E-commerce platform risk management system based on behavioral analysis

By adopting a risk management system based on behavior analysis on e-commerce platforms, using iterative risk association identification technology to deeply analyze user behavior, identify and manage risk users, the problem of insufficient accuracy of risk identification in the existing technology is solved, and more effective risk control and prevention is achieved.

CN119721729BActive Publication Date: 2025-06-06JIANGSU TIANHE CLOUD BUSINESS CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510237609.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-03-03
Publication Date
2025-06-06
Estimated Expiration
2045-03-03

AI Technical Summary

Technical Problem

The existing e-commerce platform risk management system has shortcomings in the accuracy of risk identification, and it is difficult to effectively control and prevent complex and changeable fraudulent means, resulting in more missed and false positives.

Method used

The risk management system of the e-commerce platform based on behavior analysis is adopted to collect user behavior data in the preset monitoring window in real time, combine historical monitoring data, filter out known risk behavior logs and related information, and use iterative risk association identification technology to conduct in-depth analysis of user behavior information sequences, identify risk users, and combine historical risk logs and known risk information to determine the target risk users and their behavior patterns, and formulate targeted risk management plans.

Benefits of technology

It improves the accuracy of risk identification, realizes effective control and prevention of risks, and reduces the situation of missed and false alarms.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119721729B_ABST
    Figure CN119721729B_ABST
Patent Text Reader

Abstract

The present invention discloses an e-commerce platform risk management system based on behavior analysis, which relates to the field of e-commerce risk management. The system includes: a user behavior information sequence acquisition module for acquiring information sequences within a preset monitoring window; a risk screening module for acquiring and screening historical risk behavior log sets and known risk information; a risk authentication module for iterative risk association identification of user behavior information sequences, risk authentication based on identification results, and obtaining risk users; a risk identification module for extracting risk user behavior information sequences from user behavior information sequences for risk identification; and a risk management solution identification module for identifying risk management solutions for target risk users and target risk user behavior information sequences. The system solves the technical problems of low risk identification accuracy and difficulty in achieving effective control and prevention in existing risk management, and achieves the technical effect of improving risk identification accuracy and achieving effective risk control and prevention.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field related to e-commerce risk management, and in particular to an e-commerce platform risk management system based on behavior analysis. Background Art

[0002] The security risks and challenges faced by e-commerce platforms include but are not limited to fraud, malicious order fraud, and false reviews, which not only damage the reputation of the platform, but also affect the shopping experience of users and the legitimate rights and interests of merchants. In the existing e-commerce platform risk management, a series of preset rules are usually used to detect abnormal behaviors. For example, thresholds such as transaction amount and transaction frequency are set, and alarms are triggered when user behavior exceeds these thresholds. This method relies on set rules and is difficult to deal with complex and changeable fraud methods, and there are a large number of missed reports and false reports.

[0003] Among the current relevant technologies, e-commerce platform risk management has technical problems such as low accuracy in risk identification and difficulty in achieving effective risk control and prevention. Summary of the invention

[0004] This application provides an e-commerce platform risk management system based on behavioral analysis, collects user behavior data within a preset monitoring window in real time, combines historical monitoring data, screens out known risk behavior logs and related information, uses iterative risk association identification technology, conducts in-depth analysis of user behavior information sequences, identifies risky users, extracts key behavior information from risky users, combines historical risk logs and known risk information, further determines target risk users and their behavior patterns, and formulates risk management plans for target risk users, etc., thereby achieving the technical effect of improving the accuracy of risk identification and achieving effective risk control and prevention.

[0005] The present application provides an e-commerce platform risk management system based on behavior analysis, including: a user behavior information sequence acquisition module, used to obtain Q user behavior information sequences of Q users within a preset monitoring window, wherein Q is a positive integer; a risk screening module, used to obtain a set of screened historical risk behavior logs and known risk information within a historical monitoring window; a risk authentication module, used to perform iterative risk association identification on the Q user behavior information sequences, obtain iterative risk association identification results, perform risk authentication on the Q users according to the iterative risk association identification results, and obtain M risk users, wherein M is a positive integer less than or equal to Q; a risk identification module, used to extract M risk user behavior information sequences of M risk users from the Q user behavior information sequences, perform risk identification in combination with the screened historical risk behavior log set and the known risk information, and determine P target risk users and P target risk user behavior information sequences, wherein P is a positive integer less than or equal to M; a risk management plan identification module, used to perform risk management plan identification on the P target risk users and the P target risk user behavior information sequences, and obtain P target risk management plans.

[0006] In a possible implementation, the risk screening module includes: a historical risk information extraction unit, used to extract a historical risk behavior log set and known risk information within a historical monitoring window; a risk type vector identification unit, used to traverse the historical risk behavior log set to perform risk type vector identification, and obtain an identified historical risk behavior log set after identification; a cost clustering analysis unit, used to perform cost clustering analysis on the identified historical risk behavior log set, and obtain K cluster identified historical risk behavior log sets, where K is a positive integer; a set elimination unit, used to respectively count the number of the K cluster identified historical risk behavior log sets, and eliminate the cluster identified historical risk behavior log sets with a number lower than a preset number from the K cluster identified historical risk behavior log sets to obtain a screened historical risk behavior log set.

[0007] In a possible implementation, the cost clustering analysis unit includes: an initial cluster center acquisition subunit, which is used to randomly extract K identification historical risk behavior logs from the identification historical risk behavior log set as K initial cluster centers; an initial cluster center neighborhood acquisition subunit, which is used to traverse and calculate the similarity between the identification historical risk behavior log set and the K initial cluster centers, and assign them to the cluster center neighborhood corresponding to the maximum similarity value to obtain K initial cluster center neighborhoods; an initial cost value calculation subunit, which is used to calculate the cost value of the K initial cluster center neighborhoods as a whole using a cost function to obtain An initial cost value; a cluster center update subunit, used to determine whether the initial cost value is less than a preset cost value threshold. If not, calculate the mean of the K initial cluster center neighborhoods, and update the K initial cluster centers according to the calculation result to obtain K updated cluster centers; a cluster identification subunit, used to perform cost clustering analysis on the identified historical risk behavior log set based on the K updated cluster centers until the updated cost value is less than the preset cost threshold, and use the K updated cluster center neighborhoods corresponding to the K updated cluster centers obtained after the last update as the K cluster identification historical risk behavior log set.

[0008] In a possible implementation, the initial cost value calculation subunit includes: a cost function acquisition component, which is used to acquire a cost function, wherein the cost function is:

[0009] ;

[0010] in, is the initial cost value, are the K initial cluster centers The initial cluster center neighborhood of the initial cluster center, For the The initial cluster center identifies the historical risk behavior log, For the i The first A log of historical risk behavior. For the The risk type vector identifiers of the initial cluster centers, For the The first Identify risk type vector logo for risk behavior log.

[0011] In a possible implementation, the risk authentication module includes: a user behavior information extraction unit, used to extract Q first user behavior information and Q second user behavior information located at the first and second positions respectively from the Q user behavior information sequences; a first iterative risk association identification unit, used to perform iterative risk association identification on the Q first user behavior information and the Q second user behavior information to obtain Q first iterative risk-associated user behavior features; a second iterative risk association identification unit, used to extract Q third user behavior information located at the third position from the Q user behavior information sequences again, perform iterative risk association identification on them with the Q first iterative risk-associated user behavior features, and obtain Q second iterative risk-associated user behavior features; an iterative risk association identification unit, and so on, based on the Q second iterative risk-associated user behavior features, continue to perform iterative risk association identification on the remaining user behavior information in the Q user behavior information sequences, respectively, to obtain Q final iterative risk-associated user behavior features; a risk coefficient identification unit, used to perform risk coefficient identification on the Q final iterative risk-associated user behavior features, obtain Q risk coefficients, and use the Q risk coefficients as iterative risk association identification results.

[0012] In a possible implementation, the first iterative risk association identification unit includes: a feature extraction subunit, used to perform feature extraction on the Q first user behavior information and the Q second user behavior information, respectively, to obtain Q first user behavior feature sets and Q second user behavior feature sets; a feature mapping similarity calculation subunit, used to perform feature mapping similarity calculation on the Q first user behavior feature sets and the Q second user behavior feature sets, to obtain Q first user behavior feature similarity sets; a normalization processing subunit, used to perform normalization processing on the Q first user behavior feature similarity sets, and add the processing results to Q first iterative risk association matrices that are initially empty; a convolution operation subunit, used to perform convolution operations on the Q first iterative risk association matrices and the Q second user behavior feature sets, respectively, to obtain Q first iterative risk association user behavior features.

[0013] In a possible implementation, the risk coefficient identification unit includes: a training data acquisition subunit, used to obtain multiple sample final iterative risk-associated user behavior characteristics and multiple sample risk coefficients as training data; a risk coefficient identifier training subunit, used to use the training data to perform supervised training on a framework built based on a feedforward neural network, learn a one-to-one mapping relationship between the final iterative risk-associated user behavior characteristics and the risk coefficient, until the training is completed, and obtain a risk coefficient identifier; a risk identification subunit, used to use the risk coefficient identifier to perform risk identification on the Q final iterative risk-associated user behavior characteristics to obtain Q risk coefficients.

[0014] In a possible implementation, the risk identification module includes: a judgment processing unit, used to judge whether the M risk user behavior information sequences contain the known risk information, and if so, add it to the first target risk user behavior information sequence set, and add the corresponding risk user to the first target risk user set; a matching similarity calculation unit, used to perform matching similarity calculation on the M risk user behavior information sequences by screening the historical risk behavior log set, add the risk user behavior information sequences with matching similarity greater than or equal to a preset matching similarity threshold to the second target risk user behavior information sequence set, and add the corresponding risk user to the second target risk user set; a union solving unit, used to find the union of the first target risk user set and the second target risk user set to obtain P target risk users, and find the union of the first target risk user behavior information sequence set and the second target risk user behavior information sequence set to obtain P target risk user behavior information sequences.

[0015] It is intended to adopt the e-commerce platform risk management system based on behavior analysis proposed in this application, obtain Q user behavior information sequences of Q users in a preset monitoring window through a user behavior information sequence acquisition module, wherein Q is a positive integer, obtain the filtered historical risk behavior log set and known risk information in the historical monitoring window through a risk screening module, perform iterative risk association identification on the Q user behavior information sequences through a risk authentication module, obtain iterative risk association identification results, perform risk authentication on the Q users according to the iterative risk association identification results, and obtain M risk users, wherein M is a positive integer less than or equal to Q, extract M risk user behavior information sequences of M risk users from the Q user behavior information sequences through a risk identification module, perform risk identification in combination with the filtered historical risk behavior log set and known risk information, determine P target risk users and P target risk user behavior information sequences, wherein P is a positive integer less than or equal to M, perform risk management scheme identification on P target risk users and P target risk user behavior information sequences through a risk management scheme identification module, and obtain P target risk management schemes, thereby achieving the technical effect of improving the accuracy of risk identification and realizing effective risk control and prevention. BRIEF DESCRIPTION OF THE DRAWINGS

[0016] In order to more clearly illustrate the technical solution of the embodiment of the present invention, the accompanying drawings of the embodiment of the present invention will be briefly introduced below. A structural diagram is used in the present application to illustrate the operations performed by the system according to the embodiment of the present application. It should be understood that the preceding or following operations are not necessarily performed accurately in order. On the contrary, various steps can be processed in reverse order or simultaneously as needed. At the same time, other operations can also be added to these processes, or a certain step or several steps of operations can be removed from these processes.

[0017] Figure 1 A schematic diagram of the structure of an e-commerce platform risk management system based on behavioral analysis provided in an embodiment of the present application.

[0018] Figure 2 A schematic diagram of the structure of the initial cluster center acquisition subunit in the e-commerce platform risk management system based on behavior analysis provided in an embodiment of the present application.

[0019] Explanation of reference numerals: user behavior information sequence acquisition module 10 , risk screening module 20 , risk authentication module 30 , risk identification module 40 , risk management solution identification module 50 . DETAILED DESCRIPTION

[0020] The above description is only an overview of the technical solution of the present application. In order to more clearly understand the technical means of the present application, it can be implemented in accordance with the contents of the specification. In order to make the above and other purposes, features and advantages of the present application more obvious and easy to understand, the specific implementation methods of the present application are listed below.

[0021] In order to make the objectives, technical solutions and advantages of the present application clearer, the present application will be further described in detail below in conjunction with the accompanying drawings. The described embodiments should not be regarded as limiting the present application. All other embodiments obtained by ordinary technicians in the field without making creative work are within the scope of protection of this application.

[0022] In the following description, reference is made to "some embodiments", which describe a subset of all possible embodiments, but it is understood that "some embodiments" may be the same subset or different subsets of all possible embodiments, and may be combined with each other without conflict, and the terms "first\second" involved are merely to distinguish similar objects and do not represent a specific ordering of objects. The terms "including" and "having" and any variations are intended to cover non-exclusive inclusions, for example, a process, method, system, product, or server that includes a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or modules that are not clearly listed or inherent to these processes, methods, products, or devices. Unless otherwise defined, all technical and scientific terms used herein have the same meaning as those generally understood by technicians in the technical field of this application. The terms used herein are for the purpose of describing the embodiments of the present application only.

[0023] The present application embodiment provides an e-commerce platform risk management system based on behavior analysis, such as Figure 1 As shown, the system comprises:

[0024] The user behavior information sequence acquisition module 10 is used to acquire Q user behavior information sequences of Q users within a preset monitoring window, where Q is a positive integer.

[0025] Specifically, the preset monitoring window is a specified period of time for collecting and analyzing user behavior data. Through multiple channels such as the e-commerce platform backend log system, user interaction records, and transaction data, the user's behavior data within the preset monitoring window is collected in real time or regularly. The collected user behavior data is arranged in chronological order to form a user behavior information sequence. Each sequence contains all the user's behaviors within the monitoring window, such as browsing products, adding to shopping carts, placing orders and paying, etc. The behavior information of Q users is processed in the same way to generate Q user behavior information sequences.

[0026] The risk screening module 20 is used to obtain a set of screened historical risk behavior logs and known risk information within a historical monitoring window.

[0027] Specifically, log records related to risky behaviors are screened out from historical logs to form a collection of screened historical risky behavior logs. The known risky behavior patterns, fraud methods, and other information of the e-commerce platform are integrated to obtain known risk information.

[0028] In one possible implementation, the risk screening module 20 includes: a historical risk information extraction unit, used to extract a historical risk behavior log set and known risk information within a historical monitoring window; a risk type vector identification unit, used to traverse the historical risk behavior log set to perform risk type vector identification, and obtain an identified historical risk behavior log set after identification; a cost clustering analysis unit, used to perform cost clustering analysis on the identified historical risk behavior log set, and obtain K cluster identified historical risk behavior log sets, where K is a positive integer; a set elimination unit, used to respectively count the number of the K cluster identified historical risk behavior log sets, and eliminate the cluster identified historical risk behavior log sets with a number lower than a preset number from the K cluster identified historical risk behavior log sets to obtain a screened historical risk behavior log set.

[0029] Specifically, determine the time range of the historical monitoring window, that is, the time period used to monitor and analyze historical risk behaviors. Retrieve risk behavior logs within the time range from the database or log file. Sort and classify known risk information (confirmed high-risk information, used to assist in risk identification), such as high-risk IP lists (such as from known malicious IP segments), black card number segments (payment card numbers involved in fraud or theft), high-risk device fingerprints (such as marked devices), etc.

[0030] Define risk type vectors, which are vectors used to represent different risk types. Each vector corresponds to a risk type, such as frequent login failures, abnormal device switching, and password reset attempts in account-related risks, black card payment attempts, frequent payment failures, abnormal payment amounts, etc. in payment-related risks, and high-frequency access, crawler behavior, and a large number of operations in a short period of time (such as orders, comments), etc. in access-related risks. Traverse the historical risk behavior log collection and map it to the corresponding risk type vector according to the log content. Assign a unique identifier to each risk type vector.

[0031] The identified historical risk behavior log set is used as input data, and a clustering algorithm (such as K-means, DBSCAN, etc.) is executed to obtain K clusters of historical risk behavior log sets. Among them, cost cluster analysis is a method of dividing data into multiple clusters by calculating the similarity between data points. Each cluster represents a similar risk behavior pattern.

[0032] Set a preset number threshold, which is a quantitative standard for judging whether a cluster is effective. Count the number of historical risk behavior logs in each cluster, remove clusters with numbers below the preset threshold from the results, and obtain a filtered historical risk behavior log set. This implementation method reduces the interference of noise data on risk identification results by removing clusters with a small number. These clusters may only appear occasionally or represent uncommon risk behaviors. Through screening, the amount of data that needs to be processed is reduced, and the operating efficiency of the entire risk management system is improved.

[0033] like Figure 2 As shown, in a possible implementation, the cost clustering analysis unit includes: an initial cluster center acquisition subunit, which is used to randomly extract K identification historical risk behavior logs from the identification historical risk behavior log set as K initial cluster centers; an initial cluster center neighborhood acquisition subunit, which is used to traverse and calculate the similarity between the identification historical risk behavior log set and the K initial cluster centers, and assign them to the cluster center neighborhood corresponding to the maximum similarity value to obtain K initial cluster center neighborhoods; an initial cost value calculation subunit, which is used to calculate the cost value of the K initial cluster center neighborhoods as a whole using a cost function. Obtain an initial cost value; a cluster center update subunit, used to determine whether the initial cost value is less than a preset cost value threshold, if not, calculate the mean of the K initial cluster center neighborhoods, and update the K initial cluster centers according to the calculation result to obtain K updated cluster centers; a cluster identification subunit, used to perform cost clustering analysis on the identified historical risk behavior log set based on the K updated cluster centers, until the updated cost value is less than the preset cost threshold, and use the K updated cluster center neighborhoods corresponding to the K updated cluster centers obtained after the last update as the K cluster identification historical risk behavior log set.

[0034] Specifically, K logs are randomly extracted from the set of logs that identify historical risk behaviors as the initial cluster centers. The initial cluster centers represent the center points of the K categories assumed at the beginning of the clustering algorithm. The set of logs that identify historical risk behaviors is traversed, the similarity between each log and the K initial cluster centers is calculated, and each log is assigned to the neighborhood of the cluster center corresponding to the maximum similarity. The neighborhood of the initial cluster center is the set of logs attracted by each initial cluster center.

[0035] Define a cost function, which is used to measure the quality of the current clustering result. Use the cost function to calculate the cost value of the entire neighborhood of the K initial cluster centers. The initial cost value reflects the quality of the initial clustering result. Determine whether the initial cost value is less than the preset cost value threshold (used to determine whether the clustering result reaches the required threshold). If not, calculate the mean of the neighborhood of the K initial cluster centers as the new cluster center, and update the K initial cluster centers to the new cluster centers.

[0036] Based on the new cluster centers, a new round of cluster analysis is performed on the log sets that identify historical risk behaviors. Repeat the steps of calculating the cost value and updating the cluster centers until the updated cost value is less than the preset cost threshold. The K updated cluster center neighborhoods corresponding to the K updated cluster centers obtained after the last update are used as the K clusters that identify the log sets of historical risk behaviors. This implementation method can obtain better clustering results in a relatively short time by randomly selecting the initial cluster centers and iteratively updating the cluster centers. The cost function is used to measure the quality of the clustering results, and the cost value is reduced through iterative optimization, thereby improving the accuracy of clustering.

[0037] In a possible implementation, the initial cost value calculation subunit includes: a cost function acquisition component, which is used to acquire a cost function, wherein the cost function is: ;

[0038] in, is the initial cost value, are the K initial cluster centers The initial cluster center neighborhood of the initial cluster center, For the The initial cluster center identifies the historical risk behavior log, For the i The first A log of historical risk behavior. For the The risk type vector identifiers of the initial cluster centers, For the The first Identify risk type vector logo for risk behavior log.

[0039] Specifically, For the The vector modulus of the historical risk behavior logs of the initial cluster centers is For the i The first The vector modulus of a historical risk behavior log is constructed by performing text processing on the log content (such as word segmentation, stop word removal, word vectorization, etc.). For the The modulus length of the risk type vector identification of the initial cluster center, For the The first Identifies the modulus length of the risk type vector identifying the risk behavior log. Used to characterize the similarity of log content. Used to characterize the similarity of log risk types. This implementation method constructs a cost function that takes into account both the content similarity and risk type similarity of the logs, making the clustering results more comprehensive and accurate.

[0040] The risk authentication module 30 is used to perform iterative risk association identification on the Q user behavior information sequences to obtain iterative risk association identification results, perform risk authentication on the Q users according to the iterative risk association identification results, and obtain M risk users, where M is a positive integer less than or equal to Q.

[0041] Specifically, machine learning or deep learning algorithms (such as neural networks, decision trees, etc.) are used to iteratively analyze Q user behavior information sequences to identify behavior patterns associated with known risk features. Based on the iterative risk association identification results, the Q users are risk-scored or classified to screen out M risky users.

[0042] In a possible implementation, the risk authentication module 30 includes: a user behavior information extraction unit, which is used to extract Q first user behavior information and Q second user behavior information located at the first and second positions respectively from the Q user behavior information sequences; a first iterative risk association identification unit, which is used to perform iterative risk association identification on the Q first user behavior information and the Q second user behavior information to obtain Q first iterative risk-associated user behavior features; a second iterative risk association identification unit, which is used to extract Q third user behavior information located at the third position from the Q user behavior information sequences again, and perform iterative risk association identification on them with the Q first iterative risk-associated user behavior features to obtain Q second iterative risk-associated user behavior features; an iterative risk association identification unit, and so on, based on the Q second iterative risk-associated user behavior features, continue to perform iterative risk association identification on the remaining user behavior information in the Q user behavior information sequences, respectively, to obtain Q final iterative risk-associated user behavior features; a risk coefficient identification unit, which is used to perform risk coefficient identification on the Q final iterative risk-associated user behavior features to obtain Q risk coefficients, and use the Q risk coefficients as iterative risk association identification results.

[0043] Specifically, for each user's behavior information sequence, the first behavior information is first extracted as the first user behavior information, and then the second behavior information is extracted as the second user behavior information. The extracted first user behavior information and second user behavior information are iteratively identified for risk association using a machine learning or deep learning model, and Q first user behavior information and Q second user behavior information are input into the model, and the model outputs Q first iterative risk association user behavior features, which reflect the potential risk association between user behaviors.

[0044] Extract the third user behavior information from each user's behavior information sequence. Input the third user behavior information and the first iteration risk-associated user behavior features obtained previously into the model, and the model outputs Q second iteration risk-associated user behavior features. Extract the remaining user behavior information in sequence, associate and identify each extracted behavior information with the previously obtained iteration risk-associated user behavior features, and update the iteration risk-associated user behavior features after each iteration. For example, if a user's behavior information sequence is [A, B, C, D], first extract A and B for the first iteration to obtain the first iteration risk-associated user behavior features, then extract C and the first iteration result for the second iteration, and so on.

[0045] The Q final iterative risk-associated user behavior features are input into the risk coefficient calculation model, and the model outputs Q risk coefficients, which are a quantitative indicator used to measure the size of potential risks in user behavior. This implementation method can gradually reveal the potential risk associations between user behaviors through iterative risk association identification, thereby more accurately assessing the user's risk level. Each iteration utilizes the results of the previous iteration, allowing subsequent iterations to identify risks based on richer information, thereby improving the accuracy of identification.

[0046] In a possible implementation, the first iterative risk association identification unit includes: a feature extraction subunit, used to perform feature extraction on the Q first user behavior information and the Q second user behavior information, respectively, to obtain Q first user behavior feature sets and Q second user behavior feature sets; a feature mapping similarity calculation subunit, used to perform feature mapping similarity calculation on the Q first user behavior feature sets and the Q second user behavior feature sets, to obtain Q first user behavior feature similarity sets; a normalization processing subunit, used to perform normalization processing on the Q first user behavior feature similarity sets, and add the processing results to Q first iterative risk association matrices that are initially empty; a convolution operation subunit, used to perform convolution operations on the Q first iterative risk association matrices and the Q second user behavior feature sets, respectively, to obtain Q first iterative risk association user behavior features.

[0047] Specifically, the first user behavior information and the second user behavior information of Q users are preprocessed, and feature extraction algorithms in machine learning or deep learning, such as convolutional neural network (CNN), recurrent neural network (RNN) or their variants, are used to extract features from the preprocessed user behavior information to obtain Q first user behavior feature sets and Q second user behavior feature sets. The Q first user behavior feature sets and the Q second user behavior feature sets are paired in pairs, and similarity calculation methods such as cosine similarity and Euclidean distance are used to calculate the similarity between each pair of feature sets to obtain Q first user behavior feature similarity sets.

[0048] Use normalization algorithms, such as min-max normalization, Z-score normalization, etc., to normalize the Q first user behavior feature similarity sets to ensure that the similarity values ​​are within a reasonable range (such as 0 to 1). Add the normalized similarity values ​​to the Q first iteration risk association matrices that are initially empty. Perform convolution operations on the Q first iteration risk association matrices and the Q second user behavior feature sets, use activation functions (such as ReLU) to perform nonlinear transformations on the convolution results, and extract the features after the convolution operation as the Q first iteration risk-associated user behavior features. This implementation method combines the first iteration risk association matrix and the second user behavior feature set to extract deeper risk association features through convolution operations, thereby improving the accuracy of risk identification.

[0049] In one possible implementation, the risk coefficient identification unit includes: a training data acquisition subunit, used to obtain multiple sample final iterative risk-associated user behavior characteristics and multiple sample risk coefficients as training data; a risk coefficient identifier training subunit, used to use the training data to perform supervised training on a framework built based on a feedforward neural network, learn a one-to-one mapping relationship between the final iterative risk-associated user behavior characteristics and the risk coefficient, until the training is completed, and obtain a risk coefficient identifier; a risk identification subunit, used to use the risk coefficient identifier to perform risk identification on the Q final iterative risk-associated user behavior characteristics to obtain Q risk coefficients.

[0050] Specifically, we select user behavior sequences with known risks from historical data, and extract the final iterative risk-associated user behavior features of these users through a process similar to the above iterative risk association identification. According to the actual risk situation of these user behavior sequences (such as whether they involve fraud, illegal operations, etc.), we assign a risk coefficient to each sample to form a training data set.

[0051] Design a feedforward neural network structure, the number of input layer nodes corresponds to the dimension of the final iterative risk-associated user behavior characteristics, and the number of output layer nodes is 1 (i.e., output risk coefficient). Use the sample final iterative risk-associated user behavior characteristics in the training data set as input and the sample risk coefficient as the target output to supervise the network training. During the training process, the network weights are adjusted through the back propagation algorithm to minimize the error between the predicted risk coefficient and the actual risk coefficient. When the training reaches the preset stop condition (such as error convergence, upper limit of iteration number, etc.), the training is completed and the risk coefficient identifier is obtained.

[0052] The final iterative risk-associated user behavior characteristics of each user are input into the risk factor identifier, and the risk factor identifier outputs the corresponding risk factor. According to the size of the risk factor, the user can be divided into risk levels, such as high risk, medium risk, low risk, etc. This implementation method improves the accuracy of risk factor prediction by training the risk factor identifier.

[0053] The risk identification module 40 is used to extract M risk user behavior information sequences of M risk users from Q user behavior information sequences, combine the screening of historical risk behavior log sets and known risk information to perform risk identification, and determine P target risk users and P target risk user behavior information sequences, where P is a positive integer less than or equal to M.

[0054] Specifically, from the Q user behavior information sequences, M risky users' behavior information sequences are extracted. Combined with the screening of historical risk behavior log sets and known risk information, the behavior information sequences of M risky users are further analyzed to identify P target risk users and corresponding target risk user behavior information sequences. Among them, the target risk user is a user who is determined to be at high risk after risk identification. The target risk user behavior information sequence is the behavior information sequence of the target risk user within the preset monitoring window.

[0055] In a possible implementation, the risk identification module 40 includes: a judgment processing unit, which is used to judge whether the M risk user behavior information sequences contain the known risk information. If so, it is added to the first target risk user behavior information sequence set, and the corresponding risk user is added to the first target risk user set; a matching similarity calculation unit, which is used to perform matching similarity calculation on the M risk user behavior information sequences by screening the historical risk behavior log set, and add the risk user behavior information sequences with matching similarity greater than or equal to a preset matching similarity threshold to the second target risk user behavior information sequence set, and add the corresponding risk user to the second target risk user set; a union solving unit, which is used to find the union of the first target risk user set and the second target risk user set to obtain P target risk users, and find the union of the first target risk user behavior information sequence set and the second target risk user behavior information sequence set to obtain P target risk user behavior information sequences.

[0056] Specifically, the judgment processing unit accesses a database containing known risk information, which contains various known fraudulent behavior patterns, malicious operation patterns, etc. For each risk user's behavior information sequence, the judgment processing unit compares it with the known risk information in the database one by one. If a behavior information sequence contains a certain known risk information in the database, then this sequence is considered to be high risk. For the successfully matched risk user behavior information sequence, the judgment processing unit adds it to the first target risk user behavior information sequence set, and adds the corresponding risk user to the first target risk user set.

[0057] The matching similarity calculation unit loads and filters the historical risk behavior log set, which contains various patterns that have been identified as risky behaviors in the past period of time. For each risk user's behavior information sequence, the matching similarity calculation unit calculates text similarity between it and each risk behavior pattern in the log set, such as cosine similarity, Jaccard similarity, etc. The calculated similarity is compared with a preset matching similarity threshold. If the similarity between a behavior information sequence and a risk behavior pattern is greater than or equal to this threshold, then the sequence is considered to be high risk. For risk user behavior information sequences that meet the conditions, the matching similarity calculation unit adds them to the second target risk user behavior information sequence set, and adds the corresponding risk user to the second target risk user set.

[0058] The union solving unit loads the first target risk user set, the first target risk user behavior information sequence set and the second target risk user set, the second target risk user behavior information sequence set, performs a union operation, and merges all elements of the corresponding two sets into a new set. In this process, if there are repeated elements in the two sets (i.e., the same risk user or the same risk user behavior information sequence set), they will only appear once in the result set. Finally, the union solving unit outputs the final target risk user set and the target risk user behavior information sequence set. This implementation method improves the accuracy of risk identification by combining known risk information and screening historical risk behavior log sets for risk identification. The known risk information provides direct evidence, and the screening historical risk behavior log sets provide a wider range of risk behavior patterns. By setting the matching similarity threshold, the sensitivity of risk identification can be flexibly adjusted. If you want to identify risk users more strictly, you can set the threshold higher; if you want to identify risk users more loosely, you can set the threshold lower.

[0059] The risk management solution identification module 50 is used to identify the risk management solution for the P target risk users and the P target risk user behavior information sequences to obtain P target risk management solutions.

[0060] Specifically, a solution library containing multiple risk management strategies is pre-built, such as account freezing, transaction restrictions, enhanced security verification, etc. A neural network model is used to analyze P target risk users and the corresponding behavior information sequences, and the most suitable management solution is matched from the risk management solution library according to the analysis results. P target risk management solutions are output, and the solutions are optimized and adjusted according to the actual application effect. The embodiment of the present application adopts real-time collection of user behavior data within a preset monitoring window, combined with historical monitoring data, to screen out known risk behavior logs and related information, and adopts iterative risk association identification technology to conduct in-depth analysis of user behavior information sequences, identify risk users, extract key behavior information from risk users, and combine historical risk logs and known risk information to further determine target risk users and their behavior patterns. Technical means such as formulating risk management solutions for target risk users have achieved the technical effect of improving the accuracy of risk identification and realizing effective risk control and prevention.

[0061] Although the present application makes various references to certain modules in the system according to the embodiments of the present application, any number of different modules may be used and run on the user terminal and / or server, and the various units and modules included are only divided according to functional logic, but are not limited to the above division, as long as the corresponding functions can be achieved; in addition, the specific names of the functional units are only for the convenience of distinguishing each other, and are not used to limit the scope of protection of the present invention.

[0062] The above specific implementation manner does not constitute a limitation to the protection scope of the present application. It should be understood by those skilled in the art that various modifications, combinations and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions and improvements made within the spirit and principles of the present application should be included in the protection scope of the present application. In some cases, the actions or steps recorded in the present application can be performed in an order different from that in the embodiment and can still achieve the desired results. In addition, the process depicted in the accompanying drawings does not necessarily require the specific order or continuous order shown to achieve the desired results. In some embodiments, multitasking and parallel processing are also possible or may be advantageous.

Claims

1. The e-commerce platform risk management system based on behavioral analysis is characterized by: The system comprises: A user behavior information sequence acquisition module, used to acquire Q user behavior information sequences of Q users within a preset monitoring window, where Q is a positive integer; Risk screening module, used to obtain the screening historical risk behavior log set and known risk information within the historical monitoring window; a risk authentication module, configured to perform iterative risk association identification on the Q user behavior information sequences to obtain iterative risk association identification results, perform risk authentication on the Q users according to the iterative risk association identification results to obtain M risk users, where M is a positive integer less than or equal to Q; A risk identification module is used to extract M risk user behavior information sequences of M risk users from Q user behavior information sequences, combine the screening of historical risk behavior log sets and known risk information to perform risk identification, and determine P target risk users and P target risk user behavior information sequences, where P is a positive integer less than or equal to M; The risk management scheme identification module is used to identify the risk management scheme for the P target risk users and the P target risk user behavior information sequences to obtain P target risk management schemes.

2. The e-commerce platform risk management system based on behavior analysis as claimed in claim 1, characterized in that: The risk screening module includes: A historical risk information extraction unit, used to extract a historical risk behavior log set and known risk information within a historical monitoring window; A risk type vector identification unit, used for traversing the historical risk behavior log set to perform risk type vector identification, and obtaining the identified historical risk behavior log set; A cost cluster analysis unit, configured to perform a cost cluster analysis on the set of logs identifying historical risk behaviors, to obtain K clustered sets of logs identifying historical risk behaviors, where K is a positive integer; The set elimination unit is used to respectively count the number of the K cluster identification historical risk behavior log sets, eliminate the cluster identification historical risk behavior log sets whose number is lower than a preset number from the K cluster identification historical risk behavior log sets, and obtain a filtered historical risk behavior log set.

3. The e-commerce platform risk management system based on behavior analysis as claimed in claim 2, characterized in that: The cost clustering analysis unit comprises: An initial cluster center acquisition subunit is used to randomly extract K identified historical risk behavior logs from the set of identified historical risk behavior logs as K initial cluster centers; The initial cluster center neighborhood acquisition subunit is used to traverse and calculate the similarity between the set of logs identifying historical risk behaviors and the K initial cluster centers, and assign them to the cluster center neighborhood corresponding to the maximum similarity value to obtain K initial cluster center neighborhoods; An initial cost value calculation subunit is used to calculate the cost value of the entire neighborhood of the K initial cluster centers using a cost function to obtain an initial cost value; A cluster center updating subunit is used to determine whether the initial cost value is less than a preset cost value threshold value. If not, the average of the neighborhoods of the K initial cluster centers is calculated, and the K initial cluster centers are updated according to the calculation result to obtain K updated cluster centers. The cluster identification subunit is used to perform cost clustering analysis on the identified historical risk behavior log set based on the K updated cluster centers until the update cost value is less than a preset cost threshold, and the K updated cluster center neighborhoods corresponding to the K updated cluster centers obtained after the last update are used as the K cluster identified historical risk behavior log set.

4. The e-commerce platform risk management system based on behavior analysis as claimed in claim 3, characterized in that: The initial cost value calculation subunit includes: The cost function acquisition component is used to obtain the cost function, wherein the cost function is: ; in, is the initial cost value, are the K initial cluster centers The initial cluster center neighborhood of the initial cluster center, For the The initial cluster center identifies the historical risk behavior log, For the i The first A log of historical risk behavior. For the The risk type vector identifiers of the initial cluster centers, For the The first Identify the risk type vector identifier of the risk behavior log; For the The first The vector modulus of the historical risk behavior log; For the The vector modulus of the historical risk behavior logs that identify the initial cluster centers; For the The first The modulus length of the risk type vector identifying the risk behavior log; For the The modulus length of the risk type vector identification of the initial cluster centers.

5. The e-commerce platform risk management system based on behavior analysis as claimed in claim 1, characterized in that: The risk authentication module includes: A user behavior information extraction unit, used to extract Q first user behavior information and Q second user behavior information located at the first and second positions respectively from the Q user behavior information sequences; A first iterative risk association identification unit is used to perform iterative risk association identification on the Q first user behavior information and the Q second user behavior information to obtain Q first iterative risk association user behavior features; A second iterative risk association identification unit is used to extract Q third user behavior information located at the third position from the Q user behavior information sequences again, and perform iterative risk association identification on the third user behavior information and the Q first iterative risk association user behavior features to obtain Q second iterative risk association user behavior features; The iterative risk association identification unit, and so on, continues to iteratively identify the remaining user behavior information in the Q user behavior information sequences based on the Q second iterative risk association user behavior features, to obtain Q final iterative risk association user behavior features; The risk coefficient identification unit is used to identify the risk coefficients of the Q final iterative risk-associated user behavior features, obtain Q risk coefficients, and use the Q risk coefficients as iterative risk association identification results.

6. The e-commerce platform risk management system based on behavior analysis as claimed in claim 5, characterized in that: The first iterative risk association identification unit includes: A feature extraction subunit, used to extract features from the Q first user behavior information and the Q second user behavior information respectively, to obtain Q first user behavior feature sets and Q second user behavior feature sets; A feature mapping similarity calculation subunit is used to perform feature mapping similarity calculation on the Q first user behavior feature sets and the Q second user behavior feature sets to obtain Q first user behavior feature similarity sets; A normalization processing subunit, used for normalizing the Q first user behavior feature similarity sets, and adding the processing results into the Q first iteration risk association matrices which are initially empty; The convolution operation subunit is used to perform convolution operations on the Q first iteration risk association matrices and the Q second user behavior feature sets respectively to obtain Q first iteration risk association user behavior features.

7. The e-commerce platform risk management system based on behavior analysis as claimed in claim 5, characterized in that: The risk factor identification unit includes: A training data acquisition subunit is used to acquire multiple sample final iteration risk-associated user behavior characteristics and multiple sample risk coefficients as training data; The risk factor identifier training subunit is used to supervise the training of the framework built based on the feedforward neural network using the training data, learn the one-to-one mapping relationship between the final iterative risk-related user behavior characteristics and the risk factor, until the training is completed, and obtain the risk factor identifier; The risk identification subunit is used to use the risk coefficient identifier to perform risk identification on the Q final iterative risk-associated user behavior characteristics to obtain Q risk coefficients.

8. The e-commerce platform risk management system based on behavior analysis as claimed in claim 1, characterized in that: The risk identification module includes: A judgment processing unit, used to judge whether the M risk user behavior information sequences contain the known risk information, and if so, add the known risk information to the first target risk user behavior information sequence set, and add the risk user corresponding to the known risk user to the first target risk user set; A matching similarity calculation unit is used to perform matching similarity calculation on M risk user behavior information sequences by screening the historical risk behavior log set, add the risk user behavior information sequences whose matching similarity is greater than or equal to a preset matching similarity threshold to the second target risk user behavior information sequence set, and add the corresponding risk users to the second target risk user set; The union solving unit is used to find the union of the first target risk user set and the second target risk user set to obtain P target risk users, and to find the union of the first target risk user behavior information sequence set and the second target risk user behavior information sequence set to obtain P target risk user behavior information sequences.

Citation Information

Patent Citations

  • User operation behavior risk control method and device, equipment and medium

    CN119151629A

  • Intelligent risk control system and method for cross-border e-commerce digitization

    CN119398479A