Method for detecting fraudulent users in marketplace system

By generating user graphs in the O2O market system and using graph convolutional neural network to detect fraudulent users, the problem of fraud detection in the O2O market is solved and higher detection accuracy and reliability are achieved.

CN120129918APending Publication Date: 2025-06-10GRABTAXI HOLDINGS PTE LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202380074905.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2022-11-01
Filing Date
2023-09-29
Publication Date
2025-06-10

AI Technical Summary

Technical Problem

There are challenges in detecting fraud in the O2O market, especially in online to offline systems, and it is difficult for the prior art to effectively identify and prevent various types of fraud activities.

Method used

By generating a graph, the user is represented as a node in the graph, and the nodes are connected by edges. If two users use the same market system elements, the nodes are associated with the feature set, which includes user behavior information and subgraph structure information of the graph. Then, the graph is processed using a graph convolution neural network, and the scores of each node are generated to detect fraudulent users.

Benefits of technology

This method can effectively identify and detect fraudulent users in the O2O market, and improve the accuracy and reliability of fraud detection by combining user behavior information and graph structure information.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120129918A_ABST
    Figure CN120129918A_ABST
Patent Text Reader

Abstract

Aspects relate to a method for detecting fraudulent users in a marketplace system, the method comprising: generating a graph in which users are represented as nodes in the graph, and if a user represented by one node has used at least one marketplace system element that is also used by a user represented by another node in the marketplace system, connecting the two nodes by an edge, and each node being associated with a feature set, the feature set comprises information about behaviors of the user represented by the node in the market system and structure information about a sub-graph of the graph to which the node belongs; processing the graph by a graph convolutional neural network, the graph convolutional neural network configured to generate a score for each node in the graph; and detecting one or more fraudulent users using the scores.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Aspects of the present disclosure relate to methods for detecting fraudulent users in a marketplace system. Background Art

[0002] Due to the increasing popularity of online-to-offline (O2O) marketplaces globally, such as ride-hailing, food delivery, etc., detecting fraud in O2O marketplaces has become increasingly important. Different from e-commerce platforms or social media platforms that only use online channels, O2O services use both online and offline channels to acquire users and execute transactions. For example, a user orders food online and a delivery person needs to deliver the food to the user's location offline.

[0003] Detecting fraud in O2O marketplaces is challenging because there are many different types of fraudulent activities in O2O marketplaces. For example, some fraudsters create many fake accounts to abuse promotional codes, while some fraudsters use offline channels (e.g., collude with merchants or delivery persons) to conduct fraudulent transactions, which are significantly different from fraudulent activities in online services such as e-commerce services.

[0004] Therefore, effective methods for detecting fraud in O2O marketplaces are desired. Summary of the Invention

[0005] Various embodiments relate to a method for detecting fraudulent users in a marketplace system, the method comprising: generating a graph, wherein users are represented as multiple nodes in the graph, and two nodes are connected by an edge if a user represented by one of the multiple nodes has used at least one marketplace system element that has also been used by a user represented by another of the multiple nodes in the marketplace system, and each node is associated with a feature set that includes information about the behavior of the user represented by the node in the marketplace system and information about the structure of a subgraph of the graph to which the node belongs; processing the graph by a graph convolutional neural network configured to generate a score for each node in the graph; and using the scores to detect one or more fraudulent users.

[0006] According to one embodiment, the information about the structure of the subgraph of the graph to which the node belongs includes information about how the node is connected to other nodes in the graph.

[0007] According to one embodiment, the information about the structure of the subgraph of the graph to which the node belongs includes at least one of the number of other nodes connected to the node (i.e., the count), information about how densely the node is connected to other nodes, and the number of nodes in the subgraph (i.e., the count), wherein the subgraph is the largest connected subgraph of the graph to which the node belongs.

[0008] According to one embodiment, the information about the user's behavior includes: information indicating the user's integrity.

[0009] According to one embodiment, the market system is an online-to-offline market system.

[0010] According to one embodiment, the market system element is an online channel or an offline channel of the online-to-offline market system.

[0011] According to one embodiment, the market system element is a user device, an Internet protocol address, a merchant, a delivery person, or a vehicle.

[0012] According to one embodiment, the graph convolutional neural network is configured to generate an embedding for each node, and the graph convolutional neural network is configured to generate a score for each node based on the embedding of the node.

[0013] According to one embodiment, the information about the user's behavior includes one or more of the following: the age of the user's account in the market system, the number of orders placed by the user in the market system, the proportion of promotional orders among the orders placed by the user in the market system, the average order value of the user in the market system, the time since the user last logged in to the market system, the time since the user last placed an order in the market system, the total profit of the user in the market system.

[0014] According to one embodiment, the method includes: using the score to detect one or more fraudulent users by: if the score of the node is within a predetermined range, detecting the user as a fraudulent user.

[0015] According to one embodiment, the method includes: training the graph convolutional neural network by semi-supervised training using a labeled training dataset including labels indicating fraudulent users. The training is completed before using the graph convolutional neural network for detecting fraudulent users.

[0016] According to one embodiment, the method includes: if the user is detected as a fraudulent user, activating security measures for the user.

[0017] According to one embodiment, a computer program element is provided, which includes program instructions that, when executed by one or more processors, cause the one or more processors to execute the above method for detecting fraudulent users in a market system.

[0018] According to one embodiment, a computer-readable medium is provided, which includes program instructions that, when executed by one or more processors, cause the one or more processors to execute the above method for detecting fraudulent users in a market system. BRIEF DESCRIPTION OF THE DRAWINGS

[0019] The present invention will be better understood with reference to the detailed description when considered in conjunction with the non - limiting examples and the drawings, in which:

[0020] - Figure 1 Shows a communication layout including a smart phone and a server.

[0021] - Figure 2 Shows a diagram illustrating a data processing flow (e.g., executed by the server) for fraud detection according to an embodiment.

[0022] - Figure 3 Shows an example of an O2O diagram.

[0023] - Figure 4 Shows the processing of an input diagram by a machine learning model.

[0024] - Figure 5 Shows a flowchart illustrating a method for detecting fraudulent users in a market system.

[0025] - Figure 6 Shows a server computer system according to an embodiment. DETAILED DESCRIPTION

[0026] The following detailed description refers to the drawings, which illustrate by way of illustration specific details and embodiments in which the present disclosure may be practiced. The embodiments are described in sufficient detail to enable those skilled in the art to practice the present disclosure. Without departing from the scope of the present disclosure, other embodiments may be utilized and structural and logical changes may be made. The various embodiments are not necessarily mutually exclusive, as some embodiments may be combined with one or more other embodiments to form new embodiments.

[0027] Embodiments described in the context of one of these devices or methods are similarly effective for other devices or methods. Similarly, embodiments described in the context of a device are similarly effective for a vehicle or a method, and vice versa.

[0028] Features described in the context of an embodiment may correspondingly apply to the same or similar features in other embodiments. Features described in the context of an embodiment may correspondingly apply to other embodiments even if not explicitly described in those other embodiments. Additionally, additions and / or combinations and / or substitutions as described for features in the context of an embodiment may correspondingly apply to the same or similar features in other embodiments.

[0029] In the context of the various embodiments, the articles "a", "an", and "the" as used with respect to a feature or element include references to one or more of these features or elements.

[0030] As used herein, the term "and / or" includes any and all combinations of one or more of the associated listed items.

[0031] In the following, embodiments will be described in detail.

[0032] Figure 1 A communication layout including a smartphone 100 and a server (computer) 106 is shown.

[0033] The smartphone 100 has a screen showing a graphical user interface (GUI) of applications for one or more of various services that a user of the smartphone has previously installed on their smartphone and has opened (i.e., activated) to use services (e.g., order food), such as ordering food or hailing a ride online.

[0034] The GUI 101 includes graphical user interface elements 102, 103 to assist the user in using the service, such as a map near the user's location, food available near the user (e.g., the application can determine based on location services (e.g., GPS-based location services)), buttons for placing an order, etc.

[0035] When the user has made a selection for a service (e.g., selected a restaurant or an online supermarket and / or selected the food or groceries to order), the application communicates with the server 106 of the corresponding service via a radio connection. The server 106 (executing the corresponding server program by means of the processor 107) can consult the memory 109 or the data storage device 108 having information about the service (e.g., price, availability, estimated delivery time, etc.). The server transmits any data related to or requested by the user (such as the estimated delivery time) back to the smartphone 100, and the smartphone 100 displays this information on the GUI 101. Finally, the user can accept the service, e.g., order food. In this case, the server 106 accordingly notifies the service provider 104, e.g., a restaurant or an online supermarket. The server 106 can also communicate with the service provider 104 earlier, e.g., to determine the estimated delivery time.

[0036] It should be noted that although the server 106 is described as a single server, its functions (e.g., for providing certain services and advertising data) will typically be provided by a layout of multiple server computers (e.g., implementing cloud services) in practical applications. Therefore, the functions provided by the server (e.g., the server 106) described below can be understood to be provided by a layout of multiple servers or multiple server computers.

[0037] The communication layout 100 can be regarded as implementing an online-to-offline (O2O) market (and thus as an O2O market platform) because they have online elements, such as the online information provided by the server 106 for the smartphone to retrieve from the server 106, and offline elements, such as the delivery personnel who deliver the ordered food. In other words, there is an online channel (specifically for transmitting information, such as for providing food ordering services) and an offline channel (here for the actual delivery of food).

[0038] According to various embodiments, there are provided methods for solving fraud problems in such O2O markets by considering the correlations among different fraudsters operating in the market (or on the platform), such as fraud users who may both engage in promotion abuse and collude with merchants (i.e., the user and the merchant are related fraudsters). The method can be applied to many different types of fraud activities, such as promotion abuse, non-cash payments, customer-merchant collusion, etc., thus providing a sustainable framework for fraud detection in O2O markets.

[0039] The server 106 can store information about the interactions between parties (in this example, the transactions between a user like the user of the smartphone 100 and a service provider like the service provider 104) in the data storage device 108 for analysis. For example, food ordering and grocery transactions, as well as online car-hailing trips (since the passenger pays for the trip, which can also be regarded as corresponding to a transaction), form the interactions between customers and merchants (usually including service providers such as delivery personnel).

[0040] According to various embodiments, graphs are used to explicitly model different types of user interactions in the O2O market. Specifically, various embodiments include the following operations:

[0041] 1. Identify and collect various online and offline user interaction data in the O2O market.

[0042] 2. Construct an O2O graph that explicitly models user interactions from online and offline channels in the O2O market. For example, if two users share the same device (online channel) or the same merchant (offline channel), etc., then connect these two users on the graph.

[0043] 3. Based on the graph structure information and domain knowledge, design graph node features. The graph structure information reflects how users are connected to other users, and the domain knowledge reflects the integrity of the users themselves.

[0044] 4. Utilize the graph convolution algorithm to implement automated fraud detection on the O2O graph.

[0045] Figure 2 FIG. 200 shows a diagram illustrating a data processing flow for fraud detection according to an embodiment (e.g., executed by the server 106).

[0046] The data processing flow includes data processing 201 from the registration data stream, the device data stream, and the order data stream, as well as the construction 202 of an O2O graph using the collected data.

[0047] In addition, the data processing flow includes feature calculation 203, where, for each node in the graph, features are calculated using the graph structure information and domain knowledge. The data processing flow also includes training 204 a machine learning model (including a graph convolutional neural network) using the constructed graph (including the calculated graph node features) and saving the trained model to a model storage device (model library) 205. It should be noted that the model can be trained or retrained using other similarly created graphs.

[0048] Then, the trained model can be used for inference in the model service phase 206. This includes loading the model parameters (i.e., especially the neural network weights) of the trained model from the model library 205 and running inference on a graph created for the scenario where fraud should be detected (similar to the graph used for training the model). The model outputs a model prediction score, which is used for fraud detection 207 in the O2O market (e.g., the model prediction score indicates the likelihood that the associated user (e.g., the user represented by the graph node associated with this model prediction score) commits fraud).

[0049] For Figure 2 the components and data in the data processing flow are described in more detail below. Table 1 describes the data collected in data collection 201 for specific events.

[0050]

[0051]

[0052] Table 1

[0053] This data collected for registration events, order events, and device events respectively forms the data collected from the registration data stream, the order data stream, and the device data stream. Therefore,

[0054] · When a new account is created on the platform, data collection for the registration data stream is triggered, and the user ID and IP address are collected.

[0055] · When a new order is placed, data collection for the order data stream is triggered, and the user ID, merchant ID, delivery person ID, and delivery location are collected.

[0056] · When the user launches the application, data collection for the device data stream is triggered, and the user ID, IP address, and device ID are collected.

[0057] The collected data is used to construct an O2O graph.

[0058] Figure 3 An example of the O2O graph 300 is shown.

[0059] The nodes in the graph correspond to users. If the users corresponding to the nodes have a specific type of similarity, then the graph has edges between the nodes. For example, if the corresponding users share the same IP address or the same device (online channel) when registering and / or using the application (as known from the registration data stream and the device data stream), then the two nodes are connected. If the users have ordered from the same merchant or have traveled to the same location (offline channel; as known from the order data stream), then these users are also connected.

[0060] Table 2 gives examples of the features calculated for the nodes in the graph in Feature Calculation 203.

[0061]

[0062]

[0063] Table 2

[0064] The graph structure features of the nodes are determined from the graph structure information and reflect how the users corresponding to the nodes are connected to other users (i.e., how the nodes corresponding to the users are connected in the graph), for example, the density and size of the clusters on the graph. Fraudulent users are more likely to form dense clusters on the graph because they need to reduce costs and share physical resources such as devices, IPs, locations, etc. The clustering coefficient specifies the density of the cluster (which is meaningful for clusters with more than two nodes). For example, a cluster has four nodes (A, B, C, D), so the maximum number of connections is A - B, A - C, A - D, B - C, B - D, C - D. With all these connections, the cluster has the maximum density (i.e., the maximum clustering coefficient). When one or more of these connections are missing, for example, only A - B, B - C, C - D exist, the cluster is less dense, and thus, its clustering coefficient is smaller.

[0065] The domain knowledge features of the nodes are determined from domain knowledge and reflect the account integrity of the users corresponding to the nodes. Fraudulent users are more likely to be new accounts with less activity and zero or negative profit.

[0066] Figure 4 The processing of the input graph 401 (corresponding to the constructed graph with calculated node features) by the machine learning model is shown.

[0067] The input graph 401 is passed through a number of (graph) convolutional layers 402, where the features of each node are propagated to its neighbors to update the features of these neighbors. After the convolutional layer 402, similar (updated) node features will be produced for nodes that are tightly connected (i.e., directly connected or connected via a small number of intermediate nodes).

[0068] Thereafter, for each node on the graph, an embedding 403 is calculated based on the (updated) node features. An example of a function applied to the updated node features to calculate the node embedding is the rectified linear activation function (ReLU).

[0069] Finally, based on the node embeddings, a fraud score 404 is calculated for each node. An example of a function applied to the node embeddings to calculate the node score is the Softmax function.

[0070] For example, the node score is a value in the interval [0, 1], which indicates the likelihood that the user corresponding to this user is a fraudulent user (or, in other words, the prediction of the model for this likelihood).

[0071] In 204, one or more constructed graphs are used to train the model. These graphs are partially labeled, i.e., some users (and thus nodes) are labeled as fraudulent or non-fraudulent. Then, the model can be trained in a semi-supervised manner (to achieve a high node score for nodes labeled as fraudulent). One or more constructed graphs for training can include a large number of nodes (e.g., 1.5 million nodes) and edges (e.g., 1.4 million edges), where only a small portion (e.g., 4%) of the nodes are labeled as fraudulent or non-fraudulent (true). It should be noted that according to an embodiment, since the training is semi-supervised, only some of the nodes in the training data require labels. Then, the trained model is saved to the model storage device 205.

[0072] In the model serving phase (i.e., inference), a graph is constructed based on the most recent data of the data stream, and the trained model from the model storage device 205 is used to run inference on the graph. The predicted model scores are used for fraud detection in the O2O market. For example, the server 106 or its operator can respond to a high value of a user. For example, if the node score exceeds a predetermined threshold (such as 0.8) (or equivalently, is within a predetermined ("fraud indication") range considered to indicate a fraudulent user), an investigation of the user is initiated to check whether the user is committing or has committed fraud.

[0073] According to one embodiment, as Figure 5 shown, a method is provided.

[0074] Figure 5 A flowchart showing a method for detecting fraudulent users in a market system is shown.

[0075] At 501, a graph (in the sense of mathematical graph theory) is created, where users are represented as multiple nodes in the graph, and if a user represented by one of the multiple nodes has used at least one market system element that has also been used by a user represented by another of the multiple nodes in the market system (e.g., in a predetermined set of market system elements defined for determining whether two nodes should be connected by an edge), then the two nodes are connected by an edge, and each node is associated with a feature set that includes information about the behavior of the user represented by the node in the market system and information about the structure of the subgraph of the graph to which the node belongs.

[0076] At 502, the graph is processed by a graph convolutional neural network configured to generate a score for each node in the graph.

[0077] At 503, the score is used to detect one or more fraudulent users.

[0078] According to various embodiments, in other words, fraudulent users are detected by combining behavioral information between users having a specific relationship (which information may indicate fraudulent behavior), where this specific relationship is that they have used similar elements in the market system (especially online and offline channels in an O2O market system).

[0079] The graph convolutional neural network is used to generate a score (e.g., via an embedding generated according to the features of the nodes through graph convolutional operations such as message passing between nodes), and based on the generated (i.e., computed) score, fraudulent users are detected.

[0080] For example, the method may include training the graph convolutional neural network by semi - supervised training using a training data set in which fraudulent users are labeled. For example, the training data set can be generated from historical data in which fraudulent users have been detected by other means; or generated by experts (possibly through simulation), e.g., using specific fraud scenarios to create a training data set for fraudulent users.

[0081] For example, Figure 5 The method is executed by a server computer system as shown in Figure 6 FIG.

[0082] Figure 6 FIG. 600 shows a server computer system 600 according to an embodiment.

[0083] The server computer system 600 includes a communication interface 601 (e.g., the communication interface is configured to receive data regarding demand and supply). The server computer system 600 also includes a processing unit 602 and a memory 603. The memory 603 can be used by the processing unit 602 to store, for example, data to be processed, such as information regarding demand and supply. The server computer system is configured to execute Figure 5 the method of.

[0084] The methods described herein can be executed and the various processing or computing units and devices and computing entities described herein can be implemented by one or more circuits. In an embodiment, "circuit" can be understood as any kind of logical implementation entity, which can be hardware, software, firmware, or any combination of hardware, software, and firmware. Thus, in an embodiment, "circuit" can be hard-wired logic circuitry or programmable logic circuitry such as a programmable processor, e.g., a microprocessor. For example, "circuit" can also be software implemented or executed by a processor, e.g., any kind of computer program (e.g., a computer program using virtual machine code). According to an alternative embodiment, any other kind of implementation of the various functions described herein can also be understood as "circuit".

[0085] Although the present disclosure has been specifically shown and described with reference to specific embodiments, those skilled in the art should understand that various changes in form and detail may be made therein without departing from the spirit and scope of the invention as defined by the appended claims. Accordingly, the scope of the invention is defined by the appended claims and all changes within the meaning and equivalents of the claims are intended to be embraced therein.

Claims

1. A method for detecting fraudulent users in a market system, the method comprises: generating a graph, wherein users are represented as nodes in the graph, and if a user represented by one of the nodes has used at least one market system element that has also been used by another user represented by another node in the market system, then the two nodes are connected by an edge, and each node is associated with a feature set, the feature set including information about the behavior of the user represented by the node in the market system and structural information about the subgraph of the graph to which the node belongs; processing the graph by a graph convolutional neural network, the graph convolutional neural network being configured to generate a score for each node in the graph; and using the scores to detect one or more of the fraudulent users.

2. The method according to claim 1, wherein, the structural information about the subgraph of the graph to which the node belongs includes: information about how the node is connected to other nodes in the graph.

3. The method according to claim 1 or 2, wherein, the structural information about the subgraph of the graph to which the node belongs includes at least one of: the number of other nodes connected to the node, information about how densely the node is connected to the other nodes, and the number of nodes in the subgraph, wherein the subgraph is the largest connected subgraph of the graph to which the node belongs.

4. The method according to any one of claims 1 to 3, wherein, the information about the behavior of the user includes: information indicating the integrity of the user.

5. The method according to any one of claims 1 to 4, wherein, the market system is an online-to-offline market system.

6. The method according to claim 5, wherein, the market system elements are the online channels of the online-to-offline market system or the offline channels of the online-to-offline market system.

7. The method according to any one of claims 1 to 6, wherein, the market system elements are user devices, Internet protocol addresses, merchants, deliverymen, or vehicles.

8. The method according to any one of claims 1 to 7, wherein, the graph convolutional neural network is configured to generate an embedding for each node, and the graph convolutional neural network is configured to generate the score for each node based on the embedding of the node.

9. The method according to any one of claims 1 to 8, wherein, the information about the behavior of the user includes one or more of the following: the account age of the user in the market system, the number of orders placed by the user in the market system, the proportion of promotional orders among the orders placed by the user in the market system, the average order value of the user in the market system, the time since the user last logged in to the market system, the time since the user last placed an order in the market system, the total profit of the user in the market system.

10. The method according to any one of claims 1 to 9, comprising: using the score to detect one or more of the fraudulent users by: if the score of the node is within a predetermined range, detecting the user as the fraudulent user.

11. The method according to any one of claims 1 to 10, comprising: if the user is detected as the fraudulent user, activating a security measure for the user.

12. The method according to any one of claims 1 to 11, comprising: training the graph convolutional neural network by semi-supervised training using a labeled training dataset including labels indicating the fraudulent users.

13. A server computer system comprising a radio interface, a memory interface, and a processing unit, the processing unit being configured to execute the method according to any one of claims 1 to 12.

14. A computer program element comprising program instructions which, when executed by one or more processors, cause the one or more processors to execute the method according to any one of claims 1 to 12.

15. A computer-readable medium comprising program instructions which, when executed by one or more processors, cause the one or more processors to execute the method according to any one of claims 1 to 12.