A method, apparatus and device for risk perception of a transaction event
By acquiring information about transaction events and analyzing it using a target model, the problem of high sensitivity in threshold segmentation in financial transactions was solved, enabling more detailed risk perception and channel risk attribution, and improving the accuracy of risk perception and business understanding.
Patent Information
- Application Number
- CN202310323458.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-03-29
- Publication Date
- 2026-01-23
- Estimated Expiration
- 2043-03-29
AI Technical Summary
Existing risk perception algorithms are highly sensitive to threshold segmentation in financial transactions, making it difficult to accurately identify user risks and leading to mislabeling of transaction events. Furthermore, they cannot effectively detect anomalies in risk.
By acquiring transaction event information within a preset time period, extracting features and transaction channel information, and using a pre-trained target model to determine the risk probability of transaction events and channel risk characterization information, more detailed risk perception and attribution analysis can be achieved.
It reduces the sensitivity of threshold segmentation, provides a more detailed way of accumulating risk, can detect risk anomalies in a timely manner and identify risk attribution, and improves the accuracy of risk perception and business understanding.
Smart Images

Figure CN116342281B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present document relates to the technical field of computer technology, and particularly relates to a risk perception method, device and equipment of a transaction event. BACKGROUND
[0002] Since a financial institution (especially an Internet financial institution) involves a large number of financial transactions, it is easy to be concerned by black production. With the continuous development of network technology, telecom fraud has become one of the important fraud methods commonly used by black production. However, there are still many risks that cannot be covered by the existing strategies or algorithms. Therefore, there is a new demand for risk perception. The perception algorithm not only needs to perceive the risk level and its change, but also needs to be able to discover the abnormal risk in time.
[0003] Generally, a user pool with a preset risk can be identified by user tagging, and then the transactions involving the above-mentioned users are controlled. However, the risk identification result of the user needs to be relatively accurate, and the threshold segmentation is relatively sensitive. In addition, the preset risk of the user may be due to a transaction or multiple transactions being characterized as having a preset risk, which may cause the user to be marked as the above-mentioned risk in other transactions. Therefore, a more optimal risk perception mechanism is needed to reduce the sensitivity of threshold segmentation and provide a more detailed risk accumulation method so that the transaction is directly associated with the preset risk. SUMMARY
[0004] The purpose of the embodiments of the present specification is to provide a more optimal risk perception mechanism to reduce the sensitivity of threshold segmentation and provide a more detailed risk accumulation method so that the transaction is directly associated with the preset risk.
[0005] In order to achieve the above technical solutions, the embodiments of the present specification are implemented as follows:
[0006] The risk perception method of a transaction event provided by the embodiments of the present specification comprises: obtaining information of transaction events generated within a preset time period. Based on the information of each transaction event, the characteristics corresponding to each transaction event and the transaction channel information corresponding to each transaction event are determined. The characteristics corresponding to each transaction event are respectively input into a pre-trained target model to obtain the probability of each transaction event having a preset risk, and the target model is used to determine the suspicious degree of the transaction event having the preset risk. Based on the probability of each transaction event having a preset risk and the transaction channel information corresponding to each transaction event, the risk representation information of each transaction channel for the preset risk and / or the risk attribution information of each transaction channel in the transaction channel to which the transaction events generated within the preset time period belong is determined.
[0007] An embodiment of the present specification provides a transaction event risk perception device, the device comprising: an information acquisition module, acquiring information of transaction events generated within a preset time period. An information processing module, based on the information of each transaction event, determining the corresponding features of each transaction event and the corresponding transaction channel information of each transaction event. A probability determination module, respectively inputting the corresponding features of each transaction event into a pre-trained target model to obtain the probability of each transaction event existing a preset risk, the target model being used to determine the suspicious degree of the transaction event existing the preset risk. A risk perception module, based on the probability of each transaction event existing the preset risk and the corresponding transaction channel information of each transaction event, determining the risk characterization information of each transaction channel for the preset risk and / or the risk attribution information of each transaction channel in the transaction channels to which the transaction events generated within the preset time period belong.
[0008] An embodiment of the present specification provides a transaction event risk perception device, the device comprising: a processor; and a memory arranged to store computer executable instructions that, when executed, cause the processor to: acquire information of transaction events generated within a preset time period. Based on the information of each transaction event, determine the corresponding features of each transaction event and the corresponding transaction channel information of each transaction event. Respectively input the corresponding features of each transaction event into a pre-trained target model to obtain the probability of each transaction event existing a preset risk, the target model being used to determine the suspicious degree of the transaction event existing the preset risk. Based on the probability of each transaction event existing the preset risk and the corresponding transaction channel information of each transaction event, determine the risk characterization information of each transaction channel for the preset risk and / or the risk attribution information of each transaction channel in the transaction channels to which the transaction events generated within the preset time period belong.
[0009] An embodiment of the present specification also provides a storage medium for storing computer executable instructions, the executable instructions, when executed by a processor, implement the following processes: acquiring information of transaction events generated within a preset time period. Based on the information of each transaction event, determining the corresponding features of each transaction event and the corresponding transaction channel information of each transaction event. Respectively inputting the corresponding features of each transaction event into a pre-trained target model to obtain the probability of each transaction event existing a preset risk, the target model being used to determine the suspicious degree of the transaction event existing the preset risk. Based on the probability of each transaction event existing the preset risk and the corresponding transaction channel information of each transaction event, determining the risk characterization information of each transaction channel for the preset risk and / or the risk attribution information of each transaction channel in the transaction channels to which the transaction events generated within the preset time period belong. Attached Figure Description
[0010] To more clearly illustrate the technical solutions in the embodiments or prior art of this specification, the drawings used in the description of the embodiments or prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments recorded in this specification. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0011] Figure 1 This is an embodiment of a risk perception method for transaction events as described in this specification;
[0012] Figure 2 This is another embodiment of the risk perception method for transaction events described in this specification;
[0013] Figure 3 This is a schematic diagram illustrating the risk perception process of a transaction event as described in this specification.
[0014] Figure 4 This specification provides an embodiment of a risk perception device for a transaction event.
[0015] Figure 5 This specification describes an embodiment of a risk perception device for a transaction event. Detailed Implementation
[0016] This specification provides a method, apparatus, and device for risk perception of transaction events.
[0017] To enable those skilled in the art to better understand the technical solutions in this specification, the technical solutions in the embodiments of this specification will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this specification, and not all embodiments. Based on the embodiments in this specification, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of this specification.
[0018] This specification provides a channel perception mechanism that enables the following: It statistically analyzes transaction data over a preset timeframe (e.g., the most recent day or week) to determine the corresponding channel risk level and its fluctuation. This allows for the issuance of risk warnings to customers with high risk level rankings (or those reaching a predetermined ranking) and high channel risk level volatility (or those reaching a predetermined volatility). Furthermore, it can determine the attribution of channel risks, calculating the reasons for channel anomalies to identify whether the anomalies are primarily due to an increase in illegal transactions within the current trading channel or an increase in transactions during specific time periods (e.g., 1 AM to 3 AM). Specific processing details can be found in the following embodiments.
[0019] Example 1
[0020] like Figure 1 As shown in the embodiments of this specification, a risk perception method for transaction events is provided. The execution subject of this method can be a terminal device or a server. The terminal device can be a mobile phone, tablet computer, or a computer device such as a laptop or desktop computer, or an IoT device (specifically, a smartwatch, in-vehicle device, etc.). The server can be a single server or a server cluster composed of multiple servers. The server can be a backend server for financial services or online shopping services, or a backend server for an application. This embodiment uses a server as an example for detailed description. For the execution process of the terminal device, please refer to the relevant content below, which will not be repeated here. The method specifically includes the following steps:
[0021] In step S102, information on transaction events generated within a preset time period is obtained.
[0022] The preset duration can be any duration, such as the 24 hours prior to the current time, a past day or several consecutive days, or a specified time period within each of the past day or several days. The specific duration can be set according to actual circumstances, and this embodiment does not impose any limitations. A transaction event can be an abstract event type representing an operation performed by a user on the website of a financial institution. Transaction events can include various types, such as topping up a communication account through an online payment application, paying for purchased goods through an online payment application, or transferring money to a friend through an online payment application. The specific duration can be set according to actual circumstances, and this embodiment does not impose any limitations. The information of a transaction event can include various types, such as the transaction event code, the initiation time of the transaction event, the initiation location of the transaction event, and the transaction data corresponding to the transaction event (such as relevant information of both parties to the transaction, the transaction amount, etc.). The specific duration can be set according to actual circumstances, and this embodiment does not impose any limitations.
[0023] In practice, financial institutions (especially internet financial institutions) are involved in a large number of financial transactions, making them easy targets for cybercrime. With the continuous development of network technology, telecommunications fraud has become one of the most common and important fraud methods used by cybercriminals. However, there are still many risks that cannot be covered by existing strategies or algorithms. These risks are mainly new risk patterns, which are not covered in past risk data or whose new risk distribution is inconsistent with the current risk distribution. This creates new demands for risk perception. Perception algorithms not only need to perceive the level of risk and its changes, but also need to be able to detect risk anomalies in a timely manner.
[0024] Typically, user tagging can be used to identify a pool of users with pre-defined risks, and then transactions involving these users can be controlled. However, this method requires relatively accurate risk identification results and is sensitive to threshold segmentation. Furthermore, a user's pre-defined risk might stem from one or more transactions being classified as having a pre-defined risk, leading to that user being flagged for the same risk in other transactions. Therefore, a better risk perception mechanism is needed to reduce the sensitivity of threshold segmentation and provide a more granular risk accumulation method, directly associating transactions with pre-defined risks and identifying risk attribution. This specification provides an achievable technical solution, which may include the following:
[0025] The financial institutions (especially Internet financial institutions) will have a large number of financial transactions every day, which can be a financial transaction for a user or a financial transaction for multiple different specified users. Based on this, the relevant information of each financial transaction can be recorded. When the data in a specified time period needs to be processed for risk perception, the above-mentioned financial transactions involved can be abstracted as a transaction event, and based on the above-mentioned specified time period, the time period and the length of time of the data to be extracted can be determined, and then the information of the transaction event generated in the preset time period can be obtained from the above-mentioned recorded relevant information. In actual application, the process of obtaining the information of the transaction event generated in the preset time period can also include a variety of different ways. For example, a specified database can be set, which can include one or more transaction events, and the above-mentioned transaction events are transaction events generated in a specified time period. When the data in a specified time period needs to be processed for risk perception, the information of the transaction event generated in the preset time period can be obtained from the specified database. The above-mentioned are only two kinds of implementable processing methods, and in actual application, a variety of different processing methods can also be included. The specific setting can be made according to the actual situation, and here is not described again.
[0026] In step S104, based on the information of each transaction event, the feature corresponding to each transaction event and the transaction channel information corresponding to each transaction event are determined.
[0027] The transaction channel information can include a variety of transaction channel identifiers, codes, names, etc. The specific setting can be made according to the actual situation, and the embodiments of the present specification are not limited thereto. The transaction channel corresponding to the transaction channel information can include a variety of transaction channels such as communication account recharge channels, payment channels, and transfer channels. The specific setting can be made according to the actual situation, and the embodiments of the present specification are not limited thereto.
[0028] In implementation, for each transaction event, the information of the transaction event can be extracted to obtain the feature corresponding to the transaction event. In addition, the transaction channel information of the transaction channel corresponding to the transaction event can be obtained from the information of the transaction event. Through the above-mentioned way, the feature corresponding to each transaction event and the transaction channel information corresponding to each transaction event can be obtained.
[0029] It should be noted that the feature corresponding to the transaction event can include a table type feature, and each feature can be used to describe some attributes of the transaction event itself. The feature corresponding to a transaction event can be as shown in Table 1.
[0030] Table 1
[0031] Account identification of transaction initiator Account identification of transaction target Transaction time Transaction amount A B 10:07:26 50 yuan
[0032] In step S106, the features corresponding to each transaction event are respectively input into the pre-trained target model to obtain the probability that each transaction event exists in the preset risk, and the target model is used to determine the suspicious degree of the transaction event existing in the preset risk.
[0033] The target model can be a model constructed by a specified algorithm, and the specified algorithm can include a classification algorithm, a neural network algorithm, etc., which can be set according to actual conditions, and the embodiments of the present specification do not limit this. The target model can be used to determine the suspicious degree of a certain transaction event, thereby determining whether the transaction event exists in the preset risk.
[0034] In implementation, the corresponding algorithm can be obtained, and the target model can be constructed based on the algorithm. The input data of the target model can be the features corresponding to the transaction event, and the output data can be the suspicious degree of the transaction event. Specifically, the target model can include a binary classification tree model, the input data of the tree model can be the features corresponding to the transaction event, and the leaf node code output by the tree model can be used as the probability that each transaction event exists in the preset risk. Alternatively, the target model can include a binary classification neural network model containing a self-attention mechanism, the input data of which can be the features corresponding to the transaction event, and the attention value calculated and output by the final neural network model can be the probability that each transaction event exists in the preset risk. Then, the training samples (i.e., the features corresponding to the historical transaction events) for training the target model can be obtained, and the training samples can be used to train the target model. During the model training process, the objective function can be pre-set, and the model parameters in the target model can be optimized based on the objective function, and finally the trained target model is obtained. Then, for a certain transaction event, the features corresponding to the transaction event can be input into the above trained target model to obtain the suspicious degree of the transaction event, i.e., the probability that the transaction event exists in the preset risk. Whether the transaction exists in the preset risk can be determined based on the suspicious degree of the transaction event.
[0035] In step S108, based on the probability that each transaction event exists in the preset risk and the transaction channel information corresponding to each transaction event, the risk characterization information of each transaction channel for the preset risk and / or the risk attribution information of each transaction channel in the transaction channel to which the transaction event generated within the preset time period belongs is determined.
[0036] The risk attribution information can be information of factors causing the preset risk. In actual application, the risk attribution information can be specifically, for example, an increase in illegal transactions in the current transaction channel causes the preset risk or an increase in transactions in a special period (such as the period from 1 a.m. to 3 a.m.) causes the preset risk, etc. The specific application can be set according to actual conditions, and the embodiments of the present specification do not limit this.
[0037] In implementation, for any transaction event, by the above manner, the probability that the transaction event exists preset risk can be obtained, and the transaction channel information corresponding to the transaction event can be obtained. The corresponding first transaction channel can be determined according to the transaction channel information corresponding to the transaction event. The transaction event whose transaction channel is the first transaction channel can be obtained. The calculation result obtained by using a preset algorithm according to the probability that each transaction event belonging to the first transaction channel exists preset risk can be used as the risk representation information of the first transaction channel for the preset risk. For example, the average value of the probability that each transaction event belonging to the first transaction channel exists preset risk can be calculated. Specifically, the transaction events belonging to the first transaction channel include transaction event 1, transaction event 2 and transaction event 3. The probability that transaction event 1 exists preset risk is 0.3, the probability that transaction event 2 exists preset risk is 0.2, and the probability that transaction event 3 exists preset risk is 0.1. The average value of the calculated probability can be (0.3+0.2+0.1) / 3=0.2. 0.2 can be used as the risk representation information of the first transaction channel for the preset risk. Alternatively, the sum of the probabilities corresponding to the transaction events in the first transaction channel can be used as the risk representation information of the first transaction channel for the preset risk. For example, based on the above example, (0.3+0.2+0.1)=0.6 can be used as the risk representation information of the first transaction channel for the preset risk. The specific manner can be set according to actual conditions, which is not limited in the embodiments of the present disclosure.
[0038] In addition, the risk attribution information of each transaction channel can also be determined based on the probability that each transaction event exists preset risk and the transaction channel information corresponding to each transaction event. Specifically, the corresponding second transaction channel can be determined according to the transaction channel information corresponding to a certain transaction event. The transaction event whose transaction channel is the second transaction channel can be obtained. The probability that each transaction event belonging to the second transaction channel exists preset risk can be found, and the probability that the value of which is greater than a preset threshold can be obtained. The risk attribution information of the second transaction channel can be determined based on the transaction event whose probability that the value of which is greater than the preset threshold is obtained in the second transaction channel. Specifically, the transaction event whose probability that the value of which is greater than the preset threshold in the second transaction channel can be used as the risk attribution information of the second transaction channel. The above processing manner is only one implementable processing manner. In actual application, various different processing manners can be included. The specific manner can be set according to actual conditions, which is not described herein.
[0039] The embodiment of the present specification provides a risk perception method of a transaction event. Information of a transaction event generated within a preset time length is obtained. Then, the information of each transaction event can be used to determine the corresponding feature of each transaction event and the corresponding transaction channel information of each transaction event. Then, the corresponding feature of each transaction event can be input into a pre-trained target model to obtain the probability of each transaction event existing a preset risk. Finally, the probability of each transaction event existing a preset risk and the corresponding transaction channel information of each transaction event can be used to determine the risk characterization information of each transaction channel for a preset risk and / or the risk attribution information of each transaction channel of the transaction channel to which the transaction event generated within the preset time length belongs. In this way, the embodiment of the present specification proposes a risk accumulation method based on a transaction event. The method is a more optimal risk perception mechanism. The transaction event granularity is more detailed than the customer granularity and can be directly associated with a preset risk. Therefore, the sensitivity of threshold segmentation can be reduced. In addition, in the business, it is proposed that the risk of the current transaction channel should be concentrated in which problems (i.e., the risk attribution information of each transaction channel). For example, whether there is too much transaction in a special time period (such as 1:00-3:00) or the illegal transaction in the current transaction channel is increased.
[0040] Embodiment two
[0041] As Figure 2 shown, the embodiment of the present specification provides a risk perception method of a transaction event. The execution subject of the method can be a terminal device or a server. The terminal device can be a certain terminal device such as a mobile phone, a tablet computer, etc. It can also be a computer device such as a notebook computer or a desktop computer, or it can also be an IoT device (such as a smart watch, a vehicle-mounted device, etc.). The server can be an independent server, or it can also be a server cluster composed of multiple servers, etc. The server can be a background server of a financial service or an online shopping service, or it can also be a background server of an application program, etc. In the embodiment, the server is taken as an example for detailed description. The execution process of the terminal device can be referred to the related content below, which will not be described here. The method can specifically include the following steps:
[0042] In step S202, information of a transaction event generated within a preset time length is obtained.
[0043] In implementation, for example, the calculation dimension of the channel perception mechanism in the embodiment is a preset time length, specifically, a natural day. For a natural day, n (n can be a positive integer greater than or equal to 1) transaction events can occur. Then, the information of the n transaction events generated within the natural day can be obtained.
[0044] In step S204, based on the information of each transaction event, the feature corresponding to each transaction event and the transaction channel information corresponding to each transaction event are determined.
[0045] In implementation, as shown in Figure 3 , for a preset time length dt, there can be n (n can be a positive integer greater than or equal to 1) transaction events, feature extraction can be performed on each transaction event, and k (k can be a positive integer greater than or equal to 1) features included in each transaction event can be obtained. m transaction channels can be defined in advance, the transaction channel corresponding to each transaction event can be determined based on the information of each transaction event, and then the transaction channel information corresponding to each transaction event can be determined, that is,
[0046]
[0047] wherein event dt represents a transaction event within a preset time length dt, x n,k represents the kth feature in the nth transaction event, event n represents the nth transaction event, channel X represents one of the m transaction channels, channel XX represents another of the m transaction channels, channel XXX represents another of the m transaction channels.
[0048] In step S206, the feature corresponding to each transaction event is input into a pre-trained target model respectively, to obtain the probability that each transaction event exists a preset risk, and the target model is used to determine the suspicious degree of the transaction event existing the preset risk.
[0049] The target model can be a model for classification, and the target model is a tree structure model, or the target model can be a model for classification, and the target model is a model constructed based on a neural network. In actual application, as shown in Figure 3 , the target model can be specifically constructed by an extreme gradient boosting XGB algorithm, or the target model can be constructed by a light gradient boosting machine LGB algorithm, etc. The preset risk can include multiple kinds, for example, the preset risk can include one or more of fraud risk, illegal transaction risk, etc.
[0050] In implementation, to determine the probability of a predetermined risk for each transaction event, a target model needs to be trained. This target model can be a classification model, with an evaluation granularity of a single transaction event and a perception granularity of the transaction channel. Each transaction event can be uniquely assigned to a predefined transaction channel. Specifically, for example, the target model can include a tree model, typically constructed using the XGB (XGBoost) or LGB (LightGBM) algorithm. Alternatively, a neural network can be used, with diverse structures, including embedding layers, multi-head self-attention layers, fully connected layers, and softmax layers, depending on the specific requirements. Then, information from historical transaction events and their corresponding transaction channel information can be obtained to train the target model, resulting in the trained target model.
[0051] like Figure 3 As shown, the features corresponding to each transaction event can be input into the trained target model (a tree model built using the XGB algorithm or a tree model built using the LGB algorithm, for ease of description). Figure 3 In this context, the target model is represented using the XGB / LGB model, or constructed using a neural network, for ease of description. Figure 3 In the NN model (represented in Chinese), the probability of a predetermined risk existing in each trading event is obtained (or it can be called a score for the predetermined risk existing in each trading event, the score ranging from 0 to 1). Figure 3 This will be used as an example to illustrate, where "score" refers to the rating or score.
[0052] In step S208, based on the transaction channel information corresponding to each transaction event, the transaction channel to which the transaction event generated within the preset time period belongs is determined.
[0053] In step S210, the probability of a preset risk in a transaction event contained in each transaction channel is calculated to obtain risk characterization information for each transaction channel in response to the preset risk.
[0054] In implementation, such as Figure 3 As shown, for a certain trading channel (which can be referred to as the first trading channel ch1 for ease of description later), trading events belonging to the first trading channel can be obtained. The probabilities of the trading events belonging to the first trading channel can be added together, and the result can be used as the risk characterization information of the first trading channel for the preset risk. In this way, the risk characterization information of each trading channel for the preset risk can be obtained, that is...
[0055]
[0056] wherein, channel dt represents a transaction channel to which a transaction event in a preset time length dt belongs, event i represents an i-th transaction event, event p represents a p-th transaction event, event q represents a q-th transaction event, ch j represents a j-th transaction channel, ch m represents an m-th transaction channel, score(channel m ) represents risk representation information of the m-th transaction channel for a preset risk.
[0057] In step S212, based on the probability of each transaction event existing a preset risk and the feature corresponding to each transaction event, the feature importance degree corresponding to each transaction channel is determined.
[0058] In implementation, according to the probability of a certain transaction event existing a preset risk, the probability can be allocated to the feature corresponding to the transaction event, and the feature importance degree corresponding to each transaction channel can be determined based on the allocation result.
[0059] The specific process of the above step S212 can be various, and an optional processing mode is provided below, which can include the following contents: based on the probability of each transaction event existing a preset risk and the feature corresponding to each transaction event, using SHAP algorithm or local interpretable model agnostic explanation LIME algorithm, the feature importance degree corresponding to each transaction channel is determined.
[0060] In implementation, according to the difference of the algorithm used for constructing the target model, the algorithm used for determining the feature importance degree can be determined, for example, if the target model is a tree model used for classification, Tree-SHAP algorithm can be used to determine the feature importance degree corresponding to each transaction channel, so as to finally obtain the feature interpretable result of the transaction channel in the preset time length. The specific processing process of determining the feature importance degree corresponding to each transaction channel can be determined according to the processing process and processing mode indicated by SHAP algorithm or LIME algorithm, which will not be described here.
[0061] In step S214, based on the feature importance degree corresponding to each transaction channel, the risk attribution information of each transaction channel is determined.
[0062] In implementation, as Figure 3As shown, the numerical value of the feature importance corresponding to each transaction channel can be accumulated, and the absolute value or volatility of the numerical value of the feature importance is used as the attribution result, so that the risk attribution information of each transaction channel can be determined, that is
[0063]
[0064] Wherein, explain dt represents the risk attribution information of the transaction channel to which the transaction event belongs within the preset time length, represents a risk attribution element constructed by the features corresponding to the transaction channel and the transaction event in the risk attribution information of the transaction channel to which the transaction event belongs within the preset time length, represents another risk attribution element constructed by the features corresponding to the transaction channel and the transaction event in the risk attribution information of the transaction channel to which the transaction event belongs within the preset time length. Thus, the whole process from transaction event identification to channel perception and risk attribution is realized.
[0065] In step S216, the features corresponding to the target transaction event initiated by the target user are obtained.
[0066] In step S218, the features corresponding to the target transaction event are input into the target model to obtain the probability that the target transaction event exists in the preset risk.
[0067] In step S220, based on the probability that the target transaction event exists in the preset risk and the risk representation information of the transaction channel corresponding to the target transaction event against the preset risk, the risk warning processing of the target user is performed.
[0068] In implementation, if the probability that the target transaction event exists in the preset risk exceeds the risk representation information of the transaction channel corresponding to the target transaction event against the preset risk, it can be determined that the target user may exist in the preset risk, at this time, the risk warning processing of the target user can be performed.
[0069] The embodiment of the present specification provides a risk perception method of a transaction event. By obtaining information of transaction events generated within a preset time length, the corresponding features of each transaction event and the transaction channel information corresponding to each transaction event can be determined based on the information of each transaction event. Then, the corresponding features of each transaction event can be input into a pre-trained target model to obtain the probability of each transaction event existing a preset risk. Finally, the risk representation information of each transaction channel for the preset risk and / or the risk attribution information of each transaction channel in the transaction channel to which the transaction events generated within the preset time length belong can be determined based on the probability of each transaction event existing the preset risk and the transaction channel information corresponding to each transaction event. In this way, the embodiment of the present specification proposes a risk accumulation method based on transaction events. The method is a more optimal risk perception mechanism, in which the transaction event granularity is more detailed than the customer granularity and can be directly associated with the preset risk, thereby reducing the sensitivity of threshold segmentation. In addition, in the business, it is proposed that in the channel perception, the risk of the current transaction channel should be known to be mainly concentrated in which problems (i.e., the risk attribution information of each transaction channel), for example, whether there is too much transaction in a special time period (such as the time period of 1am-3am) or the illegal transaction in the current transaction channel is increased.
[0070] Embodiment three
[0071] The above is the risk perception method of the transaction event provided by the embodiment of the present specification. Based on the same idea, the embodiment of the present specification also provides a risk perception device of a transaction event, as shown in Figure 4 .
[0072] The risk perception device of the transaction event comprises an information acquisition module 401, an information processing module 402, a probability determination module 403 and a risk perception module 404, wherein:
[0073] The information acquisition module 401 acquires information of transaction events generated within a preset time length;
[0074] The information processing module 402 determines the corresponding features of each transaction event and the transaction channel information corresponding to each transaction event based on the information of each transaction event;
[0075] The probability determination module 403 inputs the corresponding features of each transaction event into a pre-trained target model to obtain the probability of each transaction event existing a preset risk. The target model is used to determine the suspicious degree of the transaction event existing the preset risk;
[0076] The risk perception module 404 determines risk characterization information of each of the transaction channels with respect to the preset risk and / or risk attribution information of each of the transaction channels to which the transaction events generated within the preset time length belong, based on the probability of each of the transaction events existing the preset risk and the transaction channel information corresponding to each of the transaction events.
[0077] In an embodiment of the present specification, the risk perception module 404 comprises:
[0078] The first channel determination unit determines the transaction channel to which the transaction events generated within the preset time length belong, based on the transaction channel information corresponding to each of the transaction events.
[0079] The first risk perception unit obtains the risk characterization information of each of the transaction channels with respect to the preset risk by counting the probability of each of the transaction events included in each of the transaction channels existing the preset risk.
[0080] In an embodiment of the present specification, the risk perception module 404 comprises:
[0081] The second channel determination unit determines the transaction channel to which the transaction events generated within the preset time length belong, based on the transaction channel information corresponding to each of the transaction events.
[0082] The feature importance determination unit determines the feature importance corresponding to each of the transaction channels based on the probability of each of the transaction events existing the preset risk and the feature corresponding to each of the transaction events.
[0083] The second risk perception unit determines the risk attribution information of each of the transaction channels based on the feature importance corresponding to each of the transaction channels.
[0084] In an embodiment of the present specification, the feature importance determination unit determines the feature importance corresponding to each of the transaction channels by using the SHAP algorithm or the LIME algorithm based on the probability of each of the transaction events existing the preset risk and the feature corresponding to each of the transaction events.
[0085] In an embodiment of the present specification, the target model is a model for classification, and the target model is a tree structure model, or the target model is a model for classification, and the target model is a model constructed based on a neural network.
[0086] In an embodiment of the present specification, the target model is constructed by the XGB algorithm, or the target model is constructed by the LGB algorithm.
[0087] In an embodiment of the present specification, the apparatus further comprises:
[0088] a feature acquisition module, configured to acquire a feature corresponding to a target transaction event initiated by a target user;
[0089] a processing module, configured to input the feature corresponding to the target transaction event into the target model to obtain a probability that the target transaction event exists a preset risk;
[0090] a risk early warning module, configured to perform risk early warning processing on the target user based on the probability that the target transaction event exists the preset risk and risk representation information of a transaction channel corresponding to the target transaction event for the preset risk.
[0091] In an embodiment of the present specification, the preset risk includes one or more of fraud risk and illegal transaction risk.
[0092] An embodiment of the present specification provides a risk perception device for transaction events. By acquiring information of transaction events generated within a preset time period, the feature corresponding to each transaction event and the transaction channel information corresponding to each transaction event can be determined based on the information of each transaction event. Then, the probability that each transaction event exists a preset risk can be obtained by inputting the feature corresponding to each transaction event into a pre-trained target model. Finally, the risk representation information of each transaction channel for the preset risk and / or the risk attribution information of each transaction channel in the transaction channels to which the transaction events generated within the preset time period belong can be determined based on the probability that each transaction event exists the preset risk and the transaction channel information corresponding to each transaction event. Thus, an embodiment of the present specification proposes a risk accumulation method based on transaction events. This method is a more optimal risk perception mechanism. The transaction event granularity is more detailed than the customer granularity, and can be directly associated with the preset risk. Therefore, the sensitivity of threshold segmentation can be reduced. In addition, in the business, it is proposed that in the channel perception, the risk of the current transaction channel should be known to be mainly concentrated in which problems (i.e., the risk attribution information of each transaction channel), such as whether there is too much transaction in a special time period (such as 1-3 o'clock in the morning) or the illegal transaction in the current transaction channel increases.
[0093] Embodiment Four
[0094] The above is a risk perception device for transaction events provided by an embodiment of the present specification. Based on the same idea, an embodiment of the present specification further provides a risk perception device for transaction events, as shown in Figure 5 .
[0095] The risk perception device for transaction events can be a terminal device or a server provided in the above embodiments.
[0096] The transaction event risk perception device can have a large difference due to different configurations or performances, and can include one or more processors 501 and memories 502, and the memories 502 can store one or more stored applications or data. Among them, the memory 502 can be temporary storage or persistent storage. The application stored in the memory 502 can include one or more modules (not shown in the figure), and each module can include a series of computer executable instructions in the transaction event risk perception device. Further, the processor 501 can be configured to communicate with the memory 502 and execute a series of computer executable instructions in the memory 502 on the transaction event risk perception device. The transaction event risk perception device can also include one or more power supplies 503, one or more wired or wireless network interfaces 504, one or more input / output interfaces 505, and one or more keyboards 506.
[0097] In particular, in the present embodiment, the transaction event risk perception device includes a memory and one or more programs, wherein one or more programs are stored in the memory, and one or more programs can include one or more modules, and each module can include a series of computer executable instructions in the transaction event risk perception device, and the one or more programs configured to be executed by the one or more processors include computer executable instructions for:
[0098] Obtaining information of transaction events generated within a preset time period;
[0099] Based on the information of each transaction event, determining the corresponding feature of each transaction event and the corresponding transaction channel information of each transaction event;
[0100] Respectively inputting the corresponding feature of each transaction event into a pre-trained target model to obtain the probability of each transaction event existing a preset risk, and the target model is used to determine the suspicious degree of the transaction event existing a preset risk;
[0101] Based on the probability of each transaction event existing a preset risk and the corresponding transaction channel information of each transaction event, determining the risk characterization information of each transaction channel for the preset risk and / or the risk attribution information of each transaction channel in the transaction channel to which the transaction event generated within the preset time period belongs.
[0102] The various embodiments in the specification are described in a progressive manner, and the same or similar parts between the various embodiments can be referred to each other, and each embodiment focuses on the difference from other embodiments. In particular, for the risk perception device embodiment of the transaction event, since it is basically similar to the method embodiment, the description is relatively simple, and the relevant parts can be referred to the part of the method embodiment.
[0103] The embodiment of the specification provides a risk perception device of a transaction event. By acquiring information of a transaction event generated within a preset time length, the feature corresponding to each transaction event and the transaction channel information corresponding to each transaction event can be determined based on the information of each transaction event. Then, the feature corresponding to each transaction event can be input into a pre-trained target model respectively to obtain the probability that each transaction event exists a preset risk. Finally, the risk characterization information of each transaction channel for the preset risk and / or the risk attribution information of each transaction channel in the transaction channel to which the transaction event generated within the preset time length belongs can be determined based on the probability that each transaction event exists the preset risk and the transaction channel information corresponding to each transaction event. In this way, the embodiment of the specification proposes a risk accumulation mode based on a transaction event. The mode is a more optimal risk perception mechanism, in which the transaction event granularity is more detailed than the customer granularity and can be directly associated with the preset risk, so as to not only reduce the sensitivity of threshold segmentation, but also propose in the business that the risk of the current transaction channel should be known to be mainly concentrated in which problems (i.e. the risk attribution information of each transaction channel), for example, whether there is too much transaction in a special time period (such as the time period of 1am-3am) or the illegal transaction in the current transaction channel increases.
[0104] Embodiment five
[0105] Further, based on the above Figures 1 to 3 The one or more embodiments of the specification also provide a storage medium for storing computer executable instruction information. In a specific embodiment, the storage medium can be a U disk, an optical disk, a hard disk, etc. The computer executable instruction information stored in the storage medium can implement the following flow when executed by a processor.
[0106] acquire information of a transaction event generated within a preset time length;
[0107] determine the feature corresponding to each transaction event and the transaction channel information corresponding to each transaction event based on the information of each transaction event;
[0108] input the feature corresponding to each of the transaction events into a pre-trained target model respectively to obtain a probability that each of the transaction events exists a preset risk, the target model being used to determine a suspicious degree that the transaction event exists the preset risk;
[0109] determine, based on the probability that each of the transaction events exists the preset risk and the transaction channel information corresponding to each of the transaction events, risk characterization information of each of the transaction channels in the transaction channels to which the transaction events generated within a preset time length belong for the preset risk and / or risk attribution information of each of the transaction channels.
[0110] Each of the embodiments in the specification is described in a progressive manner, and the same and similar parts of each of the embodiments can be referred to each other. Each of the embodiments focuses on the difference from other embodiments. In particular, for the above-mentioned storage medium embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and the related parts can be referred to the part of the method embodiment.
[0111] The storage medium provided by the embodiment of the specification can obtain the information of the transaction events generated within a preset time length, and then can determine the feature corresponding to each transaction event and the transaction channel information corresponding to each transaction event based on the information of each transaction event. Then, the feature corresponding to each transaction event can be input into a pre-trained target model respectively to obtain a probability that each of the transaction events exists a preset risk. Finally, based on the probability that each of the transaction events exists the preset risk and the transaction channel information corresponding to each of the transaction events, risk characterization information of each of the transaction channels in the transaction channels to which the transaction events generated within a preset time length belong for the preset risk and / or risk attribution information of each of the transaction channels can be determined. In this way, the embodiment of the specification proposes a risk accumulation method based on transaction events, which is a more optimal risk perception mechanism. The transaction event granularity is more detailed than the customer granularity, and can be directly associated with the preset risk, so as to not only reduce the sensitivity of threshold segmentation, but also propose that in the business, the risk of the current transaction channel should be known to be mainly concentrated in which problems (i.e. the risk attribution information of each transaction channel), for example, whether there is too much transaction in a special time period (such as 1am-3am) or illegal transaction in the current transaction channel increases, etc.
[0112] The above described embodiments of the present description have been described. Other embodiments are within the scope of the following claims. In some cases, the actions or steps recited in the claims can be performed in a different order and still achieve desirable results. Additionally, the processes depicted in the figures do not necessarily require the particular order shown, or sequential order, to achieve the desired results. In certain implementations, multitasking and parallel processing can be advantageous.
[0113] In the 1990s, it was relatively easy to distinguish whether an improvement in a technology was a hardware improvement (e.g., an improvement in the circuit structure of a diode, transistor, switch, etc.) or a software improvement (an improvement in a method flow). However, as technology has evolved, many improvements in method flows today can be considered as direct improvements in hardware circuit structures. Designers almost always obtain the corresponding hardware circuit structures by programming the improved method flows into hardware circuits. Therefore, it cannot be said that an improvement in a method flow cannot be implemented using hardware entity modules. For example, a programmable logic device (PLD) (e.g., a field programmable gate array (FPGA)) is an integrated circuit whose logic function is determined by user programming of the device. A digital system is "integrated" on a PLD by the designer programming the PLD, rather than by ordering a chip manufacturer to design and fabricate a custom integrated circuit chip. Moreover, instead of manually fabricating integrated circuit chips, this programming is now mostly implemented using "logic compiler" software, which is similar to software compilers used in program development, and the original code to be compiled is written in a specific programming language, which is called a hardware description language (HDL), and there are many such languages, such as ABEL (Advanced Boolean Expression Language), AHDL (Altera Hardware Description Language), Confluence, CUPL (Cornell University Programming Language), HDCal, JHDL (Java Hardware Description Language), Lava, Lola, MyHDL, PALASM, RHDL (Ruby Hardware Description Language), etc., and the most commonly used are VHDL (Very-High-Speed Integrated Circuit Hardware Description Language) and Verilog. Those skilled in the art should be aware that, as long as the method flow is logically programmed in the above-mentioned hardware description languages and programmed into an integrated circuit, a hardware circuit implementing the logical method flow can be easily obtained.
[0114] The controller can be implemented in any suitable way, for example, the controller can take the form of a microprocessor or processor and a computer readable medium storing computer readable program code, such as software or firmware, executable by the (micro)processor, logic gates, switches, an application specific integrated circuit (ASIC), a programmable logic controller, and an embedded microcontroller, examples of which include but are not limited to the following microcontrollers: ARC 625D, Atmel AT91SAM, Microchip PIC18F26K20, and Silicone Labs C8051F320, the memory controller can also be implemented as part of the control logic of the memory. Those skilled in the art will also know that, in addition to implementing the controller in pure computer readable program code, it is also possible to implement the controller in the form of logic gates, switches, application specific integrated circuits, programmable logic controllers, and embedded microcontrollers, etc. to achieve the same functionality by logically programming the method steps. Such a controller can therefore be considered as a hardware component, and the means included therein for implementing various functions can also be considered as structures within the hardware component. Alternatively, the means for implementing various functions can even be considered as both a software module implementing the method and a structure within the hardware component.
[0115] The systems, apparatuses, modules or units illustrated by the above embodiments can be specifically implemented by computer chips or entities, or by products with certain functions. A typical implementation device is a computer. Specifically, the computer can be, for example, a personal computer, a laptop computer, a cellular phone, a camera phone, a smart phone, a personal digital assistant, a media player, a navigation device, an email device, a game console, a tablet computer, a wearable device, or a combination of any of these devices.
[0116] For the sake of description, the above apparatuses are described in functional division and are described respectively. Of course, the functions of each unit can be implemented in the same or more software and / or hardware when implementing one or more embodiments of the present specification.
[0117] Those skilled in the art will understand that the embodiments of the present specification can be provided as a method, a system, or a computer program product. Therefore, one or more embodiments of the present specification can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, one or more embodiments of the present specification can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0118] The embodiments of the present specification are described with reference to flowcharts and / or block diagrams of the method, device (system) and computer program product according to the embodiments of the present specification. It should be understood that each flow and / or block in the flowcharts and / or block diagrams, and the combination of flows and / or blocks in the flowcharts and / or block diagrams can be implemented by computer program instructions. These computer program instructions can be provided to a general-purpose computer, a special-purpose computer, an embedded processor or other programmable electronic devices to produce a machine, so that the instructions executed by the computer or other programmable electronic devices generate a device that implements the functions specified in the flowcharts and / or block diagrams. Figure 1 one or more flows and / or blocks. Figure 1 one or more flows and / or blocks.
[0119] These computer program instructions can also be stored in a computer readable memory capable of directing the computer or other programmable electronic devices to work in a specific manner, so that the instructions stored in the computer readable memory produce a manufactured product including instruction devices, which implement the functions specified in the flowcharts and / or block diagrams. Figure 1 one or more flows and / or blocks. Figure 1 one or more flows and / or blocks.
[0120] These computer program instructions can also be loaded into a computer or other programmable electronic devices, so that a series of operation steps are performed on the computer or other programmable electronic devices to produce a computer implemented process, so that the instructions executed on the computer or other programmable electronic devices provide steps for implementing the functions specified in the flowcharts and / or block diagrams. Figure 1 one or more flows and / or blocks. Figure 1 one or more flows and / or blocks.
[0121] In a typical configuration, the computing device includes one or more processors (CPUs), input / output interfaces, network interfaces and memories.
[0122] The memory can include non-persistent memory in the computer readable medium, random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash memory (flash RAM). The memory is an example of the computer readable medium.
[0123] Computer-readable media includes permanent and non-permanent, movable and non-movable media that can be implemented by any method or technology to store information. The information can be computer-readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassette, magnetic tape, magnetic disk storage or other magnetic storage devices, or any other non-transmission medium that can be used to store information accessible to a computing device. According to the definition herein, computer-readable media does not include transitory media such as modulated data signals and carriers.
[0124] It should also be noted that the terms "comprising", "containing", or any other variant thereof are intended to cover non-exclusive inclusion, such that a process, method, article or apparatus that comprises a list of elements does not only include those elements, but can also include other elements not expressly listed or inherent to such process, method, article or apparatus. Without more limitations, the element defined by the statement "comprising a" does not exclude the presence of additional identical elements in the process, method, article or apparatus that includes the element.
[0125] Those skilled in the art will appreciate that embodiments of the present specification can be provided as methods, systems or computer program products. Therefore, one or more embodiments of the present specification can take the form of an entirely hardware embodiment, an entirely software embodiment or an embodiment combining software and hardware aspects. Moreover, one or more embodiments of the present specification can take the form of a computer program product implemented on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0126] One or more embodiments of the present specification can be described in the general context of computer-executable instructions, such as program modules, being executed by a computer. Generally, program modules include routines, programs, objects, components, data structures, etc. that perform particular tasks or implement particular abstract data types. One or more embodiments of the present specification can also be practiced in a distributed computing environment, in which tasks are performed by remote processing devices connected through a communication network. In a distributed computing environment, program modules can be located in both local and remote computer storage media, including storage devices.
[0127] Each of the embodiments in the specification is described in a progressive manner, and the same or similar parts between the embodiments can be referred to each other. Each of the embodiments focuses on the difference from other embodiments. In particular, for the system embodiments, since they are basically similar to the method embodiments, the description is relatively simple, and the relevant parts can be referred to the part of the method embodiments.
[0128] The above only describes the embodiments of the specification and is not used to limit the application. The specification can have various changes and modifications for those skilled in the art. Any modification, equivalent replacement, improvement, etc. within the spirit and principle of the specification shall be included in the scope of claims of the specification.
Claims
1. A method for risk perception of a transaction event, the method comprising: Obtain information on transaction events generated within a preset time period; Based on the information of each transaction event, determine the characteristics corresponding to each transaction event and the transaction channel information corresponding to each transaction event; The features corresponding to each transaction event are input into a pre-trained target model to obtain the probability that each transaction event has a preset risk. The target model is used to determine the degree of suspicion that the transaction event has a preset risk. Based on the probability of a preset risk in each transaction event and the transaction channel information corresponding to each transaction event, risk characterization information and / or risk attribution information for each transaction channel are determined for each transaction channel to which the transaction event generated within a preset time period belongs. The risk characterization information is used to characterize the probability of the preset risk in the transaction channel, and the risk attribution information includes information on the factors that cause the preset risk in the transaction channel. The step of determining the risk characterization information for each transaction channel within a preset time period, based on the probability of a preset risk existing in each transaction event and the transaction channel information corresponding to each transaction event, includes: Based on the transaction channel information corresponding to each transaction event, determine the transaction channel to which the transaction event generated within a preset time period belongs; The probability of a predetermined risk existing in a transaction event contained in each of the transaction channels is statistically analyzed to obtain risk characterization information for each of the transaction channels in response to the predetermined risk.
2. The method according to claim 1, wherein determining the risk attribution information for each transaction channel based on the probability of a preset risk existing in each transaction event and the transaction channel information corresponding to each transaction event includes: Based on the transaction channel information corresponding to each transaction event, determine the transaction channel to which the transaction event generated within a preset time period belongs; Based on the probability of a preset risk in each transaction event and the characteristics corresponding to each transaction event, the feature importance of each transaction channel is determined; Based on the feature importance corresponding to each of the transaction channels, risk attribution information for each of the transaction channels is determined.
3. The method according to claim 2, wherein determining the feature importance of each transaction channel based on the probability of a preset risk in each transaction event and the features corresponding to each transaction event includes: Based on the probability of a preset risk in each transaction event and the characteristics corresponding to each transaction event, the Shapley addition method is used to interpret the SHAP algorithm or the locally interpretable model-agnostic interpretation LIME algorithm to determine the feature importance corresponding to each transaction channel.
4. The method according to claim 1, wherein the target model is a model for classification, and the target model is a tree-structured model, or the target model is a model for classification, and the target model is a model constructed based on a neural network.
5. The method according to claim 4, wherein the target model is constructed by an extreme gradient boosting XGB algorithm, or the target model is constructed by a lightweight gradient boosting machine LGB algorithm.
6. The method according to claim 1, further comprising: Obtain the characteristics corresponding to the target transaction event initiated by the target user; The features corresponding to the target transaction event are input into the target model to obtain the probability that the target transaction event has a preset risk; Based on the probability of a preset risk in the target transaction event and the risk characterization information of the transaction channel corresponding to the target transaction event for the preset risk, risk warning processing is performed on the target user.
7. The method according to claim 1, wherein the preset risk includes one or more of fraud risk and illegal transaction risk.
8. A risk perception device for a transaction event, the device comprising: The information acquisition module acquires information about transaction events generated within a preset time period; The information processing module determines the characteristics corresponding to each transaction event and the transaction channel information corresponding to each transaction event based on the information of each transaction event; The probability determination module inputs the features corresponding to each transaction event into a pre-trained target model to obtain the probability that each transaction event has a preset risk. The target model is used to determine the degree of suspicion that the transaction event has a preset risk. The risk perception module, based on the probability of a preset risk existing in each transaction event and the transaction channel information corresponding to each transaction event, determines the risk characterization information and / or risk attribution information for each transaction channel in relation to the preset risk in the transaction channel to which the transaction event generated within a preset time period belongs. The risk characterization information is used to characterize the probability of the preset risk existing in the transaction channel, and the risk attribution information includes information on the factors that cause the preset risk to exist in the transaction channel. The risk perception module determines the transaction channel to which the transaction event generated within a preset time period belongs based on the transaction channel information corresponding to each transaction event; it calculates the probability that the transaction events contained in each transaction channel have a preset risk, and obtains the risk characterization information of each transaction channel for the preset risk.
9. A risk perception device for a transaction event, the risk perception device for the transaction event comprising: processor; as well as A memory configured to store computer-executable instructions, which, when executed, cause the processor to: Obtain information on transaction events generated within a preset time period; Based on the information of each transaction event, determine the characteristics corresponding to each transaction event and the transaction channel information corresponding to each transaction event; The features corresponding to each transaction event are input into a pre-trained target model to obtain the probability that each transaction event has a preset risk. The target model is used to determine the degree of suspicion that the transaction event has a preset risk. Based on the probability of a preset risk in each transaction event and the transaction channel information corresponding to each transaction event, risk characterization information and / or risk attribution information for each transaction channel are determined for each transaction channel to which the transaction event generated within a preset time period belongs. The risk characterization information is used to characterize the probability of the preset risk in the transaction channel, and the risk attribution information includes information on the factors that cause the preset risk in the transaction channel. The step of determining the risk characterization information for each transaction channel within a preset time period, based on the probability of a preset risk existing in each transaction event and the transaction channel information corresponding to each transaction event, includes: Based on the transaction channel information corresponding to each transaction event, determine the transaction channel to which the transaction event generated within a preset time period belongs; The probability of a predetermined risk existing in a transaction event contained in each of the transaction channels is statistically analyzed to obtain risk characterization information for each of the transaction channels in response to the predetermined risk.
Citation Information
Patent Citations
Transaction risk assessment method, device and computer system
CN110533536A