Service object detection method, device, equipment and storage medium
By acquiring the service object association network and performing group clustering, the target service object group is filtered out, which solves the problem of low detection accuracy in the existing technology and achieves more efficient risk control and reduced false penalties.
Patent Information
- Application Number
- CN202111283807.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-11-01
- Publication Date
- 2025-11-28
- Estimated Expiration
- 2041-11-01
AI Technical Summary
In existing technologies, the detection accuracy of service object detection methods is low, and they cannot effectively detect the target service objects in the payment platform, resulting in an increase in the number of false penalties, which increases risk control costs and reduces the user experience for normal users of resources.
By acquiring the service object association network, group clustering is performed. The registration association between service objects and resource users is used to filter out groups containing target service objects. Clustering models and risk control strategies are employed to improve detection accuracy.
It improved the accuracy of service recipient detection, reduced the number of false penalties, curbed the registration of target resource users, reduced risk control costs, and reduced the expansion of the black market industry chain.
Smart Images

Figure CN116071154B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the field of computers, in particular to the field of electronic finance technology, and provides a service object detection method and device, equipment and a storage medium. BACKGROUND
[0002] In recent years, with the popularization of Internet financial business, it has brought a lot of convenience to people's daily life, but also provided a criminal law channel for criminals, so that they use Internet financial business to carry out illegal activities.
[0003] In the early stage of cracking down on the black industry chain, it is mainly from the resource using object itself, using the resource using object's own fund flow data and information flow data, and judging whether the resource using object has abnormal resource using behavior through simple expert rules.
[0004] However, the above resource using object detection method can only detect the target resource using object with a certain type of abnormal resource using behavior, and cannot detect all target resource using objects in the payment platform, increasing the risk control cost of the payment platform. Because the registration cost of the resource using object is low, a large number of new target resource using objects will flow into the payment platform every day, increasing the number of target resource using objects to be punished. Because the above detection method has a detection error rate, as the number of punishments increases, the number of mis-punished resource using objects also increases, which brings a poor use experience to the resource using object with normal resource using behavior.
[0005] Although the registration cost of the resource using object is low, the registration process is complicated, so the service object providing object registration service emerges as the times require, and the resource using object can be affiliated to the service object, and the object registration process is completed by the corresponding service object. Because the registration cost of the service object is higher, the criminals will not register the target service object in a low-cost batch, and each service object contains multiple resource using objects. If the service object is taken as the detection subject, the detection number is reduced, and the target service object and the target resource using object are also detected.
[0006] Therefore, the related technology further provides a service object detection method, which detects multiple target resource using objects belonging to the same service object through simple expert rules. In order to curb the registration number of target resource using objects from the source, the service object registered with multiple target resource using objects is determined as a target service object, and the target service object and the multiple resource using objects under it are subjected to risk control. However, because the dimension of the expert rule is less, the detection accuracy is low, and there are still a large number of target service objects in the payment platform that have not been detected. SUMMARY
[0007] Embodiments of the present application provide a service object detection method, device, equipment and storage medium, to solve the problem of low detection accuracy.
[0008] In a first aspect, the embodiments of the present application provide a service object detection method, comprising:
[0009] obtaining a service object association network, the service object association network representing a registered association relationship between each service object and each resource using object;
[0010] group clustering each service object contained in the service object association network to obtain at least one candidate service object group;
[0011] based on the first object registration information of each service object and the second object registration information of each resource using object registered by each service object, obtaining a group attribute feature set of each of the at least one candidate service object group;
[0012] based on the obtained each group attribute feature set, screening a target service object group containing a target service object from the at least one candidate service object group, the target service object being a service object providing an abnormal object registration service.
[0013] In a second aspect, the embodiments of the present application further provide a service object detection device, comprising:
[0014] a clustering unit configured to obtain a service object association network, the service object association network representing a registered association relationship between each service object and each resource using object;
[0015] group clustering each service object contained in the service object association network to obtain at least one candidate service object group;
[0016] a detection unit configured to obtain a group attribute feature set of each of the at least one candidate service object group based on the first object registration information of each service object and the second object registration information of each resource using object registered by each service object;
[0017] based on the obtained each group attribute feature set, screening a target service object group containing a target service object from the at least one candidate service object group, the target service object being a service object providing an abnormal object registration service.
[0018] Optionally, the device further comprises a generating unit configured to generate the service object association network in the following manner:
[0019] Obtaining, from a resource usage platform, first object registration information of each of the service objects and second object registration information of each of the resource usage objects registered by each of the service objects;
[0020] Associating the service objects containing common registration information to generate the service object association network, and determining an association weight between the associated service objects in the service object association network based on each of the common registration information, wherein the common registration information includes one or a combination of common first object registration information and common second object registration information.
[0021] Optionally, the generating unit determines an association weight by performing the following operations:
[0022] When the common registration information is the common first object registration information, a field number of a common object registration information field in the common first object registration information is taken as the association weight between the associated service objects in the service object association network.
[0023] When the common registration information is the common second object registration information, a corresponding association weight is generated based on an average value of a common registration information proportion of each object registration information field in the common second object registration information, wherein the average value of the common registration information proportion of each object registration information field is determined based on a number of second object registration information having a common object registration information field and a total number of second object registration information contained by each of the associated service objects.
[0024] When the common registration information includes the common first object registration information and the common second object registration information, a corresponding association weight is determined based on a field number of a common object registration information field in the common first object registration information and an average value of a common registration information proportion of each object registration information field.
[0025] Optionally, the generating unit obtains the average value of the common registration information proportion of an object registration information field by performing the following operations:
[0026] A ratio value between the number of second object registration information having a common object registration information field and the total number of second object registration information contained by each of the associated service objects is respectively determined as a first common registration information proportion parameter and a second common registration information proportion parameter of the object registration information field.
[0027] The first common registration information proportion parameter and the second common registration information proportion parameter are processed by an average value to obtain a common registration information proportion average value of the one object registration information field.
[0028] Optionally, before the obtaining, by the generation unit, of the first object registration information of each service object and the second object registration information of each resource using object registered by each service object from the resource using platform, the generation unit is further configured to:
[0029] The data of all service objects in the resource using platform is denoised to eliminate service objects in a preset white list.
[0030] Optionally, the clustering unit is configured to:
[0031] Based on the common registration information between the service objects, the closeness between each service object in the service object associated network is determined, and each service object whose closeness satisfies a set closeness threshold is clustered into a same group to obtain the at least one candidate service object group.
[0032] Optionally, the clustering unit is configured to:
[0033] For each service object contained in the service object associated network, the following operations are performed in a loop iteration manner until an iteration stop condition is satisfied, and the at least one candidate service object group is output:
[0034] Based on the common registration information between the service objects, the closeness between each service object is determined.
[0035] Each service object whose closeness satisfies a set closeness threshold is clustered into a same group to obtain a new plurality of service object clustering sets.
[0036] Optionally, the clustering unit is configured to:
[0037] For each service object clustering set to which each service object belongs, the following operations are respectively performed: the closeness between one service object clustering set and at least one associated service object clustering set is obtained, wherein each associated service object clustering set is a service object clustering set that has an association relationship with the one service object clustering set, and the association relationship is determined based on the common registration information between two service object clustering sets.
[0038] Optionally, the clustering unit determines the service object clustering set to which each service object belongs by performing any one of the following operations:
[0039] when being the first round iteration, associating each service object in the service object association network as a plurality of service object cluster sets to which the each service object belongs in the current round;
[0040] when being the non-first round iteration, associating the plurality of service object cluster sets clustered in the last round as the plurality of service object cluster sets to which the each service object belongs in the current round.
[0041] Optionally, the detection unit is configured to:
[0042] perform feature extraction based on the first object registration information and the first object label of the each service object in the corresponding candidate service object group, and the second object registration information, the second object label and the historical resource usage data set of the each resource usage object registered by the each service object, to obtain a group attribute feature set of the each candidate service object group.
[0043] Optionally, the detection unit is configured to:
[0044] input the obtained each group attribute feature set into a preset service object group detection model for abnormal service detection, and when an abnormal service prediction probability of each candidate service object group exceeds a set probability threshold, determine that the candidate service object group is a target service object group containing a target service object.
[0045] Optionally, after the target service object group containing the target service object is screened out, the device further comprises a risk control unit, and the risk control unit is configured to:
[0046] invoke a corresponding risk control strategy to perform risk control on the corresponding target service object group based on a risk interval in which the abnormal service prediction probability of the target service object group is located.
[0047] Optionally, the risk control unit is configured to:
[0048] when the abnormal service prediction probability of the target service object group is located in a first risk interval, suspend providing part of the management services to all service objects in the target service object group, and suspend providing part of the resource usage services to all objects in the target service object group;
[0049] when the abnormal service prediction probability of the target service object group is located in a second risk interval, suspend providing all the management services to all service objects in the target service object group, and suspend providing all the resource usage services to all objects in the target service object group.
[0050] In a third aspect, the embodiments of the present application further provide a computer device, comprising a processor and a memory, wherein the memory stores program codes, and the program codes, when executed by the processor, cause the processor to perform the steps of any of the service object detection methods.
[0051] In a fourth aspect, the embodiments of the present application further provide a computer readable storage medium, comprising program codes, and the program codes, when the program product is run on a computer device, are used to cause the computer device to perform the steps of any of the service object detection methods.
[0052] In a fifth aspect, the embodiments of the present application further provide a computer program product, comprising computer instructions, and the computer instructions, when executed by a processor, implement the steps of any of the service object detection methods.
[0053] The present application has the following beneficial effects:
[0054] The embodiments of the present application provide a service object detection method, device, equipment and storage medium, and the method comprises: obtaining a service object associated network, the service object associated network representing a registered association relationship between each service object and each resource use object; performing group clustering on each service object contained in the service object associated network to obtain at least one candidate service object group; based on the first object registration information of each service object and the second object registration information of each resource use object registered by each service object, obtaining a group attribute feature set of each candidate service object group; and based on the obtained group attribute feature set, screening a target service object group containing a target service object from the at least one candidate service object group, the target service object being a service object providing abnormal object registration service. By using the registered association relationship between each service object and each resource use object, a service object group having an association relationship with the target service object and the target resource use object is mined, and a plurality of target service object groups providing abnormal object registration service in the resource use platform are detected, which not only improves the detection accuracy and reduces the number of mis-punished resource use objects, but also suppresses the registration number of target resource use objects from the source, reduces the risk control cost of the resource use platform, and further suppresses the expansion of the black industry chain.
[0055] Other features and advantages of the present application will be set forth in the following description, and in part will become apparent to those skilled in the art from the description, or can be learned by practice of the present application. The objects and other advantages of the present application will be realized and attained by the structure particularly pointed out in the written description and claims hereof as well as the appended drawings. BRIEF DESCRIPTION OF DRAWINGS
[0056] The accompanying drawings, which are included to provide a further understanding of the application and are incorporated in and constitute a part of this application, illustrate embodiments of the application and together with the description serve to explain the application. In the drawings:
[0057] Figure 1a A schematic diagram of fund settlement in a direct connection mode;
[0058] Figure 1b A schematic diagram of fund settlement in an indirect connection mode;
[0059] Figure 1c A schematic diagram of fund settlement in a normal mode;
[0060] Figure 2 An optional schematic diagram of an application scenario in an embodiment of the application;
[0061] Figure 3a A flowchart of a service object detection method provided by an embodiment of the application;
[0062] Figure 3b A flowchart of generating a service object association network provided by an embodiment of the application;
[0063] Figure 3c A schematic diagram of a service object association network provided by an embodiment of the application;
[0064] Figure 3d A logic diagram of determining an edge based on common first object registration information provided by an embodiment of the application;
[0065] Figure 3e A logic diagram of determining an edge based on common second object registration information provided by an embodiment of the application;
[0066] Figure 3f A flowchart of performing group clustering on a service object association network provided by an embodiment of the application;
[0067] Figure 3g A schematic diagram of a service object association network after group clustering provided by an embodiment of the application;
[0068] Figure 4a A flowchart of a specific embodiment provided by an embodiment of the application;
[0069] Figure 4b A logic diagram of a specific embodiment provided by an embodiment of the application;
[0070] Figure 5 A structural diagram of a service object detection device provided by an embodiment of the application;
[0071] Figure 6This is a schematic diagram of the composition structure of a computer device provided in an embodiment of this application;
[0072] Figure 7 This is a schematic diagram of the structure of a computing device provided in an embodiment of this application. Detailed Implementation
[0073] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the technical solutions of this application will be clearly and completely described below with reference to the accompanying drawings of the embodiments of this application. Obviously, the described embodiments are only some embodiments of the technical solutions of this application, and not all embodiments. Based on the embodiments recorded in this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the technical solutions of this application.
[0074] The following explanations of some terms used in the embodiments of this application are provided to facilitate understanding by those skilled in the art.
[0075] 1. Resource users: refers to merchants on the resource usage platform. The account opened on the resource usage platform with the merchant as the registration subject can also be called a resource usage account.
[0076] The resource usage platform is a mobile payment platform specifically designed for fund settlement in various transaction scenarios, such as business-to-customer (B2C), merchant-to-merchant, and merchant-to-service provider transactions.
[0077] For example, see Figure 1a The diagram showing fund settlement illustrates that when a merchant's onboarding mode is a direct connection mode, customers transfer funds from their personal accounts on the resource usage platform to the merchant's resource usage account. The merchant then calls the relevant interfaces of the resource usage platform to transfer the funds received in the resource usage account to the bank card linked to the merchant.
[0078] For example, see Figure 1b The diagram illustrating fund settlement shows that when a merchant's onboarding mode is the indirect sub-mode, the merchant does not directly settle funds with the resource-using platform, but indirectly settles funds with the resource-using platform through institutions such as banks and third-party payment institutions.
[0079] 2. Service recipients: This refers to the service providers on the resource usage platform. The accounts opened on the resource usage platform with the service provider as the registered entity can also be called service accounts.
[0080] Service providers mainly offer the following services on the resource utilization platform: service provider application submission, transaction initiation on behalf of sub-merchants, and assistance with marketing activities for sub-merchants.
[0081] The service provider providing the service refers to the service provider providing various resources required by the merchant for the use of the resource use platform and the process of applying for a resource use account. The merchant provided by the service provider is referred to as a sub-merchant.
[0082] The service provider initiating a transaction for the sub-merchant refers to the sub-merchant indirectly settling funds with the resource use platform with the help of the service provider. For example, referring to Figure 1c The settlement of funds is shown in the schematic diagram. If the merchant's mode of entry is a normal sub-mode, the service provider initiates a transaction for the sub-merchant, and the service provider collects a commission from the resource use platform when the sub-merchant settles funds with the resource use platform.
[0083] The service provider specifically includes an internal service provider, an overseas service provider, a key account (KA) service provider, and the like.
[0084] The internal service provider refers to a service provider within the resource use platform, such as a bill payment service provider. The KA service provider refers to a service provider with a larger scale and an operating endorsement.
[0085] 3. Target resource use object: refers to a malicious merchant involved in operating a black industry chain such as gambling, pornography, fraud, and single brushing.
[0086] 4. Target service object: refers to a malicious service provider providing abnormal management services such as providing account registration services for malicious merchants and initiating transactions for malicious merchants.
[0087] 5. Fast Unfolding community discovery algorithm:
[0088] According to the definition of the community, the nodes in the same community are more closely connected, and the nodes between the communities are more sparse. Therefore, the Fast Unfolding community discovery algorithm uses modularity to measure the tightness of node connection.
[0089] In simple terms, modularity is used to measure the quality of community network division. The closer the value of modularity is to 1, the better the network community is divided, and the better the quality of the community network grouping.
[0090] The fast unfolding community discovery algorithm merges all connected nodes in the community network two by two, respectively calculates the modularity change value brought by each merging mode, merges the two nodes corresponding to the maximum modularity change value into a community, and then merges all connected communities two by two, merges the two communities corresponding to the maximum modularity change value into a new community, and so on, until the modularity change value of each community is no longer large, to obtain the divided multiple communities.
[0091] 6. Risk control strategy: refers to measures for punishing target service accounts and target resource use accounts. For example, measures such as suspending payment services and investment services for resource use accounts of malicious merchants, and measures such as suspending service accounts of malicious service providers for providing services.
[0092] 7. Artificial Intelligence (AI):
[0093] Artificial intelligence is the use of digital computers or digital computer-controlled machines to simulate, extend and expand human intelligence, perceive the environment, acquire knowledge and use knowledge to obtain the best results. In other words, artificial intelligence is a comprehensive technology of computer science, which aims to understand the essence of intelligence and produce a new intelligent machine that can react in a similar way to human intelligence. Artificial intelligence is the design principle and implementation method of various intelligent machines, so that machines have the functions of perception, reasoning and decision-making.
[0094] Artificial intelligence technology is a comprehensive discipline, involving a wide range of fields, both hardware and software technologies. Artificial intelligence basic technologies generally include technologies such as sensors, special artificial intelligence chips, cloud computing, distributed storage, big data processing technology, operation / interaction system, mechatronics, etc.; artificial intelligence software technology mainly includes computer vision technology, speech processing technology, natural language processing technology, and machine learning / deep learning, etc. With the research and progress of artificial intelligence technology, artificial intelligence has been researched and applied in many fields, such as common smart home, intelligent customer service, virtual assistant, smart speaker, intelligent marketing, unmanned driving, autonomous driving, robot, intelligent medical treatment, etc. It is believed that with the development of technology, artificial intelligence will be applied in more and more fields and play an increasingly important role.
[0095] 8. Machine Learning (ML):
[0096] Machine learning is a multi-disciplinary subject, involving probability theory, statistics, approximation theory, convex analysis, algorithm complexity theory and other disciplines. It is a specialized study of how computers simulate or implement human learning behavior to acquire new knowledge or skills, reorganize existing knowledge structure to continuously improve their performance. Machine learning is the core of artificial intelligence and the fundamental approach to making computers intelligent. Its applications are widespread in various fields of artificial intelligence. Machine learning and deep learning usually include artificial neural networks, belief networks, reinforcement learning, transfer learning, inductive learning, and rule-based learning.
[0097] The design idea of the embodiments of the present application will be briefly introduced as follows:
[0098] In recent years, with the popularization of Internet financial business, it has brought a lot of convenience to people's daily life, but also provided a legal channel for criminals, so that they use Internet financial business to carry out illegal activities.
[0099] In the early stage of cracking down on the black industry chain, it is mainly from the resource using object itself, using the resource using object's own fund flow data and information flow data, and judging whether the resource using object has abnormal resource using behavior through simple expert rules.
[0100] However, the above resource using object detection method can only detect the target resource using object with a certain type of abnormal resource using behavior, and cannot detect all target resource using objects in the payment platform, increasing the risk control cost of the payment platform. Since the registration cost of the resource using object is low, a large number of new target resource using objects will flow into the payment platform every day, increasing the number of target resource using objects to be punished. Due to the detection error rate of the above detection method, the number of mis-punished resource using objects also increases continuously, which brings poor use experience to the resource using objects with normal resource using behavior.
[0101] Although the registration cost of the resource using object is low, the registration process is complicated, therefore, the service object providing object registration service emerges as the times require, and the resource using object can be affiliated to the service object, and the object registration process is completed by the corresponding service object. Since the registration cost of the service object is higher, criminals will not register target service objects in large quantities at low cost, and each service object contains multiple resource using objects. If the service object is taken as the detection subject, the detection quantity is reduced, and the target service object and the target resource using object are detected at the same time.
[0102] Therefore, the related art proposes a service object detection method, which detects a plurality of target resource use objects belonging to the same service object through simple expert rules. In order to curb the registration quantity of the target resource use objects from the source, the service object registered with a plurality of target resource use objects is determined as a target service object, and the target service object and the plurality of resource use objects under the target service object are subjected to risk control. However, due to the low detection accuracy of the expert rules with less dimensions, there are still a large number of target service objects in the payment platform that have not been detected.
[0103] Therefore, the embodiments of the present application provide a service object detection method, device, equipment and storage medium. The method comprises: performing group clustering on each service object contained in a service object association network to obtain at least one candidate service object group, the service object association network representing the registration association relationship between each service object and each resource use object; and based on the obtained group attribute feature set, screening a target service object group containing a target service object from the at least one candidate service object group, the target service object being a service object providing abnormal object registration service.
[0104] The service object detection method provided by the embodiments of the present application uses the registration association relationship between each service object and each resource use object to mine the service object group having an association relationship with the target service object and the target resource use object, so as to detect a plurality of target service object groups providing abnormal object registration service in the resource use platform. The detection accuracy is improved, the number of mis-punished resource use objects is reduced, the registration quantity of the target resource use objects is curbed from the source, the risk control cost of the resource use platform is reduced, and the expansion of the black industry chain is further curbed.
[0105] The preferred embodiments of the present application are described below in conjunction with the accompanying drawings. It should be understood that the preferred embodiments described herein are only used to illustrate and explain the present application, and are not used to limit the present application, and the embodiments in the present application and the features in the embodiments can be combined with each other without conflict.
[0106] Referring to Figure 2 An optional schematic diagram of an application scenario is shown, which includes a first terminal device 201, a second terminal device 203 and a server 204.
[0107] The first terminal device 201 and the second terminal device 203 respectively communicate with the server 204 through a wired network or a wireless network, a service provider logs in the application operation interface 202 through the first terminal device 201, and sends a submission application request to a resource use platform deployed on the server 204, and registers a resource use account for a merchant. After completing the account registration process, the merchant logs in the application operation interface 202 through the second terminal device 203, and performs fund settlement with the resource use platform.
[0108] The first terminal device 201 and the second terminal device 203 are all computer devices with certain computing power and supporting electronic payment, such as personal computers, mobile phones, tablet computers, notebooks, e-book readers, etc.
[0109] The server 204 in the embodiment of the application can be a stand-alone physical server, a server cluster or a distributed system composed of multiple physical servers, or a cloud server providing cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, content distribution networks (CDN), and basic cloud computing services such as big data and artificial intelligence platforms, etc. The application does not limit this. For example, in the service account detection method disclosed in the application, multiple servers can form a block chain, and the server is a node on the block chain.
[0110] Referring to Figure 3a The flowchart shown in the figure details the service object detection method proposed in the embodiment of the application.
[0111] S301: Obtain a service object association network, which represents the registered association relationship between each service object and each resource use object.
[0112] In the manner as Figure 3b shown, the service object association network is generated as follows:
[0113] S3011: Obtain, from the resource use platform, first object registration information of each service object, and second object registration information of each resource use object registered by each service object.
[0114] Embodiments of the present application filter out a target service object group providing abnormal object registration services by using the registered association relationship between each service object and each resource use object in the service object association network. However, the service objects of the service providers in the preset white list, such as internal service providers, overseas service providers, and KA service providers in the resource use platform, have a low probability of being determined as target service objects. It is meaningless to add these service objects to the service object association network, and it may even increase the workload of constructing the association network, easily construct abnormal edge relationships, and affect the final detection accuracy.
[0115] Therefore, in the initial stage of constructing the service object association network, data noise reduction is performed on all service objects in the resource use platform, and the service objects in the preset white list are removed.
[0116] As shown in Table 1, the first object registration information of a service object includes multiple object registration information fields of service provider, such as object registration information field 1, object registration information field 2, and object registration information field 3 of the service provider. The object registration information field of the service provider includes the identity card of the service provider, the bank card number, and the like.
[0117] Table 1
[0118]
[0119] As shown in Table 2, the second object registration information of a resource use object includes multiple object registration information fields of a merchant, such as object registration information field 1, object registration information field 2, and object registration information field 3 of the merchant. The object registration information field of the merchant includes the identity card of the merchant, the bank card number, and the like.
[0120] Table 2
[0121]
[0122] S3012: Information association is performed on service objects containing common registration information to generate a service object association network, and based on each common registration information, the association weight between the associated service objects in the service object association network is determined respectively. The common registration information includes one or a combination of common first object registration information and common second object registration information.
[0123] A service object association network as shown in FIG. 1 is generated by taking service objects as nodes and taking the association relationship between service objects as edges. The present application provides the following several ways to determine edges: Figure 3c
[0124] Method 1: The edge between service objects is determined based on common first object registration information.
[0125] Because the registration cost of the resource use account is low, one identity certificate can register dozens of resource use accounts, but the registration cost of the service account is high, and the registration process is complicated, and criminals usually do not use one identity certificate to register service accounts in batches, but use one identity certificate to register several service accounts.
[0126] As shown in Figure 3d If the service accounts have at least one common object registration information field, it is determined that the corresponding service objects contain common first object registration information, and it is further determined that there is an edge between the service objects.
[0127] In the embodiment of the application, when the common registration information is the common first object registration information, the number of fields of the common object registration information field in the common first object registration information is taken as the association weight between the associated service objects in the service object network.
[0128] For example, there is one common first object registration information between two service accounts, and three object registration information fields in the first object registration information are the same, and then the association weight between the corresponding two service objects is set to 3.
[0129] Method 2: determining the edge between the service objects based on the common second object registration information.
[0130] When the auditors audit the merchant application, if it is found that the same service provider uses the same object registration information to register multiple resource use accounts, or multiple resource use accounts belong to the same principal, it is determined that the service provider is the target service object. In this way, the resource use platform will not only refuse the above-mentioned merchant to enter the platform, and the service provider's application function will be closed in serious cases.
[0131] Because the registration cost of the service account is high, and the registration process is complicated, criminals will try to reduce the registration cost of the resource use account to evade the audit mechanism of the platform, and usually use the same account registration information to apply for resource use accounts of different principals under multiple service providers.
[0132] Therefore, in order to enhance the strength of identifying the association relationship between service providers, the account registration information of the ordinary sub-merchants under the service providers will also be used to identify the closeness of the association relationship between the service providers.
[0133] As shown in Figure 3e If multiple resource use accounts are applied based on the same object registration information, it is determined that the corresponding service accounts contain common second object registration information, and it is further determined that there is an edge between the corresponding service objects.
[0134] In the embodiments of the present application, when the common registration information is the common second object registration information, the corresponding association weight is generated based on the average of the respective common registration information proportion of each object registration information field in the common second object registration information. The average of the respective common registration information proportion of each object registration information field is determined based on the number of second object registration information having a common object registration information field and the total number of second object registration information contained in the associated service object.
[0135] Specifically, the average of the common registration information proportion of an object registration information field is obtained by performing the following operations:
[0136] First, the ratio value between the number of second object registration information having a common object registration information field and the total number of second object registration information contained in the associated service object is determined as the first common registration information proportion parameter and the second common registration information proportion parameter of the object registration information field, respectively.
[0137] Then, the average of the first common registration information proportion parameter and the second common registration information proportion parameter is processed to obtain the average of the common registration information proportion of the object registration information field.
[0138] Suppose that service account A contains 10 second object registration information and service account B contains 15 second object registration information. Table 3 shows the number of second account registration information having a common object registration information field between the two service accounts.
[0139] Table 3
[0140]
[0141]
[0142] Therefore, the average of the common registration information proportion of the object registration information field 1 of the merchant is
[0143] The average of the common registration information proportion of the object registration information field 2 of the merchant is
[0144] The average of the common registration information proportion of the object registration information field 3 of the merchant is
[0145] The average of the common registration information proportion of the object registration information field 4 of the merchant is
[0146] The average proportion of common registration information of the object registration information field 5 of the merchant is,
[0147] The average proportion of common registration information of the object registration information field 6 of the merchant is,
[0148] Based on the average proportion of common registration information of each object registration information field obtained, the association weight between the service object of the service account A and the service object of the service account B is (0.25*3+0.33+0.17+0.08) / 6=0.2.
[0149] Method 3: determining the edge between service objects based on common first object registration information and common second object registration information.
[0150] The method 3 provided by the embodiments of the present application can construct a more complete service object association network by simultaneously using the object registration information of the service provider and the object registration information of the sub-merchant.
[0151] When the common registration information includes common first object registration information and common second object registration information, as shown in formula 1, based on the field number of the common object registration information field in the common first object registration information and the average proportion of common registration information of each object registration information field, the corresponding association weight w is determined.
[0152] w=num def1 *codef1+avgpct def2 *coef2 Formula 1;
[0153] num def1 is the first association sub-weight, codef1 is the weight coefficient of the first association sub-weight, avgpct def2 is the second association sub-weight, and coef2 is the weight coefficient of the second association sub-weight. The first association sub-weight is determined based on the field number of the common object registration information field in the common first object registration information, and the second association sub-weight is determined based on the average proportion of common registration information of each object registration information field. A larger weight coefficient can be given to the edge constructed based on the common first object registration information, and a smaller weight coefficient can be given to the edge constructed based on the common second object registration information.
[0154] The embodiment of the application further provides another more optimal manner of generating a service object association network, that is, storing the association relationship between each service object in the form of a graph, quickly and conveniently obtaining the association relationship between each service object from the constructed graph on a daily basis, and constructing a corresponding service object association network; then inputting the service object association network into a clustering model and a service object group detection model, screening a target service object group containing a target service object from at least one candidate service object group, and calling a corresponding risk control strategy to perform risk control on the corresponding target service object group.
[0155] S302: Group clustering is performed on each service object contained in the service object association network, and at least one candidate service object group is obtained.
[0156] A clustering model is constructed based on each community discovery algorithm such as the Fast Unfolding community discovery algorithm and the label propagation algorithm, a large amount of sample data is used to train the clustering model, and the trained clustering model is deployed to a server vendor. The clustering model is triggered on a daily basis, the service object association network is input into the model for group clustering, and the service object group to which each service object belongs is obtained. However, in addition to using the clustering model for group clustering, a connected graph can also be used for group clustering, which is not limited in the application.
[0157] Taking the clustering model constructed based on the Fast Unfolding community discovery algorithm as an example, the group clustering process of the service object association network is described in detail.
[0158] The basic idea of the clustering model constructed based on the Fast Unfolding community discovery algorithm is to determine the intimacy between each service object in the service object association network based on the common registration information between the service objects, and cluster each service object whose intimacy satisfies a set intimacy threshold into the same group to obtain at least one candidate service object group.
[0159] Figure 3f The process of group clustering of the service object association network is shown, and specifically:
[0160] S3021: The intimacy between the service object clustering sets to which each service object belongs is determined based on the common registration information between the service objects.
[0161] When it is the first round of iteration, each service object in the service object association network is taken as the multiple service object clustering sets to which each service object belongs in the current round;
[0162] When it is the non-first round of iteration, the multiple service object clustering sets after clustering in the last round are taken as the multiple service object clustering sets to which each service object belongs in the current round.
[0163] For each service object cluster set to which each service object belongs, the following operation is performed: obtaining a closeness between a service object cluster set and at least one associated service object cluster set, wherein each associated service object cluster set is a service object cluster set having an association relationship with the service object cluster set, and the association relationship is determined based on common registration information between the two service object cluster sets.
[0164] The closeness between a service object cluster set and an associated service object cluster set is calculated using formula 2.
[0165] Wherein m is the sum of the association weights of all edges in the service object association network, ki,in represents the sum of the association weights of the edges between the service object cluster set i and the associated service object cluster set j, ∑ tot ki represents the product of the first weight sum and the second weight sum. The first weight sum is the sum of the association weights of the edges of all associated service object cluster sets connected to the service object cluster set i; the second weight sum is the sum of the association weights of the edges of all associated service object cluster sets connected to the associated service object cluster set j.
[0166]
[0167] S3022: Clustering the service object cluster sets whose closeness meets the set closeness threshold into the same group to obtain a new plurality of service object cluster sets.
[0168] If the closeness is a positive number, it means that the modularity is getting larger, and the clustering result of this time is accepted; if the closeness is a negative number, it means that the modularity is getting smaller, and the clustering result of this time is abandoned.
[0169] If the closeness of the service object cluster sets is all positive numbers, the service object cluster set and the associated service object cluster set corresponding to the maximum closeness are clustered into a new service object cluster set.
[0170] S3023: Determine whether all service object cluster sets meet the iteration stop condition, if yes, perform step 3024; otherwise, return to step 3021.
[0171] Until the closeness of all service object cluster sets no longer changes, it is determined that all service object cluster sets meet the iteration stop condition, and step 3024 is performed to output at least one candidate service object group.
[0172] S3024: Output at least one candidate service object group.
[0173] For ease of understanding, take a service object association network as shown in FIG. 1 as an example.Figure 3c The service object association network diagram shown is an example, using a clustering model to obtain a plurality of candidate service object groups as shown Figure 3g .
[0174] Specifically, (1) each service object is taken as a service object clustering set in the first round, and the affinity between each service object clustering set and at least one associated service object clustering set is calculated respectively.
[0175]
[0176] After the first round of calculation, service object A and service object B are re-clustered to obtain a new service object clustering set (A, B), service object C and service object D are re-clustered to obtain a new service object clustering set (C, D), and service object E and service object F are re-clustered to obtain a new service object clustering set (E, F).
[0177] (2) Taking (A, B), (C, D) and (E, F) as service object clustering sets in the second round, the affinity between each service object clustering set and at least one associated service object clustering set is calculated respectively.
[0178]
[0179]
[0180] After the second round of calculation, the affinity of each service object clustering set is negative, and the clustering result of this time is abandoned; after the third round of calculation, the affinity of each service object clustering set still does not increase, satisfying the iteration stop condition, and outputting a plurality of candidate service object groups (A, B), (C, D) and (E, F).
[0181] S303: Based on the first object registration information of each service object and the second object registration information of each resource using object registered by each service object, obtain a group attribute feature set of each of the at least one candidate service object group.
[0182] Based on the first object registration information, the first object label of each service object in the corresponding candidate service object group, and the second object registration information, the second object label and the historical resource use data set of each resource using object registered by each service object, feature extraction is performed to obtain a group attribute feature set of each of the at least one candidate service object group.
[0183] According to the foregoing introduction, each first object registration information includes a plurality of object registration information fields, and each second object registration information also includes a plurality of object registration information fields. Moreover, each object registration information field is also assigned an object registration information label, which is used to mark whether the attribute value of the corresponding object registration information field is malicious registration information.
[0184] Therefore, based on each first object registration information and each second object registration information, the object registration information label carried by each object registration information field is obtained; and based on each object registration information label, the malicious registration information proportion value is obtained.
[0185] Suppose there are 5 second object registration information, and the object registration information labels included in each second object registration information are as shown in Table 4. Based on the object registration information labels of the object registration information fields of each merchant, the malicious registration information proportion sub-value of each merchant is determined, and the maximum malicious registration information proportion sub-value is output as the malicious registration proportion value. Therefore, the malicious registration information proportion value in Table 4 is
[0186] Table 4
[0187]
[0188] The service object detection method and the resource usage object detection method provided by the related art detect part of the target service objects and part of the target resource usage objects in the resource usage platform. The target service objects and the target resource usage objects detected by the embodiments of the present application are used to assign a first object label to each service object, which is used to mark whether the service object is a target service object of a malicious service provider, and a second object label to each resource usage object, which is used to mark whether the resource usage object is a target resource usage object of a malicious merchant.
[0189] Therefore, the embodiments of the present application can obtain a target service object proportion value based on the first object label of each service object, and a target resource usage object proportion value based on the second object label of each resource usage object.
[0190] For example, suppose there are 10 service accounts of service providers, and 3 service accounts of service providers carry an account label of a malicious service provider. Therefore, the target service object proportion value is
[0191] The historical resource usage data set of each resource usage object is generated based on the historical resource usage behavior of each resource usage account. The resource usage behavior refers to the way of transferring resources out or transferring resources in to complete the fund settlement between the resource usage account and the individual account or other non-individual accounts.
[0192] In the embodiment of the present application, based on each set of historical resource usage data, the proportion of suspicious transaction scenarios of each resource usage object in the transaction scenarios of corresponding historical resource usage behaviors can be determined. The suspicious transaction scenarios include transaction scenarios involving black industry chains such as gambling, pornography, fraud, and fake reviews.
[0193] For example, assuming there are 3 resource usage objects, each of which has 10 historical resource usage data, among which the first resource usage object has 3 historical resource usage data determined to belong to suspicious transaction scenarios, the second resource usage object has 4 historical resource usage data determined to belong to suspicious transaction scenarios, and the first resource usage object has 1 historical resource usage data determined to belong to suspicious transaction scenarios. The proportion of suspicious transaction scenarios is
[0194] S304: Based on the obtained set of group attribute features, a target service object group containing the target service object is screened out from at least one candidate service object group, and the target service object group is a service object providing an abnormal object registration service.
[0195] At this time, the identification target is no longer a single malicious merchant or malicious service provider, but a target service object group containing a malicious merchant and a malicious service provider. Therefore, in the embodiment of the present application, a service object group detection model based on machine learning construction, such as a logistic regression model and an XGBoost, deployed on a server is triggered daily, and the obtained set of group attribute features is used to screen out a target service object group containing a target service object from at least one candidate service object group.
[0196] The specific operation of step 304 is to input the obtained set of group attribute features into a preset service object group detection model for abnormal service detection. Each time an abnormal service prediction probability of a candidate service object group is obtained, if the abnormal service prediction probability exceeds a set probability threshold, the candidate service object group is determined to be a target service object group containing a target service object.
[0197] The service object group detection model is trained by a large amount of sample data, and the sample data includes a group attribute feature set of positive sample data and a group attribute feature set of negative sample data. The positive sample data refers to a candidate sample service object group containing one or a combination of malicious merchants, suspicious merchants, malicious service providers and suspicious service providers, and the group attribute feature set of the positive sample data includes a sample service object proportion value of malicious service providers, a sample resource usage object proportion value of malicious merchants, a sample service object proportion value of suspicious service providers, a sample resource usage object proportion value of suspicious merchants, a malicious registration information proportion value, and a suspicious registration information proportion value. The negative sample data refers to a candidate sample service object group containing only normal merchants and normal service providers, and the group attribute feature set of the negative sample data includes a sample service object proportion value of normal service providers, a sample resource usage object proportion value of normal merchants, and a normal registration information proportion value.
[0198] Using the conventional service object detection model and the resource usage object detection model, a part of sample service objects of malicious service providers and a large number of sample resource usage objects of malicious merchants are obtained in the resource usage platform. The sample service objects of the malicious service providers and the sample resource usage objects of the malicious merchants detected previously are used to add corresponding group labels to a plurality of candidate sample service object groups. The group label is used to mark whether the candidate sample service object group is a malicious service provider group.
[0199] For example, when all the sample service objects in the candidate sample service object group are sample service objects of malicious service providers, the candidate sample service object group is added with a group label of a malicious service provider group. However, such a candidate sample service object group composed of sample service objects of malicious service providers is very rare. In order to increase the number of candidate sample service object groups carrying group labels, the sample service objects in the candidate sample service object group with a sample service object proportion value of malicious service providers of more than 50% and not carrying the first object label are manually labeled.
[0200] Taking a sample service account not carrying the first object label as an example, in the process of manually labeling the sample service object, a plurality of sample resource usage accounts under the sample service account are judged to be sample resource usage accounts of malicious merchants or not by using a preset expert rule, and a corresponding second object label is added to each sample resource usage object, the second object label being a suspicious merchant or a normal merchant. If the sample resource usage account proportion value of malicious merchants in the sample service account is more than 90%, the sample service object is added with a first object label of a suspicious service provider; otherwise, the sample service object is added with a first object label of a normal service provider.
[0201] After adding the corresponding first object label to all sample service objects in the candidate sample service object group, if the sample service account proportion of malicious service providers and suspicious service providers in the candidate sample service object group reaches 90% or more, add the first object label of the suspicious service provider group to the candidate sample service object group; otherwise, add the first object label of the normal service provider group to the candidate sample service object group.
[0202] After screening out the target service object group containing the target service object, the risk control is performed on all service objects and all resource use objects in the target service object group based on the service provider. Specifically, based on the risk interval in which the abnormal service prediction probability of the target service object group is located, the corresponding risk control strategy is called to perform risk control on the corresponding target service object group.
[0203] When the abnormal service prediction probability of the target service object group is located in the first risk interval, the part of the management service provided to all service objects in the target service object group is suspended, and the part of the resource use service provided to all objects in the target service object group is suspended.
[0204] When the abnormal service prediction probability of the target service object group is located in the second risk interval, all management services provided to all service objects in the target service object group are suspended, and all resource use services provided to all objects in the target service object group are suspended.
[0205] For example, when the abnormal service prediction probability of the target service object group is located in the medium risk interval, the commission function of all service objects in the target service object group is closed, the second object label of the malicious merchant is added to all resource use objects in the target service object group, and the fund settlement time of all resource use objects is extended.
[0206] When the abnormal service prediction probability of the target service object group is located in the high risk interval, the commission function, payment function, display function and all management services of all service objects in the target service object group are closed, the second object label of the malicious merchant is added to all resource use objects in the target service object group, and the current transaction of all resource use objects is intercepted, the payment function and all resource use services of all resource use objects are closed.
[0207] Referring to Figure 4a the flowchart and Figure 4b the logic diagram, a complete process of controlling the malicious service provider and the malicious merchant in the mobile payment platform by using the above service object detection method and risk control strategy is introduced by taking a specific embodiment as an example.
[0208] S401: Data denoising is performed on all service providers for the mobile payment platform on day T for the e-commerce merchant, and the service providers in the preset whitelist are excluded;
[0209] S402: Based on the registration association relationship between the service account of each service provider and the resource use account of each e-commerce merchant, a service provider association network on day T is constructed;
[0210] S403: A clustering model based on the Fast Unfolding community discovery algorithm is called to perform group clustering on each service provider included in the service provider association network, and at least one candidate service provider group on day T is obtained;
[0211] S404: At least one candidate service provider group on day T is stored in the offline strategy system;
[0212] S405: On day T+1, at least one candidate service provider group on day T is read from the offline strategy system, and based on the first object registration information of each service provider and the second object registration information of each resource use account registered by each service provider, a group attribute feature set of each of the at least one candidate service provider group is obtained;
[0213] S406: On day T+1, a service provider group detection model is called to filter out a target service provider group containing a target service provider from the at least one candidate service provider group based on the obtained group attribute feature sets;
[0214] S407: Based on the risk interval in which the abnormal service prediction probability of the target service provider group is located, a corresponding risk control strategy is called to perform risk control on the corresponding target service provider group.
[0215] Based on the same inventive concept as the above method embodiment, the embodiments of the present application also provide a service object detection device. Referring to Figure 5 the structural schematic diagram shown, the device 500 can include:
[0216] The clustering unit 501 is configured to obtain a service object association network, the service object association network representing the registration association relationship between each service object and each resource use object;
[0217] The clustering unit 501 is configured to obtain a service object association network, the service object association network representing the registration association relationship between each service object and each resource use object;
[0218] The detection unit 502 is configured to obtain a group attribute feature set of each of the at least one candidate service object group based on the first object registration information of each service object and the second object registration information of each resource use object registered by each service object;
[0219] Based on the obtained respective group attribute feature set, a target service object group containing a target service object is screened out from at least one candidate service object group, the target service object being a service object providing an abnormal object registration service.
[0220] Optionally, the apparatus 500 further comprises a generating unit 503 which generates a service object association network in the following manner:
[0221] From the resource use platform, first object registration information of respective service objects and second object registration information of respective resource use objects registered by respective service objects are obtained;
[0222] The service objects containing common registration information are informationally associated to generate a service object association network, and based on respective common registration information, an association weight between the associated service objects in the service object association network is determined; wherein the common registration information contains one or a combination of common first object registration information and common second object registration information.
[0223] Optionally, the generating unit 503 determines an association weight by performing the following operations:
[0224] When the common registration information is the common first object registration information, a field number of a common object registration information field in the common first object registration information is taken as the association weight between the associated service objects in the service object association network;
[0225] When the common registration information is the common second object registration information, a corresponding association weight is generated based on an average value of a respective common registration information proportion of respective object registration information fields in the common second object registration information, the average value of the respective common registration information proportion of respective object registration information fields being determined based on an information number of the second object registration information having a common object registration information field and a total information number of the second object registration information contained by the associated service objects respectively;
[0226] When the common registration information contains the common first object registration information and the common second object registration information, a corresponding association weight is determined based on a field number of a common object registration information field in the common first object registration information and an average value of a respective common registration information proportion of each object registration information field.
[0227] Optionally, the generating unit 503 obtains the average value of the common registration information proportion of an object registration information field by performing the following operations:
[0228] The proportion value between the information quantity of the second object registration information having one common object registration information field and the total information quantity of the second object registration information contained by the associated service objects is respectively determined as the first common registration information proportion parameter and the second common registration information proportion parameter of one object registration information field;
[0229] The first common registration information proportion parameter and the second common registration information proportion parameter are subjected to average value processing to obtain the common registration information proportion average value of one object registration information field.
[0230] Optionally, before obtaining the first object registration information of each service object and the second object registration information of each resource using object registered by each service object from the resource using platform, the generation unit 503 is further configured to:
[0231] Data noise reduction is performed on all service objects in the resource using platform, and service objects located in a preset white list are removed.
[0232] Optionally, the clustering unit 501 is configured to:
[0233] Based on the common registration information between the service objects, the closeness between each service object in the service object associated network is determined, and each service object whose closeness satisfies a set closeness threshold is clustered into the same group to obtain at least one candidate service object group.
[0234] Optionally, the clustering unit 501 is configured to:
[0235] For each service object contained in the service object associated network, the following operations are performed in a cyclic iteration manner until an iteration stop condition is satisfied, and at least one candidate service object group is output:
[0236] Based on the common registration information between the service objects, the closeness between each service object is determined.
[0237] The service object clustering set whose closeness satisfies a set closeness threshold is clustered into the same group to obtain a new plurality of service object clustering sets.
[0238] Optionally, the clustering unit 501 is configured to:
[0239] For each service object clustering set to which each service object belongs, the following operations are respectively performed: the closeness between one service object clustering set and at least one associated service object clustering set is obtained, wherein each associated service object clustering set is a service object clustering set that has an association relationship with one service object clustering set, and the association relationship is determined based on the common registration information between the two service object clustering sets.
[0240] Optionally, the clustering unit 501 determines the service object cluster set to which each service object belongs by performing any of the following operations:
[0241] When it is the first round of iteration, the service object association network is used to determine the plurality of service object cluster sets to which each service object belongs in the current round;
[0242] When it is the non-first round of iteration, the plurality of service object cluster sets clustered in the last round are used as the plurality of service object cluster sets to which each service object belongs in the current round.
[0243] Optionally, the detection unit 502 is configured to:
[0244] Based on the first object registration information and the first object label of each service object in the corresponding candidate service object group, and the second object registration information, the second object label and the historical resource use data set of each resource use object registered by each service object, feature extraction is performed to obtain a group attribute feature set of each candidate service object group.
[0245] Optionally, the detection unit 502 is configured to:
[0246] Each obtained group attribute feature set is input into a preset service object group detection model for abnormal service detection, and each time an abnormal service prediction probability of a candidate service object group is obtained, when the abnormal service prediction probability exceeds a set probability threshold, the candidate service object group is determined as a target service object group containing a target service object.
[0247] Optionally, after the target service object group containing the target service object is screened out, the device 500 further comprises a risk control unit 504, and the risk control unit 504 is configured to:
[0248] Based on the risk interval in which the abnormal service prediction probability of the target service object group is located, a corresponding risk control strategy is called to perform risk control on the corresponding target service object group.
[0249] Optionally, the risk control unit 504 is configured to:
[0250] When the abnormal service prediction probability of the target service object group is located in the first risk interval, the provision of part of the management services to all service objects in the target service object group and the provision of part of the resource use services to all objects in the target service object group are suspended;
[0251] When the predicted probability of abnormal service for the target service object group is in the second risk range, all management services and all resource usage services for all service objects in the target service object group will be suspended.
[0252] For ease of description, the above sections are divided into modules (or units) according to their functions and described separately. Of course, in implementing this application, the functions of each module (or unit) can be implemented in one or more software or hardware components.
[0253] Having introduced the service object detection method and apparatus according to exemplary embodiments of this application, we will now introduce a computer device according to another exemplary embodiment of this application.
[0254] Those skilled in the art will understand that various aspects of this application can be implemented as a system, method, or program product. Therefore, various aspects of this application can be specifically implemented in the following forms: a completely hardware implementation, a completely software implementation (including firmware, microcode, etc.), or a combination of hardware and software implementations, collectively referred to herein as a "circuit," "module," or "system."
[0255] Based on the same inventive concept as the above-described method embodiments, this application also provides a computer device, see below. Figure 6 As shown, the computer device 600 may include at least a processor 601 and a memory 602. The memory 602 stores program code, which, when executed by the processor 601, causes the processor 601 to perform the steps of any of the aforementioned service platform access methods.
[0256] In some possible implementations, the computing device according to this application may include at least one processor and at least one memory. The memory stores program code that, when executed by the processor, causes the processor to perform the steps of the service object detection method described above. For example, the processor may perform actions such as... Figure 3a The steps are shown in the figure.
[0257] The following reference Figure 7 To describe a computing device 700 according to this embodiment of the present application. Figure 6 The computing device 700 is merely an example and should not impose any limitations on the functionality and scope of use of the embodiments of this application.
[0258] like Figure 7As shown, the computing device 700 is in the form of a general-purpose computing device. The components of computing device 700 can include, but are not limited to, the aforementioned at least one processing unit 701, the aforementioned at least one memory unit 702, a bus 703 that connects the various system components, including the memory unit 702 and the processing unit 701.
[0259] The bus 703 represents one or more of any of several bus structures, including a memory bus or memory controller, a peripheral bus, a processor or local bus using any of a variety of bus architectures, and the like.
[0260] The memory unit 702 can include read-only memory (ROM) 7023 in the form of flash memory or other suitable technology, and can also include random access memory (RAM) 7021 in the form of synchronous dynamic random access memory (SDRAM) or other suitable technology, and / or cache memory unit 7022.
[0261] The memory unit 702 can also include a program / utility 7025 having a set of programs / modules 7024, including an operating system, one or more application programs, other program modules, and program data, each of which can be executed by the processing unit 701, and possibly a network environment implementation of each of these examples, or a combination.
[0262] The computing device 700 can also communicate with one or more external devices 704 such as a keyboard or a pointing device, through an input / output (I / O) interface(s) 705. The I / O interface 705 can also include one or more devices for allowing communication between the computing device 700 and one or more other devices. For example, the I / O interface 705 can include a communication interface 706 to enable communication with one or more other computing devices. The communication interface 706 can include a modem or other device for
[0263] Based on the same inventive concept as the method embodiments described above, each aspect of the service object detection method provided by the present application can also be implemented in the form of a program product, which includes program code for causing a computer device to execute the steps of the service object detection method described above in the specification when the program product is run on the computer device, for example, the computer device can execute the steps shown in Figure 3a .
[0264] The program product can employ any combination of one or more computer readable media or storage media. The computer readable media or storage media can be a computer readable signal medium or a computer readable storage medium. A computer readable storage medium can be, for example, but not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any suitable combination of the foregoing. More specific examples (a non-exhaustive list) of the computer readable storage medium include the following: an electrical connection having one or more wires, a portable disc, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0265] While the preferred embodiments of the application have been described, additional variations and modifications can be employed by those skilled in the art once armed with the concepts reflected in the preferred embodiments without departing from the scope of the application. Accordingly, the appended claims are intended to embrace all such additional variations and modifications as fall within the scope of the application.
[0266] It will be apparent to those skilled in the art that various modifications and variations can be made to the present application without departing from the spirit or scope of the application. Thus, it is intended that the present application cover the modifications and variations of this application provided they come within the scope of the appended claims and their equivalents.
Claims
1. A method for detecting service objects, characterized in that, include: Obtain the service object association network, which represents the registration association relationship between each service object and each resource user object; During the process of generating the service object association network, the following operations are performed to determine an association weight between related service objects in the service object association network: when the common registration information is common first object registration information, the number of fields in the common object registration information field in the common first object registration information is used as the association weight between related service objects in the service object association network. When the common registration information is common second object registration information, a corresponding association weight is generated based on the average proportion of common registration information in each object registration information field of the common second object registration information. The average proportion of common registration information in each object registration information field is determined by the number of second object registration information with a common object registration information field and the total number of second object registration information contained in each of the associated service objects. When the common registration information includes the common first object registration information and the common second object registration information, a corresponding association weight is determined based on the number of common object registration information fields in the common first object registration information and the average proportion of common registration information in each object registration information field. Cluster the service objects included in the service object association network to obtain at least one candidate service object group; Based on the first object registration information of each service object and the second object registration information of each resource user object registered by each service object, the group attribute feature set of each of the at least one candidate service object group is obtained respectively. Based on the obtained set of attribute features of each group, a target service object group containing the target service object is selected from the at least one candidate service object group. The target service object is a service object that provides abnormal object registration service.
2. The method as described in claim 1, characterized in that, The service object association network is generated in the following way: From the resource usage platform, obtain the first object registration information of each service object and the second object registration information of each resource user object registered by each service object; The service objects containing the common registration information are associated to generate the service object association network, and the association weights between related service objects in the service object association network are determined based on each common registration information; wherein, the common registration information includes one or a combination of the common first object registration information and the common second object registration information.
3. The method as described in claim 1, characterized in that, The average percentage of common registration information in an object's registration information field can be obtained by performing the following operations: The ratio between the number of second object registration information items that share a common object registration information field and the total number of second object registration information items contained in each of the associated service objects is determined as the first common registration information ratio parameter and the second common registration information ratio parameter of the object registration information field, respectively. The first common registration information percentage parameter and the second common registration information percentage parameter are averaged to obtain the average common registration information percentage of the object registration information field.
4. The method as described in claim 2, characterized in that, Before obtaining the first object registration information of each service object and the second object registration information of each resource user object registered by each service object from the resource usage platform, the method further includes: Data noise reduction is performed on all service objects in the resource usage platform, and service objects located in the preset whitelist are removed.
5. The method according to any one of claims 1-4, characterized in that, The step of performing group clustering on the service object association network to obtain at least one candidate service object group includes: Based on the common registration information among the service objects, the intimacy between each service object in the service object association network is determined, and each service object whose intimacy meets the set intimacy threshold is clustered into the same group to obtain the at least one candidate service object group.
6. The method as described in claim 5, characterized in that, The process of determining the intimacy level between service objects based on their shared registration information, and clustering service objects whose intimacy levels meet a set intimacy threshold into the same group to obtain at least one candidate service object group includes: For each service object included in the service object association network, perform the following operations in a loop iterative manner until the iteration stopping condition is met, and output the at least one candidate service object group: Based on the common registration information among the service objects, the closeness between the service object cluster sets to which each service object belongs is determined; The service object clusters that meet the set intimacy threshold are grouped into the same group to obtain multiple new service object clusters.
7. The method as described in claim 6, characterized in that, The step of determining the closeness between the service object clusters to which each service object belongs based on the common registration information among the service objects includes: For each service object to which it belongs, the following operations are performed: obtain the affinity between a service object cluster and at least one associated service object cluster, wherein each associated service object cluster is a service object cluster that is associated with the first service object cluster, and the association is determined based on the common registration information between the two service object clusters.
8. The method as described in claim 6, characterized in that, The service object cluster set to which each of the service objects belongs is determined by performing any of the following operations: In the first iteration, each service object in the service object association network is taken as a cluster set of multiple service objects to which each service object belongs in the current round; When it is not the first iteration, the cluster set of multiple service objects after the previous round of clustering is used as the cluster set of multiple service objects to which each service object belongs in the current round.
9. The method as described in claim 1, characterized in that, The step of obtaining the group attribute feature set for each of the at least one candidate service object group based on the first object registration information of each service object and the second object registration information of each resource user object registered by each service object includes: Based on the first object registration information and first object tag of each service object in the corresponding candidate service object group, and the second object registration information, second object tag and historical resource usage data set of each resource user object registered by each service object, feature extraction is performed to obtain the group attribute feature set of each of the at least one candidate service object group.
10. The method as described in claim 1, characterized in that, The step of filtering out the target service object group containing the target service object from the at least one candidate service object group based on the obtained set of attribute features of each group includes: The obtained sets of group attribute features are input into the preset service object group detection model for abnormal service detection. For each candidate service object group, the abnormal service prediction probability is obtained. When the abnormal service prediction probability exceeds the set probability threshold, the candidate service object group is determined to be the target service object group containing the target service object.
11. The method as described in claim 1, characterized in that, After filtering out the target service object group containing the target service object, the following is also included: Based on the risk range of the predicted abnormal service probability of the target service object group, the corresponding risk control strategy is invoked to carry out risk control on the corresponding target service object group.
12. The method as described in claim 11, characterized in that, The step of invoking corresponding risk management strategies to manage the risk of the target service object group based on the risk range of the predicted probability of abnormal service based on the target service object group includes: When the abnormal service prediction probability of the target service object group is in the first risk range, the provision of some management services to all service objects in the target service object group and the provision of some resource usage services to all objects in the target service object group will be suspended. When the abnormal service prediction probability of the target service object group is in the second risk range, all management services are suspended to all service objects in the target service object group, and all resource usage services are suspended to all objects in the target service object group.
13. A service object detection device, characterized in that, include: Clustering unit, used to obtain service object association network, wherein the service object association network represents the registration association relationship between each service object and each resource user object; During the process of generating the service object association network, the following operations are performed to determine an association weight between related service objects in the service object association network: when the common registration information is common first object registration information, the number of fields in the common object registration information field in the common first object registration information is used as the association weight between related service objects in the service object association network. When the common registration information is common second object registration information, a corresponding association weight is generated based on the average proportion of common registration information in each object registration information field of the common second object registration information. The average proportion of common registration information in each object registration information field is determined by the number of second object registration information with a common object registration information field and the total number of second object registration information contained in each of the associated service objects. When the common registration information includes the common first object registration information and the common second object registration information, a corresponding association weight is determined based on the number of common object registration information fields in the common first object registration information and the average proportion of common registration information in each object registration information field. Cluster the service objects included in the service object association network to obtain at least one candidate service object group; The detection unit is used to obtain the group attribute feature set of each of the at least one candidate service object group based on the first object registration information of each of the service objects and the second object registration information of each resource user object registered by each of the service objects. Based on the obtained set of attribute features of each group, a target service object group containing the target service object is selected from the at least one candidate service object group. The target service object is a service object that provides abnormal object registration service.
14. A computer device, characterized in that, It includes a processor and a memory, wherein the memory stores program code that, when executed by the processor, causes the processor to perform the steps of the method according to any one of claims 1 to 12.
15. A computer-readable storage medium, characterized in that, It includes program code that, when the program product is run on a computer device, causes the computer device to perform the steps of the method according to any one of claims 1 to 12.
16. A computer program product, characterized in that, It includes computer instructions that, when executed by a processor, implement the steps of the method according to any one of claims 1 to 12.
Citation Information
Patent Citations
Indirect connection service provider risk evaluation method and device
CN108876188A
Abnormal service provider determination method, device and equipment, and storage medium
CN111353779A