Relationship graph generation method and device, equipment, medium and program product
By generating the initial value transfer relationship diagram and reducing the graph, setting and updating the weight, the detection weakness problem caused by excessive concentration of information in the strong correlation network is solved, and more accurate detection of user value anomalies is achieved.
Patent Information
- Application Number
- CN202311532025.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-11-16
- Publication Date
- 2025-05-16
AI Technical Summary
The nodes in the strong association network have strong correlation and compact structure, but the information is too concentrated, resulting in low user strength and low detection adversity.
By obtaining the value transfer data set and historical abnormal value transfer data set in the target time period, an initial value transfer relationship diagram is generated, graph reduction processing is performed, node and edge weights are set, node weights are updated, and update relationship diagrams are generated.
The accuracy and confrontation of detecting whether the user has abnormal value transfer characteristics is improved, and the generated relationship diagram can better reflect the value relationship information between the user and the medium.
Smart Images

Figure CN120011595A_ABST
Abstract
Description
Technical Field
[0001] Embodiments of the present disclosure relate to the field of computer technology, and in particular to a relationship graph generation method, apparatus, device, medium, and program product. Background Art
[0002] At present, with the development of graph-related technologies, more and more academic institutions and enterprises have begun to use graph data for exploration and experimentation. Unlike traditional tables, images, and text data, graphs can take into account the connection relationship between different entities and have association characteristics. In order to construct a relationship graph that characterizes whether a user has abnormal value transfer characteristics, the usual method is to obtain a data set of abnormal value transfer characteristics. Then, based on the data set of abnormal value transfer characteristics, with strong correlation media as graph nodes, a strong correlation network is constructed to characterize whether a user has abnormal value transfer characteristics.
[0003] However, the inventors have found that when the above method is adopted, the following technical problems often occur:
[0004] The nodes in a strongly correlated network are strongly correlated and compact in structure, but the information is too concentrated, resulting in low user intensity in detecting whether there are abnormal value transfer features and low detection resistance.
[0005] The above information disclosed in this Background section is only for enhancement of understanding of the background of the inventive concept and therefore it may contain information that does not form the prior art that is already known in this country to a person of ordinary skill in the art. Summary of the invention
[0006] The content of this disclosure is used to introduce concepts in a brief form, which will be described in detail in the detailed implementation section below. The content of this disclosure is not intended to identify the key features or essential features of the technical solution claimed for protection, nor is it intended to limit the scope of the technical solution claimed for protection.
[0007] Some embodiments of the present disclosure propose a relationship graph generation method, an apparatus, an electronic device, a computer-readable medium, and a program product to solve the technical problems mentioned in the above background technology section.
[0008] In a first aspect, some embodiments of the present disclosure provide a relationship graph generation method, including: obtaining a value transfer data set and a historical abnormal value transfer data set corresponding to at least one target correlation degree relationship medium within a target time period; generating an initial value transfer relationship graph based on the above value transfer data set and the above historical abnormal value transfer data set, wherein the above initial value transfer relationship graph represents the correlation relationship between at least one target correlation degree relationship medium and user information; performing graph reduction processing on the above initial value transfer relationship graph to obtain a reduced relationship graph; setting node weights corresponding to each node in the above reduced relationship graph and edge weights corresponding to each edge; updating the node weights of the relationship graph after setting the weights to generate an updated relationship graph.
[0009] Optionally, the method further includes: generating an abnormal user information set indicating the existence of abnormal value transfer behavior according to the update relationship diagram; and executing value transfer restriction processing for the user set corresponding to the abnormal user information set.
[0010] Optionally, the above-mentioned graph reduction processing of the above-mentioned initial value transfer relationship graph to obtain a reduced relationship graph includes: performing graph reduction processing on the above-mentioned initial value transfer relationship graph according to at least one of the historical abnormal value transfer data screening method, the node abnormal information screening method, and the edge connection restriction method to obtain a reduced relationship graph, wherein the above-mentioned historical abnormal value transfer data screening method is a method for screening nodes in the relationship graph based on historical abnormal value transfer data, the above-mentioned node abnormal information screening method is a method for screening nodes in the relationship graph based on node abnormal information, and the above-mentioned edge connection restriction method is a method for screening nodes in the relationship graph based on edge connection restriction conditions.
[0011] Optionally, the above-mentioned setting of the node weights corresponding to each node in the above-mentioned reduction relationship graph and the edge weights corresponding to each edge includes: obtaining value anomaly scenario information; using a weight generation model corresponding to the above-mentioned value anomaly scenario information to generate node weights corresponding to each node in the above-mentioned reduction relationship graph and the edge weights corresponding to each edge.
[0012] Optionally, after setting the node weights corresponding to each node in the reduced relationship graph and the edge weights corresponding to each edge, the method further includes: performing weight verification on the node weights corresponding to each node to obtain a first verification result; performing weight verification on the edge weights corresponding to each edge to obtain a second verification result; in response to determining that the first verification result indicates that the weights of each node have passed the verification, and the second verification result indicates that the edge weights have passed the verification, determining that the relationship graph after the weights have been set has passed the weight verification.
[0013] Optionally, the above-mentioned weight verification is performed on the node weights corresponding to the above-mentioned each node to obtain a first verification result, including: performing weight bucketing processing on the node weights corresponding to the above-mentioned each node to obtain a node weight group set; for each node weight group in the above-mentioned node weight group set, executing the following generation steps: weight splitting the above-mentioned node weight group according to at least one weight level to obtain at least one first node weight subgroup; determining the first value abnormal user ratio corresponding to each first node weight subgroup in the above-mentioned at least one first node weight subgroup to obtain at least one first value abnormal user ratio; generating first verification information for the above-mentioned node weight group according to the above-mentioned at least one first value abnormal user ratio; generating a first verification result for the above-mentioned node weight group according to the obtained first verification information set.
[0014] Optionally, the above-mentioned weight verification is performed on the edge weights corresponding to the above-mentioned each edge to obtain a second verification result, including: performing weight bucketing processing on the edge weights corresponding to the above-mentioned each edge to obtain an edge weight group set; for each edge weight group in the above-mentioned edge weight group set, executing the following processing steps: performing weight splitting on the above-mentioned node weight group according to at least one weight level to obtain at least one second node weight subgroup; determining the second value abnormal user ratio corresponding to each second node weight subgroup in the above-mentioned at least one second node weight subgroup to obtain at least one second value abnormal user ratio; generating second verification information for the above-mentioned edge weight group according to the above-mentioned at least one second value abnormal user ratio; and generating a second verification result for the above-mentioned edge weight group according to the obtained second verification information set.
[0015] Optionally, the above-mentioned updating of node weights of the relationship graph after weight setting to generate an updated relationship graph includes: matching corresponding scores of each node in the above-mentioned relationship graph after weight setting to obtain the relationship graph after matching scores; and updating node scores of each node in the relationship graph after matching scores according to a score weighted update method for at least one neighbor node in the relationship graph to obtain the relationship graph after updated scores, wherein the above-mentioned score weighted update method is a method for updating the node score of the node to be updated based on at least one node score corresponding to at least one neighbor node associated with the node to be updated, at least one node weight corresponding to at least one neighbor node, the node score corresponding to the node to be updated, and the node weight corresponding to the node to be updated.
[0016] In a second aspect, some embodiments of the present disclosure provide a relationship graph generation device, including: an acquisition unit, configured to acquire a value transfer data set and a historical abnormal value transfer data set corresponding to at least one target correlation degree relationship medium within a target time period; a first generation unit, configured to generate an initial value transfer relationship graph based on the above-mentioned value transfer data set and the above-mentioned historical abnormal value transfer data set, wherein the above-mentioned initial value transfer relationship graph represents the correlation relationship between at least one target correlation degree relationship medium and user information; a graph reduction unit, configured to perform graph reduction processing on the above-mentioned initial value transfer relationship graph to obtain a reduced relationship graph; a setting unit, configured to set the node weights corresponding to each node in the above-mentioned reduced relationship graph and the edge weights corresponding to each edge; a generation unit, configured to update the node weights of the relationship graph after the weights are set to generate an updated relationship graph.
[0017] Optionally, the device further includes: generating an abnormal user information set characterizing the existence of abnormal value transfer behavior according to the above-mentioned update relationship diagram; and executing value transfer restriction processing for the user set corresponding to the above-mentioned abnormal user information set.
[0018] Optionally, the graph reduction unit can be configured to: perform graph reduction processing on the above-mentioned initial value transfer relationship graph according to at least one of the historical abnormal value transfer data screening method, the node abnormal information screening method, and the edge connection restriction method to obtain a reduced relationship graph, wherein the above-mentioned historical abnormal value transfer data screening method is a method for screening nodes in the relationship graph based on historical abnormal value transfer data, the above-mentioned node abnormal information screening method is a method for screening nodes in the relationship graph based on node abnormal information, and the above-mentioned edge connection restriction method is a method for screening nodes in the relationship graph based on edge connection restriction conditions.
[0019] Optionally, the setting unit can be configured to: obtain value anomaly scenario information; and use a weight generation model corresponding to the above value anomaly scenario information to generate node weights corresponding to each node in the above reduction relationship graph and edge weights corresponding to each edge.
[0020] Optionally, the device also includes: performing weight verification on the node weights corresponding to the above-mentioned nodes to obtain a first verification result; performing weight verification on the edge weights corresponding to the above-mentioned edges to obtain a second verification result; in response to determining that the above-mentioned first verification result indicates that the weights of each node have passed the verification, and the above-mentioned second verification result indicates that the weights of each edge have passed the verification, determining that the relationship graph after the above-mentioned weight setting has passed the weight verification.
[0021] Optionally, the device also includes: performing weight bucketing processing on the node weights corresponding to the above-mentioned each node to obtain a node weight group set; for each node weight group in the above-mentioned node weight group set, executing the following generation steps: performing weight splitting on the above-mentioned node weight group according to at least one weight level to obtain at least one first node weight subgroup; determining the first value abnormal user ratio corresponding to each first node weight subgroup in the above-mentioned at least one first node weight subgroup to obtain at least one first value abnormal user ratio; generating first verification information for the above-mentioned node weight group based on the above-mentioned at least one first value abnormal user ratio; generating a first verification result for the above-mentioned node weight group set based on the obtained first verification information set.
[0022] Optionally, the device also includes: performing weight bucketing processing on the edge weights corresponding to the above-mentioned edges to obtain an edge weight group set; for each edge weight group in the above-mentioned edge weight group set, executing the following processing steps: performing weight splitting on the above-mentioned node weight group according to at least one weight level to obtain at least one second node weight subgroup; determining the second value abnormal user ratio corresponding to each second node weight subgroup in the above-mentioned at least one second node weight subgroup to obtain at least one second value abnormal user ratio; generating second verification information for the above-mentioned edge weight group based on the above-mentioned at least one second value abnormal user ratio; and generating a second verification result for the above-mentioned edge weight group set based on the obtained second verification information set.
[0023] Optionally, the generation unit can be configured to: match the corresponding scores of each node in the relationship graph after the weights are set to obtain the relationship graph after matching the scores; and update the node scores of each node in the relationship graph after matching the scores according to a weighted score update method for at least one neighbor node in the relationship graph to obtain the relationship graph after updated scores, wherein the above-mentioned score weighted update method is a method for updating the node score of the node to be updated based on at least one node score corresponding to at least one neighbor node associated with the node to be updated, at least one node weight corresponding to at least one neighbor node, the node score corresponding to the node to be updated, and the node weight corresponding to the node to be updated.
[0024] In a third aspect, some embodiments of the present disclosure provide an electronic device comprising: one or more processors; a storage device on which one or more programs are stored, and when the one or more programs are executed by the one or more processors, the one or more processors implement the method described in any implementation manner in the first aspect.
[0025] In a fourth aspect, some embodiments of the present disclosure provide a computer-readable medium having a computer program stored thereon, wherein when the program is executed by a processor, the method described in any implementation manner in the first aspect is implemented.
[0026] In a fifth aspect, some embodiments of the present disclosure provide a computer program product, including a computer program, which implements the method described in any implementation manner in the above-mentioned first aspect when executed by a processor.
[0027] The above-mentioned embodiments of the present disclosure have the following beneficial effects: through the relationship graph generation method of some embodiments of the present disclosure, a relationship graph representing whether a user has abnormal value transfer characteristics can be accurately generated. Specifically, the reason why the relevant relationship graph is not accurate is that the nodes in the strong correlation network are strongly correlated and compact in structure, but the information is too concentrated, resulting in a low intensity of users that can be detected to represent whether there are abnormal value transfer characteristics, and low detection resistance. Based on this, the relationship graph generation method of some embodiments of the present disclosure first obtains a value transfer data set and a historical abnormal value transfer data set corresponding to at least one target correlation degree relationship medium within a target time period as a data source for subsequent generation of a relationship graph, so as to facilitate the subsequent generation of a relationship graph. Then, based on the above-mentioned value transfer data set and the above-mentioned historical abnormal value transfer data set, an initial value transfer relationship graph is generated. Among them, the above-mentioned initial value transfer relationship graph represents the correlation between at least one target correlation degree relationship medium and user information. Here, the generated initial value transfer relationship graph can preliminarily show the correlation between each medium and the user. It should be noted that the degree of association between each node in the initial value transfer relationship graph is the target degree of association (for example, weak degree of association), the structures between each structure are not particularly compact, the area involved in the information is wide, and the corresponding user information that represents the existence of abnormal value transfer characteristics can be detected, and the adversarial nature is strong. Next, the above-mentioned initial value transfer relationship graph is subjected to graph reduction processing to obtain a reduced relationship graph. Here, by performing graph reduction processing on the initial value transfer relationship graph, most of the redundant information in the relationship graph can be removed, and the construction of subsequent relationship graphs can be accelerated. Furthermore, the node weights corresponding to each node in the above-mentioned reduced relationship graph and the edge weights corresponding to each edge are set. Here, the node weights corresponding to each node and the edge weights corresponding to each edge are set to more fully reflect the value relationship information between each medium and user information. Finally, the node weights of the relationship graph after setting the weights are updated to generate a more accurate updated relationship graph representing the value relationship information between each medium and user information. In summary, by constructing a relationship graph between at least one target degree of association relationship medium and user information and updating the weights of each weight in the relationship graph, a relationship graph representing whether a user has abnormal value transfer characteristics can be accurately generated. BRIEF DESCRIPTION OF THE DRAWINGS
[0028] The above and other features, advantages and aspects of the embodiments of the present disclosure will become more apparent with reference to the following detailed description in conjunction with the accompanying drawings. Throughout the accompanying drawings, the same or similar reference numerals represent the same or similar elements. It should be understood that the drawings are schematic and that components and elements are not necessarily drawn to scale.
[0029] Figure 1 is a schematic diagram of an application scenario of a relationship graph generation method according to some embodiments of the present disclosure;
[0030] Figure 2 is a flow chart of some embodiments of the relationship graph generation method according to the present disclosure;
[0031] Figure 3 is a schematic diagram of updating a relationship graph in some embodiments of the relationship graph generation method disclosed herein;
[0032] Figure 4 are flow charts of other embodiments of the relationship graph generation method according to the present disclosure;
[0033] Figure 5 is a schematic diagram of the structure of some embodiments of the relationship diagram generating device according to the present disclosure;
[0034] Figure 6 It is a schematic diagram of the structure of an electronic device suitable for implementing some embodiments of the present disclosure. DETAILED DESCRIPTION
[0035] Embodiments of the present disclosure will be described in more detail below with reference to the accompanying drawings. Although certain embodiments of the present disclosure are shown in the accompanying drawings, it should be understood that the present disclosure can be implemented in various forms and should not be construed as being limited to the embodiments set forth herein. On the contrary, these embodiments are provided to provide a more thorough and complete understanding of the present disclosure. It should be understood that the drawings and embodiments of the present disclosure are only for exemplary purposes and are not intended to limit the scope of protection of the present disclosure.
[0036] It should also be noted that, for ease of description, only the parts related to the invention are shown in the drawings. In the absence of conflict, the embodiments and features in the embodiments of the present disclosure can be combined with each other.
[0037] It should be noted that the concepts such as "first" and "second" mentioned in the present disclosure are only used to distinguish different devices, modules or units, and are not used to limit the order or interdependence of the functions performed by these devices, modules or units.
[0038] It should be noted that the modifications of "one" and "plurality" mentioned in the present disclosure are illustrative rather than restrictive, and those skilled in the art should understand that unless otherwise clearly indicated in the context, it should be understood as "one or more".
[0039] The names of the messages or information exchanged between multiple devices in the embodiments of the present disclosure are only used for illustrative purposes and are not used to limit the scope of these messages or information.
[0040] With regard to the collection, storage, and use of user data (such as value transfer data sets) involved in this disclosure, before performing the corresponding operations, the relevant organizations or individuals shall fulfill their obligations, including conducting personal data security impact assessments, fulfilling the obligation to inform the personal data subject, and obtaining the authorization and consent of the personal data subject in advance.
[0041] The present disclosure will be described in detail below with reference to the accompanying drawings and in conjunction with embodiments.
[0042] Figure 1 It is a schematic diagram of an application scenario of a relationship graph generation method according to some embodiments of the present disclosure.
[0043] exist Figure 1 In the application scenario, first, the electronic device 101 can obtain a value transfer data set 106 and a historical abnormal value transfer data set 107 corresponding to at least one target correlation degree relationship medium within the target time period 102. In this application scenario, the target time period 102 can be "November 2021"-"November 2022". The value transfer data set 106 can be a value transfer data subset for multiple users. The value transfer data set 106 includes: a value transfer data subset 1061 corresponding to user A 103, a value transfer data subset 1062 corresponding to user B 104, and a value transfer data subset 1063 corresponding to user C 105. Then, the electronic device 101 can generate an initial value transfer relationship graph 108 based on the above value transfer data set 106 and the above historical abnormal value transfer data set 107. Among them, the above initial value transfer relationship graph 108 represents the correlation relationship between at least one target correlation degree relationship medium and user information. Then, the electronic device 101 can perform graph reduction processing on the above initial value transfer relationship graph 108 to obtain a reduced relationship graph 109. Furthermore, the electronic device 101 may set the node weights corresponding to each node and the edge weights corresponding to each edge in the reduced relationship graph 109. Finally, the electronic device 101 may update the node weights of the relationship graph 110 after setting the weights, and generate an updated relationship graph 111.
[0044] It should be noted that the electronic device 101 can be hardware or software. When the electronic device is hardware, it can be implemented as a distributed cluster consisting of multiple servers or terminal devices, or it can be implemented as a single server or a single terminal device. When the electronic device is embodied as software, it can be installed in the hardware devices listed above. It can be implemented as multiple software or software modules for providing distributed services, for example, or it can be implemented as a single software or software module. No specific limitation is made here.
[0045] It should be understood that Figure 1 The number of electronic devices in the embodiment is only for illustration. Any number of electronic devices may be provided according to implementation requirements.
[0046] Continue to refer Figure 2 , shows a process 200 of some embodiments of the relationship diagram generation method according to the present disclosure. The relationship diagram generation method comprises the following steps:
[0047] Step 201 : Acquire a value transfer dataset and a historical abnormal value transfer dataset corresponding to at least one target correlation degree relationship medium within a target time period.
[0048] In some embodiments, the execution subject of the above relationship graph generation method (for example Figure 1The electronic device 101 shown can obtain a value transfer data set and a historical abnormal value transfer data set corresponding to at least one target correlation degree relationship medium within a target time period through a wired connection method or a wireless connection method. Among them, the target time period can be a pre-set time period for detecting users with abnormal user behavior. Specifically, there is also a one-to-one correspondence between the target time period and the relationship graph constructed subsequently. At least one target correlation degree relationship medium can be a pre-set at least one medium for value abnormal scene information. The target correlation degree relationship medium can be a medium with a weak correlation degree relationship with the value abnormality feature in the value abnormal scene information. The value abnormal scene information can be the scene information of the scene of value abnormality detection. In practice, for the value abnormal scene information is the scene information of the user fraud detection scene, the target correlation degree relationship medium can be a medium with a weak correlation degree with the fraud feature. That is, the target correlation degree can be a weak correlation degree. Specifically, the weaker degree can be a degree determined according to the number of frauds. The weaker degree can also be a degree defined artificially. For example, the target association degree relationship medium may be, but is not limited to, at least one of the following: contact information medium under the target street, value transfer time medium under the target street, contact information medium under the target community, and value transfer time medium under the target community. The value transfer time medium may be a medium of the time when the user transaction is generated. The value transfer data set may be a data set consisting of multiple media data sets (i.e., value transfer data subsets) for at least one target association degree relationship medium for multiple users within a target time period. For financial fraud scenarios, the value transfer data may be user transaction data. The historical abnormal value transfer data set may be a historically generated user-associated value transfer data set with abnormal user behavior.
[0049] Step 202: Generate an initial value transfer relationship diagram based on the value transfer data set and the historical abnormal value transfer data set.
[0050] In some embodiments, the execution subject may generate an initial value transfer relationship graph based on the value transfer data set and the historical abnormal value transfer data set. The initial value transfer relationship graph represents the relationship between at least one target correlation degree relationship medium and user information. The relationship between at least one target correlation degree relationship medium and user information may be a value transfer relationship between at least one target correlation degree relationship medium and at least one user corresponding to the user information. Specifically, the initial value transfer relationship graph may also indirectly represent the value transfer relationship between user information.
[0051] As an example, the above-mentioned execution entity can use the user information set corresponding to the value transfer data as a graph node, the user information set corresponding to the historical abnormal value transfer data set as a graph node, and at least one target correlation degree relationship medium as a graph node, and establish a node correlation relationship between each graph node (i.e., connect each graph node) according to the data correlation relationship between the above-mentioned value transfer data set and the above-mentioned historical abnormal value transfer data set, the correlation relationship between the value transfer data set and each graph node, and the correlation relationship between the historical abnormal value transfer data set and each graph node to obtain an initial value transfer relationship graph.
[0052] Step 203, performing graph reduction processing on the above-mentioned initial value transfer relationship graph to obtain a reduced relationship graph.
[0053] In some embodiments, the execution entity may perform graph reduction processing on the initial value transfer relationship graph to obtain a reduced relationship graph.
[0054] As an example, first, the execution subject may determine the number of edges corresponding to each graph node in the initial value transfer relationship graph, and then remove the edges and corresponding nodes with the corresponding edge number of "value 1" from the initial value transfer relationship graph to obtain a reduced relationship graph.
[0055] In some optional implementations of some embodiments, the initial value transfer relationship graph is subjected to graph reduction processing according to at least one of a historical abnormal value transfer data screening method, a node abnormal information screening method, and an edge connection restriction method to obtain a reduced relationship graph. The historical abnormal value transfer data screening method is a method for screening nodes in the relationship graph based on historical abnormal value transfer data, the node abnormal information screening method is a method for screening nodes in the relationship graph based on node abnormal information, and the edge connection restriction method is a method for screening nodes in the relationship graph based on edge connection restriction conditions.
[0056] Step 204: Set the node weight corresponding to each node and the edge weight corresponding to each edge in the reduced relationship graph.
[0057] In some embodiments, the execution entity may set the node weights corresponding to the nodes and the edge weights corresponding to the edges in the reduction relationship graph. The node weights may characterize the degree of abnormal value transfer characteristics of the user or medium corresponding to the node. For example, the more likely it is that the user corresponding to the node has abnormal value transfer, the higher the degree of abnormal value transfer characteristics, and the higher the value of the corresponding node weight. The edge weight may characterize the value transfer relationship between two nodes. In practice, the value transfer relationship may be a transaction relationship.
[0058] In some optional implementations of some embodiments, the setting of the node weights corresponding to the nodes and the edge weights corresponding to the edges in the reduced relationship graph may include the following steps:
[0059] The first step is to obtain value abnormal scenario information, wherein the value abnormal scenario information may be scenario information of a scenario where value abnormal behavior may exist.
[0060] In the second step, the weight generation model corresponding to the above-mentioned value anomaly scenario information is used to generate node weights corresponding to each node in the above-mentioned reduction relationship graph and edge weights corresponding to each edge. The weight generation model can be a neural network model that generates node weights and edge weights. In practice, the weight generation model can be an XGBoost (eXtreme GradientBoosting, extreme gradient boosting tree) model.
[0061] As an example, the execution entity may input the value transfer dataset and the historical abnormal value transfer dataset into a weight generation model to generate node weights corresponding to each node and edge weights corresponding to each edge in the reduction relationship graph.
[0062] Step 205, updating the node weights of the relationship graph after the weights are set, and generating an updated relationship graph.
[0063] In some embodiments, the execution entity may update the node weights of the relationship graph after the weights are set to generate an updated relationship graph.
[0064] As an example, first, the execution entity may input the value transfer dataset and the historical abnormal value transfer dataset into a convolutional neural network model to output the node convolution weights corresponding to each node and the edge convolution weights corresponding to each edge. Then, the node convolution weights corresponding to each node and the node weights corresponding to each node are weighted and summed to obtain a node-weighted sum weight set. Similarly, the edge weights corresponding to each edge and the edge convolution weights corresponding to each edge are weighted and summed to obtain an edge-weighted sum weight set. Finally, according to the node-weighted sum weight set and the edge-weighted sum weight set, each weight in the relationship graph after the weights are set is replaced to generate an updated relationship graph.
[0065] As an example, Figure 3As shown, the "User A" node is connected to the "A Street-A Mobile Phone" node, the "C Street-A Time" node, the "B Street-A Time" node, and the "B Street-A Mobile Phone" node. The "User B" node is connected to the "A Street-A Time" node and the "B Street-A Mobile Phone" node. The "User C" node is connected to the "A Street-A Mobile Phone" node and the "B Street-A Time" node. The "User D" node is connected to the "C Street-A Time" node, the "A Street-A Time" node, and the "A Street-A Mobile Phone" node.
[0066] In some optional implementations of some embodiments, after step 205, the steps further include:
[0067] In the first step, the execution subject may generate an abnormal user information set indicating abnormal value transfer behavior based on the update relationship diagram. In practice, for financial fraud scenarios, abnormal value transfer behavior may be abnormal transaction behavior. Abnormal user information may be user information with abnormal value transfer behavior.
[0068] As an example, the execution subject may filter out user scores corresponding to user information at corresponding nodes from the update relationship graph to obtain a user score set. Then, user information in the update relationship graph corresponding user information set whose corresponding user scores are greater than a predetermined score is determined as abnormal user information to obtain an abnormal user information set.
[0069] In the second step, the execution subject may execute the value transfer restriction processing for the user set corresponding to the abnormal user information set. The value transfer restriction processing may be a restriction processing on the value transfer operation. In practice, for financial fraud scenarios, the value transfer restriction processing may be a transfer limit processing.
[0070] In some optional implementations of some embodiments, the above-mentioned updating of node weights of the relationship graph after setting weights to generate an updated relationship graph may include the following steps:
[0071] The first step is to match the corresponding scores of each node in the above-mentioned weighted relationship graph to obtain a relationship graph with matching scores. The weighted relationship graph includes the historical abnormal user information set corresponding to the historical abnormal value transfer data set.
[0072] As an example, the execution entity may set the score of the node set corresponding to the historical abnormal user information set to a value of "1", and set the scores of the remaining node sets to a value of "0", to obtain a relationship graph after matching the scores.
[0073] In the second step, according to the score weighted update method for at least one neighbor node in the relationship graph, the node score of each node in the relationship graph after matching the score is updated to obtain the relationship graph after the score is updated, wherein the score weighted update method is a method for updating the node score of the node to be updated based on at least one node score corresponding to at least one neighbor node associated with the node to be updated, at least one node weight corresponding to at least one neighbor node, the node score corresponding to the node to be updated, and the node weight corresponding to the node to be updated. The node to be updated may be a node to be updated with a score. The at least one neighbor node associated with the node to be updated may be at least one node adjacent to the node to be updated. The specific update process of the score weighted update method may be: for the node to be updated, the score corresponding to at least one neighbor node is aggregated by score weighted summation, and the aggregated score is used as the update score of the node to be updated. However, each neighbor node in the at least one neighbor node also changes continuously with the aggregation of the scores of at least one neighboring node, so that the score of the node to be updated fluctuates again due to the update of the scores of the neighbor nodes. In the process of continuously updating the scores by using each node as a node to be updated, when the score corresponding to each node fluctuates within a certain range, it indicates that the score update of the relationship graph after matching the scores has ended, so as to obtain the relationship graph after the updated scores.
[0074] The above-mentioned embodiments of the present disclosure have the following beneficial effects: through the relationship graph generation method of some embodiments of the present disclosure, a relationship graph representing whether a user has abnormal value transfer characteristics can be accurately generated. Specifically, the reason why the relevant relationship graph is not accurate is that the nodes in the strong correlation network are strongly correlated and compact in structure, but the information is too concentrated, resulting in a low intensity of users that can be detected to represent whether there are abnormal value transfer characteristics, and low detection resistance. Based on this, the relationship graph generation method of some embodiments of the present disclosure first obtains a value transfer data set and a historical abnormal value transfer data set corresponding to at least one target correlation degree relationship medium within a target time period as a data source for subsequent generation of a relationship graph, so as to facilitate the subsequent generation of a relationship graph. Then, based on the above-mentioned value transfer data set and the above-mentioned historical abnormal value transfer data set, an initial value transfer relationship graph is generated. Among them, the above-mentioned initial value transfer relationship graph represents the correlation between at least one target correlation degree relationship medium and user information. Here, the generated initial value transfer relationship graph can preliminarily show the correlation between each medium and the user. It should be noted that the degree of association between each node in the initial value transfer relationship graph is the target degree of association (for example, weak degree of association), the structures between each structure are not particularly compact, the area involved in the information is wide, and the corresponding user information that represents the existence of abnormal value transfer characteristics can be detected, and the adversarial nature is strong. Next, the above-mentioned initial value transfer relationship graph is subjected to graph reduction processing to obtain a reduced relationship graph. Here, by performing graph reduction processing on the initial value transfer relationship graph, most of the redundant information in the relationship graph can be removed, and the construction of subsequent relationship graphs can be accelerated. Furthermore, the node weights corresponding to each node in the above-mentioned reduced relationship graph and the edge weights corresponding to each edge are set. Here, the node weights corresponding to each node and the edge weights corresponding to each edge are set to more fully reflect the value relationship information between each medium and user information. Finally, the node weights of the relationship graph after setting the weights are updated to generate a more accurate updated relationship graph representing the value relationship information between each medium and user information. In summary, by constructing a relationship graph between at least one target degree of association relationship medium and user information and updating the weights of each weight in the relationship graph, a relationship graph representing whether a user has abnormal value transfer characteristics can be accurately generated.
[0075] Further references Figure 4 , shows a process 400 of another embodiment of the relationship diagram generation method according to the present disclosure. The relationship diagram generation method comprises the following steps:
[0076] Step 401, obtaining a value transfer data set and a historical abnormal value transfer data set corresponding to at least one target correlation degree relationship medium within a target time period.
[0077] Step 402: Generate an initial value transfer relationship diagram based on the value transfer data set and the historical abnormal value transfer data set.
[0078] Step 403, performing graph reduction processing on the above-mentioned initial value transfer relationship graph to obtain a reduced relationship graph.
[0079] Step 404: Set the node weight corresponding to each node and the edge weight corresponding to each edge in the reduced relationship graph.
[0080] Step 405: Perform a weight check on the node weights corresponding to the above-mentioned nodes to obtain a first check result.
[0081] In some embodiments, an execution entity (e.g. Figure 1 The electronic device 101 shown can perform a weight check on the node weights corresponding to the above-mentioned nodes to obtain a first check result, wherein the first check result indicates whether the corresponding values of the node weights corresponding to the nodes can accurately indicate the correlation relationship of the abnormal situation of the user.
[0082] As an example, first, the execution subject may set a strongly associated medium relationship graph for each node, and then perform a weight check on the corresponding node weights of each node using the strongly associated medium relationship graph as a weight check basis to obtain a first check result.
[0083] Step 406: Perform a weight check on the edge weights corresponding to the above-mentioned edges to obtain a second check result.
[0084] In some embodiments, the execution subject may perform a weight check on the edge weights corresponding to the edges to obtain a second check result, wherein the second check result indicates whether the corresponding values of the edge weights corresponding to the edges can accurately indicate the association relationship between the two nodes.
[0085] As an example, first, the execution subject may set a strong correlation medium relationship graph for each node, and then perform a weight check on the edge weights corresponding to each edge using the strong correlation medium relationship graph as a weight check basis to obtain a second check result.
[0086] Step 407, in response to determining that the first verification result indicates that each node weight has passed verification, and the second verification result indicates that each edge weight has passed verification, it is determined that the relationship graph after setting the weights has passed the weight verification.
[0087] In some embodiments, in response to determining that the first verification result indicates that each node weight has passed verification, and the second verification result indicates that each edge weight has passed verification, the execution entity may determine that the relationship graph after setting the weights has passed the weight verification.
[0088] In some optional implementations of some embodiments, performing weight verification on the node weights corresponding to the above-mentioned nodes to obtain the first verification result may include the following steps:
[0089] In the first step, the execution entity may perform weight bucketing on the node weights corresponding to the above nodes to obtain a node weight set.
[0090] As an example, the execution entity may randomly perform weight bucketing on the node weights corresponding to the above-mentioned nodes to obtain a node weight set.
[0091] In the second step, for each node weight group in the above node weight group set, perform the following generation steps:
[0092] Sub-step 1, the above-mentioned execution entity can perform weight splitting on the above-mentioned node weight group according to at least one weight level to obtain at least one first node weight subgroup. Among them, each weight level in at least one weight level can be a pre-set level. There is a corresponding weight interval for each weight level. For example, at least one weight level includes: a first weight level, a second weight level and a third weight level. The weight interval corresponding to the first weight level can be "[0,0.4)". The weight interval corresponding to the second weight level can be "[0.4,0.8)". The weight interval corresponding to the third weight level can be "[0.8,1]". There is a one-to-one correspondence between the weight levels in at least one weight level and the node weight subgroups in at least one node weight subgroup. For example, at least one first node weight subgroup includes: a first node weight subgroup corresponding to the first weight level, a first node weight subgroup corresponding to the second weight level, and a first node weight subgroup corresponding to the third weight level.
[0093] In sub-step 2, the execution subject may determine the proportion of abnormal users with first value corresponding to each first node weight subgroup in the at least one first node weight subgroup, and obtain at least one abnormal user with first value. The abnormal user with first value may be a proportion of users between abnormal value users and user subsets in the user subset corresponding to the first node weight subgroup.
[0094] In sub-step 3, the execution entity may generate first verification information for the node weight group according to the at least one first value abnormal user ratio.
[0095] As an example, first, the above-mentioned execution subject can sort at least one weight level according to the order of weight intervals from large to small, and obtain a weight level sequence. Then, according to the weight level sequence, at least one first value abnormal user ratio is sorted accordingly to obtain a first value abnormal user ratio sequence. Next, determine whether the numerical value corresponding to the first value abnormal user ratio sequence is gradually increasing. In response to determining that it is gradually increasing, the information representing that the node weight group has passed the node verification is determined as the first verification information. In response to determining that it is not gradually increasing, the information representing that the node weight group has not passed the node verification is determined as the first verification information.
[0096] In a third step, the execution entity may generate a first verification result for the node weight set according to the obtained first verification information set.
[0097] As an example, in response to determining that each of the first verification information in the first verification information set has passed the verification, a first verification result representing that the node weight set has passed the verification is generated. In response to determining that there is first verification information in the first verification information set that has not passed the verification, a first verification result representing that the node weight set has not passed the verification is generated.
[0098] In some optional implementations of some embodiments, performing weight verification on the edge weights corresponding to the above-mentioned edges to obtain a second verification result may include the following steps:
[0099] In the first step, the execution entity may perform weight bucketing on the edge weights corresponding to the edges to obtain edge weight clusters.
[0100] As an example, the execution entity may randomly perform weight bucketing on the edge weights corresponding to the edges to obtain a set of edge weights.
[0101] In the second step, for each edge weight group in the above edge weight group set, perform the following processing steps:
[0102] In sub-step 1, the execution subject may perform weight splitting on the node weight group according to at least one weight level to obtain at least one second node weight subgroup, wherein a weight level in the at least one weight level and a second node weight subgroup in the at least one second node weight subgroup have a one-to-one correspondence.
[0103] In sub-step 2, the execution subject may determine the proportion of abnormal users with second value corresponding to each second node weight subgroup in the at least one second node weight subgroup, and obtain at least one proportion of abnormal users with second value. For specific explanations, please refer to the proportion of abnormal users with first value.
[0104] Sub-step 3: the execution subject may generate second verification information for the edge weight group according to the at least one second value abnormal user ratio. The details are not repeated here, see the generation of the first verification information.
[0105] The third step is to generate a second verification result for the edge weight set according to the obtained second verification information set. The details are not repeated here, and refer to the generation of the second verification result.
[0106] Step 308, updating the node weights of the relationship graph after the weights are set, and generating an updated relationship graph.
[0107] In some embodiments, the specific implementation of steps 401-404 and 405 and the technical effects thereof can be referred to in Figure 2 Steps 201-204 and 205 in the corresponding embodiment are not described in detail here.
[0108] from Figure 4 It can be seen that Figure 2 Compared with the description of some corresponding embodiments, Figure 4 In the corresponding process 400 of the relationship graph generation method in some embodiments, weight verification is performed on the node weight corresponding to each node and the edge weight corresponding to each edge to ensure the accuracy of each node weight and each edge weight, so that the subsequently updated relationship graph is more accurate.
[0109] Further references Figure 5 As an implementation of the methods shown in the above figures, the present disclosure provides some embodiments of a relationship graph generation device, and these device embodiments are similar to Figure 2 Corresponding to the method embodiments shown, the relationship diagram generating device can be specifically applied to various electronic devices.
[0110] like Figure 5As shown, a relationship graph generating device 500 includes: an acquisition unit 501, a first generation unit 502, a graph reduction unit 503, a setting unit 504 and a generation unit 505. The acquisition unit 501 is configured to acquire a value transfer data set and a historical abnormal value transfer data set corresponding to at least one target correlation degree relationship medium within a target time period; the first generation unit 502 is configured to generate an initial value transfer relationship graph according to the value transfer data set and the historical abnormal value transfer data set, wherein the initial value transfer relationship graph represents the correlation relationship between at least one target correlation degree relationship medium and user information; the graph reduction unit 503 is configured to perform graph reduction processing on the initial value transfer relationship graph to obtain a reduced relationship graph; the setting unit 504 is configured to set the node weights corresponding to each node and the edge weights corresponding to each edge in the reduced relationship graph; the generation unit 505 is configured to update the node weights of the relationship graph after the weights are set to generate an updated relationship graph.
[0111] In some optional implementations of some embodiments, the apparatus 500 further includes: an information generation unit and an execution unit (not shown in the figure). The information generation unit may be configured to: generate an abnormal user information set indicating the existence of abnormal value transfer behavior according to the update relationship diagram. The execution unit may be configured to: execute value transfer restriction processing for the user set corresponding to the abnormal user information set.
[0112] In some optional implementations of some embodiments, the graph reduction unit 503 can be further configured to: perform graph reduction processing on the above-mentioned initial value transfer relationship graph according to at least one of the historical abnormal value transfer data screening method, the node abnormal information screening method, and the edge connection restriction method, to obtain a reduced relationship graph, wherein the above-mentioned historical abnormal value transfer data screening method is a method for screening nodes in the relationship graph based on historical abnormal value transfer data, the above-mentioned node abnormal information screening method is a method for screening nodes in the relationship graph based on node abnormal information, and the above-mentioned edge connection restriction method is a method for screening nodes in the relationship graph based on edge connection restriction conditions.
[0113] In some optional implementations of some embodiments, the setting unit 504 can be further configured to: obtain value anomaly scenario information; use the weight generation model corresponding to the above value anomaly scenario information to generate node weights corresponding to each node in the above reduction relationship graph and edge weights corresponding to each edge.
[0114] In some optional implementations of some embodiments, the device 500 further includes: a first verification unit, a second verification unit and a determination unit (not shown in the figure). Among them, the first verification unit can be configured to: perform a weight check on the node weights corresponding to the above-mentioned each node to obtain a first verification result. The second verification unit can be configured to: perform a weight check on the edge weights corresponding to the above-mentioned each edge to obtain a second verification result. The determination unit can be configured to: in response to determining that the above-mentioned first verification result indicates that the weights of each node have passed the verification, and the above-mentioned second verification result indicates that the weights of each edge have passed the verification, determine that the relationship graph after the above-mentioned weight setting has passed the weight verification.
[0115] In some optional implementations of some embodiments, the first verification unit can be configured to: perform weight bucketing processing on the node weights corresponding to the above-mentioned each node to obtain a node weight group set; for each node weight group in the above-mentioned node weight group set, perform the following generation steps: perform weight splitting on the above-mentioned node weight group according to at least one weight level to obtain at least one first node weight subgroup; determine the first value abnormal user ratio corresponding to each first node weight subgroup in the above-mentioned at least one first node weight subgroup to obtain at least one first value abnormal user ratio; generate first verification information for the above-mentioned node weight group based on the above-mentioned at least one first value abnormal user ratio; and generate a first verification result for the above-mentioned node weight group set based on the obtained first verification information set.
[0116] In some optional implementations of some embodiments, the second verification unit can be configured to: perform weight bucketing processing on the edge weights corresponding to the above-mentioned edges to obtain an edge weight group set; for each edge weight group in the above-mentioned edge weight group set, perform the following processing steps: perform weight splitting on the above-mentioned node weight group according to at least one weight level to obtain at least one second node weight subgroup; determine the second value abnormal user ratio corresponding to each second node weight subgroup in the above-mentioned at least one second node weight subgroup to obtain at least one second value abnormal user ratio; generate second verification information for the above-mentioned edge weight group based on the above-mentioned at least one second value abnormal user ratio; and generate a second verification result for the above-mentioned edge weight group based on the obtained second verification information set.
[0117] In some optional implementations of some embodiments, the generation unit 505 may be further configured to: match the corresponding scores of each node in the relationship graph after the weights are set to obtain the relationship graph after the matching scores; and perform node score update processing on each node in the relationship graph after the matching scores according to a score weighted update method for at least one neighbor node in the relationship graph to obtain the relationship graph after the updated scores, wherein the score weighted update method is a method for updating the node score of the node to be updated based on at least one node score corresponding to at least one neighbor node associated with the node to be updated, at least one node weight corresponding to at least one neighbor node, the node score corresponding to the node to be updated, and the node weight corresponding to the node to be updated.
[0118] It can be understood that the units recorded in the relationship diagram generating device 500 and the reference Figure 2 Therefore, the operations, features and beneficial effects described above for the method are also applicable to the relationship diagram generating device 500 and the units included therein, and will not be described in detail here.
[0119] Reference below Figure 6 , which shows an electronic device (eg, Figure 1 Schematic diagram of the structure of the electronic device 101)600. Figure 6 The electronic device shown is only an example and should not bring any limitation to the functions and scope of use of the embodiments of the present disclosure.
[0120] like Figure 6 As shown, the electronic device 600 may include a processing device (e.g., a central processing unit, a graphics processing unit, etc.) 601, which can perform various appropriate actions and processes according to a program stored in a read-only memory 602 or a program loaded from a storage device 608 into a random access memory 603. Various programs and data required for the operation of the electronic device 600 are also stored in the random access memory 603. The processing device 601, the read-only memory 602, and the random access memory 603 are connected to each other via a bus 604. An input / output interface 605 is also connected to the bus 604.
[0121] Typically, the following devices may be connected to the input / output interface 605: an input device 606 including, for example, a touch screen, a touch pad, a keyboard, a mouse, a camera, a microphone, an accelerometer, a gyroscope, etc.; an output device 607 including, for example, a liquid crystal display (LCD), a speaker, a vibrator, etc.; a storage device 608 including, for example, a magnetic tape, a hard disk, etc.; and a communication device 609. The communication device 609 may allow the electronic device 600 to communicate with other devices wirelessly or by wire to exchange data. Although Figure 6The electronic device 600 is shown with various devices, but it should be understood that it is not required to implement or possess all the devices shown. More or fewer devices may be implemented or possessed instead. Figure 6 Each block shown in the figure may represent one device, or may represent multiple devices as required.
[0122] In particular, according to some embodiments of the present disclosure, the process described above with reference to the flowchart can be implemented as a computer software program. For example, some embodiments of the present disclosure include a computer program product, which includes a computer program carried on a computer-readable medium, and the computer program includes a program code for executing the method shown in the flowchart. In some such embodiments, the computer program can be downloaded and installed from a network through a communication device 609, or installed from a storage device 608, or installed from a read-only memory 602. When the computer program is executed by the processing device 601, the above-mentioned functions defined in the method of some embodiments of the present disclosure are executed.
[0123] It should be noted that the computer-readable medium in some embodiments of the present disclosure may be a computer-readable signal medium or a computer-readable storage medium or any combination of the two. The computer-readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, device or device, or any combination of the above. More specific examples of computer-readable storage media may include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In some embodiments of the present disclosure, the computer-readable storage medium may be any tangible medium containing or storing a program that can be used by or in combination with an instruction execution system, device or device. In some embodiments of the present disclosure, the computer-readable signal medium may include a data signal propagated in a baseband or as part of a carrier wave, in which a computer-readable program code is carried. This propagated data signal may take a variety of forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. The computer readable signal medium may also be any computer readable medium other than a computer readable storage medium, which may send, propagate or transmit a program for use by or in conjunction with an instruction execution system, apparatus or device. The program code contained on the computer readable medium may be transmitted using any suitable medium, including but not limited to: wires, optical cables, RF (radio frequency), etc., or any suitable combination of the above.
[0124] In some embodiments, the client and the server may communicate using any currently known or future developed network protocol such as HTTP (HyperText Transfer Protocol), and may be interconnected with any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include a local area network ("LAN"), a wide area network ("WAN"), an internet (e.g., the Internet), and a peer-to-peer network (e.g., an ad hoc peer-to-peer network), as well as any currently known or future developed network.
[0125] The computer-readable medium may be included in the electronic device; or it may exist independently without being installed in the electronic device. The computer-readable medium carries one or more programs. When the one or more programs are executed by the electronic device, the electronic device: obtains a value transfer data set and a historical abnormal value transfer data set corresponding to at least one target correlation degree relationship medium within a target time period; generates an initial value transfer relationship graph based on the value transfer data set and the historical abnormal value transfer data set, wherein the initial value transfer relationship graph represents the correlation relationship between at least one target correlation degree relationship medium and user information; performs graph reduction processing on the initial value transfer relationship graph to obtain a reduced relationship graph; sets the node weights corresponding to each node and the edge weights corresponding to each edge in the reduced relationship graph; updates the node weights of the relationship graph after setting the weights to generate an updated relationship graph.
[0126] Computer program code for performing the operations of some embodiments of the present disclosure may be written in one or more programming languages or a combination thereof, including object-oriented programming languages such as Java, Smalltalk, C++, and conventional procedural programming languages such as "C" or similar programming languages. The program code may be executed entirely on the user's computer, partially on the user's computer, as a separate software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving a remote computer, the remote computer may be connected to the user's computer via any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., via the Internet using an Internet service provider).
[0127] The flow chart and block diagram in the accompanying drawings illustrate the possible architecture, function and operation of the system, method and computer program product according to various embodiments of the present disclosure. In this regard, each square box in the flow chart or block diagram can represent a module, a program segment or a part of a code, and the module, the program segment or a part of the code contains one or more executable instructions for realizing the specified logical function. It should also be noted that in some implementations as replacements, the functions marked in the square box can also occur in a sequence different from that marked in the accompanying drawings. For example, two square boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each square box in the block diagram and / or flow chart, and the combination of the square boxes in the block diagram and / or flow chart can be implemented with a dedicated hardware-based system that performs a specified function or operation, or can be implemented with a combination of dedicated hardware and computer instructions.
[0128] The units described in some embodiments of the present disclosure may be implemented by software or by hardware. The described units may also be set in a processor, for example, may be described as: a processor includes an acquisition unit, a first generation unit, a graph reduction unit, a setting unit, and a generation unit. The names of these units do not constitute a limitation on the unit itself in some cases. For example, the acquisition unit may also be described as "a unit for acquiring a value transfer data set and a historical abnormal value transfer data set corresponding to at least one target correlation degree relationship medium within a target time period."
[0129] The functions described above herein may be performed at least in part by one or more hardware logic components. For example, without limitation, exemplary types of hardware logic components that may be used include: field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), systems on chips (SOCs), complex programmable logic devices (CPLDs), and the like.
[0130] Some embodiments of the present disclosure further provide a computer program product, including a computer program, which implements any of the above-mentioned relationship graph generation methods when executed by a processor.
[0131] The above descriptions are only some preferred embodiments of the present disclosure and an explanation of the technical principles used. Those skilled in the art should understand that the scope of the invention involved in the embodiments of the present disclosure is not limited to the technical solutions formed by a specific combination of the above-mentioned technical features, but should also cover other technical solutions formed by any combination of the above-mentioned technical features or their equivalent features without departing from the above-mentioned inventive concept. For example, the above-mentioned features are replaced with the technical features with similar functions disclosed in the embodiments of the present disclosure (but not limited to) and the technical solutions formed.
Claims
1. A method for generating a relationship graph, comprising: Acquire a value transfer data set and a historical abnormal value transfer data set corresponding to at least one target correlation degree relationship medium within a target time period; Generate an initial value transfer relationship graph based on the value transfer data set and the historical abnormal value transfer data set, wherein the initial value transfer relationship graph represents the association relationship between at least one target association degree relationship medium and user information; Performing graph reduction processing on the initial value transfer relationship graph to obtain a reduced relationship graph; Setting a node weight corresponding to each node and an edge weight corresponding to each edge in the reduced relationship graph; The node weights of the relationship graph after weight setting are updated to generate an updated relationship graph.
2. The method according to claim 1, wherein: The method further comprises: According to the update relationship graph, an abnormal user information set indicating the existence of abnormal value transfer behavior is generated; Execute value transfer restriction processing for the user set corresponding to the abnormal user information set.
3. The method according to claim 1, wherein: The graph reduction process is performed on the initial value transfer relationship graph to obtain a reduced relationship graph, including: According to at least one of the historical abnormal value transfer data screening method, the node abnormal information screening method, and the edge connection restriction method, the initial value transfer relationship graph is subjected to graph reduction processing to obtain a reduced relationship graph, wherein the historical abnormal value transfer data screening method is a method for screening nodes in the relationship graph based on historical abnormal value transfer data, the node abnormal information screening method is a method for screening nodes in the relationship graph based on node abnormal information, and the edge connection restriction method is a method for screening nodes in the relationship graph based on edge connection restriction conditions.
4. The method according to claim 1, wherein: The step of setting the node weight corresponding to each node and the edge weight corresponding to each edge in the reduced relationship graph includes: Obtain information on value anomaly scenarios; The weight generation model corresponding to the value anomaly scenario information is used to generate node weights corresponding to each node in the reduction relationship graph and edge weights corresponding to each edge.
5. The method according to claim 1, wherein: After setting the node weights corresponding to the nodes and the edge weights corresponding to the edges in the reduced relationship graph, the method further includes: Performing a weight check on the node weights corresponding to each of the nodes to obtain a first check result; Performing a weight check on the edge weights corresponding to the edges to obtain a second check result; In response to determining that the first verification result indicates that each node weight has passed verification and the second verification result indicates that each edge weight has passed verification, it is determined that the weighted relationship graph has passed the weight verification.
6. The method according to claim 5, wherein: The performing weight verification on the node weights corresponding to the respective nodes to obtain a first verification result includes: Performing weight bucketing processing on the node weights corresponding to the respective nodes to obtain a node weight set; For each node weight group in the set of node weight groups, the following generation steps are performed: According to at least one weight level, weight splitting the node weight group to obtain at least one first node weight subgroup; Determine the first value abnormal user ratio corresponding to each first node weight subgroup in the at least one first node weight subgroup to obtain at least one first value abnormal user ratio; Generating first verification information for the node weight group according to the at least one first value abnormal user ratio; A first verification result for the node weight set is generated according to the obtained first verification information set.
7. The method according to claim 5, wherein: The performing weight verification on the edge weights corresponding to the respective edges to obtain a second verification result includes: Performing weight bucketing processing on the edge weights corresponding to the edges to obtain an edge weight cluster; For each edge weight group in the edge weight group set, perform the following processing steps: According to at least one weight level, weight splitting the node weight group to obtain at least one second node weight subgroup; Determine the proportion of second value abnormal users corresponding to each second node weight subgroup in the at least one second node weight subgroup to obtain at least one second value abnormal user proportion; generating second verification information for the edge weight group according to the at least one second value abnormal user ratio; A second verification result for the edge weight set is generated according to the obtained second verification information set.
8. The method according to claim 1, wherein: The step of updating the node weights of the relationship graph after setting the weights to generate an updated relationship graph includes: Matching the corresponding scores of the nodes in the weighted relationship graph to obtain a relationship graph with matching scores; According to a score weighted update method for at least one neighbor node in a relationship graph, node score update processing is performed on each node in the relationship graph after matching scores to obtain a relationship graph after updated scores, wherein the score weighted update method is a method for updating the node score of a node to be updated based on at least one node score corresponding to at least one neighbor node associated with the node to be updated, at least one node weight corresponding to at least one neighbor node, a node score corresponding to the node to be updated, and a node weight corresponding to the node to be updated.
9. A relationship diagram generating device, comprising: An acquisition unit is configured to acquire a value transfer data set and a historical abnormal value transfer data set corresponding to at least one target correlation degree relationship medium within a target time period; A first generating unit is configured to generate an initial value transfer relationship graph according to the value transfer data set and the historical abnormal value transfer data set, wherein the initial value transfer relationship graph represents the association relationship between at least one target association degree relationship medium and user information; A graph reduction unit, configured to perform graph reduction processing on the initial value transfer relationship graph to obtain a reduced relationship graph; A setting unit, configured to set a node weight corresponding to each node and an edge weight corresponding to each edge in the reduced relationship graph; The generating unit is configured to update the node weights of the relationship graph after the weights are set, and generate an updated relationship graph.
10. An electronic device comprising: one or more processors; a storage device having one or more programs stored thereon, When the one or more programs are executed by the one or more processors, the one or more processors implement the method according to any one of claims 1 to 8.
11. A computer readable medium having a computer program stored thereon, wherein: When the computer program is executed by a processor, the method according to any one of claims 1 to 8 is implemented.
12. A computer program product, comprising a computer program, which, when executed by a processor, implements the method according to any one of claims 1 to 8.