Decision tree training method and device and method and device for determining risk users
By introducing the penalty factor function and Gini index during the training of the decision tree, the missed judgment problem caused by excessive attribute value when selecting split points is solved, and the accurate detection and recall of risk users are achieved.
Patent Information
- Application Number
- CN202411897626.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-20
- Publication Date
- 2025-05-27
AI Technical Summary
When selecting a split point in the decision tree, the attribute value is too large, resulting in a large number of recalls missing, thus missing risk users.
By constructing a sample set containing user behavior characteristics, calculate the Gini index of each user behavior characteristics, and train the decision tree based on the penalty factor function and Gini index to avoid missed judgment problems caused by too large or too small attribute values.
Improve the effectiveness of recall, avoid missed detection of risk users, and ensure accurate detection of risk users.
Smart Images

Figure CN120046705A_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the field of computer technologies, and in particular, to a method for training a decision tree, a method for determining risk users, and the field of machine learning technologies. Background Art
[0002] In the field of risk control, in order to effectively identify risk users, a decision tree model is often used to judge user behavior characteristics and determine risk users.
[0003] In some cases, the numerical value of the attribute value corresponding to the split point selected by the decision tree is very large, which may result in a large number of recalls being missed when applying the decision tree, thereby leading to the risk of missing the judgment of risk users. Summary of the Invention
[0004] The present disclosure provides a method for training a decision tree, a method for determining risk users, and an apparatus for solving at least one of the above technical problems.
[0005] According to one aspect of the present disclosure, there is provided a method for training a decision tree, wherein the method includes:
[0006] Constructing a sample set including user behavior characteristics;
[0007] Calculating the values of the Gini indices of each of the user behavior characteristics in the sample set respectively:
[0008] Training an initial decision tree based on a penalty factor function and the values of the Gini indices of each of the user behavior characteristics to obtain a trained decision tree;
[0009] Wherein the trained decision tree is used to determine risk users according to user behavior characteristics.
[0010] According to one aspect of the present disclosure, there is provided a method for determining risk users, wherein the method includes:
[0011] Inputting user behavior characteristics into a trained decision tree to obtain risk users output by the trained decision tree;
[0012] Wherein the trained decision tree is trained by the above method.
[0013] According to another aspect of the present disclosure, there is provided a decision tree training apparatus, wherein the apparatus includes:
[0014] A sample module for constructing a sample set including user behavior characteristics;
[0015] A Gini module for calculating the values of the Gini indices of each of the user behavior characteristics in the sample set respectively:
[0016] A training module, configured to train an initial decision tree based on a penalty factor function and the values of the Gini indices of each of the user behavior characteristics, to obtain a trained decision tree;
[0017] Wherein, the trained decision tree is configured to determine risk users according to user behavior characteristics.
[0018] According to another aspect of the present disclosure, there is provided an apparatus for determining risk users, wherein the apparatus includes:
[0019] A determination module, configured to input user behavior characteristics into the trained decision tree, to obtain the risk users output by the trained decision tree;
[0020] Wherein, the trained decision tree is trained by using the above method.
[0021] According to another aspect of the present disclosure, there is provided an electronic device, including:
[0022] At least one processor; and
[0023] A memory communicatively connected to the at least one processor; wherein,
[0024] The memory stores instructions executable by the at least one processor, and when the instructions are executed by the at least one processor, the at least one processor is enabled to execute the above method.
[0025] According to another aspect of the present disclosure, there is provided a non-transitory computer-readable storage medium storing computer instructions, wherein the computer instructions are used to cause the computer to execute the above method.
[0026] According to another aspect of the present disclosure, there is provided a computer program product, including a computer program, where the computer program, when executed by a processor, implements the above method.
[0027] It should be understood that the content described in this part is not intended to identify the key or important features of the embodiments of the present disclosure, nor is it used to limit the scope of the present disclosure. Other features of the present disclosure will become easily understandable through the following description. BRIEF DESCRIPTION OF THE DRAWINGS
[0028] The drawings are used to better understand the solution and do not constitute a limitation to the present disclosure. Among them:
[0029] Figure 1 is a flowchart of a method for training a decision tree provided in the first embodiment of the present disclosure;
[0030] Figure 2 is a flowchart of S103 of the method for training a decision tree provided in the first embodiment of the present disclosure;
[0031] Figure 3 It is a schematic flowchart of a method for determining risk users according to the second embodiment of the present disclosure;
[0032] Figure 4 It is a schematic structural diagram of a decision tree training device provided by the third embodiment of the present disclosure;
[0033] Figure 5 It is a schematic structural diagram of a device for determining risk users provided by the fourth embodiment of the present disclosure;
[0034] Figure 6 It is a block diagram of an electronic device for implementing the method according to the embodiments of the present disclosure. Detailed implementation manners
[0035] The following describes exemplary embodiments of the present disclosure with reference to the accompanying drawings. Various details of the embodiments of the present disclosure are included to facilitate understanding, and they should be considered merely exemplary. Therefore, those of ordinary skill in the art should recognize that various changes and modifications can be made to the embodiments described herein without departing from the scope and spirit of the present disclosure. Similarly, for the sake of clarity and conciseness, descriptions of well-known functions and structures are omitted in the following description.
[0036] Without conflict, the embodiments of the present disclosure and the features in the embodiments can be combined with each other.
[0037] As used herein, the term "and / or" includes any and all combinations of one or more of the associated listed items.
[0038] The terms used herein are only for describing specific embodiments and are not intended to limit the present disclosure. As used herein, the singular forms "a" and "the" are also intended to include the plural forms unless the context clearly indicates otherwise.
[0039] Unless otherwise defined, all terms (including technical and scientific terms) used herein have the same meaning as commonly understood by those of ordinary skill in the art. It will also be understood that terms such as those defined in common dictionaries should be interpreted as having a meaning consistent with their meaning in the context of the relevant art and the present disclosure, and will not be interpreted as having an idealized or overly formal meaning unless expressly so defined herein.
[0040] The training method of the decision tree according to the present disclosure can be executed by an electronic device such as a terminal device or a server. The terminal device can be a vehicle-mounted device, a display device (User Equipment, UE), a mobile device, a user terminal, a terminal, a cellular phone, a cordless phone, a Personal Digital Assistant (PDA), a handheld device, a computing device, a vehicle-mounted device, a wearable device, etc. The method can be implemented by a processor calling computer-readable program instructions stored in a memory. Alternatively, the training method of the decision tree provided by the present disclosure can be executed by a server.
[0041] The following explains the technical terms related to the present disclosure.
[0042] Tree model: A supervised machine learning model. The tree model can be, for example, a binary tree, etc. The tree model can include a decision tree model. In the present disclosure, the decision tree model is taken as an example for illustration. Specifically, the decision tree model can include a regression decision tree and a classification decision tree, etc., which are not limited herein. The tree model includes multiple sub-nodes. Each sub-node can correspond to a position identifier, and the position identifier can be used to identify the position of the sub-node in the tree model. Specifically, for example, it can be the number of the sub-node, etc. The multiple sub-nodes can form multiple prediction paths. The starting node of the prediction path is the root node of the tree model, and the ending node is the leaf node of the tree model.
[0043] Leaf node: When a sub-node in the tree model cannot be split downward, this sub-node can be called a leaf node. The leaf node corresponds to a leaf value. The leaf values corresponding to different leaf nodes in the tree model can be the same or different. Each leaf value can represent a prediction result. The leaf value can be a numerical value or a vector, etc.
[0044] Non-leaf node: When a sub-node in the tree model can be split downward, this node can be called a non-leaf node. The non-leaf node can specifically include the root node and other nodes (hereinafter referred to as internal nodes) except the leaf node and the root node. The non-leaf node corresponds to a splitting condition, and the splitting condition can be used to select a prediction path.
[0045] In the first embodiment of the disclosure, refer to Figure 1 , Figure 1 which shows a schematic flowchart of a training method of a decision tree provided by the first embodiment of the present disclosure. The method includes:
[0046] S101. Construct a sample set including user behavior characteristics.
[0047] S102. Calculate the values of the Gini index of each user behavior characteristic in the sample set respectively.
[0048] S103. Train an initial decision tree based on the values of the penalty factor function and the Gini index of each user behavior feature to obtain a trained decision tree.
[0049] Among them, the trained decision tree is used to determine risk users according to user behavior features.
[0050] Among them, one or more decision tree models can form a forest model. The forest model can be a supervised machine learning model, specifically including a regression decision forest and a classification decision forest. In the present disclosure, the initial decision tree and / or the trained decision tree can be a single decision tree model or a forest model, which is not limited herein.
[0051] In some examples, the decision tree models of the present disclosure can include multiple types. The initial decision tree and / or the trained decision tree, for example, include at least one of the following: Gradient Boosting Decision Tree (GDBT), eXtreme Gradient Boosting (XGBOOST), Gradient Boost Regression Tree (GBRT), etc. Of course, it can also include other types of trees, which are not limited herein.
[0052] Among them, the user behavior feature is a feature used to describe user behavior. The user behavior feature, for example, includes: content publishing behavior feature, search behavior feature, browsing behavior feature, purchase behavior feature, etc., which is not limited herein.
[0053] A risk user is a user with user behavior features. For example: a user who publishes abnormal content, a user with an abnormal frequency of search behavior, etc., which is not limited herein.
[0054] The method provided by the present disclosure constructs a sample set for training based on user behavior characteristics, then calculates the Gini index values of each user behavior characteristic in the sample set respectively, introduces a penalty factor function, and trains an initial decision tree in combination with the Gini index values. Among them, the decision tree determines the splitting point based on the Gini index value, and the penalty factor function is used to penalize the attribute value of the splitting point. By training the decision tree in this way, it is possible to avoid the problem that a large number of recalls are missed before the attribute value is reached due to the attribute value being too large or too small during the application of the decision tree, thereby improving the effectiveness of the recall and further avoiding the risk of missing the detection of users. For example, if the attribute value of the user's access behavior is 100 times and the user's address is a risk address, the attribute value of 100 times is relatively large. Then, before the user's access behavior reaches 100 times, the user will not be determined as a risk user, and in actual applications, the risk judgment of this user will be missed. In the present disclosure, the attribute value is scaled by the penalty factor function, here it is reduced, reduced to 10 times, then the recall of this risk user will not be missed.
[0055] For S101, in some examples, S101 includes:
[0056] Step 1: From the obtained user behavior data, filter out the target user behavior, where the target user behavior refers to the user behavior that belongs to the same user and occurs more than a preset number of times.
[0057] Step 2: Convert the target user behavior into a vectorized user behavior characteristic, and generate a sample set based on the user behavior characteristic.
[0058] Among them, the user behavior data is the relevant data of the original user behavior, which can be multi-source data and has one or more data sources. And the user behavior data may be multi-modal data. Therefore, the user behavior data can be vectorized and converted into user behavior characteristics to facilitate subsequent classification using a decision tree.
[0059] In Step 1, the target user behavior is a statistical type of user behavior, which represents the repetitive behavior of the same user. In other words, the target user behavior refers to the user behavior of the same user that occurs more than a preset number of times. For example: the user's multiple browsing behaviors for the same content, the user's multiple purchase behaviors for the same commodity, etc. Among them, the preset number of times can be set as needed, for example, it is 10 times. In this way, it is possible to select the long-term and repetitive behaviors of users for feature classification, avoid misjudgments caused by discrete behaviors, and make the detection of risk users more accurate; and the user behaviors of risk users usually have the characteristic of repeating multiple times in a short period. Therefore, screening the target user behavior for detecting risk users can improve the effectiveness of the detection.
[0060] Specifically, in step two, the target user behavior is converted into a vectorized user behavior feature, including: converting the target user behavior into a vectorized user behavior feature through a graph algorithm or a word vector conversion method.
[0061] Among them, the word vector refers to a distributed representation of words, which means mapping words into a vector with a fixed dimension. In the example of word vectors, it is possible to: convert the target user behavior into a user behavior feature in the form of word vectors through a language model, where the language model includes, for example, at least one of the following: the word to vector (word2vec) model, the Global Vectors for Word Representation (glove) model, the Embeddings from Language Models (ELMo) model, the Bidirectional Encoder Representation from Transformers (BERT) model, etc., which are not limited here.
[0062] Among them, a graph is an important data structure, which is composed of some points (vertices) and the connections (edges) between these points; among them, the points are usually called "vertices", and the connections between points are called "edges or arcs", usually denoted as G=(V, E), where G represents the graph, V represents the vertices, and E represents the edges or arcs. In the example of graph algorithms, the graph algorithms adopted can be various graph algorithms, such as including at least one of the following: Dijkstra algorithm, Bellman-Ford algorithm, Prim algorithm, Hungarian algorithm, etc., which are not limited here.
[0063] Among them, the sample set can include a training set and a test set. After step two, S101 can also include:
[0064] Step three: Randomly select the first part from all user behavior features to generate a training set, and the remaining second part to generate a test set.
[0065] The training set is used to train the decision tree, and the test set is used to verify the training completion degree of the decision tree. Therefore, specifically in S102: Calculate the values of the Gini index of the user behavior features in the training set respectively.
[0066] Among them, the ratio of the training set to the test set can be set as needed. For example, the ratio of the number of user behavior features in the training set to the number of user behavior features in the test set is 7:3, which is not limited here.
[0067] For S102, in some examples, the values of the Gini indices of each of the user behavior features in the sample set can be calculated according to the following formula:
[0068]
[0069] where a is the user behavior feature for partitioning the sample set D, and a has V possible values {a1, a2,..., ai,..., av}, and D v is the sample set included in the v-th child node, and G i (D, a) is the value of the Gini index of the sample set included in the v-th child node.
[0070] For S103, in some examples, refer to Figure 2 , Figure 2 which shows an exemplary flowchart of S103. Each layer of the initial decision tree includes multiple child nodes; S103 includes:
[0071] S1031. For any layer of the decision tree, determine the splitting point of the current layer according to the values of the Gini indices of the user behavior features corresponding to each child node in the same layer.
[0072] Specifically, S1031 includes: for any layer of the decision tree, select the user behavior feature with the minimum Gini index value for splitting.
[0073] Then the child node (which is a leaf node or a non-leaf node) of this user behavior feature is the splitting point, and the attribute value of this user behavior feature is the attribute value of the splitting point.
[0074] The Gini index is a value used to measure the purity of the set of child nodes. The smaller the value of the Gini index, the higher the purity, which means the corresponding user behavior feature is better. During the training process of the decision tree, when partitioning the current set of child nodes, how to select the optimal partitioning attribute is one of the key issues of the decision tree algorithm. Therefore, by using the Gini index to prohibit partitioning, the samples included in the branch nodes of the decision tree can belong to the same category as much as possible, that is, the purity is relatively high.
[0075] Of course, the decision tree can also be partitioned by other methods, such as using at least one of the following: Shannon information entropy, information gain value, etc., which are not limited here.
[0076] S1032. Based on the penalty factor function, scale the attribute value of the user behavior feature corresponding to the splitting point to obtain the final attribute value.
[0077] The specific form of the penalty factor function can include various types. For example, it can be a piecewise function or a function associated with a normalization function, which is not limited here. The penalty factor function is used to penalize the attribute values at the splitting points. By training the decision tree in this way, it can avoid the problem that due to overly large attribute values, a large number of recalls will be missed before the user behavior characteristics reach the attribute values during the application of the decision tree, thereby improving the effectiveness of recalls and further avoiding the risk of missed detections of users. Of course, for the case of overly small attribute values, the penalty factor function can also be used to amplify the attribute values to ensure the effectiveness of the attributes.
[0078] The following uses examples of multiple penalty factor functions for illustration.
[0079] Example 1: The penalty factor function includes multiple penalty factor piecewise functions, and each penalty factor piecewise function has a different scaling degree for the attribute value.
[0080] In this case, S1032 includes:
[0081] Step 1: Based on the attribute value and the preset piecewise threshold, determine the penalty factor piecewise function corresponding to the attribute value.
[0082] Step 2: Substitute the attribute value into the corresponding penalty factor piecewise function for calculation, and use the calculation result as the final attribute value.
[0083] In this case, multiple penalty factor piecewise functions can be set, and multiple piecewise thresholds are set respectively. The piecewise thresholds are, for example: the first piecewise threshold (0, 0.5], the second piecewise threshold (0.5, 0.7], and the third piecewise threshold (0.7, 1]. The scaling degrees of the penalty factor piecewise functions corresponding to the three piecewise thresholds increase from small to large. In other words, for the same attribute value, the change value of the adjusted attribute value obtained by the penalty factor piecewise function corresponding to the first piecewise threshold is the smallest compared to the original attribute value; the change value of the adjusted attribute value obtained by the penalty factor piecewise function corresponding to the third piecewise threshold is the largest compared to the original attribute value. In this way, the magnitude of the attribute value can be divided, and different degrees of scaling can be implemented to adapt to more application scenarios.
[0084] Specifically, in some examples, the penalty factor function includes a first penalty factor piecewise function and a second penalty factor piecewise function, where the scaling degree of the first penalty factor piecewise function for the attribute value is less than that of the second penalty factor piecewise function for the attribute value. Thus, step 1 of S1032 includes:
[0085] Sub-step 1: When the attribute value is less than or equal to the piecewise threshold, determine that the attribute value corresponds to the first penalty factor piecewise function.
[0086] Sub-step 2: When the attribute value is greater than the segmentation threshold, determine the second penalty factor piecewise function corresponding to the attribute value.
[0087] Based on the above, step 2 of S1032 includes:
[0088] Sub-step 1: When the attribute value corresponds to the first penalty factor piecewise function, the attribute value remains unchanged. In other words, in this case, the attribute value corresponding to the split point is not scaled, and the final attribute value is equal to the original attribute value.
[0089] Sub-step 2: When the attribute value corresponds to the second penalty factor piecewise function, based on the attribute value and the preset scaling factor, obtain the final attribute value.
[0090] In some examples, in the case of sub-step 2, it specifically includes:
[0091] Take the negative value of the product of the attribute value and the scaling factor as the exponent of the natural logarithm;
[0092] Obtain the final attribute value according to the reciprocal of the natural logarithm and the sum of the attribute values.
[0093] Specifically, the final attribute value can be determined according to the following formula:
[0094]
[0095] Among them, f(x) represents the penalty factor function, the calculation result of f(x) is the final attribute value, the upper part of f(x) is the first penalty factor piecewise function, and the lower part is the second penalty factor piecewise function; x represents the attribute value of the user behavior feature at the split point; α is the segmentation threshold; β represents the scaling factor. Among them, the scaling factor is used to adjust the scaling degree of the attribute value, which can be set as needed, and the value range is [0, +∞), which is not limited here.
[0096] In this way, for the original attribute value x of the user behavior feature at each split point, compare x with α. If x is less than or equal to α, then determine the final attribute value according to the first penalty factor piecewise function f(x) = x. In other words, the final attribute value is the original attribute value, indicating that the numerical value of the attribute value is within the normal range and is not scaled; if x is greater than α, then according to the second penalty factor piecewise function Determine the final attribute value to Scale the attribute value x.
[0097] Among them, in the second penalty factor piecewise function, Is positively correlated with the size of x. If the attribute value itself is very large, then A relatively large penalty will be imposed on the attribute value; if the attribute value itself is very small, then A relatively small penalty will be imposed on the attribute value, and the increase of the natural logarithm is stable. When the attribute value gradually becomes larger, the penalized attribute value will also increase steadily, rather than suddenly, thus making the change of the attribute value smoother.
[0098] Example 2: The penalty factor function includes a normalization function.
[0099] In this case, S1032 includes:
[0100] Step 1: Substitute the attribute value into the normalization function for normalization processing to obtain the processed attribute value;
[0101] Step 2: Use the difference between the preset reference value and the processed attribute value as the final attribute value.
[0102]
[0103] Among them, f(x) represents the penalty factor function, and the calculation result of f(x) is the final attribute value; is a normalization function, where d i represents the attribute value of the splitting point; min 1,..,N {d i} represents the minimum value of the attribute values of N child nodes in the layer to which the splitting point belongs; max 1,..,N {d i} represents the maximum value of the attribute values of N child nodes in the layer to which the splitting point belongs, and N is an integer greater than 1. In formula (3), the reference value is taken as 1. Of course, the reference value can also be other values, which are not limited here. Through normalization, the influence of larger attribute values on the decision tree is weakened, thereby improving the accuracy of recall.
[0104] Of course, the specific form of the penalty factor function can also include various forms, which are not limited here.
[0105] S1033: Based on the splitting points of each layer and the corresponding final attribute values, obtain the trained decision tree.
[0106] Specifically, for each layer of the decision tree, loop S1031 - S1033 until the splitting stops, obtain a trained decision tree, and output a classification result.
[0107] In the disclosure of the second embodiment, refer to Figure 3 , Figure 3 which shows a schematic flowchart of a method for determining risk users according to the second embodiment of the present disclosure. The method includes:
[0108] S201: Input the user behavior characteristics into the trained decision tree to obtain the risk users output by the trained decision tree.
[0109] Among them, the trained decision tree is trained by using the publicly provided decision tree training method.
[0110] In the method provided by the present disclosure, since a penalty factor function is introduced in the training stage of the decision tree to adjust the attribute value of the split point and avoid the attribute value being too large or too small; thus, based on the split point and the penalized attribute value, the decision tree obtained can, after inputting the user behavior characteristics, classify and make decisions on the user behavior characteristics based on appropriate attribute values, thereby improving the effectiveness of recall and then accurately detecting risk users.
[0111] In the disclosed third embodiment, based on the same principle as Figure 1 the same principle Figure 4 FIG. 4 shows a decision tree training apparatus 40 provided by the third embodiment of the present disclosure. The apparatus includes:
[0112] A sample module 401 for constructing a sample set including user behavior characteristics;
[0113] A Gini module 402 for calculating the Gini index values of each user behavior characteristic in the sample set respectively;
[0114] A training module 403 for training an initial decision tree based on the penalty factor function and the Gini index values of each user behavior characteristic to obtain a trained decision tree;
[0115] Among them, the trained decision tree is used to determine risk users according to user behavior characteristics.
[0116] In some examples, each layer of the initial decision tree includes multiple child nodes;
[0117] The training module includes:
[0118] A determination sub-module for determining the split point of the current layer according to the Gini index values of the user behavior characteristics corresponding to each child node in the same layer for any layer of the decision tree;
[0119] A penalty sub-module for scaling the attribute value of the user behavior characteristic corresponding to the split point based on the penalty factor function to obtain the final attribute value;
[0120] A generation sub-module for obtaining a trained decision tree based on the split point of each layer and the corresponding final attribute value.
[0121] In some examples, the penalty factor function includes multiple penalty factor piecewise functions, and each penalty factor piecewise function has a different scaling degree for the attribute value;
[0122] The penalty sub-module is used for:
[0123] Based on the attribute value and the preset segmentation threshold, determine the penalty factor piecewise function corresponding to the attribute value;
[0124] Substitute the attribute value into the corresponding penalty factor piecewise function for calculation, and use the calculation result as the final attribute value.
[0125] In some examples, the penalty factor function includes a first penalty factor piecewise function and a second penalty factor piecewise function;
[0126] When the penalty sub-module determines the penalty factor piecewise function corresponding to the attribute value based on the attribute value and the preset segmentation threshold, it is used for:
[0127] When the attribute value is less than or equal to the segmentation threshold, determine the first penalty factor piecewise function corresponding to the attribute value;
[0128] When the attribute value is greater than the segmentation threshold, determine the second penalty factor piecewise function corresponding to the attribute value;
[0129] Among them, the scaling degree of the first penalty factor piecewise function for the attribute value is less than the scaling degree of the second penalty factor piecewise function for the attribute value.
[0130] In some examples, when the penalty sub-module substitutes the attribute value into the corresponding penalty factor piecewise function for calculation and uses the calculation result as the final attribute value, it is used for:
[0131] When the attribute value corresponds to the first penalty factor piecewise function, the final attribute value is the attribute value;
[0132] When the attribute value corresponds to the second penalty factor piecewise function, based on the attribute value and the preset scaling factor, obtain the final attribute value.
[0133] In some examples, when the penalty sub-module, in the case where the attribute value corresponds to the second penalty factor piecewise function, obtains the final attribute value based on the attribute value and the preset scaling factor, it is used for:
[0134] Take the negative value of the product of the attribute value and the scaling factor as the exponent of the natural logarithm;
[0135] According to the reciprocal of the natural logarithm and the sum of the attribute values, obtain the final attribute value.
[0136] In some examples, the penalty factor function includes a normalization function;
[0137] The penalty sub-module is used for:
[0138] Substitute the attribute value into the normalization function for normalization processing to obtain the processed attribute value;
[0139] Use the difference between the preset reference value and the processed attribute value as the final attribute value.
[0140] In some examples, a sample module is used for:
[0141] Filter out target user behaviors from the obtained user behavior data, where the target user behaviors represent user behaviors that belong to the same user and occur more than a preset number of times;
[0142] Convert the target user behaviors into vectorized user behavior features, and generate a sample set based on the user behavior features.
[0143] In some examples, the decision tree includes at least one of the following: gradient boosting tree, extreme gradient boosting, gradient boosting regression tree.
[0144] In the disclosed fourth embodiment, based on the same principle as Figure 3 the same principle, Figure 5 FIG. 50 shows a device 50 for determining risk users provided by the fourth embodiment of the present disclosure. The device includes:
[0145] A determination module 501, configured to input user behavior features into a trained decision tree to obtain risk users output by the trained decision tree;
[0146] Wherein, the trained decision tree is trained by using the decision tree training method provided by the present disclosure.
[0147] In the technical solution of the present disclosure, the processing of collection, storage, use, processing, transmission, provision, disclosure, and application of user personal information involved all comply with the provisions of relevant laws and regulations, take necessary confidentiality measures, and do not violate public order and good customs.
[0148] In the technical solution of the present disclosure, before obtaining or collecting user personal information, user authorization or consent has been obtained.
[0149] According to the embodiments of the present disclosure, the present disclosure also provides an electronic device, a readable storage medium, and a computer program product.
[0150] As Figure 6 shown, the device 600 includes a computing unit 601, which can execute various appropriate actions and processes according to a computer program stored in a read-only memory (ROM) 602 or a computer program loaded from a storage unit 602 into a random access memory (RAM) 603. In the RAM 603, various programs and data required for the operation of the device 600 can also be stored. The computing unit 601, the ROM 602, and the RAM 603 are connected to each other through a bus 604. An input / output (I / O) interface 605 is also connected to the bus 604.
[0151] Multiple components in device 600 are connected to I / O interface 605, including: input unit 606, such as a keyboard, mouse, etc.; output unit 607, such as various types of displays, speakers, etc.; storage unit 608, such as a disk, optical disc, etc.; and communication unit 609, such as a network card, modem, wireless communication transceiver, etc. Communication unit 609 allows device 600 to exchange information / data with other devices via a computer network such as the Internet and / or various telecommunication networks.
[0152] Computing unit 601 can be various general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of computing unit 601 include but are not limited to a central processing unit (CPU), a graphics processing unit (GPU), various special-purpose artificial intelligence (AI) computing chips, various computing units running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. Computing unit 601 executes the various methods and processes described above, such as the training method of a decision tree. For example, in some embodiments, the training method of a decision tree can be implemented as a computer software program, which is tangibly contained in a machine-readable medium, such as storage unit 608. In some embodiments, part or all of the computer program can be loaded and / or installed onto device 600 via ROM 602 and / or communication unit 609. When the computer program is loaded into RAM 603 and executed by computing unit 601, one or more steps of the training method of the decision tree described above can be executed. Alternatively, in other embodiments, computing unit 601 can be configured for the training method of the decision tree by any other suitable means (e.g., by means of firmware).
[0153] Various embodiments of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field-programmable gate arrays (FPGA), application-specific integrated circuits (ASIC), application-specific standard products (ASSP), systems-on-chip (SOC), complex programmable logic devices (CPLD), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include: implemented in one or more computer programs, the one or more computer programs can be executed and / or interpreted on a programmable system including at least one programmable processor, the programmable processor can be a special or general-purpose programmable processor, can receive data and instructions from a storage system, at least one input device, and at least one output device, and transmit the data and instructions to the storage system, the at least one input device, and the at least one output device.
[0154] The program code for implementing the methods of the present disclosure may be written in any combination of one or more programming languages. These program codes may be provided to a processor or controller of a general purpose computer, a special purpose computer, or other programmable data processing device, such that the program codes, when executed by the processor or controller, cause the functions / operations specified in the flowchart and / or block diagram to be implemented. The program code may execute entirely on the machine, partly on the machine, as a stand-alone software package partly on the machine and partly on a remote machine, or entirely on the remote machine or server.
[0155] In the context of the present disclosure, a machine-readable medium may be a tangible medium that can contain, or store a program for use by or in connection with an instruction execution system, apparatus, or device. The machine-readable medium may be a machine-readable signal medium or a machine-readable storage medium. The machine-readable medium may include, but is not limited to, electronics, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of the machine-readable storage medium would include an electrical connection based on one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0156] In order to provide interaction with a user, the systems and techniques described herein may be implemented on a computer having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and a pointing device (e.g., a mouse or a trackball) by which the user can provide input to the computer. Other kinds of devices may also be used to provide interaction with the user; for example, the feedback provided to the user may be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user may be received in any form (including acoustic input, voice input, or tactile input).
[0157] The systems and techniques described herein can be implemented in a computing system including backend components (e.g., as a data server), or a computing system including middleware components (e.g., an application server), or a computing system including frontend components (e.g., a user computer having a graphical user interface or a web browser through which a user can interact with an implementation of the systems and techniques described herein), or a computing system including any combination of such backend components, middleware components, or frontend components. The components of the system can be interconnected to each other by digital data communication in any form or medium (e.g., a communication network). Examples of communication networks include: local area network (LAN), wide area network (WAN), and the Internet.
[0158] A computer system can include a client and a server. The client and the server are generally far from each other and typically interact through a communication network. The client-server relationship is created by computer programs running on the respective computers and having a client-server relationship with each other. The server can be a cloud server, can also be a server of a distributed system, or a server combined with a blockchain.
[0159] It should be understood that the various forms of the processes shown above can be used, steps can be reordered, added, or deleted. For example, the steps described in this disclosure can be executed in parallel, sequentially, or in a different order, as long as the desired results of the technical solutions disclosed in this disclosure can be achieved, and this is not limited herein.
[0160] The above specific implementation manners do not constitute a limitation on the protection scope of this disclosure. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this disclosure shall be included within the protection scope of this disclosure.
Claims
1. A decision tree training method, wherein: The method comprises: Construct a sample set containing user behavior characteristics; Calculating the value of the Gini index of each of the user behavior characteristics in the sample set respectively; Training an initial decision tree based on the penalty factor function and the value of the Gini index of each of the user behavior characteristics to obtain a trained decision tree; The trained decision tree is used to determine risky users based on user behavior characteristics.
2. The method according to claim 1, wherein: Each layer of the initial decision tree includes a plurality of child nodes; The initial decision tree is trained based on the penalty factor function and the value of the Gini index of each of the user behavior characteristics to obtain a trained decision tree, including: For any layer of the decision tree, determine the split point of the current layer according to the value of the Gini index of the user behavior feature corresponding to each sub-node located in the same layer; Based on the penalty factor function, scaling the attribute value of the user behavior feature corresponding to the split point to obtain a final attribute value; Based on the splitting points of each layer and the corresponding final attribute values, a trained decision tree is obtained.
3. The method according to claim 2, wherein: The penalty factor function includes a plurality of penalty factor piecewise functions, each of which has a different degree of scaling of the attribute value; The step of scaling the attribute value of the user behavior feature corresponding to the split point based on the penalty factor function to obtain a final attribute value includes: Based on the attribute value and a preset segmentation threshold, determining a penalty factor piecewise function corresponding to the attribute value; Substitute the attribute value into the corresponding penalty factor piecewise function for calculation, and use the calculation result as the final attribute value.
4. The method according to claim 3, wherein: The penalty factor function includes a first penalty factor piecewise function and a second penalty factor piecewise function; The step of determining a penalty factor piecewise function corresponding to the attribute value based on the attribute value and a preset segmentation threshold value includes: In a case where the attribute value is less than or equal to the segmentation threshold, determining that the attribute value corresponds to the first penalty factor piecewise function; In the case where the attribute value is greater than the segmentation threshold, determining that the attribute value corresponds to the second penalty factor piecewise function; The scaling degree of the first penalty factor piecewise function on the attribute value is smaller than the scaling degree of the second penalty factor piecewise function on the attribute.
5. The method according to claim 4, wherein: Substituting the attribute value into the corresponding penalty factor piecewise function for calculation, and using the calculation result as the final attribute value, includes: When the attribute value corresponds to the first penalty factor piecewise function, the attribute value remains unchanged; When the attribute value corresponds to the second penalty factor piecewise function, the final attribute value is obtained based on the attribute value and a preset scaling factor.
6. The method according to claim 5, wherein: When the attribute value corresponds to the second penalty factor piecewise function, obtaining the final attribute value based on the attribute value and a preset scaling factor includes: Taking the negative value of the product of the attribute value and the scaling factor as the exponent of the natural logarithm; The final attribute value is obtained according to the reciprocal of the natural logarithm and the sum of the attribute value.
7. The method according to claim 2, wherein: The penalty factor function comprises a normalization function; The step of scaling the attribute value of the user behavior feature corresponding to the split point based on the penalty factor function to obtain a final attribute value includes: Substituting the attribute value into the standardization function for standardization processing to obtain a processed attribute value; The difference between the preset reference value and the processed attribute value is taken as the final attribute value.
8. The method according to any one of claims 1 to 7, wherein: The constructing of a sample set containing user behavior characteristics includes: Filtering out target user behaviors from the acquired user behavior data, wherein the target user behaviors represent user behaviors that belong to the same user and occur more than a preset number of times; The target user behavior is converted into vectorized user behavior features, and the sample set is generated based on the user behavior features.
9. The method according to any one of claims 1 to 8, wherein: The decision tree includes at least one of the following: a gradient boosting tree, an extreme gradient boosting tree, and a gradient boosting regression tree.
10. A method for identifying risky users, wherein: The method comprises: Inputting user behavior characteristics into a trained decision tree to obtain risky users output by the trained decision tree; Wherein, the trained decision tree is trained using the method described in any one of claims 1-9.
11. A decision tree training device, wherein: The device comprises: Sample module, used to construct a sample set containing user behavior characteristics; A Gini module, used to calculate the value of the Gini index of each of the user behavior features in the sample set; A training module, used to train an initial decision tree based on a penalty factor function and the value of the Gini index of each of the user behavior characteristics to obtain a trained decision tree; The trained decision tree is used to determine risky users based on user behavior characteristics.
12. The device according to claim 11, wherein Each layer of the initial decision tree includes a plurality of child nodes; The training module includes: A determination submodule, for determining, for any layer of the decision tree, a split point of the current layer according to the value of the Gini index of the user behavior feature corresponding to each subnode located in the same layer; A penalty submodule, used for scaling the attribute value of the user behavior feature corresponding to the split point based on the penalty factor function to obtain a final attribute value; The generation submodule is used to obtain a trained decision tree based on the splitting point of each layer and the corresponding final attribute value.
13. The device according to claim 12, wherein: The penalty factor function includes a plurality of penalty factor piecewise functions, each of which has a different degree of scaling of the attribute value; The penalty submodule is used to: Based on the attribute value and a preset segmentation threshold, determining a penalty factor piecewise function corresponding to the attribute value; Substitute the attribute value into the corresponding penalty factor piecewise function for calculation, and use the calculation result as the final attribute value.
14. The device according to claim 13, wherein: The penalty factor function includes a first penalty factor piecewise function and a second penalty factor piecewise function; The penalty submodule is used to: determine the penalty factor piecewise function corresponding to the attribute value based on the attribute value and the preset segmentation threshold value; In a case where the attribute value is less than or equal to the segmentation threshold, determining that the attribute value corresponds to the first penalty factor piecewise function; In the case where the attribute value is greater than the segmentation threshold, determining that the attribute value corresponds to the second penalty factor piecewise function; The scaling degree of the first penalty factor piecewise function on the attribute value is smaller than the scaling degree of the second penalty factor piecewise function on the attribute.
15. The device according to claim 14, wherein: The penalty submodule is used to substitute the attribute value into the corresponding penalty factor piecewise function for calculation and use the calculation result as the final attribute value: When the attribute value corresponds to the first penalty factor piecewise function, the attribute value remains unchanged; When the attribute value corresponds to the second penalty factor piecewise function, the final attribute value is obtained based on the attribute value and a preset scaling factor.
16. The device according to claim 15, wherein: The penalty submodule, when the attribute value corresponds to the second penalty factor piecewise function, obtains the final attribute value based on the attribute value and a preset scaling factor, is used to: Taking the negative value of the product of the attribute value and the scaling factor as the exponent of the natural logarithm; The final attribute value is obtained according to the reciprocal of the natural logarithm and the sum of the attribute value.
17. The device according to claim 12, wherein: The penalty factor function comprises a normalization function; The penalty submodule is used to: Substituting the attribute value into the standardization function for standardization processing to obtain a processed attribute value; The difference between the preset reference value and the processed attribute value is taken as the final attribute value.
18. The device according to any one of claims 11 to 17, wherein: The sample module is used for: Filtering out target user behaviors from the acquired user behavior data, wherein the target user behaviors represent user behaviors that belong to the same user and occur more than a preset number of times; The target user behavior is converted into vectorized user behavior features, and the sample set is generated based on the user behavior features.
19. The device according to any one of claims 11 to 18, wherein: The decision tree includes at least one of the following: gradient boosting tree, extreme gradient boosting, gradient boosting regression tree.
20. A device for determining risky users, wherein: The device comprises: A determination module, used to input user behavior characteristics into a trained decision tree to obtain risky users output by the trained decision tree; Wherein, the trained decision tree is trained using the method described in any one of claims 1-9.
21. An electronic device comprising: at least one processor; as well as a memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to execute the method of any one of claims 1 to 10 and / or the method of claim 11.
22. A non-transitory computer-readable storage medium storing computer instructions, wherein: The computer instructions are used to cause the computer to execute the method according to any one of claims 1 to 10 and / or to execute the method according to claim 11.
23. A computer program product, comprising a computer program, which, when executed by a processor, implements the method according to any one of claims 1 to 10 and / or the method according to claim 11.