Fraud phone recognition method based on machine learning

Through the machine learning-based fraud phone recognition method, combined with the multimodal fusion layer and online learning mechanism, the problem of insufficient fraud phone recognition capabilities in the existing technology is solved, efficient and intelligent fraud phone recognition and protection is achieved, and users' property safety is significantly improved.

CN120091313APending Publication Date: 2025-06-03HEFEI IFLY DIGITAL TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510143440.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-10
Publication Date
2025-06-03

AI Technical Summary

Technical Problem

When preventing telecommunications fraud in the prior art, the blacklist filtering and keyword detection mechanisms have problems such as reduced effectiveness, high false alarm rate, and insufficient recognition ability of new fraud methods.

Method used

Using a fraudulent phone recognition method based on machine learning, a multi-modal fusion layer machine learning model is established by acquiring and preprocessing communication data, combining online learning and user feedback mechanisms to classify and predict call data in real time and take protective measures.

Benefits of technology

It realizes efficient and intelligent identification of new types of fraudulent phone calls, reduces false alarms and missed reports, adapts to the continuous evolution of fraud strategies, provides personalized protection strategies, and significantly improves the safety of users' property.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120091313A_ABST
    Figure CN120091313A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of information communication security, in particular to a fraud phone recognition method based on machine learning, and the method specifically comprises the steps: S1, obtaining communication data, and carrying out the preprocessing of the communication data; s2, establishing a machine learning model through the preprocessed communication data; and S3, performing real-time classification prediction on the real-time call data according to the machine learning model, and performing corresponding protection according to a real-time classification prediction result. According to the method, the call data flow is quickly obtained through the real-time communication interface and is subjected to preprocessing and feature extraction in time, and meanwhile, through an online learning strategy, the call can be quickly classified and predicted, and protective measures are taken in time, so that the risk that a user is defrauded is reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of information communication security technology, and in particular to a fraudulent call identification method based on machine learning. Background Art

[0002] With the rapid development of mobile Internet and communication technology, telephone services have become an indispensable part of people's daily lives, but at the same time they have also provided a new breeding ground for fraudulent activities. In recent years, the number of telecommunications and Internet fraud cases has risen sharply, and the means of fraud have been constantly updated, from traditional impersonation of public security, procuratorial and judicial organs, and lottery fraud, to phishing and fake customer service implemented using new technologies, which have seriously infringed on the public's property safety and social credit system. According to the report "Lianshan Public Security: Combating and Controlling Telecommunications and Internet Fraud, and Making All-out Efforts to Protect the Property Safety of the People", telecommunications and Internet fraud has become an important type of crime that endangers property safety in the new era, and traditional preventive measures face severe challenges.

[0003] Currently, most telecommunications fraud prevention technologies are based on blacklist filtering and keyword detection mechanisms. The blacklist database contains known fraud numbers and blocks them from accessing user terminals by comparing the incoming call numbers. However, the effectiveness of the blacklist is greatly reduced because fraudsters frequently change their numbers or use VoIP technology to disguise the caller ID. Keyword matching technology attempts to trigger an alarm by identifying specific fraud words in calls, but this method is prone to false alarms and can be easily circumvented by fraudsters, especially when faced with carefully designed scripts and personalized fraud strategies, and the recognition accuracy is low.

[0004] In addition, existing technologies often ignore the comprehensive analysis of complex information such as call behavior patterns, voice features, and conversation context, resulting in weak recognition of new and variant fraud methods. "2022 Civil Servant Essay Exam Hot Topics: Telecom Fraud Control" (Gongzhuling Huatu-Jilin Huatu Education Network, February 7, 2022) pointed out that the communications industry also has deficiencies in personal information protection and laws and regulations, further exacerbating the difficulty of telecommunications fraud control.

[0005] To sum up, given the limitations of existing preventive measures and their inadequacies in addressing the trend of diversification and intelligence of fraud methods, it is particularly urgent to develop a technical solution that can efficiently and intelligently identify and defend against new types of fraud calls. Summary of the invention

[0006] The purpose of the present invention is to provide a fraudulent call identification method based on machine learning to solve the problems raised in the above background technology.

[0007] The technical solution of the present invention is: a fraudulent call identification method based on machine learning, the fraudulent call identification method specifically comprises: S1: Obtain communication data and preprocess the communication data; S2: Establish a machine learning model based on the preprocessed communication data; S3: Perform real-time classification prediction on real-time call data according to the machine learning model, and perform corresponding protection according to the results of the real-time classification prediction.

[0008] Furthermore, the establishment of the machine learning model is specifically as follows: S2.1: Perform interactive learning on the preprocessed communication data to construct a multi-modal fusion layer; S2.2: Construct a primary machine learning model through the multi-modal fusion layer; S2.3: Perform real-time optimization on the primary machine learning model; S2.4: Establish a user feedback mechanism, obtain new communication data, and repeat steps S2.3 - S2.4.

[0009] Furthermore, the construction of the multi-modal fusion layer is specifically as follows: S2.1.1: Extract features from the preprocessed communication data and construct a feature matrix; S2.1.2: Obtain an attention weight matrix through attention weights, specifically:

[0010] Where: is the attention weight, is the attention weight matrix, is the feature matrix, is the specific weight of the attention layer, is the bias of the attention layer; S2.1.3: Obtain weighted features through the feature matrix and the attention weight matrix, specifically:

[0011] Where: is the weighted feature, is the attention weight matrix, is the feature matrix.

[0012] Furthermore, the construction of the primary machine learning model is specifically as follows: S2.2.1: Construct a preset number of different basic machine learning models according to the preprocessed communication data and the weighted features; S2.2.2: Evaluate the model performance of a preset number of different basic machine learning models, and determine the basic machine learning model with the optimal model performance from them. The basic machine learning model with the optimal model performance is the constructed primary machine learning model.

[0013] Furthermore, perform real-time optimization on the primary machine learning model as follows: S2.3.1: Perform online learning and incremental update to obtain the initial parameters of the primary machine learning model; S2.3.2: Through the initial parameters of the primary machine learning model, obtain an adaptive learning rate and dynamically adjust the primary machine learning model. The adaptive learning rate is specifically:

[0014] Where: is the first-order moment estimate corresponding to the moment, is the momentum decay fraction corresponding to the first-order moment, is the first-order moment estimate corresponding to the moment, is the decay factor corresponding to the first-order moment, is the gradient corresponding to the moment, is the second-order moment estimate corresponding to the moment, is the momentum decay fraction corresponding to the second-order moment, is the second-order moment estimate corresponding to the moment, is the decay factor corresponding to the second-order moment, is the first-order moment after regularization, is the decay factor of the first-order moment corresponding to the moment, is the second-order moment after regularization, is the actual learning rate corresponding to the moment, is the initial learning rate,

[0015] Furthermore, obtain the initial parameters of the primary machine learning model as follows: S2.3.1.1: Set the initial parameters of the primary machine learning model and obtain the gradient of the loss function corresponding to the communication data after interactive learning, specifically:

[0016] Where: is the gradient of the loss function corresponding to the communication data after interactive learning, is the true label corresponding to the communication data after interactive learning, is the model parameter vector, is the feature vector corresponding to the communication data after interactive learning; S2.3.1.2: Adjust the initial parameters of the primary machine learning model according to the gradient of the loss function corresponding to the communication data after interactive learning, specifically:

[0017] where: is the initial parameter of the updated primary machine learning model, is the initial parameter of the primary machine learning model before update, is the learning rate, is the gradient of the loss function corresponding to the communication data after interactive learning; S2.3.1.3: Repeat steps S2.3.1.1 - S2.3.1.3 until the initial parameters of the primary machine learning model corresponding to each communication data after interactive learning are obtained.

[0018] Furthermore, obtain new communication data, specifically as follows: S2.4.1: Collect and classify the user feedback data, specifically:

[0019] where: is the automatic classification result, is the user feedback, is the natural language processing function; S2.4.2: Verify and mark the classified and integrated user feedback data, and the verified and marked user feedback data is the new communication data.

[0020] Furthermore, verify and mark the classified and integrated user feedback data, specifically as follows: S2.4.2.1: Verify and identify the classified and integrated user feedback data, specifically:

[0021] where: is the verification result, is the feedback, is the historical data, is the mode; S2.4.2.2: Have the user give feedback on the verification result, specifically:

[0022] Wherein: is the final data quality, is the quality of the original input data, is the adjustment coefficient, is the contribution of user feedback; S2.4.2.3: Compare the feedback result with a preset threshold, specifically: When the feedback result is greater than the preset threshold, mark the data corresponding to the feedback result; otherwise, do not mark the data corresponding to the feedback result.

[0023] Furthermore, perform real-time classification prediction on the real-time call data, specifically as follows: S3.1: Obtain and preprocess the real-time call data stream through a real-time communication interface; S3.2: Extract features from the preprocessed real-time call data stream, specifically:

[0024] Wherein: is the audio feature, is the audio sample point, is the dynamic window function, is the total number of sampling points, is the coefficient index sub-bandwidth, is the sampling point index sub-; S3.3: Use the extracted features as the input of a machine learning model to perform real-time prediction on the real-time call data.

[0025] Furthermore, extract features from the preprocessed real-time call data stream, specifically as follows: S3.2.1: Dynamically adjust the length of the window function according to the signal-to-noise ratio in the real-time call data stream, specifically:

[0026] Wherein: is the total number of sampling points, is the basic window length, is the control reduction rate, is the signal power, is the noise power, is the threshold; S3.2.2: Frame the preprocessed real-time call data stream at time intervals, and superimpose two adjacent framed real-time call data streams, specifically:

[0027] Wherein: is the frequency coefficient of the new frame after overlapping, is the frequency coefficient corresponding to the th frame, is the frequency coefficient corresponding to the th frame.

[0028] The present invention provides a method and a system for identifying fraudulent calls based on machine learning by making improvements. Compared with the prior art, the following improvements and advantages are achieved: First: The present invention can quickly obtain the call data stream through the real-time communication interface and immediately perform preprocessing and feature extraction. At the same time, through the online learning strategy, it can quickly classify and predict calls and take protective measures in a timely manner, thereby reducing the risk of users being defrauded; Second: The present invention combines various information such as voice, call behavior, number features, text messages, and social media through multi-modal fusion technology, improving the comprehensiveness of features. At the same time, the deep learning model and advanced architecture can capture complex patterns, thereby improving the accuracy of identifying fraudulent calls and reducing false positives and false negatives; Third: The present invention enables the model to continuously learn from new data and adapt to the continuous evolution of fraud strategies through the online learning and incremental update mechanism, quickly respond to new fraud methods, and maintain the effectiveness of the identification system; Fourth: Through the user feedback mechanism, the present invention can collect the false positive or false negative situations marked by users. At the same time, combined with the personal communication behavior of users, it can continuously optimize the model, provide a more personalized protection strategy, and reduce the interference with normal calls. BRIEF DESCRIPTION OF THE DRAWINGS

[0029] The present invention will be further explained below with reference to the drawings and embodiments: Figure 1 is a schematic flowchart of the method for identifying fraudulent calls of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0030] The technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0031] It should be noted that in the description of the present invention, the orientation or positional relationship indicated by the terms "upper", "lower", "front", "rear", "left", "right", "vertical", "horizontal", "top", "bottom", "inner", "outer", etc. is based on the orientation or positional relationship shown in the drawings. It is only for the convenience of describing the present invention and simplifying the description, and does not indicate or imply that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation. Therefore, it should not be construed as a limitation to the present invention.

[0032] In addition, it should be understood that for the convenience of description, the sizes of the various components shown in the drawings are not drawn in actual proportional relationships. For example, the thickness or width of some layers may be exaggerated relative to other layers.

[0033] It should be noted that similar reference numerals and letters represent similar items in the following drawings. Therefore, once an item is defined or described in one drawing, it will not be necessary to further discuss and describe it specifically in the description of subsequent drawings.

[0034] Referring to Figure 1 , this embodiment provides a method for identifying fraudulent calls based on machine learning. The method for identifying fraudulent calls specifically includes the following steps: Step S1: Collect relevant communication data, and preprocess the collected communication data to extract features related to fraudulent behavior. Specifically, the communication data in this embodiment includes, but is not limited to, call audio, call time, call frequency, incoming call number features, text message data, and social media interaction data. Further, through the communication system interface or third-party API, call audio is recorded in real time or regularly and encrypted for storage to ensure data security and privacy protection. At the same time, text message records and social media interaction data (such as WeChat, WhatsApp messages) related to the call number are collected, and communication content, sending frequency, interaction patterns, etc. are analyzed to fully obtain more fraudulent behavior patterns and improve the accuracy and comprehensiveness of the communication data.

[0035] Similarly, when preprocessing the collected communication data, the aim is to extract key information from the original communication data that helps the machine learning model established in the subsequent steps to identify fraud, including but not limited to voice features, call behavior patterns, and abnormal number usage habits. In this embodiment, the preprocessing of the communication data mainly includes data fusion, data standardization, and quality inspection and filtering. It should be noted that this preprocessing is a conventional data processing in the prior art, so it will not be specifically described in this embodiment, and only a general description of voice features, call behavior patterns, abnormal number usage habits, text messages, and social media will be given.

[0036] Among them, the extraction of voice features includes audio conversion and segmentation, noise reduction and clarification, and feature extraction. Specifically: Audio conversion and segmentation: Convert the call audio into a format suitable for analysis (such as.wav), and segment it into small segments according to time periods for subsequent processing.

[0037] Noise reduction and clarification: Apply digital signal processing techniques (such as wavelet transform, spectral subtraction) to remove background noise to improve the voice quality.

[0038] Feature extraction: Use voice processing techniques to extract features such as MFCCs and spectrograms, and analyze the emotional color (such as tension, urgency), speech rate, pitch change, etc. of the voice.

[0039] Analysis of call behavior patterns includes call duration statistics, call interval analysis, and time period distribution. Specifically: Call duration statistics: Calculate the duration of each call and analyze the call duration distribution to identify abnormal call duration patterns.

[0040] Call interval analysis: Record the interval time between adjacent calls and identify call patterns with abnormal frequency or regular anomalies.

[0041] Time period distribution: Analyze the time period distribution of calls and mark the high-incidence time periods of fraud calls.

[0042] Identification of abnormal usage habits of numbers includes number feature analysis and behavior pattern learning. Specifically: Number feature analysis: Use the database to compare the incoming call numbers to identify known fraud number segments, virtual number features, abnormal use of international long-distance calls, etc.

[0043] Behavior pattern learning: Identify abnormal usage habits of numbers through historical data analysis, such as frequently changing numbers to make calls, making a large number of calls within a short period, etc.

[0044] Feature extraction of text messages and social media includes text content analysis and interaction pattern recognition. Specifically: Text content analysis: Convert text messages and social media texts into structured data, and use NLP techniques to extract features such as keywords, sentiment tendencies, and links.

[0045] Interaction pattern recognition: Analyze the time interval, frequency, and content similarity of message sending and receiving to identify potential fraud induction or urgent urging patterns.

[0046] Step S2: Establish a machine learning model through the preprocessed communication data in Step S1. Specifically as follows: Step S2.1: Construct a multi-modal fusion layer to perform interactive learning on the preprocessed communication data in Step S1. Specifically as follows: Step S2.1.1: Construct a feature matrix from the preprocessed communication data in Step S1. Specifically, for the speech feature X_speech, call behavior feature X_behavior, and social feature X_social in the preprocessed communication data in Step S1, these three feature matrices can be merged through a vertical stacking operation to form a new feature matrix, specifically: X_fused = concatenate([X_speech, X_behavior, X_social]) Step S2.1.2: Determine an advanced architecture in the deep learning model based on the feature matrix X_fused obtained in Step S2.1.1. That is, for the feature matrix X_fused obtained in Step S2.1.1, deep learning architectures such as Transformer, Graph Neural Network (GNN), etc. can be selected. It should be noted that specific selection can be made according to the actual situation of the data, so there are no clear specific requirements.

[0047] Meanwhile, obtain an attention weight matrix through attention weights, specifically:

[0048] Where: is the attention weight, is the attention weight matrix, is the feature matrix, is the specific weight of the attention layer, is the bias of the attention layer.

[0049] Step S2.1.3: Establish a deep learning model according to the advanced architecture determined in Step S2.1.2. At the same time, use the feature matrix X_fused obtained in Step S2.1.1 as the input of the established deep learning model to obtain the communication data after interactive learning. Specifically, through the autoencoder, convolutional layer, or self-attention mechanism of the Transformer in the deep learning model, automatically learn deeper feature representations, which can reduce the burden of manual feature engineering.

[0050] Meanwhile, obtain weighted features through the feature matrix X_fused and the attention weight matrix , specifically:

[0051] Where: is the weighted feature, is the attention weight matrix, is the feature matrix.

[0052] Step S2.2: Construct a primary machine learning model based on the communication data after interactive learning obtained in Step S2.1.3, specifically as follows: Step S2.2.1: Construct a preset number of different basic machine learning models based on the communication data after interactive learning obtained in Step S2.1.3. Specifically, the basic machine learning models include, but are not limited to, logistic regression (suitable for binary classification problems), support vector machines (SVM, applicable to small to medium-sized data sets), and random forests (RF, applicable to feature selection and handling class imbalance problems). By establishing different basic machine learning models, training and evaluation can be carried out based on the communication data in the above steps, so as to obtain the machine learning model that best meets the actual needs.

[0053] Step S2.2.2: Evaluate the model performance of the preset number of different basic machine learning models in Step S2.2.1, and determine the basic machine learning model with the best model performance from them. The basic machine learning model with the best model performance is the constructed primary machine learning model. Specifically, in the process of evaluating the model performance, the model performance can be evaluated through indicators such as accuracy, recall rate, F1 score, and ROC curve. The basic machine learning model corresponding to the maximum evaluation index is the basic machine learning model with the best model performance.

[0054] Step S2.3: Perform online learning and incremental update to optimize the primary machine learning model in real time, so that the primary machine learning model can continuously learn and adjust when receiving new data without having to retrain the entire data set. Specifically as follows: Step S2.3.1: Perform online learning and incremental update, and set the initial parameters of the primary machine learning model. Specifically, the initial parameters of the primary machine learning model are generally randomly initialized or directly initialized to zero. Specifically as follows: Step S2.3.1.1: Set the initial parameters of the primary machine learning model and obtain the gradient of the loss function corresponding to the communication data after interactive learning, specifically:

[0055] Where: is the gradient of the loss function corresponding to the communication data after interactive learning, is the true label corresponding to the communication data after interactive learning, is the model parameter vector, is the feature vector corresponding to the communication data after interactive learning Specifically, when the communication data after interactive learning is telephone call data, the true label corresponding to the communication data after interactive learning It is the label for whether it is fraud, where fraud = 1 and non-fraud = 0. At the same time, the feature vectors corresponding to the communication data after interactive learning are all the features of the call.

[0056] Step S2.3.1.2: According to the gradient of the loss function corresponding to the communication data after interactive learning obtained in Step S2.3.1 , adjust the initial parameters of the primary machine learning model, specifically:

[0057] where: is the initial parameter of the updated primary machine learning model, is the initial parameter of the primary machine learning model before update, is the learning rate, is the gradient of the loss function corresponding to the communication data after interactive learning; Step S2.3.1.3: Repeat Step S2.3.1.1 - Step S2.3.1.3 until the initial parameters of the primary machine learning model corresponding to each communication data after interactive learning are obtained.

[0058] Step S2.3.2: Through the initial parameters of the primary machine learning model obtained in Step S2.3.1, obtain the adaptive learning rate and perform dynamic adjustment on the primary machine learning model. The adaptive learning rate is specifically:

[0059] where: is the first-order moment estimate corresponding to the moment, is the momentum decay fraction corresponding to the first-order moment, is the first-order moment estimate corresponding to the moment, is the decay factor corresponding to the first-order moment, is the gradient corresponding to the moment, is the second-order moment estimate corresponding to the moment, is the momentum decay fraction corresponding to the second-order moment, is the second-order moment estimate corresponding to the moment, is the decay factor corresponding to the second-order moment, is the first-order moment after regularization, is the decay factor of the first-order moment corresponding to the moment, is the second-order moment after regularization, is the The actual learning rate corresponding to the moment, is the initial learning rate, which is a constant.

[0060] Step S2.4: Establish a user feedback mechanism to obtain new communication data, and repeat steps S2.3 - S2.4 to continuously optimize the established primary machine learning model to obtain the final machine learning model. In this embodiment, during the establishment of the user feedback mechanism, users can conveniently and quickly submit feedback through forms such as APP, SMS reply, website, etc. It should be noted that the feedback options include but are not limited to "false alarm", that is, a legal call is wrongly marked as a fraud, "missed alarm", that is, a fraud call is not correctly identified, and other possible feedback types. Specifically as follows: Step S2.4.1: Collect and classify and integrate the user feedback data, specifically:

[0061] Wherein: is the automatic classification result, is the user feedback, is the natural language processing function.

[0062] Specifically, after collecting the user feedback, the feedback is classified automatically or manually to confirm which are false alarms, missed alarms or other types of feedback, and the corresponding call records, etc. are marked. At the same time, the call data associated with the feedback also needs to be cleaned twice to remove irrelevant information, ensure the data quality, and integrate it into a feedback database to prepare for optimizing model training.

[0063] Step S2.4.2: Verify and mark the classified and integrated user feedback data, and the verified and marked user feedback data is the new communication data. In this embodiment, for key feedback data, especially new fraud strategies encountered for the first time, it is necessary for security experts or manual review teams to verify to ensure the accuracy of the marking. For repetitive and known types of feedback, an automated or semi-automated marking system can be used for automatic identification to improve the processing efficiency. Specifically as follows: Step S2.4.2.1: Verify and identify the classified and integrated user feedback data, specifically:

[0064] Wherein: is the verification result, is the feedback, is the historical data, is the pattern.

[0065] Step S2.4.2.2: The user provides feedback on the verification result, specifically:

[0066] Where: is the final data quality, is the quality of the original input data, is the adjustment coefficient, is the contribution of user feedback.

[0067] Step S2.4.2.3: Compare the feedback result with a preset threshold, specifically: When the feedback result is greater than the preset threshold, mark the data corresponding to the feedback result; otherwise, do not mark the data corresponding to the feedback result. It should be noted that the setting of the preset threshold is not fixed and is specifically set according to the actual situation.

[0068] Step S3: Perform real-time classification and prediction on the real-time call data according to the continuously optimized machine learning model in Step S2.4, and take corresponding protective measures based on the real-time classification and prediction results. Specifically, the protective measures in this embodiment include, but are not limited to, warning the user, automatically hanging up, recording and reporting, tracking and analyzing. Further, warning the user means that when the prediction result is fraud, an early warning message is immediately played through the phone system or a text message is sent to the user's mobile phone, or an APP push reminder is sent. Automatically hanging up means that for highly suspicious fraud calls, the call will be automatically hung up to protect the user from further harassment. Recording and reporting means automatically recording the details of suspected fraud calls, including call records, reasons for prediction, etc., and reporting them to the security platform or law enforcement agencies. Tracking and analyzing means starting further tracking and analysis to collect more evidence to support anti-fraud investigations.

[0069] In this embodiment, during the process of real-time classification and prediction, specifically as follows: Step S3.1: Obtain and preprocess the real-time call data stream through the real-time communication interface. That is, through the real-time communication interface, such as VoIP API, telephone exchange system interface, capture the ongoing call data stream, including audio stream, incoming call number, call time, etc.

[0070] Step S3.2: Extract features from the preprocessed real-time call data stream, specifically:

[0071] Where: is the audio feature, is the audio sample point, is the dynamic window function, is the total number of sampling points, is the coefficient index sub-bandwidth, is the sampling point index sub.

[0072] Specifically, rapid preprocessing is performed on the captured real-time data, including real-time transcoding of audio, that is, converting the audio stream into a format suitable for model processing, noise reduction processing, and real-time statistics of extracting call metadata such as call time, frequency, etc. Specifically as follows: Step S3.2.1: Dynamically adjust the length of the window function according to the signal-to-noise ratio in the real-time call data stream, specifically:

[0073] Where: is the total number of sampling points, is the basic window length, is the control reduction rate, is the signal power, is the noise power, is the threshold.

[0074] Step S3.2.2: In the preprocessed real-time call data stream, frame by time interval and superimpose two adjacent real-time call data streams after framing, specifically:

[0075] Where: is the frequency coefficient of the new frame after overlap, is the frequency coefficient corresponding to the frame, is the frequency coefficient corresponding to the

[0076] Step S3.3: Use the extracted features as the input of the machine learning model to perform real-time prediction on the real-time call data. The extracted features include voice features and behavior features. Specifically, the voice features are to use speech recognition technology to transcribe the call content in real time and extract voice features such as MFCCs, speech rate, pitch, etc., and emotional features such as tension and sense of urgency. The behavior features are the features updated in real time according to real-time call behaviors such as call duration, frequency, and historical behavior patterns.

[0077] That is to say, through the above steps, seamless connection from data capture, processing, feature extraction, real-time prediction to the execution of protection measures can be achieved, effectively identifying and protecting against scam calls and protecting users from scam threats.

[0078] Although embodiments of the present invention have been shown and described, those of ordinary skill in the art will appreciate that various changes, modifications, substitutions, and variations can be made to these embodiments without departing from the principles and spirit of the present invention. The scope of the present invention is defined by the appended claims and their equivalents.

Claims

1. A fraud call identification method based on machine learning, characterized in that: The fraud call identification method specifically includes: S1: Acquire communication data and pre-process the communication data; S2: Building a machine learning model using preprocessed communication data; S3: Perform real-time classification prediction on the real-time call data according to the machine learning model, and perform corresponding protection according to the results of the real-time classification prediction.

2. A fraudulent call identification method based on machine learning according to claim 1, characterized in that: The machine learning model is established as follows: S2.1: performing interactive learning on the pre-processed communication data to construct a multimodal fusion layer; S2.2: constructing a primary machine learning model through the multimodal fusion layer; S2.3: Optimizing the primary machine learning model in real time; S2.4: Establish a user feedback mechanism, obtain new communication data, and repeat steps S2.3-S2.

4.

3. A fraudulent call identification method based on machine learning according to claim 2, characterized in that: The multimodal fusion layer is constructed as follows: S2.1.1: extracting features from the preprocessed communication data and constructing a feature matrix; S2.1.2: Obtain the attention weight matrix through the attention weight, specifically: in: is the attention weight, is the attention weight matrix, is the feature matrix, is the specific weight of the attention layer, is the bias of the attention layer; S2.1.3: Obtain weighted features through the feature matrix and the attention weight matrix, specifically: in: is the weighted feature, is the attention weight matrix, is the feature matrix.

4. A fraudulent call identification method based on machine learning according to claim 2, characterized in that: Construct the primary machine learning model as follows: S2.2.1: constructing a preset number of different basic machine learning models based on the preprocessed communication data and weighted features; S2.2.2: Perform model performance evaluation on a preset number of different basic machine learning models to determine the basic machine learning model with the best model performance. The basic machine learning model with the best model performance is the constructed primary machine learning model.

5. A fraudulent call identification method based on machine learning according to claim 2 or 4, characterized in that: The primary machine learning model is optimized in real time as follows: S2.3.1: Perform online learning and incremental update to obtain initial parameters of the primary machine learning model; S2.3.2: Obtain an adaptive learning rate through the initial parameters of the primary machine learning model, and dynamically adjust the primary machine learning model. The adaptive learning rate is specifically: in: For the The first-order moment estimate corresponding to the moment, is the momentum decay decimal corresponding to the first-order moment, For the The first-order moment estimate corresponding to the moment, is the small attenuation factor corresponding to the first-order moment, For the The gradient corresponding to the moment, For the The second-order moment estimate corresponding to the moment, is the momentum decay decimal corresponding to the second-order moment, For the The second-order moment estimate corresponding to the moment, is the small attenuation factor corresponding to the second-order moment, is the first-order moment after correction, For the The attenuation factor of the first-order moment corresponding to the moment, is the second-order moment after correction, For the The actual learning rate corresponding to the moment, is the initial learning rate, is a constant.

6. A fraudulent call identification method based on machine learning according to claim 5, characterized in that: The initial parameters of the primary machine learning model are obtained as follows: S2.3.1.1: Setting the initial parameters of the primary machine learning model and obtaining the gradient of the loss function corresponding to the communication data after interactive learning, specifically: in: is the gradient of the loss function corresponding to the communication data after interactive learning, is the true label corresponding to the communication data after interactive learning, is the model parameter vector, is the feature vector corresponding to the communication data after interactive learning; S2.3.1.2: According to the gradient of the loss function corresponding to the communication data after interactive learning, the initial parameters of the primary machine learning model are adjusted, specifically: in: are the initial parameters of the updated primary machine learning model, are the initial parameters of the primary machine learning model before updating, is the learning rate, is the gradient of the loss function corresponding to the communication data after interactive learning; S2.3.1.3: Repeat steps S2.3.1.1 to S2.3.1.3 until the initial parameters of the primary machine learning model corresponding to the communication data after each interactive learning are obtained.

7. A fraudulent call identification method based on machine learning according to claim 2, characterized in that: Get new communication data, as follows: S2.4.1: Collect and classify user feedback data, specifically: in: For the automatic classification results, For user feedback, is a natural language processing function; S2.4.2: Verify and mark the classified and integrated user feedback data, and the verified and marked user feedback data is the new communication data.

8. The method for identifying fraudulent calls based on machine learning according to claim 7, characterized in that: The classified and integrated user feedback data is verified and marked as follows: S2.4.2.1: Verify and identify the classified and integrated user feedback data, specifically: in: To verify the results, For feedback, For historical data, for the pattern; S2.4.2.2: Provide user feedback on verification results, specifically: in: For the final data quality, is the quality of the original input data, is the adjustment factor, Contribute to user feedback; S2.4.2.3: Compare the feedback results with the preset thresholds, specifically: When the feedback result is greater than a preset threshold, the data corresponding to the feedback result is marked, otherwise, the data corresponding to the feedback result is not marked.

9. The method for identifying fraudulent calls based on machine learning according to claim 1, characterized in that: The real-time call data is classified and predicted in real time, as follows: S3.1: Obtain and pre-process the real-time call data stream through the real-time communication interface; S3.2: Extract features from the pre-processed real-time call data stream, specifically: in: is the audio feature, is the audio sample point, is a dynamic window function, is the total number of sampling points, is the coefficient index sub-bandwidth, is the sampling point index; S3.3: Using the extracted features as input of a machine learning model to perform real-time prediction on the real-time call data.

10. The method for identifying fraudulent calls based on machine learning according to claim 8, characterized in that: Feature extraction is performed from the preprocessed real-time call data stream, as follows: S3.2.1: Dynamically adjust the length of the window function according to the signal-to-noise ratio in the real-time call data stream, specifically: in: is the total number of sampling points, is the basic window length, To control the reduction rate, is the signal power, is the noise power, is the threshold value; S3.2.2: Divide the pre-processed real-time call data stream into frames according to time intervals, and superimpose two adjacent real-time call data streams after framing, specifically: in: is the frequency coefficient of the new frame after overlapping, For the The frequency coefficients corresponding to the frame, For the The frequency coefficients corresponding to the frame.