved to the ear. As a type of motion sensor, an accelerometer sensor can detect the magnitude of acceleration in various directions (generally three axes). When stationary, it can detect the magnitude and direction of gravity and can be used for applications that recognize the phone's posture (such as landscape / portrait switching, related games, magnetometer posture calibration), vibration recognition-related functions (such as pedometer, tapping), etc. Other sensors that may be configured in the mobile phone, such as gyroscopes, barometers, hygrometers, thermometers, and infrared sensors, will not be described in detail here.

[0347] Audio circuit 460, speaker 461, and microphone 462 provide an audio interface between the user and the mobile phone. Audio circuit 460 converts received audio data into electrical signals and transmits them to speaker 461, where speaker 461 converts them into sound signals for output. On the other hand, microphone 462 converts collected sound signals into electrical signals, which are received by audio circuit 460, converted into audio data, and then processed by processor 480 before being transmitted via RF circuit 410 to, for example, another mobile phone, or the audio data can be output to memory 420 for further processing.

[0348] WiFi is a short-range wireless transmission technology. Mobile phones, through their WiFi modules (470), can help users send and receive emails, browse web pages, and access streaming media, providing wireless broadband internet access. Although Figure 10 WiFi module 470 is shown, but it is understood that it is not an essential component of a mobile phone and can be omitted as needed without changing the essence of the invention.

[0349] The processor 480 is the control center of the mobile phone, connecting various parts of the phone through various interfaces and lines. It performs various functions and processes data by running or executing software programs and / or modules stored in the memory 420, and by calling data stored in the memory 420. Optionally, the processor 480 may include one or more processing units; optionally, the processor 480 may integrate an application processor and a modem processor, wherein the application processor mainly handles the operating system, user interface, and applications, and the modem processor mainly handles wireless communication. It is understood that the aforementioned modem processor may also not be integrated into the processor 480.

[0350] The mobile phone also includes a power supply 490 (such as a battery) that supplies power to various components. Optionally, the power supply can be logically connected to the processor 480 through a power management system, thereby enabling functions such as charging, discharging, and power consumption management through the power management system.

[0351] Although not shown, mobile phones may also include a camera, Bluetooth module, etc., which will not be described in detail here.

[0352] In this embodiment of the application, the processor 480 in the terminal device is used to perform the following steps:

[0353] In response to an event reporting request, obtain event information, which includes the target object name, target clue description text, and target event type;

[0354] The authenticity of clues and the importance of events are determined based on event information. The authenticity of clues indicates the credibility of event information, while the importance of events indicates the degree of relevance between the transaction event and sensitive content.

[0355] The value level of clues is determined based on their authenticity and the importance of the event.

[0356] If the value level of a lead meets the conditions for event generation, a target transaction event is generated. The target transaction event includes the name of the target object, the type of the target event, and the value level of the lead.

[0357] The steps performed by the terminal device in the above embodiments can be based on this ​ The terminal device structure is shown.

[0358] This application also provides a computer-readable storage medium storing a computer program that, when run on a computer, causes the computer to perform the methods described in the foregoing embodiments.

[0359] This application also provides a computer program product including a program, which, when run on a computer, causes the computer to perform the methods described in the foregoing embodiments.

[0360] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.

[0361] In the several embodiments provided in this application, it should be understood that the disclosed systems, apparatuses, and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be an indirect coupling or communication connection between apparatuses or units through some interfaces, and may be electrical, mechanical, or other forms.

[0362] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0363] Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.

[0364] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0365] The above-described embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit them. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of this application.

Claims

1. A method for generating transaction events, characterized in that, include: In response to an event reporting request, the event information is obtained, wherein the event information includes the target object name, the target clue description text, and the target event type; The authenticity of the clues and the importance of the event are determined based on the event information, wherein the authenticity of the clues represents the credibility of the event information, and the importance of the event represents the degree of correlation between the transaction event and sensitive content; Determining the value level of a clue based on its authenticity and the importance of the event includes: determining the authenticity of a target clue by multiplying its authenticity by a first weight value; determining the importance of a target event by multiplying its importance by a second weight value; and determining the value level of the clue based on its authenticity and the importance of the target event. If the value level of the clue meets the event generation conditions, a target transaction event is generated, wherein the target transaction event includes the name of the target object, the type of the target event, and the value level of the clue.

2. The generation method according to claim 1, characterized in that, The method further includes: The target clue description text is segmented to obtain M words, where M is an integer greater than or equal to 1; If at least one of the M words matches a word in the word library corresponding to the target event type, then the step of determining the authenticity of the clues and the importance of the event based on the event information is executed. The process of determining the authenticity of clues and the importance of events based on the event information includes: The importance of the event is determined based on the target clue description text and the target event type; The authenticity of the clue is determined based on at least one of the target object name, the target event type, and the target transaction amount, wherein the target transaction amount is derived from the event information, or the target transaction amount is determined based on historical transaction amounts.

3. The generation method according to claim 2, characterized in that, Determining the importance of the event based on the target clue description text and the target event type includes: Obtain the sensitive word matching relationship corresponding to the target event type, wherein the sensitive word matching relationship includes K sensitive words and the rating score corresponding to each sensitive word, and K is an integer greater than or equal to 1; Based on the K sensitive words included in the sensitive word matching relationship, N sensitive words are determined from the target clue description text, where N is an integer greater than or equal to 1 and less than or equal to M; The sensitive word coverage rate is determined based on the proportion of the N sensitive words in the M words. Based on the rating score corresponding to each sensitive word included in the sensitive word matching relationship, determine the average rating score corresponding to the N sensitive words; The importance of the event is determined based on the coverage of the sensitive words and the average rating score.

4. The generation method according to claim 3, characterized in that, The method further includes: Obtain a historical sample data set, wherein the historical sample data set includes C groups of historical sample data, each group of historical sample data corresponds to a label score, historical sensitive word coverage rate and historical average rating score, and C is an integer greater than 1; A first data matrix is ​​generated based on the labeled scores included in each group of historical sample data; A second data matrix is ​​generated based on the historical sensitive word coverage and historical rating average score included in each group of historical sample data; Based on the first data matrix and the second data matrix, determine the first coefficient and the second coefficient; The determination of the event importance based on the sensitive word coverage rate and the average rating score includes: The importance of the event is determined based on the sensitive word coverage rate, the first coefficient corresponding to the sensitive word coverage rate, the average rating score, and the second coefficient corresponding to the average rating score.

5. The generation method according to claim 2, characterized in that, Determining the authenticity of the clue based on at least one of the target object name, the target event type, and the target transaction amount includes: Obtain a set of historical event information within a preset period, wherein the set of historical event information includes at least one historical event information, and each historical event information includes an object name; Based on the set of historical event information, the frequency of occurrence of the target object name is counted. Based on the mapping relationship between the frequency of occurrence of object names and frequency coefficients, the target frequency coefficient corresponding to the frequency of occurrence of the target is determined, and the target frequency coefficient is used as the authenticity of the clue.

6. The generation method according to claim 2, characterized in that, Determining the authenticity of the clue based on at least one of the target object name, the target event type, and the target transaction amount includes: Based on the mapping relationship between event type and type coefficient, the target type coefficient corresponding to the target event type is determined, and the target type coefficient is used as the authenticity of the clue.

7. The generation method according to claim 2, characterized in that, Determining the authenticity of the clue based on at least one of the target object name, the target event type, and the target transaction amount includes: Based on the mapping relationship between transaction amount and amount coefficient, the target amount coefficient corresponding to the target transaction amount is determined, and the target amount coefficient is used as the authenticity of the clue.

8. The generation method according to claim 2, characterized in that, Determining the authenticity of the clue based on at least one of the target object name, the target event type, and the target transaction amount includes: Obtain a set of historical event information within a preset period, wherein the set of historical event information includes at least one historical event information, and each historical event information includes an object name; Based on the set of historical event information, the frequency of occurrence of the target object name is counted. Based on the mapping relationship between the frequency of occurrence of object names and frequency coefficients, the target frequency coefficient corresponding to the frequency of occurrence of the target is determined; Based on the mapping relationship between event type and type coefficient, determine the target type coefficient corresponding to the target event type; Based on the mapping relationship between transaction amount and amount coefficient, determine the target amount coefficient corresponding to the target transaction amount; The authenticity of the clue is determined based on the target frequency coefficient, the target type coefficient, and the target amount coefficient.

9. The generation method according to any one of claims 1 to 8, characterized in that, The response to the event reporting request, obtaining event information, includes: The system receives the event reporting request sent by the first terminal device and obtains the event information. The first terminal device is used to provide a clue delivery interface, which displays an object name input area, a clue description input area, and an event type input area.

10. The generation method according to any one of claims 1 to 8, characterized in that, The method further includes: The target transaction event is sent to a second terminal device, wherein the second terminal device is used to provide an event generation interface, the event generation interface displays at least one transaction event, and the at least one transaction event includes the target transaction event.

11. The generation method according to any one of claims 1 to 8, characterized in that, The method further includes: Receive an event filtering request sent by a second terminal device, wherein the event filtering request carries at least one of the following: object type to be filtered, event type to be filtered, clue value level to be filtered, and time event to be filtered; The event filtering result is sent to the second terminal device according to the event filtering request, so that the second terminal device displays the event filtering result.

12. A transaction event generation device, characterized in that, include: The acquisition module is used to acquire event information in response to an event reporting request, wherein the event information includes the target object name, the target clue description text, and the target event type; The determination module is used to determine the authenticity of clues and the importance of events based on the event information, wherein the authenticity of clues represents the credibility of the event information, and the importance of events represents the degree of correlation between the transaction event and sensitive content; The determining module is further configured to determine the value level of a clue based on the authenticity of the clue and the importance of the event, including: determining the authenticity of a target clue based on the product of the authenticity of the clue and a first weight value; determining the importance of a target event based on the product of the importance of the event and a second weight value; and determining the value level of the clue based on the authenticity of the target clue and the importance of the target event. The generation module is used to generate a target transaction event if the value level of the clue meets the event generation conditions, wherein the target transaction event includes the name of the target object, the type of the target event, and the value level of the clue.

13. The apparatus according to claim 12, characterized in that, The device also includes a processing module and an execution module; The processing module is used to perform word segmentation on the target clue description text to obtain M words, where M is an integer greater than or equal to 1; The execution module is configured to execute the step of determining the authenticity of the clues and the importance of the event based on the event information if at least one of the M words matches a word in the word library corresponding to the target event type. The determining module is specifically used for: The importance of the event is determined based on the target clue description text and the target event type; The authenticity of the clue is determined based on at least one of the target object name, the target event type, and the target transaction amount, wherein the target transaction amount is derived from the event information, or the target transaction amount is determined based on historical transaction amounts.

14. The apparatus according to claim 13, characterized in that, The determining module is specifically used for: Obtain the sensitive word matching relationship corresponding to the target event type, wherein the sensitive word matching relationship includes K sensitive words and the rating score corresponding to each sensitive word, and K is an integer greater than or equal to 1; Based on the K sensitive words included in the sensitive word matching relationship, N sensitive words are determined from the target clue description text, where N is an integer greater than or equal to 1 and less than or equal to M; The sensitive word coverage rate is determined based on the proportion of the N sensitive words in the M words. Based on the rating score corresponding to each sensitive word included in the sensitive word matching relationship, determine the average rating score corresponding to the N sensitive words; The importance of the event is determined based on the coverage of the sensitive words and the average rating score.

15. The apparatus according to claim 14, characterized in that, The determining module is also used for: Obtain a historical sample data set, wherein the historical sample data set includes C groups of historical sample data, each group of historical sample data corresponds to a label score, historical sensitive word coverage rate and historical average rating score, and C is an integer greater than 1; A first data matrix is ​​generated based on the labeled scores included in each group of historical sample data; A second data matrix is ​​generated based on the historical sensitive word coverage and historical rating average score included in each group of historical sample data; Based on the first data matrix and the second data matrix, determine the first coefficient and the second coefficient; The determining module is specifically used to determine the importance of the event based on the sensitive word coverage rate, the first coefficient corresponding to the sensitive word coverage rate, the average rating score, and the second coefficient corresponding to the average rating score.

16. The apparatus according to claim 13, characterized in that, The determining module is specifically used for: Obtain a set of historical event information within a preset period, wherein the set of historical event information includes at least one historical event information, and each historical event information includes an object name; Based on the set of historical event information, the frequency of occurrence of the target object name is counted. Based on the mapping relationship between the frequency of occurrence of object names and frequency coefficients, the target frequency coefficient corresponding to the frequency of occurrence of the target is determined, and the target frequency coefficient is used as the authenticity of the clue.

17. The apparatus according to claim 13, characterized in that, The determining module is specifically used to determine the target type coefficient corresponding to the target event type based on the mapping relationship between event type and type coefficient, and to use the target type coefficient as the authenticity of the clue.

18. The apparatus according to claim 13, characterized in that, The determining module is specifically used to determine the target amount coefficient corresponding to the target transaction amount based on the mapping relationship between the transaction amount and the amount coefficient, and to use the target amount coefficient as the authenticity of the clue.

19. The apparatus according to claim 13, characterized in that, The determining module is specifically used for: Obtain a set of historical event information within a preset period, wherein the set of historical event information includes at least one historical event information, and each historical event information includes an object name; Based on the set of historical event information, the frequency of occurrence of the target object name is counted. Based on the mapping relationship between the frequency of occurrence of object names and frequency coefficients, the target frequency coefficient corresponding to the frequency of occurrence of the target is determined; Based on the mapping relationship between event type and type coefficient, determine the target type coefficient corresponding to the target event type; Based on the mapping relationship between transaction amount and amount coefficient, determine the target amount coefficient corresponding to the target transaction amount; The authenticity of the clue is determined based on the target frequency coefficient, the target type coefficient, and the target amount coefficient.

20. The apparatus according to any one of claims 12 to 19, characterized in that, The acquisition module is specifically used to receive the event reporting request sent by the first terminal device and acquire the event information. The first terminal device is used to provide a clue delivery interface, which displays an object name input area, a clue description input area, and an event type input area.

21. The apparatus according to any one of claims 12 to 19, characterized in that, The device also includes a transmitting module; The sending module is used to send the target transaction event to the second terminal device, wherein the second terminal device is used to provide an event generation interface, the event generation interface displays at least one transaction event, and the at least one transaction event includes the target transaction event.

22. The apparatus according to any one of claims 12 to 19, characterized in that, The device also includes a receiving module and a transmitting module; The receiving module is used to receive an event filtering request sent by the second terminal device, wherein the event filtering request carries at least one of the following: the type of object to be filtered, the type of event to be filtered, the value level of the clue to be filtered, and the time event to be filtered. The sending module is configured to send the event filtering result to the second terminal device according to the event filtering request, so that the second terminal device displays the event filtering result.

23. A computer device, characterized in that, include: Memory, processor, and bus system; The memory is used to store programs; The processor is configured to execute a program in the memory, and the processor is configured to execute the generation method according to any one of claims 1 to 11 according to the instructions in the program code; The bus system is used to connect the memory and the processor to enable communication between the memory and the processor.

24. A computer-readable storage medium comprising instructions, when executed on a computer, causing the computer to perform the generation method as described in any one of claims 1 to 11.

25. A computer program product, characterized in that, The computer program product includes computer instructions, which are executed by a processor of a computer device to cause the computer device to perform the generation method as described in any one of claims 1 to 11.

Citation Information

Patent Citations

  • Case information reporting and publishing method and device

    CN106952075A

  • Risk event processing method and device

    CN111784357A

  • Risk event processing system, method and device and storage medium

    CN112651608A