Group fraud risk identification method and device, electronic equipment and storage medium

By extracting and retrieving background image data in identity authentication operations, identifying gang fraud risks, solving the problem of difficult to identify gang fraud risks in real time in the prior art, and achieving efficient and real-time risk identification and early warning.

CN119961473APending Publication Date: 2025-05-09CHINA TELECOM ARTIFICIAL INTELLIGENCE TECHNOLOGY (BEIJING) CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411836559.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-12
Publication Date
2025-05-09

AI Technical Summary

Technical Problem

In risk control scenarios such as financial transaction business, it is difficult to identify the risk of gang fraud in real time, resulting in the inability to conduct risk warnings in the first time, seriously affecting property safety.

Method used

By responding to the target user's identity authentication operation, the authentication image is obtained and background extraction is performed to generate background image data. Then search in the database to determine whether there are similar background images. If there are and the number of users corresponding to similar background images exceeds the preset threshold, it is determined that the target user is at risk of gang fraud.

Benefits of technology

Real-time identification of gang fraud risks is realized, allowing the system to automatically and synchronize risk identification when users perform identity authentication-related operations, reducing execution costs, improving real-timeness, and ensuring property safety.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119961473A_ABST
    Figure CN119961473A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides a gang fraud risk identification method and device, electronic equipment and a storage medium, and the method comprises the steps: obtaining an authentication picture uploaded by a target user through responding to an identity authentication operation of the target user, carrying out the background extraction of the authentication picture, and generating background picture data corresponding to the authentication picture; searching in a database according to the background picture data so as to determine whether similar background pictures exist in the database or not; and determining that the target user has a gang fraud risk under the condition that the similar background pictures exist in the database and the number of the users corresponding to the similar background pictures exceeds a preset threshold value. The real-time identification of the gang fraud risk is realized, so that the system can automatically and synchronously complete the identification of the gang fraud risk when the user carries out identity authentication related operation, the execution cost of gang fraud risk identification is reduced, the real-time performance of gang fraud risk identification is improved, and the property safety is ensured.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of image recognition technology, and in particular to a method and device for identifying gang fraud risks, electronic equipment, and storage medium. Background Art

[0002] In some identity authentication scenarios, the system usually requires users to enter their identity information for liveness detection (face verification, voice recognition, etc.), which is used by the system to verify the identity of the person concerned and store relevant identity information.

[0003] In risk control scenarios such as financial transaction business and consumer Internet platform business, the system background generally needs to analyze and calculate identity information and qualification information in order to further determine whether there is fraudulent behavior, so as to make fraud risk warnings;

[0004] However, related technologies generally use historical data and abnormal transaction related parties to mine and identify group fraud risks (for example, mining related party graphs by analyzing transaction frequency, time, common means, transaction objects and other data). This method is not only time-consuming and labor-intensive, but also difficult to meet the real-time risk warning needs due to the use of offline mining methods. Risk warnings cannot be issued in the first place, which seriously affects property safety. Summary of the invention

[0005] In view of the above problems, a method and device for identifying group fraud risks, an electronic device, and a storage medium are proposed to overcome the above problems or at least partially solve the above problems, including:

[0006] A method for identifying group fraud risks, the method comprising:

[0007] In response to the identity authentication operation of the target user, obtaining the authentication picture uploaded by the target user, and performing background extraction on the authentication picture to generate background picture data corresponding to the authentication picture;

[0008] Searching a database according to the background image data to determine whether a similar background image exists in the database;

[0009] When the similar background picture exists in the database and the number of users corresponding to the similar background picture exceeds a preset threshold, it is determined that the target user has the risk of gang fraud.

[0010] Optionally, extracting the background of the authentication image to generate background image data corresponding to the authentication image includes:

[0011] Determine a head portrait area in the authentication picture, and remove the head portrait area from the authentication picture to obtain a background picture;

[0012] The background picture data is generated according to the background picture.

[0013] Optionally, the background image data is a feature vector representing the background image, and searching in a database according to the background image data to determine whether there is a similar background image in the database includes:

[0014] Performing vector retrieval in the database according to the feature vector to determine the similarity between the target image and the background image;

[0015] The target picture whose similarity is higher than a preset similarity threshold is determined as the similar background picture.

[0016] Optionally, when the similar background picture exists in the database and the number of users corresponding to the similar background picture exceeds a preset threshold, determining that the target user has the risk of gang fraud includes:

[0017] If the similar background picture exists in the database, the number of users corresponding to the similar background picture exceeds a preset threshold, and the time period when the user performs the identity authentication operation is the same as the time period when the target user performs the identity authentication operation, it is determined that the target user is at risk of gang fraud.

[0018] Optionally, generating the background image data according to the background image includes:

[0019] Extracting local information from the background image through a preset neural network to obtain shallow local information of the background image;

[0020] The background image data is obtained according to the shallow local information through a preset neural network.

[0021] Optionally, after determining that the target user has the risk of group fraud, the method further includes:

[0022] A gang fraud warning message is sent to the management end for the target user.

[0023] Optionally, the shallow local information includes at least one or more of contour information, line information, contrast information, and light and dark shadow information.

[0024] A gang fraud risk identification device, the device comprising:

[0025] A background image data generating module is used to obtain an authentication image uploaded by a target user in response to an identity authentication operation of the target user, and to extract the background of the authentication image to generate background image data corresponding to the authentication image;

[0026] A similar background picture determination module is used to search in a database according to the background picture data to determine whether there is a similar background picture in the database;

[0027] The group fraud risk determination module is used to determine that the target user has the group fraud risk when the similar background picture exists in the database and the number of users corresponding to the similar background picture exceeds a preset threshold.

[0028] An electronic device comprises a processor, a memory and a computer program stored in the memory and capable of running on the processor, wherein the computer program, when executed by the processor, implements the above-mentioned method for identifying the risk of gang fraud.

[0029] A computer-readable storage medium, characterized in that a computer program is stored on the computer-readable storage medium, and when the computer program is executed by a processor, the gang fraud risk identification method as described above is implemented.

[0030] A computer program product includes a computer program, which, when executed by a processor, implements the above-mentioned method for identifying group fraud risks.

[0031] The embodiments of the present invention have the following advantages:

[0032] The present invention provides a method for identifying group fraud risk, which obtains the authentication picture uploaded by the target user in response to the identity authentication operation of the target user, extracts the background of the authentication picture, and generates background picture data corresponding to the authentication picture; then searches in the database according to the background picture data to determine whether there is a similar background picture in the database; and then determines that the target user has a group fraud risk when there are similar background pictures in the database and the number of users corresponding to the similar background pictures exceeds a preset threshold. The real-time identification of group fraud risk is realized, so that the system can automatically and synchronously complete the identification of group fraud risk when the user performs identity authentication related operations, reducing the execution cost of group fraud risk identification, improving the real-time nature of group fraud risk identification, and ensuring property safety. BRIEF DESCRIPTION OF THE DRAWINGS

[0033] In order to more clearly illustrate the technical solution of the present invention, the accompanying drawings required for use in the description of the present invention will be briefly introduced below. Obviously, the accompanying drawings in the following description are only some embodiments of the present invention. For ordinary technicians in this field, other accompanying drawings can be obtained based on these accompanying drawings without paying creative labor.

[0034] Figure 1 It is a flowchart of the steps of a method for identifying group fraud risk provided by some embodiments of the present invention;

[0035] Figure 2 It is an example diagram of the overall execution flow of an embodiment of the present invention provided by some embodiments of the present invention;

[0036] Figure 3 is a flowchart of the steps of another method for identifying group fraud risk provided by some embodiments of the present invention;

[0037] Figure 4 is a flowchart of the steps of another method for identifying group fraud risk provided by some embodiments of the present invention;

[0038] Figure 5 It is a schematic diagram of the structure of a gang fraud risk identification device provided by some embodiments of the present invention;

[0039] Figure 6 is a block diagram of an electronic device provided in some embodiments of the present invention;

[0040] Figure 7 is a schematic diagram of a computer-readable medium provided in some embodiments of the present invention. DETAILED DESCRIPTION

[0041] In order to make the above-mentioned purposes, features and advantages of the present invention more obvious and easy to understand, the present invention is further described in detail below in conjunction with the accompanying drawings and specific embodiments. Obviously, the described embodiments are part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0042] In the embodiments of the present application, words such as "first" and "second" are used to distinguish between identical or similar items with basically the same functions and effects. This is only for the purpose of clearly describing the technical solutions of the embodiments of the present application, and shall not be understood as indicating or implying relative importance or implicitly indicating the number of the indicated technical features.

[0043] In the embodiments of the present application, the terms "upper", "lower", etc. indicate orientations or positional relationships based on the orientations or positional relationships shown in the accompanying drawings, and are only for the convenience of describing the present application and simplifying the description, rather than indicating or implying that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation, and therefore should not be understood as a limitation on the present application.

[0044] For the sake of convenience, the following is a glossary of terms used in the embodiments of the present application:

[0045] CNN, Convolutional Neural Networks, is a type of feedforward neural network that includes convolution calculations and has a deep structure. It is one of the representative algorithms of deep learning.

[0046] MobileNet, a computer vision model, is trained to handle a wide variety of tasks, including analyzing faces, detecting common objects, localizing photos, and it can also perform fine-grained recognition tasks.

[0047] In some identity authentication scenarios, the system usually requires users to enter their identity information for liveness detection (face verification, voice recognition, etc.), which is used by the system to verify the identity of the person concerned and store relevant identity information.

[0048] In risk control scenarios such as financial transaction business and consumer Internet platform business, the system background generally needs to analyze and calculate identity information and qualification information in order to further determine whether there is fraudulent behavior, so as to make fraud risk warnings;

[0049] However, related technologies generally use historical data and abnormal transaction related parties to mine and identify group fraud risks (for example, mining related party graphs by analyzing transaction frequency, time, common means, transaction objects and other data). This method is not only time-consuming and labor-intensive, but also difficult to meet the needs of real-time risk warnings due to the use of offline mining methods; in addition, if a new user is performing identity authentication operations and there is no black sample data, possible fraud cannot be identified; it is impossible to issue risk warnings in the first place for group fraud such as buying and selling identities, loan fraud, finding passers-by to register on a large scale, defrauding platform promotions, and transactions, which seriously affects property safety.

[0050] In order to solve the above problems, the present invention is based on the core technical concept of automatically and synchronously completing the group fraud risk identification when the user performs identity authentication related operations, and improves the group fraud risk identification method in the related technology. The present invention will be described in detail in conjunction with the accompanying drawings below:

[0051] Reference Figure 1, shows a flowchart of a method for identifying group fraud risk provided by some embodiments of the present invention, which may specifically include the following steps:

[0052] Step 101, in response to the identity authentication operation of the target user, obtaining the authentication picture uploaded by the target user, and performing background extraction on the authentication picture to generate background picture data corresponding to the authentication picture;

[0053] In a specific implementation, when the target user initiates an identity authentication operation or the system initiates an identity authentication operation on the target user, the authentication picture uploaded by the target user can be obtained, and the target user can undergo a normal identity verification process. After the verification is passed, the target user's avatar in the authentication picture can be removed first, and the target user's avatar area can be replaced with a solid color to generate a background picture without an avatar; or the avatar image can be extracted from the authentication picture first, and the target user's avatar in the avatar image can be removed, and then the background picture without an avatar can be generated based on the avatar image with reference to the aforementioned steps; thereafter, a deep learning CNN convolutional neural network (such as VGG, ResNet, InceptionNet, MobileNet) model can be used to extract shallow local information (contours, lines, contrast, light and dark shadows, etc.) of the background picture, and generate a multi-dimensional vector (background picture data) representing the background picture for use in the subsequent judgment process of the risk of gang fraud.

[0054] In some embodiments of the present invention, extracting the background of the authentication image to generate background image data corresponding to the authentication image includes:

[0055] Determine a head portrait area in the authentication picture, and remove the head portrait area from the authentication picture to obtain a background picture;

[0056] The background picture data is generated according to the background picture.

[0057] In actual applications, when the target user initiates an identity authentication operation or the system initiates an identity authentication operation on the target user, the authentication picture uploaded by the target user can be obtained, and the target user can undergo a normal identity verification process. After the verification is passed, the target user's avatar in the authentication picture can be removed first, and the target user's avatar area can be replaced with a solid color to generate a background picture without an avatar; then the deep learning CNN convolutional neural network (such as VGG, ResNet, InceptionNet, MobileNet) model can be used to extract shallow local information (contours, lines, contrast, light and dark shadows, etc.) of the background picture, and generate a multi-dimensional vector (background picture data) representing the background picture for use in the subsequent judgment process of group fraud risks.

[0058] In some embodiments of the present invention, generating the background image data according to the background image includes:

[0059] Extracting local information from the background image through a preset neural network to obtain shallow local information of the background image;

[0060] The background image data is obtained according to the shallow local information through a preset neural network.

[0061] In practical applications, deep learning CNN convolutional neural network (such as VGG, ResNet, InceptionNet, MobileNet) models can be used to extract shallow local information (contours, lines, contrast, light and dark shadows, etc.) of the background image, and then the deep learning CNN convolutional neural network can be used to generate a multi-dimensional vector (background image data) representing the background image based on the shallow local information, which can be used for the subsequent gang fraud risk judgment process.

[0062] In some embodiments of the present invention, the shallow local information includes at least one or more of contour information, line information, contrast information, and light and dark shadow information.

[0063] In practical applications, a deep learning CNN convolutional neural network (such as VGG, ResNet, InceptionNet, MobileNet) model can be used to extract shallow local information of the background image (for example, one or more of contour information, line information, contrast information, light and dark shadow information, etc.), and then the deep learning CNN convolutional neural network can be used to generate a multi-dimensional vector (background image data) representing the background image based on the shallow local information for use in the subsequent gang fraud risk judgment process.

[0064] Step 102, searching in a database according to the background image data to determine whether there is a similar background image in the database;

[0065] In a specific implementation, vector retrieval can be performed in the database based on the background image feature vector obtained in the aforementioned steps. For example, an image similarity algorithm can be used to determine the similarity between the target image and the background image in the database, and the target image with a similarity higher than a preset similarity threshold can be determined as a similar background image, which can be used as a condition for determining the subsequent risk of gang fraud.

[0066] In some embodiments of the present invention, the background image data is a feature vector representing the background image, and searching in a database according to the background image data to determine whether there is a similar background image in the database includes:

[0067] Performing vector retrieval in the database according to the feature vector to determine the similarity between the target image and the background image;

[0068] The target picture whose similarity is higher than a preset similarity threshold is determined as the similar background picture.

[0069] In practical applications, a deep learning CNN convolutional neural network (such as VGG, ResNet, InceptionNet, MobileNet) model can be used to extract shallow local information of the background image (for example, it can be one or more of the information such as contour information, line information, contrast information, and light and dark shadow information), and then the deep learning CNN convolutional neural network can be used to generate a multidimensional vector (background image data) representing the background image according to the shallow local information; further, based on the background image feature vector obtained in the aforementioned steps, vector retrieval can be performed in the database, for example, the image similarity algorithm can be used to determine the similarity between the target image and the background image in the database, and the target image with a similarity higher than a preset similarity threshold can be determined as a similar background image, which can be used as a condition for determining the subsequent risk of gang fraud.

[0070] Step 103, when the similar background picture exists in the database and the number of users corresponding to the similar background picture exceeds a preset threshold, it is determined that the target user has the risk of gang fraud.

[0071] In a specific implementation, a comprehensive calculation can be performed based on the result data of the aforementioned retrieval process and some preset business rules to determine whether the current target user is a member of a gang fraud. For example, if it is detected that different gang members have performed multiple identity authentication-related system operations at the same location and in the same time period, it can be determined that the current target user is at risk of gang fraud. Specifically, if there are similar background pictures in the database and the number of users corresponding to the similar background pictures exceeds a preset threshold, it can be determined that the target user is at risk of the said gang fraud.

[0072] In some embodiments of the present invention, when the similar background picture exists in the database and the number of users corresponding to the similar background picture exceeds a preset threshold, determining that the target user has the risk of gang fraud includes:

[0073] If the similar background picture exists in the database, the number of users corresponding to the similar background picture exceeds a preset threshold, and the time period when the user performs the identity authentication operation is the same as the time period when the target user performs the identity authentication operation, it is determined that the target user is at risk of gang fraud.

[0074] In practical applications, as mentioned above, a comprehensive calculation can be performed based on the result data of the aforementioned retrieval process and some preset business rules to determine whether the current target user is a member of a gang fraud. For example, if it is detected that different gang members have performed multiple identity authentication-related system operations at the same location and in the same time period, it can be determined that the current target user is at risk of gang fraud; specifically, if there are similar background pictures in the database and the number of users corresponding to the similar background pictures exceeds a preset threshold, it can be determined that the target user is at risk of gang fraud; or if there are similar background pictures in the database and the number of users corresponding to the similar background pictures exceeds the preset threshold, and the time period when the user performs the identity authentication operation is the same time period as the time period when the target user performs the identity authentication operation, it can be determined that the target user is at risk of gang fraud.

[0075] In some embodiments of the present invention, after determining that the target user has the risk of group fraud, the method further includes:

[0076] A gang fraud warning message is sent to the management end for the target user.

[0077] In actual applications, after determining that a target user is at risk of group fraud, group fraud warning information can be sent to the management end for the target user. For example, group fraud warning information can be sent to the system administrator, thereby achieving pre-emptive warning of group fraud behavior and further improving the real-time nature of group fraud risk identification.

[0078] The following will be combined Figure 2 The embodiments of the present invention are further described as follows:

[0079] like Figure 2 As shown, the overall execution process of the embodiment of the present invention can be summarized as follows based on the different service types set:

[0080] Liveness detection service:

[0081] The system performs normal identity verification on the party concerned (target user), and extracts the avatar image after the verification is passed.

[0082] Avatar Removal Service:

[0083] Remove the avatar from the avatar image and replace the avatar area with a solid color to generate a background image without an avatar.

[0084] Image computing services:

[0085] Deep learning CNN convolutional neural network (such as VGG, ResNet, InceptionNet, MobileNet) model can be used to extract shallow local information (contours, lines, contrast, light and dark shadows, etc.) of the background image and generate a multi-dimensional vector representing the background image.

[0086] Image retrieval service:

[0087] Based on the background image feature vector obtained by the image computing service, vector retrieval is performed, and the similarity between the target image and the background image is determined in the database using the image similarity algorithm. The target image with a similarity higher than a preset similarity threshold can be determined as a similar background image.

[0088] Risk Control Brain Service:

[0089] The image retrieval service result data is comprehensively calculated according to some business rules to determine whether the current target user is a member of a gang fraud (for example, if different gang members perform multiple system operations at the same location, it can be determined that the target user is at risk of gang fraud).

[0090] Reference Figure 3 , shows a flowchart of another method for identifying group fraud risk provided by some embodiments of the present invention, which may specifically include the following steps:

[0091] Step 301, in response to the identity authentication operation of the target user, obtaining the authentication picture uploaded by the target user, and performing background extraction on the authentication picture to generate background picture data corresponding to the authentication picture;

[0092] In a specific implementation, when the target user initiates an identity authentication operation or the system initiates an identity authentication operation on the target user, the authentication picture uploaded by the target user can be obtained, and the target user can undergo a normal identity verification process. After the verification is passed, the target user's avatar in the authentication picture can be removed first, and the target user's avatar area can be replaced with a solid color to generate a background picture without an avatar; or the avatar image can be extracted from the authentication picture first, and the target user's avatar in the avatar image can be removed, and then the background picture without an avatar can be generated based on the avatar image with reference to the aforementioned steps; thereafter, a deep learning CNN convolutional neural network (such as VGG, ResNet, InceptionNet, MobileNet) model can be used to extract shallow local information (contours, lines, contrast, light and dark shadows, etc.) of the background picture, and generate a multi-dimensional vector (background picture data) representing the background picture for use in the subsequent judgment process of the risk of gang fraud.

[0093] Step 302, searching in a database according to the background image data to determine whether there is a similar background image in the database;

[0094] In a specific implementation, vector retrieval can be performed in the database based on the background image feature vector obtained in the aforementioned steps. For example, an image similarity algorithm can be used to determine the similarity between the target image and the background image in the database, and the target image with a similarity higher than a preset similarity threshold can be determined as a similar background image, which can be used as a condition for determining the subsequent risk of gang fraud.

[0095] Step 303: If the similar background picture exists in the database, the number of users corresponding to the similar background picture exceeds a preset threshold, and the time period when the user performs the identity authentication operation is the same as the time period when the target user performs the identity authentication operation, it is determined that the target user is at risk of gang fraud.

[0096] In a specific implementation, a comprehensive calculation can be performed based on the result data of the aforementioned retrieval process and some preset business rules to determine whether the current target user is a member of a gang fraud. For example, if it is detected that different gang members have performed multiple identity authentication-related system operations at the same location and in the same time period, it can be determined that the current target user is at risk of gang fraud; specifically, if there are similar background pictures in the database and the number of users corresponding to the similar background pictures exceeds a preset threshold, it can be determined that the target user is at risk of gang fraud; or if there are similar background pictures in the database and the number of users corresponding to the similar background pictures exceeds the preset threshold and the time period when the user performs the identity authentication operation is the same time period as the time period when the target user performs the identity authentication operation, it can be determined that the target user is at risk of gang fraud.

[0097] Step 304: Sending a group fraud warning message to the management end for the target user.

[0098] In actual applications, after determining that a target user is at risk of group fraud, group fraud warning information can be sent to the management end for the target user. For example, group fraud warning information can be sent to the system administrator, thereby achieving pre-emptive warning of group fraud behavior and further improving the real-time nature of group fraud risk identification.

[0099] Reference Figure 4 , shows a flowchart of another method for identifying group fraud risk provided by some embodiments of the present invention, which may specifically include the following steps:

[0100] Step 401, in response to the identity authentication operation of the target user, obtaining the authentication picture uploaded by the target user, and performing background extraction on the authentication picture to generate background picture data corresponding to the authentication picture;

[0101] In a specific implementation, when the target user initiates an identity authentication operation or the system initiates an identity authentication operation on the target user, the authentication picture uploaded by the target user can be obtained, and the target user can undergo a normal identity verification process. After the verification is passed, the target user's avatar in the authentication picture can be removed first, and the target user's avatar area can be replaced with a solid color to generate a background picture without an avatar; or the avatar image can be extracted from the authentication picture first, and the target user's avatar in the avatar image can be removed, and then the background picture without an avatar can be generated based on the avatar image with reference to the aforementioned steps; thereafter, a deep learning CNN convolutional neural network (such as VGG, ResNet, InceptionNet, MobileNet) model can be used to extract shallow local information (contours, lines, contrast, light and dark shadows, etc.) of the background picture, and generate a multi-dimensional vector (background picture data) representing the background picture for use in the subsequent judgment process of the risk of gang fraud.

[0102] Step 402, searching in a database according to the background image data to determine whether there is a similar background image in the database;

[0103] In a specific implementation, vector retrieval can be performed in the database based on the background image feature vector obtained in the aforementioned steps. For example, an image similarity algorithm can be used to determine the similarity between the target image and the background image in the database, and the target image with a similarity higher than a preset similarity threshold can be determined as a similar background image, which can be used as a condition for determining the subsequent risk of gang fraud.

[0104] Step 403, when the similar background picture exists in the database and the number of users corresponding to the similar background picture exceeds a preset threshold, it is determined that the target user has the risk of gang fraud.

[0105] In a specific implementation, a comprehensive calculation can be performed based on the result data of the aforementioned retrieval process and some preset business rules to determine whether the current target user is a member of a gang fraud. For example, if it is detected that different gang members have performed multiple identity authentication-related system operations at the same location and in the same time period, it can be determined that the current target user is at risk of gang fraud. Specifically, if there are similar background pictures in the database and the number of users corresponding to the similar background pictures exceeds a preset threshold, it can be determined that the target user is at risk of the said gang fraud.

[0106] Step 404: Sending a group fraud warning message to the management end for the target user.

[0107] In actual applications, after determining that a target user is at risk of group fraud, group fraud warning information can be sent to the management end for the target user. For example, group fraud warning information can be sent to the system administrator, thereby achieving pre-emptive warning of group fraud behavior and further improving the real-time nature of group fraud risk identification.

[0108] In general, the above-mentioned embodiment of the present invention provides a method for identifying the risk of group fraud. By responding to the identity authentication operation of the target user, the authentication picture uploaded by the target user is obtained, and the background of the authentication picture is extracted to generate the background picture data corresponding to the authentication picture; then the database is searched according to the background picture data to determine whether there is a similar background picture in the database; and then when there are similar background pictures in the database and the number of users corresponding to the similar background pictures exceeds the preset threshold, it is determined that the target user has the risk of group fraud. The real-time identification of the risk of group fraud is realized, so that the system can automatically and synchronously complete the identification of the risk of group fraud when the user performs identity authentication related operations, reducing the execution cost of the identification of the risk of group fraud, improving the real-time nature of the identification of the risk of group fraud, and ensuring the safety of property.

[0109] Specifically, related technical solutions usually use offline mining methods to mine historical data (elements such as transaction frequency, time, means, and objects) in a related graph, which is time-consuming and labor-intensive. The embodiments of the present invention can identify the risk of group fraud in real time and give advance warnings; the embodiments of the present invention can also identify fraudulent behaviors (such as buying and selling identities, loan fraud, finding passers-by to register, defrauding platform discounts, maliciously attacking systems, etc.) for new users who do not have black and gray historical data; improve the risk identification rate and accuracy of network group fraud; reduce the asset loss of the platform / system; and reduce the probability of the platform / system being maliciously attacked.

[0110] It should be noted that, for the sake of simplicity, the method embodiments are described as a series of action combinations, but those skilled in the art should be aware that the embodiments of the present invention are not limited by the order of the actions described, because according to the embodiments of the present invention, certain steps can be performed in other orders or simultaneously. Secondly, those skilled in the art should also be aware that the embodiments described in the specification are all preferred embodiments, and the actions involved are not necessarily required by the embodiments of the present invention.

[0111] Reference Figure 5 , shows a schematic diagram of the structure of a gang fraud risk identification device provided by some embodiments of the present invention; specifically, it may include the following modules:

[0112] The background image data generating module 501 is used to obtain the authentication image uploaded by the target user in response to the identity authentication operation of the target user, and perform background extraction on the authentication image to generate background image data corresponding to the authentication image;

[0113] A similar background picture determination module 502 is used to search in a database according to the background picture data to determine whether there is a similar background picture in the database;

[0114] The group fraud risk determination module 503 is used to determine that the target user has the group fraud risk when the similar background picture exists in the database and the number of users corresponding to the similar background picture exceeds a preset threshold.

[0115] In some embodiments of the present invention, the background image data generating module 501 includes:

[0116] A background image acquisition submodule, used to determine the head portrait area in the authentication image, and remove the head portrait area from the authentication image to obtain a background image;

[0117] The background picture data generating submodule is used to generate the background picture data according to the background picture.

[0118] In some embodiments of the present invention, the background image data is a feature vector representing the background image, and the similar background image determination module 502 includes:

[0119] A similarity determination submodule, used for performing vector retrieval in the database according to the feature vector to determine the similarity between the target image and the background image;

[0120] The similar background picture determination submodule is used to determine the target picture whose similarity is higher than a preset similarity threshold as the similar background picture.

[0121] In some embodiments of the present invention, the gang fraud risk determination module 503 includes:

[0122] The gang fraud risk determination submodule is used to determine that the target user has the gang fraud risk when the similar background picture exists in the database, the number of users corresponding to the similar background picture exceeds a preset threshold, and the time period when the user performs the identity authentication operation is the same time period as the target user performs the identity authentication operation.

[0123] In some embodiments of the present invention, the background image data generating submodule includes:

[0124] A shallow local information acquisition unit, used to extract local information from the background image through a preset neural network to obtain shallow local information of the background image;

[0125] A background image data acquisition unit is used to obtain the background image data according to the shallow local information through a preset neural network.

[0126] In some embodiments of the present invention, the device further comprises:

[0127] The early warning information sending module is used to send gang fraud early warning information to the management end for the target user.

[0128] Some embodiments of the present invention further provide a computer program product, including a computer program, which implements the above-mentioned gang fraud risk identification method when executed by a processor.

[0129] In addition, an embodiment of the present invention further provides an electronic device, such as Figure 6 As shown, it includes a processor 701, a communication interface 602, a memory 603 and a communication bus 604, wherein the processor 601, the communication interface 602, and the memory 603 communicate with each other through the communication bus 604.

[0130] Memory 603, used for storing computer programs;

[0131] The processor 601 is used to execute the program stored in the memory 603 to implement the following steps:

[0132] In response to the identity authentication operation of the target user, obtaining the authentication picture uploaded by the target user, and performing background extraction on the authentication picture to generate background picture data corresponding to the authentication picture;

[0133] Searching a database according to the background image data to determine whether a similar background image exists in the database;

[0134] When the similar background picture exists in the database and the number of users corresponding to the similar background picture exceeds a preset threshold, it is determined that the target user has the risk of gang fraud.

[0135] In an optional embodiment of the present invention, extracting the background of the authentication image to generate background image data corresponding to the authentication image includes:

[0136] Determine a head portrait area in the authentication picture, and remove the head portrait area from the authentication picture to obtain a background picture;

[0137] The background picture data is generated according to the background picture.

[0138] In an optional embodiment of the present invention, the background image data is a feature vector representing the background image, and searching in a database according to the background image data to determine whether there is a similar background image in the database includes:

[0139] Performing vector retrieval in the database according to the feature vector to determine the similarity between the target image and the background image;

[0140] The target picture whose similarity is higher than a preset similarity threshold is determined as the similar background picture.

[0141] In an optional embodiment of the present invention, when the similar background picture exists in the database and the number of users corresponding to the similar background picture exceeds a preset threshold, determining that the target user has the risk of gang fraud includes:

[0142] If the similar background picture exists in the database, the number of users corresponding to the similar background picture exceeds a preset threshold, and the time period when the user performs the identity authentication operation is the same as the time period when the target user performs the identity authentication operation, it is determined that the target user is at risk of gang fraud.

[0143] In an optional embodiment of the present invention, generating the background picture data according to the background picture includes:

[0144] Extracting local information from the background image through a preset neural network to obtain shallow local information of the background image;

[0145] The background image data is obtained according to the shallow local information through a preset neural network.

[0146] In an optional embodiment of the present invention, after determining that the target user has the risk of group fraud, the method further includes:

[0147] A gang fraud warning message is sent to the management end for the target user.

[0148] The communication bus mentioned in the above terminal can be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, etc. The communication bus can be divided into an address bus, a data bus, a control bus, etc. For ease of representation, only one thick line is used in the figure, but it does not mean that there is only one bus or one type of bus.

[0149] The communication interface is used for communication between the above terminal and other devices.

[0150] The memory may include a random access memory (RAM) or a non-volatile memory, such as at least one disk memory. Optionally, the memory may also be at least one storage device located away from the aforementioned processor.

[0151] The above-mentioned processor can be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it can also be a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components.

[0152] like Figure 7 As shown, in another embodiment provided by the present invention, a computer-readable storage medium 701 is also provided, in which instructions are stored. When the computer-readable storage medium 701 is run on a computer, the computer executes the gang fraud risk identification method described in the above embodiment.

[0153] As for the device embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and the relevant parts can be referred to the partial description of the method embodiment.

[0154] The various embodiments in this specification are described in a progressive manner, and each embodiment focuses on the differences from other embodiments. The same or similar parts between the various embodiments can be referenced to each other.

[0155] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of relevant data must comply with the relevant laws, regulations and standards of the relevant countries and regions, and provide corresponding operation entrances for users to choose to authorize or refuse.

[0156] Those skilled in the art will appreciate that the embodiments of the present invention may be provided as methods, devices, or computer program products. Therefore, the embodiments of the present invention may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Moreover, the embodiments of the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program codes.

[0157] The embodiments of the present invention are described with reference to the flowcharts and / or block diagrams of the methods, terminal devices (systems), and computer program products according to the embodiments of the present invention. It should be understood that each process and / or block in the flowchart and / or block diagram, as well as the combination of the processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing terminal device to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing terminal device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0158] These computer program instructions may also be stored in a computer-readable memory capable of directing a computer or other programmable data processing terminal device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce a manufactured product including an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.

[0159] These computer program instructions can also be loaded onto a computer or other programmable data processing terminal device so that a series of operating steps are executed on the computer or other programmable terminal device to produce a computer-implemented process, thereby providing instructions for executing on the computer or other programmable terminal device to implement the process. Figure 1 A process or multiple processes and / or boxes Figure 1 The steps for the functions specified in one or more boxes.

[0160] Although the preferred embodiments of the present invention have been described, those skilled in the art may make other changes and modifications to these embodiments once they have learned the basic creative concept. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments and all changes and modifications that fall within the scope of the embodiments of the present invention.

[0161] Finally, it should be noted that, in this article, relational terms such as first and second, etc. are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the terms "include", "comprise" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or terminal device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or terminal device. In the absence of further restrictions, the elements defined by the sentence "including one..." do not exclude the existence of other identical elements in the process, method, article or terminal device including the above elements.

[0162] The above is a detailed introduction to a method and device for identifying the risk of gang fraud, an electronic device, and a storage medium. Specific examples are used in this article to illustrate the principles and implementation methods of the present invention. The description of the above embodiments is only used to help understand the method of the present invention and its core idea; at the same time, for those skilled in the art, according to the idea of ​​the present invention, there will be changes in the specific implementation method and application scope. In summary, the content of this specification should not be understood as a limitation on the present invention.

Claims

1. A method for identifying group fraud risk, characterized in that: The method comprises: In response to the identity authentication operation of the target user, obtaining the authentication picture uploaded by the target user, and performing background extraction on the authentication picture to generate background picture data corresponding to the authentication picture; Searching a database according to the background image data to determine whether a similar background image exists in the database; When the similar background picture exists in the database and the number of users corresponding to the similar background picture exceeds a preset threshold, it is determined that the target user has the risk of gang fraud.

2. The method according to claim 1, characterized in that The step of extracting the background of the authentication picture to generate background picture data corresponding to the authentication picture includes: Determine a head portrait area in the authentication picture, and remove the head portrait area from the authentication picture to obtain a background picture; The background picture data is generated according to the background picture.

3. The method according to claim 2, characterized in that The background picture data is a feature vector representing the background picture, and searching in a database according to the background picture data to determine whether there is a similar background picture in the database includes: Performing vector retrieval in the database according to the feature vector to determine the similarity between the target image and the background image; The target picture whose similarity is higher than a preset similarity threshold is determined as the similar background picture.

4. The method according to claim 1, characterized in that: When the similar background picture exists in the database and the number of users corresponding to the similar background picture exceeds a preset threshold, determining that the target user has the risk of gang fraud includes: If the similar background picture exists in the database, the number of users corresponding to the similar background picture exceeds a preset threshold, and the time period when the user performs the identity authentication operation is the same as the time period when the target user performs the identity authentication operation, it is determined that the target user is at risk of gang fraud.

5. The method according to claim 2, characterized in that: The step of generating the background picture data according to the background picture includes: Extracting local information from the background image through a preset neural network to obtain shallow local information of the background image; The background image data is obtained according to the shallow local information through a preset neural network.

6. The method according to claim 1, characterized in that After determining that the target user has the risk of group fraud, the method further includes: A gang fraud warning message is sent to the management end for the target user.

7. The method according to claim 5, characterized in that The shallow local information includes at least one or more of contour information, line information, contrast information, and light and dark shadow information.

8. A gang fraud risk identification device, characterized in that: The device comprises: A background image data generating module is used to obtain an authentication image uploaded by a target user in response to an identity authentication operation of the target user, and to extract the background of the authentication image to generate background image data corresponding to the authentication image; A similar background picture determination module is used to search in a database according to the background picture data to determine whether there is a similar background picture in the database; The group fraud risk determination module is used to determine that the target user has the group fraud risk when the similar background picture exists in the database and the number of users corresponding to the similar background picture exceeds a preset threshold.

9. An electronic device, characterized in that: The method comprises a processor, a memory and a computer program stored in the memory and capable of running on the processor, wherein the computer program, when executed by the processor, implements the group fraud risk identification method as described in any one of claims 1 to 7.

10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the method for identifying the risk of gang fraud as described in any one of claims 1 to 7 is implemented.