Risk processing model training method, risk object processing method, and related devices
By displaying a feature selection page in the risk processing model and selecting target feature information, determining rule information, and training the generation model, the problem of low development efficiency in existing technologies is solved, and the rapid development of risk assessment and combat rules is realized.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- TENCENT TECHNOLOGY (SHENZHEN) CO LTD
- Filing Date
- 2021-10-27
- Publication Date
- 2026-05-22
AI Technical Summary
In existing technologies, the siloed approach to combating the black market results in developers spending a lot of time and energy, leading to low development efficiency and an inability to efficiently handle risk assessments and enforcement rules for different business types.
By displaying a risk feature selection page, users can select target risk assessment feature information, determine reference risk handling rule information, and train the risk handling model to generate a trained risk handling model, thereby enabling the rapid development of risk assessment and enforcement rules.
It improves the development efficiency of risk management models by quickly generating trained models through visualized risk feature selection and rule information determination, thereby improving development efficiency.
Smart Images

Figure CN116050520B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of data processing technology, specifically to a risk processing model training method, a risk object processing method, and related apparatus. The related apparatus includes a risk processing model training apparatus, a risk object processing apparatus, a computer device, and a computer-readable storage medium. Background Technology
[0002] With the development of internet technology, the traffic of popular online services such as social networking, short videos, and news highlights has grown rapidly. Simultaneously, a black market industry has emerged. This black market industry can be addressed through crackdowns. Current methods for combating this industry often employ a siloed approach. This approach extracts user accounts from the transaction logs of business-related crackdown requests, analyzes their behavior, and then uses expert experience to assess this behavior to determine the appropriate action. The action result is whether or not to take action against the user account. If it is determined that the user account should be targeted, the appropriate action rules are applied, resulting in the outcome of the crackdown.
[0003] The existing siloed attack method encompasses all data processing, feature calculation, and rule formulation from receiving business attack requests to outputting attack results, thus forming a siloed black box. As the number of business types increases, numerous independent silos emerge to attack different business types. This leads to developers spending a significant amount of time and energy developing siloed attack methods, resulting in low development efficiency. Summary of the Invention
[0004] This application provides a risk management model training method and related apparatus. The related apparatus includes a risk management model training device, a computer device, and a computer-readable storage medium, which can improve development efficiency.
[0005] A risk management model training method, comprising:
[0006] Displays a risk feature selection page, which includes risk assessment feature information for at least one dimension of the target risk object;
[0007] In response to a selection operation on risk assessment feature information, at least one target risk assessment feature information is selected from risk assessment feature information in at least one dimension;
[0008] Based on at least one target risk assessment feature, determine the reference risk treatment rule information;
[0009] Using a risk treatment model and at least one target risk assessment feature, predict risk treatment rule information for the target risk object;
[0010] Based on the risk handling rule information and the reference risk handling rule information of the target risk object, the risk handling model is trained to obtain the trained risk handling model.
[0011] Accordingly, embodiments of this application provide a risk management model training apparatus, comprising:
[0012] The display unit is used to display the risk feature selection page, which includes risk assessment feature information for at least one dimension of the target risk object.
[0013] A response unit is configured to, in response to a selection operation on risk assessment feature information, select at least one target risk assessment feature information from risk assessment feature information in at least one dimension;
[0014] The first determining unit is used to determine reference risk treatment rule information based on at least one target risk assessment feature information;
[0015] The first prediction unit is used to predict risk treatment rule information for the target risk object by using a risk treatment model and at least one target risk assessment feature information.
[0016] The training unit is used to train the risk processing model based on the risk processing rule information and the reference risk processing rule information of the target risk object, so as to obtain the trained risk processing model.
[0017] In some embodiments, the first determining unit may be specifically used to determine the sub-risk assessment logic information corresponding to each target risk assessment feature information; and to combine the sub-risk assessment logic information corresponding to each target risk assessment feature information to generate reference risk handling rule information for the target risk object.
[0018] In some embodiments, the first determining unit may be used to display a risk assessment logic editing page, which includes a component selection area and a logic editing area. The component selection area includes a logic unit component corresponding to at least one sub-risk assessment logic information of the target risk assessment feature information. In response to a selection operation for the target logic unit component, the target logic unit component is displayed in the logic editing area to obtain the sub-risk assessment logic information corresponding to each target risk assessment feature information.
[0019] In some embodiments, the first determining unit may be specifically used to establish connections between target logical unit components in response to a connection operation for the target logical unit components, so as to combine and process the sub-risk assessment logic information to obtain reference risk processing rule information for the target risk object, and the connections represent the execution order between the target logical unit components.
[0020] This application also provides a method for handling risky objects, including:
[0021] Obtain at least one target risk assessment characteristic information of the target risk object;
[0022] Based on at least one target risk assessment feature information, a post-trained risk processing model is used to predict the target risk object to obtain the risk processing rule information of the target risk object. The post-trained risk processing model is the aforementioned post-trained risk processing model.
[0023] Based on the risk handling rule information, determine the risk level of the risk handling rule information; based on the risk level, carry out risk handling on the target risk object.
[0024] Accordingly, embodiments of this application provide a risk object processing apparatus, including:
[0025] The acquisition unit can be used to acquire at least one target risk assessment feature information of the target risk object;
[0026] The second prediction unit can be used to predict the target risk object based on at least one target risk assessment feature information and a post-trained risk processing model to obtain the risk processing rule information of the target risk object. The post-trained risk processing model is as described above.
[0027] The second determining unit can be used to determine the risk level of the risk handling rule information based on the risk handling rule information;
[0028] The risk processing unit can be used to determine the risk level of the risk processing rule information based on the risk processing rule information; and to perform risk processing on the target risk object based on the risk level.
[0029] In some embodiments, the second determining unit may be specifically configured to: obtain the actual risk level of the risk handling rule information based on the risk handling rule information; and obtain a plurality of preset level threshold sets, wherein the preset level threshold sets include at least one preset level threshold; for each preset level threshold set, determine the candidate risk level of the risk handling rule information based on the preset level threshold in the preset level threshold set; determine the target level threshold set from the plurality of preset level threshold sets based on the actual risk level and the candidate risk level; and determine the risk level corresponding to the risk handling rule information based on the target level threshold set.
[0030] In some embodiments, the second determining unit may be specifically used to determine a target classification curve based on the actual risk level and candidate risk levels, wherein the target classification curve represents the classification of risk processing rule information for each preset level threshold set; obtain the slope of the target classification curve, wherein the slope represents the accuracy of risk processing rule information in classifying each preset level threshold set; and determine a target level threshold set from the preset level threshold set based on the slope of the target classification curve.
[0031] In some embodiments, the second determining unit may be specifically used to obtain a risk level mapping relationship set, which includes a mapping relationship between preset risk handling rule information and preset risk levels; and to determine the risk level corresponding to the risk handling rule information based on the risk level and the risk level mapping relationship set.
[0032] Furthermore, embodiments of this application also provide a computer device, including a memory and a processor; the memory stores a computer program, and the processor is used to run the computer program in the memory to execute any of the risk processing model training methods provided in embodiments of this application.
[0033] Furthermore, embodiments of this application also provide a computer-readable storage medium storing a computer program adapted for loading by a processor to execute any of the risk management model training methods provided in embodiments of this application.
[0034] Furthermore, embodiments of this application also provide a computer device, including a memory and a processor; the memory stores a computer program, and the processor is used to run the computer program in the memory to execute any of the risk object processing methods provided in embodiments of this application.
[0035] Furthermore, embodiments of this application also provide a computer-readable storage medium storing a computer program adapted for loading by a processor to execute any of the risk object processing methods provided in embodiments of this application.
[0036] This application embodiment can display a risk feature selection page, which includes risk assessment feature information on at least one dimension for a target risk object. In response to a selection operation on the risk assessment feature information, at least one target risk assessment feature is selected from the risk assessment feature information on the at least one dimension. Based on the at least one target risk assessment feature, reference risk handling rule information is determined. Using a risk handling model and the at least one target risk assessment feature, the risk handling rule information for the target risk object is predicted. Based on the risk handling rule information and the reference risk handling rule information for the target risk object, the risk handling model is trained to obtain a trained risk handling model. Because this application embodiment allows selection of risk assessment feature information on the risk feature selection page, selecting at least one target risk assessment feature, and presenting the risk assessment feature information in a visual form, target risk assessment feature information can be quickly selected. Based on the target risk assessment feature information, reference risk handling rule information can be determined, and risk handling rule information can be predicted, thereby accelerating the training of the risk handling model and improving development efficiency. Attached Figure Description
[0037] To more clearly illustrate the technical solutions in the embodiments of this application, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0038] Figure 1 This is a schematic diagram of a scenario for the risk management model training method provided in an embodiment of this application;
[0039] Figure 2 This is a flowchart illustrating the risk management model training method provided in an embodiment of this application;
[0040] Figure 3 This is a flowchart illustrating the process of generating reference risk handling rule information for target risk objects, as provided in an embodiment of this application.
[0041] Figure 4 This is a flowchart illustrating the process of determining the sub-risk assessment logic information corresponding to each target risk assessment feature information, as provided in the embodiments of this application.
[0042] Figure 5 This is a flowchart illustrating the risk object handling method provided in an embodiment of this application;
[0043] Figure 6 This is a flowchart illustrating the process of determining the risk level of risk handling rule information based on risk handling rule information, as provided in an embodiment of this application.
[0044] Figure 7 This is a schematic diagram of the grade threshold provided in the embodiments of this application;
[0045] Figure 8 This is a schematic diagram of the coordinate points on the ROC curve provided in the embodiments of this application;
[0046] Figure 9 These are two schematic flowcharts illustrating the risk object handling method provided in the embodiments of this application;
[0047] Figure 10 This is a schematic diagram of the risk feature selection page provided in an embodiment of this application;
[0048] Figure 11 This is a schematic diagram of the risk assessment logic editing page provided in an embodiment of this application;
[0049] Figure 12 This is a schematic diagram of the risk management model training device provided in the embodiments of this application;
[0050] Figure 13 This is a schematic diagram of the risk object processing device provided in the embodiments of this application;
[0051] Figure 14 This is a schematic diagram of the structure of the computer device provided in the embodiments of this application. Detailed Implementation
[0052] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.
[0053] This application relates to Artificial Intelligence (AI), which is the theory, method, technology, and application system that uses digital computers or machines controlled by digital computers to simulate, extend, and expand human intelligence, perceive the environment, acquire knowledge, and use that knowledge to obtain optimal results. In other words, AI is a comprehensive technology within computer science that attempts to understand the essence of intelligence and produce a new kind of intelligent machine that can react in a way similar to human intelligence. AI studies the design principles and implementation methods of various intelligent machines, enabling them to possess perception, reasoning, and decision-making capabilities.
[0054] Artificial intelligence (AI) is a comprehensive discipline encompassing a wide range of fields, including both hardware and software technologies. Fundamental AI technologies generally include sensors, dedicated AI chips, cloud computing, distributed storage, big data processing, operating / interactive systems, and mechatronics. AI software technologies primarily include computer vision, speech processing, natural language processing, and machine learning / deep learning.
[0055] This application provides a risk management model training method, a risk object processing method, and related apparatus. The related apparatus includes a risk management model training device, a risk object processing device, a computer device, and a computer-readable storage medium. The risk management model training device can be integrated into the computer device, which can be a server or a terminal, etc. The risk object processing device can also be integrated into the computer device, which can be a server or a terminal, etc.
[0056] The server can be a standalone physical server, a server cluster or distributed system composed of multiple physical servers, or a cloud server providing basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, content delivery network (CDN) acceleration services, and big data and artificial intelligence platforms. The terminal can be a smartphone, tablet, laptop, desktop computer, smart speaker, smartwatch, smart vehicle, etc., but is not limited to these. The terminal and server can be directly or indirectly connected via wired or wireless communication, which is not limited herein.
[0057] For example, see Figure 1 Taking the risk management model training device integrated into a computer device as an example, the computer device displays a risk feature selection page, which includes risk assessment feature information for at least one dimension of the target risk object; in response to the selection operation for the risk assessment feature information, at least one target risk assessment feature information is selected from the risk assessment feature information of at least one dimension; based on the at least one target risk assessment feature information, reference risk management rule information is determined; using the risk management model and the at least one target risk assessment feature information, the risk management rule information for the target risk object is predicted; based on the risk management rule information and the reference risk management rule information for the target risk object, the risk management model is trained to obtain the trained risk management model.
[0058] Among them, the target risk object can be represented in the form of an identifier, which includes account, device identifier, terminal identifier, website identifier, mobile phone number, etc.
[0059] The dimensions include basic attribute dimensions, account behavior dimensions, model dimensions, etc.
[0060] The risk assessment features for basic attributes include the identifier's credit score, a score indicating whether the identifier uses malicious software, the normality of the identifier's basic attributes, and whether the identifier is on a blacklist or whitelist. Basic attributes include the number of friends, registration time, and the completeness of the profile. Malicious software refers to software used for illicit activities; the illicit industry refers to industries that do not comply with pre-defined rules.
[0061] Account behavior dimensions include active and passive behavior dimensions. Risk assessment features for active behavior include the number of friends added, frequency of likes, content viewed, changes in account IP address, total number of messages posted, and number of groups joined. Risk assessment features for passive behavior include the number of times the account has had friends deleted, the number of times it has been kicked from groups, and the number of times it has been reported or complained about. Risk assessment features for account behavior dimensions can be derived from risk assessment data from different time periods.
[0062] The model dimension includes various sub-models that predict information about the target risk object. For example, a video understanding deep learning model can identify whether the image messages sent by an account contain advertisements that do not conform to preset rules, a video understanding deep learning model can identify whether the profile picture of an account contains QR codes that do not conform to preset rules, and a text semantic NLP model can identify whether the text sent by an account contains information that does not conform to preset rules, etc.
[0063] The reference risk processing rule information refers to the rule information obtained by using at least one sub-risk assessment logic information to assess the target risk assessment feature information. Sub-risk assessment logic information includes expert rules.
[0064] The following sections provide detailed descriptions of each example. It should be noted that the order in which the embodiments are described is not intended to limit the preferred order of the embodiments.
[0065] This embodiment will be described from the perspective of a risk management model training device, which can be integrated into a computer device, such as a server or a terminal. The terminal can include tablet computers, laptops, personal computers (PCs), wearable devices, virtual reality devices, or other smart devices that can acquire data.
[0066] like Figure 2As shown, the specific process of training this risk management model is as follows:
[0067] S101, Display the risk feature selection page.
[0068] The risk feature selection page includes risk assessment feature information for at least one dimension of the target risk object.
[0069] Among them, the target risk object can be represented in the form of an identifier, which includes account, device identifier, terminal identifier, website identifier, mobile phone number, etc.
[0070] The dimensions include basic attribute dimensions, account behavior dimensions, model dimensions, etc.
[0071] The risk assessment features for basic attributes include the identifier's credit score, a score indicating whether the identifier uses malicious software, the normality of the identifier's basic attributes, and whether the identifier is on a blacklist or whitelist. Basic attributes include the number of friends, registration time, and the completeness of the profile. Malicious software refers to software used for illicit activities; the illicit industry refers to industries that do not comply with pre-defined rules.
[0072] Account behavior dimensions include active and passive behavior dimensions. Risk assessment features for active behavior include the number of friends added, frequency of likes, content viewed, changes in account IP address, total number of messages posted, and number of groups joined. Risk assessment features for passive behavior include the number of times the account has had friends deleted, the number of times it has been kicked from groups, and the number of times it has been reported or complained about. Risk assessment features for account behavior dimensions can be derived from risk assessment data from different time periods.
[0073] The model dimension includes various sub-models that predict information about the target risk object. For example, a video understanding deep learning model can identify whether the image messages sent by an account contain advertisements that do not conform to preset rules, a video understanding deep learning model can identify whether the profile picture of an account contains QR codes that do not conform to preset rules, and a text semantic NLP model can identify whether the text sent by an account contains information that does not conform to preset rules, etc.
[0074] S102. In response to the selection operation for risk assessment feature information, select at least one target risk assessment feature information from risk assessment feature information in at least one dimension.
[0075] In this embodiment of the application, users can select risk assessment feature information on the risk feature selection page and select the target risk assessment feature information.
[0076] The selection operation includes clicking and dragging.
[0077] S103. Based on at least one target risk assessment feature information, determine reference risk treatment rule information.
[0078] The reference risk processing rule information refers to the rule information obtained by using at least one sub-risk assessment logic information to assess the target risk assessment feature information. The sub-risk assessment logic information includes rules set by experts.
[0079] like Figure 3 As shown, the process by which computer equipment generates reference risk handling rule information for the target risk object can be as follows:
[0080] A1. Determine the sub-risk assessment logic information corresponding to each target risk assessment feature information.
[0081] Among them, sub-risk assessment logic information refers to information used to assess the risk characteristics of the target risk assessment.
[0082] Each target risk assessment feature can correspond to a separate sub-risk assessment logic. For example, if the target risk assessment feature is the credit score of a WeChat account, the sub-risk assessment logic is: when the credit score of a WeChat account is greater than a first preset threshold, the WeChat account is not risky; when the credit score of a WeChat account is less than or equal to the first preset threshold, the WeChat account is risky.
[0083] In this embodiment of the application, at least two target risk assessment features can correspond to one sub-risk assessment logic. For example, the target risk assessment features include the credit score of a WeChat account and the credit score of a QQ account. The sub-risk assessment logic corresponding to the target risk assessment features is as follows: when the credit score of the WeChat account is greater than a first preset threshold and the credit score of the QQ account is greater than a second preset threshold, neither the WeChat account nor the QQ account is at risk; when the credit score of the WeChat account is less than or equal to the first preset threshold and the credit score of the QQ account is less than or equal to the second preset threshold, both the WeChat account and the QQ account are at risk.
[0084] The computer equipment can respond to user input commands and determine the sub-risk assessment logic information corresponding to each target risk assessment feature based on the input commands. That is, the user inputs code to construct the sub-risk assessment logic information corresponding to each target risk assessment feature.
[0085] like Figure 4 As shown, embodiments of this application can also use the following process to determine the sub-risk assessment logic information corresponding to each target risk assessment feature information:
[0086] a1. Display the risk assessment logic editing page.
[0087] The risk assessment logic editing page includes a component selection area and a logic editing area. The component selection area can be located on the left side of the risk assessment logic editing page, while the logic editing area is located on the right side.
[0088] The component selection area can be understood as a toolbox, which includes logical unit components corresponding to at least one sub-risk assessment logical information of the target risk assessment feature information. Each logical unit component corresponds to one sub-risk assessment logical information.
[0089] The risk assessment logic editing page can be triggered by a user performing a target operation on the computer device's display screen. This target operation can be a voice command, a triggering operation of virtual buttons on the computer device's display screen, etc. The risk assessment logic editing page can also be displayed based on the computer device's response to the confirmation control on the risk feature selection page.
[0090] a2. In response to the selection operation of the target logical unit component, the target logical unit component is displayed in the logic editing area to obtain the sub-risk assessment logic information corresponding to each target risk assessment feature information.
[0091] Among them, the selection operation for the target logical unit component can be a drag operation for the target logical unit component. For example, the computer device responds to the drag operation for the target logical unit component, and the position of the drag operation is the logical editing area. If the target logical unit component is detected in the logical editing area, the target logical unit component is displayed in the logical editing area.
[0092] Furthermore, for example, the computer device responds to a drag operation on a target logical unit component, and the position of the drag operation is a preset position in the logical editing area. If the target logical unit component is detected at the preset position, the target logical unit component is displayed at the preset position.
[0093] The selection operation for the target logical unit component can also be a click operation for the target logical unit component. For example, in response to a click operation for the target logical unit component in the component selection area, the computer device displays the target logical unit component in the logic editing area.
[0094] A2. Combine and process the sub-risk assessment logic information corresponding to each target risk assessment feature information to generate reference risk handling rule information for the target risk object.
[0095] The computer equipment can combine and process the sub-risk assessment logic information in a preset order. The preset order can be determined based on the dimensions of the target risk assessment feature information. For example, the order of the target risk assessment feature information in the basic attribute dimension takes precedence over the order of the target risk assessment feature information in the account behavior dimension, and the order of the target risk assessment feature information in the account behavior dimension takes precedence over the target risk assessment feature information in the model dimension.
[0096] Computer equipment can also use the following process to combine and process sub-risk assessment logic information:
[0097] Specifically, in response to a connection operation targeting a target logical unit component, the computer device establishes connections between the target logical unit components to combine and process the sub-risk assessment logic information to obtain reference risk handling rule information for the target risk object.
[0098] The connecting lines represent the execution order between the target logic unit components.
[0099] For example, the target risk object is a mobile phone account linked to a QQ account and a WeChat account. The target risk assessment features include the WeChat account's credit score, the QQ account's credit score, the number of times the WeChat account has had friends deleted, and whether the image messages sent by the QQ account contain advertisements that do not conform to preset rules. There are multiple sub-risk assessment logic pieces, including a first sub-risk assessment logic, a second sub-risk assessment logic, and a third sub-risk assessment logic. For example, the first sub-risk assessment logic is: when the WeChat account's credit score is greater than a first preset threshold, and the QQ account's credit score is greater than a second preset threshold, neither the WeChat account nor the QQ account is at risk; when the WeChat account's credit score is less than or equal to the first preset threshold, and the QQ account's credit score is less than or equal to the second preset threshold, both the WeChat account and the QQ account are at risk. Similarly, the second sub-risk assessment logic is: when the number of times a WeChat account has had friends deleted is greater than a third preset threshold, the WeChat account is at risk; when the number of times a WeChat account has had friends deleted is less than or equal to the third preset threshold, the WeChat account is not at risk. For example, the third sub-risk assessment logic is: if a QQ account sends an image message containing advertisements that do not conform to preset rules, the QQ account is at risk; if a QQ account sends an image message that does not contain advertisements that do not conform to preset rules, the QQ account is not at risk.
[0100] The target logic unit component includes a first target logic unit component, a second target logic unit component, and a third target logic unit component. The first target logic unit component corresponds to the first sub-risk assessment logic information, the second target logic unit component corresponds to the second sub-risk assessment logic information, and the third target logic unit component corresponds to the third sub-risk assessment logic information. In response to a connection operation targeting the target logic unit components, the computer device establishes a connection between the first and second target logic unit components, and also establishes a connection between the second and third target logic unit components. This yields the reference risk handling rule information for the target risk object.
[0101] Specifically, after establishing connections between target logical unit components in response to connection operations for target logical unit components, the computer device obtains a reference risk handling rule diagram for the target risk object; in response to the operation of the reference risk handling rule diagram, the computer device obtains reference risk handling rule information for the target risk object.
[0102] In this embodiment of the application, a running control can be set in the risk assessment logic editing page. By running the running control, reference risk handling rule information for the target risk object can be obtained. Running the running control can be done by clicking or touching the control.
[0103] For example, target risk assessment features include the WeChat account's credit score and the number of times the account has had friends deleted. The reference risk processing rule diagram includes target logic unit components and the connections between them. Target logic unit components include Target Logic Unit Component A and Target Logic Unit Component B, with Target Logic Unit Component A operating before Target Logic Unit Component B.
[0104] The sub-risk assessment logic information represented by Target Logic Unit Component A is as follows: When the credit score of a WeChat account is greater than the first preset threshold, the WeChat account is not risky; when the credit score of a WeChat account is less than or equal to the first preset threshold, the WeChat account is risky. The sub-risk assessment logic information represented by Target Logic Unit Component B is as follows: When the number of times a WeChat account has had friends deleted exceeds the third preset threshold, the WeChat account is risky; when the number of times a WeChat account has had friends deleted is less than or equal to the third preset threshold, the WeChat account is not risky.
[0105] The computer device, in response to an operation targeting a reference risk processing rule graph, runs the graph and obtains the judgment results of target logic unit component A and target logic unit component B. Target logic unit component A determines that the WeChat account is at risk, and target logic unit component B also determines that the WeChat account is at risk. Based on the judgment results of target logic unit components A and B, the computer device obtains reference risk processing rule information. This reference risk processing rule information can be represented as a score.
[0106] This application embodiment uses a risk assessment logic editing page to operate on target logic unit components to combine and process sub-risk assessment logic information. This method enables rapid arrangement of sub-risk assessment logic information and improves the generation efficiency of reference risk processing rule information.
[0107] S104. Using a risk treatment model and at least one target risk assessment feature, predict risk treatment rule information for the target risk object.
[0108] The risk treatment model can be either an LR logistic regression model or an XGBoost decision tree.
[0109] S105. Based on the risk handling rule information and the reference risk handling rule information of the target risk object, the risk handling model is trained to obtain the trained risk handling model.
[0110] In this embodiment, the reference risk processing rule information is the label, and the risk processing rule information is the predicted value. The loss value between the reference risk processing rule information and the risk processing rule information is calculated, and the risk processing model is trained based on this loss value until the risk processing model converges.
[0111] Specifically, when the risk processing model is an LR logistic regression model, the risk processing model is trained in this embodiment to obtain the weights of the risk assessment feature information; when the risk processing model is an XGBoost decision tree, the risk processing model is trained in this embodiment to obtain the tree split nodes.
[0112] This application embodiment can display a risk feature selection page, which includes risk assessment feature information on at least one dimension for a target risk object. In response to a selection operation on the risk assessment feature information, at least one target risk assessment feature is selected from the risk assessment feature information on the at least one dimension. Based on the at least one target risk assessment feature, reference risk handling rule information is determined. Using a risk handling model and the at least one target risk assessment feature, the risk handling rule information for the target risk object is predicted. Based on the risk handling rule information and the reference risk handling rule information for the target risk object, the risk handling model is trained to obtain a trained risk handling model. Because this application embodiment allows selection of risk assessment feature information on the risk feature selection page, selecting at least one target risk assessment feature, and presenting the risk assessment feature information in a visual form, target risk assessment feature information can be quickly selected. Based on the target risk assessment feature information, reference risk handling rule information can be determined, and risk handling rule information can be predicted, thereby accelerating the training of the risk handling model and improving development efficiency.
[0113] This embodiment will be described from the perspective of a risk object processing device, which can be integrated into a computer device, such as a server or a terminal. The terminal can include tablet computers, laptops, personal computers (PCs), wearable devices, virtual reality devices, or other smart devices that can acquire data.
[0114] like Figure 5 As shown, the specific process of this risk object handling method is as follows:
[0115] S201. Obtain at least one target risk assessment characteristic information of the target risk object.
[0116] Specifically, the computer device may acquire the target risk assessment feature information in response to a selection operation for the target risk assessment feature information on a risk feature selection page. Specifically, this can be as follows:
[0117] The computer device displays a risk feature selection page, which includes risk assessment feature information for at least one dimension of the target risk object; in response to a selection operation on the risk assessment feature information, at least one target risk assessment feature information is selected from the risk assessment feature information of at least one dimension.
[0118] S202. Based on at least one target risk assessment feature information, a trained risk processing model is used to predict the target risk object to obtain the risk processing rule information of the target risk object.
[0119] The post-training risk processing model is the same as described above. This model can be either an LR logistic regression model or an XGBoost decision tree model.
[0120] S203. Based on the risk handling rule information, determine the risk level of the risk handling rule information.
[0121] There are multiple risk levels, for example, in descending order of risk level are: first risk level, second risk level, third risk level, and fourth risk level.
[0122] Among them, risk handling rule information can be represented in the form of scores.
[0123] This application embodiment can pre-define the mapping relationship between risk handling rule information and risk level. Specifically, the computer device determines the range of the risk handling rule information based on the risk handling rule information; obtains a first mapping relationship set, which includes the mapping relationship between the preset range and the preset risk level; and determines the risk level of the risk handling rule information based on the first mapping relationship set and the range.
[0124] like Figure 6 As shown, the process by which computer equipment determines the risk level of risk handling rule information based on risk handling rule information can also be as follows:
[0125] B1. Based on the risk handling rule information, obtain the actual risk level of the risk handling rule information, and obtain a set of several preset level thresholds.
[0126] The actual risk level can be determined based on the assessment of reference risk handling rule information. For example, the reference risk handling rule information can be represented in the form of a score. Based on the reference risk handling rule information, a reference range for the reference risk handling rule information is determined; a second mapping relationship set is obtained, which includes the mapping relationship between the preset reference range and the preset actual risk level; based on the first mapping relationship set and the reference range, the actual risk level of the reference risk handling rule information is determined.
[0127] Since risk handling rule information can be represented in the form of scores, it can be compared with preset score thresholds to determine whether to handle the risk object.
[0128] For example, if the risk handling rule information is higher than or equal to a preset score threshold, it indicates that the target risk object is a safe object, and no risk handling is performed on the target risk object; if the risk handling rule information is lower than the preset score threshold, it indicates that the target risk object is a risky object, and risk handling is performed on the risky object. Based on this, the computer device compares the risk handling rule information with the preset score threshold. If the risk handling rule information is lower than the preset score threshold, it obtains the actual risk level of the risk handling rule information and a set of several preset level thresholds. The preset score threshold can be set to 0.5.
[0129] When the risk handling rule information is lower than the preset score threshold, at least one level threshold needs to be calculated, and the risk level is determined based on the level threshold, so as to handle the risk object according to the risk level.
[0130] For example, such as Figure 7 As shown, taking a scenario with three risk levels as an example, the risk levels are listed in ascending order of value: Level 1 Threshold, Level 2 Threshold, and Level 3 Threshold. Specifically, the range [0, Level 1 Threshold] represents the first risk level, the range (Level 1 Threshold, Level 2 Threshold) represents the second risk level, the range (Level 2 Threshold, Level 3 Threshold) represents the third risk level, and the range (Level 3 Threshold, Preset Score Threshold) represents the fourth risk level.
[0131] When the risk level is Level 1, the risk treatment for the target risk object is permanent account suspension; when the risk level is Level 2, the risk treatment for the target risk object is short-term account suspension; when the risk level is Level 3, the risk treatment for the target risk object is sending a verification code; when the risk level is Level 4, the risk treatment for the target risk object is rejection.
[0132] Since not every level threshold is reasonable when the risk handling rule information is below a preset score threshold, this application embodiment needs to calculate a more reasonable level threshold. Therefore, this application embodiment obtains a set of several preset level thresholds, wherein the preset level threshold set includes at least one preset level threshold.
[0133] The embodiments of this application can use the ROC curve evaluation method to calculate a reasonable level threshold. For example, as many values as possible are taken within the interval [0, preset score threshold), such as taking 500 preset level thresholds, and calculating each preset level threshold as an attempt value for the first level threshold, the second level threshold, and the third level threshold.
[0134] B2. For each preset level threshold set, determine the candidate risk level of the risk handling rule information based on the preset level threshold in the preset level threshold set.
[0135] In this embodiment, multiple candidate intervals are divided based on preset level thresholds in a preset level threshold set. Candidate risk levels are determined based on these candidate intervals, with each candidate interval corresponding to a specific candidate risk level. The candidate intervals within which risk handling rule information exists are then determined to ascertain the candidate risk level of the risk handling rule information.
[0136] B3. Based on the actual risk level and candidate risk levels, determine the target level threshold set from several preset level threshold sets.
[0137] Specifically, the computer equipment determines the target risk level threshold set from several preset risk level threshold sets based on the actual risk level and candidate risk levels, as follows:
[0138] The computer equipment determines the target classification curve based on the actual risk level and candidate risk levels. The target classification curve represents the classification of risk processing rules for each preset level threshold set. The slope of the target classification curve is obtained, and the slope represents the accuracy of risk processing rules for each preset level threshold set. Based on the slope of the target classification curve, the target level threshold set is determined from the preset level threshold set.
[0139] In this embodiment, the True Positive Rate (TPR) and Negative Positive Rate are determined based on the actual risk level and candidate risk levels. The formula for calculating the True Positive Rate (TPR) is: TPR = TP / (TP + FN). The True Positive Rate (TPR) represents the proportion of the candidate risk levels of the true positive classes predicted by the classifier based on the risk processing rule information to the candidate risk levels of all positive classes.
[0140] Positive candidate risk levels include true negative candidate risk levels (TP) and false negative candidate risk levels (FN). When the risk handling rule information is positive and the predicted candidate risk level is positive, this candidate risk level can be called the true negative candidate risk level (TP). When the risk handling rule information is positive and the predicted candidate risk level is negative, this candidate risk level can be called the false negative candidate risk level (FN).
[0141] The formula for calculating the positive-negative class ratio (FPR) is: FPR = FP / (FP + TN). The FPR represents the proportion of candidate risk levels of the false positive class obtained by the classifier from predicting risk processing rule information out of all candidate risk levels of the negative class.
[0142] The candidate risk levels for negative classes include the candidate risk level FP (false positive) and the candidate risk level TN (true negative). When the risk handling rule information is negative, but the predicted candidate risk level is positive, this candidate risk level can be called the candidate risk level FP (false positive). When the risk handling rule information is negative, but the predicted candidate risk level is negative, this candidate risk level can be called the candidate risk level TN (true negative).
[0143] This application's embodiments compare the actual risk level and the candidate risk level to determine whether the actual risk level is a positive or negative candidate risk level. For example, when the actual risk level and the candidate risk level are the same, the candidate risk level is a positive candidate risk level; when the actual risk level and the candidate risk level are different, the candidate risk level is a negative candidate risk level.
[0144] This application embodiment can compare risk handling rule information with reference risk handling rule information to determine whether the risk handling rule information is positive or negative. For example, when the reference risk handling rule information is the same as the risk handling rule information, the risk handling rule information is positive; when the reference risk handling rule information is different from the risk handling rule information, the risk handling rule information is negative.
[0145] This application embodiment determines the target classification curve based on the true positive rate and the negative / positive rate; the target classification curve is the ROC curve. The coordinate points on the ROC curve are shown below. Figure 8 As shown. The preset level threshold set is in Figure 8 The system can draw coordinate points, some of which are shown below. Figure 8 Points A, B, and C are shown in the diagram. Connecting all the coordinate points yields the ROC curve.
[0146] Among them, the point where the target classification curve is steepest corresponds to the lowest positive and negative class ratio (FPR) and the highest true positive class ratio (TPR), and the corresponding preset level threshold set is optimal. Based on this, embodiments of this application can determine the target level threshold set based on the slope of the target classification curve.
[0147] B4. Based on the target level threshold set, determine the risk level corresponding to the risk handling rule information.
[0148] Specifically, the process by which computer equipment determines the risk level corresponding to risk handling rule information based on a set of target level thresholds can be as follows:
[0149] The computer equipment acquires a set of risk level mapping relationships, which includes the mapping relationship between preset risk handling rule information and preset risk levels; based on the risk level and the set of risk level mapping relationships, the risk level corresponding to the risk handling rule information is determined.
[0150] S204. Based on the risk level, perform risk management on the target risk object.
[0151] This application embodiment applies different risk treatments to target risk objects according to different risk levels. Risk treatments include permanent account bans, short-term account bans, sending verification codes, and rejection processing.
[0152] For example, the risk levels, ranked from highest to lowest, are: Level 1, Level 2, Level 3, and Level 4. When the risk level is Level 1, the target account is permanently banned; when it's Level 2, the account is temporarily banned; when it's Level 3, a verification code is issued; and when it's Level 4, the account is rejected.
[0153] As can be seen from the above, the embodiments of this application can obtain at least one target risk assessment feature information of the target risk object; based on the at least one target risk assessment feature information, a trained risk processing model is used to predict the target risk object to obtain risk processing rule information of the target risk object, wherein the trained risk processing model is the aforementioned trained risk processing model; based on the risk processing rule information, the risk level of the risk processing rule information is determined; and based on the risk level, risk processing is performed on the target risk object. Since the embodiments of this application can directly use the trained risk processing model to predict the target risk object, risk processing rule information can be obtained quickly, thus enabling rapid risk processing of the target risk object based on the risk processing rule information.
[0154] Based on the method described in the above embodiments, the following examples will provide further detailed explanations.
[0155] In this embodiment, the risk object processing device is specifically integrated into a computer device, which serves as a server.
[0156] like Figure 9 As shown, a method for handling risky objects has the following specific process:
[0157] S301, Computer equipment displays a risk feature selection page.
[0158] The risk feature selection page includes risk assessment feature information for the target risk object across at least one dimension. Dimensions include basic attribute dimensions, account behavior dimensions, model dimensions, etc.
[0159] Among them, the target risk object can be represented in the form of an identifier, which includes account, device identifier, terminal identifier, website identifier, mobile phone number, etc.
[0160] like Figure 10 As shown, the risk feature selection page has multiple dimension controls, such as basic attribute dimension controls, account behavior dimension controls, and model dimension controls. The basic attribute dimension controls correspond to the risk assessment feature information of the basic attribute dimension, the account behavior dimension controls correspond to the risk assessment feature information of the account behavior dimension, and the model dimension controls correspond to the risk assessment feature information of the model dimension.
[0161] In response to a trigger operation on a dimension control, the computer device displays the risk assessment feature information of that dimension control on the risk feature selection page. For example, in response to a trigger operation on a basic attribute dimension control, the risk assessment feature information under the account behavior dimension corresponding to the basic attribute dimension control is displayed on the risk feature selection page. The risk assessment feature information under the account behavior dimension includes QQ account credit score, number of friends, and whether black market software is used.
[0162] S302, The computer device, in response to a selection operation for risk assessment feature information, selects at least one target risk assessment feature information from risk assessment feature information in at least one dimension.
[0163] like Figure 10 As shown, for example, clicking on risk assessment features such as QQ account credit score on the risk feature selection page will select the risk assessment features such as QQ account credit score.
[0164] A confirmation control can also be set on the risk characteristic selection page. In response to a click on this confirmation control, the computer device displays the risk assessment logic editing page.
[0165] This application embodiment can abstract risk assessment feature information into visualized basic attribute dimensions, account behavior dimensions, model dimensions, and other dimensions of risk assessment feature information. Developers can select the risk assessment feature information among them for development, which has real-time performance.
[0166] S303. The computer equipment determines reference risk handling rule information based on at least one target risk assessment feature information.
[0167] Specifically, the computer device displays a risk assessment logic editing page. For example... Figure 11As shown, the risk assessment logic editing page includes a component selection area and a logic editing area. The component selection area is located on the left side of the risk assessment logic editing page, and the logic editing area is located on the right side of the page.
[0168] The component selection area includes at least one logical unit component corresponding to at least one sub-risk assessment logical information of the target risk assessment feature information. For example, the component selection area includes a first logical unit component, a second logical unit component, a third logical unit component, and a fourth logical unit component, where the first logical unit component is the logical unit component corresponding to the first sub-risk assessment logical information, the second logical unit component is the logical unit component corresponding to the second sub-risk assessment logical information, the third logical unit component is the logical unit component corresponding to the third sub-risk assessment logical information, and the fourth logical unit component is the logical unit component corresponding to the fourth sub-risk assessment logical information.
[0169] The target risk object is a mobile phone number linked to both a WeChat account and a QQ account. The first sub-risk assessment logic is as follows: if the WeChat account's credit score is greater than a first preset threshold and the QQ account's credit score is greater than a second preset threshold, neither the WeChat account nor the QQ account is considered risky; if the WeChat account's credit score is less than or equal to the first preset threshold and the QQ account's credit score is less than or equal to the second preset threshold, both the WeChat account and the QQ account are considered risky. For example, the second sub-risk assessment logic is as follows: if a WeChat account has had more than a third preset threshold of deleted friends, the WeChat account is considered risky; if the number of deleted friends is less than or equal to the third preset threshold, the WeChat account is not considered risky. Similarly, the third sub-risk assessment logic is as follows: if a QQ account sends image messages containing advertisements that do not conform to preset rules, the QQ account is considered risky; if a QQ account sends image messages that do not contain advertisements that do not conform to preset rules, the QQ account is not considered risky. For example, the fourth sub-risk assessment logic is: if the number of complaints and reports against a WeChat account is greater than the fourth preset threshold, the WeChat account is at risk; if the number of complaints and reports against a WeChat account is less than or equal to the fourth preset threshold, the WeChat account is not at risk.
[0170] Specifically, in response to a selection operation on a target logical unit component, the computer device displays the target logical unit component in the logical editing area and obtains the sub-risk assessment logical information corresponding to each target risk assessment feature information.
[0171] For example, the computer device responds to a drag-and-drop operation targeting a target logical unit component, and the drag-and-drop operation is performed at a preset position in the logical editing area. If the target logical unit component is detected at the preset position, it is displayed there. In this way, target logical units, including a first logical unit component, a second logical unit component, and a third logical unit component, are selected and displayed in the logical editing area.
[0172] In response to a connection operation targeting a logical unit component, the computer device establishes connections between the target logical unit components to combine and process the sub-risk assessment logic information, thereby obtaining reference risk handling rule information for the target risk object. The connections represent the execution order between the target logical unit components.
[0173] For example, the first logic unit component is connected to the second logic unit component, and the second logic unit component is connected to the third logic unit component.
[0174] The component selection area may include a start component and connection components. In response to a selection operation on the start component, the computer device displays the start component in the logic editing area. In response to a selection operation on the connection components, the computer device displays the connection components in the logic editing area. When a connection component is detected at a preset position in the logic editing area, connections are established between target logical unit components, and connections are established between the target logical unit components and the start component, thus obtaining a reference risk handling rule diagram for the target risk object.
[0175] The risk assessment logic editing page can also include a run control. In response to a click on the run control, the reference risk handling rule diagram is run to generate reference risk handling rule information for the target risk object.
[0176] The execution of the reference risk processing rule diagram in this application embodiment requires the execution of a script, which includes conditional statements, parallel statements, serial statements, etc.
[0177] For example, by running the reference risk handling rule graph and making judgments through the target logic unit component, Rule 1 is obtained. Rule 1 includes the judgment results of the first logic unit component, the second logic unit component, and the third logic unit component. The first logic unit component's judgment result: When the credit score of a WeChat account is less than or equal to a first preset threshold, and the credit score of a QQ account is less than or equal to a second preset threshold, both the WeChat account and the QQ account are considered risky. The second logic unit component's judgment result: When the number of times a WeChat account has had friends deleted exceeds a third preset threshold, the WeChat account is considered risky. The third logic unit component's judgment result: When a QQ account sends image messages containing advertisements that do not conform to preset rules, the QQ account is considered risky. Based on Rule 1, reference risk handling rule information for Rule 1 is generated. The reference risk handling rule information can be represented in the form of a score.
[0178] Based on the above method, different rules can be determined, such as rule 1, rule 2, and rule n, where n is a positive integer; and reference risk handling rule information corresponding to each rule can be determined, as shown in Table 1.
[0179]
[0180] Table 1
[0181] In the embodiments of this application, risk assessment feature information and reference risk processing rule information in at least one dimension can influence risk processing rule information, thereby refining the risk processing model's prediction of risk processing rule information and improving the prediction performance of the trained risk processing model.
[0182] S304. The computer equipment uses a risk processing model and at least one target risk assessment feature information to predict risk processing rule information for the target risk object.
[0183] The risk treatment model can be either an LR logistic regression model or an XGBoost decision tree.
[0184] S305. The computer equipment trains the risk processing model based on the risk processing rule information and the reference risk processing rule information of the target risk object, and obtains the trained risk processing model.
[0185] In this embodiment, the reference risk processing rule information is the label, and the risk processing rule information is the predicted value. The embodiment calculates the loss value between the reference risk processing rule information and the risk processing rule information, and trains the risk processing model based on this loss value until the risk processing model converges.
[0186] As shown in Table 1, the risk assessment feature information of the basic attribute dimension, the risk assessment feature information of the account behavior dimension, the risk assessment feature information of the model dimension, and the reference risk handling rule information are standardized to a value range of 0-1, which is conducive to the rapid convergence of the model.
[0187] In this embodiment, risk assessment feature information of basic attribute dimension, risk assessment feature information of account behavior dimension, and risk assessment feature information of model dimension are used as samples, and risk processing rule information is used as labels to train the risk processing model.
[0188] Specifically, when the risk processing model is an LR logistic regression model, the risk processing model is trained in this embodiment to obtain the weights of the risk assessment feature information; when the risk processing model is an XGBoost decision tree, the risk processing model is trained in this embodiment to obtain the tree split nodes.
[0189] This application embodiment can utilize the weights of various risk assessment feature information to evaluate the impact of each risk assessment feature information on risk treatment rule information, filter out important risk assessment feature information, and eliminate invalid risk assessment feature information. Since this application embodiment is applied to the risk treatment of target risk objects, a small number of important risk assessment feature information can often accurately determine the risk treatment rule information. Previously, a large number of other invalid risk assessment feature information often consumed significant computational and storage costs due to the lack of an effective evaluation system. Therefore, establishing an effective evaluation system is essential to provide quality assurance for mining more massive amounts of risk assessment feature information.
[0190] In this embodiment of the application, during the training process of the risk processing model, a large amount of risk assessment feature information affects the risk processing model, thereby making the trained risk processing model more adversarial.
[0191] S306. The computer equipment acquires at least one target risk assessment characteristic information of the target risk object.
[0192] In this embodiment, a risk feature selection page as described above can be displayed. The risk feature selection page includes risk assessment feature information for at least one dimension of the target risk object; in response to a selection operation on the risk assessment feature information, the computer device selects at least one target risk assessment feature information from the risk assessment feature information of at least one dimension.
[0193] S307. The computer equipment, based on at least one target risk assessment feature information, uses a trained risk processing model to predict the target risk object and obtain the risk processing rule information of the target risk object.
[0194] The post-training risk handling model is the same as the aforementioned post-training risk handling model.
[0195] S308. Computer equipment determines the risk level of risk processing rule information based on risk processing rule information.
[0196] Specifically, the computer equipment obtains the actual risk level of the risk handling rule information based on the risk handling rule information, and obtains several preset level threshold sets, each preset level threshold set including at least one preset level threshold; for each preset level threshold set, it determines the candidate risk level of the risk handling rule information based on the preset level thresholds in the preset level threshold set; based on the actual risk level and the candidate risk level, it determines the target level threshold set from the several preset level threshold sets; and based on the target level threshold set, it determines the risk level corresponding to the risk handling rule information.
[0197] Specifically, the computer equipment determines a target classification curve based on the actual risk level and candidate risk levels. The target classification curve represents the classification of risk processing rules for each preset level threshold set. The slope of the target classification curve is obtained, and the slope represents the accuracy of risk processing rules for each preset level threshold set. Based on the slope of the target classification curve, a target level threshold set is determined from the preset level threshold set.
[0198] Specifically, the computer equipment acquires a set of risk level mapping relationships, which includes the mapping relationship between preset risk handling rule information and preset risk levels; based on the risk level and the set of risk level mapping relationships, the risk level corresponding to the risk handling rule information is determined.
[0199] S309. Computer equipment performs risk management on target risk objects based on risk level.
[0200] This application embodiment applies different risk treatments to target risk objects according to different risk levels. Risk treatments include permanent account bans, short-term account bans, sending verification codes, and rejection processing.
[0201] This application embodiment can display the risk processing results obtained from risk processing of the target risk object on the risk feature selection page. Risk processing results include permanent account suspension, short-term account suspension, sending a verification code, and rejection. For example... Figure 10 As shown, the risk feature selection page has a risk handling result control. When the computer device responds to the click operation on the risk handling result control, it displays the risk handling result for the target risk object on the risk feature selection page.
[0202] For example, when targeting a high-risk account, a trained risk processing model is used to predict its activity. The model identifies the account as using fake IPs, bots, or black market software for login, resulting in a very low score on its basic attribute dimension, indicating a risky account. Furthermore, the account exhibits abnormal proactive behavior: adding a large number of friends in a short period, frequently joining multiple groups, and sending a large number of messages. It also passively experiences being blocked and kicked out of groups multiple times, further indicating a low score on its behavioral dimension, also suggesting a risky account. The image messages sent by the target account are analyzed using a segmentation model, revealing QR codes and text / image information that does not conform to preset rules, resulting in a low score on the model dimension, indicating a risky account. Based on a comprehensive assessment of all features, the target account can be broadly defined as a black market account. Assuming the risk processing rule information score predicted by the trained risk processing model is 0.1, the risk level corresponding to the range of 0.1 is determined, and risk processing is then linked to a short-term account suspension level based on this risk level.
[0203] For details on the implementation of each of the above operations, please refer to the previous examples, which will not be repeated here.
[0204] This application embodiment can display a risk feature selection page, which includes risk assessment feature information on at least one dimension for a target risk object. In response to a selection operation on the risk assessment feature information, at least one target risk assessment feature is selected from the risk assessment feature information on the at least one dimension. Based on the at least one target risk assessment feature, reference risk handling rule information is determined. Using a risk handling model and the at least one target risk assessment feature, the risk handling rule information for the target risk object is predicted. Based on the risk handling rule information and the reference risk handling rule information for the target risk object, the risk handling model is trained to obtain a trained risk handling model. Because this application embodiment allows selection of risk assessment feature information on the risk feature selection page, selecting at least one target risk assessment feature, and presenting the risk assessment feature information in a visual form, target risk assessment feature information can be quickly selected. Based on the target risk assessment feature information, reference risk handling rule information can be determined, and risk handling rule information can be predicted, thereby accelerating the training of the risk handling model and improving development efficiency.
[0205] To better implement the above methods, this application also provides a risk management model training device, which can be integrated into a computer device, such as a server or terminal. The terminal may include a tablet computer, a laptop computer, and / or a personal computer.
[0206] For example, such as Figure 12As shown, the risk management model training device may include a display unit 301, a response unit 302, a first determination unit 303, a first prediction unit 304, and a training unit 305, as follows:
[0207] (1) Display unit 301;
[0208] Display unit 301 is used to display a risk feature selection page, which includes risk assessment feature information for at least one dimension of the target risk object.
[0209] (2) Response unit 302;
[0210] The response unit 302 can be used to select at least one target risk assessment feature from risk assessment feature information in at least one dimension in response to a selection operation for risk assessment feature information.
[0211] (3) First determining unit 303;
[0212] The first determining unit 303 can be used to determine reference risk treatment rule information based on at least one target risk assessment feature information.
[0213] In some embodiments, the first determining unit 303 may be specifically used to determine the sub-risk assessment logic information corresponding to each target risk assessment feature information; and to combine the sub-risk assessment logic information corresponding to each target risk assessment feature information to generate reference risk handling rule information for the target risk object.
[0214] In some embodiments, the first determining unit 303 may be specifically used to display a risk assessment logic editing page. The risk assessment logic editing page includes a component selection area and a logic editing area. The component selection area includes a logic unit component corresponding to at least one sub-risk assessment logic information of the target risk assessment feature information. In response to the selection operation of the target logic unit component, the target logic unit component is displayed in the logic editing area to obtain the sub-risk assessment logic information corresponding to each target risk assessment feature information.
[0215] In some embodiments, the first determining unit 303 may be specifically used to establish connections between target logical unit components in response to a connection operation for the target logical unit components, so as to combine and process the sub-risk assessment logic information to obtain reference risk processing rule information for the target risk object, and the connections represent the execution order between the target logical unit components.
[0216] (4) First prediction unit 304;
[0217] The first prediction unit 304 can be used to predict risk treatment rule information for a target risk object by using a risk treatment model and at least one target risk assessment feature information.
[0218] (5) Training Unit 305;
[0219] Training unit 305 can be used to train the risk processing model based on risk processing rule information and reference risk processing rule information of the target risk object, so as to obtain the trained risk processing model.
[0220] As can be seen from the above, the display unit 301 of this application embodiment can display a risk feature selection page, which includes risk assessment feature information for at least one dimension of the target risk object; the response unit 302 can respond to the selection operation of the risk assessment feature information and select at least one target risk assessment feature information from the risk assessment feature information for at least one dimension; the first determining unit 303 can determine reference risk handling rule information based on at least one target risk assessment feature information; the first prediction unit 304 can use a risk handling model and at least one target risk assessment feature information to predict risk handling rule information for the target risk object; and the training unit 305 can train the risk handling model based on the risk handling rule information and the reference risk handling rule information for the target risk object to obtain a trained risk handling model. Since this application embodiment can perform a selection operation on the risk assessment feature information on the risk feature selection page and select at least one target risk assessment feature information, that is, this application embodiment presents the risk assessment feature information in a visual form, it can quickly select the target risk assessment feature information, determine the reference risk handling rule information based on the target risk assessment feature information, and predict the risk handling rule information, thereby accelerating the training of the risk handling model and improving development efficiency.
[0221] To better implement the above methods, this application also provides a risk object processing device, which can be integrated into a computer device, such as a server or terminal. The terminal may include a tablet computer, a laptop computer, and / or a personal computer.
[0222] For example, such as Figure 13 As shown, the risk object processing device may include an acquisition unit S401, a second prediction unit S402, a second determination unit S403, and a risk processing unit S404, as follows:
[0223] (1) Obtain unit S401;
[0224] The acquisition unit S401 can be used to acquire at least one target risk assessment feature information of the target risk object.
[0225] (2) Second prediction unit S402;
[0226] The second prediction unit S402 can be used to predict the target risk object based on at least one target risk assessment feature information and a post-trained risk processing model to obtain the risk processing rule information of the target risk object. The post-trained risk processing model is the aforementioned post-trained risk processing model.
[0227] (3) Second determining unit S403;
[0228] The second determining unit S403 can be used to determine the risk level of the risk handling rule information based on the risk handling rule information.
[0229] In some embodiments, the second determining unit S403 may be specifically used to: obtain the actual risk level of the risk handling rule information based on the risk handling rule information; and obtain a plurality of preset level threshold sets, wherein the preset level threshold sets include at least one preset level threshold; for each preset level threshold set, determine the candidate risk level of the risk handling rule information based on the preset level threshold in the preset level threshold set; determine the target level threshold set from the plurality of preset level threshold sets based on the actual risk level and the candidate risk level; and determine the risk level corresponding to the risk handling rule information based on the target level threshold set.
[0230] In some embodiments, the second determining unit S403 can be specifically used to determine a target classification curve based on the actual risk level and the candidate risk level, wherein the target classification curve represents the classification of risk processing rule information for each preset level threshold set; obtain the slope of the target classification curve, wherein the slope represents the accuracy of risk processing rule information for each preset level threshold set; and determine a target level threshold set from the preset level threshold set based on the slope of the target classification curve.
[0231] In some embodiments, the second determining unit S403 can be specifically used to obtain a risk level mapping relationship set, which includes the mapping relationship between preset risk handling rule information and preset risk level; and to determine the risk level corresponding to the risk handling rule information based on the risk level and the risk level mapping relationship set.
[0232] (4) Risk handling unit S404;
[0233] The risk processing unit S404 can be used to process the risk of a target risk object based on the risk level.
[0234] As can be seen from the above, the acquisition unit S401 of this application embodiment can acquire at least one target risk assessment feature information of the target risk object; the second prediction unit S402 can perform prediction processing on the target risk object based on at least one target risk assessment feature information and a trained risk processing model to obtain risk processing rule information of the target risk object, wherein the trained risk processing model is the aforementioned trained risk processing model; the second determination unit S403 can determine the risk level of the risk processing rule information based on the risk processing rule information; and the risk processing unit S404 can perform risk processing on the target risk object based on the risk level. Since this application embodiment can directly use the trained risk processing model to perform prediction processing on the target risk object, it can quickly obtain risk processing rule information, thus enabling rapid risk processing of the target risk object based on the risk processing rule information.
[0235] This application also provides a computer device, such as... Figure 14 As shown, it illustrates a structural schematic diagram of the computer device involved in the embodiments of this application, specifically:
[0236] The computer device may include components such as a processor 401 with one or more processing cores, a memory 402 with one or more computer-readable storage media, a power supply 403, and an input unit 404. Those skilled in the art will understand that... Figure 14 The computer device structure shown does not constitute a limitation on the computer device and may include more or fewer components than shown, or combine certain components, or have different component arrangements. Wherein:
[0237] The processor 401 is the control center of the computer device. It connects various parts of the computer device via various interfaces and lines, and performs various functions and processes data by running or executing software programs and / or modules stored in the memory 402, and by calling data stored in the memory 402, thereby providing overall monitoring of the computer device. Optionally, the processor 401 may include one or more processing cores; preferably, the processor 401 may integrate an application processor and a modem processor, wherein the application processor mainly handles the operating system, user interface, and computer programs, and the modem processor mainly handles wireless communication. It is understood that the modem processor may not be integrated into the processor 401.
[0238] The memory 402 can be used to store software programs and modules. The processor 401 executes various functional applications and data processing by running the software programs and modules stored in the memory 402. The memory 402 may mainly include a program storage area and a data storage area. The program storage area may store the operating system, computer programs required for at least one function (such as sound playback function, image playback function, etc.), etc.; the data storage area may store data created according to the use of the computer device, etc. In addition, the memory 402 may include high-speed random access memory, and may also include non-volatile memory, such as at least one disk storage device, flash memory device, or other volatile solid-state storage device. Accordingly, the memory 402 may also include a memory controller to provide the processor 401 with access to the memory 402.
[0239] The computer device also includes a power supply 403 that supplies power to the various components. Preferably, the power supply 403 can be logically connected to the processor 401 through a power management system, thereby enabling functions such as charging, discharging, and power consumption management through the power management system. The power supply 403 may also include one or more DC or AC power supplies, recharging systems, power fault detection circuits, power converters or inverters, power status indicators, and other arbitrary components.
[0240] The computer device may also include an input unit 404, which can be used to receive input digital or character information communication, and to generate keyboard, mouse, joystick, optical or trackball signal inputs related to user settings and function control.
[0241] Although not shown, the computer device may also include a display unit, etc., which will not be described in detail here. Specifically, in this embodiment, the processor 401 in the computer device loads the executable files corresponding to the processes of one or more computer programs into the memory 402 according to the following instructions, and the processor 401 runs the computer programs stored in the memory 402 to realize various functions, as follows:
[0242] Display a risk feature selection page, which includes risk assessment feature information for at least one dimension of the target risk object; respond to the selection operation for the risk assessment feature information, select at least one target risk assessment feature information from the risk assessment feature information for at least one dimension; determine reference risk treatment rule information based on the at least one target risk assessment feature information; use a risk treatment model and the at least one target risk assessment feature information to predict the risk treatment rule information for the target risk object; train the risk treatment model based on the risk treatment rule information and the reference risk treatment rule information for the target risk object to obtain the trained risk treatment model.
[0243] For details on the implementation of each of the above operations, please refer to the previous examples, which will not be repeated here.
[0244] Those skilled in the art will understand that all or part of the steps in the various methods of the above embodiments can be performed by a computer program, or by a computer program controlling related hardware. The computer program can be stored in a computer-readable storage medium and loaded and executed by a processor.
[0245] Therefore, embodiments of this application provide a computer-readable storage medium storing a computer program that can be loaded by a processor to execute any of the risk processing model training methods and any of the risk object processing methods provided in embodiments of this application.
[0246] For details on the implementation of each of the above operations, please refer to the previous examples, which will not be repeated here.
[0247] The computer-readable storage medium may include: read-only memory (ROM), random access memory (RAM), disk or optical disk, etc.
[0248] Since the instructions stored in the computer-readable storage medium can execute the steps in any of the risk management model training methods provided in the embodiments of this application, the beneficial effects that any of the risk management model training methods provided in the embodiments of this application can achieve can be realized, as detailed in the preceding embodiments, and will not be repeated here.
[0249] The instructions stored in the computer-readable storage medium can also execute the steps of any of the risk object processing methods provided in the embodiments of this application. Therefore, the beneficial effects that any of the risk object processing methods provided in the embodiments of this application can achieve can be realized. For details, please refer to the previous embodiments, which will not be repeated here.
[0250] According to one aspect of this application, a computer program product or computer program is provided, comprising computer instructions stored in a computer-readable storage medium. A processor of a computer device reads the computer instructions from the computer-readable storage medium and executes the computer instructions, causing the computer device to perform the methods provided in the various optional implementations of the above embodiments.
[0251] The foregoing has provided a detailed description of a risk management model training method, a risk object processing method, and related apparatus provided in the embodiments of this application. The related apparatus includes a risk management model training apparatus, a risk object processing apparatus, a computer device, and a computer-readable storage medium. Specific examples have been used to illustrate the principles and implementation methods of this application. The descriptions of the above embodiments are only for the purpose of helping to understand the method and its core ideas. Furthermore, those skilled in the art will recognize that, based on the ideas of this application, there will be changes in the specific implementation methods and application scope. Therefore, the content of this specification should not be construed as a limitation of this application.
Claims
1. A method for training a risk management model, characterized in that, include: The risk feature selection page is displayed, which includes risk assessment feature information for at least one dimension of the target risk object; In response to a selection operation for risk assessment feature information, at least one target risk assessment feature information is selected from the risk assessment feature information in the at least one dimension; Display a risk assessment logic editing page, which includes a component selection area and a logic editing area. The component selection area includes at least one logic unit component corresponding to at least one sub-risk assessment logic information of the target risk assessment feature information. In response to a selection operation for a target logical unit component, the target logical unit component is displayed in the logical editing area to obtain sub-risk assessment logical information corresponding to each target risk assessment feature information; The sub-risk assessment logic information corresponding to each of the target risk assessment feature information is combined and processed to generate reference risk handling rule information for the target risk object; Using a risk treatment model and the at least one target risk assessment feature information, predict risk treatment rule information for the target risk object; Based on the risk handling rule information and the reference risk handling rule information of the target risk object, the risk handling model is trained to obtain the trained risk handling model.
2. The risk management model training method according to claim 1, characterized in that, The step of combining and processing the sub-risk assessment logic information corresponding to each of the target risk assessment feature information to generate reference risk handling rule information for the target risk object includes: In response to the connection operation for the target logic unit component, a connection is established between the target logic unit components to combine and process the sub-risk assessment logic information to obtain reference risk processing rule information for the target risk object. The connection represents the execution order between the target logic unit components.
3. A method for handling risky objects, characterized in that, include: Obtain at least one target risk assessment characteristic information of the target risk object; Based on the at least one target risk assessment feature information, a post-trained risk processing model is used to predict the target risk object to obtain the risk processing rule information of the target risk object. The post-trained risk processing model is the post-trained risk processing model as described in any one of claims 1 to 2. Based on the risk handling rule information, the risk level of the risk handling rule information is determined; Based on the risk level, risk management is carried out on the target risk object.
4. The risk object handling method according to claim 3, characterized in that, The step of determining the risk level of the risk handling rule information based on the risk handling rule information includes: Based on the risk handling rule information, the actual risk level of the risk handling rule information is obtained, and a set of several preset level thresholds is obtained, wherein the set of preset level thresholds includes at least one preset level threshold. For each preset level threshold set, a candidate risk level for the risk handling rule information is determined based on the preset level threshold in the preset level threshold set. Based on the actual risk level and the candidate risk level, a target risk level threshold set is determined from the plurality of preset risk level threshold sets; Based on the target level threshold set, the risk level corresponding to the risk handling rule information is determined.
5. The risk object handling method according to claim 4, characterized in that, The step of determining the target level threshold set from the plurality of preset level threshold sets based on the actual risk level and the candidate risk levels includes: Based on the actual risk level and the candidate risk level, a target classification curve is determined, which represents the classification of the risk processing rule information for each preset level threshold set. Obtain the slope of the target classification curve, whereby the slope represents the accuracy of the risk processing rule information in classifying each preset level threshold set; Based on the slope of the target classification curve, a target level threshold set is determined from the preset level threshold set.
6. The risk object handling method according to claim 5, characterized in that, The step of determining the risk level of the risk handling rule information based on the risk handling rule information includes: Obtain a set of risk level mapping relationships, which includes the mapping relationship between preset risk handling rule information and preset risk levels; Based on the risk level and the set of risk level mapping relationships, the risk level corresponding to the risk handling rule information is determined.
7. A risk management model training device, characterized in that, include: The display unit is used to display a risk feature selection page, which includes risk assessment feature information for at least one dimension of the target risk object. A response unit is configured to select at least one target risk assessment feature from the risk assessment feature information in the at least one dimension in response to a selection operation for risk assessment feature information; The first determining unit is used to display a risk assessment logic editing page, which includes a component selection area and a logic editing area. The component selection area includes at least one logic unit component corresponding to at least one sub-risk assessment logic information of the target risk assessment feature information. In response to a selection operation for a target logical unit component, the target logical unit component is displayed in the logical editing area to obtain sub-risk assessment logical information corresponding to each target risk assessment feature information; the sub-risk assessment logical information corresponding to each target risk assessment feature information is combined to generate reference risk handling rule information for the target risk object; The first prediction unit is used to predict risk treatment rule information for the target risk object by employing a risk treatment model and the at least one target risk assessment feature information; The training unit is used to train the risk processing model based on the risk processing rule information and the reference risk processing rule information of the target risk object, so as to obtain the trained risk processing model.
8. A computer device, characterized in that, It includes a memory and a processor; the memory stores a computer program, and the processor is used to run the computer program in the memory to perform the risk management model training method according to any one of claims 1 to 2.
9. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program adapted for loading by a processor to execute the risk management model training method according to any one of claims 1 to 2.