Risk account monitoring method and device, equipment, storage medium and product

By combining the basic account data and real-time behavior data, calculating and integrating features, inputting pre-trained models for real-time risk monitoring, the problems of lag in risk account monitoring in the existing technology are solved, and real-time and in-depth risk monitoring of accounts are realized.

CN119941404APending Publication Date: 2025-05-06SHANGHAI PUDONG DEVELOPMENT BANK
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411921341.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-25
Publication Date
2025-05-06

AI Technical Summary

Technical Problem

In the prior art, risk account monitoring has problems such as timeliness lag and it is difficult to form effective features based on real-time data.

Method used

By obtaining the basic data of the account and real-time behavior data, real-time behavior characteristics and state characteristics are calculated, and feature fusion is used by predefined feature operators, and inputting the pre-trained account risk prediction model for real-time risk monitoring.

Benefits of technology

Real-time monitoring of account operations and behaviors is realized, avoiding the problems of lagging batch monitoring timeliness and insufficient coverage of real-time monitoring, and improving the ability to respond and prevent unknown risks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119941404A_ABST
    Figure CN119941404A_ABST
Patent Text Reader

Abstract

The embodiment of the invention relates to the technical field of computers, and provides a risk account monitoring method and device, equipment, a storage medium and a product, and the method comprises the steps: obtaining first account basic data and first account real-time behavior data of a target account; calculating according to the real-time behavior data of the first account to obtain a first real-time behavior characteristic of the target account; calculating a first state feature of the target account according to the first account basic data; performing calculation according to the first real-time behavior feature and the first state feature by using a predefined feature operator to obtain a first modulo feature, wherein the feature operator is used for executing a specific data calculation logic; and inputting the first modulo feature into a pre-trained account risk prediction model, and performing real-time risk monitoring on the target account. According to the embodiment of the invention, the method can effectively improve the effectiveness of real-time features, achieves the real-time monitoring of account operation and behaviors, and improves the capability of responding to and preventing unknown risks.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments of this specification relate to the field of computer technology, and in particular to a risk account monitoring method, device, equipment, storage medium and product. Background Art

[0002] Existing risk account monitoring is mainly based on two types of models. One is based on risk cases and regulatory requirements. Through batch processing of data, various thresholds are set in combination with business experience to form rule models, or based on black and white samples discovered afterwards, machine learning models are trained in combination with account feature indicators to predict risk accounts. Due to the relatively lagging data timeliness, this type of method often discovers risks only after the risks have occurred or the funds have been transferred. It is difficult to prevent or intercept the increasingly changing illegal trading methods in advance. The other type is a simple rule established based on real-time business data. Due to the limitations of various aspects such as resources and system docking, the real-time data volume is small and it is difficult to form effective features. Therefore, the coverage of business scenarios is insufficient, making it difficult to prevent various risk events in depth and breadth. Therefore, there is an urgent need for a risk account monitoring method that can combine real-time data to form effective features, so as to improve the response and prevention capabilities for unknown risks. Summary of the invention

[0003] In view of the above-mentioned problems in the prior art, the purpose of the embodiments of this specification is to provide a risk account monitoring method, device, equipment, storage medium and product to solve the problems in the prior art that risk account monitoring has a time lag and it is difficult to form effective features based on real-time data.

[0004] In order to solve the above technical problems, the specific technical solutions of the embodiments of this specification are as follows:

[0005] On the one hand, an embodiment of this specification provides a risk account monitoring method, the method comprising:

[0006] Obtain the first account basic data and the first account real-time behavior data of the target account;

[0007] Calculate a first real-time behavior feature of the target account according to the real-time behavior data of the first account;

[0008] Calculate a first status feature of the target account according to the first account basic data;

[0009] Using a predefined feature operator to calculate the first real-time behavior feature and the first state feature to obtain a first input feature, wherein the feature operator is used to execute a specific data calculation logic;

[0010] The first input feature is input into a pre-trained account risk prediction model to perform real-time risk monitoring on the target account.

[0011] Furthermore, the step of calculating the first real-time behavior feature of the target account according to the real-time behavior data of the first account includes:

[0012] Preprocessing the first account real-time behavior data to obtain preprocessed first account real-time behavior data;

[0013] Extracting feature data from the preprocessed real-time behavior data of the first account;

[0014] The feature data is calculated according to a predefined real-time calculation logic to obtain a first real-time behavior feature, wherein the real-time calculation logic is defined according to a business rule.

[0015] Furthermore, the step of calculating the first status feature of the target account according to the first account basic data includes:

[0016] Preprocessing the first account basic data to obtain preprocessed first account basic data;

[0017] Determine the state characteristics that need to be calculated and the corresponding calculation method according to business rules;

[0018] The first status feature of the target account is calculated according to the calculation method and the first account basic data.

[0019] Furthermore, the using a predefined feature operator to calculate the first input feature according to the first real-time behavior feature and the first state feature includes:

[0020] Determine the target feature operator from the predefined feature operator library according to monitoring requirements;

[0021] Converting the first real-time behavior feature and the first state feature into a key-value pair, and storing the key-value pair in a feature database, wherein the key is a unique account identifier, and the value is a real-time behavior feature value and a state feature value;

[0022] A pairing is performed from the feature database according to the unique account identifier in the key-value pair. If a match is successful, a first input feature is calculated according to the matched value and the real-time behavior feature value and the state feature value.

[0023] Furthermore, the training process of the account risk prediction model includes:

[0024] Obtaining the second account basic data and the second account real-time behavior data of several accounts;

[0025] Performing data cleaning on the second account basic data and the second account real-time behavior data;

[0026] Perform feature calculations on the cleaned second account basic data and the second account real-time behavior data to obtain second real-time behavior features and second state features;

[0027] Calculate a second input feature according to the second real-time behavior feature and the second state feature using a predefined feature operator;

[0028] Extracting time series features from the second input features using a time series analysis method;

[0029] The extracted time series features, the second account basic data, and the second account real-time behavior data are used as training data sets;

[0030] The neural network model is trained using a batch training method according to the training data set, and the trained neural network model is used as an account risk prediction model.

[0031] Furthermore, the method further comprises:

[0032] Obtain monitoring requirements from downstream users;

[0033] Decoupling the output results of the account risk prediction model according to the monitoring requirements and the preset decoupling rules, and sending the decoupled results to the corresponding downstream users;

[0034] receiving feedback from the downstream user on the decomposed output result;

[0035] If the feedback is that it does not meet the monitoring requirements of the downstream user, receiving a decoupling parameter threshold adjustment requirement sent by the downstream user;

[0036] The decoupling rule is adjusted according to the decoupling parameter threshold adjustment requirement, and the output result of the account risk prediction model is decoupled again using the adjusted decoupling rule;

[0037] Determine whether the output result after the re-decoupling meets the monitoring requirements of the downstream user;

[0038] If not, the step of adjusting the decoupling rule according to the decoupling parameter threshold adjustment requirement is repeated until a result that meets the monitoring requirement of the downstream user is output.

[0039] On the other hand, an embodiment of the present specification provides a risk account monitoring device, the device comprising:

[0040] An acquisition module, used to acquire the first account basic data and the first account real-time behavior data of the target account;

[0041] A first calculation module, configured to calculate a first real-time behavior feature of the target account according to the real-time behavior data of the first account;

[0042] A second calculation module, configured to calculate a first status feature of the target account according to the first account basic data;

[0043] a third calculation module, configured to calculate a first input feature according to the first real-time behavior feature and the first state feature using a predefined feature operator, wherein the feature operator is used to execute a specific data calculation logic;

[0044] The real-time prediction module is used to input the first input feature into the pre-trained account risk prediction model to perform real-time risk monitoring on the target account.

[0045] On the other hand, an embodiment of the present specification further provides a computer device, including a memory, a processor, and a computer program stored in the memory, wherein when the computer program is executed by the processor, the instructions of any one of the above methods are executed.

[0046] On the other hand, an embodiment of the present specification further provides a computer-readable storage medium having a computer program stored thereon, wherein when the computer program is executed by a processor of a computer device, the computer program executes instructions of any one of the above-described methods.

[0047] On the other hand, the embodiments of this specification further provide a computer program product, which, when executed by a processor of a computer device, executes instructions of any one of the above methods.

[0048] By adopting the above-mentioned technical scheme, the risk account monitoring method provided in the embodiment of this specification collects basic account data and real-time account behavior data to form state features based on the basic account data and real-time behavior features based on the real-time account behavior data, and then uses a combination of stream and batch methods to perform feature fusion, and further processes the state features and real-time behavior features into model input features, thereby expanding the range of model input features and the amount of real-time information, effectively improving the effectiveness of real-time features, realizing real-time monitoring of account operations and behaviors, and effectively avoiding problems such as delayed batch monitoring and insufficient real-time monitoring coverage, thereby improving the ability to respond to and prevent unknown risks.

[0049] The above description is only an overview of the technical solutions of some embodiments of this specification. In order to more clearly understand the technical means of some embodiments of this specification, they can be implemented in accordance with the contents of the specification. In order to make the above and other purposes, features and advantages of the embodiments of this specification more obvious and easy to understand, the following specifically cites the preferred embodiments and describes them in detail in conjunction with the attached drawings. BRIEF DESCRIPTION OF THE DRAWINGS

[0050] In order to more clearly illustrate the embodiments of this specification or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this specification. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.

[0051] Figure 1 A schematic diagram showing the steps of a risk account monitoring method in some embodiments of this specification is shown;

[0052] Figure 2 A schematic diagram of a process for calculating the first real-time behavior feature of the target account in some embodiments of this specification is shown;

[0053] Figure 3 A schematic diagram of a process of calculating the first state feature of the target account in some embodiments of this specification is shown;

[0054] Figure 4 A schematic diagram of a process for calculating a first mold-entry feature in some embodiments of this specification is shown;

[0055] Figure 5 A schematic diagram showing the training process of the account risk prediction model in some embodiments of this specification is shown;

[0056] Figure 6 A schematic diagram of a process for decoupling prediction results in some embodiments of this specification is shown;

[0057] Figure 7 A schematic diagram of the structure of a risk account monitoring device in some embodiments of this specification is shown;

[0058] Figure 8 A schematic diagram of the structure of a computer device in this specification is shown.

[0059] Description of the accompanying symbols:

[0060] 701. Get module;

[0061] 702. A first calculation module;

[0062] 703. A second calculation module;

[0063] 704. A third calculation module;

[0064] 705. Real-time prediction module;

[0065] 802. Computer equipment;

[0066] 804, processor;

[0067] 806. Memory;

[0068] 808, driving mechanism;

[0069] 810, input / output module;

[0070] 812. Input device;

[0071] 814. Output device;

[0072] 816. Presentation equipment;

[0073] 818. Graphical user interface;

[0074] 820, network interface;

[0075] 822, communication link;

[0076] 824. Communication bus. DETAILED DESCRIPTION

[0077] The following will be combined with the drawings in the embodiments of this specification to clearly and completely describe the technical solutions in the embodiments of this specification. Obviously, the described embodiments are only part of the embodiments of this specification, not all of the embodiments. Based on the embodiments in this specification, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of this specification.

[0078] It should be noted that the terms "first", "second", etc. in this specification and claims and the above-mentioned drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence. It should be understood that the data used in this way can be interchanged where appropriate, so that the embodiments of this specification described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions, for example, a process, method, device, product or equipment that includes a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or equipment.

[0079] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties. And the acquisition, storage, use, and processing of data in the technical solutions described in the embodiments of this application are in compliance with relevant regulations.

[0080] In order to solve the above problems, the present invention provides a method for monitoring risky accounts. Figure 1 This is a step diagram of a risk account monitoring method provided in an embodiment of this specification. This specification provides method operation steps as described in the embodiment or flowchart, but may include more or fewer operation steps based on conventional or non-creative labor. The order of steps listed in the embodiment is only one way of executing the steps among many orders, and does not represent the only order of execution. When the actual system or device product is executed, it can be executed in the order of the method shown in the embodiment or the accompanying drawings or in parallel. Specifically, Figure 1 As shown, the method may include:

[0081] S101: Acquire first account basic data and first account real-time behavior data of a target account.

[0082] In the embodiments of this specification, the risk account monitoring method provided in this specification is described in detail by taking the financial business application field as an example. The basic account data refers to the account status and basic account information, which are relatively slow to change and have a large total data volume, such as account type, account opening time, account opening address, customer preferences and customer identity information, etc. Such data can be regularly extracted from a database or other information storage system. The real-time account behavior data includes real-time account transactions, footprints, login logs, permission change records, level change records, etc., which are stream data with high time dependence and frequent updates. Such data can be set in data collection components in various business systems, and can be easily converted into real-time data by collecting real-time messages.

[0083] S102: Calculate a first real-time behavior feature of the target account according to the real-time behavior data of the first account.

[0084] In this embodiment, based on real-time behavior data, first set up a data pipeline, and deploy a data collection interface in each source system to ensure that real-time messages can be obtained from the source efficiently and stably, and use the message queue Kafka for normalized storage, and then use the stream processing platform Flink to process the stream data and store these stream data in the state cache redis, and use rolling accumulation and other calculation methods or corresponding data processing logic to calculate real-time features. For example, the transaction purity of the account is calculated based on the account's transaction interval, transaction amount, balance, counterparty and other data, and the transaction interval time is calculated in combination with the transaction amount, transaction time and other data, as well as a series of account behavior characteristics such as overseas transactions and frequent upgrades and downgrades.

[0085] S103: Calculate the first status feature of the target account according to the first account basic data.

[0086] In this embodiment, status characteristics are calculated according to business needs or business scenarios. The status characteristics may include account type, account opening time, credit score, historical risk record, customer preference characteristics, etc. These characteristics can reflect the basic situation of the account and customer background information, which is of great significance for account risk prediction.

[0087] S104: Calculate a first input feature according to the first real-time behavior feature and the first state feature using a predefined feature operator, wherein the feature operator is used to execute a specific data calculation logic.

[0088] In this embodiment, a series of predefined feature operators are used to execute specific data calculation logic to combine real-time behavior features and state features into model input features. Feature operators are defined based on business scenarios, monitoring requirements, etc., and may include, for example, frequent transaction operators, abnormal transaction detection operators, etc. Through feature operators, model input features such as transaction anomaly index and credit score change rate can be calculated.

[0089] S105: Input the first input feature into a pre-trained account risk prediction model to perform real-time risk monitoring on the target account.

[0090] In this embodiment, the account risk prediction model can be based on machine learning or deep learning algorithms to automatically identify potential risks in account behavior. The account risk prediction model is trained based on account behavior data and account basic data of several accounts. The trained account risk prediction model calculates the risk score or probability of the account based on the input model features, thereby realizing real-time risk monitoring of the account.

[0091] By adopting the above-mentioned technical scheme, the risk account monitoring method provided in the embodiment of this specification collects basic account data and real-time account behavior data to form state features based on the basic account data and real-time behavior features based on the real-time account behavior data, and then uses a combination of stream and batch methods to perform feature fusion, and further processes the state features and real-time behavior features into model input features, thereby expanding the range of model input features and the amount of real-time information, effectively improving the effectiveness of real-time features, realizing real-time monitoring of account operations and behaviors, and effectively avoiding problems such as delayed batch monitoring and insufficient real-time monitoring coverage, thereby improving the ability to respond to and prevent unknown risks.

[0092] In the embodiments of this specification, refer to Figure 2 , the calculating the first real-time behavior feature of the target account according to the real-time behavior data of the first account includes:

[0093] S201: preprocessing the first account real-time behavior data to obtain preprocessed first account real-time behavior data;

[0094] S202: Extracting feature data from the pre-processed real-time behavior data of the first account;

[0095] S203: Calculate the feature data according to a predefined real-time calculation logic to obtain a first real-time behavior feature, wherein the real-time calculation logic is defined according to a business rule.

[0096] Specifically, the acquired real-time behavior data of the first account is first preprocessed, including removing duplicate records, filling missing values, format standardization, etc. At the same time, exploratory data analysis can also be performed on the data to understand the distribution of the data and potential abnormal patterns. After the data preprocessing is completed, a series of business rules are defined according to the monitoring needs, such as transaction amount thresholds, transaction frequency limits, abnormal transaction patterns, etc. Based on the business rules, feature extraction logic is designed to extract feature data useful for calculating real-time behavior features from a large amount of real-time behavior data, such as transaction amount, transaction frequency, counterparty, transaction time, login location, permission change type, etc. Based on the extracted feature data, the feature value that can reflect the real-time behavior pattern of the account is calculated through real-time calculation logic, where the real-time calculation logic is used to calculate the real-time behavior feature value based on the feature data and a specific calculation method. In the embodiments of this specification, real-time behavior features include transaction intervals (time intervals between consecutive transactions), transaction purity (number and proportion of transactions with the same amount), test transactions (identifying whether an account conducts small test transactions), concentrated transfers in and dispersed transfers out (identifying whether an account has the behavior of concentrated transfers of large amounts of funds followed by dispersed transfers out), overseas transactions (identifying whether an account has overseas transaction behaviors), frequent promotions and demotions (identifying whether an account has frequent level changes), etc.

[0097] In the embodiments of this specification, refer to Figure 3 , the first state feature of the target account is calculated according to the first account basic data, including:

[0098] S301: preprocessing the first account basic data to obtain preprocessed first account basic data;

[0099] S302: Determine the state characteristics to be calculated and the corresponding calculation method according to the business rules;

[0100] S303: Calculate the first status feature of the target account according to the calculation method and the first account basic data.

[0101] Specifically, the first account basic data obtained is preprocessed as in the above-mentioned first account real-time behavior data. The preprocessing method is the same as that of the first account real-time behavior data, and will not be repeated here. After the preprocessing is completed, the state characteristics to be calculated and the corresponding calculation methods are determined according to the business rules formulated based on the monitoring requirements, such as account activity, account health, credit score, risk level, etc. Then, for each state characteristic, the account basic data to be calculated is determined according to the corresponding calculation method, and then each state characteristic value is calculated according to the account basic data using the calculation method. For example, for account activity, a certain time window (such as the past 30 days) can be set, the number of transactions and transaction amount within the time window can be counted, and then the average value or sum within the time period can be calculated to characterize the activity of the account. For account health, the health score of the account can be calculated based on factors such as whether the account balance is sufficient and whether there is an overdue record.

[0102] In the embodiments of this specification, refer to Figure 4 , the step of using a predefined feature operator to calculate the first input feature according to the first real-time behavior feature and the first state feature includes:

[0103] S401: determining a target feature operator from a predefined feature operator library according to monitoring requirements;

[0104] S402: Convert the first real-time behavior feature and the first state feature into a key-value pair, and store the key-value pair in a feature database, wherein the key is a unique account identifier, and the value is a real-time behavior feature value and a state feature value;

[0105] S403: Matching is performed from the feature database according to the account unique identifier in the key-value pair. If the match is successful, the first input feature is calculated according to the matched value and the real-time behavior feature value and the state feature value.

[0106] Specifically, in the embodiments of this specification, each feature operator in the feature operator library has corresponding label information, wherein the label information is defined according to the monitoring requirements or application scenarios. The monitoring requirements in step S401 can be the requirement text or keywords input by the user, and the matching degree between the requirement text or keywords and the label information is calculated, and the feature operators corresponding to the first n label information with a matching degree greater than a preset threshold are used as the target feature operators corresponding to the monitoring requirements. Feature operators include fast-in-fast-out operators, frequent transaction operators, and abnormal transaction detection operators, and each feature operator executes specific data processing logic respectively. For the status features of the basic data of the account, they are first processed through database tools such as sql, and the key and value are extracted, and written to the Redis database in a storage method similar to map. Based on the behavioral features of the real-time behavior data of the account, they are processed through Flinksql, linked with the status features in the Redis database, and calculated through the feature operators of each scene to form the final input features.

[0107] For example, the fast-in-fast-out operator is used to monitor the transfer of money into an account and then quickly transfer it out. By comparing real-time transaction data with historical transaction records, it can identify the pattern of rapid inflow and outflow of account funds. Whenever a transaction message is generated, the operator will extract real-time behavior features such as transaction amount and transaction time based on the data in the transaction message, and extract corresponding status features such as account activity and account health status. The serial number + account number is used as the unique identifier of the account as the key, and the transaction amount, transaction time, account activity, and account health status are stored as values ​​in the Redis database. They are paired with the key of the historical transaction message previously stored in Redis by the operator. Through pairing, it is possible to identify which transactions are consecutively occurred in a short period of time by the same account, which is crucial for determining whether the account has an abnormal transaction pattern of fast-in-fast-out. If the pairing is successful, the transaction time interval, number of transactions, transaction frequency, account accumulation, and other features between the current transaction and the previous transaction can be calculated based on the value of the two transactions. The fast-in-fast-out operator determines whether the current account has fast-in-fast-out features based on these features. If so, the fast-in-fast-out feature value is calculated based on the specific feature value.

[0108] In the embodiments of this specification, refer to Figure 5 The training process of the account risk prediction model includes:

[0109] S501: Obtaining second account basic data and second account real-time behavior data of a plurality of accounts;

[0110] S502: Cleaning the second account basic data and the second account real-time behavior data;

[0111] S503: performing feature calculations on the cleaned second account basic data and the second account real-time behavior data to obtain second real-time behavior features and second state features;

[0112] S504: Calculate a second input feature according to the second real-time behavior feature and the second state feature using a predefined feature operator;

[0113] S505: extracting time series features from the second input features using a time series analysis method;

[0114] S506: Using the extracted time series features, the second account basic data, and the second account real-time behavior data as a training data set;

[0115] S507: Train the neural network model using a batch training method according to the training data set, and use the trained neural network model as an account risk prediction model.

[0116] In the embodiment of this specification, the specific implementation method of cleaning the second account basic data and the second account real-time behavior data, extracting the second real-time behavior features and the second state features, and calculating the second input model features in steps S501-S504 is the same as the aforementioned cleaning of the first account basic data and the first account real-time behavior data, extracting the first real-time behavior features and the first state features, and calculating the first input model features, so it is not repeated here. For step S505, what is different from the conventional machine learning model training is that all the second input model features used for training need to be processed based on time series to form a smooth feature flow in the time dimension, which can effectively improve the effectiveness of real-time features and improve the response and prevention capabilities for unknown risks.

[0117] Preferably, the second input model feature can be extracted by using time series analysis methods such as autoregressive moving average (ARMA) model and seasonal decomposition time series prediction (STL). In the embodiment of this specification, the time series features are divided into the following three types: lag features, rolling features and cyclic features. Lag features refer to the relationship between the data at a certain moment in the time series and the data at a certain moment in the past, which can help the model understand the dynamic changes in the time series data. For example, the transaction data of the previous day (1 day lag) or the previous week (7 days lag) can be used as features for predicting the current transaction behavior. Rolling features refer to capturing the recent trends and fluctuations of time series data by calculating statistics within the time window. For example, statistics such as IQR (interquartile range), PACF (partial autocorrelation function), RMSE (root mean square error) in the past 1 hour can be calculated. The rolling features can reflect the outliers and trend changes in the time series, thereby helping the model identify potential risks and trends. Cyclic features refer to periodic or repetitive patterns that appear in time series data. In the financial field, many trading behaviors show obvious periodic characteristics, such as seasonal fluctuations, holiday effects, etc. Cyclic features can help identify these cyclical patterns and predict future trading trends accordingly. Cyclic features are often combined with seasonal decomposition and cyclical analysis in time series analysis to extract and utilize these cyclical information. Lag features, rolling features, and cyclical features capture the autocorrelation properties, dynamic changes, and cyclical patterns of time series data, respectively, providing rich information for subsequent model training and real-time prediction.

[0118] The extracted time series features, the second account basic data, and the second account real-time behavior data are used as training data sets, and the neural network model is trained according to the training data sets, and the trained neural network model is used as the account risk prediction model. For the training part, the embodiment of this specification mainly adopts the batch model training mode, and repeatedly iterates the training in a batch mode after setting a specific training interval until the iteration termination condition is met.

[0119] For the prediction part, the trained account risk prediction model is called online, and the first input feature data in step S104 is input. The account risk prediction model performs real-time risk prediction on the account based on the input feature data, and sends the prediction results to the relevant personnel terminal for real-time monitoring. Different downstream users or systems may have different requirements for prediction results. For example, some departments may focus on specific types of account behaviors, while other departments may be more concerned with overall risk assessment. By decoupling the prediction results, the output can be customized according to the needs of each user, ensuring that only relevant, filtered and formatted information is received.

[0120] In the embodiments of this specification, refer to Figure 6 , the method further comprises:

[0121] S601: Obtain monitoring requirements of downstream users;

[0122] S602: Decoupling the output result of the account risk prediction model according to the monitoring requirements and the preset decoupling rules, and sending the decoupled result to the corresponding downstream user;

[0123] S603: receiving feedback from the downstream user on the decomposed output result;

[0124] S604: If the feedback is that it does not meet the monitoring requirement of the downstream user, receiving a decoupling parameter threshold adjustment requirement sent by the downstream user;

[0125] S605: adjusting the decoupling rule according to the decoupling parameter threshold adjustment requirement, and decoupling the output result of the account risk prediction model again by using the adjusted decoupling rule;

[0126] S606: Determine whether the output result after the decoupling again meets the monitoring requirements of the downstream user;

[0127] S607: If not, repeat the step of adjusting the decoupling rule according to the decoupling parameter threshold adjustment requirement until a result that meets the monitoring requirement of the downstream user is output.

[0128] Specifically, the prediction results are decoupled and output by connecting the decoupling rules according to the different monitoring needs of each downstream user. For example, if the monitoring needs of Department A are based on the granular control of personal accounts without moving accounts, the corresponding restricted account types and account history transaction rules are input to decompose the relevant output items, and the personal accounts without moving accounts are output, and the model results are transmitted to Department A through Kafka. Due to the rapid changes in financial risks and fraud methods, the monitoring needs of downstream users are also constantly changing. Therefore, the embodiments of this specification support parameterized management of various decoupling rule thresholds for various decoupling rules. After the model results are transmitted to each user through the decoupling rules, the user can adjust the decoupling parameter thresholds through the downstream system and return the parameter table to the decoupling rule part in the model layer through Kafka. The adjusted decoupling rules are based on the needs of downstream users. Decompose the corresponding data output items into results that meet the downstream needs. After a few minutes, the threshold adjustment effect will take effect. In this way, the model layer can predict and decouple according to the latest parameters to ensure that the output results always meet the monitoring needs.

[0129] Based on the above-mentioned risk account monitoring method, the embodiment of this specification also provides a corresponding risk account monitoring device. The device may include a system (including a distributed system), software (application), module, component, server, client, etc. using the method described in the embodiment of this specification and a device combined with necessary implementation hardware. Based on the same innovative concept, the device in one or more embodiments provided in the embodiment of this specification is as described in the following embodiments. Since the implementation scheme and method of the device to solve the problem are similar, the implementation of the specific device in the embodiment of this specification can refer to the implementation of the aforementioned method, and the repetitions will not be repeated. As used below, the term "unit" or "module" can be a combination of software and / or hardware that implements a predetermined function. Although the device described in the following embodiments is preferably implemented in software, the implementation of hardware, or a combination of software and hardware, is also possible and conceived.

[0130] Specifically, Figure 7 This is a schematic diagram of the module structure of an embodiment of a risk account monitoring device provided in the embodiment of this specification, referring to Figure 7 As shown, a risk account monitoring device provided in an embodiment of this specification includes:

[0131] An acquisition module 701 is used to acquire first account basic data and first account real-time behavior data of a target account;

[0132] A first calculation module 702, configured to calculate a first real-time behavior feature of the target account according to the real-time behavior data of the first account;

[0133] A second calculation module 703, configured to calculate a first status feature of the target account according to the first account basic data;

[0134] A third calculation module 704, configured to calculate a first input feature according to the first real-time behavior feature and the first state feature using a predefined feature operator, wherein the feature operator is used to execute a specific data calculation logic;

[0135] The real-time prediction module 705 is used to input the first input feature into the pre-trained account risk prediction model to perform real-time risk monitoring on the target account.

[0136] The beneficial effects obtained by the device provided in the embodiments of this specification are consistent with the beneficial effects obtained by the above method and will not be repeated here.

[0137] Reference Figure 8As shown, based on the above-mentioned risk account monitoring method, a computer device 802 is also provided in an embodiment of this specification, wherein the above-mentioned method runs on the computer device 802. The computer device 802 may include one or more processors 804, such as one or more central processing units (CPUs), each of which may implement one or more hardware threads. The computer device 802 may also include any memory 806, which is used to store any kind of information such as code, settings, data, etc. Non-limitingly, for example, the memory 806 may include any one or more combinations of the following: any type of RAM, any type of ROM, flash memory device, hard disk, optical disk, etc. More generally, any memory may use any technology to store information. Further, any memory may provide volatile or non-volatile retention of information. Further, any memory may represent a fixed or removable component of the computer device 802. In one case, when the processor 804 executes an associated instruction stored in any memory or combination of memories, the computer device 802 may perform any operation of the associated instruction. The computer device 802 also includes one or more drive mechanisms 808 for interacting with any storage, such as a hard disk drive mechanism, an optical disk drive mechanism, etc.

[0138] The computer device 802 may also include an input / output module 810 (I / O) for receiving various inputs (via input devices 812) and for providing various outputs (via output devices 814). A specific output mechanism may include a presentation device 816 and an associated graphical user interface (GUI) 818. In other embodiments, the input / output module 810 (I / O), the input device 812, and the output device 814 may not be included, and the computer device 802 may be used as a computer device in a network. The computer device 802 may also include one or more network interfaces 820 for exchanging data with other devices via one or more communication links 822. One or more communication buses 824 couple the components described above together.

[0139] The communication link 822 may be implemented in any manner, for example, through a local area network, a wide area network (e.g., the Internet), a point-to-point connection, etc., or any combination thereof. The communication link 822 may include any combination of hardwired links, wireless links, routers, gateway functions, name servers, etc. governed by any protocol or combination of protocols.

[0140] Corresponding to Figures 1 to 6 In addition to the method shown, an embodiment of the specification also provides a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the steps of the above method are executed.

[0141] The embodiment of the present specification also provides a computer-readable instruction, wherein when the processor executes the instruction, the program therein causes the processor to execute the following Figures 1 to 6 The method shown.

[0142] The embodiments of the present specification also provide a computer program product, including at least one instruction or at least one program, wherein the at least one instruction or the at least one program is loaded and executed by a processor to implement the following Figures 1 to 6 The method shown.

[0143] It should be understood that in the various embodiments of this specification, the size of the serial numbers of the above-mentioned processes does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this specification.

[0144] It should also be understood that in the embodiments of this specification, the term "and / or" is only a description of the association relationship of the associated objects, indicating that three relationships can exist. For example, A and / or B can represent: A exists alone, A and B exist at the same time, and B exists alone. In addition, the character " / " in this specification generally indicates that the associated objects before and after are in an "or" relationship.

[0145] Those of ordinary skill in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed in this specification can be implemented in electronic hardware, computer software, or a combination of the two. In order to clearly illustrate the interchangeability of hardware and software, the composition and steps of each example have been generally described in terms of function in the above description. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this specification.

[0146] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.

[0147] In the several embodiments provided in this specification, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are only schematic. For example, the division of the units is only a logical function division. There may be other division methods in actual implementation, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the mutual coupling or direct coupling or communication connection shown or discussed can be an indirect coupling or communication connection through some interfaces, devices or units, or it can be an electrical, mechanical or other form of connection.

[0148] The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the embodiments of this specification.

[0149] In addition, each functional unit in each embodiment of this specification may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit. The above integrated unit may be implemented in the form of hardware or in the form of software functional units.

[0150] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this specification is essentially or the part that contributes to the prior art, or all or part of the technical solution can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a number of instructions to enable a computer device (which can be a personal computer, a server, or a network device, etc.) to perform all or part of the steps of the method described in each embodiment of this specification. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), disk or optical disk and other media that can store program codes.

[0151] Specific embodiments are used in this specification to illustrate the principles and implementation methods of this specification. The description of the above embodiments is only used to help understand the methods and core ideas of this specification. At the same time, for those skilled in the art, according to the ideas of this specification, there will be changes in the specific implementation methods and application scope. In summary, the content of this specification should not be understood as a limitation on this specification.

Claims

1. A risk account monitoring method, characterized in that: The method comprises: Obtain the first account basic data and the first account real-time behavior data of the target account; Calculate a first real-time behavior feature of the target account according to the real-time behavior data of the first account; Calculate a first status feature of the target account according to the first account basic data; Using a predefined feature operator to calculate the first real-time behavior feature and the first state feature to obtain a first input feature, wherein the feature operator is used to execute a specific data calculation logic; The first input feature is input into a pre-trained account risk prediction model to perform real-time risk monitoring on the target account.

2. The method according to claim 1, characterized in that The calculating the first real-time behavior feature of the target account according to the real-time behavior data of the first account includes: Preprocessing the first account real-time behavior data to obtain preprocessed first account real-time behavior data; Extracting feature data from the preprocessed real-time behavior data of the first account; The feature data is calculated according to a predefined real-time calculation logic to obtain a first real-time behavior feature, wherein the real-time calculation logic is defined according to a business rule.

3. The method according to claim 1, characterized in that The step of calculating the first status feature of the target account according to the first account basic data includes: Preprocessing the first account basic data to obtain preprocessed first account basic data; Determine the state characteristics that need to be calculated and the corresponding calculation method according to business rules; The first status feature of the target account is calculated according to the calculation method and the first account basic data.

4. The method according to claim 1, characterized in that: The step of using a predefined feature operator to calculate the first input feature according to the first real-time behavior feature and the first state feature includes: Determine the target feature operator from the predefined feature operator library according to monitoring requirements; Converting the first real-time behavior feature and the first state feature into a key-value pair, and storing the key-value pair in a feature database, wherein the key is a unique account identifier, and the value is a real-time behavior feature value and a state feature value; A pairing is performed from the feature database according to the unique account identifier in the key-value pair. If a match is successful, a first input feature is calculated according to the matched value and the real-time behavior feature value and the state feature value.

5. The method according to claim 1, characterized in that The training process of the account risk prediction model includes: Obtaining the second account basic data and the second account real-time behavior data of several accounts; Performing data cleaning on the second account basic data and the second account real-time behavior data; Perform feature calculations on the cleaned second account basic data and the second account real-time behavior data to obtain second real-time behavior features and second state features; Calculate a second input feature according to the second real-time behavior feature and the second state feature using a predefined feature operator; Extracting time series features from the second input features using a time series analysis method; The extracted time series features, the second account basic data, and the second account real-time behavior data are used as training data sets; The neural network model is trained using a batch training method according to the training data set, and the trained neural network model is used as an account risk prediction model.

6. The method according to claim 1, characterized in that The method further comprises: Obtain monitoring requirements from downstream users; Decoupling the output results of the account risk prediction model according to the monitoring requirements and the preset decoupling rules, and sending the decoupled results to the corresponding downstream users; receiving feedback from the downstream user on the decomposed output result; If the feedback is that it does not meet the monitoring requirements of the downstream user, receiving a decoupling parameter threshold adjustment requirement sent by the downstream user; The decoupling rule is adjusted according to the decoupling parameter threshold adjustment requirement, and the output result of the account risk prediction model is decoupled again using the adjusted decoupling rule; Determine whether the output result after the re-decoupling meets the monitoring requirements of the downstream user; If not, the step of adjusting the decoupling rule according to the decoupling parameter threshold adjustment requirement is repeated until a result that meets the monitoring requirement of the downstream user is output.

7. A risk account monitoring device, characterized in that: The device comprises: An acquisition module, used to acquire the first account basic data and the first account real-time behavior data of the target account; A first calculation module, configured to calculate a first real-time behavior feature of the target account according to the real-time behavior data of the first account; A second calculation module, configured to calculate a first status feature of the target account according to the first account basic data; a third calculation module, configured to calculate a first input feature according to the first real-time behavior feature and the first state feature using a predefined feature operator, wherein the feature operator is used to execute a specific data calculation logic; The real-time prediction module is used to input the first input feature into the pre-trained account risk prediction model to perform real-time risk monitoring on the target account.

8. A computer device comprising a memory, a processor and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the computer program, the method according to any one of claims 1 to 6 is implemented.

9. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the method according to any one of claims 1 to 6 is implemented.

10. A computer program product, characterized in that The method comprises at least one instruction or at least one program, wherein the at least one instruction or the at least one program is loaded and executed by a processor to implement the method according to any one of claims 1 to 6.