Data analysis method and device, electronic equipment and storage medium

Through the methods of risk assessment, clustering and abnormal dimension positioning of enterprise asset data, the problem of inefficient abnormal analysis in the existing technology is solved, automated risk positioning and early warning are realized, and data analysis efficiency and management capabilities are improved.

CN120070060APending Publication Date: 2025-05-30PING AN INT FINANCIAL LEASING CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510138317.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-07
Publication Date
2025-05-30

AI Technical Summary

Technical Problem

When performing abnormal analysis of enterprise asset data, the existing technology is inefficient and the manual identification process is cumbersome, resulting in low analysis efficiency.

Method used

A data analysis method is proposed to obtain enterprise asset data, conduct risk assessment, clustering and splitting, abnormal dimension positioning and risk warning point generation, and realize automated abnormal data analysis.

Benefits of technology

It improves the efficiency of data anomaly analysis, can automatically locate risk sources, reduce manual processing costs, and improves the ability to manage asset data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120070060A_ABST
    Figure CN120070060A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides a data analysis method and device, electronic equipment and a storage medium, belongs to the technical field of data analysis, and is suitable for financial scenes. The method comprises the steps of obtaining enterprise asset data which comprises index data under a plurality of preset indexes, performing risk assessment processing on the index data to obtain attention indexes, performing clustering splitting processing on the enterprise asset data according to the attention indexes to obtain abnormal data, and carrying out abnormal dimension positioning processing on the abnormal data to obtain a risk dimension, generating a risk early warning point according to the risk dimension, and carrying out risk pushing based on the risk early warning point. The embodiment of the invention can improve the data exception analysis efficiency, and can be widely applied to the technical field of data processing.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the technical field of data analysis, is applicable to the financial field, and particularly relates to a data analysis method, device, electronic device, and storage medium. Background Art

[0002] With the rapid development of computer technology, the data that applications or systems need to process is increasing day by day. Enterprise asset data refers to all asset-related information and data involved and managed by an enterprise during its operation. In a financial scenario, it is necessary to perform anomaly analysis on enterprise asset data so that the enterprise can better understand its asset status and optimize resource allocation. Currently, the analysis method for abnormal data usually uses a combination of system calculation and manual screening, and the process of manual screening of data is fixed and cumbersome, resulting in low efficiency in analyzing abnormal data. Therefore, how to improve the efficiency of anomaly analysis of data has become a technical problem to be solved urgently. Summary of the Invention

[0003] The main purpose of the embodiments of this application is to propose a data analysis method, device, electronic device, and storage medium, aiming to improve the efficiency of anomaly analysis of data.

[0004] To achieve the above purpose, on the one hand, the embodiments of this application propose a data analysis method, and the method includes:

[0005] Obtain enterprise asset data, where the enterprise asset data includes index data under multiple preset indexes;

[0006] Perform risk assessment processing on the index data to obtain concerned indexes;

[0007] Perform clustering and splitting processing on the enterprise asset data according to the concerned indexes to obtain abnormal data;

[0008] Perform abnormal dimension positioning processing on the abnormal data to obtain risk dimensions;

[0009] Generate risk warning points according to the risk dimensions, and perform risk push based on the risk warning points.

[0010] In some embodiments, the performing risk assessment processing on the index data to obtain concerned indexes includes:

[0011] Input the index data into a neural network model for evaluation processing to obtain risk data;

[0012] Perform screening processing on the multiple preset indexes according to the risk data to obtain the concerned indexes.

[0013] In some embodiments, the clustering and splitting process of the enterprise asset data according to the concerned metrics to obtain abnormal data includes:

[0014] Performing a feature tree construction process on the enterprise asset data to obtain a clustering feature tree;

[0015] Performing a node splitting process on the clustering feature tree to obtain split data;

[0016] Performing a screening process on the split data according to the concerned metrics to obtain the abnormal data.

[0017] In some embodiments, the screening process of the split data according to the concerned metrics to obtain the abnormal data includes:

[0018] Performing a metric calculation process on the split data according to the concerned metrics, and performing a screening process on the calculated metric data based on a preset threshold to obtain abnormal clusters;

[0019] Performing a clustering analysis process on the abnormal clusters, updating the split data according to the clustering analysis result, and returning to the step of performing a metric calculation process on the split data according to the concerned metrics until the abnormal clusters are minimum-dimension data, and determining the abnormal clusters of the minimum-dimension data as the abnormal data.

[0020] In some embodiments, the abnormal dimension positioning process of the abnormal data to obtain risk dimensions includes:

[0021] Performing an analysis process on the dimension attributes of the abnormal data to obtain data dimensions;

[0022] Performing an interval positioning process on the abnormal data according to the data dimensions to obtain the risk dimensions.

[0023] In some embodiments, the interval positioning process of the abnormal data according to the data dimensions to obtain the risk dimensions includes:

[0024] Constructing a dimension space according to the data dimensions;

[0025] Performing a weighted statistical process on the abnormal data according to the dimension space to obtain the risk dimensions.

[0026] In some embodiments, the risk push based on risk warning points includes:

[0027] Generating abnormal information according to the risk warning points, and inputting the abnormal information into a language model to generate warning information;

[0028] Pushing the warning information to a target object for risk handling.

[0029] To achieve the above object, on the other hand, an embodiment of the present application proposes a data analysis device, which is applied to the data analysis method as described above. The device includes:

[0030] A first module, configured to obtain enterprise asset data, where the enterprise asset data includes index data under multiple preset indexes;

[0031] A second module, configured to perform risk assessment processing on the index data to obtain concerned indexes;

[0032] A third module, configured to perform clustering and splitting processing on the enterprise asset data according to the concerned indexes to obtain abnormal data;

[0033] A fourth module, configured to perform abnormal dimension positioning processing on the abnormal data to obtain risk dimensions;

[0034] A fifth module, configured to generate risk warning points according to the risk dimensions and perform risk push based on the risk warning points.

[0035] In some embodiments, the second module, configured to perform risk assessment processing on the index data to obtain concerned indexes, includes the following units:

[0036] A first unit, configured to input the index data into a neural network model for evaluation processing to obtain risk data;

[0037] A second unit, configured to perform screening processing on the multiple preset indexes according to the risk data to obtain the concerned indexes.

[0038] In some embodiments, the third module, configured to perform clustering and splitting processing on the enterprise asset data according to the concerned indexes to obtain abnormal data, includes the following units:

[0039] A third unit, configured to perform feature tree construction processing on the enterprise asset data to obtain a clustering feature tree;

[0040] A fourth unit, configured to perform node splitting processing on the clustering feature tree to obtain split data;

[0041] A fifth unit, configured to perform screening processing on the split data according to the concerned indexes to obtain the abnormal data.

[0042] In some embodiments, the fifth unit, configured to perform screening processing on the split data according to the concerned indexes to obtain the abnormal data, includes:

[0043] The first sub-unit is configured to perform index calculation processing on the split data according to the concerned index, and perform screening processing on the calculated index data based on a preset threshold to obtain abnormal clusters;

[0044] The second sub-unit is configured to perform clustering analysis processing on the abnormal clusters, update the split data according to the clustering analysis result, and return it to the first sub-unit until the abnormal clusters are the minimum-dimensional data, and determine the abnormal clusters of the minimum-dimensional data as the abnormal data.

[0045] In some embodiments, the fourth module is configured to perform abnormal dimension location processing on the abnormal data to obtain a risk dimension, including:

[0046] The sixth unit is configured to perform analysis processing on the dimension attributes of the abnormal data to obtain data dimensions;

[0047] The seventh unit is configured to perform interval location processing on the abnormal data according to the data dimensions to obtain the risk dimension.

[0048] On the other hand, to achieve the above object, an embodiment of the present application proposes an electronic device, the electronic device includes a memory and a processor, the memory stores a computer program, and when the processor executes the computer program, the data analysis method described above is implemented.

[0049] On another aspect, to achieve the above object, an embodiment of the present application proposes a computer-readable storage medium, the computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the data analysis method described above is implemented.

[0050] A data analysis method, device, electronic device and storage medium proposed by the present application can obtain enterprise asset data, perform risk assessment processing on the enterprise asset data to obtain concerned indexes, and can determine the concerned indexes by focusing on the causes of risk occurrence in asset management, so as to better monitor the asset data through the concerned indexes. In addition, the solution performs clustering and splitting processing on the enterprise asset data according to the concerned indexes to obtain abnormal data, performs abnormal dimension location processing on the abnormal data to obtain a risk dimension, generates a risk warning point according to the risk dimension, and performs risk push based on the risk warning point. This solution can automatically locate the risk source by performing down exploration and dimension analysis on the abnormal data to the dimension where the problem occurs, improves the data analysis efficiency, and enhances the management ability of the asset data. Description of the Drawings

[0051] Figure 1 is a flowchart of a data analysis method provided by an embodiment of the present application;

[0052] Figure 2 isFigure 1 The flowchart of step S102 in

[0053] Figure 3 is Figure 1 The flowchart of step S103 in

[0054] Figure 4 is Figure 3 The flowchart of step S303 in

[0055] Figure 5 is Figure 1 The flowchart of step S104 in

[0056] Figure 6 is Figure 5 The flowchart of step S502 in

[0057] Figure 7 is Figure 1 The flowchart of step S105 in

[0058] Figure 8 The structural schematic diagram of a data analysis device provided by an embodiment of the present application;

[0059] Figure 9 The hardware structural schematic diagram of an electronic device provided by an embodiment of the present application. Detailed implementation manners

[0060] In order to make the objectives, technical solutions and advantages of the present application clearer, the present application will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application, and are not used to limit the present application.

[0061] It should be noted that although the functional modules are divided in the device schematic diagram and the logical order is shown in the flowchart, in some cases, the steps shown or described may be executed in a different order from the module division in the device or the order in the flowchart. Terms such as "first" and "second" in the description, claims and the above drawings are used to distinguish similar objects, and do not necessarily need to describe a specific order or sequence.

[0062] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by those skilled in the technical field to which this application belongs. The terms used herein are only for the purpose of describing the embodiments of this application, and are not intended to limit this application.

[0063] First, several nouns involved in the present application are analyzed:

[0064] Artificial Intelligence (AI): It is a new technical science that studies and develops theories, methods, technologies, and application systems for simulating, extending, and expanding human intelligence. Artificial intelligence is a branch of computer science. It attempts to understand the essence of intelligence and produce a new intelligent machine that can respond in a way similar to human intelligence. The research in this field includes robots, speech recognition, image recognition, natural language processing, and expert systems, etc. Artificial intelligence can simulate the information process of human consciousness and thinking. It also uses digital computers or machines controlled by digital computers to simulate, extend, and expand human intelligence, perceive the environment, acquire knowledge, and use knowledge to obtain the best results in terms of theories, methods, technologies, and application systems.

[0065] Natural Language Processing (NLP): NLP uses computers to process, understand, and apply human languages (such as Chinese, English, etc.). NLP is a branch of artificial intelligence and an interdisciplinary field of computer science and linguistics, often referred to as computational linguistics. Natural language processing includes syntactic analysis, semantic analysis, discourse understanding, etc. Natural language processing is commonly used in technical fields such as machine translation, recognition of handwritten and printed characters, speech recognition, text-to-speech conversion, information intention recognition, information extraction and filtering, text classification and clustering, public opinion analysis, and opinion mining. It involves data mining, machine learning, knowledge acquisition, knowledge engineering, artificial intelligence research related to language processing, and linguistic research related to language computing.

[0066] Data mining technology: It is a technology that searches for patterns from a large amount of data by analyzing each piece of data. Data mining is a decision-making support process. It mainly relies on artificial intelligence, machine learning, pattern recognition, statistics, databases, visualization technology, etc., to highly automate the analysis of enterprise data, conduct inductive reasoning, and extract potential patterns from it, helping decision-makers adjust market strategies, reduce risks, and make correct decisions.

[0067] As described in the background technology section, in the related technology, when facing the abnormal data analysis process of a large amount of data, the overall index results are calculated by the system for display, the dimensional direction is determined manually, and then interactively drilled down to the data of the corresponding dimension for manual analysis to locate the ultimate cause of the problem. However, manual analysis of problems has the situations of lag, long process, time-consuming, and low efficiency, which affects the data analysis efficiency.

[0068] Based on this, the embodiments of the present application provide a data analysis method, device, electronic device, and storage medium, aiming to improve the efficiency of abnormal analysis of asset data.

[0069] A data analysis method, apparatus, electronic device, and storage medium provided by an embodiment of the present application will be specifically described through the following embodiments. First, the data processing method in the embodiment of the present application will be described.

[0070] The embodiment of the present application can acquire and process relevant data based on artificial intelligence technology. Among them, Artificial Intelligence (AI) is a theory, method, technology, and application system that uses digital computers or machines controlled by digital computers to simulate, extend, and expand human intelligence, perceive the environment, acquire knowledge, and use knowledge to obtain the best results.

[0071] Artificial intelligence basic technologies generally include technologies such as sensors, dedicated artificial intelligence chips, cloud computing, distributed storage, big data processing technology, operation / interaction systems, and mechatronics. Artificial intelligence software technologies mainly include several major directions such as computer vision technology, robotics, biometric technology, speech processing technology, natural language processing technology, and machine learning / deep learning.

[0072] A data analysis method provided by an embodiment of the present application relates to the field of artificial intelligence technology. The data analysis method provided by the embodiment of the present application can be applied to a terminal, or to a server side, or can also be software running on a terminal or a server side. In some embodiments, the terminal can be a smart phone, a tablet computer, a notebook computer, a desktop computer, etc.; the server side can be configured as an independent physical server, or can be configured as a server cluster or distributed system composed of multiple physical servers, or can also be configured as a cloud server providing basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, CDN, and big data and artificial intelligence platforms; the software can be an application that implements a data analysis method, etc., but is not limited to the above forms.

[0073] This application can be used in many general or specific computer system environments or configurations. For example: personal computers, server computers, handheld or portable devices, tablet devices, multiprocessor systems, microprocessor-based systems, set-top boxes, programmable consumer electronic devices, network PCs, minicomputers, mainframe computers, distributed computing environments including any of the above systems or devices, and so on. This application can be described in the general context of computer-executable instructions executed by a computer, such as program modules. Generally, program modules include routines, programs, objects, components, data structures, etc. that perform specific tasks or implement specific abstract data types. This application can also be practiced in a distributed computing environment, where tasks are performed by remote processing devices connected through a communication network. In a distributed computing environment, program modules can be located in local and remote computer storage media including storage devices.

[0074] It should be noted that in each specific embodiment of this application, when it comes to relevant processing based on data related to user identity or characteristics such as user information, user behavior data, user historical data, and user location information, user permission or consent will be obtained first. Moreover, the collection, use, and processing of these data will comply with relevant laws, regulations, and standards. In addition, when an embodiment of this application needs to obtain sensitive personal information of a user, the user's separate permission or separate consent will be obtained through methods such as pop-up windows or redirecting to a confirmation page. After clearly obtaining the user's separate permission or separate consent, the necessary user-related data for the normal operation of the embodiment of this application will be obtained.

[0075] Please refer to Figure 1 , Figure 1 which is an optional flowchart of a data analysis method provided by an embodiment of this application, Figure 1 The method in

[0076] Step S101, obtain enterprise asset data, where the enterprise asset data includes index data under multiple preset indexes;

[0077] Step S102, perform a risk assessment process on the index data to obtain concerned indexes;

[0078] Step S103, perform a clustering and splitting process on the enterprise asset data according to the concerned indexes to obtain abnormal data;

[0079] Step S104, perform an abnormal dimension positioning process on the abnormal data to obtain risk dimensions;

[0080] Step S105: Generate risk warning points according to the risk dimensions and perform risk push based on the risk warning points.

[0081] Steps S101 to S105 as shown in the embodiments of the present application can be applied to the field of data analysis technology, especially in the financial scenario. An enterprise evaluates the investment value and optimizes the asset allocation by analyzing enterprise asset data, such as financial status, industry trends, market competition, etc. The embodiments of the present application first obtain enterprise asset data for risk assessment processing. The enterprise asset data includes index data under multiple preset indexes. The preset indexes may include overdue rate, non-performing rate, credit approval passing rate, rejection rate, duration, profit rate, etc. The index data is the corresponding actual data. The system can perform risk assessment on the index data, so as to focus on the reasons for the occurrence of risks in the asset management process, establish corresponding attention indexes, and use the attention indexes as the scope for monitoring abnormal data. Then, perform clustering and splitting processing on the enterprise asset data according to the attention indexes. Cluster analysis is performed on the data through the attention indexes for abnormal monitoring and split to the smallest dimension to obtain abnormal data, which can automatically drill down the abnormal indexes to obtain abnormal data. Then, perform abnormal dimension positioning processing on the abnormal data. By analyzing the levels and correlations of each dimension where the risk or abnormality is located, the risk dimension is located. Finally, corresponding risk warning points are generated by analyzing the risk dimension, and risk push is performed based on the risk warning points. The relevant information is pushed to the target object, and the target object performs corresponding processing according to the risk information. The embodiments of the present application can analyze the levels and correlations of each dimension where the risk or abnormal data is located by setting attention indexes for the asset data and performing clustering, splitting, and dimension positioning on the asset data through the attention indexes. Finally, it is found that the risk gathers in a certain dimension, and a task is automatically pushed to the target object, thereby reducing the cost of manual processing, automatically helping the enterprise locate the source of the risk, and improving the efficiency of abnormal analysis of data.

[0082] In step S101 of some embodiments, obtain enterprise asset data, where the enterprise asset data includes index data under multiple preset indexes;

[0083] In the embodiments of the present application, enterprise asset data may include fixed - asset data and current - asset data. The fixed - asset data includes equipment such as production equipment, transportation equipment, office equipment, and their equipment data. The current - asset data includes cash, bank deposits, money - market funds, inventories, products, etc. The enterprise asset data also includes index data under multiple preset indexes. The preset indexes may include overdue rate, non - performing rate, credit - approval passing rate, rejection rate, duration, profit rate, etc., and the index data are the corresponding actual data. In the embodiments of the present application, the asset data can be digitally stored and managed through an asset - management system. By using web - crawler technology or data - embedding technology to obtain enterprise asset data for analysis, abnormal phenomena in asset use, such as frequent failures, over - use, insufficient maintenance, etc., can be discovered.

[0084] Please refer to Figure 2 , in step S102 of some embodiments, the risk - assessment processing of the index data to obtain the concerned indexes includes:

[0085] Step S201, inputting the index data into a neural - network model for evaluation processing to obtain risk data;

[0086] Step S202, screening the multiple preset indexes according to the risk data to obtain the concerned indexes.

[0087] In the embodiments of the present application, by performing risk assessment on the metric data through big data analysis and artificial intelligence algorithms or models, it is possible to focus on the reasons for possible risks or anomalies in the asset management process, and based on these risks or anomalies, corresponding attention metrics are established. The attention metrics can include one or more of the preset metrics. Finally, the enterprise asset data is monitored for anomalies through the attention metrics. It can be envisioned that the embodiments of the present application can also manually add key metrics for monitoring according to the actual situation. In the embodiments of the present application, multiple metrics can be established by analyzing the obtained enterprise asset data through relevant data such as the system's log files and user behavior data. First, data cleaning and data preprocessing are performed on the enterprise asset data. Data cleaning includes removing duplicate data, handling missing values, correcting incorrect data, etc. Data preprocessing includes data transformation, data normalization, etc. Performing data cleaning and data preprocessing on the enterprise asset data helps improve the quality and accuracy of the data, thereby providing a reliable basis for subsequent analysis. Then, the enterprise asset data is analyzed based on data mining-related models or algorithms. The analysis can be performed through statistical methods or machine learning-based methods. The statistical method is to calculate the maximum value, minimum value, mean value, standard deviation, etc. in the enterprise asset data, or to help identify outliers in the data through visualization tools such as box plots. Machine learning-based methods can include algorithms such as the Isolation Forest algorithm, K-Means clustering, and density-based clustering. Outliers are identified through the above methods, and corresponding preset metrics are established based on the outliers. Specifically, possible problems or abnormal behaviors in the data set can be identified according to information such as the number of abnormal points, the degree of abnormality, and the type of abnormality, and corresponding metric data is established.

[0088] In step S201 of some embodiments, the metric data is input into a neural network model for evaluation processing to obtain risk data.

[0089] In the embodiments of the present application, a pre-trained neural network model is used to perform risk assessment and prediction on metric data, and data that may have risks or anomalies is output. The neural network model can be a Transformer model, an LSTM model, a GPT-2 model, etc. Taking the Transformer model as an example, the Transformer model includes an encoder and a decoder. The training process of the neural network model includes: obtaining sample asset data, using a corresponding text tokenizer to split the text data in the sample asset data into tokens such as words and punctuation marks, and converting these tokens into digital indices so as to be converted into tensors for training. The processed data is divided into multiple small batches, each batch containing a certain number of samples, to obtain a training dataset. Then, the Transformer model is trained using the labeled training dataset. During the training process, the model will gradually learn to extract features and patterns from the input data, and update the weights of the model according to the gradient of the loss function. For time series data, anomalies can be detected by comparing the difference between the predicted value and the actual value. For example, a threshold can be set, and when the difference exceeds the threshold, the data point is considered abnormal. For text data, anomalies can be detected by analyzing the probability distribution of the model output or comparing it with the output of other models. The embodiments of the present application can also use the Adam optimizer for training and apply regularization strategies such as layer normalization and Dropout to reduce overfitting. After training is completed, the metric data is input into the neural network model for evaluation, and the neural network model will output a prediction result according to the learned features and patterns to obtain risk data.

[0090] In step S202 of some embodiments, the multiple preset metrics are screened according to the risk data to obtain the concerned metrics.

[0091] In the embodiments of the present application, the metric data obtained by analyzing through data mining techniques can be compared with the risk data predicted by the neural network model, and the final concerned metrics are screened from multiple preset metrics according to the comparison result. The comparison result can be the degree of risk, the degree of anomaly, etc. For example, the metrics with a higher degree of risk are screened from multiple preset metrics as the concerned metrics. In this way, data can be analyzed by combining data mining techniques and artificial intelligence techniques, and the concerned metrics can be obtained by focusing on the possible risk causes in the asset management process, and anomaly monitoring can be carried out through the concerned metrics.

[0092] One of the above technical solutions has the following advantages or beneficial effects: The embodiments of the present application perform risk assessment on enterprise asset data through data mining techniques and artificial intelligence techniques, can analyze the causes of risks or anomalies more comprehensively, thus better establish the corresponding concerned metrics, and can perform anomaly monitoring on the data through the concerned metrics, improving the discovery efficiency of abnormal data.

[0093] Please refer to Figure 3 , in step S103 of some embodiments, the clustering and splitting process of the enterprise asset data according to the concerned indicators to obtain abnormal data includes:

[0094] Step S301, perform feature tree construction processing on the enterprise asset data to obtain a clustering feature tree;

[0095] Step S302, perform node splitting processing on the clustering feature tree to obtain split data;

[0096] Step S303, perform screening processing on the split data according to the concerned indicators to obtain the abnormal data.

[0097] In the embodiments of the present application, by automatically performing clustering and splitting on enterprise asset data, clusters are formed downward for each indicator, and then the value of the indicator in each cluster after splitting is calculated according to the concerned indicators, and the data lower than the baseline benchmark or preset threshold is marked as abnormal data. It can be imagined that the embodiments of the present application can set a threshold for the concerned indicators, or use the data in the last 20% ratio of the concerned indicators as the abnormal baseline benchmark.

[0098] In step S301 of some embodiments, perform feature tree construction processing on the enterprise asset data to obtain a clustering feature tree.

[0099] In the embodiments of the present application, when performing feature extraction processing on enterprise asset data, corresponding feature data can be extracted based on modules such as convolutional layers, and then a clustering feature tree is constructed based on the feature data. In a feasible embodiment, the parameters of the clustering feature tree can be defined first, such as the maximum number of internal nodes, the maximum number of leaf nodes, the maximum sample radius threshold of leaf nodes, etc. Then the first sample point is read from the dataset as the root node, and the second sample point is continuously read, and then the distance between the second sample point and the first sample point is calculated. When the distance is within the maximum sample radius threshold, the second sample point and the first sample point are used as a combination. When the distance is outside the maximum sample radius threshold, the second sample point and the first sample point are grouped. It should be noted that the combined data cannot exceed the maximum number of internal nodes. When it exceeds the maximum number of internal nodes, the two farthest data in the combination are used as the seeds of the new leaf nodes, and the data in the combination are re-divided according to the distance into the leaf nodes. Similarly, when the number of leaf nodes exceeds the maximum number of leaf nodes, the data is divided and allocated according to the distance between the data.

[0100] In step S302 of some embodiments, perform node splitting processing on the clustering feature tree to obtain split data;

[0101] In the embodiments of the present application, node splitting is performed on the clustering feature tree, that is, the clustering feature tree is split and expanded from the root node. First, the first-layer node data is obtained, and the first-layer node data is used as the splitting data. When specific conditions are met, the splitting data is split and calculated again, and the second-layer node data is used as the splitting data, and so on.

[0102] In step S303 of some embodiments, the splitting data is screened according to the concerned metrics to obtain the abnormal data.

[0103] In the embodiments of the present application, the splitting data is screened according to the concerned metrics, and the data lower than the preset threshold or baseline is marked as abnormal data. It should be noted that the embodiments of the present application can also perform splitting processing on the abnormal data again until the abnormal data is split into the data with the smallest dimension, and the data with the smallest dimension is used as the abnormal data.

[0104] One of the above technical solutions has the following advantages or beneficial effects: In the embodiments of the present application, clustering and splitting processing is performed on enterprise asset data through concerned metrics, which can automatically execute analysis tasks through concerned metrics, can simulate the way of human thinking about problems, automatically drill down abnormal metrics, and thus obtain abnormal data.

[0105] Please refer to Figure 4 , in step S303 of some embodiments, the screening the splitting data according to the concerned metrics to obtain the abnormal data includes:

[0106] Step S401, performing metric calculation processing on the splitting data according to the concerned metrics, and screening the calculated metric data based on a preset threshold to obtain abnormal clusters;

[0107] Step S402, performing clustering analysis processing on the abnormal clusters, updating the splitting data according to the clustering analysis results, and returning to the step of performing metric calculation processing on the splitting data according to the concerned metrics until the abnormal clusters are data with the smallest dimension, and determining the abnormal clusters of the data with the smallest dimension as the abnormal data.

[0108] In the embodiments of the present application, the splitting data is screened according to the concerned metrics, the metric values of the splitting data are calculated through the concerned metrics. When the metric values exceed the preset threshold or baseline, the splitting data is used as abnormal data. And clustering analysis is performed on the abnormal data again, metric calculation is performed on the clustered data again, and the data exceeding the preset threshold or baseline is screened out, and the screening steps are repeated for recursive processing until the splitting data is split into the data with the smallest dimension, and this data is used as the abnormal data.

[0109] In step S401 of some embodiments, index calculation processing is performed on the split data according to the concerned index, and the calculated index data is screened based on a preset threshold to obtain an abnormal cluster.

[0110] In the embodiments of the present application, the concerned index is used to monitor data anomalies and can be the overdue rate, defect rate, credit approval pass rate, rejection rate, duration, profit rate, etc. The split data is the node data of the constructed clustering feature tree and can be the first-layer node data, second-layer node data, etc. Index values are obtained by performing index calculations on the node data, and the calculated index data is screened based on a preset threshold to obtain an abnormal cluster. In a feasible embodiment, for multiple batches of products, these products are used as the split data, the concerned index is selected as the defect rate, and the preset threshold of the defect rate is set to twenty percent. Among them, the defect rate refers to the proportion of products or services that do not meet the quality requirements within a certain period of time and is an important indicator for measuring product quality or service level. The lower the defect rate, the higher the product quality or service level. Controlling the defect rate is a necessary means for an enterprise to maintain competitiveness, which can effectively improve production efficiency and product quality and reduce the costs of later repairs and reworks. Index calculations are performed on these products according to the defect rate to obtain the defect rate values of each batch of products, and the products with a defect rate value higher than twenty percent are used as the abnormal cluster.

[0111] In step S402 of some embodiments, clustering analysis processing is performed on the abnormal cluster, the split data is updated according to the clustering analysis result, and the process returns to the step of performing index calculation processing on the split data according to the concerned index until the abnormal cluster is the minimum-dimension data, and the abnormal cluster of the minimum-dimension data is determined as the abnormal data.

[0112] In the embodiments of the present application, clustering analysis processing is performed on the abnormal cluster. By performing clustering analysis on the data again, deeper-dimension data can be obtained. Then, according to the clustering analysis result, i.e., the clustering data, the split data is updated, and the clustered data is used as the new split data. Then, the process returns to the step of performing index calculation on the split data according to the concerned index, i.e., returns to step S401, performs index calculation on the data for which clustering analysis is performed again, and screens to obtain an abnormal cluster. By continuously performing the above steps until the abnormal cluster is the minimum-dimension data, i.e., the data cannot be split anymore, this abnormal cluster is determined as the abnormal data. In a feasible embodiment, the products with a defect rate value higher than twenty percent are used as the abnormal cluster, clustering analysis is performed on this abnormal cluster, the component or module data of the product is analyzed, the module data is screened according to the corresponding concerned index to obtain an abnormal cluster, and then clustering analysis is performed on the abnormal cluster again until the abnormal cluster is split into the minimum-dimension data, i.e., the minimum subunit data of the product.

[0113] One of the above technical solutions has the following advantages or beneficial effects: In the embodiment of the present application, by screening and processing the split data through the attention indicators to obtain abnormal data, it is possible to accurately measure the normal range and abnormal range of the data by setting clear attention indicators, thereby accurately identifying the abnormal data, improving the quality of the overall data, and providing a more accurate and reliable basis for subsequent data analysis and decision-making.

[0114] Please refer to Figure 5 , in step S104 of some embodiments, the abnormal dimension positioning process for the abnormal data to obtain the risk dimension includes:

[0115] Step S501, analyzing and processing the dimension attributes of the abnormal data to obtain the data dimension;

[0116] Step S502, performing interval positioning processing on the abnormal data according to the data dimension to obtain the risk dimension.

[0117] In the embodiment of the present application, by performing abnormal dimension positioning on the abnormal data, it is possible to analyze the dimension attributes of the abnormal data, locate the subdivision dimension where the abnormality occurs, and obtain the risk dimension. Among them, the abnormal data is the data obtained by clustering and splitting the enterprise asset data through the attention indicators, that is, the data in the enterprise asset data that may have risks or abnormalities. Dimension refers to the characteristics used to describe a complex system or data. For example, in data analysis, multiple dimensions are usually used to describe a data set, such as time, location, age, gender, etc., and these dimensions help to reveal the hidden patterns and associations in the data set. The risk dimension refers to that there may be abnormalities or risks in this dimension, that is, in which aspect or level there is a problem.

[0118] In step S501 of some embodiments, the dimension attributes of the abnormal data are analyzed and processed to obtain the data dimension.

[0119] In the embodiments of the present application, dimensional attribute analysis is performed on data that may have anomalies or risks. By decomposing the abnormal data into different dimensions and then evaluating different dimensions separately. Specifically, the dimensions can be divided into qualitative dimensions and quantitative dimensions, that is, divided according to the data type. If the data type is character (text) data, it is a qualitative dimension, such as region and gender are qualitative dimensions; if the data type is numerical data, it is a quantitative dimension, such as income, age, consumption, etc. Generally, numerical grouping processing needs to be done for quantitative dimensions, that is, discretization of numerical data. The purpose of doing this is to make the rules more obvious. In the embodiments of the present application, by performing multi-dimensional decomposition processing on abnormal data, it can be decomposed from the index composition to analyze the composition of a single index. For example, a single index is a user, and a user can be decomposed into new users and old users. It can also be decomposed from the business process: disassemble and analyze according to the business process, such as the user payment rate of different channels.

[0120] In step S502 of some embodiments, interval positioning processing is performed on the abnormal data according to the data dimension to obtain the risk dimension.

[0121] In the embodiments of the present application, interval positioning is performed on the abnormal data through multiple data dimensions obtained by splitting the abnormal data in the above steps, so as to determine the dimensions that may have risks or anomalies. In the embodiments of the present application, key data dimensions such as time, region, user type, product category, etc. can be selected from the data dimensions according to business requirements and data analysis objectives, ensuring that the selected dimensions can comprehensively cover the business scenario and help identify abnormal data. Then, reasonable interval thresholds are set according to the distribution of the abnormal data and business requirements. These thresholds can be determined based on the statistical characteristics of the data, such as mean, plus or minus standard deviation, business rules, or expert experience. According to the cause and concentration interval of the abnormal data, the risk dimension is determined. The risk dimension can be one or more, specifically depending on the complexity of the abnormal data and the diversity of business requirements.

[0122] One of the technical solutions in the above technical solutions has the following advantages or beneficial effects: In the embodiments of the present application, by performing abnormal dimension positioning processing on abnormal data to obtain the risk dimension, it is possible to analyze the hierarchical levels and associations of risks in each dimension, and finally find that the risks gather in a certain dimension. It is also possible to perform data monitoring and result feedback according to the risk dimension, continuously optimize and improve the data analysis method and risk response strategy, which helps enterprises timely identify and manage potential risks, and ensure the stable operation and sustainable development of the business.

[0123] Please refer to Figure 6 In step S502 of some embodiments, the interval positioning processing of the abnormal data according to the data dimension to obtain the risk dimension includes:

[0124] Step S601: Construct a dimensional space according to the data dimensions;

[0125] Step S602: Perform weighted statistical processing on the abnormal data according to the dimensional space to obtain the risk dimension.

[0126] In the embodiment of the present application, by performing interval positioning processing on abnormal data according to data dimensions to obtain a risk dimension, a corresponding dimensional space can be constructed based on the data dimensions analyzed from the abnormal data, so as to perform weighted statistics on the abnormal data according to the dimensional space, and thus determine the risk dimension of the abnormal data according to the statistical results.

[0127] In step S601 of some embodiments, a dimensional space is constructed according to the data dimensions.

[0128] In the embodiment of the present application, it is first necessary to clarify the goal of constructing the dimensional space. By clarifying the goal, it helps to guide the subsequent data dimension selection and dimensional space construction process. In the embodiment of the present application, according to business requirements and data characteristics, data dimensions that have an important impact on business analysis are selected. These dimensions may include time, region, user behavior, product attributes, etc. Some dimensions may have a hierarchical structure, such as geographical location (country-province-city) or product classification (major category-middle category-minor category). When constructing the dimensional space, these hierarchical structures need to be fully considered. Then, the main data source is selected as the main dimension table. Usually, these tables contain the most detailed and comprehensive dimension information. According to business logic and data relationships, other relevant tables are associated with the main dimension table to form a complete dimension system. These relevant tables may contain additional dimension attributes or business rules. Finally, the dimensional space structure is defined according to the dimension table: according to the selected dimensions and dimension attributes, the structure of the dimensional space is defined. In the embodiment of the present application, by determining the association relationships between dimensions, the hierarchical structures between attributes, and the value ranges of attribute values, the dimensional space is constructed, which can be implemented through tools such as data warehouses, data lakes, or data marts.

[0129] In step S602 of some embodiments, weighted statistical processing is performed on the abnormal data according to the dimensional space to obtain the risk dimension.

[0130] In the embodiments of the present application, weighted statistical processing is performed on abnormal data through a dimensional space. Specifically, weighted statistics are performed on the sub - dimensions where abnormal data occurs, and sorted by metrics to determine the dimensions where abnormalities occur. In a feasible embodiment, a suitable weighting method is selected according to business requirements and data characteristics. Common weighting methods include frequency - based weighting, importance - based weighting, distance - based weighting, etc. According to the selected weighting method, the weight distribution of each dimension in the dimensional space is determined, which can be achieved through methods such as expert scoring, data analysis, or machine learning algorithms, and can be sorted by corresponding metrics. The top five dimensions are selected as risk dimensions, and the number of selected dimensions can be adjusted or set according to actual situations.

[0131] One of the technical solutions in the above - mentioned technical solutions has the following advantages or beneficial effects: In the embodiments of the present application, interval positioning processing is performed on abnormal data according to data dimensions to obtain risk dimensions, which can more accurately locate the dimensions where corresponding risks occur. This helps enterprises better understand and evaluate business risks, improves the ability of risk management and decision - making support, and improves the efficiency of data analysis.

[0132] Please refer to Figure 7 , in step S105 of some embodiments, the risk push based on the risk warning point includes:

[0133] Step S701, generating abnormal information according to the risk warning point, and inputting the abnormal information into a language model to generate a warning message;

[0134] Step S702, pushing the warning message to the target object for risk processing.

[0135] In the embodiments of the present application, there are various implementation methods for risk push based on risk warning points. An improvement to - do for abnormalities can be generated through risk warning points. For the target object, a special implementation plan is formulated for the abnormal dimension, and the implementation of this improvement plan is monitored. The target object is the indicator responsible person or the corresponding operation and maintenance processing personnel. The push method can be SMS notification, email notification, etc., which is not limited here.

[0136] In step S701 of some embodiments, abnormal information is generated according to the risk warning point, and the abnormal information is input into a language model to generate a warning message.

[0137] In the embodiments of the present application, abnormal information can be generated according to the risk warning point. The abnormal information includes abnormal data and its corresponding dimensional attributes, etc., and the abnormal information is input into a language model for completion or modification to regenerate a warning message. The language model can adopt an LSTM model or a GPT - 2 model, etc.

[0138] In step S702 of some embodiments, the warning information is pushed to the target object for risk handling.

[0139] In the embodiments of the present application, when pushing the warning information to the target object for risk handling, different push processes can be performed according to the level or urgency of the warning information. For example, when the urgency is relatively low, it can be notified by text message or social media, and when the urgency is relatively high, it can be notified by phone call, etc. The push frequency can also be set according to the duration of the warning information and risk changes.

[0140] One of the technical solutions in the above technical solutions has the following advantages or beneficial effects: By combining the language model to generate warning information, the embodiments of the present application can modify or rewrite the information based on the language model to generate more understandable content, making the content concise and clear, and improving the efficiency of data processing.

[0141] Next, combined with specific application examples, the solutions of the embodiments of the present application will be introduced and described in detail:

[0142] The embodiments of the present application can be applied to the field of data analysis technology, are applicable to the financial field, and are specifically applied to the scenario of analyzing asset data. For example, monitoring product data in asset data, performing anomaly analysis on financial data, and conducting risk assessment on financial data through the system. The system can be used for applying for loans, credit cards, or purchasing insurance, financial products, etc. The system can also be an insurance system, a bank system, a trading system, or an order system. By adding attention indicators for anomaly monitoring, clustering and splitting the data through the attention indicators, and discovering the crossing of the line, and performing recursion step by step, the embodiments of the present application analyze the hierarchical levels and associations of risks in each dimension, and finally find that the risks gather in a certain dimension, and automatically push tasks to the asset manager, releasing a large amount of manpower of the planning analysts, automatically helping the enterprise locate the source of the risks, and improving the efficiency of data analysis.

[0143] Please refer to Figure 8 , the embodiments of the present application also provide a data analysis device that can implement the above data analysis method. The device includes:

[0144] The first module 801 is used to obtain enterprise asset data, and the enterprise asset data includes index data under multiple preset indexes;

[0145] The second module 802 is used to perform risk assessment processing on the index data to obtain attention indicators;

[0146] The third module 803 is used to perform clustering and splitting processing on the enterprise asset data according to the attention indicators to obtain abnormal data;

[0147] The fourth module 804 is configured to perform abnormal dimension location processing on the abnormal data to obtain risk dimensions;

[0148] The fifth module 805 is configured to generate risk warning points according to the risk dimensions and perform risk push based on the risk warning points.

[0149] It can be understood that the content in the above method embodiments is applicable to the device embodiments. The functions specifically implemented by the device embodiments are the same as those in the above method embodiments, and the beneficial effects achieved are also the same as those in the above method embodiments.

[0150] The embodiment of the present application further provides an electronic device. The electronic device includes a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, the above data processing method is implemented. The electronic device can be any intelligent terminal including a tablet computer, an in-vehicle computer, etc.

[0151] Please refer to Figure 9 , Figure 9 , which schematically shows the hardware structure of an electronic device in another embodiment. The electronic device includes:

[0152] A processor 901, which can be implemented in a general-purpose CPU (Central Processing Unit), a microprocessor, an application-specific integrated circuit (ASIC), or one or more integrated circuits, etc., and is configured to execute relevant programs to implement the technical solutions provided by the embodiments of the present application;

[0153] A memory 902, which can be implemented in the form of a read-only memory (ROM), a static storage device, a dynamic storage device, or a random access memory (RAM), etc. The memory 902 can store an operating system and other application programs. When implementing the technical solutions provided by the embodiments of this specification through software or firmware, the relevant program codes are stored in the memory 902 and are called by the processor 901 to execute a data analysis method of the embodiments of the present application;

[0154] An input / output interface 903, which is used to implement information input and output;

[0155] A communication interface 904, which is used to implement communication interaction between this device and other devices, and can implement communication through a wired method (such as USB, network cable, etc.) or through a wireless method (such as mobile network, WIFI, Bluetooth, etc.);

[0156] The bus 905 transmits information between various components of the device (such as the processor 901, the memory 902, the input / output interface 903, and the communication interface 904).

[0157] Among them, the processor 901, the memory 902, the input / output interface 903, and the communication interface 904 achieve communication connections with each other inside the device through the bus 905.

[0158] The embodiment of the present application also provides a computer-readable storage medium, which stores a computer program. When the computer program is executed by a processor, the above-mentioned data analysis method is implemented.

[0159] As a non-transitory computer-readable storage medium, the memory can be used to store non-transitory software programs and non-transitory computer-executable programs. In addition, the memory may include high-speed random access memory, and may also include non-transitory memory, such as at least one magnetic disk storage device, a flash memory device, or other non-transitory solid-state storage devices. In some embodiments, the memory may optionally include a memory remotely set relative to the processor, and these remote memories can be connected to the processor through a network. Examples of the above networks include, but are not limited to, the Internet, an enterprise intranet, a local area network, a mobile communication network, and combinations thereof.

[0160] A data analysis method, device, electronic device, and storage medium provided by the embodiment of the present application can obtain enterprise asset data, perform risk assessment processing on the enterprise asset data to obtain attention indicators, and can determine attention indicators by focusing on the causes of risk occurrence in asset management, so as to better monitor asset data through the attention indicators. In addition, the solution performs clustering and splitting processing on the enterprise asset data according to the attention indicators to obtain abnormal data, performs abnormal dimension positioning processing on the abnormal data to obtain risk dimensions, generates risk warning points according to the risk dimensions, and performs risk push based on the risk warning points. This solution can automatically locate the source of risk by performing down-probing and dimension analysis on abnormal data to locate the dimension where the problem occurs, improving the data analysis efficiency and enhancing the management ability of asset data.

[0161] The embodiments described in the embodiments of the present application are for more clearly illustrating the technical solutions of the embodiments of the present application, and do not constitute a limitation on the technical solutions provided by the embodiments of the present application. Those skilled in the art know that with the evolution of technology and the emergence of new application scenarios, the technical solutions provided by the embodiments of the present application are equally applicable to similar technical problems.

[0162] Those skilled in the art can understand that the technical solutions shown in the figures do not constitute a limitation on the embodiments of the present application, and may include more or fewer steps than those shown in the figures, or combine certain steps, or different steps.

[0163] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separated, that is, they may be located in one place or distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0164] Those of ordinary skill in the art can understand that all or some of the steps in the methods disclosed above, and the functional modules / units in the systems and devices, can be implemented as software, firmware, hardware, and appropriate combinations thereof.

[0165] In the specification of this application and the above-mentioned drawings, the terms "first", "second", "third", "fourth", etc. (if any) are used to distinguish similar objects and do not necessarily describe a specific order or sequence. It should be understood that the data used in this way can be interchanged under appropriate circumstances so that the embodiments of this application described here can be implemented in an order other than those illustrated or described here. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or device that includes a series of steps or units does not necessarily limit to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products, or devices.

[0166] It should be understood that in this application, "at least one (item)" means one or more, and "a plurality" means two or more. "And / or" is used to describe the association relationship of associated objects and indicates that three relationships can exist. For example, "A and / or B" can mean: only A exists, only B exists, and both A and B exist at the same time. Among them, A and B can be singular or plural. The character " / " generally means that the associated objects before and after are in an "or" relationship. "At least one (one) of the following" or a similar expression refers to any combination of these items, including any combination of single item (one) or plural items (ones). For example, at least one (one) of a, b, or c can mean: a, b, c, "a and b", "a and c", "b and c", or "a and b and c", where a, b, c can be single or multiple.

[0167] In several embodiments provided in the present application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the above division of units is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed couplings or direct couplings or communication connections to each other can be through some interfaces. The indirect couplings or communication connections of devices or units can be in electrical, mechanical or other forms.

[0168] The units described above as separate components may or may not be physically separated. The components displayed as units may or may not be physical units, that is, they can be located in one place, or they can be distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0169] In addition, in each embodiment of the present application, each functional unit can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit. The above integrated unit can be implemented in the form of hardware or in the form of a software functional unit.

[0170] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, or all or part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes multiple instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods in each embodiment of the present application. And the aforementioned storage medium includes: various media that can store programs such as USB flash drives, mobile hard disks, read-only memory (ROM for short), random access memory (RAM for short), magnetic disks, or optical discs.

[0171] The preferred embodiments of the embodiments of the present application have been described above with reference to the accompanying drawings, but this does not limit the scope of the rights of the embodiments of the present application. Any modifications, equivalent replacements, and improvements made by those skilled in the art without departing from the scope and essence of the embodiments of the present application shall be within the scope of the rights of the embodiments of the present application.

Claims

1. A data analysis method, characterized in that: The method comprises: Acquire enterprise asset data, wherein the enterprise asset data includes indicator data under a plurality of preset indicators; Performing risk assessment processing on the indicator data to obtain the indicator of concern; Performing clustering and splitting processing on the enterprise asset data according to the focus index to obtain abnormal data; Performing abnormal dimension location processing on the abnormal data to obtain a risk dimension; Risk warning points are generated according to the risk dimensions, and risk push is performed based on the risk warning points.

2. The method according to claim 1, characterized in that The risk assessment process is performed on the indicator data to obtain the concerned indicators, including: Inputting the indicator data into a neural network model for evaluation and processing to obtain risk data; The plurality of preset indicators are screened according to the risk data to obtain the focus indicator.

3. The method according to claim 1, characterized in that The clustering and splitting processing of the enterprise asset data according to the focus index to obtain abnormal data includes: Performing feature tree construction processing on the enterprise asset data to obtain a cluster feature tree; Performing node splitting processing on the cluster feature tree to obtain split data; The split data is screened and processed according to the focus index to obtain the abnormal data.

4. The method according to claim 3, characterized in that The screening and processing of the split data according to the focus index to obtain the abnormal data includes: Performing an indicator calculation process on the split data according to the focus indicator, and screening the calculated indicator data based on a preset threshold to obtain an abnormal cluster; Perform cluster analysis on the abnormal cluster, update the split data according to the cluster analysis result, and return to the step of performing indicator calculation on the split data according to the focus indicator until the abnormal cluster is the minimum dimensional data, and determine the abnormal cluster of the minimum dimensional data as the abnormal data.

5. The method according to claim 1, characterized in that The performing abnormal dimension location processing on the abnormal data to obtain the risk dimension includes: Analyze and process the dimension attributes of the abnormal data to obtain data dimensions; The abnormal data is interval-located according to the data dimension to obtain the risk dimension.

6. The method according to claim 5, characterized in that The performing interval positioning processing on the abnormal data according to the data dimension to obtain the risk dimension includes: Constructing a dimensional space according to the data dimensions; The abnormal data is subjected to weighted statistical processing according to the dimensional space to obtain the risk dimension.

7. The method according to any one of claims 1 to 6, characterized in that: The risk push based on risk warning points includes: Generate abnormal information according to the risk warning point, and input the abnormal information into a language model to generate warning information; The warning information is pushed to the target object for risk management.

8. A data analysis device, characterized in that: The device comprises: The first module is used to obtain enterprise asset data, wherein the enterprise asset data includes indicator data under multiple preset indicators; The second module is used to perform risk assessment processing on the indicator data to obtain the indicator of concern; The third module is used to perform clustering and splitting processing on the enterprise asset data according to the focus index to obtain abnormal data; The fourth module is used to perform abnormal dimension location processing on the abnormal data to obtain a risk dimension; The fifth module is used to generate risk warning points according to the risk dimensions and push risks based on the risk warning points.

9. An electronic device, characterized in that: The electronic device comprises a memory and a processor, the memory stores a computer program, and the processor implements the data analysis method according to any one of claims 1 to 7 when executing the computer program.

10. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by a processor, the data analysis method according to any one of claims 1 to 7 is implemented.