Customer Risk Tracking Method and Device Based on 5G Messaging
By performing data privacy set intersection and joint statistical analysis of customer data across multiple institutions, and combining multiple sub-model risk adversarial models for comprehensive analysis, the risk level is determined. Customer risk tracking based on the risk level is then performed within the 5G message page. This solves the problem of tracking high-risk customer risk levels in existing technologies.
Patent Information
- Application Number
- CN202410116307.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-01-26
- Publication Date
- 2026-01-06
- Estimated Expiration
- 2044-01-26
AI Technical Summary
Existing technologies lack quantitative analysis for identifying high-risk customers, resulting in inconsistent risk analysis results and insufficient customer data security, leading to low reliability in customer risk tracking.
The system collects customer data from multiple institutions, obtains total assets through privacy set intersection and joint statistics, conducts comprehensive analysis using a risk adversarial model with multiple sub-models, determines risk levels, and tracks customers with the highest risk levels within the 5G messaging page.
It has achieved reliability and security in customer risk level assessment, and the customer risk assessment results have been accepted by multiple institutions, protecting customer privacy data from being leaked by other institutions.
Smart Images

Figure CN119963321B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of 5G technology and can be used in the field of financial technology, and in particular to a customer risk tracking method and device based on 5G messaging. Background Technology
[0002] This section is intended to provide background or context for the embodiments of the invention set forth in the claims. The description herein is not an admission that it is prior art simply because it is included in this section.
[0003] From a financial risk management perspective, understanding and recognizing high-risk clients, and then identifying and assessing them using appropriate methods, is one of the key issues in high-risk client identification. This arises because, from a financial institution's perspective, the definition of financial risk is not intuitive and is relatively difficult to describe accurately.
[0004] The existing risk customer tracking mainly has the following problems:
[0005] First, in current technologies, there is no precise definition of high-risk customers. Generally, customer data is collected extensively, and whether a customer is considered high-risk is determined according to preset rules. However, currently, these preset rules are often defined arbitrarily and lack convincing quantitative analysis.
[0006] Secondly, because most current risk customer tracking is based on customer data from a single institution, and analysis is conducted through subjective systems or pre-set rules, the risk analysis results are not convincing to multiple parties, and the reliability of customer risk analysis results is not high.
[0007] Third, since customer risk analysis requires customer data, existing solutions do not consider the security of collected customer data when it is transmitted to multiple parties, which can easily lead to data leakage.
[0008] Therefore, there is a need for a risk customer tracking solution that offers both strong data security and high reliability in gauging customer risk. Summary of the Invention
[0009] In a first aspect, embodiments of the present invention provide a customer risk tracking method based on 5G messaging, which offers good customer data security and reliable risk level tracking, including:
[0010] Collect customer data from multiple institutions for the customer group to be analyzed;
[0011] Based on data from multiple institutions and according to preset conditions, a preliminary risk analysis is conducted on the customer to obtain the customer's level of concern, which includes key concerns and non-key concerns;
[0012] By performing privacy-preserving set intersection and joint statistics on data from multiple key clients across multiple institutions, the total assets of the selected key clients can be explored.
[0013] The total assets and data from multiple institutions of the selected key clients are input into the risk mitigation model to determine the risk level of the selected key clients. The risk mitigation model includes multiple sub-models, each of which is trained based on data from multiple clients across multiple institutions in one dimension. After obtaining the total assets and data from multiple institutions of the selected key clients, the risk mitigation model first obtains the risk calculated by each sub-model, and then performs a comprehensive analysis of the risks calculated by multiple sub-models to obtain the risk level of the selected key clients.
[0014] The 5G messaging page tracks the mobile phone numbers and associated accounts of customers with the highest risk level.
[0015] Secondly, embodiments of the present invention also provide another customer risk tracking device based on 5G messaging, which offers good customer data security and reliable risk level tracking, including:
[0016] The customer data acquisition module is used to collect customer data of the customers to be analyzed from multiple institutions.
[0017] The preliminary risk analysis module is used to conduct a preliminary risk analysis of customers based on data from multiple institutions and according to preset conditions, to obtain the customer's level of concern, which includes key concerns and non-key concerns;
[0018] The Total Assets Multi-Party Probe Module is used to perform privacy set intersection and joint statistics on the data of multiple key clients across multiple institutions, and to explore the total assets of the selected key clients.
[0019] The customer risk level determination module is used to input the total assets and data from multiple institutions of the selected key customers into the risk mitigation model to determine the risk level of the selected key customers. The risk mitigation model includes multiple sub-models, each of which is trained based on data from multiple customers in multiple institutions in one dimension. After obtaining the total assets and data from multiple institutions of the selected key customers, the risk mitigation model first obtains the risk calculated by each sub-model, and then performs a comprehensive analysis of the risks calculated by multiple sub-models to obtain the risk level of the selected key customers.
[0020] The tracking module is used to track the mobile phone numbers and associated accounts of customers with the highest risk level within the 5G messaging page.
[0021] Thirdly, embodiments of the present invention also provide a computer device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the above-described customer risk tracking method based on 5G messages.
[0022] Fourthly, embodiments of the present invention also provide a computer-readable storage medium storing a computer program that, when executed by a processor, implements the above-described customer risk tracking method based on 5G messages.
[0023] In this embodiment of the invention, customer data of the customer group to be analyzed is collected from multiple institutions; based on the data from multiple institutions and according to preset conditions, a preliminary risk analysis is performed on the customer to obtain the customer attention level, which includes key attention and non-key attention; privacy set intersection and joint statistics are performed on the data of multiple key attention customers from multiple institutions to explore the total assets of the selected key attention customers; the total assets of the selected key attention customers and the data from multiple institutions are input into a risk mitigation model to determine the risk level of the selected key attention customers; the risk mitigation model includes multiple sub-models, each of which is trained based on one dimension of data of multiple customers from multiple institutions. After obtaining the total assets of the selected key attention customers and the data from multiple institutions, the risk mitigation model first obtains the risk calculated by each sub-model, and then performs a comprehensive analysis of the risks calculated by multiple sub-models to obtain the risk level of the selected key attention customers; the mobile phone number and associated account of the customer with the highest risk level are tracked on the 5G messaging page. Compared to existing technologies that only determine high-risk customers based on preset rules and analyze data from a single institution without considering the security of data transmission across multiple parties, this invention performs privacy set intersection and joint statistics on data from multiple key customers across multiple institutions to explore the total assets of selected key customers. This process allows for the determination of total assets while protecting the privacy of key customers' data from being accessed by other institutions. Subsequently, a risk adversarial model comprising multiple sub-models is used to conduct risk level analysis based on the total assets of key customers and data from multiple institutions. Since each sub-model is trained on one dimension of data from multiple customers across multiple institutions, the risk adversarial model fully considers data from multiple dimensions and multiple institutions, ensuring that the analysis results are acceptable to multiple institutions and demonstrating high reliability in customer risk analysis. Attached Figure Description
[0024] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort. In the drawings:
[0025] Figure 1 This is a flowchart of a customer risk tracking method based on 5G messages in an embodiment of the present invention;
[0026] Figure 2 This is a schematic diagram illustrating the principle of intersection of privacy sets in an embodiment of the present invention;
[0027] Figure 3 This is a schematic diagram of the password sharing technology in an embodiment of the present invention;
[0028] Figure 4 This is a flowchart illustrating the tracking of customers with the highest risk level in an embodiment of the present invention;
[0029] Figure 5 This is a schematic diagram of a customer risk tracking device based on 5G messages in an embodiment of the present invention;
[0030] Figure 6 This is a schematic diagram of a computer device in an embodiment of the present invention. Detailed Implementation
[0031] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the embodiments of the present invention will be further described in detail below with reference to the accompanying drawings. Here, the illustrative embodiments of the present invention and their descriptions are used to explain the present invention, but are not intended to limit the present invention.
[0032] The acquisition, storage, use, and processing of data in this application all comply with the relevant provisions of national laws and regulations.
[0033] Figure 1 This is a flowchart of a customer risk tracking method based on 5G messages in an embodiment of the present invention, including:
[0034] Step 101: Collect customer data of the customer group to be analyzed across multiple institutions;
[0035] Step 102: Based on data from multiple institutions and according to preset conditions, conduct a preliminary risk analysis of the customer to obtain the customer's level of concern, which includes key concerns and non-key concerns;
[0036] Step 103: Perform privacy set intersection and joint statistics on the data of multiple key clients across multiple institutions to explore the total assets of the selected key clients.
[0037] Step 104: Input the total assets and data from multiple institutions of the selected key clients into the risk mitigation model to determine the risk level of the selected key clients. The risk mitigation model includes multiple sub-models, each of which is trained based on data from multiple clients in multiple institutions in one dimension. After obtaining the total assets and data from multiple institutions of the selected key clients, the risk mitigation model first obtains the risk calculated by each sub-model, and then performs a comprehensive analysis of the risks calculated by multiple sub-models to obtain the risk level of the selected key clients.
[0038] Step 105: Track the mobile phone number and associated accounts of customers with the highest risk level on the 5G messaging page.
[0039] In this embodiment of the invention, privacy-preserving set intersection and joint statistics are performed on the data of multiple key clients across multiple institutions to explore the total assets of the selected key clients. This process allows the total asset amount to be obtained while protecting the privacy of the key clients' data from being accessed by other institutions. Subsequently, a risk adversarial model comprising multiple sub-models is used to conduct risk level analysis based on the total assets of the key clients and the data from multiple institutions. Since each sub-model is trained on one dimension of data from multiple clients across multiple institutions, the risk adversarial model fully considers data from multiple dimensions and multiple institutions, ensuring that the analysis results are acceptable to multiple institutions and that the client risk analysis has high reliability. Each step is described in detail below.
[0040] In step 101, customer data of the customer group to be analyzed is collected from multiple institutions;
[0041] If the client is a private individual, the collected client data is for the individual. If the client is a corporate client, the collected data is more for the company and its employees. Corporate client-specific data includes business status, legal entity status, changes in registration information, and the business status of the relevant legal entity.
[0042] The customer set to be analyzed here can be multiple customers to be analyzed in this study. The highest risk level customers should be selected and then tracked in detail.
[0043] In step 102, based on data from multiple institutions and according to preset conditions, a preliminary risk analysis is conducted on the customer to obtain the customer's level of concern, which includes key concerns and non-key concerns;
[0044] Preset conditions can be specifically defined according to the type of risk to be analyzed. For example, taking a customer as a merchant, the preset conditions could be: a customer is identified as a key customer when the following conditions occur:
[0045] 1) Monitoring of the number of days with no transactions for merchants in the past month.
[0046] 2) Monitoring of the merchant's daily transaction volume over the past month showed a significant anomaly compared to the average daily transaction volume over the 12 months prior to the customer's credit granting.
[0047] 3) Monitoring and comparison showed that the merchant's loan demand was higher than 50% of the acquiring transaction volume in the 12 months prior to the credit line.
[0048] In step 103, privacy set intersection and joint statistics are performed on the data of multiple key clients across multiple institutions to explore the total assets of the selected key clients.
[0049] In one embodiment, privacy-preserving set intersection and joint statistics are performed on data from multiple key clients across multiple institutions to explore the total assets of the selected key clients, including:
[0050] Perform privacy set intersection on the data of all key clients at the two institutions to obtain the intersection of the two institutions, and use it as the current intersection;
[0051] Repeat the following steps until the data of all institutions have completed the privacy set intersection and the latest current intersection is obtained. The latest current intersection contains the selected key customers: Perform privacy set intersection with the data of institutions that have not performed privacy set intersection to obtain a new current intersection;
[0052] By sharing passwords, the total assets of selected key clients across multiple institutions can be jointly analyzed.
[0053] The above steps can be used to analyze overlapping remittance requests from multiple parties, enabling the exploration of the total assets of the same client across multiple institutions. Furthermore, the participating institutions cannot deduce the data of each participant from the total amount, thereby achieving the effect of data confidentiality for the participants.
[0054] Figure 2 This is a schematic diagram of the principle of privacy set intersection in an embodiment of the present invention. It uses privacy set intersection to perform data from two companies A and B to obtain the intersection of customers of both companies without disclosing various customer information.
[0055] 1) Data preparation: The client provides ID_a and ID_b from both Company A and Company B;
[0056] 2) Company B generates key A and key B, and Company B sends key A to Company A;
[0057] 3) Company A uses a random number R to add blind encryption and encrypts it with key A to obtain key A(perturbation) × ID_a, and sends it to company B;
[0058] 4) Company B uses key B to encrypt key A (perturbation) × ID_a and ID_b to obtain perturbation × key B (ID_a) and Hash (key B (ID_b)), and sends it to company A;
[0059] 5) Company A removes the perturbation and transforms it into key B(ID_a). It calculates the intersection of Hash(key B(ID_b)) and Hash(key B(ID_a)) to obtain the intersection Hash(key B(S)), and shares it with Company B.
[0060] 6) Company B decrypts the hash(key B(S)) to obtain the intersection S of the actual ID numbers, and shares the intersection S with Company A.
[0061] Secondly, the intersection result S is then subjected to privacy-based intersection with a third-party company C to finally obtain the intersection of the three clients.
[0062] During the joint statistics phase, cryptographic sharing technology can be used to calculate the total assets of a specific client across the three institutions. Figure 3 This is a schematic diagram of the password sharing technology in an embodiment of the present invention, where x, y, and z are the assets of the customer in institutions A, B, and C, respectively. The total amount of assets can be calculated using the formula M = f(x, y, z), but none of the three parties can deduce their respective data from M.
[0063] In one embodiment, the data from multiple institutions includes group-dimensional data, which includes one or any combination of asset data, credit data, communication data, transaction data, and identity data.
[0064] The sub-model includes a group risk confrontation sub-model, which is represented by a risk graph.
[0065] The training steps for the group risk adversarial sub-model include:
[0066] Risk characteristics of multiple customers across multiple institutions and their total assets are extracted as risk relationship attributes between customers, and these risk relationship attributes are represented using probability.
[0067] Based on the aforementioned risk relationship attributes, the correlation attributes between risk features are mined as new risk relationship attributes;
[0068] Construct a risk graph based on all risk relationship attributes.
[0069] Customer data includes the total assets of customers across multiple institutions. Risk mapping can uncover common characteristics of discrete attack behaviors. Due to the behavioral inertia of risky customers and the convergence of groups, the methods and underlying information are highly similar. Therefore, risk mapping analysis uses risk features extracted from risk identification and transaction risk identification as risk relationship attributes, while also incorporating business information such as device ID, mobile phone number, and geographical location as basic relationship attributes to construct a risk map and identify potential risks.
[0070] The risk map includes a fraud network relationship map, a network indicator analysis map, and an account transaction relationship map, which are used to create fraud customer profiles, identify group risks, and protect potential victims.
[0071] In one embodiment, the data from multiple organizations includes traffic-dimensional data, which includes normal application traffic data and risk attack traffic data;
[0072] The sub-model includes a traffic risk countermeasure sub-model;
[0073] The training steps for the traffic risk adversarial sub-model include:
[0074] Data based on traffic dimensions is sharded;
[0075] In the traffic dimension data after sharding, isolated traffic is identified through an unsupervised model;
[0076] The time-domain data of the flow dimension is converted into frequency-domain data through Fourier transform to identify timed flow.
[0077] Identify data theft behavior tags corresponding to normal application traffic data, risky attack traffic data, isolated traffic, and timed traffic, respectively;
[0078] Based on normal application traffic data, risk attack traffic data, isolated traffic, timed traffic, and corresponding data theft behavior labels, a traffic risk adversarial sub-model is trained to obtain a well-trained traffic risk adversarial sub-model.
[0079] Traffic-related data includes web logs, access logs, and app.log, which can be analyzed to identify potential threats at layers 2 through 7 of the OSI model by examining differences in characteristics such as session, protocol, payload, connection, and timing window. This includes investigating third-party API fraud or internal data theft. Traffic risks include encrypted traffic risks, intermittent traffic risks, and traffic surge risks.
[0080] In one embodiment, the data from multiple organizations includes data on the dimensions of the devices used, which is collected by embedding device risk probes on the devices used by the customers; the data on the dimensions of the devices used includes one or any combination of device model, screen resolution, CANVAS data, CPU information, system version, driver and configuration;
[0081] The sub-model includes a device risk countermeasure sub-model;
[0082] The training steps for the equipment risk adversarial sub-model include:
[0083] Extract device characteristics from the data at the device dimension;
[0084] Based on the device characteristics and corresponding risk labels, a device risk adversary model is trained to obtain a well-trained device risk adversary model.
[0085] Utilizing device data to identify device risks helps improve the predictability and accuracy of risk monitoring. Device fingerprinting technology generates unique identifiers for each device, enabling precise location of devices accessing internet finance services. Device risk adversarial models can be constructed using algorithms such as classification and clustering.
[0086] In one embodiment, the data from multiple organizations includes behavioral dimension data;
[0087] The sub-model includes a behavioral risk adversarial sub-model;
[0088] The training steps for the behavioral risk adversarial sub-model include:
[0089] Utilize machine learning methods to analyze customer behavior data during page operations;
[0090] Based on the behavioral data, a transaction access sequence is identified, the characteristics of which include the sequence characteristics of normal access and the sequence characteristics of attack access.
[0091] Train a behavioral risk adversarial sub-model based on the transaction access sequence to obtain a well-trained behavioral risk adversarial sub-model.
[0092] In the above embodiments, attackers attempt to disrupt business logic, alter the normal business process sequence, and deviate from normal transaction time intervals during their attacks, thus obtaining the sequence characteristics of the attack access. Machine-automated operations often lack page interaction or rely solely on simple rule-based simulations, exhibiting strong regularity and repetitiveness. Therefore, machine learning methods such as JavaScript or ActiveX controls can be used to collect user behavior data during page operations. This data includes mouse behavior, keyboard behavior, touchscreen behavior, navigation behavior, and sensor behavior, and statistical analysis of coordinates, frequency, angle, speed, and acceleration is performed. Algorithms such as SynchroTrap are then used to identify the sequence characteristics of normal access and the sequence characteristics of attack access.
[0093] Mouse behavior includes mouse speed, mouse dragging, and mouse angle; keyboard behavior includes keyboard keystrokes and keyboard frequency; touch screen behavior includes screen pressure, screen touch, and screen swiping; and the sequence characteristics of attack access include fixed sequence detection, transaction out-of-order detection, and sequence frequency detection targeting the sequence characteristics of normal access.
[0094] In one embodiment, the data from multiple institutions includes transaction-related data;
[0095] The sub-model includes a behavioral transaction adversarial sub-model;
[0096] The training steps for the transaction risk adversarial sub-model include:
[0097] Extract transaction features from transaction dimension data, wherein the transaction features include one or any combination of counterparty, time period, trial card and high frequency;
[0098] Based on the transaction characteristics and corresponding risk labels, a transaction risk adversarial sub-model is trained to obtain a well-trained transaction risk adversarial sub-model.
[0099] In practice, transaction-level data includes transaction logs, protocol data, and account data, which are used for tracing and analysis.
[0100] In step 104, the total assets and data from multiple institutions of the selected key clients are input into the risk mitigation model to determine the risk level of the selected key clients.
[0101] In one embodiment, the total assets and data from multiple institutions of the selected key focus clients are input into a risk mitigation model to determine the risk level of the selected key focus clients, including:
[0102] The total assets of the selected key clients and the group dimension data of multiple institutions are input into the group risk countermeasure sub-model to obtain the probabilities corresponding to all risk relationship attributes connected with the key clients, and the comprehensive probability is calculated as the group risk calculated by the group risk countermeasure sub-model.
[0103] The traffic data of multiple institutions of the selected key clients are input into the traffic risk countermeasure sub-model to obtain the data theft risk calculated by the traffic risk countermeasure sub-model.
[0104] Input the data on the equipment used by multiple institutions of the selected key clients into the equipment risk countermeasure sub-model to obtain the equipment risk calculated by the equipment risk countermeasure sub-model;
[0105] The data of multiple behavioral dimensions of the selected key clients are input into the behavioral risk adversarial sub-model to obtain the sequential behavioral risk calculated by the behavioral risk adversarial sub-model.
[0106] The transaction data of multiple institutions that are selected as key clients are input into the behavioral transaction adversarial sub-model to obtain the transaction risk calculated by the transaction risk adversarial sub-model.
[0107] A comprehensive analysis is conducted on the group risk calculated by the group risk countermeasure sub-model, the data theft risk calculated by the traffic risk countermeasure sub-model, the equipment risk calculated by the equipment risk countermeasure sub-model, the sequential behavior risk calculated by the behavior risk countermeasure sub-model, and the transaction risk calculated by the transaction risk countermeasure sub-model to determine the risk level of the selected key customers.
[0108] In practice, comprehensive analysis includes the process of calculating the risk for each probability representation, such as averaging, maximizing, or weighted calculation.
[0109] In step 105, the mobile phone number and associated account of the customer with the highest risk level are tracked on the 5G message page.
[0110] In one embodiment, tracking the mobile phone number and associated accounts of customers with the highest risk level is performed within the 5G messaging page, including:
[0111] Within the 5G messaging page, you receive customer information sent by the operator. This customer information is sent by the operator after receiving a service application from a customer with the highest risk level from the 5G client, based on which the operator authenticates the customer's identity.
[0112] Track the dynamic data of the mobile phone numbers and associated accounts of customers with the highest risk level, and filter out the dynamic data that meets the preset tracking rules.
[0113] Dynamic data that meets preset tracking rules includes traffic control data (such as IP blocking data, MAC blocking data, honeypot traffic redirection data), device control data (such as device crash data, device upgrade data, device blocking data), behavior control data (including flexible authentication data, multi-level verification data, interactive prompt data), account control data (including data on receiving but not paying, identity verification data, account blocking data), transaction control data (including transaction cooling-off data, delayed payment data, delayed transfer data), and manual contact data (including data on manual telephone verification, remote witnessing data, and branch network control data).
[0114] Dynamic data can be shared among multiple parties to collaboratively build a high-risk user tracking database. This allows for the enhancement of risk parameter weights in risk mitigation models and the implementation of correlation stress tests.
[0115] Figure 4 This is a flowchart illustrating the tracking of customers with the highest risk level in an embodiment of the present invention, specifically including:
[0116] 5G clients send service requests to operators, such as loan applications and repayment requests;
[0117] The operator performs identity authentication and pushes customer information to the bank's risk monitoring service after the identity authentication is successful.
[0118] The bank's risk monitoring service tracks the dynamic data of the mobile phone numbers and associated accounts of customers with the highest risk level, filters out dynamic data that meets the preset tracking rules, and sends it to the bank's internal management system.
[0119] Once the bank's internal management system confirms, based on dynamic data, that the business transaction is below the risk threshold, it will process the transaction and send a 5G card message to the 5G client.
[0120] The preset tracking rules can be determined according to the actual situation, and there are no restrictions here.
[0121] In this embodiment of the invention, the 5G client can be a mobile phone that provides SIM card services.
[0122] This invention also proposes a customer risk tracking device based on 5G messages, the principle of which is similar to the customer risk tracking method based on 5G messages, and will not be described in detail here.
[0123] Figure 5 This is a schematic diagram of a customer risk tracking device based on 5G messages in an embodiment of the present invention, including:
[0124] Customer data acquisition module 501 is used to collect customer data of the customers to be analyzed from multiple institutions.
[0125] The preliminary risk analysis module 502 is used to conduct a preliminary risk analysis on customers based on data from multiple institutions and according to preset conditions, to obtain the customer's level of concern, which includes key concerns and non-key concerns;
[0126] The Total Assets Multi-Party Probing Module 503 is used to perform privacy set intersection and joint statistics on the data of multiple key clients across multiple institutions to explore the total assets of the selected key clients.
[0127] The customer risk level determination module 504 is used to input the total assets and data from multiple institutions of the selected key customers into the risk mitigation model to determine the risk level of the selected key customers. The risk mitigation model includes multiple sub-models, each of which is trained based on data from multiple customers in multiple institutions in one dimension. After obtaining the total assets and data from multiple institutions of the selected key customers, the risk mitigation model first obtains the risk calculated by each sub-model, and then performs a comprehensive analysis of the risks calculated by multiple sub-models to obtain the risk level of the selected key customers.
[0128] The tracking module 505 is used to track the mobile phone numbers and associated accounts of customers with the highest risk level within the 5G messaging page.
[0129] In one embodiment, the total asset multi-party exploration module is specifically used for:
[0130] Perform privacy set intersection on the data of all key clients at the two institutions to obtain the intersection of the two institutions, and use it as the current intersection;
[0131] Repeat the following steps until the data of all institutions have completed the privacy set intersection and the latest current intersection is obtained. The latest current intersection contains the selected key customers: Perform privacy set intersection with the data of institutions that have not performed privacy set intersection to obtain a new current intersection;
[0132] By sharing passwords, the total assets of selected key clients across multiple institutions can be jointly analyzed.
[0133] In one embodiment, the data from multiple institutions includes group-dimensional data, which includes one or any combination of asset data, credit data, communication data, transaction data, and identity data.
[0134] The sub-model includes a group risk confrontation sub-model, which is represented by a risk graph.
[0135] The training steps for the group risk adversarial sub-model include:
[0136] Risk characteristics of multiple customers across multiple institutions and their total assets are extracted as risk relationship attributes between customers, and these risk relationship attributes are represented using probability.
[0137] Based on the aforementioned risk relationship attributes, the correlation attributes between risk features are mined as new risk relationship attributes;
[0138] Construct a risk graph based on all risk relationship attributes.
[0139] In one embodiment, the data from multiple organizations includes traffic-dimensional data, which includes normal application traffic data and risk attack traffic data;
[0140] The sub-model includes a traffic risk countermeasure sub-model;
[0141] The training steps for the traffic risk adversarial sub-model include:
[0142] Data based on traffic dimensions is sharded;
[0143] In the traffic dimension data after sharding, isolated traffic is identified through an unsupervised model;
[0144] The time-domain data of the flow dimension is converted into frequency-domain data through Fourier transform to identify timed flow.
[0145] Identify data theft behavior tags corresponding to normal application traffic data, risky attack traffic data, isolated traffic, and timed traffic, respectively;
[0146] Based on normal application traffic data, risk attack traffic data, isolated traffic, timed traffic, and corresponding data theft behavior labels, a traffic risk adversarial sub-model is trained to obtain a well-trained traffic risk adversarial sub-model.
[0147] In one embodiment, the data from multiple organizations includes data on the dimensions of the devices used, which is collected by embedding device risk probes on the devices used by the customers; the data on the dimensions of the devices used includes one or any combination of device model, screen resolution, CANVAS data, CPU information, system version, driver and configuration;
[0148] The sub-model includes a device risk countermeasure sub-model;
[0149] The training steps for the equipment risk adversarial sub-model include:
[0150] Extract device characteristics from the data at the device dimension;
[0151] Based on the device characteristics and corresponding risk labels, a device risk adversary model is trained to obtain a well-trained device risk adversary model.
[0152] In one embodiment, the data from multiple organizations includes behavioral dimension data;
[0153] The sub-model includes a behavioral risk adversarial sub-model;
[0154] The training steps for the behavioral risk adversarial sub-model include:
[0155] Utilize machine learning methods to analyze customer behavior data during page operations;
[0156] Based on the behavioral data, a transaction access sequence is identified, the characteristics of which include the sequence characteristics of normal access and the sequence characteristics of attack access.
[0157] Train a behavioral risk adversarial sub-model based on the transaction access sequence to obtain a well-trained behavioral risk adversarial sub-model.
[0158] In one embodiment, the data from multiple institutions includes transaction-related data;
[0159] The sub-model includes a behavioral transaction adversarial sub-model;
[0160] The training steps for the transaction risk adversarial sub-model include:
[0161] Extract transaction features from transaction dimension data, wherein the transaction features include one or any combination of counterparty, time period, trial card and high frequency;
[0162] Based on the transaction characteristics and corresponding risk labels, a transaction risk adversarial sub-model is trained to obtain a well-trained transaction risk adversarial sub-model.
[0163] In one embodiment, the customer risk level determination module is specifically used for:
[0164] The total assets of the selected key clients and the group dimension data of multiple institutions are input into the group risk countermeasure sub-model to obtain the probabilities corresponding to all risk relationship attributes connected with the key clients, and the comprehensive probability is calculated as the group risk calculated by the group risk countermeasure sub-model.
[0165] The traffic data of multiple institutions of the selected key clients are input into the traffic risk countermeasure sub-model to obtain the data theft risk calculated by the traffic risk countermeasure sub-model.
[0166] Input the data on the equipment used by multiple institutions of the selected key clients into the equipment risk countermeasure sub-model to obtain the equipment risk calculated by the equipment risk countermeasure sub-model;
[0167] The data of multiple behavioral dimensions of the selected key clients are input into the behavioral risk adversarial sub-model to obtain the sequential behavioral risk calculated by the behavioral risk adversarial sub-model.
[0168] The transaction data of multiple institutions that are selected as key clients are input into the behavioral transaction adversarial sub-model to obtain the transaction risk calculated by the transaction risk adversarial sub-model.
[0169] A comprehensive analysis is conducted on the group risk calculated by the group risk countermeasure sub-model, the data theft risk calculated by the traffic risk countermeasure sub-model, the equipment risk calculated by the equipment risk countermeasure sub-model, the sequential behavior risk calculated by the behavior risk countermeasure sub-model, and the transaction risk calculated by the transaction risk countermeasure sub-model to determine the risk level of the selected key customers.
[0170] In one embodiment, the tracking module is specifically used for:
[0171] Within the 5G messaging page, you receive customer information sent by the operator. This customer information is sent by the operator after receiving a service application from a customer with the highest risk level from the 5G client, based on which the operator authenticates the customer's identity.
[0172] Track the dynamic data of the mobile phone numbers and associated accounts of customers with the highest risk level, and filter out the dynamic data that meets the preset tracking rules.
[0173] In summary, the method and apparatus proposed in this invention involve collecting customer data from multiple institutions for a customer group to be analyzed; conducting preliminary risk analysis on customers based on data from multiple institutions and according to preset conditions to obtain customer attention levels, including key and non-key attention levels; performing privacy set intersection and joint statistics on the data of multiple key attention customers from multiple institutions to explore the total assets of selected key attention customers; inputting the total assets of selected key attention customers and the data from multiple institutions into a risk mitigation model to determine the risk level of selected key attention customers; the risk mitigation model includes multiple sub-models, each of which is trained based on one dimension of data from multiple customers from multiple institutions; after obtaining the total assets of selected key attention customers and the data from multiple institutions, the risk mitigation model first obtains the risk calculated by each sub-model, and then performs a comprehensive analysis of the risks calculated by multiple sub-models to obtain the risk level of selected key attention customers; and tracking the mobile phone numbers and associated accounts of customers with the highest risk level within the 5G messaging page. In this embodiment of the invention, privacy-preserving set intersection and joint statistics are performed on the data of multiple key customers across multiple institutions to explore the total assets of the selected key customers. This process can obtain the total assets while protecting the privacy of the key customers' data from being accessed by other institutions. Subsequently, a risk adversarial model containing multiple sub-models is used to conduct risk level analysis based on the total assets of the key customers and the data from multiple institutions. Since each sub-model is trained based on one dimension of data from multiple customers across multiple institutions, the risk adversarial model fully considers data from multiple dimensions and multiple institutions, making the analysis results acceptable to multiple institutions and ensuring high reliability of customer risk analysis.
[0174] This invention also provides a computer device. Figure 6 This is a schematic diagram of a computer device in an embodiment of the present invention. The computer device 600 includes a memory 610, a processor 620, and a computer program 630 stored in the memory 610 and executable on the processor 620. When the processor 620 executes the computer program 630, it implements the above-mentioned customer risk tracking method based on 5G messages.
[0175] This invention also provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the aforementioned customer risk tracking method based on 5G messages.
[0176] Those skilled in the art will understand that embodiments of the present invention can be provided as methods, systems, or computer program products. Therefore, the present invention can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, the present invention can take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0177] This invention is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the invention. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart illustrations and / or block diagrams. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.
[0178] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.
[0179] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.
[0180] The specific embodiments described above further illustrate the purpose, technical solution, and beneficial effects of the present invention. It should be understood that the above descriptions are merely specific embodiments of the present invention and are not intended to limit the scope of protection of the present invention. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the scope of protection of the present invention.
Claims
1. A 5G message-based customer risk tracking method, characterized by, The method comprises the following steps: Collecting customer data of a plurality of institutions of a customer to be analyzed; According to the data of the plurality of institutions, performing preliminary risk analysis on the customer according to preset conditions to obtain a customer attention degree, the customer attention degree including a key attention and a non-key attention; Performing privacy set intersection and joint statistics on the data of the plurality of institutions of a plurality of key attention customers to explore the total assets of the screened key attention customers; Inputting the total assets of the screened key attention customers and the data of the plurality of institutions into a risk confrontation model to determine the risk level of the screened key attention customers; The risk confrontation model comprises a plurality of sub-models, each of which is obtained by training according to the data of a plurality of customers in one dimension of a plurality of institutions; The data of the plurality of institutions includes traffic dimension data, and the traffic dimension data includes normal application traffic data and risk attack traffic data; The sub-models include a traffic risk confrontation sub-model; The traffic risk confrontation sub-model training step comprises: Sharding the traffic dimension data; In the sharded traffic dimension data, identifying isolated traffic through an unsupervised model; Converting time domain data of the traffic dimension data into frequency domain data through Fourier transform to identify timing traffic; Determining the data stealing behavior labels corresponding to the normal application traffic data and the risk attack traffic data, the isolated traffic and the timing traffic, respectively; Training the traffic risk confrontation sub-model according to the normal application traffic data and the risk attack traffic data, the isolated traffic, the timing traffic and the corresponding data stealing behavior labels to obtain the trained traffic risk confrontation sub-model; The risk confrontation model obtains the risk calculated by each sub-model respectively after obtaining the total assets of the screened key attention customers and the data of the plurality of institutions, and then comprehensively analyzes the risks calculated by the plurality of sub-models to obtain the risk level of the screened key attention customers; Tracking the mobile phone number and the associated account of the customer with the highest risk level in the 5G message page.
2. The method of claim 1, wherein, The privacy set intersection and joint statistics on the data of the plurality of key attention customers in the plurality of institutions to explore the total assets of the screened key attention customers comprise: Performing privacy set intersection on the data of all key attention customers in two institutions respectively to obtain the intersection of the two institutions as the current intersection; Repeating the following steps until the data of all institutions have completed privacy set intersection to obtain the latest current intersection, which is the screened key attention customer: performing privacy set intersection on the current intersection and the data of the institution that has not been subjected to privacy set intersection to obtain a new current intersection; Performing joint statistics on the total assets of the screened key attention customers in the plurality of institutions through password sharing.
3. The method of claim 1, wherein, The data of the plurality of institutions includes group dimension data, and the group dimension data includes one or any combination of asset data, credit data, communication data, transaction data and identity data; The sub-models include a group risk confrontation sub-model, and the group risk confrontation sub-model adopts a risk atlas representation; The group risk confrontation sub-model training step comprises: Extracting risk features in the data of a plurality of institutions and the total assets of a plurality of customers in a group dimension as risk relationship attributes between the customers, the risk relationship attributes being expressed in probabilities; According to the risk relationship attributes, mining correlation attributes between the risk features as new risk relationship attributes; According to all the risk relationship attributes, constructing a risk map.
4. The method of claim 1, wherein, The data of the plurality of institutions includes data in a device dimension, which is collected by implanting a device risk probe on a device used by a customer; the data in the device dimension includes one or any combination of a device model, a screen resolution, CANVAS data, CPU information, a system version, a driver and a configuration; The sub-models include a device risk confrontation sub-model; The device risk confrontation sub-model training step includes: Extracting device features of the data in the device dimension; According to the device features and corresponding risk labels, training the device risk confrontation sub-model to obtain a trained device risk confrontation sub-model.
5. The method of claim 1, wherein, The data of the plurality of institutions includes data in a behavior dimension; The sub-models include a behavior risk confrontation sub-model; The behavior risk confrontation sub-model training step includes: Analyzing behavior data of a customer in a page operation process by using a machine learning method; According to the behavior data, identifying a transaction access sequence, the transaction access sequence features including sequence features of normal access and sequence features of attack access; According to the transaction access sequence, training the behavior risk confrontation sub-model to obtain a trained behavior risk confrontation sub-model.
6. The method of claim 1, wherein, The data of the plurality of institutions includes data in a transaction dimension; The sub-models include a transaction risk confrontation sub-model; The transaction risk confrontation sub-model training step includes: Extracting transaction features of the data in the transaction dimension, the transaction features including one or any combination of a counterparty, a time period, a card test and high frequency; According to the transaction features and corresponding risk labels, training the transaction risk confrontation sub-model to obtain a trained transaction risk confrontation sub-model.
7. The method of claim 1, wherein, Inputting the total assets of the screened focus customers and the data of the plurality of institutions into the risk confrontation model to determine risk levels of the screened focus customers, including: Inputting the total assets of the screened focus customers and the data of the plurality of institutions in a group dimension into a group risk confrontation sub-model to obtain probabilities corresponding to all risk relationship attributes connected with the focus customers and to calculate a comprehensive probability as a group risk calculated by the group risk confrontation sub-model; Inputting the data of the plurality of institutions in a traffic dimension of the screened focus customers into a traffic risk confrontation sub-model to obtain a data stealing behavior risk calculated by the traffic risk confrontation sub-model; Inputting the data of the plurality of institutions in a device dimension of the screened focus customers into a device risk confrontation sub-model to obtain a device risk calculated by the device risk confrontation sub-model; Inputting the data of the plurality of institutions in a behavior dimension of the screened focus customers into a behavior risk confrontation sub-model to obtain a sequence behavior risk calculated by the behavior risk confrontation sub-model; input the data of the transaction dimension of the multiple institutions of the screened focus customer into a transaction risk confrontation sub-model to obtain transaction risk calculated by the transaction risk confrontation sub-model; comprehensively analyze the group risk calculated by the group risk confrontation sub-model, the data theft behavior risk calculated by the traffic risk confrontation sub-model, the device risk calculated by the device risk confrontation sub-model, the sequential behavior risk calculated by the behavior risk confrontation sub-model, and the transaction risk calculated by the transaction risk confrontation sub-model to determine the risk level of the screened focus customer.
8. The method of claim 1, wherein, track the mobile phone number and associated account of the customer with the highest risk level in the 5G message page, including: receive customer information sent by the operator in the 5G message page, wherein the customer information is sent by the operator after identity authentication of the customer after receiving the service application of the customer with the highest risk level sent by the 5G client; track the dynamic data of the mobile phone number and associated account of the customer with the highest risk level, and screen out dynamic data that meets the preset tracking rule. 9.A 5G message based customer risk tracking apparatus, characterized by, including: a customer data collection module for collecting customer data of a customer to be analyzed in multiple institutions; a preliminary risk analysis module for performing preliminary risk analysis on the customer according to the data of the multiple institutions according to a preset condition to obtain a customer attention degree, wherein the customer attention degree includes focus attention and non-focus attention; a total asset amount multi-party exploration module for performing privacy set intersection and joint statistics on the data of the multiple institutions of the multiple focus customers to explore the total asset amount of the screened focus customers; a customer risk level determination module for inputting the total asset amount of the screened focus customers and the data of the multiple institutions into a risk confrontation model to determine the risk level of the screened focus customers; the risk confrontation model includes multiple sub-models, and each sub-model is obtained by training according to the data of one dimension of multiple customers in multiple institutions; wherein the data of the multiple institutions includes traffic dimension data, and the traffic dimension data includes normal application traffic data and risk attack traffic data; the sub-model includes a traffic risk confrontation sub-model; the traffic risk confrontation sub-model training step includes: sharding the traffic dimension data; identifying isolated traffic in the sharded traffic dimension data through an unsupervised model; converting time domain data of the traffic dimension data into frequency domain data through Fourier transform to identify timed traffic; determining the data theft behavior labels corresponding to the normal application traffic data and risk attack traffic data, isolated traffic, and timed traffic; training the traffic risk confrontation sub-model according to the normal application traffic data and risk attack traffic data, isolated traffic, timed traffic, and corresponding data theft behavior labels to obtain the trained traffic risk confrontation sub-model; the risk confrontation model obtains the risk calculated by each sub-model respectively after obtaining the total asset amount of the screened focus customers and the data of the multiple institutions, and then comprehensively analyzes the risks calculated by the multiple sub-models to obtain the risk level of the screened focus customers; A tracking module is configured to track the mobile phone number and the associated account of the customer with the highest risk level among the risk levels in the 5G message page.
10. A computer device comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, characterized in that, The processor implements the method in any one of claims 1-8 when executing the computer program.
11. A computer readable storage medium, characterized in that, The computer readable storage medium stores a computer program, and the computer program is executed by the processor to implement the method in any one of claims 1-8. The computer readable storage medium stores a computer program, and the computer program is executed by the processor to implement the method in any one of claims 1-8.
Citation Information
Patent Citations
Credit card anti-fraud prediction method based on dual-mode network diagram mining algorithm
CN108492173A
Risk prediction model training method and device
CN112330035A
Multi-party privacy set intersection method, device and system and storage medium
CN116090002A