Artificial Intelligence-Based Business Log Information Processing Method and Server
The AI-based method for analyzing e-commerce logs identifies and associates business interactions to enhance anomaly detection, ensuring e-commerce platform security and efficiency by matching current logs with historical data.
Patent Information
- Application Number
- CN202510069593.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-16
- Publication Date
- 2025-07-15
- Estimated Expiration
- 2045-01-16
AI Technical Summary
Traditional log processing methods are difficult to quickly and effectively identify and analyze e-commerce business interaction events from the massive log data of e-commerce platforms, resulting in the inability to detect abnormal situations and potential vulnerabilities in a timely manner, affecting the security and efficiency of e-commerce business.
Using an artificial intelligence-based method, we can identify e-commerce business interaction events, generate abnormal pattern attribute information and interactive event correlation attribute information, judge the matching between the target application log and the historical log, and achieve in-depth analysis of e-commerce business and risk prevention.
It improves the monitoring efficiency of e-commerce business, promptly detects malicious operations and business process loopholes, and ensures the safe, stable and efficient operation of e-commerce business.
Smart Images

Figure CN119474041B_ABST
Abstract
Description
Technical Field
[0001] Embodiments of the present invention relate to the technical field of data analysis, and more specifically, to a method and a server for processing business log information based on artificial intelligence. Background Art
[0002] Today, with the rapid development of e-commerce business, e-commerce platforms generate a huge amount of application program logs every day. Traditional log processing methods are difficult to quickly and effectively obtain valuable information from complex log data. Due to the lack of detailed identification and in-depth analysis of e-commerce business interaction events, it is impossible to accurately judge abnormal situations in the business process. For example, new malicious attack means such as abnormal login and order placement behaviors cannot be detected in a timely manner, and potential loopholes in the business process such as the mismatch between the order amount and the commodity value are also difficult to discover. At the same time, in the face of a large amount of log data, it is impossible to efficiently determine whether the current situation is a newly emerging problem, resulting in low efficiency in risk prevention and problem troubleshooting. Summary of the Invention
[0003] Embodiments of the present invention at least provide a method and a server for processing business log information based on artificial intelligence.
[0004] Embodiments of the present invention provide a method for processing business log information based on artificial intelligence, which is applied to a business log information processing server. The method includes: identifying each e-commerce business interaction event included in the target application program log to obtain an interaction event identification report; generating abnormal pattern attribute information of each e-commerce business interaction event based on the interaction event identification report; extracting business association tags between each e-commerce business interaction event included in the target application program log based on the abnormal pattern attribute information of each e-commerce business interaction event to obtain interaction event association attribute information; and determining whether the target application program log matches the historical application program logs in the application program log pool based on the abnormal pattern attribute information and the interaction event association attribute information.
[0005] Embodiments of the present invention also provide a business log information processing server, including a processor and a memory; the processor is communicatively connected to the memory, and the processor is configured to read and execute a computer program from the memory to implement the above method.
[0006] Embodiments of the present invention also provide a computer-readable storage medium, on which a computer program is stored, and the computer program implements the above method when running.
[0007] The technical solutions provided by the embodiments of the present invention may include the following beneficial effects: By identifying e-commerce business interaction events to obtain an identification report, the business activities in the target application program logs can be comprehensively sorted out. Generating abnormal pattern attribute information helps to accurately locate interaction events that may pose risks or do not conform to the normal process, such as discovering abnormal order amounts or login behaviors. Extracting the correlation attribute information of interaction events can deeply explore the internal connections between events, for example, the correlation between abnormal order placement and payment. Judging the matching with historical logs based on this information can quickly determine whether the current log situation is a new problem, improve the efficiency of monitoring e-commerce business, and timely discover problems such as malicious operations and business process loopholes, ensuring the safe, stable, and efficient operation of e-commerce business.
[0008] For the description of the effects of the above business log information processing server and computer-readable storage medium, refer to the description of the above method.
[0009] To make the above objects, features, and advantages of the embodiments of the present invention more obvious and understandable, the following specific preferred embodiments are given, and in conjunction with the accompanying drawings, the detailed description is as follows. BRIEF DESCRIPTION OF THE DRAWINGS
[0010] To more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings required for use in the embodiments will be briefly introduced below. The drawings herein are incorporated into the specification and constitute a part of this specification. These drawings show embodiments that conform to the embodiments of the present invention and are used together with the specification to explain the technical solutions of the embodiments of the present invention. It should be understood that the following drawings only show some embodiments of the embodiments of the present invention, and therefore should not be regarded as a limitation on the scope. For those of ordinary skill in the art, without creative efforts, other related drawings can also be obtained based on these drawings.
[0011] Figure 1 It is a block diagram of a business log information processing server shown in an embodiment of the present invention.
[0012] Figure 2 It is a schematic flowchart of a business log information processing method based on artificial intelligence shown in an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0013] Here, the exemplary embodiments will be described in detail, and the examples are shown in the drawings. When the following description refers to the drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with the embodiments of the present invention. On the contrary, they are only examples of devices and methods that are consistent with some aspects of the embodiments of the present invention.
[0014] Figure 1The structural diagram of the business log information processing server 10 provided in the embodiment of the present invention includes a processor 102, a memory 104, and a bus 106. Among them, the memory 104 is used to store execution instructions, including a memory and an external memory. The memory can also be understood as an internal memory, which is used to temporarily store the operation data in the processor 102 and the data exchanged with the external memory such as the hard disk. The processor 102 exchanges data with the external memory through the memory. When the business log information processing server 10 is running, the processor 102 communicates with the memory 104 through the bus 106, so that the processor 102 executes the business log information processing method based on artificial intelligence in the embodiment of the present invention.
[0015] Please combine Figure 2 , Figure 2 It is a flow chart of a business log information processing method based on artificial intelligence provided by an embodiment of the present invention, which is applied to a business log information processing server. The method may exemplarily include S101-S104.
[0016] S101: The business log information processing server identifies each e-commerce business interaction event contained in the target application log and obtains an interaction event identification report.
[0017] First, in step S101, the business log information processing server needs to identify each e-commerce business interaction event contained in the target application log, so as to obtain an interaction event identification report. E-commerce business interaction events cover a variety of operations, such as user login, product browsing, product addition to shopping cart, ordering, payment, logistics query, etc. Take a typical e-commerce application log as an example, which may contain a series of operation records of the user in a certain period of time. For example, the user logged in to the e-commerce platform at 10:00 on October 1, 2023, and then browsed several mobile phones in the electronic product category, added one of the mobile phones to the shopping cart at 10:15, placed an order at 10:30 and selected a payment method, and completed the payment at 10:35. The business log information processing server will parse these log contents through specific algorithms and technical means to identify these different e-commerce business interaction events. This identification process may involve understanding the log format, searching for specific keywords, and analyzing the order of operations. For example, for a login event, the server may search for log records containing keywords such as "login" or "login", and determine based on the context that this is an e-commerce business interaction event in which a user logged in. Through such a comprehensive and detailed identification process, the business log information processing server can accurately obtain an interaction event identification report for each e-commerce business interaction event in the target application log, which records in detail the type, occurrence time, and related parameters of each identified interaction event.
[0018] S102: The business log information processing server generates the abnormal pattern attribute information of each e-commerce business interaction event based on the interaction event recognition report.
[0019] Next, enter step S102. The business log information processing server generates the abnormal pattern attribute information (abnormal pattern attribute features) of each e-commerce business interaction event based on the interaction event recognition report obtained previously. The generation of the abnormal pattern attribute information is based on the understanding of the normal pattern of the e-commerce business interaction event and the judgment of possible abnormal situations. Still taking the above e-commerce business interaction event as an example, under normal circumstances, the order placement operation usually occurs after the product is added to the shopping cart. If the order placement operation occurs before the product is added to the shopping cart, this may be an abnormal pattern. For the payment operation, if the payment amount does not match the product price (for example, the product price is 100 yuan, the payment amount is 10 yuan and there is no discount or preferential label), this may also be an abnormal pattern. The business log information processing server will establish a model or rule set about the normal pattern through the learning and analysis of a large amount of normal e-commerce business interaction event data. Then, each interaction event in the interaction event recognition report is compared with this normal pattern model or rule set to determine whether each interaction event has abnormal pattern attributes. For example, the server may find that a certain user has made multiple login attempts within a very short period of time (such as within 1 minute), which does not conform to the normal user login pattern and may be abnormal. Then the server will mark this login interaction event with abnormal pattern attributes, such as "frequent login attempt anomaly", and record relevant attribute information, such as the number of attempts and the time interval. In this way, the business log information processing server generates the abnormal pattern attribute information for each e-commerce business interaction event, and this information helps to further analyze and process the target application program log.
[0020] S103: The business log information processing server extracts the business association labels between each e-commerce business interaction event included in the target application program log based on the abnormal pattern attribute information of each e-commerce business interaction event, and obtains the interaction event association attribute information.
[0021] In step S103, the business log information processing server extracts the business association tags between each e-commerce business interaction event contained in the target application log based on the abnormal pattern attribute information of each e-commerce business interaction event, and obtains the interaction event association attribute information (interaction event association attribute characteristics). There are inherent business associations between e-commerce business interaction events, and these associations are very important for understanding the entire e-commerce business process and discovering potential problems. For example, there is an association between the order placement operation and the product browsing and adding to cart operations, an association between the payment operation and the order placement operation, and an association between the logistics query operation and the order placement operation, etc. The business log information processing server will analyze these associations based on the abnormal pattern attribute information. For example, if an abnormal pattern attribute (such as the quantity of the added product exceeding the normal purchase limit) is found in the interaction event of adding a product to the cart in the target application log, and the subsequent order placement operation is also abnormal (such as the order amount not matching the total amount of the products in the cart), then the server will mark a specific business association tag between these two interaction events, such as "association between cart and order amount mismatch". Another example is that if a user's login operation is abnormal (such as logging in from a different location), and subsequent product browsing and order placement operations are also abnormal (such as browsing product categories that do not match the user's preferences and using an abnormal payment method when placing an order), the server may mark a business association tag such as "association between login abnormality and subsequent operation abnormalities". By analyzing and marking the relationships between all e-commerce business interaction events, the business log information processing server obtains the interaction event association attribute information, which reflects the mutual relationships of each interaction event in the abnormal situation.
[0022] S104: The business log information processing server determines whether the target application log matches the historical application logs in the application log pool based on the abnormal pattern attribute information and the interaction event association attribute information.
[0023] Finally, in step S104, the business log information processing server determines whether the target application log matches the historical application logs in the application log pool based on the abnormal pattern attribute information and the interaction event correlation attribute information. The historical application logs in the application log pool contain a large number of past e-commerce business operation records. The business log information processing server will compare the abnormal pattern attribute information and the interaction event correlation attribute information in the target application log with the corresponding information in the historical application logs. For example, in the historical application logs, there may be some known abnormal patterns and related interaction event correlation situations, such as frequent login abnormalities and abnormal order placement behaviors among users in a certain region during a certain period. When similar abnormal pattern attribute information and interaction event correlation attribute information also appear in the target application log (such as frequent login abnormalities and abnormal order placement behaviors among users in the same region), it can be considered that the target application log matches the historical application logs to a certain extent. If there are few or almost no similar abnormal patterns and interaction event correlation situations in the historical application logs as those in the target application log, then it can be considered that the target application log does not match the historical application logs. This matching judgment helps the business log information processing server further determine whether the abnormal situation in the target application log is newly emerged, whether special attention is needed, or specific handling measures should be taken, etc.
[0024] Through the operations of S101 - S104, the business log information processing server can effectively conduct in-depth analysis of the target application log, from identifying e-commerce business interaction events, generating abnormal pattern attribute information, extracting interaction event correlation attribute information, to finally making a matching judgment with the historical application logs, thereby providing strong support for the normal operation, risk prevention, and problem troubleshooting of e-commerce business. In the actual e-commerce business environment, with the continuous growth of business volume and the increase in business complexity, this effective processing of application logs becomes increasingly important. For example, for the massive log data generated by a large e-commerce platform every day, if abnormal situations can be accurately identified and compared with historical data, problems such as malicious attacks, business process errors, and user abnormal behaviors can be discovered in a timely manner, thus ensuring the safe, stable, and efficient operation of e-commerce business.
[0025] Based on the above content, taking a large e-commerce platform as an example, this platform generates a huge amount of application logs every day. The business log information processing server of this platform has to process log information from all corners every day to ensure the normal operation of e-commerce business, timely discover risks, and conduct problem troubleshooting, etc.
[0026] In the initial step of S101, the business log information processing server analyzes the target application log to identify each e-commerce business interaction event contained therein, and then obtains an interaction event recognition report. Take a specific user shopping process as an example. A certain user started a shopping journey on November 10, 2023. At 9:00, the user opened the APP of the e-commerce platform, and this operation will be recorded in the log. The business log information processing server will start analyzing this record according to its own parsing algorithm. The server knows that this may be the initial operation after a user logs in or the starting point of browsing some content of the platform (such as some public promotion pages) in the unlogged state.
[0027] As the user's operations proceed, at 9:05 the user logged in to the account. The server determined this as an e-commerce business interaction event of user login by searching for "login" or related signs indicating successful login (such as specific successful login return codes, etc.) in the log and combining the information before and after. Then, at 9:10, the user started browsing products in the clothing category. The server identified this as a product browsing event based on the page jump information, product category identification, etc. recorded in the log.
[0028] At 9:20, the user added a shirt worth 50 yuan to the shopping cart. The server identified the interaction event of adding this product to the shopping cart by analyzing the relevant records in the log related to shopping cart operations (such as shopping cart update records, product ID and shopping cart association records, etc.). After that, at 9:30, the user placed an order to buy this shirt and selected the online payment method. The server identified the two interaction events of placing an order and selecting the payment method based on the relevant signs of the order placement operation (such as order creation records, records starting from the "pending payment" order status, etc.) and the payment method selection record. Finally, at 9:35, the user completed the payment. The server identified the interaction event of payment completion through the confirmation record of successful payment (such as the record of the payment success notification returned by the payment platform in the log, etc.).
[0029] Through such a series of meticulous analyses of the log content, the business log information processing server identified all these different types of e-commerce business interaction events and generated an interaction event recognition report. This report details the type of each interaction event (such as login, product browsing, adding to the shopping cart, placing an order, payment, etc.), the occurrence time (accurate to minutes or even seconds), and the relevant parameters (such as the price of the product, order number, payment method, etc.).
[0030] Then, it enters step S102. Based on the generated interaction event recognition report, the business log information processing server starts to generate the abnormal pattern attribute information of each e-commerce business interaction event. Considering that e-commerce business interaction events have their normal processes and patterns, the server will make judgments based on the normal pattern model or rule set established through the previous learning and analysis of a large amount of normal business interaction data.
[0031] For example, under normal circumstances, the goods ordered by a user should be the ones previously added to the shopping cart, and the order amount should match the total amount of the goods in the shopping cart (taking into account possible discounts, shipping fees, etc.). If it is found in the log record of a certain user that the ordered goods are completely different from those in the shopping cart, or the order amount varies greatly from the total amount of the goods in the shopping cart (such as the total price of the goods in the shopping cart is 50 yuan, and the order amount is 1000 yuan without a reasonable explanation, like not adding other high-priced goods or not applying special high shipping fees, etc.), then for this order interaction event, the server will mark it as having an abnormal pattern attribute, such as marking it as "abnormal: ordered goods do not match the shopping cart" or "abnormal order amount", and at the same time record the relevant attribute information, such as the difference content between the ordered goods and the goods in the shopping cart, the specific difference in amount, etc.
[0032] Looking at the login event again, if under normal circumstances, the average number of logins of a user in a day is 2 - 3 times, and a certain user logs in 20 times in a day, and the IP addresses of these logins are distributed in different regions (obtained through the analysis of the IP address records in the log), this obviously does not match the normal login pattern. The business log information processing server will mark this login interaction event with an abnormal pattern attribute, such as "abnormal: frequent logins from different locations", and record the relevant attribute information such as the time and IP address of each login. For the product browsing event, if a user browses hundreds of different categories of products in a short period of time (such as within 10 minutes), which is very different from the browsing behavior pattern of normal users, the server will mark it as "abnormal: extremely fast and large-scale browsing", and at the same time record the attribute information such as the number of product categories browsed and the browsing time range.
[0033] In this way, the business log information processing server generates the abnormal pattern attribute information for each e-commerce business interaction event, and this information becomes an important basis for subsequent analysis.
[0034] Next is step S103. The business log information processing server extracts the business association tags between each e-commerce business interaction event contained in the target application program log based on the abnormal pattern attribute information of each e-commerce business interaction event, so as to obtain the interaction event association attribute information.
[0035] For example, during the user shopping process mentioned above, if it is found that the user's login event has an abnormal pattern attribute, such as "frequent abnormal login from different locations", and then during subsequent product browsing, it is found that the products browsed by the user are all high-value products that are completely unrelated to the user's previous browsing history (marked as "abnormal product browsing anomaly"), and finally, a very rare payment method is used when placing an order (marked as "abnormal payment method selection anomaly"). The business log information processing server will mark a business association label of "associated abnormal login and abnormal product browsing" between the login event and the product browsing event, and mark a business association label of "associated abnormal product browsing and abnormal payment method" between the product browsing event and the payment method selection event.
[0036] Another example is that in the log of a certain user, the interaction event of adding products to the shopping cart has an abnormal pattern attribute. For example, the number of products added is 1000 pieces, far exceeding the normal purchase limit (marked as "abnormal number of products in the shopping cart"), and there is an anomaly in the subsequent order placement operation where the order amount is 0 yuan (marked as "abnormal order amount of zero"). The server will mark a business association label of "associated abnormal number of products in the shopping cart and abnormal order amount of zero" between these two interaction events.
[0037] Through this analysis and marking of the relationships between all e-commerce business interaction events in the entire target application program log, the business log information processing server obtains the interaction event association attribute information, which accurately reflects the mutual relationships of each interaction event under abnormal conditions.
[0038] Finally, in step S104, the business log information processing server determines whether the target application program log matches the historical application program logs in the application program log pool based on the abnormal pattern attribute information and interaction event association attribute information obtained previously.
[0039] The historical application program logs in the application program log pool contain the e-commerce business operation records of numerous past users. These historical records are like a huge experience library, containing various normal and abnormal business operation patterns.
[0040] For example, in the historical application logs, it was once found that a group of users in a certain region had frequent login anomalies (more than 10 logins per day) during a certain promotional event, and were accompanied by a large number of views of high-value products (more than 50 high-value products were viewed within 1 hour), but finally had a very low order placement rate. When similar frequent login anomalies (15 logins per day) and a large number of views of high-value products (60 high-value products were viewed within 45 minutes) with a very low order placement rate were also found among users in a similar region in the target application logs, the business log information processing server would consider that the target application logs were somewhat matched with the historical application logs.
[0041] Conversely, if such an abnormal pattern and related interaction event association where a user first adds products to the shopping cart (and the quantity of added products is normal), and then without any modification, the order amount becomes 10 times the total amount of the products in the shopping cart rarely occurred in the historical application logs, but such a situation appears in the target application logs, then it can be considered that the target application logs do not match the historical application logs.
[0042] This judgment of whether they match has important significance for the e-commerce business. If they match, it indicates that the abnormal situation in the target application logs may be a repetition of a certain situation that has occurred before, and may be affected by similar factors (such as promotional strategies, market trends, external environment, etc.). If they do not match, it means that this may be a completely new abnormal situation, which requires the business log information processing server to pay special attention, perhaps a new malicious attack method, a new business process vulnerability, or a new abnormal behavior pattern of users, etc.
[0043] Based on the above application scenario examples, it can be seen that the business log information processing server can deeply mine the information in the target application log. It can accurately identify e-commerce business interaction events, keenly discover the abnormal pattern attribute information, carefully extract the interaction event related attribute information, and finally accurately judge the matching with the historical application log. This series of operations is crucial to the healthy development of e-commerce business. With the continuous development of e-commerce business, the continuous growth of business volume, and the increasing complexity of business, the massive log data generated every day hides various information about business operation status, user behavior, risk factors, etc. Through this effective log analysis technology solution, the e-commerce platform can timely discover problems such as malicious attacks (such as hackers obtaining user information through abnormal logins to steal credit cards, etc.), business process errors (such as incorrect price calculations leading to abnormal order amounts, etc.), and abnormal user behaviors (such as abnormal purchase patterns, browsing patterns, etc.), thereby ensuring the safe, stable and efficient operation of e-commerce business. For example, when a large number of users are found to have similar abnormal ordering behaviors (such as ordering high-value goods at low prices) and they do not match historical data, the platform can take timely measures, such as suspending the processing of related orders, checking whether the price system has errors, and investigating whether there are malicious attacks, etc., to avoid possible economic losses and business risks.
[0044] In an optional technical solution, business association tags between each e-commerce business interaction event contained in the target application log are extracted based on the abnormal pattern attribute information of each e-commerce business interaction event to obtain interaction event association attribute information, including: based on the abnormal pattern attribute information of each e-commerce business interaction event, performing knowledge entity conversion on each e-commerce business interaction event to obtain event entity information of each e-commerce business interaction event; based on the distribution characteristics of each e-commerce business interaction event in the target application log and the event entity information of each e-commerce business interaction event, generating an event knowledge relationship spectrum corresponding to the target application log; and extracting the interaction event association attribute information from the event knowledge relationship spectrum.
[0045] In the above optional technical scheme, there is a more detailed and unique operation process for extracting business association tags between each e-commerce business interaction event in the target application log based on the abnormal pattern attribute information of each e-commerce business interaction event to obtain the interaction event association attribute information.
[0046] First, based on the abnormal pattern attribute information of each e-commerce business interaction event, perform knowledge entity conversion on each e-commerce business interaction event to obtain the event entity information of each e-commerce business interaction event. Take the user login event in e-commerce business as an example. If this login event has an abnormal pattern attribute, such as "abnormal login from a different location", during the knowledge entity conversion, this login event will be converted from the original log record form into event entity information with specific semantics and structure. This may involve combining relevant information about the login, such as login time, login IP address, login account, etc., with the attribute "abnormal login from a different location" to construct an event entity with rich semantics. For example, it is converted into an "abnormal login from a different location event entity", which contains attributes such as "login time: 2023-11-15, 10:00", "login IP address: 192.168.100.200 (different from the usual address)", "login account: user123", etc.
[0047] Similarly, for the event of adding a product to the shopping cart, if there is an abnormal pattern attribute of "abnormal quantity of products in the shopping cart", the converted event entity information may be an "abnormal quantity of products in the shopping cart event entity", and its attributes include "adding time: 2023-11-15, 10:10", "quantity of products: 100 (far exceeding the normal quantity)", "product category: electronic products", etc. Through such knowledge entity conversion, each e-commerce business interaction event is transformed into event entity information with more semantics and logical structure, which is more conducive to subsequent analysis and processing.
[0048] Next, based on the distribution characteristics of each e-commerce business interaction event in the target application program log and the event entity information of each e-commerce business interaction event, generate an event knowledge relationship spectrum corresponding to the target application program log. The distribution characteristics of e-commerce business interaction events in the log include information such as the sequence, time interval, and occurrence frequency of events. For example, in the shopping process log of a user, the login event occurs first, then the product browsing event occurs within a short period of time (such as 5 minutes later), and then the event of adding a product to the shopping cart occurs after another 3 minutes. This sequence and time interval of events are part of the distribution characteristics.
[0049] Meanwhile, considering the event entity information of each e-commerce business interaction event obtained previously, these information are integrated to construct an event knowledge relationship spectrum. For example, within a certain time period, there are log data of multiple users. The event entity information of the login event shows that there are abnormal off-site logins for multiple users. And after these abnormal off-site logins, the event entity information of the product browsing event indicates that the product categories browsed by the users are all high-value products and the browsing time is short. Then, in the event knowledge relationship spectrum, a relationship connection will be established from the "abnormal off-site login event entity" to the "rapid browsing of high-value products event entity". This relationship spectrum is a comprehensive and structured representation of all e-commerce business interaction events and their relationships in the target application program logs. It shows the relationships between various event entities in the form of a graphical or logical relationship structure, similar to the construction of a knowledge graph.
[0050] Finally, extract the interaction event correlation attribute information from the event knowledge relationship spectrum. In this already constructed event knowledge relationship spectrum, by analyzing information such as the connection relationships between various event entities and the weights of the connections (if any, for example, determining the weights according to the frequency of simultaneous occurrence of events), the interaction event correlation attribute information can be accurately extracted. For example, if it is found in the event knowledge relationship spectrum that there is a strong connection relationship between the "abnormal off-site login event entity" and the "rapid browsing of high-value products event entity" (such as a high connection weight, indicating that this association frequently appears in the logs of multiple users), then the interaction event correlation attribute information such as "association between off-site login and rapid browsing of high-value products" can be extracted. Another example, if a specific connection relationship is found between the "abnormal number of products in the shopping cart event entity" and the "order amount is zero event entity", the interaction event correlation attribute information such as "association between abnormal number of products in the shopping cart and zero order amount" can be extracted.
[0051] In this way, by means of converting e-commerce business interaction events into knowledge entities, constructing an event knowledge relationship spectrum and extracting interaction event correlation attribute information from it, an effective way is provided for more accurately analyzing the associations between e-commerce business interaction events. It can dig deeper into the information in the target application program logs, help better understand various abnormal situations and their mutual relationships in e-commerce business, and thus provide more powerful support for risk prevention and problem troubleshooting in e-commerce business.
[0052] In the following design concept, based on the abnormal pattern attribute information of each e-commerce business interaction event, perform knowledge entity conversion on each e-commerce business interaction event to obtain the event entity information of each e-commerce business interaction event, including: obtaining a number of key attribute information, where the key attribute information is obtained by clustering the abnormal pattern attribute information of the e-commerce business interaction events included in the historical application logs; based on the difference between the abnormal pattern attribute information of each e-commerce business interaction event and the number of key attribute information, determine the key attribute information with the smallest difference from the abnormal pattern attribute information of each e-commerce business interaction event; according to the entity index corresponding to the key attribute information with the smallest difference from the abnormal pattern attribute information of each e-commerce business interaction event, generate the event entity information of each e-commerce business interaction event.
[0053] Based on the above design concept, the artificial intelligence-based business log information processing method further includes: obtaining the number of prior e-commerce business interaction events and the number of upstream and downstream business interaction events of the prior e-commerce business interaction events, and obtaining the abnormal pattern attribute information of the e-commerce business interaction events included in the historical application logs; determining the number of key attribute information based on the number of prior e-commerce business interaction events and the number of upstream and downstream business interaction events; based on the number of key attribute information, perform clustering processing on the abnormal pattern attribute information of the e-commerce business interaction events included in the historical application logs to obtain the number of key attribute information.
[0054] In the artificial intelligence-based business log information processing method, the process of performing knowledge entity conversion on the abnormal pattern attribute information of each e-commerce business interaction event to obtain event entity information has a rigorous logic and specific operation method.
[0055] First, in order to obtain a number of key attribute information, it is necessary to start from the historical application logs. The historical application logs contain the abnormal pattern attribute information of many e-commerce business interaction events. In this process, first obtain the number of prior e-commerce business interaction events and the number of their upstream and downstream business interaction events, and at the same time obtain the abnormal pattern attribute information of the e-commerce business interaction events in the historical application logs. For example, the prior e-commerce business interaction event is set as the product order placement event. If it is found in the log analysis within a period of time that the number of order placement events is 500 times, the average number of upstream product browsing events corresponding to each order placement event is 4 times, and the number of downstream payment events is 480 times (which means that 20 orders did not complete the payment conversion). Based on the number of such prior e-commerce business interaction events and the number of upstream and downstream business interaction events to determine the number of key attribute information. For example, according to a specific algorithm (this algorithm is based on an in-depth understanding of e-commerce business logic and data rules), the number of key attribute information is determined to be 30.
[0056] Then, according to the number of the determined key attribute information, the abnormal pattern attribute information of e-commerce business interaction events contained in the historical application logs is grouped to obtain several pieces of key attribute information. The abnormal pattern attribute information of these e-commerce business interaction events has multiple types. Taking the related product order placement as an example, there may be abnormal pattern attribute information such as "the order amount does not match the marked price of the product" and "the quantity of the ordered product exceeds the inventory limit". During the grouping process, similar or related abnormal pattern attribute information will be grouped together according to a certain logic. For example, all abnormal pattern attribute information related to the amount (such as "the order amount does not match the marked price of the product" and "the payment amount has a large difference from the order amount") is grouped into one group, and the abnormal pattern attribute information related to the product quantity (such as "the quantity of the ordered product exceeds the inventory limit" and "the quantity of products in the shopping cart does not match the quantity of the ordered product") is grouped into another group. Each group represents a piece of key attribute information.
[0057] After obtaining this key attribute information, for the abnormal pattern attribute information of each e-commerce business interaction event, it is necessary to determine the key attribute information with the smallest difference from them. For example, for a current e-commerce business interaction event, its abnormal pattern attribute information is "the order amount is much lower than the marked price of the product and there is no reasonable discount". Compare this abnormal pattern attribute information with the key attribute information obtained from the previous grouping process. In the group related to the amount, there are multiple pieces of key attribute information, such as "the order amount does not match the marked price of the product" and "the payment amount has a large difference from the order amount". Through detailed comparison, it is found that the key attribute information "the order amount does not match the marked price of the product" has the smallest difference from the abnormal pattern attribute information "the order amount is much lower than the marked price of the product and there is no reasonable discount" of the current e-commerce business interaction event. The judgment of this difference may involve multiple aspects. For example, numerically, for the key attribute information "the order amount does not match the marked price of the product", if the common non-matching ratio in the historical data is between 20% - 50%, and the order amount of the current event is 10% of the marked price of the product, it is closer to the numerical range covered by the key attribute information "the order amount does not match the marked price of the product" and is more similar to other key attribute information in terms of the numerical feature vector; semantically, both are centered around the relationship between the order amount and the marked price of the product and have a stronger correlation.
[0058] Finally, according to the entity index corresponding to the key attribute information with the smallest difference between the abnormal pattern attribute information of each e-commerce business interaction event, generate the event entity information of each e-commerce business interaction event. Each key attribute information corresponds to a specific entity index, and these entity indexes contain rich information. Continuing with the above-mentioned order placement event as an example, if the entity index corresponding to the key attribute information of "the order amount does not match the marked price of the commodity" includes the order number range of the order placement event (such as order numbers between 1000 and 2000), the value range of the marked price of the commodity (such as commodity marked prices between 50 and 200 yuan), and the characteristics of the user group involved (such as a relatively high proportion of new users), etc., which are entity-related index information. According to these entity index information, generate the event entity information of this e-commerce business interaction event, the order placement event. This event entity information will detail the relevant attributes of the order placement event, such as the order number being 1500, the order placement time being 10:00 on November 10, 2023, and the information related to the non-conformity between the order amount and the commodity marked price, such as the commodity marked price being 100 yuan and the order amount being 10 yuan, etc.
[0059] Based on the above embodiments, first, by closely combining with historical application logs, use the number of prior e-commerce business interaction events and their upstream and downstream business interaction events to determine the number of key attribute information, so that the key attribute information obtained by the clustering process has strong pertinence and representativeness. This helps to accurately find the key attribute information with the smallest difference from the abnormal pattern attribute information of each e-commerce business interaction event. Secondly, when determining the key attribute information with the smallest difference, comprehensively consider various factors such as numerical feature vectors and semantics, which can achieve more accurate matching, thereby improving the accuracy of event entity information generation. Finally, accurate event entity information provides a reliable basis for subsequent operations such as constructing an event knowledge relationship spectrum and extracting interaction event association attribute information, which helps to overall improve the quality and efficiency of business log information processing, and better realize functions such as monitoring, risk prevention, and problem troubleshooting of e-commerce business.
[0060] In a preferred embodiment, based on the distribution characteristics of each e-commerce business interaction event in the target application log, and the event entity information of each e-commerce business interaction event, generate the event knowledge relationship spectrum corresponding to the target application log, including: based on the distribution characteristics of each e-commerce business interaction event in the target application log, update the semantic variables of the distribution characteristics corresponding to each e-commerce business interaction event through the event entity information of each e-commerce business interaction event; update the semantic variables other than the distribution characteristics corresponding to each e-commerce business interaction event in the target application log to target variables, so as to generate the event knowledge relationship spectrum corresponding to the target application log.
[0061] In this preferred embodiment, an event knowledge relationship spectrum corresponding to the target application log is generated based on the distribution characteristics of each e-commerce business interaction event in the target application log and the event entity information of each e-commerce business interaction event. This process has a detailed and unique operation logic.
[0062] First, based on the distribution characteristics of each e-commerce business interaction event in the target application log, the semantic variables of the distribution characteristics corresponding to each e-commerce business interaction event are updated through the event entity information of each e-commerce business interaction event. Taking the user login event and the product browsing event in e-commerce business as examples, in the target application log, the login event occurs before the browsing event, which is a distribution characteristic. For example, the event entity information of the login event includes information such as the login time being 10:00 on December 1, 2023, the login location being Beijing, and the account level being an ordinary user; the event entity information of the browsing event includes information such as the browsing start time being 10:05 on December 1, 2023, the product category browsed being electronic products, and the browsing duration being 10 minutes. For the distribution characteristic of the login event, such as the semantic variable of the time interval, it might originally be simply represented by a numerical value of a 5-minute interval. However, after being updated through the event entity information of the login event and the browsing event, this semantic variable has a richer semantic connotation. For example, the semantic meaning that an ordinary user in Beijing starts browsing electronic products within 5 minutes after logging in at 10:00 involves the update of the semantic variable of the time interval by information such as user type, login location, and browsed product category.
[0063] Looking at the numerical manifestation, for example, in the log of a certain e-commerce platform, for the distribution characteristic of the time interval between the order placement event and the payment event, the original numerical value might be an average of 3 minutes. But when combined with the event entity information of the order placement event (such as the order amount being 100 yuan, the product being clothing, and the placing user being a new user, etc.) and the event entity information of the payment event (payment method being online payment, payment success flag, etc.), this 3-minute time interval semantic variable will be updated. For example, if it is found that when a new user places an order for low-value (100 yuan) clothing products, the payment event often occurs within a shorter time, then this semantic variable of the time interval might be updated to "short time interval from when a new user places an order for low-value clothing products to payment", which reflects the influence of numerical characteristics in the event entity information (such as the order amount being 100 yuan, which can be regarded as a numerical manifestation of low value) on the semantic variable of the distribution characteristic.
[0064] Then, update the semantic variables in the target application log, except for the distribution features corresponding to each e-commerce business interaction event, to target variables, so as to generate an event knowledge relationship spectrum corresponding to the target application log. For example, in the target application log, in addition to the semantic variables related to the distribution features of events such as the above-mentioned login-browsing, placing an order-paying, etc., there are also some other semantic variables, such as server load information, network traffic information, etc. These information may not be directly related to e-commerce business interaction events, but in order to construct a complete event knowledge relationship spectrum, these semantic variables are uniformly updated to target variables. This target variable can be a standardized representation. For example, the server load information is divided into three levels of target variable representations: high, medium, and low according to the load level, and the network traffic information is divided into three levels of target variable representations: large, medium, and small according to the traffic size.
[0065] The event knowledge relationship spectrum constructed in this way is a comprehensive structure with rich semantic information. In this relationship spectrum, the relationships between various e-commerce business interaction events are not only based on simple distribution features such as chronological order or operation order, but also incorporate more semantic connotations brought by event entity information. For example, in the event knowledge relationship spectrum, the relationship between the user login event and the product browsing event is no longer just a sequential relationship, but also includes the association of various information such as user type, login location, and browsed product categories. The relationship between the order placement event and the payment event is not only a time interval relationship, but also involves the comprehensive consideration of factors such as order amount, product category, and payment method. This construction method enables the event knowledge relationship spectrum to more accurately reflect the real relationships between e-commerce business interaction events, providing a more reliable basis for extracting interaction event correlation attribute information from the event knowledge relationship spectrum subsequently.
[0066] It can be seen that by using the event entity information of each e-commerce business interaction event to update the semantic variables of the distribution features, the relationship information in the event knowledge relationship spectrum can be made more abundant and accurate. It is no longer limited to the traditional simple distribution feature representation, but incorporates more business-related semantic information, which helps to more deeply understand the internal connections between e-commerce business interaction events. Updating other semantic variables to target variables can simplify the construction of the relationship spectrum while not losing information that is not related to business interaction events but may affect the overall business environment, making the entire event knowledge relationship spectrum both comprehensive and focused. This method of constructing the event knowledge relationship spectrum provides a more effective tool for the analysis, monitoring, risk prevention, etc. of e-commerce business, enabling more accurate discovery of abnormal situations and potential problems in the business process, and improving the efficiency and security of e-commerce business operations.
[0067] In an alternative embodiment, extracting the interaction event association attribute information from the event knowledge relationship spectrum includes: inputting the event knowledge relationship spectrum into an event knowledge mining algorithm, where the event knowledge mining algorithm includes a number of cascaded feature pyramid branches, and the event knowledge relationship spectrum is input into the first feature pyramid branch among the number of feature pyramid branches; integrating the outputs of at least two feature pyramid branches among the number of feature pyramid branches after respectively performing knowledge feature downsampling processing to obtain the interaction event association attribute information.
[0068] Based on the above alternative embodiment, the artificial intelligence-based business log information processing method further includes the following technical idea: obtaining a training data set for debugging the event knowledge mining algorithm, where the training data set includes an initial application program log, a first application program training log, and a second application program training log; wherein, the initial application program log, the first application program training log, and the second application program training log are all mapped into an event knowledge relationship spectrum; inputting the training data set into the event knowledge mining algorithm to obtain first abnormal pattern training information generated by the event knowledge mining algorithm for the initial application program log, second abnormal pattern training information for the second application program training log, and third abnormal pattern training information for the first application program training log; based on a first difference between the first abnormal pattern training information and the second abnormal pattern training information, and a second difference between the first abnormal pattern training information and the third abnormal pattern training information, determining a discrimination index according to the first difference and the second difference; taking the discrimination index not less than a preset index as a debugging termination requirement to optimize the algorithm weights of the event knowledge mining algorithm.
[0069] Further, taking the discrimination index not less than a preset index as a debugging termination requirement to optimize the algorithm weights of the event knowledge mining algorithm includes: generating a training error corresponding to the training data set based on the discrimination index and the preset index; summing the training errors corresponding to a set number of training data sets respectively to determine a cycle error in one debugging cycle; optimizing the algorithm weights of the event knowledge mining algorithm according to the cycle error.
[0070] In this alternative embodiment, the process of extracting the interaction event association attribute information from the event knowledge relationship spectrum has a set of complex and refined technical solutions, and the technical idea of debugging the event knowledge mining algorithm in the related artificial intelligence-based business log information processing method is also very crucial.
[0071] Extracting interactive event correlation attribute information from the event knowledge relationship spectrum is an important link in the whole process. First, input the event knowledge relationship spectrum into the event knowledge mining algorithm. The event knowledge mining algorithm in the embodiments of the present invention includes a number of cascaded feature pyramid branches. Taking a specific e-commerce business system as an example, for instance, this system processes a large number of user interaction events every day, such as user login, browsing products, adding to the shopping cart, placing an order, payment, logistics query, etc. These interaction events and their relationships constitute the event knowledge relationship spectrum. If there are 5 feature pyramid branches, each branch processes different feature dimensions in the event knowledge relationship spectrum.
[0072] When the event knowledge relationship spectrum enters the first feature pyramid branch, it will perform preliminary feature extraction on various types of information in the event knowledge relationship spectrum. For example, in e-commerce business, the nodes in the event knowledge relationship spectrum can represent different interaction events, and the edges represent the relationships between events. For the features of the edges, it may include information such as the time interval and the sequence between events. The first feature pyramid branch may perform quantization processing on these edge features. For example, convert the time interval into a specific numerical range. For instance, 0 - 5 minutes is represented as a numerical range of 0.1 - 0.3 (this is a mapping relationship determined according to business logic and data distribution), and 5 - 10 minutes is represented as 0.3 - 0.5, etc. For the sequence, it may be converted into a binary feature vector value through a certain coding method. For example, the event that occurs first is 0, and the event that occurs later is 1. These coded values will be part of the feature vector.
[0073] As the event knowledge relationship spectrum is passed through the feature pyramid branches, different branches will process different features. Taking the second feature pyramid branch as an example, it may pay more attention to the type of events and the related user attribute information. In e-commerce business, user attributes may include user level, user registration duration, user geographical location, etc. For different types of interaction events, such as the event of browsing products, if a high-level user browses high-value products, it may be assigned a specific feature vector value, such as [0.6, 0.3, 0.1]. In the embodiments of the present invention, the values may respectively represent the possibility of browsing high-value products, the user's purchase tendency, and the association degree with other products. For a low-level user browsing low-value products, it may be assigned a feature vector value of [0.1, 0.6, 0.3].
[0074] The third feature pyramid branch may focus on processing the semantic associations between events. In the event knowledge relationship spectrum, semantic association is a complex relationship. For example, between the order placement event and the payment event, there is not only a chronological order relationship in terms of time, but also a semantic logical association, that is, payment is an inevitable operation after order placement (under normal business processes). This branch will quantitatively process such semantic associations. For example, the semantic association strength from the order placement event to the payment event is quantified as 0.8. For other events with weaker associations, such as browsing products and logistics query (normally, browsing products does not necessarily immediately trigger a logistics query), their semantic association strength may be quantified as 0.1.
[0075] When the outputs of at least two of several feature pyramid branches need to be integrated after knowledge feature downsampling processing to obtain interactive event association attribute information, this process requires careful operation. For example, select the outputs of the second and third feature pyramid branches for integration. The numerical values of the feature vectors output by the second feature pyramid branch are such as [0.6, 0.3, 0.1] and [0.1, 0.6, 0.3] mentioned before, and the outputs of the third feature pyramid branch are such as 0.8, 0.1, etc. Knowledge feature downsampling processing is to reduce the data volume while retaining key features. For example, for the output of the second feature pyramid branch, the dimension of the feature vector may be reduced through a certain algorithm, such as from 3D to 2D, and [0.6, 0.3, 0.1] may be downsampled to [0.7, 0.3]. For the output of the third feature pyramid branch, 0.8 may be downsampled to 0.9 (indicating that the semantic association strength emphasizes its importance more after downsampling), and 0.1 may be downsampled to 0.05.
[0076] Then integration is performed. Integration is not simply adding, but different weights are assigned according to the importance of each feature. For example, the weight of the feature vector after downsampling of the second feature pyramid branch is 0.6, and the weight of the feature vector after downsampling of the third feature pyramid branch is 0.4. Then the integration result of [0.7, 0.3] and [0.9, 0.05] is [(0.7 * 0.6 + 0.9 * 0.4), (0.3 * 0.6 + 0.05 * 0.4)] = [0.78, 0.2], which is a part of the obtained interactive event association attribute information, and it synthesizes information from multiple aspects such as user attributes and semantic associations.
[0077] Based on the above replaceable embodiments, for the technical idea further included in the method for processing business log information based on artificial intelligence. First, obtain a training data set for debugging the event knowledge mining algorithm. This training data set includes initial application logs, first application training logs, and second application training logs, and all these logs are mapped into an event knowledge relationship spectrum.
[0078] Taking a large-scale e-commerce platform as an example, the initial application program logs may contain tens of thousands of interaction event records. These records cover the operations of different users at different time periods. For example, during a promotional event, the operation frequency and behavior patterns of users may be different from usual. When mapping these interaction events and their relationships into an event knowledge relationship spectrum, a huge and complex structure will be formed. For example, one node can represent the browsing event of a certain popular product, and the edges connected to it represent other events related to this browsing event, such as whether it is added to the shopping cart after browsing, whether it is shared with other users, etc. The numerical values of the feature vectors of these edges will be set according to business rules and data statistics.
[0079] The same is true for the first application program training log and the second application program training log. The first application program training log may be obtained from a specific business module of the platform, such as the interaction event log specifically for mobile users. The interaction events may focus more on the operation characteristics of the mobile end, such as the impact of touch operations and screen swipes on interaction events. The second application program training log may be obtained from the high-value user group of the platform. The operation patterns of these users may be different from those of ordinary users. For example, they are more inclined to purchase high-end products, and the order frequency may be low but the order amount may be high.
[0080] After inputting the training data set into the event knowledge mining algorithm, the first abnormal pattern training information for the initial application program log, the second abnormal pattern training information for the second application program training log, and the third abnormal pattern training information for the first application program training log generated by the event knowledge mining algorithm can be obtained.
[0081] Taking a numerical example to illustrate, for example, the first abnormal pattern training information in the initial application program log represents the abnormal operation pattern of users during a promotional event. For example, a large number of users browse high-value products frequently in a short period of time but have an extremely low order placement rate. This abnormal pattern may be represented as [0.9, 0.05, 0.05] in terms of the numerical values of the feature vectors. In the embodiments of the present invention, 0.9 represents the degree of extremely high browsing frequency of high-value products, 0.05 represents the degree of extremely low order placement rate, and the other 0.05 can represent the degree of abnormal association with other related events (such as sharing, adding to the shopping cart, etc.).
[0082] The second abnormal pattern training information may be a special abnormal pattern for the high-value user group. For example, the behavior of a large number of purchases of low-price products that occasionally appears in the high-value user group (there may be malicious brushing or other abnormal situations), and its feature vector numerical value may be [0.05, 0.9, 0.05], where 0.9 represents the degree of extremely high purchase volume of low-price products.
[0083] The third abnormal mode training information may be an abnormal mode for mobile users. For example, after a certain version update of mobile users, there is a frequent login failure but normal browsing situation. The numerical value of its feature vector may be [0.8, 0.1, 0.1], and 0.8 represents the degree of extremely high login failure frequency.
[0084] Next, based on the first difference between the first abnormal mode training information and the second abnormal mode training information, and the second difference between the first abnormal mode training information and the third abnormal mode training information, a discrimination index is determined according to the first difference and the second difference. When calculating the first difference, for example, subtract the values at the corresponding positions of the two feature vector numerical values [0.9, 0.05, 0.05] and [0.05, 0.9, 0.05] and then sum the absolute values, resulting in (0.85 + 0.85 + 0) = 1.7. When calculating the second difference, perform the same operation on [0.9, 0.05, 0.05] and [0.8, 0.1, 0.1], resulting in (0.1 + 0.05 + 0.05) = 0.2. Then, a discrimination index is determined based on these two differences. For example, using the weighted average method, the weight of the first difference is 0.6, and the weight of the second difference is 0.4. Then the discrimination index is (1.7 * 0.6 + 0.2 * 0.4) = 1.06.
[0085] Finally, with the requirement that the discrimination index is not less than the preset index as the termination requirement for debugging, the algorithm weights of the event knowledge mining algorithm are optimized. First, a training error corresponding to the training data set is generated based on the discrimination index and the preset index. For example, if the preset index is 1 and the discrimination index is 1.06, then the training error may be calculated according to a certain algorithm based on the difference between the two. For example, the difference is 0.06, and the training error is calculated to be 0.0036 through a certain function (such as the square function).
[0086] Sum the training errors corresponding to a set number of training data sets to determine the periodic error in one debugging cycle. If the set number is 10, and the training errors corresponding to each training data set are 0.0036, 0.0025, 0.0041, etc. (exemplary training errors of different training data sets), then the periodic error is the sum of these values, for example, 0.03. Optimize the algorithm weights of the event knowledge mining algorithm based on this periodic error. For example, if there is a weight related to user attribute processing in the algorithm weights is 0.3, the weight related to semantic association processing is 0.4, and the weight related to time interval processing is 0.3. According to the periodic error, these weights may be adjusted in a certain proportion, such as adjusting the weight related to user attribute processing to 0.28, the weight related to semantic association processing to 0.42, and the weight related to time interval processing to 0.3. Continuously optimizing the algorithm weights can improve the accuracy and generalization ability of the event knowledge mining algorithm.
[0087] With such a design, by means of the complex feature pyramid branch processing and knowledge feature downsampling integration operations in the event knowledge mining algorithm to extract the interactive event correlation attribute information, it is possible to deeply mine the hidden information in the event knowledge relationship spectrum and accurately obtain the interactive event correlation attribute information by synthesizing various factors. Debugging the event knowledge mining algorithm using the training data set and optimizing the algorithm weights according to the discrimination index, training error, and cycle error can enable the algorithm to better adapt to different business scenarios and data patterns, improve the accuracy and stability of the algorithm when processing business log information, thus more effectively identifying abnormal patterns, ensuring the safe and stable operation of e-commerce business, and helping e-commerce enterprises with risk prevention, user behavior analysis, and other operations.
[0088] Based on the above technical idea, the artificial intelligence-based business log information processing method further includes: obtaining a plurality of event knowledge relationship spectra and the corresponding interactive event annotation list for each event knowledge relationship spectrum, where the interactive event annotation list is obtained by sorting the event entity information of the e-commerce business interactive events included in the event knowledge relationship spectrum according to a preset rule; screening a target event knowledge relationship spectrum from the plurality of event knowledge relationship spectra, and based on the target interactive event annotation list corresponding to the target event knowledge relationship spectrum, retrieving from the plurality of event knowledge relationship spectra the first event knowledge relationship spectrum whose corresponding interactive event annotation list is the same as or includes the target interactive event annotation list; using the target event knowledge relationship spectrum as the initial application program log, using the first event knowledge relationship spectrum as the first application program training log corresponding to the target event knowledge relationship spectrum, and using the remaining event knowledge relationship spectra in the plurality of event knowledge relationship spectra except the target event knowledge relationship spectrum and the first event knowledge relationship spectrum as the second application program training log corresponding to the target event knowledge relationship spectrum to generate the training data set.
[0089] Based on the above technical idea of the artificial intelligence-based business log information processing method, a series of operations are also included to generate the training data set.
[0090] First, obtain multiple event knowledge relationship spectra and the corresponding interaction event annotation lists for each event knowledge relationship spectrum. The interaction event annotation list in the embodiments of the present invention is obtained by sorting the event entity information of the e-commerce business interaction events included in the event knowledge relationship spectrum according to preset rules. Taking the order processing process in e-commerce business as an example, the event entity information of e-commerce business interaction events such as placing an order, payment, and logistics is included in the event knowledge relationship spectrum. The entity information of the order placement event may include the order placement time, ordered goods, order amount, etc., and the entity information of the payment event includes the payment method, payment time, etc. Sorting according to preset rules, if the normal progress of the business process is taken as an important consideration factor, then the order placement event may have a higher priority because it is the starting key link of the entire order processing process. In its corresponding interaction event annotation list, the order placement event and its related entity information will be ranked in the front position, followed by the payment, logistics and other events and their entity information in turn.
[0091] Screen the target event knowledge relationship spectrum from multiple event knowledge relationship spectra. This screening process may be based on multiple factors, such as the business scope, business period, or specific business indicators involved in the event knowledge relationship spectrum. For example, there is a batch of event knowledge relationship spectra, among which some relationship spectra are about e-commerce business interaction events of a certain type of specific commodity (such as electronic products), and the other part is about other commodities (such as clothing). If the current research focus is on the business related to electronic products, then the event knowledge relationship spectrum about electronic products can be screened as the target event knowledge relationship spectrum.
[0092] Based on the target interaction event annotation list corresponding to the target event knowledge relationship spectrum, retrieve the first event knowledge relationship spectrum from multiple event knowledge relationship spectra whose corresponding interaction event annotation list is the same as or contains the target interaction event annotation list. Taking numerical examples to illustrate, for example, the feature vector value of the order placement event in the target interaction event annotation list is [0.8, 0.1, 0.1] (the values in the embodiments of the present invention can represent the comprehensive features of factors such as order placement amount, order placement quantity of goods, order placement user type, etc.), and the feature vector value of the payment event is [0.6, 0.3, 0.1]. During the retrieval process, if the feature vector value of the order placement event in the interaction event annotation list of a certain event knowledge relationship spectrum is [0.8, 0.1, 0.1] and the feature vector value of the payment event is [0.6, 0.3, 0.1], then this event knowledge relationship spectrum meets the requirements and can be regarded as the first event knowledge relationship spectrum. Or if the interaction event annotation list of a certain event knowledge relationship spectrum contains, in addition to the feature vector values of the order placement and payment events that are the same as the target interaction event annotation list, the feature vector value of the logistics event [0.5, 0.4, 0.1], it also meets the requirement of containing the target interaction event annotation list and can also be regarded as the first event knowledge relationship spectrum.
[0093] Then, use the target event knowledge relationship spectrum as the initial application program log, use the first event knowledge relationship spectrum as the first application program training log corresponding to the target event knowledge relationship spectrum, and use the remaining event knowledge relationship spectra in the multiple event knowledge relationship spectra except the target event knowledge relationship spectrum and the first event knowledge relationship spectrum as the second application program training log corresponding to the target event knowledge relationship spectrum, thereby generating a training dataset. For example, there are 10 event knowledge relationship spectra, 1 of which is selected as the target event knowledge relationship spectrum, and 3 are retrieved as the first event knowledge relationship spectra, then the remaining 6 are used as the second application program training log. By constructing the training dataset in this way, the relationship between the event knowledge relationship spectrum and its interaction event annotation list can be fully utilized, making the training dataset have a certain degree of pertinence and representativeness.
[0094] By sorting the event entity information according to preset rules to obtain an interaction event annotation list, the training data set can better focus on important e-commerce business interaction event features during the construction process. Screening the target event knowledge relationship spectrum and retrieving the first event knowledge relationship spectrum according to the target interaction event annotation list helps to ensure the logical relevance and consistency within the training data set. Using different event knowledge relationship spectra as the initial application program log, the first application program training log, and the second application program training log respectively can enable the training data set to cover different situations, improve the accuracy and generalization ability of the artificial intelligence-based business log information processing method when processing different types of business logs, and thus better realize functions such as the analysis and anomaly detection of e-commerce business interaction events.
[0095] Based on the above technical idea, obtaining a training data set for debugging the event knowledge mining algorithm includes: obtaining the selected initial application program log; adjusting the initial application program log on the basis that the business association features in the initial application program log have not been updated to obtain the first application program training log corresponding to the initial application program log.
[0096] Alternatively, based on the above technical idea, obtaining a training data set for debugging the event knowledge mining algorithm includes: obtaining the selected initial application program log; updating at least one of the e-commerce business interaction events and business association features in the initial application program log to obtain the second application program training log corresponding to the initial application program log.
[0097] Based on the above technical idea, there is a specific operation method for obtaining a training data set for debugging the event knowledge mining algorithm.
[0098] First, regarding the method of obtaining the selected initial application program log and adjusting the initial application program log on the basis that the business association features in the initial application program log have not been updated to obtain the first application program training log corresponding to the initial application program log.
[0099] The initial application log contains information such as numerous e-commerce business interaction events and the business association characteristics between them. Taking the user behavior log in e-commerce business as an example, a series of interaction events such as user login, product browsing, placing an order, and payment are recorded in the initial application log. For example, in this initial application log, for the user login event, the feature vector value is [0.1, 0.8, 0.1] (the values in the embodiments of the present invention may respectively represent certain quantitative characteristics of factors such as login time, login device type, and login location), and the feature vector value of the product browsing event is [0.3, 0.5, 0.2] (which can represent factors such as the category of products browsed, browsing duration, and browsing period). In terms of business association characteristics, for example, the association strength between user login and product browsing may be quantified as 0.6, indicating the possibility of browsing after login to a certain extent.
[0100] Based on the business association characteristics not being updated, the initial application log is adjusted to obtain the first application training log. This adjustment may be a fine-tuning of certain numerical characteristics in the interaction events. For example, for the user login event, the feature value of the login time is adjusted from the original [0.1, 0.8, 0.1] to [0.2, 0.7, 0.1], which may simulate a login situation with a slightly delayed time. For the product browsing event, the feature value of the browsing duration is adjusted from [0.3, 0.5, 0.2] to [0.4, 0.4, 0.2], indicating a change in the browsing duration. These adjusted interaction events are combined to form the first application training log, which is consistent with the initial application log in terms of business association characteristics but different in certain numerical characteristics of the interaction events, so that it can be used to test the performance of the event knowledge mining algorithm when facing similar business associations but changes in the numerical characteristics of the interaction events.
[0101] Another way to obtain the training dataset is to obtain the selected initial application log, and then update at least one of the e-commerce business interaction events and business association characteristics in the initial application log to obtain the second application training log corresponding to the initial application log.
[0102] Still taking the user behavior logs of the previous e-commerce business as an example, the e-commerce business interaction events in the initial application logs are updated. For example, in the user login event, the original login device type might mainly be mobile devices, but now it is updated to show that some users log in from the PC side, which changes the characteristics of the login event. From the perspective of the feature vector values, if the feature vector value for the original mobile login was [0.1, 0.8, 0.1], where 0.8 represents the feature of the mobile device type, after updating to a PC login, this value might change to [0.1, 0.2, 0.7] (here 0.2 indicates a weakened feature of the mobile device, and 0.7 indicates an enhanced feature of the PC device).
[0103] Regarding the update of business association features, for example, the original association strength between user login and product browsing was 0.6. Now, due to a change in a certain business strategy, such as the launch of personalized recommendations for logged-in users, which makes it more likely for users to browse products after logging in, this association strength is updated to 0.8. These updated logs of e-commerce business interaction events and business association features constitute the second application program training logs. This method can be used to test the performance of the event knowledge mining algorithm when faced with changes in e-commerce business interaction events and business association features, ensuring that the algorithm can adapt to different business situations.
[0104] By adjusting the initial application logs under the condition that the business association features remain unchanged to obtain the first application program training logs, the sensitivity of the event knowledge mining algorithm to changes in the numerical features of interaction events can be tested, which helps improve the accuracy of the algorithm when dealing with different data performances under similar business logics. And by updating the e-commerce business interaction events and business association features to obtain the second application program training logs, the event knowledge mining algorithm can better adapt to the dynamic changes of the e-commerce business, enhance the generalization ability of the algorithm, enable the algorithm to effectively mine event knowledge under different business scenarios and changes in business logics, thereby improving the reliability and effectiveness of the entire artificial intelligence-based business log information processing method.
[0105] In an optional technical solution, based on the abnormal pattern attribute information and the interaction event association attribute information, determining whether the target application log matches the historical application logs in the application log pool includes: if the abnormal pattern attribute information meets the correspondence condition with the abnormal pattern attribute information corresponding to the specified historical application log, and the interaction event association attribute information meets the correspondence condition with the interaction event association attribute information corresponding to the specified historical application log, then it is determined that the target application log matches the specified historical application log.
[0106] In another alternative technical solution, based on the abnormal pattern attribute information and the interaction event associated attribute information, determining whether the target application program log matches the historical application program logs in the application program log pool includes: if the abnormal pattern attribute information does not meet the corresponding condition with the abnormal pattern attribute information corresponding to the specified historical application program log, or the interaction event associated attribute information does not meet the corresponding condition with the interaction event associated attribute information corresponding to the specified historical application program log, it is determined that the target application program log does not match the specified historical application program log.
[0107] In the method for processing business log information based on artificial intelligence, for the target application program log and the historical application program log, both contain a large amount of information related to e-commerce business interaction events, and this information is embodied in the form of abnormal pattern attribute information and interaction event associated attribute information.
[0108] First, look at the situation where if the abnormal pattern attribute information meets the corresponding condition with the abnormal pattern attribute information corresponding to the specified historical application program log, and the interaction event associated attribute information meets the corresponding condition with the interaction event associated attribute information corresponding to the specified historical application program log, it is determined that the target application program log matches the specified historical application program log.
[0109] Taking the order processing process in e-commerce business as an example, in the target application program log, the abnormal pattern attribute information for the order placement event may be presented in the form of eigenvector values. For example, the eigenvector value of the abnormal pattern attribute information regarding the order placement amount is [0.8, 0.1, 0.1] (the values in the embodiments of the present invention can represent the quantitative characteristics of factors such as the order placement amount being too high, the order placement amount not matching the commodity value, and the order placement amount not matching the user's historical consumption habits). In the specified historical application program log, the eigenvector value of the abnormal pattern attribute information corresponding to the order placement event is [0.7, 0.2, 0.1]. Numerically, the two are similar in terms of the two factors of the order placement amount being too high and the order placement amount not matching the commodity value, and can be considered to meet the corresponding condition.
[0110] Next, look at the interaction event correlation attribute information. In the target application log, the interaction event correlation attribute information between the order placement event and the payment event may be represented by the eigenvector values [0.6, 0.3, 0.1] (here, it can represent factors such as the closeness of the correlation and the time interval of the correlation). In the specified historical application log, the interaction event correlation attribute information between the order placement and payment events is [0.5, 0.4, 0.1]. The two are similar in terms of the closeness of the correlation and other factors, meeting the correspondence condition. When both of these conditions are met, it can be determined that the target application log matches the specified historical application log. This match means that a similar pattern has occurred historically in the target application log, which may be normal business fluctuations or a repetition of known business situations.
[0111] Next, consider the case where the abnormal pattern attribute information does not meet the correspondence condition with the abnormal pattern attribute information corresponding to the specified historical application log, or the interaction event correlation attribute information does not meet the correspondence condition with the interaction event correlation attribute information corresponding to the specified historical application log. In such a case, it is determined that the target application log does not match the specified historical application log.
[0112] For example, in the target application log, the eigenvector values of the abnormal pattern attribute information for the product browsing event are [0.9, 0.05, 0.05] (here, it can represent factors such as abnormally quickly browsing a large number of products and browsing products that do not match the user's interests). In the specified historical application log, the eigenvector values of the abnormal pattern attribute information corresponding to the product browsing event are [0.1, 0.8, 0.1]. The two differ greatly in various factors and do not meet the correspondence condition.
[0113] Or in terms of the interaction event correlation attribute information, in the target application log, the eigenvector values of the interaction event correlation attribute information between adding a product to the shopping cart and the order placement event are [0.8, 0.1, 0.1] (representing factors such as the correlation strength and the order sequence between the two). In the specified historical application log, the corresponding interaction event correlation attribute information is [0.1, 0.8, 0.1]. The two are very different in terms of the correlation strength and the order sequence, etc., and do not meet the correspondence condition. When such a situation where the abnormal pattern attribute information or the interaction event correlation attribute information does not meet the correspondence condition occurs, it is determined that the target application log does not match the specified historical application log. This non - match indicates that the situation in the target application log is newly emerged or is very different from the historical situation, and may require further attention. For example, it may be a new business risk, a new user behavior pattern, or a new problem with the system, etc.
[0114] By accurately comparing the abnormal pattern attribute information and interaction event correlation attribute information of the target application log and the historical application log, it is possible to accurately identify whether the situation in the target application log has occurred in the past. If there is a match, it helps to classify the situation in the target application log into known business models, reducing unnecessary analysis and processing. If there is no match, new situations can be discovered in a timely manner, enabling the e-commerce business operator to perform operations such as risk assessment, business optimization, or problem troubleshooting for the new situations, improving the security, stability, and operational efficiency of the e-commerce business.
[0115] Based on S101 - S104, in an independent embodiment, the method for processing business log information based on artificial intelligence further includes: if it is detected that there is a historical application log that needs to be disaster-toleranced to the application log pool, identify each e-commerce business interaction event included in the historical application log to obtain an interaction event recognition report corresponding to the historical application log; generate abnormal pattern attribute information for each e-commerce business interaction event in the historical application log based on the interaction event recognition report corresponding to the historical application log to obtain abnormal pattern attribute information corresponding to the historical application log; extract business association tags between each e-commerce business interaction event included in the historical application log based on the abnormal pattern attribute information corresponding to each e-commerce business interaction event in the historical application log to obtain interaction event correlation attribute information corresponding to the historical application log; synchronously disaster-tolerate the historical application log and the abnormal pattern attribute information and interaction event correlation attribute information corresponding to the historical application log to the application log pool.
[0116] Based on S101 - S104, this independent embodiment adds new content to the method for processing business log information based on artificial intelligence, especially in terms of disaster-tolerancing historical application logs to the application log pool.
[0117] When it is detected that there are historical application logs that need to be disaster-toleranced to the application log pool, it is first necessary to identify each e-commerce business interaction event contained in the historical application logs, so as to obtain an interaction event recognition report corresponding to the historical application logs. Taking the historical records of e-commerce business as an example, it contains e-commerce business interaction events such as user login, product browsing, placing an order, and payment. For the user login event, the login time may be recorded (for example, represented by the feature vector value [0.1, 0.8, 0.1], and the values in the embodiments of the present invention may respectively represent the quantification features of factors such as the login period, the type of login device, and the login location), and the product browsing event may record the product category browsed (represented by [0.3, 0.5, 0.2], which can represent factors such as the popularity of the product, the price range of the product, and the category attributes of the product), etc. Through the analysis and identification of this information, a complete interaction event recognition report is formed, which details information such as the type of each interaction event and the relevant feature vector values.
[0118] Next, based on the interaction event recognition report corresponding to the historical application logs, generate the abnormal pattern attribute information of each e-commerce business interaction event in the historical application logs, and obtain the abnormal pattern attribute information corresponding to the historical application logs. Still taking the above e-commerce business interaction events as an example, for the placing an order event, if there is an abnormal relationship between the order amount and the marked price of the product, such as the order amount is far lower than the marked price of the product and there is no reasonable discount or promotion explanation, then the abnormal pattern attribute information of the placing an order event may be represented by the feature vector value [0.8, 0.1, 0.1] (the values in the embodiments of the present invention can represent factors such as the difference degree between the order amount and the marked price, whether there are suspicious operation factors, and the deviation degree from the user's historical order amount pattern). By analyzing each interaction event in the interaction event recognition report, determine whether each interaction event has an abnormality and the specific pattern attributes of the abnormality, so as to obtain the abnormal pattern attribute information corresponding to the entire historical application logs.
[0119] Then, based on the abnormal pattern attribute information corresponding to each e-commerce business interaction event in the historical application log, extract the business association tags between each e-commerce business interaction event contained in the historical application log, and obtain the interaction event association attribute information corresponding to the historical application log. For example, in the historical application log, if it is found that the login event has abnormal pattern attribute information (such as abnormal login from a different location, and the feature vector values are [0.7, 0.2, 0.1], which can represent the degree of abnormality of the login location, the deviation from the usual login location, the risk factors of the login, etc.), and the subsequent order placement event is also abnormal (such as abnormal order amount, and the feature vector values are [0.8, 0.1, 0.1]), then these two events can be marked with a specific business association tag, such as "association between abnormal login and abnormal order amount". Through the relationship analysis of this kind based on the abnormal pattern attribute information between all e-commerce business interaction events, the interaction event association attribute information corresponding to the historical application log is obtained.
[0120] Finally, synchronize and disaster-tolerate the historical application log, the abnormal pattern attribute information corresponding to the historical application log, and the interaction event association attribute information to the application log pool. The significance of this is that when a comprehensive analysis, risk assessment, or problem troubleshooting of the e-commerce business is required, the data in the application log pool not only contains the original historical application log, but also the abnormal pattern attribute information and interaction event association attribute information obtained through analysis and processing. This enables the direct utilization of these rich information when querying, analyzing, or comparing the data in the application log pool with new target application logs in the future, without the need to repeat the analysis and processing of the historical application log again, improving the efficiency and accuracy of data processing.
[0121] By comprehensively analyzing and processing the historical application log during the disaster-tolerant process, obtaining the abnormal pattern attribute information and interaction event association attribute information and synchronizing and disaster-tolerating them to the application log pool, the data content in the application log pool can be enriched. This helps to improve the efficiency of subsequent data processing. For example, when performing operations such as log matching and anomaly detection, these existing analysis results can be directly utilized. At the same time, the preservation of the complete historical application log and its related analysis information is beneficial for the long-term monitoring and risk analysis of the e-commerce business, enabling a more comprehensive understanding of the development trend and potential risks of the e-commerce business, and thus providing better support for the stable operation of the e-commerce business.
[0122] In summary, the embodiments of the present invention obtain an identification report by identifying e-commerce business interaction events, which can comprehensively sort out the business activities in the target application program logs. Generating abnormal pattern attribute information helps to accurately locate interaction events that may pose risks or do not conform to the normal process, such as discovering abnormal order amounts or login behaviors. Extracting the associated attribute information of interaction events can deeply explore the internal connections between events, such as the association between abnormal order placement and payment. Judging the matching with historical logs based on this information can quickly determine whether the current log situation is a new problem, improve the efficiency of e-commerce business monitoring, and timely discover problems such as malicious operations and business process loopholes, ensuring the safe, stable, and efficient operation of e-commerce business.
[0123] Furthermore, a readable storage medium is also provided, on which a program is stored, and when the program is executed by a processor, the above-mentioned method is implemented.
[0124] Those skilled in the art can clearly understand that for the convenience and simplicity of description, the specific working processes of the above-described exemplary systems and devices can refer to the corresponding processes in the foregoing method embodiments, which will not be repeated here. In several embodiments provided by the embodiments of the present invention, it should be understood that the disclosed systems, devices, and methods can be implemented in other ways. The device embodiments described above are merely illustrative. For example, the division of the units is only a logical function division, and there may be other division methods in actual implementation. For another example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed couplings or direct couplings or communication connections to each other can be through some communication interfaces. The indirect couplings or communication connections of the devices or units can be in electrical, mechanical, or other forms.
Claims
1. A method for processing business log information based on artificial intelligence, characterized in that, The method is applied to a business log information processing server, and the method includes: Identifying each e-commerce business interaction event included in the target application program log to obtain an interaction event identification report; Generating abnormal pattern attribute information of each e-commerce business interaction event based on the interaction event identification report. Specifically, by learning and analyzing normal e-commerce business interaction event data, a model or rule set of normal patterns is established, and each e-commerce business interaction event in the interaction event identification report is compared with the model or rule set of normal patterns, so as to determine whether each e-commerce business interaction event has abnormal pattern attributes, and obtain the abnormal pattern attribute information of each e-commerce business interaction event; Extracting business association labels between each e-commerce business interaction event included in the target application program log based on the abnormal pattern attribute information of each e-commerce business interaction event to obtain interaction event association attribute information, where the interaction event association attribute information is used to reflect the mutual relationship between each e-commerce business interaction event in the target application program log under abnormal conditions; Judging whether the target application program log matches the historical application program logs in the application program log pool based on the abnormal pattern attribute information and the interaction event association attribute information; Extracting business association labels between each e-commerce business interaction event included in the target application program log based on the abnormal pattern attribute information of each e-commerce business interaction event to obtain interaction event association attribute information, including: Performing knowledge entity conversion on each e-commerce business interaction event based on the abnormal pattern attribute information of each e-commerce business interaction event to obtain event entity information of each e-commerce business interaction event; Generating an event knowledge relationship spectrum corresponding to the target application program log based on the distribution characteristics of each e-commerce business interaction event in the target application program log and the event entity information of each e-commerce business interaction event; Extracting the interaction event association attribute information from the event knowledge relationship spectrum.
2. The method for processing business log information based on artificial intelligence according to claim 1, wherein Performing knowledge entity conversion on each e-commerce business interaction event based on the abnormal pattern attribute information of each e-commerce business interaction event to obtain event entity information of each e-commerce business interaction event, including: Obtaining a number of key attribute information, where the key attribute information is obtained by clustering the abnormal pattern attribute information of e-commerce business interaction events included in historical application program logs; Determining the key attribute information with the smallest difference from the abnormal pattern attribute information of each e-commerce business interaction event based on the difference between the abnormal pattern attribute information of each e-commerce business interaction event and the number of key attribute information; Generating event entity information of each e-commerce business interaction event according to the entity index corresponding to the key attribute information with the smallest difference from the abnormal pattern attribute information of each e-commerce business interaction event; The method for processing business log information based on artificial intelligence further includes: Obtain the number of prior e-commerce business interaction events and the number of upstream and downstream business interaction events of the prior e-commerce business interaction events, and obtain the abnormal pattern attribute information of the e-commerce business interaction events included in the historical application log; Determine the number of key attribute information based on the number of the prior e-commerce business interaction events and the number of the upstream and downstream business interaction events; Based on the number of the key attribute information, perform clustering processing on the abnormal pattern attribute information of the e-commerce business interaction events included in the historical application log to obtain the several key attribute information.
3. The method for processing business log information based on artificial intelligence according to claim 1, characterized in that Generate an event knowledge relationship spectrum corresponding to the target application log based on the distribution characteristics of each e-commerce business interaction event in the target application log and the event entity information of each e-commerce business interaction event, including: Based on the distribution characteristics of each e-commerce business interaction event in the target application log, update the semantic variables of the distribution characteristics corresponding to each e-commerce business interaction event through the event entity information of each e-commerce business interaction event; Update the semantic variables other than the distribution characteristics corresponding to each e-commerce business interaction event in the target application log to target variables to generate an event knowledge relationship spectrum corresponding to the target application log.
4. The method for processing business log information based on artificial intelligence according to claim 1, wherein Extract the interaction event association attribute information from the event knowledge relationship spectrum, including: Input the event knowledge relationship spectrum into an event knowledge mining algorithm, where the event knowledge mining algorithm includes several cascaded feature pyramid branches, and the event knowledge relationship spectrum is input into the first feature pyramid branch among the several feature pyramid branches; Integrate the outputs of at least two feature pyramid branches among the several feature pyramid branches after performing knowledge feature downsampling processing respectively to obtain the interaction event association attribute information; The business log information processing method based on artificial intelligence further includes: Obtain a training data set for debugging the event knowledge mining algorithm, where the training data set includes an initial application log, a first application training log, and a second application training log; wherein, the initial application log, the first application training log, and the second application training log are all mapped into event knowledge relationship spectra; Input the training data set into the event knowledge mining algorithm to obtain first abnormal pattern training information for the initial application log, second abnormal pattern training information for the second application training log, and third abnormal pattern training information for the first application training log generated by the event knowledge mining algorithm; Based on the first difference between the first abnormal pattern training information and the second abnormal pattern training information, and the second difference between the first abnormal pattern training information and the third abnormal pattern training information, determine a discrimination index according to the first difference and the second difference; Optimize the algorithm weights of the event knowledge mining algorithm with the requirement that the discrimination index is not less than a preset index as the debugging termination requirement.
5. The method for processing business log information based on artificial intelligence according to claim 4, wherein Taking that the discrimination index is not less than the preset index as the debugging termination requirement, optimize the algorithm weights of the event knowledge mining algorithm, including: Generate the training error corresponding to the training data set based on the discrimination index and the preset index; Sum up the training errors corresponding to a set number of training data sets to determine the periodic error in one debugging cycle; Optimize the algorithm weights of the event knowledge mining algorithm according to the periodic error.
6. The method for processing service log information based on artificial intelligence according to claim 4, wherein The business log information processing method based on artificial intelligence further includes: Obtain multiple event knowledge relationship spectra and the interactive event annotation list corresponding to each event knowledge relationship spectrum, where the interactive event annotation list is obtained by sorting the event entity information of the e-commerce business interactive events included in the event knowledge relationship spectrum according to preset rules; Screen the target event knowledge relationship spectrum from the multiple event knowledge relationship spectra, and based on the target interactive event annotation list corresponding to the target event knowledge relationship spectrum, retrieve from the multiple event knowledge relationship spectra the first event knowledge relationship spectrum whose corresponding interactive event annotation list is the same as or includes the target interactive event annotation list; Use the target event knowledge relationship spectrum as the initial application program log, use the first event knowledge relationship spectrum as the first application program training log corresponding to the target event knowledge relationship spectrum, and use the remaining event knowledge relationship spectra in the multiple event knowledge relationship spectra except the target event knowledge relationship spectrum and the first event knowledge relationship spectrum as the second application program training log corresponding to the target event knowledge relationship spectrum to generate the training data set.
7. The method for processing business log information based on artificial intelligence according to claim 4, wherein Obtain the training data set for debugging the event knowledge mining algorithm, including: Obtain the selected initial application program log; On the basis that the business association features in the initial application program log have not been updated, adjust the initial application program log to obtain the first application program training log corresponding to the initial application program log; Alternatively, obtain the training data set for debugging the event knowledge mining algorithm, including: Obtain the selected initial application program log; Update at least one of the e-commerce business interactive events and business association features in the initial application program log to obtain the second application program training log corresponding to the initial application program log.
8. The method for processing business log information based on artificial intelligence according to claim 1, wherein Based on the abnormal pattern attribute information and the interactive event association attribute information, determine whether the target application program log matches the historical application program logs in the application program log pool, including: if the abnormal pattern attribute information meets the correspondence condition with the abnormal pattern attribute information corresponding to the specified historical application program log, and the interactive event association attribute information meets the correspondence condition with the interactive event association attribute information corresponding to the specified historical application program log, then determine that the target application program log matches the specified historical application program log; Alternatively, based on the abnormal pattern attribute information and the interaction event associated attribute information, determining whether the target application program log matches the historical application program logs in the application program log pool includes: if the abnormal pattern attribute information does not meet the corresponding condition with the abnormal pattern attribute information corresponding to the specified historical application program log, or the interaction event associated attribute information does not meet the corresponding condition with the interaction event associated attribute information corresponding to the specified historical application program log, then it is determined that the target application program log does not match the specified historical application program log.
9. A business log information processing server, characterized in that, It includes a processor and a memory; the processor and the memory are communicatively connected, and the processor is configured to read and execute a computer program from the memory to implement the method according to any one of claims 1-8 above.
Citation Information
Patent Citations
Fraud discrimination method and device and storage medium
CN109816397A
Smart park industrial control system network attack scene identification method based on multi-Agent distributed association analysis
CN114915478A