Risk detection method and device, equipment and storage medium
By semantic extraction of user communication data and building communication storylines, the problem that existing technology cannot effectively deal with complex telecommunications fraud strategies is solved, and accurate detection and early warning of fraud risks is achieved.
Patent Information
- Application Number
- CN202311658115.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-12-05
- Publication Date
- 2025-06-10
- Estimated Expiration
- 2043-12-05
AI Technical Summary
The existing technology cannot effectively deal with complex and changeable telecommunications fraud strategies, and there are problems such as difficulty in identifying complex semantic information, long training cycles, delayed detection, high maintenance costs and data isolation.
By semantic extraction of the collected user communication data, communication semantic data can be obtained; user communication story lines are constructed based on communication semantic data and user communication data; risk detection is carried out based on communication semantic data and user communication story lines to determine whether there is a risk of fraud.
Accurate detection of complex and changeable fraud behaviors is achieved, the limitations of single keyword filtering and single information analysis are avoided, and the efficiency and accuracy of telecommunications fraud risk detection is improved.
Smart Images

Figure CN120128345A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and particularly to a risk detection method, device, equipment and storage medium. Background Art
[0002] In recent years, with the popularization of mobile communication networks, the number of telecommunications fraud incidents has been continuously increasing, seriously threatening the lives and property safety of users. Traditional prevention means such as keyword filtering, sample annotation and single information analysis methods have various limitations, such as being unable to identify complex semantic information, having a long training cycle, a delayed detection scheme, high maintenance costs, and data isolation problems, and it is difficult to effectively cope with complex and changeable telecommunications fraud strategies. Summary of the Invention
[0003] The main purpose of the present invention is to provide a risk detection method, device, equipment and storage medium, aiming to solve the technical problem that the existing technology cannot effectively cope with complex and changeable telecommunications fraud strategies.
[0004] To achieve the above object, the present invention provides a risk detection method, and the method includes the following steps:
[0005] Perform semantic extraction on the collected user communication data to obtain communication semantic data;
[0006] Construct a user communication story line based on the communication semantic data and the user communication data, where the user communication story line is a data stream constructed according to at least one communication data corresponding to the same semantics of the same user;
[0007] Perform risk detection according to the communication semantic data and the user communication story line to determine whether there is a fraud risk.
[0008] Optionally, the user communication data is multimodal data;
[0009] The step of performing semantic extraction on the collected user communication data to obtain communication semantic data includes:
[0010] Perform semantic extraction on the collected user communication data through a multimodal large model to obtain communication semantic data, where the multimodal large model is a model pre-trained for semantic extraction of various different types of data.
[0011] Optionally, the step of performing risk detection according to the communication semantic data and the user communication story line to determine whether there is a fraud risk includes:
[0012] Obtain the target user identifier corresponding to the user communication story line;
[0013] Search for the target user portrait corresponding to the target user identifier;
[0014] Determine whether there is a fraud risk based on the target user profile, the user communication storyline, and the communication semantic data.
[0015] Optionally, the step of determining whether there is a fraud risk based on the target user profile, the user communication storyline, and the communication semantic data includes:
[0016] Update the target user profile according to the user communication storyline and the communication semantic data to obtain an updated user profile;
[0017] Compare the target user profile with the updated user profile to determine the profile difference degree;
[0018] If the profile difference degree is greater than a preset difference threshold, it is determined that there is a fraud risk.
[0019] Optionally, the step of comparing the target user profile with the updated user profile to determine the profile difference degree includes:
[0020] Detect the user communication storyline to determine whether there are risk behaviors;
[0021] If there are risk behaviors, compare the target user profile with the updated user profile to determine the profile difference degree.
[0022] Optionally, the step of performing risk detection based on the communication semantic data and the user communication storyline to determine whether there is a fraud risk includes:
[0023] Mark the user communication storyline according to the communication semantic data to obtain a semantic marked storyline;
[0024] Obtain the target user corresponding to the user communication storyline;
[0025] In the storyline repository, search for the semantic marked storylines corresponding to other users except the target user to obtain comparison storylines;
[0026] Construct broadcast event information based on the semantic marked storyline and the comparison storylines;
[0027] Determine whether there is a fraud risk based on the broadcast event information.
[0028] Optionally, the step of constructing broadcast event information based on the semantic marked storyline and the comparison storylines includes:
[0029] Semantically count the semantic marked storylines and the comparison storylines to obtain intersection semantic information, where the intersection semantic information is the same or approximate semantics shared by at least two different semantic marked storylines;
[0030] Conduct a statistics on the users to whom the semantic marked storylines corresponding to the intersection semantic information belong, and determine the number of associated users corresponding to each intersection semantic information;
[0031] Construct broadcast event information based on the intersection semantic information and the number of associated users.
[0032] Optionally, the step of determining whether there is a fraud risk based on the broadcast event information includes:
[0033] Extract the number of associated users from the broadcast event information;
[0034] If the number of associated users is greater than or equal to a preset risk threshold, it is determined that there is a fraud risk.
[0035] Optionally, after the step of detecting risks based on the communication semantic data and the user communication storylines to determine whether there is a fraud risk, the following steps are further included:
[0036] When there is a fraud risk, obtain the risk type;
[0037] Search for the coping strategy corresponding to the risk type in the coping strategy library;
[0038] Give a risk warning according to the coping strategy.
[0039] Optionally, the step of giving a risk warning according to the coping strategy includes:
[0040] Obtain a risk warning permission, where the risk warning permission is used to represent the warning methods allowed to be used for the current warning;
[0041] Filter the coping strategy according to the risk warning permission to determine the target coping strategy;
[0042] Give a risk warning according to the target coping strategy.
[0043] Optionally, the step of constructing a user communication storyline based on the communication semantic data and the user communication data includes:
[0044] Cluster the communication semantic data to obtain at least one clustering cluster;
[0045] Sort the user communication data corresponding to each clustering cluster in ascending order according to the corresponding communication time to obtain a user communication storyline.
[0046] In addition, to achieve the above object, the present invention also provides a risk detection device, which includes the following modules:
[0047] An extraction module, configured to perform semantic extraction on the collected user communication data to obtain communication semantic data;
[0048] A construction module, configured to construct a user communication story line based on the communication semantic data and the user communication data, where the user communication story line is a data stream constructed according to at least one communication data corresponding to the same user and the same semantics;
[0049] A detection module, configured to perform risk detection according to the communication semantic data and the user communication story line to determine whether there is a fraud risk.
[0050] Optionally, the user communication data is multimodal data;
[0051] The extraction module is further configured to perform semantic extraction on the collected user communication data through a multimodal large model to obtain communication semantic data, where the multimodal large model is a pre-trained model for performing semantic extraction on various different types of data.
[0052] Optionally, the detection module is further configured to obtain a target user identifier corresponding to the user communication story line; search for a target user portrait corresponding to the target user identifier; determine whether there is a fraud risk according to the target user portrait, the user communication story line, and the communication semantic data.
[0053] Optionally, the detection module is further configured to update the target user portrait according to the user communication story line and the communication semantic data to obtain an updated user portrait; compare the target user portrait with the updated user portrait to determine the portrait difference degree; if the portrait difference degree is greater than a preset difference threshold, it is determined that there is a fraud risk.
[0054] Optionally, the detection module is further configured to detect the user communication story line to determine whether there is a risk behavior; if there is a risk behavior, compare the target user portrait with the updated user portrait to determine the portrait difference degree.
[0055] Optionally, the detection module is further configured to mark the user communication story line according to the communication semantic data to obtain a semantic marked story line; obtain the target user corresponding to the user communication story line; search for the semantic marked story lines corresponding to other users except the target user in the story line repository to obtain comparison story lines; construct broadcast event information according to the semantic marked story line and the comparison story lines; determine whether there is a fraud risk according to the broadcast event information.
[0056] Optionally, the detection module is further configured to perform semantic statistics on the semantic marked story line and the comparison story line to obtain intersection semantic information, where the intersection semantic information is the same or approximate semantics possessed by at least two different semantic marked story lines; perform attribution user statistics on the semantic marked story lines corresponding to the intersection semantic information to determine the number of associated users corresponding to each intersection semantic information; and construct broadcast event information according to the intersection semantic information and the number of associated users.
[0057] In addition, to achieve the above object, the present invention further provides a risk detection device, where the risk detection device includes: a processor, a memory, and a risk detection program stored on the memory and executable on the processor, and when the risk detection program is executed by the processor, the steps of the above-mentioned risk detection method are implemented.
[0058] In addition, to achieve the above object, the present invention further provides a computer-readable storage medium, where a risk detection program is stored on the computer-readable storage medium, and when the risk detection program is executed, the steps of the above-mentioned risk detection method are implemented.
[0059] The present invention extracts semantics from the collected user communication data to obtain communication semantic data; constructs a user communication story line based on the communication semantic data and the user communication data, where the user communication story line is a data stream constructed according to at least one communication data corresponding to the same user and the same semantics; performs risk detection according to the communication semantic data and the user communication story line to determine whether there is a fraud risk. Since it is not based on single keyword filtering or single information analysis, but constructs a user communication story line based on the corresponding communication semantic information according to the user communication data, and performs overall behavior analysis and information statistics based on the user communication story line, and makes a more accurate analysis by connecting the user's previous and subsequent behaviors, so as to ensure that complex and changeable fraud behaviors can also be detected. BRIEF DESCRIPTION OF THE DRAWINGS
[0060] Figure 1 is a schematic structural diagram of an electronic device in the hardware operating environment related to the embodiment solution of the present invention;
[0061] Figure 2 is a schematic flowchart of the first embodiment of the risk detection method of the present invention;
[0062] Figure 3 is a schematic flowchart of the second embodiment of the risk detection method of the present invention;
[0063] Figure 4 is a schematic flowchart of the second embodiment of the risk detection method of the present invention;
[0064] Figure 5 is a schematic flowchart of the risk detection processing flow of an embodiment of the present invention;
[0065] Figure 6 This is the structural block diagram of the first embodiment of the risk detection device of the present invention.
[0066] The realization of the object, functional features and advantages of the present invention will be further described with reference to the embodiments and the accompanying drawings. Specific Embodiments
[0067] It should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention.
[0068] Refer to Figure 1 , Figure 1 This is the structural schematic diagram of the risk detection device for the hardware operating environment involved in the embodiment solution of the present invention.
[0069] As Figure 1 shown, the electronic device may include: a processor 1001, such as a Central Processing Unit (CPU), a communication bus 1002, a user interface 1003, a network interface 1004, and a memory 1005. Among them, the communication bus 1002 is used to realize the connection and communication between these components. The user interface 1003 may include a display screen (Display) and an input unit such as a keyboard (Keyboard). Optionally, the user interface 1003 may further include a standard wired interface and a wireless interface. The network interface 1004 may optionally include a standard wired interface and a wireless interface (such as a Wireless-Fidelity (WI-FI) interface). The memory 1005 may be a high-speed random access memory (Random Access Memory, RAM), or a stable non-volatile memory (Non-Volatile Memory, NVM), such as a disk memory. Optionally, the memory 1005 may also be a storage device independent of the aforementioned processor 1001.
[0070] Those skilled in the art can understand that Figure 1 the structure shown in
[0071] As Figure 1 shown, the memory 1005, as a storage medium, may include an operating system, a network communication module, a user interface module, and a risk detection program.
[0072] In Figure 1In the electronic device shown, the network interface 1004 is mainly used for data communication with a network server; the user interface 1003 is mainly used for data interaction with a user; the processor 1001 and the memory 1005 in the electronic device of the present invention can be arranged in a risk detection device. The electronic device calls a risk detection program stored in the memory 1005 through the processor 1001 and executes the risk detection method provided by the embodiments of the present invention.
[0073] Embodiments of the present invention provide a risk detection method. Refer to Figure 2 , Figure 2 which is a schematic flowchart of the first embodiment of a risk detection method of the present invention.
[0074] In this embodiment, the risk detection method includes the following steps:
[0075] Step S10: Perform semantic extraction on the collected user communication data to obtain communication semantic data.
[0076] It should be noted that the execution subject of this embodiment can be the risk detection device. The risk detection device can be an electronic device such as a personal computer or a server, or other devices that can implement the same or similar functions. This embodiment does not limit this. In this embodiment and the following embodiments, the risk detection method of the present invention is described by taking the risk detection device as an example.
[0077] It should be noted that the user communication data can be data generated when the user communicates, such as text messages, voice, multimedia messages, or chat records of specific software applications, etc. After obtaining the authorization permission of the user, the risk detection device can collect the user communication data.
[0078] In actual use, since there may be many users involved when collecting user communication data, and the amount of user communication data collected may be large. If all of it is directly processed, the processing speed may be slow, and the performance of the device may not support it either. Therefore, after collecting the user communication data, it can be stored (such as stored in a specific database or storage space), and then the risk detection device can read the stored user communication data in batches or quantitatively and process it sequentially.
[0079] In specific implementation, performing semantic extraction on the collected user communication data to obtain communication semantic data can be to perform semantic extraction on the collected user communication data through a semantic extraction algorithm (such as the TextRank algorithm, the KeyBert algorithm, or an algorithm with similar functions) or a pre-trained semantic extraction model (such as a deep learning model or a neural network model), so as to obtain communication semantic data.
[0080] Among them, the communication semantic data corresponds to the user communication data one by one. The communication semantic data may include semantic content and classification vectors for characterizing content association categories (such as classification vectors for daily necessities, luxury goods, daily-use electronic products, high-end electronic products, etc.). Of course, if necessary, other data may also be included, and this embodiment does not limit this.
[0081] In practical applications, in order to ensure that complex and changeable fraud strategies can be targeted, the user communication data collected can be multi-modal data, that is, the user communication data collected simultaneously includes various different types of data such as text (such as text messages), graphics and text (such as multimedia messages or screenshots of software chat interfaces, etc.), and voice (such as call recordings). At this time, in order to ensure that semantic extraction can be normally performed on the user communication data, step S10 described in this embodiment may include:
[0082] Performing semantic extraction on the collected user communication data through a multi-modal large model to obtain communication semantic data.
[0083] It should be noted that the multi-modal large model can be a model trained in advance according to a model training set of multi-modal data and capable of performing semantic extraction on various different types (i.e., different data types) of data. Among them, the multi-modal large model can be a model that has been partially trained in advance using transfer learning and then transferred to the semantic extraction field for further training to save model training time.
[0084] In actual use, the multi-modal large model can also be a large model composed of multiple different sub-models. The sub-model can be trained by a model training set constructed by one type of data and can perform semantic extraction on one type of user communication data. Then, when performing semantic extraction on the collected user communication data through the multi-modal large model to obtain communication semantic data, it can be to input the collected user communication data into the multi-modal large model. Then, the multi-modal large model will distribute it to the corresponding sub-model for semantic extraction processing according to the data type of the user communication data and generate communication semantic data in a unified format.
[0085] Step S20: Construct a user communication story line based on the communication semantic data and the user communication data.
[0086] It should be noted that the user communication story line can be a data stream constructed based on at least one communication data corresponding to the same semantics of the same user. For example: By constructing a data stream based on all the communication data involved in user A's purchase of daily necessity B, a user communication story line can be obtained.
[0087] Among them, the same user may correspond to multiple different semantics, that is, the same user may correspond to multiple user communication story lines.
[0088] In a specific implementation, in order to quickly construct a user communication story line, step S20 in this embodiment may include:
[0089] Clustering the communication semantic data to obtain at least one cluster;
[0090] The user communication data corresponding to each cluster is sorted from small to large according to the corresponding communication time to obtain the user communication story line.
[0091] It should be noted that clustering the communication semantic data to obtain at least one cluster may be to cluster the communication semantic data with the same classification vector and similar or identical semantic content into the same cluster, thereby obtaining at least one cluster.
[0092] It can be understood that after obtaining the clustering clusters, the user communication data corresponding to the same clustering cluster are all communication data of the same user for the same semantics (or approximate semantics). At this time, the data stream can be constructed based on it. In order to ensure accurate analysis, the user communication data corresponding to the clustering clusters can be sorted from small to large according to the corresponding communication time, and the order of occurrence of each user's communication data is clarified, thereby constructing the user communication story line.
[0093] In a specific implementation, the collected user communication data may include user communication data of multiple different users. In this case, the user communication data may be classified first to obtain the user communication data corresponding to each user, and then each user may be processed separately to obtain at least one user communication story line corresponding to each user.
[0094] Step S30: Perform risk detection based on the communication semantic data and the user communication story line to determine whether there is a fraud risk.
[0095] In actual use, risk detection is performed based on communication semantic data and user communication story lines to determine whether there is a risk of fraud. The overall behavior detection can be performed through communication semantic data and user communication story lines to determine whether the user is misled, or to detect whether there is a malicious team conducting group fraud, thereby determining whether there is a risk of fraud.
[0096] In a specific implementation, in order to ensure the security of the user's assets as much as possible, after step S30 in this embodiment, the following may also be included:
[0097] When there is a risk of fraud, obtain the risk type;
[0098] Searching for a response strategy corresponding to the risk type in a response strategy library;
[0099] Provide risk warnings based on the described response strategies.
[0100] It should be noted that according to different types of fraud, the risk types can be divided into: various different types such as telecom fraud, information induction, information simulation, etc. The risk type can be determined according to the user's behavior in the user communication storyline where fraud risk is determined to exist and the type of user communication data used to construct the user communication storyline.
[0101] For example: if the user communication data is text data, and the user's behavior is to feedback a message after receiving a message and finally send personal account information, then the risk type can be determined as information induction at this time.
[0102] It should be noted that the countermeasure library can be a database storing different countermeasures. In the countermeasure library, each risk type corresponds to at least one countermeasure.
[0103] In actual use, the countermeasure can include a processing flow for warning against fraud risks, such as: message prompt, call warning, service delay, service block, etc. Conducting risk warning according to the countermeasure can be to execute the processing flow recorded in the countermeasure to conduct risk warning.
[0104] In actual application, since there may be multiple different countermeasures for a risk type, conducting risk warning according to the countermeasure can be to execute all the processing flows corresponding to each countermeasure for warning; it can also be to select the countermeasure with the highest execution priority from the corresponding multiple countermeasures as the target countermeasure and execute the processing flow recorded in the target countermeasure for risk warning. Among them, the execution priority of each countermeasure can be pre-set by the management personnel of the risk detection device.
[0105] Furthermore, since there will actually be certain differences in the executable processing flows when the enterprise or department to which the risk detection device belongs is different, in order to ensure reasonable warning, the step of conducting risk warning according to the countermeasure in this embodiment can include:
[0106] Obtain the risk warning permission;
[0107] Screen the countermeasure according to the risk warning permission to determine the target countermeasure;
[0108] Conduct risk warning according to the target countermeasure.
[0109] It should be noted that the risk warning permission is used to represent the warning methods that are currently allowed for warning. For example, if the department to which the risk detection device belongs is an official department, then the warning methods that are allowed at this time include various prompt means such as phone calls, voices, and text messages. In this case, the risk warning permission can be "phone, voice, message"; if the department to which the risk detection device belongs is a relevant department or enterprise for asset management, then the warning methods that are allowed at this time include service interruption, text message prompts, etc. In this case, the risk warning permission can be "block, message".
[0110] In actual use, the corresponding response strategies are screened according to the risk warning permission. Determining the target response strategy can be to screen the response strategies according to the risk warning permission, filter out the partial strategies in the processing flow of the response strategies that do not conform to the risk warning permission, and use the remaining response strategies as the target response strategies.
[0111] Among them, since the target response strategy may still be multiple, therefore, the processing method when there are multiple above-mentioned strategies can also be adopted, which will not be elaborated here.
[0112] In this embodiment, semantic extraction is performed on the collected user communication data to obtain communication semantic data; a user communication story line is constructed based on the communication semantic data and the user communication data. The user communication story line is a data stream constructed according to at least one communication data corresponding to the same user and the same semantics; risk detection is performed according to the communication semantic data and the user communication story line to determine whether there is a fraud risk. Since it is not based on single keyword filtering or single information analysis, but based on the corresponding communication semantic information, a user communication story line is constructed according to the user communication data, and overall behavior analysis and information statistics are performed based on the user communication story line, and more accurate analysis is carried out by connecting the user's previous and subsequent behaviors, so as to ensure that complex and changeable fraud behaviors can also be detected.
[0113] Reference Figure 3 , Figure 3 is a schematic flowchart of the second embodiment of a risk detection method of the present invention.
[0114] Based on the above first embodiment, step S30 of the risk detection method in this embodiment includes:
[0115] Step S301: Obtain the target user identifier corresponding to the user communication story line.
[0116] It should be noted that obtaining the target user identifier corresponding to the user communication story line can be to obtain the user identifier of the user corresponding to the user communication story line, and use the obtained user identifier as the target user identifier. Among them, the user identifier can be identifier data used to uniquely identify a user, such as a mobile phone number.
[0117] Step S302: Search for the target user profile corresponding to the target user identifier.
[0118] It should be noted that searching for the target user profile corresponding to the target user identifier may be to search for the user profile corresponding to the target user identifier in the user profile library and use the found user profile as the target user profile. Among them, the target user profile is used to represent information such as the user habits and personal circumstances of the target user.
[0119] Step S303: Determine whether there is a fraud risk based on the target user profile, the user communication story line, and the communication semantic data.
[0120] In actual use, determining whether there is a fraud risk based on the target user profile, the user communication story line, and the communication semantic data may be to mark the user communication story line through the communication semantic data, extract the behavioral characteristics of the marked user communication story line, so as to obtain the user behavioral characteristics, compare the user behavioral characteristics with the target user profile, and determine whether the behavior of the user in the user communication story line conforms to the user habits and personal circumstances recorded in the target user profile. If it conforms, it is determined that there is no fraud risk; if it does not conform, it is determined that there is a fraud risk.
[0121] In actual use, there may be multiple user communication story lines. On this basis, each user communication story line can be processed separately. For example, the user communication story line corresponding to user A may correspond to four numbers 1-4. At this time, steps S301-S303 can be executed once for each of the four user communication story lines 1-4.
[0122] In a specific implementation, due to the derivation of whether it conforms to the behavior habits, there are certain subjective factors, and the probability of derivation misjudgment may be relatively high. In order to minimize misjudgment as much as possible, step S303 in this embodiment may include:
[0123] Update the target user profile according to the user communication story line and the communication semantic data to obtain an updated user profile;
[0124] Compare the target user profile with the updated user profile to determine the portrait difference degree;
[0125] If the portrait difference degree is greater than the preset difference threshold, it is determined that there is a fraud risk.
[0126] It should be noted that the portrait difference degree can be a quantitative score used to represent the difference between two user profiles. The greater the portrait difference degree, the greater the difference between the two user profiles.
[0127] In actual use, the target user profile is updated according to the user communication storyline and communication semantic data. Obtaining the updated user profile can be achieved by marking the user communication storyline with communication semantic data, extracting behavioral features from the marked user communication storyline, updating the user habits and personal circumstances recorded in the target user profile based on the extracted behavioral features, and using the updated user profile as the updated user profile.
[0128] In actual applications, a user profile can be represented by multiple different categories of tags. Comparing the target user profile with the updated user profile to determine the profile difference degree can be done by calculating the tag difference degrees of various categories in the target user profile and the updated user profile through a preset difference algorithm, and then performing a weighted average on the tag difference degrees to obtain the overall profile difference degree. Among them, the preset difference algorithm can be pre-set by the management personnel of the risk detection device, such as setting the preset difference algorithm to algorithms such as Euclidean distance and cosine similarity.
[0129] It can be understood that if the profile difference degree is greater than the preset difference threshold, it means that the user profile updated through the user communication storyline has a large difference degree from the user's previous user profile. At this time, the user may have been induced, resulting in abnormal behavior. Therefore, it can be determined that there is a fraud risk.
[0130] In a specific implementation, since the comparison of user profiles requires a large amount of computing resources, in order to reduce unnecessary resource consumption, the step of comparing the target user profile with the updated user profile to determine the profile difference degree in this embodiment may include:
[0131] Detect the user communication storyline to determine whether there are risk behaviors;
[0132] If there are risk behaviors, then compare the target user profile with the updated user profile to determine the profile difference degree.
[0133] It should be noted that risk behaviors can be related behaviors that may affect the user's assets, such as: consumption, transfer, red envelope sending, etc. behaviors; of course, behaviors such as sending personal information and sending relevant account information that may have an indirect impact on the user's assets can also be determined as risk behaviors.
[0134] It can be understood that if the user has risk behaviors, it means that the user's assets may be affected at this time. Therefore, if risk behaviors are detected when detecting the user communication storyline, the target user profile can be compared with the updated user profile to determine the profile difference degree, and based on the profile difference degree, further determine whether the user has been induced, that is, determine whether there is a fraud risk;
[0135] If the user has no risk behaviors, it means that the user's assets will basically not be affected at this time. Therefore, the subsequent steps can be skipped to reduce unnecessary performance losses and ensure that the computing resources of the device can be used for relevant users whose assets may be affected.
[0136] In this embodiment, the target user identifier corresponding to the user communication story line is obtained; the target user portrait corresponding to the target user identifier is searched; and whether there is a fraud risk is determined according to the target user portrait, the user communication story line, and the communication semantic data. Since the rationality of the behaviors extracted from the user communication story line is analyzed in combination with the user portrait of the user, it is ensured that when the user is induced and the behaviors change unreasonably, they can be detected.
[0137] Reference Figure 4 , Figure 4 is a schematic flowchart of the third embodiment of a risk detection method according to the present invention.
[0138] Based on the above first embodiment, step S30 of the risk detection method in this embodiment includes:
[0139] Step S301': Mark the user communication story line according to the communication semantic data to obtain a semantic marked story line.
[0140] It should be noted that marking the user communication story line according to the communication semantic data to obtain a semantic marked story line can be to mark the content and type of each user communication data for constructing the user communication story line according to the corresponding relationship between the communication semantic data and the user communication data, and use the marked user communication story line as the semantic marked story line.
[0141] Step S302': Obtain the target user corresponding to the user communication story line.
[0142] It should be noted that obtaining the target user corresponding to the user communication story line can be to use the user corresponding to the user communication story line as the target user.
[0143] Step S303': Search for the semantic marked story lines corresponding to other users except the target user in the story line repository to obtain comparison story lines.
[0144] It should be noted that the story line repository can be a database for storing the constructed semantic marked story lines. Searching for the semantic marked story lines corresponding to other users except the target user in the story line repository to obtain comparison story lines can be to read the semantic marked story lines corresponding to the remaining other users except the target user in the story line repository.
[0145] In actual use, since the collected user communication data may be relatively large, including user communication data of multiple different users, at different times, and of different types, therefore, during processing, it may be processed in batches. At this time, the semantic marker storylines generated during the processing will be stored in the storyline repository first, so as to facilitate subsequent horizontal comparison (that is, comparing the semantic marker storylines of different users). Therefore, after obtaining the semantic marker storyline in the current processing flow, the semantic marker storylines corresponding to other users except the target user can be searched in the storyline repository, and the found semantic marker storylines are used as comparison storylines.
[0146] In a specific implementation, since horizontal comparison requires comparing a large amount of data, the overall execution will consume a large amount of computing resources, and horizontal comparison has relatively high requirements for data comprehensiveness. Therefore, after obtaining the last batch of semantic marker storylines in the current risk detection cycle, the steps of this embodiment S303' can be executed.
[0147] For example: In the current risk detection cycle, the volume of user communication data is large. The user communication data is divided into 5 batches for detection according to different users. Then, the semantic marker storylines generated by the first 1-4 batch processes can be stored in the storyline repository. When executing the 5th batch process to obtain the semantic marker storylines generated by the 5th batch process, the steps S303' of this embodiment can be executed, so as to obtain all the semantic marker storylines generated in the current risk detection cycle.
[0148] Step S304': Construct broadcast event information according to the semantic marker storyline and the comparison storyline.
[0149] It should be noted that constructing broadcast event information according to the semantic marker storyline and the comparison storyline may be to analyze the semantic marker storyline and the comparison storyline, obtain the same or similar information received by different users, and thus generate broadcast event information.
[0150] In a specific implementation, in order to quickly construct broadcast event information, step S304' of this embodiment may include:
[0151] Perform semantic statistics on the semantic marker storyline and the comparison storyline to obtain intersection semantic information;
[0152] Perform statistics on the attributed users of the semantic marker storylines corresponding to the intersection semantic information to determine the number of associated users corresponding to each intersection semantic information;
[0153] Construct broadcast event information according to the intersection semantic information and the number of associated users.
[0154] It should be noted that the intersection semantic information may be the same or similar semantics possessed by at least two different semantically marked story lines, and the number of associated users may be the number of users whose corresponding semantically marked story lines include the intersection semantic information.
[0155] In actual use, semantic statistics are performed on the semantically marked story line and the comparison story line to obtain intersection semantic information, which can be performed by counting the frequency of occurrence of each semantic information in the semantically marked story line and the comparison story line, and the semantic information that appears in different story lines more than or equal to a preset number of times is used as intersection semantic information. The preset number can be pre-set by the manager of the risk detection device, for example, the preset number is set to 2.
[0156] In practical applications, the users belonging to the semantically marked story lines corresponding to the intersection semantic information are counted. To determine the number of associated users corresponding to the intersection semantic information, the user identifiers corresponding to the semantically marked story lines corresponding to the intersection semantic information can be added to a set, and then the set is deduplicated, and the number of user identifiers in the deduplicated set is counted, and this number is used as the number of associated users corresponding to the intersection semantic information.
[0157] For example: assuming that the intersection semantic information is A, there are 60 corresponding semantically marked story lines. After adding the user tags corresponding to the 60 semantically marked story lines to the set for deduplication, the number of remaining user identifiers is 30. At this time, the number of associated users corresponding to the intersection semantic information is 30, and the broadcast event information generated at this time is "Ms: A, times: 30".
[0158] In order to facilitate subsequent response, when determining the intersection semantic information, the sender of each information can also be obtained, and the semantic information with the same sender and a number of appearances greater than or equal to a preset number in different story lines can be used as the intersection semantic information.
[0159] Step S305': Determine whether there is a fraud risk based on the broadcast event information.
[0160] In actual use, the broadcast event information can be used to determine how many different users the semantically identical or similar information has been sent to. By comparing the information with the analysis of the fraud strategy, it can be determined whether there is a risk of fraud.
[0161] In a specific implementation, in order to avoid false alarms as much as possible, step S305' in this embodiment may include:
[0162] Extracting the number of associated users from the broadcast event information;
[0163] If the number of associated users is greater than or equal to a preset risk threshold, it is determined that there is a fraud risk.
[0164] It should be noted that the preset risk threshold can be set by the management personnel of the risk detection device after analyzing the fraud strategy. For example, assume that after the management personnel of the risk detection device analyze the fraud strategy and determine that if more than 30 different users receive the same or similar information, there is a fraud risk. At this time, the preset risk threshold can be set to 30.
[0165] It can be understood that if the number of associated users is greater than or equal to the preset risk threshold, it means that a large number of different users have received information with the same or similar intersection semantic information as that contained in the broadcast event information. At this time, it may be that a fraud team is conducting a broadcast or fishing behavior. Therefore, it can be determined that there is a fraud risk;
[0166] If the number of associated users is less than the preset risk threshold, it means that although multiple users have received information with the same or similar intersection semantic information as that contained in the broadcast event information, the number of users involved is small. At this time, it may be that some users are conducting group notification behaviors, and at this time, it can be determined that there is no fraud risk.
[0167] For the sake of easy understanding, it is now combined with Figure 5 for explanation, but it does not limit this solution. Figure 5 It is a schematic diagram of the risk detection and processing flow for this embodiment.
[0168] As Figure 5 shown, through the real-time acquisition technology of communication network raw data, the system can seamlessly access various communication networks and obtain text, voice, and picture data in real time (that is, Figure 5 various types of communication information such as SMS, MMS, and phone calls shown), and then perform semantic extraction through a multi-modal large model (which can also be called a deep semantic understanding model) to extract key features (that is, classification vectors used to represent content association categories), and at the same time cluster the user's communication information according to the corresponding semantic relevance to form a story line (that is, the above-mentioned user communication story line), and then input it into the decision tree, and conduct horizontal comparison (that is, constructing the above-mentioned broadcast event information and determining whether there is a fraud risk according to the broadcast event information) and / or vertical in-depth analysis (that is, determining whether there is a fraud risk in combination with the user portrait) in combination with the user portrait and statistical rules to determine whether there is a fraud risk. Then, according to the risk assessment result (that is, whether there is a fraud risk), combined with the response strategy library (that is, Figure 5 the knowledge graph in, which can also be called the knowledge graph strategy library) to generate corresponding processing decisions (that is, processing decisions such as release, reminder, warning, delay, and block shown in Figure 5 ).
[0169] In this embodiment, the semantic marked story line is obtained by marking the user communication story line according to the communication semantic data; the target user corresponding to the user communication story line is obtained; the semantic marked story lines corresponding to other users except the target user are searched in the story line repository to obtain comparison story lines; the broadcast event information is constructed according to the semantic marked story line and the comparison story line; and whether there is a fraud risk is determined according to the broadcast event information. Since the currently constructed semantic marked story line is horizontally compared with the semantic marked story lines of other users, and the broadcast event information is constructed to represent the situation where the same or similar information is received by different users, it is ensured that the broadcast or mass fishing fraud behavior of the fraud team can be identified.
[0170] In addition, an embodiment of the present invention further provides a storage medium, on which a risk detection program is stored, and when the risk detection program is executed by a processor, the steps of the risk detection method described above are implemented.
[0171] Refer to Figure 6 , Figure 6 which is the structural block diagram of the first embodiment of the risk detection device of the present invention.
[0172] As Figure 6 shown, the risk detection device proposed by the embodiment of the present invention includes:
[0173] An extraction module 10, configured to perform semantic extraction on the collected user communication data to obtain communication semantic data;
[0174] A construction module 20, configured to construct a user communication story line based on the communication semantic data and the user communication data, where the user communication story line is a data stream constructed according to at least one communication data corresponding to the same user and the same semantics;
[0175] A detection module 30, configured to perform risk detection according to the communication semantic data and the user communication story line to determine whether there is a fraud risk.
[0176] In this embodiment, the communication semantic data is obtained by performing semantic extraction on the collected user communication data; the user communication story line is constructed based on the communication semantic data and the user communication data, where the user communication story line is a data stream constructed according to at least one communication data corresponding to the same user and the same semantics; and risk detection is performed according to the communication semantic data and the user communication story line to determine whether there is a fraud risk. Since it is not based on single keyword filtering or single information analysis, but constructs a user communication story line based on the corresponding communication semantic information according to the user communication data, and performs overall behavior analysis and information statistics based on the user communication story line, and makes a more accurate analysis by connecting the user's previous and subsequent behaviors, so as to ensure that complex and changeable fraud behaviors can also be detected.
[0177] Further, the user communication data is multimodal data;
[0178] The extraction module 10 is further configured to perform semantic extraction on the collected user communication data through a multimodal large model to obtain communication semantic data, where the multimodal large model is a pre-trained model for performing semantic extraction on multiple different types of data.
[0179] Further, the detection module 30 is further configured to obtain a target user identifier corresponding to the user communication storyline; search for a target user profile corresponding to the target user identifier; and determine whether there is a fraud risk based on the target user profile, the user communication storyline, and the communication semantic data.
[0180] Further, the detection module 30 is further configured to update the target user profile according to the user communication storyline and the communication semantic data to obtain an updated user profile; compare the target user profile with the updated user profile to determine a profile difference degree; and if the profile difference degree is greater than a preset difference threshold, determine that there is a fraud risk.
[0181] Further, the detection module 30 is further configured to detect the user communication storyline to determine whether there is a risk behavior; and if there is a risk behavior, compare the target user profile with the updated user profile to determine a profile difference degree.
[0182] Further, the detection module 30 is further configured to mark the user communication storyline according to the communication semantic data to obtain a semantic marked storyline; obtain a target user corresponding to the user communication storyline; search for semantic marked storylines corresponding to other users except the target user in a storyline repository to obtain comparison storylines; construct broadcast event information based on the semantic marked storyline and the comparison storylines; and determine whether there is a fraud risk based on the broadcast event information.
[0183] Further, the detection module 30 is further configured to perform semantic statistics on the semantic marked storyline and the comparison storylines to obtain intersection semantic information, where the intersection semantic information is the same or approximate semantics shared by at least two different semantic marked storylines; perform attribution user statistics on the semantic marked storylines corresponding to the intersection semantic information to determine the number of associated users corresponding to each intersection semantic information; and construct broadcast event information based on the intersection semantic information and the number of associated users.
[0184] Further, the detection module 30 is further configured to extract the number of associated users from the broadcast event information; and if the number of associated users is greater than or equal to a preset risk threshold, determine that there is a fraud risk.
[0185] Furthermore, the detection module 30 is further configured to obtain the risk type when there is a fraud risk, search for the corresponding countermeasure in the countermeasure library, and give a risk warning according to the countermeasure.
[0186] Furthermore, the detection module 30 is further configured to obtain a risk warning permission, where the risk warning permission is used to characterize the warning methods allowed to be used for the current warning, screen the countermeasures according to the risk warning permission to determine the target countermeasure, and give a risk warning according to the target countermeasure.
[0187] Furthermore, the construction module 20 is further configured to cluster the communication semantic data to obtain at least one clustering cluster, and sort the user communication data corresponding to each clustering cluster in ascending order of the corresponding communication time to obtain a user communication story line.
[0188] It should be understood that the above is only an example, and does not constitute any limitation to the technical solution of the present invention. In specific applications, those skilled in the art can set according to needs, and the present invention does not limit this.
[0189] It should be noted that the above-described work process is only illustrative and does not limit the protection scope of the present invention. In actual applications, those skilled in the art can select some or all of them according to actual needs to achieve the purpose of the solution of this embodiment, and there is no limitation here.
[0190] In addition, for the technical details not described in detail in this embodiment, reference can be made to the risk detection method provided in any embodiment of the present invention, which will not be elaborated here.
[0191] In addition, it should be noted that in this article, the terms "include", "comprise" or any other variant thereof are intended to cover non-exclusive inclusion, so that a process, method, article or system including a series of elements not only includes those elements, but also includes other elements not expressly listed, or further includes elements inherent to such process, method, article or system. Without further limitation, an element defined by the statement "including a..." does not exclude the existence of another identical element in the process, method, article or system including the element.
[0192] The serial numbers of the above embodiments of the present invention are only for description and do not represent the advantages and disadvantages of the embodiments.
[0193] Through the description of the above embodiments, those skilled in the art can clearly understand that the above embodiment methods can be implemented by means of software plus a necessary general hardware platform. Of course, they can also be implemented by hardware, but in many cases, the former is a better implementation method. Based on such an understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as a read-only memory (ROM) / RAM, magnetic disk, optical disc), and includes several instructions for causing a terminal device (which can be a mobile phone, computer, server, or network device, etc.) to execute the methods described in various embodiments of the present invention.
[0194] The above are only the preferred embodiments of the present invention, and do not limit the patent scope of the present invention. Any equivalent structure or equivalent process transformation made by using the content of the specification and drawings of the present invention, or directly or indirectly applied in other related technical fields, shall be equally included in the patent protection scope of the present invention.
[0195] The present invention discloses A1. A risk detection method, the risk detection method comprising the following steps:
[0196] Perform semantic extraction on the collected user communication data to obtain communication semantic data;
[0197] Construct a user communication story line based on the communication semantic data and the user communication data, where the user communication story line is a data stream constructed according to at least one communication data corresponding to the same user and the same semantics;
[0198] Perform risk detection according to the communication semantic data and the user communication story line to determine whether there is a fraud risk.
[0199] A2. The risk detection method as described in A1, where the user communication data is multi-modal data;
[0200] The step of performing semantic extraction on the collected user communication data to obtain communication semantic data includes:
[0201] Perform semantic extraction on the collected user communication data through a multi-modal large model to obtain communication semantic data, where the multi-modal large model is a pre-trained model for performing semantic extraction on various different types of data.
[0202] A3. The risk detection method as described in A1, where the step of performing risk detection according to the communication semantic data and the user communication story line to determine whether there is a fraud risk includes:
[0203] Obtain the target user identifier corresponding to the user communication story line;
[0204] Search for the target user profile corresponding to the target user identifier;
[0205] Determine whether there is a fraud risk based on the target user profile, the user communication storyline, and the communication semantic data.
[0206] A4. The risk detection method as described in A3, the step of determining whether there is a fraud risk according to the target user profile, the user communication storyline, and the communication semantic data includes:
[0207] Update the target user profile according to the user communication storyline and the communication semantic data to obtain an updated user profile;
[0208] Compare the target user profile with the updated user profile to determine the profile difference degree;
[0209] If the profile difference degree is greater than a preset difference threshold, it is determined that there is a fraud risk.
[0210] A5. The risk detection method as described in A4, the step of comparing the target user profile with the updated user profile to determine the profile difference degree includes:
[0211] Detect the user communication storyline to determine whether there are risk behaviors;
[0212] If there are risk behaviors, compare the target user profile with the updated user profile to determine the profile difference degree.
[0213] A6. The risk detection method as described in A1, the step of performing risk detection according to the communication semantic data and the user communication storyline to determine whether there is a fraud risk includes:
[0214] Mark the user communication storyline according to the communication semantic data to obtain a semantic marked storyline;
[0215] Obtain the target user corresponding to the user communication storyline;
[0216] Search for the semantic marked storylines corresponding to other users except the target user in the storyline repository to obtain comparison storylines;
[0217] Construct broadcast event information according to the semantic marked storyline and the comparison storylines;
[0218] Determine whether there is a fraud risk according to the broadcast event information.
[0219] A7. The risk detection method as described in A6, the step of constructing broadcast event information according to the semantic marked story line and the comparison story line includes:
[0220] Perform semantic statistics on the semantic marked story line and the comparison story line to obtain intersection semantic information, where the intersection semantic information is the same or approximate semantics possessed by at least two different semantic marked story lines;
[0221] Perform a statistics on the users to whom the semantic marked story lines corresponding to the intersection semantic information belong, and determine the number of associated users corresponding to each intersection semantic information;
[0222] Construct broadcast event information according to the intersection semantic information and the number of associated users.
[0223] A8. The risk detection method as described in A6, the step of determining whether there is a fraud risk according to the broadcast event information includes:
[0224] Extract the number of associated users from the broadcast event information;
[0225] If the number of associated users is greater than or equal to a preset risk threshold, it is determined that there is a fraud risk.
[0226] A9. The risk detection method as described in A1, after the step of performing risk detection according to the communication semantic data and the user communication story line to determine whether there is a fraud risk, further includes:
[0227] When there is a fraud risk, obtain the risk type;
[0228] Search for the coping strategy corresponding to the risk type in the coping strategy library;
[0229] Perform a risk warning according to the coping strategy.
[0230] A10. The risk detection method as described in A9, the step of performing a risk warning according to the coping strategy includes:
[0231] Obtain a risk warning permission, where the risk warning permission is used to represent the warning methods allowed to be used for the current warning;
[0232] Filter the coping strategy according to the risk warning permission to determine the target coping strategy;
[0233] Perform a risk warning according to the target coping strategy.
[0234] A11. The risk detection method as described in any one of A1 - A10, the step of constructing a user communication story line based on the communication semantic data and the user communication data includes:
[0235] Cluster the communication semantic data to obtain at least one cluster.
[0236] Sort the user communication data corresponding to each cluster in ascending order of the corresponding communication time to obtain a user communication storyline.
[0237] The present invention also discloses B12, a risk detection device, which includes the following modules:
[0238] An extraction module, configured to perform semantic extraction on the collected user communication data to obtain communication semantic data.
[0239] A construction module, configured to construct a user communication storyline based on the communication semantic data and the user communication data, where the user communication storyline is a data stream constructed according to at least one communication data corresponding to the same user and the same semantics.
[0240] A detection module, configured to perform risk detection based on the communication semantic data and the user communication storyline to determine whether there is a fraud risk.
[0241] B13. The risk detection device as described in B12, where the user communication data is multi-modal data.
[0242] The extraction module is further configured to perform semantic extraction on the collected user communication data through a multi-modal large model to obtain communication semantic data, where the multi-modal large model is a pre-trained model for performing semantic extraction on various different types of data.
[0243] B14. The risk detection device as described in B12, where the detection module is further configured to obtain a target user identifier corresponding to the user communication storyline; search for a target user portrait corresponding to the target user identifier; and determine whether there is a fraud risk according to the target user portrait, the user communication storyline, and the communication semantic data.
[0244] B15. The risk detection device as described in B14, where the detection module is further configured to update the target user portrait according to the user communication storyline and the communication semantic data to obtain an updated user portrait; compare the target user portrait with the updated user portrait to determine the portrait difference degree; if the portrait difference degree is greater than a preset difference threshold, it is determined that there is a fraud risk.
[0245] B16. The risk detection device as described in B14, where the detection module is further configured to detect the user communication storyline to determine whether there is a risk behavior; if there is a risk behavior, compare the target user portrait with the updated user portrait to determine the portrait difference degree.
[0246] B17. The risk detection device as described in B12, wherein the detection module is further configured to mark the user communication story line according to the communication semantic data to obtain a semantic marked story line; obtain the target user corresponding to the user communication story line; search for the semantic marked story lines corresponding to other users except the target user in the story line repository to obtain comparison story lines; construct broadcast event information according to the semantic marked story line and the comparison story lines; and determine whether there is a fraud risk according to the broadcast event information.
[0247] B18. The risk detection device as described in B17, wherein the detection module is further configured to perform semantic statistics on the semantic marked story line and the comparison story lines to obtain intersection semantic information, where the intersection semantic information is the same or approximate semantics possessed by at least two different semantic marked story lines; perform attribution user statistics on the semantic marked story lines corresponding to the intersection semantic information to determine the number of associated users corresponding to each intersection semantic information; and construct broadcast event information according to the intersection semantic information and the number of associated users.
[0248] The present invention also discloses C19. A risk detection device, the risk detection device includes: a processor, a memory, and a risk detection program stored on the memory and executable on the processor, and when the risk detection program is executed by the processor, the steps of the risk detection method as described above are implemented.
[0249] The present invention also discloses D20. A computer-readable storage medium, on which a risk detection program is stored, and when the risk detection program is executed, the steps of the risk detection method as described above are implemented.
Claims
1. A risk detection method, characterized in that, the risk detection method includes the following steps: Performing semantic extraction on the collected user communication data to obtain communication semantic data; Constructing a user communication story line based on the communication semantic data and the user communication data, where the user communication story line is a data stream constructed according to at least one communication data corresponding to the same user and the same semantics; Performing risk detection according to the communication semantic data and the user communication story line to determine whether there is a fraud risk.
2. The risk detection method according to claim 1, characterized in that, the user communication data is multi-modal data; The step of performing semantic extraction on the collected user communication data to obtain communication semantic data includes: Performing semantic extraction on the collected user communication data through a multi-modal large model to obtain communication semantic data, where the multi-modal large model is a pre-trained model for performing semantic extraction on multiple different types of data.
3. The risk detection method according to claim 1, characterized in that, The step of performing risk detection according to the communication semantic data and the user communication story line to determine whether there is a fraud risk includes: Obtaining the target user identifier corresponding to the user communication story line; Searching for the target user portrait corresponding to the target user identifier; Determining whether there is a fraud risk according to the target user portrait, the user communication story line and the communication semantic data.
4. The risk detection method according to claim 3, characterized in that, The step of determining whether there is a fraud risk according to the target user portrait, the user communication story line and the communication semantic data includes: Updating the target user portrait according to the user communication story line and the communication semantic data to obtain an updated user portrait; Comparing the target user portrait with the updated user portrait to determine the portrait difference degree; If the portrait difference degree is greater than a preset difference threshold, it is determined that there is a fraud risk.
5. The risk detection method according to claim 4, characterized in that, The step of comparing the target user portrait with the updated user portrait to determine the portrait difference degree includes: Detecting the user communication story line to determine whether there is a risk behavior; If there is a risk behavior, comparing the target user portrait with the updated user portrait to determine the portrait difference degree.
6. The risk detection method according to claim 1, characterized in that, The step of performing risk detection according to the communication semantic data and the user communication story line to determine whether there is a fraud risk includes: Marking the user communication story line according to the communication semantic data to obtain a semantic marked story line; Obtaining the target user corresponding to the user communication story line; Searching for the semantic marked story lines corresponding to other users except the target user in the story line repository to obtain comparison story lines; Constructing broadcast event information according to the semantic marked story line and the comparison story line; Determining whether there is a fraud risk according to the broadcast event information.
7. The risk detection method according to claim 6, characterized in that, The step of constructing broadcast event information according to the semantic marked story line and the comparison story line includes: Performing semantic statistics on the semantic marked story line and the comparison story line to obtain intersection semantic information, where the intersection semantic information is the same or approximate semantics possessed by at least two different semantic marked story lines; Performing attribution user statistics on the semantic marked story lines corresponding to the intersection semantic information to determine the number of associated users corresponding to each intersection semantic information; Constructing broadcast event information according to the intersection semantic information and the number of associated users.
8. A risk detection device Characterized in that The risk detection device includes the following modules: An extraction module for performing semantic extraction on the collected user communication data to obtain communication semantic data; A construction module for constructing a user communication story line based on the communication semantic data and the user communication data, where the user communication story line is a data stream constructed according to at least one communication data corresponding to the same user and the same semantics; A detection module for performing risk detection according to the communication semantic data and the user communication story line to determine whether there is a fraud risk.
9. A risk detection device Characterized in that The risk detection device includes: a processor, a memory, and a risk detection program stored on the memory and executable on the processor, and when the risk detection program is executed by the processor, the steps of the risk detection method described in any one of claims 1-7 are implemented.
10. A computer-readable storage medium Characterized in that A risk detection program is stored on the computer-readable storage medium, and when the risk detection program is executed, the steps of the risk detection method described in any one of claims 1-7 are implemented.
Citation Information
Patent Citations
Method and system for real-time detection of communication fraud base on suspicious behavior recognition
CN107222865A
The invention relates to a transaction security control method and a system based on subject portrait
CN109509093A
The invention discloses a tTelecommunication fraud event detection method and system
CN109615116A
Method and device for identifying communication information fraud
CN110839216A
Massive fraud short message detection method and device, server and storage medium
CN111083705A