Fraud information identification method and device, electronic equipment, storage medium and program product
The method of automatically generating fraud samples using large language models solves the problem of time-consuming and labor-intensive fraud sample collection and analysis, achieving efficient and accurate fraud detection, enabling responses to new fraud methods, and enhancing the defense capabilities of anti-fraud systems.
Patent Information
- Application Number
- CN202411592442.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-11-08
- Publication Date
- 2025-11-28
- Estimated Expiration
- 2044-11-08
AI Technical Summary
In existing technologies, the collection and analysis of fraud samples rely on manual operation, which is time-consuming, labor-intensive, and difficult to keep up with the rapid changes in fraud methods, resulting in insufficient effectiveness and accuracy of fraud detection systems.
Fraud samples are automatically generated using a large language model. By acquiring fraudulent advertising descriptions, analyzing and preprocessing them, constructing prompt words, optimizing them, and then inputting them into the large language model to generate fraud information samples, which are then identified using a trained fraud information recognition model.
It improves the efficiency and accuracy of the fraud detection system, enabling timely responses to new fraud methods, generating high-quality and diverse fraud samples, and enhancing the defense capabilities of anti-fraud technology.
Smart Images

Figure CN119722094B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present disclosure relates to the technical field of fraud information recognition, and in particular, to a fraud information recognition method and device, an electronic device, a storage medium, and a program product. BACKGROUND
[0002] This section is intended to provide background or context to the embodiments of the disclosure recited in the claims. The description herein does not constitute admission that the prior art is prior art nor does it constitute an admission of any description in this section pertaining to background or context.
[0003] With the popularity of the Internet and digital communication, the forms and methods of fraud activities are constantly evolving, bringing serious security risks. Fraudulent behavior is usually highly concealed and deceptive, which makes it increasingly difficult to manually collect and analyze fraud samples in related technologies. In order to improve the effectiveness and accuracy of fraud detection systems, researchers and practitioners need a large number of fraud samples for training and testing machine learning models.
[0004] In related technologies, the collection and analysis of fraud samples usually rely on manual operation, which not only consumes time and effort, but also makes it difficult to keep up with the rapid changes in fraud methods. SUMMARY
[0005] Therefore, the purpose of the present disclosure is to provide a fraud information recognition method, device, electronic device, storage medium, and program product, which at least partially solves one of the technical problems in the related art.
[0006] To achieve the above purpose, in a first aspect, the present disclosure provides a fraud information recognition method, comprising:
[0007] obtaining fraud propaganda description information;
[0008] analyzing the fraud propaganda description information to obtain an analysis result;
[0009] constructing a prompt word based on the analysis result;
[0010] testing the prompt word based on a first large language model to obtain a test result, optimizing the prompt word based on the test result to obtain an optimized prompt word;
[0011] reasoning the optimized prompt word based on a second large language model to generate a fraud information sample;
[0012] obtaining to-be-recognized information, inputting the to-be-recognized information into a fraud information recognition model to obtain a fraud information recognition result output by the fraud information recognition model, wherein the fraud information recognition model is trained based on the fraud information sample.
[0013] Based on the same inventive concept, a second aspect of the exemplary embodiments of the present disclosure provides a fraud information identification device, comprising:
[0014] A fraud propaganda description information acquisition module is configured to acquire fraud propaganda description information.
[0015] A fraud propaganda description information analysis module is configured to analyze the fraud propaganda description information to obtain an analysis result.
[0016] A prompt word construction module is configured to construct a prompt word based on the analysis result.
[0017] A prompt word optimization module is configured to test the prompt word based on a first large language model to obtain a test result, optimize the prompt word based on the test result to obtain an optimized prompt word.
[0018] A fraud information sample generation module is configured to infer the optimized prompt word based on a second large language model to generate a fraud information sample.
[0019] A fraud information identification module is configured to acquire to-be-identified information, input the to-be-identified information into a fraud information identification model, and obtain a fraud information identification result output by the fraud information identification model, wherein the fraud information identification model is trained based on the fraud information sample.
[0020] Based on the same inventive concept, a third aspect of the exemplary embodiments of the present disclosure provides an electronic device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement the method of the first aspect.
[0021] Based on the same inventive concept, a fourth aspect of the exemplary embodiments of the present disclosure provides a non-transitory computer-readable storage medium, which stores computer instructions for causing a computer to execute the method of the first aspect.
[0022] Based on the same inventive concept, a fifth aspect of the exemplary embodiments of the present disclosure provides a computer program product, comprising computer program instructions, which, when executed on a computer, cause the computer to execute the method of the first aspect.
[0023] As can be seen from the above description, the fraud information identification method, device, electronic device, storage medium, and program product provided in this disclosure include: acquiring fraudulent advertising description information; analyzing the fraudulent advertising description information to obtain analysis results; constructing prompt words based on the analysis results; testing the prompt words based on a first large language model to obtain test results; optimizing the prompt words based on the test results to obtain optimized prompt words; inferring from the optimized prompt words based on a second large language model to generate fraud information samples; acquiring information to be identified; inputting the information to be identified into a fraud information identification model to obtain fraud information identification results output by the fraud information identification model, wherein the fraud information identification model is trained based on the fraud information samples. This disclosure utilizes a large language model to achieve automated generation of fraud samples, improving the efficiency and accuracy of anti-fraud technology in dealing with new fraud methods. Attached Figure Description
[0024] To more clearly illustrate the technical solutions in this disclosure or related technologies, the accompanying drawings used in the description of the embodiments or related technologies will be briefly introduced below. Obviously, the accompanying drawings described below are only embodiments of this disclosure. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0025] Figure 1 A schematic diagram illustrating an application scenario of the fraud information identification method provided as an exemplary embodiment of this disclosure;
[0026] Figure 2 A flowchart illustrating a fraud information identification method provided as an exemplary embodiment of this disclosure;
[0027] Figure 3 A schematic diagram of a fraud information identification device provided as an exemplary embodiment of this disclosure;
[0028] Figure 4 A schematic diagram of the structure of an electronic device provided as an exemplary embodiment of the present disclosure. Detailed Implementation
[0029] It is understood that before using the technical solutions disclosed in the various embodiments of this application, users should be informed of the types, scope of use, and usage scenarios of the personal information involved in this application in an appropriate manner in accordance with relevant laws and regulations, and user authorization should be obtained.
[0030] For example, in response to receiving an active request of a user, a prompt information is sent to the user to explicitly prompt the user that the operation requested to be performed will need to acquire and use personal information of the user. Thus, the user can autonomously select whether to provide personal information to the software or hardware such as an electronic device, an application program, a server or a storage medium, etc. performing the operation of the technical solution of the present application according to the prompt information.
[0031] As an optional but non-limiting implementation manner, in response to receiving an active request of a user, the manner of sending a prompt information to the user may, for example, be a pop-up window manner, in which the prompt information can be presented in a text manner. In addition, the pop-up window can also carry a selection control for the user to select “agree” or “disagree” to provide personal information to the electronic device.
[0032] It can be understood that the above notification and acquisition of user authorization process is only illustrative and does not limit the implementation manner of the present application, and other manners meeting relevant laws and regulations can also be applied to the implementation manner of the present application.
[0033] It can be understood that the data (including but not limited to the data itself, acquisition or use of the data) involved in the technical solution should comply with the requirements of relevant laws and regulations and relevant provisions.
[0034] In order to make the purpose, technical solution and advantages of the present disclosure clearer, the principles and spirits of the present disclosure will be described below with reference to several exemplary embodiments. It should be understood that these embodiments are only given to enable those skilled in the art to better understand and implement the present disclosure, and do not limit the scope of the present disclosure in any way. On the contrary, these embodiments are provided to make the present disclosure more thorough and complete, and to fully convey the scope of the present disclosure to those skilled in the art.
[0035] In the present disclosure, it should be understood that any number of elements in the drawings is used for illustration and not limitation, and any naming is only used for differentiation and does not have any limiting meaning.
[0036] For clarity, unless otherwise defined, technical and scientific terms used in the present disclosure shall have the same meaning as commonly understood by one of ordinary skill in the art to which this present disclosure belongs. The terms "first", "second", and similar terms do not imply any order, quantity, or importance, but are used to distinguish one element from another. The terms "include", "contain", and similar terms mean that the elements or objects before the term encompass the elements or objects listed after the term and their equivalents, without excluding other elements or objects. The terms "connect" or "connected" and similar terms are not limited to physical or mechanical connections, but can include electrical connections, whether direct or indirect. The terms "upper", "lower", "left", "right", and the like are used only to indicate relative positional relationships, which can change accordingly when the absolute positions of the described objects change. The article "a" or "an" before an element does not exclude the presence of multiple such elements.
[0037] The principles and spirits of the present disclosure will be explained in detail below with reference to several representative embodiments of the present disclosure.
[0038] As described in the background, with the popularity of the Internet and digital communication, the forms and methods of fraud activities are constantly evolving, bringing serious security risks. Fraudulent behavior is usually highly concealed and deceptive, which makes it increasingly difficult to manually collect and analyze fraud samples in related technologies. In order to improve the effectiveness and accuracy of fraud detection systems, researchers and practitioners need a large number of fraud samples for training and testing machine learning models.
[0039] In related technologies, the collection and analysis of fraud samples usually rely on manual operations, which not only consumes time and effort, but also makes it difficult to keep up with the rapid changes in fraud methods.
[0040] With the rapid development of large language models, using these models to automatically generate fraud samples has become a new solution. These models can generate high-quality and diverse text samples based on existing data, simulate different types of fraud methods and strategies, and thus provide rich data support for fraud detection systems.
[0041] However, the inventors of the present disclosure found that the prior art in generating fraud samples based on large language models usually faces the following challenges: how to accurately extract and update fraud keywords and patterns, how to design effective prompt words to generate high-quality fraud samples, and how to ensure that the generated samples can cover the latest fraud trends and methods.
[0042] To solve the above problems, the present disclosure provides a fraud information identification scheme, specifically including: obtaining fraud propaganda description information; analyzing the fraud propaganda description information to obtain an analysis result; based on the analysis result, constructing a prompt word; based on a first large language model, testing the prompt word to obtain a test result, optimizing the prompt word based on the test result to obtain an optimized prompt word; based on a second large language model, reasoning the optimized prompt word to generate a fraud information sample; obtaining to-be-identified information, inputting the to-be-identified information into a fraud information identification model to obtain a fraud information identification result output by the fraud information identification model, wherein the fraud information identification model is trained based on the fraud information sample. The present disclosure uses a large language model to realize the automatic generation of fraud samples, and improves the efficiency and accuracy of anti-fraud technology in response to new fraud methods.
[0043] The method for automatically generating fraud samples based on a large language model provided by the present disclosure improves the generation effect of fraud samples and the diversity of data through systematic data processing and prompt word optimization.
[0044] After introducing the basic principles of the present disclosure, various non-limiting embodiments of the present disclosure will be specifically introduced.
[0045] Reference Figure 1 It is a kind of application scene schematic diagram of fraud information identification method provided by the exemplary embodiment of the present disclosure.
[0046] In this application scenario, it includes terminal device 101, server 102 and data storage system 103. Among them, terminal device 101, server 102 and data storage system 103 can be connected through wired or wireless communication network to realize data interaction.
[0047] The terminal device 101 can be an electronic device close to the user side with data transmission, multimedia input / output function, including but not limited to desktop computer, mobile phone, mobile computer, tablet computer, media player, smart wearable device, personal digital assistant (PDA) or other electronic devices capable of realizing the above functions. The electronic device can include a processor and a display screen with touch input function, the display screen is used to present a graphical user interface, the graphical user interface can display an application interface, the processor is used to process application data, generate a graphical user interface and control the display of the graphical user interface on the display screen.
[0048] The server 102 and the data storage system 103 can each be a stand-alone physical server, a server cluster or a distributed system composed of multiple physical servers, a cloud server providing cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, CDN (Content Delivery Network), and basic cloud computing services such as big data and artificial intelligence platforms.
[0049] In some example embodiments, the fraud information identification method can run on the terminal device 101 or the server 102.
[0050] When the fraud information identification method runs on the server 102, the server 102 is configured to provide a fraud information identification service to a user of the terminal device 101. The terminal device 101 is installed with a client that communicates with the server 102. The client can actively capture the to-be-identified information from the terminal device 101, or the user can input the to-be-identified information through the client. The client sends the to-be-identified information to the server 102. The server 102 obtains the to-be-identified information, inputs the to-be-identified information into the fraud information identification model, and obtains a fraud information identification result output by the fraud information identification model. The fraud information identification model is trained based on the fraud information samples.
[0051] The fraud information samples are obtained in the following manner. Fraud propaganda description information is obtained. The fraud propaganda description information is analyzed to obtain an analysis result. A prompt word is constructed based on the analysis result. The prompt word is tested based on a first large language model to obtain a test result. The prompt word is optimized based on the test result to obtain an optimized prompt word. The optimized prompt word is reasoned based on a second large language model to generate a fraud information sample.
[0052] After obtaining the fraud information identification result, the server 102 generates a fraud information warning message in response to determining that the fraud information identification result indicates that the to-be-identified information is fraud information. The server 102 sends the fraud information warning message to the client of the terminal device 101. The client displays the fraud information warning message to the user to help the user identify fraud.
[0053] The data storage system 103 stores fraud information samples. The server 102 can train the fraud information identification model based on the fraud information samples, so that the fraud information identification model can identify the input to-be-identified information. When the accuracy of the fraud information identification model output reaches a certain requirement, the server 102 can provide a fraud information identification service to the user based on the fraud information identification model. Meanwhile, the server 102 can continuously optimize the fraud information identification model based on newly added fraud information samples.
[0054] The training method of a fraud information recognition model and a fraud information recognition method according to an exemplary embodiment of the disclosure will be described below in connection with an application scenario of Figure 1 Note that the above application scenario is merely shown for the convenience of understanding the spirit and principles of the disclosure, and the embodiments of the disclosure are not limited in this respect. On the contrary, the embodiments of the disclosure can be applied to any applicable scenario.
[0055] Referring to Figure 2 FIG. 1 is a flowchart of a fraud information recognition method according to an exemplary embodiment of the disclosure.
[0056] The fraud information recognition method comprises the following steps:
[0057] In step S210, fraud propaganda description information is acquired.
[0058] In the present exemplary embodiment, the sources of the fraud propaganda description information include, but are not limited to, existing databases and data crawled from the Internet, etc. Some exemplary sources are introduced as follows:
[0059] Social media platforms: Collecting user-reported fraud information or suspicious activities detected by the platform itself from mainstream social media platforms. Social media is an important way for fraud means to spread, so the data obtained from these platforms usually has high timeliness.
[0060] Online forums and communities: Online forums, community websites, and hacker forums often become the birthplace of new fraud means. The system can regularly crawl and monitor these websites to collect the latest fraud means and cases.
[0061] News media: Regularly reported fraud cases are also an important data source. These cases are investigated and verified by journalists, and usually have high reliability and typicality.
[0062] Public databases: For example, publicly available fraud datasets published by governments or non-profit organizations, which may contain detailed fraud case analysis and statistical information.
[0063] Reports of security companies and research institutions: Many network security companies and research institutions regularly publish research reports and white papers on fraud means. These documents usually contain detailed fraud means analysis and countermeasures, and are an important source of collecting high-quality data.
[0064] Through the above exemplary embodiments, the latest fraud propaganda description information can be collected from various public information sources or reliable data sources, ensuring that the scheme provided by the present disclosure always has timeliness and high simulation, so that the defense capability and response effect can be maintained when facing new fraud methods, thereby better protecting users and systems from fraud threats.
[0065] Step S220, analyzing the fraud propaganda description information to obtain an analysis result.
[0066] In the present exemplary embodiment, the fraud propaganda description information is preprocessed before being analyzed. Specifically:
[0067] The fraud propaganda description information is cleaned to obtain cleaned fraud propaganda description information.
[0068] In specific implementation, in order to ensure the consistency of data, the system needs to clean the text data from different sources and standardize the data format. Through the content similarity algorithm, duplicate text data is detected and deleted. The existence of redundant data may affect the accuracy of the analysis result, so it must be strictly handled.
[0069] The standardized content includes unified coding format and unified text structure:
[0070] The unified coding format converts all text data into a unified character encoding (such as UTF-8) to avoid the problem of garbled characters caused by inconsistent encoding.
[0071] The unified text structure unifies the text structure of data from different sources, such as unified paragraph format, punctuation usage rules, etc. This can be achieved through regular expressions or text parsing tools.
[0072] Through the above exemplary embodiments, the fraud propaganda description information is cleaned, which can improve the accuracy of analyzing the fraud propaganda description information.
[0073] The collected latest fraud text data is preprocessed to remove noise and irrelevant information, ensuring that the remaining text data has high quality for further analysis.
[0074] Further, duplicate or highly similar texts are deleted to avoid the influence of redundant data on subsequent analysis results. This step helps to improve the effectiveness and representativeness of the data.
[0075] Then, the text data of different sources are uniformly processed in format, ensuring that the encoding, font, case, etc. of all data meet the standards. This makes the subsequent analysis process smoother and reduces errors caused by inconsistent formats.
[0076] Through the above preprocessing steps, the system can ensure that the collected fraud text data has high quality, uniformity and usability, providing a solid foundation for the subsequent prompt word design and large language model generation.
[0077] In the example embodiment, the analysis of the fraud propaganda description information obtains an analysis result, which includes:
[0078] Fraud means type analysis is performed on the fraud propaganda description information to obtain a fraud means classification result.
[0079] Based on the fraud means classification result, natural language analysis is performed on the fraud propaganda description information to obtain feature information of the fraud propaganda description information.
[0080] Based on the fraud means classification result, trend analysis is performed on the fraud propaganda description information to obtain a priority corresponding to different fraud means types.
[0081] In specific implementation, different fraud means are classified according to the text content, such as phishing fraud, impersonating customer service, and false investment. Classification helps to identify the main features and common methods of each type of fraud.
[0082] In specific implementation, through natural language processing technology, the system extracts common sentence structures, keywords, and tone styles from the fraud text. These features will provide a basis for subsequent prompt word design.
[0083] In specific implementation, the system performs trend analysis on the frequency of fraud means, victim groups, and transmission channels to identify which fraud means are emerging and which have gradually been eliminated. This helps to ensure that the generated samples are consistent with the reality of fraud dynamics.
[0084] Step S230, based on the analysis result, constructing a prompt word.
[0085] In the example embodiment, the construction of the prompt word based on the analysis result includes:
[0086] Based on the feature information of the fraud propaganda description information and the priority corresponding to the different fraud means types, the prompt word for different fraud scenarios is constructed.
[0087] In specific implementation, according to the analysis of the latest fraud data, the preliminary design of the prompt words should be combined with the current popular fraud means and common fraud scenarios. The prompt words not only need to accurately capture the characteristics of fraud language, but also need to have a certain flexibility to generate diversified text samples.
[0088] In specific implementation, based on the analysis results, prompt word templates are designed for different fraud scenarios. The design of the templates should have a certain universality to adapt to different specific situations.
[0089] In specific implementation, for some complex fraud scenarios, a single prompt word may not be able to cover all situations. At this time, multi-segment or hierarchical prompt words can be designed to guide the model to generate more complex text samples.
[0090] In specific implementation, according to the evaluation results, all effective prompt words are selected, and the effective prompt words are further enhanced by logical combination.
[0091] Step S240, test the prompt words based on the first large language model to obtain test results, optimize the prompt words based on the test results to obtain optimized prompt words.
[0092] In specific implementation, after designing the prompt words, the system will conduct a preliminary test on these prompt words to evaluate their generation effect and effectiveness in actual application.
[0093] In the example embodiment, the testing of the prompt words based on the first large language model to obtain test results, the optimization of the prompt words based on the test results to obtain optimized prompt words, includes:
[0094] input the prompt words into the first large language model to obtain fraud text samples output by the first large language model;
[0095] perform effectiveness mixed correlation evaluation and diversity evaluation on the fraud text samples to obtain effectiveness mixed correlation evaluation results and diversity evaluation results;
[0096] based on the effectiveness mixed correlation evaluation results and the diversity evaluation results, optimize the prompt words to obtain the optimized prompt words.
[0097] In specific implementation, each designed prompt word is input into the large language model as input. A small amount of fraud text samples are generated, and the samples are analyzed and evaluated.
[0098] Quality evaluation of generated fraud samples is an important step in prompt optimization. This process directly affects the effectiveness of the prompt and the quality of the final generated samples. By evaluating the relevance, diversity, and effectiveness of the generated samples, the system can identify the strengths and weaknesses of the prompt and make appropriate optimization adjustments to ensure that the large language model can generate high-quality fraud text that meets expectations.
[0099] In implementation, the effectiveness mixed relevance evaluation aims to ensure that the generated fraud samples are consistent with the expected content of the prompt and can accurately reflect the fraud scenarios set by the prompt. By checking whether the generated samples contain the key words in the prompt, it ensures that the generated content is consistent with the intent of the prompt. Figure 1
[0100] In implementation, diversity evaluation mainly examines the diversity of generated fraud samples in content, style, and structure, avoiding the generation of overly single and repetitive text. The improvement of diversity helps to simulate more types of fraud methods and improve the adaptability of the anti-fraud system. By checking the repetition rate between generated samples, it ensures that the system can generate content-rich and diverse text.
[0101] Then, according to the generation result, identify the possible problems of the prompt in the generation process, such as the generated text not meeting expectations, content repetition, or not being diverse enough.
[0102] In implementation, for prompts that meet the conditions, further optimization and polishing are carried out, and iteration is continuously carried out until the prompt can generate effective samples.
[0103] Step S250, based on the second large language model, the optimized prompt is inferred to generate a fraud information sample.
[0104] In the example embodiment, the second large language model is used to infer the optimized prompt to generate a fraud information sample, which includes:
[0105] Obtain a fraud information sample example;
[0106] Input the fraud information sample example and the optimized prompt into the second large language model to obtain the fraud information sample output by the second large language model.
[0107] In implementation, in the process of generating fraud samples, a small amount of existing fraud text data is used as an example, combined with the designed prompt, and the large language model can generate fraud samples consistent with the current fraud trend. This step is to combine the real fraud text collected in the early stage with the optimized prompt to fully utilize the generation ability of the large language model and ensure that the generated samples have diversity and effectiveness in content, style, and structure.
[0108] In practice, the example data needs to be representative. The system selects a representative small sample set from the collected and processed fraud text data. This example data typically includes typical fraud cases, commonly used fraud language patterns, and the latest fraud strategies. The selection of example data is crucial; it provides a realistic foundation for the large language model, ensuring that the generated samples closely match actual fraud scenarios.
[0109] After selecting sample data, the system combines this data with previously optimized prompts and feeds it into the large language model. The optimized prompts have been tested and adjusted to effectively guide the model in generating high-quality text samples. Combining them with the sample data further enhances the guiding role of the prompts, making the generated text more diverse and relevant.
[0110] In practice, the system needs to select suitable sample data from the existing fraud text database. This data should be representative and reflect common current fraud methods and trends.
[0111] Furthermore, priority is given to recent fraud cases to ensure that the data reflects current fraud trends and provides a basis for generating timely samples for large language models.
[0112] The design of prompt words is key to guiding large language models to generate specific types of fraudulent text, and combining prompt words with example data can enhance the realism and consistency of the generated results.
[0113] In practice, selected sample data is embedded in prompt words, and a large language model is guided to imitate the language style and logical structure of the sample data to generate fraudulent text with similar characteristics.
[0114] In practice, the generation process requires certain management and optimization measures to ensure the quality and consistency of the generated samples.
[0115] In practice, the generation parameters of the large language model, such as temperature and maximum generation length, are adjusted according to the characteristics of the example data and prompt words in order to control the diversity and logical consistency of the generated samples.
[0116] In addition, by generating samples in batches, the most suitable fraudulent samples can be gradually generated and filtered out, avoiding the generation of a large number of low-quality texts at once and saving computing resources. During the generation process, the output quality of the model is monitored in real time, and prompt words or generation parameters are adjusted as necessary to ensure high-quality output of the final samples.
[0117] After generating fraud samples using a large language model, the generated results need to be initially screened and evaluated to remove unqualified samples and retain high-quality generated content.
[0118] In implementation, it is necessary to ensure that the generated samples meet the expected requirements of the example data and prompt words in terms of logical structure, language style and content consistency. During screening, the authenticity of the generated samples is focused on, that is, whether these texts are sufficiently deceptive and potentially confusing in reality. Samples with high similarity or repetition are removed to ensure that the final retained samples have diversity in content and form to meet the multi-dimensional needs of the anti-fraud system.
[0119] Through the above steps, the system can make full use of existing fraud text data and the generation ability of large language models, combined with carefully designed prompt words, to generate high-quality samples that meet the current fraud trends.
[0120] Step S260, obtaining the to-be-identified information, inputting the to-be-identified information into the fraud information identification model to obtain a fraud information identification result output by the fraud information identification model, wherein the fraud information identification model is trained based on the fraud information samples.
[0121] In the present exemplary embodiment, after obtaining the fraud information identification result output by the fraud information identification model, the method further comprises:
[0122] In response to determining that the fraud information identification result is that the to-be-identified information is fraud information, a fraud information warning message is generated, and the fraud information warning message is sent to a specified terminal device.
[0123] In the present exemplary embodiment, the method further comprises:
[0124] The prompt words are updated regularly, and the prompt words are adjusted based on new fraud means and strategies.
[0125] In the context of rapid evolution of fraud means, maintaining the timeliness and effectiveness of prompt words is the key to generating high-quality fraud samples. Regularly updating prompt words and adjusting them based on new fraud means and strategies can ensure that the generated fraud samples always reflect the latest fraud trends and enhance the defense capabilities of the anti-fraud system.
[0126] In order to ensure the long-term effectiveness and adaptability of the prompt words, the maintenance and management of the prompt word library are essential.
[0127] In implementation, the latest fraud methods and trends are regularly monitored and collected, and new fraud patterns and strategies are identified by analyzing the latest fraud texts and cases. The existing prompt words are reviewed to identify the parts that need to be updated, and they are adjusted or expanded according to the latest fraud features found. The prompt words are redesigned and optimized to ensure that they can cover emerging fraud scenarios and methods. The effectiveness of the adjusted prompt words is verified by generating new samples and testing and evaluating them to ensure that they can accurately simulate the latest fraud strategies and maintain the high quality and diversity of the generated samples.
[0128] In implementation, the prompt word library is structured and managed according to dimensions such as fraud types and application scenarios, facilitating subsequent prompt word queries, updates, and applications. Structured management can also improve the scalability of the prompt word library, supporting the addition of new fraud types in the future. Structuring and managing the prompt word library according to dimensions such as fraud types and application scenarios facilitates subsequent prompt word queries, updates, and applications. Structured management can also improve the scalability of the prompt word library, supporting the addition of new fraud types in the future.
[0129] Through the above mechanisms, the system can regularly update and optimize the prompt word library to ensure that the generated fraud samples always have timeliness and high simulation. In this way, the anti-fraud system will be able to maintain high defense capabilities and response effectiveness when facing new fraud methods, thereby better protecting users and systems from fraud threats.
[0130] As can be seen from the above, the present disclosure can use a large language model to realize the automatic generation of fraud samples, greatly improving the efficiency and accuracy of anti-fraud technology in response to new fraud methods. At the same time, the method of regularly updating and optimizing the prompt words ensures the timeliness of the generated samples, so that the anti-fraud system can always effectively defend based on the latest fraud methods.
[0131] It should be noted that the method of the present embodiment can be executed by a single device, such as a computer or a server. The method of the present embodiment can also be applied in a distributed scenario, with multiple devices cooperating to complete the method. In this distributed scenario, one of the multiple devices can only execute one or more steps of the method of the present embodiment, and the multiple devices can interact with each other to complete the method.
[0132] It is to be noted that some embodiments of the present disclosure are described above. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims can be performed in a different order and still achieve desirable results. Additionally, the processes depicted in the figures do not necessarily require the particular order shown or sequential order to achieve desirable results. In certain implementations, multitasking and parallel processing can be advantageous.
[0133] Based on the same inventive concept, the present disclosure also provides a fraud information identification device corresponding to any of the above-mentioned embodiment methods.
[0134] Reference Figure 3 , which is a structural schematic diagram of a fraud information identification device provided by an exemplary embodiment of the present disclosure.
[0135] The fraud information identification device comprises the following modules:
[0136] The fraud propaganda description information acquisition module 310 is configured to acquire fraud propaganda description information;
[0137] The fraud propaganda description information analysis module 320 is configured to analyze the fraud propaganda description information to obtain an analysis result;
[0138] The prompt word construction module 330 is configured to construct a prompt word based on the analysis result;
[0139] The prompt word optimization module 340 is configured to test the prompt word based on a first large language model to obtain a test result, optimize the prompt word based on the test result, and obtain an optimized prompt word;
[0140] The fraud information sample generation module 350 is configured to infer the optimized prompt word based on a second large language model to generate a fraud information sample;
[0141] The fraud information identification module 360 is configured to acquire to-be-identified information, input the to-be-identified information into a fraud information identification model, and obtain a fraud information identification result output by the fraud information identification model, wherein the fraud information identification model is trained based on the fraud information sample.
[0142] In some exemplary embodiments, the fraud propaganda description information analysis module 320 is specifically configured to:
[0143] analyze the fraud propaganda description information in terms of fraud means type to obtain a fraud means classification result;
[0144] perform natural language analysis on the fraud propaganda description information based on the fraud means classification result, to obtain feature information of the fraud propaganda description information;
[0145] perform trend analysis on the fraud propaganda description information based on the fraud means classification result, to obtain a priority corresponding to different fraud means types.
[0146] In some example embodiments, the prompt word construction module 330 is specifically configured to:
[0147] construct the prompt word for different fraud scenarios based on the feature information of the fraud propaganda description information and the priority corresponding to the different fraud means types.
[0148] In some example embodiments, the prompt word optimization module 340 is specifically configured to:
[0149] input the prompt word into the first large language model to obtain a fraud text sample output by the first large language model;
[0150] perform effectiveness and diversity evaluation on the fraud text sample to obtain an effectiveness and diversity evaluation result;
[0151] optimize the prompt word based on the effectiveness and diversity evaluation result to obtain an optimized prompt word.
[0152] In some example embodiments, the fraud information sample generation module 350 is specifically configured to:
[0153] obtain a fraud information sample example;
[0154] input the fraud information sample example and the optimized prompt word into the second large language model to obtain the fraud information sample output by the second large language model.
[0155] In some example embodiments, the fraud information identification module 360 is further configured to:
[0156] in response to determining that the fraud information identification result is that the to-be-identified information is fraud information, generate a fraud information warning message, and send the fraud information warning message to a specified terminal device.
[0157] For the convenience of description, the above apparatus is described in various modules respectively based on functions. Of course, the functions of each module can be implemented in one or more software and / or hardware when implementing the present disclosure.
[0158] The device of the above embodiment is used to implement the corresponding fraud information identification method in any of the preceding embodiments, and has the beneficial effects of the corresponding method embodiments, which will not be described here.
[0159] Based on the same inventive concept, the disclosure also provides an electronic device corresponding to the method of any of the above embodiments, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the fraud information identification method of any of the above embodiments when executing the program.
[0160] Figure 4 A more specific hardware structure of an electronic device is shown in this embodiment, which can include a processor 1010, a memory 1020, an input / output interface 1030, a communication interface 1040, and a bus 1050. The processor 1010, the memory 1020, the input / output interface 1030, and the communication interface 1040 are connected to each other through the bus 1050 for communication within the device.
[0161] The processor 1010 can be implemented by a general-purpose CPU (Central Processing Unit), a microprocessor, an ASIC (Application Specific Integrated Circuit), or one or more integrated circuits, etc., for executing related programs to implement the technical solutions provided by the embodiments of the present specification.
[0162] The memory 1020 can be implemented by a ROM (Read Only Memory), a RAM (Random Access Memory), a static storage device, a dynamic storage device, etc. The memory 1020 can store an operating system and other application programs, and when the technical solutions provided by the embodiments of the present specification are implemented by software or firmware, the related program codes are stored in the memory 1020 and executed by the processor 1010.
[0163] The input / output interface 1030 is used to connect the input / output module to realize information input and output. The input / output module can be configured as a component in the device (not shown in the figure), or can be externally connected to the device to provide corresponding functions. The input device can include a keyboard, a mouse, a touch screen, a microphone, various sensors, etc., and the output device can include a display, a speaker, a vibrator, an indicator light, etc.
[0164] The communication interface 1040 is configured to connect a communication module (not shown in the figure) to realize the communication interaction between the device and other devices. The communication module can realize communication through wired mode (such as USB, network cable, etc.), or can realize communication through wireless mode (such as mobile network, WIFI, Bluetooth, etc.).
[0165] The bus 1050 includes a path for transmitting information between various components (such as the processor 1010, the memory 1020, the input / output interface 1030, and the communication interface 1040) of the device.
[0166] It should be noted that although the above device only shows the processor 1010, the memory 1020, the input / output interface 1030, the communication interface 1040, and the bus 1050, in the specific implementation process, the device can also include other components necessary for normal operation. In addition, those skilled in the art can understand that the above device can also only contain the components necessary for the implementation of the embodiments of the present specification, and does not have to contain all the components shown in the figure.
[0167] The electronic device of the above embodiment is used to implement the fraud information identification method corresponding to any of the above embodiments, and has the beneficial effects of the corresponding method embodiments, which are not described here.
[0168] The memory 1020 stores machine-readable instructions executable by the processor 1010. When the electronic device is running, the processor 1010 and the memory 1020 communicate through the bus 1030, so that the processor 1010 executes the following instructions when running:
[0169] Obtain fraud propaganda description information;
[0170] Analyze the fraud propaganda description information to obtain an analysis result;
[0171] Based on the analysis result, construct a prompt word;
[0172] Test the prompt word based on a first large language model to obtain a test result, optimize the prompt word based on the test result to obtain an optimized prompt word;
[0173] Infer the optimized prompt word based on a second large language model to generate a fraud information sample;
[0174] Obtain the to-be-identified information, input the to-be-identified information into a fraud information identification model, and obtain a fraud information identification result output by the fraud information identification model, wherein the fraud information identification model is trained based on the fraud information sample.
[0175] In a possible implementation, in the instructions executed by the processor 1010, the analysis on the fraud propaganda description information to obtain an analysis result includes:
[0176] fraud means type analysis on the fraud propaganda description information to obtain a fraud means classification result;
[0177] natural language analysis on the fraud propaganda description information based on the fraud means classification result to obtain feature information of the fraud propaganda description information;
[0178] trend analysis on the fraud propaganda description information based on the fraud means classification result to obtain a priority corresponding to different fraud means types.
[0179] In a possible implementation, in the instructions executed by the processor 1010, the construction of the prompt word based on the analysis result includes:
[0180] construction of the prompt word for different fraud scenarios based on the feature information of the fraud propaganda description information and the priority corresponding to the different fraud means types.
[0181] In a possible implementation, in the instructions executed by the processor 1010, the testing of the prompt word based on the first large language model to obtain a test result, the optimization of the prompt word based on the test result to obtain an optimized prompt word includes:
[0182] inputting the prompt word into the first large language model to obtain a fraud text sample output by the first large language model;
[0183] validity and mixed relevance evaluation and diversity evaluation on the fraud text sample to obtain a validity and mixed relevance evaluation result and a diversity evaluation result;
[0184] optimization of the prompt word based on the validity and mixed relevance evaluation result and the diversity evaluation result to obtain the optimized prompt word.
[0185] In a possible implementation, in the instructions executed by the processor 1010, the inference of the optimized prompt word based on the second large language model to generate a fraud information sample includes:
[0186] obtaining a fraud information sample example;
[0187] inputting the fraud information sample example and the optimized prompt word into the second large language model to obtain the fraud information sample output by the second large language model.
[0188] In a possible implementation, after obtaining the fraud information identification result output by the fraud information identification model, the processor 1010 executes the instructions, and the method further includes:
[0189] In response to determining that the fraud information identification result is that the to-be-identified information is fraud information, generating a fraud information warning message, and sending the fraud information warning message to a specified terminal device.
[0190] Based on the same inventive concept, the disclosure also provides a non-transitory computer-readable storage medium, which stores computer instructions for causing a computer to execute the fraud information identification method according to any one of the above embodiments.
[0191] The computer-readable medium of the present embodiment includes permanent and non-permanent, removable and non-removable media, which can be implemented by any method or technology to store information. The information can be computer-readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassette, magnetic tape, magnetic disk storage or other magnetic storage devices, or any other non-transmission medium that can be used to store information accessible by a computing device.
[0192] The above non-transitory computer-readable storage medium can be any available medium or data storage device that can be accessed by a computer, including but not limited to magnetic storage (such as floppy disks, hard disks, magnetic tapes, magneto-optical disks (MO) and the like), optical storage (such as CDs, DVDs, BDs, HVDs and the like), and semiconductor memory (such as ROM, EPROM, EEPROM, non-volatile memory (NAND FLASH), solid state disk (SSD)) and the like.
[0193] The storage medium of the above embodiment stores computer instructions for causing the computer to execute the fraud information identification method according to any one of the above exemplary method embodiments, and has the beneficial effects of the corresponding method embodiments, which are not repeated here.
[0194] Based on the same inventive concept, the disclosure also provides a computer program product corresponding to the fraud information identification method described in any of the above embodiments, which comprises computer program instructions. In some embodiments, the computer program instructions can be executed by one or more processors of a computer to cause the computer and / or the processor to perform the fraud information identification method described above. Corresponding to the execution subject of each step in each embodiment of the fraud information identification method, the processor performing the corresponding step can belong to the corresponding execution subject.
[0195] The computer program product of the above embodiments is used to cause the computer and / or the processor to perform the fraud information identification method described in any of the above embodiments, and has the beneficial effects of the corresponding method embodiments, which are not repeated here.
[0196] Those skilled in the art know that the embodiments of the disclosure can be implemented as a system, a method or a computer program product. Therefore, the disclosure can be embodied in the form of entire hardware, entire software (including firmware, resident software, microcode, etc.), or a combination of hardware and software, which is generally referred to as "circuitry", "module" or "system". In addition, in some embodiments, the disclosure can also be embodied in the form of a computer program product in one or more computer readable media, which contains computer readable program code.
[0197] Any combination of one or more computer readable medium can be used. The computer readable medium can be a computer readable signal medium or a computer readable storage medium. The computer readable storage medium can be, for example, but not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, device or apparatus, or any combination of the above. More specific examples (non-exhaustive list) of the computer readable storage medium can include an electrical connection having one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the disclosure, the computer readable storage medium can be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, device or apparatus.
[0198] A computer readable signal medium can include a propagated data signal with computer executable instructions. A propagated signal can be an electromagnetic signal, an optical signal, and / or any other suitable type of signal. A computer readable medium can include any suitable medium that is accessible by a computer. Examples of a computer readable medium include a random access memory (RAM), a read-only memory (ROM), a compact disk (CD-ROM), a floppy disk, a hard disk, an optical disk, a magnetic tape, and / or another suitable medium. Combinations of the above should also be included within the scope of computer readable media.
[0199] The program code embodied on a computer readable medium can be transmitted using any appropriate medium, including but not limited to wireless, wire line, optical fiber cable, RF, etc., or any suitable combination of the foregoing.
[0200] Computer program code for carrying out operations of the present disclosure can be written in any combination of one or more programming languages, including an object oriented programming language such as Java, Smalltalk, C++ or the like and conventional procedural programming languages, such as the "C" programming language or similar programming languages. The program code can execute entirely on the user's computer, partly on the user's computer, as a stand-alone software package, partly on the user's computer and partly on a remote computer or entirely on the remote computer or server. In the latter scenario, the remote computer can be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or the connection can be made to an external computer (for example, through the Internet using an Internet Service Provider).
[0201] It should be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general purpose computer, special purpose computer, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, create means for implementing the functions / acts specified in the flowchart and / or block diagram block or blocks.
[0202] These computer program instructions can also be stored in a computer readable medium that can direct a computer or other programmable data processing apparatus to function in a particular manner, such that the instructions stored in the computer readable medium produce an article of manufacture including instructions which implement the functions / acts specified in the flowchart and / or block diagram block or blocks.
[0203] The computer program instructions can also be loaded onto a computer, other programmable data processing apparatus, or other device to cause a series of operational steps to be performed on the computer, other programmable apparatus or other device to produce a computer implemented process such that the instructions which execute on the computer or other programmable apparatus provide processes for implementing the functions / acts specified in the flowchart and / or block diagram block or blocks.
[0204] Further, although the operations of the method of the present disclosure are described in a particular, sequential order, this order is not meant to be a limitation. For example, some operations can be performed in an order different than that described. Further, some operations can be performed in parallel, in combination with, or in place of, one another. In addition, some operations can be omitted. Moreover, where appropriate, aspects of the disclosure can be implemented by various means, for example, hardware, software, firmware, or a combination thereof. In the case of a software implementation, the program code, or portions of it, can be embodied as a computer-readable medium, for example, a floppy disk, a CD-ROM, a DVD, a Blu-ray disk, a Flash drive, a memory stick, a magnetic tape, or a suitable computer readable medium. The program code can be downloaded from an Internet website, a server, a cloud storage, or a suitable computer program product. In the case of a firmware or hardware implementation, the program code, or portions of it, can be embodied as a computer-readable medium, for example, an EPROM, an FPGA, an ASIC, or a suitable computer readable medium.
[0205] The flow diagrams and the block diagrams in the drawings are illustrations of possible architectures, functions, and operations for systems, methods, and computer program products according to various embodiments of the present application. It will be understood that each block of the flow diagrams and / or block diagrams, and combinations of blocks in the flow diagrams and / or block diagrams, can be implemented by various means, such as hardware, software, firmware, or a combination thereof. Also, it will be appreciated that each block and / or a combination of blocks can be implemented by an appropriately configured processor, such as a general purpose processor, a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA) or other programmable logic component, a microcontroller, or a combination of hardware and software. In this manner, the operations and functions indicated in the flow diagrams and / or block diagrams can be carried out.
[0206] It should be noted that, although the above detailed description refers to several modules or units of the device for action execution, this division is not mandatory. Indeed, according to the embodiments of the present application, the features and functionalities of two or more modules or units described above can be embodied in one module or unit. Conversely, the features and functionalities of one module or unit described above can be further divided into several modules or units embodied by several modules or units.
[0207] Those skilled in the art should understand that the above discussion of any embodiment is merely exemplary and is not intended to be limiting of the scope of the application (including the claims) which is intended to be limited only by the claims. The above embodiments or technical features among different embodiments can also be combined, steps can be implemented in any order, and there are many other variations of the aspects of the embodiments of the application as described above, which are not provided in detail in order to be brief. The embodiments of the application are not limited in scope by the sum of the embodiments disclosed because the embodiments of the application include any combination of the embodiments.
[0208] In addition, to simplify the description and discussion, and so as not to make the embodiments of the application difficult to understand, the well-known power / ground connections to integrated circuit (IC) chips and other components can or can not be shown in the provided drawings. Furthermore, devices can be shown in block diagram form in order to avoid making the embodiments of the application difficult to understand, and this also takes into account the fact that the details regarding the implementation of these block diagram devices are highly dependent on the platform on which the embodiments of the application are to be implemented (i.e., these details should be well within the understanding of those skilled in the art). Where specific details (e.g., circuitry) are set forth in order to describe an illustrative embodiment of the application, it should be apparent to those skilled in the art that the embodiment of the application can be practiced without these specific details or with an equivalent arrangement. Therefore, the description should not be construed as limiting, but merely as illustrative.
[0209] Although the application has been described in conjunction with specific embodiments thereof, numerous alternatives, modifications, and variations will be readily apparent to those skilled in the art. For example, other memory architectures (e.g., dynamic RAM (DRAM)) can use the embodiments discussed.
[0210] The embodiments of the application are intended to cover all such alternatives, modifications, and variations which fall within the broad scope of the appended claims. Accordingly, any one of the above-described embodiments of the application can be further modified or combined in any manner possible within the scope of the application. Therefore, the application is not limited by the specific embodiments described herein, but only by the scope of the appended claims, and any equivalents thereof.
[0211] While the principles of the disclosure have been described above in connection with specific embodiments, it is to be understood that this disclosure is not limited to the disclosed embodiments, but is intended to encompass various modifications and equivalent arrangements within the scope of the appended claims. The scope of the claims should be accorded the broadest interpretation so as to encompass all such modifications and equivalent structures and functions.
Claims
1. A fraud information recognition method characterized by comprising: The method comprises the following steps: obtain fraud propaganda description information; perform fraud means type analysis on the fraud propaganda description information to obtain fraud means classification results; perform natural language analysis on the fraud propaganda description information based on the fraud means classification results to obtain feature information of the fraud propaganda description information; perform trend analysis on the fraud propaganda description information based on the fraud means classification results to obtain priorities corresponding to different fraud means types; construct prompt words for different fraud scenarios based on the feature information of the fraud propaganda description information and the priorities corresponding to the different fraud means types; input the prompt words into a first large language model to obtain fraud text samples output by the first large language model, optimize the prompt words based on test results to obtain optimized prompt words; perform reasoning on the optimized prompt words based on a second large language model to generate fraud information samples; obtain to-be-recognized information, input the to-be-recognized information into a fraud information recognition model to obtain fraud information recognition results output by the fraud information recognition model, wherein the fraud information recognition model is trained based on the fraud information samples.
2. The method of claim 1, wherein, The method comprises the following steps: perform effectiveness mixed correlation evaluation and diversity evaluation on the fraud text samples to obtain effectiveness mixed correlation evaluation results and diversity evaluation results; optimize the prompt words based on the effectiveness mixed correlation evaluation results and the diversity evaluation results to obtain the optimized prompt words.
3. The method of claim 1, wherein, The method comprises the following steps: obtain fraud information sample examples; input the fraud information sample examples and the optimized prompt words into the second large language model to obtain the fraud information samples output by the second large language model.
4. The method of claim 1, wherein, After obtaining the fraud information recognition results output by the fraud information recognition model, the method further comprises the following steps: in response to determining that the fraud information recognition result is that the to-be-recognized information is fraud information, generate a fraud information warning message and send the fraud information warning message to a specified terminal device.
5. A fraud information recognition apparatus characterized by comprising: The method comprises the following steps: a fraud propaganda description information obtaining module configured to obtain fraud propaganda description information; a fraud propaganda description information analysis module configured to perform fraud means type analysis on the fraud propaganda description information to obtain fraud means classification results; perform natural language analysis on the fraud propaganda description information based on the fraud means classification results to obtain feature information of the fraud propaganda description information; perform trend analysis on the fraud propaganda description information based on the fraud means classification results to obtain priorities corresponding to different fraud means types; a prompt word construction module configured to construct prompt words for different fraud scenarios based on the feature information of the fraud propaganda description information and the priorities corresponding to the different fraud means types; The prompt word optimization module is configured to input the prompt word into a first large language model, obtain a fraud text sample output by the first large language model, optimize the prompt word based on a test result, and obtain an optimized prompt word; The fraud information sample generation module is configured to perform reasoning on the optimized prompt word based on a second large language model, and generate a fraud information sample; The fraud information identification module is configured to obtain to-be-identified information, input the to-be-identified information into a fraud information identification model, and obtain a fraud information identification result output by the fraud information identification model, wherein the fraud information identification model is trained based on the fraud information sample.
6. An electronic device, comprising: The computer program is stored in the memory and executable on the processor, and the processor executes the program to implement the method of any one of claims 1 to 4.
7. A non-transitory computer-readable storage medium, comprising: The non-transitory computer readable storage medium stores computer instructions for causing a computer to execute the method of any one of claims 1 to 4.
8. A computer program product, characterised in that, The computer program instructions, when executed on a computer, cause the computer to execute the method of any one of claims 1 to 4.
Citation Information
Patent Citations
Transaction behavior identification method and device, electronic equipment and storage medium
CN117575602A
Intelligent anti-fraud technology and system based on large language model adaptive iteration
CN117910452A