Data processing method and device, electronic equipment, storage medium and program product

By conducting risk detection of the payment object and the order itself on the order to be transferred on the mobile payment platform, the problem of inaccuracy and inefficiency of identifying and intercepting malicious merchants in the prior art is solved, and more efficient risk identification and interception is achieved.

CN120069877APending Publication Date: 2025-05-30TENCENT TECHNOLOGY (SHENZHEN) CO LTD
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202311636129.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-11-30
Publication Date
2025-05-30

AI Technical Summary

Technical Problem

The prior art has low recognition accuracy and efficiency when identifying and intercepting malicious merchants on mobile payment platforms, especially in the identification and interception of resource transfer behavior.

Method used

By obtaining the order to be transferred to the resource, the first risk detection and processing of the collection object is carried out. If the detection result indicates that the collection object is risky, the order is intercepted; if there is no risk, the second risk detection is carried out. Based on the risk inspection of the order itself, if the detection result indicates that the order is risky, the order is intercepted.

Benefits of technology

It improves the accuracy and efficiency of identifying resource transfer risks, ensures that risky orders can be effectively intercepted before resource transfer, and prevents illegal resource transfer.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120069877A_ABST
    Figure CN120069877A_ABST
Patent Text Reader

Abstract

The invention provides a data processing method and device, electronic equipment, a computer readable storage medium and a computer program product, and the method comprises the steps: obtaining an order to be subjected to resource transfer, carrying out the first risk detection processing of a collection object of the order to be subjected to resource transfer, and obtaining a risk detection result of the collection object, when the risk detection result of the collection object represents that the collection object has a risk, intercepting the order to be subjected to resource transfer, and when the risk detection result of the collection object represents that the collection object does not have the risk, performing second risk detection processing on the order to be subjected to resource transfer to obtain a risk detection result of the order to be subjected to resource transfer, and when the risk detection result of the order to be subjected to resource transfer represents that the order to be subjected to resource transfer has a risk, intercepting the order to be subjected to resource transfer. According to the method, the resource transfer risk can be more comprehensively identified, and interception is performed before resource transfer, so that the risk control accuracy and the risk control efficiency are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of computer technologies, and in particular, to a data processing method, apparatus, electronic device, computer-readable storage medium, and computer program product. Background Art

[0002] With the popularization of mobile payment, the transaction process has become more convenient. The commercial payment ability of mobile payment has greatly facilitated various commercial transactions in daily life. However, it also attracts malicious merchants to conduct malicious transactions on the mobile payment platform.

[0003] In related technologies, malicious merchants are identified and intercepted based on the merchant's own industrial and commercial information, registration information for entering the mobile payment platform, and complaint information. However, the interception scheme in related technologies that relies on complaints and identified objects for interception can only identify complaints and identified objects, and has low accuracy and efficiency in identifying illegal resource transfer behaviors. Summary of the Invention

[0004] Embodiments of this application provide a data processing method, apparatus, electronic device, computer-readable storage medium, and computer program product, which can more comprehensively identify resource transfer risks and intercept them before resource transfer to improve the accuracy and efficiency of risk control.

[0005] The technical solution of the embodiments of this application is implemented as follows:

[0006] Embodiments of this application provide a data processing method, and the method includes:

[0007] Obtain an order for resource transfer to be processed;

[0008] Perform a first risk detection process on the payee of the order for resource transfer to be processed to obtain a risk detection result of the payee;

[0009] When the risk detection result of the payee indicates that the payee has a risk, intercept the order for resource transfer to be processed;

[0010] When the risk detection result of the payee indicates that the payee has no risk, perform a second risk detection process on the order for resource transfer to be processed to obtain a risk detection result of the order for resource transfer to be processed;

[0011] When the risk detection result of the order for resource transfer to be processed indicates that the order for resource transfer to be processed has a risk, intercept the order for resource transfer to be processed.

[0012] Embodiments of this application provide a data processing apparatus, including:

[0013] An obtaining module, configured to obtain an order for resource transfer to be processed;

[0014] A risk detection module, configured to perform a first risk detection process on the payee of the to-be-resource-transfer order to obtain a risk detection result of the payee;

[0015] The risk detection module is further configured to intercept the to-be-resource-transfer order when the risk detection result of the payee indicates that the payee has a risk;

[0016] The risk detection module is further configured to perform a second risk detection process on the to-be-resource-transfer order to obtain a risk detection result of the to-be-resource-transfer order when the risk detection result of the payee indicates that the payee does not have a risk;

[0017] The risk detection module is further configured to intercept the to-be-resource-transfer order when the risk detection result of the to-be-resource-transfer order indicates that the to-be-resource-transfer order has a risk.

[0018] In the above solution, the risk detection module is further configured to obtain a credit mark of the payee. When the credit mark is a risk mark, it is determined that the risk detection result of the payee is that the payee has a risk. When the credit mark is a normal mark, it is determined that the risk detection result of the payee is that the payee does not have a risk.

[0019] In the above solution, the risk detection module is further configured to, when the risk level of the payee is higher than a risk level threshold, perform a risk feature identification process on the payee based on a risk detection strategy. When a risk feature is identified, the credit mark of the payee is determined as the risk mark. When the risk level of the payee is not higher than the risk level threshold, it receives a risk review result input by an audit institution for the payee. When the risk review result indicates that the payee is a suspicious object, the credit mark of the payee is determined as the risk mark.

[0020] In the above solution, the risk detection module is further configured to obtain risk data features of the payee with the credit mark being the risk mark, and based on the risk data features, determine a diffused payee associated with the payee. When the risk level of the diffused payee is higher than the risk level threshold, perform a risk feature identification process on the diffused payee based on the risk detection strategy to determine the credit mark of the diffused payee. When the risk level of the diffused payee is not higher than the risk level threshold, receive a risk review result input by the audit institution for the diffused payee, and determine the credit mark of the diffused payee based on the risk review result of the diffused payee.

[0021] In the above solution, the risk detection module is further configured to obtain the media data of multiple historical payees and obtain the resource transfer data of the multiple historical payees, where the multiple historical payees include the payee, and construct a resource transfer bipartite graph based on the media data of the multiple historical payees and the resource transfer data of the multiple historical payees, and perform risk level identification processing on the payee based on the resource transfer bipartite graph of the multiple historical payees to obtain the risk level identification result of the payee.

[0022] In the above solution, the risk detection module is further configured to perform risk identification processing on multiple social groups to obtain the risk results of each social group. When the risk results indicate that the social group is a risk group and any historical payee is associated with the risk group, obtain the warning data corresponding to the risk group as the media data of the any historical payee.

[0023] In the above solution, the risk detection module is further configured to perform the following processing for each historical payee: perform risk identification processing on the target social group associated with the historical payee to obtain the risk result of the target social group. When the risk result indicates that the target social group is a risk group, obtain the warning data corresponding to the target risk group as the media data of the historical payee.

[0024] In the above solution, the risk detection module is further configured to determine the historical payers associated with each historical payee and the historical organizational objects associated with each historical payee based on the media data and the resource transfer data, and construct the resource transfer bipartite graph with the historical payee, the historical organizational object, and the historical payer as nodes and the drainage relationship between the historical payee and the historical organizational object and the resource transfer relationship between the historical payee and the historical payer as edges.

[0025] In the above solution, the risk detection module is further configured to perform feature aggregation processing on the payee based on the resource transfer bipartite graph of the multiple historical payees to obtain the risk level features of the payee, and call a deep neural network model to perform mapping processing on the risk level features to obtain the risk level identification result of the payee.

[0026] In the above solution, the risk detection module is further configured to perform first-hop adjacent node sampling processing on the payee object in the resource transfer bipartite graph to obtain first adjacent nodes, where the categories of the first adjacent nodes include at least one of the following: the historical payee object, the historical payer object, and the historical organization object. For each of the first adjacent nodes, perform second-hop adjacent node sampling processing to obtain second adjacent nodes, where the categories of the second adjacent nodes include at least one of the following: the historical payee object, the historical payer object, and the historical organization object. For each of the first adjacent nodes, perform the following processing: perform feature aggregation processing on all the second adjacent nodes of the first adjacent node to obtain a first aggregated feature of the first adjacent node, and perform aggregation processing on the first aggregated features of all the first adjacent nodes to obtain a risk feature of the payee object.

[0027] In the above solution, the risk detection module is further configured to obtain a credit mark of the payer object of the to-be-resource-transferred order. When the credit mark indicates that the payer object has risks, perform feature extraction processing on the to-be-resource-transferred order to obtain a risk feature of the to-be-resource-transferred order, and based on the risk feature of the to-be-resource-transferred order, perform order risk detection processing on the to-be-resource-transferred order to obtain a risk detection result of the to-be-resource-transferred order.

[0028] In the above solution, the risk detection module is further configured to obtain order standard features. When the risk features of the to-be-resource-transferred order do not conform to the order standard features, determine that the risk detection result of the to-be-resource-transferred order is that the to-be-resource-transferred order has risks. When the risk features of the to-be-resource-transferred order conform to the order standard features, determine that the risk detection result of the to-be-resource-transferred order is that the to-be-resource-transferred order does not have risks.

[0029] An embodiment of the present application provides an electronic device, which includes:

[0030] A memory for storing computer-executable instructions;

[0031] A processor, configured to implement the data processing method provided by the embodiment of the present application when executing the computer-executable instructions stored in the memory.

[0032] An embodiment of the present application provides a computer-readable storage medium storing computer-executable instructions, which are used to implement the data processing method provided by the embodiment of the present application when being executed by a processor.

[0033] An embodiment of the present application provides a computer program product including computer-executable instructions, which implement the data processing method provided by the embodiment of the present application when being executed by a processor.

[0034] The embodiments of the present application have the following beneficial effects:

[0035] Obtain a resource transfer order to be processed, perform a first risk detection process on the payee of the resource transfer order to be processed to obtain the risk detection result of the payee. Here, it is equivalent to identifying risks for the payee. When the risk detection result of the payee indicates that the payee has risks, intercept the resource transfer order to be processed to avoid resource transfer with a payee having risks. When the risk detection result of the payee indicates that the payee does not have risks, perform a second risk detection process on the resource transfer order to be processed to obtain the risk detection result of the resource transfer order to be processed. Conduct a risk investigation based on the resource transfer order to be processed itself. When the risk detection result of the resource transfer order to be processed indicates that the resource transfer order to be processed has risks, intercept the resource transfer order to be processed to avoid illegal resource transfer behavior by an illegal object using the identity of a payee without risks. Thus, risk control of resource transfer behavior is achieved from two dimensions of the payee and the resource transfer order to be processed, malicious merchants who use legitimate platform merchants to conduct illegal resource transfer behavior are identified, and the accuracy and efficiency of identifying illegal resource transfer behavior are improved. Description of the Drawings

[0036] Figure 1 is a schematic structural diagram of the data processing system architecture provided by the embodiments of the present application;

[0037] Figure 2 is a schematic structural diagram of the server provided by the embodiments of the present application;

[0038] Figure 3A is a schematic flowchart of the data processing method provided by the embodiments of the present application;

[0039] Figure 3B is an alternative schematic flowchart of the data processing method provided by the embodiments of the present application;

[0040] Figure 3C is an alternative schematic flowchart of the data processing method provided by the embodiments of the present application;

[0041] Figure 4 is a schematic flowchart of the method for determining the credit mark of the payee provided by the embodiments of the present application;

[0042] Figure 5A is a schematic flowchart of the method for determining the risk level of the payee provided by the embodiments of the present application;

[0043] Figure 5B is an alternative schematic flowchart of the method for determining the risk level of the payee provided by the embodiments of the present application;

[0044] Figure 5CIt is an optional process schematic diagram of the method for determining the risk level of the payee provided by the embodiments of the present application;

[0045] Figure 5D It is an optional process schematic diagram of the method for determining the risk level of the payee provided by the embodiments of the present application;

[0046] Figure 5E It is an optional process schematic diagram of the method for determining the risk level of the payee provided by the embodiments of the present application;

[0047] Figure 6 It is a schematic diagram of the merchant - dimension interception interface provided by the embodiments of the present application;

[0048] Figure 7 It is a schematic diagram of the order - dimension interception interface provided by the embodiments of the present application;

[0049] Figure 8 It is a schematic diagram of the overall process of fund - pool business governance provided by the embodiments of the present application;

[0050] Figure 9 It is a schematic diagram of the processing flow of the commercial interception module provided by the embodiments of the present application;

[0051] Figure 10 It is a flow chart of fund - pool fraud social recognition provided by the embodiments of the present application;

[0052] Figure 11 It is a bipartite graph of commercial payment provided by the embodiments of the present application;

[0053] Figure 12 It is a schematic diagram of the processing flow of model recognition provided by the embodiments of the present application;

[0054] Figure 13 It is a flow chart of automatically combining policies with manual review and punishing merchants provided by the embodiments of the present application;

[0055] Figure 14 It is a schematic diagram of the merchant super - graph provided by the embodiments of the present application;

[0056] Figure 15 It is a schematic diagram of the processing flow of the order interception module provided by the embodiments of the present application. Detailed implementation manners

[0057] In order to make the objectives, technical solutions, and advantages of the present application clearer, the present application will be further described in detail below with reference to the accompanying drawings. The described embodiments should not be regarded as limitations on the present application. All other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the scope of protection of the present application.

[0058] In the following description, reference is made to "some embodiments", which describe a subset of all possible embodiments. However, it is understood that "some embodiments" can be the same subset or different subsets of all possible embodiments, and can be combined with each other without conflict.

[0059] In the following description, the terms "first / second / third" are only used to distinguish similar objects and do not represent a specific order for the objects. It is understood that "first / second / third" can be interchanged in a specific order or sequence when permitted, so that the embodiments of the present application described herein can be implemented in an order other than that illustrated or described herein.

[0060] In the embodiments of the present application, the term "module" or "unit" refers to a computer program with a predetermined function or a part of a computer program, which works together with other related parts to achieve a predetermined goal, and can be implemented in whole or in part by using software, hardware (such as a processing circuit or a memory), or a combination thereof. Similarly, one processor (or multiple processors or memories) can be used to implement one or more modules or units. In addition, each module or unit can be a part of the overall module or unit that includes the function of the module or unit.

[0061] Unless otherwise defined, all technical and scientific terms used in the embodiments of the present application have the same meaning as commonly understood by those skilled in the art to which the present application belongs. The terms used in the embodiments of the present application are only for the purpose of describing the embodiments of the present application and are not intended to limit the present application.

[0062] Before further elaborating on the embodiments of the present application, the nouns and terms involved in the embodiments of the present application are described, and the nouns and terms involved in the embodiments of the present application are subject to the following explanations.

[0063] 1) Ponzi scheme: It refers to a form of network pyramid scheme that uses the principle of direct sales multiplication and circulates funds in a rolling or static manner, robbing Peter to pay Paul, and using the money of later members who join the scheme to pay earlier members.

[0064] 2) Commercial payment: It provides a means of payment for commercial transactions. During the process of commercial payment, the two parties to the transaction are the object and the merchant respectively, and the funds flow from the account of the object to the account of the corresponding merchant through a certain channel. Generally speaking, commercial payment is a transaction model in which the object pays the merchant (C2B).

[0065] With the popularization of mobile payment, the transaction process has become more convenient. The commercial payment ability of mobile payment has greatly facilitated various commercial transactions in daily life, but it will also attract malicious merchants to conduct malicious transactions on the mobile payment platform.

[0066] In the related art, malicious merchants are identified and intercepted based on the business registration information of the merchant itself, the registration information for entering the mobile payment platform, and the first-level complaint information. In particular, the object complaint here is an important evidence for determining a merchant as a malicious merchant. When a general merchant is complained about, there are two possibilities. One possibility is that the malicious transaction is still in progress. At this time, the complaints from the payment objects are generally scattered, but there are high-risk words related to the malicious transaction in the description of the complaint reasons. At this time, it is necessary for the operation personnel to intervene quickly, conduct manual review of the merchant, and decide whether control is needed. The other possibility is that the malicious transaction has ended and the malicious merchant has escaped. At this time, the complaint willingness of the payment object is usually very strong. Malicious transactions usually have a pyramid scheme nature, and the participants often firmly believe in them. Therefore, once a complaint occurs, most of the malicious merchants have escaped at this time, and the interception of malicious merchants has lagged behind.

[0067] When the applicant implemented the embodiments of the present application, it was found that the related art had the following defects:

[0068] 1) Interception lag. The related art mainly relies on payment object complaints and external warning clues to discover malicious transactions. Most of the participants are middle-aged and elderly people, and they firmly believe in the related projects of malicious transactions. Therefore, before the malicious transaction explodes, basically no complaints from the victims will be received. Moreover, usually after a large-scale object aggregation complaint has occurred, a certain external warning will be formed. At this time, it is already too late to trace and intercept malicious merchants based on the relevant clues.

[0069] 2) Incomplete coverage. Whether it is the interception of merchants or transaction orders in the related art strongly depends on the spread results of malicious transactions that have been determined. The spread media of malicious transactions here generally include: the same entity (such as the same business license, the same enterprise name + the same registration number), the same natural person (the same natural person behind roles such as legal person, employer, contact person, employee, etc.), the same contact information (verified mobile phone, email), the same name (the same merchant abbreviation, the same company name), the same address (the company addresses are exactly the same), and so on. However, there are many types of malicious transaction-related projects, such as false health products, false investment rebates, and false calligraphy and painting auctions, etc. Sometimes the malicious merchants and the participating populations of each project do not intersect, and it will be difficult to cover them through the spread of existing malicious transaction cases at this time.

[0070] Embodiments of the present application provide a data processing method, apparatus, electronic device, computer-readable storage medium, and computer program product, which can intercept fraudulent merchants that use legitimate platform merchants to conduct illegal resource transfer behaviors. The following describes an exemplary application of the electronic device provided by the embodiments of the present application. The electronic device provided by the embodiments of the present application can be implemented as various types of object terminals such as laptop computers, tablet computers, desktop computers, set-top boxes, mobile devices (e.g., mobile phones, portable music players, personal digital assistants, dedicated messaging devices, portable game devices), etc., or can be implemented as a server. Hereinafter, an exemplary application will be described when the electronic device is implemented as a server.

[0071] See Figure 1 , Figure 1 FIG. 1 is a schematic architecture diagram of a data processing system 100 provided by the embodiments of the present application. To support a data processing application, the terminal 400 is connected to the server 200 through the network 300. The network 300 can be a wide area network, a local area network, or a combination of the two.

[0072] The terminal 400 is used to obtain a resource transfer request. For example, the terminal 400 generates a resource transfer request through the input interface 410. The server 200 is used to obtain a to-be-resource-transferred order based on the resource transfer request, perform a first risk detection process on the payee of the to-be-resource-transferred order to obtain a risk detection result of the payee. When the risk detection result of the payee indicates that the payee has a risk, intercept the to-be-resource-transferred order. When the risk detection result of the payee indicates that the payee does not have a risk, perform a second risk detection process on the to-be-resource-transferred order to obtain a risk detection result of the to-be-resource-transferred order. When the risk detection result of the to-be-resource-transferred order indicates that the to-be-resource-transferred order has a risk, intercept the to-be-resource-transferred order and return the risk detection result to the terminal 400.

[0073] In some embodiments, the server 200 can be an independent physical server, or a server cluster or distributed system composed of multiple physical servers. It can also be a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, Content Delivery Network (CDN), and big data and artificial intelligence platforms. The terminal 400 can be a smart phone, a tablet computer, a laptop computer, a desktop computer, a smart speaker, a smart watch, a vehicle-mounted terminal, etc., but is not limited thereto. The terminal and the server can be directly or indirectly connected through wired or wireless communication methods, which are not limited in the embodiments of the present application.

[0074] See Figure 2 , Figure 2It is a schematic structural diagram of the server 200 provided by an embodiment of the present application. Figure 2 The illustrated server 200 includes: at least one processor 210, a memory 250, at least one network interface 220, and an object interface 230. Each component in the server 200 is coupled together through a bus system 240. It can be understood that the bus system 240 is used to realize the connection and communication between these components. In addition to including a data bus, the bus system 240 also includes a power bus, a control bus, and a status signal bus. However, for the sake of clear illustration, in Figure 2 all kinds of buses are labeled as the bus system 240.

[0075] The processor 210 can be an integrated circuit chip with signal processing capabilities, such as a general-purpose processor, a digital signal processor (DSP, Digital Signal Processor), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. Among them, the general-purpose processor can be a microprocessor or any conventional processor, etc.

[0076] The object interface 230 includes one or more output devices 231 that enable the presentation of media content, including one or more speakers and / or one or more visual display screens. The object interface 230 also includes one or more input devices 232, including object interface components that facilitate object input, such as a keyboard, a mouse, a microphone, a touch screen display, a camera, other input buttons, and controls.

[0077] The memory 250 can be removable, non-removable, or a combination thereof. Exemplary hardware devices include solid-state memories, hard disk drives, optical disc drives, etc. The memory 250 optionally includes one or more storage devices that are physically located away from the processor 210.

[0078] The memory 250 includes volatile memory or non-volatile memory, and can also include both volatile and non-volatile memory. The non-volatile memory can be a read-only memory (ROM, Read Only Memory), and the volatile memory can be a random access memory (RAM, Random Access Memory). The memory 250 described in the embodiments of the present application is intended to include any suitable type of memory.

[0079] In some embodiments, the memory 250 is capable of storing data to support various operations. Examples of these data include programs, modules, and data structures, or subsets or supersets thereof, which are illustrated below.

[0080] The operating system 251 includes system programs for processing various basic system services and performing hardware-related tasks, such as the framework layer, the core library layer, the driver layer, etc., for implementing various basic services and processing hardware-based tasks;

[0081] The network communication module 252 is used to reach other computing devices via one or more (wired or wireless) network interfaces 420. Exemplary network interfaces 420 include: Bluetooth, Wi-Fi (Wireless Fidelity), and USB (Universal Serial Bus), etc.;

[0082] In some embodiments, the data processing device provided by the embodiments of the present application can be implemented in software. Figure 2 Shown is the data processing device 253 stored in the memory 250, which can be software in the form of programs and plugins, etc., including the following software modules: the acquisition module 2531 and the risk detection module 2532. These modules are logical, so they can be combined arbitrarily or further split according to the functions to be implemented. The functions of each module will be described below.

[0083] In other embodiments, the data processing device provided by the embodiments of the present application can be implemented in hardware. As an example, the device provided by the embodiments of the present application can be a processor in the form of a hardware decoding processor, which is programmed to execute the data processing method provided by the embodiments of the present application. For example, a processor in the form of a hardware decoding processor can employ one or more application specific integrated circuits (ASICs), digital signal processors (DSPs), programmable logic devices (PLDs), complex programmable logic devices (CPLDs), field programmable gate arrays (FPGAs), or other electronic components.

[0084] In some embodiments, a terminal or a server may implement the data processing method provided in the embodiments of the present application by running various computer-executable instructions or computer programs. For example, the computer-executable instructions may be commands at the microprogram level, machine instructions, or software instructions. The computer program may be a native program or a software module in an operating system; it may be a native application (APP), that is, a program that needs to be installed in the operating system to run, such as an instant messaging APP; it may also be a small program that can be embedded in any APP, that is, a program that only needs to be downloaded into a browser environment to run. In short, the above computer-executable instructions may be instructions in any form, and the above computer programs may be application programs, modules, or plug-ins in any form.

[0085] The exemplary applications and implementations of the server provided in the embodiments of the present application will be combined to illustrate the data processing method provided in the embodiments of the present application.

[0086] It should be noted that in the following examples of data processing, the interception of pyramid scheme fraud is used as an example for illustration. Those skilled in the art can apply the data processing method provided in the embodiments of the present application to data processing including the interception of other illegal acts according to the understanding of the following text.

[0087] See Figure 3A , Figure 3A is a schematic flowchart of the data processing method provided in the embodiments of the present application. Taking the server 200 as an example, the steps 101 to 105 shown will be described. Figure 3A will be described with reference to the steps 101 to 105 shown.

[0088] In step 101, a to-be-resource-transfer order is obtained.

[0089] As an example, when an object initiates a resource transfer application, the resource transfer application here may be a payment application, and the background generates a to-be-resource-transfer order corresponding to the resource transfer application. The to-be-resource-transfer order includes information such as the payee object, the payer object, the transaction amount, the type of transaction goods, the quantity of transaction goods, and the unit price of transaction goods.

[0090] In step 102, a first risk detection process is performed on the payee object of the to-be-resource-transfer order to obtain a risk detection result of the payee object.

[0091] See Figure 3B , Figure 3B is an alternative schematic flowchart of the data processing method provided in the embodiments of the present application. In some embodiments, Figure 3A step 102 in Figure 3B can be implemented by the steps 1021 to 1023 shown in

[0092] In step 1021, obtain the credit mark of the payee object.

[0093] As an example, after obtaining the resource transfer order to be processed, confirm the payee object of the resource transfer order to be processed, and query the credit mark of the payee object of the resource transfer order to be processed in the background. The credit mark is used to indicate whether the payee object is an illegal object.

[0094] In step 1022, when the credit mark is a risk mark, determine that the risk detection result of the payee object is that the payee object has a risk.

[0095] As an example, for payee object a, through background query, it is determined that the credit mark of payee object a is a risk mark, then it is determined that payee object a is an illegal object, that is, it is determined that the risk detection result of payee object a is that payee object a has a risk.

[0096] In step 1023, when the credit mark is a normal mark, determine that the risk detection result of the payee object is that the payee object does not have a risk.

[0097] As an example, for payee object b, through background query, it is determined that the credit mark of payee object b is a normal mark, then it is determined that payee object b is a legal object, that is, it is determined that the risk detection result of payee object b is that payee object b does not have a risk.

[0098] By performing risk detection on the payee object of the resource transfer order to be processed before resource transfer, it is determined whether the payee object is an illegal object. Starting from the initiation of the resource transfer behavior, the risk verification of the payee object is realized, preventing illegal objects from participating in the resource transfer behavior, intercepting illegal resource transfer behaviors from the source, and improving the interception efficiency of illegal objects and illegal behaviors.

[0099] In step 103, when the risk detection result of the payee object indicates that the payee object has a risk, intercept the resource transfer order to be processed.

[0100] As an example, for payee object a, whose credit mark is a risk mark, it is determined that the risk detection result of payee object a indicates that payee object a has a risk. At this time, the background intercepts this resource transfer behavior, prevents the payer object from performing transfer behaviors such as entering the password and confirming the payment, and gives a prompt to the payer object that payee object a has a risk, arousing the payer object's vigilance towards payee object a and the fund pool project related to payee object a.

[0101] In step 104, when the risk detection result of the payee object indicates that the payee object does not have a risk, perform a second risk detection process on the resource transfer order to be processed to obtain the risk detection result of the resource transfer order to be processed.

[0102] SeeFigure 3C , Figure 3C is an optional flowchart of the data processing method provided by the embodiments of the present application. In some embodiments, Figure 3A step 104 in Figure 3C can be implemented by steps 1041 to 1043 shown in

[0103] In step 1041, obtain the credit mark of the payment object of the resource transfer order to be processed.

[0104] As an example, when the risk detection process for the collection object is completed and it is determined that the collection object is a normal object, it is still not possible to determine that the resource transfer behavior is safe and legal, because an illegal object may use the account of a legal collection object to defraud the payment object. However, in such a case, risk detection for the collection object can no longer achieve effective interception. Given that payment objects vulnerable to fraud by illegal objects have common characteristics, such as the elderly, those who have been defrauded, etc., therefore, based on common characteristics, a credit mark is set for the payment object. After the risk detection process for the collection object is completed and it is determined that the collection object is a normal object, the credit mark of the payment object is queried through the background.

[0105] In step 1042, when the credit mark indicates that the payment object has risks, perform feature extraction processing on the resource transfer order to be processed to obtain the risk features of the resource transfer order to be processed.

[0106] As an example, for payment object c, if it is queried through the background that payment object c is a 70-year-old elderly person and has been a victim of illegal behavior, it is determined that payment object c has risks, that is, there is an analysis that payment object c may be defrauded by an illegal object. At this time, based on other information of the resource transfer order to be processed, such as transaction amount, transaction commodity type, transaction commodity quantity, transaction commodity unit price, etc., perform feature extraction processing to obtain the risk features of the resource transfer order to be processed.

[0107] In step 1043, based on the risk features of the resource transfer order to be processed, perform order risk detection processing on the resource transfer order to be processed to obtain the risk detection result of the resource transfer order to be processed.

[0108] In some embodiments, step 1043 can be implemented in the following manner: obtain the order standard features. When the risk features of the resource transfer order to be processed do not conform to the order standard features, determine that the risk detection result of the resource transfer order to be processed is that the resource transfer order to be processed has risks. When the risk features of the resource transfer order to be processed conform to the order standard features, determine that the risk detection result of the resource transfer order to be processed is that the resource transfer order to be processed does not have risks.

[0109] As an example, for the resource transfer order 1 to be processed, the payee is b, the payer is c, the transaction amount is 50,000 yuan, and the type of transaction goods is game equipment (this type of transaction goods may be a false type set by illegal entities to avoid punishment). In the first risk detection process, no risk is identified for the payee b, but based on the credit mark of the payer c obtained from the background, it is determined that the payer c has a risk. At this time, the standard order features are obtained. For example, the standard feature of the transaction amount for the corresponding game equipment type is 1 to 500 yuan, and the standard feature of the payer's age for the corresponding game equipment type is 16 - 60 years old. Based on the risk features of the resource transfer order 1 to be processed, such as the risk feature of the transaction amount corresponding to the type of transaction goods being 50,000 yuan and the risk feature of the payer's age corresponding to the type of transaction goods being 70 years old, the risk detection process for the resource transfer order 1 is carried out. The risk features of the resource transfer order 1 do not conform to the standard order features, and it is determined that the risk detection result of the resource transfer order 1 is that the resource transfer order 1 has a risk. For the resource transfer order 2 to be processed, the payee is d, the payer is c, the transaction amount is 100 yuan, and the type of transaction goods is medicine. In the first risk detection process, no risk is identified for the payee d, but based on the credit mark of the payer c obtained from the background, it is determined that the payer c has a risk. At this time, the standard order features are obtained. For example, the standard feature of the transaction amount for the corresponding medicine type is 1 to 5,000 yuan, and the standard feature of the payer's age for the corresponding medicine type is 16 - 95 years old. Based on the risk features of the resource transfer order 2, such as the risk feature of the transaction amount corresponding to the type of transaction goods being 100 yuan and the risk feature of the payer's age corresponding to the type of transaction goods being 70 years old, the risk detection process for the resource transfer order 2 is carried out. The risk features of the resource transfer order 2 conform to the standard order features, and it is determined that the risk detection result of the resource transfer order 2 is that the resource transfer order 2 does not have a risk.

[0110] When it is determined that the payer has a risk of participating in illegal activities, by re - detecting the risk of the resource transfer behavior based on the risk features of the resource transfer order to be processed, on the one hand, it can prevent illegal entities from conducting illegal activities through the accounts of payees identified as not having risks, and on the other hand, it can avoid misjudgments caused by only detecting the risk of the payer and intercepting according to the detection results, which may affect the normal resource transfer behavior of the payer, thereby improving the interception efficiency for illegal entities and illegal activities.

[0111] When conducting risk detection on the payee and determining that the payee does not have a risk, by carrying out the order risk detection process based on the resource transfer order to be processed, a secondary detection of the resource transfer behavior is carried out from the dimension of the resource transfer order to be processed, preventing the inability to intercept illegal entities because they conduct illegal activities through the accounts of payees identified as not having risks, and improving the interception efficiency for illegal entities and illegal activities.

[0112] In step 105, when the risk detection result of the resource transfer order to be processed indicates that the resource transfer order to be processed has risks, intercept the resource transfer order to be processed.

[0113] See Figure 4 , Figure 4 which is a schematic flowchart of the method for determining the credit mark of the payee provided by the embodiments of the present application. In some embodiments, before performing step 102, the steps 201 to 204 in Figure 4 may also be executed, and the details are described below.

[0114] In step 201, when the risk level of the payee is higher than the risk level threshold, perform risk feature identification processing on the payee based on the risk detection strategy.

[0115] As an example, the credit mark of the payee is marked by the background after evaluating the risk level of the payee according to the historical resource transfer data of the payee. When the risk level of the payee is higher than the risk level threshold, it is considered that the account of the payee may be an account of an illegal object used for illegal activities. Therefore, it is necessary to perform risk feature identification on the payee based on the risk detection strategy to further determine whether the account of the payee is an account of an illegal object used for illegal activities, and determine the credit mark of the payee according to the risk feature identification result.

[0116] In step 202, when a risk feature is identified, determine the credit mark of the payee as a risk mark.

[0117] As an example, when performing risk feature identification processing on the payee, if a risk feature is identified, such as the proportion of historical untrustworthy transactions of the payee, historical false commodity categories, prices not meeting market regulations, etc., it is directly determined that the account of the payee is an account of an illegal object used for illegal activities, and then the credit mark of the payee is determined as a risk mark.

[0118] In step 203, when the risk level of the payee is not higher than the risk level threshold, receive the risk audit result input by the audit institution for the payee.

[0119] As an example, when the risk level of the payee is not higher than the risk level threshold, it cannot be determined that the payee is a legal object. It is necessary to introduce the risk audit result input by the audit institution for the payee, that is, the manual audit result, to further determine whether the account of the payee is an account of an illegal object used for illegal activities, and determine the credit mark of the payee according to the risk audit result.

[0120] In step 204, when the collection object in the risk review result table belongs to a suspicious object, determine that the credit mark of the collection object is a risk mark.

[0121] As an example, based on the associated information of the collection object mastered by the review agency, such as evidence of substantial illegal acts such as hierarchical distribution and false propaganda involved in the operation process of the money pool project participated by the collection object, determine that the collection object belongs to a suspicious object, and determine the information mark of the collection object as a risk mark.

[0122] By setting different risk detection strategies for collection objects according to different risk levels, for collection objects with a risk level higher than the risk level threshold, directly determine the credit mark based on the risk characteristics of the collection object to improve the risk determination efficiency of the collection object. For collection objects with a risk level not higher than the risk level threshold, introduce the risk review result of the review agency to detect the risk of the collection object, avoiding missing collection objects with a risk level not higher than the risk level threshold but still having illegal acts, and improving the interception efficiency of illegal objects and illegal acts.

[0123] In some embodiments, after performing step 204, the following operations can also be performed: obtain the risk data characteristics of the collection object with a credit mark of a risk mark, based on the risk data characteristics, determine the spreading collection objects associated with the collection object. When the risk level of the spreading collection object is higher than the risk level threshold, perform risk feature identification processing on the spreading collection object based on the risk detection strategy to determine the credit mark of the spreading collection object. When the risk level of the spreading collection object is not higher than the risk level threshold, receive the risk review result input by the review agency for the spreading collection object, and determine the credit mark of the spreading collection object based on the risk review result of the spreading collection object.

[0124] As an example, the risk data features can be data features such as the business license of the payee object, application programs, etc. For example, when the risk data feature is the business license, obtain the business license of the payee object with a credit mark as a risk mark. Based on the business license of the payee object, query other payee objects using the same business license as the diffused payee objects associated with the payee object. The diffused payee objects may be other accounts for real-time illegal activities applied by illegal objects that use the account of the payee object to carry out illegal activities in order to avoid interception. Therefore, it is necessary to perform risk identification on the diffused payee objects, determine the risk levels of the diffused payee objects, and based on the risk levels of the diffused payee objects, determine the risk audit results based on the above risk detection strategy or by introducing an audit institution, and determine the risk marks of the diffused payee objects to achieve interception in the resource transfer behaviors participated by the diffused payee objects. Among them, the method of determining the risk marks of the diffused payee objects based on the risk levels of the diffused payee objects, determining the risk audit results based on the above risk detection strategy or by introducing an audit institution is the same as that in steps 201 to 204, and will not be elaborated here.

[0125] After determining the payee object with risks, by automatically querying the diffused payee objects associated with it according to the risk data features of the payee object, and selecting the corresponding strategy according to the risk levels of the diffused payee objects to determine the risk marks of the diffused payee objects, other risk objects can be quickly identified after determining a risky payee object, realizing diffused interception. On the one hand, it increases the coverage of risk identification. On the other hand, when illegal objects apply for multiple accounts to carry out illegal activities, effective interception can still be achieved, improving the interception efficiency of illegal objects and illegal activities.

[0126] See Figure 5A , Figure 5A is a schematic flowchart of the method for determining the risk level of the payee object provided by the embodiment of the present application. In some embodiments, before performing step 201, the steps 301 to 303 shown in Figure 5A may also be executed, which will be described in detail below.

[0127] In step 301, obtain the media data of multiple historical payee objects and obtain the resource transfer data of multiple historical payee objects, where the multiple historical payee objects include the payee object.

[0128] See Figure 5B , Figure 5B is an alternative schematic flowchart of the method for determining the risk level of the payee object provided by the embodiment of the present application. In some embodiments, Figure 5A the obtaining of the media data of multiple historical payee objects in step 301 in Figure 5B can be realized through the steps 3011A and 3012A shown in

[0129] In step 3011A, risk identification processing is performed on multiple social groups to obtain the risk results of each social group.

[0130] As an example, feature extraction is performed on multiple social groups on the platform to obtain the group features of each social group and the account features of the group members in the social group. For example, attribute features (whether it is a trading group), statistical features, behavioral features (whether resource transfer is performed in the social group), and content features (whether there is publicity content of a money circulation project in the conversation content or group announcement). Based on the group features and account features, risk identification processing is performed on the social group to obtain the risk results of each social group.

[0131] In step 3012A, when the risk result indicates that the social group is a risk group and any historical collection object is associated with the risk group, the warning data corresponding to the risk group is obtained as the media data of any historical collection object.

[0132] As an example, when the risk result obtained by performing risk identification processing based on the group features of the social group and the account features of the group members indicates that the social group is a risk group, that is, it is considered that the group members in the social group are related to illegal behaviors. If the group members in the risk group were historical collection objects in the historical resource transfer behavior, then the warning data of the risk group is obtained as the media data of the historical collection object, and the warning data can be object complaints, etc.

[0133] By performing a full - scale analysis on multiple social groups to implement risk identification processing, quickly identify and determine the risk groups where illegal objects and victims gather, and determine the media data of historical collection objects based on the warning information of the risk groups. On the one hand, quickly determine the risk groups and historical collection objects suspected of having risks, and on the other hand, obtain the media data for further risk detection of historical collection objects suspected of having risks.

[0134] See Figure 5C , Figure 5C is an optional process schematic diagram of the method for determining the risk level of a collection object provided by an embodiment of the present application. In some embodiments, Figure 5A the obtaining of the media data of multiple historical collection objects in step 301 can be implemented through Figure 5C the steps 3011B and 3012B shown below, and the following is a detailed description.

[0135] The following processing is performed for each historical collection object:

[0136] In step 3011B, risk identification processing is performed on the target social group associated with the historical collection object to obtain the risk result of the target social group.

[0137] As an example, for a historical collection object participating in a historical resource transfer behavior, determine the target social group to which the historical collection object belongs based on social-side information, and extract the group characteristics of the target social group and the account characteristics of the group members in the target social group. For example, attribute characteristics, statistical characteristics, behavior characteristics, and content characteristics. Perform risk identification processing on the target social group based on the group characteristics and account characteristics to obtain the risk result of the target social group.

[0138] In step 3012B, when the risk result indicates that the target social group is a risk group, obtain the alarm data corresponding to the target risk group as the media data of the historical collection object.

[0139] As an example, if, based on the group characteristics and account characteristics, for example, there are a large number of promotional money pool projects in the conversations of the target social group, and it is determined that the target social group is a risk group, then obtain the alarm data of the target social group as the media data of the historical collection object. In the actual application process, when the target social group is determined to be a risk group, the alarm data of the target social group can be used as the media data of other group members who were historical collection objects in the historical resource transfer behavior in the target social group.

[0140] By obtaining the target social group associated with the historical collection object based on the already determined social-side information of the historical collection object and performing risk identification, lock an illegal object aggregation point based on one historical collection object, quickly determine relevant suspicious risk clues, and improve the interception efficiency of illegal objects and illegal behaviors.

[0141] In step 302, construct a resource transfer bipartite graph based on the media data of multiple historical collection objects and the resource transfer data of multiple historical collection objects.

[0142] See Figure 5D , Figure 5D is an optional process schematic diagram of the method for determining the risk level of a collection object provided by an embodiment of the present application. In some embodiments, Figure 5A Step 302 in Figure 5D can be implemented through steps 3021 and 3022 shown in

[0143] In step 3021, based on the media data and the resource transfer data, determine the historical payment objects associated with each historical collection object and the historical organizational objects associated with each historical collection object.

[0144] As an example, query the resource transfer data of historical collection objects, determine the historical payment objects that have a resource transfer association with the historical collection objects, and then based on the media data of the historical collection objects, determine the historical organization objects that divert the historical collection objects to the historical payment objects. For example, on the social side, there is a social association between the historical payment object m and the historical organization object n, where the historical organization object n pushes information related to the account or program associated with the historical collection object x to the historical payment object m, and the historical payment object m performs a historical resource transfer behavior with the historical collection object x based on the push behavior (i.e., diversion) of the historical organization object n.

[0145] In step 3022, taking the historical collection object, the historical organization object, and the historical payment object as nodes, and taking the diversion relationship between the historical payment object and the historical organization object and the resource transfer relationship between the historical collection object and the historical payment object as edges, construct a resource transfer bipartite graph.

[0146] As an example, taking the historical collection object x, the historical organization object n, and the historical payment object m as nodes, constructing a diversion edge based on the diversion relationship between the historical payment object m and the historical organization object n, and constructing a resource transfer edge based on the resource transfer association between the historical collection object x and the historical payment object m, to construct a resource transfer bipartite graph. Among them, the basic structure of the resource transfer bipartite graph is: historical organization object n - diversion edge - historical payment object m - resource transfer edge - historical collection object x. In the actual application process, the number of objects associated with each historical organization object, each historical payment object, and each historical collection object is greater than or equal to 1, and the historical organization object and the historical payment object can be the same node.

[0147] By determining the historical payment objects and historical organization objects associated with the historical collection objects based on the media data and resource transfer data of the historical collection objects, and constructing a resource transfer bipartite graph with the diversion relationship between the historical payment objects and the historical organization objects and the resource transfer relationship between the historical collection objects and the historical payment objects as edges, the social side information and the resource transfer side information are fused in the same data graph, providing a data basis for subsequent feature aggregation processing and diffusion interception.

[0148] In step 303, based on the resource transfer bipartite graphs of multiple historical collection objects, perform risk level identification processing on the collection objects to obtain the risk level identification results of the collection objects.

[0149] See Figure 5E , Figure 5E which is an optional flowchart of the method for determining the risk level of collection objects provided by the embodiments of the present application. In some embodiments, Figure 5A step 303 in Figure 5EThe implementation of steps 3031 and 3032 shown in [Chinese text] will be described in detail below.

[0150] In step 3031, based on the resource transfer bipartite graph of multiple historical collection objects, feature aggregation processing is performed on the collection objects to obtain the risk level features of the collection objects.

[0151] In some embodiments, step 3031 can be implemented in the following manner: in the resource transfer bipartite graph, first-hop adjacent node sampling processing is performed on the collection objects to obtain first adjacent nodes, where the categories of the first adjacent nodes include at least one of the following: historical collection objects, historical payment objects, historical organization objects. For each first adjacent node, second-hop adjacent node sampling processing is performed to obtain second adjacent nodes, where the categories of the second adjacent nodes include at least one of the following: historical collection objects, historical payment objects, historical organization objects. For each first adjacent node, the following processing is performed: feature aggregation processing is performed on all the second adjacent nodes of the first adjacent node to obtain the first aggregation feature of the first adjacent node, and aggregation processing is performed on the first aggregation features of all the first adjacent nodes to obtain the risk features of the collection objects.

[0152] As an example, in the resource transfer bipartite graph, the basic structure is: historical organization object - drainage edge - historical payment object - resource transfer edge - historical receipt object. Each node can be associated with other nodes through drainage edges or resource transfer edges. For a certain historical receipt object y, it can be regarded as the receipt object y in this resource transfer behavior. When performing feature aggregation processing, for the receipt object y, the first-hop adjacent node sampling process is carried out to obtain the first adjacent nodes among the nodes adjacent to the receipt object y: historical receipt object 1, historical payment object 2, historical payment object 3, historical organization object 4. Then, for historical receipt object 1, historical payment object 2, historical payment object 3, and historical organization object 4, the second-hop adjacent node sampling process is carried out to obtain the second adjacent nodes: historical organization object 11, historical payment object 12, historical receipt object 21, historical receipt object 31, historical organization object 32, historical payment object 41, historical payment object 42, and historical receipt object 43. Feature aggregation processing is carried out for each first adjacent node: based on the features of historical organization object 11 and historical payment object 12, feature aggregation processing is carried out for historical receipt object 1 node to obtain the first aggregated feature of historical receipt object 1; based on the feature of historical receipt object 21, feature aggregation processing is carried out for historical payment object 2 to obtain the first aggregated feature of historical payment object 2; based on the features of historical receipt object 31 and historical organization object 32, feature aggregation processing is carried out for historical payment object 3 to obtain the first aggregated feature of historical payment object 3; based on the features of historical payment object 41, historical payment object 42, and historical receipt object 43, feature aggregation processing is carried out for historical organization object 4 to obtain the first aggregated feature of historical organization object 4. Then, based on the first aggregated feature of historical receipt object 1, the first aggregated feature of historical payment object 2, the first aggregated feature of historical payment object 3, and the first aggregated feature of historical organization object 4, feature aggregation processing is carried out to obtain the risk feature of the receipt object y.

[0153] By determining the nodes strongly associated with the receipt object based on the resource transfer bipartite graph and performing feature aggregation processing on the associated nodes, and finally performing feature aggregation processing on the receipt object based on the aggregated features of the associated nodes, the risk feature of the receipt object includes the information features of other nodes having a drainage relationship and a resource transfer relationship with it, enriching the information contained in the risk feature.

[0154] In step 3032, the deep neural network model is called to perform mapping processing on the risk level feature to obtain the risk level recognition result of the receipt object.

[0155] As an example, the risk characteristics of the collection target y are used as the input of the deep neural network model. The deep neural network model performs mapping processing on the risk level characteristics of the collection target y to predict the risk degree of the collection target y. The deep neural network model outputs the risk prediction result of the collection target y. The risk prediction result can be a risk level, such as high-risk, suspicious risk, or risk-free, or it can be a risk prediction score. Then, the risk level of the collection target y is determined according to the risk prediction score of the collection target y. For example, it is assumed that 0-20 points is risk-free, 21-50 points is suspicious risk, and 51-100 points is high-risk. If the deep neural network model outputs a risk prediction score of 79 points for the collection target y, then the risk level of the collection target y is determined to be high-risk.

[0156] By constructing a resource transfer bipartite graph and using the resource transfer bipartite graph to perform feature aggregation processing on the collection target, the risk characteristics of the collection target include the information characteristics of other nodes that have a drainage relationship and a resource transfer relationship with it, enriching the information contained in the risk characteristics. Then, the deep neural network model is used to perform mapping processing on the risk characteristics of the collection target to predict the risk degree of the collection target y, improve the accuracy of the risk prediction result, determine the risk level of the collection target, and determine the credit label of the collection target, thereby improving the interception efficiency of illegal objects and illegal behaviors.

[0157] Based on the information on the social side, the media data of historical collection targets is obtained, and based on the media data and resource transfer data of historical collection targets, a resource transfer bipartite graph is constructed. The historical organizational objects and historical payment objects associated with the collection target are reflected in the resource transfer bipartite graph. Based on the historical organizational objects and historical payment objects associated with the historical collection target, feature aggregation processing is performed on the collection target to obtain the risk characteristics of the collection target, so that the risk characteristics of the collection target incorporate the information characteristics of other nodes that have a drainage relationship and a resource transfer relationship with it. Then, the deep neural network model is used to perform mapping processing on the risk characteristics of the collection target to predict the risk degree of the collection target, determine the risk level of the collection target, improve the accuracy of the risk level determination of the collection target, ensure that the credit label of the collection target determined based on the risk level corresponds to the actual risk degree of the collection target, and then timely intercept the resource transfer orders to be associated with the collection target with risks, improving the interception efficiency for illegal objects and illegal behaviors.

[0158] Next, an exemplary application of the embodiments of the present application in an actual mobile payment platform application scenario will be described.

[0159] There are two dimensions for anti-fraud interception of money-making schemes in the embodiments of the present application: the merchant dimension and the order dimension.

[0160] Refer to Figure 6 ,Figure 6 This is a schematic diagram of the merchant - dimension interception interface provided by an embodiment of the present application. As Figure 6 shown in the merchant - dimension interception interface, before the object initiates a resource transfer application, the merchant has been identified as a Ponzi - scheme fraud merchant by the security side and has been punished. When the object clicks to pay and has not entered the password yet, the security side will immediately return the punishment result of the Ponzi - scheme fraud merchant to the payment background (that is, feedback the information that the merchant is a Ponzi - scheme fraud merchant to the payment background). Then the payment background immediately intercepts the resource transfer behavior of this order and returns the result of the failed resource transfer (that is Figure 6 the "temporarily unable to pay" shown in Figure 6 and the information that the current merchant is abnormal to the client, and displays it to the payment object. The payment object can enter the details interface through the "learn more" option on the interface. The details interface shows that the reason for the inability to pay is that the current resource transfer behavior (that is

[0161] Refer to Figure 7 Figure 7 This is a schematic diagram of the order - dimension interception interface provided by an embodiment of the present application. In Figure 7 the order - dimension interception interface shown, when the object starts to enter the password (starting to enter the password means starting to type numbers, starting face recognition, or starting fingerprint recognition), this order to be resource - transferred will immediately enter the Ponzi - scheme anti - fraud inspection process of the security side. Taking the input of a numeric password as an example, the inspection result will be returned to the payment background before the object completes the input of the six - digit password. The payment background decides whether to intercept this order to be resource - transferred according to the inspection result. When the payment background decides to intercept this order to be resource - transferred according to the order risk detection result, it returns the result of the failed resource transfer (that is Figure 7 the "temporarily unable to pay" shown in Figure 7 and the information that the current resource transfer behavior is abnormal (that is

[0162] the "current transaction behavior is abnormal" shown in Figure 8 Figure 8 This is a schematic diagram of the overall process of Ponzi - scheme business governance provided by an embodiment of the present application. As Figure 8 shown, when the client initiates a resource transfer application (that is, initiates an order to be resource - transferred) (that is, when the customer enters the resource transfer interface), it will send the associated information to the background security center and make a corresponding resource transfer result response according to the inspection result returned by the background security center. The overall general process is as follows:

[0163] ​​1. The object (i.e., the payment recipient) clicks to initiate an order for pending resource transfer, and the client sends the resource transfer request information to the background security center.

[0164] 2. At this time, the merchant interception module has asynchronously completed the identification of the merchant status (i.e., credit mark) of the receiving merchant (i.e., the recipient) through the merchant manual review module and the merchant automatic review module before this round of resource transfer behavior. If the receiving merchant is identified as a Ponzi scheme fraud merchant (i.e., risk mark), the order for pending resource transfer will be directly intercepted when the object conducts resource transfer. If the merchant passes the inspection, the merchant interception module will not intercept the order for pending resource transfer, and the object will enter the stage of inputting the resource transfer password.

[0165] 3. The object starts to input the password, and the order automatic review module in the order interception module starts to check the order status of this order for pending resource transfer. If the order for pending resource transfer is identified as a Ponzi scheme fraud order, the order for pending resource transfer will be intercepted. If the order for pending resource transfer passes the inspection, the order interception module will not intercept the order for pending resource transfer, and the background security center will confirm the successful resource transfer and feedback the resource transfer success message to the client.

[0166] 4. Whether it is the merchant interception module or the order interception module that intercepts the order for pending resource transfer, the corresponding result will be sent to the object and an appeal channel will be provided. Thus, the overall process ends.

[0167] The following describes Figure 8 the specific processing flow of the commercial interception module.

[0168] Referring to Figure 9 , Figure 9 which is a schematic diagram of the processing flow of the commercial interception module provided by an embodiment of the present application. As shown in Figure 9As shown in the figure, based on the external warning clues and Ponzi scheme fraud groups in the upstream social side information, merchants and objects are determined, and commercial side data features are generated (i.e., feature extraction processing) based on the merchants and objects, obtaining merchant attributes, merchant side statistical features, collection features, object attributes, object side statistical features, and behavior features. Based on the above features, a Ponzi scheme fraud suspicious merchant is identified by combining rules with an Extreme Gradient Boosting (XGB) model, a Deep Neural Networks (DNN) model, and a Graph Neural Network (GNN) model. A merchant is triggered based on an automatic policy combined with manual review. Among them, when a merchant is identified as a suspicious merchant (i.e., a suspicious object), the merchant is identified through a merchant manual review platform (i.e., a review institution) to determine whether to intercept the merchant. When a merchant is identified as a high-risk merchant (i.e., a risk object), the merchant is intercepted through a policy platform. After intercepting the merchant, a merchant super graph is established with the intercepted merchant as the object, and merchants with multi-dimensional associations with the intercepted merchant in the merchant super graph are intercepted through diffusion coverage. The following is a detailed description.

[0169] 1. Upstream social side information: The social groups of the mobile payment platform are a scenario that combines the characteristics of public and private domains, and naturally become the preferred place for Ponzi scheme illegal organizations to communicate. Refer to Figure 10 , Figure 10 which is the social recognition flowchart for Ponzi scheme fraud provided by the embodiments of this application. As Figure 10 shown, by extracting the attribute features, statistical features, behavior features, and content features in the group features of the suspected Ponzi scheme fraud groups (i.e., social groups) and the account features of group members, and then combining the models and rules on the social side to identify the features of these suspected Ponzi scheme fraud groups, the Ponzi scheme fraud groups (i.e., risk groups) are determined. The merchants (i.e., historical collection objects) and organizers (i.e., historical organization objects) in the Ponzi scheme fraud groups are used as risk detection objects. Finally, the Ponzi scheme fraud groups and organizer accounts are blocked and intercepted, and the participants enter the victim population database. And the fraud projects, fraud models, and relevant external warning clues obtained based on the group features and account features will be simultaneously brought to the downstream commercial payment side. This is also an important reason why the embodiments of this application can timely cover downstream fraud merchants and complete the interception of the entire Ponzi scheme project.

[0170] 2. Commercial-side data feature production: extract merchant features (merchant attributes, merchant statistical features, payment behavior features, etc.) and payment object features (object attributes, object statistical features, payment behavior features, etc.). Merchants and objects (i.e. historical payment objects) are linked together through a series of pending resource transfer orders. Since Ponzi scheme fraud is highly organized, organizers (i.e. historical organization objects) are often important "drainage" objects for victims and fraudulent merchants to complete resource transfers in commercial payments (organizers can be understood as the person in charge of the Ponzi scheme fraud project, and merchants are the persons in charge of the fraud project who are opened on the mobile payment platform for centralized payment collection). Reference Figure 11 , Figure 11 is a bipartite graph of commercial payments provided by the embodiment of the present application. Figure 11 As shown, a commercial payment bipartite graph (i.e., resource transfer bipartite graph) is constructed based on the relationship between organizers, merchants, objects, and merchants and objects-resource transfer-merchants, objects-flow-organizers, which contains two nodes: merchants and organizers, objects, and two edges: objects-resource transfer edges-merchants, objects-flow edges-organizers. By analyzing some common characteristics of merchants in the Ponzi scheme fraud project, such as merchant attributes, statistical characteristics, and collection characteristics, such as object attributes, statistical characteristics, and behavioral characteristics, the transaction ratio of Ponzi scheme participants, the unit price and amount distribution of a single transaction are selected as merchant characteristics, and age, average daily commercial payment amount, and number of transaction merchants are selected as object characteristics.

[0171] 3. Model combined with rule identification: Use rules, machine learning models and deep learning models to explore the common characteristics of various modes of Ponzi scheme fraud and identify fraudulent merchants. In actual applications, illegal objects often register multiple backup merchants. Once a merchant is intercepted, a new merchant can be quickly launched to avoid interception. On the other hand, the same group of illegal objects may operate different projects to deceive the same participants. At this time, the fraudulent projects and operating modes may have changed, but the associated illegal objects and core participants are highly homologous. Therefore, the embodiment of the present application is based on a commercial payment bipartite graph, and uses a GNN graph learning model to mine and identify backup merchants and related merchants of fraudulent merchants, and uses an unsupervised bipartite graph sampling neural network (Unsupervised Bipartite Graph Sample and Aggregate) algorithm to complete the mining of fraudulent merchants. The specific process is as follows. Figure 12 As shown, Figure 12It is a schematic diagram of the model recognition processing flow provided by the embodiment of the present application. First, neighbor sampling is performed, and the graph sampling neural network (GraphSAGE) is called to randomly sample the neighbor nodes of the target merchant (i.e., the payment object) in the commercial payment two-part graph. For example, 5 neighbor nodes (i.e., the first neighbor nodes) are collected in the first hop, and 20 neighbor nodes (i.e., the second neighbor nodes) are collected in the second hop; then feature aggregation is performed. In the node feature aggregation process, the features of the two-hop neighbors are first aggregated to obtain the first aggregated features of the first-hop neighbor nodes, and then the first aggregated features of the first-hop neighbor nodes are aggregated, and finally the merchant node aggregation features (i.e., the risk features of the payment object) are generated according to the first aggregated features and the merchant node features; finally, the score prediction stage is entered, and the deep learning classification stage of the downstream is entered. The merchant node features and merchant node aggregation features of the upstream will enter the deep neural network model (DNN) for prediction, and finally the predicted score of the capital dish fraud merchant is obtained. The GraphSAGE+DNN model is actually applied online in the identification process of capital dish fraud merchants, and the overall accuracy rate has reached more than 98%, and the potential capital dish fraud merchants have been effectively covered.

[0172] 4. Automatic strategy combined with manual review to punish merchants: Figure 13 , Figure 13 This is a flowchart of the automatic strategy combined with manual review and punishment of merchants provided in the embodiment of this application. Figure 13 As shown, after the suspicious merchants of Ponzi scheme fraud are identified, the merchants with risks are obtained. The merchants with risks are judged whether they are high-risk merchants or suspicious merchants, and the corresponding risk detection strategy is determined according to the type. For high-risk merchants (i.e., the recipients whose risk level is higher than the risk level threshold), the automatic strategy platform directly imposes qualitative penalties based on the actual fraud characteristics (such as: the proportion of untrustworthy transactions, false commodity categories and extremely high prices that do not conform to market rules, etc.). For suspicious merchants (i.e., the recipients whose risk level is not higher than the risk level threshold), it is necessary to rely on the manual intervention of the merchant review station to determine whether the merchant is fraudulent through human review and whether to punish the merchant (i.e., receive the risk review results for the recipient input by the review agency). For example, the customer review station actually participates in the entire operation process of the merchant-related Ponzi scheme project, records the substantial fraud evidence involving hierarchical distribution and false propaganda, and punishes the merchant based on the merchant review station. For merchants that have not been punished, the platform will maintain observation on the merchants.

[0173] 5. Diffusion coverage interception: refer to Figure 14 , Figure 14 Schematic diagram of the merchant super graph provided in the embodiment of the present application. Figure 14As shown, for merchants identified as fraudulent merchants, their suspicious information is queried, such as the application programs and product service platforms that initiate orders pending resource transfer, the marketing platforms for drainage, the aggregation groups and drainage targets, the payment targets participating in resource transfer, the business licenses of the merchants, and the servers and common gateway interfaces used for the above behaviors, etc., to construct a merchant super graph. It is worth mentioning that the high-performance graph database (wegraph) independently developed by the applicant endows graph computing with extremely high query efficiency. Even in the face of complex multi-dimensional diffusion computing requirements (millions of edges in two-hop relationships), the graph can return query calculation results within milliseconds of time-consuming, which is an indispensable tool in the work of intercepting the spread of fraudulent merchants in money-making schemes. Once a money-making scheme fraudulent merchant is identified as a high-risk merchant and punished, the automatic strategy will immediately spread rapidly, intercepting merchants related to the intercepted merchant in terms of multi-dimensional information, so as to completely eliminate relevant risk hazards. At this time, the method of multi-merchant decentralized collection by illegal objects no longer works. In addition, money-making scheme fraudulent merchants will immediately enter the black library, and the corresponding payment targets are associated through the merchant graph. These payment targets that have carried out resource transfer behaviors become the actual victims of money-making scheme fraud, and are the groups that need to be focused on and protected.

[0174] The following describes Figure 8 the specific processing flow of the order interception module in

[0175] In the process of combating the governance strategy against money-making scheme fraudulent merchants, illegal objects have gradually upgraded their fraud technologies and models. Nowadays, the most common countermeasure is to "separate the organization from resource transfer and let the funds go through large merchants". Specifically, illegal objects turn to adopt a fraud model of "other communication platforms" + "large merchants on mobile payment platforms", and no longer place the two processes of "organization" and "resource transfer" on the same platform. Although this move by illegal objects reduces the possibility of being detected and intercepted in the social group scenario and makes it impossible to directly intercept these large merchants on mobile payment platforms against illegal objects, their resource transfer behaviors are still completed within the mobile payment platform. At this time, the order interception module plays a key role.

[0176] Referring to Figure 15 , Figure 15 is a schematic diagram of the processing flow of the order interception module provided by an embodiment of the present application. As Figure 15 shown, based on the social side information of the participants in the money-making scheme fraud group and the money-making scheme fraudulent merchants, the victim population is circled to determine high-risk victims. During the process of resource transfer, based on the merchant characteristics of the large merchants exploited in the resource transfer behavior, the object characteristics of high-risk victims, and the order characteristics of the order pending resource transfer itself, the policy platform determines whether to intercept the order based on the above characteristics. The following is a detailed description.

[0177] 1. Victim population identification: Ponzi scheme projects have specific target participant groups. For example, the middle-aged and elderly. Often, after one project is intercepted, the illegal actors can restart another project and still attract the target participants. By analyzing the participants in the identified and intercepted Ponzi fraud groups and the payers of Ponzi fraud merchants, the victim population can be identified. The resource transfer orders of these targets that are yet to be processed are the main interception targets of the order interception module.

[0178] 2. Data feature generation: In addition to extracting the characteristics of the receiving merchants and victim objects, this also includes the important resource transfer relationship pairs carried by this resource transfer order to be processed. For example, whether the relationship between the object and the merchant is a commonly used resource transfer pair, whether the object belongs to the main receiving population of the merchant, and whether the transaction unit price deviates from the average receiving unit price of the merchant, etc.

[0179] 3. Automatic policy interception: As mentioned above, in order to minimize the impact on the user experience of the object, it is necessary to decide whether to intercept the resource transfer order to be processed before the object completes the verification of the resource transfer password. This means that only automatic policies can be used for auditing. The automatic policy combines rich merchant characteristics, object characteristics, and order characteristics, and is supplemented by some general characteristics of the Ponzi business resource transfer scenario, such as the resource transfer method, resource transfer location, and resource transfer time, etc., to promptly intercept Ponzi fraud orders.

[0180] It can be understood that in the embodiments of this application, when it comes to data related to the resource transfer behavior of the object, when the embodiments of this application are applied to specific products or technologies, the consent or permission of the object needs to be obtained, and the collection, use, and processing of relevant data need to comply with the relevant laws, regulations, and standards of relevant countries and regions.

[0181] Next, the implementation of the data processing device 253 provided in the embodiments of this application as an exemplary structure of software modules will be further described. In some embodiments, as Figure 2 shown, the software modules stored in the data processing device 253 in the memory 250 may include: an acquisition module 2531, configured to acquire a resource transfer order to be processed; a risk detection module 2532, configured to perform a first risk detection process on the receiving object of the resource transfer order to be processed to obtain a risk detection result of the receiving object; the risk detection module 2532 is further configured to intercept the resource transfer order to be processed when the risk detection result of the receiving object indicates that the receiving object has a risk; the risk detection module 2532 is further configured to perform a second risk detection process on the resource transfer order to be processed to obtain a risk detection result of the resource transfer order to be processed when the risk detection result of the receiving object indicates that the receiving object does not have a risk; the risk detection module 2532 is further configured to intercept the resource transfer order to be processed when the risk detection result of the resource transfer order to be processed indicates that the resource transfer order to be processed has a risk.

[0182] In some embodiments, the risk detection module 2532 is further configured to obtain a credit mark of the collection object. When the credit mark is a risk mark, it is determined that the risk detection result of the collection object is that the collection object has a risk. When the credit mark is a normal mark, it is determined that the risk detection result of the collection object is that the collection object does not have a risk.

[0183] In some embodiments, the risk detection module 2532 is further configured to, when the risk level of the collection object is higher than the risk level threshold, perform risk feature identification processing on the collection object based on a risk detection strategy. When a risk feature is identified, it is determined that the credit mark of the collection object is a risk mark. When the risk level of the collection object is not higher than the risk level threshold, it receives a risk audit result input by an audit institution for the collection object. When the risk audit result indicates that the collection object is a suspicious object, it is determined that the credit mark of the collection object is a risk mark.

[0184] In some embodiments, the risk detection module 2532 is further configured to obtain risk data characteristics of a collection object with a credit mark of a risk mark, and based on the risk data characteristics, determine a diffused collection object associated with the collection object. When the risk level of the diffused collection object is higher than the risk level threshold, perform risk feature identification processing on the diffused collection object based on a risk detection strategy to determine the credit mark of the diffused collection object. When the risk level of the diffused collection object is not higher than the risk level threshold, it receives a risk audit result input by an audit institution for the diffused collection object, and determines the credit mark of the diffused collection object based on the risk audit result of the diffused collection object.

[0185] In some embodiments, the risk detection module 2532 is further configured to obtain media data of multiple historical collection objects and obtain resource transfer data of multiple historical collection objects. Among them, the multiple historical collection objects include the collection object. A resource transfer bipartite graph is constructed based on the media data of the multiple historical collection objects and the resource transfer data of the multiple historical collection objects. Based on the resource transfer bipartite graph of the multiple historical collection objects, risk level identification processing is performed on the collection object to obtain a risk level identification result of the collection object.

[0186] In some embodiments, the risk detection module 2532 is further configured to perform risk identification processing on multiple social groups to obtain a risk result for each social group. When the risk result indicates that a social group is a risk group and any historical collection object is associated with the risk group, it obtains the warning data of the corresponding risk group as the media data of any historical collection object.

[0187] In some embodiments, the risk detection module 2532 is further configured to perform the following processing for each historical collection object: perform risk identification processing on the target social group associated with the historical collection object to obtain the risk result of the target social group, and when the risk result indicates that the target social group is a risk group, obtain the alarm data corresponding to the target risk group as the media data of the historical collection object.

[0188] In some embodiments, the risk detection module 2532 is further configured to determine the historical payment object associated with each historical collection object and the historical organization object associated with each historical collection object based on the media data and the resource transfer data, and construct a resource transfer bipartite graph with the historical collection object, the historical organization object, and the historical payment object as nodes and the drainage relationship between the historical collection object and the historical organization object and the resource transfer relationship between the historical collection object and the historical payment object as edges.

[0189] In some embodiments, the risk detection module 2532 is further configured to perform feature aggregation processing on the collection objects based on the resource transfer bipartite graphs of multiple historical collection objects to obtain the risk level features of the collection objects, and call a deep neural network model to perform mapping processing on the risk level features to obtain the risk level identification results of the collection objects.

[0190] In some embodiments, the risk detection module 2532 is further configured to perform first-hop adjacent node sampling processing on the collection objects in the resource transfer bipartite graph to obtain first adjacent nodes, where the categories of the first adjacent nodes include at least one of the following: historical collection objects, historical payment objects, and historical organization objects, perform second-hop adjacent node sampling processing on each first adjacent node to obtain second adjacent nodes, where the categories of the second adjacent nodes include at least one of the following: historical collection objects, historical payment objects, and historical organization objects, and perform the following processing for each first adjacent node: perform feature aggregation processing on all the second adjacent nodes of the first adjacent node to obtain the first aggregation feature of the first adjacent node, and perform aggregation processing on the first aggregation features of all the first adjacent nodes to obtain the risk features of the collection objects.

[0191] In some embodiments, the risk detection module 2532 is further configured to obtain the credit mark of the payment object of the order to be resource transferred, and when the credit mark indicates that the payment object has risks, perform feature extraction processing on the order to be resource transferred to obtain the risk features of the order to be resource transferred, and perform order risk detection processing on the order to be resource transferred based on the risk features of the order to be resource transferred to obtain the risk detection result of the order to be resource transferred.

[0192] In some embodiments, the risk detection module 2532 is further configured to obtain order standard features. When the risk features of the order to be resource-transferred do not conform to the order standard features, it is determined that the risk detection result of the order to be resource-transferred is that the order to be resource-transferred has risks. When the risk features of the order to be resource-transferred conform to the order standard features, it is determined that the risk detection result of the order to be resource-transferred is that the order to be resource-transferred does not have risks.

[0193] An embodiment of the present application provides a computer program product, which includes computer-executable instructions stored in a computer-readable storage medium. A processor of an electronic device reads the computer-executable instructions from the computer-readable storage medium, and the processor executes the computer-executable instructions, so that the electronic device executes the data processing method described above in the embodiments of the present application.

[0194] An embodiment of the present application provides a computer-readable storage medium storing computer-executable instructions, where the computer-executable instructions are stored. When the computer-executable instructions are executed by a processor, the processor will be caused to execute the data processing method provided in the embodiments of the present application. For example, as Figure 3A the data processing method shown.

[0195] In some embodiments, the computer-readable storage medium may be a memory such as RAM, ROM, flash memory, magnetic surface memory, optical disc, or CD-ROM; it may also be various devices including one or any combination of the above memories.

[0196] In some embodiments, the computer-executable instructions may be in the form of a program, software, software module, script, or code, and may be written in any form of programming language (including compiled or interpreted languages, or declarative or procedural languages), and may be deployed in any form, including being deployed as an independent program or being deployed as a module, component, subroutine, or other unit suitable for use in a computing environment.

[0197] As an example, the computer-executable instructions may or may not correspond to a file in a file system, and may be stored as part of a file that stores other programs or data. For example, they may be stored in one or more scripts in a Hyper Text Markup Language (HTML) document, stored in a single file dedicated to the program being discussed, or stored in multiple cooperating files (for example, files that store one or more modules, subroutines, or code portions).

[0198] As an example, the computer-executable instructions may be deployed to be executed on one electronic device, or on multiple electronic devices located at one location, or on multiple electronic devices distributed at multiple locations and interconnected through a communication network.

[0199] In summary, through the embodiments of this application, the data characteristics of the two major processes of organization and resource transfer in the Ponzi scheme fraud chain are coordinated, and fraudulent merchants are intercepted by combining manual review and automatic strategies, and fraudulent orders are intercepted by a fully automatic mechanism, which greatly improves the accuracy and coverage of intercepting Ponzi scheme commercial fraud. The highly automated identification and interception process not only reduces the manual operating costs, but also can intercept Ponzi scheme projects in time before they explode. The embodiments of this application focus on solving the following problems:

[0200] 1. Delayed interception. By opening up the data link between the social side and the business side, the upstream characteristic information of the payment object is greatly enriched, so that the time of discovery of illegal behavior is much earlier than the time of complaint. At the same time, more comprehensive fraud risk data can be fed back to the manual review side in a timely manner, promoting the early completion of manual characterization and interception of those "difficult and hidden" fraudulent merchants.

[0201] 2. Insufficient coverage. By sorting out the key entities (points) and associated (edge) information in the Ponzi scheme fraud chain, a merchant super graph with vast information is constructed. The graph neural network model and powerful graph computing capabilities are used to strengthen the identification, coverage and diffusion interception of Ponzi scheme fraud merchants, leaving no place for illegal objects to hide.

[0202] 3. The cost of manual operation is huge. The difficulty in identifying fraud has always been a major feature of Ponzi schemes, and heavy manual operations are unsustainable. The embodiment of this application first automatically collects clues from multiple parties by establishing a black database, and then the model and strategy automatically identify the associations of suspicious merchants. At this time, manual work can rely on the merchant review desk for review, and finally the review results are automatically pushed for punishment. The entire link is highly automated, so that very few people only need to focus on the most core review and qualitative issues, greatly improving operational efficiency.

[0203] The above is only an embodiment of the present application and is not intended to limit the protection scope of the present application. Any modifications, equivalent substitutions and improvements made within the spirit and scope of the present application are included in the protection scope of the present application.

Claims

1. A data processing method, characterized in that, the method includes: obtaining a to-be-resource-transfer order; performing a first risk detection process on the payee of the to-be-resource-transfer order to obtain a risk detection result of the payee; when the risk detection result of the payee indicates that the payee has a risk, intercepting the to-be-resource-transfer order; when the risk detection result of the payee indicates that the payee has no risk, performing a second risk detection process on the to-be-resource-transfer order to obtain a risk detection result of the to-be-resource-transfer order; when the risk detection result of the to-be-resource-transfer order indicates that the to-be-resource-transfer order has a risk, intercepting the to-be-resource-transfer order.

2. The method according to claim 1, characterized in that, the performing a first risk detection process on the payee of the to-be-resource-transfer order to obtain a risk detection result of the payee includes: obtaining a credit mark of the payee; when the credit mark is a risk mark, determining that the risk detection result of the payee is that the payee has a risk; when the credit mark is a normal mark, determining that the risk detection result of the payee is that the payee has no risk.

3. The method according to claim 2, characterized in that, the method further includes: when the risk level of the payee is higher than a risk level threshold, performing a risk feature identification process on the payee based on a risk detection strategy; when a risk feature is identified, determining that the credit mark of the payee is the risk mark; when the risk level of the payee is not higher than the risk level threshold, receiving a risk review result input by a review institution for the payee; when the risk review result indicates that the payee is a suspicious object, determining that the credit mark of the payee is the risk mark.

4. The method according to claim 3, characterized in that, the method further includes: obtaining risk data features of the payee whose credit mark is the risk mark; based on the risk data features, determining a diffused payee associated with the payee; when the risk level of the diffused payee is higher than the risk level threshold, performing a risk feature identification process on the diffused payee based on a risk detection strategy to determine the credit mark of the diffused payee; when the risk level of the diffused payee is not higher than the risk level threshold, receiving a risk review result input by a review institution for the diffused payee, and determining the credit mark of the diffused payee based on the risk review result of the diffused payee.

5. The method according to claim 3, characterized in that, the method further includes: obtaining media data of multiple historical payees and obtaining resource transfer data of multiple historical payees, where the multiple historical payees include the payee; constructing a resource transfer bipartite graph based on the media data of the multiple historical payees and the resource transfer data of the multiple historical payees; Based on the resource transfer bipartite graph of the multiple historical payees, perform risk level identification processing on the payees to obtain the risk level identification results of the payees.

6. The method according to claim 5, wherein, the obtaining of the media data of multiple historical payees includes: performing risk identification processing on multiple social groups to obtain the risk results of each social group; when the risk result indicates that the social group is a risk group and any historical payee is associated with the risk group, obtaining the warning data corresponding to the risk group as the media data of the any historical payee.

7. The method according to claim 5, wherein, the obtaining of the media data of multiple historical payees includes: performing the following processing for each historical payee: performing risk identification processing on the target social group associated with the historical payee to obtain the risk result of the target social group; when the risk result indicates that the target social group is a risk group, obtaining the warning data corresponding to the target risk group as the media data of the historical payee.

8. The method according to claim 5, wherein, the constructing of the resource transfer bipartite graph based on the media data of the multiple historical payees and the resource transfer data of the multiple historical payees includes: based on the media data and the resource transfer data, determining the historical payers associated with each historical payee and the historical organizational objects associated with each historical payee; using the historical payees, the historical organizational objects, and the historical payers as nodes, and using the drainage relationship between the historical payers and the historical organizational objects and the resource transfer relationship between the historical payees and the historical payers as edges, constructing the resource transfer bipartite graph.

9. The method according to claim 5, wherein, the performing of risk level identification processing on the payees based on the resource transfer bipartite graph of the multiple historical payees to obtain the risk level identification results of the payees includes: performing feature aggregation processing on the payees based on the resource transfer bipartite graph of the multiple historical payees to obtain the risk level features of the payees; invoking a deep neural network model to perform mapping processing on the risk level features to obtain the risk level identification results of the payees.

10. The method according to claim 9, wherein, the performing of feature aggregation processing on the payees based on the resource transfer bipartite graph of the multiple historical payees to obtain the risk level features of the payees includes: performing first-hop adjacent node sampling processing on the payees in the resource transfer bipartite graph to obtain first adjacent nodes, where the categories of the first adjacent nodes include at least one of the following: the historical payees, historical payers, historical organizational objects; For each of the first adjacent nodes, perform second adjacent node sampling processing to obtain second adjacent nodes, where the categories of the second adjacent nodes include at least one of the following: the historical collection object, the historical payment object, and the historical organization object; For each of the first adjacent nodes, perform the following processing: perform feature aggregation processing on all second adjacent nodes of the first adjacent node to obtain the first aggregated feature of the first adjacent node; Perform aggregation processing on the first aggregated features of all first adjacent nodes to obtain the risk feature of the collection object.

11. The method according to claim 1, wherein, the performing second risk detection processing on the to-be-resource-transfer order to obtain the risk detection result of the to-be-resource-transfer order includes: obtaining a credit mark of the payment object of the to-be-resource-transfer order; when the credit mark indicates that the payment object has a risk, perform feature extraction processing on the to-be-resource-transfer order to obtain the risk feature of the to-be-resource-transfer order; based on the risk feature of the to-be-resource-transfer order, perform order risk detection processing on the to-be-resource-transfer order to obtain the risk detection result of the to-be-resource-transfer order.

12. The method according to claim 11, wherein, the performing order risk detection processing on the to-be-resource-transfer order based on the risk feature of the to-be-resource-transfer order to obtain the risk detection result of the to-be-resource-transfer order includes: obtaining order standard features; when the risk feature of the to-be-resource-transfer order does not conform to the order standard features, determine that the risk detection result of the to-be-resource-transfer order is that the to-be-resource-transfer order has a risk; when the risk feature of the to-be-resource-transfer order conforms to the order standard features, determine that the risk detection result of the to-be-resource-transfer order is that the to-be-resource-transfer order does not have a risk.

13. A data processing device, wherein, the device includes: an acquisition module, configured to acquire a to-be-resource-transfer order; a risk detection module, configured to perform first risk detection processing on the collection object of the to-be-resource-transfer order to obtain the risk detection result of the collection object; the risk detection module is further configured to intercept the to-be-resource-transfer order when the risk detection result of the collection object indicates that the collection object has a risk; the risk detection module is further configured to perform second risk detection processing on the to-be-resource-transfer order when the risk detection result of the collection object indicates that the collection object does not have a risk to obtain the risk detection result of the to-be-resource-transfer order; the risk detection module is further configured to intercept the to-be-resource-transfer order when the risk detection result of the to-be-resource-transfer order indicates that the to-be-resource-transfer order has a risk.

14. An electronic device, wherein, the electronic device includes: a memory, configured to store computer-executable instructions; a processor, configured to implement the method according to any one of claims 1 to 12 when executing the computer-executable instructions stored in the memory.

15. A computer-readable storage medium stores computer-executable instructions, wherein, when the executable instructions are executed by a processor, the method according to any one of claims 1 to 12 is implemented.

16. A computer program product includes computer-executable instructions, wherein, when the computer-executable instructions are executed by a processor, the method according to any one of claims 1 to 12 is implemented.

Citation Information

Cited By

  • Feature recognition management method and system for electronic payment

    CN121052830A