Data processing method, device and equipment

By constructing graph structure data, calculating the similarity and matching degree of walking paths, determining the target score and filtering nodes, the problem of low risk group mining efficiency and accuracy is solved, and more efficient risk group identification is achieved.

CN119991304AActive Publication Date: 2025-05-13ANT ZHIXIN HANGZHOU INFORMATION TECH CO LTD
View PDF 9 Cites 0 Cited by

Patent Information

Application Number
CN202510464682.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-14
Publication Date
2025-05-13
Estimated Expiration
2045-04-14

AI Technical Summary

Technical Problem

When risk detection is performed on a group composed of multiple users, due to the large number of users and the complex relationship, the mining efficiency and accuracy of the risk groups are low.

Method used

By receiving the risk group mining request triggered by the target user, the target resource flow pattern is determined, and the graph structure data is constructed based on the resource flow relationship, the roaming path is obtained, the similarity and matching degree is calculated, the target score of the node is determined, the target node is filtered, and the target graph structure data is constructed to determine the risk group mining results.

Benefits of technology

It improves the mining efficiency and accuracy of risk groups, and can quickly and accurately perform node screening in complex resource flow relationships.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119991304A_ABST
    Figure CN119991304A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides a data processing method, device and equipment, and the method comprises the steps: in response to a risk group mining request, determining a target resource circulation mode corresponding to the risk group mining request, and graph structure data constructed according to the resource circulation relation of a first detection object; acquiring a first walk path corresponding to a first node and a second walk path corresponding to a second node according to the graph structure data; determining a target score of each second node according to the similarity between the first walk path and the second walk path and the matching degree between the second walk path and the target resource circulation mode; obtaining a target node according to the target score of each second node; and according to the target node, constructing target graph structure data corresponding to the first detection object, and according to the target graph structure data, determining a risk group mining result for the first detection object.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of computer technology, and in particular to a data processing method, device and equipment. Background Art

[0002] Since transaction risks often exist in the form of groups in the scenario of risk control for resource transfer, risk detection for groups has better risk mining potential and explainability compared to risk detection for a single user.

[0003] When performing risk detection on a group composed of multiple users, since the group contains many users and the relationships between users are relatively complex, the mining efficiency and accuracy of risk groups are low. Therefore, the embodiments of this specification provide a better technical solution for mining risk groups. Summary of the invention

[0004] The purpose of the embodiments of this specification is to provide a better technical solution for risk group mining.

[0005] In order to implement the above technical solution, the embodiments of this specification are implemented as follows: A data processing method provided by an embodiment of the present specification includes: receiving a risk group mining request for a first detection object triggered by a target user; determining, in response to the risk group mining request, a target resource flow pattern corresponding to the risk group mining request, and graph structure data constructed according to the resource flow relationship of the first detection object; acquiring, according to the graph structure data, a first wandering path corresponding to a first node, and a second wandering path corresponding to a second node, wherein the first node is a node corresponding to the first detection object in the graph structure data, and the second node is a node in the graph structure data that has a resource flow relationship with the first node; determining a target score for each second node according to a similarity between the first wandering path and the second wandering path, and a match between the second wandering path and the target resource flow pattern; screening the second nodes according to the target score of each second node to obtain a target node; constructing target graph structure data corresponding to the first detection object according to the target node, and determining a risk group mining result for the first detection object according to the target graph structure data.

[0006] A data processing device provided by an embodiment of the present specification includes: a request receiving module, configured to receive a risk group mining request for a first detection object triggered by a target user; a data acquisition module, configured to determine, in response to the risk group mining request, a target resource flow pattern corresponding to the risk group mining request, and graph structure data constructed according to the resource flow relationship of the first detection object; a path acquisition module, configured to acquire, according to the graph structure data, a first wandering path corresponding to a first node and a second wandering path corresponding to a second node, wherein the first node is a node corresponding to the first detection object in the graph structure data, and the second node is a node having a resource flow relationship with the first node in the graph structure data; a score determination module, configured to determine a target score for each second node according to a similarity between the first wandering path and the second wandering path, and a match between the second wandering path and the target resource flow pattern; a node determination module, configured to screen the second nodes according to the target score of each second node to obtain a target node; and a result determination module, configured to construct target graph structure data corresponding to the first detection object according to the target node, and determine a risk group mining result for the first detection object according to the target graph structure data.

[0007] A data processing device provided by an embodiment of the present specification includes: a processor; and a memory arranged to store computer executable instructions, wherein when the executable instructions are executed, the processor: receives a risk group mining request for a first detection object triggered by a target user; determines, in response to the risk group mining request, a target resource flow pattern corresponding to the risk group mining request, and graph structure data constructed according to the resource flow relationship of the first detection object; obtains, according to the graph structure data, a first wandering path corresponding to a first node, and a second wandering path corresponding to a second node, wherein the first node is a node corresponding to the first detection object in the graph structure data, and the second node is a node in the graph structure data that has a resource flow relationship with the first node; determines a target score for each second node according to a similarity between the first wandering path and the second wandering path, and a matching degree between the second wandering path and the target resource flow pattern; performs screening processing on the second nodes according to the target score of each second node to obtain a target node; constructs target graph structure data corresponding to the first detection object according to the target node, and determines a risk group mining result for the first detection object according to the target graph structure data.

[0008] The embodiment of the present specification also provides a storage medium, the storage medium is used to store computer executable instructions, and the executable instructions implement the following process when executed by a processor: receiving a risk group mining request for a first detection object triggered by a target user; in response to the risk group mining request, determining a target resource flow pattern corresponding to the risk group mining request, and graph structure data constructed according to the resource flow relationship of the first detection object; according to the graph structure data, obtaining a first wandering path corresponding to a first node, and a second wandering path corresponding to a second node, the first node is a node corresponding to the first detection object in the graph structure data, and the second node is a node in the graph structure data that has a resource flow relationship with the first node; determining a target score for each second node according to a similarity between the first wandering path and the second wandering path, and a match between the second wandering path and the target resource flow pattern; screening the second nodes according to the target score of each second node to obtain a target node; according to the target node, constructing a target graph structure data corresponding to the first detection object, and determining a risk group mining result for the first detection object according to the target graph structure data.

[0009] The embodiment of the present specification also provides a computer program product, including a computer program, which implements the following process when executed by a processor: receiving a risk group mining request for a first detection object triggered by a target user; in response to the risk group mining request, determining a target resource flow pattern corresponding to the risk group mining request, and graph structure data constructed according to the resource flow relationship of the first detection object; according to the graph structure data, obtaining a first wandering path corresponding to a first node, and a second wandering path corresponding to a second node, the first node being a node corresponding to the first detection object in the graph structure data, and the second node being a node in the graph structure data that has a resource flow relationship with the first node; determining a target score for each second node according to a similarity between the first wandering path and the second wandering path, and a match between the second wandering path and the target resource flow pattern; screening the second nodes according to the target score of each second node to obtain a target node; constructing a target graph structure data corresponding to the first detection object according to the target node, and determining a risk group mining result for the first detection object according to the target graph structure data. BRIEF DESCRIPTION OF THE DRAWINGS

[0010] In order to more clearly illustrate the technical solutions in the embodiments of this specification or the prior art, the drawings required for use in the embodiments or the prior art description will be briefly introduced below. Obviously, the drawings described below are only some embodiments recorded in this specification. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative labor. Figure 1 A flowchart of a data processing method in this specification; Figure 2 This is a schematic diagram of a resource flow model for this manual; Figure 3 A schematic diagram of a process for determining a target score of a node in this specification; Figure 4 A flowchart of a matching degree determination process in this specification; Figure 5 This is a schematic diagram of matching processing according to the encoding result of this specification; Figure 6 This is a flowchart of a target node determination process of this specification; Figure 7 This is a flowchart of a risk group mining process in this specification; Figure 8 A schematic diagram of a topological structure of this specification; Fig. 9 This is a flow chart of data processing using a large language model in this specification; Fig.10 A schematic diagram of an interaction process between a user and an interactive group mining system in this specification; Fig.11 This is a flowchart of a process for determining a walking path in this specification; Fig.12 A schematic diagram of a data processing device in this specification; Fig.13 This is a structural schematic diagram of a data processing device in this specification. DETAILED DESCRIPTION

[0011] The embodiments of this specification provide a data processing method, device and equipment.

[0012] In order to enable those skilled in the art to better understand the technical solutions in this specification, the technical solutions in the embodiments of this specification will be clearly and completely described below in conjunction with the drawings in the embodiments of this specification. Obviously, the described embodiments are only part of the embodiments of this specification, not all of the embodiments. Based on the embodiments in this specification, all other embodiments obtained by ordinary technicians in this field without creative work should fall within the scope of protection of this specification.

[0013] The embodiments of the present specification provide a better processing mechanism for risk group mining, by receiving a risk group mining request for a first detection object triggered by a target user, responding to the risk group mining request, determining a target resource flow pattern corresponding to the risk group mining request, and graph structure data constructed according to the resource flow relationship of the first detection object, and then, according to the graph structure data, obtaining a first wandering path corresponding to the first node and a second wandering path corresponding to the second node, wherein the first node may be a node corresponding to the first detection object in the graph structure data, and the second node may be a node having a resource flow relationship with the first node in the graph structure data, determining a target score for each second node according to the similarity between the first wandering path and the second wandering path, and a matching degree between the second wandering path and the target resource flow pattern, and screening the second nodes according to the target score of each second node to obtain a target node, and finally, constructing a target graph structure data corresponding to the first detection object according to the target node, and determining a risk group mining result for the first detection object according to the target graph structure data. In this way, in combination with the target resource flow pattern corresponding to the risk group mining request, the target score of each first node's neighbor node (i.e., the second node) can be determined in a targeted manner through the similarity between the first wandering path and the second wandering path, and the matching degree between the second wandering path and the target resource flow pattern, so that when the resource flow relationship of the first detection object is relatively complex, the node screening process can be performed quickly and accurately according to the target score of the second node, so as to determine the risk group mining result according to the screened target node, thereby improving the mining efficiency and mining accuracy of the risk group. For specific processing, please refer to the specific content in the following embodiments.

[0014] like Figure 1 As shown, the embodiment of this specification provides a data processing method, and the execution subject of the method can be a server, wherein the server can be an independent server, or a server cluster composed of multiple servers, etc. In this embodiment, the execution subject is taken as an example to be described in detail, and the method can specifically include the following steps: In step S102, a risk group mining request for a first detection object triggered by a target user is received.

[0015] The target user may be any user, and the first detection object may include objects such as account objects and user objects.

[0016] In implementation, since the accuracy of risk detection on a single object is low, the risk detection process can be performed on the object to be detected by mining the risk group of the object to be detected to improve the accuracy of risk detection on a single object.

[0017] The risk group may be a group formed by the first detection object and multiple other objects, and the resource flow pattern between the multiple objects in the risk group matches the target resource flow pattern.

[0018] For example, taking the target user as a registered user of a resource transfer application, the target user can trigger a risk group mining request for a certain account (or a certain user) before triggering the resource transfer behavior for the account (or the user). At this time, the server can determine the account (or user) selected by the target user as the first detection object.

[0019] In addition, there may be multiple first detection objects. For example, the target user may trigger a risk group mining request for multiple first detection objects having a resource transfer relationship, so as to mine the risk group containing the multiple first detection objects.

[0020] In step S104, in response to the risk group mining request, a target resource flow pattern corresponding to the risk group mining request and graph structure data constructed according to the resource flow relationship of the first detection object are determined.

[0021] The target resource flow mode can be used to characterize the resource flow relationship between an object and other objects. For example, the target resource flow mode can include collection, circulation, refund and other modes. Figure 2 As shown, the collection mode can be used to characterize that the amount of resource inflow of an object is greater than the amount of resource outflow, and the refund mode can be used to characterize that the amount of resource outflow of an object is greater than the amount of resource inflow.

[0022] In implementation, the server can determine the target resource flow pattern corresponding to the risk group mining request based on the pattern identifier of the resource flow pattern carried in the risk group mining request. Alternatively, the server can also perform pattern extraction processing on the input data of the target user to obtain the target resource flow pattern. Alternatively, the server can also determine the risk type of the first detection object based on the historical resource flow data of the first detection object according to a pre-trained risk detection model, and determine the resource flow pattern corresponding to the risk type of the first detection object according to the preset object relationship between the risk type and the resource flow model, so as to determine the determined resource flow pattern as the target resource flow pattern.

[0023] The method for determining the target resource flow pattern corresponding to the above-mentioned risk group mining request is an optional and feasible determination method. In actual application scenarios, there may be a variety of different determination methods. Different determination methods can be selected according to different actual application scenarios. The embodiments of this specification do not make specific limitations on this.

[0024] The server may obtain historical resource flow data corresponding to the object identifier within a preset detection period according to the object identifier of the first detection object carried in the risk group mining request, and construct graph structure data corresponding to the first detection object according to the obtained historical resource flow data.

[0025] Among them, the graph structure data may include nodes corresponding to the first detection object, nodes corresponding to objects that have a resource flow relationship with the first detection object, and node association relationships constructed based on the resource flow relationship between objects (i.e., the first detection object, and the object that has a resource flow relationship with the first detection object).

[0026] In addition, the risk group mining request can also carry the target object type. The server can filter out the second detection object corresponding to the target object type based on the target object type and the historical resource flow data corresponding to the first detection object, and construct graph structure data corresponding to the first detection object based on the first detection object and the second detection object.

[0027] For example, taking the target object type as account type, the server can filter out detection objects of account type in the historical resource flow data, and determine the filtered detection objects as the second detection objects, and construct graph structure data corresponding to the first detection object based on the historical resource flow data of the first detection object within a preset detection period and the historical resource flow data of the second detection object.

[0028] The method for constructing the graph structure data corresponding to the above-mentioned first detection object is an optional and feasible construction method. In actual application scenarios, there may be a variety of different construction methods. Different construction methods can be selected according to different actual application scenarios. The embodiments of this specification do not make specific limitations on this.

[0029] In step S106, a first walking path corresponding to the first node and a second walking path corresponding to the second node are acquired according to the graph structure data.

[0030] Among them, the first node can be a node in the graph structure data corresponding to the first detection object, the second node is a node in the graph structure data that has a resource flow relationship with the first node, the first walking path can be one or more walking paths constructed by random walking processing with the first node as the center node, and the second walking path can be one or more walking paths constructed by random walking processing with the second node as the center node. For example, the server can use the first node as the center node and perform random walking processing according to a preset number of nodes to obtain a walking path.

[0031] In implementation, the server may utilize a heuristic algorithm to determine, based on the graph structure data, a first wandering path corresponding to the first node and a second wandering path corresponding to the second node.

[0032] Among them, heuristic algorithms can be problem-solving methods based on experience and heuristic rules, which can approach the ideal answer by guiding the search process without exhausting all possibilities.

[0033] In step S108, a target score of each second node is determined according to the similarity between the first wandering path and the second wandering path, and the matching degree between the second wandering path and the target resource flow pattern.

[0034] In implementation, the server may determine the similarity between the first wandering path and the second wandering path according to a preset similarity algorithm, for example, Figure 3 As shown, the server can use the Jacard similarity algorithm to calculate the intersection-and-union ratio between the number of nodes included in the first wandering path and the number of nodes included in the second wandering path, and determine the calculated result as the similarity between the first wandering path and the second wandering path.

[0035] Similarly, the server may also use the Jacard similarity algorithm to determine the matching degree between the second wandering path and the target resource flow pattern.

[0036] The similarity between the first wandering path and the second wandering path can measure the aggregation score of the second wandering path, and the matching degree between the second wandering path and the target resource flow pattern can be used to measure the characterization strength of the second wandering path for the target resource flow pattern (original path).

[0037] The server may determine the target score of each second node according to preset hyperparameters, the similarity between the first wandering path and the second wandering path, and the matching degree between the second wandering path and the target resource flow pattern.

[0038] That is, the server may determine the target score of the second node according to the following formula.

[0039]

[0040] in, is the similarity between the first and second walking paths, is the matching degree between the second wandering path and the target resource flow pattern, The preset hyperparameters can be used to balance the similarity between the first wandering path and the second wandering path, and the importance of the matching degree between the second wandering path and the target resource flow pattern. The preset hyperparameters can select different values ​​according to different actual application scenarios, and the embodiments of this specification do not make specific limitations on this.

[0041] In this way, starting from the first node, the neighboring nodes (i.e., the second node) can be gradually included in the risk group. Among them, the scoring mechanism can be used to determine whether the neighboring node should be included, thereby screening out the target node. During the entire diffusion process, the wandering path of the neighboring node will be matched with the meta-path group (i.e., the target resource flow pattern) input as explicit information, thereby generating a meta-path matching score (i.e., the matching degree between the second wandering path and the target resource flow pattern). These pre-defined meta-path groups can be derived from the pattern extraction and characterization of real group cases. Therefore, the original path matching score can effectively reflect whether the neighboring node meets the characteristics of the real risk group. In addition, the scoring mechanism also includes a clustering score (i.e., the similarity between the first wandering path and the second wandering path), which together with the meta-path matching score constitutes the total score of the neighboring node (i.e., the target score).

[0042] In step S110, the second nodes are screened according to the target score of each second node to obtain a target node.

[0043] In implementation, the server may sort the second nodes according to the target score of each second node, and determine the target node according to the sorted second nodes.

[0044] Alternatively, the server may also screen the second nodes according to the score threshold corresponding to the first detection object and the target score of each second node to obtain the target node. There are also various methods for determining the target node, and different determination methods may be selected according to different actual application scenarios, which are not specifically limited in the embodiments of this specification.

[0045] In step S112, target graph structure data corresponding to the first detection object is constructed according to the target node, and a risk group mining result for the first detection object is determined according to the target graph structure data.

[0046] In implementation, the server may construct target graph structure data corresponding to the first detection object based on the target node, the first node corresponding to the first detection object, the resource flow relationship between the target nodes, and the resource flow relationship between the target node and the first node.

[0047] The server may determine the target graph structure data as the risk group mining result for the first detection object, or the server may also generate the risk group mining result for the first detection object according to the target graph structure data by using a large language model.

[0048] The embodiment of the present specification provides a data processing method, which receives a risk group mining request for a first detection object triggered by a target user, and in response to the risk group mining request, determines a target resource flow pattern corresponding to the risk group mining request, and graph structure data constructed according to the resource flow relationship of the first detection object. Then, according to the graph structure data, a first wandering path corresponding to the first node and a second wandering path corresponding to the second node can be obtained, wherein the first node can be a node corresponding to the first detection object in the graph structure data, and the second node can be a node in the graph structure data that has a resource flow relationship with the first node. According to the similarity between the first wandering path and the second wandering path, and the matching degree between the second wandering path and the target resource flow pattern, a target score of each second node is determined, so that the second nodes are screened and processed according to the target score of each second node to obtain the target node. Finally, according to the target node, target graph structure data corresponding to the first detection object can be constructed, and according to the target graph structure data, a risk group mining result for the first detection object is determined. In this way, in combination with the target resource flow pattern corresponding to the risk group mining request, the target score of the neighbor node (i.e., the second node) of each first node can be determined in a targeted manner through the similarity between the first wandering path and the second wandering path, and the matching degree between the second wandering path and the target resource flow pattern. When the resource flow relationship of the first detection object is relatively complex, the node screening process can be quickly and accurately performed according to the target score of the second node, so as to determine the risk group mining result according to the screened target node, thereby improving the mining efficiency and mining accuracy of the risk group.

[0049] In practical applications, before determining the target score of each second node, the matching degree between the second wandering path and the target resource flow mode may also be determined. There are many ways to determine the matching degree. An optional processing method is provided below. Figure 4 As shown, the processing may specifically include the following steps S402 to S404.

[0050] In step S402, according to a preset encoding rule, the second wandering path and the target resource flow mode are encoded respectively to obtain a first encoding result corresponding to the second wandering path and a second encoding result corresponding to the target resource flow mode.

[0051] In practical applications, the preset encoding rules may include prefix tree encoding rules and suffix tree encoding rules. The prefix tree encoding rules may mean that when encoding a character set, the encoding of any character in the character set is not a prefix of the encoding of other characters. The suffix tree encoding rules can be used to represent all suffixes of a string. The suffix tree may be composed of a root node and multiple paths, each path representing a string suffix. The suffix tree stores common prefixes through path compression, which can greatly reduce space occupancy. Each leaf node can represent a suffix of a string and store the position of the suffix in the original string. The suffix tree can quickly complete pattern matching operations.

[0052] In implementation, Figure 5 As shown, the server can encode the second wandering path and the target resource flow mode according to the prefix tree encoding rule or the suffix tree encoding rule, respectively, so as to improve the matching efficiency through the first encoding result and the second encoding result obtained by encoding.

[0053] In step S404, the matching degree between the second walking path and the target resource flow mode is determined according to the similarity between the first encoding result and the second encoding result.

[0054] In implementation, the server may determine the similarity between the first encoding result and the second encoding result as the matching degree between the second walking path and the target resource flow mode.

[0055] In practical applications, in step S110, the second nodes are screened according to the target score of each second node, and the specific processing method for obtaining the target node can be various, such as Figure 6 As shown, the processing may specifically include the following steps S1102 to S1106.

[0056] In step S1102, historical resource flow data of a second detection object corresponding to the second node is obtained. The historical resource flow data may be data related to resource flow (such as data flow quantity, resource flow time, data flow object, etc.) involved in the resource flow processing performed by the second detection object within a preset detection period.

[0057] In step S1104, according to the pre-trained risk detection model, based on the historical resource flow data of the second detection object, risk detection processing is performed on the second detection object to obtain a risk score of the second detection object.

[0058] Among them, the risk detection model can be a model built based on a preset machine learning algorithm.

[0059] During implementation, the server can train the risk detection model according to a supervised training method to obtain a trained risk detection model, and based on the pre-trained risk detection model and the historical resource flow data of the second detection object, perform risk detection processing on the second detection object to obtain a risk score for the second detection object.

[0060] In step S1106, the second nodes are screened according to the target score of each second node and the risk score of the second detection object corresponding to each second node to obtain the target node.

[0061] In implementation, the server can determine the first score corresponding to each second node based on the preset weight, the target score of each second node, and the risk score of the second detection object corresponding to each second node, and screen the second nodes according to the first integral value of each second node to obtain the target node.

[0062] In this way, the server can use the existing data set and annotation information to train a supervised learning model (i.e., risk detection model). The trained risk detection model can be used to evaluate and score newly added data or nodes to identify effective expansion nodes (i.e., target nodes).

[0063] In practical applications, after the risk group mining results are determined, the risk group mining results can also be sent to the target user, and the risk group mining request of the target user for the risk group mining results can be received to continue the risk group mining process. The specific processing methods for continuing the risk group mining process can be various. The following is an optional processing method, such as Figure 7 As shown, the processing may specifically include the following steps S702 to S704.

[0064] In step S702, the risk group mining result is fed back to the target user, and when a risk group mining request for the risk group mining result is received from the target user, an object corresponding to a node in the target graph structure data is determined as a first detection object.

[0065] During implementation, the server can feed back the risk group mining results to the target user. If the target user determines that the received risk group mining results do not meet the mining requirements (such as the number of objects included in the risk group mining results does not meet the preset number requirements, etc.), the target user can trigger a risk group mining request for the risk group mining results.

[0066] Upon receiving a risk group mining request from a target user for a risk group mining result, the server may determine an object corresponding to a node in the target graph structure data as a first detection object.

[0067] In step S704, risk group mining processing is continued according to the target resource flow pattern and the first detection object to obtain a risk group mining result for the first detection object.

[0068] During implementation, the server can continue to perform risk group mining processing on each first detection object based on the target resource flow pattern and each first detection object, and obtain the risk group mining results for each first detection object. Then, the server can summarize the risk group mining results of each first detection object and feed back the summarized risk group mining results to the target user again.

[0069] In practical applications, the target resource flow mode may include topology structure data for representing multiple resource flow modes, and / or text description data containing multiple resource flow modes.

[0070] For example, the target resource transfer mode can be Figure 8 The topological structure shown, the topological structure data may include a collection mode and a refund mode, or the target resource flow mode may also be text description data such as: "collection->flow->refund".

[0071] In this way, through the predefined topology structure data, the server can automatically determine the addition of nodes, so as to make it well interpretable through the reasonably designed topology structure data.

[0072] In practical applications, the specific processing methods for determining the target resource flow mode corresponding to the risk group mining request in the above step S104 and constructing the graph structure data according to the resource flow relationship of the first detection object can be varied. An optional processing method is provided below, such as Fig. 9 As shown, the processing may specifically include the following steps S1042 to S1044.

[0073] In step S1042, input data of the target user corresponding to the risk group mining request is obtained.

[0074] In step S1044, the preset large language model is used to determine the first detection object corresponding to the risk group mining request, the target resource flow pattern, and the graph structure data constructed according to the resource flow relationship of the first detection object according to the input data of the target user.

[0075] In implementation, Fig.10As shown, the target user can input a risk group mining request for a first detection object in an interactive group mining system built based on a large language model (LLM). The server can use a preset large language model to determine the first detection object and the target resource flow mode corresponding to the risk group mining request, as well as graph structure data constructed based on the resource flow relationship of the first detection object according to the input data of the target user.

[0076] In this way, on the one hand, the server can use the natural language processing capabilities of the large language model to parse the resource flow patterns between manually specified group members, thereby assisting in identifying and mining group behaviors. On the other hand, through the interactive group mining system, users can guide the group mining process by entering specific queries, adjusting parameters, or providing feedback. The interactive group mining system can update and display the mining results in real time based on the interaction with the user.

[0077] In general, the interactive group mining system can be built based on a large language model (LLM), which can help users quickly identify and mine groups associated with specific customers. Users can enter natural language requests, for example, to query group information of specific customers and the fund transaction pattern of the group. After receiving the user's request, the system can use the built-in mining algorithm to perform data analysis based on the established resource flow pattern (such as collection -> circulation -> refund), thereby identifying the group related to the customer entered by the user (such as the user identified as 2088××8912).

[0078] In addition, if Fig.10 As shown, when the target user re-enters the first risk group mining request in the interactive group mining system, the server can perform a 2-hop expansion to present the basic structure and members of the mined risk groups.

[0079] After obtaining preliminary results, the target user can further request the system to expand and seek more extensive group information. At this stage, LLM can increase the expansion range to 4 hops according to the target user's instructions to further explore potential group members and their interactive relationships. This process can not only improve the comprehensiveness of information, but also enhance users' understanding of group behavior patterns. The entire system can reduce the difficulty of operation for non-professional users through a highly adaptive interactive method, making complex data mining tasks more intuitive and efficient.

[0080] Through advanced natural language processing technology, combined with an interactive user interface, it can provide users with an intuitive, flexible and efficient risk group identification tool. It can adapt to the ever-changing risk resource flow model and provide regulators with a powerful risk management and prevention tool.

[0081] In practical applications, the specific processing methods for obtaining the first wandering path corresponding to the first node and the second wandering path corresponding to the second node according to the graph structure data in the above step S106 can be various, and the instruction variation can include instruction-level variation. Accordingly, an optional processing method is provided below, such as Fig.11 As shown, the processing may specifically include the following steps S1062 to S1064.

[0082] In step S1062, a preset large language model is used to determine a search level requirement corresponding to the risk group mining request according to the input data of the target user.

[0083] Among them, the search level may include high level, medium level, etc.

[0084] In implementation, the server can utilize the text understanding capability of the large language model to parse the input data of the target user to determine the retrieval level requirement corresponding to the risk group mining request.

[0085] In this way, the server can transform qualitative natural language descriptions into quantitative pattern recognition tasks through the powerful capabilities of LLM, thereby accurately discovering potential risk groups in massive data. This can not only improve the accuracy of recognition, but also enhance the response speed and adaptability to emerging risk data flow patterns.

[0086] In step S1064, the walk order is determined according to the search level requirement, and based on the walk order and the graph structure data, a first walk path and a second walk path are obtained.

[0087] Among them, the walk order can refer to the average number of steps from a node to another node after n steps in the random walk process. For example, taking the walk order as 2 as an example, the server can take the first node as the central node, obtain node 1 adjacent to the first node after 1 step, and obtain node 2 adjacent to node 1 after another step. Finally, the first walk path can be constructed based on the first node, node 1 and node 2.

[0088] In implementation, the server can determine the wandering order according to a preset correspondence between the retrieval level and the wandering order. Then, based on the wandering order and according to the graph structure data, the server can perform node wandering processing with the first node as the center node to obtain a first wandering path, and perform node wandering processing with the second node as the center node to obtain a second wandering path.

[0089] The embodiment of the present specification provides a data processing method, which receives a risk group mining request for a first detection object triggered by a target user, and in response to the risk group mining request, determines a target resource flow pattern corresponding to the risk group mining request, and graph structure data constructed according to the resource flow relationship of the first detection object. Then, according to the graph structure data, a first wandering path corresponding to the first node and a second wandering path corresponding to the second node can be obtained, wherein the first node can be a node corresponding to the first detection object in the graph structure data, and the second node can be a node in the graph structure data that has a resource flow relationship with the first node. According to the similarity between the first wandering path and the second wandering path, and the matching degree between the second wandering path and the target resource flow pattern, a target score of each second node is determined, so that the second nodes are screened and processed according to the target score of each second node to obtain the target node. Finally, according to the target node, target graph structure data corresponding to the first detection object can be constructed, and according to the target graph structure data, a risk group mining result for the first detection object is determined. In this way, in combination with the target resource flow pattern corresponding to the risk group mining request, the target score of the neighbor node (i.e., the second node) of each first node can be determined in a targeted manner through the similarity between the first wandering path and the second wandering path, and the matching degree between the second wandering path and the target resource flow pattern. When the resource flow relationship of the first detection object is relatively complex, the node screening process can be quickly and accurately performed according to the target score of the second node, so as to determine the risk group mining result according to the screened target node, thereby improving the mining efficiency and mining accuracy of the risk group.

[0090] The above is a data processing method provided in the embodiments of this specification. Based on the same idea, the embodiments of this specification also provide a data processing device, such as Fig.12 shown.

[0091] The data processing device includes: a request receiving module 1201, a data acquiring module 1202, a path acquiring module 1203, a score determining module 1204, a node determining module 1205 and a result determining module 1206, wherein: The request receiving module 1201 is used to receive a risk group mining request for a first detection object triggered by a target user; The data acquisition module 1202 is used to determine, in response to the risk group mining request, a target resource flow pattern corresponding to the risk group mining request and graph structure data constructed according to the resource flow relationship of the first detection object; A path acquisition module 1203 is used to acquire, according to the graph structure data, a first wandering path corresponding to a first node and a second wandering path corresponding to a second node, wherein the first node is a node in the graph structure data corresponding to the first detection object, and the second node is a node in the graph structure data having a resource flow relationship with the first node; A score determination module 1204, configured to determine a target score for each second node according to a similarity between the first wandering path and the second wandering path, and a matching degree between the second wandering path and the target resource flow pattern; A node determination module 1205 is used to screen the second nodes according to the target score of each second node to obtain a target node; The result determination module 1206 is used to construct target graph structure data corresponding to the first detection object according to the target node, and determine the risk group mining result for the first detection object according to the target graph structure data.

[0092] In the embodiment of this specification, the device further includes: A data encoding module, configured to encode the second wandering path and the target resource flow mode according to a preset encoding rule, respectively, to obtain a first encoding result corresponding to the second wandering path and a second encoding result corresponding to the target resource flow mode; A result matching module is used to determine the matching degree between the second walking path and the target resource flow mode according to the similarity between the first encoding result and the second encoding result.

[0093] In the embodiment of this specification, the preset encoding rules include prefix tree encoding rules and suffix tree encoding rules.

[0094] In the embodiment of this specification, the node determination module 1205 is used to: Acquire historical resource flow data of a second detection object corresponding to the second node; According to the pre-trained risk detection model, based on the historical resource flow data of the second detection object, risk detection processing is performed on the second detection object to obtain a risk score of the second detection object; According to the target score of each of the second nodes and the risk score of the second detection object corresponding to each of the second nodes, the second nodes are screened to obtain the target nodes.

[0095] In the embodiment of this specification, the device further includes: A result feedback module is used to feed back the risk group mining result to the target user, and upon receiving a risk group mining request from the target user for the risk group mining result, determine the object corresponding to the node in the target graph structure data as the first detection object; The group mining module is used to continue to perform risk group mining processing according to the target resource flow mode and the first detection object to obtain a risk group mining result for the first detection object.

[0096] In the embodiment of the present specification, the target resource flow mode includes topology structure data for representing multiple resource flow modes, and / or text description data containing multiple resource flow modes.

[0097] In the embodiment of this specification, the data acquisition module 1202 is used to: Acquire input data of the target user corresponding to the risk group mining request; By using a preset large language model, according to the input data of the target user, a first detection object corresponding to the risk group mining request, the target resource flow mode, and graph structure data constructed according to the resource flow relationship of the first detection object are determined.

[0098] In the embodiment of this specification, the path acquisition module 1203 is used to: Using the preset large language model, according to the input data of the target user, determining a search level requirement corresponding to the risk group mining request; According to the retrieval level requirement, a walking order is determined, and based on the walking order and according to the graph structure data, the first walking path and the second walking path are acquired.

[0099] An embodiment of the present specification provides a data processing device, which receives a risk group mining request for a first detection object triggered by a target user, and in response to the risk group mining request, determines a target resource flow pattern corresponding to the risk group mining request, and graph structure data constructed according to the resource flow relationship of the first detection object. Then, according to the graph structure data, a first wandering path corresponding to the first node and a second wandering path corresponding to the second node can be obtained, wherein the first node can be a node corresponding to the first detection object in the graph structure data, and the second node can be a node in the graph structure data that has a resource flow relationship with the first node. According to the similarity between the first wandering path and the second wandering path, and the matching degree between the second wandering path and the target resource flow pattern, a target score of each second node is determined, so that the second nodes are screened and processed according to the target score of each second node to obtain a target node. Finally, according to the target node, target graph structure data corresponding to the first detection object can be constructed, and according to the target graph structure data, a risk group mining result for the first detection object is determined. In this way, in combination with the target resource flow pattern corresponding to the risk group mining request, the target score of the neighbor node (i.e., the second node) of each first node can be determined in a targeted manner through the similarity between the first wandering path and the second wandering path, and the matching degree between the second wandering path and the target resource flow pattern. When the resource flow relationship of the first detection object is relatively complex, the node screening process can be quickly and accurately performed according to the target score of the second node, so as to determine the risk group mining result according to the screened target node, thereby improving the mining efficiency and mining accuracy of the risk group.

[0100] The above is a data processing device provided in the embodiment of this specification. Based on the same idea, the embodiment of this specification also provides a data processing device, such as Fig.13 shown.

[0101] The data processing device may provide a terminal device or a server, etc. for the above-mentioned embodiments.

[0102] The data processing device may have relatively large differences due to different configurations or performances, and may include one or more processors 1301 and memory 1302, and the memory 1302 may store one or more storage applications or data. Among them, the memory 1302 may be a temporary storage or a permanent storage. The application stored in the memory 1302 may include one or more modules (not shown in the figure), and each module may include a series of computer executable instructions in the data processing device. Furthermore, the processor 1301 may be configured to communicate with the memory 1302 and execute a series of computer executable instructions in the memory 1302 on the data processing device. The data processing device may also include one or more power supplies 1303, one or more wired or wireless network interfaces 1304, one or more input and output interfaces 1305, and one or more keyboards 1306.

[0103] Specifically in this embodiment, the data processing device includes a memory and one or more programs, wherein the one or more programs are stored in the memory, and the one or more programs may include one or more modules, and each module may include a series of computer executable instructions in the data processing device, and the one or more programs are configured to be executed by one or more processors, including computer executable instructions for performing the following: Receiving a risk group mining request for a first detection object triggered by a target user; In response to the risk group mining request, determining a target resource flow pattern corresponding to the risk group mining request and graph structure data constructed according to a resource flow relationship of the first detection object; According to the graph structure data, a first wandering path corresponding to a first node and a second wandering path corresponding to a second node are acquired, wherein the first node is a node corresponding to the first detection object in the graph structure data, and the second node is a node in the graph structure data that has a resource flow relationship with the first node; Determining a target score for each second node according to a similarity between the first wandering path and the second wandering path, and a matching degree between the second wandering path and the target resource flow pattern; According to the target score of each of the second nodes, the second nodes are screened to obtain a target node; According to the target node, target graph structure data corresponding to the first detection object is constructed, and according to the target graph structure data, a risk group mining result for the first detection object is determined.

[0104] Each embodiment in this specification is described in a progressive manner, and the same or similar parts between the embodiments can be referred to each other, and each embodiment focuses on the differences from other embodiments. In particular, for the data processing device embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and the relevant parts can be referred to the partial description of the method embodiment.

[0105] An embodiment of the present specification provides a data processing device, which receives a risk group mining request for a first detection object triggered by a target user, and in response to the risk group mining request, determines a target resource flow pattern corresponding to the risk group mining request, and graph structure data constructed according to the resource flow relationship of the first detection object. Then, according to the graph structure data, a first wandering path corresponding to the first node and a second wandering path corresponding to the second node can be obtained, wherein the first node can be a node corresponding to the first detection object in the graph structure data, and the second node can be a node in the graph structure data that has a resource flow relationship with the first node. According to the similarity between the first wandering path and the second wandering path, and the matching degree between the second wandering path and the target resource flow pattern, a target score of each second node is determined, so that the second nodes are screened and processed according to the target score of each second node to obtain a target node. Finally, according to the target node, target graph structure data corresponding to the first detection object can be constructed, and according to the target graph structure data, a risk group mining result for the first detection object is determined. In this way, in combination with the target resource flow pattern corresponding to the risk group mining request, the target score of the neighbor node (i.e., the second node) of each first node can be determined in a targeted manner through the similarity between the first wandering path and the second wandering path, and the matching degree between the second wandering path and the target resource flow pattern. When the resource flow relationship of the first detection object is relatively complex, the node screening process can be quickly and accurately performed according to the target score of the second node, so as to determine the risk group mining result according to the screened target node, thereby improving the mining efficiency and mining accuracy of the risk group.

[0106] Furthermore, based on the above Figures 1 to 11 One or more embodiments of this specification further provide a storage medium for storing computer executable instruction information. In a specific embodiment, the storage medium may be a USB flash drive, an optical disk, a hard disk, etc. When the computer executable instruction information stored in the storage medium is executed by the processor, the following process can be implemented: Receiving a risk group mining request for a first detection object triggered by a target user; In response to the risk group mining request, determining a target resource flow pattern corresponding to the risk group mining request and graph structure data constructed according to a resource flow relationship of the first detection object; According to the graph structure data, a first wandering path corresponding to a first node and a second wandering path corresponding to a second node are acquired, wherein the first node is a node corresponding to the first detection object in the graph structure data, and the second node is a node in the graph structure data that has a resource flow relationship with the first node; Determining a target score for each second node according to a similarity between the first wandering path and the second wandering path, and a matching degree between the second wandering path and the target resource flow pattern; According to the target score of each of the second nodes, the second nodes are screened to obtain a target node; According to the target node, target graph structure data corresponding to the first detection object is constructed, and according to the target graph structure data, a risk group mining result for the first detection object is determined.

[0107] Each embodiment in this specification is described in a progressive manner, and the same or similar parts between the embodiments can be referred to each other, and each embodiment focuses on the differences from other embodiments. In particular, for the above-mentioned storage medium embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and the relevant parts can be referred to the partial description of the method embodiment.

[0108] An embodiment of the present specification provides a storage medium, which receives a risk group mining request for a first detection object triggered by a target user, and in response to the risk group mining request, determines a target resource flow pattern corresponding to the risk group mining request, and graph structure data constructed according to the resource flow relationship of the first detection object. Then, according to the graph structure data, a first wandering path corresponding to the first node and a second wandering path corresponding to the second node can be obtained, wherein the first node can be a node corresponding to the first detection object in the graph structure data, and the second node can be a node in the graph structure data that has a resource flow relationship with the first node. According to the similarity between the first wandering path and the second wandering path, and the matching degree between the second wandering path and the target resource flow pattern, a target score of each second node is determined, so that the second nodes are screened and processed according to the target score of each second node to obtain a target node. Finally, according to the target node, target graph structure data corresponding to the first detection object can be constructed, and according to the target graph structure data, a risk group mining result for the first detection object is determined. In this way, in combination with the target resource flow pattern corresponding to the risk group mining request, the target score of the neighbor node (i.e., the second node) of each first node can be determined in a targeted manner through the similarity between the first wandering path and the second wandering path, and the matching degree between the second wandering path and the target resource flow pattern. When the resource flow relationship of the first detection object is relatively complex, the node screening process can be quickly and accurately performed according to the target score of the second node, so as to determine the risk group mining result according to the screened target node, thereby improving the mining efficiency and mining accuracy of the risk group.

[0109] Furthermore, based on the above Figures 1 to 11 One or more embodiments of the present specification further provide a computer program product, including a computer program. When the computer program in the computer program product is executed by a processor, the following process can be implemented: Receiving a risk group mining request for a first detection object triggered by a target user; In response to the risk group mining request, determining a target resource flow pattern corresponding to the risk group mining request and graph structure data constructed according to a resource flow relationship of the first detection object; According to the graph structure data, a first wandering path corresponding to a first node and a second wandering path corresponding to a second node are acquired, wherein the first node is a node corresponding to the first detection object in the graph structure data, and the second node is a node in the graph structure data that has a resource flow relationship with the first node; Determining a target score for each second node according to a similarity between the first wandering path and the second wandering path, and a matching degree between the second wandering path and the target resource flow pattern; According to the target score of each of the second nodes, the second nodes are screened to obtain a target node; According to the target node, target graph structure data corresponding to the first detection object is constructed, and according to the target graph structure data, a risk group mining result for the first detection object is determined.

[0110] Each embodiment in this specification is described in a progressive manner, and the same or similar parts between the embodiments can be referred to each other, and each embodiment focuses on the differences from other embodiments. In particular, for the above-mentioned computer program product embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and the relevant parts can be referred to the partial description of the method embodiment.

[0111] The embodiment of the present specification provides a computer program product, which receives a risk group mining request for a first detection object triggered by a target user, and in response to the risk group mining request, determines a target resource flow pattern corresponding to the risk group mining request, and graph structure data constructed according to the resource flow relationship of the first detection object. Then, according to the graph structure data, a first wandering path corresponding to the first node and a second wandering path corresponding to the second node can be obtained, wherein the first node can be a node corresponding to the first detection object in the graph structure data, and the second node can be a node in the graph structure data that has a resource flow relationship with the first node. According to the similarity between the first wandering path and the second wandering path, and the matching degree between the second wandering path and the target resource flow pattern, a target score of each second node is determined, so that the second nodes are screened and processed according to the target score of each second node to obtain a target node. Finally, according to the target node, target graph structure data corresponding to the first detection object can be constructed, and according to the target graph structure data, a risk group mining result for the first detection object is determined. In this way, in combination with the target resource flow pattern corresponding to the risk group mining request, the target score of the neighbor node (i.e., the second node) of each first node can be determined in a targeted manner through the similarity between the first wandering path and the second wandering path, and the matching degree between the second wandering path and the target resource flow pattern. When the resource flow relationship of the first detection object is relatively complex, the node screening process can be quickly and accurately performed according to the target score of the second node, so as to determine the risk group mining result according to the screened target node, thereby improving the mining efficiency and mining accuracy of the risk group.

[0112] The above is a description of a specific embodiment of the specification. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recorded in the claims can be performed in an order different from that in the embodiments and still achieve the desired results. In addition, the processes depicted in the drawings do not necessarily require the specific order or continuous order shown to achieve the desired results. In some embodiments, multitasking and parallel processing are also possible or may be advantageous.

[0113] In the 1990s, it was very clear whether the improvement of a technology was hardware improvement (for example, improvement of the circuit structure of diodes, transistors, switches, etc.) or software improvement (improvement of the method flow). However, with the development of technology, many improvements of the method flow today can be regarded as direct improvements of the hardware circuit structure. Designers almost always obtain the corresponding hardware circuit structure by programming the improved method flow into the hardware circuit. Therefore, it cannot be said that the improvement of a method flow cannot be implemented with a hardware entity module. For example, a programmable logic device (PLD) (such as a field programmable gate array (FPGA)) is such an integrated circuit whose logical function is determined by the user's programming of the device. Designers can "integrate" a digital system on a PLD by programming themselves, without having to ask chip manufacturers to design and make dedicated integrated circuit chips. Moreover, nowadays, instead of manually making integrated circuit chips, this kind of programming is mostly implemented by "logic compiler" software, which is similar to the software compiler used when developing and writing programs, and the original code before compilation must also be written in a specific programming language, which is called hardware description language (HDL). There is not only one kind of HDL, but many kinds, such as ABEL (Advanced Boolean Expression Language), AHDL (Altera Hardware Description Language), Confluence, CUPL (Cornell University Programming Language), HDCal, JHDL (Java Hardware Description Language), Lava, Lola, MyHDL, PALASM, RHDL (Ruby Hardware Description Language), etc. The most commonly used ones are VHDL (Very-High-Speed ​​Integrated Circuit Hardware Description Language) and Verilog. Those skilled in the art should also know that it is only necessary to program the method flow slightly in the above-mentioned hardware description languages ​​and program it into the integrated circuit, and then it is easy to obtain the hardware circuit that implements the logic method flow.

[0114] The controller may be implemented in any suitable manner, for example, the controller may take the form of a microprocessor or processor and a computer-readable medium storing a computer-readable program code (e.g., software or firmware) executable by the (micro)processor, a logic gate, a switch, an application-specific integrated circuit (ASIC), a programmable logic controller, and an embedded microcontroller, examples of which include but are not limited to the following microcontrollers: ARC 625D, Atmel AT91SAM, Microchip PIC18F26K20, and Silicone Labs C8051F320, and the memory controller may also be implemented as part of the control logic of the memory. It is also known to those skilled in the art that, in addition to implementing the controller in a purely computer-readable program code manner, the controller may be implemented in the form of a logic gate, a switch, an application-specific integrated circuit, a programmable logic controller, and an embedded microcontroller by logically programming the method steps. Therefore, such a controller may be considered as a hardware component, and the devices for implementing various functions included therein may also be considered as structures within the hardware component. Or even, the devices for implementing various functions may be considered as both software modules for implementing the method and structures within the hardware component.

[0115] The systems, devices, modules or units described in the above embodiments may be implemented by computer chips or entities, or by products with certain functions. A typical implementation device is a computer. Specifically, the computer may be, for example, a personal computer, a laptop computer, a cellular phone, a camera phone, a smart phone, a personal digital assistant, a media player, a navigation device, an email device, a game console, a tablet computer, a wearable device, or a combination of any of these devices.

[0116] For the convenience of description, the above devices are described in terms of functions and are divided into various units. Of course, when implementing one or more embodiments of this specification, the functions of each unit can be implemented in the same or multiple software and / or hardware.

[0117] Those skilled in the art will appreciate that the embodiments of this specification may be provided as methods, systems, or computer program products. Therefore, one or more embodiments of this specification may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Moreover, one or more embodiments of this specification may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program codes.

[0118] The embodiments of this specification are described with reference to flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to the embodiments of this specification. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable fraud case serial and parallel device to produce a machine, so that the instructions executed by the processor of the computer or other programmable fraud case serial and parallel device generate instructions for implementing the processes in the process. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0119] These computer program instructions may also be stored in a computer readable memory capable of directing a computer or other programmable fraud case serial and parallel device to operate in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture including an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.

[0120] These computer program instructions may also be loaded onto a computer or other programmable device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, whereby the instructions executed on the computer or other programmable device provide for implementing the process. Figure 1 A process or multiple processes and / or boxes Figure 1 The steps for the functions specified in one or more boxes.

[0121] In a typical configuration, a computing device includes one or more processors (CPU), input / output interfaces, network interfaces, and memory.

[0122] Memory may include non-permanent storage in a computer-readable medium, random access memory (RAM) and / or non-volatile memory in the form of read-only memory (ROM) or flash RAM. Memory is an example of a computer-readable medium.

[0123] Computer readable media include permanent and non-permanent, removable and non-removable media that can be implemented by any method or technology to store information. Information can be computer readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disk read-only memory (CD-ROM), digital versatile disk (DVD) or other optical storage, magnetic cassettes, magnetic disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined in this article, computer readable media does not include temporary computer readable media (transitory media), such as modulated data signals and carrier waves.

[0124] It should also be noted that the terms "include", "comprises" or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, commodity or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, commodity or device. In the absence of more restrictions, the elements defined by the sentence "comprises a ..." do not exclude the existence of other identical elements in the process, method, commodity or device including the elements.

[0125] Those skilled in the art will appreciate that the embodiments of this specification may be provided as methods, systems or computer program products. Therefore, one or more embodiments of this specification may be in the form of a complete hardware embodiment, a complete software embodiment or an embodiment combining software and hardware. Furthermore, one or more embodiments of this specification may be in the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0126] One or more embodiments of the present specification may be described in the general context of computer-executable instructions executed by a computer, such as program modules. Generally, program modules include routines, programs, objects, components, data structures, etc. that perform specific tasks or implement specific abstract data types. One or more embodiments of the present specification may also be practiced in distributed computing environments where tasks are performed by remote processing devices connected through a communication network. In a distributed computing environment, program modules may be located in local and remote computer storage media, including storage devices.

[0127] Each embodiment in this specification is described in a progressive manner, and the same or similar parts between the embodiments can be referred to each other, and each embodiment focuses on the differences from other embodiments. In particular, for the system embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and the relevant parts can be referred to the partial description of the method embodiment.

[0128] The above description is only an embodiment of this specification and is not intended to limit this document. For those skilled in the art, this specification may have various changes and variations. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of this specification should be included in the scope of the claims of this specification.

Claims

1. A data processing method, comprising: Receiving a risk group mining request for a first detection object triggered by a target user; In response to the risk group mining request, determining a target resource flow pattern corresponding to the risk group mining request and graph structure data constructed according to a resource flow relationship of the first detection object; According to the graph structure data, a first wandering path corresponding to a first node and a second wandering path corresponding to a second node are acquired, wherein the first node is a node corresponding to the first detection object in the graph structure data, and the second node is a node in the graph structure data that has a resource flow relationship with the first node; Determining a target score for each second node according to a similarity between the first wandering path and the second wandering path, and a matching degree between the second wandering path and the target resource flow pattern; According to the target score of each of the second nodes, the second nodes are screened to obtain a target node; According to the target node, target graph structure data corresponding to the first detection object is constructed, and according to the target graph structure data, a risk group mining result for the first detection object is determined.

2. The method according to claim 1, before determining the target score of each second node according to the similarity between the first wandering path and the second wandering path, and the matching degree between the second wandering path and the target resource flow pattern, further comprising: According to a preset encoding rule, encoding processing is performed on the second wandering path and the target resource flow mode respectively to obtain a first encoding result corresponding to the second wandering path and a second encoding result corresponding to the target resource flow mode; According to the similarity between the first encoding result and the second encoding result, a matching degree between the second wandering path and the target resource flow mode is determined.

3. According to the method of claim 2, the preset encoding rules include prefix tree encoding rules and suffix tree encoding rules.

4. The method according to claim 1, wherein the second nodes are screened according to the target score of each second node to obtain the target node, comprising: Acquire historical resource flow data of a second detection object corresponding to the second node; According to the pre-trained risk detection model, based on the historical resource flow data of the second detection object, risk detection processing is performed on the second detection object to obtain a risk score of the second detection object; According to the target score of each of the second nodes and the risk score of the second detection object corresponding to each of the second nodes, the second nodes are screened to obtain the target nodes.

5. The method according to claim 1, further comprising: Feeding back the risk group mining result to the target user, and upon receiving a risk group mining request from the target user for the risk group mining result, determining an object corresponding to a node in the target graph structure data as the first detection object; According to the target resource flow pattern and the first detection object, risk group mining processing is continued to obtain a risk group mining result for the first detection object.

6. According to the method of claim 1, the target resource flow mode includes topological diagram structure data for representing multiple resource flow modes, and / or text description data containing multiple resource flow modes.

7. The method according to claim 6, wherein determining the target resource flow pattern corresponding to the risk group mining request and constructing the graph structure data according to the resource flow relationship of the first detection object comprises: Acquire input data of the target user corresponding to the risk group mining request; By using a preset large language model, according to the input data of the target user, a first detection object corresponding to the risk group mining request, the target resource flow mode, and graph structure data constructed according to the resource flow relationship of the first detection object are determined.

8. The method according to claim 7, wherein obtaining, according to the graph structure data, a first wandering path corresponding to the first node and a second wandering path corresponding to the second node comprises: Using the preset large language model, according to the input data of the target user, determining a search level requirement corresponding to the risk group mining request; According to the retrieval level requirement, a walking order is determined, and based on the walking order and according to the graph structure data, the first walking path and the second walking path are acquired.

9. A data processing device, comprising: A request receiving module, configured to receive a risk group mining request for a first detection object triggered by a target user; A data acquisition module, configured to determine, in response to the risk group mining request, a target resource flow pattern corresponding to the risk group mining request and graph structure data constructed according to the resource flow relationship of the first detection object; A path acquisition module, configured to acquire, according to the graph structure data, a first wandering path corresponding to a first node and a second wandering path corresponding to a second node, wherein the first node is a node in the graph structure data corresponding to the first detection object, and the second node is a node in the graph structure data having a resource flow relationship with the first node; A score determination module, configured to determine a target score for each second node according to a similarity between the first wandering path and the second wandering path, and a match between the second wandering path and the target resource flow pattern; A node determination module, configured to screen the second nodes according to the target score of each of the second nodes to obtain a target node; The result determination module is used to construct target graph structure data corresponding to the first detection object according to the target node, and determine the risk group mining result for the first detection object according to the target graph structure data.

10. A data processing device, comprising: processor; as well as a memory arranged to store computer executable instructions which, when executed, cause the processor to: Receiving a risk group mining request for a first detection object triggered by a target user; In response to the risk group mining request, determining a target resource flow pattern corresponding to the risk group mining request and graph structure data constructed according to a resource flow relationship of the first detection object; According to the graph structure data, a first wandering path corresponding to a first node and a second wandering path corresponding to a second node are acquired, wherein the first node is a node corresponding to the first detection object in the graph structure data, and the second node is a node in the graph structure data that has a resource flow relationship with the first node; Determining a target score for each second node according to a similarity between the first wandering path and the second wandering path, and a matching degree between the second wandering path and the target resource flow pattern; According to the target score of each of the second nodes, the second nodes are screened to obtain a target node; According to the target node, target graph structure data corresponding to the first detection object is constructed, and according to the target graph structure data, a risk group mining result for the first detection object is determined.

Citation Information

Patent Citations

  • Information processing method and device of knowledge graph, electronic equipment and storage medium

    CN113220902A

  • Community division method and device based on artificial intelligence, equipment and storage medium

    CN113570391A

  • Data processing method, device and equipment

    CN115827935A

  • Group mining method and device based on heterogeneous knowledge graph, equipment and medium

    CN117474678A

  • Group mining method, device and equipment

    CN118708630A