Anti-fraud information pushing method, graphical interface and related device
By collecting user behavior data to generate user profiles and pushing precise anti-fraud information, the problem of insufficient public awareness of anti-fraud has been solved, effectively preventing online fraud.
Patent Information
- Application Number
- CN202211527538.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-12-01
- Publication Date
- 2026-05-15
- Estimated Expiration
- 2042-12-01
AI Technical Summary
How to promptly and effectively disseminate anti-fraud information to the public in order to raise public awareness of fraud prevention and prevent online fraud cases from occurring.
By collecting user behavior data, user profiles are generated, and combined with fraud detection rules, accurate anti-fraud information, including fraud cases and information about fraudsters, is pushed to users.
It enables the push of accurate anti-fraud information to users, reducing the risk of users falling into fraud and protecting their personal and property safety.
Smart Images

Figure CN118134617B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of terminals, and in particular to a method, graphical interface and related device for pushing anti-fraud information. Background Technology
[0002] With the development of terminal technology, there are more and more cases of online fraud. How to timely and effectively disseminate anti-fraud information to the public in order to raise public awareness of fraud prevention and prevent people from being deceived is an urgent problem to be solved. Summary of the Invention
[0003] This application provides a method, graphical interface, and related devices for pushing anti-fraud information. The electronic device reports collected user behavior data to a server, which then generates a corresponding user profile based on this data. Furthermore, the electronic device extracts fraud-related data features from the user behavior data and reports these features to the server. The server determines whether these features pose a fraud risk based on pre-stored fraud detection rules. If so, it determines the type of anti-fraud information based on the fraud type, fraud content, and user profile, and sends the corresponding type of anti-fraud information from its database to the electronic device, enabling the device to push this type of anti-fraud information to the user.
[0004] In a first aspect, this application provides a method for pushing anti-fraud information. The method is applied to a communication system including an electronic device and a server. The method includes: the electronic device collecting first behavioral data of a user using the electronic device; the electronic device sending the first behavioral data to the server; the server generating a user profile based on the first behavioral data; the server filtering first anti-fraud information from multiple anti-fraud information based on the user profile, the first anti-fraud information including: fraud cases and / or, fraudster information; the server sending the first anti-fraud information to the electronic device; and the electronic device outputting the first anti-fraud information.
[0005] After implementing the method provided in the first aspect, the server can send anti-fraud information that matches the user profile to electronic devices, thereby achieving the purpose of precise push notifications.
[0006] Secondly, this application provides a method for pushing anti-fraud information. This method is applied to a communication system including an electronic device and a server. The method includes: the electronic device collecting first behavioral data of a user using the electronic device; the electronic device sending the first behavioral data to the server; the server generating a user profile based on the first behavioral data; the electronic device collecting second behavioral data of the user using the electronic device, the second behavioral data including information from any one or more of the following sources: a phone application, an SMS application, an application installation manager, or a browser; the electronic device sending the second behavioral data to the server; the server determining second anti-fraud information based on the user profile and the source and information of the fraud-risk behavioral data in the second behavioral data; the server sending the second anti-fraud information to the electronic device, the second anti-fraud information including: fraud cases and / or information about the fraudsters; and the electronic device outputting the second anti-fraud information.
[0007] After implementing the method provided in the second aspect, electronic devices can collect behavioral data from phone applications, SMS applications, application installation managers, or browsers in real time. Since this data may be related to fraud, the electronic devices collect and report it to the server in a timely manner. The server then further determines whether the characteristics of the fraudulent data indicate a risk of being defrauded. If so, based on the user profile and the behavioral data indicating a risk of fraud, the server pushes corresponding anti-fraud information to the user. This timely and accurate push of anti-fraud information to users, which matches the user profile, can largely prevent users from falling into subsequent fraud and protect their personal and property safety.
[0008] In conjunction with the method provided in the second aspect, the server stores one or more of the following preset information: such as preset call initiator, preset SMS initiator, preset SMS keywords, preset application identifier or preset URL, preset number of times the call / SMS is blocked due to harassment (e.g., the number of times within 1 day is greater than or equal to 2 times); the fraud risk behavior data in the second behavior data is behavior data containing any of the preset information.
[0009] In this way, the server can determine whether a user's behavioral data poses a fraud risk based on a variety of preset information, namely, a variety of preset fraud detection rules.
[0010] In conjunction with the method provided in the second aspect, this preset information is determined by the server based on multiple fraud cases collected.
[0011] In this way, the server can analyze a large number of fraud cases and determine the corresponding preset information based on the fraud methods and content used in the cases, thus obtaining more accurate and comprehensive fraud detection rules.
[0012] In conjunction with the methods provided in the first or second aspect, the server stores various types of anti-fraud information; the type of anti-fraud information is determined according to the fraud method and the fraud content, the fraud method includes any one or more of the following: telephone fraud, SMS fraud, application fraud or web fraud, and the fraud content includes any one or more of the following: winning a prize, insurance, points redemption, loan, fundraising and credit investigation.
[0013] In this way, the server can store various types of anti-fraud information, and use this information to selectively filter out those that meet the corresponding criteria and send them to electronic devices.
[0014] In conjunction with the method provided in the first aspect, the electronic device outputs the first anti-fraud information in one or more of the following ways: SMS notification, telephone notification, or notification from the first application.
[0015] In conjunction with the method provided in the first aspect, the notification of the first application is displayed in any one or more of the following scenarios: on the desktop of the electronic device, in the user interface provided by the first application, in a drop-down notification bar, or in a pop-up window.
[0016] In this way, electronic devices can output anti-fraud information to users in various forms, ensuring that users can understand anti-fraud information in a timely manner and avoid falling into fraud scenarios.
[0017] In conjunction with the methods provided in the first or second aspect, the user's first behavioral data includes any one or more of the following: the user's registration information, application installation list, application usage duration, application usage frequency, call logs, SMS logs, browsing history, and location information.
[0018] In this way, the server can generate a user profile that is more consistent with the user's behavioral characteristics based on various types of user data, and then push anti-fraud information that is more consistent with the user's attributes to the user.
[0019] In conjunction with the methods provided in the first or second aspect, the user profile indicates one or more of the following characteristics of the user: interests, age, gender, and occupation.
[0020] In this way, the server can push anti-fraud information to users that is more in line with their interests, age, gender, or occupation.
[0021] In conjunction with the method provided in the first or second aspect, before the electronic device collects the user's first behavioral data, the method further includes: the electronic device running a first application, and the electronic device enabling the anti-fraud information push function provided by the first application. The first application may, for example, be a system manager installed on the electronic device.
[0022] In this way, electronic devices can determine whether to collect user behavior data based on the user's authorized actions, thus ensuring the user's right to know.
[0023] Thirdly, this application provides a method for pushing anti-fraud information, which is applied to electronic devices and includes:
[0024] The electronic device collects first behavioral data of the user using the electronic device; the electronic device sends the first behavioral data to the server, and the first behavioral data is used by the server to generate a user profile; the electronic device receives first anti-fraud information sent by the server, which is selected by the server from multiple anti-fraud information based on the user profile, and the first anti-fraud information includes: fraud cases, and / or, fraudster information; the electronic device outputs the first anti-fraud information.
[0025] After implementing the method provided in the third aspect, the electronic device can output anti-fraud information that matches the user profile, thereby achieving the purpose of accurate push notifications.
[0026] Fourthly, this application provides a method for pushing anti-fraud information. This method is applied to an electronic device and includes: the electronic device collecting first behavioral data of a user using the device; the electronic device sending the first behavioral data to a server, whereby the first behavioral data is used by the server to generate a user profile; the electronic device collecting second behavioral data of a user using the device, the second behavioral data including information from any one or more of the following sources: a phone application, an SMS application, an application installation manager, or a browser; the electronic device sending the second behavioral data to the server; the electronic device receiving second anti-fraud information sent by the server, the second anti-fraud information being selected by the server from multiple anti-fraud information sources based on the user profile and the sources and information of fraud-risk behavioral data in the second behavioral data, the second anti-fraud information including: fraud cases, and / or, fraudster information; and the electronic device outputting the second anti-fraud information.
[0027] After implementing the method provided in the fourth aspect, electronic devices can collect behavioral data from phone applications, SMS applications, application installation managers, or browsers in real time. Since this data may be related to fraud, the electronic devices collect and report it to the server in a timely manner. The server then further determines whether the characteristics of the fraudulent data indicate a risk of being defrauded. If so, based on the user profile and the behavioral data indicating a risk of fraud, the server pushes corresponding anti-fraud information to the user. This timely and accurate push of anti-fraud information to users, which matches the user profile, can largely prevent users from falling into subsequent fraud and protect their personal and property safety.
[0028] In conjunction with the method described in the fourth aspect, the electronic device outputs the first anti-fraud information in one or more of the following ways: SMS notification, telephone notification, or notification from the first application.
[0029] In conjunction with the method provided by the third aspect, the notification of the first application is displayed in any one or more of the following scenarios: on the desktop of the electronic device, in the user interface provided by the first application, in a drop-down notification bar, or in a pop-up window.
[0030] In this way, electronic devices can output anti-fraud information to users in various forms, ensuring that users can understand anti-fraud information in a timely manner and avoid falling into fraud scenarios.
[0031] In conjunction with the methods provided in the third or fourth aspect, the user's first behavioral data includes any one or more of the following: the user's registration information, application installation list, application usage duration, application usage frequency, call logs, SMS logs, browsing history, and location information.
[0032] In this way, electronic devices can collect various types of user behavior data, enabling servers to perform comprehensive analysis and generate user profiles that better match the user's attributes.
[0033] In conjunction with the method provided in the third or fourth aspect, before the electronic device collects the user's first behavioral data, the method further includes: the electronic device running a first application, and the electronic device enabling the anti-fraud information push function provided by the first application.
[0034] In this way, electronic devices can determine whether to collect user behavior data based on the user's authorized actions, thus ensuring the user's right to know.
[0035] Fifthly, this application provides a method for pushing anti-fraud information, which is applied to a server and includes:
[0036] The server receives first behavioral data sent by the electronic device; the server generates a user profile based on the first behavioral data; the server filters out first anti-fraud information from multiple anti-fraud information based on the user profile, the first anti-fraud information including: fraud cases, and / or, fraudster information; the server sends the first anti-fraud information to the electronic device, the first anti-fraud information is used for output by the electronic device.
[0037] After implementing the method provided in the fifth aspect, the server can send anti-fraud information that matches the user profile to electronic devices, thereby achieving the purpose of precise push notifications.
[0038] Sixthly, this application provides a method for pushing anti-fraud information. This method is applied to a server and includes: the server receiving first behavioral data sent by an electronic device; the server generating a user profile based on the first behavioral data; the server receiving second behavioral data sent by the electronic device, the second behavioral data including information from any one or more of the following sources: a phone application, an SMS application, an application installation manager, or a browser; the server determining second anti-fraud information based on the user profile and the source and information of the fraud-risk behavioral data in the second behavioral data, the second anti-fraud information including: fraud cases and / or information about the fraudsters; and the server sending the second anti-fraud information to the electronic device.
[0039] After implementing the method provided in the sixth aspect, electronic devices can collect behavioral data from phone applications, SMS applications, application installation managers, or browsers in real time. Since this data may be related to fraud, the electronic devices collect and report it to the server in a timely manner. The server then further determines whether the characteristics of the fraudulent data indicate a risk of being defrauded. If so, based on the user profile and the behavioral data indicating a risk of fraud, the server pushes corresponding anti-fraud information to the user. This timely and accurate push of anti-fraud information that matches the user profile can largely prevent users from falling into subsequent fraud and protect their personal and property safety.
[0040] In conjunction with the method described in the sixth aspect, the server stores one or more of the following preset information: for example, preset call initiator, preset SMS initiator, preset SMS keywords, preset application identifier or preset URL, preset number of times the call / SMS was blocked due to harassment; the fraud risk behavior data in the second behavior data is behavior data that includes any of the preset information.
[0041] In this way, the server can determine whether a user's behavioral data poses a fraud risk based on a variety of preset information, namely, a variety of preset fraud detection rules.
[0042] In conjunction with the method described in the sixth aspect, this preset information is determined by the server based on multiple fraud cases collected.
[0043] In this way, the server can analyze a large number of fraud cases and determine the corresponding preset information based on the fraud methods and content used in the cases, thus obtaining more accurate and comprehensive fraud detection rules.
[0044] In conjunction with the methods described in the fifth or sixth aspect, the server stores various types of anti-fraud information; the type of anti-fraud information is determined according to the fraud method and the fraud content, the fraud method includes any one or more of the following: telephone fraud, SMS fraud, application fraud or web fraud, and the fraud content includes any one or more of the following: winning a prize, insurance, points redemption, loan, fundraising and credit investigation.
[0045] In this way, the server can store various types of anti-fraud information, and use this information to selectively filter out those that meet the corresponding criteria and send them to electronic devices.
[0046] In a seventh aspect, this application provides a communication system comprising: an electronic device and a server; the electronic device is configured to perform the method described in any one of the third or fourth aspects, and the server is configured to perform the method described in any one of the fifth or sixth aspects.
[0047] Eighthly, this application provides an electronic device including one or more processors, one or more memories, and one or more displays; wherein the one or more memories are coupled to the one or more processors, and the one or more memories are used to store computer program code including computer instructions that, when the one or more processors execute the computer instructions, cause the electronic device to perform the method described in any one of the third or fourth aspects.
[0048] Ninthly, this application provides a server including one or more processors and one or more memories; wherein the one or more memories are coupled to the one or more processors, and the one or more memories are used to store computer program code including computer instructions that, when executed by the one or more processors, cause the server to perform the methods described in any one of the fifth or sixth aspects.
[0049] In a tenth aspect, this application provides a chip for use in a communication device, the chip including one or more processors, the processors being configured to invoke computer instructions to cause the communication device to perform the methods described in any one of the third, fourth, fifth, or sixth aspects.
[0050] In one aspect, this application provides a computer-readable storage medium including instructions that, when executed on a communication device, cause the communication device to perform the method described in any one of the third, fourth, fifth, or sixth aspects. Attached Figure Description
[0051] Figure 1A schematic diagram of a communication system provided in an embodiment of this application;
[0052] Figure 2 A schematic diagram of an electronic device hardware architecture provided in an embodiment of this application;
[0053] Figure 3 A schematic diagram of an electronic device software architecture provided in an embodiment of this application;
[0054] Figure 4 A schematic diagram of a server hardware architecture provided in an embodiment of this application;
[0055] Figure 5 A server software architecture diagram provided for an embodiment of this application;
[0056] Figure 6 A flowchart of an anti-fraud information push method provided in this application embodiment;
[0057] Figures 7A-7E A set of anti-fraud information push interface diagrams provided in the embodiments of this application;
[0058] Figure 8 This is a diagram illustrating an anti-fraud information push architecture provided in an embodiment of this application. Detailed Implementation
[0059] The technical solutions in the embodiments of this application will be clearly and thoroughly described below with reference to the accompanying drawings. In the description of the embodiments of this application, unless otherwise stated, " / " means "or," for example, A / B can mean A or B; the word "and / or" in the text is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, and B existing alone.
[0060] Hereinafter, the terms "first" and "second" are used for descriptive purposes only and should not be construed as implying or suggesting relative importance or implicitly indicating the number of indicated technical features. Thus, a feature defined as "first" or "second" may explicitly or implicitly include one or more of that feature, and in the description of the embodiments of this application, unless otherwise stated, "multiple" means two or more.
[0061] In this application, the reference to "embodiment" means that a specific feature, structure, or characteristic described in connection with an embodiment may be included in at least one embodiment of this application. The appearance of this phrase in various places throughout the specification does not necessarily refer to the same embodiment, nor is it a mutually exclusive, independent, or alternative embodiment. It will be explicitly and implicitly understood by those skilled in the art that the embodiments described in this application can be combined with other embodiments.
[0062] The term "user interface (UI)" used in the following embodiments of this application refers to the medium interface through which an application or operating system interacts and exchanges information with the user. It realizes the conversion between the internal form of information and the form that the user can accept. The user interface is source code written in a specific computer language such as Java or Extensible Markup Language (XML). The interface source code is parsed and rendered on the electronic device, ultimately presenting content that the user can recognize. A common form of user interface is the graphical user interface (GUI), which refers to a user interface related to computer operation displayed graphically. It can be visible interface elements such as text, icons, buttons, menus, tabs, text boxes, dialog boxes, status bars, navigation bars, and widgets displayed on the screen of an electronic device.
[0063] Nowadays, fraud cases are increasing. Fraudsters create various scams, such as insurance fraud, shopping fraud, prize fraud, phishing fraud, fundraising fraud, loan fraud, and bill fraud, through telephone, text message, website, and application, in order to defraud others of their property.
[0064] To raise public awareness of fraud prevention and prevent people from being scammed, this application provides a method, graphical interface, and related apparatus for pushing anti-fraud information. The method is applied to a communication system including electronic devices and a server. The method includes: the electronic device reporting collected user behavior data to the server; the server generating a corresponding user profile based on the user behavior data; and the electronic device also reporting collected user behavior data to the server for the server to determine whether there is a risk of fraud. If so, the server combines the user profile and the behavior data indicating a risk of fraud to determine the type of anti-fraud information, and sends the corresponding type of anti-fraud information from the anti-fraud information database to the electronic device, enabling the electronic device to push that type of anti-fraud information to the user.
[0065] After implementing the method provided in this application, the electronic device can collect user behavior data in real time and report it to the server in a timely manner. The server can then further determine whether the behavior data poses a risk of fraud. If so, it can determine the type of anti-fraud information based on the user profile and the type and content of the fraud corresponding to the behavior data, and push anti-fraud information of that type to the user. This timely and accurate push of anti-fraud information to users, which matches the user profile, can largely prevent users from falling into subsequent fraud and protect the personal and property safety of users.
[0066] In one feasible approach, the behavioral data used by the server to generate user profiles can be referred to as first behavioral data, while the behavioral data used by the server to determine whether there is a risk of fraud can be referred to as second behavioral data.
[0067] The first and second behavioral data can be data collected by the electronic device within the same time period, or data collected at different time periods. When the first and second behavioral data are collected at different time periods, for example, the electronic device can first send the first behavioral data to the server to generate a user profile. If the electronic device then collects the second behavioral data, it can be used by the server to update the previously generated user profile and also by the server to detect fraud risks.
[0068] Furthermore, the types of the first and second behavioral data may differ. For example, the first behavioral data may include one or more of the following: user registration information, application installation list, application usage duration, application usage frequency, call logs, SMS logs, browsing history, and location information, etc. The second behavioral data may be a further filter on top of the first behavioral data, containing only one or more of the following: application installation list, call logs, SMS logs, and browsing history. In other words, the second behavioral data includes information from any one or more of the following sources: phone applications, SMS applications, application installation managers, or browsers, because data from these sources is often associated with channels used for fraud.
[0069] In one feasible approach, electronic devices may push anti-fraud information to users in various forms, including but not limited to: sending the anti-fraud information through SMS, telephone, official accounts, notifications, etc., to remind users to be wary of fraud.
[0070] The following section details the communication system involved in the anti-fraud information push method provided in this application, as well as the hardware and software architecture of the electronic devices and servers included in the communication system.
[0071] refer to Figure 1 , Figure 1 An exemplary schematic diagram of the communication system provided in this application is shown.
[0072] like Figure 1 As shown, the communication system includes electronic devices and a server.
[0073] There may be one or more electronic devices, such as electronic device 101 and electronic device 102. The electronic devices may be equipped with... Or other portable terminal devices with different operating systems, such as mobile phones, tablets, desktop computers, laptops, handheld computers, notebook computers, ultra-mobile personal computers (UMPCs), netbooks, as well as cellular phones, personal digital assistants (PDAs), augmented reality (AR) devices, virtual reality (VR) devices, artificial intelligence (AI) devices, wearable devices, in-vehicle devices, smart home devices, and / or smart city devices, etc. When there are multiple electronic devices, the different electronic devices may have the same or different forms, and the embodiments described herein are not limited in this respect.
[0074] In this embodiment, the electronic device can provide users with anti-fraud information push services, specifically through a first application installed on the electronic device. This first application can be a system-level application, such as a system manager, or it can be another third-party application. System-level applications refer to those provided or developed by the manufacturer of the electronic device, while third-party applications refer to those provided or developed by a entity other than the manufacturer of the electronic device. The manufacturer of the electronic device can include the manufacturer, supplier, provider, or operator of the electronic device.
[0075] A server is a server that provides application services for the primary application in an electronic device. A server can be one or more servers provided by the developer or provider of the electronic device, or by the developer or provider of the primary application.
[0076] In this embodiment of the application, the server stores user profiles of one or more users, fraud detection rules, and an anti-fraud information database.
[0077] In this context, user profiling refers to the process by which a server analyzes and processes behavioral data reported by one or more electronic devices to create a specific user profile for each user. A user profile includes tags representing a user's age, gender, interests, and social attributes.
[0078] Fraud detection rules refer to a set of rules developed by developers based on collected fraud cases, extracting the characteristics of these cases, and pre-installed on the server. These rules are updated in real time as fraud cases are updated. For example, a fraud detection rule may include one or more preset pieces of information (also known as a blacklist), such as preset call initiators, preset SMS initiators, preset SMS keywords, preset application identifiers or preset URLs, and preset numbers of times a call / SMS has been blocked (e.g., more than or equal to 2 times within 1 day).
[0079] The anti-fraud information database stores various types of anti-fraud information. The types of anti-fraud information are defined based on factors such as user profiles, fraud types, and fraud content. Specifically, this anti-fraud information is obtained by the server from other devices or from fraud cases input during manual maintenance. The obtained fraud cases are then updated and categorized in real time to obtain anti-fraud information under different types. These other devices could be, for example, the national anti-fraud platform or other platforms specifically designed for collecting and organizing fraud cases.
[0080] In the communication system provided in this application, after receiving fraud-related data features reported by an electronic device, the server determines whether the fraud-related data features pose a fraud risk according to fraud detection rules. If so, it outputs the corresponding fraud type and fraud content, and, in conjunction with the user profile, retrieves the corresponding anti-fraud information from the anti-fraud information database to send to the electronic device, so that the electronic device pushes the anti-fraud information to the user.
[0081] refer to Figure 2 , Figure 2 A schematic diagram of the electronic device is shown.
[0082] like Figure 2As shown, the electronic device may include: a processor 110, an external memory interface 120, an internal memory 121, a universal serial bus (USB) interface 130, a charging management module 140, a power management module 141, a battery 142, antenna 1, antenna 2, a mobile communication module 150, a wireless communication module 160, an audio module 170, a speaker 170A, a receiver 170B, a microphone 170C, a headphone jack 170D, a sensor module 180, buttons 190, a motor 191, an indicator 192, a camera 193, a display screen 194, and a subscriber identification module (SIM) card interface 195, etc. The sensor module 180 may include a pressure sensor 180A and a touch sensor 180B. Alternatively, the sensor module may also include, but is not shown, a gyroscope sensor, a barometric pressure sensor, a magnetic sensor, an accelerometer, a distance sensor, a proximity sensor, a fingerprint sensor, a temperature sensor, an ambient light sensor, and a bone conduction sensor, etc.
[0083] It is understood that the structures illustrated in the embodiments of this application do not constitute a specific limitation on the electronic device. In other embodiments of this application, the electronic device may include more or fewer components than illustrated, or combine some components, or split some components, or have different component arrangements. The illustrated components may be implemented in hardware, software, or a combination of software and hardware.
[0084] Processor 110 may include one or more processing units, such as an application processor (AP), a modem processor, a graphics processing unit (GPU), an image signal processor (ISP), a controller, memory, a video codec, a digital signal processor (DSP), a baseband processor, and / or a neural network processing unit (NPU). These different processing units may be independent devices or integrated into one or more processors.
[0085] The controller can serve as the nerve center and command center of an electronic device. Based on the instruction opcode and timing signals, the controller generates operation control signals to control the fetching and execution of instructions.
[0086] The processor 110 may also include a memory for storing instructions and data. In some embodiments, the memory in the processor 110 is a cache memory. This memory can store instructions or data that the processor 110 has just used or that are used repeatedly. If the processor 110 needs to use the instruction or data again, it can retrieve it directly from the memory. This avoids repeated accesses, reduces the waiting time of the processor 110, and thus improves the efficiency of the system.
[0087] In this embodiment, the processor 110 can control the first application to collect user behavior data, and then report the collected user behavior data to the server for analysis to establish a corresponding user profile. The processor 110 can also control the first application to extract fraud-related data features from the user behavior data (i.e., obtain second behavior data from multiple types of behavior data). When fraud-related data features are extracted, they are also reported to the server for fraud detection. The server combines the detection results with the user profile to determine the type of anti-fraud information. Afterwards, when the electronic device receives the corresponding type of anti-fraud information from the server, the processor 110 also controls the display screen to output the anti-fraud information. For a detailed description of the specific functions of the processor 110 in the following method embodiments, please refer to the description below; details will not be elaborated here.
[0088] In some embodiments, the processor 110 may include one or more interfaces. Interfaces may include inter-integrated circuit (I2C) interfaces, inter-integrated circuit sound (I2S) interfaces, pulse code modulation (PCM) interfaces, universal asynchronous receiver / transmitter (UART) interfaces, mobile industry processor interfaces (MIPI), general-purpose input / output (GPIO) interfaces, subscriber identity module (SIM) interfaces, and / or universal serial bus (USB) interfaces, etc.
[0089] It is understood that the interface connection relationships between the modules illustrated in the embodiments of this application are merely illustrative and do not constitute a limitation on the structure of the electronic device. In other embodiments of this application, the electronic device may also employ different interface connection methods or combinations of multiple interface connection methods as described in the above embodiments.
[0090] The charging management module 140 receives charging input from a charger. The charger can be a wireless charger or a wired charger. In some wired charging embodiments, the charging management module 140 receives charging input from the wired charger via a USB interface 130. In some wireless charging embodiments, the charging management module 140 receives wireless charging input via the wireless charging coil of the electronic device. While charging the battery 142, the charging management module 140 can also supply power to the electronic device via the power management module 141.
[0091] The power management module 141 connects the battery 142, the charging management module 140, and the processor 110. The power management module 141 receives input from the battery 142 and / or the charging management module 140, providing power to the processor 110, internal memory 121, external memory, display screen 194, camera 193, and wireless communication module 160, etc. The power management module 141 can also monitor parameters such as battery capacity, battery cycle count, and battery health status (leakage current, impedance). In some other embodiments, the power management module 141 may also be located within the processor 110. In other embodiments, the power management module 141 and the charging management module 140 may be located in the same device.
[0092] The wireless communication function of electronic devices can be realized through antenna 1, antenna 2, mobile communication module 150, wireless communication module 160, modem processor and baseband processor, etc.
[0093] Antenna 1 and antenna 2 are used to transmit and receive electromagnetic wave signals. Each antenna in the electronic device can be used to cover one or more communication frequency bands. Different antennas can also be reused to improve antenna utilization. For example, antenna 1 can be reused as a diversity antenna for a wireless local area network. In some other embodiments, the antennas can be used in conjunction with a tuning switch.
[0094] The mobile communication module 150 can provide solutions for wireless communication applications including 2G / 3G / 4G / 5G in electronic devices. The mobile communication module 150 may include at least one filter, switch, power amplifier, low noise amplifier (LNA), etc. The mobile communication module 150 can receive electromagnetic waves via antenna 1, and perform filtering, amplification, and other processing on the received electromagnetic waves before transmitting them to a modem processor for demodulation. The mobile communication module 150 can also amplify the signal modulated by the modem processor and convert it into electromagnetic waves for radiation via antenna 1. In some embodiments, at least some functional modules of the mobile communication module 150 may be housed in processor 110. In some embodiments, at least some functional modules of the mobile communication module 150 and at least some modules of the processor 110 may be housed in the same device.
[0095] The modem processor may include a modulator and a demodulator. The modulator modulates the low-frequency baseband signal to be transmitted into a mid-to-high frequency signal. The demodulator demodulates the received electromagnetic wave signal into a low-frequency baseband signal. The demodulator then transmits the demodulated low-frequency baseband signal to the baseband processor for processing. After processing by the baseband processor, the low-frequency baseband signal is transmitted to the application processor. The application processor outputs sound signals through audio devices (not limited to speaker 170A, receiver 170B, etc.) or displays images or videos through the display screen 194. In some embodiments, the modem processor may be a separate device. In other embodiments, the modem processor may be independent of the processor 110 and may be housed in the same device as the mobile communication module 150 or other functional modules.
[0096] The wireless communication module 160 can provide solutions for wireless communication applications in electronic devices, including wireless local area networks (WLANs) (such as wireless fidelity (Wi-Fi) networks), Bluetooth (BT), global navigation satellite system (GNSS), frequency modulation (FM), near field communication (NFC), and infrared (IR) technologies. The wireless communication module 160 can be one or more devices integrating at least one communication processing module. The wireless communication module 160 receives electromagnetic waves via antenna 2, demodulates and filters the electromagnetic wave signals, and sends the processed signal to processor 110. The wireless communication module 160 can also receive signals to be transmitted from processor 110, frequency modulate and amplify them, and then convert them into electromagnetic waves for radiation via antenna 2.
[0097] In some embodiments, antenna 1 of the electronic device is coupled to mobile communication module 150, and antenna 2 is coupled to wireless communication module 160, enabling the electronic device to communicate with networks and other devices via wireless communication technology. The wireless communication technology may include Global System for Mobile Communications (GSM), General Packet Radio Service (GPRS), Code Division Multiple Access (CDMA), Wideband Code Division Multiple Access (WCDMA), Time-Division Code Division Multiple Access (TD-SCDMA), Long Term Evolution (LTE), BT, GNSS, WLAN, NFC, FM, and / or IR technologies. The GNSS may include Global Positioning System (GPS), Global Navigation Satellite System (GLONASS), BeiDou Navigation Satellite System (BDS), Quasi-Zenith Satellite System (QZSS), and / or Satellite Based Augmentation Systems (SBAS).
[0098] In this embodiment, the electronic device can establish a communication connection with the server through the mobile communication module 150 or the wireless communication module 160, and report the user behavior data collected by the electronic device to the server based on the communication connection, so that the server can build a corresponding user profile based on the user behavior data. The electronic device can also report the fraud-related data features extracted by the electronic device to the server based on the communication connection, so that the server can determine the corresponding fraud type and fraud content based on the fraud-related data features. In addition, the electronic device can also receive anti-fraud information sent by the server based on the communication connection.
[0099] Electronic devices implement display functions through a GPU, a display screen 194, and an application processor. The GPU is a microprocessor for image processing, connecting the display screen 194 and the application processor. The GPU is used to perform mathematical and geometric calculations and for graphics rendering. The processor 110 may include one or more GPUs, which execute program instructions to generate or modify display information.
[0100] Display screen 194 is used to display images, videos, etc. Display screen 194 includes a display panel. The display panel can be a liquid crystal display (LCD). The display panel can also be manufactured using organic light-emitting diodes (OLEDs), active-matrix organic light-emitting diodes (AMOLEDs), flexible light-emitting diodes (FLEDs), miniled, microLEDs, micro-OLEDs, quantum dot light-emitting diodes (QLEDs), etc. In some embodiments, the electronic device may include one or N displays 194, where N is a positive integer greater than 1.
[0101] In this embodiment, the display screen 194 of the electronic device can be used to display various user interfaces, including but not limited to a user interface for activating the anti-fraud function provided by the first application (see below for details). Figure 7A The first application provides a user interface for anti-fraud information (see details below). Figures 7B-7E (Description).
[0102] Electronic devices can achieve shooting functions through ISP, camera 193, video codec, GPU, display 194 and application processor.
[0103] The ISP (Image Signal Processor) is used to process data fed back from the camera 193. For example, when taking a picture, the shutter is opened, and light is transmitted through the lens to the camera's photosensitive element. The light signal is converted into an electrical signal, and the camera's photosensitive element transmits the electrical signal to the ISP for processing, transforming it into an image visible to the naked eye. The ISP can also perform algorithmic optimization of image noise, brightness, and skin tone. The ISP can also optimize parameters such as exposure and color temperature of the shooting scene. In some embodiments, the ISP can be set in the camera 193.
[0104] Camera 193 is used to capture still images or videos. An object is projected onto a photosensitive element by generating an optical image through the lens. The photosensitive element can be a charge-coupled device (CCD) or a complementary metal-oxide-semiconductor (CMOS) phototransistor. The photosensitive element converts the light signal into an electrical signal, which is then passed to an ISP for conversion into a digital image signal. The ISP outputs the digital image signal to a DSP for processing. The DSP converts the digital image signal into image signals in standard RGB, YUV, or other formats. In some embodiments, the electronic device may include one or N cameras 193, where N is a positive integer greater than 1.
[0105] Digital signal processors (DSPs) are used to process digital signals. Besides digital image signals, they can also process other digital signals. For example, when an electronic device is selecting a frequency, a DSP can perform a Fourier transform on the frequency energy.
[0106] Video codecs are used to compress or decompress digital video. Electronic devices can support one or more video codecs. This allows the electronic device to play or record video in various encoded formats, such as Moving Picture Experts Group (MPEG) 1, MPEG2, MPEG3, MPEG4, etc.
[0107] In this embodiment of the application, in scenarios such as screen sharing, remote control, and screen projection, electronic devices need to encode the content displayed on the current display screen 194 into a video stream using a video codec before sending it to other electronic devices.
[0108] An NPU (Neural Processing Unit) is a computational processor for neural networks (NNs). By borrowing the structure of biological neural networks, such as the transmission patterns between neurons in the human brain, it can rapidly process input information and continuously learn on its own. NPUs enable intelligent cognitive applications in electronic devices, such as image recognition, facial recognition, speech recognition, and text understanding.
[0109] Internal memory 121 may include one or more random access memory (RAM) and one or more non-volatile memory (NVM).
[0110] Random access memory can include static random-access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM, for example, fifth generation DDR SDRAM is generally called DDR5 SDRAM), etc.
[0111] Non-volatile memory can include disk storage devices and flash memory.
[0112] Flash memory can be classified according to its operating principle, including NOR FLASH, NAND FLASH, 3D NAND FLASH, etc.; according to the level of the storage cell, including single-level cell (SLC), multi-level cell (MLC), triple-level cell (TLC), quad-level cell (QLC), etc.; and according to the storage specification, including universal flash storage (UFS) and embedded multimedia card (eMMC), etc.
[0113] The random access memory can be directly read and written by the processor 110. It can be used to store executable programs (such as machine instructions) of the operating system or other running programs, as well as user and application data.
[0114] Non-volatile memory can also store executable programs and user and application data, and can be pre-loaded into random access memory for direct reading and writing by the processor 110.
[0115] The external memory interface 120 can be used to connect to external non-volatile memory, thereby expanding the storage capacity of the electronic device. The external non-volatile memory communicates with the processor 110 through the external memory interface 120 to perform data storage functions. For example, music, video, and other files can be stored in the external non-volatile memory.
[0116] The aforementioned memory is also used to store relevant algorithms or programs for extracting fraud-related data features. For specific implementation methods of extracting fraud-related data features by electronic devices, please refer to the description of S605 in the following method flow.
[0117] Electronic devices can implement audio functions such as music playback and recording through audio modules 170, speakers 170A, receivers 170B, microphones 170C, headphone jacks 170D, and application processors.
[0118] The audio module 170 is used to convert digital audio information into analog audio signals for output, and also to convert analog audio input into digital audio signals. The audio module 170 can also be used for encoding and decoding audio signals. In some embodiments, the audio module 170 may be located in the processor 110, or some functional modules of the audio module 170 may be located in the processor 110.
[0119] The speaker 170A, also known as a "loudspeaker," is used to convert audio electrical signals into sound signals. Electronic devices can listen to music or make hands-free calls through the speaker 170A.
[0120] The receiver 170B, also known as the "earpiece," is used to convert audio electrical signals into sound signals. When an electronic device answers a phone call or voice message, the receiver 170B can be brought close to the ear to hear the voice.
[0121] Microphone 170C, also known as a "microphone" or "voice transducer," is used to convert sound signals into electrical signals. When making a phone call or sending a voice message, the user can speak by bringing their mouth close to microphone 170C, inputting the sound signal into microphone 170C. Electronic devices can have at least one microphone 170C. In some embodiments, electronic devices can have two microphones 170C, which, in addition to collecting sound signals, can also perform noise reduction. In other embodiments, electronic devices can have three, four, or more microphones 170C, enabling sound signal collection, noise reduction, sound source identification, and directional recording, among other functions.
[0122] The 170D headphone jack is used to connect wired headphones. The 170D headphone jack can be a USB 130 interface or a 3.5mm Open Mobile Terminal Platform (OMTP) standard interface, a CTIA (Cellular Telecommunications Industry Association of the USA) standard interface.
[0123] In this embodiment of the application, after the electronic device enables the anti-fraud function, when the electronic device receives anti-fraud information sent by the server, it may display the prompt information on the display screen 194, or it may play the anti-fraud information through the speaker 170A / receiver 170B.
[0124] Pressure sensor 180A is used to sense pressure signals and convert them into electrical signals. In some embodiments, pressure sensor 180A can be disposed on display screen 194. There are many types of pressure sensors 180A, such as resistive pressure sensors, inductive pressure sensors, and capacitive pressure sensors. A capacitive pressure sensor may include at least two parallel plates with conductive material. When force is applied to pressure sensor 180A, the capacitance between the electrodes changes. The electronic device determines the pressure intensity based on the change in capacitance. When a touch operation is applied to display screen 194, the electronic device detects the intensity of the touch operation based on pressure sensor 180A. The electronic device can also calculate the touch position based on the detection signal from pressure sensor 180A. In some embodiments, touch operations applied to the same touch position but with different touch operation intensities can correspond to different operation commands. For example, when a touch operation with an intensity less than a first pressure threshold is applied to the SMS application icon, a command to view an SMS is executed. When a touch operation with an intensity greater than or equal to the first pressure threshold is applied to the SMS application icon, a command to create a new SMS is executed.
[0125] Touch sensor 180B, also known as a "touch panel," can be located on display screen 194. The touch sensor 180B and display screen 194 together form a touchscreen, also known as a "touchscreen." Touch sensor 180B detects touch operations applied to or near it. The touch sensor can transmit the detected touch operation to the application processor to determine the type of touch event. Visual output related to the touch operation can be provided through display screen 194. In other embodiments, touch sensor 180B may also be located on the surface of the electronic device, in a different position than display screen 194.
[0126] In this embodiment, pressure sensor A and touch sensor 180B can be used to collect data related to pressing or touching operations on the display screen 194, and report this data to processor 110. Processor 110 then determines the corresponding event based on this data to control the corresponding module of the electronic device to execute the corresponding event. For example, in the UI embodiment described above, processor 110 of the electronic device can detect a touch operation on the switch control corresponding to the anti-fraud information push function provided by the first application displayed on the display screen 194. In response to this operation, processor 110 can call the first application to collect user behavior data, and processor 110 will also control the display screen 194 to output a prompt message.
[0127] Buttons 190 include a power button, volume buttons, etc. Buttons 190 can be mechanical buttons or touch-sensitive buttons. The electronic device can receive button input and generate key signal inputs related to user settings and function control of the electronic device.
[0128] Motor 191 can generate vibration alerts. Motor 191 can be used for incoming call vibration alerts or for touch vibration feedback. For example, different vibration feedback effects can correspond to touch operations performed on different applications (such as taking photos, playing audio, etc.). Motor 191 can also correspond to different vibration feedback effects for touch operations performed on different areas of the display screen 194. Different application scenarios (such as time reminders, receiving messages, alarm clocks, games, etc.) can also correspond to different vibration feedback effects. The touch vibration feedback effect can also be customized.
[0129] Indicator 192 can be an indicator light, used to indicate charging status, power changes, or to indicate messages, missed calls, notifications, etc.
[0130] In this embodiment of the application, the prompt information output by the electronic device after detecting a rogue application includes, but is not limited to, displaying the prompt information on a screen. It can also be output by vibrating the motor 191 and flashing the indicator 192.
[0131] The SIM card interface 195 is used to connect a SIM card. The SIM card can be inserted into or removed from the SIM card interface 195 to achieve contact and separation with the electronic device. The electronic device can support one or N SIM card interfaces, where N is a positive integer greater than 1. The SIM card interface 195 can support Nano SIM cards, Micro SIM cards, SIM cards, etc. Multiple cards can be inserted into the same SIM card interface 195 simultaneously. The multiple cards can be of the same or different types. The SIM card interface 195 is also compatible with different types of SIM cards. The SIM card interface 195 is also compatible with external memory cards. The electronic device interacts with the network through the SIM card to achieve functions such as calls and data communication. In some embodiments, the electronic device uses an eSIM, i.e., an embedded SIM card. The eSIM card can be embedded in the electronic device and cannot be separated from it.
[0132] In the embodiments of this application, the electronic device can interact with the network through a SIM card to make and receive phone calls and send and receive text messages, including receiving fraudulent phone calls and text messages.
[0133] The software system of an electronic device can adopt a layered architecture, event-driven architecture, microkernel architecture, microservice architecture, or cloud architecture. This application uses the layered architecture Android system as an example to illustrate the software structure of an electronic device.
[0134] Figure 3 This is a software structure block diagram of an electronic device according to an embodiment of this application.
[0135] A layered architecture divides software into several layers, each with a clear role and function. Layers communicate with each other through software interfaces. In some embodiments, the Android system is divided into four layers, from top to bottom: the application layer, the application framework layer, the Android runtime and system libraries, and the kernel layer.
[0136] The application layer can include a series of application packages.
[0137] like Figure 3 As shown, the applications include, but are not limited to, the first application, phone, SMS, and other applications. The first application can be a system-level application such as a system manager, or it can be other third-party applications.
[0138] The first application includes a data collection module, a fraud-related data feature extraction module, and an anti-fraud information push module. These modules work together to provide users with anti-fraud information push services.
[0139] Specifically, the data acquisition module can obtain the required user behavior data from the corresponding application programming interface in the framework layer. Then, the data acquisition module reports the acquired behavior data to the data analysis module in the server, where it analyzes the data to create a corresponding user profile. Furthermore, the data acquisition module also sends the collected behavior data to the fraud-related data feature extraction module in the first application.
[0140] Specifically, the fraud-related data feature extraction module detects received behavioral data to determine if it contains fraud-related data features. If so, it extracts these features (equivalent to extracting a second set of behavioral data from multiple sets) and reports them to the fraud detection module on the server. The fraud detection module then uses pre-stored fraud detection rules to determine if these features pose a fraud risk. If so, it outputs the corresponding fraud type and content. This information is then used by the anti-fraud information decision module to determine, based on the fraud type, content, and user profile, what type of anti-fraud information to push to the anti-fraud information push module of the first application. Here, fraud-related data features refer to the data features corresponding to fraud channels, i.e., behavioral data from telephone applications, SMS applications, application installation managers, or browsers.
[0141] Specifically, the anti-fraud information push module is used to push specific categories of anti-fraud information received from the server's anti-fraud information database to users. This can be done through various push methods, including but not limited to SMS, telephone, official accounts, notifications, and other forms.
[0142] The first application can be a system-level application installed on the electronic device or a third application; this application does not limit this.
[0143] The application framework layer provides application programming interfaces (APIs) and a programming framework for applications in the application layer. The application framework layer includes some predefined functions.
[0144] like Figure 3 As shown, the application framework layer may include an activity manager, package manager, content provider, window manager, location service, notification manager, view system, resource manager, etc.
[0145] ActivityManager (AM) is a crucial system service in electronic devices. It is primarily responsible for starting, switching, and scheduling various system components, as well as managing and scheduling application processes, similar to the process management and scheduling modules in an operating system. AM can uniformly schedule Activities across all applications. From a system operation perspective, AM can be divided into client and server sides. The client runs within each application process, which implements specific Activities and Services. AM informs the system what Activities and Services are needed and calls system interfaces to complete the display. The server runs within the system service process and is the concrete implementation of the system-level activity management service. It responds to system call requests from clients and manages the lifecycle of each application process on the client side.
[0146] In this embodiment, the Application Management Module (AM) can be used to collect user behavior data and report this data to the data collection module in the first application. In this application, the user behavior data collected by the AM specifically includes, but is not limited to, the application's usage duration and the number of times the application is used.
[0147] Package Manager (PM) is an application used to manage the installations on electronic devices.
[0148] In this embodiment, the PM can also be used to collect user behavior data and report this data to the data collection module in the first application. In this application, the user behavior data collected by the PM includes, but is not limited to, an application installation list.
[0149] Content providers store and retrieve data, making that data accessible to applications. This data can include videos, images, audio, phone calls made and received, browsing history and bookmarks, phone books, etc.
[0150] In this embodiment, the content provider can also be used to collect user behavior data and report this data to the data collection module in the first application. In this application, the user behavior data collected by the content provider specifically includes, but is not limited to, call logs, SMS logs, and browsing history.
[0151] Location-based services (LBS) can be used to obtain the location information of electronic devices, provide users with map and navigation services, and also record the locations that users have visited.
[0152] In this embodiment, the content provider can also be used to collect user behavior data and report this data to the data collection module in the first application. In this application, the user behavior data collected by the LBS application specifically includes, but is not limited to, location records.
[0153] A window manager (WM) is used to manage window programs. A window manager can obtain the screen size, determine if a status bar is present, lock the screen, capture screenshots, and more.
[0154] A view system includes visual controls, such as controls for displaying text and controls for displaying images. View systems can be used to build applications. A display interface can consist of one or more views. For example, a display interface including a text notification icon could include views for displaying text and views for displaying images.
[0155] The file explorer provides applications with various resources, such as localized strings, icons, images, layout files, video files, and more.
[0156] The notification manager allows applications to display notifications in the status bar. These notifications can be used to deliver informational messages and can disappear automatically after a short pause, requiring no user interaction. For example, the notification manager can be used to notify users of completed downloads or message alerts. The notification manager can also display notifications as icons or scrolling text in the top status bar, such as notifications from background applications, or as dialog boxes on the screen. Examples include displaying text messages in the status bar, emitting sounds, vibrating electronic devices, and flashing indicator lights.
[0157] The Android Runtime consists of core libraries and a virtual machine. The Android runtime is responsible for the scheduling and management of the Android system.
[0158] The core library consists of two parts: one part is the functionalities that need to be called by the Java language, and the other part is the Android core library.
[0159] The application layer and application framework layer run in a virtual machine. The virtual machine executes the Java files of the application layer and application framework layer as binary files. The virtual machine is used to perform functions such as object lifecycle management, stack management, thread management, security and exception management, and garbage collection.
[0160] System libraries can include multiple functional modules. For example: surface manager, media libraries, 3D graphics processing libraries (e.g., OpenGL ES), 2D graphics engines (e.g., SGL), etc.
[0161] The Surface Manager is used to manage the display subsystem and provides the blending of 2D and 3D layers for multiple applications.
[0162] The media library supports playback and recording of various common audio and video formats, as well as still image files. It supports multiple audio and video encoding formats, such as MPEG4, H.264, MP3, AAC, AMR, JPG, and PNG.
[0163] The 3D graphics processing library is used to implement 3D graphics drawing, image rendering, compositing, and layer processing.
[0164] A 2D graphics engine is a graphics engine for 2D drawing.
[0165] The kernel layer is the layer between hardware and software. The kernel layer contains at least the display driver, camera driver, audio driver, and sensor driver.
[0166] refer to Figure 4 , Figure 4 An exemplary schematic diagram of the hardware architecture of a server provided in this application is shown.
[0167] like Figure 4 As shown, the server may include: one or more processors 201, memory 202, communication interface 203, transmitter 205, receiver 206, coupler 207, and antenna 208. These components can be connected via bus 204 or other means. Figure 4 Taking a connection via bus 204 as an example. Where:
[0168] The processor 201 can be used to read and execute computer-readable instructions. Specifically, the processor 201 can be used to call a program stored in the memory 202, such as the method provided in the embodiments of this application, which generates new detection rules based on user behavior data reported by the electronic device, or also includes management rules, reporting rules, etc., and then distributes these rules to the electronic device, and implements the program on the server side, and executes the instructions contained in the program.
[0169] In this embodiment, the processor 201 controls the server to perform the following steps: performing data analysis on user behavior data reported by the electronic device to generate a user profile for the corresponding user; employing fraud detection rules to detect fraud-related data features (also referred to as second behavioral data) reported by the electronic device to determine whether there is a fraud risk; if so, determining the fraud type and content corresponding to the fraud-related data feature; and determining the type of anti-fraud information based on the fraud type, fraud content, and the corresponding user profile, and sending the corresponding type of anti-fraud information to the electronic device. For more details, please refer to the following text. Figure 6The methods and procedures described herein will not be elaborated upon here.
[0170] The memory 202 is coupled to the processor 201 and is used to store various software programs and / or multiple sets of instructions. Specifically, the memory 202 may include high-speed random access memory and may also include non-volatile memory, such as one or more disk storage devices, flash memory devices, or other non-volatile solid-state storage devices.
[0171] The memory 202 can store an operating system (hereinafter referred to as the system), such as uCOS, VxWorks, RTLinux, and other embedded operating systems. The memory 202 can also store network communication programs, which can be used to communicate with electronic devices. The memory 202 can also store the most recently updated detection rules, or may include reporting rules and management rules.
[0172] In this embodiment of the application, the memory 202 stores an algorithm for analyzing user behavior data to generate user profiles, as well as fraud detection rules and an anti-fraud information database.
[0173] The user profile indicates one or more of the following characteristics of the user: interests, age, gender, occupation, and place of residence.
[0174] The fraud detection rules are determined by the server based on multiple collected fraud cases, and can be updated whenever new cases are collected. The fraud detection rules refer to the server storing one or more of the following preset information: preset call initiator, preset SMS initiator, preset SMS keywords, preset application identifier or preset URL, and preset number of times the call / SMS was blocked due to harassment. These fraud detection rules are used by the server to determine whether the fraudulent data characteristics reported by electronic devices (i.e., the second behavioral data) pose a fraud risk.
[0175] For more details on fraud detection rules and the specific functions of the anti-fraud database, please refer to the following text. Figure 6 The methods and procedures described herein will not be elaborated upon here.
[0176] The communication interface 203 can be used for communication between the server and other communication devices, such as electronic devices. Specifically, the communication interface 203 can be a 3G communication interface, a Long Term Evolution (LTE) (4G) communication interface, a 5G communication interface, a WLAN communication interface, a WAN communication interface, etc. Not limited to wireless communication interfaces, the server can also be configured with a wired communication interface 203 to support wired communication; for example, the link between the server and electronic devices can be a wired communication connection.
[0177] In some embodiments of this application, transmitter 205 and receiver 206 can be considered as a wireless modem. Transmitter 205 can be used to transmit signals output by processor 201. Receiver 206 can be used to receive signals. In a server, the number of transmitters 205 and receivers 206 can be one or more. Antenna 208 can be used to convert electromagnetic energy in a transmission line into electromagnetic waves in free space, or to convert electromagnetic waves in free space into electromagnetic energy in a transmission line. Coupler 207 can be used to split mobile communication signals into multiple paths and distribute them to multiple receivers 206. Understandably, the antenna 208 of the network device can be implemented as a massive MIMO (Massively Multi-Size Antenna Array).
[0178] refer to Figure 5 , Figure 5 An exemplary schematic diagram of the software architecture of a server provided in this application is shown.
[0179] like Figure 5 As shown, the server includes, but is not limited to: a data analysis module, a fraud detection module, an anti-fraud information decision-making module, and an anti-fraud information database.
[0180] The system comprises several modules: a data analysis module receives user behavior data reported by electronic devices and generates corresponding user profiles based on this data; a fraud detection module receives fraud-related data features reported by electronic devices and determines whether a fraud risk exists based on these features; if so, it sends the fraud type and content to the anti-fraud information decision module; the anti-fraud information decision module, upon receiving the fraud type and content, determines the type of anti-fraud information based on the corresponding user profile; and an anti-fraud information database sends the corresponding type of anti-fraud information to the electronic devices based on the anti-fraud information type determined by the anti-fraud information decision module.
[0181] Understandable Figure 5 The software architecture of the server shown is merely an example. The server may include more modules, and the above-mentioned multiple modules may be combined into fewer modules. This application embodiment does not limit this.
[0182] Based on the communication system involved in this application and the hardware and software architecture of the electronic devices and servers included in the communication system, the anti-fraud information push method provided by this application will be described in detail below.
[0183] refer to Figure 6 , Figure 6 This application provides an exemplary method for pushing anti-fraud information, which specifically includes the following steps:
[0184] S601, Electronic devices enable anti-fraud information push function.
[0185] Specifically, electronic devices may have the anti-fraud information push function enabled by default, or the anti-fraud information push function may be enabled based on user operation.
[0186] In one possible implementation, the anti-fraud information push function can be provided by a system-level application, a third-party application, or a system service component. Here, we will only take the first application mentioned above as an example to introduce the anti-fraud information push function.
[0187] When an electronic device enables the anti-fraud information push function based on user input, the first application installed on the device provides controls for enabling / disabling the anti-fraud information push function. Next, we will combine... Figure 7A Here is a schematic diagram of the interface for enabling the anti-fraud information push function.
[0188] like Figure 7A As shown, the electronic device displays an interface provided by the first application. This interface displays an anti-fraud push option 711A, and a control 711B corresponding to option 711A for enabling the anti-fraud information push function.
[0189] When the electronic device detects an opening operation applied to the control 711B, the state of the control 711B will switch from the closed state to the open state, that is, the anti-fraud information push function will be enabled.
[0190] Optionally, during the process of the electronic device activating the anti-fraud information push function based on user operation, for example, after the electronic device receives an activation operation on control 711B, and before the state of control 711B switches from the closed state to the open state, the electronic device can also output a prompt message informing the user that after activating the anti-fraud information push function, the first application will obtain the user's behavioral data for building a user profile and extracting anti-fraud data features, etc. Only after receiving no user operation to refuse to activate the anti-fraud information push function will the electronic device switch the state of control 711B from the closed state to the open state, that is, activate the anti-fraud information push function. This embodiment of the application does not limit the output method of this prompt message; for example, it can be in the form of a pop-up window.
[0191] Understandable, Figure 7A This example merely illustrates one way to enable the anti-fraud information push function. In addition, the anti-fraud information push function can be enabled in other ways, such as through the corresponding control provided in the drop-down notification bar of the electronic device, or through the corresponding control displayed in the settings application, or by inputting voice commands, etc. This application embodiment does not limit this.
[0192] S602, Electronic devices collect user behavior data.
[0193] Specifically, after the anti-fraud information push function is enabled on the electronic device, the electronic device has the right to collect user behavior data. The collection of user behavior data by the electronic device is continuous, that is, the electronic device will collect user data periodically. In other words, after the anti-fraud information push function is enabled, the electronic device will continuously collect user behavior data in subsequent steps S603-S610.
[0194] In one possible implementation, after the electronic device enables the anti-fraud information push function provided by the first application, the corresponding module in the first application (e.g., the data acquisition module) can register an event to detect user behavior data with the corresponding module in the framework layer. After registering the event to detect user behavior data, the user's behavior data can be obtained through the corresponding module in the framework layer.
[0195] In this embodiment of the application, the first application may register events for detecting user behavior data in the activity manager, package manager, content provider, and LBS in the framework layer, respectively.
[0196] The detection events registered in the Activity Manager are mainly used to obtain user behavior data, including but not limited to: application usage duration, application usage frequency, and other types of data.
[0197] The detection events registered in the package manager are mainly used to obtain user behavior data, including but not limited to: application installation list and other types of data.
[0198] The detection events registered with the content provider are primarily used to acquire user behavior data, including but not limited to: call logs, SMS logs, and browsing history. Call logs may include phone numbers or call content; SMS logs may include phone numbers or call content; browsing history may include URLs or content corresponding to those URLs.
[0199] Among them, the events registered in LBS to detect user behavior data are mainly used to obtain user behavior data including but not limited to: location records.
[0200] It is understood that the embodiments of this application do not impose specific limitations on the user behavior data collected by the electronic device. In other embodiments of this application, the first application installed on the electronic device may also obtain other types of user behavior data through other modules of the framework layer, such as the notification manager and the resource manager.
[0201] S603, electronic devices report user behavior data to the server.
[0202] Specifically, after electronic devices collect user behavior data, it can be directly reported to the server or cached first, and then reported to the server periodically. This period could be, for example, reporting to the server at a fixed time every day. The behavior data used by the server to generate user profiles can also be called primary behavior data. The specific types of primary behavior data have been explained in the previous text and will not be elaborated upon here.
[0203] In one possible implementation, the behavior data acquisition module in the electronic device can report the acquired behavior data to the corresponding module in the server (such as the data analysis module described above).
[0204] In one example, the specifications of the user behavior data reported by the electronic device are as follows: it includes a user identifier and the behavior data of the user corresponding to the user identifier.
[0205] S604, the server generates user profiles based on user behavior data.
[0206] Specifically, after receiving user behavior data reported by electronic devices, the server can generate a corresponding user profile based on the user behavior data. In this embodiment, the behavior data used by the server to generate the user profile can also be referred to as first behavior data.
[0207] In one possible implementation, after receiving user behavior data reported by the electronic device's behavior data acquisition module, the data analysis module in the server can generate a user profile through methods such as data preprocessing and user tag modeling. Data preprocessing includes normalizing and removing missing values from the user behavior data, and user tag modeling can be implemented using deep neural networks.
[0208] User profiles are tags that represent a user's age, gender, interests, and social attributes. Servers can create and store user profiles for different users based on behavioral data reported from multiple electronic devices.
[0209] Optionally, the server can also update previously generated user profiles using behavioral data pairs uploaded by electronic devices at different times.
[0210] S605, electronic devices extract fraud-related data features from user behavior data.
[0211] Specifically, after the electronic device executes S602, it further detects the user behavior data collected by the data acquisition module according to the fraud-related data feature extraction rules, determining whether it contains fraud-related data features. If so, the fraud-related data features are extracted. In other words, fraud-related data features refer to the second type of behavior data that the electronic device filters from various collected behavior data to identify those consistent with fraudulent channels. This data originates from one or more of the following: telephone applications, SMS applications, application installation managers, or browsers. Both the second type of behavior data and the aforementioned first type of behavior data are obtained by the electronic device during continuous behavior data collection. They can be a batch of behavior data collected within the same time period or different batches of behavior data collected within different time periods; this embodiment does not impose such limitations.
[0212] In one specific implementation, the fraud data feature extraction module in the first application of the electronic device will use fraud data feature extraction rules to detect the user behavior data collected by the data acquisition module, determine whether it contains fraud data features, and if so, extract the fraud data features.
[0213] Among them, the rules for extracting fraud-related data features refer to those determined by developers based on the methods of fraud in current fraud cases. Specifically, most current fraud cases are committed through methods such as phone calls, text messages, websites, and applications. Users' actions such as making and receiving phone calls, sending and receiving text messages, browsing web pages, and installing applications may all be involved in fraud. Therefore, this application can use data features such as phone records, text message records, browsing history, and application installation history as fraud-related data features.
[0214] The above-mentioned S605 can occur after S604, or it can also occur in any step between S602 and S604. This application embodiment does not limit this.
[0215] S606, Electronic devices report fraud-related data characteristics to the server.
[0216] Specifically, after electronic devices extract fraud-related data features, these features may also be extracted from behavioral data such as making and receiving phone calls, sending and receiving text messages, browsing web pages, and installing applications during normal work and life. Therefore, it is not possible to directly determine whether the fraud-related data features indicate that the user is actually being scammed. Therefore, electronic devices also need to report the extracted fraud-related data features to the server for further accurate judgment.
[0217] In one specific implementation, the fraud-related data feature extraction module in the first application of the electronic device reports the fraud-related data features to the fraud detection module in the server.
[0218] When an electronic device reports the extraction of fraud-related data features, it also carries the user identifier to which the fraud-related data features belong.
[0219] S607: The server detects whether the characteristics of fraudulent data indicate a risk of fraud. If so, it determines the corresponding type and content of the fraud.
[0220] Specifically, the server pre-stores fraud detection rules. The server can use these rules to detect fraudulent data features to determine if there is a risk of fraud. If so, it identifies the corresponding fraud type and content. The fraudulent data features used by the server to detect fraud risk can also be called secondary behavioral data. The specific types of secondary behavioral data have been explained previously and will not be elaborated upon here.
[0221] In one specific implementation, fraud detection rules are stored in a fraud detection module on the server, which detects fraudulent data features. These fraud detection rules are determined by the server through collecting and analyzing a large number of fraud cases, and are updated in real time as fraud cases are updated.
[0222] In one feasible approach, fraud detection rules may include one or more blacklists, such as blacklists corresponding to phone numbers, blacklists corresponding to SMS keywords, blacklists corresponding to applications, blacklists corresponding to websites, etc.
[0223] After receiving fraud-related data features, the server determines whether these features match the blacklist in the fraud detection rules. If so, it indicates that the fraud-related data features pose a fraud risk. Therefore, the server's fraud detection module will also analyze the fraud type and content corresponding to the fraud-related data features.
[0224] Fraud types can include, but are not limited to: telephone fraud, SMS fraud, app fraud, and website fraud. Fraudulent content can include, for example, prize winnings, insurance scams, points redemption scams, loan scams, fundraising scams, and credit investigation scams. The classification of fraud types and content depends on changes in fraud cases. When new fraud cases emerge and change—that is, when the methods and content of the fraud change—the corresponding server will update the fraud types and content accordingly.
[0225] In other words, after determining that the second behavioral data has a fraud risk, the server can then determine the fraud type and fraud content of the fraud risky behavioral data. The fraud type corresponds to the source of the fraud risky behavioral data in the second behavioral data (telephone application, SMS application, application installer, or browser), and the fraud content corresponds to the information of the fraud risky behavioral data in the second behavioral data.
[0226] S608, the server determines the type of anti-fraud information based on the fraud type and content corresponding to the fraud data characteristics and in combination with the user profile.
[0227] Specifically, the server pre-stores decision rules that combine user profiles, fraud types, and fraud content to determine the type of anti-fraud information. The server can use these decision rules to determine the appropriate type of anti-fraud information based on user profiles, fraud types, and fraud content. In other words, the server can determine the type of anti-fraud information based on user profiles and the source and information of behavioral data with fraud risk in the second behavioral data.
[0228] In one specific implementation, the aforementioned decision rules are specifically stored in the anti-fraud information decision module on the server. In S606, the fraud detection module on the server receives fraudulent data features carrying the corresponding user identifier. After the fraud detection module determines the fraud type and content corresponding to the fraudulent data, the anti-fraud information decision module can obtain the user profile corresponding to the user identifier carried by the fraudulent data feature from one or more user profiles previously generated by the server. Then, combined with the fraud type and fraud content, it determines the type of anti-fraud information.
[0229] To illustrate a specific example of anti-fraud information, if the user profile indicates that the user's interests are electronic products, their social attribute is a student at a school in Shenzhen, the fraud type is telephone fraud, and the fraud content is a lottery to win a tablet computer, then the type of anti-fraud information determined by the server is a fraud case (also known as a risk case) that occurred in Shenzhen. This fraud case involves telephone fraud, falsely claiming that a tablet computer can be won through a lottery.
[0230] To illustrate another specific type of anti-fraud information, if the user profile indicates that the user's interests are health and wellness, their social attribute is a retiree in Beijing, the fraud type is web-based fraud, and the fraud content involves paying membership fees to join a health and wellness association, then the type of anti-fraud information determined by the server is a fraud case (also known as a risk case) that occurred in Beijing. This fraud case uses web-based fraud, falsely claiming that paying fees can join a health and wellness association. Alternatively, the type of anti-fraud information could be information about all health and wellness associations in Beijing, including their names and locations.
[0231] The above-mentioned types of anti-fraud information are merely examples. When the user profile is different, and the anti-fraud type or anti-fraud content is also different, the corresponding types of anti-fraud information will be different. The anti-fraud information provided in this application may specifically be fraud cases and / or information about the fraudsters. This application will not provide examples of each of these.
[0232] S609, the server sends the corresponding type of anti-fraud information to electronic devices.
[0233] Specifically, after the anti-fraud information decision module in the server determines the type of anti-fraud information, it controls the anti-fraud information database to retrieve the corresponding type of anti-fraud information (which can also be called the second anti-fraud information) from the various types of anti-fraud information stored in advance, and sends it to the anti-fraud information push module in the first application in the electronic device.
[0234] Optionally, the anti-fraud information database may contain multiple pieces of each type of anti-fraud information. The anti-fraud information decision module can control the anti-fraud information database to only retrieve the latest anti-fraud information of the corresponding type.
[0235] S610, the electronic device outputs anti-fraud information of the corresponding type.
[0236] Specifically, after the anti-fraud push module of the first application in the electronic device receives the anti-fraud information sent by the anti-fraud information database in the server, it can output it in any one or more of the following ways to remind users to avoid being scammed: SMS, telephone, notification from official account or the first application, pop-up window, etc.
[0237] refer to Figures 7B-7E , Figures 7B-7E The following are schematic diagrams of the interfaces for outputting anti-fraud information in several different ways.
[0238] like Figure 7B As shown, Figure 7B This is a schematic diagram of an interface that outputs anti-fraud information in the form of a notification. The interface is the pull-down notification bar of the electronic device. The notification bar 712 is the notification of anti-fraud information output by the first application. Users can click on the notification bar 712 to jump to the details page of the anti-fraud information, or users can click on the "Don't remind me again" control to turn off the anti-fraud information push function provided by this application.
[0239] like Figure 7C As shown, Figure 7C This is a screenshot of the anti-fraud information interface provided in the first application after it is opened. This interface includes a "Risk Cases" section (713), where users can click the view control to jump to the details page for viewing the risk case.
[0240] like Figure 7D As shown, Figure 7D This is a screenshot of the interface displaying anti-fraud information during the installation of a new application (fraudulent application). The interface includes pop-up window 714, which allows users to click the "View Shared Cases" control to jump to a details page showcasing risk cases.
[0241] like Figure 7E As shown, Figure 7EThis is a details page for viewing risk cases. Specifically, this details page may be provided by the first application mentioned above, and it may include one or more risk cases.
[0242] The above Figures 7B-7E These are just a few examples of ways to push anti-fraud information. In addition, electronic devices can also push anti-fraud information through telephone, SMS, public account, voice broadcast, etc. This application embodiment does not limit this.
[0243] Optionally, steps S605-S607 in the above method flow are optional. This means the server can determine the type of anti-fraud information based solely on the user profile and send that type of anti-fraud information (also referred to as the first anti-fraud information) to the electronic device, without considering the fraud type or content corresponding to the fraudulent behavior data reported by the electronic device. Furthermore, the server can periodically send anti-fraud information corresponding to the user profile to the electronic device, or the server can trigger the sending of anti-fraud information corresponding to the user profile to the electronic device after updating the anti-fraud case database, or the server can send anti-fraud information corresponding to the user profile to the electronic device after receiving a request from the electronic device. Here, the request sent by the electronic device refers to the electronic device receiving an operation from the user to actively view anti-fraud information; specifically, this could be opening the first application and clicking on... Figure 7C The operation of risk case section 713 corresponding to the Risk Science Popularization Center shown.
[0244] In addition, the anti-fraud information push method provided in this application may also include: electronic devices may also give users corresponding points based on the number of times, time or feedback of users viewing anti-fraud cases, and these points can be redeemed for goods in the mall provided by the first application.
[0245] Based on the anti-fraud information push methods introduced above, the following will combine... Figure 8 This application provides a detailed diagram of an anti-fraud information push architecture.
[0246] like Figure 8 As shown, this anti-fraud information push architecture consists of three parts: behavioral data collection, anti-fraud information push, and anti-fraud information decision-making. Behavioral data collection and anti-fraud information push are executed on the electronic device side, while anti-fraud information decision-making is executed on the server. The detailed execution process is as follows:
[0247] 1. Behavioral data collection is performed by applications or service components installed in the electronic device that provide anti-fraud information push functionality, such as the first application mentioned above. Specifically, the behavioral data collection module in the first application can collect behavioral data through corresponding modules in the application framework layer of the electronic device.
[0248] The modules used for collecting behavioral data include, but are not limited to: Activity Manager, Package Manager, Content Provider, and LBS. Behavioral data includes, but is not limited to: application usage duration, application usage count, application installation list, call logs, SMS logs, browsing history, and location records. For details on the specific implementation of electronic devices collecting application behavioral data, and the types of behavioral data, please refer to the descriptions of steps S601-S602 in the preceding method flow; they will not be elaborated upon here.
[0249] 2. The anti-fraud information decision-making module is executed by the server. Specifically, the anti-fraud decision-making module in the server determines the corresponding type of anti-fraud information based on the type of fraud, the content of the fraud, and the user profile, and controls the anti-fraud information database to send the anti-fraud information of this type to the anti-fraud information database of the electronic device.
[0250] The fraud type and content are determined by the server's fraud detection module after detecting fraud-related data features reported by the electronic device. The fraud-related data features are extracted from behavioral data collected by the behavioral data acquisition module in the electronic device's first application and sent to the server's fraud detection module.
[0251] The user profile is generated by the server's data analysis module after analyzing the data reported by the behavioral data collection module in the electronic device.
[0252] For details on the specific implementation of the server generating user profiles, obtaining fraud types and fraud content, and determining the corresponding type of anti-fraud information by combining user profiles, fraud types and fraud content, please refer to the description of steps S603-S608 in the above method flow, which will not be elaborated here.
[0253] 3. Anti-fraud information push is performed by an application or service component installed in the electronic device that provides anti-fraud information push functionality, such as the first application mentioned above. Specifically, the anti-fraud information push module in the first application can receive anti-fraud information of the corresponding type sent by the server's anti-fraud information database, and then output the anti-fraud information of that type through one or more methods to remind users to avoid falling into this type of scam.
[0254] For details on the specific implementation of pushing anti-fraud information to electronic devices, please refer to the description of steps S609-S610 in the above method flow, which will not be repeated here.
[0255] It should be understood that the steps in the above-described method embodiments provided in this application can be implemented by integrated logic circuits in the processor hardware or by instructions in software form. The method steps disclosed in the embodiments of this application can be directly implemented by a hardware processor, or implemented by a combination of hardware and software modules in the processor.
[0256] This application also provides an electronic device that may include a memory and a processor. The memory may be used to store a computer program; the processor may be used to invoke the computer program in the memory to cause the electronic device to perform the method in any of the above embodiments.
[0257] This application also provides a chip system including at least one processor for implementing the functions involved in the methods performed by the electronic device in any of the above embodiments.
[0258] In one possible design, the chip system also includes a memory for storing program instructions and data, which may be located within or outside the processor.
[0259] The chip system can consist of chips or include chips and other discrete components.
[0260] Optionally, the chip system may contain one or more processors. These processors can be implemented in hardware or software. When implemented in hardware, the processor can be a logic circuit, an integrated circuit, etc. When implemented in software, the processor can be a general-purpose processor, implemented by reading software code stored in memory.
[0261] Optionally, the chip system may contain one or more memories. The memory may be integrated with the processor or disposed separately from it; this application embodiment does not limit this. For example, the memory may be a non-transient processor, such as a read-only memory (ROM), which may be integrated with the processor on the same chip or disposed separately on different chips. This application embodiment does not specifically limit the type of memory or the arrangement of the memory and processor.
[0262] For example, the chip system may be a field programmable gate array (FPGA), an application specific integrated circuit (ASIC), a system on chip (SoC), a central processor unit (CPU), a network processor (NP), a digital signal processor (DSP), a micro controller unit (MCU), a programmable logic device (PLD), or other integrated chips.
[0263] This application also provides a computer program product comprising: a computer program (also referred to as code or instructions) that, when run, causes a computer to perform the method executed by the electronic device in any of the above embodiments.
[0264] This application also provides a computer-readable storage medium storing a computer program (also referred to as code or instructions). When the computer program is run, it causes the computer to perform the method executed by the electronic device in any of the above embodiments.
[0265] The various embodiments of this application can be combined arbitrarily to achieve different technical effects.
[0266] In the above embodiments, implementation can be achieved, in whole or in part, through software, hardware, firmware, or any combination thereof. When implemented in software, it can be implemented, in whole or in part, as a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the processes or functions described in this application are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired (e.g., coaxial cable, fiber optic, digital subscriber line) or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium accessible to a computer or a data storage device such as a server or data center that integrates one or more available media. The available medium can be a magnetic medium (e.g., floppy disk, hard disk, magnetic tape), an optical medium (e.g., DVD), or a semiconductor medium (e.g., solid-state drive).
[0267] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. This program can be stored in a computer-readable storage medium, and when executed, it can include the processes described in the above method embodiments. The aforementioned storage medium includes various media capable of storing program code, such as ROM or random access memory (RAM), magnetic disks, or optical disks.
[0268] In summary, the above description is merely an embodiment of the technical solution of the present invention and is not intended to limit the scope of protection of the present invention. Any modifications, equivalent substitutions, improvements, etc., made according to the disclosure of the present invention should be included within the scope of protection of the present invention.
Claims
1. A method for pushing anti-fraud information, characterized in that, The method is applied to a communication system including electronic devices and servers, and the method includes: The electronic device collects first behavioral data of the user's use of the electronic device, which includes one or more of the following: user registration information, application installation list, application usage duration, application usage frequency, call logs, SMS logs, browsing history, and location information; The electronic device sends the first behavioral data to the server; The server generates a user profile based on the first behavioral data; The electronic device extracts second behavioral data that matches the source of fraud from the first behavioral data. The second behavioral data includes information from any one or more of the following sources: phone application, SMS application, application installation manager, or browser. The electronic device sends the second behavioral data to the server; The second server determines that the second behavioral data has a fraud risk based on preset information, and determines the fraud type and fraud content corresponding to the second behavioral data; the server determines the second anti-fraud information from multiple anti-fraud information based on the user profile, the fraud type and fraud content corresponding to the second behavioral data; The server sends the second anti-fraud information to the electronic device, the second anti-fraud information including: fraud cases, and / or, fraudster information; The electronic device outputs the second anti-fraud information.
2. The method according to claim 1, characterized in that, The preset information includes any one or more of the following: preset call initiator, preset SMS initiator, preset SMS keywords, preset application identifier or preset URL, and preset number of times the call / SMS has been blocked due to harassment.
3. The method according to claim 1 or 2, characterized in that, The preset information is determined by the server based on multiple fraud cases collected.
4. The method according to claim 1, characterized in that, The server stores various types of anti-fraud information. The type of anti-fraud information is determined according to the fraud method and the fraud content. The fraud method includes any one or more of the following: telephone fraud, SMS fraud, application fraud, or web page fraud. The fraud content includes any one or more of the following: winning a prize, insurance, points redemption, loan, fundraising, and credit investigation.
5. The method according to claim 1, characterized in that, Before the electronic device collects the user's first behavioral data, the method further includes: The electronic device runs a first application and enables the anti-fraud information push function provided by the first application.
6. The method according to claim 1, characterized in that, The user profile indicates one or more of the following characteristics of the user: interests, age, gender, occupation, and place of residence.
7. A method for pushing anti-fraud information, characterized in that, The method is applied to an electronic device, and the method includes: The electronic device collects first behavioral data of the user's use of the electronic device, which includes one or more of the following: user registration information, application installation list, application usage duration, application usage frequency, call logs, SMS logs, browsing history, and location information; The electronic device sends the first behavioral data to the server, and the first behavioral data is used by the server to generate a user profile. The electronic device extracts second behavioral data that matches the source of fraud from the first behavioral data. The second behavioral data includes information from any one or more of the following sources: phone application, SMS application, application installation manager, or browser. The electronic device sends the second behavioral data to the server; The electronic device receives second anti-fraud information sent by the server. The second anti-fraud information is selected by the server from multiple anti-fraud information based on the user profile and the fraud type and fraud content corresponding to the second behavioral data. The fraud type and fraud content corresponding to the second behavioral data are determined by the second server after determining that the second behavioral data has a fraud risk based on preset information. The second anti-fraud information includes: fraud cases, and / or, fraudster information. The electronic device outputs the second anti-fraud information.
8. The method according to claim 7, characterized in that, The preset information includes any one or more of the following: preset call initiator, preset SMS initiator, preset SMS keywords, preset application identifier or preset URL, and preset number of times the call / SMS has been blocked due to harassment.
9. The method according to claim 7 or 8, characterized in that, The electronic device outputs the second anti-fraud information in one or more of the following ways: SMS notification, telephone notification, or notification from the first application.
10. The method according to claim 9, characterized in that, The notification from the first application is displayed in any one or more of the following scenarios: on the desktop of the electronic device, in the user interface provided by the first application, in the drop-down notification bar, or in a pop-up window.
11. The method according to claim 7, characterized in that, Before the electronic device collects the user's first behavioral data, the method further includes: The electronic device runs a first application and enables the anti-fraud information push function provided by the first application.
12. The method according to claim 7, characterized in that, The user profile indicates one or more of the following characteristics of the user: interests, age, gender, occupation, and place of residence.
13. A communication system, characterized in that, The communication system includes: an electronic device and a server; the electronic device is used to perform the method as described in any one of claims 7-12.
14. An electronic device, characterized in that, The electronic device includes one or more processors, one or more memories, and one or more displays; wherein the one or more memories are coupled to the one or more processors, and the one or more memories are used to store computer program code, the computer program code including computer instructions, which, when executed by the one or more processors, cause the electronic device to perform the method as described in any one of claims 7-12.
15. A chip used in a communication device, characterized in that, The chip includes one or more processors, the processors being configured to invoke computer instructions to cause the communication device to perform the method as described in any one of claims 7-12.
16. A computer-readable storage medium comprising instructions, characterized in that, When the instruction is executed on the communication device, it causes the communication device to perform the method as described in any one of claims 7-12.