Data processing method of internet of things card, electronic device, storage medium and program product

By constructing a knowledge graph set of IoT cards and using data augmentation technology to generate a set of target entity pairs, the problem of inaccurate IoT card monitoring is solved, and a wider and more accurate monitoring effect is achieved.

CN119254479BActive Publication Date: 2025-11-18CHINA UNITED NETWORK COMM GRP CO LTD +2
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411322657.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-09-20
Publication Date
2025-11-18
Estimated Expiration
2044-09-20

AI Technical Summary

Technical Problem

In existing technologies, the amount of raw data during entity parsing of IoT cards is limited, resulting in insufficient coverage of risk communities and thus affecting the accuracy of IoT card monitoring.

Method used

By acquiring operational data from IoT cards, first and second knowledge graph sets are constructed. Data augmentation is performed using TransE components and pseudo-twin networks. Combined with a large language model and preset domain rules, a set of target entity pairs is generated, forming a knowledge graph community to monitor fraudulent IoT cards.

Benefits of technology

It enables precise monitoring of IoT cards, expands the coverage of high-risk communities, and improves the accuracy and speed of fraud detection and response.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119254479B_ABST
    Figure CN119254479B_ABST
Patent Text Reader

Abstract

Embodiments of the present application provide a data processing method of an Internet of Things card, an electronic device, a storage medium and a program product. The method comprises: obtaining Internet of Things card data in a preset region within a preset statistical period; obtaining a first knowledge graph set and a second knowledge graph set according to the Internet of Things card data, a preset entity type and a preset attribute type; obtaining an entity pair set of entity alignment with data enhancement according to the first knowledge graph set and the second knowledge graph set; inputting a preset field rule and the entity pair set into a large language model to obtain a target entity pair set output by the large language model; generating a plurality of knowledge graph communities according to the target entity pair set; and monitoring the Internet of Things card based on the knowledge graph communities to discover fraudulent Internet of Things cards. Data enhancement is performed when the knowledge graph is analyzed, a large amount of data after enhancement is used to make the coverage range of the risk community more comprehensive, thereby achieving accurate monitoring of the Internet of Things card.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of data processing, and particularly relates to a data processing method of an Internet of Things card, an electronic device, a storage medium and a program product. BACKGROUND

[0002] With the rapid development of Internet of Things (IoT) technology, Internet of Things devices have been widely used in smart cities, smart homes, industrial control, smart agriculture and other fields, greatly promoting the process of social informatization and intelligentization. As a key bridge connecting Internet of Things devices and cloud servers, the security of Internet of Things cards is directly related to the stable operation and data security of the entire Internet of Things system.

[0003] Generally, when improving the anti-fraud capability of the Internet of Things, a complete domain knowledge graph is constructed to realize deep understanding and efficient query of complex relationships in the Internet of Things ecosystem, providing a solid data foundation for Internet of Things anti-fraud.

[0004] After constructing the knowledge graph, entity resolution maps ambiguous or duplicate entities in the original data to explicit and unique entities in the knowledge graph, ensuring the accuracy and consistency of the data. This process is crucial for identifying abnormal behavior in the use of Internet of Things cards, associating potential fraudsters and their activity tracks. Based on the results of entity resolution, possible risk communities can be established, which are collections of Internet of Things card users, devices or transactions with similar fraud characteristics or behavior patterns. By identifying and monitoring these risk communities, potential fraud activities can be discovered in a timely manner, enabling early warning and precise strikes against risks.

[0005] When establishing risk communities after entity resolution of the knowledge graph, a large amount of original data is usually required. The larger the amount of data, the more extensive and comprehensive the coverage of the risk community. However, the amount of original data is limited during entity resolution, which makes the coverage of the risk community not comprehensive enough, resulting in inaccurate monitoring of Internet of Things cards. SUMMARY

[0006] The data processing method of the Internet of Things card, the electronic device, the storage medium and the program product provided by the embodiments of the present application perform data enhancement when performing entity resolution on the knowledge graph, and through a large amount of data after enhancement, the coverage of the risk community is more comprehensive, thereby realizing accurate monitoring of the Internet of Things card.

[0007] In a first aspect, the embodiments of the present application provide a data processing method of an Internet of Things card, comprising: acquiring Internet of Things card data in a preset region in a preset statistical period, wherein the Internet of Things card data comprises running data of each Internet of Things card in the statistical period;

[0008] According to the Internet of Things card data, the preset entity type and the preset attribute type, a first knowledge graph set and a second knowledge graph set are obtained, wherein a first knowledge graph in the first knowledge graph set comprises structure information, and a second knowledge graph in the second knowledge graph set comprises attribute information;

[0009] According to the first knowledge graph set and the second knowledge graph set, a data-enhanced entity-aligned entity pair set is obtained, wherein the entity pair set comprises a first entity in a first knowledge graph and a second entity in a second knowledge graph having an entity alignment relationship with the first entity;

[0010] A preset domain rule and the entity pair set are input into a large language model, and a target entity pair set output by the large language model is obtained, wherein the target entity pair set comprises a first entity and a second entity similar to the first entity;

[0011] According to the target entity pair set, a plurality of knowledge graph communities are generated, and the Internet of Things card is monitored based on the knowledge graph communities to find fraudulent Internet of Things cards.

[0012] In a possible implementation, the method further comprises:

[0013] According to the Internet of Things card data and the preset entity type, an initial entity is obtained; wherein the preset entity type comprises an Internet of Things card and a geographic entity, wherein the geographic entity comprises a roaming province and a roaming city, and the preset attribute type comprises at least one of traffic, access to high-risk number of times or number of times of binding change;

[0014] According to the initial entity, the preset attribute type and the Internet of Things card data, attribute information of the initial entity and a relationship between the initial entities are extracted;

[0015] According to the relationship between the initial entities, a first knowledge graph set is constructed;

[0016] According to the attribute information of the initial entity, a second knowledge graph set is constructed.

[0017] In a possible implementation, before the preset domain rule and the entity pair set are input into the large language model, the method further comprises:

[0018] According to each entity pair in the entity pair set, a similarity between the first entity and the second entity is obtained according to a cosine similarity algorithm;

[0019] According to the similarity between the first entity and the second entity, for each first entity, K most similar second entities are obtained, where K is an integer;

[0020] According to the first entity and the K second entities, a new entity pair set is obtained;

[0021] The preset field rule and the entity pair set are input into a large language model, including:

[0022] The preset field rule and the new entity pair set are input into a large language model.

[0023] In a possible implementation, the preset field rule and the entity pair set are input into a large language model, and a target entity pair set output by the large language model is obtained, including:

[0024] The preset field rule is input into a large language model, and the preset field rule includes at least two field rules, each of which is used to indicate whether the entity alignment is met between the difference data;

[0025] The instruction information and the entity pair set are input into a large language model, and a target entity pair set output by the large language model is obtained; wherein the instruction information is used to instruct the large language model to judge the similarity between the first entity and the second entity, and the instruction information is also used to instruct the output content of the large language model.

[0026] In a possible implementation, the knowledge graph community is used to monitor the Internet of Things card to find a fraudulent Internet of Things card, including:

[0027] The knowledge graph community is drawn, and entities in the first knowledge graph set and the second knowledge graph set are explicitly labeled in the knowledge graph community, wherein the entities of the Internet of Things card are different from other entities in color.

[0028] According to the association relationship between the Internet of Things card and other entities or attributes, a to-be-monitored Internet of Things card is determined;

[0029] The to-be-monitored Internet of Things card is monitored to find a fraudulent Internet of Things card.

[0030] In a possible implementation, the first knowledge graph set and the second knowledge graph set are used to obtain a data-enhanced entity pair set, including:

[0031] According to the first knowledge graph set and the second knowledge graph set, a set of labeled aligned entities is obtained;

[0032] Based on the aligned entity set, alternately pass through the TransE component and the pseudo twin network to enhance entity alignment until the TransE component and the pseudo twin network no longer predict new aligned entities, and obtain a data-enhanced entity pair set;

[0033] The TransE component is configured to learn embedding of entities in structure according to the aligned entity set and the first knowledge graph set, and obtain first aligned entities.

[0034] The pseudo twin network is configured to learn embedding of entities in attribute information according to the aligned entity set and the second knowledge graph set, and obtain second aligned entities.

[0035] In a second aspect, an embodiment of the present application provides a data processing device of an Internet of Things card, including:

[0036] A data acquisition module is configured to acquire Internet of Things card data in a preset area in a preset statistical period, wherein the Internet of Things card data includes running data of each Internet of Things card in the statistical period.

[0037] A graph acquisition module is configured to acquire a first knowledge graph set and a second knowledge graph set according to the Internet of Things card data, a preset entity type and a preset attribute type, wherein a first knowledge graph in the first knowledge graph set includes structure information, and a second knowledge graph in the second knowledge graph set includes attribute information.

[0038] A data enhancement module is configured to acquire a data-enhanced entity-aligned entity pair set according to the first knowledge graph set and the second knowledge graph set, wherein the entity pair set includes a first entity in a first knowledge graph and a second entity in a second knowledge graph having an entity alignment relationship with the first entity.

[0039] A target entity pair acquisition module is configured to input a preset field rule and the entity pair set to a large language model, and acquire a target entity pair set output by the large language model, wherein the target entity pair set includes a first entity and a second entity similar to the first entity.

[0040] A knowledge graph community generation module is configured to generate a plurality of knowledge graph communities according to the target entity pair set, and monitor the Internet of Things card based on the knowledge graph communities to find fraudulent Internet of Things cards.

[0041] In a third aspect, an embodiment of the present application provides a data processing device of an Internet of Things card, including a memory and a processor.

[0042] The memory stores computer execution instructions.

[0043] The processor executes the computer-executed instructions stored in the memory, so that the processor executes the first aspect and / or various possible implementation manners of the first aspect.

[0044] In a fourth aspect, an embodiment of the present application provides a computer readable storage medium, wherein the computer readable storage medium stores computer-executed instructions, and the computer-executed instructions are executed by a processor to implement the first aspect and / or various possible implementation manners of the first aspect.

[0045] In a fifth aspect, an embodiment of the present application provides a computer program product, comprising a computer program, and the computer program is executed by a processor to implement the first aspect and / or various possible implementation manners of the first aspect.

[0046] The data processing method of the Internet of Things card, the electronic device, the storage medium and the program product provided by the embodiments of the present application can obtain the first knowledge graph set and the second knowledge graph set through the running data of the Internet of Things card and the preset entity type, can realize data enhancement of the entity, and can generate an entity pair set after aligning the data-enhanced entity. The target entity pair set is obtained by screening the entity pair set through the large language model and the preset field rule, and then the knowledge graph community can be generated according to the target entity pair set. Through the generation of the knowledge graph community after the data enhancement of the entity, the precise monitoring of the Internet of Things card can be realized. BRIEF DESCRIPTION OF DRAWINGS

[0047] The accompanying drawings, which are incorporated herein and constitute part of the specification, illustrate embodiments consistent with the present application and, together with the description, serve to explain the principles of the present application.

[0048] Figure 1 Flowchart of the data processing method of the Internet of Things card provided by the present application Figure 1 ;

[0049] Figure 2 Flowchart of the data processing method of the Internet of Things card provided by the present application Figure 2 ;

[0050] Figure 3 Structure diagram of the data processing device of the Internet of Things card provided by the present application;

[0051] Figure 4 Structure diagram of the data processing device of the Internet of Things card provided by the present application.

[0052] Through the above-mentioned drawings, the specific embodiments of the present application have been shown, and more detailed descriptions will be given hereinafter. These drawings and textual descriptions are not intended to limit the scope of the concept of the present application by any means, but to illustrate the concept of the present application to those skilled in the art by referring to specific embodiments. Detailed Implementation

[0053] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numbers in different drawings denote the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this application as detailed in the appended claims.

[0054] The technical solution of this application and how the technical solution of this application solves the above-mentioned technical problems are described in detail below with specific embodiments. These specific embodiments can be combined with each other, and the same or similar concepts or processes may not be described again in some embodiments. The embodiments of this application will now be described with reference to the accompanying drawings.

[0055] In the IoT SIM card anti-fraud model, after constructing the domain knowledge graph, entity parsing and establishing potential risk communities can improve the accuracy and response speed of IoT SIM card fraud identification.

[0056] The purpose of entity resolution is to discover multiple entity records belonging to the same group in the real world. Precise entity resolution methods can aggregate entities with similar or identical characteristics and discover new risk entities, tags, etc.

[0057] In existing technologies, entities are usually existing data when performing entity parsing, resulting in a limited number of entities. This limits the coverage of risk communities and makes the monitoring accuracy of IoT cards somewhat lacking.

[0058] By parsing existing knowledge graph entities and performing data augmentation, the entities are expanded, thereby enabling a wider coverage of the generated risk community and achieving precise monitoring of IoT cards.

[0059] Figure 1 Flowchart of the data processing method for the IoT card provided in this application Figure 1 ,like Figure 1 As shown, the method includes:

[0060] S101. Obtain IoT card data in a preset area within a preset statistical period.

[0061] IoT SIM card data includes the operational data of each IoT SIM card within the statistical period.

[0062] Operational data refers to the operational records of the IoT SIM card on the installed device. Operational data may include the IoT SIM card's roaming location, data usage, number of high-risk accesses, number of times the card has been re-bound, etc.

[0063] The running status of the Internet of Things card can be monitored by the running data in the statistical period, and the statistical period can be one month, six months or one year.

[0064] S102, according to the Internet of Things card data, the preset entity type and the preset attribute type, a first knowledge graph set and a second knowledge graph set are obtained.

[0065] By obtaining the Internet of Things card data in the statistical period, the Internet of Things card and the corresponding running data of the Internet of Things card can be obtained, and the data standardization processing is completed by data cleaning and deduplication of the running data. The cleaned running data includes multiple entities, the relationship between entities, and the attributes of entities.

[0066] According to the preset entity type, the entities in the running data can be identified, and the extracted relationship is integrated to generate a first knowledge graph. The first knowledge graph includes structure information, which is the relationship between entities. The first knowledge graph set includes the first knowledge graph of multiple Internet of Things cards.

[0067] According to the preset entity type and the preset attribute type, the attribute information of the entity in the running data is extracted, and the entity is taken as a node, and the attribute information is taken as the attribute or metadata of the node, to generate a second knowledge graph. The second knowledge graph includes attribute information. The second knowledge graph set includes the second knowledge graph of multiple Internet of Things cards.

[0068] S103, according to the first knowledge graph set and the second knowledge graph set, a data-enhanced entity-aligned entity pair set is obtained.

[0069] Through the structure information and attribute information in the first knowledge graph and the second knowledge graph, entity alignment can be realized, and through continuous iteration and expansion training, the structure information and the attribute information are complementary and enhanced, the expansion of the entity pair is realized, and the entity pair set is generated. The entity pair set includes multiple entity pairs, and the entity pair is a first entity in the first knowledge graph and a second entity in the second knowledge graph having an alignment relationship with the first entity.

[0070] S104, inputting the preset field rule and the entity pair set into a large language model to obtain a target entity pair set output by the large language model.

[0071] The target entity pair set includes multiple target entity pairs, and the target entity pair includes a first entity and a second entity similar to the first entity.

[0072] The preset domain rule is a rule set according to a corresponding domain. For example, the preset domain rule is that the traffic usage of an Internet of Things card within a certain usage period is less than 100M, which is a small traffic scenario. When it is obtained that the traffic usage of a to-be-monitored Internet of Things card is less than 100M within the same usage period, the attribute of the to-be-monitored Internet of Things card meets the preset domain rule, and it is considered that the attributes of the two entities are the same.

[0073] S105, generate a plurality of knowledge graph communities according to the set of target entity pairs, and monitor the Internet of Things card based on the knowledge graph communities to find fraudulent Internet of Things cards.

[0074] The knowledge graph community connects entities with similar or identical attributes and correlation, improves the correlation between entities, and thus makes the monitoring of the Internet of Things card more comprehensive, mines potential risks of the Internet of Things card, and improves the security of the Internet of Things card.

[0075] The data processing method for the Internet of Things card provided in the embodiments of the present application performs data enhancement on entities in the first knowledge graph and the second knowledge graph generated by the data of the Internet of Things card about structural information and attribute information, to generate a set of data-enhanced entity pairs, the set of data-enhanced entity pairs realizes expansion of the number of entities in a preset entity type, to generate more entity alignment results, and further screens the set of entity pairs in combination with a preset domain rule and a large language model to generate a set of target entity pairs, to obtain entity alignment results with higher similarity, connects the target entity pairs that have been expanded and screened through a risk graph community, realizes more comprehensive monitoring of the Internet of Things card, mines potential risks of the Internet of Things card, and improves the security of the Internet of Things card.

[0076] Figure 2 The flowchart of the data processing method for the Internet of Things card provided in the present application Figure 2 As shown in Figure 1 the present embodiment is based on Figure 3 the embodiment, the data processing method for the Internet of Things card is described in detail, and the method comprises the following steps:

[0077] S201, obtain Internet of Things card data in a preset region within a preset statistical period.

[0078] S202, obtain initial entities according to the Internet of Things card data and a preset entity type.

[0079] The preset entity type includes an Internet of Things card and a geographic entity.

[0080] The geographic entity includes a roaming province and a roaming city.

[0081] For example, the initial entities are: an Internet of Things card, Yunnan, and Kunming.

[0082] The preset attribute type includes at least one of traffic, access high-risk times, or binding change times.

[0083] S203, attribute information of the initial entity and relationships between the initial entities are extracted according to the initial entity, the preset attribute type, and the Internet of Things card data.

[0084] For example, the attribute information of the initial entity is: Internet of Things card-traffic-300M, and the relationship between the initial entities is: Internet of Things card-roaming location-Yunnan / Kunming.

[0085] S204, a first knowledge graph set is constructed according to the relationships between the initial entities.

[0086] S205, a second knowledge graph set is constructed according to the attribute information of the initial entity.

[0087] S206, an aligned entity set that has been marked is obtained according to the first knowledge graph set and the second knowledge graph set.

[0088] According to running data, entity alignment and marking are performed between the initial entities in the first knowledge graph and the second knowledge graph in advance, and an aligned entity can be obtained. The aligned entity set includes multiple aligned entities.

[0089] S207, based on the aligned entity set, entity alignment is enhanced by alternately using a TransE component and a pseudo twin network until the TransE component and the pseudo twin network no longer predict new aligned entities, and a data-enhanced entity pair set is obtained.

[0090] The TransE component is used to learn embedding of entities in structure according to the aligned entity set and the first knowledge graph set, and a first aligned entity is obtained.

[0091] The pseudo twin network is used to learn embedding of entities in attribute information according to the aligned entity set and the second knowledge graph set, and a second aligned entity is obtained.

[0092] In the TransE model, using a known aligned relationship, an initial entity in one of the knowledge graphs is used to replace an initial entity in a triple in the other knowledge graph to form a new triple positive example. A nearest neighbor algorithm is used to replace a second initial entity in an aligned entity pair to generate a negative sample, that is, according to the nearest neighbor algorithm, n entities most similar to the replaced initial entity in cosine are selected as candidate entities for replacement.

[0093] A triple (h, r, t) e S is given, where h, t e E, r e R. E, R represent the initial entity set and the relation set in the knowledge graph respectively, and S represents the triple set in the knowledge graph. In the TransE model, h, r and t are represented by 1-dimensional vectors of length k, and it is assumed that for any triple (h, r, t), h + r ≈ t. According to this assumption, a margin-based objective function is defined as follows:

[0094]

[0095] Where d(x, y) represents the Euclidean distance between x and y, γ1>0, γ2>0 represent the margin hyperparameters, [x] + represents 0 when x < 0, (h ′ , r ′ , t ′ ) e S ′ represents the triple set after replacing the head entity or tail entity, which is the negative sample of the training triple.

[0096] Positive examples and negative samples jointly act on the training process of the model in the TransE model, which promotes the improvement of model performance through defining correct entity relations, enhancing the discrimination ability of the model, improving the generalization ability of the model, and avoiding overfitting.

[0097] In each iteration, the TransE component is used to learn the structural embedding of entities, and the pseudo-twin network is used to learn the entity embedding based on attribute information.

[0098] The pseudo-twin network learns the entity embedding representation based on the attribute information of the two knowledge graphs, and then uses some trained metrics to evaluate the similarity between entities. Bidirectional GRU units are used to extract features at the character level of attribute values, and shared attention matrices are used to act on attribute types and attribute values to form a joint attention mechanism.

[0099] The embedding similarity of entity pairs in the first knowledge graph and the second knowledge graph is calculated, and a threshold is used for filtering to generate all candidate aligned entity pairs in the form of a bipartite graph. Then the best bipartite graph matching algorithm is used to obtain the data-enhanced entity pair set.

[0100] By alternately using structure information and attribute information to align entities, the data-enhanced entity pair set can be continuously iteratively expanded.

[0101] For example, if the initial state of the first knowledge graph and the second knowledge graph is:

[0102] Relationship: Internet card A - binding device - smart water meter; Internet card B - binding device - smart electricity meter.

[0103] Attributes: IoT SIM - ID; IoT SIM - Operator; IoT SIM - Activation Date.

[0104] First round of expansion: TransE

[0105] New entity: No new entity is directly discovered, but the TransE model may recognize that IoT SIM A and IoT SIM B are highly similar in their flow usage patterns through the similarity in vector space.

[0106] New relationship: Similar Flow Pattern. The TransE model infers this relationship between IoT SIM A and IoT SIM B because their flow usage patterns are close in the vector space.

[0107] Second round of expansion: Pseudo Twins Network

[0108] New entity: Pseudo Twins Network analyzes the geographical location information of IoT SIM A and IoT SIM B and finds that they are both located in the same commercial area, and there are also multiple IoT SIMs in this area. Therefore, the Pseudo Twins Network infers the new entity of Commercial Area IoT SIM Cluster.

[0109] New relationship: Cluster Member. The Pseudo Twins Network establishes this relationship between IoT SIM A, IoT SIM B, and the Commercial Area IoT SIM Cluster, indicating that they are members of the cluster.

[0110] Third round of expansion: TransE (based on new information)

[0111] New relationship: Based on the new entity of Commercial Area IoT SIM Cluster, the TransE model can further analyze the flow usage patterns of IoT SIMs within the cluster and find that in addition to the original Similar Flow Pattern, these IoT SIMs also exhibit the commonality of high flow usage during specific time periods (such as 9 am to 5 pm on weekdays). Therefore, the TransE model can infer the new relationship of Peak Hour High Flow and apply it between IoT SIMs within the cluster.

[0112] Fourth round of expansion: Pseudo Twins Network (refinement)

[0113] New relationship: The pseudo-twin network can further analyze the operation data of the business district IoT card cluster and find that the IoT cards in the cluster also exhibit certain similarities in signal strength, network latency, etc., and these characteristics are greatly influenced by the regional environment. Therefore, the pseudo-twin network can refine the region dependency (Region Dependency) relationship and specify it as region signal dependency (Region Signal Dependency) and region latency dependency (Region Latency Dependency) to more accurately describe the relationship between the IoT cards in the cluster and the regional environment.

[0114] After the alternation expansion of TransE and the pseudo-twin network, the first knowledge graph and the second knowledge graph not only contain the basic information of the IoT card and the binding relationship with the device, but also add entities such as similar traffic patterns, business district IoT card clusters, and new relationships such as peak period high traffic, region signal dependency, and region latency dependency. These newly added entities and relationships expand the entities of the first knowledge graph and the second knowledge graph, obtaining a data-enhanced entity pair set, which can more comprehensively reflect the operation of the IoT card and the interaction with the environment.

[0115] S208、According to each entity pair in the entity pair set, the similarity between the first entity and the second entity is obtained according to the cosine similarity algorithm.

[0116] Generally, the first entity corresponds to multiple second entities, and through the similarity calculation of the first entity and the second entity, the correlation degree result between entities can be obtained, which is convenient for the expansion of entity relationships.

[0117] S209、According to the similarity between the first entity and the second entity, for each first entity, the K most similar second entities are obtained, where K is an integer.

[0118] S210、According to the first entity and the K second entities, a new entity pair set is obtained.

[0119] S211、The pre-set field rule is input into the large language model.

[0120] The pre-set field rule includes at least two field rules, and each field rule is used to indicate whether the entity alignment is met between the difference data.

[0121] For example, the pre-set field rule is:

Field rule 1: IoT card uses less than 100M traffic in a day as small traffic. Field rule 2: Device binding frequency reaches 10 times in the last 7 days as frequent device binding. Rule N: …

[0122] S212, input the instruction information and the entity pair set to the large language model, and obtain a target entity pair set output by the large language model.

[0123] The instruction information is used to instruct the large language model to judge the similarity between the first entity and the second entity, and the instruction information is also used to instruct the output content of the large language model.

[0124] For example, in combination with the above-mentioned preset field rule, the instruction information is:

Please judge the similarity between the candidate entity and the target entity from the perspective of a language expert, and combine your knowledge with the field rules set by me, and output in the following format: {“Is it the same type of entity”:“Yes or no”,“Reason explanation”:“Please write down the thinking process”}

[0125] Target entity:

Entity type: Internet of Things card, roaming province: Yunnan, roaming city: Kunming, daily traffic usage: 30M, access to high-risk areas: 3 times, change the binding device within 7 days: 15 times...

[0126] Candidate entity 1:

Entity type: Internet of Things card, roaming province: Yunnan, roaming city: Kunming, daily traffic usage: 70M, access to high-risk areas: 5 times, change the binding device within 7 days: 22 times...

[0127] After inputting the instruction information and the entity pair set to the large language model, the result given by the large language model can be obtained: {“Is it the same type of entity”:“Yes”,“Reason explanation”:“The target entity and the candidate entity are slightly different in the number of times of accessing high-risk areas, but according to common sense, they are probably the same type of entity. First of all, the types of the two entities are consistent, which meets the consistency. The province and city of roaming are completely the same, which meets the consistency. The target entity's daily traffic usage is 30M, while the candidate entity's daily usage is 70M, according to the expert rule, they both belong to the attribute of small traffic, so the traffic usage meets the consistency. The number of times of changing the binding device within 7 days of the target entity and the candidate entity is 15 times and 22 times respectively, according to the expert rule, both of them belong to the attribute of frequent device change, which meets the consistency. In summary, except for the slight difference in the number of times of accessing high-risk areas, other attributes meet the consistency, so it can be basically determined that the target entity and the candidate entity belong to the same type of entity.”}.

[0128] By inputting the instruction information and the entity pair set to the large language model, and combining the preset field rule, the matching and screening of the target entity pair can be realized.

[0129] S213, according to the target entity pair set, draw a knowledge graph community, and in the knowledge graph community, mark the entities in the first knowledge graph set and the second knowledge graph set.

[0130] The entity type is an IoT card, and its annotation color is different from other entities.

[0131] In the first knowledge graph and the second knowledge graph,

[0132] Entity: IoT card

[0133] Property: activation date - January 1, 2000; traffic: 1G; device type: smart water meter, smart electricity meter, smart security camera

[0134] Relationship: binding device

[0135] After the expansion of TransE and pseudo-twin networks, new relationships or new entities can be obtained. New entities can be high-traffic IoT cards (if a certain IoT card consistently exhibits high-traffic usage characteristics, the TransE model may infer that it is a new entity category representing high-traffic demand IoT cards by comparing its traffic usage patterns with other IoT cards), and specific regional IoT card clusters (pseudo-twin networks may discover that multiple IoT cards are concentrated in a certain area and exhibit similar running characteristics (such as network delay, signal strength, etc.) by analyzing their geographic location information. Based on this information, pseudo-twin networks can infer a new entity); new relationships can be similar traffic patterns (if multiple IoT cards exhibit similar traffic usage patterns (such as peak hours, periodic changes, etc.), the TransE model can learn these patterns and infer that there is a "similar traffic pattern" relationship between these IoT cards), and regional dependence (if pseudo-twin networks find that the performance (such as data transmission speed, connection stability) of a certain IoT card is highly related to other IoT cards in the same area, then it can be inferred that there is a "regional dependence" relationship between these IoT cards, that is, their performance is affected by common regional factors).

[0136] Suppose an IoT card (IoT SIM Card A) is bound to a smart security camera located in a certain business district in City A. Through the TransE model, the traffic usage pattern of IoT SIM Card A is very similar to that of another IoT card (IoT SIM Card B) bound to a smart electricity meter, both of which exhibit lower night traffic and higher daytime traffic characteristics. Therefore, we can infer that there is a "similar traffic pattern" relationship between IoT SIM Card A and IoT SIM Card B.

[0137] Meanwhile, the pseudo twin network can discover that IoT SIM Card A has similar characteristics in signal strength, network delay, etc. with other multiple Internet of Things cards (such as IoT SIM Card C, D, etc.) in the business district by analyzing the geographical location information and running data of IoT SIM Card A. Based on this information, the pseudo twin network can infer a new entity-“business district Internet of Things card cluster”, and add IoT SIM Card A, B, C, D, etc. to this cluster, and establish the “regional dependence” relationship between them.

[0138] The knowledge graph community not only contains the structural information and attribute information of the entities in the first knowledge graph and the second knowledge graph, but also extends more entities and relationships, improving the coverage and accuracy of the risk community.

[0139] And by explicitly labeling the entities in the first knowledge graph set and the second knowledge graph set, it is convenient to accurately judge and distinguish the association relationship of the Internet of Things card.

[0140] S214, determining the Internet of Things card to be monitored according to the association relationship of the Internet of Things card with other entities or attributes.

[0141] S215, monitoring the Internet of Things card to be monitored to find fraudulent Internet of Things cards.

[0142] The data processing method of the Internet of Things card provided by the embodiment of the application, through the TransE component and the pseudo twin network, the initial entities in the Internet of Things card data are data enhanced to generate a set of data-enhanced entity pairs. The set of data-enhanced entity pairs facilitates the discovery of the association between entities on a wider scale and the more comprehensive risk mining of the Internet of Things card. The difference data is indicated by the pre-set domain rule, and the entity alignment is performed based on the pre-set domain rule by the large language model. The similarity between the data-enhanced entities is further screened, so that the knowledge graph community is more comprehensive and accurate. And by labeling the Internet of Things card and the entity, it is convenient to distinguish the relationship between the entities or the attributes of the entities, so as to clearly discover the association of the entities in the knowledge graph community, so as to monitor the Internet of Things to be detected and find fraudulent Internet of Things cards.

[0143] Figure 3 The structure diagram of the data processing device of the Internet of Things card provided by the application is shown in Figure 4 As shown in the figure, the data processing device 30 of the Internet of Things card provided by the embodiment includes:

[0144] The data acquisition module 301 is configured to acquire the Internet of Things card data in the preset area in the preset statistical period, wherein the Internet of Things card data includes the running data of each Internet of Things card in the statistical period.

[0145] The atlas acquisition module 302 is configured to acquire a first knowledge graph set and a second knowledge graph set according to the Internet of Things card data, the preset entity type and the preset attribute type, wherein a first knowledge graph in the first knowledge graph set includes structure information, and a second knowledge graph in the second knowledge graph set includes attribute information.

[0146] The data enhancement module 303 is configured to acquire a data-enhanced entity-aligned entity pair set according to the first knowledge graph set and the second knowledge graph set, wherein the entity pair set includes a first entity in the first knowledge graph and a second entity in the second knowledge graph that has an entity alignment relationship with the first entity.

[0147] The target entity pair acquisition module 304 is configured to input the preset domain rule and the entity pair set to a large language model, and acquire a target entity pair set output by the large language model, wherein the target entity pair set includes a second entity similar to the first entity.

[0148] The knowledge graph community generation module 305 is configured to generate a plurality of knowledge graph communities according to the target entity pair set, and monitor the Internet of Things card based on the knowledge graph communities to find fraudulent Internet of Things cards.

[0149] The data processing apparatus for the Internet of Things card provided in this embodiment can execute the method provided in the method embodiment, and has similar implementation principles and technical effects, which will not be described here.

[0150] Figure 4 The data processing apparatus for the Internet of Things card provided in this embodiment is shown in a structural schematic diagram. As shown in the figure, ​ The electronic device 40 provided in this embodiment includes at least one processor 401 and a memory 402. Optionally, the device 40 further includes a communication component 403. The processor 401, the memory 402 and the communication component 403 are connected through a bus 404.

[0151] In the specific implementation process, the at least one processor 401 executes the computer execution instructions stored in the memory 402, so that the at least one processor 401 executes the method described above.

[0152] The specific implementation process of the processor 401 can refer to the method embodiment described above, and has similar implementation principles and technical effects, which will not be described here.

[0153] In the above embodiments, it should be understood that the processor can be a central processing unit (CPU) and can also be other general-purpose processors, digital signal processors (DSP), application specific integrated circuits (ASIC), etc. The general-purpose processor can be a microprocessor or can also be any conventional processor. The steps of the method disclosed in combination with the application can be directly embodied as hardware processor execution or combined with hardware and software modules in the processor for execution.

[0154] The memory can include a random access memory (RAM) and can also include a non-volatile memory (NVM), such as at least one disk memory.

[0155] The bus can be an industry standard architecture (ISA) bus, a peripheral component (PCI) bus, an extended industry standard architecture (EISA) bus, etc. The bus can be divided into an address bus, a data bus, a control bus, etc. For ease of representation, the bus in the drawings of the present application does not limit to only one bus or one type of bus.

[0156] The present application also provides a computer program product comprising a computer program which, when executed by a processor, implements the above method.

[0157] The present application also provides a computer readable storage medium having computer execution instructions stored therein, wherein when a processor executes the computer execution instructions, the above method is implemented.

[0158] The above readable storage medium can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic memory, flash memory, magnetic disk or optical disk. The readable storage medium can be any available medium that can be accessed by a general-purpose or special-purpose computer.

[0159] An example readable storage medium is coupled to the processor such that the processor can read information from the readable storage medium and can write information to the readable storage medium. Of course, the readable storage medium can also be a part of the processor. The processor and the readable storage medium can be located in an application specific integrated circuit (ASIC). Of course, the processor and the readable storage medium can also exist as discrete components in the device.

[0160] The division of units is only a logical functional division, and in actual implementation, there can be another division manner, for example, a plurality of units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the coupling or direct coupling or communication connection between the units shown or discussed can be indirect coupling or communication connection through some interfaces, devices or units, and can be electrical, mechanical or other forms.

[0161] The units described as separate components can or can not be physically separated, and the components shown as units can or can not be physical units, that is, can be located in one place, or can be distributed on a plurality of network units. Part or all of the units can be selected according to actual needs to achieve the purpose of the embodiment scheme.

[0162] In addition, the functional units in each embodiment of the present application can be integrated in one processing unit, or each unit can be physically present separately, or two or more units can be integrated in one unit.

[0163] If the functions are realized in the form of software function units and sold or used as independent products, they can be stored in a computer readable storage medium. Based on this understanding, the technical solutions of the present application or the part of the present application that essentially contributes to the prior art or the part of the technical solutions can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes a plurality of instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the embodiments of the present application. The foregoing storage medium includes a U disk, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk, and various program code storage media.

[0164] Those skilled in the art can understand that all or part of the steps of the above-mentioned method embodiments can be completed by program instruction related hardware. The foregoing program can be stored in a computer readable storage medium. The program executes to perform the steps of the above-mentioned method embodiments; and the foregoing storage medium includes various media capable of storing program codes, such as ROM, RAM, magnetic disk, or optical disk.

[0165] Finally, it should be noted that other embodiments of the present application will readily occur to those skilled in the art upon consideration of the specification and practice of the present application disclosed herein. The present application is intended to include all such variations, uses, or adaptations of the application in which the general principles of the application are used to best advantage and encompassed within its scope. The present application is not limited to the precise structures described and shown in the accompanying drawings and figures, and can be practiced with variation of modifications and alterations without departing from the scope of the present application. The scope of the present application is limited only by the claims appended hereto.

Claims

1. A data processing method for an Internet of Things (IoT) card, characterized in that, include: Obtain IoT card data in a preset area within a preset statistical period, wherein the IoT card data includes the operating data of each IoT card within the statistical period; Based on the IoT card data, preset entity type and preset attribute type, a first knowledge graph set and a second knowledge graph set are obtained, wherein the first knowledge graph in the first knowledge graph set includes structural information, and the second knowledge graph in the second knowledge graph set includes attribute information; Based on the first knowledge graph set and the second knowledge graph set, a set of data-enhanced entity-aligned entity pairs is obtained, wherein the set of entity pairs includes a first entity in the first knowledge graph and a second entity in the second knowledge graph that has an entity alignment relationship with the first entity; The preset domain rules and the set of entity pairs are input into the large language model to obtain the target entity pair set output by the large language model. The target entity pair set includes a first entity and a second entity similar to the first entity. Based on the target entity pair set, multiple knowledge graph communities are generated. Based on the knowledge graph communities, IoT cards are monitored to detect fraudulent IoT cards.

2. The method according to claim 1, characterized in that, The step of obtaining a first knowledge graph set and a second knowledge graph set based on the IoT card data, preset entity types, and preset attribute types includes: Based on the IoT card data and the preset entity type, an initial entity is obtained; wherein, the preset entity type includes IoT card and geographic entity, wherein the geographic entity includes roaming province and roaming city, and the preset attribute type includes at least one of traffic, number of high-risk accesses, or number of times the binding has been changed; Based on the initial entity, the preset attribute type, and the IoT card data, extract the attribute information of the initial entity and the relationship between the initial entities; Based on the relationships between the initial entities, a first knowledge graph set is constructed; Based on the attribute information of the initial entity, a second knowledge graph set is constructed.

3. The method according to claim 2, characterized in that, Before inputting the preset domain rules and the entity pair set into the large language model, the method further includes: For each entity pair in the entity pair set, the similarity between the first entity and the second entity is obtained using the cosine similarity algorithm. Based on the similarity between the first entity and the second entity, for each first entity, obtain the K most similar second entities, where K is an integer; Based on the first entity and the K second entities, a new set of entity pairs is obtained; The step of inputting the preset domain rules and the entity pair set into the large language model includes: The preset domain rules and the new set of entity pairs are input into the large language model.

4. The method according to claim 1, characterized in that, The step of inputting the preset domain rules and the entity pair set into the large language model to obtain the target entity pair set output by the large language model includes: The preset domain rules are input into the large language model. The preset domain rules include at least two domain rules, each of which is used to indicate whether entity alignment is satisfied between the differential data. The instruction information and the set of entity pairs are input into the large language model to obtain the target entity pair set output by the large language model; wherein, the instruction information is used to instruct the large language model to determine the similarity between the first entity and the second entity, and the instruction information is also used to instruct the output content of the large language model.

5. The method according to claim 1, characterized in that, The monitoring of IoT cards based on the knowledge graph community to detect fraudulent IoT cards includes: The knowledge graph community is drawn, and entities in the first knowledge graph set and the second knowledge graph set are explicitly labeled in the knowledge graph community. Entities of type IoT card are labeled with a different color than other entities. Based on the association between the IoT card and other entities or attributes, determine the IoT card to be monitored; The IoT cards to be monitored are monitored to detect fraudulent IoT cards.

6. The method according to claim 1, characterized in that, The step of obtaining a set of data-enhanced entity pairs based on the first knowledge graph set and the second knowledge graph set includes: Based on the first knowledge graph set and the second knowledge graph set, obtain the set of already labeled aligned entities; Based on the aligned entity set, entity alignment is enhanced by alternating between the TransE component and the pseudo-Twin network until the TransE component and the pseudo-Twin network no longer predict new aligned entities, resulting in a data-enhanced entity pair set. The TransE component is used to learn the structural embedding of entities based on the aligned entity set and the first knowledge graph set to obtain the first aligned entity; The pseudo-twin network is used to learn the embedding of entities in attribute information based on the aligned entity set and the second knowledge graph set, so as to obtain the second aligned entity.

7. A data processing device for an Internet of Things (IoT) card, characterized in that, include: The data acquisition module is used to acquire IoT card data in a preset area within a preset statistical period, wherein the IoT card data includes the operating data of each IoT card within the statistical period; The knowledge graph acquisition module is used to acquire a first knowledge graph set and a second knowledge graph set based on the IoT card data, a preset entity type, and a preset attribute type. The first knowledge graph in the first knowledge graph set includes structural information, and the second knowledge graph in the second knowledge graph set includes attribute information. The data augmentation module is used to obtain a set of entity pairs for data augmentation and entity alignment based on the first knowledge graph set and the second knowledge graph set, wherein the set of entity pairs includes a first entity in the first knowledge graph and a second entity in the second knowledge graph that has an entity alignment relationship with the first entity; The target entity pair acquisition module is used to input the preset domain rules and the entity pair set into the large language model, and obtain the target entity pair set output by the large language model. The target entity pair set includes a first entity and a second entity similar to the first entity. The knowledge graph community generation module is used to generate multiple knowledge graph communities based on the target entity pair set, and to monitor IoT cards based on the knowledge graph communities to detect fraudulent IoT cards.

8. A data processing device for an Internet of Things (IoT) card, characterized in that, include: Memory, processor; The memory stores computer-executed instructions; The processor executes computer execution instructions stored in the memory, causing the processor to perform the method as described in any one of claims 1-6.

9. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer-executable instructions, which, when executed by a processor, are used to implement the method as described in any one of claims 1-6.

10. A computer program product, characterized in that, Includes a computer program that, when executed by a processor, implements the method described in any one of claims 1-6.

Citation Information

Patent Citations

  • Electronic card risk early warning method and device based on knowledge graph

    CN113094518A

  • Risk identification method and device, computer equipment and storage medium

    CN117196846A