A data processing method and device, computer equipment and readable storage medium
By constructing a data structure diagram and feature matrix and combining it with a reference evaluation matrix, the problems of low coverage of associated objects and insufficient evaluation accuracy in Internet fraud detection are solved, and efficient detection and evaluation of Internet fraud are achieved.
Patent Information
- Application Number
- CN202110986900.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-08-26
- Publication Date
- 2025-10-24
- Estimated Expiration
- 2041-08-26
AI Technical Summary
In the existing technology, the coverage rate of related objects in Internet fraud detection is not high, and the accuracy of the evaluation results needs to be improved. Especially in Internet finance, the security of virtual resources faces huge challenges.
Construct a data structure graph between the target object and the associated objects. By determining the characteristic matrix of the data structure graph and combining the reference evaluation matrix and the characteristic matrix, determine the evaluation results of the target object and the associated objects. Introduce the first-class associated objects and the second-class associated objects, and use the edge weights to represent their relationship, thereby improving the detection coverage and evaluation accuracy.
It effectively improves the detection coverage of related objects and the accuracy of evaluation results, can quickly and accurately mine objects that are closely related to the target object, and improves the effect of Internet fraud detection.
Smart Images

Figure CN115907765B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of computer, in particular to a data processing method, a data processing device, a computer device and a computer readable storage medium. BACKGROUND
[0002] With the development of computer technology and electronic technology, the Internet finance has shown great market space and development potential. Under the environment of Internet finance, virtual resource transaction has become one of the main means of financial transaction, and has brought a lot of convenience to people, but at the same time, it also exposes some security risks.
[0003] Nowadays, Internet fraud has developed very professional and industrialized, which threatens the safety of virtual resources held by users, and also brings great challenges and losses to the Internet financial industry, so it is necessary to crack down on such Internet fraud. Before that, it is necessary to evaluate each object to obtain evaluation results, and then determine the specific object to be cracked down based on the evaluation results. At present, the object evaluation method can adopt manual review evaluation, but this method may result in low coverage of associated object detection, and the accuracy of the evaluation results of each object needs to be improved. SUMMARY
[0004] The embodiments of the present application provide a data processing method, device, computer device and readable storage medium, which can effectively improve the detection coverage of associated objects and effectively improve the accuracy of evaluation results.
[0005] The embodiments of the present application provide a data processing method, device, computer device and readable storage medium, which can effectively improve the detection coverage of associated objects and effectively improve the accuracy of evaluation results.
[0006] Determine the target object and the associated object set of the target object, and construct the data structure graph between the target object and the associated objects in the associated object set;
[0007] Determine the feature matrix of the data structure graph, and determine the evaluation results corresponding to the target object and the associated objects respectively according to the reference evaluation matrix and the feature matrix, wherein the reference evaluation matrix is determined according to the reference evaluation parameters corresponding to the target object and the associated objects respectively;
[0008] The data structure diagram includes nodes for representing the target object and the associated objects, the associated object set includes one or more of the first type of associated objects and the second type of associated objects, the data structure diagram includes one or more of the first type of edges and the second type of edges, the first type of edges are used to connect the nodes representing the target object and the nodes representing the first type of associated objects, the second type of edges are used to connect the nodes representing the target object and the nodes representing the second type of associated objects, the first type of associated objects include objects having common associated objects with the target object, the second type of associated objects include objects having transaction relationships with the target object, and the first type of edges and the second type of edges are determined in different ways.
[0009] The embodiment of the application provides a data processing device, which comprises:
[0010] A determination module is configured to determine a target object and an associated object set of the target object, and construct a data structure diagram between the target object and the associated objects in the associated object set.
[0011] The determination module is further configured to determine a feature matrix of the data structure diagram, and determine corresponding evaluation results of the target object and the associated objects according to a reference evaluation matrix and the feature matrix, wherein the reference evaluation matrix is determined according to reference evaluation parameters corresponding to the target object and the associated objects; wherein the data structure diagram includes nodes for representing the target object and the associated objects, the associated object set includes one or more of the first type of associated objects and the second type of associated objects, the data structure diagram includes one or more of the first type of edges and the second type of edges, the first type of edges are used to connect the nodes representing the target object and the nodes representing the first type of associated objects, the second type of edges are used to connect the nodes representing the target object and the nodes representing the second type of associated objects, the first type of associated objects include objects having common associated objects with the target object, the second type of associated objects include objects having transaction relationships with the target object, and the first type of edges and the second type of edges are determined in different ways.
[0012] In an embodiment, the determination module is specifically configured to determine the weight of the first type of edges according to the number of common associated objects between the target object and the first type of associated objects, and determine the weight of the second type of edges according to transaction parameters between the target object and the second type of associated objects.
[0013] In an embodiment, the associated object set includes the first type of associated objects, and the data processing device further comprises an adjustment module, wherein:
[0014] The determination module is further configured to determine a transaction object having a transaction relationship with the first type of associated objects, and determine the transaction object as a third type of associated object associated with the target object.
[0015] The adjustment module is used to adjust the data structure graph according to the third-type associated objects to obtain an adjusted data structure graph; wherein the associated object set also includes the third-type associated objects; the adjusted data structure graph also includes a third-type edge, the third-type edge is used to connect the node representing the first-type associated object and the node representing the third-type associated object, and the weight of the third-type edge is determined according to the transaction parameters between the third-type associated object and the second-type associated object; the determination module is further used to determine the characteristic matrix of the adjusted data structure graph.
[0016] In one embodiment, the set of associated objects also includes a second type of associated objects, and the adjustment module is further used to: when it is detected that the common transaction objects between the second type of associated objects and the third type of associated objects meet the first set condition, adjust the data structure graph to obtain an adjusted data structure graph; wherein the adjusted data structure graph also includes a fourth type of edge, the fourth type of edge is used to connect the node representing the third type of associated objects and the node representing the second type of associated objects, and the weight of the fourth type of edge is determined according to the number of common transaction objects between the third type of associated objects and the second type of associated objects; the determination module is specifically further used to determine the characteristic matrix of the adjusted data structure graph.
[0017] In one embodiment, the adjustment module is further used to: when the third-category associated objects include at least two and the common transaction objects between any two third-category associated objects meet the second set condition, adjust the data structure graph to obtain an adjusted data structure graph; wherein the adjusted data structure graph also includes a fifth-category edge, the fifth-category edge is used to connect nodes representing any two third-category associated objects, and the weight of the fifth-category edge is determined according to the number of common transaction objects between any two third-category associated objects; the determination module is specifically further used to determine the characteristic matrix of the adjusted data structure graph.
[0018] In one embodiment, the feature matrix includes an adjacency matrix and an association matrix, and the determination module is specifically used to: calculate the adjacency matrix, the association matrix and the reference evaluation matrix to determine the intermediate evaluation matrix; calculate the adjacency matrix, the association matrix and the intermediate evaluation matrix to determine the target evaluation matrix; determine the evaluation results corresponding to the target object and the associated object respectively according to the target evaluation matrix.
[0019] In one embodiment, the data processing device further includes a receiving module and a sending module, wherein:
[0020] A receiving module, configured to receive a query request for an evaluation result of a current transaction object from a client;
[0021] The sending module is configured to return, in response to the evaluation result query request, indication information including an evaluation result of the current transaction object to the client, the indication information being used to instruct the client to display the evaluation result of the current transaction object.
[0022] In an embodiment, the data processing apparatus further comprises an intercepting module and a pre-warning module, wherein:
[0023] The intercepting module is configured to intercept the first transaction when detecting the first transaction related to the intercepting object;
[0024] The pre-warning module is configured to pre-warn the initiator of the second transaction when detecting the second transaction related to the pre-warning object;
[0025] The intercepting object comprises an object whose evaluation value indicated by the evaluation result is greater than or equal to a first evaluation threshold, the pre-warning object comprises an object whose evaluation value indicated by the evaluation result is greater than or equal to a second evaluation threshold and less than or equal to a third evaluation threshold, and the first evaluation threshold is greater than or equal to the third evaluation threshold.
[0026] An embodiment of the present application provides a computer device, comprising a processor, a memory and a network interface; the network interface is configured to provide network communication function, the memory is configured to store program code, and the processor is configured to invoke the program code to execute the data processing method in the embodiment of the present application.
[0027] An embodiment of the present application provides a computer readable storage medium, which stores a computer program, and the computer program comprises program instructions. When the program instructions are executed by a processor, the data processing method in the embodiment of the present application is executed.
[0028] Correspondingly, the embodiment of the present application provides a computer program product or a computer program, which comprises computer instructions stored in a computer readable storage medium. The processor of the computer device reads the computer instructions from the computer readable storage medium, and the processor executes the computer instructions, so that the computer device executes the data processing method provided in the embodiment of the present application.
[0029] In the embodiment of the present application, by constructing the data structure graph representing the relationship between the target object and the associated object, in addition to the second associated object having a transaction relationship with the target object, the first associated object having a common associated object with the target object can also be introduced, so as to mine the associated object having a direct relationship or an indirect relationship with the target object, which can effectively cover other associated objects that can have the same behavior as the target object, and improve the detection coverage; in addition, based on the feature matrix of the data structure graph, the reference evaluation matrix composed of the reference evaluation parameter information of the target object and the associated object, the final evaluation result can be obtained in combination with the initial evaluation information of the object itself, and the accuracy and reliability of the evaluation result can be effectively improved. BRIEF DESCRIPTION OF DRAWINGS
[0030] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the drawings needed to be used in the embodiments or the prior art description will be briefly introduced. Obviously, the drawings in the following description are some embodiments of the present application, and other drawings can also be obtained by those skilled in the art without creative labor.
[0031] Figure 1 is a schematic diagram of a data structure graph provided by the embodiment of the present application;
[0032] Figure 2 is an architecture diagram of a data processing system provided by the embodiment of the present application;
[0033] Figure 3 is a flowchart of a data processing method provided by the embodiment of the present application;
[0034] Figure 4 is a schematic diagram of an entity relationship graph provided by the embodiment of the present application;
[0035] Figure 5 is a schematic diagram of an adjacency matrix and a degree matrix of a data structure graph provided by the embodiment of the present application;
[0036] Figure 6 is a flowchart of another data processing method provided by the embodiment of the present application;
[0037] Figure 7 is a schematic diagram of a data structure graph containing a common associated object provided by the embodiment of the present application;
[0038] Figure 8 is a schematic diagram of another entity relationship graph provided by the embodiment of the present application;
[0039] Figure 9 is a schematic diagram of another entity relationship graph provided by the embodiment of the present application;
[0040] Figure 10 is a flow diagram of an application method based on an evaluation result provided by an embodiment of the present application;
[0041] Figure 11 is an effect diagram of a client querying an evaluation result provided by an embodiment of the present application;
[0042] Figure 12 is a structural diagram of a data processing apparatus provided by an embodiment of the present application;
[0043] Figure 13 is a structural diagram of a computer device provided by an embodiment of the present application. DETAILED DESCRIPTION
[0044] In order to enable those skilled in the art to better understand the present application, the technical solutions in the embodiments of the present application will be described clearly and completely below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only some of the embodiments of the present application, not all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative labor fall within the scope of protection of the present application.
[0045] Blockchain (BlockChain or Block Chain) is a new application mode of distributed data storage, peer-to-peer transmission, consensus mechanism, and encryption algorithm. Blockchain is essentially a decentralized database, which is a series of data blocks associated using cryptographic methods. Each data block contains information about a batch of network transactions, which is used to verify the validity (anti-fake) of the information and generate the next block. It includes a series of blocks (Block) connected in chronological order. Once a new block is added to the blockchain, it cannot be removed. The block records the recorded data submitted by the nodes in the blockchain system. The distributed ledger connected by blockchain technology can effectively record transactions between two parties and permanently verify the transaction.
[0046] In an implementable embodiment, the data processing method provided by the embodiments of the present application is further based on cloud technology and / or block chain technology. Specifically, it can involve one or more of cloud storage, cloud database, and big data in cloud technology. For example, data required for executing the data processing method (e.g., target objects (such as account numbers), associated objects, etc.) is obtained from a cloud database. For another example, data generated by executing the data processing method (e.g., reference evaluation parameters, evaluation results) can be stored in a block chain network in the form of a block, and transaction data between objects (such as account numbers) can also be obtained from the block chain network. In addition, the device executing the data processing method can be a node device in the block chain network.
[0047] In computer science, a graph, i.e., the data structure graph described in the embodiments of the present application, is a data structure composed of two parts of vertices and edges. A graph G can be described by a vertex set V and an edge set E contained therein. As shown in Figure 1 , a data structure graph is shown. The vertices in the graph can be represented by circles, and the edges are the connections between the circles. Vertices can also be called nodes or intersections, and edges can also be called connections. For example, a graph can represent a social network, and each person is a vertex, and people who know each other are connected by edges. Graphs come in various shapes and sizes, and edges can have weights, i.e., each edge is assigned a positive or negative value. For a graph representing an airline, each city is a vertex, and the airline is an edge, and the weight of the edge can be the flight time or the ticket price, etc. In addition, according to whether there is a directional dependency relationship between vertices, the edge can be directed or undirected; a directed edge means that there is only a one-way relationship between two vertices, while an undirected edge (or bidirectional edge) means that there is a two-way relationship between two vertices.
[0048] Next, the architecture diagram of the data processing system provided by the embodiments of the present application is described. Please refer to Figure 2 , Figure 2 is an architecture diagram of a data processing system provided by the embodiments of the present application, as shown in Figure 2 , the architecture diagram includes a server 100 and a plurality of terminal devices 101. Any terminal device 101 and the server 100 can be connected by wired or wireless means.
[0049] The server 100 can be a server owned by a service provider who develops the target function application, or a third-party server who provides evaluation services for the service provider of the function application. The server 100 can obtain a target object from a database storing objects, determine a set of associated objects of the target object according to multi-dimensional data of the target object and some predetermined rules, including a first type of associated object having a common associated object with the target object or a second type of associated object having a transaction relationship with the target object. After obtaining these objects (including the target object and the associated objects), the server 100 can map each object as a node and the relationship between each object as an edge, and then construct a data structure graph. According to the characteristic information of the data structure graph and the reference evaluation matrix, the final evaluation parameters of each node can be determined, and then used as the evaluation results of the target object and the associated objects. The evaluation results can also be used to mine the objects most closely associated with the target object. The present scheme can be applied to the scene of risk account identification or anti-fraud. Taking the target object as a complained account as an example, the associated accounts can be determined according to the multi-dimensional information (such as the flow direction of virtual resources between accounts, account login address or login device) of the collected complained accounts, and then the evaluation results of the accounts can be determined based on the characteristic matrix of the constructed data structure graph and the initial evaluation parameters of each account. The evaluation results can correspond to the fraud risk of the account, i.e. the possibility of the account being an abnormal account, and then the closely associated accounts of the complained account can be mined to prevent abnormal objects in the set of abnormal objects from performing abnormal operations. The above method integrates a large amount of heterogeneous and diversified massive data collected through the data structure graph into machine-understandable information, converts the "single-point" check into a "surface" form for fraud risk detection, and thus provides more feasible measures for fraud identification and prevention. The server 100 can also respond to the evaluation result query request for a certain transaction object sent by the terminal device 101, and send the evaluation result corresponding to the transaction object to the terminal device 101.
[0050] The terminal device 101 can install or run a target function application, which can be an online application, a third-party social application, a financial application, and the like. The terminal device 101 can generate application data and send the application data to the server 100, and the server 100 can determine a target object based on the application data. In addition, the terminal device 101 can query an evaluation result of a current transaction object. Specifically, the terminal device 101 can send a query request for the evaluation result to the server 100, and the server 100 can respond to the query request and return the evaluation result to the terminal device 101. Taking an account of an application platform as an example, the application data can include a login account of the terminal device 101, a communication record of other accounts using the application, such as sending a chat message, conducting a virtual resource transaction, sharing information, and the like, and a record of reporting or reporting an illegal fraudulent account in the target application platform through the terminal device 101. The terminal device 101 can also query whether a user added or followed in a list is a risk user in the entire application platform, so as to avoid some risk transactions.
[0051] It can be found that the server 100 can abstract the target object and the associated object as different nodes by constructing an association graph between the target object and the associated object, i.e., a data structure graph in the present application, and describe the relationship between the objects as edges and weights of the edges. Based on the common associated objects between the target object and the associated object, the first associated object and the target object are connected, and the target object and the second associated object are connected based on the transaction relationship, so as to effectively cover some potential target objects. According to the weights of the edges between the nodes in the data structure graph and the reference evaluation parameters of the nodes, the accuracy of the evaluation result of each object can be improved, and the object closely related to the target object can be accurately and quickly mined.
[0052] It should be noted that the server 100 described above can be a stand-alone physical server, a server cluster or a distributed system composed of multiple physical servers, or a cloud server providing cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, CDNs, and basic cloud computing services such as big data and artificial intelligence platforms. The terminal device 101 can be a smart phone, a tablet computer, a smart wearable device, a personal computer, and the like.
[0053] It can be understood that the data processing method provided in the embodiments of the present application can be executed by a computer device, which can be a terminal device or a server. For better illustration, the execution subject involved in the following embodiments is described by taking the server (such as the server 100 shown in the above Figure 2
[0054] Please refer to Figure 3 , Figure 3 is a flowchart of a data processing method provided by an embodiment of the present application. The data processing method includes but is not limited to the following steps:
[0055] S101, determine a target object and a set of associated objects of the target object, and construct a data structure diagram between the target object and the associated objects in the set of associated objects.
[0056] In an embodiment of the present application, the set of associated objects includes one or more of a first type of associated object and a second type of associated object, the first type of associated object includes an object having a common associated object with the target object, and the second type of associated object includes an object having a transaction relationship with the target object.
[0057] The set of associated objects of the target object includes objects directly or indirectly associated with the target object, wherein the first type of associated object is an object indirectly associated with the target object, and the indirect association here means that the first type of associated object and the target object have a common associated object, which not only represents the same object, but also an object whose behavior data meets the condition within a certain period of time, for example, the transaction amount exceeds the daily transaction amount, and the subsequent common transaction object is also the same. It can be considered that there is some common relationship between the common associated object, the target object and the first type of associated object. The second type of associated object is an object directly associated with the target object, i.e., an object having a direct transaction relationship, which is used to represent the transaction resource flow between the two parties, which can mean that the transaction resource flows from the target object to the second type of associated object. It should be noted that the first type of associated object and the second type of associated object can be one or more.
[0058] In an embodiment, the object can refer to an account, which is used to uniquely identify a user, and the target object, the associated object, the common associated object and the transaction object can refer to different types of accounts. For ease of understanding, taking the application of the data processing scheme provided by the present application in the anti-fraud scene as an example, the target object can refer to an abnormal account, the first type of associated object can refer to a first type of associated account indirectly associated with the abnormal account, the second type of associated object can refer to a second type of associated account directly associated with the abnormal account, and the first type of associated account and the second type of associated account can be referred to as associated accounts, and the common associated object can refer to a normal account having an association relationship with the abnormal account and the associated account, i.e., the normal account and the abnormal account have a complaint and being complained relationship, and the first type of associated account has a transaction relationship. The number of associated accounts and normal accounts is not limited here. It should be noted that the account and the account in the embodiments of the present application have the same meaning, i.e., representing the identity of the user.
[0059] The abnormal account is an account that is complained about and implements fraud on other users, and can be used as a seed account to mine the accounts associated with it, so as to detect a possible abnormal object set. In addition, not all complained accounts can be used as seed accounts, because the account may be complained about due to a dispute between the user of the account and other users, resulting in malicious or intentional complaints, and this part of the complained accounts are not real abnormal accounts. Therefore, in order to eliminate these malicious complaints or dispute cases, the daily user complaints can be screened by manual review or intelligent machine model before being used as a seed account. The seed account can be selected by manual review or machine model, and the specific screening process can refer to the attribute information of the complained account, which can be the number of complaints or the number of blacklists within a period of time, or virtual resource transaction information, or device information collected under user authorization (used to describe the behavior habits, operation state, etc. of the device operator), etc. without limitation. The seed account is selected from all complained accounts by analyzing the attribute information. In this way, by combining the information of the complained dimension and other reference dimension data, it can be ensured that the seed account screened is an account with high maliciousness, i.e. an account with a high possibility of implementing fraud on other users or an account that has implemented fraud. The associated account can be determined according to the multiple dimension information of the abnormal account (i.e. the seed account), such as the account data added by the seed account, the transaction information within a fixed period, the device information (such as device address, device model, device connection WiFi model, etc.) of the logged-in account, etc. without limitation.
[0060] The seed account is denoted as a class A account, the first type of associated account is denoted as a class B account, the second type of associated account is denoted as a class C account, and the normal account is denoted as a class V account. It should be noted that the V type node representing the V type account is not included in the following data structure diagram, but is used to assist in determining the first type of associated account. Alternatively, the first type of associated account can be obtained through the virtual resource expenditure relationship of the normal account, specifically by using the suspicious payment record of the normal account on the date of fraud to determine the first type of associated account. The suspicious payment record can be a record of transferring virtual resources to a newly added account, which can be regarded as the first type of associated account, and the first type of associated account can be regarded as a potential abnormal account. The reason for determining the first type of associated account in this way is that as the anti-black production becomes increasingly fierce, some fraudsters will use the method of switching numbers when receiving money, that is, using multiple accounts to receive virtual resources transferred from other accounts. These switched accounts are potential abnormal accounts, so by determining potential abnormal accounts through suspicious payments of normal accounts, the situation of switching accounts when receiving money by abnormal accounts can be effectively covered, and the detection coverage can be improved. Alternatively, the second type of associated account can be determined according to the transaction information of the seed account, and the payee of the seed account (that is, the object receiving the virtual resource transfer) can be regarded as the second type of associated account. It should be noted that if the suspicious payment account of the victim user and the complained account are the same, that is, the first type of associated account determined by the virtual resource expenditure relationship of the normal account can also be the seed account, then the first type of associated account is empty, that is, there is no situation of switching number when receiving money. That is, the abnormal account can be both an A type account and a B type account, and the node representing the first type of associated account is not included in the data structure diagram.
[0061] In the embodiment of the present application, the data structure diagram includes nodes for representing target objects and associated objects, and includes one or more of first type edges and second type edges. The first type edges are used to connect the nodes representing the target objects and the nodes representing the first type of associated objects, and the second type edges are used to connect the nodes representing the target objects and the nodes representing the second type of associated objects. The determination methods of the weights of the first type edges and the second type edges are different. That is, the data structure diagram includes one or more of the first type edges between the nodes representing the first type of associated objects and the nodes representing the target objects, and the second type edges between the nodes representing the second type of associated objects and the nodes representing the target objects, and each edge corresponds to a weight. The data structure diagram is a graph in computer science mentioned above, including nodes and edges. It can also be regarded as an entity relationship graph, each node is a different entity, representing different objects, and the relationship between entities is represented by edges (including directed edges and undirected edges). The first type edges are undirected edges, and the second type edges are directed edges.
[0062] Optionally, the weight of the first type of edge is determined according to the number of common associated objects between the target object and the first type of associated object, and the weight of the second type of edge is determined according to the transaction parameter between the target object and the second type of associated object. The specific expressions thereof can be seen in formula (1) and formula (2) respectively:
[0063] w1 = sigmoid (cx3) (1)
[0064] wherein x3 represents the number of common associated objects, c is an adjustment parameter,
[0065] w2 = sigmoid (ax1 + bx2) (2)
[0066] wherein x1 and x2 are transaction parameters, and a and b are adjustment parameters. Optionally, x1 and x2 can represent the transaction amount and the number of transactions respectively.
[0067] In the data structure diagram, the types of nodes can be divided into A-type nodes (corresponding to target objects), and B-type nodes (corresponding to the first type of associated objects) or C-type nodes (corresponding to the second type of associated objects) or both. The first type of edge between the A-type nodes and the B-type nodes is a non-directed edge, which connects the first type of associated objects and the second type of associated objects, indicating that the two types of objects have common associated objects. The second type of edge between the A-type nodes and the C-type nodes is a directed edge, with the direction being from the A-type nodes to the C-type nodes, indicating that the transaction resources flow from the A-type nodes to the C-type nodes. Exemplarily, as shown in Figure 4 a schematic diagram of an entity relationship diagram is shown, as shown in Figure 4 wherein sub-diagram (a) can be regarded as a data structure diagram, including a first type of edge (which can also be referred to as a common associated object edge) between the node A1 representing the target object and the node B1 representing the first type of associated object, and a second type of edge (which can also be referred to as a withdrawal edge) between the node A1 representing the target object and the node C1 representing the second type of associated object. Sub-diagram (b) shows the relationship diagram between the A-type nodes and the B-type nodes, having a common associated object V. It should be noted that, in order to emphasize the relationship between the objects, the data structure diagrams described below do not show the weights, but this does not mean that the corresponding edges in the data structure diagram do not have weights.
[0068] In one embodiment, the weight of each edge in the data structure diagram represents the ability to spread risk in anti-fraud or risk account identification scenarios. For the weight of the common victim edge, equation (1) represents the risk spreading ability. For the weight of the withdrawal edge, since a larger transaction amount and number of transactions indicate a closer relationship, the ability to spread risk is also stronger, and its spreading ability is as shown in equation (2). The reason for associating Class A accounts with Class B accounts is that it is rare for a victim to be defrauded by multiple abnormal objects on the same day. Therefore, the users corresponding to Class A and Class B accounts can be classified as one abnormal object set. It should be noted that when the target object is an abnormal account, each type of node in the data structure diagram corresponds to the account type, that is, a type A node can represent a type A account (abnormal account), a type B node can represent a type B account (a first-type associated account), a type C node can represent a type C account (a second-type associated account), and a type V node can represent a type V account (i.e., a normal account). In the anti-fraud scenario, considering that in fraud cases, the division of labor between various abnormal objects is clear, and there is also a clear hierarchical relationship, the abnormal account and the first-type associated account as a potential abnormal account can be considered as a first-level collection number, and there may be a second-level collection number above this first-level collection number. Therefore, the payment counterparty of the abnormal account can be considered as a second-level collection number, and whether it is an abnormal object in the same abnormal object set or the level of fraud risk can be further determined based on subsequent evaluation results. In addition, the embodiment of the present application constructs a data structure diagram for a certain target object and its associated objects, and can also merge the data structure diagrams corresponding to different target objects into an overall entity relationship diagram to mine closely related associated objects. Due to the merging of the same nodes between the data structure diagrams, a certain target object may also serve as an associated object of other target objects. In this way, in a specific application, the data structure diagram can be constructed in the same way for all seed accounts of a certain application platform, and then the data structure diagrams corresponding to each seed account can be merged to mine potential abnormal accounts. The potential abnormal account and the user corresponding to the seed account are abnormal objects in the same abnormal object set.
[0069] S102, determining a characteristic matrix of the data structure graph, and determining evaluation results corresponding to the target object and the associated objects respectively according to the reference evaluation matrix and the characteristic matrix.
[0070] In one embodiment, the characteristic matrix of a data structure graph includes an adjacency matrix and an association matrix. The adjacency matrix is an n×n matrix, where n represents the number of nodes, and the elements in the matrix are composed of the weights of the edges between each node. The association matrix is the degree matrix of the graph, which is an n×n diagonal matrix, and the elements on the diagonal are the degrees of each vertex. Optionally, the degree matrix can be determined by treating the data structure graph as an undirected graph. Figure 5A schematic diagram of an adjacency matrix and a degree matrix of a data structure graph is shown as follows, Figure 5 As shown, the example data structure graph includes 3 vertices (i.e., nodes) and 2 edges, and 0 in the adjacency matrix indicates that there is no association between two nodes, and the degree matrix is the number of edges associated with the vertex.
[0071] Optionally, the reference evaluation matrix is determined according to reference evaluation parameters corresponding to the target object and the associated object respectively, the reference evaluation parameters are initial evaluation values of the objects, and the reference evaluation parameters can be determined in an artificial manner or an intelligent model prediction manner.
[0072] In an embodiment, the manner of determining the evaluation results corresponding to the target object and the associated object respectively according to the reference evaluation matrix and the feature matrix can be: performing calculation on the adjacency matrix, the association degree matrix and the reference evaluation matrix to determine an intermediate evaluation matrix; performing calculation on the adjacency matrix, the association degree matrix and the intermediate evaluation matrix to determine a target evaluation matrix; and determining the evaluation results corresponding to the target object and the associated object respectively according to the target evaluation matrix. For convenience of description, the adjacency matrix of the data structure graph is denoted as A, the association degree matrix is denoted as D, and the reference evaluation matrix is denoted as X, and the specific expression of the evaluation results is:
[0073] H (1) =sigmoid((D -0.5 AD 0.5 +I)X),H (2) =sigmoid((D -0.5 AD 0.5 +I)H (1) ) (3)
[0074] Wherein, H (1) represents the intermediate evaluation matrix, sigmoid represents a nonlinear activation function, I is a unit matrix, and H (2) represents the target evaluation matrix. According to the corresponding relationship between the numerical values included in the target evaluation matrix and the objects, the evaluation results of the target object and the associated object can be determined. It should be noted that the calculation formula of the evaluation results is an aggregation function of the improved graph convolution network, wherein the reference evaluation parameters of the objects are introduced through IX, so that the final evaluation results are more reliable.
[0075] Taking the target object and the associated object as an account, the above reference evaluation parameter can be an initial risk value of the account, and the corresponding is also an initial risk value of each node in the data structure diagram. The process of obtaining the evaluation result based on the calculation of various matrices can be regarded as the process of risk propagation to obtain the final risk value. The specific risk propagation function adopts the content expressed in formula (3), the reference evaluation matrix refers to the initial risk matrix of the node, the element value included in the intermediate evaluation matrix is the value after one-time diffusion of the initial risk value of each node, and the evaluation result represents the final risk value of each node after the risk propagation after two-time diffusion.
[0076] In an embodiment, according to the risk score of the node, that is, the initial risk value of the account, the nodes included in the data structure diagram can be divided into black nodes and white nodes. The black node refers to a node with high risk degree, for example, a node representing an abnormal account. The white node refers to a node with low risk degree, that is, a node with low fraud possibility, for example, a node representing the payee of the abnormal account. The black nodes included in the data structure diagram are all assigned with initial risk values, and this part of the black nodes are a small part of known nodes representing high-risk abnormal accounts in the data structure diagram. In addition, most of them are unknown nodes, that is, the risk value and nature (including black node or white node) of the node are uncertain. These unknown nodes can also be assigned with initial risk values, which can be adjusted according to subsequent calculation. According to the risk degree of the node, the node can also be divided into four levels, including manual review qualitative, transaction model qualitative, strong rule qualitative and complaint record, which are four ways to determine the score, as shown in Table 1 below.
[0077] Category Score Manual review qualification s Transaction model qualification x Hard rule qualification y Complaint record z
[0078] Wherein, s>x>y>z, it is indicated that the account node score determined by artificial qualitative audit is the highest, the account score determined by transaction model is the second, the accounts obtained by strong rule screening and the accounts complained are the third, and the initial score of the remaining accounts which cannot be determined is 0. Among them, the transaction model, the strong rule and the complaint record are all ways of automatically calculating the node risk value by computer, the transaction model is a machine learning model with high intelligence, which can use big data analysis to mine rich and comprehensive rules for training, so that the model learns and determines the risk value of the node. The effect is equivalent to or better than artificial qualitative audit, while the rules learned by the strong rule are inferior to the transaction model, that is, the rules used are not as comprehensive and rich as the transaction model, and the complaint record is a more single judgment method. The determination of the initial risk value of each node can adopt one or more of the above-mentioned ways. For example, artificial qualitative audit can be used to obtain a node risk value with high accuracy, but considering the time cost and labor cost of artificial, the transaction model can also be used for qualitative determination, and all methods can be used to evaluate the node, and the maximum score is selected from the four scores as the initial risk value of the node. For example, the association between the account and other accounts can be combined to select the qualitative method, and then the initial risk value of the node is obtained.
[0079] The propagation formula of formula (3) can introduce the initial risk value of the node itself, so that the risk value of the node itself is relatively high, and will not be lowered after propagation, and the result of the second diffusion is taken as the final result, so that the final risk score of each node is referenced to the risk value of the second neighbor, which can ensure the reliability of the risk value of the node.
[0080] In summary, the embodiments of the present application have at least the following advantages:
[0081] By constructing the data structure diagram between the target object and the associated object, one or more of the first associated object having a common associated object with the target object and the second associated object having a transaction relationship are added to the construction of the data structure diagram, which can improve the coverage of different associated objects. The relationship between each object is represented by the feature matrix of the data structure diagram, and the reference evaluation matrix of the reference evaluation parameter of the object itself is combined to calculate the evaluation result, which can improve the accuracy and reliability of the evaluation result. When applied to the risk identification or anti-fraud scene, the improved aggregation function introducing the risk value of the node itself can ensure the sustainability of the node risk in the data structure diagram, improve the accuracy of the node risk value, and then quickly and accurately mine other high-risk accounts based on the accurate node risk value.
[0082] Please refer to Figure 6 , Figure 6is a flowchart of another data processing method provided by the embodiment of the present application. The data processing method comprises but is not limited to the following steps:
[0083] S201, determining a target object and a set of associated objects of the target object, and constructing a data structure graph between the target object and the associated objects in the set of associated objects.
[0084] In the embodiment, the set of associated objects comprises first-type associated objects, and the data structure graph is constructed based on the target object and the first-type associated objects.
[0085] S202, determining a transaction object having a transaction relationship with the first-type associated objects, and determining the transaction object as a third-type associated object associated with the target object.
[0086] In an embodiment, the transaction relationship with the first-type associated objects here refers to a relationship in which a transaction resource (such as a virtual resource) flows from the first-type associated objects to other objects except the target object. Since the first-type associated objects and the target object are also associated, and the transaction object and the first-type associated objects are directly associated, the transaction object can be regarded as a third-type associated object indirectly associated with the target object. Thus, the set of associated objects further comprises the third-type associated object. It should be noted that the difference between the third-type transaction object and the second-type associated object is that the directly associated objects are different, and the determined third-type associated object can also belong to the second-type associated object. Here, further expanding the associated objects through the transaction relationship can improve the coverage of the objects associated with the target object.
[0087] In an embodiment, taking the target object as an abnormal account as an example, the third-type associated object can refer to an account associated with the first-type associated account, which is simply understood as a payment account or a transaction account of the first-type associated account, and the transaction account can be a secondary collection account above the primary collection account (here, referring to the aforementioned B-type account, i.e., the first-type associated account), and it is also classified as a C-type account together with the second-type associated account. The account based on the diffusion evaluation of the B-type account can further cover each abnormal object in the abnormal object set, achieving fast and effective evaluation. In the following data structure graph, the connection between the third-type associated account and the first-type associated account also indicates that the transaction account can be an abnormal account corresponding to an abnormal object of the same abnormal object set as the target account.
[0088] S203, adjusting the data structure graph according to the third-type associated object, to obtain an adjusted data structure graph.
[0089] In an embodiment, after the third type of associated object is determined, the data structure graph originally constructed based on the target object and the first type of associated object is also adjusted accordingly, specifically, the third type of associated object and the relationship between the third type of associated object and the first type of associated object are added to the original data structure graph through nodes, edges and weights of the edges. Optionally, the adjusted data structure graph further includes a third type of edge, the third type of edge is used to connect the node representing the first type of associated object and the node representing the third type of associated object, and the weight of the third type of edge is determined according to the transaction parameter between the third type of associated object and the second type of associated object. The specific determination method is similar to the determination method of the second type of edge in the foregoing embodiment, and can be obtained by substituting the transaction parameter between the third type of associated object and the second type of associated object into formula (1). Details are omitted here.
[0090] In an embodiment, the set of associated objects further includes a second type of associated object, and when it is detected that the common transaction object between the second type of associated object and the third type of associated object satisfies a first set condition, the data structure graph is adjusted to obtain an adjusted data structure graph. The adjusted data structure graph further includes a fourth type of edge, the fourth type of edge is used to connect the node representing the third type of associated object and the node representing the second type of associated object, and the weight of the fourth type of edge is determined according to the number of common transaction objects between the third type of associated object and the second type of associated object.
[0091] The node representing the second type of associated object and the node representing the third type of associated object are both denoted as a C type node, and the third type of associated object and the second type of associated object can be the same. At this time, the node representing the target object and the node representing the first type of associated object included in the data structure graph after adjustment all point to a certain node, such as Figure 7 The data structure graph shown in FIG. 1A, A1 and B1 have the same transaction object C1, so after C1 is determined, the edge from B1 to C1 and the weight of the edge are directly added. When the second type of associated object and the third type of associated object are different, it is detected that the second type of associated object and the third type of associated object satisfy the first set condition, for example, as long as there is a common transaction object or the number of common transaction objects satisfies a certain number threshold, the data structure graph can be adjusted. Specifically, the node representing the second type of associated object and the node representing the third type of associated object are connected through an edge, and the nodes, edges and weights of the edges are updated. Here, the weight is determined in a manner similar to the manner of formula (2), by replacing the number of common associated objects in formula (2) with the number of common transaction objects of the fourth type of edge. It should be noted that the weight of the fourth type of edge can also be determined according to the transaction amount and the number of transactions, that is, in a manner similar to formula (1).
[0092] In an embodiment, when the third type of associated objects includes at least two, and the common transaction object between any two third type of associated objects satisfies the second set condition, the data structure graph is adjusted to obtain an adjusted data structure graph. The adjusted data structure graph further includes a fifth type of edge, the fifth type of edge is used to connect nodes representing any two third type of associated objects, and the weight of the fifth type of edge is determined according to the number of common transaction objects between any two third type of associated objects. Optionally, the second set condition and the first set condition can be the same condition or different conditions, which is not limited herein. The weight of the fifth type of edge can be determined in a similar manner as the fourth type of edge, according to the number of common transaction objects between the two third type of associated objects, or according to the transaction amount and the number of transactions with the common transaction object, and the specific calculation manner is the same as formula (1) or formula (2), which is not described herein. The fourth type of edge and the fifth type of edge can be referred to as common transaction object edges.
[0093] Exemplarily, please refer to Figure 9 , Figure 9 is another entity relationship graph shown in the embodiments of the present application, wherein subgraph (a) is a data structure graph adjusted according to the third type of associated objects, including a plurality of third type of associated objects, and edges and corresponding weights (not shown in the figure) exist between two nodes whose common transaction objects satisfy the set condition, D1 and D2 in subgraph (b) can be the same common transaction object, i.e., the common transaction object (for example, the common payee here) of the second type of associated object and the plurality of third type of associated objects is the same, or can be different common transaction objects. It should be noted that it is also feasible that the embodiments do not include the second type of associated object in the associated object set (i.e., do not include C1 directly associated with the target object), because subsequent judgment can be made according to the weight of each edge and the reference evaluation parameter of each object. When the associated object is an account, the common transaction object can refer to the common payee account of the third type of associated account and the second type of associated account.
[0094] It should be noted that when the second type of associated object includes at least two, that is, there are multiple second type of associated objects having a direct association relationship with the target object, and the third type of associated object also includes at least two, if the common transaction object between any two second type of associated objects satisfies the third set condition, the data structure diagram is adjusted to obtain an adjusted data structure diagram. In the adjusted data structure diagram, edges and edge weights between two second type of objects can also exist. The edge weight determination also adopts a similar determination method of the fifth type of edge, and details are not repeated here. Connecting two different second type of associated objects or two different third type of associated objects, or the second type of associated object and the third type of associated object, that is, connecting two different C type nodes, can effectively cover the objects with the same or similar transaction relationship, so that the connection between the associated objects is closer. Here, the associated objects obtained by continuing to spread the second type of associated object or the third type of associated object are not used. Whether the second type of associated object and the third type of associated object (that is, two different C type nodes) have a common transaction object can be determined to decide whether an edge exists between them. In this way, a large number of irrelevant objects can be avoided, and the influence of noise data can be reduced. For example Figure 8 As shown in the entity relationship diagram, subgraph (a) is a data structure diagram, which includes nodes A1, B1, C1, and C2 representing target objects, first type of associated objects, second type of associated objects, and third type of associated objects, respectively. Among them, the second type of associated object C1 and the third type of associated object C2 have a common transaction object, so there is an edge between the two nodes. Subgraph (b) represents the relationship between objects and common associated objects in the data structure diagram, and the V node representing the common associated object and the D node representing the common transaction object are not connected to the data structure diagram.
[0095] In an embodiment, the associated object set includes associated accounts. In the case of multiple associated accounts, the above method connects the edges of two related associated accounts to ensure that the size of the spread abnormal object set is large enough, and to combine as many abnormal objects belonging to the same abnormal object set as possible. However, if the payee of the associated account as a secondary account is used as a third level payee, a large amount of noise will be introduced. To solve this problem, the two associated accounts are connected, which reduces noise while ensuring that the abnormal object set is not split into multiple abnormal object sub-sets, so that a complete abnormal object set can be mined. The abnormal operation detection of the abnormal object can also apply the above data structure diagram to adapt to different fraud scenarios, including various fraud scenarios involving virtual resource transactions. The abnormal object set can be mined according to the graphing rules and node risk propagation without re-specifying rules, and the extension performance is good.
[0096] S204, determine the feature matrix of the adjusted data structure graph, and determine the evaluation results of the target object and the associated objects according to the reference evaluation matrix and the feature matrix.
[0097] In an embodiment, whether the relationship representation between the third type of associated object and the first type of associated object is added after one third type of associated object is determined, or the relationship representation between the third type of associated objects (or the second type of associated objects) is added after at least two third type of associated objects (or the second type of associated objects) are determined, the data structure graph is adjusted, and the feature matrix of the data structure graph also changes after each adjustment due to the addition of new nodes and edge weights. Therefore, the determination of the feature matrix of the data structure graph is to determine the feature matrix of the adjusted data structure graph. In addition, the reference evaluation matrix also adds new reference evaluation parameters of the associated objects due to the addition of nodes, that is, the adjustment of the data structure graph is accompanied by the adjustment of the feature matrix and the reference evaluation matrix. Based on the adjusted feature matrix and the reference evaluation matrix, the evaluation results of the target object and the associated objects are determined by using the same calculation method as in the previous embodiment. It should be noted that the above embodiment only constructs the data structure graph for one target object and evaluates the target object and the associated objects of the target object. Further, the above method can be used to construct a target data structure graph for all target objects that meet the conditions, the target data structure graph includes all target objects and associated objects determined according to each target object, and then each object is evaluated, and the corresponding processing is performed according to the evaluation results.
[0098] In an embodiment, after obtaining the evaluation results, the method further includes: when detecting a first transaction related to the interception object, intercepting the first transaction; and when detecting a second transaction related to the early warning object, performing early warning processing on the initiator of the second transaction; wherein the interception object includes an object whose evaluation value indicated by the evaluation results is greater than or equal to a first evaluation threshold, the early warning object includes an object whose evaluation value indicated by the evaluation results is greater than or equal to a second evaluation threshold and less than or equal to a third evaluation threshold, and the first evaluation threshold is greater than or equal to the third evaluation threshold.
[0099] The objects can be classified by different evaluation thresholds and evaluation results of the objects, to indicate the evaluation levels of the objects. The intercepting object is an object with a high evaluation level, and for a first transaction related to the intercepting object, including a transaction resource of other objects flowing to the intercepting object or a transaction resource of the intercepting object flowing to other intercepting objects, the server can automatically detect the first transaction and perform corresponding intercepting processing on the first transaction. The early warning object indicated by the evaluation value in the evaluation result between the second evaluation threshold and the third evaluation threshold, for a second transaction related to the early warning object, can mean that a transaction resource of an object flows to the early warning object, and the corresponding processing can be a warning prompt, for example, sending a prompt message to the object initiating the transaction. And for other objects less than the second evaluation threshold, the objects are low-risk fraud objects, and the transactions with the objects can be considered safe.
[0100] In an embodiment, taking a risk identification scenario as an example, the evaluation result can be a risk value of an account, the intercepting object in the first echelon is a high-risk fraud account, the early warning object in the second echelon is a medium-risk fraud account, and the object in the third echelon is a low-risk account. The specific intercepting processing for the high-risk account can be intercepting in the transaction process, for example, the other party cannot receive the virtual resource after the virtual resource is transferred out, or the virtual resource is directly returned to the original account, or intercepting before the transaction, for example, a normal user account cannot transfer virtual resources to the intercepting object, or the intercepting object cannot transfer virtual resources to a high-risk account of a superior. For a transaction that needs to be confirmed by a party receiving the transfer-in of virtual resources, the intercepting processing can also be to intercept in the way of invalid confirmation of the party receiving the transfer-in of virtual resources, and the like, and the specific intercepting manner is not limited here. In this way, the suspicious transaction of the newly added risk account online can be intercepted, so as to avoid the loss of virtual resources. The warning for the account initiating the transaction of the medium-risk account can be sending a prompt message such as "the account may have risks" or "trade carefully". The above data processing scheme is used in the interception of suspicious transactions of abnormal accounts, and when a user implements a fraud behavior and is complained, the accounts closely related to the user can be quickly associated, and the suspicious transactions of the accounts are intercepted. In terms of actual application effect, the scheme is applied to the in-process fraud strategy, and tens of thousands of payee accounts can be intervened every day, and the coverage rate of malicious accounts is improved by 5%.
[0101] In summary, the embodiments of the present application have at least the following advantages:
[0102] The second type of associated object and the third type of associated object that meet the conditions of the common transaction object, or two different second type of associated objects, or two different third type of associated objects are associated, the corresponding nodes are connected through edges in the data structure diagram, the associated objects can be connected together as much as possible, and meanwhile, other unnecessary associated objects are avoided to be introduced, and thus the noise is greatly reduced. According to the target object, the evaluation result can be determined in real time and quickly by using the above-mentioned mapping method, and the objects closely related to the target object can be quickly associated. When the target object and the associated object are account numbers, the suspicious transactions of the newly added high-risk accounts can be intercepted, and the timeliness and coverage of anti-fraud can be greatly improved.
[0103] Please refer to Figure 10 , Figure 10 is a flowchart of an application method based on an evaluation result provided by the embodiment of the application, and the application method based on the evaluation result includes but is not limited to the following steps:
[0104] S301, determining a target object and a set of associated objects of the target object, and constructing a data structure diagram between the target object and the associated objects in the set of associated objects.
[0105] S302, determining a feature matrix of the data structure diagram, and determining the evaluation results corresponding to the target object and the associated objects according to a reference evaluation matrix and the feature matrix.
[0106] The steps S301-S302 can refer to the steps S101-S102 in the foregoing Figure 3 corresponding embodiments, and details are not repeated here.
[0107] S303, receiving an evaluation result query request about a current transaction object sent by a client.
[0108] In an embodiment, the above-mentioned steps can construct an entity relationship graph between each object, and obtain the evaluation result of each object. The evaluation result is specifically applied to the client, which can be a function of providing the user with the evaluation result of the other object. The server can accept the evaluation result query request for the current transaction object sent by the terminal device. The query request can be triggered by the user clicking the corresponding function button in the terminal device or triggered by voice, which is not limited here. For example, when the current transaction object is an account number, the evaluation result can be a risk evaluation value of the current transaction account, which is used to indicate the risk level of the account in the network. The user makes a decision on whether to trade according to the risk level of the current transaction account in the network obtained by the query.
[0109] S304, responding to the evaluation result query request and returning indication information including the evaluation result of the current transaction object to the client.
[0110] In an embodiment, the indication information is used to indicate the client to display the evaluation result of the current transaction object. After receiving and responding to the evaluation result query request sent by the client for the current transaction object, the server returns the indication information including the evaluation result of the transaction object to the client, and the evaluation result displayed on the client based on the indication information can be a numerical value, a risk level, or other forms of results, which are not limited herein. Exemplarily, Figure 11 An effect schematic diagram of a client querying an evaluation result is shown, and the current transaction object is account A. By clicking the button of providing risk query at 1101 Figure 11 The evaluation result of the transaction object (account A) and the prompt speech returned by the screen of the terminal device can know the risk level of the account A.
[0111] In summary, the embodiments of the present application have the following advantages:
[0112] The evaluation result of each object is used to provide actual use functions for users, including providing the function of querying the evaluation result for the user, which can enrich the intelligent application scenarios of the evaluation result, and in the risk identification or anti-fraud scene, the user can avoid the transaction with risk in advance based on the queried evaluation result.
[0113] Please refer to Figure 12 , Figure 12 is a structural schematic diagram of a data processing apparatus provided by an embodiment of the present application. The data processing apparatus can be a computer program (including program code) running in a computer device, for example, the data processing apparatus is an application software; the apparatus can be used to execute the corresponding steps in the method provided by the embodiments of the present application. As Figure 12 shown, the data processing apparatus 120 can include a determination module 1201.
[0114] The determination module 1201 is configured to determine a target object and a set of associated objects of the target object, and construct a data structure graph between the target object and the associated objects in the set of associated objects.
[0115] The determination module 1201 is further configured to determine a feature matrix of the data structure graph, and determine the evaluation results corresponding to the target object and the associated objects respectively according to a reference evaluation matrix and the feature matrix, wherein the reference evaluation matrix is determined according to reference evaluation parameters corresponding to the target object and the associated objects respectively.
[0116] The data structure diagram includes nodes for representing the target object and the associated objects, the associated object set includes one or more of the first type of associated objects and the second type of associated objects, the data structure diagram includes one or more of the first type of edges and the second type of edges, the first type of edges are used to connect the nodes representing the target object and the nodes representing the first type of associated objects, the second type of edges are used to connect the nodes representing the target object and the nodes representing the second type of associated objects, the first type of associated objects include objects having common associated objects with the target object, the second type of associated objects include objects having transaction relationships with the target object, and the first type of edges and the second type of edges are determined in different ways.
[0117] In an embodiment, the determining module 1201 is specifically configured to determine the weight of the first type of edges according to the number of common associated objects between the target object and the first type of associated objects, and determine the weight of the second type of edges according to the transaction parameter between the target object and the second type of associated objects.
[0118] In an embodiment, the associated object set includes the first type of associated objects, and the data processing apparatus 120 further includes an adjusting module 1202, where:
[0119] The determining module 1201 is further configured to determine a transaction object having a transaction relationship with the first type of associated objects, and determine the transaction object as a third type of associated object associated with the target object.
[0120] The adjusting module 1202 is configured to adjust the data structure diagram according to the third type of associated object to obtain an adjusted data structure diagram, where the associated object set further includes the third type of associated object, the adjusted data structure diagram further includes a third type of edge, the third type of edge is used to connect the nodes representing the first type of associated objects and the nodes representing the third type of associated objects, and the weight of the third type of edge is determined according to the transaction parameter between the third type of associated object and the second type of associated object; and the determining module 1201 is further configured to determine a feature matrix of the adjusted data structure diagram.
[0121] In an embodiment, the associated object set further includes the second type of associated objects, and the adjusting module 1202 is further configured to: when detecting that a common transaction object existing between the second type of associated objects and the third type of associated objects meets a first set condition, adjust the data structure diagram to obtain an adjusted data structure diagram; the adjusted data structure diagram further includes a fourth type of edge, the fourth type of edge is used to connect the nodes representing the third type of associated objects and the nodes representing the second type of associated objects, and the weight of the fourth type of edge is determined according to the number of common transaction objects between the third type of associated object and the second type of associated object; and the determining module 1201 is further configured to determine a feature matrix of the adjusted data structure diagram.
[0122] In an embodiment, the adjusting module 1202 is further configured to: when the third type of associated objects include at least two, and the common transaction object between any two third type of associated objects meets the second set condition, adjust the data structure graph to obtain an adjusted data structure graph; wherein the adjusted data structure graph further includes a fifth type of edge, the fifth type of edge is used to connect nodes respectively representing any two third type of associated objects, and the weight of the fifth type of edge is determined according to the number of the common transaction object between any two third type of associated objects; and the determining module 1201 is further configured to determine a feature matrix of the adjusted data structure graph.
[0123] In an embodiment, the feature matrix includes an adjacency matrix and a correlation degree matrix, and the determining module 1201 is further configured to: calculate the adjacency matrix, the correlation degree matrix and a reference evaluation matrix to determine an intermediate evaluation matrix; calculate the adjacency matrix, the correlation degree matrix and the intermediate evaluation matrix to determine a target evaluation matrix; and determine the evaluation results corresponding to the target object and the associated object according to the target evaluation matrix.
[0124] In an embodiment, the data processing apparatus 120 further includes a receiving module 1203 and a sending module 1204, wherein: the receiving module 1203 is configured to receive an evaluation result query request about a current transaction object sent by a client; and the sending module 1204 is configured to return indication information including the evaluation result of the current transaction object to the client in response to the evaluation result query request, and the indication information is used to instruct the client to display the evaluation result of the current transaction object.
[0125] In an embodiment, the data processing apparatus 120 further includes an intercepting module 1205 and a warning module 1206, wherein:
[0126] The intercepting module 1205 is configured to intercept a first transaction when detecting the first transaction related to an intercepting object;
[0127] The warning module 1206 is configured to perform a warning process on an initiating object of a second transaction when detecting the second transaction related to a warning object; wherein the intercepting object includes an object whose evaluation value indicated by the evaluation result is greater than or equal to a first evaluation threshold, the warning object includes an object whose evaluation value indicated by the evaluation result is greater than or equal to a second evaluation threshold and less than or equal to a third evaluation threshold, and the first evaluation threshold is greater than or equal to the third evaluation threshold.
[0128] It can be understood that the functions of each functional module of the data processing apparatus described in the embodiments of the present application can be specifically implemented according to the methods in the above method embodiments, and the specific implementation process can refer to the related description of the above method embodiments, which will not be described here.
[0129] In the embodiments of the present application, by constructing the data structure graph representing the relationship between the target object and the associated object, in addition to introducing the second associated object having a transaction relationship with the target object, the first associated object having a common associated object with the target object can also be introduced, so as to mine the associated object having a direct relationship or an indirect relationship with the target object, which can effectively cover other associated objects that can have the same behavior as the target object, and improve the detection coverage. In addition, based on the feature matrix of the data structure graph, the reference evaluation matrix composed of the reference evaluation parameter information of the target object and the associated object, the final evaluation result can be obtained in combination with the initial evaluation information of the object itself, and the accuracy and reliability of the evaluation result can be effectively improved.
[0130] Please refer to Figure 13 , Figure 13 is a structural schematic diagram of a computer device 130 provided by the embodiments of the present application. The computer device 130 can include a stand-alone device (for example, one or more of servers, nodes, terminals, etc.) or components (for example, chips, software modules or hardware modules, etc.) inside the stand-alone device. The computer device 130 can include at least one processor 1301 and a communication interface 1302, and further optionally, the computer device 130 can also include at least one memory 1303 and a bus 1304. The processor 1301, the communication interface 1302 and the memory 1303 are connected through the bus 1304.
[0131] The processor 1301 is a module for performing arithmetic operations and / or logical operations, and can be one or a combination of a central processing unit (CPU), a graphics processing unit (GPU), a microprocessor unit (MPU), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA), a complex programmable logic device (CPLD), a co-processor (assisting the central processing unit to complete corresponding processing and application), a microcontroller unit (MCU), etc.
[0132] The communication interface 1302 can be used to provide information input or output for the at least one processor. And / or, the communication interface 1302 can be used to receive externally transmitted data and / or transmit data to the outside, which can be a wired link interface including an Ethernet cable, etc., or a wireless link (Wi-Fi, Bluetooth, general wireless transmission, vehicle-mounted short-range communication technology, and other short-range wireless communication technologies, etc.) interface.
[0133] The memory 1303 is used to provide storage space, in which data such as operating systems and computer programs can be stored. The memory 1303 can be one or a combination of random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM), or compact disc read-only memory (CD-ROM), etc.
[0134] The at least one processor 1301 in the computer device 130 is used to call the computer program stored in the at least one memory 1303, and is used to execute the foregoing data processing method, such as the data processing method described in the embodiment shown in FIG. 6. Figure 3 Figure 10 The computer device can be the server 100 in FIG. 1. Figure 2
[0135] In a possible implementation, the processor 1301 in the computer device 130 is configured to invoke a computer program stored in the at least one memory 1303, and perform the following operations: determining a target object and a set of associated objects of the target object, and constructing a data structure graph between the target object and associated objects in the set of associated objects; determining a feature matrix of the data structure graph, and determining evaluation results corresponding to the target object and the associated objects respectively according to a reference evaluation matrix and the feature matrix, the reference evaluation matrix being determined according to reference evaluation parameters corresponding to the target object and the associated objects respectively; wherein the data structure graph includes nodes representing the target object and the associated objects, the set of associated objects includes one or more of a first type of associated object and a second type of associated object, the data structure graph includes one or more of a first type of edge and a second type of edge, the first type of edge is used to connect the node representing the target object and the node representing the first type of associated object, the second type of edge is used to connect the node representing the target object and the node representing the second type of associated object, the first type of associated object includes an object having a common associated object with the target object, the second type of associated object includes an object having a transaction relationship with the target object, and the first type of edge and the second type of edge are determined in different manners.
[0136] In an embodiment, the processor 1301 is further configured to determine the weight of the first type of edge according to a number of common associated objects between the target object and the first type of associated object, and determine the weight of the second type of edge according to a transaction parameter between the target object and the second type of associated object.
[0137] In an embodiment, the set of associated objects includes the first type of associated object, and the processor 1301 is further configured to: determine a transaction object having a transaction relationship with the first type of associated object, and determine the transaction object as a third type of associated object associated with the target object; adjust the data structure graph according to the third type of associated object to obtain an adjusted data structure graph; wherein the set of associated objects further includes the third type of associated object; the adjusted data structure graph further includes a third type of edge, the third type of edge is used to connect the node representing the first type of associated object and the node representing the third type of associated object, and the weight of the third type of edge is determined according to a transaction parameter between the third type of associated object and the second type of associated object; and determine a feature matrix of the adjusted data structure graph.
[0138] In an embodiment, the set of association objects further includes a second type of association object, and the processor 1301 is further configured to: when detecting that the common transaction object between the second type of association object and the third type of association object meets a first set condition, adjusting the data structure graph to obtain an adjusted data structure graph; wherein the fourth type of edge is further included in the adjusted data structure graph, the fourth type of edge is used to connect the node representing the third type of association object and the node representing the second type of association object, and the weight of the fourth type of edge is determined according to the number of the common transaction object between the third type of association object and the second type of association object; and determining the feature matrix of the adjusted data structure graph.
[0139] In an embodiment, the processor 1301 is further configured to: when the third type of association object includes at least two, and the common transaction object between any two third type of association objects meets a second set condition, adjusting the data structure graph to obtain an adjusted data structure graph; wherein the fifth type of edge is further included in the adjusted data structure graph, the fifth type of edge is used to connect the nodes representing any two third type of association objects respectively, and the weight of the fifth type of edge is determined according to the number of the common transaction object between any two third type of association objects; and determining the feature matrix of the adjusted data structure graph.
[0140] In an embodiment, the feature matrix includes an adjacency matrix and a correlation matrix, and the processor 1301 is specifically further configured to: calculating the adjacency matrix, the correlation matrix and the reference evaluation matrix to determine an intermediate evaluation matrix; calculating the adjacency matrix, the correlation matrix and the intermediate evaluation matrix to determine a target evaluation matrix; and determining the evaluation results corresponding to the target object and the association object according to the target evaluation matrix.
[0141] In an embodiment, the processor 1301 is further configured to: receiving an evaluation result query request about the current transaction object sent by the client; and in response to the evaluation result query request, returning the indication information including the evaluation result of the current transaction object to the client, the indication information being used to instruct the client to display the evaluation result of the current transaction object.
[0142] In an embodiment, the processor 1301 is further configured to: when detecting a first transaction related to an interception object, intercepting the first transaction; and when detecting a second transaction related to a warning object, performing a warning process on an initiator of the second transaction; wherein the interception object includes an object whose evaluation value indicated by the evaluation result is greater than or equal to a first evaluation threshold, the warning object includes an object whose evaluation value indicated by the evaluation result is greater than or equal to a second evaluation threshold and less than or equal to a third evaluation threshold, and the first evaluation threshold is greater than or equal to the third evaluation threshold.
[0143] It should be understood that the computer device 130 described in the embodiments of the present application can perform the description of the data processing method in the foregoing corresponding embodiments, and can also perform the description of the data processing apparatus 120 in the foregoing corresponding embodiments, which will not be repeated here. Figure 12 The description of the data processing apparatus 120 in the foregoing corresponding embodiments will not be repeated here.
[0144] In the embodiments of the present application, by constructing the data structure graph representing the relationship between the target object and the associated object, in addition to introducing the second associated object having a transaction relationship with the target object, the first associated object having a common associated object with the target object can also be introduced, so as to mine the associated object having a direct relationship or an indirect relationship with the target object, which can effectively cover other associated objects that can have the same behavior as the target object, and improve the detection coverage. In addition, based on the feature matrix of the data structure graph, the reference evaluation matrix composed of the reference evaluation parameter information of the target object and the associated object, the final evaluation result can be obtained in combination with the initial evaluation information of the object itself, and the accuracy and reliability of the evaluation result can be effectively improved.
[0145] In addition, it should be pointed out that the embodiments of the present application also provide a storage medium in which the computer program of the foregoing data processing method is stored, and the computer program includes program instructions. When one or more processors load and execute the program instructions, the description of the data processing method in the embodiments can be implemented, and the description of the beneficial effects of using the same method will not be repeated here. It can be understood that the program instructions can be executed on one or more computer devices that can communicate with each other.
[0146] The embodiments of the present application also provide a computer program product or a computer program, which includes computer instructions stored in a computer readable storage medium. The processor of the computer device reads the computer instructions from the computer readable storage medium, and the processor executes the computer instructions, so that the computer device executes the steps performed in the embodiments of the methods described above.
[0147] Finally, it has to be noted that the terms "first", "second", and the like in the description and in the claims do not necessarily have to refer to a certain number or order of things, but can also refer to different states of one and the same thing. Moreover, the terms "comprises", "comprising", or the like should be interpreted as a non- limiting inclusion, such that a process or method or an apparatus or article that comprises one list of features is not necessarily restricted to the features of only that one list but can include other features that are not expressly listed or even other structural or functional entities that are not present or not expressly described. Furthermore, the terms "comprise", "comprising", or the like should be interpreted as a non- limiting inclusion, such that a process or method or an apparatus or article that comprises one list of features is not necessarily restricted to those features but can include other features not expressly listed or even other structural or functional entities that are not present or not expressly described.
[0148] The foregoing merely illustrates the principles of the application. It will thus be appreciated that those skilled in the art will be able to devise various arrangements which, although not explicitly described or shown herein, embody the principles of the application and are thus within its spirit and scope. Furthermore, all examples and conditional language recited herein are principally intended to be only for pedagogical purposes to aid the reader in understanding the principles of the application and the concepts contributed by the inventor to furthering the art, and are to be construed as being without limitation to such specifically recited examples and conditions.
Claims
1. A data processing method, characterized by, The method comprises: determining a target object and a set of associated objects of the target object, and constructing a data structure graph between the target object and the associated objects in the set of associated objects; the target object is an abnormal account; determining a feature matrix of the data structure graph, the feature matrix comprising an adjacency matrix and a correlation degree matrix; the adjacency matrix is used to indicate the weight of the edge between each node in the data structure graph, and the correlation degree matrix is used to indicate the number of edges connected to each node in the data structure graph; The adjacency matrix, the correlation degree matrix and a reference evaluation matrix are calculated to determine an intermediate evaluation matrix; the reference evaluation matrix is determined according to reference evaluation parameters corresponding to the target object and the correlation object respectively; the reference evaluation parameters are initial evaluation values, and the intermediate evaluation matrix is calculated based on a formula wherein, represents the intermediate evaluation matrix, sigmoid represents a nonlinear activation function, D represents the correlation degree matrix, A represents the adjacency matrix, I is an identity matrix, and X represents the reference evaluation matrix. The adjacency matrix, the correlation degree matrix and the intermediate evaluation matrix are calculated to determine a target evaluation matrix; the target evaluation matrix is based on a formula The calculation is The target evaluation matrix is represented by determining the evaluation results corresponding to the target object and the associated objects respectively according to the target evaluation matrix; wherein the data structure graph comprises nodes representing the target object and the associated objects, the set of associated objects comprises one or more of a first type of associated object and a second type of associated object, the data structure graph comprises one or more of a first type of edge and a second type of edge, the first type of edge is used to connect the node representing the target object and the node representing the first type of associated object, the second type of edge is used to connect the node representing the target object and the node representing the second type of associated object, the first type of associated object comprises an object having a common associated object with the target object, the second type of associated object comprises an object having a transaction relationship with the target object, and the determination method of the weight of the first type of edge and the weight of the second type of edge is different.
2. The method of claim 1, wherein, The weight of the first type of edge is determined according to the number of common associated objects between the target object and the first type of associated object, and the weight of the second type of edge is determined according to the transaction parameters between the target object and the second type of associated object.
3. The method of claim 1, wherein, The set of associated objects comprises the first type of associated object, and the method further comprises: determining a transaction object having a transaction relationship with the first type of associated object, and determining the transaction object as a third type of associated object associated with the target object; adjusting the data structure graph according to the third type of associated object to obtain an adjusted data structure graph; wherein the set of associated objects further comprises the third type of associated object; the adjusted data structure graph further comprises a third type of edge, the third type of edge is used to connect the node representing the first type of associated object and the node representing the third type of associated object, and the weight of the third type of edge is determined according to the transaction parameters between the third type of associated object and the second type of associated object; wherein the determination of the feature matrix of the data structure graph comprises: determining the feature matrix of the adjusted data structure graph.
4. The method of claim 3, wherein, The set of associated objects further comprises the second type of associated object, and the method further comprises: when it is detected that the common transaction object existing between the second type of associated object and the third type of associated object satisfies a first set condition, adjusting the data structure graph to obtain an adjusted data structure graph; The fourth type of edge is used for connecting the node representing the third type of associated object and the node representing the second type of associated object, and the weight of the fourth type of edge is determined according to the number of common transaction objects between the third type of associated object and the second type of associated object. The method further comprises: When the third type of associated object includes at least two, and the common transaction objects between any two third type of associated objects meet a second set condition, the data structure graph is adjusted to obtain an adjusted data structure graph; 5. The method of claim 3 or 4, wherein, The fifth type of edge is used for connecting the nodes representing the any two third type of associated objects respectively, and the weight of the fifth type of edge is determined according to the number of common transaction objects between the any two third type of associated objects. The method further comprises: The method further comprises: receiving an evaluation result query request about a current transaction object sent by a client; in response to the evaluation result query request, returning indication information including an evaluation result of the current transaction object to the client, the indication information being used to instruct the client to display the evaluation result of the current transaction object.
6. The method according to any one of claims 1 to 4, wherein The method further comprises: When a first transaction related to an interception object is detected, the first transaction is intercepted; When a second transaction related to a pre-warning object is detected, a pre-warning processing is performed on an initiator of the second transaction; 7. The method according to any one of claims 1 to 4, wherein The interception object includes an object whose evaluation value indicated by the evaluation result is greater than or equal to a first evaluation threshold, the pre-warning object includes an object whose evaluation value indicated by the evaluation result is greater than or equal to a second evaluation threshold and less than or equal to a third evaluation threshold, and the first evaluation threshold is greater than or equal to the third evaluation threshold. The method further comprises: The determination module is configured to determine a target object and a set of associated objects of the target object, and construct a data structure graph between the target object and the associated objects in the set of associated objects; the target object is an abnormal account; The determination module is further configured to determine a feature matrix of the data structure graph, the feature matrix including an adjacency matrix and a correlation degree matrix; the adjacency matrix is used to indicate the weight of the edge between each node in the data structure graph, and the correlation degree matrix is used to indicate the number of edges connected to each node in the data structure graph; 8. A data processing apparatus, characterized by, The adjacency matrix, the correlation degree matrix and a reference evaluation matrix are calculated to determine an intermediate evaluation matrix; The reference evaluation matrix is determined according to reference evaluation parameters corresponding to the target object and the associated object respectively; the reference evaluation parameters are initial evaluation values, and the intermediate evaluation matrix is calculated based on a formula wherein, represents the intermediate evaluation matrix, sigmoid represents a nonlinear activation function, D represents the correlation degree matrix, A represents the adjacency matrix, I is an identity matrix, and X represents the reference evaluation matrix. The adjacency matrix, the correlation degree matrix and the intermediate evaluation matrix are calculated to determine a target evaluation matrix; the target evaluation matrix is based on a formula The calculation is shown in the following formula: The target evaluation matrix is shown in the following formula: The evaluation results corresponding to the target object and the correlation object are determined according to the target evaluation matrix. The data structure graph includes nodes for representing the target object and the associated objects, the associated object set includes one or more of a first type of associated object and a second type of associated object, the data structure graph includes one or more of a first type of edge and a second type of edge, the first type of edge is used to connect the node representing the target object and the node representing the first type of associated object, the second type of edge is used to connect the node representing the target object and the node representing the second type of associated object, the first type of associated object includes an object having a common associated object with the target object, the second type of associated object includes an object having a transaction relationship with the target object, and the determination manner of the weight of the first type of edge and the weight of the second type of edge is different.
9. A computer device, comprising: Comprise: a processor, a memory and a network interface; the processor is connected with the memory and the network interface, wherein the network interface is used to provide network communication function, the memory is used to store program code, and the processor is used to call the program code to execute the data processing method in any one of claims 1-7.
10. A computer-readable storage medium, characterized in that, The computer readable storage medium stores a computer program, the computer program includes program instructions, and the program instructions are executed by the processor to execute the data processing method in any one of claims 1-7.
11. A computer program product, characterised in that, The computer program product includes computer instructions stored in a computer readable storage medium, and the computer instructions are read and executed by the processor from the computer readable storage medium, and are used for the data processing method in any one of claims 1-7.
Citation Information
Patent Citations
User detection method and device
CN104933570A
Association risk assessment method and device based on social data and electronic equipment
CN110349003A
Relationship determination method, device and system and electronic equipment
CN111563187A