Method, device and server for identifying risk type of internet of things card, and storage medium

By adding a directional network module to the output layer of the large language model, the semantic illusion problem caused by the lack of semantic relationships between IoT card terminal types is solved, and high-accuracy identification of IoT card risk types is achieved.

CN119544370BActive Publication Date: 2025-11-25CHINA UNITED NETWORK COMM GRP CO LTD +2
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411814999.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-10
Publication Date
2025-11-25
Estimated Expiration
2044-12-10

AI Technical Summary

Technical Problem

Because there is no semantic relationship between the terminal types of IoT cards, the large language model suffers from semantic illusion, outputting incorrect risk types and reducing the accuracy of identifying IoT card risk types.

Method used

By adding a directional network module to the output layer of the large language model, the probability value corresponding to the terminal type with the largest comprehensive weight value is obtained from multiple terminal types to be pointed to. Combined with IoT card data and risk type feature library, the risk type of IoT card is identified.

Benefits of technology

It improves the accuracy of identifying risk types of IoT cards, avoids the semantic illusion problem of large language models, and provides accurate data support.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119544370B_ABST
    Figure CN119544370B_ABST
Patent Text Reader

Abstract

The application provides a method and device for identifying risk types of Internet of Things (IoT) cards, a server and a storage medium. The method comprises: collecting IoT card data from an IoT data platform; inputting the IoT card data into an adjusted large language model; generating a plurality of terminal types to be pointed to corresponding to each terminal type by an output layer of the adjusted large language model; inputting the plurality of terminal types to be pointed to into a directional network module, so that the directional network module obtains a probability value corresponding to a terminal type to be pointed to with the largest comprehensive weight value from the plurality of terminal types to be pointed to; obtaining IoT card data corresponding to the probability value from the IoT card data to obtain IoT card data corresponding to each terminal type; and identifying the risk types of the IoT cards according to IoT card feature data of each terminal type and data in an IoT card risk type feature library. The method improves the accuracy of identifying the risk types of the IoT cards.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of Internet of Things, and in particular to an Internet of Things card risk type identification method and device, a server and a storage medium. BACKGROUND

[0002] An Internet of Things card is a traffic card provided by an operator to meet the management needs of the Internet of Things industry for device networking, and provides network connection services for Internet of Things devices, and cannot be used for personal devices such as mobile phones. Due to the simplification of the application process of the Internet of Things card, many Internet of Things card misuse problems have arisen.

[0003] At present, in the safety monitoring process of the Internet of Things card, since the terminal types of the Internet of Things card do not have semantic relationships, the large language model has a semantic illusion problem, which outputs an incorrect risk type, and reduces the accuracy of identifying the risk type of the Internet of Things card. SUMMARY

[0004] The embodiments of the present application provide an Internet of Things card risk type identification method, device, server and storage medium, to achieve the effect of improving the accuracy of identifying the risk type of the Internet of Things card.

[0005] In a first aspect, the embodiments of the present application provide an Internet of Things card risk type identification method, comprising: collecting Internet of Things card data from an Internet of Things data platform; wherein the Internet of Things card data comprises a plurality of terminal types; inputting the Internet of Things card data into an adjusted large language model; wherein the adjusted large language model comprises a directional network module; the output layer of the adjusted large language model generates a plurality of terminal types to be pointed to corresponding to each terminal type; inputting the plurality of terminal types to be pointed to into the directional network module, so that the directional network module obtains a probability value corresponding to a terminal type to be pointed to with the largest comprehensive weight value from the plurality of terminal types to be pointed to; obtaining the Internet of Things card data corresponding to the probability value from the Internet of Things card data, to obtain the Internet of Things card data corresponding to each terminal type; extracting the features of the Internet of Things card data corresponding to each terminal type to obtain Internet of Things card feature data of each terminal type; and identifying the Internet of Things card risk type of the Internet of Things card data corresponding to each terminal type according to the Internet of Things card feature data of each terminal type and the data in the Internet of Things card risk type feature library.

[0006] In a possible implementation, inputting the plurality of terminal types to be pointed to into the directional network module, so that the directional network module obtains a probability value corresponding to a terminal type to be pointed to with the largest comprehensive weight value from the plurality of terminal types to be pointed to, comprises: obtaining a comprehensive weight value of each terminal type to be pointed to; and obtaining a probability value corresponding to a terminal type to be pointed to with the largest comprehensive weight value from the plurality of terminal types to be pointed to according to the comprehensive weight value of each terminal type to be pointed to.

[0007] In a possible implementation, a formula for obtaining a comprehensive weight value of each terminal type to be pointed to is:

[0008]

[0009] In the formula, denotes a comprehensive weight value of the jth terminal type to be pointed to, i denotes the number of the plurality of terminal types to be pointed to, and γ denotes an initialization matrix weight. And denotes different two characters in the jth terminal type to be pointed to. denotes a weight of . denotes a weight of .

[0010] In a possible implementation, a formula for obtaining a probability value corresponding to a terminal type to be pointed to with the maximum comprehensive weight value is:

[0011]

[0012] In the formula, denotes a probability value corresponding to the terminal type to be pointed to with the maximum comprehensive weight value. denotes obtaining the maximum comprehensive weight value from the i terminal types to be pointed to, and γ denotes an initialization matrix weight.

[0013] In a possible implementation, before collecting the Internet of Things card data from the Internet of Things data platform, the method further includes: collecting historical Internet of Things card data from the Internet of Things data platform at a time; labeling a risk type involved in the historical Internet of Things card data according to a risk type sample library to obtain an Internet of Things card risk type library; and performing feature extraction on historical Internet of Things card data of different risk types in the Internet of Things card risk type library to obtain an Internet of Things card risk type feature library.

[0014] In a possible implementation, before collecting the Internet of Things card data from the Internet of Things data platform, the method further includes: shielding a specific attention head of the large language model to obtain an initial large language model; and adding a pointing network module to an output layer of the initial large language model to obtain an adjusted large language model.

[0015] In a second aspect, an embodiment of the present application provides an Internet of Things card risk type identification device, including:

[0016] A data collection module is configured to collect Internet of Things card data from an Internet of Things data platform; wherein the Internet of Things card data includes a plurality of terminal types.

[0017] The input module is configured to input the Internet of Things card data into the adjusted large language model; and the adjusted large language model comprises the directional network module.

[0018] The generation module is configured to generate, by an output layer of the adjusted large language model, a plurality of terminal types to be directed corresponding to each terminal type.

[0019] The first acquisition module is configured to input the plurality of terminal types to be directed into the directional network module, so that the directional network module acquires a probability value corresponding to a terminal type to be directed with the largest comprehensive weight value from the plurality of terminal types to be directed.

[0020] The second acquisition module is configured to acquire, from the Internet of Things card data, the Internet of Things card data corresponding to the probability value, to obtain the Internet of Things card data corresponding to each terminal type.

[0021] The extraction module is configured to extract features of the Internet of Things card data corresponding to each terminal type, to obtain Internet of Things card feature data of each terminal type.

[0022] The risk type identification module is configured to identify, according to the Internet of Things card feature data of each terminal type and data in an Internet of Things card risk type feature library, an Internet of Things card risk type of the Internet of Things card data corresponding to each terminal type.

[0023] In a third aspect, an embodiment of the present application provides a server, comprising: a memory, a processor;

[0024] The memory stores computer execution instructions.

[0025] The processor executes the computer execution instructions stored in the memory, so that the processor executes the first aspect and / or various possible implementation manners of the first aspect.

[0026] In a fourth aspect, an embodiment of the present application provides a computer readable storage medium, wherein the computer readable storage medium stores computer execution instructions, and the computer execution instructions are executed by a processor to implement the first aspect and / or various possible implementation manners of the first aspect.

[0027] In a fifth aspect, an embodiment of the present application provides a computer program product, comprising a computer program, and the computer program is executed by a processor to implement the first aspect and / or various possible implementation manners of the first aspect.

[0028] The method and device for identifying the risk type of the Internet of Things card provided by the embodiment of the application, the collected Internet of Things card data containing the terminal type are input into the adjusted large language model, and a plurality of terminal types to be pointed to corresponding to each terminal type are generated at the output layer of the adjusted large language model; the pointing network module is used to obtain a probability value corresponding to the terminal type to be pointed to with the maximum comprehensive weight value from the Internet of Things card data. The pointing network module can point to the terminal type in the Internet of Things card data from the collected Internet of Things card data, and output the Internet of Things card data related to the terminal type, so as to avoid the semantic illusion problem of the large language model, and provide data support for identifying the risk type of the Internet of Things card. The features of the Internet of Things card data are extracted, and the risk type is identified according to the Internet of Things card feature data and the data in the Internet of Things card risk type feature library. Therefore, the accuracy of identifying the risk type of the Internet of Things card is improved. BRIEF DESCRIPTION OF DRAWINGS

[0029] The accompanying drawings, which are incorporated herein and form a part of the specification, illustrate embodiments consistent with the present application and, together with the description, further serve to explain the principles of the application.

[0030] Figure 1 The structural schematic diagram of the server provided by the embodiment of the application is shown in the accompanying drawings.

[0031] Figure 2 The flowchart of the method for identifying the risk type of the Internet of Things card provided by the embodiment of the application is shown in the accompanying drawings.

[0032] Figure 3 The structural schematic diagram of the device for identifying the risk type of the Internet of Things card provided by the embodiment of the application is shown in the accompanying drawings.

[0033] Figure 4 The hardware structural schematic diagram of the server provided by the embodiment of the application is shown in the accompanying drawings.

[0034] The specific embodiments of the application have been shown in the above-described drawings, and will be described in more detail hereinafter. These drawings and the description are not intended to limit the scope of the concept of the application by any means, but to illustrate the concept of the application to those skilled in the art by referring to specific embodiments. DETAILED DESCRIPTION

[0035] The exemplary embodiments will be described in detail herein with reference to the accompanying drawings. Unless otherwise indicated, the same numbers on different drawings represent the same or similar elements. The following detailed description does not limit the application to only the disclosed embodiments. Instead, the disclosed embodiments are examples of apparatuses and methods consistent with the application as recited in the claims.

[0036] Figure 1 A structural diagram of a server provided in an embodiment of the present application is shown in FIG. 1. Figure 1 As shown in the figure, the server provided in the embodiment includes a receiving device 101, a processor 102, and a display device 103.

[0037] It can be understood that the structure shown in the embodiment of the present application does not constitute a specific limitation on the method. In other possible embodiments of the present application, the above architecture can include more or fewer components than the diagram, or combine certain components, or split certain components, or different component arrangement, which can be determined according to the actual application scenario, and is not limited herein. Figure 1 The components shown in the figure can be implemented in hardware, software, or a combination of software and hardware.

[0038] In the specific implementation process, the receiving device 101 can be an input / output interface or a communication interface, and can collect Internet of Things card data from an Internet of Things data platform.

[0039] The processor 102 can process the Internet of Things card data collected from the Internet of Things data platform to obtain the risk type of the Internet of Things card.

[0040] The display device 103 can be used to display the risk type of the Internet of Things card.

[0041] It should be understood that the above processor can be implemented by reading instructions in the memory of the processor and executing the instructions, or by a chip circuit.

[0042] In addition, the network architecture and business scenarios described in the embodiments of the present application are used to more clearly illustrate the technical solutions of the embodiments of the present application, and do not constitute a limitation on the technical solutions provided by the embodiments of the present application. Those skilled in the art can know that, as the network architecture evolves and new business scenarios appear, the technical solutions provided by the embodiments of the present application are also applicable to similar technical problems.

[0043] The Internet of Things card is a traffic card provided by an operator to meet the management needs of the Internet of Things industry for device networking, and provides network connection services for Internet of Things devices, and cannot be used for personal devices such as mobile phones. Due to the simplification of the application process of the Internet of Things card, many Internet of Things card misuse problems have arisen. At present, in the safety monitoring process of the Internet of Things card, it is found that due to the absence of semantic relationship between the terminal types of the Internet of Things card, the large language model has a semantic illusion problem, outputting an incorrect risk type, which reduces the accuracy of identifying the risk type of the Internet of Things card.

[0044] To solve the above technical problems, the present application proposes the following technical concept: because the terminal type of the Internet of Things card does not have a semantic relationship, the large language model has a semantic illusion problem, outputting the wrong risk type, and reducing the accuracy of identifying the risk type of the Internet of Things card. The inventor thought that the risk type of the Internet of Things card is not output by the large language model, and the data related to the terminal type is directly obtained and output from the collected Internet of Things card data. A directional network module is added to the output layer of the large language model, which can point to the terminal type in the Internet of Things card data and output the Internet of Things card data related to the terminal type, avoiding the semantic illusion problem of the large language model, providing data support for identifying the risk type of the Internet of Things card. The characteristics of the Internet of Things card data are extracted, and the risk type is identified according to the Internet of Things card characteristic data and the data in the Internet of Things card risk type feature library. Thus, the accuracy of identifying the risk type of the Internet of Things card is improved.

[0045] The technical solutions of the present application and how the technical solutions of the present application solve the above technical problems will be described in detail below with specific examples. The following specific examples can be combined with each other, and the same or similar concepts or processes may not be described again in some examples. The embodiments of the present application will be described below with reference to the accompanying drawings.

[0046] Figure 2 The flowchart of the method for identifying the risk type of the Internet of Things card provided by the embodiments of the present application is shown in FIG. 1, which comprises the following steps. Figure 2

[0047] S201: Collecting Internet of Things card data from an Internet of Things data platform; wherein the Internet of Things card data comprises a plurality of terminal types.

[0048] In this embodiment, the collected Internet of Things card data includes real-time call data, traffic data, roaming data, Internet access logs, real-time billing information of Internet of Things cards, cmp platform data and Jasper platform data.

[0049] In this embodiment, the Internet of Things card data is processed under the same vectorization dimension.

[0050] S202: Inputting the Internet of Things card data into an adjusted large language model; wherein the adjusted large language model comprises a directional network module.

[0051] In this embodiment, a directional network module is added to the output layer of the large language model. The directional network module is used to point to the terminal type in the Internet of Things card data and obtain and output the Internet of Things card data corresponding to the terminal type from the Internet of Things card data input into the adjusted large language model.

[0052] ​S203: The output layer of the adjusted large language model generates a plurality of terminal types to be pointed to corresponding to each terminal type.

[0053] S204: Input the plurality of terminal types to be pointed to into the directivity network module, so that the directivity network module obtains the probability value corresponding to the terminal type to be pointed to with the maximum comprehensive weight value from the plurality of terminal types to be pointed to.

[0054] Specifically, the comprehensive weight value of each terminal type to be pointed to is obtained; and according to the comprehensive weight value of each terminal type to be pointed to, the probability value corresponding to the terminal type to be pointed to with the maximum comprehensive weight value is obtained from the plurality of terminal types to be pointed to.

[0055] In this embodiment, the formula for obtaining the comprehensive weight value of each terminal type to be pointed to is:

[0056]

[0057] In the formula, denotes the comprehensive weight value of the jth terminal type to be pointed to, i denotes the number of the plurality of terminal types to be pointed to, and γ denotes the initialization matrix weight. and denote different two characters in the jth terminal type to be pointed to. denotes the weight of . denotes the weight of .

[0058] In this embodiment, the historical Internet of Things card data is collected from the Internet of Things data platform in real time to form an Internet of Things card basic database, and the terminal types of all Internet of Things cards in the basic database are labeled, and a large weight is assigned to each character in the terminal type to ensure that the comprehensive weight value of the terminal type of the real Internet of Things card is greater than that of other terminal types to be pointed to.

[0059] In this embodiment, the formula for obtaining the probability value corresponding to the terminal type to be pointed to with the maximum comprehensive weight value is:

[0060]

[0061] In the formula, denotes the probability value corresponding to the terminal type to be pointed to with the maximum comprehensive weight value, denotes the maximum comprehensive weight value obtained from the i terminal types to be pointed to, and γ denotes the initialization matrix weight.

[0062] In this embodiment, the probability value corresponding to the maximum comprehensive weight value is obtained from the plurality of terminal types to be pointed to.

[0063] S205: Obtain the Internet of Things card data corresponding to the probability value from the Internet of Things card data to obtain the Internet of Things card data corresponding to each terminal type.

[0064] In this embodiment, the probability value corresponding to the maximum comprehensive weight value is also the maximum. The Internet of Things card data corresponding to the maximum probability value is the Internet of Things card data corresponding to the terminal type of the real Internet of Things card.

[0065] In this embodiment, since the terminal types do not have semantic relationships, multiple terminal types to be pointed to are generated in the output layer, and the terminal type of the real Internet of Things card is pointed to by the pointing network module to obtain the Internet of Things card data corresponding to the terminal type of the real Internet of Things card from the Internet of Things card data.

[0066] S206: Extract the features of the Internet of Things card data corresponding to each terminal type to obtain the Internet of Things card feature data of each terminal type.

[0067] S207: According to the Internet of Things card feature data of each terminal type and the data in the Internet of Things card risk type feature library, identify the Internet of Things card risk type of the Internet of Things card data corresponding to each terminal type.

[0068] In this embodiment, the Internet of Things card risk types include high-frequency main calling risk, machine changing risk, high-risk area roaming risk, abnormal traffic usage risk, and rail breaking risk. The Internet of Things card risk type feature library includes the features of each risk type. By comparing the Internet of Things card feature data of each terminal type with the data in the Internet of Things card risk type feature library, the risk type is identified.

[0069] As can be seen from the above, the collected Internet of Things card data containing terminal types is input into the adjusted large language model, and multiple terminal types to be pointed to corresponding to each terminal type are generated in the output layer of the adjusted large language model. The probability value corresponding to the terminal type to be pointed to with the maximum comprehensive weight value is obtained by the pointing network module, and the Internet of Things card data corresponding to the probability value is obtained from the Internet of Things card data. Through the pointing network module, the terminal type in the Internet of Things card data can be pointed to from the collected Internet of Things card data, and the Internet of Things card data related to the terminal type is output, avoiding the semantic illusion problem of the large language model, providing data support for identifying the Internet of Things card risk type. The features of the Internet of Things card data are extracted, and the risk type is identified according to the Internet of Things card feature data and the data in the Internet of Things card risk type feature library. Therefore, the accuracy of identifying the Internet of Things card risk type is improved.

[0070] On the basis of the above embodiments, in this embodiment, the process of obtaining the Internet of Things card risk type feature library is introduced, which is described in detail as follows:

[0071] S301: Collect historical Internet of Things card data from the Internet of Things data platform regularly.

[0072] In the embodiment, the historical IoT card data is collected in a timely manner to ensure the continuity and regularity of the acquisition of the IoT card data.

[0073] Optionally, the historical IoT card data includes historical real-time bill data, traffic data, roaming data, online log, real-time charging information of the IoT card, cmp platform data and Jasper platform data.

[0074] In the embodiment, the historical IoT card data of different sources and different types is stored in different types in the HDFS to form an IoT card basic database.

[0075] Optionally, the terminal type of the IoT card is labeled, and the terminal type corresponding to each IoT card is determined, and a large weight is assigned to each character in the terminal type.

[0076] Optionally, the abnormal data in the IoT card basic database is removed, such as obviously incorrect or not conforming to the normal use logic data; the repeated roaming records are eliminated to avoid the deviation of the analysis result caused by the repeated data and reduce the unnecessary data redundancy.

[0077] S302: According to the risk type sample library, the risk types involved in the historical IoT card data are labeled to obtain an IoT card risk type library.

[0078] The risk type sample library includes known risk behavior patterns and case data.

[0079] The risk types include high-frequency main and called risk, i.e., the number of calls is abnormally frequent in a short time; terminal device replacement risk, i.e., the IoT card frequently replaces the connected terminal device in a short time; high-risk area roaming risk, i.e., the IoT card appears in a high-risk area for roaming activities; abnormal traffic usage risk, including a sudden large increase in traffic usage or an abnormal traffic usage mode; and track breakage risk, i.e., the usage track of the IoT card is abnormally interrupted or does not conform to the normal business logic.

[0080] S303: The features of the historical IoT card data of different risk types in the IoT card risk type library are extracted to obtain an IoT card risk type feature library.

[0081] In the embodiment, the features of the historical IoT card data of different types are extracted to obtain the feature data of each type of IoT card to form the IoT card risk type feature library.

[0082] In summary, a large amount of Internet of Things card data in different time periods can be accumulated through regular collection, covering multiple terminal types and providing a sample basis for subsequent risk identification; by labeling the risk types involved in the historical Internet of Things card data, an Internet of Things card risk type library is obtained. Through feature extraction, an Internet of Things card feature database of different risk types is obtained, providing strong data support for subsequent accurate identification of the risk type of the Internet of Things card.

[0083] On the basis of the above-mentioned embodiments, in the present embodiment, the process of obtaining the adjusted large language model is introduced, which is described in detail as follows:

[0084] S401: shielding a specific attention head of the large language model, to obtain an initial large language model;

[0085] In the present embodiment, when the large language model processes information, the attention mechanism is a key part in the architecture of the large language model, which helps the model decide which parts to focus on when processing input information. The attention head is a component of the attention mechanism, and each attention head can focus on different aspects or features of the input.

[0086] Optionally, the initial large language model after shielding the specific attention head (RH) adopts an end-to-end principle to construct a directional network module.

[0087] S402: adding a directional network module to the output layer of the initial large language model, to obtain an adjusted large language model.

[0088] In the present embodiment, the initial large language model after shielding the specific attention head (RH) adopts an end-to-end principle to construct a directional network module.

[0089] In summary, shielding the specific attention head of the large language model can directly obtain the Internet of Things card data corresponding to the terminal type from the input Internet of Things card data through the directional network module, avoid the semantic hallucination problem of the large language model, provide data support for identifying the risk type of the Internet of Things card, and thus improve the accuracy of identifying the risk type of the Internet of Things card.

[0090] Figure 3 The structure diagram of the Internet of Things card risk type identification device provided by the embodiments of the present application is shown in Figure 3 As shown in the figure, the Internet of Things card risk type identification device provided by the present embodiment includes a data collection module 301, an input module 302, a generation module 303, a first acquisition module 304, a second acquisition module 305, an extraction module 306, and a risk type identification module 307.

[0091] The data collection module 301 is configured to collect Internet of Things card data from an Internet of Things data platform; wherein the Internet of Things card data includes multiple terminal types.

[0092] The input module 302 is used to input IoT card data into the adjusted large language model; wherein the adjusted large language model includes a directional network module.

[0093] The generation module 303 is used to generate multiple terminal types to be pointed to for each terminal type in the output layer of the adjusted large language model.

[0094] The first acquisition module 304 is used to input multiple terminal types to be targeted to the directional network module, so that the directional network module can obtain the probability value corresponding to the terminal type with the largest comprehensive weight value from the multiple terminal types to be targeted.

[0095] The second acquisition module 305 is used to acquire IoT card data corresponding to probability values ​​from IoT card data, so as to obtain IoT card data corresponding to each terminal type.

[0096] The extraction module 306 is used to extract the features of the IoT card data corresponding to each terminal type, and obtain the IoT card feature data of each terminal type.

[0097] The risk type identification module 307 is used to identify the IoT card risk type of the IoT card data corresponding to each terminal type based on the IoT card feature data of each terminal type and the data in the IoT card risk type feature library.

[0098] In one possible implementation, the first acquisition module 304 is specifically used to: acquire the comprehensive weight value of each terminal type to be targeted; and based on the comprehensive weight value of each terminal type to be targeted, acquire the probability value corresponding to the terminal type to be targeted with the largest comprehensive weight value from among multiple terminal types to be targeted.

[0099] In one possible implementation, the first acquisition module 304 includes a comprehensive weight value calculation unit, the formula of which is:

[0100]

[0101] In the formula, γ represents the comprehensive weight value of the j-th terminal type to be pointed to, i represents the number of terminal types to be pointed to, and γ represents the weight of the initial matrix. and This represents two distinct characters in the j-th terminal type to be pointed to. express The weight, express The weight.

[0102] In a possible implementation, the first obtaining module 304 includes a probability calculation unit, and the formula of the probability calculation unit is:

[0103]

[0104] wherein, denotes a probability value corresponding to a terminal type to be pointed to with the largest comprehensive weight value, denotes the largest comprehensive weight value from i terminal types to be pointed to, and γ denotes an initialized matrix weight.

[0105] In a possible implementation, the device for identifying the risk type of the Internet of Things card further includes a third obtaining module configured to collect historical Internet of Things card data from the Internet of Things data platform at a time; label a risk type involved in the historical Internet of Things card data according to the risk type sample library to obtain an Internet of Things card risk type library; and perform feature extraction on historical Internet of Things card data of different risk types in the Internet of Things card risk type library to obtain an Internet of Things card risk type feature library.

[0106] In a possible implementation, the device for identifying the risk type of the Internet of Things card further includes a fourth obtaining module configured to shield a specific attention head of the large language model to obtain an initial large language model; and add a directional network module to an output layer of the initial large language model to obtain an adjusted large language model.

[0107] The device for identifying the risk type of the Internet of Things card provided in this embodiment can perform the method provided in the method embodiments described above, and has similar implementation principles and technical effects, which will not be described here again in this embodiment.

[0108] Figure 4 A hardware structure schematic diagram of a server provided in an embodiment of the present application is shown in FIG. 4. As shown in FIG. 4, the server provided in this embodiment includes at least one processor 401 and a memory 402. Optionally, the server further includes a communication component 403. The processor 401, the memory 402, and the communication component 403 are connected through a bus 404. Figure 4

[0109] In the specific implementation process, the at least one processor 401 executes computer execution instructions stored in the memory 402, so that the at least one processor 401 performs the method described above.

[0110] The specific implementation process of the processor 401 can refer to the method embodiments described above, and has similar implementation principles and technical effects, which will not be described here again in this embodiment.

[0111] ​In the above embodiments, it should be understood that the processor can be a central processing unit (CPU), and can also be other general-purpose processors, digital signal processors (DSP), application specific integrated circuits (ASIC), etc. The general-purpose processor can be a microprocessor or the processor can also be any conventional processor. The steps of the method disclosed in combination with the application can be directly embodied as hardware processor execution, or executed by a combination of hardware and software modules in the processor.

[0112] The memory can include a random access memory (RAM), and can also include a non-volatile memory (NVM), such as at least one disk memory.

[0113] The bus can be an industry standard architecture (ISA) bus, a peripheral component (PCI) bus, or an extended industry standard architecture (EISA) bus, etc. The bus can be divided into an address bus, a data bus, a control bus, etc. For ease of representation, the bus in the drawings of the present application does not limit to only one bus or one type of bus.

[0114] The present application also provides a computer program product, comprising a computer program, which, when executed by a processor, implements the above method.

[0115] The present application also provides a computer readable storage medium, which stores computer execution instructions, and when a processor executes the computer execution instructions, the above method is implemented.

[0116] The above readable storage medium can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic memory, flash memory, magnetic disk or optical disk. The readable storage medium can be any available medium that can be accessed by a general-purpose or special-purpose computer.

[0117] An example readable storage medium is coupled to the processor such that the processor can read information from the readable storage medium and can write information to the readable storage medium. Of course, the readable storage medium can also be a part of the processor. The processor and the readable storage medium can be located in an application specific integrated circuit (ASIC). Of course, the processor and the readable storage medium can also exist as discrete components in the device.

[0118] The division of units is only a logical functional division, and in actual implementation, there can be another division manner, for example, a plurality of units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the coupling or direct coupling or communication connection between the units shown or discussed can be indirect coupling or communication connection through some interfaces, devices or units, and can be electrical, mechanical or other forms.

[0119] The units described as separate components can or can not be physically separated, and the components shown as units can or can not be physical units, that is, can be located in one place, or can be distributed on a plurality of network units. Part or all of the units can be selected according to actual needs to achieve the purpose of the embodiment scheme.

[0120] In addition, the functional units in each embodiment of the present application can be integrated in one processing unit, or each unit can be physically present separately, or two or more units can be integrated in one unit.

[0121] If the functions are realized in the form of software function units and sold or used as independent products, they can be stored in a computer readable storage medium. Based on this understanding, the technical solutions of the present application or the part of the present application that essentially contributes to the prior art or the part of the technical solutions can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes a plurality of instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the embodiments of the present application. The foregoing storage medium includes a U disk, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk, and various program code storage media.

[0122] Those skilled in the art can understand that all or part of the steps of the above-mentioned method embodiments can be completed by program instruction related hardware. The foregoing program can be stored in a computer readable storage medium. The program executes to perform the steps of the above-mentioned method embodiments; and the foregoing storage medium includes various media capable of storing program codes, such as ROM, RAM, magnetic disk, or optical disk.

[0123] Finally, it should be noted that other embodiments of the present application will readily occur to those skilled in the art upon consideration of the specification and practice of the present application disclosed herein. The present application is intended to include all such variations, uses, or adaptations of the application in which the general principles of the application are used to best advantage and encompassed within its scope. The present application is not limited to the precise structures described and shown in the accompanying drawings and figures, and can be practiced with modification and alteration, and has different functions and configurations without departing from the scope of the present application. The scope of the present application is limited only by the claims appended hereto.

Claims

1. A method for identifying risk types of Internet of Things (IoT) cards, characterized in that, Applied to servers, including: Data from IoT cards is collected from an IoT data platform; wherein the IoT card data includes multiple terminal types. The IoT card data is input into the adjusted large language model; wherein the adjusted large language model includes a directional network module; The output layer of the adjusted large language model generates multiple terminal types to be pointed to for each terminal type. Multiple terminal types to be targeted are input into the directional network module, so that the directional network module obtains the probability value corresponding to the terminal type with the largest comprehensive weight value from the multiple terminal types to be targeted; Obtain the IoT card data corresponding to the probability value from the IoT card data to obtain the IoT card data corresponding to each terminal type; Extract the features of the IoT card data corresponding to each terminal type to obtain IoT card feature data for each terminal type; Based on the IoT card feature data of each terminal type and the data in the IoT card risk type feature library, identify the IoT card risk type of the IoT card data corresponding to each terminal type.

2. The method according to claim 1, characterized in that, The step of inputting multiple terminal types to be targeted to the directional network module, so that the directional network module obtains the probability value corresponding to the terminal type with the largest comprehensive weight value from the multiple terminal types to be targeted, includes: Obtain the comprehensive weight value for each terminal type to be targeted; Based on the comprehensive weight value of each terminal type to be targeted, the probability value corresponding to the terminal type with the largest comprehensive weight value is obtained from the plurality of terminal types to be targeted.

3. The method according to claim 2, characterized in that, The formula for obtaining the comprehensive weight value of each terminal type to be targeted is: In the formula, γ represents the comprehensive weight value of the j-th terminal type to be pointed to, i represents the number of terminal types to be pointed to, and γ represents the weight of the initialization matrix. and This represents two distinct characters in the j-th terminal type to be pointed to. express The weight, express The weight.

4. The method according to claim 3, characterized in that, The formula for obtaining the probability value corresponding to the terminal type with the largest comprehensive weight value is as follows: In the formula, This represents the probability value corresponding to the terminal type to which the target device has the highest overall weight value. This indicates that the maximum comprehensive weight value is obtained from the i terminal types to be pointed to, and γ represents the weight of the initialization matrix.

5. The method according to any one of claims 1-4, characterized in that, Before collecting IoT card data from the IoT data platform, the process also includes: Historical IoT card data is collected periodically from the IoT data platform. Based on the risk type sample library, the risk types involved in the historical IoT card data are labeled to obtain the IoT card risk type library; Feature extraction is performed on historical IoT card data of different risk types in the IoT card risk type library to obtain the IoT card risk type feature library.

6. The method according to any one of claims 1-4, characterized in that, Before collecting IoT card data from the IoT data platform, the process also includes: By disabling specific attention heads of the large language model, an initial large language model is obtained; A directional network module is added to the output layer of the initial large language model to obtain the adjusted large language model.

7. A device for identifying the risk type of an Internet of Things (IoT) card, characterized in that, Applied to servers, including: The data acquisition module is used to acquire IoT card data from the IoT data platform; wherein the IoT card data includes multiple terminal types; An input module is used to input the IoT card data into the adjusted large language model; wherein the adjusted large language model includes a directional network module; The generation module is used to generate multiple terminal types to be pointed to for each terminal type in the output layer of the adjusted large language model. The first acquisition module is used to input multiple terminal types to be targeted to the directional network module, so that the directional network module can obtain the probability value corresponding to the terminal type with the largest comprehensive weight value from the multiple terminal types to be targeted. The second acquisition module is used to acquire the IoT card data corresponding to the probability value from the IoT card data, so as to obtain the IoT card data corresponding to each terminal type. The extraction module is used to extract the features of the IoT card data corresponding to each terminal type to obtain IoT card feature data for each terminal type. The risk type identification module is used to identify the IoT card risk type of the IoT card data corresponding to each terminal type based on the IoT card feature data of each terminal type and the data in the IoT card risk type feature library.

8. A server, characterized in that, include: Memory, processor; The memory stores computer-executed instructions; The processor executes computer execution instructions stored in the memory, causing the processor to perform the method as described in any one of claims 1-6.

9. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer-executable instructions, which, when executed by a processor, are used to implement the method as described in any one of claims 1-6.

10. A computer program product, characterized in that, Includes a computer program that, when executed by a processor, implements the method described in any one of claims 1-6.

Citation Information

Patent Citations

  • Internet of Things card risk identification method, device and equipment and storage medium

    CN116527398A

  • Internet of Things card abnormal flow detection method, system and device and medium

    CN117479143A