Abnormal account detection method, device and electronic device based on privacy computing

By setting up a privacy computing module in the trusted execution environment of each business party, data encryption and intersection operations are performed, security risks and privacy protection problems caused by centralized data processing in the existing technology are solved, and safe and efficient abnormal account detection is achieved.

CN119416207BActive Publication Date: 2025-06-06ZHEJIANG YIDE RONGXIN SOFTWARE CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411997693.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-31
Publication Date
2025-06-06
Estimated Expiration
2044-12-31

AI Technical Summary

Technical Problem

The existing abnormal account identification method depends on the centralized processing of data, resulting in data security risks and privacy protection issues, making it difficult to effectively balance the needs of risk prevention and control and privacy protection.

Method used

The abnormal account detection method based on privacy computing is adopted. By setting up a privacy computing module in the trusted execution environment of each business party, data encryption and intersection operations are performed to ensure that data is encrypted and processed and exchanged locally, and data leakage is avoided.

Benefits of technology

It realizes abnormal account detection while ensuring data security and privacy, avoids large-scale data leakage problems caused by centralized processing, and improves data security and privacy.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119416207B_ABST
    Figure CN119416207B_ABST
Patent Text Reader

Abstract

The present disclosure provides an abnormal account detection method, device and electronic device based on privacy computing, which relates to the field of computer technology. It includes: receiving an abnormal detection request sent by a business execution module of a first business party; encrypting the first data corresponding to the target identifier in the first business party, sending the obtained first encryption result to multiple second business parties, and receiving the second encryption results obtained by multiple second business parties based on the abnormal detection request; performing an intersection operation on the first encryption result and the second encryption result to obtain an intersection operation result; sending the intersection operation result to a scheduling system, and receiving a target encrypted data block sent by the scheduling system; based on the target encrypted data block, performing abnormal account detection through an abnormal account detection model, and sending the obtained first detection result to multiple second business parties; receiving the second detection result sent by the second business party, and determining the abnormal account detection result based on the first detection result and the second detection result.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the field of computer technology, and in particular to an abnormal account detection method, device and electronic device based on privacy computing. Background Art

[0002] Existing methods for identifying abnormal accounts generally rely on centralized data processing, that is, collecting multiple data related to an account on a single platform for abnormal identification. Although this approach facilitates centralized computing and decision-making, it also creates significant data security risks. For example, when centrally stored data encounters external attacks or internal omissions, it is very easy to have large-scale data leakage, and it does not comply with the increasingly stringent requirements of personal information protection laws and regulations, and it is difficult to effectively balance the needs of risk prevention and control and privacy protection. Summary of the invention

[0003] The present disclosure provides a method, device and electronic device for detecting abnormal accounts based on privacy computing to at least solve the above technical problems existing in the prior art.

[0004] According to a first aspect of the present disclosure, there is provided an abnormal account detection method based on privacy computing, which is applied to a privacy computing module of a first business party, and the privacy computing module is set in a trusted execution environment of the first business party. The method comprises: receiving an abnormal account detection request sent by a business execution module of the first business party, and the business execution module is used to send the abnormal account detection request to the privacy computing module and multiple second business parties, and the abnormal account detection request includes a target identifier of data requested by the first business party to be provided by the second business party; encrypting first data corresponding to the target identifier in the first business party, sending the obtained first encryption result to multiple second business parties, and receiving multiple second business parties based on a second encryption result obtained from the anomaly detection request; performing an intersection operation on the first encryption result and the second encryption result to obtain an intersection operation result; sending the intersection operation result to the scheduling system, and receiving a target encrypted data block sent by the scheduling system, wherein the target encrypted data block is a part of all encrypted data blocks obtained by the scheduling system by slicing the intersection operation results sent by all business parties; performing abnormal account detection through an abnormal account detection model based on the target encrypted data block, and sending the obtained first detection result to multiple second business parties; receiving second detection results sent by multiple second business parties, and determining the abnormal account detection result based on the first detection result and the second detection result.

[0005] In one possible implementation, the anomaly detection request also includes identity information of the first business party, and the business execution module sends the anomaly detection request to multiple second business parties in the following manner: the business execution module sends the anomaly detection request to a blockchain node; the blockchain node verifies the identity information of the first business party based on smart contracts and permission rules; in response to successful verification, the blockchain node sends the anomaly detection request to multiple second business parties.

[0006] In one possible implementation manner, the encryption processing of the first data corresponding to the target identifier in the first business party includes: based on the target identifier, determining the first data from the database of the first business party; performing hash processing on the first data to obtain a first hash value; and symmetrically encrypting the first hash value based on a hardware encryption card to obtain the first encryption result.

[0007] In one possible implementation, the scheduling system sends corresponding target encrypted data blocks to the privacy computing modules of all business parties in the following manner: based on the data type and the association relationship between the data, the intersection operation results received from all business parties are cut into blocks to obtain encrypted data blocks; the status information of the trusted execution environment of all the business parties is obtained, and the status information includes at least one of the operating status, response time, CPU usage, memory occupancy, network bandwidth, task queue length and task execution time of the trusted execution environment; based on the status information and the priority of the encrypted data block, the allocation strategy of the encrypted data block is determined by a weighted polling algorithm; based on the allocation strategy, the corresponding target encrypted data block is sent to the privacy computing modules of all business parties.

[0008] In one possible implementation, based on the allocation strategy, the corresponding target encrypted data blocks are sent to the privacy computing modules of all business parties, including: based on the allocation strategy, determining the target encrypted data block corresponding to each of the privacy computing modules; based on the status information, adjusting the size of the target encrypted data block to obtain an adjusted target encrypted data block; and sending the adjusted target encrypted data block to the corresponding privacy computing module.

[0009] In one possible implementation, an abnormal account detection method based on privacy computing also includes: performing abnormal account detection based on the first data to obtain a third detection result; and determining the abnormal account detection result based on the first detection result, the second detection result and the third detection result.

[0010] In one possible implementation, an abnormal account detection method based on privacy computing also includes: hashing the first detection result based on a national secret algorithm through a hardware encryption card to obtain a second hash value; sending the second hash value to a blockchain node, the blockchain node verifies the second hash value based on a consensus algorithm, and stores the verified second hash value in a distributed ledger.

[0011] In one possible implementation, an abnormal account detection method based on privacy computing also includes: encrypting the abnormal account detection result based on a national encryption algorithm through a hardware encryption card to obtain an encrypted detection result; sending the encrypted detection result to a business execution module of the first business party, and the business execution module decrypts the encrypted detection result to obtain the abnormal account detection result.

[0012] According to a second aspect of the present disclosure, there is provided an abnormal account detection device based on privacy computing, which is applied to a privacy computing module of a first business party, and the privacy computing module is arranged in a trusted execution environment of the first business party. The device comprises: a receiving module, which is used to receive an abnormality detection request sent by a business execution module of the first business party, and the business execution module is used to send the abnormality detection request to the privacy computing module and multiple second business parties, and the abnormality detection request includes a target identifier of the data requested by the first business party to be provided by the second business party; an encryption module, which is used to encrypt first data corresponding to the target identifier in the first business party; a sending module, which is used to send the obtained first encryption result to multiple second business parties; the receiving module is also used to receive multiple second business parties based on the abnormality detection request a second encryption result obtained; a calculation module, used to perform an intersection operation on the first encryption result and the second encryption result to obtain an intersection operation result; the sending module, also used to send the intersection operation result to the scheduling system; the receiving module, also used to receive a target encrypted data block sent by the scheduling system, the target encrypted data block being a part of all encrypted data blocks obtained by the scheduling system by slicing the intersection operation results sent by all business parties; a detection module, used to perform abnormal account detection through an abnormal account detection model based on the target encrypted data block, and send the obtained first detection result to multiple second business parties; the receiving module, also used to receive second detection results sent by multiple second business parties; a determination module, used to determine the abnormal account detection result based on the first detection result and the second detection result.

[0013] According to a third aspect of the present disclosure, there is provided an electronic device, including:

[0014] at least one processor; and

[0015] a memory communicatively connected to the at least one processor; wherein,

[0016] The memory stores instructions that can be executed by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to perform the method described in the present disclosure.

[0017] According to a fourth aspect of the present disclosure, a non-transitory computer-readable storage medium storing computer instructions is provided, wherein the computer instructions are used to cause the computer to execute the method described in the present disclosure.

[0018] The present invention discloses an abnormal account detection method, device and electronic device based on privacy computing, which first receives an abnormal detection request sent by a business execution module of a first business party, encrypts the first data required for the abnormal detection request, sends the obtained first encryption result to multiple second business parties, and receives the second encryption results obtained by the multiple second business parties based on the abnormal detection request, then performs an intersection operation on the first encryption result and the second encryption result to obtain the intersection operation result, and sends the intersection operation result to a scheduling system, and receives a target encrypted data block sent by the scheduling system, and finally performs abnormal account detection based on the target encrypted data block through an abnormal account detection model, sends the obtained first detection result to multiple second business parties, and receives the second detection results sent by multiple second business parties, and determines the abnormal account detection result based on the first detection result and the second detection result. Therefore, multiple business parties encrypt the local data required for the anomaly detection request and exchange the encrypted local data with each other. Each business party performs an intersection operation on the local encrypted data and the encrypted data of other business parties to obtain the intersection operation result. The intersection operation result includes the encrypted data involved by all business parties. Therefore, in the subsequent calculation process, the business party will not obtain the non-matching data, real plaintext data and query intention of other business parties, thereby ensuring the security and privacy of each business party's data. In addition, the scheduling system will cut the intersection operation results of all business parties into blocks, and send the cut data blocks to different business parties respectively. Different business parties will perform abnormal account detection based on the data blocks. Finally, the detection results of all business parties are summarized to determine the anomaly detection results, thereby performing decentralized detection on the encrypted data required for the anomaly detection request, avoiding the problem of large-scale data leakage in centralized processing.

[0019] It should be understood that the content described in this section is not intended to identify the key or important features of the embodiments of the present disclosure, nor is it intended to limit the scope of the present disclosure. Other features of the present disclosure will become easily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS

[0020] The above and other objects, features and advantages of the exemplary embodiments of the present disclosure will become readily understood by reading the detailed description below with reference to the accompanying drawings. In the accompanying drawings, several embodiments of the present disclosure are shown in an exemplary and non-limiting manner, in which:

[0021] In the drawings, the same or corresponding reference numerals represent the same or corresponding parts.

[0022] Figure 1 The following is a schematic diagram showing the process of an abnormal account detection method based on privacy computing in an embodiment of the present disclosure. Figure 1 ;

[0023] Figure 2 The following is a schematic diagram showing the process of an abnormal account detection method based on privacy computing in an embodiment of the present disclosure. Figure 2 ;

[0024] Figure 3 The following is a schematic diagram showing the process of an abnormal account detection method based on privacy computing in an embodiment of the present disclosure. Figure 3 ;

[0025] Figure 4 A scenario diagram showing an abnormal account detection method based on privacy computing in an embodiment of the present disclosure Figure 1 ;

[0026] Figure 5 A scenario diagram showing an abnormal account detection method based on privacy computing in an embodiment of the present disclosure Figure 2 ;

[0027] Figure 6 A scenario diagram showing an abnormal account detection method based on privacy computing in an embodiment of the present disclosure Figure 3 ;

[0028] Figure 7 A schematic diagram of the structure of an abnormal account detection device based on privacy computing according to an embodiment of the present disclosure is shown;

[0029] Figure 8 A schematic diagram of the structure of an electronic device according to an embodiment of the present disclosure is shown. DETAILED DESCRIPTION

[0030] In order to make the purpose, features, and advantages of the present disclosure more obvious and easy to understand, the technical solutions in the embodiments of the present disclosure will be clearly and completely described below in conjunction with the drawings in the embodiments of the present disclosure. Obviously, the described embodiments are only part of the embodiments of the present disclosure, not all of the embodiments. Based on the embodiments in the present disclosure, all other embodiments obtained by those skilled in the art without creative work are within the scope of protection of the present disclosure.

[0031] Figure 1 The following is a schematic diagram showing the process of an abnormal account detection method based on privacy computing in an embodiment of the present disclosure. Figure 1 ,like Figure 1 As shown, a method for detecting abnormal accounts based on privacy computing is applied to a privacy computing module of a first business party, and the privacy computing module is set in a trusted execution environment of the first business party. The method includes:

[0032] Step S101: receiving an anomaly detection request sent by a service execution module of a first service party.

[0033] In this embodiment, each business party includes a business execution module, a privacy computing module and a trusted execution environment (TEE), and the privacy computing module is set in the trusted execution environment of the business party. The business execution module is used to support the business operation of the business party. The business execution module includes the database of the business party and the computing call module for calling the data. The business execution module can be used to initiate abnormal account detection, and the business party that initiates abnormal account detection is the first business party. In one example, the business party can be a financial institution, such as a bank and an insurance institution, or a website platform, such as a shopping website, a social networking website, and an entertainment website. The business party can also be other platforms or institutions, which are not limited by this disclosure. Among them, the trusted execution environment protects the data processing process by combining hardware and software. The trusted execution environment can provide an isolated environment for the data processing process, such as dividing the system memory of the first business party into a secure area (that is, encrypted memory) and a non-secure area. The data processing process is executed in the secure area and isolated from the external operating system and other applications.

[0034] In this embodiment, when it is necessary to initiate abnormal account detection, the business execution module of the first business party may trigger an abnormal detection request in response to a user operation or in response to a trigger condition. The trigger condition may be that the time since the last abnormal account detection was initiated reaches a time threshold, or the number of operations related to the business of the first business party, such as transfer operations or shopping operations of a certain account, reaches a number threshold, etc., and then send the abnormal detection request to the privacy computing module of the first business party. Since the present disclosure adopts multi-party secure computing (MPC, Multi-Party Computation) to perform abnormal account detection, the business execution module of the first business party also needs to send the abnormal detection request to the privacy computing modules of other multiple second business parties. The abnormal detection request includes a target identifier of the data requested by the first business party to be provided by the second business party. For example, if the first business party requests the second business party to provide relevant data of account A, the target identifier may be a unique identifier of account A, such as account information or ID card information of account A; if the first business party requests the second business party to provide data within a certain time period, the target identifier may be the start timestamp and end timestamp of the time period.

[0035] Figure 4 A scenario diagram showing an abnormal account detection method based on privacy computing in an embodiment of the present disclosure Figure 1 ,like Figure 4 As shown, the first business party includes a business execution module A, a privacy computing module A and a trusted execution environment A, wherein the trusted execution environment A includes a trusted computing program and an encrypted memory, the privacy computing module A is set in the encrypted memory, and the privacy computing module A includes a data model (which can be an abnormal account detection model) and a computing strategy; the second business party includes a business execution module B, a privacy computing module B and a trusted execution environment B, wherein the trusted execution environment B includes a trusted computing program and an encrypted memory, the privacy computing module B is set in the encrypted memory, and the privacy computing module B includes a data model and a computing strategy. The business execution module A can trigger an abnormal detection request and send the abnormal detection request to the privacy computing module A and the privacy computing module B to initiate abnormal account detection involving multiple parties. It should be emphasized that there can be multiple second business parties, and this disclosure does not limit their number.

[0036] Step S102: encrypt the first data corresponding to the target identifier in the first business party, send the obtained first encryption result to multiple second business parties, and receive the second encryption results obtained by the multiple second business parties based on the anomaly detection request.

[0037] In this embodiment, since the present disclosure adopts a multi-party secure computing method to perform abnormal account detection, the first business party needs to exchange data required for abnormal account detection with multiple second business parties. The privacy computing module of the first business party can encrypt the first data corresponding to the target identifier in the local data of the first business party, and send the obtained first encryption result to multiple second business parties; the privacy computing module of the second business party can encrypt the second data corresponding to the target identifier in the local data of the second business party, and send the obtained second encryption result to multiple other business parties. Thus, the first business party and the second business party exchange the encryption results of the data required for abnormal account detection. Among them, multi-party secure computing is a subfield of applied cryptography, which includes a series of cryptographic protocols and algorithms. Its goal is to enable each business party to perform related calculations with the input data of each business party without leaking their own input data, and obtain a joint calculation result.

[0038] Step S103, performing an intersection operation on the first encryption result and the second encryption result to obtain an intersection operation result.

[0039] In this embodiment, after the privacy computing module of the first business party obtains the first encryption result and the second encryption result, it can perform an intersection operation on the first encryption result and the second encryption result to obtain an intersection operation result. The intersection operation result includes the encrypted data involved by all business parties. When abnormal account detection is performed based on the intersection operation result, the business party will not obtain non-matching data, real plaintext data and query intentions of other business parties. Correspondingly, the privacy computing module of the second business party will also obtain the first encryption result and the local second encryption result of the first business party and other second business parties, and perform an intersection operation on the first encryption result and the second encryption result to obtain an intersection operation result. Among them, the private set intersection (PSI) algorithm is used between each business party to perform privacy intersection to obtain the intersection operation result.

[0040] Step S104, sending the intersection operation result to the scheduling system, and receiving the target encrypted data block sent by the scheduling system.

[0041] In this embodiment, after the privacy computing module of each business party obtains the corresponding intersection operation result, it will send the intersection operation result to the scheduling system. The scheduling system cuts the received intersection operation result into blocks to obtain multiple encrypted data blocks, and distributes the multiple encrypted data blocks to different business parties for processing. The encrypted data block received by each business party is the target encrypted data block corresponding to the business party, that is, the target encrypted data block is a part of all encrypted data blocks obtained by cutting the intersection operation results sent by all business parties into blocks by the scheduling system.

[0042] Step S105: Based on the target encrypted data block, abnormal account detection is performed through an abnormal account detection model, and the obtained first detection result is sent to multiple second business parties.

[0043] In this embodiment, the privacy computing module of the first business party can input the target encrypted data block into the abnormal account detection model, and the abnormal account detection model outputs a first detection result based on the target encrypted data block, and the first detection result can include the unique identifier of the abnormal account, the cause of the abnormality, and the classification, etc. The privacy computing module of the first business party sends the obtained first detection result to multiple second business parties; accordingly, the privacy computing module of the second business party can input the target encrypted data block received locally into the abnormal account detection model, and the abnormal account detection model outputs a second detection result based on the target encrypted data block, and the second detection result can include the unique identifier of the abnormal account, the cause of the abnormality, and the classification, etc. The privacy computing module of the second business party sends the obtained second detection result to other second business parties and the first business party. In one example, if the business party is a financial institution, the abnormal account in the first detection result can be a black market account or a fraudulent account, etc.; if the business party is a shopping website, the abnormal account in the first detection result can be an account with frequent returns. In another example, the abnormal account detection model can be trained based on the data of sample accounts that have been determined to be abnormal accounts.

[0044] In this embodiment, when the obtained first detection result is sent to multiple second business parties, an asymmetric encryption algorithm can be used to encrypt the first detection result, and the encrypted first detection result can be sent to the multiple second business parties to ensure data security.

[0045] Step S106, receiving second detection results sent by multiple second business parties, and determining abnormal account detection results based on the first detection results and the second detection results.

[0046] In this embodiment, the privacy computing module of the first business party will receive the second detection results sent by multiple second business parties, and then determine the abnormal account detection result based on the first detection result and the second detection result. For example, the intersection or union of the first detection result and the second detection result can be determined as the abnormal account detection result.

[0047] In the present disclosure, multiple business parties encrypt local data required for anomaly detection requests and exchange the encrypted local data with each other. Each business party performs an intersection operation on the local encrypted data and the encrypted data of other business parties to obtain an intersection operation result. The intersection operation result includes the encrypted data involved by all business parties. Therefore, in the subsequent calculation process, the business party will not obtain non-matching data, real plaintext data and query intentions of other business parties, thereby ensuring the security and privacy of each business party's data. In addition, the scheduling system will cut the intersection operation results of all business parties into blocks, and send the cut data blocks to different business parties respectively. Different business parties will perform abnormal account detection based on the data blocks. Finally, the detection results of all business parties are summarized to determine the anomaly detection results, thereby performing decentralized detection on the encrypted data required for the anomaly detection request, avoiding the problem of large-scale data leakage in centralized processing.

[0048] The advantages of this disclosure in the financial field are particularly prominent. Through privacy computing, model verification is carried out across financial institutions while ensuring data security, transcending the limitations of a single financial institution. With the help of privacy computing, the dimension of risk control data is broadened, and a risk mutual verification mechanism is established among various financial institutions. In addition, cross-financial institution data is combined to identify abnormal account buying and selling behaviors such as opening multiple cards across financial institutions and frequent account closings for a certain account.

[0049] In another embodiment, the anomaly detection request further includes identity information of the first business party. Before or after step S101, the business execution module may send the anomaly detection request to multiple second business parties in the following manner:

[0050] The business execution module sends an anomaly detection request to the blockchain node; the blockchain node verifies the identity information of the first business party based on the smart contract and permission rules; in response to the verification being successful, the blockchain node sends the anomaly detection request to multiple second business parties.

[0051] In this embodiment, multiple business parties are connected to the blockchain node, and the business execution module initiates an anomaly detection request based on demand. The anomaly detection request is first sent to the blockchain node. The blockchain adopts consortium chain technology. The business execution module of the first business party submits identity information to the blockchain through digital signatures, etc., that is, the anomaly detection request includes the identity information of the first business party in the form of digital signatures, etc. The blockchain node verifies the identity of the first business party according to the pre-set smart contract and permission rules, and feeds back the corresponding verification results to the second business party. Only when the identity and authority of the first business party meet the access rules, the anomaly detection request will enter the privacy computing module of the second business party.

[0052] like Figure 4As shown in the figure, the blockchain is connected to the trusted execution environment. In the blockchain trusted execution environment, plaintext data and confidential data are mixed and packaged. Confidential data is protected by cryptographic digital envelopes and can only be decrypted and executed after entering the trusted execution environment. At the same time, the generated account data is encrypted and stored. While protecting privacy, the blockchain trusted execution environment also provides a user data authorization mechanism. Transactions and data authorized by users can be accessed by third parties for data mining, statistics or information review. In terms of key management, the blockchain trusted execution environment hardware already supports autonomous distributed key protocols as a security base. The full life cycle management and maintenance of keys can be achieved based on the secure computing hardware base. At the same time, the complete trust root management mechanism, trusted startup and security design can fully guarantee the security protection of blockchain confidential data.

[0053] In another embodiment, the “encrypting the first data corresponding to the target identifier in the first business party” in step S102 includes:

[0054] Based on the target identifier, first data is determined from a database of the first business party; the first data is hashed to obtain a first hash value; and the first hash value is symmetrically encrypted based on a hardware encryption card to obtain a first encryption result.

[0055] In this embodiment, the privacy computing module of the first business party can first extract the first data indicated by the target identifier from the database, then perform hash processing on the first data to obtain a first hash value, and perform symmetrical encryption on the first hash value based on the hardware encryption card to obtain a first encryption result. Among them, the hardware encryption card adopts a high-performance encryption chip and supports the national secret encryption algorithm. The hardware encryption card and the node of the privacy computing module are connected through the PCI-E interface. During the calculation process, the data transmission between the hardware encryption card and the privacy computing module adopts an encrypted channel to ensure the security of the data. Correspondingly, the second business party also obtains the second encryption result in the same way as the first business party, which will not be repeated here.

[0056] Figure 2 The following is a schematic diagram showing the process of an abnormal account detection method based on privacy computing in an embodiment of the present disclosure. Figure 2 ,like Figure 2 As shown, in step S104, the scheduling system can send the corresponding target encrypted data block to the privacy computing modules of all business parties in the following manner:

[0057] Step S201, based on the data type and the association relationship of the data, the intersection operation results received from all business parties are divided into blocks to obtain encrypted data blocks.

[0058] In this embodiment, different types of data may require different processing methods, and it may be more efficient to process highly correlated data blocks together. Therefore, the privacy computing module of the first business party can segment the intersection operation results sent by all business parties based on the data type and the association relationship of the data to obtain encrypted data blocks. For example, when segmenting based on the data type, text data can be divided into the same encrypted data block, and image data can be divided into the same encrypted data block; when segmenting based on the association relationship of the data, multiple operation records of the same account can be placed in the same data block, which can make account behavior analysis more efficient.

[0059] Figure 6 A scenario diagram showing an abnormal account detection method based on privacy computing in an embodiment of the present disclosure Figure 3 ,like Figure 6 As shown, data A is divided into data blocks to obtain data blocks A1, A2, A3..., and data blocks A1, A2, A3... are further divided into data blocks, wherein data block A1 is divided into data blocks A11, A12, A13...; data B is divided into data blocks B1, B2, B3..., and data blocks B1, B2, B3... are further divided into data blocks, wherein data block B1 is divided into data blocks B11, B12, B13...

[0060] The encryption algorithm used in ordinary secure multi-party computing has extremely low computing efficiency when low hardware computing performance and large file byte streams are involved at the same time, which will produce abnormal expected results and is only suitable for scenarios with small data volumes. Therefore, in order to meet the privacy requirements of billions of account data, this disclosure optimizes the existing encryption algorithm process. On the basis of ensuring the encryption results, it optimizes the computing efficiency and memory usage. By introducing block processing to divide large files into several small blocks, and obtain the minimized optimal data level, each of which is encrypted separately. This can not only reduce the load of a single calculation, but also facilitate retries when errors occur, thereby improving the overall processing efficiency. In the future, the advantages of multi-core processors can be used to calculate multiple data blocks, fully utilize hardware resources, and significantly improve the calculation speed.

[0061] Step S202: Acquire the status information of the trusted execution environments of all business parties.

[0062] In this embodiment, the status information includes at least one of the running status, response time, CPU usage, memory occupancy, network bandwidth, task queue length and task execution time of the trusted execution environment. The scheduling system can obtain the running status of the trusted execution environment hardware through the trusted execution environment status information monitoring module. Since the privacy computing module is set in the trusted execution environment, the status information of the trusted execution environment hardware can reflect the status of the privacy computing modules of each business party.

[0063] Step S203: Based on the state information and the priority of the encrypted data block, determine the allocation strategy of the encrypted data block through a weighted polling algorithm.

[0064] In this embodiment, the scheduling system can determine the distribution strategy of the encrypted data blocks through a weighted polling algorithm based on the state information and the priority of the encrypted data blocks. The weighted polling algorithm is a common load balancing algorithm that allows different weights to be given according to the capabilities of the nodes, thereby distributing tasks more fairly. For example, nodes with stronger performance or lower current load may be given higher weights to receive more tasks. In this embodiment, encrypted data blocks with higher priorities can be allocated to privacy computing modules with higher weights.

[0065] In this embodiment, the scheduling system not only performs evaluation and planning at the initial stage of task allocation, but also continuously monitors the status of each node during task execution and dynamically adjusts the task allocation strategy according to real-time conditions. For example, if a node suddenly experiences high load or network conditions deteriorate, the scheduling system can reduce the new task allocation of the node or even reallocate some tasks to other nodes.

[0066] Figure 5 A scenario diagram showing an abnormal account detection method based on privacy computing in an embodiment of the present disclosure Figure 2 ,like Figure 5 As shown, the scheduling system includes a TEE status information monitoring module, a priority management module, a dynamic resource allocation module and a task queue execution module. Node 1, node 2, node 3, etc. correspond to the privacy computing modules of each business party respectively. The scheduling system can determine the allocation strategy of the encrypted data block based on the status information and the priority of the encrypted data block through a weighted polling algorithm. For example, if the priority of the encrypted data block related to node 1 is higher, the encrypted data block related to node 1 will be allocated first, and the encrypted data block related to node 1 will be allocated to the node with a larger weight for processing; among them, the task queue execution module can realize the orderly execution of tasks. In order to further optimize the task processing flow, this method can not only improve the request throughput to the business system, but also ensure the efficient and stable execution of privacy computing tasks. Through queue management, the scheduling system can reasonably arrange the task order according to the task priority to avoid system overload due to sudden requests.

[0067] It should be emphasized that the privacy computing in the traditional abnormal account detection is basically realized by the networking of two business parties, and one business party initiates the privacy computing to the other business party. However, in order to meet the accuracy of the abnormal account detection results across business parties, the business party needs to access the data. Therefore, the present disclosure can access the privacy computing nodes of nearly 20 business parties, and each node is performing real-time business processing, which has extremely high performance response requirements and needs to return results in seconds. However, due to the multi-threaded congestion caused by the performance of the trusted execution environment hardware itself and the process design, it is impossible to return in real time. Therefore, the present disclosure designs a high-performance scheduling system for privacy tasks under large-scale nodes to solve the privacy computing needs under multiple concurrent tasks. The scheduling system of the present disclosure realizes dynamic resource allocation and task priority management by combining TEE hardware status information with weighted polling algorithm, optimizes resource utilization and reduces waiting time. At the same time, by requesting the status information of the current TEE hardware in real time, it dynamically adjusts task allocation to avoid the problem of TEE overload and failure of other tasks. The scheduling system introduces a queue mechanism to realize orderly execution of tasks, which can not only improve the request throughput of the business execution module, but also ensure the efficient and stable execution of privacy computing tasks.

[0068] Step S204: Based on the allocation strategy, the corresponding target encrypted data block is sent to the privacy computing modules of all business parties.

[0069] In this embodiment, after the scheduling system determines the allocation strategy, it can send the encrypted data block to the privacy computing module corresponding to it in the allocation strategy.

[0070] Figure 3 The following is a schematic diagram showing the process of an abnormal account detection method based on privacy computing in an embodiment of the present disclosure. Figure 3 ,like Figure 3 As shown, step S204 "sending the corresponding target encrypted data block to the privacy computing modules of all business parties based on the allocation strategy" includes:

[0071] Step S301: Determine the target encrypted data block corresponding to each privacy computing module based on the allocation strategy.

[0072] Step S302: Based on the state information, the size of the target encrypted data block is adjusted to obtain an adjusted target encrypted data block.

[0073] Step S303: Send the adjusted target encrypted data block to the corresponding privacy computing module.

[0074] In this embodiment, the target encrypted data block corresponding to each privacy computing module can be determined based on the allocation strategy, and then the size of the target encrypted data block can be dynamically adjusted based on the status information. For example, if the status of the trusted execution environment where the privacy computing module is located is better, the data block can be adjusted to a larger block; conversely, if the status of the trusted execution environment where the privacy computing module is located is poor, the data will be divided into smaller blocks for fast transmission and processing.

[0075] In another embodiment, a method for detecting abnormal accounts based on privacy computing further includes:

[0076] An abnormal account detection is performed based on the first data to obtain a third detection result; and an abnormal account detection result is determined based on the first detection result, the second detection result and the third detection result.

[0077] In this embodiment, the first business party can also perform internal abnormal account detection based on the first data to obtain a third detection result, that is, input the first data into the abnormal account detection model, and the abnormal account detection model outputs the third detection result based on the first data. The third detection result includes a unique identifier of the abnormal account, an abnormal reason and classification, etc. The intersection or union of the first detection result, the second detection result and the third detection result can be used to determine the abnormal account detection result. Therefore, the accuracy of the abnormal account detection result can be further improved based on the internal detection result and the cross-business party detection result.

[0078] In this embodiment, when the first business party performs anomaly detection on an account, the query request includes internal anomaly detection, cross-business party risk label sharing, and cross-business party account opening anomaly detection. First, anomaly detection will be performed based on local data to obtain the internal anomaly detection result of the account, and then cross-bank verification will be initiated to other business parties. Other business parties will return the anomaly detection results of this account in other business parties, and at the same time, they will call cross-business party account opening behavior models, such as whether accounts have been opened in multiple business parties recently, etc., to verify the risk of its account opening behavior, and finally return to the first business party to assemble the results to obtain the final abnormal account detection results, and complete the account classification based on the abnormal account detection results.

[0079] In another embodiment, a method for detecting abnormal accounts based on privacy computing further includes:

[0080] The first detection result is hashed based on the national secret algorithm through the hardware encryption card to obtain a second hash value; the second hash value is sent to the blockchain node, the blockchain node verifies the second hash value based on the consensus algorithm, and stores the verified second hash value in the distributed ledger.

[0081] In this embodiment, after obtaining the calculation result, the first detection result can be hashed based on the national secret algorithm through the hardware encryption card to obtain a second hash value, and the second hash value is sent to the blockchain node. The blockchain node can verify the second hash value based on the consensus algorithm and store the verified second hash value in the distributed ledger to ensure the transparency and non-tamperability of the calculation process.

[0082] In this disclosure, blockchain technology is applied at the bottom layer to put data models, data approval, data usage, data calculation process, data audit and other functions on the chain, so as to realize the full process of data storage and traceability, ensure that each business party performs query and calculation in accordance with the agreed method, and improve the security of data sharing and collaboration.

[0083] In another embodiment, a method for detecting abnormal accounts based on privacy computing further includes:

[0084] The abnormal account detection result is encrypted by a hardware encryption card based on a national encryption algorithm to obtain an encrypted detection result; the encrypted detection result is sent to the business execution module of the first business party, and the business execution module decrypts the encrypted detection result to obtain the abnormal account detection result.

[0085] In this embodiment, the final abnormal account detection result can be encrypted by a hardware encryption card based on a national secret algorithm to obtain an encrypted detection result, and then the encrypted detection result is sent to the business execution module of the first business party, so that the business execution module decrypts the encrypted detection result to obtain the abnormal account detection result. The business execution module can subsequently perform business logic processing based on the abnormal account detection result, such as freezing accounts, restricting transactions, enhancing identity authentication and risk warnings, etc.

[0086] Figure 7 A schematic diagram of the structure of an abnormal account detection device based on privacy computing according to an embodiment of the present disclosure is shown. Figure 7 As shown, an abnormal account detection device based on privacy computing is applied to a privacy computing module of a first business party, and the privacy computing module is set in a trusted execution environment of the first business party. The device includes:

[0087] The receiving module 10 is used to receive an anomaly detection request sent by the business execution module of the first business party, and the business execution module is used to send the anomaly detection request to the privacy computing module and multiple second business parties. The anomaly detection request includes a target identifier of the data requested by the first business party to be provided by the second business party; the encryption module 11 is used to encrypt the first data corresponding to the target identifier in the first business party; the sending module 12 is used to send the obtained first encryption result to multiple second business parties; the receiving module 10 is also used to receive the second encryption results obtained by multiple second business parties based on the anomaly detection request; the computing module 13 is used to perform an intersection operation on the first encryption result and the second encryption result to obtain The intersection operation result; the sending module 12 is also used to send the intersection operation result to the scheduling system; the receiving module 10 is also used to receive the target encrypted data block sent by the scheduling system, and the target encrypted data block is a part of all encrypted data blocks obtained by slicing the intersection operation results sent by all business parties by the scheduling system; the detection module 14 is used to perform abnormal account detection based on the target encrypted data block through the abnormal account detection model, and send the obtained first detection result to multiple second business parties; the receiving module 10 is also used to receive the second detection results sent by multiple second business parties; the determination module 15 is used to determine the abnormal account detection result based on the first detection result and the second detection result.

[0088] In one possible implementation, the anomaly detection request also includes the identity information of the first business party, and the sending module 12 is also used to assist the business execution module in executing: the business execution module sends the anomaly detection request to the blockchain node; the blockchain node verifies the identity information of the first business party based on the smart contract and authority rules; in response to the verification being successful, the blockchain node sends the anomaly detection request to multiple second business parties.

[0089] In one possible implementation, the encryption module 11 is further used to: determine first data from a database of a first business party based on a target identifier; perform hash processing on the first data to obtain a first hash value; and perform symmetrical encryption on the first hash value based on a hardware encryption card to obtain a first encryption result.

[0090] In one possible implementation, the sending module 12 is also used to assist the scheduling system in executing: based on the data type and the association relationship between the data, the intersection operation results sent by all business parties are segmented to obtain encrypted data blocks; the status information of the trusted execution environment of all business parties is obtained, and the status information includes at least one of the operating status, response time, CPU usage, memory occupancy, network bandwidth, task queue length and task execution time of the trusted execution environment; based on the status information and the priority of the encrypted data block, the allocation strategy of the encrypted data block is determined through a weighted polling algorithm; based on the allocation strategy, the corresponding target encrypted data block is sent to the privacy computing modules of all business parties.

[0091] In one possible implementation, the sending module 12 is also used to assist the scheduling system in executing: based on the allocation strategy, determining the target encrypted data block corresponding to each privacy computing module; based on the status information, adjusting the size of the target encrypted data block to obtain an adjusted target encrypted data block; and sending the adjusted target encrypted data block to the corresponding privacy computing module.

[0092] In one possible implementation, the detection module 14 is further used to: perform abnormal account detection based on the first data to obtain a third detection result; and determine the abnormal account detection result based on the first detection result, the second detection result and the third detection result.

[0093] In one possible implementation mode, the encryption module 11 is also used to: perform hash processing on the first detection result based on the national secret algorithm through a hardware encryption card to obtain a second hash value; the sending module 12 is also used to: send the second hash value to the blockchain node, the blockchain node verifies the second hash value based on the consensus algorithm, and stores the verified second hash value in the distributed ledger.

[0094] In one possible implementation mode, the encryption module 11 is also used to: encrypt the abnormal account detection result based on the national encryption algorithm through a hardware encryption card to obtain an encrypted detection result; the sending module 12 is also used to: send the encrypted detection result to the business execution module of the first business party, and the business execution module decrypts the encrypted detection result to obtain the abnormal account detection result.

[0095] The collection, use and processing of information involved in this application must comply with relevant laws, regulations and standards of relevant countries and regions.

[0096] According to an embodiment of the present disclosure, the present disclosure also provides an electronic device and a readable storage medium.

[0097] Figure 8 A schematic block diagram of an example electronic device 800 that can be used to implement an embodiment of the present disclosure is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital processing, cellular phones, smart phones, wearable devices, and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely examples and are not intended to limit the implementation of the present disclosure described and / or required herein.

[0098] like Figure 8As shown, the device 800 includes a computing unit 801, which can perform various appropriate actions and processes according to a computer program stored in a read-only memory (ROM) 802 or a computer program loaded from a storage unit 808 to a random access memory (RAM) 803. In the RAM 803, various programs and data required for the operation of the device 800 can also be stored. The computing unit 801, the ROM 802, and the RAM 803 are connected to each other via a bus 804. An input / output (I / O) interface 805 is also connected to the bus 804.

[0099] A number of components in the device 800 are connected to the I / O interface 805, including: an input unit 806, such as a keyboard, a mouse, etc.; an output unit 807, such as various types of displays, speakers, etc.; a storage unit 808, such as a disk, an optical disk, etc.; and a communication unit 809, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 809 allows the device 800 to exchange information / data with other devices through a computer network such as the Internet and / or various telecommunication networks.

[0100] The computing unit 801 may be a variety of general and / or special processing components with processing and computing capabilities. Some examples of the computing unit 801 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various dedicated artificial intelligence (AI) computing chips, various computing units running machine learning model algorithms, digital signal processors (DSPs), and any appropriate processors, controllers, microcontrollers, etc. The computing unit 801 performs the various methods and processes described above, such as an abnormal account detection method based on privacy computing. For example, in some embodiments, an abnormal account detection method based on privacy computing may be implemented as a computer software program, which is tangibly contained in a machine-readable medium, such as a storage unit 808. In some embodiments, part or all of the computer program may be loaded and / or installed on the device 800 via the ROM 802 and / or the communication unit 809. When the computer program is loaded into the RAM 803 and executed by the computing unit 801, one or more steps of the abnormal account detection method based on privacy computing described above may be performed. Alternatively, in other embodiments, the computing unit 801 may be configured to perform an abnormal account detection method based on privacy computing in any other appropriate manner (for example, by means of firmware).

[0101] Various implementations of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), systems on chips (SOCs), load programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various implementations can include: being implemented in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which can be a special purpose or general purpose programmable processor that can receive data and instructions from a storage system, at least one input device, and at least one output device, and transmit data and instructions to the storage system, the at least one input device, and the at least one output device.

[0102] The program code for implementing the method of the present disclosure may be written in any combination of one or more programming languages. These program codes may be provided to a processor or controller of a general-purpose computer, a special-purpose computer, or other programmable data processing device, so that the program code, when executed by the processor or controller, enables the functions / operations specified in the flow chart and / or block diagram to be implemented. The program code may be executed entirely on the machine, partially on the machine, partially on the machine and partially on a remote machine as a stand-alone software package, or entirely on a remote machine or server.

[0103] In the context of the present disclosure, a machine-readable medium may be a tangible medium that may contain or store a program for use by or in conjunction with an instruction execution system, device, or equipment. A machine-readable medium may be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium may include, but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, device, or device, or any suitable combination of the foregoing. A more specific example of a machine-readable storage medium may include an electrical connection based on one or more lines, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0104] To provide interaction with a user, the systems and techniques described herein can be implemented on a computer having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user can provide input to the computer. Other types of devices can also be used to provide interaction with the user; for example, the feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, voice input, or tactile input).

[0105] The systems and techniques described herein may be implemented in a computing system that includes back-end components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes front-end components (e.g., a user computer with a graphical user interface or a web browser through which a user can interact with implementations of the systems and techniques described herein), or a computing system that includes any combination of such back-end components, middleware components, or front-end components. The components of the system may be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include: a local area network (LAN), a wide area network (WAN), and the Internet.

[0106] A computer system may include a client and a server. The client and the server are generally remote from each other and usually interact through a communication network. The relationship of client and server is generated by computer programs running on respective computers and having a client-server relationship with each other. The server may be a cloud server, a server of a distributed system, or a server combined with a blockchain.

[0107] It should be understood that the various forms of processes shown above can be used to reorder, add or delete steps. For example, the steps recorded in this disclosure can be executed in parallel, sequentially or in different orders, as long as the desired results of the technical solutions disclosed in this disclosure can be achieved, and this document does not limit this.

[0108] In addition, the terms "first" and "second" are used for descriptive purposes only and should not be understood as indicating or implying relative importance or implicitly indicating the number of technical features indicated. Thus, a feature defined as "first" or "second" may explicitly or implicitly include at least one of the features. In the description of the present disclosure, the meaning of "plurality" is two or more, unless otherwise clearly and specifically defined.

[0109] The above is only a specific embodiment of the present disclosure, but the protection scope of the present disclosure is not limited thereto. Any person skilled in the art who is familiar with the technical field can easily think of changes or substitutions within the technical scope disclosed in the present disclosure, which should be included in the protection scope of the present disclosure. Therefore, the protection scope of the present disclosure should be based on the protection scope of the claims.

Claims

1. An abnormal account detection method based on privacy computing, characterized in that: A privacy computing module applied to a first business party, wherein the privacy computing module is set in a trusted execution environment of the first business party, and the method includes: receiving an anomaly detection request sent by a business execution module of the first business party, wherein the business execution module is used to send the anomaly detection request to the privacy computing module and multiple second business parties, wherein the anomaly detection request includes a target identifier of data requested by the first business party to be provided by the second business party; Encrypting the first data corresponding to the target identifier in the first business party, sending the obtained first encryption result to the plurality of second business parties, and receiving the second encryption results obtained by the plurality of second business parties based on the anomaly detection request; Performing an intersection operation on the first encryption result and the second encryption result to obtain an intersection operation result; Sending the intersection operation result to the scheduling system, and receiving the target encrypted data block sent by the scheduling system, wherein the target encrypted data block is a part of all encrypted data blocks obtained by the scheduling system by slicing the intersection operation results sent by all business parties; wherein the scheduling system sends the corresponding target encrypted data block to the privacy computing modules of all business parties; Based on the target encrypted data block, abnormal account detection is performed through an abnormal account detection model, and the obtained first detection result is sent to multiple second business parties; the privacy computing module of the second business party receives the corresponding target encrypted data block and inputs it into the abnormal account detection model to obtain a second detection result; Receive the second detection results sent by the plurality of second business parties, and determine the abnormal account detection result based on the first detection result and the second detection result.

2. The method according to claim 1, characterized in that The anomaly detection request also includes the identity information of the first business party, and the business execution module sends the anomaly detection request to multiple second business parties based on the following method: The business execution module sends the anomaly detection request to the blockchain node; The blockchain node verifies the identity information of the first business party based on the smart contract and permission rules; In response to the verification being successful, the blockchain node sends the anomaly detection request to multiple second business parties.

3. The method according to claim 1, characterized in that The encrypting the first data corresponding to the target identifier in the first service party includes: Based on the target identifier, determining the first data from a database of the first service party; Performing hash processing on the first data to obtain a first hash value; The first hash value is symmetrically encrypted based on the hardware encryption card to obtain the first encryption result.

4. The method according to claim 1, characterized in that: The scheduling system sends the corresponding target encrypted data blocks to the privacy computing modules of all business parties in the following manner: Based on the data type and the association relationship of the data, the intersection operation results sent by all business parties are cut into blocks to obtain encrypted data blocks; Acquire status information of the trusted execution environments of all the business parties, the status information including at least one of the running status, response time, CPU usage, memory occupancy, network bandwidth, task queue length, and task execution time of the trusted execution environment; Based on the state information and the priority of the encrypted data block, determining the allocation strategy of the encrypted data block by a weighted polling algorithm; Based on the allocation strategy, the corresponding target encrypted data blocks are sent to the privacy computing modules of all business parties.

5. The method according to claim 4, characterized in that The sending of the corresponding target encrypted data blocks to the privacy computing modules of all business parties based on the allocation strategy includes: Based on the allocation strategy, determine the target encrypted data block corresponding to each of the privacy computing modules; Based on the state information, adjusting the size of the target encrypted data block to obtain an adjusted target encrypted data block; Send the adjusted target encrypted data block to the corresponding privacy computing module.

6. The method according to claim 1, characterized in that Also includes: Perform abnormal account detection based on the first data to obtain a third detection result; Based on the first detection result, the second detection result and the third detection result, an abnormal account detection result is determined.

7. The method according to claim 1, characterized in that Also includes: Performing hash processing on the first detection result based on the national encryption algorithm through the hardware encryption card to obtain a second hash value; The second hash value is sent to a blockchain node, the blockchain node verifies the second hash value based on a consensus algorithm, and stores the verified second hash value in a distributed ledger.

8. The method according to any one of claims 1 to 7, characterized in that: Also includes: Encrypt the abnormal account detection result by a hardware encryption card based on a national encryption algorithm to obtain an encrypted detection result; The encrypted detection result is sent to the business execution module of the first business party, and the business execution module decrypts the encrypted detection result to obtain the abnormal account detection result.

9. An abnormal account detection device based on privacy computing, characterized in that: A privacy computing module applied to a first business party, wherein the privacy computing module is set in a trusted execution environment of the first business party, and the device includes: a receiving module, configured to receive an anomaly detection request sent by a business execution module of the first business party, wherein the business execution module is configured to send the anomaly detection request to the privacy computing module and multiple second business parties, wherein the anomaly detection request includes a target identifier of data requested by the first business party to be provided by the second business party; An encryption module, used for encrypting the first data corresponding to the target identifier in the first business party; A sending module, used for sending the obtained first encryption result to a plurality of the second business parties; The receiving module is further used to receive second encryption results obtained by multiple second business parties based on the anomaly detection request; A calculation module, used for performing an intersection operation on the first encryption result and the second encryption result to obtain an intersection operation result; The sending module is further used to send the intersection operation result to the scheduling system; The receiving module is further used to receive a target encrypted data block sent by the scheduling system, where the target encrypted data block is a part of all encrypted data blocks obtained by the scheduling system by slicing the intersection operation results sent by all business parties; wherein the scheduling system sends the corresponding target encrypted data block to the privacy computing modules of all business parties; A detection module, configured to perform abnormal account detection based on the target encrypted data block through an abnormal account detection model, and send the obtained first detection result to the plurality of second business parties; the privacy computing module of the second business party inputs the received corresponding target encrypted data block into the abnormal account detection model to obtain a second detection result; The receiving module is further used to receive the second detection results sent by multiple second service parties; A determination module is used to determine an abnormal account detection result based on the first detection result and the second detection result.

10. An electronic device, characterized in that: include: at least one processor; as well as a memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to perform the method according to any one of claims 1 to 8.

Citation Information

Patent Citations

  • Data set anomaly identification method based on multi-source data joint detection

    CN117556363A

  • Multivariate outlier detection for data privacy protection

    US20230237380A1