Risk merchant identification method, device, equipment, medium and product
By constructing a transaction network graph and utilizing a risk merchant identification model, the problems of low identification efficiency and poor results in existing technologies have been solved, enabling rapid and efficient identification of potential risk merchants.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-02-13
- Publication Date
- 2026-03-24
AI Technical Summary
Existing technologies for identifying risky merchants mainly rely on the analysis of transaction information of individual merchants, resulting in low identification efficiency and failure to discover potential risky merchants, thus reducing the identification effect.
A transaction network graph with accounts, users, and merchants as nodes is constructed. The potential relationships between various entities are discovered through the graph structure. A risk merchant identification model is used to identify suspected risk merchants associated with target risk accounts from the transaction network graph. The identification efficiency and accuracy are improved through community identification and multi-angle risk identification rules.
It enables rapid identification of potential risky merchants, improves the efficiency and effectiveness of risky merchant identification, and can discover relationships between entities that are geographically distant, thus promptly identifying groups of risky merchants.
Smart Images

Figure CN116205488B_ABST
Abstract
Description
Technical Field
[0001] This application pertains to information processing technology, and particularly relates to a method, apparatus, equipment, medium, and product for identifying risky merchants. Background Technology
[0002] In recent years, with various financial institutions launching acquiring businesses and the rapid emergence of specialized acquiring institutions and third-party platforms, the number of risky merchants engaging in illegal cash-out and other violations has been increasing, and they are gradually showing a trend towards concealment and clustering, harming the interests of various institutions and platforms. Therefore, how to identify risky merchants with illegal activities from among numerous merchants has become one of the urgent problems to be solved.
[0003] Currently, the main method for identifying risky merchants is based on analyzing the characteristics of individual merchants. This method is not only inefficient but also fails to identify potential risky merchants, thus reducing the effectiveness of risky merchant identification. Summary of the Invention
[0004] This application provides a method, apparatus, device, medium, and product for identifying risky merchants, which can quickly identify potential risky merchants and improve the efficiency and effectiveness of risky merchant identification.
[0005] In a first aspect, embodiments of this application provide a method for identifying risky merchants, the method comprising:
[0006] Obtain merchant transaction information corresponding to multiple merchants;
[0007] Based on the merchant transaction information, a transaction network graph is constructed with accounts, users, and merchants as nodes, wherein the transaction network graph is used to describe the relationship between accounts, users, and merchants;
[0008] Based on the transaction network graph, identify suspected risk merchants associated with the target risk account from among the multiple merchants;
[0009] Obtain a portion of the transaction network graph associated with the suspected high-risk merchant to obtain the target network graph;
[0010] Based on the target network graph, a risk merchant identification model is used to identify the risk of merchants in the target network graph, thereby obtaining risk merchants.
[0011] Secondly, embodiments of this application provide a risk merchant identification device, the device comprising:
[0012] The information acquisition module is used to acquire merchant transaction information corresponding to multiple merchants;
[0013] The graph construction module is used to construct a transaction network graph with accounts, users and merchants as nodes based on the merchant transaction information. The transaction network graph is used to describe the relationship between accounts, users and merchants.
[0014] The first identification module is used to identify, based on the transaction network graph, suspected risk merchants associated with the target risk account from among the multiple merchants;
[0015] The target acquisition module is used to acquire a portion of the graph associated with the suspected risky merchant from the transaction network graph, thereby obtaining the target network graph;
[0016] The second identification module is used to identify the risk of merchants in the target network graph based on the target network graph and using a risk merchant identification model to obtain risk merchants.
[0017] Thirdly, embodiments of this application provide an electronic device, which includes: a processor and a memory storing computer program instructions;
[0018] When the processor executes the computer program instructions, it implements the steps of the risk merchant identification method as described in any embodiment of the first aspect.
[0019] Fourthly, embodiments of this application provide a computer-readable storage medium storing computer program instructions, which, when executed by a processor, implement the steps of the risk merchant identification method as described in any embodiment of the first aspect.
[0020] Fifthly, embodiments of this application provide a computer program product in which instructions, when executed by a processor of an electronic device, cause the electronic device to perform the steps of the risk merchant identification method as described in any embodiment of the first aspect.
[0021] The risk merchant identification method, apparatus, device, medium, and product in this application embodiment construct a transaction network graph to describe the relationships between accounts, users, and merchants. Using this transaction network graph, suspected risk merchants associated with a target risk account are identified from multiple merchants. Then, a portion of the graph associated with the suspected risk merchant, i.e., the target network graph, is obtained from the transaction network graph. A risk merchant identification model is then used to identify the risk merchants in this target network graph, thus obtaining the risk merchants. In this way, because the graph structure can reveal potential relationships between entities, even entities with large distances can be quickly retrieved based on association paths, relying on the performance advantages of the graph structure. This allows for the discovery of relationships between potential risk merchants, rapid identification of potential risk merchant groups, and improved efficiency and effectiveness in identifying risk merchants. Attached Figure Description
[0022] To more clearly illustrate the technical solutions of the embodiments of this application, the accompanying drawings used in the embodiments of this application will be briefly introduced below. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0023] Figure 1 This is a flowchart illustrating a risk merchant identification method provided in one embodiment of this application;
[0024] Figure 2 This is a schematic diagram of the transaction network map provided in this application;
[0025] Figure 3 This is a flowchart illustrating a risk merchant identification method provided in another embodiment of this application;
[0026] Figure 4 This is a schematic diagram of the community identification results provided in this application;
[0027] Figure 5 This is a schematic diagram of the complete community formation process provided in this application;
[0028] Figure 6 This is a schematic diagram of the potential risk community discovery process provided in this application;
[0029] Figure 7 This is a flowchart illustrating a risk merchant identification method provided in another embodiment of this application;
[0030] Figure 8 This is a schematic diagram illustrating the use of a model to identify risky merchants, as provided in this application.
[0031] Figure 9 This is a schematic diagram of the structure of a risk merchant identification device provided in one embodiment of this application;
[0032] Figure 10 This is a schematic diagram of the structure of an electronic device provided in one embodiment of this application. Detailed Implementation
[0033] The features and exemplary embodiments of various aspects of this application will be described in detail below. To make the objectives, technical solutions, and advantages of this application clearer, the application will be further described in detail below with reference to the accompanying drawings and specific embodiments. It should be understood that the specific embodiments described herein are only intended to explain this application and not to limit it. For those skilled in the art, this application can be implemented without some of these specific details. The following description of the embodiments is merely to provide a better understanding of this application by illustrating examples.
[0034] It should be noted that, in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.
[0035] Currently, the identification of risky merchants mainly involves analyzing the transaction information of individual merchants to determine whether they are risky. However, existing identification methods are inefficient because they require analyzing and identifying the transaction characteristics of each merchant individually. Furthermore, these methods cannot detect potential risky merchants. For example, if a merchant's own transaction information does not show obvious characteristics of a risky merchant, but it has a potential connection with risky merchants, then that merchant may not be identified as a risky merchant, thus reducing the effectiveness of risky merchant identification.
[0036] To address the problems of existing technologies, embodiments of this application provide a method, apparatus, device, medium, and product for identifying high-risk merchants. This method can be applied to scenarios involving the identification of high-risk merchants. The high-risk merchant identification method provided in this application embodiment is described below.
[0037] Figure 1 This is a flowchart illustrating a risk merchant identification method provided in one embodiment of this application. Figure 1 As shown, the risk merchant identification method may specifically include the following steps:
[0038] S110. Obtain merchant transaction information corresponding to multiple merchants;
[0039] S120. Based on merchant transaction information, construct a transaction network graph with accounts, users, and merchants as nodes, wherein the transaction network graph is used to describe the relationship between accounts, users, and merchants;
[0040] S130. Based on the transaction network graph, identify suspected risk merchants associated with the target risk account from multiple merchants;
[0041] S140. Obtain a portion of the transaction network graph that is associated with the suspected risky merchants to obtain the target network graph;
[0042] S150. Based on the target network graph, the risk merchant identification model is used to identify the risk of merchants in the target network graph and obtain the risk merchants.
[0043] Therefore, by constructing a transaction network graph to describe the relationships between accounts, users, and merchants, this graph is used to identify potentially risky merchants associated with the target risky account from among multiple merchants. Then, a portion of the graph associated with the potentially risky merchant—the target network graph—is obtained from this transaction network graph. A risky merchant identification model is then used to identify the merchants in this target network graph to determine the risky merchants. In this way, because the graph structure can reveal potential relationships between entities, even entities with large distances can be quickly retrieved based on their association paths, thanks to the performance advantages of the graph structure. This allows for the discovery of relationships between potential risky merchants, rapid identification of potential risky merchant groups, and improved efficiency and effectiveness in identifying risky merchants.
[0044] The specific implementation methods for each of the above steps are described below.
[0045] In some implementations, in S110, the merchant transaction information may include information related to the merchant and the transaction, such as transaction flow information, merchant holding relationship information, account holding relationship information, merchant equity information, etc.
[0046] In addition, merchant transaction information may involve multiple entities such as multiple merchants, multiple accounts, and multiple users, and a transaction network graph can be constructed based on the relationships between these multiple entities in subsequent steps.
[0047] In some implementations, in S120, since the merchant transaction information contains information about the merchant and its transactions, a transaction network graph can be constructed based on the merchant transaction information, with accounts, users, and merchants as entities.
[0048] In this embodiment, the transaction network graph primarily adopts an "entity-relationship-entity" representation and is constructed based on this representation. The relationships between entities can be represented as relationships between accounts, between accounts and users, between accounts and merchants, between users, between users and merchants, and between merchants, etc. Furthermore, the relationships between entities can be represented as edges in the transaction network graph, while the entities themselves can be represented as nodes in the transaction network graph.
[0049] In some implementations, the above-mentioned S120 may specifically include:
[0050] Based on merchant transaction information, determine the relationships between multiple accounts, users and merchants, where the relationships include at least one of transfer transaction relationships, account holding relationships and merchant holding relationships;
[0051] Based on the relationships, a transaction network graph is constructed with accounts, users, and merchants as nodes.
[0052] Here, because the merchant transaction information includes transaction flow information, merchant holding relationship information, account holding relationship information, and merchant equity information, the relationship between accounts, users and merchants can be determined through this information. For example, the transfer transaction relationship between accounts, the account holding relationship between accounts and merchants or users, and the merchant holding relationship between users and merchants.
[0053] For example, a transaction network graph can be constructed using accounts, users, and merchants as entities, based on transfer transaction relationships, account holding relationships, and merchant holding relationships. Specific graph construction rules can include establishing associations between accounts and users based on the holding relationship between cardholders and accounts; establishing associations between users and merchants based on the holding relationship between corporate users and merchants; establishing associations between accounts based on transfer relationships between accounts; and establishing associations between users based on publicly available external data such as shares in merchants jointly held by users. Thus, for example, the following can be obtained: Figure 2 The transaction network diagram shown.
[0054] Of course, in addition to the above-mentioned graph construction rules, other relationships can also be used to establish connections between entities, that is, edges between nodes. For example, the consumption relationship between a user's personal account and a merchant can establish a connection between an account and a merchant, etc., which are not limited here.
[0055] In some implementations, in S130, the target risk account can be a risk account with relatively obvious characteristics of violation identified using basic risk control rules and strategies, and the number of such target risk accounts can be one or more.
[0056] For example, merchants directly and / or indirectly associated with the target risk account can be searched in the constructed transaction network graph as suspected risk merchants. Merchants directly associated with the target risk account can refer to merchants corresponding to merchant nodes directly connected to the node corresponding to the target risk account in the transaction network graph. Merchants indirectly associated with the target risk account can refer to merchants corresponding to merchant nodes within a preset number of connection hops connected to the node corresponding to the target risk account in the transaction network graph. This preset number of connection hops can be set according to actual needs and is not limited here.
[0057] In some implementations, in S140, the target network graph can be a portion of the graph associated with the suspected risky merchant, which is segmented from the transaction network graph. The portion of the graph associated with the suspected risky merchant may include, for example, the node corresponding to the suspected risky merchant and its nodes within a preset number of connection hops, as well as the connection edges between these nodes.
[0058] Since the transaction network graph contains nodes corresponding to both risky merchants and normal merchants, in order to improve identification efficiency and reduce the complexity of risky merchant identification, a portion of the graph associated with suspected risky merchants can be segmented from the transaction network graph. This allows for the elimination of the need to identify normal merchants when using the risky merchant identification model for risk identification in the future.
[0059] In some implementations, in S150, the risk merchant identification model can be a trained graph deep neural network. This risk merchant identification model can be used to identify risk merchants in the graph, classify the merchants corresponding to the merchant nodes contained in the graph according to graph features and node features, and then finally determine the risk merchants from the suspected risk merchants.
[0060] In addition, to further improve the efficiency and effectiveness of identifying risky merchants and to promptly detect potential risky merchants, in some implementations, the aforementioned S130 may specifically include, for example... Figure 3 The steps shown are as follows:
[0061] S1301. Perform community segmentation on the nodes in the transaction network graph to obtain multiple communities corresponding to the transaction network graph;
[0062] S1302. Identify the target community from multiple communities that is associated with the target risk account;
[0063] S1303. Identify merchants in the target community that are associated with the target risk account as suspected risk merchants.
[0064] Because high-risk merchants often exhibit clustering characteristics, community identification can be performed on the transaction network graph to discover risky communities and subsequently identify potential high-risk merchants. This further improves the efficiency and effectiveness of high-risk merchant identification, allowing for the timely discovery of potential high-risk merchants.
[0065] In some implementations, in S1301, a community can be a tightly connected set of nodes with many internal connections and relatively few external connections. For example, after performing community partitioning on the nodes in a transaction network graph, the following can be obtained: Figure 4 The community identification results shown are illustrated, where small dots represent nodes and large circles represent communities. Figure 4The CCP comprises 12 communities, each containing several nodes, including but not limited to merchant nodes, account nodes, and user nodes. This creates multiple communities that integrate merchants, accounts, and users.
[0066] Based on this, in some implementations, the above S1301 may specifically include:
[0067] Based on a pre-defined community identification algorithm, community identification is performed on nodes in the transaction network graph to obtain multiple initial communities;
[0068] Perform the following steps for each of the multiple initial communities to obtain multiple communities corresponding to the transaction network graph:
[0069] Identify the core accounts within the initial community and obtain transaction flow information corresponding to these core accounts;
[0070] Search for target merchants not in the initial community based on transaction flow information;
[0071] Once a target merchant is found, the node corresponding to the target merchant is categorized into an initial community, thus obtaining the community.
[0072] In this embodiment, the preset community identification algorithm can be, for example, the Louvain algorithm. The Louvain algorithm is a modular community identification algorithm that performs well in both identification efficiency and identification effect.
[0073] For example, the general idea behind using the Louvain algorithm to identify communities among nodes in a transaction network graph can be summarized as follows:
[0074] 1) Treat each node in the graph as an independent community, with the number of communities being the same as the number of nodes;
[0075] 2) For each node i, try to assign node i to the community where each of its neighboring nodes is located in turn, calculate the change in modularity ΔQ before and after the assignment, and record the neighboring node with the largest ΔQ. If maxΔQ>0, then assign node i to the community where the neighboring node with the largest ΔQ is located; otherwise, leave it unchanged.
[0076] 3) Return to step 2) until the community affiliation of all nodes no longer changes;
[0077] 4) Compress the graph by compressing all nodes in the same community into a new node. The weights of the edges between nodes within the community are converted into the weights of the cycles in the new node, and the weights of the edges between communities are converted into the weights of the edges between the new nodes.
[0078] 5) Return to step 1) until the modularity of the entire graph no longer changes.
[0079] Thus, through the above process, the community identification result corresponding to the transaction network graph can be obtained. The community identification result can be represented as the funds held by each merchant's account eventually flowing and converging into one or several accounts, with these one or several core accounts as the main body, forming an initial community integrating merchants, accounts, and users.
[0080] Based on this, for each initial community, further searches can be conducted according to the transaction flow corresponding to the core account in the initial community to identify merchants corresponding to hidden scattered nodes that did not originally belong to the initial community. Then, the account nodes and merchant nodes corresponding to the merchant are assigned to the initial community. After a certain number of consecutive searches, a complete community is finally formed.
[0081] For example, such as Figure 5 As shown, the initial community includes nodes of core account a, core account b, and core account c. Based on the transaction flow, it is identified that there is a transfer transaction record between core account a and account i outside the initial community, and there is also a transfer transaction record between core account c and account j outside the initial community. Since both account i and account j belong to merchant c, the three nodes of merchant c, account i, and account j can all be assigned to the initial community, thus forming a complete community.
[0082] In some implementations, in S1302, the target community can be a community with potential risks. The community associated with the target risk account can include the community containing the node corresponding to the target risk account in the transaction network graph. Additionally, hidden transaction flows can be discovered based on transfer transactions within the community, thereby uncovering potential risk communities.
[0083] Based on this, in some implementations, the above-mentioned S1302 may specifically include:
[0084] The community containing the target risk account was identified from multiple communities as the primary target community;
[0085] The community that has a transactional relationship with the first target community is identified from multiple communities as the second target community;
[0086] The target community includes the first target community and the second target community.
[0087] Here, transaction relationships include, but are not limited to, direct transaction relationships and indirect transaction relationships. Direct transaction relationships can be, for example, direct transfers, which are reflected in direct connections between communities. Indirect transaction relationships can be, for example, indirect transfers, which are reflected in indirect connections between communities within a preset number of hops.
[0088] For example, such as Figure 6As shown, the target risk account belongs to community 61, which is the first target community. If a path search reveals that core account a in community 61 has transferred funds to account k outside of community 61, and account k has transferred funds to account j in community 62, then community 62 can be identified as a risk community, i.e., the second target community. In this way, potential risky trading communities can be identified.
[0089] In some implementations, in S1303, when identifying suspected risky merchants, merchants directly associated with the target risky account can be identified as suspected risky merchants, such as merchants corresponding to merchant nodes directly connected to the node corresponding to the target risky account in the transaction network graph. Alternatively, merchants indirectly associated with the target risky account can also be identified as suspected risky merchants. For example, based on the transfer relationships between accounts within the community, the relationships between merchant holders, and combined with expert rules and strategies, merchants that are deeply hidden and whose risk characteristics are not obvious can be identified.
[0090] Based on this, in some implementations, the above-mentioned S1303 may specifically include:
[0091] The merchants to which the target risk accounts belong in the target community are identified as the first suspected risk merchants;
[0092] Merchants identified from the target community who are associated with the first suspected risk merchant are designated as the second suspected risk merchants;
[0093] Among them, suspected risk merchants include first suspected risk merchants and second suspected risk merchants.
[0094] Here, based on the transfer relationships between accounts within the target community, the relationships between merchant holders, and in conjunction with expert rules and strategies, the merchants associated with the first suspected risk merchant, i.e., the second suspected risk merchant, can be identified.
[0095] For example, if the merchant to which the target risk account belongs is merchant a, then merchant a can be identified as the first suspected risk merchant. Based on this, if there is a transfer relationship between the target risk account and account b, then merchant b to which account b belongs can be identified as the second suspected risk merchant. Additionally, if user a, the holder of merchant a, also holds merchant c, then merchant c can also be identified as the second suspected risk merchant. Of course, other relationships can also be used to identify suspected risk merchants, which are not limited here.
[0096] In this way, the above-mentioned process of identifying suspected merchants can uncover those that are deeply hidden and whose risk characteristics are not obvious, thereby further improving the identification effect of risky merchants.
[0097] In addition, in order to identify risky merchants from multiple risk identification perspectives and improve the accuracy of the identification results, this application embodiment also divides the target network graph into multiple sub-graphs, and then identifies risky merchants based on each sub-graph.
[0098] Based on this, in some implementations, the risk merchant identification model may include N classification models, with each classification model corresponding to a risk identification rule, where N is an integer greater than 1.
[0099] Accordingly, the above-mentioned S150 may specifically include, for example: Figure 7 The steps shown are as follows:
[0100] S1501. Based on N risk identification rules, the target network graph is split into N sub-graphs.
[0101] S1502. Using each of the N classification models, risk assessment is performed on the merchants in the sub-maps obtained by splitting under the risk identification rules corresponding to the classification model, and the assessment results output by the N classification models are obtained respectively.
[0102] S1503. Determine the risk merchants based on the judgment results output by N classification models.
[0103] In this way, by splitting the target network graph into multiple sub-graphs according to different risk identification rules, and then judging the risk of merchants based on each sub-graph, the final risk merchants are determined by combining the judgment results of each sub-graph. This allows risk merchants to be identified from different risk identification perspectives, thereby improving the accuracy of the final identification results.
[0104] In some implementations, in S1501, the N risk identification rules can be N distinct risk identification rules set from multiple risk identification perspectives. Specifically, risk identification rules can be set based on account transaction data, considering characteristics such as time, stability, and density. The time characteristic can be reflected in the transaction time interval, such as the time interval between the two most recent transactions between two accounts; the stability characteristic can be reflected in whether the transaction or transfer cycle is fixed; and the density characteristic can be reflected in whether the transaction or transfer amount falls within a fixed range.
[0105] Based on this, for example, one risk identification rule can be set as "the time interval between two transactions is less than 0.01s". Based on this risk identification rule, if the time interval between the two most recent transactions between two accounts in the target network graph is less than 0.01s, the connection edge between the two account nodes is retained; otherwise, the connection edge between the two account nodes is cut off. In this way, a sub-graph obtained by splitting the target network graph according to this risk identification rule can be obtained.
[0106] In some implementations, in S1502, different classification models can be pre-trained for different risk identification rules. The classification model can be a network structure formed by stacking graph convolutional layers and max pooling layers.
[0107] Here, a subgraph can correspond to a classification model. For example, if the subgraph m is obtained by splitting the target network graph based on the risk identification rule M, then the classification model trained for the risk identification rule M can be used to determine the risk of the merchants included in the subgraph m and output the determination result corresponding to each merchant in the subgraph m. The determination result can include whether the merchant is a risky merchant or a normal merchant.
[0108] Based on this, in some implementations, the above-mentioned S1502 may specifically include:
[0109] For each of the N sub-graphs, feature extraction is performed to obtain the feature information corresponding to each of the N sub-graphs. The feature information includes graph feature information and node feature information.
[0110] The feature information corresponding to each of the N sub-maps is input into the classification model of the corresponding risk identification rule. The classification model is used to determine the risk of merchants in the sub-maps, and the judgment results output by the N classification models are obtained.
[0111] Here, graph feature information can be feature information used to describe the connection relationships between nodes in the graph, such as the degree matrix and adjacency matrix. Node feature information can be feature information used to describe the characteristics of the nodes themselves in the graph.
[0112] For example, when extracting features from each subgraph, a degree matrix, an adjacency matrix, and a feature list recording the feature information of each node in the subgraph can be constructed for each subgraph. Based on this, the information extracted from each subgraph can be input into the corresponding classification model, and then the classification model can be used to determine the risk of merchants in each subgraph, determining whether a merchant is a risky merchant, and obtaining a judgment result. Since one classification model can output one judgment result, N judgment results can be obtained for each merchant in the target network graph.
[0113] In some implementations, in S1503, after obtaining the judgment results output by N classification models respectively, the risky merchants can be finally determined based on the judgment results output by the N classification models respectively.
[0114] In some examples, such as Figure 8As shown, sub-map a can be input into classification model A, sub-map b can be input into classification model B, and so on. Then, by comprehensively considering the judgment results output by each classification model, the final risk merchant identification result is obtained.
[0115] Therefore, to improve the accuracy of the final judgment, a voting method can be used to determine whether a merchant is at risk. In some implementations, S1503 may specifically include:
[0116] Based on the judgment results output by N classification models, determine the percentage of judgment results that classify the first merchant as a risk merchant, where the first merchant is any merchant in the target network graph;
[0117] If the percentage of the judgment results exceeds the preset threshold, the first merchant will be identified as a risk merchant.
[0118] For example, if n out of the judgment results output by N classification models classify the first merchant as a risky merchant, then the proportion of judgment results classifying the first merchant as a risky merchant is n / N. In this case, if n / N is greater than a preset threshold, the first merchant can be identified as a risky merchant; if n / N is not greater than the preset threshold, the first merchant can be identified as a normal merchant. The preset threshold can be set according to actual needs and is not limited here.
[0119] Therefore, by using the voting method described above to determine whether a merchant is a risky merchant, the results obtained from different risk identification perspectives can be comprehensively considered, resulting in a more accurate final judgment and further improving the accuracy of risky merchant identification.
[0120] It should be noted that the application scenarios described in the above embodiments of this application are for the purpose of more clearly illustrating the technical solutions of the embodiments of this application, and do not constitute a limitation on the technical solutions provided by the embodiments of this application. As those skilled in the art will know, with the emergence of new application scenarios, the technical solutions provided by the embodiments of this application are also applicable to similar technical problems.
[0121] Based on the same inventive concept, this application also provides a risk merchant identification device. Specifically, in conjunction with... Figure 9 Please provide a detailed explanation.
[0122] Figure 9 This is a schematic diagram of the structure of a risk merchant identification device provided in one embodiment of this application.
[0123] like Figure 9 As shown, the risk merchant identification device 900 may include:
[0124] The information acquisition module 901 is used to acquire merchant transaction information corresponding to multiple merchants;
[0125] The graph construction module 902 is used to construct a transaction network graph with accounts, users and merchants as nodes based on the merchant transaction information, wherein the transaction network graph is used to describe the relationship between accounts, users and merchants;
[0126] The first identification module 903 is used to identify suspected risk merchants associated with the target risk account from among the multiple merchants based on the transaction network graph;
[0127] The target acquisition module 904 is used to acquire a portion of the graph associated with the suspected risky merchant from the transaction network graph, thereby obtaining the target network graph;
[0128] The second identification module 905 is used to identify the risk of merchants in the target network graph based on the target network graph and using a risk merchant identification model to obtain risk merchants.
[0129] The risk merchant identification device 900 described above is explained in detail below:
[0130] In some embodiments, the first identification module 903 may specifically include:
[0131] The community segmentation submodule is used to perform community segmentation processing on the nodes in the transaction network graph to obtain multiple communities corresponding to the transaction network graph.
[0132] The first determining submodule is used to determine, from the plurality of communities, the community associated with the target risk account as the target community;
[0133] The second determination submodule is used to identify merchants associated with the target risk account from the target community as the suspected risk merchants.
[0134] In some embodiments, the community segmentation submodule may specifically include:
[0135] The community identification unit is used to identify the communities of nodes in the transaction network graph based on a preset community identification algorithm to obtain multiple initial communities.
[0136] The community improvement unit is used to perform the following steps on each of the plurality of initial communities to obtain multiple communities corresponding to the transaction network graph: identify the core account within the initial community and obtain the transaction flow information corresponding to the core account; search for target merchants not within the initial community based on the transaction flow information; if the target merchant is found, classify the node corresponding to the target merchant as the initial community to obtain the community.
[0137] In some embodiments, the first determining submodule may specifically include:
[0138] The first determining unit is used to determine, from the plurality of communities, the community where the target risk account is located as the first target community;
[0139] The second determining unit is used to determine, from the plurality of communities, a community that has a transaction relationship with the first target community as the second target community;
[0140] The target community includes the first target community and the second target community.
[0141] In some embodiments, the second determining submodule may specifically include:
[0142] The third determining unit is used to determine from the target community the merchant to which the target risk account belongs as the first suspected risk merchant;
[0143] The fourth determining unit is used to determine, from the target community, a merchant associated with the first suspected risk merchant as a second suspected risk merchant;
[0144] The suspected risk merchants include the first suspected risk merchant and the second suspected risk merchant.
[0145] In some embodiments, the risk merchant identification model includes N classification models, each classification model corresponding to a risk identification rule, where N is an integer greater than 1;
[0146] The second identification module 905 may specifically include:
[0147] The graph splitting submodule is used to split the target network graph based on N risk identification rules to obtain N sub-graphs;
[0148] The risk assessment submodule is used to assess the risk of merchants in the sub-maps obtained by splitting the risk identification rules corresponding to the N classification models using each of the N classification models, and to obtain the assessment results output by the N classification models respectively.
[0149] The comprehensive determination submodule is used to determine risky merchants based on the judgment results output by the N classification models respectively.
[0150] In some embodiments, the risk assessment submodule may specifically include:
[0151] The feature extraction unit is used to extract features from each of the N sub-graphs to obtain feature information corresponding to the N sub-graphs respectively, wherein the feature information includes graph feature information and node feature information;
[0152] The risk assessment unit is used to input the feature information corresponding to each of the N sub-maps into the classification model of the corresponding risk identification rule, and use the classification model to assess the risk of merchants in the sub-maps, thereby obtaining the assessment results output by the N classification models respectively.
[0153] In some embodiments, the comprehensive determination submodule may specifically include:
[0154] The percentage determination unit is used to determine the percentage of the judgment result that classifies the first merchant as a risk merchant based on the judgment results output by the N classification models respectively, wherein the first merchant is any merchant in the target network graph.
[0155] The risk determination unit is used to determine the first merchant as a risk merchant when the proportion of the determination result is greater than a preset threshold.
[0156] In some embodiments, the map construction module 902 may specifically include:
[0157] The relationship determination submodule is used to determine the association relationship between multiple accounts, users and merchants based on the merchant transaction information, wherein the association relationship includes at least one of transfer transaction relationship, account holding relationship and merchant holding relationship;
[0158] The graph construction submodule is used to construct a transaction network graph with accounts, users, and merchants as nodes based on the aforementioned relationships.
[0159] Therefore, by constructing a transaction network graph to describe the relationships between accounts, users, and merchants, this graph is used to identify potentially risky merchants associated with the target risky account from among multiple merchants. Then, a portion of the graph associated with the potentially risky merchant—the target network graph—is obtained from this transaction network graph. A risky merchant identification model is then used to identify the merchants in this target network graph to determine the risky merchants. In this way, because the graph structure can reveal potential relationships between entities, even entities with large distances can be quickly retrieved based on their association paths, thanks to the performance advantages of the graph structure. This allows for the discovery of relationships between potential risky merchants, rapid identification of potential risky merchant groups, and improved efficiency and effectiveness in identifying risky merchants.
[0160] Figure 10 This is a schematic diagram of the structure of an electronic device provided in one embodiment of this application.
[0161] The electronic device 1000 may include a processor 1001 and a memory 1002 storing computer program instructions.
[0162] Specifically, the processor 1001 may include a central processing unit (CPU), an application-specific integrated circuit (ASIC), or one or more integrated circuits that can be configured to implement the embodiments of this application.
[0163] Memory 1002 may include mass storage for data or instructions. For example, and not limitingly, memory 1002 may include a hard disk drive (HDD), floppy disk drive, flash memory, optical disk, magneto-optical disk, magnetic tape, or Universal Serial Bus (USB) drive, or a combination of two or more of these. Where appropriate, memory 1002 may include removable or non-removable (or fixed) media. Where appropriate, memory 1002 may be internal or external to the integrated gateway disaster recovery device. In a particular embodiment, memory 1002 is non-volatile solid-state memory.
[0164] In certain embodiments, the memory may include read-only memory (ROM), random access memory (RAM), disk storage media devices, optical storage media devices, flash memory devices, and electrical, optical, or other physical / tangible memory storage devices. Thus, typically, memory includes one or more tangible (non-transitory) computer-readable storage media (e.g., memory devices) encoded with software including computer-executable instructions, and when the software is executed (e.g., by one or more processors), it is operable to perform the operations described with reference to the method according to one aspect of this application.
[0165] The processor 1001 reads and executes computer program instructions stored in the memory 1002 to implement any of the risk merchant identification methods in the above embodiments.
[0166] In some examples, the electronic device 1000 may also include a communication interface 1003 and a bus 1010. For example, Figure 10 As shown, the processor 1001, memory 1002, and communication interface 1003 are connected through bus 1010 and complete communication with each other.
[0167] The communication interface 1003 is mainly used to realize communication between various modules, devices, units and / or equipment in the embodiments of this application.
[0168] Bus 1010 includes hardware, software, or both, that couples components of an online data traffic metering device together. For example, and not as a limitation, bus 1010 may include an Accelerated Graphics Port (AGP) or other graphics bus, an Enhanced Industry Standard Architecture (EISA) bus, a Front Side Bus (FSB), HyperTransport (HT) interconnect, an Industry Standard Architecture (ISA) bus, an Infinite Bandwidth Interconnect, a Low Pin Count (LPC) bus, a memory bus, a Microchannel Architecture (MCA) bus, a Peripheral Component Interconnect (PCI) bus, a PCI-Express (PCI-X) bus, a Serial Advanced Technology Attachment (SATA) bus, a Video Electronics Standards Association Local (VLB) bus, or other suitable buses, or combinations of two or more of these. Where appropriate, bus 1010 may include one or more buses. Although specific buses are described and illustrated in embodiments of this application, any suitable bus or interconnect is contemplated herein.
[0169] For example, the electronic device 1000 can be a mobile phone, tablet computer, laptop computer, handheld computer, in-vehicle electronic device, ultra-mobile personal computer (UMPC), netbook, or personal digital assistant (PDA), etc.
[0170] The electronic device 1000 can execute the risk merchant identification method in the embodiments of this application, thereby achieving a combination of Figures 1 to 9 The methods and apparatus for identifying risky merchants are described.
[0171] Furthermore, in conjunction with the risk merchant identification methods in the above embodiments, this application embodiment can provide a computer-readable storage medium for implementation. This computer-readable storage medium stores computer program instructions; when these computer program instructions are executed by a processor, they implement any of the risk merchant identification methods in the above embodiments. Examples of computer-readable storage media include non-transitory computer-readable storage media, such as portable disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, etc.
[0172] It should be clarified that this application is not limited to the specific configurations and processes described above and shown in the figures. For the sake of brevity, detailed descriptions of known methods are omitted here. In the above embodiments, several specific steps are described and shown as examples. However, the method process of this application is not limited to the specific steps described and shown. Those skilled in the art can make various changes, modifications, and additions, or change the order of steps, after understanding the spirit of this application.
[0173] The functional blocks shown in the above-described structural diagram can be implemented as hardware, software, firmware, or a combination thereof. When implemented in hardware, they can be, for example, electronic circuits, application-specific integrated circuits (ASICs), appropriate firmware, plug-ins, function cards, etc. When implemented in software, the elements of this application are programs or code segments used to perform the required tasks. Programs or code segments can be stored on a machine-readable medium or transmitted over a transmission medium or communication link via data signals carried on a carrier wave. "Machine-readable medium" can include any medium capable of storing or transmitting information. Examples of machine-readable media include electronic circuits, semiconductor memory devices, ROM, flash memory, erasable ROM (EROM), floppy disks, CD-ROMs, optical disks, hard disks, fiber optic media, radio frequency (RF) links, etc. Code segments can be downloaded via computer networks such as the Internet, intranets, etc.
[0174] It should also be noted that the exemplary embodiments mentioned in this application describe methods or systems based on a series of steps or apparatus. However, this application is not limited to the order of the above steps; that is, the steps can be performed in the order mentioned in the embodiments, or in a different order, or several steps can be performed simultaneously.
[0175] The aspects of this application have been described above with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this application. It should be understood that each block in the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing apparatus to produce a machine such that these instructions, executable via the processor of the computer or other programmable data processing apparatus, enable the implementation of the functions / actions specified in one or more blocks of the flowchart illustrations and / or block diagrams. Such a processor can be, but is not limited to, a general-purpose processor, a special-purpose processor, a special application processor, or a field-programmable logic circuit. It is also understood that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, can also be implemented by dedicated hardware performing the specified functions or actions, or can be implemented by a combination of dedicated hardware and computer instructions.
[0176] The above description is merely a specific implementation of this application. Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working processes of the systems, modules, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here. It should be understood that the protection scope of this application is not limited thereto. Any person skilled in the art can easily conceive of various equivalent modifications or substitutions within the technical scope disclosed in this application, and these modifications or substitutions should all be covered within the protection scope of this application.
Claims
1. A method for identifying high-risk merchants, characterized in that, The method comprises: obtaining merchant transaction information corresponding to a plurality of merchants, the merchant transaction information comprising transaction flow information, merchant holding relationship information, account holding relationship information and merchant equity information; constructing a transaction network graph taking accounts, users and merchants as nodes according to the merchant transaction information, wherein the transaction network graph is used to describe the association relationship between accounts, users and merchants, and the association relationship comprises the transfer transaction relationship between accounts, the account holding relationship between accounts and merchants, the account holding relationship between accounts and users, the merchant holding relationship between users and merchants, and the relationship between users and users holding shares of a merchant; identifying a suspected risk merchant associated with a target risk account from the plurality of merchants based on the transaction network graph; obtaining a part of the graph associated with the suspected risk merchant from the transaction network graph to obtain a target network graph; performing risk identification on the merchants in the target network graph based on the graph features and node features of the target network graph using a risk merchant identification model to obtain a risk merchant, wherein the graph features are used to describe the connection relationship between nodes in the target network graph; The method comprises: performing community division processing on the nodes in the transaction network graph to obtain a plurality of communities corresponding to the transaction network graph; determining a community associated with the target risk account from the plurality of communities as a target community; determining a merchant associated with the target risk account from the target community as the suspected risk merchant.
2. The method of claim 1, wherein, The method comprises: performing community identification on the nodes in the transaction network graph based on a preset community identification algorithm to obtain a plurality of initial communities; performing the following steps on each initial community in the plurality of initial communities to obtain a plurality of communities corresponding to the transaction network graph: determining a core account within the initial community and obtaining transaction flow information corresponding to the core account; searching for a target merchant not within the initial community according to the transaction flow information; in the case of searching for the target merchant, classifying the node corresponding to the target merchant into the initial community to obtain the community.
3. The method of claim 1, wherein, The method comprises: determining a community in which the target risk account is located as a first target community from the plurality of communities; determining a community having a transaction relationship with the first target community as a second target community from the plurality of communities; wherein the target community comprises the first target community and the second target community.
4. The method of claim 1, wherein, The method comprises: determining a merchant to which the target risk account belongs as a first suspected risk merchant from the target community; determining a merchant associated with the first suspected risk merchant as a second suspected risk merchant from the target community; The suspected risk merchants include the first suspected risk merchant and the second suspected risk merchant.
5. The method of claim 1, wherein, The risk merchant identification model includes N classification models, one classification model corresponding to one risk identification rule, wherein N is an integer greater than 1. The risk identification of the merchants in the target network graph based on the target network graph and the risk merchant identification model includes: Splitting and processing the target network graph based on N risk identification rules to obtain N sub-graphs; Using each classification model in the N classification models to determine the risk of the merchants in the sub-graphs obtained by splitting according to the risk identification rule corresponding to the classification model, to obtain the determination results output by the N classification models respectively; Determining the risk merchants according to the determination results output by the N classification models respectively.
6. The method of claim 5, wherein, The determination of the risk of the merchants in the sub-graphs obtained by splitting according to the risk identification rule corresponding to the classification model using each classification model in the N classification models to obtain the determination results output by the N classification models respectively includes: Extracting features from each of the N sub-graphs to obtain feature information corresponding to the N sub-graphs respectively, wherein the feature information includes graph feature information and node feature information; Inputting the feature information corresponding to each of the N sub-graphs into the classification model corresponding to the risk identification rule, and determining the risk of the merchants in the sub-graphs using the classification model to obtain the determination results output by the N classification models respectively.
7. The method of claim 5, wherein, The determination of the risk merchants according to the determination results output by the N classification models respectively includes: According to the determination results output by the N classification models respectively, determining the proportion of the determination results that determine the first merchant as a risk merchant, wherein the first merchant is any merchant in the target network graph; If the proportion of the determination results is greater than a preset threshold, the first merchant is determined as a risk merchant.
8. The method of claim 1, wherein, The construction of the transaction network graph with accounts, users and merchants as nodes based on the merchant transaction information includes: According to the merchant transaction information, determining the association relationship between a plurality of accounts, users and merchants, wherein the association relationship includes at least one of a transfer transaction relationship, an account holding relationship and a merchant holding relationship; Based on the association relationship, a transaction network graph is constructed with accounts, users and merchants as nodes.
9. A risk merchant identification apparatus, comprising: It includes: An information acquisition module is configured to acquire merchant transaction information corresponding to a plurality of merchants, wherein the merchant transaction information includes transaction flow information, merchant holding relationship information, account holding relationship information and merchant equity information; The device comprises a processor and a memory having computer program instructions stored therein; The processor executes the computer program instructions to implement the steps of the risk merchant identification method according to any one of claims 1-8. The computer program instructions are stored on the computer readable storage medium, and when executed by the processor, implement the steps of the risk merchant identification method according to any one of claims 1-8. The instructions in the computer program product are executed by the processor of the electronic device, so that the electronic device executes the steps of the risk merchant identification method according to any one of claims 1-8. The device comprises a processor and a memory having computer program instructions stored therein; The processor executes the computer program instructions to implement the steps of the risk merchant identification method according to any one of claims 1-8. The computer program instructions are stored on the computer readable storage medium, and when executed by the processor, implement the steps of the risk merchant identification method according to any one of claims 1-8. The instructions in the computer program product are executed by the processor of the electronic device, so that the electronic device executes the steps of the risk merchant identification method according to any one of claims 1-8.
10. An electronic device, comprising: The device comprises a processor and a memory having computer program instructions stored therein; The processor executes the computer program instructions to implement the steps of the risk merchant identification method according to any one of claims 1-8.
11. A computer readable storage medium, characterized in that, The computer program instructions are stored on the computer readable storage medium, and when executed by the processor, implement the steps of the risk merchant identification method according to any one of claims 1-8.
12. A computer program product, characterised in that, The instructions in the computer program product are executed by the processor of the electronic device, so that the electronic device executes the steps of the risk merchant identification method according to any one of claims 1-8.
Citation Information
Patent Citations
Safety protection processing method and system based on user behavior big data mining
CN113704772A
Abnormal tissue identification method and device, electronic equipment and medium
CN115062163A
Object risk assessment method and device, storage medium and electronic equipment
CN115374983A