Risk model updating method and device, electronic equipment and storage medium

By using the semi-supervised graph neural network model in the task processing platform to generate sample data sets and automatically update the risk model, the inefficiency and update lag problems caused by manual updates in the existing technology are solved, and the risk identification effect and update efficiency are improved.

CN120029639APending Publication Date: 2025-05-23JINGDONG TECH HLDG CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202311579811.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-11-23
Publication Date
2025-05-23

Smart Images

  • Figure CN120029639A_ABST
    Figure CN120029639A_ABST
Patent Text Reader

Abstract

The embodiment of the invention discloses a risk model updating method and device, electronic equipment and a storage medium. The method comprises the steps of determining current task interception data corresponding to a current risk model at a current moment in a task processing platform; generating a sample data set based on a semi-supervised graph neural network model under the condition that the current task interception data meets a preset updating condition; and training the current risk model based on the sample data set to obtain a target risk model corresponding to the current moment, and updating the current risk model in the task processing platform based on the target risk model. According to the technical scheme, the current risk model can be automatically updated, and the risk identification effect of the current risk model can be improved; moreover, the sample data set is generated based on the semi-supervised graph neural network, so that the marked sample required for training the current risk model is efficiently and quickly obtained, and the updating efficiency of the current risk model is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Embodiments of the present invention relate to the field of computer technology, and in particular to a model updating method, device, electronic device and storage medium. Background Art

[0002] With the increasing popularity of e-commerce and Internet services, in order to improve the security of the working process of e-commerce and Internet platforms, risk models are usually set up to identify and intercept risky behaviors in task requests received by the platform; and, the risk models need to be continuously updated to maintain efficient interception of different risky behaviors.

[0003] In the prior art, business personnel usually manually update the risk model periodically, and deploy and launch the risk model after training. However, in the process of implementing the present invention, it is found that the prior art has at least the following technical problems: manual training and updating of risk models has a long update cycle and a certain lag, resulting in poor risk identification effect of the updated risk model; and manual training and updating of models cannot avoid a large amount of repeated engineering development, which is inefficient and costly, and it is difficult to meet the increasingly rapid model update needs. Summary of the invention

[0004] The embodiments of the present invention provide a method, device, electronic device and storage medium for updating a risk model, so as to achieve the purpose of improving the risk identification effect and updating efficiency of the current risk model.

[0005] According to one aspect of the present invention, there is provided a method for updating a risk model, comprising:

[0006] Determine the current task interception data corresponding to the current risk model in the task processing platform at the current moment;

[0007] When the interception data of the current task meets the preset update conditions, a sample data set is generated based on the semi-supervised graph neural network model;

[0008] The current risk model is trained based on the sample data set to obtain a target risk model corresponding to the current moment, and the current risk model in the task processing platform is updated based on the target risk model.

[0009] According to another aspect of the present invention, there is provided a device for updating a risk model, the device comprising:

[0010] A current task interception data determination module is used to determine the current task interception data corresponding to the current risk model in the task processing platform at the current moment;

[0011] A sample data set generation module, used to generate a sample data set based on a semi-supervised graph neural network model when the interception data of the current task meets a preset update condition;

[0012] The current risk model updating module is used to train the current risk model based on the sample data set to obtain the target risk model corresponding to the current moment, and update the current risk model in the task processing platform based on the target risk model.

[0013] According to another aspect of the present invention, an electronic device is provided, the electronic device comprising:

[0014] at least one processor; and

[0015] a memory communicatively connected to the at least one processor; wherein,

[0016] The memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can execute the risk model updating method described in any embodiment of the present invention.

[0017] According to another aspect of the present invention, a computer-readable storage medium is provided, wherein the computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a processor to implement the risk model updating method described in any embodiment of the present invention when executed.

[0018] The technical solution of the embodiment of the present invention determines the current task interception data corresponding to the current risk model in the task processing platform at the current moment, and generates a sample data set based on the semi-supervised graph neural network model when the current task interception data meets the preset update conditions, so as to train the current risk model based on the sample data set, thereby using whether the current interception data meets the update conditions as a trigger condition for triggering the update of the current risk model; by training the current risk model, the target risk model corresponding to the current moment is obtained, and the current risk model in the task processing platform is updated based on the target risk model; the automatic update of the current risk model is realized, which solves the problems of low efficiency and untimely update caused by manual periodic update in the prior art, and helps to improve the risk identification effect of the current risk model; and, by generating a sample data set based on the semi-supervised graph neural network, there is no need to manually label all the sample data, and the labeled samples required for training the current risk model can be obtained efficiently and quickly, which helps to improve the update efficiency of the current risk model.

[0019] It should be understood that the contents described in this section are not intended to identify the key or important features of the embodiments of the present invention, nor are they intended to limit the scope of the present invention. Other features of the present invention will become easily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS

[0020] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.

[0021] Figure 1 is a flow chart of a method for updating a risk model provided according to an embodiment of the present invention;

[0022] Figure 2 is a flow chart of another risk model updating method provided according to an embodiment of the present invention;

[0023] Figure 3 is a schematic diagram of a risk model updating system provided according to an embodiment of the present invention;

[0024] Figure 4 is a schematic diagram of a process of an update iterative operation provided according to an embodiment of the present invention;

[0025] Figure 5 is a workflow diagram of an incremental sample expansion module provided according to an embodiment of the present invention;

[0026] Figure 6 is a schematic diagram of functional modules of a real-time model service subsystem provided according to an embodiment of the present invention;

[0027] Figure 7 is a schematic diagram of the structure of a risk model updating device provided according to an embodiment of the present invention;

[0028] Figure 8 It is a structural schematic diagram of an electronic device for implementing the risk model updating method of an embodiment of the present invention. DETAILED DESCRIPTION

[0029] In order to enable those skilled in the art to better understand the scheme of the present invention, the technical scheme in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work should fall within the scope of protection of the present invention.

[0030] It should be noted that the terms "first", "second", etc. in the specification and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence. It should be understood that the data used in this way can be interchanged where appropriate, so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "etc." and any variations thereof are intended to cover non-exclusive inclusions, for example, a process, method, system, product or device that includes a series of steps or units is not necessarily limited to those steps or units that are clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.

[0031] It should be noted that the collection, collection, updating, analysis, processing, use, transmission, storage and other aspects of user personal information involved in the technical solution of this disclosure are in compliance with the provisions of relevant laws and regulations, are used for legitimate purposes, and do not violate public order and good morals. Necessary measures are taken for user personal information to prevent illegal access to user personal information data and maintain the security of user personal information, network security and national security.

[0032] Before introducing the technical solution, an example of the application scenario can be first described. This technical solution can be applied to the scenario of updating the risk model, which is used to detect whether there is a risk in the business processing platform; exemplarily, the business processing platform may include an online item recommendation platform, a business consulting platform, etc. The risks existing in the business processing platform may include: the user accessing the business processing platform is a risk user, and the request operation on the business processing platform is a risk operation; for example, for the item recommendation platform, the risk operation may include the same user terminal using the user activity mechanism provided by the item recommendation platform to send a first number of service requests to the item recommendation platform to obtain a first number of items according to the value attribute value corresponding to the user activity mechanism; wherein the first number is greater than the preset number. In order to effectively and timely prevent the risks brought by risk operations to the business processing platform, it is necessary to timely update the risk model used to detect the risks of the business processing platform to cope with the endless risk operations. Based on the solution of this embodiment, the labeled samples required for training the current risk model can be obtained efficiently and quickly, and the current risk model can be updated in time.

[0033] Figure 1 1 is a flow chart of a method for updating a risk model provided according to an embodiment of the present invention. This embodiment is applicable to the case where a risk model for detecting risks of a business processing platform is updated. The method can be executed by a risk model update device, which can be implemented in the form of hardware and / or software.

[0034] like Figure 1 As shown, the method of this embodiment may specifically include:

[0035] S110, determining the current task interception data corresponding to the current risk model in the task processing platform at the current moment.

[0036] Among them, the task processing platform is a platform for receiving business requests and processing tasks corresponding to the business requests. Exemplarily, the business processing platform includes an online item recommendation platform. The current risk model is a model used to identify the risks existing in the task processing platform at the current moment; for example, the current risk model may be an XGBoost (eXtreme GradientBoosting) model. The current task interception data is used to reflect the interception of risky tasks in the task processing platform by the current risk model. It should be noted that in this embodiment, the current task interception data can reflect the current risk model's ability to identify risky tasks in the task processing platform.

[0037] In a specific implementation, the number of interception tasks that intercept tasks in the task processing platform within a preset time period corresponding to the current moment can be determined, and the current task interception data can be determined based on the interception data.

[0038] In this embodiment, the current task interception data includes the interception number of interception tasks. The specific implementation method of determining the current task interception data corresponding to the current risk model in the task processing platform at the current moment can be: determining the interception number of interception tasks corresponding to the current risk model in the task processing platform within a preset time period, so as to reflect the interception situation of the interception tasks by the current risk model within the preset time period through the interception number.

[0039] Alternatively, the current task interception data includes the current task interception rate; the implementation method of determining the current task interception data corresponding to the current risk model in the task processing platform at the current moment includes: determining the total number of tasks received in the task processing platform within a preset time period, and the interception number of intercepted tasks; determining the ratio of the total number to the interception number as the current task interception rate.

[0040] The preset time period may be a time period starting from the launch time of the current risk model and ending at the current time; or a time period starting from the current time and ending at a preset time interval. Those skilled in the art may set the preset time period according to the time application situation.

[0041] Specifically, the number of tasks intercepted by the current risk model within a preset time period is determined, as well as the total number of tasks received by the task processing platform within the preset time period, and the ratio of the total number to the number of interceptions is determined as the current task interception rate. This embodiment uses the current task interception rate as the current task interception data, combining the total number of received tasks and the number of interceptions, and can more accurately and effectively reflect the interception of intercepted tasks, as well as the current risk model's ability to identify risky tasks at the current moment, so as to determine whether the current risk model needs to be updated based on the current task interception data.

[0042] Optionally, after determining the current task interception data corresponding to the current risk model in the task processing platform at the current moment, it also includes: determining the predicted task interception data corresponding to the current risk model; determining the difference between the predicted task interception data and the current task interception data, if the difference is greater than a preset threshold, determining that the current task interception data meets the preset update conditions.

[0043] Among them, the predicted task interception data can be the ideal value of task interception set for the current risk model when the current risk model is online, which is used to reflect the risk identification ability of the current risk model under ideal circumstances. Exemplarily, the predicted task interception data can be the preset interception number of the interception task; or, it can be the predicted task interception rate, that is, the ratio of the total number of tasks received in a preset time period to the number of interceptions. For example, the predicted task interception rate can be set to 80%. The difference between the predicted task interception data and the current task interception data can be understood as: the absolute value of the predicted task interception data minus the current task interception data. The preset threshold is a positive number greater than 0.

[0044] In a specific implementation, the method for determining the prediction task interception data may be: obtaining pre-stored prediction task interception data; or, sending a data acquisition request to the operation and maintenance terminal, and determining the prediction task interception data based on the received feedback information.

[0045] After determining the interception data of the predicted task, the difference between the interception data of the predicted task and the interception data of the current task can be determined, and the difference reflects the gap between the actual risk identification ability of the current risk model and the preset ideal risk identification ability. If the difference is greater than the preset threshold, it means that the gap between the actual risk identification ability of the current risk model and the preset ideal risk identification ability is large, and the risks appearing in the task processing platform cannot be effectively identified. In order to improve the identification effect of risk tasks in the task processing platform, when the difference is greater than the preset threshold, it can be determined that the current task interception data meets the preset update conditions, and the current risk model can be updated.

[0046] This embodiment determines whether the current task interception data meets the preset update conditions by determining the difference between the predicted task interception data and the current task interception data, so as to accurately and quickly determine whether the current risk model needs to be updated, thereby automatically triggering the update operation of the current risk model.

[0047] S120. When the interception data of the current task meets the preset update conditions, a sample data set is generated based on the semi-supervised graph neural network model.

[0048] In this embodiment, if the update conditions are met, the current risk model can be updated based on the sample data set. Since a large amount of sample data is required to train the current risk model, labeling the sample data requires a lot of human resources and time. In order to reduce resource waste and improve the update efficiency of the current risk model, a sample data set can be generated based on a semi-supervised graph neural network model.

[0049] In a specific implementation, before generating a sample data set based on a semi-supervised graph neural network model, it includes: obtaining first task data, second task data and a first risk label corresponding to the first task data; generating a sample data set based on the semi-supervised graph neural network model, including: determining a second risk label corresponding to the second task data based on the semi-supervised graph neural network model, the first task data, the first risk label and the second task data; and forming a sample data set from the first task data, the second task data, the first risk label and the second risk label.

[0050] The first task data and the second task data may be task data pulled from the task processing platform. In order to enable the updated current risk model to identify the latest type of risk, historical task data within a preset time interval from the current moment may be pulled as the first task data and the second task data. For example, one tenth of the historical task data may be used as the first task data, and the remaining historical task data may be used as the second task data.

[0051] In this embodiment, the first risk label corresponding to the first task data can be obtained. The first risk label includes two situations: risky and non-risky. The first task data, the first risk label and the second task data can be clustered and learned by a semi-supervised graph neural network model to obtain the second risk label corresponding to the second task data. The first task data, the second task data, the first risk label and the second risk label form a sample data set.

[0052] This embodiment determines the first task data, the second task data and the first risk label through the task data pulled from the task processing platform, and generates a sample data set through a semi-supervised graph neural network model, so as to obtain the second risk label based on less first task data with the first risk label, and can efficiently and quickly obtain the labeled samples required for training the current risk model; and, by forming a sample data set with the task data pulled from the task processing platform, the updated current risk model has both the risk identification capability of the customer distribution of historical data and the risk identification capability of learning the newly added sample data set, which helps to improve the training effect of the current risk model.

[0053] S130: Train the current risk model based on the sample data set to obtain the target risk model corresponding to the current moment, and update the current risk model in the task processing platform based on the target risk model.

[0054] Among them, the target risk model can be an XGBoost model.

[0055] In a specific implementation, the current risk model can be trained based on the sample data set according to the preset target conditions to obtain a target risk model that meets the target conditions. Exemplarily, the target conditions may include the convergence of the loss function corresponding to the risk model to be trained during the training process; the risk model to be trained corresponding to the target condition being met is determined as the target risk model. The target risk model is used to replace the current risk model to complete the update operation of the current risk model.

[0056] In this embodiment, before updating the current risk model in the task processing platform based on the target risk model, it includes: sending the target risk model to the operation and maintenance terminal, and receiving the evaluation result of the target risk model fed back by the operation and maintenance terminal; updating the current risk model in the task processing platform based on the target risk model includes: when the evaluation result is passed, updating the current risk model in the task processing platform to the target risk model.

[0057] Among them, the evaluation results are used to reflect the recognition effect of the target risk model on the tasks in the task processing platform; illustratively, the evaluation results can be divided into two results: evaluation passed and evaluation failed, and the evaluation results are also expressed in the form of percentages. Based on the percentage corresponding to the evaluation results, it is determined whether the target risk model passes the evaluation.

[0058] In the specific implementation, in order to ensure the risk identification effect of the updated current risk model, the target risk model can be sent to the operation and maintenance terminal so that the operation and maintenance staff can evaluate the target risk model. Based on the received evaluation results, it is determined whether to update the current risk model.

[0059] Specifically, for the evaluation results including the evaluation passed and the evaluation failed, if the evaluation result is the evaluation passed, it means that the risk identification effect of the target risk model meets the requirements, and the current risk model in the task processing platform can be updated to the target risk model; if the evaluation result is failed, the sample data set can be regenerated to train the current risk model until the trained target risk model passes the evaluation. For the case where the evaluation result is expressed as a percentage, it can be determined whether the percentage corresponding to the evaluation result is greater than the preset passing percentage. If it is greater than the preset passing percentage, it can be determined that the target risk model has passed the evaluation; if it is less than or equal to the preset passing percentage, it means that the evaluation result has failed.

[0060] This embodiment further improves the effectiveness of the target risk model in risk identification by evaluating the target risk model before updating the current risk model.

[0061] The technical solution of the embodiment of the present invention determines the current task interception data corresponding to the current risk model in the task processing platform at the current moment, and generates a sample data set based on the semi-supervised graph neural network model when the current task interception data meets the preset update conditions, so as to train the current risk model based on the sample data set, thereby using whether the current interception data meets the update conditions as a trigger condition for triggering the update of the current risk model; by training the current risk model, the target risk model corresponding to the current moment is obtained, and the current risk model in the task processing platform is updated based on the target risk model; the automatic update of the current risk model is realized, which solves the problems of low efficiency and untimely update caused by manual periodic update in the prior art, and helps to improve the risk identification effect of the current risk model; and, by generating a sample data set based on the semi-supervised graph neural network, there is no need to manually label all the sample data, and the labeled samples required for training the current risk model can be obtained efficiently and quickly, which helps to improve the update efficiency of the current risk model.

[0062] Figure 2 It is a flowchart of another risk model updating method provided according to an embodiment of the present invention. Optionally, after updating the current risk model in the task processing platform based on the target risk model, it also includes: upon receiving a task request sent by a user terminal, determining the task characteristics corresponding to the user terminal; performing data processing on the task characteristics, inputting the processed task characteristics into the updated current risk model, and obtaining a risk assessment value corresponding to the task characteristics; and determining the risk level of the task request based on the risk assessment value. Among them, the explanations of the terms that are the same as or corresponding to the above embodiments are not repeated here. Figure 2 As shown, the method includes:

[0063] S210: Determine the current task interception data corresponding to the current risk model in the task processing platform at the current moment.

[0064] S220. When the interception data of the current task meets the preset update conditions, a sample data set is generated based on the semi-supervised graph neural network model.

[0065] S230: Train the current risk model based on the sample data set to obtain the target risk model corresponding to the current moment, and update the current risk model in the task processing platform based on the target risk model.

[0066] S240: When receiving a task request sent by a user terminal, determine a task feature corresponding to the user terminal.

[0067] The task characteristics are used to reflect the characteristics of at least one task request sent by the user terminal. For example, if the task processing platform is a shopping platform, the task request may be a shopping request; accordingly, the task characteristics corresponding to the user terminal may be the order quantity, order address, and other characteristics corresponding to the shopping request sent by the user terminal in the historical time period.

[0068] Specifically, the task characteristics corresponding to the task requests of the user terminal in the historical time period can be determined through the pre-stored request records of the user terminal. For example, the historical time period can be a time period one week away from the current time; the task characteristics can include the number of delivery addresses of the orders corresponding to the user terminal in the past week.

[0069] S250: Perform data processing on the task characteristics, input the processed task characteristics into the updated current risk model, and obtain the risk assessment value corresponding to the task characteristics.

[0070] The data processing includes at least one of data deduplication, abnormal feature replacement and feature fusion processing. The risk assessment value is used to reflect the risk level of the task request sent by the user terminal. Exemplarily, the risk assessment value can be a specific value or a proportional value; when it is a proportional value, the value range can be [0,1]. For example, the output risk assessment value is 95%.

[0071] In a specific implementation, the specific implementation method of data processing on the task features includes: determining whether there is duplicate data in the task features, and if so, performing data deduplication processing. The deduplication processing ensures that the information of the task features is complete while removing redundant data.

[0072] Alternatively, a specific implementation method of performing data processing on task characteristics includes: if there are abnormal characteristics in the task characteristics, the abnormal characteristics are replaced based on a preset backup characteristic.

[0073] Among them, the abnormal feature may be a feature that exceeds the normal value range of the task feature. Exemplarily, if the task feature is the number of orders, the normal value range of the task feature is a non-negative number; if a negative number is detected in the task feature, the task feature can be determined as an abnormal feature. The bottom-line feature is pre-determined for the type of task feature. For example, if the task feature is the number of orders, the bottom-line feature can be determined as the average number of orders placed by the user terminal in the historical time period.

[0074] In a specific implementation, each task feature can be detected based on a predetermined detection rule to determine abnormal features. For example, when the task feature is the order quantity, the detection rule can be determined to determine whether the task feature is a negative number, and if it is a negative number, the task feature is determined to be an abnormal feature. In order to avoid the impact of abnormal features on the risk identification process, the corresponding backup feature of the task feature can be determined to replace the abnormal feature, ensure the correctness of the task feature input into the current risk model, and thus ensure the correctness of the risk assessment value.

[0075] Alternatively, a specific implementation of data processing on task features includes: performing feature fusion processing on at least one task feature based on a predetermined order of inputting the updated current risk model.

[0076] It should be noted that the current risk model needs to combine at least one task feature to identify whether a task request is risky. In the case where multiple task features need to be combined, the task features can be fused and then input into the current risk model.

[0077] The input order is the order requirement of the current risk model for the type of input features or the data source.

[0078] In this embodiment, since the business scenarios of the current risk model application are different, the corresponding input task features are put into the model in different orders, and the order of inputting the model can be uploaded by the operation and maintenance terminal when the current risk model is updated. Specifically, for each determined task feature, feature fusion processing is performed according to a predetermined order of inputting the model to obtain the input features of the current risk model.

[0079] This embodiment performs feature fusion processing on task features according to the order in which they are input into the model, thereby ensuring that the current risk model can work properly and avoiding risk identification errors caused by the disordered input order of the input task features.

[0080] In the specific implementation, the processed task features can be input into the updated current risk model to obtain the risk assessment value corresponding to the task features. The larger the risk assessment value, the greater the risk of the task request sent by the user terminal; conversely, the smaller the risk of the task request sent by the user terminal.

[0081] In order to conduct a comprehensive and detailed detection of various types of risks in the business processing platform, optionally, the number of current risk models includes two or more, so as to identify different types of risks through different current risk models. Exemplarily, when the business processing platform is a shopping platform, the current risk model may include two, one is a delivery address risk identification model, which is used to identify the risks of the delivery address provided by the user terminal; the other may be a preferential activity risk identification model, which is used to identify the risk of whether the user terminal uses the preferential activity abnormally.

[0082] In the case where there are two or more current risk models, the processed task features are input into the updated current risk model. The specific implementation method for obtaining the risk assessment value corresponding to the task features can be: for each current risk model, the model task features corresponding to the current risk model are determined from the processed task features, the model task features are input into the current risk model, and the model risk values ​​corresponding to the model task features are output; based on the predetermined risk weights corresponding to each current risk model, the risk values ​​of each model are weighted summed to obtain the risk assessment value.

[0083] Since each current risk model identifies different risk types, the corresponding task features that need to be input are also different. In order to ensure that each current risk model can work properly, for each current risk model, the model task features corresponding to the current risk model can be determined in the task features. For example, for the delivery address risk identification model, the features containing the delivery address information can be determined in the task features as the model task features.

[0084] Furthermore, by inputting the model task characteristics into the current risk model, a model risk value corresponding to the model task characteristics can be output to reflect the risk identification type for the current risk model and the risk level of the task request.

[0085] In order to determine the comprehensive risk level of the task request, risk weights can be set for the current risk models used to identify different risk types according to the importance of different risk types. The risk assessment value corresponding to the task request is determined by weighted summing the risk values ​​of each model.

[0086] In this embodiment, by setting at least two current risk models for identifying different types of risks, the risks existing in the task request are comprehensively and detailedly detected, which is conducive to improving the accuracy and comprehensiveness of risk identification; and by weighted summing up the risk values ​​of each model, the risk assessment value is determined based on the importance of the impact of different risk types, taking into account the impact of each risk type, and can be flexibly applied to different business scenarios.

[0087] S260: Determine the risk level of the task request based on the risk assessment value.

[0088] Specifically, the larger the risk assessment value is, the higher the risk level of the task request is; and the smaller the risk assessment value is, the lower the risk level of the task request is.

[0089] Exemplarily, the risk level may include three levels: high, medium, and low; before determining the risk level of the task request, a first risk threshold and a second risk threshold may be set; wherein the second risk threshold is greater than the first risk threshold. Based on the risk assessment value, the specific implementation method of determining the risk level of the task request may be: determining whether the risk assessment value is less than the first risk threshold; if less than, determining the risk level of the task request to be low; if the risk assessment value is greater than or equal to the first risk threshold, determining whether the risk assessment value is less than the second risk threshold, if less than the second risk threshold, determining the risk level of the task request to be medium; if greater than or equal to the second risk threshold, determining the risk level of the task request to be high.

[0090] In this embodiment, if the risk level of the task request is high, to ensure the security of task processing, the task request can be intercepted and a prompt message can be generated and fed back to the user terminal to prompt the user to terminate the task request. There is a risk and please confirm.

[0091] Furthermore, if the risk level of the task request is medium or low, the task request sent by the user terminal can be executed. Optionally, after determining the risk level of the task request based on the risk assessment value, it also includes: determining execution information during the execution of the task request; when the execution information meets the preset abnormal condition, generating abnormal information and feeding it back to the operation and maintenance terminal for abnormal warning.

[0092] The execution information includes flow information and / or response time information.

[0093] In a specific implementation, the execution information in the process of executing the task request can be determined by the gateway. For example, if the execution information is flow information, the preset abnormal condition is that the flow value corresponding to the flow information is greater than the preset flow threshold; if the execution information is response duration information, the preset abnormal condition can be that the response duration corresponding to the response duration information is greater than the preset duration. Those skilled in the art can pre-set the preset flow threshold and preset duration according to the actual business scenario.

[0094] When the execution information meets the preset abnormal conditions, it means that an abnormality has occurred in the process of executing the task request. To ensure that the task request can be effectively executed, the abnormal information can be fed back to the operation and maintenance terminal for abnormal warning. In this embodiment, when the execution information meets the preset abnormal conditions, abnormal information is generated and fed back to the operation and maintenance terminal to provide an early warning based on the abnormal situation, which helps to ensure that the task request can be effectively executed; at the same time, abnormal situations can be discovered in time to avoid the execution of risky task requests.

[0095] This embodiment illustrates the implementation method of risk identification using the updated current risk model, so that when a task request is found to be risky, timely intervention can be made to intercept the risky task request, reduce the losses caused by the execution of risky task requests, and help improve the security of the business processing platform in processing task requests; and, for execution information that meets preset abnormal conditions during the execution process, abnormal information is generated to prompt, thereby ensuring that the task request can be effectively executed.

[0096] The above describes in detail the embodiments corresponding to the method for updating the risk model. In order to make the technical solution of the method further clear to those skilled in the art, a specific application scenario is given below.

[0097] This embodiment provides a schematic diagram of a risk model update system; Figure 3 As shown, the update system includes a model iteration trigger module, an incremental sample expansion module, a model training module, and a real-time model service subsystem. The risk model update system can be used in scenarios where the risk model of an online item recommendation platform is updated. Task requests may include order requests. The risk model can intercept order requests for unconventional items obtained by user terminals using the user activity mechanism provided by the item recommendation platform to ensure the operational security of the online item recommendation platform.

[0098] In this embodiment, the model iteration trigger module can realize functions such as order interception rate determination, interception rate detection, effect evaluation, and triggering model iteration; the incremental sample expansion module can realize functions such as incremental data acquisition, label learning, incremental data output, and data set labeling; the model training module can realize functions such as data fusion, model training, model file update, and automatic deployment; the implementation of the model service subsystem can realize functions such as feature extraction and real-time intervention.

[0099] For this application scenario, the four parts of the model iteration trigger module, incremental sample expansion module, model training module and real-time model service subsystem are explained in detail.

[0100] Model iteration trigger module: used to perform real-time detection on the risk identification effect of the current risk model, and trigger the model iteration function when the risk identification effect of the current risk model decays, so as to complete the update and iteration operation of the current risk model.

[0101] Among them, the process of updating the iterative operation is as follows Figure 4 As shown, the following steps are included:

[0102] 1. Determine the total number of orders received by the item recommendation platform within the preset time period and the number of intercepted orders determined as abnormal orders by the current risk model. The total number of orders is divided by the number of interceptions to determine the online order interception rate.

[0103] 2. Based on the predetermined predicted order interception rate, the risk identification effect of the current risk model is evaluated. Specifically, the difference between the online order interception rate and the predicted order interception rate is determined. If the difference is greater than the preset threshold, it is determined that the current risk model needs to be iteratively updated, and the update operation of the current risk model is triggered; if the difference is less than or equal to the preset threshold, there is no need to iteratively update the current risk model, and the evaluation result of the current risk model can be generated based on the difference and fed back to the operation and maintenance terminal.

[0104] Incremental sample expansion module: used to pull online order data from the online item recommendation platform, and perform label learning on the order data based on the semi-supervised graph neural network model, and form the labeled data into an incremental sample data set to update the current risk model.

[0105] The workflow diagram of the incremental sample expansion module is as follows: Figure 5 As shown, the following steps may be included:

[0106] 1. Pull online order data through message queues, logs, and hive data warehouse tools. Divide the online order data into first task data and second task data, and use a labeling tool to label the first task data to obtain a first risk label; the number of first task data is less than the number of second task data; the labels include risky and non-risky.

[0107] 2. Input the first task data, the second task data, and the first risk label into the pre-trained semi-supervised neural network model, perform label learning on the order data through clustering, and obtain the second risk label corresponding to the second task data. The first task data, the second task data, the first risk label, and the second risk label constitute an incremental sample data set.

[0108] Among them, the main structure of the semi-supervised neural network model is as follows:

[0109] Node: The user ID corresponding to the user terminal is used as the node to predict the risk attribute of the node.

[0110] Edge prediction: Predict whether there is a link between two nodes, for example, whether there is a link between the delivery address, order time, item category, activity number, etc.

[0111] Node clustering: Detect whether the nodes form a clustered community. The semi-supervised neural network model contains the extracted risk attribute user nodes and risk-free attribute user nodes as labeled data. When the unlabeled data generates a clustering relationship to the labeled data through edge links, the unlabeled data can learn the label knowledge of the risk attribute.

[0112] Model training module: Establish training tasks for the current risk model, train the current risk model based on the incremental sample data set, and obtain the target risk model. The target risk model is evaluated, and if the evaluation passes, the target risk model is pushed to the model warehouse for online model update and deployment.

[0113] Real-time model service subsystem: used to perform risk detection on received order requests in real time based on the authorization information and order requests of the user terminal, and to intervene in order requests with risks in a timely manner.

[0114] Figure 6 is a schematic diagram of functional modules of a real-time model service subsystem provided according to an embodiment of the present invention; Figure 6 As shown in the figure, the real-time model service subsystem includes gateway detection, feature processing, and risk model detection. Each part is described in detail below.

[0115] 1. Gateway

[0116] Traffic control: Determine the total traffic of order requests on the online item recommendation platform. When the total traffic exceeds the preset total traffic threshold, start the traffic control mechanism. The traffic control mechanism may include flow limiting, capacity expansion and other operation mechanisms.

[0117] Authority review: Based on the request identifier in the order request of the user terminal, determine the request authority and requested business of the user terminal, and review the request authority of the user terminal.

[0118] Request scheduling: For user terminals with request permissions, order requests are routed to different current risk models for different types of risk identification according to the types of requested services, and request scheduling is completed; and abnormal requests that do not match the requested services and request permissions are deleted.

[0119] Abnormal warning: When executing an order request, an alarm will be issued for abnormal situations such as the call traffic being greater than the preset traffic threshold, or the response time being longer than the preset duration.

[0120] 2. Feature processing

[0121] Feature fusion: According to the set model entry order of the current risk model, the task features corresponding to the order request are obtained, and the feature fusion operation is performed on each task feature according to the model entry order.

[0122] Backup cache: For abnormal features in task characteristics, pre-set cache values ​​are used to assign them.

[0123] 3. Risk model detection

[0124] The processed task features are passed to at least one current risk model to obtain the model scores corresponding to each current risk model; wherein the model scores are risk assessment values ​​output for the task features, and the risk level corresponding to the risk assessment value is determined according to the preset risk assessment method, thereby determining whether the order request has risks, and feeding back the risk level to the user terminal. Real-time intervention is performed on risky order requests.

[0125] This embodiment performs cluster analysis on sample data through a semi-supervised graph neural network model, so that the current risk model can efficiently and quickly obtain the sample data set required for model training; and, by setting a model iteration trigger module, the current risk model is automatically updated in a timely manner, making risk interception operations more efficient, while avoiding duplication of work for developers, meeting risk identification requirements while reducing costs and increasing efficiency.

[0126] Figure 7 1 is a schematic diagram of a structure of a risk model updating device provided according to an embodiment of the present invention, and the device is used to execute the risk model updating method provided in any of the above embodiments. The device and the risk model updating method of the above embodiments belong to the same inventive concept, and the details not described in detail in the embodiment of the risk model updating device can refer to the embodiment of the risk model updating method. Figure 7 As shown, the device comprises:

[0127] The current task interception data determination module 10 is used to determine the current task interception data corresponding to the current risk model in the task processing platform at the current moment;

[0128] A sample data set generation module 11 is used to generate a sample data set based on a semi-supervised graph neural network model when the interception data of the current task meets the preset update conditions;

[0129] The current risk model updating module 12 is used to train the current risk model based on the sample data set to obtain the target risk model corresponding to the current moment, and update the current risk model in the task processing platform based on the target risk model.

[0130] Based on any optional technical solution in the embodiment of the present invention, optionally, the current task interception data includes a current task interception rate; and the current task interception data determination module 10 includes:

[0131] An interception quantity determination unit, used to determine the total number of tasks received in the task processing platform within a preset time period, and the interception number of intercepted tasks;

[0132] The current task interception rate determination unit is used to determine the ratio of the total number to the interception number as the current task interception rate.

[0133] Based on any optional technical solution in the embodiments of the present invention, optionally, the following further includes:

[0134] A prediction task interception data determination module, configured to determine the prediction task interception data corresponding to the current risk model after determining the current task interception data corresponding to the current risk model at the current moment in the task processing platform;

[0135] The difference determination module is used to determine the difference between the predicted task interception data and the current task interception data. If the difference is greater than a preset threshold, it is determined that the current task interception data meets the preset update condition.

[0136] Based on any optional technical solution in the embodiments of the present invention, optionally, the following further includes:

[0137] A first risk label acquisition module, used to acquire the first task data, the second task data and the first risk label corresponding to the first task data before generating a sample data set based on the semi-supervised graph neural network model;

[0138] The sample data set generation module 11 includes:

[0139] A second risk label determination unit, configured to determine a second risk label corresponding to the second task data based on the semi-supervised graph neural network model, the first task data, the first risk label, and the second task data;

[0140] The sample data set composition unit is used to compose a sample data set from the first task data, the second task data, the first risk label and the second risk label.

[0141] Based on any optional technical solution in the embodiments of the present invention, optionally, the following further includes:

[0142] An evaluation result receiving module is used to send the target risk model to the operation and maintenance terminal before updating the current risk model in the task processing platform based on the target risk model, and receive the evaluation result of the target risk model fed back by the operation and maintenance terminal;

[0143] The current risk model update module 12 includes:

[0144] The current risk model updating unit is used to update the current risk model in the task processing platform to the target risk model when the evaluation result is that the evaluation passes.

[0145] Based on any optional technical solution in the embodiments of the present invention, optionally, the following further includes:

[0146] A task feature determination module, configured to determine a task feature corresponding to a user terminal upon receiving a task request sent by a user terminal after updating a current risk model in the task processing platform based on a target risk model;

[0147] The risk assessment value determination module is used to process the task characteristics and input the processed task characteristics into the updated current risk model to obtain the risk assessment value corresponding to the task characteristics;

[0148] The risk level determination module is used to determine the risk level of the task request based on the risk assessment value.

[0149] Based on any optional technical solution in the embodiments of the present invention, optionally, the risk assessment value determination module includes:

[0150] The abnormal feature replacement unit is used to replace the abnormal feature based on a preset backup feature if there is an abnormal feature in the task feature.

[0151] Based on any optional technical solution in the embodiments of the present invention, optionally, the risk assessment value determination module includes:

[0152] The feature fusion unit is used to perform feature fusion processing on at least one task feature based on a predetermined order of inputting the updated current risk model.

[0153] Based on any optional technical solution in the embodiment of the present invention, optionally, the number of current risk models includes two or more;

[0154] The risk assessment value determination module includes:

[0155] A model risk value output unit is used to determine, for each current risk model, a model task feature corresponding to the current risk model from the processed task features, input the model task feature into the current risk model, and output a model risk value corresponding to the model task feature;

[0156] The weighted summation unit is used to perform weighted summation on the risk values ​​of each model based on the predetermined risk weights corresponding to each current risk model to obtain a risk assessment value.

[0157] Based on any optional technical solution in the embodiments of the present invention, optionally, the following further includes:

[0158] An execution information module, used to determine the execution information during the execution of the task request;

[0159] The abnormal warning module is used to generate abnormal information and feed it back to the operation and maintenance terminal for abnormal warning when the execution information meets the preset abnormal conditions;

[0160] The execution information includes flow information and / or response time information.

[0161] The technical solution of the embodiment of the present invention determines the current task interception data corresponding to the current risk model in the task processing platform at the current moment, and generates a sample data set based on the semi-supervised graph neural network model when the current task interception data meets the preset update conditions, so as to train the current risk model based on the sample data set, thereby using whether the current interception data meets the update conditions as a trigger condition for triggering the update of the current risk model; by training the current risk model, the target risk model corresponding to the current moment is obtained, and the current risk model in the task processing platform is updated based on the target risk model; the automatic update of the current risk model is realized, which solves the problems of low efficiency and untimely update caused by manual periodic update in the prior art, and helps to improve the risk identification effect of the current risk model; and, by generating a sample data set based on the semi-supervised graph neural network, there is no need to manually label all the sample data, and the labeled samples required for training the current risk model can be obtained efficiently and quickly, which helps to improve the update efficiency of the current risk model.

[0162] It is worth noting that in the embodiment of the above-mentioned risk model updating device, the various units and modules included are only divided according to functional logic, but are not limited to the above-mentioned division, as long as the corresponding functions can be achieved; in addition, the specific names of the functional units are only for the convenience of distinguishing each other, and are not used to limit the scope of protection of the present invention.

[0163] Figure 8 Schematic diagram of the structure of an electronic device for implementing the updating method of the risk model of an embodiment of the present invention. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device may also represent various forms of mobile devices, such as personal digital processing, cellular phones, smart phones, wearable devices (such as helmets, glasses, watches, etc.) and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely examples and are not intended to limit the implementation of the present invention described and / or required herein.

[0164] like Figure 8 As shown, the electronic device 20 includes at least one processor 21, and a memory connected to the at least one processor 21, such as a read-only memory (ROM) 22, a random access memory (RAM) 23, etc., wherein the memory stores a computer program that can be executed by at least one processor, and the processor 21 can perform various appropriate actions and processes according to the computer program stored in the read-only memory (ROM) 22 or the computer program loaded from the storage unit 28 to the random access memory (RAM) 23. In RAM23, various programs and data required for the operation of the electronic device 20 can also be stored. The processor 21, ROM22 and RAM23 are connected to each other through a bus 24. An input / output (I / O) interface 25 is also connected to the bus 24.

[0165] A number of components in the electronic device 20 are connected to the I / O interface 25, including: an input unit 26, such as a keyboard, a mouse, etc.; an output unit 27, such as various types of displays, speakers, etc.; a storage unit 28, such as a disk, an optical disk, etc.; and a communication unit 29, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 29 allows the electronic device 20 to exchange information / data with other devices through a computer network such as the Internet and / or various telecommunication networks.

[0166] The processor 21 may be a variety of general and / or special processing components with processing and computing capabilities. Some examples of the processor 21 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various special artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any appropriate processor, controller, microcontroller, etc. The processor 21 executes the various methods and processes described above, such as the update method of the risk model.

[0167] In some embodiments, the updating method of the risk model may be implemented as a computer program, which is tangibly contained in a computer-readable storage medium, such as a storage unit 28. In some embodiments, part or all of the computer program may be loaded and / or installed on the electronic device 20 via the ROM 22 and / or the communication unit 29. When the computer program is loaded into the RAM 23 and executed by the processor 21, one or more steps of the updating method of the risk model described above may be performed. Alternatively, in other embodiments, the processor 21 may be configured to execute the updating method of the risk model in any other appropriate manner (e.g., by means of firmware).

[0168] Various implementations of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), systems on chips (SOCs), load programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various implementations can include: being implemented in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which can be a special purpose or general purpose programmable processor that can receive data and instructions from a storage system, at least one input device, and at least one output device, and transmit data and instructions to the storage system, the at least one input device, and the at least one output device.

[0169] Computer programs for implementing the methods of the present invention may be written in any combination of one or more programming languages. These computer programs may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, so that when the computer program is executed by the processor, the functions / operations specified in the flow chart and / or block diagram are implemented. The computer program may be executed entirely on the machine, partially on the machine, partially on the machine and partially on a remote machine as a stand-alone software package, or entirely on a remote machine or server.

[0170] In the context of the present invention, a computer-readable storage medium may be a tangible medium that may contain or store a computer program for use by or in combination with an instruction execution system, device or equipment. A computer-readable storage medium may include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, devices or equipment, or any suitable combination of the foregoing. Alternatively, a computer-readable storage medium may be a machine-readable signal medium. A more specific example of a machine-readable storage medium may include an electrical connection based on one or more lines, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0171] To provide interaction with a user, the systems and techniques described herein may be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and a pointing device (e.g., a mouse or trackball) through which the user can provide input to the electronic device. Other types of devices may also be used to provide interaction with the user; for example, the feedback provided to the user may be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user may be received in any form (including acoustic input, voice input, or tactile input).

[0172] The systems and techniques described herein may be implemented in a computing system that includes backend components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes frontend components (e.g., a user computer with a graphical user interface or a web browser through which a user can interact with implementations of the systems and techniques described herein), or a computing system that includes any combination of such backend components, middleware components, or frontend components. The components of the system may be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include: a local area network (LAN), a wide area network (WAN), a blockchain network, and the Internet.

[0173] A computing system may include a client and a server. The client and the server are generally remote from each other and usually interact through a communication network. The client and server relationship is generated by computer programs running on the corresponding computers and having a client-server relationship with each other. The server may be a cloud server, also known as a cloud computing server or cloud host, which is a host product in the cloud computing service system to solve the defects of difficult management and weak business scalability in traditional physical hosts and VPS services.

[0174] It should be understood that the various forms of processes shown above can be used to reorder, add or delete steps. For example, the steps described in the present invention can be executed in parallel, sequentially or in different orders, as long as the desired results of the technical solution of the present invention can be achieved, and this document does not limit this.

[0175] The above specific implementations do not constitute a limitation on the protection scope of the present invention. It should be understood by those skilled in the art that various modifications, combinations, sub-combinations and substitutions can be made according to design requirements and other factors. Any modification, equivalent substitution and improvement made within the spirit and principle of the present invention should be included in the protection scope of the present invention.

Claims

1. A method for updating risk models, It is characterized in that include: Determine the current task interception data corresponding to the current risk model in the task processing platform at the current moment; When the interception data of the current task meets the preset update conditions, a sample data set is generated based on the semi-supervised graph neural network model; The current risk model is trained based on the sample data set to obtain a target risk model corresponding to the current moment, and the current risk model in the task processing platform is updated based on the target risk model.

2. The method according to claim 1, It is characterized in that The current task interception data includes the current task interception rate; The determining of the current task interception data corresponding to the current risk model in the task processing platform at the current moment includes: Determine the total number of tasks received in the task processing platform within a preset time period, and the interception number of intercepted tasks; The ratio of the total number to the interception number is determined as the current task interception rate.

3. The method according to claim 1 or 2, It is characterized in that After determining the current task interception data corresponding to the current risk model at the current moment in the task processing platform, the method further includes: Determining prediction task interception data corresponding to the current risk model; A difference between the predicted task interception data and the current task interception data is determined, and if the difference is greater than a preset threshold, it is determined that the current task interception data meets a preset update condition.

4. The method according to claim 1, It is characterized in that Before generating a sample data set based on the semi-supervised graph neural network model, the method includes: Acquire first task data, second task data, and a first risk label corresponding to the first task data; The generating of a sample data set based on a semi-supervised graph neural network model comprises: Based on the semi-supervised graph neural network model, the first task data, the first risk label and the second task data, determining a second risk label corresponding to the second task data; The sample data set is composed of the first task data, the second task data, the first risk label and the second risk label.

5. The method according to claim 1, It is characterized in that Before the current risk model in the task processing platform is updated based on the target risk model, the method includes: Sending the target risk model to the operation and maintenance terminal, and receiving the evaluation result of the target risk model fed back by the operation and maintenance terminal; The updating of the current risk model in the task processing platform based on the target risk model includes: When the evaluation result is that the evaluation is passed, the current risk model in the task processing platform is updated to the target risk model.

6. The method according to claim 1, It is characterized in that After the current risk model in the task processing platform is updated based on the target risk model, the method further includes: When receiving a task request sent by a user terminal, determining a task feature corresponding to the user terminal; Performing data processing on the task characteristics, inputting the processed task characteristics into an updated current risk model, and obtaining a risk assessment value corresponding to the task characteristics; Based on the risk assessment value, a risk level of the task request is determined.

7. The method according to claim 6, It is characterized in that The data processing of the task features includes: If there are abnormal features in the task features, the abnormal features are replaced based on pre-set fallback features.

8. The method according to claim 6, It is characterized in that The data processing of the task features includes: Based on the predetermined updated order of inputting the current risk model, feature fusion processing is performed on at least one of the task features.

9. The method according to claim 6, It is characterized in that The number of the current risk models includes two or more; The step of inputting the processed task features into the updated current risk model to obtain the risk assessment value corresponding to the task features includes: For each of the current risk models, determine a model task feature corresponding to the current risk model from the processed task features, input the model task feature into the current risk model, and output a model risk value corresponding to the model task feature; Based on the predetermined risk weights corresponding to the current risk models, the risk values ​​of the models are weighted and summed to obtain the risk assessment value.

10. The method according to claim 6, It is characterized in that Also includes: Determining execution information in the process of executing the task request; When the execution information meets the preset abnormal conditions, abnormal information is generated and fed back to the operation and maintenance terminal for abnormal warning; The execution information includes flow information and / or response time information.

11. A device for updating a risk model, It is characterized in that include: A current task interception data determination module is used to determine the current task interception data corresponding to the current risk model in the task processing platform at the current moment; A sample data set generation module, used to generate a sample data set based on a semi-supervised graph neural network model when the interception data of the current task meets a preset update condition; The current risk model updating module is used to train the current risk model based on the sample data set to obtain the target risk model corresponding to the current moment, and update the current risk model in the task processing platform based on the target risk model.

12. An electronic device, It is characterized in that The electronic device comprises: at least one processor; and a memory communicatively connected to the at least one processor; wherein, The memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can perform the risk model updating method according to any one of claims 1 to 10.

13. A computer-readable storage medium, It is characterized in that The computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a processor to implement the risk model updating method according to any one of claims 1 to 10 when executed.