Enterprise abnormal behavior monitoring method, device and computer equipment
Through the need analysis, pattern recognition and fusion analysis of enterprise abnormal behavior monitoring data, combined with cross-modal comparison learning, the problem of insufficient monitoring accuracy in the existing technology is solved, and accurate identification and risk warning of enterprise abnormal behavior is achieved.
Patent Information
- Application Number
- CN202510397443.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-01
- Publication Date
- 2025-08-26
- Estimated Expiration
- 2045-04-01
AI Technical Summary
The accuracy of enterprise abnormal behavior monitoring in the prior art needs to be improved, and it is difficult to achieve accurate identification and early warning.
By obtaining the deployment and early warning problem data, performing requirements analysis and task disassembly, combining multiple agents for pattern recognition and behavioral pattern fusion analysis, using cross-modal comparison learning to monitor abnormality in spatio-temporal semantics, and generating graphic and text decision guidance data.
It has achieved more accurate monitoring of abnormal behaviors of enterprises, provided more comprehensive graphic and text decision-making guidance, and supported regulatory departments to timely identify and respond to potential risks.
Smart Images

Figure CN119919157B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of artificial intelligence technology, and in particular to a method, apparatus, and computer equipment for monitoring abnormal behavior in an enterprise. Background Art
[0002] By monitoring abnormal corporate behavior, potential risks can be identified promptly, helping regulatory authorities make prompt decisions and take effective measures to avoid significant economic losses and social impacts. However, the accuracy of abnormal corporate behavior monitoring in related technologies still needs to be improved.
[0003] Therefore, it is urgent to propose a new method for monitoring abnormal enterprise behavior. Summary of the Invention
[0004] The present application provides a method, apparatus and computer equipment for monitoring abnormal behavior of an enterprise, which solves the technical problem in the related art that the accuracy of monitoring abnormal behavior of an enterprise needs to be improved, and achieves the technical effect of more accurately monitoring abnormal behavior of an enterprise.
[0005] In order to achieve the above objectives, the main technical solutions adopted in this application include:
[0006] In a first aspect, an embodiment of the present application provides a method for monitoring abnormal behavior of an enterprise, which is applied to an enterprise monitoring platform; the method comprises:
[0007] Obtaining control and early warning problem data for the target enterprise, performing demand analysis and task decomposition on the control and early warning problem data, and obtaining multiple subtasks to be processed;
[0008] Performing pattern recognition based on any pending subtask to obtain a behavior pattern analysis result of the target enterprise under any pending subtask; wherein the target enterprise has multiple behavior pattern analysis results; the behavior pattern analysis results include a public opinion tendency assessment result, which is obtained by analyzing public opinion-related information of the target enterprise and constructing a multidimensional assessment matrix including a dissemination heat and a time decay factor;
[0009] Performing a behavioral pattern fusion analysis on the multiple behavioral pattern analysis results of the target enterprise and the control and early warning problem data to obtain graphic and text decision guidance data corresponding to the control and early warning problem data;
[0010] In response to the confirmation operation of the graphic decision guidance data, the time series features of the historical risk behavior data of the target enterprise and the visual semantic features of the graphic decision guidance data are mapped to the same representation space, and cross-modal contrastive learning is used to perform spatiotemporal semantic joint anomaly monitoring to obtain the abnormal behavior category of the target enterprise; wherein, the abnormal behavior category is used to describe the abnormal behavior type of the target enterprise identified during the monitoring process.
[0011] Optionally, obtaining the control and early warning problem data for the target enterprise includes any one of the following methods:
[0012] In response to the text input operation, determining the control and early warning problem data;
[0013] Acquire voice description data for the target enterprise, parse the voice description data, and obtain the control and early warning problem data.
[0014] Optionally, an enterprise anomaly monitoring model is deployed on the enterprise monitoring platform, and the enterprise anomaly monitoring model includes a problem analysis agent; the demand analysis and task decomposition of the control and warning problem data are performed to obtain multiple subtasks to be processed, including:
[0015] The problem analysis agent performs intention decomposition and step disassembly on the control and warning problem data to obtain the multiple subtasks to be processed.
[0016] Optionally, an enterprise anomaly monitoring model is deployed on the enterprise monitoring platform, and the enterprise anomaly monitoring model includes multiple candidate agents. Before performing pattern recognition based on any subtask to be processed, the method further includes:
[0017] Selecting a target agent that matches any subtask to be processed from the plurality of candidate agents, and accordingly assigning the any subtask to be processed to the target agent;
[0018] Accordingly, the pattern recognition based on any pending subtask to obtain the behavior pattern analysis result of the target enterprise under any pending subtask includes:
[0019] The target intelligent agent obtains the enterprise-related data corresponding to any of the subtasks to be processed, and performs feature extraction and similarity calculation on the enterprise-related data to obtain the behavior pattern analysis result.
[0020] Optionally, the target agent includes a public opinion analysis agent and a recruitment analysis agent, and the multiple subtasks to be processed include a public opinion analysis task and a recruitment analysis task; the step of obtaining enterprise-related data corresponding to any of the subtasks to be processed through the target agent, and performing feature extraction and similarity calculation on the enterprise-related data to obtain the behavior pattern analysis result includes:
[0021] Obtaining public opinion-related information of the target enterprise through the public opinion analysis agent, performing feature extraction and similarity calculation on the public opinion-related information, and obtaining a public opinion tendency evaluation result of the target enterprise;
[0022] The recruitment analysis agent obtains the recruitment-related information of the target enterprise, performs feature extraction and similarity calculation on the recruitment-related information, and obtains the recruitment behavior evaluation result of the target enterprise; wherein the behavior pattern analysis result includes the public opinion tendency evaluation result and the recruitment behavior evaluation result.
[0023] Optionally, the recruitment analysis agent includes a recruitment posting analysis agent and a visitor record analysis agent. The recruitment analysis agent obtains recruitment-related information of the target enterprise, performs feature extraction and similarity calculation on the recruitment-related information, and obtains recruitment behavior evaluation results of the target enterprise, including:
[0024] Obtaining the target company's recruitment posting information through the recruitment posting analysis agent, performing text mining and cluster analysis on the recruitment posting information, and obtaining a recruitment posting evaluation result;
[0025] The personnel flow image data of the target enterprise is obtained through the visitor record analysis agent, and visitor object recognition and activity trajectory recognition are performed on the personnel flow image data to obtain the interview-related evaluation results of the target enterprise; wherein, the recruitment behavior evaluation results include the recruitment posting evaluation results and the interview-related evaluation results.
[0026] Optionally, an enterprise anomaly monitoring model is deployed on the enterprise monitoring platform, and the enterprise anomaly monitoring model includes a risk fusion agent. The behavior pattern fusion analysis is performed on multiple behavior pattern analysis results of the target enterprise and the control and early warning problem data to obtain graphic and text decision guidance data corresponding to the control and early warning problem data, including:
[0027] The risk fusion intelligent agent performs risk fusion assessment and visualization processing on multiple behavior pattern analysis results of the target enterprise and the control and early warning problem data to obtain the graphic decision guidance data.
[0028] In a second aspect, an embodiment of the present application provides an enterprise abnormal behavior monitoring device, which is applied to an enterprise monitoring platform and includes:
[0029] A data acquisition module is used to obtain the control and early warning problem data for the target enterprise, perform demand analysis and task decomposition on the control and early warning problem data, and obtain multiple subtasks to be processed;
[0030] A pattern recognition module is configured to perform pattern recognition based on any pending subtask to obtain a behavior pattern analysis result of the target enterprise under any pending subtask; wherein the target enterprise has multiple behavior pattern analysis results; the behavior pattern analysis results include a public opinion tendency assessment result, which is obtained by analyzing public opinion-related information of the target enterprise and constructing a multidimensional assessment matrix including a dissemination heat and a time decay factor;
[0031] A fusion analysis module is used to perform a fusion analysis of the multiple behavior pattern analysis results of the target enterprise and the control and early warning problem data to obtain graphic and text decision guidance data corresponding to the control and early warning problem data;
[0032] An anomaly monitoring module is used to respond to the confirmation operation of the graphic decision-making guidance data, map the time series features of the historical risk behavior data of the target enterprise and the visual semantic features of the graphic decision-making guidance data to the same representation space, and use cross-modal contrastive learning to perform spatiotemporal semantic joint anomaly monitoring to obtain the abnormal behavior category of the target enterprise; wherein the abnormal behavior category is used to describe the abnormal behavior type of the target enterprise identified during the monitoring process
[0033] In a third aspect, an embodiment of the present application provides a computer device, including:
[0034] A memory and a processor, wherein the memory and the processor are communicatively connected to each other, the memory stores computer instructions, and the processor executes the method described in any of the above embodiments by executing the computer instructions.
[0035] In an embodiment of the present application, first, the control and early warning problem data for the target enterprise is obtained, and the control and early warning problem data is subjected to demand analysis and task decomposition to obtain a plurality of subtasks to be processed; then, pattern recognition is performed based on any subtask to be processed to obtain the behavior pattern analysis result of the target enterprise under any subtask to be processed; then, a behavior pattern fusion analysis is performed on the multiple behavior pattern analysis results of the target enterprise and the control and early warning problem data to obtain the graphic decision guidance data corresponding to the control and early warning problem data; finally, in response to the confirmation operation of the graphic decision guidance data, the time series features of the historical risk behavior data of the target enterprise and the visual semantic features of the graphic decision guidance data are mapped to the same representation space, and a spatiotemporal semantic joint anomaly monitoring is performed in a cross-modal comparative learning manner to obtain the abnormal behavior category of the target enterprise. By fusing and analyzing the behavior patterns of multiple behavior pattern analysis results and the control and early warning problem data, more accurate graphic decision guidance data can be obtained, and further, based on the time series features of the historical risk behavior data and the visual semantic features of the graphic decision guidance data, a spatiotemporal semantic joint anomaly monitoring is performed in a cross-modal comparative learning manner to obtain a more accurate abnormal behavior category of the target enterprise. BRIEF DESCRIPTION OF THE DRAWINGS
[0036] In order to more clearly illustrate the specific implementation methods of the present application or the technical solutions in the prior art, the following is a brief introduction to the drawings required for use in the specific implementation methods or the description of the prior art. Obviously, the drawings described below are some implementation methods of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.
[0037] Figure 1a A flowchart of a method for monitoring abnormal enterprise behavior provided in an embodiment of this specification;
[0038] Figure 1b A flowchart of a method for monitoring abnormal enterprise behavior provided in an embodiment of this specification;
[0039] Figure 2 A flowchart of a method for monitoring abnormal enterprise behavior provided in an embodiment of this specification;
[0040] Figure 3 A flowchart of a method for monitoring abnormal enterprise behavior provided in an embodiment of this specification;
[0041] Figure 4a A schematic diagram of the target enterprise risk probability provided in the embodiments of this specification;
[0042] Figure 4b A schematic diagram of the frequency of recruitment for risky positions in target enterprises provided in the embodiments of this specification;
[0043] Figure 4c This is a schematic diagram of the target enterprise risk position interview analysis provided in the embodiment of this specification;
[0044] Figure 4d This is a schematic diagram of the negative public opinion analysis of the target enterprise provided in the embodiment of this specification;
[0045] Figure 5 This is an architectural diagram of the enterprise anomaly monitoring model provided in the embodiments of this specification;
[0046] Figure 6 A flowchart of a method for monitoring abnormal enterprise behavior provided in an embodiment of this specification;
[0047] Figure 7 A schematic diagram of a device for monitoring abnormal behavior of an enterprise provided in an embodiment of this specification;
[0048] Figure 8 A schematic diagram of a computer structure provided in an embodiment of this specification. DETAILED DESCRIPTION
[0049] To make the purpose, technical solutions, and advantages of the embodiments of the present application more clear, the technical solutions in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without making creative efforts shall fall within the scope of protection of this application.
[0050] By monitoring corporate behavior, potential anomalies can be identified promptly. This process not only helps regulatory authorities accurately identify potential violations by companies, but also provides data support and decision-making basis for developing response strategies, thereby avoiding significant economic losses and negative social impacts. However, there is still significant room for improvement in the accuracy of relevant technologies in monitoring abnormal corporate behavior.
[0051] Based on this, the present application provides a method for monitoring abnormal behavior of an enterprise. First, the control and warning problem data for the target enterprise is obtained, and the control and warning problem data is analyzed and task-decomposed to obtain multiple subtasks to be processed; then, pattern recognition is performed based on any subtask to be processed to obtain the behavior pattern analysis results of the target enterprise under any subtask to be processed; then, the multiple behavior pattern analysis results of the target enterprise and the control and warning problem data are analyzed by behavioral pattern fusion to obtain the graphic decision guidance data corresponding to the control and warning problem data; finally, in response to the confirmation operation of the graphic decision guidance data, the historical risk behavior data of the target enterprise and the graphic decision guidance data are used to perform joint abnormal monitoring to obtain the abnormal behavior category of the target enterprise. Based on the demand analysis of the control and warning problem data, the control and warning problem data can be understood more accurately and task-decomposed. Based on the pattern recognition of multiple subtasks, the behavior pattern analysis results of the target enterprise under a specific subtask can be revealed more accurately and quickly. Based on the behavior pattern fusion analysis of the multiple behavior pattern analysis results of the target enterprise and the control and warning problem data, data from different sources can be deeply integrated and analyzed, thereby obtaining more accurate and comprehensive graphic decision guidance data. By conducting joint anomaly monitoring based on historical risk behavior data and graphic decision-making guidance data, we can obtain more accurate abnormal behavior categories of target enterprises.
[0052] It should be noted that this enterprise abnormal behavior monitoring method can be applied to an enterprise monitoring platform; an enterprise abnormality monitoring model is deployed on the enterprise monitoring platform, and the enterprise abnormality monitoring model includes a problem analysis agent, a public opinion analysis agent, a recruitment analysis agent, and a risk fusion agent. Control and warning problem data for a target enterprise is obtained; the problem analysis agent performs demand analysis and task decomposition on the control and warning problem data, resulting in multiple pending subtasks, including public opinion analysis tasks and recruitment analysis tasks; the public opinion analysis agent analyzes the target enterprise's public opinion-related information, constructs a multidimensional evaluation matrix containing dissemination heat and time decay factors, and obtains a public opinion tendency assessment result for the target enterprise; the recruitment analysis agent evaluates the recruitment-related information of the target enterprise's recruitment, and obtains a recruitment behavior assessment result for the target enterprise; the risk fusion agent performs risk fusion assessment and visualization processing on the public opinion tendency assessment results, recruitment behavior assessment results, and control and warning problem data, and obtains graphic decision-making guidance data; and in response to a confirmation operation on the graphic decision-making guidance data, the target enterprise's historical risk behavior data and the graphic decision-making guidance data are used to perform joint anomaly monitoring, and the target enterprise's abnormal behavior category is obtained.
[0053] According to an embodiment of the present application, an embodiment of a method for monitoring abnormal behavior of an enterprise is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer executable instructions, and although a logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in an order different from that shown here.
[0054] See also Figure 1a In this embodiment, a method for monitoring abnormal behavior of an enterprise is provided, which is applied to an enterprise monitoring platform. The method includes:
[0055] S101. Obtaining control and early warning problem data for a target enterprise, performing demand analysis and task decomposition on the control and early warning problem data, and obtaining a plurality of subtasks to be processed.
[0056] Target enterprises can be those that regulatory authorities need to monitor for unusual behavior. Monitoring and early warning problem data can be issues related to the business practices of the target enterprise, entered by regulators on the enterprise monitoring platform. Demand analysis can involve an intelligent agent deeply understanding and identifying the semantics of monitoring and early warning problem data. Task decomposition can be further broken down into specific subtasks based on the semantics derived from demand analysis. These subtasks identify specific business practices of the target enterprise.
[0057] In some implementations, supervisors can submit control and early warning problem data on the enterprise monitoring platform. The intelligent agent then performs semantic understanding of the data and decomposes the semantics into multiple subtasks to be processed. For example, if the user previously entered several historical control and early warning problem data before entering the control and early warning problem data, the intelligent agent can use this historical data to understand the semantics of the control and early warning problem data and decompose the tasks.
[0058] S103: Perform pattern recognition based on any pending subtask to obtain a behavior pattern analysis result of the target enterprise under any pending subtask.
[0059] The target enterprise has multiple behavioral pattern analysis results. These include a public opinion trend assessment, which is derived by analyzing the target enterprise's public opinion-related information and constructing a multidimensional assessment matrix that includes communication heat and a time decay factor. Communication heat can be measured through a combination of data such as the number of reads, forwards, likes, and comments on the public opinion. The time decay factor can be obtained by fitting a time decay factor model using historical communication heat data.
[0060] In some implementations, the enterprise monitoring platform can access target enterprise-related data, such as monitoring data, visitor logs, online public opinion, and online recruitment information. Each pending subtask has a corresponding subtask processing agent. The subtask processing agent performs pattern recognition on the enterprise-related data to obtain a behavioral pattern analysis result for the target enterprise under any pending subtask. This analysis may include behavioral characteristics of the target enterprise, abnormal behavior, or both. For example, the behavioral pattern analysis result of the target enterprise based on online recruitment information may indicate a large number of financial personnel recruitments or abnormal recruitment.
[0061] In some embodiments, the behavior pattern analysis results include public opinion tendency evaluation results, which are obtained by analyzing the public opinion-related information of the target enterprise and constructing a multi-dimensional evaluation matrix including the propagation heat and the time decay factor. Specifically, a web crawler can be used to crawl the public opinion data on the target enterprise on the Internet, including news websites, social media platforms (such as Weibo, WeChat), forums, etc., and then analyze the crawled public opinion data. Exemplarily, a web crawler is first used to crawl the financial public opinion data on the target enterprise on the Internet, including both positive and negative public opinions. For each type of public opinion (positive, negative), multiple days of historical data from its appearance can be obtained. Then, a time decay factor model is fitted through historical data. Exemplarily, for the time decay factor model , through parameter fitting, the lambda value is 3, and the time decay factor of positive public opinion is obtained as Finally, a multi-dimensional evaluation matrix is constructed. For example, the multi-dimensional evaluation matrix of a certain enterprise is as follows:
[0062]
[0063] Here, a1 is the first-day spread of positive forum public opinion, w11(t) is the time decay factor for positive forum public opinion, a2 is the first-day spread of negative forum public opinion, and w12(t) is the time decay factor for negative forum public opinion; b1 is the first-day spread of positive Weibo public opinion, w21(t) is the time decay factor for positive Weibo public opinion, b2 is the first-day spread of negative Weibo public opinion, and w22(t) is the time decay factor for negative Weibo public opinion; c1 is the first-day spread of positive news portal public opinion, w31(t) is the time decay factor for positive news portal public opinion, c2 is the first-day spread of negative news portal public opinion, and w32(t) is the time decay factor for negative news portal public opinion. It should be noted that when calculating the time decay factor, the starting day t=0, the next day t=1, and so on. It can be understood that by multiplying the first-day spread of a particular public opinion (such as positive forum public opinion) by its time decay factor, its daily spread can be calculated. For example, if the total number of negative public opinions on the target company's finances minus the total number of positive public opinions in two weeks is greater than 100,000, the public opinion tendency assessment result is that its negative public opinions on finances are serious.
[0064] S105. Conduct behavioral pattern fusion analysis on multiple behavioral pattern analysis results and deployment and early warning problem data of the target enterprise to obtain graphic and text decision-making guidance data corresponding to the deployment and early warning problem data.
[0065] Among them, the graphic and text decision guidance data is used to intuitively display at least one of the target enterprise's behavioral change trends and potential risk situations.
[0066] In some implementations, a fusion analysis intelligent agent is provided in the enterprise monitoring platform, and multiple behavior pattern analysis results and control and warning problem data of the target enterprise are input into the fusion analysis intelligent agent to obtain graphic and text decision guidance data corresponding to the control and warning problem data.
[0067] It should be noted that initially, the control and early warning problem data is analyzed for requirements and tasks, resulting in multiple pending subtasks. Then, pattern recognition is performed on each pending subtask to obtain multiple behavioral pattern analysis results for the target enterprise. Finally, these behavioral pattern analysis results are integrated with the control and early warning problem data for a deeper understanding, resulting in more accurate graphical and textual decision-making guidance data.
[0068] S107. In response to the confirmation operation of the graphic and text decision guidance data, the time series features of the historical risk behavior data of the target enterprise and the visual semantic features of the graphic and text decision guidance data are mapped to the same representation space, and cross-modal comparative learning is used to perform spatiotemporal semantic joint anomaly monitoring to obtain the abnormal behavior category of the target enterprise.
[0069] Historical risk behavior data can be the target enterprise's past risk behavior records, stored in a time series format. Abnormal behavior categories describe the types of abnormal behavior identified during monitoring, such as financial anomalies, supply chain anomalies, and legal compliance anomalies. Contrastive learning can be a method for learning feature representations by comparing the similarity between the time series feature vectors of the target enterprise's historical risk behavior data and the visual semantic feature vectors of graphic and text decision-making guidance data. This method can map these two different modalities' vectors into the same representation space.
[0070] In some embodiments, the accuracy of the graphic and text decision guidance data is confirmed based on feedback from supervisors. It is understood that if the graphic and text decision guidance data does not meet the supervisor's query intent, the supervisor can adjust the control and warning problem data or conduct follow-up inquiries and submit a new request to obtain more desired graphic and text decision guidance data.
[0071] In some embodiments, supervisors monitor target enterprises for abnormal behavior. Once the graphic and text decision guidance data is confirmed, the enterprise monitoring platform uses an intelligent agent (such as a model with a transformer architecture) to extract features from the time series data corresponding to multiple historical risk behaviors of the target enterprise, thereby obtaining time series features of multiple historical risk behavior data. It also extracts features from the graphic and text decision guidance data, thereby obtaining visual semantic features of the graphic and text decision guidance data. Then, through comparative learning, the features of the two different modalities are mapped to the same representation space. Multiple similarity data are obtained by performing a similarity comparison between the visual semantic features of the graphic and text decision guidance data and the time series features of each historical risk behavior data. For example, when a certain similarity data exceeds a preset threshold, it is determined that the target enterprise has the corresponding risk behavior.
[0072] In the above embodiment, first, the control and warning problem data for the target enterprise is obtained, and the control and warning problem data is subjected to demand analysis and task decomposition to obtain multiple subtasks to be processed; then, pattern recognition is performed based on any subtask to be processed to obtain the behavior pattern analysis results of the target enterprise under any subtask to be processed; then, the multiple behavior pattern analysis results of the target enterprise and the control and warning problem data are subjected to behavior pattern fusion analysis to obtain the graphic decision guidance data corresponding to the control and warning problem data; finally, in response to the confirmation operation of the graphic decision guidance data, the time series features of the historical risk behavior data of the target enterprise and the visual semantic features of the graphic decision guidance data are mapped to the same representation space, and the spatiotemporal semantic joint anomaly monitoring is performed using cross-modal comparative learning to obtain the abnormal behavior category of the target enterprise. Based on the demand analysis of the control and warning problem data, the control and warning problem data can be more accurately understood and the task decomposition can be performed. Based on pattern recognition of multiple subtasks, the behavior pattern analysis results of the target enterprise under a specific subtask can be revealed more accurately and quickly. Based on behavioral pattern fusion analysis of multiple target enterprise behavior patterns and control and early warning problem data, we can deeply integrate and analyze data from different sources, thereby generating more accurate and comprehensive graphic and text decision-making guidance data. By combining the time series characteristics of historical risk behavior data with the visual semantic features of graphic and text decision-making guidance data through cross-modal comparative learning, we can conduct spatiotemporal semantic joint anomaly monitoring to obtain more accurate abnormal behavior classifications for target enterprises.
[0073] See also Figure 1b In this embodiment, a method for monitoring abnormal behavior of an enterprise is provided, which is applied to an enterprise monitoring platform. The method includes:
[0074] S110: Obtaining deployment and early warning problem data for the target enterprise, performing demand analysis and task decomposition on the deployment and early warning problem data, and obtaining a plurality of subtasks to be processed.
[0075] Target enterprises can be those that regulatory authorities need to monitor for unusual behavior. Monitoring and early warning problem data can be issues related to the business practices of the target enterprise, entered by regulators on the enterprise monitoring platform. Demand analysis can involve an intelligent agent deeply understanding and identifying the semantics of monitoring and early warning problem data. Task decomposition can be further broken down into specific subtasks based on the semantics derived from demand analysis. These subtasks identify specific business practices of the target enterprise.
[0076] In some implementations, supervisors can submit control and early warning problem data on the enterprise monitoring platform. The intelligent agent then performs semantic understanding of the data and decomposes the semantics into multiple subtasks to be processed. For example, if the supervisor has previously entered several historical control and early warning problem data before entering the control and early warning problem data, the intelligent agent can then use the historical control and early warning problem data to understand the semantics of the control and early warning problem data and decompose the tasks.
[0077] S120: Perform pattern recognition based on any pending subtask to obtain a behavior pattern analysis result of the target enterprise under any pending subtask.
[0078] The target enterprise has multiple behavior pattern analysis results; the behavior pattern analysis results are used to describe at least one of the behavior characteristics and abnormal performance of the target enterprise under the corresponding subtask to be processed.
[0079] In some embodiments, the enterprise monitoring platform can obtain the required enterprise-related data of the target enterprise, such as monitoring data, visitor records, online public opinion, online recruitment information, etc. Each subtask to be processed has a corresponding subtask processing agent. The subtask processing agent performs pattern recognition through enterprise-related data to obtain the behavior pattern analysis results of the target enterprise under any subtask to be processed. It can be the behavioral characteristics of the target enterprise, or it can be abnormal performance, or it can be both behavioral characteristics and abnormal performance. For example, the behavior pattern analysis results of the target enterprise obtained based on online public opinion may be financial anomalies. For example, the behavior pattern analysis results of the target enterprise obtained based on online recruitment information may be a large number of financial personnel recruitment or recruitment anomalies.
[0080] S130. Conduct behavioral pattern fusion analysis on multiple behavioral pattern analysis results and deployment and early warning problem data of the target enterprise to obtain graphic and text decision-making guidance data corresponding to the deployment and early warning problem data.
[0081] Among them, the graphic and text decision guidance data is used to intuitively display at least one of the target enterprise's behavioral change trends and potential risk situations.
[0082] In some implementations, a fusion analysis intelligent agent is provided in the enterprise monitoring platform, and multiple behavior pattern analysis results and control and warning problem data of the target enterprise are input into the fusion analysis intelligent agent to obtain graphic and text decision guidance data corresponding to the control and warning problem data.
[0083] It should be noted that initially, the control and early warning problem data is analyzed for requirements and tasks, resulting in multiple pending subtasks. Then, pattern recognition is performed on each pending subtask to obtain multiple behavioral pattern analysis results for the target enterprise. Finally, these behavioral pattern analysis results are integrated with the control and early warning problem data for a deeper understanding, resulting in more accurate graphical and textual decision-making guidance data.
[0084] S140 , in response to a confirmation operation on the graphic-text decision guidance data, performing joint anomaly monitoring using the historical risk behavior data of the target enterprise and the graphic-text decision guidance data to obtain an abnormal behavior category of the target enterprise.
[0085] The historical risk behavior data can be the target enterprise's past risk behavior records. Abnormal behavior categories are used to describe the types of abnormal behaviors identified by the target enterprise during the monitoring process, such as financial anomalies, supply chain anomalies, and legal compliance anomalies.
[0086] In some embodiments, the accuracy of the graphic and text decision guidance data is confirmed based on feedback from supervisors. It is understood that if the graphic and text decision guidance data does not meet the supervisor's query intent, the supervisor can adjust the control and warning problem data or conduct follow-up inquiries and submit a new request to obtain more desired graphic and text decision guidance data.
[0087] In some embodiments, the relevant regulatory authorities monitor the target enterprise for abnormal behavior. After the confirmation operation of the graphic decision-making guidance data triggers the joint abnormality monitoring process, the enterprise monitoring platform will combine the historical risk behavior data of the target enterprise with the current graphic decision-making guidance data for analysis. For example, if the target enterprise has historical risk behavior data that has been punished for falsifying financial data, the enterprise monitoring platform can conduct joint abnormality monitoring based on the historical risk behavior data and the graphic decision-making guidance data to determine whether the target enterprise has repeated financial data falsification behavior. For example, if the target enterprise has multiple historical risk behavior data, the enterprise monitoring platform can conduct joint abnormality monitoring based on the above multiple historical risk behavior data and graphic decision-making guidance data to determine whether the target enterprise has repeated abnormal behavior, or other abnormal behavior in the abnormal behavior category to which the above multiple historical risk behavior data belong.
[0088] In the above embodiment, first, control and early warning problem data for a target enterprise is acquired, and requirements analysis and task breakdown are performed on the control and early warning problem data to obtain multiple pending subtasks. Then, pattern recognition is performed on any pending subtask to obtain the target enterprise's behavior pattern analysis results for any pending subtask. Next, a behavior pattern fusion analysis is performed on the target enterprise's multiple behavior pattern analysis results and the control and early warning problem data to obtain graphic decision-making guidance data corresponding to the control and early warning problem data. Finally, in response to a confirmation operation on the graphic decision-making guidance data, joint anomaly monitoring is performed using the target enterprise's historical risk behavior data and the graphic decision-making guidance data to obtain the target enterprise's abnormal behavior category. Based on the requirements analysis of the control and early warning problem data, a more accurate understanding and task breakdown of the control and early warning problem data can be achieved. Based on pattern recognition of multiple subtasks, the behavior pattern analysis results of the target enterprise under specific subtasks can be more accurately and quickly revealed. Based on the behavior pattern fusion analysis of the target enterprise's multiple behavior pattern analysis results and the control and early warning problem data, data from different sources can be deeply integrated and analyzed, thereby obtaining more accurate and comprehensive graphic decision-making guidance data. By conducting joint anomaly monitoring based on historical risk behavior data and graphic decision-making guidance data, we can obtain more accurate abnormal behavior categories of target enterprises.
[0089] In some embodiments, obtaining the control and early warning problem data for the target enterprise includes any of the following methods:
[0090] In response to the text input operation, control and early warning problem data is determined.
[0091] Acquire voice description data for the target enterprise, parse the voice description data, and obtain control and early warning problem data.
[0092] The voice description data may be the voice form of the control and warning problem data. The analysis may be to recognize the voice input data and convert it into text format data.
[0093] In some embodiments, the enterprise monitoring platform includes a problem input module, into which supervisors can input control and early warning problem data in text form. For example, the control and early warning problem data might include "analyzing enterprise A's recruitment behavior and public opinion information over the past three months to determine whether there are any unusual hiring practices or negative public opinion." In other embodiments, the enterprise monitoring platform includes a speech analysis module, into which supervisors can submit speech description data in the form of voice. The speech analysis module then parses the speech description data to generate textual control and early warning problem data.
[0094] In the above embodiment, the deployment and early warning problem data is obtained by text input or voice description data analysis, which improves the accuracy and flexibility of the acquisition of the deployment and early warning problem data.
[0095] In some embodiments, an enterprise anomaly monitoring model is deployed on the enterprise monitoring platform, and the enterprise anomaly monitoring model includes a problem analysis intelligent agent; the control and warning problem data is analyzed for requirements and tasks are decomposed to obtain multiple subtasks to be processed, including: the control and warning problem data is decomposed for intentions and steps through the problem analysis intelligent agent to obtain multiple subtasks to be processed.
[0096] Among them, the enterprise anomaly monitoring model can be an intelligent analysis model deployed on the enterprise monitoring platform, whose main function is to identify and analyze abnormal behaviors in the operation of the target enterprise.
[0097] The problem analysis agent is a core component of the enterprise anomaly monitoring model. Its primary function is to decompose intent and deconstruct steps of control and warning problem data, transforming it into multiple specific, actionable subtasks. Intent decomposition involves understanding control and warning problem data to derive multiple intents. Some intents can be directly processed as subtasks, while others require further decomposition. Step decomposition involves further decomposition of some intents to generate subtasks, with subtasks having a sequential execution order.
[0098] In some implementations, the problem analysis agent is a large language model (LLM), such as GPT-4. When the enterprise anomaly monitoring model receives control and warning problem data input by supervisors, it passes this data to the problem analysis agent. The problem analysis agent uses chain-of-thought (CoT) reasoning to decompose the control and warning problem data into intent and steps.
[0099] In some implementations, prompt word engineering is used to implement intent decomposition of control and early warning problem data. For example, the prompt word template can be as follows:
[0100] "###role play
[0101] You are an excellent corporate regulator, particularly good at reading and analyzing data on control and early warning issues.
[0102] ###Quest Requirements
[0103] The following control and early warning questions involve descriptions of business operations. Please use the format below to summarize the relevant issues for each business operation from the following perspectives.
[0104] ###Notes
[0105] {Analyze business activities such as recruitment, public opinion, visitors, and capital flow, paying attention to the time period of analysis}
[0106] Output format
[0107] |Business Practices|Issues|
[0108] ###Analysis of control and early warning problem data
[0109] {Enter analysis, control and early warning problem data here}".
[0110] For example, for the control and early warning problem data "Analyze whether there are any abnormal situations in Enterprise A in the past three months", multiple decomposition intentions are obtained as follows:
[0111] 1) Analyze the recruitment information of Company A in the past three months
[0112] 2) Analyze the online public opinion of Company A in the past three months
[0113] 3) Analyze the cash flow of Company A in the past three months
[0114] Exemplarily, online public opinion analysis can be directly used as a subtask to be analyzed. Exemplarily, recruitment information analysis can be decomposed into recruitment release information analysis and interview information analysis, and the recruitment release information analysis is performed first, and the evaluation result is abnormal, such as when a large number of financial personnel are recruited, interview information analysis is performed. Because the interview is a subsequent step in the release of recruitment information, the interview information analysis is a further confirmation of the recruitment release information analysis. When the recruitment release information is normal, there is no need to perform interview information analysis. Only when the recruitment release information is abnormal, is it necessary to perform interview information analysis. In some embodiments, the steps can be disassembled based on rule management. Exemplarily, when the data obtained by the intention decomposition contains "recruitment information", the corresponding steps are to perform recruitment release information analysis first and then interview information analysis.
[0115] In the above embodiment, the problem analysis agent in the enterprise anomaly monitoring model performs demand analysis and task decomposition on the control and warning problem data, which can more accurately identify and process the control and warning problem data and improve the abnormal behavior monitoring capability of the enterprise monitoring platform.
[0116] In some embodiments, an enterprise anomaly monitoring model is deployed on the enterprise monitoring platform, and the enterprise anomaly monitoring model includes multiple candidate intelligent agents. Before performing pattern recognition based on any subtask to be processed, the method also includes: selecting a target intelligent agent that matches any subtask to be processed from multiple candidate intelligent agents, and accordingly assigning any subtask to be processed to the target intelligent agent.
[0117] In some embodiments, each candidate agent has functional characteristics, wherein the functional characteristics can be obtained by extracting features from the functional description text of the candidate agent. The enterprise anomaly monitoring model can extract features from any pending subtask to obtain the pending subtask features. By comparing the pending subtask features with the functional characteristics of each candidate agent for similarity, the candidate agent corresponding to the functional characteristics with the highest similarity is determined as the target agent.
[0118] Accordingly, pattern recognition is performed based on any subtask to be processed to obtain the behavior pattern analysis results of the target enterprise under any subtask to be processed, including: obtaining the enterprise-related data corresponding to any subtask to be processed through the target intelligent agent, and performing feature extraction and similarity calculation on the enterprise-related data to obtain the behavior pattern analysis results.
[0119] Pattern recognition can be used to identify the target company's operating model based on company-related data, such as recruitment patterns, transfer patterns, and public opinion patterns. Behavioral pattern analysis can identify potential behavioral patterns and trends based on company-related data. For example, recruitment pattern analysis can reveal fraudulent recruitment or frequent recruitment. Company-related data can include various aspects of data related to the target company, such as online public opinion, job postings, monitoring data, and visitor information.
[0120] In some embodiments, any target intelligent agent is pre-set with a method for obtaining enterprise-related data. For example, if the target intelligent agent needs to analyze the online public opinion of the target enterprise, it can use a web crawler to crawl various data about the target enterprise on the Internet, including news websites, social media platforms, forums, etc. For example, if the target intelligent agent needs to analyze the monitoring data of the target enterprise, it can access the cloud storage that stores the monitoring data of the target enterprise through an account. After receiving the subtask to be processed, the target intelligent agent first obtains the enterprise-related data according to the subtask to be processed. For example, if the target intelligent agent receives the subtask to be processed "Identify the online public opinion of Enterprise A within six months", the target intelligent agent first uses a web crawler to crawl the public opinion-related information about Enterprise A on the Internet within six months.
[0121] In some embodiments, the enterprise monitoring platform is pre-installed with a pattern feature knowledge base, which stores various features of the enterprise's business model. The target intelligent agent obtains the behavior pattern analysis result by extracting features and performing similarity calculations on the enterprise-related data. For example, the target intelligent agent uses natural language processing technology (NLP) to extract features of the public opinion-related information of the target enterprise A captured on the Internet to obtain A's public opinion features, and then compares the public opinion features with the various public opinion features stored in the pattern feature knowledge base for similarity, which can be Euclidean distance or cosine similarity. Finally, the public opinion pattern name corresponding to the public opinion feature with the greatest similarity is selected as the public opinion pattern analysis result of A, such as less negative public opinion, more negative public opinion, serious negative public opinion, etc.
[0122] In the above embodiment, first, by selecting a target agent within the anomaly monitoring model that matches the subtask to be processed and assigning the subtask to the target agent, precise task allocation is achieved. Second, pattern recognition based on the target agent enables rapid acquisition of target enterprise-related data, feature extraction, and similarity calculation, thereby analyzing the target enterprise's behavior patterns under specific subtasks. This approach effectively improves task processing efficiency and analysis accuracy.
[0123] See also Figure 2 In some embodiments, the target agent includes a public opinion analysis agent and a recruitment analysis agent, and the multiple pending subtasks include a public opinion analysis task and a recruitment analysis task. The target agent obtains enterprise-related data corresponding to any pending subtask, performs feature extraction and similarity calculation on the enterprise-related data, and obtains behavior pattern analysis results, including:
[0124] S510. Obtain public opinion-related information of the target enterprise through the public opinion analysis intelligent agent, perform feature extraction and similarity calculation on the public opinion-related information, and obtain the public opinion tendency evaluation result of the target enterprise.
[0125] S520. Obtain recruitment-related information of the target enterprise through the recruitment analysis agent, perform feature extraction and similarity calculation on the recruitment-related information, and obtain the recruitment behavior evaluation result of the target enterprise.
[0126] Among them, the behavioral pattern analysis results include public opinion tendency assessment results and recruitment behavior assessment results.
[0127] In some embodiments, the enterprise monitoring platform is pre-installed with a pattern feature knowledge base that stores relevant features of enterprise business models. Upon receiving a pending subtask, the public opinion analysis agent first uses a web crawler to crawl public opinion-related information about the target enterprise from the internet. It then uses natural language processing (NLP) technology to extract features from this public opinion-related information to obtain public opinion features. This public opinion feature is then compared with each public opinion feature stored in the pattern feature knowledge base for similarity, using either Euclidean distance or cosine similarity. Finally, the public opinion pattern corresponding to the public opinion feature with the greatest similarity is selected as the public opinion pattern assessment result for the target enterprise, e.g., indicating significant negative public opinion regarding financial matters.
[0128] In some embodiments, after receiving the subtask to be processed, the recruitment analysis agent first uses a web crawler to crawl recruitment-related information about the target enterprise on the Internet, and then uses natural language processing technology (NLP) to extract features of the recruitment-related information to obtain recruitment features. The recruitment features are then compared with the various recruitment features stored in the pattern feature knowledge base for similarity, which can be Euclidean distance or cosine similarity. Finally, the recruitment pattern name corresponding to the recruitment feature with the greatest similarity is selected as the recruitment behavior evaluation result of the target enterprise, such as frequent recruitment of financial positions.
[0129] In some embodiments, the behavioral pattern analysis result shows that the target enterprise has serious negative public opinion on finance and is frequently recruiting for financial positions, which may indicate that the target enterprise has financial problems, such as a financial crisis, and is trying to cope with complex financial problems by expanding the financial team.
[0130] In the above embodiment, the public opinion analysis agent and the recruitment analysis agent obtain public opinion-related and recruitment-related information about the target enterprise, perform feature extraction and similarity calculation on this information, and thus obtain the target enterprise's public opinion tendency assessment results and recruitment behavior assessment results. This method can effectively analyze the target enterprise's public opinion and recruitment behavior, providing more accurate analysis results of the enterprise's behavior patterns.
[0131] See also Figure 3 In some embodiments, the recruitment analysis agent includes a recruitment posting analysis agent and a visitor record analysis agent. The recruitment analysis agent obtains recruitment-related information of the target enterprise, performs feature extraction and similarity calculation on the recruitment-related information, and obtains the recruitment behavior evaluation results of the target enterprise, including:
[0132] S610. Obtain the target company's recruitment release information through the recruitment release analysis agent, perform text mining and cluster analysis on the recruitment release information, and obtain the recruitment release evaluation results.
[0133] S620. Obtain personnel flow image data of the target enterprise through the visitor record analysis agent, perform visitor object recognition and activity trajectory recognition on the personnel flow image data, and obtain interview-related evaluation results of the target enterprise.
[0134] Recruitment behavior assessment results include job posting assessment results and interview-related assessment results. A recruitment posting analysis agent can be an intelligent component used to analyze recruitment posting information. Text mining can be used to process recruitment postings using natural language processing techniques to identify and extract key information fields within the postings, such as key information on job descriptions, required skills, work experience, and posting time. The goal is to convert unstructured recruitment postings into structured data to facilitate subsequent analysis. Cluster analysis can be the process of classifying quantized recruitment postings by one or more fields to discover potential patterns and trends in recruitment behavior.
[0135] The visitor history analysis agent can be an intelligent component used to analyze visitor flow data within a target enterprise. Personnel flow image data can be image information captured by cameras showing visitor movement within the target enterprise area. Each camera has location information, and the image information includes time data. Visitor object identification can use facial recognition technology to identify the true identity of visitors in personnel flow image data. Activity trajectory identification can simulate visitor movement trajectories based on visitor location and time data captured by cameras.
[0136] In some embodiments, the enterprise monitoring platform is pre-installed with a pattern feature knowledge base that stores various characteristics of enterprise operating models. Upon receiving a pending subtask, the job posting analysis agent first uses a web crawler to crawl online job postings related to the target enterprise. It then uses natural language processing techniques to perform text mining on these job postings, obtaining the key information fields of each position posting. Next, it uses a vector embedding model (such as BERT) to vectorize the key information fields of each job posting, generating a job posting vector. Finally, it performs cluster analysis on the job posting vectors.
[0137] In some embodiments, the job posting analysis agent uses a K-means clustering method to cluster job posting information vectors by posting time and position, thereby obtaining the target company's annual job posting information. Given that the target company's annual turnover rates are relatively similar, and therefore the target company's recruitment situation is also relatively similar, if this year's job postings are significantly higher than previous years, this indicates that there may be anomalies in this year's job postings. The job posting analysis agent will determine the job posting assessment result as a large-scale recruitment. For example, in the clustering results, if there are significantly more finance job postings in this year's job postings than in previous years, this means that the target company is hiring finance personnel for an extended period of time or in large quantities this year, and is likely experiencing financial anomalies and needs to recruit finance personnel to handle complex issues.
[0138] In some embodiments, upon receiving a pending subtask, the visitor record analysis agent first retrieves the target enterprise's personnel flow image data from cloud storage based on the visitor's name, identification, visit time, and other information recorded on the visitor's machine. It then identifies the visitor within the personnel flow image data. Finally, based on the visitor's location and time data within the personnel flow image data, it simulates the visitor's movement trajectory within the target enterprise. For example, upon entering the enterprise, the visitor first signs in at the front desk reception area before entering the negotiation room. If a large number of similar visitor instances are present, it indicates that the target enterprise is likely interviewing a large number of applicants. The visitor record analysis agent then determines the interview-related assessment result as a high-volume recruitment.
[0139] In some embodiments, when both the recruitment release evaluation results and the interview-related evaluation results are large-scale recruitment, the recruitment analysis intelligent agent determines that the recruitment behavior evaluation result is large-scale recruitment, and the interview-related evaluation results can further confirm the recruitment release evaluation results.
[0140] In the above example, the job posting analysis agent first performs text mining and cluster analysis on the job posting information to obtain job posting evaluation results. Secondly, the visitor log analysis agent obtains employee flow image data for the target company and performs visitor object recognition and activity trajectory identification on this data to obtain interview-related evaluation results. Further verification based on the job posting evaluation results and combined with interview-related evaluation results helps to obtain more accurate recruitment behavior assessment results.
[0141] In some embodiments, an enterprise anomaly monitoring model is deployed on the enterprise monitoring platform. The enterprise anomaly monitoring model includes a risk fusion intelligent agent, which performs behavioral pattern fusion analysis on multiple behavioral pattern analysis results and control and warning problem data of the target enterprise to obtain graphic decision guidance data corresponding to the control and warning problem data, including: performing risk fusion assessment and visualization processing on multiple behavioral pattern analysis results and control and warning problem data of the target enterprise through the risk fusion intelligent agent to obtain graphic decision guidance data.
[0142] The risk fusion agent can be an AI-based system component that integrates data from different sources, such as behavioral pattern analysis results and control and early warning problem data, to provide a more accurate risk assessment of the target enterprise's risk behavior. Graphical decision-making guidance data can be decision-support information generated through behavioral pattern fusion analysis. It can be a combination of text, graphics, and charts, demonstrating potential risk points to regulators and serving as a basis for their decision-making.
[0143] In some embodiments, the problem analysis agent interprets the requirements of the control and warning problem data and breaks it down into multiple pending subtasks. Upon completion, it returns multiple behavioral pattern analysis results. If a behavioral pattern analysis result indicates abnormal behavior, it is accompanied by a corresponding risk probability value. This risk probability value can be the maximum similarity between a certain behavioral pattern feature of the target enterprise and a corresponding behavioral pattern feature in the pattern feature knowledge base. If a behavioral pattern analysis result is non-abnormal, the corresponding risk probability value can be 0. By extracting features from each behavioral pattern analysis result and comparing it with the control and warning problem data for similarity, such as by calculating the Euclidean distance, the similarity between each behavioral pattern analysis result and the control and warning problem data can be determined. The ratio of the similarity corresponding to each behavioral pattern analysis result to the sum of the similarities of all behavioral pattern analysis results is then used as the weight for that behavior pattern analysis result. Finally, the risk probability of each behavioral pattern analysis result is multiplied by the corresponding weight, and the sum of the results is used to determine the abnormal risk probability of the target enterprise.
[0144] In some embodiments, see Figure 4a , the graph shows the risk probability of the target enterprise, and each part of the graph represents its proportion in the risk probability of the target enterprise. Figure 4b , this figure shows the recruitment frequency of risky positions in the target enterprise. Each part of the figure represents the recruitment frequency of a risky position in a period of time, such as the frequency of job postings for this position in a year. Figure 4c , the figure shows the risk interview situation of the target enterprise, each part of the figure represents the number of interviews for a risk position in a period of time. Figure 4d ,This figure shows the changing trend of negative public opinion of the target enterprise.
[0145] In the above example, a risk fusion agent performs risk fusion assessment and visualization on multiple behavioral pattern analysis results and control and warning problem data from a target enterprise, generating graphical and textual decision-making guidance data. Based on this visualized data, supervisors can more quickly and accurately analyze, assess, and issue warnings regarding abnormal behavior at target enterprises.
[0146] In this embodiment, the enterprise monitoring platform deploys an enterprise anomaly monitoring model. Figure 5 The enterprise anomaly monitoring model includes a problem analysis agent, multiple candidate agents, and a risk fusion agent. The multiple candidate agents include a public opinion analysis agent, a recruitment analysis agent, and other agents. The recruitment analysis agent also includes a job posting analysis agent and a visitor record analysis agent.
[0147] See also Figure 6 In some embodiments, the target enterprise's historical risk behavior data and graphic decision guidance data are used to perform joint anomaly monitoring to obtain the target enterprise's abnormal behavior categories, including:
[0148] S810: Integrate historical risk behavior data with current risk behavior data in the graphic decision guidance data to obtain target risk behavior data.
[0149] S820: Perform graphic fusion on the target risk behavior data and the enterprise behavior analysis graph in the graphic decision guidance data to obtain the abnormal behavior category of the target enterprise.
[0150] Current risk behavior data can include multiple behavioral pattern analysis results and corresponding risk probability values for target enterprises obtained by the risk fusion agent. Historical risk behavior data can include multiple behavioral pattern analysis results and corresponding risk probability values for target enterprises obtained by the risk fusion agent. Historical risk behavior data can be stored in the database of the enterprise monitoring platform. Enterprise behavior analysis charts can include risk position recruitment frequency charts, risk position interview analysis charts, enterprise negative public opinion analysis charts, enterprise visitor analysis charts, enterprise transaction analysis charts, enterprise capital flow analysis charts, etc. Graphics and text fusion can be the fusion of graphical data features in graphic and text decision-making guidance data with target risk behavior data features.
[0151] In some embodiments, target risk behavior data is obtained by integrating historical risk behavior data with current risk behavior data based on weights. It is understood that the longer the time between historical risk behavior data and current risk behavior data, the smaller the weight assigned to the historical risk behavior data. This is because changes in the environment over time may cause past behavior patterns to change accordingly, and new risk factors may emerge. Therefore, current data has a greater impact on the accuracy and effectiveness of risk prediction.
[0152] In some implementations, a fine-tuned multimodal large model, such as GPT-4, is used to perform text-graphic fusion on the target risk behavior data and the enterprise behavior analysis graph in the text-graphic decision guidance data. Specifically, a text encoder is first used to extract features from the target risk behavior data to obtain target risk behavior features; a visual encoder is then used to extract features from the enterprise behavior analysis graph to obtain enterprise behavior analysis graph features. The target risk behavior features and enterprise behavior analysis graph features are then concatenated or weighted averaged to obtain enterprise behavior text-graphic fusion features. Finally, the multimodal large model infers the enterprise behavior text-graphic fusion features to determine the target enterprise's abnormal behavior category, such as financial anomalies.
[0153] In the above embodiment, by integrating the current risk behavior data and the historical risk behavior data, more accurate target risk behavior data is obtained; further, by fusing the target risk behavior data and the enterprise behavior analysis chart, the abnormal behavior category of the target enterprise can be determined more accurately.
[0154] See also Figure 7 In this embodiment, an enterprise abnormal behavior monitoring device 900 is further provided. The enterprise abnormal behavior monitoring device 900 is applied to an enterprise monitoring platform and includes:
[0155] The data acquisition module 910 is used to obtain the control and early warning problem data for the target enterprise, perform demand analysis and task decomposition on the control and early warning problem data, and obtain multiple subtasks to be processed;
[0156] Pattern recognition module 920 is used to perform pattern recognition based on any pending subtask to obtain a behavior pattern analysis result of the target enterprise under any pending subtask; wherein the target enterprise has multiple behavior pattern analysis results; the behavior pattern analysis results include a public opinion tendency assessment result, which is obtained by analyzing the public opinion-related information of the target enterprise and constructing a multi-dimensional assessment matrix including the spread heat and time decay factor;
[0157] Fusion analysis module 930 is used to perform behavior pattern fusion analysis on multiple behavior pattern analysis results and control and early warning problem data of the target enterprise to obtain graphic and text decision guidance data corresponding to the control and early warning problem data;
[0158] The anomaly monitoring module 940 is used to respond to the confirmation operation of the graphic decision-making guidance data, map the time series characteristics of the target enterprise's historical risk behavior data and the visual semantic characteristics of the graphic decision-making guidance data to the same representation space, and use cross-modal comparative learning to perform spatiotemporal semantic joint anomaly monitoring to obtain the abnormal behavior category of the target enterprise; wherein the abnormal behavior category is used to describe the type of abnormal behavior of the target enterprise identified during the monitoring process.
[0159] In some embodiments, the data acquisition module 910 further includes any of the following units:
[0160] A text data determining unit, configured to determine control and early warning problem data in response to a text input operation;
[0161] The voice data acquisition unit is used to obtain voice description data for the target enterprise, analyze the voice description data, and obtain control and early warning problem data.
[0162] In some embodiments, an enterprise anomaly monitoring model is deployed on the enterprise monitoring platform, and the enterprise anomaly monitoring model includes a problem analysis agent; the data acquisition module 910 also includes:
[0163] The decomposition and disassembly unit is used to decompose the intention and disassemble the steps of the control and warning problem data through the problem analysis agent to obtain multiple subtasks to be processed.
[0164] In some embodiments, an enterprise anomaly monitoring model is deployed on the enterprise monitoring platform. The enterprise anomaly monitoring model includes multiple candidate agents. The pattern recognition module 920 further includes:
[0165] An agent selection unit is used to select a target agent that matches any subtask to be processed from multiple candidate agents, and accordingly assign any subtask to be processed to the target agent;
[0166] The enterprise data acquisition unit is used to obtain the enterprise-related data corresponding to any subtask to be processed through the target intelligent agent, and perform feature extraction and similarity calculation on the enterprise-related data to obtain the behavior pattern analysis results.
[0167] In some embodiments, the target agent includes a public opinion analysis agent and a recruitment analysis agent, and the multiple subtasks to be processed include a public opinion analysis task and a recruitment analysis task; the pattern recognition module 920 further includes:
[0168] The public opinion information acquisition unit is used to obtain the public opinion related information of the target enterprise through the public opinion analysis agent, perform feature extraction and similarity calculation on the public opinion related information, and obtain the public opinion tendency evaluation result of the target enterprise;
[0169] The recruitment-related information acquisition unit is used to obtain the recruitment-related information of the target enterprise through the recruitment analysis intelligent agent, perform feature extraction and similarity calculation on the recruitment-related information, and obtain the recruitment behavior evaluation results of the target enterprise; among which, the behavior pattern analysis results include public opinion tendency evaluation results and recruitment behavior evaluation results.
[0170] In some embodiments, the recruitment analysis agent includes a recruitment posting analysis agent and a visitor record analysis agent, and the pattern recognition module 920 further includes:
[0171] The recruitment posting information acquisition unit is used to obtain the recruitment posting information of the target enterprise through the recruitment posting analysis agent, perform text mining and cluster analysis on the recruitment posting information, and obtain the recruitment posting evaluation results;
[0172] The image data acquisition unit is used to obtain the personnel flow image data of the target enterprise through the visitor record analysis intelligent agent, perform visitor object recognition and activity trajectory recognition on the personnel flow image data, and obtain the interview-related evaluation results of the target enterprise; among which, the recruitment behavior evaluation results include recruitment posting evaluation results and interview-related evaluation results.
[0173] In some embodiments, an enterprise anomaly monitoring model is deployed on the enterprise monitoring platform. The enterprise anomaly monitoring model includes a risk fusion agent. The fusion analysis module 930 further includes:
[0174] The evaluation and processing unit is used to perform risk fusion evaluation and visualization processing on multiple behavioral pattern analysis results and control and warning problem data of the target enterprise through the risk fusion intelligent agent to obtain graphic decision-making guidance data.
[0175] In some embodiments, the anomaly monitoring module 940 further includes:
[0176] A data integration unit is used to integrate historical risk behavior data with current risk behavior data in graphic decision guidance data to obtain target risk behavior data;
[0177] The computing unit is used to fuse the target risk behavior data and the enterprise behavior analysis diagram in the graphic and text decision guidance data to obtain the abnormal behavior category of the target enterprise.
[0178] The further functional description of each of the above modules and units is the same as that of the above corresponding embodiments and will not be repeated here.
[0179] In this embodiment, the enterprise abnormal behavior monitoring device is presented in the form of a functional unit, where the unit refers to an ASIC (Application Specific Integrated Circuit) circuit, a processor and memory that executes one or more software or fixed programs, and / or other devices that can provide the above functions.
[0180] See also Figure 8 , Figure 8 This is a schematic diagram of the structure of a computer device provided in an embodiment of the present application. Figure 8 As shown, the computer device includes: one or more processors 10, memory 20, and interfaces for connecting various components, including high-speed interfaces and low-speed interfaces. Various components utilize different buses to communicate with each other and can be installed on a common mainboard or installed in other ways as needed. The processor can process the instructions executed in the computer device, including instructions stored in the memory or on the memory to display the graphical information of the GUI on an external input / output device (such as, a display device coupled to the interface). In some optional embodiments, if necessary, multiple processors and / or multiple buses can be used together with multiple memories and multiple memories. Equally, multiple computer devices can be connected, and each device provides part of the necessary operations (for example, as a server array, a group of blade servers, or a multi-processor system). Figure 8 A processor 10 is taken as an example.
[0181] The processor 10 may be a central processing unit, a network processor, or a combination thereof. The processor 10 may further include a hardware chip. The hardware chip may be an application-specific integrated circuit, a programmable logic device, or a combination thereof. The programmable logic device may be a complex programmable logic device, a field programmable gate array, a general purpose array logic, or any combination thereof.
[0182] The memory 20 stores instructions that can be executed by at least one processor 10, so that the at least one processor 10 executes the method shown in the above embodiment.
[0183] The memory 20 may include a program storage area and a data storage area, wherein the program storage area may store an operating system and application programs required for at least one function; the data storage area may store data created based on the use of the computer device, etc. In addition, the memory 20 may include a high-speed random access memory, and may also include a non-transient memory, such as at least one disk storage device, a flash memory device, or other non-transient solid-state storage device. In some optional embodiments, the memory 20 may optionally include a memory remotely located relative to the processor 10, and these remote memories may be connected to the computer device via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.
[0184] The memory 20 may include a volatile memory, such as a random access memory; the memory may also include a non-volatile memory, such as a flash memory, a hard disk or a solid-state drive; the memory 20 may also include a combination of the above types of memory.
[0185] The computer device also includes an input device 30 and an output device 40. The processor 10, the memory 20, the input device 30 and the output device 20 can be connected via a bus or other means. Figure 8 The bus connection is taken as an example.
[0186] The input device 30 can receive input digital or character information and generate key signal input related to user settings and function control of the computer device. Examples include a touch screen, keypad, mouse, trackpad, touchpad, pointing stick, one or more mouse buttons, trackball, joystick, etc. The output device 40 may include a display device, auxiliary lighting devices (e.g., LEDs), and tactile feedback devices (e.g., vibration motors). Such display devices include, but are not limited to, liquid crystal displays, light emitting diodes, monitors, and plasma displays. In some optional embodiments, the display device may be a touch screen.
[0187] The embodiments of the present application also provide a computer-readable storage medium. The above-mentioned method according to the embodiment of the present application can be implemented in hardware, firmware, or implemented as a computer code that can be recorded in a storage medium, or implemented as a computer code that is originally stored in a remote storage medium or a non-temporary machine-readable storage medium and downloaded through a network and will be stored in a local storage medium, so that the method described herein can be stored in such software processing on a storage medium using a general-purpose computer, a dedicated processor, or programmable or dedicated hardware. Among them, the storage medium can be a magnetic disk, an optical disk, a read-only storage memory, a random access memory, a flash memory, a hard disk or a solid-state drive, etc.; further, the storage medium can also include a combination of the above-mentioned types of memory. It can be understood that a computer, a processor, a microprocessor controller or programmable hardware includes a storage component that can store or receive software or computer code. When the software or computer code is accessed and executed by a computer, a processor or hardware, the method shown in the above embodiment is implemented.
[0188] An embodiment of the present application provides a computer program product, which includes computer instructions stored in a computer-readable storage medium. A processor of a computer device reads the computer instructions from the computer-readable storage medium and executes the computer instructions, causing the computer device to perform a method according to any embodiment of the present application.
[0189] Although the embodiments of the present application have been described with reference to the accompanying drawings, those skilled in the art may make various modifications and variations without departing from the spirit and scope of the present application, and such modifications and variations shall fall within the scope defined by the appended claims.
[0190] The systems, devices, modules, or units described in the above embodiments may be implemented by computer chips or entities, or by products having certain functions. A typical implementation device is a computer. Specifically, the computer may be, for example, a personal computer, a laptop computer, a cellular phone, a camera phone, a smartphone, a personal digital assistant, a media player, a navigation device, an email device, a game console, a tablet computer, a wearable device, or a combination of any of these devices.
[0191] For the convenience of description, the above devices are described as being divided into various units according to their functions. Of course, when implementing this application, the functions of each unit can be implemented in the same or multiple software and / or hardware.
[0192] Those skilled in the art will appreciate that the embodiments of the present application may be provided as methods, systems, or computer program products. Therefore, the present application may take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware. Furthermore, the present application may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0193] This application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of the application. It should be understood that each process and / or block in the flowchart and / or block diagram, as well as the combination of processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate a device for implementing the functions specified in one or more processes in the flowchart and / or one or more blocks in the block diagram.
[0194] These computer program instructions may also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce a product including an instruction device that implements the functions specified in one or more processes in the flowchart and / or one or more boxes in the block diagram.
[0195] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, so that the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in one or more processes in the flowchart and / or one or more boxes in the block diagram.
[0196] It should also be noted that the terms "comprises," "includes," or any other variations thereof are intended to encompass non-exclusive inclusion, such that a process, method, commodity, or apparatus that includes a series of elements includes not only those elements but also other elements not explicitly listed, or includes elements inherent to such process, method, commodity, or apparatus. In the absence of further limitations, an element defined by the phrase "comprises a ..." does not exclude the presence of other identical elements in the process, method, commodity, or apparatus that includes the element.
[0197] The various embodiments in this specification are described in a progressive manner. Similar parts between the various embodiments can be referred to in conjunction with each other. Each embodiment focuses on the differences between the other embodiments. In particular, the system embodiments are generally similar to the method embodiments, so the description is relatively simple. For relevant parts, refer to the description of the method embodiments.
[0198] The foregoing is merely an embodiment of the present application and is not intended to limit the present application. For those skilled in the art, the present application may have various changes and variations. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present application should all be included within the scope of the claims of the present application.
[0199] Although the embodiments of the present application have been described with reference to the accompanying drawings, those skilled in the art may make various modifications and variations without departing from the spirit and scope of the present application, and such modifications and variations shall fall within the scope defined by the appended claims.
Claims
1. A method for monitoring abnormal behavior of an enterprise, characterized in that: The method is applied to an enterprise monitoring platform, where an enterprise anomaly monitoring model is deployed. The enterprise anomaly monitoring model includes a problem analysis agent, multiple candidate agents, and a risk fusion agent. The method includes: Obtaining the deployment and early warning problem data for the target enterprise, performing demand analysis and task decomposition on the deployment and early warning problem data through the problem analysis agent, and obtaining a plurality of subtasks to be processed; wherein, any subtask to be processed matches a target agent among the plurality of candidate agents, and the target agent includes a recruitment analysis agent, and the recruitment analysis agent includes a recruitment release analysis agent and a visitor record analysis agent, and the recruitment release analysis agent is used to obtain the recruitment release information of the target enterprise, perform text mining and cluster analysis on the recruitment release information, and obtain a recruitment release evaluation result; the visitor record analysis agent is used to obtain the personnel flow image data of the target enterprise, perform visitor object recognition and activity trajectory recognition on the personnel flow image data, and obtain the interview-related evaluation result of the target enterprise; The target intelligent agent performs pattern recognition based on any pending subtask to obtain a behavior pattern analysis result of the target enterprise under any pending subtask; wherein the target enterprise has multiple behavior pattern analysis results; the behavior pattern analysis results include a public opinion tendency evaluation result and a recruitment behavior evaluation result, the public opinion tendency evaluation result is obtained by analyzing the public opinion-related information of the target enterprise and constructing a multidimensional evaluation matrix including a dissemination heat and a time decay factor, and the recruitment behavior evaluation result includes the recruitment posting evaluation result and the interview-related evaluation result; The risk fusion agent performs a behavior pattern fusion analysis on multiple behavior pattern analysis results of the target enterprise and the control and early warning problem data to obtain graphic and text decision guidance data corresponding to the control and early warning problem data; In response to the confirmation operation of the graphic decision guidance data, the time series features of the historical risk behavior data of the target enterprise and the visual semantic features of the graphic decision guidance data are mapped to the same representation space, and cross-modal contrastive learning is used to perform spatiotemporal semantic joint anomaly monitoring to obtain the abnormal behavior category of the target enterprise; wherein, the abnormal behavior category is used to describe the abnormal behavior type of the target enterprise identified during the monitoring process.
2. The method according to claim 1, characterized in that The acquisition of control and early warning problem data for the target enterprise includes any of the following methods: In response to the text input operation, determining the control and early warning problem data; Acquire voice description data for the target enterprise, parse the voice description data, and obtain the control and early warning problem data.
3. The method according to claim 1, characterized in that The requirements analysis and task decomposition of the control and early warning problem data are performed to obtain multiple subtasks to be processed, including: The problem analysis agent performs intention decomposition and step disassembly on the control and warning problem data to obtain the multiple subtasks to be processed.
4. The method according to claim 1, wherein The pattern recognition based on any pending subtask to obtain the behavior pattern analysis result of the target enterprise under any pending subtask includes: The target intelligent agent obtains the enterprise-related data corresponding to any of the subtasks to be processed, and performs feature extraction and similarity calculation on the enterprise-related data to obtain the behavior pattern analysis result.
5. The method according to claim 4, characterized in that The target agent includes a public opinion analysis agent, and the multiple subtasks to be processed include a public opinion analysis task and a recruitment analysis task; the step of obtaining enterprise-related data corresponding to any of the subtasks to be processed through the target agent, and performing feature extraction and similarity calculation on the enterprise-related data to obtain the behavior pattern analysis results includes: Obtaining public opinion-related information of the target enterprise through the public opinion analysis agent, performing feature extraction and similarity calculation on the public opinion-related information, and obtaining a public opinion tendency evaluation result of the target enterprise; The recruitment analysis agent obtains the recruitment-related information of the target enterprise, performs feature extraction and similarity calculation on the recruitment-related information, and obtains the recruitment behavior evaluation result of the target enterprise; wherein the behavior pattern analysis result includes the public opinion tendency evaluation result and the recruitment behavior evaluation result.
6. The method according to any one of claims 1 to 5, characterized in that An enterprise anomaly monitoring model is deployed on the enterprise monitoring platform. The enterprise anomaly monitoring model includes a risk fusion agent. The behavior pattern fusion analysis is performed on multiple behavior pattern analysis results of the target enterprise and the control and early warning problem data to obtain graphic and text decision guidance data corresponding to the control and early warning problem data, including: The risk fusion intelligent agent performs risk fusion assessment and visualization processing on multiple behavior pattern analysis results of the target enterprise and the control and early warning problem data to obtain the graphic decision guidance data.
7. The method according to claim 1, characterized in that The abnormal behavior category of the target enterprise is obtained by performing graphic fusion on the target risk behavior data and the enterprise behavior analysis diagram in the graphic decision guidance data. The target risk behavior data is obtained by integrating the historical risk behavior data with the current risk behavior data in the graphic decision guidance data.
8. A device for monitoring abnormal behavior of an enterprise, characterized in that: The enterprise abnormal behavior monitoring device is applied to an enterprise monitoring platform, on which an enterprise abnormality monitoring model is deployed. The enterprise abnormality monitoring model includes a problem analysis agent, multiple candidate agents, and a risk fusion agent, including: A data acquisition module is used to obtain the control and early warning problem data for the target enterprise, and perform demand analysis and task decomposition on the control and early warning problem data through the problem analysis agent to obtain multiple subtasks to be processed; wherein, any subtask to be processed is matched with a target agent among the multiple candidate agents, and the target agent includes a recruitment analysis agent, and the recruitment analysis agent includes a recruitment release analysis agent and a visitor record analysis agent. The recruitment release analysis agent is used to obtain the recruitment release information of the target enterprise, perform text mining and cluster analysis on the recruitment release information, and obtain the recruitment release evaluation result; the visitor record analysis agent is used to obtain the personnel flow image data of the target enterprise, perform visitor object recognition and activity trajectory recognition on the personnel flow image data, and obtain the interview-related evaluation result of the target enterprise; A pattern recognition module is configured to perform pattern recognition based on any pending subtask by the target intelligent agent to obtain a behavior pattern analysis result of the target enterprise under any pending subtask; wherein the target enterprise has multiple behavior pattern analysis results; the behavior pattern analysis results include a public opinion tendency assessment result and a recruitment behavior assessment result, the public opinion tendency assessment result is obtained by analyzing the public opinion-related information of the target enterprise and constructing a multidimensional assessment matrix including a dissemination heat and a time decay factor, and the recruitment behavior assessment result includes the recruitment posting assessment result and the interview-related assessment result; A fusion analysis module is used to perform a fusion analysis of the target enterprise's multiple behavior pattern analysis results and the control and early warning problem data through the risk fusion agent to obtain graphic and text decision guidance data corresponding to the control and early warning problem data; An anomaly monitoring module is used to, in response to a confirmation operation on the graphic decision-making guidance data, map the time series features of the target enterprise's historical risk behavior data and the visual semantic features of the graphic decision-making guidance data to the same representation space, and perform spatiotemporal semantic joint anomaly monitoring using cross-modal contrastive learning to obtain the abnormal behavior category of the target enterprise; wherein the abnormal behavior category is used to describe the type of abnormal behavior of the target enterprise identified during the monitoring process.
9. A computer device, characterized in that: include: A memory and a processor, wherein the memory and the processor are communicatively connected to each other, the memory stores computer instructions, and the processor executes the method according to any one of claims 1 to 7 by executing the computer instructions.
Citation Information
Patent Citations
Device and method for identifying and evaluating emergency hot topic
CN102937960A
Wafer manufacturing process evaluation and anomaly detection method assisted by machine learning
CN118887208A
Index question and answer intelligent platform realized based on large model Agent
CN118964546A
Transform-based electric power image-text cross-modal retrieval method and related equipment
CN119719449A