Data processing methods, apparatus and equipment
By constructing target graph structure data and subgraph data, and determining risk characteristic information based on node attribute features and connection relationships, the problem of low efficiency and accuracy of risk detection in existing technologies is solved, and rapid and accurate risk detection is achieved.
Patent Information
- Application Number
- CN202411920064.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-24
- Publication Date
- 2026-01-30
- Estimated Expiration
- 2044-12-24
AI Technical Summary
In existing technologies, manually set risk detection rules suffer from low detection efficiency and accuracy when dealing with various business services, and cannot quickly and accurately detect whether there are risks in a user's use of business services.
By constructing target graph structure data, detection rules are determined based on the target node and the first node with a preset association relationship. The node attribute features and connection relationships in the subgraph data are obtained, and risk feature information is used to determine whether the target object has resource transfer risks.
It improves the efficiency and accuracy of risk detection, avoids the problems of poor efficiency and accuracy caused by manually set rules, and achieves rapid and accurate risk detection.
Smart Images

Figure CN119784389B_ABST
Abstract
Description
Technical Field
[0001] This document relates to the field of data processing technology, and in particular to a data processing method, apparatus and equipment. Background Technology
[0002] With the rapid development of the internet industry, network operators are providing users with an increasing variety and number of services. As a result, how to conduct risk detection on users' use of these services in order to better provide them with services (such as detecting the risks of users triggering resource transfer operations to protect users' privacy data from being leaked) has become a focus of attention for network operators.
[0003] When conducting risk detection on user engagement with business services, manually set risk detection rules can be used to analyze data related to user engagement to determine if any risks exist. However, with the increasing variety of business services, manually set risk detection rules suffer from low efficiency and accuracy, making it difficult to quickly and accurately detect risks in user engagement. Therefore, a solution is needed that improves the efficiency and accuracy of risk detection by enhancing the efficiency and accuracy of risk detection rule setting. Summary of the Invention
[0004] The purpose of the embodiments in this specification is to provide a solution that can improve the efficiency and accuracy of risk detection by increasing the efficiency and accuracy of determining risk detection rules.
[0005] To achieve the above technical solution, the embodiments in this specification are implemented as follows:
[0006] In a first aspect, an embodiment of this specification provides a data processing method, comprising: receiving a risk detection request for a target object; responding to the risk detection request, acquiring target graph structure data corresponding to the target object, the target graph structure data including target nodes corresponding to the target object, and edges between nodes determined based on resource transfer relationships of the target object; determining a detection rule for risk detection of the target object based on a first node in the target graph structure data that has a preset association relationship with the target node; acquiring subgraph data in the target graph structure data corresponding to the detection rule, and determining risk feature information corresponding to the detection rule based on the attribute characteristics of nodes contained in the subgraph data and the connection relationships between nodes; and determining whether the target object has resource transfer risk based on the risk feature information.
[0007] Secondly, embodiments of this specification provide a data processing apparatus, comprising: a request receiving module for receiving a risk detection request for a target object; a first acquisition module for acquiring target graph structure data corresponding to the target object in response to the risk detection request, the target graph structure data including target nodes corresponding to the target object and edges between nodes determined based on resource transfer relationships of the target object; a rule determination module for determining a detection rule for risk detection of the target object based on a first node in the target graph structure data that has a preset association relationship with the target node; a second acquisition module for acquiring subgraph data in the target graph structure data corresponding to the detection rule, and determining risk feature information corresponding to the detection rule based on the attribute characteristics of nodes contained in the subgraph data and the connection relationships between nodes; and a risk detection module for determining whether the target object has resource transfer risk based on the risk feature information.
[0008] Thirdly, embodiments of this specification provide a data processing device, the data processing device comprising: a processor; and a memory arranged to store computer-executable instructions, wherein the executable instructions, when executed, cause the processor to: receive a risk detection request for a target object; in response to the risk detection request, acquire target graph structure data corresponding to the target object, the target graph structure data including target nodes corresponding to the target object, and edges between nodes determined based on resource transfer relationships of the target object; determine a detection rule for risk detection of the target object based on a first node in the target graph structure data that has a preset association relationship with the target node; acquire subgraph data in the target graph structure data corresponding to the detection rule, and determine risk feature information corresponding to the detection rule based on the attribute characteristics of nodes contained in the subgraph data and the connection relationships between nodes; and determine whether the target object has resource transfer risk based on the risk feature information.
[0009] Fourthly, embodiments of this specification provide a storage medium for storing computer-executable instructions. When executed, the executable instructions implement the following process: receiving a risk detection request for a target object; responding to the risk detection request, acquiring target graph structure data corresponding to the target object, the target graph structure data including target nodes corresponding to the target object and edges between nodes determined based on resource transfer relationships of the target object; determining detection rules for risk detection of the target object based on a first node in the target graph structure data that has a preset association relationship with the target node; acquiring subgraph data in the target graph structure data corresponding to the detection rules, and determining risk feature information corresponding to the detection rules based on the attribute characteristics of nodes contained in the subgraph data and the connection relationships between nodes; and determining whether the target object has resource transfer risks based on the risk feature information. Attached Figure Description
[0010] To more clearly illustrate the technical solutions in the embodiments or prior art of this specification, the drawings used in the description of the embodiments or prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments recorded in this specification. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0011] Figure 1 This is a schematic diagram of a data processing system described in this specification;
[0012] Figure 2A This is a flowchart illustrating an embodiment of a data processing method described in this specification;
[0013] Figure 2B This is a schematic diagram of the processing procedure of one data processing method described in this specification;
[0014] Figure 3 This is a schematic diagram of a target graph structure data in this specification;
[0015] Figure 4 This is a schematic diagram illustrating the processing procedure of another data processing method described in this specification;
[0016] Figure 5 This is a schematic diagram of another target graph structure data in this specification;
[0017] Figure 6 This is a schematic diagram illustrating one type of field correspondence in this specification;
[0018] Figure 7 This is a schematic diagram of one type of subgraph data in this specification;
[0019] Figure 8 This is a schematic diagram of another type of sub-graph data in this specification;
[0020] Figure 9 This is a schematic diagram of another type of sub-graph data in this specification;
[0021] Figure 10 This is a schematic diagram of the structure of an embodiment of a data processing device according to this specification;
[0022] Figure 11 This is a schematic diagram of the structure of a data processing device described in this specification. Detailed Implementation
[0023] This specification provides a data processing method, apparatus, and device through its embodiments.
[0024] To enable those skilled in the art to better understand the technical solutions in this specification, the technical solutions in the embodiments of this specification will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this specification, and not all embodiments. Based on the embodiments in this specification, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of this specification.
[0025] The technical solutions in this specification can be applied to data processing systems, such as... Figure 1 As shown, the data processing system can have terminal devices and servers. The servers can be independent servers or server clusters composed of multiple servers. The terminal devices can be devices such as personal computers or mobile terminal devices such as mobile phones and tablets.
[0026] The data processing system may include n terminal devices and m servers, where n and m are positive integers greater than or equal to 1. The servers may be the backend servers of a certain application, and the terminal devices may be the client devices of the application. The application may be an application that can provide resource transfer services to users.
[0027] Users can trigger resource transfer services on their terminal devices. Upon receiving a user's trigger for a resource transfer service, the terminal device can identify the user or the resource transfer service as the target object and send a risk detection request to the server for the target object.
[0028] In response to the risk detection request, the server can obtain the target graph structure data corresponding to the target object, and determine the detection rules for risk detection of the target object based on the first node in the target graph structure data that has a preset association with the target node. Then, the server can obtain the subgraph data in the target graph structure data corresponding to the detection rules, and determine the risk feature information corresponding to the detection rules based on the attribute characteristics of the nodes contained in the subgraph data and the connection relationships between the nodes. Finally, the server can determine whether the target object has a resource transfer risk based on the risk feature information.
[0029] The server can obtain multiple data tables related to the target object and construct the target graph structure data corresponding to the target object based on the multiple data tables.
[0030] In addition, in such Figure 1 In the data processing system shown, different servers can be backend servers for different applications, that is, different servers can be used to process different businesses. For example, server 2 can be a backend server for an instant messaging application, that is, server 2 can provide users with instant messaging services and resource transfer services, etc. Server 3 can be a resource transfer account management application, that is, server 3 can provide users with resource transfer account management services (such as the creation and cancellation of resource transfer accounts) and resource transfer services, etc.
[0031] In this way, different servers can store data tables related to the target object. When a server receives a risk detection request, it can retrieve the relevant data tables from its local storage based on the target object's object identifier. The server can also send the target object's object identifier to other servers in the data processing system, enabling those servers to retrieve the relevant data tables from their local storage and return them to the server.
[0032] Furthermore, to improve business processing efficiency, the data processing system may also include a central server for determining the target graph structure data corresponding to the target object, for example, in a system like... Figure 1 In the data processing system shown, server 1 can be the central server. That is, when other servers receive a risk detection request for a target object, they can send the target object's identifier to the central server (i.e., server 1). Then, server 1 can retrieve multiple data tables related to the target object based on the identifier. These data tables can be obtained by server 1 from its local machine, other servers, and terminal devices. This avoids business interruptions caused by the server needing to generate target graph structure data, improving business processing efficiency and user satisfaction.
[0033] Based on the above data processing system architecture, the data processing methods in the following embodiments can be implemented.
[0034] Example 1
[0035] like Figure 2A and Figure 2B As shown in the embodiments of this specification, a data processing method is provided. The execution subject of this method can be a server, which can be a standalone server or a server cluster composed of multiple servers. The method specifically includes the following steps:
[0036] In S202, a risk detection request for the target object is received.
[0037] The target object can be any object that may be at risk of resource transfer, such as user object, business object, or account object. That is, the server can detect whether a user is at risk of resource transfer, whether the resource transfer business triggered by the user is at risk of resource transfer, and whether a certain account is at risk of resource transfer.
[0038] In practice, with the rapid development of the internet industry, network operators are providing users with an increasing variety and number of services. A key focus for network operators has become how to conduct risk detection on user service usage to better serve users (e.g., detecting the risk of users triggering resource transfer operations to protect user privacy). While manually set risk detection rules can be used to assess data related to user service usage to determine if risks exist, the increasing variety of services makes manually set rules (or rules derived from pre-set regulations, expert experience, or past events) inefficient and inaccurate, hindering rapid and accurate risk detection. Therefore, a solution is needed to improve the efficiency and accuracy of risk detection by enhancing the determination of risk detection rules. This specification provides a technical solution to address these issues, as detailed below.
[0039] Users can trigger the resource transfer service through a resource transfer application installed on their terminal device. That is, when the terminal device detects that a user has triggered the resource transfer service through a resource transfer application, the terminal device can identify the user as the target and send a risk detection request to the server for the target.
[0040] In addition, the terminal device can also identify the resource transfer service, the resource transfer object, and the resource transfer account used by the user as the target objects to be detected.
[0041] In S204, in response to a risk detection request, target graph structure data corresponding to the target object is obtained.
[0042] The target graph structure data can include target nodes corresponding to the target object, as well as edges between nodes determined based on the resource transfer relationships of the target object.
[0043] In implementation, the risk detection request may include the object identifier of the target object. The server can obtain historical business data corresponding to the target object based on the object identifier. The historical business data may include any business data corresponding to the target object, such as historical resource transfer data or historical instant messaging data corresponding to the target object within a preset detection period. The server can determine the target graph structure data corresponding to the target object based on the obtained historical business data.
[0044] Specifically, taking a user who triggers the execution of resource transfer business as the target object, the server can obtain the historical business data corresponding to the user within a preset detection period based on the user's user representation, and determine the target graph structure data based on the obtained historical business data.
[0045] Taking historical business data, including historical resource transfer data triggered by this user, as an example, suppose the historical resource transfer data shows that this user transferred 100 resources to user 2 at time 1, 200 resources to user 3 at time 2, and 150 resources to user 3 at time 3. Then, the server can construct the nodes contained in the target graph structure data based on this user, user 2, and user 3, and determine the edges between nodes in the target graph structure data according to the resource transfer relationships between users 1, 2, and 3.
[0046] Furthermore, the method for determining the target graph structure data described above is an optional and feasible method. In practical application scenarios, there can be a variety of different methods. Different methods can be selected according to different practical application scenarios. This specification does not specifically limit the embodiments in this regard.
[0047] In S206, based on the first node in the target graph structure data that has a preset association with the target node, a detection rule for risk detection of the target object is determined.
[0048] Among them, the preset association relationship can be a resource transfer relationship, an instant messaging relationship, an information recommendation relationship, a preset correspondence relationship, etc., and the first node can be one or more nodes that have a direct or indirect association relationship with the target node.
[0049] In implementation, taking a preset association relationship as an example, assuming the target node is the node corresponding to the user, the first node can include a first node 1 corresponding to the address and a first node 2 corresponding to the account. That is, the user has a preset correspondence with the address and the account, respectively. The server can determine the detection rules for risk detection of the target object based on the first node 1 and / or the first node 2.
[0050] When determining the detection rules, the server can determine the corresponding detection rules based on the association between the first node and other nodes. For example, taking the first node as including first node 1 corresponding to an address and first node 2 corresponding to an account, assuming that the first node also has association with other user nodes, then detection rule 1 determined for first node 1 can be to determine the number of different users corresponding to that address. Assuming that first node 2 also has association with other account nodes, then detection rule 2 determined for first node 2 can be to determine the number of different users corresponding to that account.
[0051] Furthermore, the method for determining the above-mentioned detection rules is an optional and feasible method. In actual application scenarios, there can be a variety of different methods. Different methods can be selected according to different actual application scenarios. This specification does not specifically limit this method in the embodiments.
[0052] In S208, subgraph data corresponding to the detection rule is obtained from the target graph structure data, and risk feature information corresponding to the detection rule is determined based on the attribute features of the nodes contained in the subgraph data and the connection relationship between the nodes.
[0053] In implementation, the server can extract subgraph data corresponding to the detection rules from the target graph structure data. For example, assuming the target node is the node corresponding to a user, the first node may include the first node corresponding to an address, and the detection rule may be to determine the number of risky users corresponding to that address. For example, ... Figure 3 As shown, the first node may include the first node a corresponding to address 1 and the first node b corresponding to address 2.
[0054] According to this detection rule, subgraph data corresponding to each first node can be generated based on the user nodes in the target graph structure data that have connections to each first node. That is, as follows... Figure 3As shown, we can obtain subgraph data 1 corresponding to the first node a and subgraph data 2 corresponding to the first node b.
[0055] The server can determine the risk feature information corresponding to each subgraph data based on the subgraph data and the detection rules, and then determine the risk feature information corresponding to the detection rules based on the risk feature information corresponding to each subgraph data.
[0056] When the detection rule is to determine the number of risky users corresponding to an address, the number of risky users corresponding to the first node a can be determined based on the risk label in the attribute features of the user nodes in subgraph data 1. The number of risky users corresponding to the first node b can be determined based on the number of user nodes in subgraph data 2. Based on the number 1 and the number 2, the risk feature information corresponding to the detection rule can be determined.
[0057] Furthermore, subgraph data can correspond to multiple detection rules. Based on these rules, the risk characteristic information corresponding to each subgraph data can be determined. For example, a detection rule could be to determine the number of different users corresponding to an address. Then, based on this detection rule and the number of user nodes in subgraph data 1 that are connected to the first node a, the number 3 corresponding to this detection rule can be determined. Similarly, based on the number of user nodes in subgraph data 2 that are connected to the first node b, the number 4 corresponding to this detection rule can be determined. Finally, based on the number 5 determined by number 1 and number 2, and the number 6 determined by number 3 and number 4, the risk characteristic information corresponding to the detection rule can be determined.
[0058] Among them, such as Figure 3 As shown, a calculation node carrying operators (such as average value operator, maximum value operator, minimum value operator, etc.) can be set. The risk feature information corresponding to the detection rule can be determined through the calculation node and the risk feature information corresponding to each subgraph data.
[0059] In addition, there can be multiple computing nodes carrying different operators. The risk feature information corresponding to each subgraph data can be processed according to different computing nodes. Based on the calculation results of each computing node, the risk feature information corresponding to the detection rule can be determined.
[0060] The method for determining the subgraph data and risk characteristic information mentioned above is an optional and feasible method. In actual application scenarios, there can be a variety of different methods. Different methods can be selected according to different actual application scenarios. This specification does not specifically limit this method in the embodiments.
[0061] In S210, based on risk characteristic information, it is determined whether the target object has the risk of resource transfer.
[0062] In implementation, the server can determine whether a target object poses a resource transfer risk based on historical risk data and risk characteristic information. For example, assuming the risk characteristic information is the number of risky users corresponding to the address of the object to be detected, then the number of risky users corresponding to the risky addresses can be determined based on historical risk data, and a quantity threshold can be determined based on this quantity threshold and the risk characteristic information. In this way, it can be determined whether the target object poses a resource transfer risk based on the quantity threshold and the risk characteristic information.
[0063] In addition, there are many other methods for determining resource transfer risk. For example, the server can obtain the weight corresponding to each risk feature information, and determine the risk value corresponding to the target object based on each risk feature information and the weight. Then, it can determine whether the target object has resource transfer risk based on the risk value. In addition, there are many other different methods for determination. Different methods can be selected according to different actual application scenarios. This specification does not specifically limit the embodiments in this way.
[0064] This specification provides a data processing method that receives a risk detection request for a target object, and in response to the request, acquires target graph structure data corresponding to the target object. The target graph structure data includes target nodes corresponding to the target object and edges between nodes determined based on resource transfer relationships of the target object. Based on a first node in the target graph structure data that has a preset association with the target node, a detection rule for risk detection of the target object is determined. Subgraph data corresponding to the detection rule is acquired from the target graph structure data, and risk feature information corresponding to the detection rule is determined based on the attribute characteristics of nodes contained in the subgraph data and the connection relationships between nodes. Based on the risk feature information, it is determined whether the target object has a resource transfer risk. In this way, by using the first node in the target graph structure data that has a preset association with the target node, the detection rule can be quickly and accurately determined, avoiding the problems of poor efficiency and accuracy in determining risk detection rules that exist when manually setting detection rules. Furthermore, by using the risk feature information determined by the detection rule and the subgraph data, it is possible to determine whether the target object has a resource transfer risk, thus improving the efficiency and accuracy of risk detection.
[0065] Example 2
[0066] like Figure 4 As shown in the embodiments of this specification, a data processing method is provided. The execution subject of this method can be a server, which can be a standalone server or a server cluster composed of multiple servers. The method specifically includes the following steps:
[0067] In S202, a risk detection request for the target object is received.
[0068] In S402, multiple data tables related to the target object are retrieved.
[0069] In implementation, the server can obtain a first data table containing the target object based on the object identifier of the target object. Then, the server can extract other fields contained in the first data table and obtain a second data table containing the other fields, so as to determine multiple data tables related to the target object based on the first data table and the second data table.
[0070] For example, assuming the target object is user 1, the server can obtain a first data table 1 containing the user identifier of user 1. Assume that the first data table 1 is the user table as shown in Table 1 below, and the transaction table as shown in Table 2 below.
[0071] Table 1
[0072]
[0073] Table 2
[0074]
[0075] The server can determine the second data table based on the account identifier field, transaction identifier field, and IP address field contained in the user table and transaction table. For example, the second data table determined based on the account identifier field can be the customer table shown in Table 3 below.
[0076] Table 3
[0077]
[0078] In addition, there are many other methods for determining multiple data tables related to the target object. For example, the server can obtain a first data table containing the object identifier of the target object. Then, the server can determine a third data table based on the field in the first data table that corresponds to the object identifier of the target object, and the object identifiers of other objects in the first data table that correspond to the field. Finally, the server can determine multiple data tables related to the target object based on the first data table and the third data table. In addition, there are many other different methods for determining the target object. Different methods can be selected according to different application scenarios. This specification does not specifically limit the embodiments in this way.
[0079] In S404, extract the object features from the data table, as well as the attribute features corresponding to each object feature.
[0080] In S406, nodes in the target graph structure data are constructed based on object characteristics, and attribute characteristics of nodes in the target graph structure data are determined based on attribute characteristics corresponding to object characteristics.
[0081] In S408, the relationships between object features are determined based on the relationships between multiple data tables, and the connection relationships between nodes in the target graph structure data are determined based on the relationships between object features.
[0082] In implementation, after analyzing data from multiple data tables, the server can identify primary key fields (i.e., object characteristics), attribute fields (i.e., attribute characteristics), and the relationships between data tables. Then, based on the identified primary key fields, a connected graph is constructed, the attribute fields are associated with the corresponding primary key fields, and the connection relationships between nodes in the connected graph are determined according to the relationships between data tables, so as to obtain the target graph structure data.
[0083] For example, the target graph structure data constructed based on Tables 1, 2, and 3 above can be as follows: Figure 5 As shown. Furthermore, as... Figure 6 As shown, there are various correspondences between nodes in the target graph structure data. For example, there can be a many-to-many correspondence between user identifiers and account identifiers (i.e., M user identifiers can correspond to N account identifiers), or a many-to-one correspondence between account identifiers and transaction card identifiers (i.e., N user identifiers can correspond to one transaction card identifier).
[0084] In S204, in response to a risk detection request, target graph structure data corresponding to the target object is obtained.
[0085] The target graph structure data can include target nodes corresponding to the target object, as well as edges between nodes determined based on the resource transfer relationships of the target object.
[0086] In addition, the first node may include a first child node that is connected to the target node, and a second child node that is connected to the first child node.
[0087] In S410, the attribute characteristics of the first child node and the attribute characteristics of the second child node are obtained.
[0088] In S412, a detection rule for risk detection of the target object is determined based on one or more of the first child node, the second child node, the attribute features of the first child node, and the attribute features of the second child node.
[0089] In implementation, assuming the target node is the node corresponding to user 1, the first child node is the account node corresponding to user 1, and the second child node is the node that has a transaction with the account node, the attribute characteristics of the transaction node can be determined according to the transaction table shown in Table 2 above, including the number of transactions and the transaction method.
[0090] Based on the attribute characteristics of the transaction nodes, the generated detection rules may include detection rule 1 for determining the number of transactions conducted by each transaction card corresponding to user 1 through transaction method 1, detection rule 2 for determining the number of other users corresponding to each transaction card corresponding to user 1, and detection rule 3 for determining the number of IP addresses corresponding to each transaction card corresponding to user 1, etc.
[0091] Furthermore, in practical applications, the processing method of S412 described above can vary. The following is one optional implementation method, which can be found in step one below:
[0092] Step 1: Generate a model based on pre-trained rules, and determine the detection rules for risk detection of the target object based on one or more of the first child node, the second child node, the attribute features of the first child node, and the attribute features of the second child node.
[0093] The rule generation model can be a model built based on a preset machine learning algorithm to generate detection rules.
[0094] In practice, the server can input the first child node, the second child node, the attribute features of the first child node, and the attribute features of the second child node into a pre-trained rule generation model to obtain detection rules for risk detection of the target object.
[0095] Alternatively, the server can combine the first child node, the second child node, the attribute features of the first child node, and the attribute features of the second child node to obtain multiple data combinations, and input the multiple data combinations into a pre-trained rule generation model to obtain the detection rule corresponding to each data combination.
[0096] In S414, the node information corresponding to the detection rule is obtained, and based on the node information, the subgraph data corresponding to the detection rule in the target graph structure data is determined.
[0097] In implementation, for example, suppose the detection rules include Detection Rule 1, which determines the number of transactions made by each transaction card corresponding to User 1 through different transaction methods; Detection Rule 2, which determines the number of other users corresponding to each transaction card corresponding to User 1; and Detection Rule 3, which determines the number of IP addresses corresponding to each transaction card corresponding to User 1. Then, the server can separate the node information corresponding to these three detection rules and, based on the determined node information, determine, as follows: Figure 7 The sub-graph data 1 shown corresponds to detection rule 1, such as... Figure 8 The subgraph data 2 shown corresponds to detection rule 2, and as shown in the figure Figure 9 The sub-graph data shown is corresponding to detection rule 3.
[0098] In S416, the target attribute features corresponding to the detection rule are obtained from the attribute features of each node contained in the subgraph data.
[0099] In S418, risk feature information corresponding to the detection rule is determined based on the connection relationship between nodes contained in the subgraph data and the target attribute features corresponding to each node.
[0100] In implementation, the server can determine the risk feature information corresponding to the detection rules by broadcasting messages, based on the connection relationships between nodes contained in the subgraph data and the target attribute features corresponding to each node.
[0101] For example, the server can determine the inspiration node based on the connection relationships between nodes in the subgraph data, and start sending messages from the starting node. It broadcasts the feature values of the target attributes that need to be calculated along the outgoing edges. If a node's attribute feature is a target attribute feature that satisfies the feature calculation filtering conditions (i.e., detection rules), then message aggregation processing is performed at that node. In this way, the server can perform feature calculations using operators on that node (such as aggregation operators, deduplication aggregation operators, minimum value operators, maximum value operators, etc.), and store the calculated feature values in the structure Map<feature, feature value>.
[0102] Then, the server can continue to broadcast messages iteratively along the outgoing edges of the node, sending them to the next node that is connected to the node, and completing the message aggregation at the next node. Then, it can continue to perform statistical feature calculations through the operators in the node, and the calculated feature values are stored in the structure Map<feature, feature value>.
[0103] In this way, the server can construct attribute information composed of target attribute features on the edges between nodes in the subgraph data. When broadcasting messages, it can pass messages to features that meet the feature calculation filtering conditions to complete feature calculation and obtain risk feature information.
[0104] In practical applications, the processing method of S418 described above can vary. The following is one optional implementation method, which can be found in step one below:
[0105] Step 1: Based on the connection relationships between nodes contained in the subgraph data, as well as the target attribute features and risk weights corresponding to each node, determine the risk feature information corresponding to the detection rules.
[0106] The risk weight can be determined based on the number of nodes that are connected to each node.
[0107] In practice, when a node propagates a message, it can weight the feature information propagated to that node according to the risk weight corresponding to that node, and then continue to propagate the message along the connection relationship between the nodes.
[0108] In this way, the server can convert the relationships in the relational database into the nodes and edges of a graph, and send messages starting from the starting node on the constructed graph structure data. The messages are accumulated along the message propagation path and terminated at the ending node. The accumulated messages are then processed accordingly, completing the message broadcasting process of the graph structure data and obtaining risk feature information corresponding to the detection rules.
[0109] On the one hand, based on the aforementioned distributed graph computing framework, it can not only handle large-scale graph data in the internet finance field that exceeds the capabilities of a single machine, but also complete high-dimensional and highly complex feature calculations, maintaining good scalability under different workloads and ever-increasing data volumes. On the other hand, feature calculation is performed through message broadcasting, a mode that can be reused in different business scenarios, demonstrating strong versatility.
[0110] In S420, the risk type corresponding to the target object is determined based on the risk feature information according to the pre-trained risk detection model.
[0111] The risk detection model can be a model built based on a preset tree structure algorithm to determine the risk type. The risk type can include various risk types such as high risk, medium risk, low risk, and no risk.
[0112] In S422, based on the risk type of the target object, it is determined whether the target object has a risk of resource transfer.
[0113] In practice, if the server determines that the target object has a risk of resource transfer based on the risk type of the target object, it can suspend the processing of resource transfer business related to the target object and send the resource transfer data related to the target object to the preset management party. The preset management party can then determine whether to continue processing the resource transfer business related to the target object based on the resource transfer data related to the target object and the risk type of the target object.
[0114] This specification provides a data processing method that receives a risk detection request for a target object, and in response to the request, acquires target graph structure data corresponding to the target object. The target graph structure data includes target nodes corresponding to the target object and edges between nodes determined based on resource transfer relationships of the target object. Based on a first node in the target graph structure data that has a preset association with the target node, a detection rule for risk detection of the target object is determined. Subgraph data corresponding to the detection rule is acquired from the target graph structure data, and risk feature information corresponding to the detection rule is determined based on the attribute characteristics of nodes contained in the subgraph data and the connection relationships between nodes. Based on the risk feature information, it is determined whether the target object has a resource transfer risk. In this way, by using the first node in the target graph structure data that has a preset association with the target node, the detection rule can be quickly and accurately determined, avoiding the problems of poor efficiency and accuracy in determining risk detection rules that exist when manually setting detection rules. Furthermore, by using the risk feature information determined by the detection rule and the subgraph data, it is possible to determine whether the target object has a resource transfer risk, thus improving the efficiency and accuracy of risk detection.
[0115] Example 3
[0116] The above describes the data processing method provided in the embodiments of this specification. Based on the same idea, the embodiments of this specification also provide a data processing device, such as... Figure 10 As shown.
[0117] The data processing device includes: a request receiving module 1001, a first acquisition module 1002, a rule determination module 1003, a second acquisition module 1004, and a risk detection module 1005, wherein:
[0118] The request receiving module 1001 is used to receive risk detection requests for the target object;
[0119] The first acquisition module 1002 is used to respond to the risk detection request and acquire target graph structure data corresponding to the target object. The target graph structure data includes target nodes corresponding to the target object and edges between nodes determined based on the resource transfer relationship of the target object.
[0120] The rule determination module 1003 is used to determine the detection rules for risk detection of the target object based on the first node in the target graph structure data that has a preset association relationship with the target node;
[0121] The second acquisition module 1004 is used to acquire subgraph data corresponding to the detection rule in the target graph structure data, and determine risk feature information corresponding to the detection rule based on the attribute features of the nodes contained in the subgraph data and the connection relationship between the nodes.
[0122] The risk detection module 1005 is used to determine whether the target object has a risk of resource transfer based on the risk characteristic information.
[0123] In the embodiments described in this specification, the device further includes:
[0124] The third acquisition module is used to acquire multiple data tables related to the target object;
[0125] The feature extraction module is used to extract object features from the data table, as well as attribute features corresponding to each object feature;
[0126] A node construction module is used to construct nodes in the target graph structure data based on the object features, and to determine the attribute features of the nodes in the target graph structure data based on the attribute features corresponding to the object features.
[0127] The relationship building module is used to determine the relationship between the object features based on the relationship between the multiple data tables, and to determine the connection relationship between the nodes in the target graph structure data based on the relationship between the object features.
[0128] In this embodiment of the specification, the first node includes a first child node connected to the target node and a second child node connected to the first child node. The rule determination module 1003 is used for:
[0129] Obtain the attribute characteristics of the first child node and the attribute characteristics of the second child node;
[0130] Based on one or more of the first child node, the second child node, the attribute features of the first child node, and the attribute features of the second child node, a detection rule for risk detection of the target object is determined.
[0131] In this embodiment of the specification, the rule determination module 1003 is used to: determine a detection rule for risk detection of the target object based on one or more of the first child node, the second child node, the attribute features of the first child node, and the attribute features of the second child node, according to a pre-trained rule generation model. The rule generation model is a model for generating detection rules constructed based on a preset machine learning algorithm.
[0132] In this embodiment of the specification, the second acquisition module 1004 is used for:
[0133] Obtain the node information corresponding to the detection rule, and determine the subgraph data in the target graph structure data that corresponds to the detection rule based on the node information.
[0134] In this embodiment of the specification, the second acquisition module 1004 is used for:
[0135] Obtain the target attribute features corresponding to the detection rule from the attribute features of each node contained in the subgraph data;
[0136] Based on the connection relationships between nodes contained in the subgraph data and the target attribute features corresponding to each node, risk feature information corresponding to the detection rule is determined.
[0137] In this embodiment of the specification, the second acquisition module 1004 is used for
[0138] Based on the connection relationships between nodes contained in the subgraph data, as well as the target attribute features and risk weights corresponding to each node, risk feature information corresponding to the detection rule is determined.
[0139] In this embodiment of the specification, the risk detection module 1005 is used for:
[0140] Based on the risk feature information, the risk type corresponding to the target object is determined according to the pre-trained risk detection model. The risk detection model is a model for determining risk type constructed based on a preset tree structure algorithm.
[0141] Based on the risk type of the target object, determine whether the target object is at risk of resource transfer.
[0142] This specification provides a data processing apparatus that receives a risk detection request for a target object, and in response to the request, acquires target graph structure data corresponding to the target object. The target graph structure data includes target nodes corresponding to the target object and edges between nodes determined based on resource transfer relationships of the target object. Based on a first node in the target graph structure data that has a preset association with the target node, a detection rule for risk detection of the target object is determined. Subgraph data corresponding to the detection rule is acquired from the target graph structure data, and risk feature information corresponding to the detection rule is determined based on the attribute characteristics of nodes contained in the subgraph data and the connection relationships between nodes. Based on the risk feature information, it is determined whether the target object has a resource transfer risk. In this way, by using the first node in the target graph structure data that has a preset association with the target node, the detection rule can be quickly and accurately determined, avoiding the problems of poor efficiency and accuracy in determining risk detection rules that exist when manually setting detection rules. Furthermore, by using the risk feature information determined by the detection rule and the subgraph data, it is possible to determine whether the target object has a resource transfer risk, thus improving the efficiency and accuracy of risk detection.
[0143] Example 4
[0144] Following the same line of thought, embodiments of this specification also provide a data processing device, such as... Figure 11 As shown.
[0145] Data processing devices can vary considerably depending on configuration or performance, and may include one or more processors 1101 and memory 1102. Memory 1102 may store one or more application programs or data. Memory 1102 may be temporary or persistent storage. The application programs stored in memory 1102 may include one or more modules (not shown), each module including a series of computer-executable instructions for the data processing device. Furthermore, processor 1101 may be configured to communicate with memory 1102 and execute the series of computer-executable instructions in memory 1102 on the data processing device. The data processing device may also include one or more power supplies 1103, one or more wired or wireless network interfaces 1104, one or more input / output interfaces 1105, and one or more keyboards 1106.
[0146] Specifically, in this embodiment, the data processing device includes a memory and one or more programs, wherein one or more programs are stored in the memory, and one or more programs may include one or more modules, and each module may include a series of computer-executable instructions for the data processing device, and is configured to be executed by one or more processors. The one or more programs include computer-executable instructions for performing the following:
[0147] Receive risk detection requests for the target object;
[0148] In response to the risk detection request, target graph structure data corresponding to the target object is obtained. The target graph structure data includes target nodes corresponding to the target object and edges between nodes determined based on the resource transfer relationship of the target object.
[0149] Based on the first node in the target graph structure data that has a preset association with the target node, a detection rule for risk detection of the target object is determined;
[0150] Obtain subgraph data corresponding to the detection rule from the target graph structure data, and determine the risk feature information corresponding to the detection rule based on the attribute features of the nodes contained in the subgraph data and the connection relationship between the nodes;
[0151] Based on the risk characteristics information, it is determined whether the target object is at risk of resource transfer.
[0152] The various embodiments in this specification are described in a progressive manner. Similar or identical parts between embodiments can be referred to mutually. Each embodiment focuses on describing the differences from other embodiments. In particular, the data processing device embodiments are basically similar to the method embodiments, so the description is relatively simple; relevant parts can be referred to the descriptions of the method embodiments.
[0153] This specification provides a data processing device that receives a risk detection request for a target object, and in response to the request, acquires target graph structure data corresponding to the target object. The target graph structure data includes target nodes corresponding to the target object and edges between nodes determined based on resource transfer relationships of the target object. Based on a first node in the target graph structure data that has a preset association with the target node, a detection rule for risk detection of the target object is determined. Subgraph data corresponding to the detection rule is acquired from the target graph structure data, and risk feature information corresponding to the detection rule is determined based on the attribute characteristics of nodes contained in the subgraph data and the connection relationships between nodes. Based on the risk feature information, it is determined whether the target object has a resource transfer risk. In this way, by using the first node in the target graph structure data that has a preset association with the target node, the detection rule can be quickly and accurately determined, avoiding the problems of poor efficiency and accuracy in determining risk detection rules that exist when manually setting detection rules. Furthermore, by using the risk feature information determined by the detection rule and the subgraph data, it is possible to determine whether the target object has a resource transfer risk, thus improving the efficiency and accuracy of risk detection.
[0154] Example 5
[0155] This specification also provides a computer-readable storage medium storing a computer program. When executed by a processor, this computer program implements the various processes of the above-described data processing method embodiments and achieves the same technical effects. To avoid repetition, it will not be described again here. The computer-readable storage medium may include, for example, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk.
[0156] This specification provides a computer-readable storage medium that, upon receiving a risk detection request for a target object, acquires target graph structure data corresponding to the target object in response to the request. The target graph structure data includes target nodes corresponding to the target object and edges between nodes determined based on resource transfer relationships of the target object. Based on a first node in the target graph structure data that has a preset association with the target node, a detection rule for risk detection of the target object is determined. Subgraph data corresponding to the detection rule is acquired in the target graph structure data. Based on the attribute characteristics of nodes contained in the subgraph data and the connection relationships between nodes, risk feature information corresponding to the detection rule is determined. Based on the risk feature information, it is determined whether the target object has a resource transfer risk. In this way, by using the first node in the target graph structure data that has a preset association with the target node, the detection rule can be quickly and accurately determined, avoiding the problems of poor efficiency and accuracy in determining risk detection rules that exist when manually setting detection rules. Furthermore, by using the risk feature information determined by the detection rule and the subgraph data, it is possible to determine whether the target object has a resource transfer risk, thus improving the efficiency and accuracy of risk detection.
[0157] The foregoing has described specific embodiments of this specification. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims may be performed in a different order than that shown in the embodiments and may still achieve the desired result. Furthermore, the processes depicted in the drawings do not necessarily require the specific or sequential order shown to achieve the desired result. In some embodiments, multitasking and parallel processing are possible or may be advantageous.
[0158] In the 1990s, improvements to a technology could be clearly distinguished as either hardware improvements (e.g., improvements to the circuit structure of diodes, transistors, switches, etc.) or software improvements (improvements to the methodology). However, with technological advancements, many methodological improvements today can be considered direct improvements to the hardware circuit structure. Designers almost always obtain the corresponding hardware circuit structure by programming the improved methodology into the hardware circuit. Therefore, it cannot be said that a methodological improvement cannot be implemented using hardware physical modules. For example, a Programmable Logic Device (PLD) (such as a Field Programmable Gate Array (FPGA)) is such an integrated circuit whose logic function is determined by the user programming the device. Designers can program and "integrate" a digital system onto a PLD themselves, without needing chip manufacturers to design and manufacture dedicated integrated circuit chips. Furthermore, nowadays, instead of manually manufacturing integrated circuit chips, this programming is mostly implemented using "logic compiler" software. Similar to the software compiler used in program development, the original code before compilation must also be written in a specific programming language, called a Hardware Description Language (HDL). There are many HDLs, such as ABEL (Advanced Boolean Expression Language), AHDL (Altera Hardware Description Language), Confluence, CUPL (Cornell University Programming Language), HDCal, JHDL (Java Hardware Description Language), Lava, Lola, MyHDL, PALASM, and RHDL (Ruby Hardware Description Language). Currently, the most commonly used are VHDL (Very-High-Speed Integrated Circuit Hardware Description Language) and Verilog. Those skilled in the art should also understand that by simply performing some logic programming on the method flow using one of these hardware description languages and programming it into an integrated circuit, the hardware circuit implementing the logical method flow can be easily obtained.
[0159] The controller can be implemented in any suitable manner. For example, it can take the form of a microprocessor or processor and a computer-readable medium storing computer-readable program code (e.g., software or firmware) executable by the (micro)processor, logic gates, switches, application-specific integrated circuits (ASICs), programmable logic controllers, and embedded microcontrollers. Examples of controllers include, but are not limited to, the following microcontrollers: ARC 625D, Atmel AT91SAM, Microchip PIC18F26K20, and Silicon Labs C8051F320. A memory controller can also be implemented as part of the control logic of the memory. Those skilled in the art will also recognize that, in addition to implementing the controller in purely computer-readable program code form, the same functionality can be achieved by logically programming the method steps to make the controller take the form of logic gates, switches, application-specific integrated circuits, programmable logic controllers, and embedded microcontrollers. Therefore, such a controller can be considered a hardware component, and the means included therein for implementing various functions can also be considered as structures within the hardware component. Alternatively, the means for implementing various functions can be considered as both software modules implementing the method and structures within the hardware component.
[0160] The systems, devices, modules, or units described in the above embodiments can be implemented by computer chips or entities, or by products with certain functions. A typical implementation device is a computer. Specifically, a computer can be, for example, a personal computer, laptop computer, cellular phone, camera phone, smartphone, personal digital assistant, media player, navigation device, email device, game console, tablet computer, wearable device, or any combination of these devices.
[0161] For ease of description, the above apparatus is described by dividing it into various functional units. Of course, when implementing one or more embodiments of this specification, the functions of each unit can be implemented in one or more software and / or hardware.
[0162] Those skilled in the art will understand that the embodiments of this specification can be provided as methods, systems, or computer program products. Therefore, one or more embodiments of this specification may take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, one or more embodiments of this specification may take the form of a computer program product implemented on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0163] The embodiments described herein are illustrated with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this specification. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart illustrations. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.
[0164] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.
[0165] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.
[0166] In a typical configuration, a computing device includes one or more processors (CPU), input / output interfaces, network interfaces, and memory.
[0167] Memory may include non-persistent storage in computer-readable media, such as random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM. Memory is an example of computer-readable media.
[0168] Computer-readable media includes both permanent and non-permanent, removable and non-removable media that can store information by any method or technology. Information can be computer-readable instructions, data structures, modules of programs, or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, CD-ROM, digital versatile optical disc (DVD) or other optical storage, magnetic tape, magnetic disk storage or other magnetic storage devices, or any other non-transferable medium that can be used to store information accessible by a computing device. As defined herein, computer-readable media does not include transient computer-readable media, such as modulated data signals and carrier waves.
[0169] It should also be noted that the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitation, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.
[0170] Those skilled in the art will understand that the embodiments of this specification can be provided as methods, systems, or computer program products. Therefore, one or more embodiments of this specification may take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, one or more embodiments of this specification may take the form of a computer program product implemented on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0171] One or more embodiments of this specification can be described in the general context of computer-executable instructions, such as program modules, that are executed by a computer. Generally, program modules include routines, programs, objects, components, data structures, etc., that perform a particular task or implement a particular abstract data type. One or more embodiments of this specification can also be practiced in distributed computing environments where tasks are performed by remote processing devices connected via a communication network. In distributed computing environments, program modules can reside in local and remote computer storage media, including storage devices.
[0172] The various embodiments in this specification are described in a progressive manner. Similar or identical parts between embodiments can be referred to interchangeably. Each embodiment focuses on describing the differences from other embodiments. In particular, the system embodiments are basically similar to the method embodiments, so the description is relatively simple; relevant parts can be referred to the descriptions in the method embodiments.
[0173] The above description is merely an embodiment of this specification and is not intended to limit this specification. Various modifications and variations can be made to this specification by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this specification should be included within the scope of the claims of this specification.
Claims
1. A data processing method, comprising: receiving a risk detection request for a target object; in response to the risk detection request, obtaining target graph structure data corresponding to the target object, the target graph structure data containing a target node corresponding to the target object and edges between nodes determined based on resource transfer relationships of the target object; based on a first node in the target graph structure data having a preset association relationship with the target node, determining a detection rule for risk detection of the target object; obtaining subgraph data in the target graph structure data corresponding to the detection rule, and determining risk feature information corresponding to the detection rule based on attribute features of nodes contained in the subgraph data and connection relationships between the nodes; based on the risk feature information, determining whether the target object has a resource transfer risk; before the obtaining of the target graph structure data corresponding to the target object, further comprising: obtaining a plurality of data tables related to the target object; extracting object features in the data tables and attribute features corresponding to each of the object features; constructing nodes in the target graph structure data according to the object features, and determining attribute features of the nodes in the target graph structure data according to the attribute features corresponding to the object features; determining association relationships between the object features according to association relationships between the plurality of data tables, and determining connection relationships between the nodes in the target graph structure data according to the association relationships between the object features.
2. The method of claim 1, the first node comprising a first sub-node having a connection relationship with the target node, and a second sub-node having a connection relationship with the first sub-node, the determining of the detection rule for risk detection of the target object based on the first node in the target graph structure data having a preset association relationship with the target node comprising: obtaining attribute features of the first sub-node and attribute features of the second sub-node; determining the detection rule for risk detection of the target object based on one or more of the first sub-node, the second sub-node, the attribute features of the first sub-node, and the attribute features of the second sub-node.
3. The method of claim 2, wherein determining the detection rule for risk detection of the target object based on the first node having a preset correlation relationship with the target node in the target graph structure data comprises: determining the detection rule for risk detection of the target object based on one or more of the first sub-node, the second sub-node, the attribute features of the first sub-node, and the attribute features of the second sub-node according to a pre-trained rule generation model, the rule generation model being a model for generating a detection rule constructed based on a preset machine learning algorithm.
4. The method of claim 2, the obtaining of the subgraph data in the target graph structure data corresponding to the detection rule comprising: obtaining node information corresponding to the detection rule, and determining the subgraph data in the target graph structure data corresponding to the detection rule according to the node information.
5. The method of claim 4, wherein determining the risk feature information corresponding to the detection rule based on the attribute features of the nodes and the connection relationships between the nodes included in the subgraph data comprises: obtaining a target attribute feature corresponding to the detection rule from the attribute features of each node included in the subgraph data; and determining the risk feature information corresponding to the detection rule based on the connection relationships between the nodes and the target attribute features of each node included in the subgraph data.
6. The method of claim 5, wherein determining the risk feature information corresponding to the detection rule based on the connection relationships between the nodes and the target attribute features of each node included in the subgraph data comprises: determining the risk feature information corresponding to the detection rule based on the connection relationships between the nodes, the target attribute features of each node, and risk weights.
7. The method of claim 6, wherein determining whether the target object has a resource transfer risk based on the risk feature information comprises: determining a risk type corresponding to the target object based on the risk feature information according to a pre-trained risk detection model, the risk detection model being a model for determining a risk type constructed based on a preset tree structure algorithm; and determining whether the target object has a resource transfer risk according to the risk type of the target object.
8. A data processing apparatus, comprising: a request receiving module configured to receive a risk detection request for a target object; a first obtaining module configured to obtain target graph structure data corresponding to the target object in response to the risk detection request, the target graph structure data including a target node corresponding to the target object and edges between nodes determined based on a resource transfer relationship of the target object; a rule determining module configured to determine a detection rule for risk detection of the target object based on a first node having a preset association relationship with the target node in the target graph structure data; a second obtaining module configured to obtain subgraph data corresponding to the detection rule from the target graph structure data, and determine risk feature information corresponding to the detection rule based on attribute features of nodes and connection relationships between the nodes included in the subgraph data; and a risk detection module configured to determine whether the target object has a resource transfer risk based on the risk feature information. The apparatus further comprises: a third obtaining module configured to obtain a plurality of data tables related to the target object; a feature extraction module configured to extract object features and attribute features corresponding to each of the object features from the data tables; a node construction module configured to construct nodes in the target graph structure data according to the object features, and determine attribute features of the nodes in the target graph structure data according to the attribute features corresponding to the object features. The relationship construction module is configured to determine the association relationship between the object features according to the association relationship between the plurality of data tables, and determine the connection relationship between the nodes in the target graph structure data according to the association relationship between the object features.
9. A data processing device, the data processing device comprising: a processor; and a memory arranged to store computer executable instructions that, when executed, cause the processor to: receive a risk detection request for a target object; in response to the risk detection request, obtain target graph structure data corresponding to the target object, the target graph structure data including a target node corresponding to the target object and edges between nodes determined based on a resource transfer relationship of the target object; determine a detection rule for risk detection of the target object based on a first node in the target graph structure data that has a preset association relationship with the target node; obtain subgraph data corresponding to the detection rule in the target graph structure data, and determine risk feature information corresponding to the detection rule based on attribute features of nodes included in the subgraph data and connection relationships between the nodes; determine whether the target object has a resource transfer risk based on the risk feature information; before the obtaining of the target graph structure data corresponding to the target object, the method further comprises: obtaining a plurality of data tables related to the target object; extracting object features in the data tables and attribute features corresponding to each of the object features; constructing nodes in the target graph structure data according to the object features, and determining attribute features of the nodes in the target graph structure data according to the attribute features corresponding to the object features; determining the association relationship between the object features according to the association relationship between the plurality of data tables, and determining the connection relationship between the nodes in the target graph structure data according to the association relationship between the object features.
Citation Information
Patent Citations
Risk value evaluation method and device
CN111402064A
Entity group identification method and device, equipment and medium
CN116432129A