Method and apparatus for identifying into ground, electronic device and storage medium

By integrating call detail record (CDR) data and signaling data, and combining feature index evaluation and self-encoding models, the problem of low accuracy in roaming location identification in existing technologies has been solved, achieving more accurate and complete user roaming location identification.

CN118803629BActive Publication Date: 2026-01-27CHINA MOBILE GRP HENAN CO LTD +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202311786297.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-12-22
Publication Date
2026-01-27
Estimated Expiration
2043-12-22

AI Technical Summary

Technical Problem

Existing roaming location identification methods rely on call detail records (CDRs), resulting in low accuracy and a high risk of errors, especially in border roaming situations where it is difficult to accurately determine the user's actual roaming location.

Method used

By integrating call detail record (CDR) data and signaling data, the roaming location of the target user is identified, the boundary roaming base station table is updated, boundary roaming trajectories are excluded, and the real-time and completeness of signaling data is utilized. Combined with feature index evaluation and self-encoding models, the identification process is optimized to determine the user's true roaming location.

Benefits of technology

It improves the accuracy and completeness of roaming identification, reduces the limitations of call detail record data, and can identify unrecorded boundary roaming base stations, ensuring the accuracy and completeness of user trajectory identification.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118803629B_ABST
    Figure CN118803629B_ABST
Patent Text Reader

Abstract

The present disclosure provides a method and device for identifying a place of roaming in, an electronic device and a storage medium. Based on fused data of call detail record (CDR) data and signaling data, a place of roaming in of a target user is identified to obtain a preliminary identification result. A boundary roaming base station is identified according to the signaling data, and a boundary roaming base station table is updated according to the identification result. A boundary roaming track of the target user accessing the base station in the boundary roaming base station table is identified, and the boundary roaming track is excluded from the preliminary identification result to obtain a roaming-in identification result. The roaming-in identification result is analyzed to determine the place of roaming in of the target user. Compared with the related art, the present disclosure can reduce the limitations caused by using only the CDR data by fusing the CDR data and the signaling data, and can identify a boundary roaming base station that is not recorded by identifying the boundary roaming base station, thereby ensuring the integrity and accuracy of the user track identification, and accurately identifying the place of roaming in.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to the field of communication technology, and in particular to a method and apparatus for infiltrating identification, an electronic device, and a storage medium. Background Technology

[0002] Identifying the source of a user's roaming incursion is a critical issue in current communication networks. Currently, the primary method is through call detail record (CDR) data. However, CDR data, as the main data source for identifying the source of a user's roaming incursion, is incomplete. Due to various reasons, such as equipment failure and network coverage issues, the communication data of some users may not be accurately recorded or collected. This prevents us from obtaining complete information on the user's roaming incursion location, thus affecting the accuracy and reliability of the identification. Relying solely on CDR data for identifying the source of a user's roaming incursion fails to effectively avoid the problem of boundary roaming. This makes it difficult to accurately determine the user's actual roaming incursion location. Furthermore, CDR service behavior is actively triggered by the user, and its data cycle has significant uncertainty and discontinuity; that is, it is uncertain whether the user uses CDR services, when they use them, and whether the user will use the service at a high frequency and fixed period as set by the operator. Therefore, using low-density CDR data for user trajectory identification has considerable limitations, leading to errors and omissions in the trajectory identification of the target user group. Summary of the Invention

[0003] This disclosure provides a method, apparatus, electronic device, and storage medium for identifying land intrusion. Its main objective is to address the problem of low accuracy in current land intrusion identification methods.

[0004] According to a first aspect of this disclosure, a method for identifying intrusive locations is provided, comprising:

[0005] Based on the fusion of call detail record (CDR) data and signaling data, preliminary identification results were obtained by identifying the roaming location of the target user.

[0006] The boundary roaming base stations are identified based on the signaling data, and the boundary roaming base station table is updated based on the identification results.

[0007] The boundary roaming trajectory of the target user accessing the base station in the boundary roaming base station table is identified, and the boundary roaming trajectory is excluded from the preliminary identification result to obtain the roaming in identification result;

[0008] The intrusion identification results are analyzed to determine the intrusion location of the target user.

[0009] Optionally, the preliminary identification result for identifying the roaming location of the target user based on the fused data of call detail record (CDR) data and signaling data includes:

[0010] The call detail record (CDR) data and the signaling data are fused together to obtain the fused data, wherein the signaling data includes signaling data from different communication protocols.

[0011] Obtain the intrusion information from the fused data and generate the preliminary identification result.

[0012] Optionally, the step of identifying border roaming base stations based on the signaling data and updating the border roaming base station table based on the identification result includes:

[0013] The importance of the feature indicators in the signaling data is evaluated and analyzed, and key feature indicators are determined, wherein the key feature indicators are the feature indicators whose importance evaluation values ​​exceed the importance threshold.

[0014] The feature data of the key feature indicators are traversed and optimized to obtain the optimal combination of indicators.

[0015] Based on the optimal combination of indicators, the boundary roaming base stations in the trajectory of the target user are identified, and the boundary roaming base stations are updated in the boundary roaming base station table.

[0016] Optionally, the step of evaluating and analyzing the importance of feature indicators in the signaling data and determining key feature indicators includes:

[0017] Obtain the feature data corresponding to the feature indicators in the signaling data, and perform variance analysis on the feature data;

[0018] The feature data after variance analysis is input into a preset decision tree model to evaluate the importance of the feature data;

[0019] The feature indicators whose importance is greater than the importance threshold are classified as the key feature indicators.

[0020] Optionally, the step of traversing and optimizing the feature data of the key feature indicators to obtain the optimal combination of indicators includes:

[0021] The feature data of the key feature indicators are input into the logistic regression model and used as the objective function.

[0022] An optimization model is established based on the particle swarm optimization algorithm. The objective function and the combination of indices are then input into the optimization model for traversal optimization to obtain the optimal combination of indices.

[0023] Optionally, identifying the boundary roaming trajectory of the target user accessing the base station in the boundary roaming base station table, and excluding the boundary roaming trajectory from the preliminary identification result to obtain the roaming intrusion identification result, includes:

[0024] Obtain the target users and their unidentified boundary roaming segments that access the base stations in the boundary roaming base station table;

[0025] Boundary roaming trajectory identification is performed on the boundary roaming segment to be identified in order to determine whether the boundary roaming segment to be identified is a boundary roaming trajectory;

[0026] If the boundary roaming segment to be identified is determined to be a boundary roaming trajectory, the boundary roaming segment to be identified is excluded from the preliminary identification result to obtain the roaming in identification result.

[0027] Optionally, the step of performing boundary roaming trajectory identification on the boundary roaming segment to be identified, to determine whether the boundary roaming segment to be identified is a boundary roaming trajectory, includes:

[0028] Based on the autoencoder model, the sample data corresponding to the boundary roaming segment to be identified is reconstructed to obtain the reconstructed data;

[0029] Calculate the error between the sample data and the reconstructed data, and determine whether the boundary roaming segment to be identified is a boundary roaming trajectory based on the error.

[0030] Optionally, analyzing the intrusion identification results to determine the intrusion location of the target user includes:

[0031] Based on the intrusion recognition results, obtain the locations in the target user's movement trajectory where the user stayed for more than a preset time.

[0032] The location closest to the target location in the target user's movement trajectory is determined as the target user's intrusion point.

[0033] According to a second aspect of this disclosure, an apparatus for identifying intrusion sites is provided, comprising:

[0034] The first identification unit is used to identify the roaming location of the target user based on the fused data of call detail record data and signaling data to obtain preliminary identification results;

[0035] The second identification unit is used to identify the boundary roaming base stations according to the signaling data, and update the boundary roaming base station table according to the identification result;

[0036] The third identification unit is used to identify the boundary roaming trajectory of the target user accessing the base station in the boundary roaming base station table, and exclude the boundary roaming trajectory from the preliminary identification result to obtain the roaming identification result;

[0037] The determining unit is used to analyze the intrusion identification results to determine the intrusion location of the target user.

[0038] Optionally, the first identification unit includes:

[0039] The fusion module is used to fuse the call detail record (CDR) data and the signaling data to obtain the fused data, wherein the signaling data includes signaling data from different communication protocols;

[0040] The first acquisition module is used to acquire the infiltrated ground information in the fused data and generate the preliminary identification result.

[0041] Optionally, the second identification unit includes:

[0042] An evaluation module is used to evaluate and analyze the importance of feature indicators in the signaling data and determine key feature indicators, wherein the key feature indicators are the feature indicators whose importance evaluation values ​​exceed the importance threshold.

[0043] The optimization module is used to iterate and optimize the feature data of the key feature indicators in order to obtain the optimal combination of indicators.

[0044] The first identification module is used to identify the boundary roaming base stations in the trajectory of the target user based on the optimal combination of indicators, and update the boundary roaming base stations to the boundary roaming base station table.

[0045] Optionally, the evaluation module is also used for:

[0046] Obtain the feature data corresponding to the feature indicators in the signaling data, and perform variance analysis on the feature data;

[0047] The feature data after variance analysis is input into a preset decision tree model to evaluate the importance of the feature data;

[0048] The feature indicators whose importance is greater than the importance threshold are classified as the key feature indicators.

[0049] Optionally, the optimization module is further configured to:

[0050] The feature data of the key feature indicators are input into the logistic regression model and used as the objective function.

[0051] An optimization model is established based on the particle swarm optimization algorithm. The objective function and the combination of indices are then input into the optimization model for traversal optimization to obtain the optimal combination of indices.

[0052] Optionally, the third identification unit includes:

[0053] The second acquisition module is used to acquire the target users and their unidentified boundary roaming segments that access the base stations in the boundary roaming base station table.

[0054] The second identification module is used to identify the boundary roaming segment to be identified, so as to determine whether the boundary roaming segment to be identified is a boundary roaming trajectory.

[0055] The exclusion module is used to exclude the boundary roaming segment to be identified from the preliminary identification result when it is determined that the boundary roaming segment to be identified is a boundary roaming trajectory, so as to obtain the roaming identification result.

[0056] Optionally, the second identification module is further used for:

[0057] Based on the autoencoder model, the sample data corresponding to the boundary roaming segment to be identified is reconstructed to obtain the reconstructed data;

[0058] Calculate the error between the sample data and the reconstructed data, and determine whether the boundary roaming segment to be identified is a boundary roaming trajectory based on the error.

[0059] Optionally, the determining unit includes:

[0060] The third acquisition module is used to acquire, based on the intrusion recognition result, locations in the target user's movement trajectory where the user has stayed for more than a preset time.

[0061] The determination module is used to determine the location closest to the target location in the target user's movement trajectory as the target user's intrusion point.

[0062] According to a third aspect of this disclosure, an electronic device is provided, comprising:

[0063] At least one processor; and

[0064] A memory communicatively connected to the at least one processor; wherein,

[0065] The memory stores instructions that can be executed by the at least one processor to enable the at least one processor to perform the method described in the first aspect above.

[0066] According to a fourth aspect of this disclosure, a non-transitory computer-readable storage medium is provided storing computer instructions, wherein the computer instructions are configured to cause the computer to perform the method described in the first aspect above.

[0067] According to a fifth aspect of this disclosure, a computer program product is provided, comprising a computer program that, when executed by a processor, implements the method described in the first aspect above.

[0068] This disclosure provides a method, apparatus, electronic device, and storage medium for roaming location identification. Based on fused call detail record (CDR) data and signaling data, a preliminary identification result is obtained by identifying the roaming location of a target user. Boundary roaming base stations are identified according to the signaling data, and a boundary roaming base station table is updated based on the identification result. The boundary roaming trajectories of target users accessing base stations in the boundary roaming base station table are identified, and boundary roaming trajectories are excluded from the preliminary identification result to obtain a roaming location identification result. The roaming location identification result is analyzed to determine the roaming location of the target user. Compared with related technologies, this disclosure, by fusing CDR data and signaling data, can reduce the limitations of using only CDR data. Furthermore, by identifying boundary roaming base stations, unrecorded boundary roaming base stations can be identified, thereby ensuring the completeness and accuracy of user trajectory identification and accurately identifying the roaming location.

[0069] It should be understood that the description in this section is not intended to identify key or essential features of the embodiments of this application, nor is it intended to limit the scope of this application. Other features of this application will become readily apparent from the following description. Attached Figure Description

[0070] The accompanying drawings are provided to better understand this solution and do not constitute a limitation of this disclosure. Wherein:

[0071] Figure 1 A flowchart illustrating a method for identifying intrusive locations provided in this embodiment of the disclosure;

[0072] Figure 2 A flowchart illustrating another method for identifying intrusive locations provided in this disclosure embodiment;

[0073] Figure 3 A schematic flowchart of a method for screening key feature indicators provided in this embodiment of the disclosure;

[0074] Figure 4 This is a graph showing how the IV value changes with the number of bins.

[0075] Figure 5 This is another graph showing how the IV value changes with the number of bins;

[0076] Figure 6 A flowchart illustrating a method for identifying a boundary roaming base station provided in this embodiment of the present disclosure;

[0077] Figure 7 A flowchart illustrating another method for identifying infiltrated areas provided in this disclosure embodiment;

[0078] Figure 8 A schematic diagram of the structure of a device for identifying intrusive locations provided in an embodiment of this disclosure;

[0079] Figure 9 A schematic diagram of the structure of another device for identifying intrusion sites provided in an embodiment of this disclosure;

[0080] Figure 10 A schematic block diagram of an example electronic device provided for embodiments of this disclosure. Detailed Implementation

[0081] The exemplary embodiments of this disclosure are described below with reference to the accompanying drawings, including various details of the embodiments to aid understanding, and should be considered merely exemplary. Therefore, those skilled in the art will recognize that various changes and modifications can be made to the embodiments described herein without departing from the scope and spirit of this disclosure. Similarly, for clarity and brevity, descriptions of well-known functions and structures are omitted in the following description.

[0082] Currently, roaming identification for users mainly relies on simple call detail record (CDR) data to identify roaming boundaries. This involves using user CDR data (including voice calls, SMS messages, and data usage) for roaming identification. However, CDR service behavior is user-initiated, and its data cycle has significant uncertainty and discontinuity. It's uncertain whether a user will use CDR services, when they will use them, and users don't typically use services at a fixed frequency as set by the operator. Therefore, using low-density CDR data for user trajectory identification has considerable limitations, leading to errors and omissions in the trajectory identification of target user groups.

[0083] Border roaming refers to the phenomenon of overlapping signal coverage between base stations located at the administrative boundary of two places. This occurs when the signal strength differs between the two locations. In border areas between provinces, due to overlapping base station signals, a mobile phone may use the signal of a base station in another province without actually roaming outside that province, thus generating roaming call records. Roaming is a common term used by mobile phone users. It refers to the ability of cellular mobile phone users to continue using their mobile phones in other regions or countries even when they leave their home country. The root cause of border roaming problems is that base station signals in border areas are too strong, causing coverage in neighboring provinces. For example, when a user is located at the border of Province A and Province B, signal coverage may be unstable due to weather, buildings, trees, etc. The phone will be on the network of the side with the stronger signal. Each province often conducts independent frequency planning and network construction, resulting in problems such as mutual interference and cross-border coverage in some inter-provincial border areas. Therefore, when identifying roaming locations, it is necessary to eliminate interference from border roaming to ensure the accuracy of roaming location identification.

[0084] The following description, with reference to the accompanying drawings, describes a method, apparatus, electronic device, and storage medium for identifying intrusive locations according to embodiments of the present disclosure.

[0085] Figure 1 This is a schematic flowchart illustrating a method for identifying infiltrated locations provided in an embodiment of this disclosure.

[0086] like Figure 1 As shown, the method includes the following steps:

[0087] Step 101: Based on the fusion of call detail record (CDR) data and signaling data, the roaming location of the target user is identified to obtain preliminary identification results.

[0088] In the embodiments of this disclosure, call detail record (CDR) data refers to the record data generated by telecommunications operators when users make calls, send text messages, or engage in other communication activities. CDR service activities are actively triggered by users, and their data cycles exhibit significant uncertainty and discontinuity. Using only CDR data to identify a user's roaming location may lead to inaccurate identification and omissions. Therefore, the embodiments of this disclosure use fused signaling data to identify the roaming location of target users. Signaling data consists of control commands generated in the communication network, used to guide the coordinated operation of terminals, switching systems, and transmission systems to establish temporary communication channels and maintain normal network operation. Signaling data has different signaling formats depending on the communication protocol, such as map signaling in 2G mobile networks. It should be noted that this disclosure does not limit the use of signaling data under any particular communication protocol; it can be signaling data from all available communication protocols. Because the signaling data refresh interval is short, updates can be achieved at the minute or second level. High refresh rates help to more accurately reflect network conditions and user behavior, thereby accurately obtaining the target user's location information.

[0089] Call detail record (CDR) data and signaling data contain information about the target user's communication behavior and network status. By fusing this data, a more comprehensive understanding of the target user's behavioral characteristics can be obtained, thus enabling more accurate identification of their roaming locations. CDR data and signaling data respectively reflect the target user's communication behavior and network status, and the two are complementary. When one type of data is abnormal or missing, the other type can provide supplementary information, thereby enhancing the robustness of the identification results. Data fusion can also leverage the advantages of both types of data to improve identification efficiency.

[0090] Step 102: Identify the border roaming base stations based on the signaling data, and update the border roaming base station table based on the identification results.

[0091] In the embodiments of this disclosure, when identifying the roaming location of a target user, the existence of boundary roaming issues may lead to inaccurate identification. Furthermore, due to reasons such as untimely updates to the boundary roaming base station table, base stations not listed in the table may actually be boundary roaming base stations. Therefore, boundary roaming base stations within the user's trajectory range are identified by analyzing and processing the user's signaling data. Features related to boundary roaming are extracted from the signaling data. These features may include, but are not limited to, the user's equipment movement trajectory and signal strength changes between base stations. By analyzing these features, it can be determined whether the user is roaming at the boundary.

[0092] By analyzing signaling data, boundary roaming base stations can be identified more accurately. This method is unaffected by incomplete or inaccurate call detail record (CDR) data, thus improving identification accuracy. Signaling data reflects the operational status of base stations and the movement of user equipment in real time, enabling real-time monitoring of boundary roaming base stations and timely updates to the boundary roaming base station table.

[0093] In some other embodiments of this disclosure, the signaling data is preprocessed before analysis and processing to facilitate subsequent analysis and processing.

[0094] Step 103: Identify the boundary roaming trajectory of the target user accessing the base station in the boundary roaming base station table, and exclude the boundary roaming trajectory from the preliminary identification result to obtain the roaming identification result.

[0095] In the embodiments of this disclosure, the boundary roaming trajectory of the target user can be identified based on the target user's information and signaling data. By analyzing the boundary roaming trajectory, it can be determined whether the user has actually engaged in boundary roaming. In the preliminary identification results, there may be some users who are mistakenly identified as having engaged in roaming due to boundary roaming issues. To obtain more accurate roaming identification results, it is necessary to exclude users who are mistakenly identified as engaging in boundary roaming. This can be done by comparing the target user's boundary roaming trajectory with the preliminary identification results. After excluding boundary roaming trajectories, a more accurate roaming identification result can be obtained.

[0096] By excluding users mistakenly identified as roaming at the border, false positives can be reduced, improving identification accuracy. Identifying and analyzing the border roaming trajectories of target users helps operators better understand network coverage, user behavior, and other factors, thereby optimizing network management and improving network performance and user experience.

[0097] Step 104: Analyze the intrusion identification results to determine the intrusion location of the target user.

[0098] In the embodiments of this disclosure, based on the obtained roaming initiation identification results, information such as, but not limited to, the user's roaming in and out times, and examples, can be obtained; further, the user's actual roaming location can be identified. For example, due to boundary roaming information, a user may briefly pass through location B while traveling from location C to location A, and be identified by a base station in location B, and the roaming initiation identification results will contain information about location B. Therefore, further rule analysis is needed to determine the user's specific roaming location. By determining the target user's roaming location, the user's geographical location can be more accurately located, thereby providing more precise services and business. By analyzing the target user's roaming location, operators can better understand network coverage, thereby optimizing network layout and resource allocation, and improving network performance and user experience.

[0099] This disclosure provides a method for roaming location identification. Based on fused call detail record (CDR) data and signaling data, a preliminary identification result is obtained by identifying the roaming location of a target user. Boundary roaming base stations are identified according to the signaling data, and the boundary roaming base station table is updated based on the identification result. The boundary roaming trajectories of target users accessing base stations in the boundary roaming base station table are identified, and boundary roaming trajectories are excluded from the preliminary identification result to obtain a roaming location identification result. The roaming location identification result is analyzed to determine the roaming location of the target user. Compared with related technologies, this disclosure, by fusing CDR data and signaling data, can reduce the limitations of using only CDR data. Furthermore, by identifying boundary roaming base stations, unrecorded boundary roaming base stations can be identified, thereby ensuring the completeness and accuracy of user trajectory identification and accurately identifying the roaming location.

[0100] To clearly illustrate the embodiments of this disclosure, this embodiment provides a flowchart illustrating another method for infiltrating identification.

[0101] like Figure 2 As shown, the method includes the following steps:

[0102] Step 201: The call detail record (CDR) data and the signaling data are fused to obtain the fused data, wherein the signaling data includes signaling data from different communication protocols.

[0103] Step 202: Obtain the intrusion information from the fused data and generate the preliminary identification result.

[0104] Specifically, in steps 201 to 202, high-precision, low-density call detail record (CDR) data and high-precision, high-density map signaling are fused with VoLTE signaling (MW protocol) data. This embodiment is based on the integration of these three data resources.

[0105] The fusion steps are as follows:

[0106] Extract call detail records (CDRs), MAP signaling, and Volte signaling (MW protocol) according to the user identifier.

[0107] Prioritize matching the roaming results of call detail records (CDRs).

[0108] If no call detail record (CDR) data is found, then match MAP signaling and VoLTE signaling data based on the same time and user information.

[0109] The preliminary identification results of a single user's intrusion location are as follows:

[0110]

[0111] Where α is the user's roaming location, β c For the call detail record (CDR) data identification results, β m ||β v This is the identification result for MAP signaling or VoLTE signaling.

[0112] Step 203: Evaluate and analyze the importance of the feature indicators in the signaling data, and determine the key feature indicators, wherein the key feature indicators are the feature indicators whose importance evaluation values ​​exceed the importance threshold.

[0113] As one possible implementation of this disclosure, the step of evaluating and analyzing the importance of feature indicators in the signaling data and determining key feature indicators includes: obtaining feature data corresponding to the feature indicators in the signaling data and performing variance analysis on the feature data; inputting the feature data after variance analysis into a preset decision tree model to evaluate the importance of the feature data; and classifying the feature indicators with an importance greater than an importance threshold as the key feature indicators.

[0114] Specifically, in step 203, signaling data needs to be collected first. This data may include communication signaling between base stations and connection information between user equipment and base stations. This data can be obtained through network monitoring equipment, user equipment, and the operator's backend system. Feature indicators related to boundary roaming are extracted from the collected signaling data. These feature indicators can determine whether a user's location at a certain point belongs to a boundary roaming point. Whether a user belongs to a boundary roaming point is determined by the user's state at a previous time, the current state, and the state at a future time. The indicator system table is as follows.

[0115] Table 2.1 Identification Feature Indicators of Roaming Base Stations

[0116] Serial Number Feature Indicator Name Feature indicators 1 Average dwell time at the previous point d_a 2 Average dwell time at the next point d_n 3 Average dwell time at current point d 4 Average distance from the previous point s_a 5 Average distance to the next point s_n 6 Average velocity at the previous point v_a 7 Average velocity at the next point v_n 8 Are the previous point and the next point the same point (in terms of percentage)? z 9 Average distance to the next point s_n 10 Average velocity at current point v

[0117] Different feature indicators convey information of varying importance; therefore, it is important to analyze the importance of these feature indicators. Figure 3This is a flowchart illustrating a method for selecting key feature indicators. Based on the extracted feature indicators, corresponding feature data is obtained from signaling data. An analysis of variance (ANOVA) is performed on the obtained feature data. ANOVA identifies which feature indicators show significant differences in the boundary roaming problem. The ANOVA-reduced feature data is then input into a pre-defined decision tree model. The importance of the feature data is assessed using the CART decision tree model.

[0118] Decision tree models assess the importance of each feature indicator. Importance assessment is determined based on the contribution of each feature indicator to the classification or prediction problem. This assessment helps identify which features are more important in the boundary roaming problem. Features with importance greater than a threshold are classified as key features. This importance threshold can be set based on specific needs and scenarios. By identifying key features, it's possible to determine which features contribute more significantly to the identification and resolution of the boundary roaming problem.

[0119] This embodiment of the CART tree uses the Gini coefficient to select splitting feature indicators. To ensure the universality of the rules for existing samples, key indicators are binned. To measure the contribution of information content to a feature, the information value (IV) indicator of the scoring card model is referenced.

[0120]

[0121] Where N is the number of boxes in this feature, i represents each box, good% is the proportion of users with a label of 0 in this box out of all correctly identified users in the entire feature, and bad% is the proportion of users with a label of 1 in this box out of all incorrectly identified users in the entire feature. The WOE formula is as follows.

[0122]

[0123] WOE (Word Entity) refers to a single bin; a larger WOE indicates more users correctly identified within that bin. IV (Input Value), on the other hand, refers to the entire feature. IV represents the information content of the feature and its contribution to the model. An IV value less than 0.03 indicates the feature contains almost no useful information and contributes nothing to the model; such features can be removed. An IV value greater than 0.5 indicates a lot of useful information and a high contribution to the model.

[0124] This embodiment uses actual data from a certain location to verify the results of this method, as follows:

[0125] First, a function is constructed to determine the number of containers and the upper and lower bounds of the containers. Second, based on the curve of the IV value changing with the number of containers (the dwell time at this point, the dwell time at the previous point, and the dwell time at the next point are respectively shown in the figure),... Figure 4 and Figure 5 As shown in the figure, the optimal number of bins for dwell time is 6, and the graph of iv value changing with the number of bins is shown in the figure. Figure 4 and Figure 5 As shown in the table below, the final upper and lower boundaries of the bins are obtained.

[0126] Table 2.2 Container Information Table of Dwell Time

[0127] level 1 2 3 4 5 6 scope <10 10-20 20-60 60-255 255-500 >500

[0128] The usable metrics derived from the final case study data are as follows.

[0129] Table 2.3 Final Screening Feature Table

[0130] Serial Number Indicator Name index 1 Average dwell time at the previous point d_a 2 Average dwell time at the next point d_n 3 Average dwell time at current point d 4 Average distance from the previous point s_a

[0131] By performing analysis of variance (ANOVA) and importance assessment on the feature data, we can determine which feature indicators are more important for identifying the boundary roaming problem. These key feature indicators can more accurately reflect the behavior and patterns of boundary roaming, thereby improving the accuracy of identification. ANOVA and importance assessment can reduce the amount of data that needs to be processed, thus reducing computational complexity. At the same time, identifying key feature indicators can also reduce model complexity and improve model efficiency and performance.

[0132] Step 204: The feature data of the key feature indicators are traversed and optimized to obtain the optimal combination of indicators.

[0133] As one possible implementation of this disclosure, the step of traversing and optimizing the feature data of the key feature indicators to obtain the optimal indicator combination includes: inputting the feature data of the key feature indicators into a logistic regression model and using it as the objective function; establishing an optimization model based on the particle swarm optimization algorithm, and inputting the objective function and the indicator combination into the optimization model for traversal optimization to obtain the optimal indicator combination.

[0134] Specifically, in step 204, based on the four key feature indicators (d_a, d_n, d, s_a) selected in step 203 as independent variables, a logit model was trained using real samples. This model is used to predict whether a base station is a boundary roaming base station. The logit model is a commonly used classification model that maps input variables to two categories, 0 or 1. To find the optimal combination of indicators, it is necessary to iterate through each possible combination of indicators and calculate its prediction error on the logit model (here, F1 score is used as the evaluation metric). F1 score is a commonly used evaluation metric for classification models, which comprehensively considers the model's accuracy and recall. During the iteration process, each combination of indicators is used as the independent variable, and the prediction error of the logit model is used as the dependent variable to establish an optimization solution model. The goal of this model is to find the value of the independent variable that minimizes the dependent variable, i.e., to find the optimal combination of indicators. Figure 6 This is a flowchart illustrating a method for identifying border roaming base stations. By solving this optimization model, an optimal combination of indicators can be obtained, which minimizes the prediction error on the logit model. This combination of indicators can then be used to establish identification rules to determine whether a base station is a border roaming base station.

[0135] The objective function formula is as follows:

[0136] logit(p) = ln(p / (1-p))

[0137] Where p represents the probability value.

[0138] In particle swarm optimization (PSO) algorithms, a fitness function is used to evaluate the quality of each particle. If the logit function is minimized, the fitness function can be defined as its inverse, i.e.:

[0139] f(x)=-logit(x)=-ln(x / (1-x))

[0140] Here, x represents the position or solution of the particle.

[0141] The goal of the particle swarm optimization algorithm is to minimize the fitness function f(x). Therefore, the positions and velocities of the particles are updated to continuously decrease the value of the fitness function. The update rule may include the following formula:

[0142] v(t+1)=w*v(t)+c1*rand1*(pbest-x(t))+c2*rand2*(gbest-x(t))

[0143] v(t+1)=x(t+1)=x(t)+v(t+1)

[0144] In the above formula, v(t) represents the particle's velocity, x(t) represents the particle's position, w is the inertia weight, c1 and c2 are acceleration factors, rand1 and rand2 are random numbers, pbest represents the particle's individual optimal solution, and gbest represents the global optimal solution.

[0145] Step 205: Based on the optimal combination of indicators, identify the boundary roaming base stations in the trajectory of the target user, and update the boundary roaming base station table.

[0146] Specifically, in step 205, the optimal combination of indicators is identified, which has the smallest prediction error on the logit model. This combination of indicators can then be used to establish identification rules to determine whether a base station is a boundary roaming base station. Because the boundary roaming base station table may be updated untimely or for other reasons, base stations not listed in the table may actually be boundary roaming base stations. The identified boundary roaming base stations are then integrated and updated with the original boundary roaming base station dimension table to complete the boundary roaming base station information.

[0147] Step 206: Obtain the target users and their unidentified boundary roaming segments from the base stations in the boundary roaming base station table.

[0148] Specifically, in step 206, for each target user, the boundary roaming segment to be identified is determined. This can be determined based on information such as communication records and movement trajectories in the user's fused data. Users who are misidentified as having roamed due to boundary roaming issues need to be excluded to obtain more accurate roaming identification results.

[0149] By identifying target users and determining the boundary roaming segments to be identified, users' boundary roaming behavior can be identified more accurately.

[0150] Step 207: Perform boundary roaming trajectory identification on the boundary roaming segment to be identified, so as to determine whether the boundary roaming segment to be identified is a boundary roaming trajectory.

[0151] As one possible implementation of this disclosure, the step of performing boundary roaming trajectory identification on the boundary roaming segment to be identified in order to determine whether the boundary roaming segment to be identified is a boundary roaming trajectory includes: reconstructing the sample data corresponding to the boundary roaming segment to be identified based on an autoencoder model to obtain reconstructed data; calculating the error between the sample data and the reconstructed data, and determining whether the boundary roaming segment to be identified is a boundary roaming trajectory based on the error.

[0152] Specifically, in step 207, an autoencoder model is used to reconstruct the sample data corresponding to the boundary roaming segment to be identified. An autoencoder model is an unsupervised neural network model that can learn useful features from data and generate new data. By using an autoencoder model, new data similar to the original data can be generated, i.e., reconstructed data. The error between the sample data and the reconstructed data is calculated. The error can be measured in various ways, such as mean squared error (MSE) and mean absolute error (MAE). The smaller the error, the closer the reconstructed data is to the original data. The error is used to determine whether the boundary roaming segment to be identified is a boundary roaming trajectory. If the error exceeds a set threshold, the boundary roaming segment to be identified is considered a boundary roaming trajectory; if the error does not exceed the set threshold, the boundary roaming segment to be identified is considered not a boundary roaming trajectory.

[0153] The Autoencoder Algorithm (AE) is a neural network model used for unsupervised learning. Its main principle is to learn how to encode and decode input data by inputting itself, thereby achieving dimensionality reduction and reconstruction of the data. During this process, if outliers exist, the AE algorithm can determine which data points are outside the normal distribution range by the magnitude of the reconstruction error, thus achieving outlier detection. The model features are constructed as follows:

[0154] Table 3.1 AE Algorithm Feature Table

[0155] Serial Number Feature Name Name Abbreviation 1 Does it involve boundary roaming (dependent variable)? y 2 Current length of stay d 3 Current speed v 4 Is Shangshang base station the current base station? aba 5 Distance from the previous base station d_a

[0156] When using the AE algorithm for outlier detection, the following steps can be followed:

[0157] (1) Train the AE model using a normal dataset, and then reconstruct all the data using the trained model. Here, a normal dataset refers to a dataset that does not contain outliers;

[0158] (2) Calculate the error between each sample data and its reconstructed data, and use the error as a feature value to construct an outlier detection model.

[0159] The formula for calculating reconstruction error is as follows:

[0160] L(x) = ||xG(E(x))|| 2

[0161] Where x represents the original data, E(x) represents the encoder's transformation of the original data into a feature vector, and G(E(x)) represents the decoder's transformation of the feature vector back into data. 2 This represents the square of the Euclidean distance.

[0162] From the above formula,

[0163]

[0164] Where n represents the number of samples in the dataset, X i This represents the original input data (i.e., features d, v, d_a, aba). w represents the reconstructed output data. i R(θ) is a weighting coefficient used to balance the contribution of each sample to the total error, and R(θ) represents the regularization term. θ is the regularization coefficient, used to control the influence of the regularization term. θ is a model parameter. This scheme uses L1 regularization, therefore the specific formula for the reconstruction error is as follows.

[0165]

[0166] Select an appropriate threshold and consider samples with errors greater than the threshold as outliers, otherwise consider them as normal points.

[0167] The formula for determining whether a point is an outlier is as follows:

[0168]

[0169] Here, threshold is a set threshold. If the reconstruction error of the user signaling data exceeds this threshold, the point is considered an outlier point, and the location of the base station at this point is a boundary roaming drift point.

[0170] By using an autoencoder model for data reconstruction and error calculation, it is possible to more accurately determine whether a boundary roaming segment to be identified is a boundary roaming trajectory. This method can effectively handle data noise and outliers, thereby improving the accuracy of identification. Using an autoencoder model for data reconstruction reduces the amount of data that needs to be processed, thus reducing computational complexity. Simultaneously, this method can also reduce model complexity, improving model efficiency and performance. The autoencoder model is an unsupervised neural network model with strong robustness. This method can adapt to different data distributions and scenarios, thus obtaining more accurate results.

[0171] Step 208: If it is determined that the boundary roaming segment to be identified is a boundary roaming trajectory, the boundary roaming segment to be identified is excluded from the preliminary identification result to obtain the roaming identification result.

[0172] Specifically, in step 208, the abnormal signaling points of users identified by the AE algorithm are further eliminated, and finally the real user signaling data of users after eliminating boundary roaming is obtained (roaming in identification result).

[0173] Step 209: According to the intrusion recognition result, obtain the locations in the moving trajectory of the target user where the residence time exceeds a preset duration.

[0174] Step 210: Determine the location closest to the target location in the moving trajectory of the target user as the intrusion location of the target user.

[0175] Specifically, in Steps 209 to 210, using the intrusion recognition result obtained in Step 208, take the location b of the base station before the base station where the target location a is marked by the user, and the cumulative residence time of the user at this location exceeds 8 hours. If it does not exceed 8 hours, then continue to push forward. Location b is the intrusion location of the user. Capture the intrusion locations of each user coming to a by day and create a table. It should be noted that in this embodiment of the present disclosure, the preset duration is taken as 8 hours for illustration, which does not constitute a limitation on the preset duration.

[0176] Further, in some embodiments of the present disclosure, according to the obtained intrusion recognition result, identify the means of transportation or transportation mode of the target user. Take the first base station A where the user enters the destination a and the last base station B where the user is at the intrusion location b, calculate the distance and interval duration between A and B, and calculate the intrusion means of transportation according to the speed. Where the speed v = s / t, s is the distance, and t is the time. When 20 < v < 180, it is considered that the intrusion means of transportation is a car; when 180 < v < 400, it is considered that the intrusion means of transportation is a high-speed rail / diesel multiple unit / train; when 400 < v, it is considered that the intrusion means of transportation is an airplane; when 20 > v, it is considered that the intrusion means of transportation is other.

[0177] Compared with the traditional method, first, this solution is for multi-dimensional data fusion, creatively uses VOLTE signaling (MW protocol) data, combines the call detail record data in the traditional way, and uses MAP signaling to supplement the 2 / 3G signaling, greatly improving the integrity of the basic data for user trajectory recognition, thereby ensuring the accuracy of intrusion location recognition; second, for the recognition of boundary roaming trajectories in this solution, a multiple structure innovation model is adopted and applied to actual cases, solving the problem of misinformation and omission of boundary base station information caused by the traditional method relying only on the operator to simply mark the boundary base stations based on the geographical location of the base stations, and achieving a major progress in the accurate recognition of boundary roaming trajectories in the communication industry.

[0178] Figure 7 It is a flow schematic diagram of another method for identifying the intrusion location. This method includes the following steps:

[0179] Step 301: Conduct a preliminary identification of the intrusion location on multi-dimensional signaling data.

[0180] First, high-precision, low-density call / SMS / data traffic service call detail records and high-precision, high-density location signaling are integrated to form basic data for preliminary user trajectory identification. The user data is then labeled and sorted according to the service time to achieve preliminary identification of user trajectories in the target area.

[0181] Step 302, Identification of Boundary Roaming Base Stations.

[0182] Identifying drifting roaming base stations based on user signaling data currently employs many traditional methods, such as merging ping-pong sequences and limiting the angle between trajectory points. This patent addresses current roaming intrusion identification scenarios by utilizing a CART tree algorithm to extract features from user trajectory segments and determine whether a base station is a boundary roaming station, in addition to applying traditional methods.

[0183] Normal handover points are often correlated with drift roaming. This patent explores the data characteristics of signaling segments between the user's lagging point and the previous point, and attempts to summarize patterns for rule-based judgment. This step uses the CART tree algorithm for feature selection to construct recognition rules, accurately identifying base stations that are not in the operator's boundary roaming base station dimension table but are indeed boundary roaming base stations.

[0184] Step 303: Identify and remove boundary roaming trajectories.

[0185] The boundary roaming base stations identified in the previous step are constructed into a boundary roaming base station table. Users who have passed through base stations in this table and their suspected boundary roaming segments are taken. The AE algorithm is used to identify the real boundary roaming segments and remove the boundary roaming segments.

[0186] Step 304, final identification of the infiltrated area.

[0187] Based on the results of the previous step, the roaming areas are removed from the original data to obtain the final roaming area identification results. Then, based on the roaming time and distance, the roaming vehicles are identified.

[0188] It should be noted that the embodiments of this disclosure may include multiple steps. For ease of description, these steps are numbered, but these numbers are not a limitation on the execution time slots or execution order between the steps; these steps can be implemented in any order, and the embodiments of this disclosure do not limit this.

[0189] Corresponding to the aforementioned method for identifying intrusion, this invention also proposes a device for identifying intrusion. Since the device embodiments of this invention correspond to the method embodiments described above, details not disclosed in the device embodiments can be referred to the method embodiments described above, and will not be repeated here.

[0190] Figure 8This is a schematic diagram of the structure of a device for identifying intrusive locations provided in an embodiment of this disclosure, as shown below. Figure 8 As shown, it includes:

[0191] The first identification unit 41 is used to identify the roaming location of the target user based on the fusion data of call detail record data and signaling data to obtain a preliminary identification result.

[0192] The second identification unit 42 is used to identify the boundary roaming base station according to the signaling data, and update the boundary roaming base station table according to the identification result;

[0193] The third identification unit 43 is used to identify the boundary roaming trajectory of the target user accessing the base station in the boundary roaming base station table, and exclude the boundary roaming trajectory from the preliminary identification result to obtain the roaming identification result;

[0194] The determining unit 44 is used to analyze the intrusion identification results to determine the intrusion location of the target user.

[0195] This disclosure provides a roaming location identification device. Based on the fusion of call detail record (CDR) data and signaling data, it identifies the roaming location of a target user to obtain a preliminary identification result; it identifies border roaming base stations based on the signaling data and updates the border roaming base station table based on the identification result; it identifies the border roaming trajectory of the target user accessing the base stations in the border roaming base station table and excludes the border roaming trajectory from the preliminary identification result to obtain the roaming location identification result; and it analyzes the roaming location identification result to determine the roaming location of the target user. Compared with related technologies, this disclosure reduces the limitations of using only CDR data by fusing CDR data and signaling data, and by identifying border roaming base stations, it can identify unrecorded border roaming base stations, thereby ensuring the completeness and accuracy of user trajectory identification and accurately identifying the roaming location.

[0196] Furthermore, in one possible implementation of this embodiment, such as Figure 9 As shown, the first identification unit 41 includes:

[0197] The fusion module 411 is used to fuse the call detail record data and the signaling data to obtain the fused data, wherein the signaling data includes signaling data of different communication protocols;

[0198] The first acquisition module 412 is used to acquire the infiltrated ground information in the fused data and generate the preliminary identification result.

[0199] Furthermore, in one possible implementation of this embodiment, such as Figure 9 As shown, the second identification unit 42 includes:

[0200] Evaluation module 421 is used to evaluate and analyze the importance of feature indicators in the signaling data and determine key feature indicators, wherein the key feature indicators are the feature indicators whose importance evaluation values ​​exceed the importance threshold.

[0201] The optimization module 422 is used to traverse and optimize the feature data of the key feature indicators in order to obtain the optimal combination of indicators.

[0202] The first identification module 423 is used to identify the boundary roaming base stations in the trajectory of the target user based on the optimal combination of indicators, and update the boundary roaming base stations to the boundary roaming base station table.

[0203] Furthermore, in one possible implementation of this embodiment, the evaluation module 421 is further configured to:

[0204] Obtain the feature data corresponding to the feature indicators in the signaling data, and perform variance analysis on the feature data;

[0205] The feature data after variance analysis is input into a preset decision tree model to evaluate the importance of the feature data;

[0206] The feature indicators whose importance is greater than the importance threshold are classified as the key feature indicators.

[0207] Furthermore, in one possible implementation of this embodiment, the optimization module 422 is further configured to:

[0208] The feature data of the key feature indicators are input into the logistic regression model and used as the objective function.

[0209] An optimization model is established based on the particle swarm optimization algorithm. The objective function and the combination of indices are then input into the optimization model for traversal optimization to obtain the optimal combination of indices.

[0210] Furthermore, in one possible implementation of this embodiment, such as Figure 9 As shown, the third identification unit 43 includes:

[0211] The second acquisition module 431 is used to acquire the target users and their unidentified boundary roaming segments that access the base stations in the boundary roaming base station table.

[0212] The second identification module 432 is used to identify the boundary roaming segment to be identified, so as to determine whether the boundary roaming segment to be identified is a boundary roaming trajectory.

[0213] The exclusion module 433 is used to exclude the boundary roaming segment to be identified from the preliminary identification result when it is determined that the boundary roaming segment to be identified is a boundary roaming trajectory, so as to obtain the roaming identification result.

[0214] Furthermore, in one possible implementation of this embodiment, the second identification module 432 is further configured to:

[0215] Based on the autoencoder model, the sample data corresponding to the boundary roaming segment to be identified is reconstructed to obtain the reconstructed data;

[0216] Calculate the error between the sample data and the reconstructed data, and determine whether the boundary roaming segment to be identified is a boundary roaming trajectory based on the error.

[0217] Furthermore, in one possible implementation of this embodiment, such as Figure 9 As shown, the determining unit 44 includes:

[0218] The third acquisition module 441 is used to acquire, based on the intrusion recognition result, locations in the target user's movement trajectory where the user has stayed for more than a preset time.

[0219] The determination module 442 is used to determine the location closest to the target location in the target user's movement trajectory as the target user's intrusion point.

[0220] It should be noted that the foregoing explanation of the method embodiments also applies to the apparatus of this embodiment, and the principle is the same, so it is not limited in this embodiment.

[0221] According to embodiments of this disclosure, this disclosure also provides an electronic device, a readable storage medium, and a computer program product.

[0222] Figure 10 A schematic block diagram of an example electronic device 500 that can be used to implement embodiments of the present disclosure is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device may also represent various forms of mobile devices, such as personal digital processors, cellular phones, smartphones, wearable devices, and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the present disclosure described and / or claimed herein.

[0223] like Figure 10As shown, device 500 includes a computing unit 501, which can perform various appropriate actions and processes based on a computer program stored in ROM (Read-Only Memory) 502 or a computer program loaded from storage unit 508 into RAM (Random Access Memory) 503. RAM 503 can also store various programs and data required for the operation of device 500. The computing unit 501, ROM 502, and RAM 503 are interconnected via bus 504. I / O (Input / Output) interface 505 is also connected to bus 504.

[0224] Multiple components in device 500 are connected to I / O interface 505, including: input unit 506, such as keyboard, mouse, etc.; output unit 507, such as various types of monitors, speakers, etc.; storage unit 508, such as disk, optical disk, etc.; and communication unit 509, such as network card, modem, wireless transceiver, etc. Communication unit 509 allows device 500 to exchange information / data with other devices through computer networks such as the Internet and / or various telecommunications networks.

[0225] The computing unit 501 can be a variety of general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of the computing unit 501 include, but are not limited to, CPUs (Central Processing Units), GPUs (Graphics Processing Units), various special-purpose AI (Artificial Intelligence) computing chips, various computing units running machine learning model algorithms, DSPs (Digital Signal Processors), and any suitable processor, controller, microcontroller, etc. The computing unit 501 performs the various methods and processes described above, such as the creepage identification method. For example, in some embodiments, the creepage identification method may be implemented as a computer software program tangibly contained in a machine-readable medium, such as storage unit 508. In some embodiments, part or all of the computer program may be loaded and / or installed on device 500 via ROM 502 and / or communication unit 509. When the computer program is loaded into RAM 503 and executed by the computing unit 501, one or more steps of the methods described above may be performed. Alternatively, in other embodiments, the computing unit 501 may be configured to perform the aforementioned intrusion identification method by any other suitable means (e.g., by means of firmware).

[0226] Various implementations of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, FPGAs (Field Programmable Gate Arrays), ASICs (Application-Specific Integrated Circuits), ASSPs (Application-Specific Standard Products), SOCs (System-on-Chips), CPLDs (Complex Programmable Logic Devices), computer hardware, firmware, software, and / or combinations thereof. These various implementations may include implementations in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which may be a dedicated or general-purpose programmable processor, capable of receiving data and instructions from a storage system, at least one input device, and at least one output device, and transmitting data and instructions to the storage system, the at least one input device, and the at least one output device.

[0227] The program code used to implement the methods of this disclosure may be written in any combination of one or more programming languages. This program code may be provided to a processor or controller of a general-purpose computer, special-purpose computer, or other programmable data processing apparatus, such that when executed by the processor or controller, the program code causes the functions / operations specified in the flowcharts and / or block diagrams to be implemented. The program code may be executed entirely on a machine, partially on a machine, as a standalone software package partially on a machine and partially on a remote machine, or entirely on a remote machine or server.

[0228] In the context of this disclosure, a machine-readable medium can be a tangible medium that may contain or store a program for use by or in conjunction with an instruction execution system, apparatus, or device. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can be, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, RAM, ROM, EPROM (Electrically Programmable Read-Only Memory) or flash memory, optical fiber, CD-ROM (Compact Disc Read-Only Memory), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.

[0229] To provide interaction with a user, the systems and techniques described herein can be implemented on a computer having: a display device for displaying information to the user (e.g., a CRT (Cathode-Ray Tube) or LCD (Liquid Crystal Display) monitor); and a keyboard and pointing device (e.g., a mouse or trackball) through which the user provides input to the computer. Other types of devices can also be used to provide interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including sound input, voice input, or tactile input).

[0230] The systems and technologies described herein can be implemented in computing systems that include backend components (e.g., as data servers), or middleware components (e.g., application servers), or frontend components (e.g., user computers with graphical user interfaces or web browsers through which users can interact with implementations of the systems and technologies described herein), or any combination of such backend, middleware, or frontend components. The components of the system can be interconnected via digital data communication (e.g., communication networks) of any form or medium. Examples of communication networks include LANs (Local Area Networks), WANs (Wide Area Networks), the Internet, and blockchain networks.

[0231] Computer systems can include clients and servers. Clients and servers are generally geographically separated and typically interact via communication networks. The client-server relationship is created by computer programs running on the respective computers and having a client-server relationship with each other. A server can be a cloud server, also known as a cloud computing server or cloud host, a hosting product within the cloud computing service ecosystem, addressing the shortcomings of traditional physical hosts and VPS (Virtual Private Server, or simply "VPS") services, such as high management difficulty and weak business scalability. Servers can also be servers for distributed systems or servers incorporating blockchain technology.

[0232] It's important to note that artificial intelligence (AI) is the study of enabling computers to simulate certain human thought processes and intelligent behaviors (such as learning, reasoning, thinking, and planning). It encompasses both hardware and software technologies. AI hardware technologies generally include sensors, dedicated AI chips, cloud computing, distributed storage, and big data processing. AI software technologies primarily include computer vision, speech recognition, natural language processing, machine learning / deep learning, big data processing, and knowledge graph technologies.

[0233] The various numerical designations such as "first," "second," etc., used in this disclosure are merely for ease of description and are not intended to limit the scope of the embodiments of this disclosure, nor do they indicate a sequential order.

[0234] At least one of the features described in this disclosure can also be described as one or more, and multiple features can be two, three, four or more, and this disclosure does not impose any limitations. In the embodiments of this disclosure, for a technical feature, the technical features in that technical feature are distinguished by "first", "second", "third", "A", "B", "C" and "D", etc., and there is no sequential order or size order among the technical features described by "first", "second", "third", "A", "B", "C" and "D".

[0235] It should be understood that the various forms of processes shown above can be used to rearrange, add, or delete steps. For example, the steps described in this disclosure can be executed in parallel, sequentially, or in different orders, as long as the desired result of the technical solution disclosed in this disclosure can be achieved, and this is not limited herein.

[0236] The specific embodiments described above do not constitute a limitation on the scope of protection of this disclosure. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this disclosure should be included within the scope of protection of this disclosure.

Claims

1. A method for infiltrating identification, characterized in that, include: Based on the fusion of call detail record (CDR) data and signaling data, preliminary identification results were obtained by identifying the roaming location of the target user. The boundary roaming base stations are identified based on the signaling data, and the boundary roaming base station table is updated based on the identification results. The boundary roaming trajectory of the target user accessing the base station in the boundary roaming base station table is identified, and the boundary roaming trajectory is excluded from the preliminary identification result to obtain the roaming in identification result; The intrusion identification results are analyzed to determine the intrusion location of the target user; The step of identifying border roaming base stations based on the signaling data and updating the border roaming base station table based on the identification results includes: The importance of feature indicators in the signaling data is evaluated and analyzed to determine key feature indicators, wherein the key feature indicators are those whose importance evaluation values ​​exceed an importance threshold; the importance evaluation is performed on the feature data using a CART decision tree model; the feature data is obtained from the signaling data based on the feature indicators; the feature indicators are used to determine whether a user's marker at a certain point belongs to a boundary roaming point; whether it belongs to a boundary roaming point is determined by the user's state at a previous time, the state at the current point, and the state at a subsequent time. The characteristic indicators include: the average dwell time of the previous point, the average dwell time of the next point, the average dwell time of the current point, the average distance from the previous point, the average distance from the next point, the average speed of the previous point, the average speed of the next point, whether the previous point and the next point are the same point, the average distance from the next point, and the average speed of the current point. The feature data of the key feature indicators are traversed and optimized to obtain the optimal combination of indicators. Based on the optimal combination of indicators, identify the boundary roaming base stations in the trajectory of the target user, and update the boundary roaming base station table; The step of traversing and optimizing the feature data of the key feature indicators to obtain the optimal combination of indicators includes: The feature data of the key feature indicators are input into the logistic regression model and used as the objective function. An optimization model is established based on the particle swarm optimization algorithm. The objective function and the combination of indicators are input into the optimization model for traversal optimization to obtain the optimal combination of indicators. The step of identifying the boundary roaming trajectory of the target user accessing the base station in the boundary roaming base station table, and excluding the boundary roaming trajectory from the preliminary identification result to obtain the roaming intrusion identification result includes: Obtain the target users and their unidentified boundary roaming segments that access the base stations in the boundary roaming base station table; Boundary roaming trajectory identification is performed on the boundary roaming segment to be identified in order to determine whether the boundary roaming segment to be identified is a boundary roaming trajectory; If the boundary roaming segment to be identified is determined to be a boundary roaming trajectory, the boundary roaming segment to be identified is excluded from the preliminary identification result to obtain the roaming in identification result; The step of identifying the boundary roaming segment to be identified, in order to determine whether the boundary roaming segment to be identified is a boundary roaming trajectory, includes: Based on the autoencoder model, the sample data corresponding to the boundary roaming segment to be identified is reconstructed to obtain the reconstructed data; Calculate the error between the sample data and the reconstructed data, and determine whether the boundary roaming segment to be identified is a boundary roaming trajectory based on the error.

2. The method according to claim 1, characterized in that, The fusion data based on call detail record (CDR) data and signaling data is used to identify the roaming location of the target user to obtain preliminary identification results, including: The call detail record (CDR) data and the signaling data are fused together to obtain the fused data, wherein the signaling data includes signaling data from different communication protocols. Obtain the intrusion information from the fused data and generate the preliminary identification result.

3. The method according to claim 1, characterized in that, The evaluation and analysis of the importance of feature indicators in the signaling data, and the determination of key feature indicators, include: Obtain the feature data corresponding to the feature indicators in the signaling data, and perform variance analysis on the feature data; The feature data after variance analysis is input into a preset decision tree model to evaluate the importance of the feature data; The feature indicators whose importance is greater than the importance threshold are classified as the key feature indicators.

4. The method according to claim 1, characterized in that, The step of analyzing the intrusion identification results to determine the intrusion location of the target user includes: Based on the intrusion recognition results, obtain the locations in the target user's movement trajectory where the user stayed for more than a preset time. The location closest to the target location in the target user's movement trajectory is determined as the target user's intrusion point.

5. A device for identifying infiltrated areas, characterized in that, include: The first identification unit is used to identify the roaming location of the target user based on the fused data of call detail record data and signaling data to obtain preliminary identification results; The second identification unit is used to identify the boundary roaming base stations according to the signaling data, and update the boundary roaming base station table according to the identification result; The third identification unit is used to identify the boundary roaming trajectory of the target user accessing the base station in the boundary roaming base station table, and exclude the boundary roaming trajectory from the preliminary identification result to obtain the roaming identification result; A determining unit is used to analyze the intrusion identification results to determine the intrusion location of the target user; The step of identifying border roaming base stations based on the signaling data and updating the border roaming base station table based on the identification results includes: The importance of feature indicators in the signaling data is evaluated and analyzed to determine key feature indicators, wherein the key feature indicators are those whose importance evaluation values ​​exceed an importance threshold; the importance evaluation is performed on the feature data using a CART decision tree model; the feature data is obtained from the signaling data based on the feature indicators; the feature indicators are used to determine whether a user's marker at a certain point belongs to a boundary roaming point; whether it belongs to a boundary roaming point is determined by the user's state at a previous time, the state at the current point, and the state at a subsequent time. The characteristic indicators include: the average dwell time of the previous point, the average dwell time of the next point, the average dwell time of the current point, the average distance from the previous point, the average distance from the next point, the average speed of the previous point, the average speed of the next point, whether the previous point and the next point are the same point, the average distance from the next point, and the average speed of the current point. The feature data of the key feature indicators are traversed and optimized to obtain the optimal combination of indicators. Based on the optimal combination of indicators, identify the boundary roaming base stations in the trajectory of the target user, and update the boundary roaming base station table; The step of traversing and optimizing the feature data of the key feature indicators to obtain the optimal combination of indicators includes: The feature data of the key feature indicators are input into the logistic regression model and used as the objective function. An optimization model is established based on the particle swarm optimization algorithm. The objective function and the combination of indicators are input into the optimization model for traversal optimization to obtain the optimal combination of indicators. The step of identifying the boundary roaming trajectory of the target user accessing the base station in the boundary roaming base station table, and excluding the boundary roaming trajectory from the preliminary identification result to obtain the roaming intrusion identification result includes: Obtain the target users and their unidentified boundary roaming segments that access the base stations in the boundary roaming base station table; Boundary roaming trajectory identification is performed on the boundary roaming segment to be identified in order to determine whether the boundary roaming segment to be identified is a boundary roaming trajectory; If the boundary roaming segment to be identified is determined to be a boundary roaming trajectory, the boundary roaming segment to be identified is excluded from the preliminary identification result to obtain the roaming in identification result; The step of identifying the boundary roaming segment to be identified, in order to determine whether the boundary roaming segment to be identified is a boundary roaming trajectory, includes: Based on the autoencoder model, the sample data corresponding to the boundary roaming segment to be identified is reconstructed to obtain the reconstructed data; Calculate the error between the sample data and the reconstructed data, and determine whether the boundary roaming segment to be identified is a boundary roaming trajectory based on the error.

6. An electronic device, characterized in that, include: At least one processor; as well as A memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor to enable the at least one processor to perform the method of any one of claims 1-4.

7. A non-transitory computer-readable storage medium storing computer instructions, characterized in that, The computer instructions are used to cause the computer to perform the method according to any one of claims 1-4.

8. A computer program product, characterized in that, Includes a computer program that, when executed by a processor, implements the method according to any one of claims 1-4.

Citation Information

Patent Citations

  • Multi-data source position information fusion method based on Spark cluster and system

    CN106844546A

  • User real-time travel calculation method based on mobile phone signaling data

    CN116546452A