A method and device for preventing fraud on traffic platforms.

By analyzing user logs from traffic platforms, we can filter and identify abnormal user behavior, thus solving the problem of fake click data on traffic platforms and accurately identifying and reducing advertisers' losses.

CN116455597BActive Publication Date: 2026-05-26TUYOO GAMES +1
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
TUYOO GAMES
Filing Date
2023-02-23
Publication Date
2026-05-26

AI Technical Summary

Technical Problem

In the internet advertising market, some traffic platforms use fraudulent methods to falsify user click data, causing advertisers to lose advertising fees. Existing methods for judging this are inaccurate and lack timeliness.

Method used

By scanning user logs, paying users are obtained from different channels, low-paying users are filtered out, their game status is determined, and abnormal users are marked as evidence of cheating for anti-cheating management.

Benefits of technology

It improves the accuracy of identifying fake users, reduces advertisers' losses, and curbs cheating behavior on traffic platforms.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116455597B_ABST
    Figure CN116455597B_ABST
Patent Text Reader

Abstract

This application provides an anti-fraud method, apparatus, device, and storage medium for traffic platforms. In embodiments of this application, to identify potential fraudulent behavior on a traffic platform, a log scan is first performed to obtain users who paid on the registration day by channel. Then, users are filtered based on their payment tier, identifying those who chose lower payment tiers on the registration day. Furthermore, the game performance of these users is assessed; if their game efficiency is low in the first few days after registration, these users are marked as abnormal users, and these abnormal users serve as evidence of fraudulent behavior on the traffic platform. This not only reduces losses for advertisers but also constrains fraudulent behavior on the traffic platform.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of computer system security technology, and in particular to an anti-fraud method and apparatus, computing device and computer-readable storage medium for traffic platforms. Background Technology

[0002] Currently, with the rapid development of the internet and the widespread application of mobile smart terminals, the internet advertising market is expanding rapidly. Advertisers pay traffic platforms to place their ads through the platforms' apps, websites, and other means. However, some traffic platforms in the internet advertising market, in order to gain more profit, resort to fraudulent methods to generate fake clicks on displayed ads. When advertisers settle accounts with these platforms based on the number of clicks, they have to pay extra for these ineffective, fake impressions. Therefore, advertisers urgently need an anti-fraud method to identify the fraudulent practices of traffic platforms and avoid losses. Summary of the Invention

[0003] In view of this, embodiments of this application provide an anti-fraud method and apparatus, computing device and computer-readable storage medium for traffic platforms, to address the technical deficiencies existing in the prior art.

[0004] According to a first aspect of the embodiments of this application, an anti-fraud method for traffic platforms is provided, comprising:

[0005] Scan user logs to identify the first user who made a payment on the day of registration, categorized by channel.

[0006] The second user was obtained by filtering the payment tiers of the first user on the day of registration;

[0007] The game status of the second user is judged, and a list of abnormal users is obtained by filtering.

[0008] Anti-fraud management is carried out based on the list of abnormal users.

[0009] According to a second aspect of the embodiments of this application, an anti-fraud device for a traffic platform is provided, comprising:

[0010] The scanning unit is used to identify the first user who paid on the day of registration through different channels;

[0011] The filtering unit is used to filter the first user's payment tier on the day of registration to obtain the second user;

[0012] The judgment unit is used to judge the game status of the second user and filter to obtain a list of abnormal users;

[0013] The management unit is used to perform anti-fraud management based on the list of abnormal users.

[0014] According to a third aspect of the embodiments of this application, a computing device is provided, including a memory, a processor, and computer instructions stored in the memory and executable on the processor, wherein the processor executes the instructions to implement the steps of the anti-fraud method of the traffic platform.

[0015] According to a fourth aspect of the embodiments of this application, a computer-readable storage medium is provided that stores computer instructions, which, when executed by a processor, implement the steps of the anti-fraud method of the traffic platform.

[0016] In this embodiment, to protect advertisers' interests and identify fraudulent activities by traffic platforms posing as paying users to defraud advertising revenue, the accuracy of identifying such users is improved by utilizing their abnormal behavior in the game, which differs from that of normal users. In this embodiment, logs are first scanned to obtain users who paid on the registration day from different channels. Then, users who chose lower payment tiers on the registration day are filtered out. Further analysis of these users' in-game behavior is conducted. If these users exhibit low game efficiency in the first few days after registration, or even simply enter the game and leave it idle without any action, these users are marked as abnormal users. These abnormal users serve as evidence of fraudulent activities by the traffic platform, reducing advertisers' losses and curbing fraudulent behavior by the traffic platform. Attached Figure Description

[0017] Figure 1 This is a structural block diagram of the computing device provided in the embodiments of this application;

[0018] Figure 2 This is a flowchart illustrating an anti-fraud method for a traffic platform provided in an embodiment of this application;

[0019] Figure 3 This is a schematic diagram of the structure of an anti-fraud device for a traffic platform provided in an embodiment of this application; Detailed Implementation

[0020] Many specific details are set forth in the following description to provide a full understanding of this application. However, this application can be implemented in many other ways different from those described herein, and those skilled in the art can make similar extensions without departing from the spirit of this application; therefore, this application is not limited to the specific embodiments disclosed below.

[0021] The terminology used in one or more embodiments of this application is for the purpose of describing particular embodiments only and is not intended to limit the scope of one or more embodiments of this application. The singular forms “a,” “the,” and “the” used in one or more embodiments of this application and in the appended claims are also intended to include the plural forms unless the context clearly indicates otherwise. It should also be understood that the term “and / or” used in one or more embodiments of this application refers to and includes any or all possible combinations of one or more associated listed items.

[0022] It should be understood that although the terms first, second, etc., may be used to describe various information in one or more embodiments of this application, such information should not be limited to these terms. These terms are only used to distinguish information of the same type from one another. For example, first may also be referred to as second without departing from the scope of one or more embodiments of this application, and similarly, second may also be referred to as first. Depending on the context, the word "if" as used herein may be interpreted as "in response to a determination".

[0023] This application provides an anti-fraud method and apparatus, a computing device and a computer-readable storage medium for traffic platforms, which will be described in detail in the following embodiments.

[0024] Figure 1 A structural block diagram of a computing device 100 according to an embodiment of this application is shown. The components of the computing device 100 include, but are not limited to, a memory 110 and a processor 120. The processor 120 is connected to the memory 110 via a bus 130, and a database 150 is used to store data.

[0025] The computing device 100 also includes an access device 140, which enables the computing device 100 to communicate via one or more networks 160. Examples of these networks include a Public Switched Telephone Network (PSTN), a Local Area Network (LAN), a Wide Area Network (WAN), a Personal Area Network (PAN), or a combination of communication networks such as the Internet. The access device 140 may include one or more of any type of wired or wireless network interface (e.g., a Network Interface Card (NIC)), such as an IEEE 802.11 Wireless Local Area Network (WLAN) interface, a Wi-MAX interface, an Ethernet interface, a Universal Serial Bus (USB) interface, a cellular network interface, a Bluetooth interface, a Near Field Communication (NFC) interface, and so on.

[0026] In one embodiment of this application, the aforementioned components of the computing device 100 and Figure 1 Other components, not shown, can also be connected to each other, for example, via a bus. It should be understood that... Figure 1The block diagram of the computing device shown is for illustrative purposes only and is not intended to limit the scope of this application. Those skilled in the art can add or replace other components as needed.

[0027] The computing device 100 can be any type of stationary or mobile computing device, including mobile computers or mobile computing devices (e.g., tablet computers, personal digital assistants, laptop computers, notebook computers, netbooks, etc.), mobile phones (e.g., smartphones), wearable computing devices (e.g., smartwatches, smart glasses, etc.) or other types of mobile devices, or stationary computing devices such as desktop computers or PCs. The computing device 100 can also be a mobile or stationary server.

[0028] In the existing internet advertising industry, advertisers typically pay traffic platforms to gain exposure on various internet channels to promote their products. On the one hand, advertisers want greater transparency in budget usage and a more transparent approach to campaign strategies and data, aiming to minimize unnecessary expenses. On the other hand, traffic platforms prefer a more opaque advertising process to maintain greater strategic and profit margins. Typically, media platforms do not disclose their campaign strategies to advertisers. Because advertising costs are linked to user behavior such as clicks, some traffic platforms resort to fraudulent methods to falsify data. For example, they might use multiple devices to impersonate users clicking ads and downloading apps, defrauding advertisers and severely damaging their interests. Existing methods for detecting fraud typically involve analyzing user retention rates across channels. However, this method is not only untimely—by the time a problem is discovered, the settlement period between the advertiser and the traffic platform has already passed—but also inaccurate in its results.

[0029] Therefore, in order to solve the above problems, this application proposes an anti-fraud method for traffic platforms, see [link to relevant documentation]. Figure 2 As shown, the method includes steps 202 to 208:

[0030] Step 202: Scan user logs and identify the first user who paid on the day of registration, categorized by channel.

[0031] In the existing internet advertising market, advertisers typically submit their product advertisements, such as promotional ads for mobile apps, to multiple different traffic platforms for publication. When users on these platforms trigger the ads, advertisers can collect user access data from these various channels and save this data to a log database maintained by the advertiser. This user access data includes, but is not limited to, actions such as clicking on ads, downloading mobile apps, registering new users, and making payments.

[0032] In one feasible implementation, the log database is scanned periodically to obtain user access data from different channels. This user access data is limited to users who paid on the day of registration. This method yields user data from various channels who paid on the day of registration.

[0033] Step 204: Filter the payment tier of the first user on the day of registration to obtain the second user;

[0034] In this step, the user data obtained in step 202 is further filtered to determine the payment tiers for the users on the day of registration. For example, the app may offer different payment tiers, such as 1 yuan, 6 yuan, and 15 yuan.

[0035] The payment tier data of the first user is filtered to obtain the second user whose payment tier is less than the first threshold.

[0036] In this implementation, considering that fake paying users always choose lower payment tiers in order to save costs, the payment tiers are filtered according to a first threshold. The first threshold can be adjusted according to specific needs and actual data conditions, and is not specifically limited here.

[0037] Step 206: Determine the game status of the second user and filter to obtain a list of abnormal users.

[0038] In this step, the status of the second user in the game is judged. When the second user's game efficiency value is lower than the preset value, he / she is marked as an abnormal user.

[0039] In one feasible implementation, the game status of the second user on the registration day is determined, including the duration of the second user's game battles, to obtain the game battle duration T1 on the registration day.

[0040] For example, in shooting games, the game duration mentioned above refers to the duration of combat within the game room;

[0041] In card and board games, the aforementioned game duration refers to the duration of each table match in the game lobby;

[0042] In RPG games, the aforementioned game time refers to the time spent participating in in-game quests, such as various dungeons;

[0043] For other types of games, such as puzzle games and sports games, game time also refers to the duration of in-room battles.

[0044] Judging the second user's game status on the day of registration also includes obtaining the second user's game battle score S1 obtained through battles on the day of registration.

[0045] For example, the number of enemies knocked down in a shooting game; the number of games participated in in a card game, etc.

[0046] Furthermore, the game status of the second user over several consecutive days after registration is assessed to obtain the user's daily game playtime Tn and daily game score Sn, where n is the number of registration days and n≥2. For example, T2 is the user's game playtime on the second day after registration, T3 is the user's game playtime on the third day after registration, S2 is the user's game score on the second day after registration, S3 is the user's game score on the third day after registration, and so on. Those skilled in the art can choose the value of n according to the specific circumstances, which will not be elaborated here.

[0047] Furthermore, abnormal users are filtered based on the second user's game status. If the second user's game efficiency value is lower than the second threshold on the day of registration or any day after registration, the second user is marked as an abnormal user.

[0048] Specifically, S1 / T1 and Sn / Tn represent the game efficiency values ​​of the second user on the registration day and every day thereafter. When either S1 / T1 or Sn / Tn is less than a second threshold, the second user is marked as an abnormal user, where n≥2.

[0049] Preferably, n=2, that is, when the value of S1 / T1 or S2 / T2 is less than the second threshold, it is considered that the second user has a low game efficiency value in the first two days after registration, that is, the game participation is low, and there may even be a situation where the user is AFK in the game without any action; combined with the characteristic in step 204 that the second user always chooses the smaller payment level, this type of second user is marked as an abnormal user.

[0050] The second threshold can be derived from experience based on big data results and can be adjusted according to the actual data situation; no special restrictions are imposed here.

[0051] Optionally, a second threshold can be obtained by comparing and matching the game efficiency values ​​from users of the target channel with the normal game efficiency values ​​from users of other channels.

[0052] In another feasible implementation, the remaining game points M of the second user on the registration day are obtained, which are the number of points obtained through payment in the game and not used up on the registration day.

[0053] Furthermore, when M is greater than the third threshold, the aforementioned second user is identified as an abnormal user.

[0054] In another feasible implementation, if the second user's game efficiency value is lower than the second threshold on the day of registration or any day after registration, and the number of remaining game points M on the day of registration is greater than the third threshold, the second user is identified as an abnormal user.

[0055] Step 208: Implement anti-fraud management based on the list of abnormal users.

[0056] In this step, the user_id of the abnormal user list is recorded into the relevant subgroup, and then used as evidence to prove that the traffic platform has cheating behavior.

[0057] In the above embodiments of this application, in order to protect the interests of advertisers and identify the fraudulent behavior of traffic platforms posing as paying users to defraud advertising fees, the abnormal behavior of these fake users in the game, which differs from that of normal users, is fully utilized, thereby improving the accuracy of identifying such users. This abnormal behavior always aims to obtain a seemingly normal user identity from its own traffic channels by incurring minimal costs, such as money or time. These users are not genuinely interested in the advertising content, and therefore, they can be identified. In the embodiments of this application, logs are first scanned to obtain users who paid on the registration day by channel; then, the payment tier is filtered to identify users who chose lower payment tiers on the registration day. Further analysis of these users' in-game status is conducted. When these users have low game efficiency values ​​in the first few days after registration, or even simply enter the game and leave it running without any gameplay activity, these users are marked as abnormal users. These abnormal users are used as evidence of fraudulent behavior by the traffic platform. This solution not only reduces the losses of advertisers but also constrains the fraudulent behavior of traffic platforms.

[0058] Corresponding to the above-described anti-fraud method embodiments for traffic platforms, this application also provides an anti-fraud device for traffic platforms, such as... Figure 3 As shown, the device includes:

[0059] The scanning unit is used to identify the first user who paid on the day of registration through different channels;

[0060] The filtering unit is used to filter the first user's payment tier on the day of registration to obtain the second user;

[0061] The judgment unit is used to judge the game status of the second user and filter to obtain a list of abnormal users;

[0062] The management unit is used to perform anti-fraud management based on the list of abnormal users.

[0063] This application also provides a server on which the aforementioned anti-fraud device for traffic platforms is deployed.

[0064] It should be noted that the technical solution of the anti-fraud device for traffic platforms and the technical solution of the anti-fraud method for traffic platforms are based on the same concept. For details not described in detail in the technical solution of the anti-fraud device for traffic platforms, please refer to the description of the technical solution of the anti-fraud method for traffic platforms.

[0065] One embodiment of this application also provides a computing device, including a memory, a processor, and computer instructions stored in the memory and executable on the processor, wherein the processor executes the instructions to implement the steps of the anti-fraud method for the traffic platform.

[0066] The above is an illustrative scheme of a computing device according to this embodiment. It should be noted that the technical solution of this computing device and the technical solution of the anti-fraud method for traffic platforms described above belong to the same concept. For details not described in detail in the technical solution of the computing device, please refer to the description of the technical solution of the anti-fraud method for traffic platforms described above.

[0067] An embodiment of this application also provides a computer-readable storage medium storing computer instructions that, when executed by a processor, implement the steps of the anti-fraud method for a traffic platform as described above.

[0068] The above is an illustrative scheme of a computer-readable storage medium according to this embodiment. It should be noted that the technical solution of this storage medium belongs to the same concept as the technical solution of the anti-fraud method for traffic platforms described above. For details not described in detail in the technical solution of the storage medium, please refer to the description of the technical solution of the anti-fraud method for traffic platforms described above.

[0069] The foregoing has described specific embodiments of this application. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims may be performed in a different order than that shown in the embodiments and may still achieve the desired results. Furthermore, the processes depicted in the drawings do not necessarily require the specific or sequential order shown to achieve the desired results. In some embodiments, multitasking and parallel processing are also possible or may be advantageous.

[0070] The computer instructions include computer program code, which may be in the form of source code, user code, executable files, or certain intermediate forms. The computer-readable medium may include any entity or device capable of carrying the computer program code, recording media, USB flash drives, portable hard drives, magnetic disks, optical disks, computer memory, read-only memory (ROM), random access memory (RAM), electrical carrier signals, telecommunication signals, and software distribution media, etc. It should be noted that the content contained in the computer-readable medium may be appropriately added to or subtracted according to the requirements of legislation and patent practice in the jurisdiction. For example, in some jurisdictions, according to legislation and patent practice, computer-readable media may not include electrical carrier signals and telecommunication signals.

[0071] It should be noted that, for the sake of simplicity, the foregoing method embodiments are all described as a series of actions. However, those skilled in the art should understand that this application is not limited to the described order of actions, as some steps may be performed in other orders or simultaneously according to this application. Furthermore, those skilled in the art should also understand that the embodiments described in the specification are preferred embodiments, and the actions and modules involved are not necessarily essential to this application.

[0072] In the above embodiments, the descriptions of each embodiment have different focuses. For parts not described in detail in a certain embodiment, please refer to the relevant descriptions of other embodiments.

[0073] The preferred embodiments disclosed above are merely illustrative of this application. The optional embodiments do not exhaustively describe all details, nor do they limit the invention to the specific implementations described. Clearly, many modifications and variations can be made based on the content of this application. These embodiments are selected and specifically described in this application to better explain the principles and practical applications of this application, thereby enabling those skilled in the art to better understand and utilize this application. This application is limited only by the claims and their full scope and equivalents.

Claims

1. An anti-cheating method for a traffic platform, characterized in that, include: Scan user logs to identify the first user who paid on the day of registration, categorized by channel; To obtain a second user by filtering the payment tier of the first user on the day of registration, the process includes: filtering the payment tier data of the first user to obtain a second user whose payment tier is less than a first threshold. The game status of the second user is assessed, and a list of abnormal users is obtained. This includes: on the registration day or any day n after registration, if the game efficiency value of the second user is lower than a second threshold, the user is marked as an abnormal user, where n ≥ 2; wherein, marking the second user as an abnormal user on the registration day or any day n after registration when the game efficiency value of the second user is lower than the second threshold includes: Get the game battle duration T1 on the day the second user registered and the game battle score S1 on the day the second user registered; get the game battle duration Tn and the game battle score Sn of the second user every day after the day of registration, where n≥2; when either S1 / T1 or Sn / Tn is less than the second threshold, mark the second user as an abnormal user; Anti-fraud management is carried out based on the list of abnormal users.

2. The method of claim 1, wherein, The second threshold is obtained by comparing the game efficiency value of users in the target channel with the normal game efficiency value of users in other channels.

3. The method of claim 1, wherein, The abnormal user list obtained by judging the game status of the second user also includes: Obtain the remaining game points M of the second user on the registration day, where M is the points obtained through payment in the game and not used up on the registration day; When M is greater than the third threshold, the second user is identified as an abnormal user.

4. An anti-cheating device for a traffic platform, characterized in that, include: The scanning unit is used to identify the first user who paid on the day of registration through different channels. The filtering unit is used to filter the payment tier of the first user on the registration day to obtain the second user, including filtering the payment tier data of the first user to obtain the second user whose payment tier is less than a first threshold. The judgment unit is used to judge the game status of the second user and filter to obtain a list of abnormal users, including any day on the registration day or the nth day after registration, when the game efficiency value of the second user is lower than a second threshold, the user is marked as an abnormal user, where n≥2; wherein, marking the second user as an abnormal user on any day on the registration day or the nth day after registration when the game efficiency value of the second user is lower than the second threshold includes: obtaining the game battle duration T1 and the game battle score S1 of the second user on the registration day; obtaining the game battle duration Tn and the game battle score Sn of the second user on each day after the registration day, where n≥2; when either S1 / T1 or Sn / Tn is less than the second threshold, the second user is marked as an abnormal user; The management unit is used to perform anti-fraud management based on the list of abnormal users.

5. A server, wherein the anti-fraud device for a traffic platform as described in claim 4 is deployed on the server.

6. A computing device comprising a memory, a processor, and computer instructions stored on the memory and executable on the processor, wherein, When the processor executes the instructions, it implements the steps of the method according to any one of claims 1-3.

7. A computer-readable storage medium storing computer instructions, wherein, When executed by the processor, this instruction implements the steps of the method according to any one of claims 1-3.