Risk identification model training method and device, electronic equipment and storage medium

CN119740627BActive Publication Date: 2026-08-21CHINA TOWER CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202411653961.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-11-18
Publication Date
2026-08-21
Estimated Expiration
2044-11-18

AI Technical Summary

Technical Problem

[0004]一方面交易风险识别模型的训练需要大量有标签数据,而人工进行标签的标注费时费力

Benefits of technology

[0011]上述技术方案中的一个技术方案具有如下的优点或有益效果,能够自动为预设的风险业务规则为事件序列中的风险事件序列标注风险标签,同时在通过无标签的事件序列对自编码器神经网络进行训练基础上构建初步的识别模型,并通过自动标注的标签对初步的识别模型进行训练,得到训练后的识别模型,能够在保障风险识别模型的准确性的基础上,大幅减少人工标注标签的工作量。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119740627B_ABST
    Figure CN119740627B_ABST
Patent Text Reader

Abstract

The embodiment of the present disclosure provides a kind of training method, device, electronic equipment and storage medium of transaction risk identification model, involve artificial intelligence technical field.The method comprises the following steps: obtaining a plurality of event sequences in a financial transaction process;According to the risk event sequence in the plurality of event sequences, a risk label is labeled for the risk event sequence according to a preset risk business rule, to obtain a risk event sequence;The event sequence without label is input into the self-encoder neural network to be trained for training, to obtain the self-encoder neural network trained, and the self-encoder neural network trained is added to constitute a first identification model by full connection layer;The risk event sequence is input into the first identification model for training, to obtain the second identification model after training.The technical scheme can greatly reduce the workload of manual label marking on the basis of ensuring the accuracy of risk identification model.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to the field of artificial intelligence technology, and in particular to a method, apparatus, electronic device and storage medium for training a risk identification model. Background Technology

[0002] With the development of internet technology, online financial transactions are becoming increasingly common through technologies such as blockchain, making risk identification in these transactions increasingly important.

[0003] While technical solutions for identifying trading risks through training models have emerged, these risk identification models still have some technical problems.

[0004] On the one hand, training transaction risk identification models requires a large amount of labeled data, and manual labeling is time-consuming and labor-intensive. On the other hand, the accuracy of transaction risk identification models also needs improvement. For example, the model may encounter abnormal transaction types that it cannot resolve. For instance, if the remitter or victim in a transaction is identified as a high-end or special customer by a credit rating agency, any transaction risk method based on machine learning or human analysis cannot easily reject the transaction, which could lead to potential risks in the transaction process. Furthermore, high-end or special customers may rarely appeal even if a transaction is rejected, and the transaction risk identification model may not be able to learn the corresponding characteristics in a timely manner, further affecting the model's accuracy. Summary of the Invention

[0005] The purpose of this disclosure is to provide a training method, apparatus, electronic device, and storage medium for a transaction risk identification model.

[0006] To solve the above-mentioned technical problems, the embodiments of this disclosure are achieved through the following aspects.

[0007] According to a first aspect of the present disclosure, a method for training a transaction risk identification model is provided, the method comprising: Acquire multiple event sequences during a financial transaction process, wherein the event sequence includes event type, event occurrence time, and event subject; Risk tags are assigned to the risk event sequences among the multiple event sequences according to preset risk business rules, thereby obtaining the risk event sequences; Unlabeled event sequences are input into an autoencoder neural network to be trained to obtain a trained autoencoder neural network. A fully connected layer is added to the trained autoencoder neural network to form a first recognition model. The unlabeled event sequences are other event sequences besides the risk event sequences among the multiple event sequences. The risk event sequence is input into the first identification model for training to obtain the trained second identification model.

[0008] According to a second aspect of the present disclosure, a training apparatus for a transaction risk identification model is provided. The apparatus includes: an acquisition module, configured to acquire multiple event sequences during a financial transaction process, wherein the event sequence includes event type, event occurrence time, and event subject. The labeling module is used to label risk event sequences in the multiple event sequences with risk tags according to preset risk business rules, thereby obtaining risk event sequences; The first training module is used to input unlabeled event sequences into the autoencoder neural network to be trained for training, to obtain a trained autoencoder neural network, and to add a fully connected layer to the trained autoencoder neural network to form a first recognition model. The unlabeled event sequences are other event sequences besides the risk event sequences among the multiple event sequences. The second training module is used to input the risk event sequence into the first identification model for training, so as to obtain the trained second identification model.

[0009] According to a third aspect of the present disclosure, an electronic device is provided, comprising: a processor; and a memory for storing processor-executable instructions; wherein the processor is configured to perform the steps of the training method for the transaction risk identification model described in the first aspect.

[0010] According to a fourth aspect of the present disclosure, a computer-readable storage medium is provided that stores one or more programs, which, when executed by an electronic device including a plurality of applications, cause the electronic device to perform the steps of the training method for the transaction risk identification model described in the first aspect.

[0011] One of the above technical solutions has the following advantages or beneficial effects: it can automatically label risk event sequences in the event sequence for preset risk business rules, and at the same time, it can build a preliminary recognition model based on training the autoencoder neural network with unlabeled event sequences, and train the preliminary recognition model with automatically labeled tags to obtain the trained recognition model. This can significantly reduce the workload of manual labeling while ensuring the accuracy of the risk recognition model.

[0012] It should be understood that the above general description and the following detailed description are exemplary and explanatory only, and are not intended to limit this disclosure.

[0013] Other features and advantages of this disclosure will be described in detail in the following detailed description section. Attached Figure Description

[0014] To more clearly illustrate the technical solutions in the embodiments of this disclosure or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments recorded in this disclosure. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0015] Figure 1 This diagram illustrates a flowchart of a training method for a transaction risk identification model provided in an embodiment of this disclosure. Figure 2 This diagram illustrates another flowchart of the training method for the transaction risk identification model provided in this embodiment of the present disclosure. Figure 3 This diagram illustrates yet another flowchart of the training method for the transaction risk identification model provided in this embodiment of the present disclosure; Figure 4 This diagram illustrates yet another flowchart of the training method for the transaction risk identification model provided in this embodiment of the present disclosure; Figure 5 This diagram illustrates yet another flowchart of the training method for the transaction risk identification model provided in this embodiment of the present disclosure; Figure 6 This diagram shows a block diagram of a training device for a transaction risk identification model provided in an embodiment of this application; Figure 7 This diagram illustrates a training apparatus for another transaction risk identification model provided in an embodiment of this application. Figure 8 A schematic diagram of the hardware structure of an electronic device for implementing the training method of the transaction risk identification model provided in the embodiments of this disclosure. Detailed Implementation

[0016] To enable those skilled in the art to better understand the technical solutions in this disclosure, the technical solutions in the embodiments of this disclosure will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this disclosure, and not all embodiments. Based on the embodiments in this disclosure, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of this disclosure.

[0017] It should be noted that the transactions in this application can be financial transactions based on network technology, such as data trust transactions based on blockchain technology, or online transfers, online shopping, and other transactions based on the network. This application does not limit the specific types of financial transactions.

[0018] Figure 1 This illustration shows a flowchart of a training method for a transaction risk identification model provided in an embodiment of this disclosure, such as... Figure 1 As shown, the method may include the following steps: In step S101, multiple event sequences in the financial transaction process are obtained.

[0019] The event sequence includes the event type, the time of the event, and the subject of the event.

[0020] Taking data trust transactions based on blockchain technology as an example, in the fintech industry, blockchain stores data scattered across a distributed architecture in a chain, forming a transparent record. Each record block is ordered according to the event sequence, and multiple record blocks together form a public ledger. The public ledger data comes from financial transaction events in nodes. A node is a hardware terminal in the financial information blockchain with financial transaction permissions and node information. Each node corresponds to a different financial transaction subsystem. Event data occurring on different nodes during the original financial transaction process can be obtained. For the same event subject on different nodes, the event sequence can be obtained by arranging the events in chronological order.

[0021] An event sequence is a collection of events arranged in chronological order. Events can refer to various behaviors, operations, or state changes that occur during a transaction, such as user login, transaction initiation, and transaction confirmation.

[0022] In some embodiments, an event sequence may include an event type, an event occurrence time, and an event subject, wherein the event subject may be a user, account, or other entity involved in the event. The event sequence may further include an event identifier and additional event information, wherein the event identifier is used to uniquely identify an event, and the additional event information is used to record other information related to the event, such as transaction amount and transaction location.

[0023] In practical applications, event sequences can be stored in the form of data structures (such as lists, arrays) or database tables, with each event serving as an element in the data structure or a row in the database table.

[0024] As an example, Table 1 below shows the raw data obtained from the nodes.

[0025]

[0026] Table 1 Based on the raw data obtained from the nodes in Table 1, we can further obtain the event sequence corresponding to the raw data as follows: Event 1: Event identifier: E001 Event type: User login Time of incident: 2023-04-01 10:00:01 Event subject: User ID 001 Additional information about the event: None Event 2: Event identifier: E002 Event type: Transaction initiation Time of incident: 2023-04-01 10:05:30 Event subject: User ID 001 Additional information about the event: Transaction amount: 1000 Event 3: Event identifier: E003 Event type: Transaction confirmation Time of incident: 2023-04-01 10:06:00 Event subject: User ID 001 Additional information about the event: Transaction amount: 1000 Through the steps described above, the raw data is transformed into a series of events arranged chronologically. Each event contains necessary information, such as event type, event time, and event subject. It may also include additional event information and corresponding event identifiers. These event sequences can serve as input data for subsequent risk identification models, used to train and optimize the models.

[0027] In step S102, risk labels are marked on the risk event sequences in multiple event sequences according to preset risk business rules to obtain risk event sequences.

[0028] In some embodiments, event sequences can be analyzed using preset risk business rules to identify the risk factors contained therein, identify the corresponding risk event sequences, and label the risk event sequences among multiple event sequences with risk tags.

[0029] For example, an account with a low credit rating but unusually high trading activity is a typical risk factor. The preset risk business rule can be "the account's credit rating is less than the credit threshold, and the number of transactions exceeds the quantity threshold in any preset time period". When the same account meets the preset risk business rule in multiple event sequences, one or more event sequences corresponding to that account are regarded as risk event sequences, and risk labels are marked on the risk event sequences.

[0030] In some embodiments, preset risk business rules can be classified according to the degree of risk, thereby labeling risk event sequences with different levels of risk tags. Figure 2This illustration shows another flowchart of the training method for the transaction risk identification model provided in this embodiment of the disclosure, such as... Figure 2 As shown, step S102 may include the following steps.

[0031] In step S1021, the event sequences that satisfy the first risk business rule are labeled with a high-risk tag.

[0032] In step S1022, the event sequence that meets the second risk business rule is labeled with a general risk label.

[0033] The preset risk business rules may include a first risk business rule and a second risk business rule, wherein the risk level of the event sequence corresponding to the first risk business rule is higher than the risk level of the event sequence corresponding to the second risk business rule.

[0034] In some embodiments, the subjects of an event can be divided into primary and secondary objects according to the degree of risk. The primary object is the core entity directly related to the high-risk behavior, such as the account with a low credit rating but abnormally active trading activity in the example above. The secondary object is an entity with a lower degree of risk but which has some connection with the primary object, or an entity with a certain degree of risk itself, such as an entity that has traded with the primary object.

[0035] Accordingly, the preset risk business rules can be divided into first risk business rules and second risk business rules. Event sequences that meet the first risk business rules are designated as high-risk event sequences and labeled as high-risk events. Event sequences that meet the first risk business rules are designated as ordinary risk event sequences and labeled as ordinary risk events.

[0036] In some embodiments, the high-risk label may specifically be "fraud risk", and the ordinary risk label may specifically be "suspected abnormal transaction risk".

[0037] In step S1023, the event sequences other than those labeled with high-risk and ordinary-risk tags are treated as unlabeled event sequences.

[0038] In step S103, the unlabeled event sequence is input into the autoencoder neural network to be trained for training, and a trained autoencoder neural network is obtained. A fully connected layer is then added to the trained autoencoder neural network to form the first recognition model.

[0039] Among them, the unlabeled event sequence is the event sequence other than the risk event sequence among multiple event sequences.

[0040] Autoencoder neural networks can include encoders and decoders. By restricting the flow of information between the encoder and decoder, the model can learn a compact representation of the input data. The encoder transforms the input data into a representation in the latent space through layer-by-layer processing. This representation typically has higher-level abstract features than the original data. The decoder then transforms the representation in the latent space back into the original input space through inverse operations, thereby reconstructing the data.

[0041] In some embodiments, an unlabeled event sequence can be input into the autoencoder neural network to be trained. With the goal of minimizing the reconstruction error of the autoencoder neural network to be trained, the parameters of the autoencoder neural network to be trained are iteratively optimized through the backpropagation algorithm until a preset number of iterations is reached or the reconstruction error is less than a preset threshold, thus obtaining a trained autoencoder neural network.

[0042] It is understood that, in this application, inputting the event sequence into the neural network model means performing corresponding feature transformation or extraction on the event sequence, and then inputting the transformed or extracted event sequence features into the neural network model.

[0043] After obtaining the trained autoencoder neural network, a fully connected layer can be added to the trained autoencoder neural network to form the first recognition model, so that the first recognition model can obtain the output results corresponding to the unlabeled event sequence through the corresponding activation function.

[0044] In step S104, the risk event sequence is input into the first identification model for training to obtain the trained second identification model.

[0045] After obtaining the first identification model, the risk event sequence can be input into the first identification model for training to obtain the second identification model through the following steps.

[0046] In step 10, the risk event sequence is input into the first identification model to obtain the output of the first identification model. During this process, the data will pass through each layer of the neural network in sequence, and each layer will calculate the output of the layer based on the current weights and input data.

[0047] In step 11, the loss value between the output result and the label of the risk event sequence is calculated, and the gradient of each model parameter in each first identification model is calculated using the backpropagation algorithm. The gradient represents the sensitivity of the loss value to the model parameters, that is, how a small change in the model parameters will affect the loss value.

[0048] In step 12, based on the calculated gradient, the values ​​of each model parameter are updated using an optimization algorithm (such as gradient descent or Adam algorithm). The purpose of the update is to reduce the loss value between the output and the labels of the risk event sequence.

[0049] In step 13, steps 10-13 are repeated until a preset training termination condition is reached. For example, this training termination condition may be reaching a preset number of training epochs or the loss value being less than a preset loss value threshold.

[0050] By adopting the above technical solution, the workload of manual labeling can be significantly reduced while ensuring the accuracy of the risk identification model.

[0051] Figure 3 This illustration shows another flowchart of the training method for the transaction risk identification model provided in this disclosure, such as... Figure 3 As shown, the method may also include the following steps.

[0052] In step S105, in response to the user's labeling operation on the unlabeled event sequence or the labeling update operation on the risk event sequence, the updated labeled event sequence is obtained.

[0053] In some embodiments, users can manually annotate unlabeled time series, and then manually correct any erroneous annotations in the manually annotated event series. The manually annotated event series, the corrected risk event series, and the original risk event series (i.e., the event series that were not manually corrected) can be used as the updated annotated event series to optimize the second identification model.

[0054] In step S106, the updated labeled event sequence is input into the second recognition model, and the second recognition model is trained to obtain the updated second recognition model.

[0055] In some possible implementations, the specific steps for optimizing the training of the second recognition model are described in steps 10-13, which will not be elaborated here.

[0056] By adopting the above technical solution, the labeled event sequence can be obtained by combining automatic and manual annotation. Through the updated labeled event sequence, the second identification model can learn from expert experience, thereby further improving the accuracy of the risk identification model.

[0057] Figure 4 This illustration shows another flowchart of the training method for the transaction risk identification model provided in this disclosure, such as... Figure 4 As shown, the method may also include the following steps.

[0058] In step S107, the sequence of events in which the output of the second recognition model is different from the corresponding label during the training process is taken as the abnormal event sequence set.

[0059] In some embodiments, event sequences that the second recognition model cannot correctly identify during training are taken as an abnormal event sequence set.

[0060] In step S108, the abnormal event sequence with the highest tag frequency is selected from the abnormal event sequence set to obtain a subset of abnormal event sequences.

[0061] In some possible implementations, the set of event sequences whose corresponding labels appear more frequently than a preset frequency threshold (e.g., 60%) can be used as a subset of the abnormal event sequences.

[0062] For example, if there are 100 event sequences in the abnormal event sequence set, and 73 of them are labeled "high risk", then these 73 event sequences can be considered as the subset of abnormal event sequences labeled "high risk".

[0063] In step S109, the correlation degree between each pair of abnormal event sequences in the subset of abnormal event sequences is calculated, and the corresponding label is updated according to at least one correlation degree corresponding to the abnormal event sequence.

[0064] Among them, the correlation degree characterizes the temporal correlation and attribute similarity between two corresponding anomalous event sequences. Attribute similarity, also known as attribute weight, is used to measure the similarity of features between two event sequences. Temporal correlation degree measures the correlation between two event sequences along the event dimension.

[0065] In some embodiments, the attribute similarity between any two event sequences can be determined using the following formula.

[0066] (Formula 1) in, For attribute similarity, These are preset values ​​for commonly used tags (i.e., tags corresponding to subsets of abnormal event sequences). For example, when the commonly used tag is a high-risk tag, It can be 0.7, when the commonly used label is the ordinary risk label. It can be 1, and These represent the probabilities that the two event sequences obtained on the second recognition model belong to common labels.

[0067] For example, suppose that the risk labels for event sequence A and event sequence B are both ordinary risk labels, and event sequence A corresponds to... =0.6, the event sequence B corresponds to If the similarity is 0.8, then the attribute similarity is 0.48.

[0068] The temporal correlation between any two event sequences can be determined using the following formula (Formula 2).

[0069] (Formula 2) in, For the time correlation degree, The time difference between two event sequences This represents the time difference between the latest and earliest event sequences within a subset of anomalous event sequences. This represents the time difference between the later event sequence and the earliest event sequence in two event sequences. This is a preset adjustment parameter, such as 0.8.

[0070] Suppose that the subset of abnormal event sequences includes event sequence A, event sequence B, event sequence C, and event sequence D, and the times when event sequence A, event sequence B, and event sequence C occur are t0=2022-12-31, t1=2023-01-01, t2=2023-01-10, and t3=2023-01-30, respectively.

[0071] The temporal correlation between event sequence B and event sequence C can be calculated as follows.

[0072] but = t3 - t0 = 30 days, =10 days =9 days, substituting the above values ​​into Formula 2 yields the following result. =2.4.

[0073] In some embodiments, for the same event sequence, multiple correlation degrees can be obtained by calculating the correlation degree with other event sequences in the subset of abnormal event sequences. The maximum value among the multiple correlation degrees corresponding to the event sequence can be taken as the final correlation degree corresponding to the event sequence.

[0074] In some embodiments, the degree of connection is the product of temporal correlation and attribute similarity. Figure 5 This illustration shows another flowchart of the training method for the transaction risk identification model provided in this disclosure, such as... Figure 5 As shown, step S109 may specifically include the following steps.

[0075] In step S1091, the first probability of the risk event output by the second identification model before the update is obtained for the abnormal event sequence.

[0076] For example, the first probability of a risk event output by the second identification model before the update of the abnormal event sequence is 0.71. The threshold assumption of the second identification model when making risk identification judgment is 0.8. Since the first probability is less than the threshold, the result output by the second identification model is a normal risk label.

[0077] In step S1092, the product of the connection degree and the first probability is used as the second probability.

[0078] For example, the correlation degree of the anomalous event sequence is 0.48. 2.4 = 1.152. Multiplying this correlation degree by the first probability of 0.71 yields the second probability of 1.152. 0.71 = 0.82.

[0079] In step S1093, the updated label corresponding to the abnormal event sequence is determined based on the second probability and the preset threshold in the second identification model before the update.

[0080] After obtaining the second probability, based on the second probability of 0.82 and the corresponding threshold of 0.8, since the second probability is greater than the threshold, the updated label corresponding to the abnormal event sequence is a high-risk label.

[0081] Understandably, the correlation coefficient can be greater than or less than 1, so the second probability can be greater than or less than the first probability. Correspondingly, the label determined based on the second probability and the preset threshold in the second recognition model before the update can be the same as or different from the output of the second recognition model before the update.

[0082] In step S110, the abnormal event sequence after the label is updated is input into the second recognition model, and the second recognition model is trained to obtain the updated second recognition model.

[0083] In some possible implementations, the specific steps for optimizing the training of the second recognition model are described in steps 10-13, which will not be elaborated here.

[0084] By adopting the above technical solution, it is possible to calculate the frequency and correlation of data in the abnormal event sequence set, extract the highly correlated set, and use the highly correlated set to adjust and optimize the identification model, thereby further improving the accuracy of the risk identification model.

[0085] It should be noted that, Figure 3 and Figure 4 The steps shown can be performed alternately and iteratively. Figure 1 The steps shown can also be followed after obtaining the latest event sequence in real time. Figure 3 and / or Figure 4The steps shown are performed iteratively to obtain financial transaction information in real time and dynamically adjust and optimize the model.

[0086] Figure 6 This diagram illustrates a block diagram of a training apparatus for a transaction risk identification model provided in an embodiment of this application. Figure 6 As shown, the training device 100 for the transaction risk identification model includes: The acquisition module 110 is used to acquire multiple event sequences in the financial transaction process. The event sequence includes event type, event occurrence time and event subject.

[0087] The labeling module 120 is used to label risk event sequences in multiple event sequences with risk tags according to preset risk business rules, thereby obtaining risk event sequences.

[0088] The first training module 130 is used to input unlabeled event sequences into the autoencoder neural network to be trained for training, to obtain a trained autoencoder neural network, and to add a fully connected layer to the trained autoencoder neural network to form a first recognition model. The unlabeled event sequences are other event sequences other than risk event sequences among multiple event sequences.

[0089] The second training module 140 is used to input the risk event sequence into the first identification model for training, so as to obtain the trained second identification model.

[0090] Optionally, the preset risk business rules include a first risk business rule and a second risk business rule. The risk level of the event sequence corresponding to the first risk business rule is higher than the risk level of the event sequence corresponding to the second risk business rule. The labeling module 120 is further used to label risk event sequences among multiple event sequences with risk tags according to the preset risk business rules. Event sequences that meet the first risk business rule will be labeled as high-risk.

[0091] Event sequences that meet the second risk business rules will be labeled with ordinary risk tags.

[0092] Other event sequences in the event sequence, except those labeled with high-risk and ordinary-risk tags, are treated as unlabeled event sequences.

[0093] Optionally, the first training module 130 is also used for: The unlabeled event sequence is input into the autoencoder neural network to be trained. With the goal of minimizing the reconstruction error of the autoencoder neural network, the parameters of the autoencoder neural network to be trained are iteratively optimized through the backpropagation algorithm until a preset number of iterations is reached or the reconstruction error is less than a preset threshold, thus obtaining a trained autoencoder neural network.

[0094] The device 100 provided in this application embodiment can execute the methods in the preceding method embodiments and realize the functions and beneficial effects of the methods in the preceding method embodiments, which will not be repeated here.

[0095] Figure 7 This diagram illustrates a block diagram of a training apparatus for a transaction risk identification model provided in an embodiment of this application. Figure 7 As shown, the training device 100 for the transaction risk identification model also includes an optimization module 150, used for: In response to user annotation operations on unlabeled event sequences or label update operations on risk event sequences, the updated labeled event sequences are obtained; The updated labeled event sequence is input into the second recognition model, and the second recognition model is trained to obtain the updated second recognition model.

[0096] Optionally, the optimization module 150 is also used for: The sequence of events in which the output of the second recognition model differs from the corresponding label during the training process is taken as the set of abnormal event sequences. The abnormal event sequence set is filtered to obtain a subset of abnormal event sequences by selecting the abnormal event sequence sets with the highest tag frequency; Calculate the correlation degree between each pair of anomalous event sequences in the subset of anomalous event sequences, and update the corresponding label based on at least one correlation degree corresponding to the anomalous event sequence. The correlation degree represents the temporal correlation and attribute similarity between the corresponding two anomalous event sequences. The updated sequence of abnormal events is input into the second recognition model, and the second recognition model is trained to obtain the updated second recognition model.

[0097] Optionally, the optimization module 150 is also used for: Obtain the first probability of the risk event from the output of the second identification model before the update of the abnormal event sequence; The product of the degree of connection and the first probability is used as the second probability; The updated label corresponding to the abnormal event sequence is determined based on the second probability and the preset threshold in the second recognition model before the update.

[0098] The device 100 provided in this application embodiment can execute the methods in the preceding method embodiments and realize the functions and beneficial effects of the methods in the preceding method embodiments, which will not be repeated here.

[0099] Figure 8 This diagram illustrates the hardware structure of an electronic device implementing embodiments of the present disclosure, such as... Figure 8As shown, at the hardware level, the electronic device includes at least one processor, and optionally, an internal bus, a network interface, and memory. The memory may include main memory, such as high-speed random-access memory (RAM), or it may also include non-volatile memory, such as at least one disk drive. Of course, the electronic device may also include other hardware required for other business operations.

[0100] The processor, network interface, and memory can be interconnected via an internal bus, which can be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, or an Extended Industry Standard Architecture (EISA) bus, etc. This bus can be categorized as an address bus, data bus, control bus, etc. For ease of illustration, only a single bidirectional arrow is used in this diagram, but this does not imply that there is only one bus or one type of bus.

[0101] Memory stores programs. Specifically, the program may include program code, which includes at least one computer operation instruction. Memory may include main memory and non-volatile memory, and provides instructions and data to the processor.

[0102] At least one processor reads a corresponding computer program from non-volatile memory into memory and then runs it, forming a device for locating a target user at the logical level. At least one processor executes the program stored in memory and specifically performs the method disclosed in the embodiments shown in the first aspect, achieving the functions and beneficial effects of the methods described in the foregoing method embodiments, which will not be repeated here.

[0103] The methods disclosed in the embodiments shown in the first aspect of this disclosure can be applied to at least one processor, or implemented by at least one processor. The processor may be an integrated circuit chip with signal processing capabilities. During implementation, each step of the above method can be completed by integrated logic circuits in the hardware or by instructions in the form of software within at least one processor. The processor may be a general-purpose processor, including a Central Processing Unit (CPU), a Network Processor (NP), etc.; it may also be a Digital Signal Processor (DSP), an Application Specific Integrated Circuit (ASIC), a Field-Programmable Gate Array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components. The methods, steps, and logic block diagrams disclosed in the embodiments of this disclosure can be implemented or executed. The general-purpose processor may be a microprocessor or any conventional processor. The steps of the methods disclosed in the embodiments of this disclosure can be directly embodied in the execution of a hardware decoding processor, or executed by a combination of hardware and software modules in the decoding processor. The software module can reside in a mature storage medium in the field, such as random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, or registers. This storage medium is located in memory, and the processor reads information from the memory and, in conjunction with its hardware, completes the steps of the above method.

[0104] The electronic device can also execute the methods described in the preceding method embodiments and achieve the functions and beneficial effects of the methods described in the preceding method embodiments, which will not be repeated here.

[0105] Of course, in addition to software implementation, the electronic device disclosed herein does not exclude other implementation methods, such as logic devices or a combination of hardware and software, etc. In other words, the execution subject of the following processing flow is not limited to each logic unit, but can also be hardware or logic devices.

[0106] This disclosure also proposes a computer-readable storage medium that stores one or more programs, which, when executed by at least one processor, implement the methods disclosed in the embodiments of the first aspect and achieve the functions and beneficial effects of the methods described in the foregoing method embodiments, which will not be repeated here.

[0107] The computer-readable storage medium mentioned above includes read-only memory (ROM), random access memory (RAM), magnetic disk, or optical disk, etc.

[0108] Furthermore, this disclosure also provides a computer program product, which includes a computer program stored on a non-transitory computer-readable storage medium. The computer program includes program instructions that, when executed by a computer, implement the following process: the method disclosed in the first aspect embodiment and the functions and beneficial effects of the methods described in the foregoing method embodiments are not repeated here.

[0109] This application provides a computer program product, which includes a computer program. When the computer program is executed by a processor, it implements the various processes of the method disclosed in the first aspect embodiment and can achieve the same technical effect. To avoid repetition, it will not be described again here.

[0110] In summary, the above description is merely a preferred embodiment of this disclosure and does not limit the scope of protection of this disclosure. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this disclosure should be included within the scope of protection of this disclosure.

[0111] The systems, modules, or units described in the above embodiments can be implemented by computer chips or entities, or by products with certain functions. A typical implementation device is a computer. Specifically, a computer can be, for example, a personal computer, laptop computer, cellular phone, camera phone, smartphone, personal digital assistant, media player, navigation device, email device, game console, tablet computer, wearable device, or any combination of these devices.

[0112] Computer-readable media includes both permanent and non-permanent, removable and non-removable media that can store information by any method or technology. Information can be computer-readable instructions, data structures, modules of programs, or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, CD-ROM, digital versatile optical disc (DVD) or other optical storage, magnetic tape, magnetic magnetic disk storage or other magnetic storage devices, or any other non-transferable medium that can store information accessible to a computing device. As defined herein, computer-readable media does not include transient computer-readable media, such as modulated data signals and carrier waves.

[0113] It should also be noted that the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitation, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.

[0114] The various embodiments in this specification are described in a progressive manner. Similar or identical parts between embodiments can be referred to interchangeably. Each embodiment focuses on describing the differences from other embodiments. In particular, the system embodiments are basically similar to the method embodiments, so the description is relatively simple; relevant parts can be referred to the descriptions in the method embodiments.

Claims

1. A training method for a risk identification model, characterized in that, The method includes: Acquire multiple event sequences during a financial transaction process, wherein the event sequence includes event type, event occurrence time, and event subject; Risk tags are assigned to the risk event sequences among the multiple event sequences according to preset risk business rules, thereby obtaining the risk event sequences; Unlabeled event sequences are input into an autoencoder neural network to be trained to obtain a trained autoencoder neural network. A fully connected layer is added to the trained autoencoder neural network to form a first recognition model. The unlabeled event sequences are other event sequences besides the risk event sequences among the multiple event sequences. The risk event sequence is input into the first identification model for training to obtain the trained second identification model; The method further includes: The sequence of events in the training process of the first recognition model whose output results are different from the corresponding labels is taken as the abnormal event sequence set; From the set of abnormal event sequences, filter the abnormal event sequences with the highest tag frequency to obtain a subset of abnormal event sequences; Calculate the correlation degree between each pair of abnormal event sequences in the subset of abnormal event sequences, and update the corresponding label according to at least one of the correlation degrees corresponding to the abnormal event sequences. The correlation degree represents the temporal correlation and attribute similarity between the two corresponding abnormal event sequences. The updated sequence of abnormal events is input into the second recognition model, and the second recognition model is trained to obtain the updated second recognition model.

2. The method according to claim 1, characterized in that, The preset risk business rules include a first risk business rule and a second risk business rule. The risk level of the event sequence corresponding to the first risk business rule is higher than the risk level of the event sequence corresponding to the second risk business rule. The step of labeling risk event sequences among the multiple event sequences with risk tags according to the preset risk business rules to obtain risk event sequences includes: The event sequence that meets the first risk business rule will be labeled with a high-risk tag; The event sequence that meets the second risk business rule is labeled with a general risk label; The event sequences other than those labeled with the high-risk label and the ordinary-risk label are regarded as the unlabeled event sequences.

3. The method according to claim 1, characterized in that, The step of inputting an unlabeled event sequence into the autoencoder neural network to be trained for training, to obtain a trained autoencoder neural network, includes: The unlabeled event sequence is input into the autoencoder neural network to be trained. With the goal of minimizing the reconstruction error of the autoencoder neural network to be trained, the parameters of the autoencoder neural network to be trained are iteratively optimized through the backpropagation algorithm until a preset number of iterations is reached or the reconstruction error is less than a preset threshold, thus obtaining the trained autoencoder neural network.

4. The method according to claim 1, characterized in that, The method further includes: In response to a user's labeling operation on the unlabeled event sequence or a labeling update operation on the risk event sequence, an updated labeled event sequence is obtained; The updated labeled event sequence is input into the second recognition model, and the second recognition model is trained to obtain the updated second recognition model.

5. The method according to claim 1, characterized in that, The correlation degree is the product of the temporal correlation degree and the attribute similarity degree. Updating the corresponding label based on at least one correlation degree corresponding to the abnormal event sequence includes: Obtain the first probability of the risk event output by the second identification model before the update of the abnormal event sequence; The product of the degree of connection and the first probability is taken as the second probability; The updated label corresponding to the abnormal event sequence is determined based on the second probability and the preset threshold in the second identification model before the update.

6. The method according to claim 1, characterized in that, The time correlation degree is determined by the following formula: Among them, the For the time correlation degree, the The time difference between two event sequences, the The time difference between the latest and earliest event sequences in the subset of abnormal event sequences. The time difference between the later event sequence and the earliest event sequence in the two event sequences. These are the preset adjustment parameters.

7. A training device for a risk identification model, characterized in that, The device includes: The acquisition module is used to acquire multiple event sequences during a financial transaction process. The event sequence includes event type, event occurrence time, and event subject. The labeling module is used to label risk event sequences in the multiple event sequences with risk tags according to preset risk business rules, thereby obtaining risk event sequences; The first training module is used to input unlabeled event sequences into the autoencoder neural network to be trained for training, to obtain a trained autoencoder neural network, and to add a fully connected layer to the trained autoencoder neural network to form a first recognition model. The unlabeled event sequences are other event sequences besides the risk event sequences among the multiple event sequences. The second training module is used to input the risk event sequence into the first identification model for training, so as to obtain the trained second identification model. An optimized model is used to take the sequence of events in which the output of the first recognition model is different from the corresponding label during the training process as an abnormal event sequence set; From the set of abnormal event sequences, filter the abnormal event sequences with the highest tag frequency to obtain a subset of abnormal event sequences; Calculate the correlation degree between each pair of abnormal event sequences in the subset of abnormal event sequences, and update the corresponding label according to at least one of the correlation degrees corresponding to the abnormal event sequences. The correlation degree represents the temporal correlation and attribute similarity between the two corresponding abnormal event sequences. The updated sequence of abnormal events is input into the second recognition model, and the second recognition model is trained to obtain the updated second recognition model.

8. An electronic device, characterized in that, include: A memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the computer program, when executed by the processor, implements a training method for the risk identification model as described in any one of claims 1 to 6.

9. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program that, when executed by a processor, implements the training method for the risk identification model as described in any one of claims 1 to 6.

Citation Information

Patent Citations

  • Active anomaly detection method for multivariate time series and related device thereof

    CN114298240A

  • Image recognition method and device, electronic equipment and medium

    CN114511758A

  • Risk prediction model training method and device, risk prediction model using method and device, equipment and medium

    CN116957059A