Timing sequence feature risk decision-making method and system based on rule and machine learning fusion

By integrating rules and machine learning in financial risk decisions and processing timing feature data, it solves the problem that traditional decision-making methods are difficult to adapt to changes in financial business and dealing with timing features, and achieves more efficient and flexible risk decisions.

CN120106849APending Publication Date: 2025-06-06BANK OF NANJING CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510068126.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-16
Publication Date
2025-06-06

AI Technical Summary

Technical Problem

Traditional financial risk decisions are difficult to adapt to changes in financial business needs, cannot effectively handle the timing characteristics in tens of millions of customer transaction data, and are difficult to adapt to the weight changes set by different rules.

Method used

The timing characteristic risk decision method based on the integration of rules and machine learning is adopted, and the historical business data is processed through the timing engine, and the timing indicator data is generated. The points risk decision engine combines real-time data and timing indicator data to calculate rules and machine learning models to perform risk judgment and processing.

Benefits of technology

Decisions with different weights for different rules are realized, real-time transaction data can be monitored and analyzed more effectively, abnormal transaction behaviors are discovered in a timely manner, real-time risks are prevented, and the adaptability and accuracy of risk decisions are improved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120106849A_ABST
    Figure CN120106849A_ABST
Patent Text Reader

Abstract

The invention discloses a time sequence characteristic risk decision-making method and system based on rule and machine learning fusion, and is used for the field of financial risk decision-making. The time sequence feature risk decision-making method based on rule and machine learning fusion comprises the following steps of obtaining historical business data of successful transaction at a channel end or historical business data and calculation scripts stored in a data warehouse, and performing time sequence processing; obtaining time sequence index data according to the real-time business data by using an integral risk decision engine; the risk rules are synchronized to an integral risk decision engine, and calculation of the rules and a machine learning model is carried out based on real-time data and time sequence index data; and judging the risk of the real-time business data based on the comparison result by using an integral risk decision engine. According to the invention, real-time transaction data is monitored and analyzed, so that the security is improved; browsing behaviors of the user are obtained and analyzed, and the sales volume of the shopping website is increased; sensor data are acquired in real time, and system stability is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of financial risk decision-making, and in particular, to a time series feature risk decision-making method and system based on the fusion of rules and machine learning. Background Art

[0002] In financial risk scenarios, raw data is usually processed to form indicators, which have time series characteristics. For example, "the cumulative number of transactions with a transaction amount greater than RMB 1,000 by the same user in the past 24 hours" refers to the "past 24 hours". Faced with transaction data from tens of millions of customers, how to generate time series features of different time granularities and different subjects within a limited time and perform effective storage and extremely fast access becomes the key to processing real-time risk data.

[0003] Traditional financial risk decision-making mainly uses the hit system, that is, matching data with risk rules. If the rules are hit, the corresponding risk of the rule is triggered, and the business personnel will deal with it and then determine whether the risk subject is risky. Although traditional risk decision-making can identify the potential risks of risk subjects, it will default to the same weight for risk rules, which is difficult to adapt to the evolving financial business needs.

[0004] Currently, no effective solution has been proposed for the problems in the related technologies. Summary of the invention

[0005] In order to overcome the above problems, the present invention aims to propose a time series feature risk decision-making method and system based on the fusion of rules and machine learning, so as to overcome the above technical problems existing in the existing related technologies.

[0006] To this end, the specific technical solution adopted by the present invention is as follows:

[0007] According to one aspect of the present invention, a time series feature risk decision method based on the fusion of rules and machine learning is provided, and the time series feature risk decision method based on the fusion of rules and machine learning comprises the following steps:

[0008] S1. Obtain historical business data of successful transactions on the channel side or historical business data and calculation scripts stored in the data warehouse, perform time series processing on the historical business data through the time series engine, and store the processed time series indicator data in the memory database;

[0009] S2. Use the score risk decision engine to obtain the time series indicator data in the memory database based on the real-time business data pushed by the channel end; synchronize the risk rules to the score risk decision engine, calculate the rules and machine learning models based on the real-time data and time series indicator data, and obtain the rule calculation results;

[0010] S3. Use the integral risk decision engine to judge the risk of real-time business data based on the comparison results of rule calculation and risk rules, and perform risk processing based on the judgment results.

[0011] Optionally, obtaining historical business data of successful transactions on the channel side or historical business data and calculation scripts stored in a data warehouse, performing time series processing on the historical business data through a time series engine, and storing the processed time series indicator data in a memory database includes the following steps:

[0012] S11. Use the channel end to collect historical business data of successful transactions or historical business data and calculation scripts stored in the data warehouse;

[0013] S12. Use the time series engine to perform time series processing on historical business data according to the primary key of the indicator;

[0014] S13: Slice the processed time series indicator data and store the processing results in the memory database.

[0015] Optionally, using a time series engine to perform time series processing on historical business data according to the primary key of the indicator includes the following steps:

[0016] S121, obtaining a specified historical business data object and specifying a namespace;

[0017] S122, specifying the primary key of the historical business data object;

[0018] S123, setting filtering conditions, and filtering historical business data objects according to the filtering conditions;

[0019] S124, obtaining the transaction time of the historical business data object;

[0020] S125. Setting a transaction time window for historical business data;

[0021] S126. Select a corresponding calculation function for the indicator to obtain corresponding time series indicator data.

[0022] Optionally, the method of slicing the processed time series indicator data includes:

[0023] Time series indicator data is stored in the memory database as slice data in units of hours, days, months, etc.

[0024] Optionally, using the integral risk decision engine, obtaining the time series indicator data in the memory database according to the real-time business data pushed by the channel end; synchronizing the risk rules to the integral risk decision engine, calculating the rules and machine learning models based on the real-time data and the time series indicator data, and obtaining the rule calculation results include the following steps:

[0025] S21. Obtain real-time business data based on the channel end;

[0026] S22, using the integral risk decision engine to obtain the time series indicator data corresponding to the real-time business data in the memory database, combining the risk rules, performing time range processing operations on the time series indicator data, and performing rule calculation to obtain the rule calculation results of the real-time business data;

[0027] S23. According to the real-time business data, the time series indicator data corresponding to the real-time business data in the memory database is obtained, and the time range processing operation is performed in combination with the time series range of the machine learning model, and the model calculation is performed to obtain the model calculation result;

[0028] S24. Based on the integral risk decision engine, logical judgment of rules and machine learning is performed on the rule calculation results and model calculation results.

[0029] Optionally, using the integral risk decision engine to obtain time series indicator data corresponding to the real-time business data in the memory database, combining the risk rules, performing time range processing operations on the time series indicator data, and performing rule calculation to obtain the rule calculation results of the real-time business data include the following steps:

[0030] S221, performing object determination on the acquired real-time business data;

[0031] S222. Assigning primary keys to historical business data based on real-time business data;

[0032] S223. According to the time span set in the rule, obtain the time series indicator data within the corresponding primary key and the corresponding time range in the memory database;

[0033] S224. The risk decision engine processes the acquired time series indicator data group into a single indicator, compares it with the indicator threshold in the rule, determines whether the indicator meets the rule requirements, and obtains the rule calculation result.

[0034] Optionally, the step of performing logical judgment of rules and machine learning on the rule calculation results and the model calculation results based on the integral risk decision engine includes the following steps:

[0035] S241. Setting rule scores according to different rules;

[0036] S242. Setting a machine learning model score according to different machine learning models;

[0037] S243. Determine the rules and machine learning models to which the real-time business data belongs, and obtain corresponding rule scores and machine learning model scores;

[0038] S243. Calculate the final risk score of the real-time business data based on the rule score and the machine learning model score of the real-time business data.

[0039] Optionally, the final risk score of the real-time business data is expressed as:

[0040]

[0041] In the formula, Score represents the risk score;

[0042] SR k Indicates the score of hitting the kth rule;

[0043] n is the number of rules;

[0044] SM k Indicates the score that triggers the k-th model;

[0045] m is the number of models.

[0046] Optionally, using the integral risk decision engine, based on the rule calculation result and the comparison result of the risk rule, the risk of the real-time business data is judged, and the risk processing is performed according to the judgment result, including the following steps:

[0047] S31. Set risk thresholds;

[0048] S32. Synchronize the risk rules to the score risk decision engine according to the open source business rule engine, and compare the business data with the rules;

[0049] S33. Determine the risk score of the real-time business data according to the risk threshold;

[0050] S34. According to the judgment result of step S33, if the risk score of the current real-time business data is higher than or equal to the risk threshold, the current real-time business data triggers risk and is determined to be risk data. The risk data is fed back to the channel end, and the business personnel determine the disposal strategy for the risk data; if the risk score of the real-time business data is lower than the risk threshold, the current real-time business data does not trigger risk and is determined to be normal business data, and the business personnel can operate normally;

[0051] S35. Store the risk data in a database for later analysis and calculation of real-time business data.

[0052] According to another aspect of the present invention, a time series feature risk decision system based on the fusion of rules and machine learning is also provided. The time series feature risk decision system based on the fusion of rules and machine learning includes: a time series processing module, an indicator calculation module and a risk judgment module;

[0053] A time series processing module is used to obtain historical business data of successful transactions through the channel end, and perform time series processing on the historical business data through the time series engine, and store the time series indicator data after processing in the memory database;

[0054] The indicator calculation module is used to obtain real-time business data and time-series indicator data stored in memory data based on the channel end, and use the integral risk decision engine to perform logical judgment of rules and machine learning based on real-time data and time-series indicator data to obtain rule calculation results;

[0055] The risk judgment module is used to use the integral risk decision engine to judge the risks of real-time business data based on the comparison results of rule calculation and risk rules, and perform risk processing according to the judgment results.

[0056] Compared with the prior art, this application has the following beneficial effects:

[0057] The decision-making method of the present invention, which sets different weights for different rules and integrates the results of machine learning models, is more in line with modern scenarios such as expert decision-making and data mining. Real-time transaction data is monitored and analyzed, abnormal transaction behaviors are discovered in a timely manner, and responsive measures are taken, which can effectively prevent real-time risks; the present invention obtains users' browsing and purchasing behaviors in real time for analysis, and can recommend products that users are most interested in and most likely to buy, thereby increasing the sales of shopping websites; the present invention obtains sensor data or server logs in real time, thereby discovering equipment problems or system operation conditions in real time, improving production efficiency, product quality or system stability. BRIEF DESCRIPTION OF THE DRAWINGS

[0058] The above characteristics, features and advantages of the present invention and their implementation methods and methods will become more clearly understood in conjunction with the following description of the embodiments, which are described in detail in conjunction with the accompanying drawings. Herein, a schematic diagram is shown:

[0059] Figure 1 is a flow chart of a time series feature risk decision-making method based on rule and machine learning fusion according to an embodiment of the present invention;

[0060] Figure 2 It is a principle block diagram of a time series feature risk decision system based on rule and machine learning fusion according to an embodiment of the present invention;

[0061] Figure 3 is a flowchart of indicator calculation in a time series feature risk decision-making method based on rule and machine learning fusion according to an embodiment of the present invention;

[0062] Figure 4 It is a specific application flow chart of the time series feature risk decision-making method based on the fusion of rules and machine learning according to an embodiment of the present invention.

[0063] In the figure:

[0064] 1. Time series processing module; 2. Index calculation module; 3. Risk judgment module. DETAILED DESCRIPTION

[0065] In order to enable those skilled in the art to better understand the solution of the present application, the technical solution in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of this application.

[0066] According to an embodiment of the present invention, a time series feature risk decision-making method and system based on the fusion of rules and machine learning are provided.

[0067] The present invention is further described with reference to the accompanying drawings and specific embodiments. Figure 1 and Figure 4 As shown, according to one embodiment of the present invention, a time series feature risk decision method based on the fusion of rules and machine learning is provided, and the time series feature risk decision method based on the fusion of rules and machine learning includes the following steps:

[0068] S1. Obtain historical business data of successful transactions on the channel side or historical business data and calculation scripts stored in the data warehouse, perform time series processing on the historical business data through a time series engine, and store the processed time series indicator data in a memory database.

[0069] Preferably, obtaining historical business data of successful transactions on the channel side or historical business data and calculation scripts stored in the data warehouse, performing time series processing on the historical business data through a time series engine, and storing the processed time series indicator data in a memory database includes the following steps:

[0070] S11. Use the channel end to collect historical business data of successful transactions or historical business data and calculation scripts stored in the data warehouse;

[0071] S12. Use the time series engine to perform time series processing on historical business data according to the primary key of the indicator;

[0072] S13: Slice the processed time series indicator data and store the processing results in the memory database.

[0073] Preferably, using the time series engine to perform time series processing on historical business data according to the primary key of the indicator includes the following steps:

[0074] S121, obtaining a specified historical business data object and specifying a namespace;

[0075] S122, specifying the primary key of the historical business data object;

[0076] S123, setting filtering conditions, and filtering historical business data objects according to the filtering conditions;

[0077] S124, obtaining the transaction time of the historical business data object;

[0078] S125. Setting a transaction time window for historical business data;

[0079] S126. Select a corresponding calculation function for the indicator to obtain corresponding time series indicator data.

[0080] Preferably, the method of slicing the processed time series indicator data includes:

[0081] Time series indicator data is stored in the memory database as slice data in units of hours, days, months, etc.

[0082] It should be explained that the time series engine is used to perform time series processing on historical business data based on the primary key of the indicator.

[0083] Based on the indicator of the cumulative number of transactions with a transaction amount greater than 1,000 yuan for the same user in the past 24 hours, the constructed code is as follows:

[0084]

[0085] The primary key of the indicator in this code example is "user number"; the time range is "24 hours"; the filtering condition is "amount greater than 1,000 yuan"; the statistical feature is "number of times"; the indicator refers to the number of times the transaction amount is greater than 1,000 yuan within 24 hours for different user numbers.

[0086] According to the indicator of the cumulative amount of personal transfers to corporate customers in the past 24 hours, the constructed code is as follows:

[0087]

[0088]

[0089] The primary key of the indicator in this code example is "personal bank card number"; the time range is "24 hours"; the filtering condition is "personal to public transfer"; the statistical feature is "transfer amount"; the indicator refers to the transaction amount within 24 hours for the bank card number.

[0090] In the constructed code, the indicator is the cumulative amount of personal transfers to corporate customers in the past 24 hours. The time series engine calculates the cumulative number of transactions with a transaction amount greater than 1,000 yuan in the past 24 hours based on the user number. The time series engine calculates the results and stores them in the cache. Each indicator is actually stored based on "h" as a unit. This slicing method can save space and improve storage efficiency. For example, when querying, the reference time is [2020-01-12 09:10:10], the interval is 3 hours, and the query time window is [2020-01-12 07:00:00, 2020-01-12 09:10:10]. When querying, the reference time is [2020-01-12 09:10:10], the interval is 3 days, and the query time window is [2020-01-10 00:00:00, 2020-01-12 09:10:10].

[0091] The storage slices of specific features in the cache are shown below.

[0092] MemCachedItem{

[0093] reference_time=1713867867089,

[0094] expire_duration=63244800000,

[0095] Slice by day: The total number of outgoing transactions on the channel side on that day = TimeItems{allItems={2024-04-2400:00:00.000=CountNumber{count=1,value=1,merged=true}}},

[0096] Slice by hour: The cumulative number of transactions with the same bank card in the past four hours through the public channel_DG=TimedItems{allItems={2024-04-23

[0097] 19:00:00.000=CountNumber{count=1,value=1,merged=true}}},

[0098] Primary_biz=BANK,

[0099] Total number of outgoing transactions on the day (including recharging wallets) = TimedItems{allItems = {2024-04-2419:00:00.000 = CountNumber{count = 1, value = 1, merged = true}}}

[0100] }

[0101] "Slice by day": The specific operation is to classify the data at any time point into the next full hour start time of the day, that is, midnight of the next day. For example, the data at the time point [2024-04-23 18:24:27.089] is divided into hours: [2024-04-24 00:00:00], and count = 1 means that the number of records is 1.

[0102] "Hourly Slicing": The specific operation is to classify the data at any time point into the next hour of the hour. For example, the data at the time point [2024-04-23 18:24:27.089] is divided into hours: [2024-04-23 19:00:00], and count = 1 means the number of records is 1;

[0103] S2. Use the integral risk decision engine to obtain the time series indicator data in the memory database based on the real-time business data pushed by the channel end; synchronize the risk rules to the integral risk decision engine, calculate the rules and machine learning models based on the real-time data and time series indicator data, and obtain the rule calculation results.

[0104] Preferably, using the integral risk decision engine, obtaining the time series indicator data in the memory database according to the real-time business data pushed by the channel end; synchronizing the risk rules to the integral risk decision engine, calculating the rules and machine learning models based on the real-time data and the time series indicator data, and obtaining the rule calculation results include the following steps:

[0105] S21. Obtain real-time business data based on the channel end;

[0106] S22, using the integral risk decision engine to obtain the time series indicator data corresponding to the real-time business data in the memory database, combining the risk rules, performing time range processing operations on the time series indicator data, and performing rule calculation to obtain the rule calculation results of the real-time business data;

[0107] S23. According to the real-time business data, the time series indicator data corresponding to the real-time business data in the memory database is obtained, and the time range processing operation is performed in combination with the time series range of the machine learning model, and the model calculation is performed to obtain the model calculation result;

[0108] S24. Based on the integral risk decision engine, logical judgment of rules and machine learning is performed on the rule calculation results and model calculation results.

[0109] Preferably, using the integral risk decision engine to obtain the time series indicator data corresponding to the real-time business data in the memory database, combining the risk rules, performing time range processing operations on the time series indicator data, and performing rule calculation to obtain the rule calculation results of the real-time business data include the following steps:

[0110] S221, performing object determination on the acquired real-time business data;

[0111] S222. Assigning primary keys to historical business data based on real-time business data;

[0112] S223. According to the time span set in the rule, obtain the time series indicator data within the corresponding primary key and the corresponding time range in the memory database;

[0113] S224. The risk decision engine processes the acquired time series indicator data group into a single indicator, compares it with the indicator threshold in the rule, determines whether the indicator meets the rule requirements, and obtains the rule calculation result.

[0114] Preferably, based on the integral risk decision engine, performing logical judgment of rules and machine learning on the rule calculation results and the model calculation results includes the following steps:

[0115] S241. Setting rule scores according to different rules;

[0116] S242. Setting a machine learning model score according to different machine learning models;

[0117] S243. Determine the rules and machine learning models to which the real-time business data belongs, and obtain corresponding rule scores and machine learning model scores;

[0118] S243. Calculate the final risk score of the real-time business data based on the rule score and the machine learning model score of the real-time business data.

[0119] Preferably, the final risk score of the real-time business data is expressed as:

[0120]

[0121] In the formula, Score represents the risk score;

[0122] SR k Indicates the score of hitting the kth rule;

[0123] n is the number of rules;

[0124] SM k Indicates the score that triggers the k-th model;

[0125] m is the number of models.

[0126] It needs to be explained that Figure 3As shown, based on the real-time business data obtained from the channel, the historical business data stored in the data warehouse and the calculation scripts, the time series engine is used to perform indicator calculations on the real-time business data and the historical business data respectively; the integral risk decision engine is used to perform logical judgments on the indicator calculation results based on rules and machine learning, and a flow chart of the rule calculation results is obtained.

[0127] Figure 3 The post-event interface means that the data provided by this interface is mainly real-time transaction data on the channel side, which is used for the calculation of time series indicators; file synchronization means that the data provided by this interface is mainly dimensional data that cannot be obtained through the real-time interface, generally belonging to T+1 day data, which is provided to the time series engine together with the post-event interface to assist in indicator calculation; script synchronization means that the decision engine synchronizes the indicator calculation script to the time series engine, and the time series engine calculates the indicators on the acquired data based on the calculation script. The calculation script is described as follows:

[0128]

[0129]

[0130] Based on the above code, the interface data will be processed by the calculation script afterwards, mainly including:

[0131] 1. Perform object judgment on the data. For example, in the above example, we need to determine whether the current data belongs to the TransFlow object and specify the primary key.

[0132] 2. Perform conditional filtering, such as whether getTransAmt() is greater than 1,000 yuan;

[0133] 3. Set the expiration time, such as expirePattern("24h"), the expiration time is 24 hours. If the data exceeds 24 hours, the data will become invalid;

[0134] 4. Finally, the data is calculated. For example, CountNumber(1L) is set to 1. The system will store the transaction count of the current object at the corresponding time in the cache as: 1;

[0135] The model result indicates that the calculation of the machine learning model depends on the feature data. In the present invention, the feature data is the index data in the cache. When performing model calculation, the index data in the cache is queried, and then the model calculation is performed to obtain the model result. The model result will be provided to the decision engine for rule calculation. The decision engine is triggered by the in-process interface call. The decision engine calls the index data to perform logical judgment of rules and machine learning. The decision mechanism is as follows:

[0136] For example, a rule A contains rules and machine learning models:

[0137] Set Rule 1 Score SR k (SR k represents the rule k score, and the specific numbers represent different rules);

[0138] Set up machine learning model 1 score SM k (SM k represents the model k score, and the specific numbers represent different models).

[0139] Based on the rule score and machine learning model score of real-time business data, the final risk score of real-time business data is expressed as:

[0140]

[0141] In the formula, Score represents the risk score;

[0142] SR k Indicates the score of hitting the kth rule;

[0143] n is the number of rules;

[0144] SM k Indicates the score that triggers the k-th model;

[0145] m is the number of models.

[0146] S3. Use the integral risk decision engine to judge the risk of real-time business data based on the comparison results of rule calculation and risk rules, and perform risk processing based on the judgment results.

[0147] Preferably, using the integral risk decision engine, based on the comparison results of the rule calculation results and the risk rules, the risk of the real-time business data is judged, and the risk processing is performed according to the judgment results, including the following steps:

[0148] S31. Set risk thresholds;

[0149] S32. Synchronize the risk rules to the score risk decision engine according to the open source business rule engine, and compare the business data with the rules;

[0150] S33. Determine the risk score of the real-time business data according to the risk threshold;

[0151] S34. According to the judgment result of step S33, if the risk score of the current real-time business data is higher than or equal to the risk threshold, the current real-time business data triggers risk and is determined to be risk data. The risk data is fed back to the channel end, and the business personnel determine the disposal strategy for the risk data; if the risk score of the real-time business data is lower than the risk threshold, the current real-time business data does not trigger risk and is determined to be normal business data, and the business personnel can operate normally;

[0152] S35. Store the risk data in the database for later analysis and calculation of real-time business data.

[0153] It should be noted that according to the rule score and machine learning model score of the real-time business data, the expression for the final risk score of the real-time business data is:

[0154]

[0155] In the formula, Score represents the risk score;

[0156] SR k represents the score for hitting the k-th rule;

[0157] n is the number of rules;

[0158] SM k represents the score for triggering the k-th model;

[0159] m is the number of models.

[0160] The analyst and business personnel jointly determine the thresholdValue (set threshold). If Score >= thresholdValue (set threshold), then this piece of data triggers a risk; if Score < thresholdValue, then no risk is triggered.

[0161] According to the business data comparison rules, determine whether the risk rules are met. The specific implementation method is to make risk decisions based on drools (open-source business rule engine). For example:

[0162] Rule 1: The cumulative number of transactions where the user's transaction amount in the past 24 hours is greater than 1000 yuan > 10 times, SR 1 = 5 points;

[0163] Rule 2: The transaction amount of the user in the specified time period [23:00:00, 1:00:00] > 500,000 yuan, SR 2 = 4 points;

[0164] Model 1: The current user belongs to a suspicious customer, SM 1 = 5 points; The current user belongs to a normal user, SM 1 = 1 point.

[0165] The threshold is set to threshold = 8 points.

[0166] Assume that the transaction data trigger situations of the current users C1 and C2 are shown in Table 1.

[0167] Table 1 Transaction Data Trigger Situation Table

[0168] user Trigger rules and models Score C1 Rule 1, Model 1 (Suspicious Customers) 5+5=10 C2 Rule 2, Model 1 (Normal Customer) 4+1=5

[0169] As shown in Table 1, if the score of C1 (Score = 10) > (threshold = 8), user C1 triggers risk; if the score of C2 (Score = 4 < (threshold = 8), user C2 does not trigger risk; the risk data is fed back to the channel end, and the business personnel determine the disposal strategy of the risk data, which includes SMS verification, delayed payment, etc.; the determined risk data is stored in the database for later analysis and calculation of real-time business data.

[0170] According to another embodiment of the present invention, Figure 2 As shown, a time series feature risk decision system based on the fusion of rules and machine learning is also provided. The time series feature risk decision system based on the fusion of rules and machine learning includes: a time series processing module 1, an indicator calculation module 2 and a risk judgment module 3;

[0171] The time series processing module 1 is used to obtain historical business data of successful transactions through the channel end, and perform time series processing on the historical business data through the time series engine, and store the time series indicator data after processing in the memory database;

[0172] The indicator calculation module 2 is used to obtain the real-time business data and the time series indicator data stored in the memory data based on the channel end, and use the integral risk decision engine to perform logical judgment of rules and machine learning based on the real-time data and the time series indicator data to obtain the rule calculation results;

[0173] The risk judgment module 3 is used to use the integral risk decision engine to judge the risk of real-time business data based on the rule calculation results and the comparison results of the risk rules, and perform risk processing according to the judgment results.

[0174] In summary, with the help of the above technical solutions of the present invention, the decision-making method of the present invention, which sets different weights for different rules and integrates the results of machine learning models, is more in line with modern scenarios such as expert decision-making and data mining. Real-time transaction data is monitored and analyzed, abnormal transaction behaviors are discovered in a timely manner, and responsive measures are taken, which can effectively prevent real-time risks; the present invention obtains users' browsing behaviors and purchasing behaviors in real time for analysis, and can recommend products that users are most interested in and most likely to buy, thereby increasing the sales of shopping websites; the present invention obtains sensor data or server logs in real time, thereby discovering equipment problems or system operation conditions in real time, and improving production efficiency, product quality or system stability.

[0175] Although the present invention has been disclosed as above with preferred embodiments, the embodiments are merely examples for the convenience of description and are not intended to limit the present invention. Those skilled in the art may make several changes and modifications without departing from the spirit and scope of the present invention. The scope of protection claimed by the present invention shall be based on the claims.

Claims

1. A time series feature risk decision-making method based on the fusion of rules and machine learning, characterized by: The time series feature risk decision-making method based on the fusion of rules and machine learning includes the following steps: S1. Obtain historical business data of successful transactions on the channel side or historical business data and calculation scripts stored in the data warehouse, perform time series processing on the historical business data through the time series engine, and store the processed time series indicator data in the memory database; S2. Use the score risk decision engine to obtain the time series indicator data in the memory database based on the real-time business data pushed by the channel end; synchronize the risk rules to the score risk decision engine, calculate the rules and machine learning models based on the real-time data and time series indicator data, and obtain the rule calculation results; S3. Use the integral risk decision engine to judge the risk of real-time business data based on the comparison results of rule calculation and risk rules, and perform risk processing based on the judgment results.

2. The time series feature risk decision-making method based on rule and machine learning fusion according to claim 1 is characterized in that: The obtaining of historical business data of successful transactions on the channel side or historical business data and calculation scripts stored in the data warehouse, performing time series processing on the historical business data through a time series engine, and storing the processed time series indicator data in the memory database comprises the following steps: S11. Use the channel end to collect historical business data of successful transactions or historical business data and calculation scripts stored in the data warehouse; S12. Use the time series engine to perform time series processing on historical business data according to the primary key of the indicator; S13: Slice the processed time series indicator data and store the processing results in the memory database.

3. The time series feature risk decision-making method based on rule and machine learning fusion according to claim 2 is characterized in that: The use of the time series engine to perform time series processing on historical business data according to the primary key of the indicator includes the following steps: S121, obtaining a specified historical business data object and specifying a namespace; S122, specifying the primary key of the historical business data object; S123, setting filtering conditions, and filtering historical business data objects according to the filtering conditions; S124, obtaining the transaction time of the historical business data object; S125. Setting a transaction time window for historical business data; S126. Select a corresponding calculation function for the indicator to obtain corresponding time series indicator data.

4. The time series feature risk decision-making method based on rule and machine learning fusion according to claim 2 is characterized in that: The method of slicing the processed time series indicator data includes: Time series indicator data is stored in the memory database as slice data in units of hours, days, and months.

5. The time series feature risk decision-making method based on rule and machine learning fusion according to claim 1 is characterized in that: The point risk decision engine is used to obtain time series indicator data in the memory database according to the real-time business data pushed by the channel end; The risk rules are synchronized to the integral risk decision engine, and the rules and machine learning models are calculated based on real-time data and time series indicator data. The rule calculation results are obtained by the following steps: S21. Obtain real-time business data based on the channel end; S22, using the integral risk decision engine to obtain the time series indicator data corresponding to the real-time business data in the memory database, combining the risk rules, performing time range processing operations on the time series indicator data, and performing rule calculation to obtain the rule calculation results of the real-time business data; S23. According to the real-time business data, the time series indicator data corresponding to the real-time business data in the memory database is obtained, and the time range processing operation is performed in combination with the time series range of the machine learning model, and the model calculation is performed to obtain the model calculation result; S24. Based on the integral risk decision engine, logical judgment of rules and machine learning is performed on the rule calculation results and model calculation results.

6. The time series feature risk decision-making method based on rule and machine learning fusion according to claim 5 is characterized in that: The method of using the integral risk decision engine to obtain the time series indicator data corresponding to the real-time business data in the memory database, combining the risk rules, performing time range processing operations on the time series indicator data, and performing rule calculation to obtain the rule calculation results of the real-time business data includes the following steps: S221, performing object determination on the acquired real-time business data; S222. Assigning primary keys to historical business data based on real-time business data; S223. According to the time span set in the rule, obtain the time series indicator data within the corresponding primary key and the corresponding time range in the memory database; S224. The risk decision engine processes the acquired time series indicator data group into a single indicator, compares it with the indicator threshold in the rule, determines whether the indicator meets the rule requirements, and obtains the rule calculation result.

7. The time series feature risk decision-making method based on rule and machine learning fusion according to claim 5 is characterized in that: The logic judgment of rules and machine learning based on the integral risk decision engine for the rule calculation results and the model calculation results includes the following steps: S241. Setting rule scores according to different rules; S242. Setting a machine learning model score according to different machine learning models; S243. Determine the rules and machine learning models to which the real-time business data belongs, and obtain corresponding rule scores and machine learning model scores; S243. Calculate the final risk score of the real-time business data based on the rule score and the machine learning model score of the real-time business data.

8. The time series feature risk decision-making method based on rule and machine learning fusion according to claim 7 is characterized in that: The final risk score of the real-time business data is expressed as: In the formula, Score represents the risk score; SR k Indicates the score of hitting the kth rule; n is the number of rules; SM k Indicates the score that triggers the k-th model; m is the number of models.

9. The time series feature risk decision-making method based on rule and machine learning fusion according to claim 1 is characterized in that: The method of using the integral risk decision engine to judge the risk of real-time business data based on the comparison result of the rule calculation result and the risk rule, and performing risk processing according to the judgment result includes the following steps: S31. Set risk thresholds; S32. Synchronize the risk rules to the score risk decision engine according to the open source business rule engine, and compare the business data with the rules; S33. Determine the risk score of the real-time business data according to the risk threshold; S34. According to the judgment result of step S33, if the risk score of the current real-time business data is higher than or equal to the risk threshold, the current real-time business data triggers risk and is determined to be risk data. The risk data is fed back to the channel end, and the business personnel determine the disposal strategy for the risk data; if the risk score of the real-time business data is lower than the risk threshold, the current real-time business data does not trigger risk and is determined to be normal business data, and the business personnel can operate normally; S35. Store the risk data in a database for later analysis and calculation of real-time business data.

10. A time series feature risk decision system based on the fusion of rules and machine learning, used to implement the time series feature risk decision method based on the fusion of rules and machine learning as described in any one of claims 1 to 9, characterized in that: The time series feature risk decision-making system based on the fusion of rules and machine learning includes: a time series processing module, an indicator calculation module and a risk judgment module; A time series processing module is used to obtain historical business data of successful transactions through the channel end, and perform time series processing on the historical business data through the time series engine, and store the time series indicator data after processing in the memory database; The indicator calculation module is used to obtain real-time business data and time-series indicator data stored in memory data based on the channel end, and use the integral risk decision engine to perform logical judgment of rules and machine learning based on real-time data and time-series indicator data to obtain rule calculation results; The risk judgment module is used to use the integral risk decision engine to judge the risks of real-time business data based on the comparison results of rule calculation and risk rules, and perform risk processing according to the judgment results.