IC Card Transaction Security Processing Method and System Based on Mobile Terminal System
By obtaining the historical transaction data of IC cards on the mobile terminal, extracting features and using pre-trained models for risk prediction and dynamic strategy generation, the problem of dynamic adjustment and insufficient risk identification of existing IC card transaction security processing technology is solved, and intelligent security optimization and continuous protection are achieved.
Patent Information
- Application Number
- CN202510632042.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-16
- Publication Date
- 2025-07-22
- Estimated Expiration
- 2045-05-16
AI Technical Summary
The existing IC card transaction security processing technology lacks in-depth analysis and dynamic perception of the entire transaction process, making it difficult to identify complex transaction risk patterns, and the security strategy cannot be dynamically adjusted, resulting in insufficient protection capabilities.
By obtaining the historical transaction data of the target IC card on the mobile terminal, extracting the trading environment characteristics and behavioral characteristics, calling the pre-trained transaction risk detection model for risk prediction, generating a dynamic security strategy, and triggering verification operations through the transaction verification interface, and incrementally updating the model parameters based on the execution log of the verification interface.
It has achieved global optimization of IC card transactions, improved the real-time response capabilities and flexibility of verification of transaction risks, and built an intelligent, efficient and evolving security protection system that can continuously adapt to new transaction models and risk characteristics.
Smart Images

Figure CN120146857B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of artificial intelligence technology. Specifically, it relates to a method and system for secure IC card transaction processing based on a mobile terminal system. Background Art
[0002] At present, with the rapid development of mobile payment technology, as a key carrier in the field of mobile payment, the transaction security of IC cards has become a core element in ensuring the security of users' funds and personal information privacy. However, when dealing with increasingly complex and changeable transaction risks, the existing IC card transaction security processing technologies have exposed many limitations.
[0003] Currently, traditional IC card transaction security processing methods mainly rely on static security rules and fixed verification processes. The above methods usually only perform simple rule matching and risk judgment based on limited dimensions such as transaction amount and transaction time at the time of transaction, lacking in-depth analysis and dynamic perception of the entire transaction process. Due to the failure to fully explore the environmental characteristics and behavioral characteristics in the transaction process, traditional methods are difficult to effectively identify new and complex transaction risk patterns, such as cross-regional abnormal transactions and frequent small-scale exploratory transactions, resulting in a stretched protective ability when facing evolving fraud means.
[0004] In addition, the existing transaction security strategies are often static and cannot be dynamically adjusted according to real-time transaction risk situations. Once the security rules are set, it is difficult to flexibly respond to sudden risks during the transaction process, making the transaction security verification lack pertinence and adaptability, and easily giving opportunities to lawbreakers. Moreover, traditional methods lack an effective feedback and utilization mechanism for transaction verification results, unable to learn and evolve from the data accumulated in the actual transaction verification process, and difficult to continuously improve the ability to identify and prevent transaction risks. Summary of the Invention
[0005] In view of the above-mentioned problems, in combination with the first aspect of the present invention, embodiments of the present invention provide a method for secure IC card transaction processing based on a mobile terminal system, the method comprising:
[0006] Obtain a historical transaction data set of a target IC card on a mobile terminal, the historical transaction data set including a plurality of transaction sequences, each transaction sequence consisting of a transaction request event and a corresponding transaction verification event;
[0007] Perform transaction feature extraction processing on the historical transaction data set to obtain the transaction environment feature and transaction behavior feature of each transaction sequence;
[0008] Invoke a pre-trained transaction risk detection model to perform transaction risk prediction on the transaction environment feature and the transaction behavior feature, and generate a risk determination result of the transaction sequence;
[0009] Generate a dynamic transaction security policy based on the risk determination result, and feed back the dynamic transaction security policy to the transaction verification interface of the mobile terminal to trigger a verification operation;
[0010] A feedback data set is generated according to the execution log of the transaction verification interface, and model parameters of the transaction risk detection model are incrementally updated based on the feedback data set.
[0011] On the other hand, an embodiment of the present invention also provides an IC card transaction security processing system based on a mobile terminal system, including a processor and a machine-readable storage medium, wherein the machine-readable storage medium is connected to the processor, the machine-readable storage medium is used to store programs, instructions or codes, and the processor is used to execute the programs, instructions or codes in the machine-readable storage medium to implement the above method.
[0012] Based on the above aspects, the embodiment of the present application realizes the global optimization and intelligent improvement of IC card transaction security. Specifically, by collecting the historical transaction data set of the target IC card on the mobile terminal, and on this basis, through feature extraction processing, the transaction environment characteristics and transaction behavior characteristics of each transaction sequence are analyzed, and risk prediction is performed by calling the pre-trained transaction risk detection model, realizing the intelligent mapping from features to risk judgments, effectively overcoming the limitations of traditional rule engines, and being able to capture potential nonlinear risk patterns. The dynamic transaction security strategy generated based on the risk judgment results not only reflects the real-time response capability to transaction risks, but also triggers the verification operation through feedback to the transaction verification interface of the mobile terminal, constructing an active defense security barrier, and significantly improving the flexibility and effectiveness of transaction verification. What is particularly important is that by generating a feedback data set based on the execution log of the transaction verification interface, and incrementally updating the model parameters of the transaction risk detection model based on the feedback data set, a continuous learning and evolution mechanism is formed, which enables the transaction risk detection model to continuously adapt to new transaction patterns and risk characteristics, maintain its predictive accuracy and robustness, and thus achieve continuous optimization and dynamic protection of IC card transaction security on a global scale, which not only improves the security of a single transaction, but also builds an intelligent, efficient, and evolvable IC card transaction security protection system as a whole. BRIEF DESCRIPTION OF THE DRAWINGS
[0013] Figure 1 It is a schematic diagram of the execution flow of the IC card transaction security processing method based on the mobile terminal system provided by an embodiment of the present invention.
[0014] Figure 2 It is a schematic diagram of exemplary hardware and software components of the IC card transaction security processing system based on the mobile terminal system provided by an embodiment of the present invention. DETAILED DESCRIPTION
[0015] The present invention will be described in detail below with reference to the accompanying drawings. Figure 1 It is a flow chart of a method for secure processing of IC card transactions based on a mobile terminal system provided by an embodiment of the present invention. The method for secure processing of IC card transactions based on a mobile terminal system is introduced in detail below.
[0016] Step S110, obtaining a historical transaction data set of the target IC card on the mobile terminal, wherein the historical transaction data set includes a plurality of transaction sequences, each transaction sequence consisting of a transaction request event and a corresponding transaction verification event.
[0017] For example, a target IC card has performed multiple transactions on a mobile terminal in the past period of time, and the resulting transaction records are saved to form the historical transaction data set. In detail, in one transaction sequence, the transaction request event may be that at a certain moment, the IC card initiated a payment request of 500 yuan to the mobile terminal, and carried relevant information such as terminal device identification information and transaction time; the corresponding transaction verification event is that the mobile terminal verifies the payment request, and the verification response time, verification results and other information are recorded during the verification process. Therefore, there are multiple transaction sequences like this in the historical transaction data set, each of which contains its own transaction request event and corresponding transaction verification event.
[0018] Step S120, performing transaction feature extraction processing on the historical transaction data set to obtain transaction environment features and transaction behavior features of each transaction sequence.
[0019] In this embodiment, for the transaction request event, the environmental parameter parsing process can be performed first. For example, in the transaction request event mentioned above, the terminal device identification information can be parsed. Assume that the terminal device identification information is a unique code composed of numbers and letters, such as "123abc567def". This unique code represents the terminal device that initiates the transaction request; the network protocol address information is "192.168.1.100", which is the address of the terminal device in the network; the signal strength information is "-80dBm". Therefore, based on the above information, the corresponding code is generated. For example, based on the terminal device identification information "123abc567def", a device fingerprint code is generated, and it is converted into a new code, such as "abcdef123456" through a coding algorithm; based on the network protocol address information "192.168.1.100", a geographic area code is generated, such as the code "001" mapped to "area A" according to the address range; based on the signal strength information "-80dBm", a network fluctuation code is generated, assuming that the code "01" is generated according to the strength range. The device fingerprint code "abcdef123456", the geographic area code "001" and the network fluctuation code "01" are then subjected to feature fusion processing, for example, spliced together in a specific order to generate the transaction environment feature "abcdef12345600101" of the transaction sequence.
[0020] Furthermore, for transaction verification events, time series analysis and processing are continued. For example, there are several consecutive transaction verification events, the first verification event is completed at 10:00:00, the second is completed at 10:01:30, and the third is completed at 10:03:00. Through analysis, the time interval distribution characteristics between consecutive transaction verification events can be obtained, such as the interval between the first and the second is 1 minute and 30 seconds, and the interval between the second and the third is 1 minute and 30 seconds; at the same time, the verification operation duration characteristics are extracted, assuming that the first verification operation duration is 5 seconds, the second is 3 seconds, and the third is 4 seconds. The time interval distribution characteristics and the verification operation duration characteristics are time-series associated, such as combining the time interval and duration information according to certain rules to generate transaction behavior characteristics, such as "1 minute 30 seconds_5 seconds, 1 minute 30 seconds_3 seconds, 1 minute 30 seconds_4 seconds".
[0021] Step S130, calling a pre-trained transaction risk detection model, performing transaction risk prediction on the transaction environment characteristics and the transaction behavior characteristics, and generating a risk determination result of the transaction sequence.
[0022] In this embodiment, first, the environmental feature encoder in the transaction risk detection model can be called to perform hierarchical embedding processing on the transaction environmental feature "abcdef12345600101", converting it into a high-dimensional vector. Suppose the first high-dimensional feature vector "[0.1, 0.2, …, 0.10]" is generated. Here, the first high-dimensional feature vector contains values of multiple dimensions. Then, the transaction behavior feature encoder is called to perform sliding window convolution processing on the transaction behavior features "1 minute 30 seconds _ 5 seconds, 1 minute 30 seconds _ 3 seconds, 1 minute 30 seconds _ 4 seconds", generating the second high-dimensional feature vector "[0.3, 0.4, …, 0.15]".
[0023] On this basis, the first high-dimensional feature vector "[0.1, 0.2, …, 0.10]" and the second high-dimensional feature vector "[0.3, 0.4, …, 0.15]" can be input into the cross-dimensional association module in the transaction risk detection model, and feature interaction processing is performed on these two vectors based on the dynamic weight allocation mechanism.
[0024] Specifically, the first high-dimensional feature vector can be mapped to a query vector group. Suppose after mapping, it is "[[0.1, 0.2], [0.3, 0.4], …, [0.9, 0.10]]". The second high-dimensional feature vector is mapped to a key vector group and a value vector group. The key vector group is supposed to be "[[0.3, 0.4], [0.5, 0.6], …, [0.14, 0.15]]", and the value vector group is supposed to be "[[0.5, 0.6], [0.7, 0.8], …, [0.16, 0.17]]". Calculate the cosine similarity between each query vector in the query vector group and the corresponding key vector in the key vector group. For example, calculate the cosine similarity between the first query vector "[0.1, 0.2]" and the first key vector "[0.3, 0.4]", and obtain the initial attention weights through the set calculation method. Suppose "[0.2, 0.3, …, 0.1]" is obtained. Then, normalize the initial attention weights so that their sum is 1, generating a normalized attention weight distribution, such as "[0.15, 0.25, …, 0.08]". Perform a weighted sum operation on the value vector group according to the normalized attention weight distribution to generate a primary association feature, such as "[0.4, 0.5, …, 0.12]" obtained through calculation. Perform a residual connection process on the primary association feature "[0.4, 0.5, …, 0.12]" and the first high-dimensional feature vector "[0.1, 0.2, …, 0.10]" to generate a normalized risk association feature "[0.5, 0.7, …, 0.22]".
[0025] Next, call the classifier in the transaction risk detection model to perform probability mapping processing on the risk-related feature "[0.5, 0.7, …, 0.22]" to generate the risk determination probability values corresponding to each risk type identifier of the transaction sequence. For example, the determination probability value for risk type A is 0.6, the determination probability value for risk type B is 0.3, and the determination probability value for risk type C is 0.1. Generate a risk determination result based on the comparison result between the risk determination probability value and the preset threshold. Assume the preset threshold is 0.5. Since the probability value of 0.6 for risk type A is greater than 0.5, the risk determination result for this transaction sequence is that there is a risk of risk type A.
[0026] Step S140, generate a dynamic transaction security policy based on the risk determination result, and feedback the dynamic transaction security policy to the transaction verification interface of the mobile terminal to trigger a verification operation.
[0027] In this embodiment, the risk probability value and the risk type identifier in the risk determination result can be parsed. For example, the probability value of risk type A obtained just now is 0.6. When the risk probability value exceeds the first dynamic threshold, assuming the first dynamic threshold is 0.55, a first-level security policy including multi-factor authentication rules and real-time transaction blocking rules can be generated. The multi-factor authentication rules may require the user to not only enter a password but also be verified through fingerprint recognition or SMS verification code, etc.; the real-time transaction blocking rule is to immediately block the transaction when the verification fails.
[0028] Further, when the risk probability value is between the second dynamic threshold and the first dynamic threshold, assuming the second dynamic threshold is 0.4, a second-level security policy including a dynamic adjustment rule for the transaction amount and a strengthening rule for the verification process is generated. The dynamic adjustment rule for the transaction amount may appropriately reduce the operable amount of this transaction according to the risk situation, and the strengthening rule for the verification process may add additional verification steps, such as reconfirming the transaction amount, etc.
[0029] Further, when the risk probability value is lower than the second dynamic threshold, a third-level security policy including a fast matching rule for device fingerprints and a geographical location verification rule is generated. The fast matching rule for device fingerprints speeds up the verification of device fingerprints, and the geographical location verification rule verifies whether the geographical location where the transaction is initiated conforms to the preset range.
[0030] Accordingly, the generated security policy can be dynamically configured to the policy execution queue of the transaction verification interface. For example, if it is determined to be a first-level security policy, it is placed in the policy execution queue. A policy priority evaluation thread is created in the transaction verification interface and run to calculate the policy execution priority according to the real-time load status of the current transaction request. For example, if there are many current transaction requests and the load is large, the thread will calculate the execution priorities of each policy according to a preset algorithm. Sort the security policies in the policy execution queue according to the policy execution priority to generate an ordered policy execution sequence, and allocate an independent memory cache area for each security policy. When a new transaction request event arrives, the corresponding verification rule executor is called in sequence according to the ordered policy execution sequence for processing to generate a composite verification instruction set, and the composite verification instruction set is atomically executed through the trusted execution environment of the mobile terminal.
[0031] Step S150, generate a feedback data set according to the execution log of the transaction verification interface, and incrementally update the model parameters of the transaction risk detection model based on the feedback data set.
[0032] In this embodiment, the operation status data of each transaction verification event in the transaction verification interface can be captured in real time. For example, the operation status data of a transaction verification event includes a verification response timestamp "2023-10-01 10:05:00", a verification result identifier "success", and an exception error code "000". Then, perform a structured parsing process on the operation status data to extract the execution efficiency index of the verification success event and the risk trigger type of the verification failure event. For the verification success event, the execution efficiency index may include the response time from the request to the verification completion, assumed to be 3 seconds, and the duration of the verification operation, assumed to be 2 seconds. For the verification failure event, parse the risk trigger type from the exception error code. For example, the error code "101" parses out the risk trigger type as "password error".
[0033] Then, perform an association annotation process on the execution efficiency index and the risk trigger type with the corresponding risk determination result to generate a timestamped feedback data set. For example, the transaction sequence identifier of the verification success event can be extracted from the operation status data, assumed to be "TX001", and based on this, match the corresponding risk type identifier and risk determination probability value from the risk determination result. Assume the risk type identifier is "risk type A" and the risk determination probability value is 0.9. Perform a segmented quantization process on the execution efficiency index of the verification success event to generate an execution efficiency quantization vector including a response time interval code and a verification duration level code. For example, the response time of 3 seconds is in the "2-4 seconds" interval and is encoded as "01", and the verification duration of 2 seconds is in the "1-3 seconds" level and is encoded as "02", generating the execution efficiency quantization vector "01_02".
[0034] Next, a multi-level classification mapping process can be performed on the risk trigger type code of the verification failure event to generate a risk trigger classification vector including a risk trigger source code and an anomaly severity code. For example, if the risk trigger type is "password error", it is mapped to the risk trigger source code "user authentication" and the anomaly severity code "low", generating the risk trigger classification vector "user authentication_low". Align the execution efficiency quantization vector "01_02" with the corresponding risk type identifier "risk type A" and the risk determination probability value 0.9 to generate a verification success feedback record with a verification response timestamp "2023-10-01 10:05:00", i.e., "TX001_risk type A_0.9_01_02_2023-10-01 10:05:00". Align the risk trigger classification vector "user authentication_low" with the corresponding risk type identifier and risk determination probability value to generate a verification failure feedback record with a verification response timestamp. Perform a timestamp sorting process on the verification success feedback record and the verification failure feedback record to generate an initial feedback record queue sorted in ascending order of timestamps. Perform a field integrity verification process on each feedback record in the initial feedback record queue to remove invalid feedback records missing a transaction sequence identifier or a risk determination probability value, generating a standard feedback record set.
[0035] Next, balance sampling is performed on the verification success feedback records and verification failure feedback records in the standard feedback record set according to a preset ratio to generate a feedback data subset. For example, if the preset ratio is 1:1, a certain number of records are taken from both the verification success and verification failure feedback records to form a feedback data subset. Add a data source identifier and a data version number to each feedback record in the feedback data subset to generate a timestamped feedback data set. Call an online learning algorithm to perform incremental sampling on the feedback data set to generate an incremental training sample set. Generate a data weight coefficient based on the timestamp of each feedback data in the feedback data set, where the newer the timestamp, the higher the weight coefficient. For example, the weight coefficient corresponding to the latest timestamp is 0.8, and the older one is 0.3, etc. Perform weighted random sampling on the feedback data set based on the data weight coefficient to generate an initial sampling data set. Perform noise injection on the transaction environment features and transaction behavior features in the initial sampling data set. For example, add some random noise to the transaction environment feature vector to make it more diverse, generating an enhanced feature set. Mix and recombine the enhanced feature set with the original features in the initial sampling data set to generate an incremental training sample set. Perform gradient update on the model parameters of the transaction risk detection model based on the incremental training sample set to adjust the model weight distribution, thereby continuously optimizing the transaction risk detection model to make it more accurate in risk prediction and determination.
[0036] Based on the above steps, the embodiment of the present application realizes the global optimization and intelligent improvement of IC card transaction security. Specifically, by collecting the historical transaction data set of the target IC card on the mobile terminal, and on this basis, through feature extraction processing, the transaction environment characteristics and transaction behavior characteristics of each transaction sequence are analyzed, and risk prediction is performed by calling the pre-trained transaction risk detection model, realizing the intelligent mapping from features to risk judgments, effectively overcoming the limitations of traditional rule engines, and being able to capture potential nonlinear risk patterns. The dynamic transaction security strategy generated based on the risk judgment results not only reflects the real-time response capability to transaction risks, but also triggers the verification operation through feedback to the transaction verification interface of the mobile terminal, constructing an active defense security barrier, and significantly improving the flexibility and effectiveness of transaction verification. What is particularly important is that by generating a feedback data set based on the execution log of the transaction verification interface, and incrementally updating the model parameters of the transaction risk detection model based on the feedback data set, a continuous learning and evolution mechanism is formed, which enables the transaction risk detection model to continuously adapt to new transaction patterns and risk characteristics, maintain its predictive accuracy and robustness, and thus achieve continuous optimization and dynamic protection of IC card transaction security on a global scale, which not only improves the security of a single transaction, but also builds an intelligent, efficient, and evolvable IC card transaction security protection system as a whole.
[0037] In a possible implementation, step S120 includes:
[0038] Step S121, performing environmental parameter analysis processing on the transaction request event, and extracting terminal device identification information, network protocol address information and signal strength information when the transaction request event occurs.
[0039] For example, suppose that in a specific transaction scenario, a transaction request event occurs. At this time, the relevant information when the transaction request event occurs is extracted. The terminal device identification information is a unique character combination, such as "device_1234567890abcdef". This identification information can uniquely identify the terminal device that initiated the transaction request. The network protocol address information is "192.168.0.101", which clarifies the location of the device in the current network environment. The signal strength information is "-75dBm", and the signal strength value reflects the strength of the network signal at that time.
[0040] Step S122, generating a device fingerprint code based on the terminal device identification information, generating a geographic area code based on the network protocol address information, and generating a network fluctuation code based on the signal strength information.
[0041] For example, a device fingerprint code is generated based on the terminal device identification information "device_1234567890abcdef". Through a hash algorithm set in any relevant technology, this long string of characters can be converted. For example, the hash algorithm can perform specific mathematical operations on each position of the characters and convert them into a new code. Suppose that after calculation, the finally generated device fingerprint code is "fingerprint_56789abcdef1234". For the network protocol address information "192.168.0.101", according to the pre-set address range division rules, it is mapped to a geographical area code. For example, it is pre-specified that the address segment "192.168.0.0 - 192.168.0.255" belongs to "Region B", and the corresponding geographical area code is "region_B_002". A network fluctuation code is generated based on the signal strength information "-75dBm". According to the interval division of the signal strength, for example, "-80dBm to -70dBm" is defined as the interval with small signal fluctuations, and the corresponding network fluctuation code is "stable_01".
[0042] Step S123: Perform feature fusion processing on the device fingerprint code, the geographical area code, and the network fluctuation code to generate the transaction environment feature of the transaction sequence.
[0043] For example, the device fingerprint code "fingerprint_56789abcdef1234", the geographical area code "region_B_002", and the network fluctuation code "stable_01" can be subjected to feature fusion processing. Here, the fusion processing is to splice the above codes together in a specific order.
[0044] For example, placing the device fingerprint code at the first place, followed by the geographical area code, and finally the network fluctuation code, the generated transaction environment feature of the transaction sequence is:
[0045] "fingerprint_56789abcdef1234region_B_002stable_01".
[0046] Step S124: Perform time series analysis processing on the transaction verification event to extract the time interval distribution feature and the verification operation duration feature between consecutive transaction verification events.
[0047] For example, assume that in a series of consecutive transaction verification events, the first transaction verification event is completed at "2023-10-01 10:00:00", the second at "2023-10-01 10:02:30", and the third at "2023-10-01 10:05:00". Through calculation, the time interval distribution characteristics between consecutive transaction verification events can be obtained. For example, the time interval between the first and the second transaction verification events is 2 minutes and 30 seconds, and the time interval between the second and the third is also 2 minutes and 30 seconds. At the same time, the duration characteristics of each verification operation are extracted. Assume that the duration of the first verification operation is 4 seconds, the second is 5 seconds, and the third is 3 seconds.
[0048] Step S125, perform a temporal correlation process on the time interval distribution characteristics and the verification operation duration characteristics to generate the transaction behavior characteristics.
[0049] For example, based on the time sequence, arrange the time intervals and the corresponding durations in sequence to generate the transaction behavior characteristics "2 minutes and 30 seconds_4 seconds, 2 minutes and 30 seconds_5 seconds, 2 minutes and 30 seconds_3 seconds".
[0050] In a possible implementation manner, step S130 includes:
[0051] Step S131, call the environment feature encoder in the transaction risk detection model to perform hierarchical embedding processing on the transaction environment characteristics, and generate a first high-dimensional feature vector.
[0052] First, call the environment feature encoder in the transaction risk detection model to perform hierarchical embedding processing on the generated transaction environment characteristics "fingerprint_56789abcdef1234region_B_002stable_01". The environment feature encoder can perform step-by-step transformation and mapping on this transaction environment characteristic, decompose the encoded information into multiple levels for processing, and each level performs specific feature extraction and transformation on the information. For example, in the first layer, feature analysis can be performed on the device fingerprint coding part, key feature points are extracted, and they are converted into a digital feature representation. After multiple layers of processing, a first high-dimensional feature vector is finally generated. Assume that this first high-dimensional feature vector is a vector containing multiple dimensional values, such as "[0.12, 0.34, 0.56,..., 0.98]", where each dimension of the first high-dimensional feature vector represents the feature values of the transaction environment characteristics in different aspects.
[0053] Step S132, call the transaction behavior feature encoder to perform sliding window convolution processing on the transaction behavior characteristics, and generate a second high-dimensional feature vector.
[0054] Then, call the transaction behavior feature encoder to perform sliding window convolution processing on the transaction behavior features "2 minutes 30 seconds _ 4 seconds, 2 minutes 30 seconds _ 5 seconds, 2 minutes 30 seconds _ 3 seconds". The transaction behavior feature encoder will perform convolution operations on this time series feature in a sliding window manner. For example, set a window size of 2 time interval and duration combinations and slide it starting from the beginning of the sequence. In the first window, it contains the two pieces of information "2 minutes 30 seconds _ 4 seconds" and "2 minutes 30 seconds _ 5 seconds". The encoder will perform convolution calculations on these two pieces of information, that is, perform a series of mathematical operations on the numerical values of the time interval and duration. For example, first convert the time interval to seconds, 2 minutes 30 seconds is 150 seconds, and then perform a weighted operation with the duration value. Assume the weighting coefficients are 0.6 and 0.4 respectively, then the calculation process is "(150×0.6 + 4×0.4)+(150×0.4 + 5×0.6)", and a new value is obtained after calculation. As the window slides in sequence, the entire transaction behavior feature sequence is processed, and finally a second high-dimensional feature vector is generated. Assume this second high-dimensional feature vector is "[0.23, 0.45, 0.67, …, 0.89]".
[0055] Step S133, input the first high-dimensional feature vector and the second high-dimensional feature vector into the cross-dimensional association module in the transaction risk detection model, and perform feature interaction processing on the first high-dimensional feature vector and the second high-dimensional feature vector based on the dynamic weight allocation mechanism to generate risk-associated features.
[0056] In a possible implementation manner, step S133 includes:
[0057] Step S1331, map the first high-dimensional feature vector to a query vector group, and map the second high-dimensional feature vector to a key vector group and a value vector group.
[0058] For example, input the first high-dimensional feature vector "[0.12, 0.34, 0.56, …, 0.98]" and the second high-dimensional feature vector "[0.23, 0.45, 0.67, …, 0.89]" into the cross-dimensional association module in the transaction risk detection model, and perform feature interaction processing on these two high-dimensional feature vectors based on the dynamic weight allocation mechanism to generate risk-associated features. First, map the first high-dimensional feature vector to a query vector group. Assume that the first high-dimensional feature vector is divided into multiple query vectors according to a certain dimension division rule. For example, if every two dimensions are divided into a query vector, then multiple query vectors can be obtained, forming a query vector group "[[0.12, 0.34], [0.56, 0.78], [0.98, 0.10]]". Map the second high-dimensional feature vector to a key vector group and a value vector group. Also divide according to the set rule. Assume that the key vector group "[[0.23, 0.45], [0.67, 0.89], [0.11, 0.22]]" and the value vector group "[[0.33, 0.55], [0.77, 0.99], [0.13, 0.25]]" are obtained.
[0059] Step S1332: Calculate the cosine similarity between each query vector in the query vector group and the corresponding key vector in the key vector group to generate initial attention weights.
[0060] Taking the first query vector "[0.12, 0.34]" and the first key vector "[0.23, 0.45]" as an example, the process of calculating the cosine similarity is as follows: First, calculate the dot product of the two vectors, that is, "0.12×0.23 + 0.34×0.45 = 0.0276 + 0.153 = 0.1806". Then calculate the magnitudes of the two vectors respectively. The magnitude of the query vector "[0.12, 0.34]" is "sqrt(0.12² + 0.34²) = sqrt(0.0144 + 0.1156) = sqrt(0.13) ≈ 0.36", and the magnitude of the key vector "[0.23, 0.45]" is "sqrt(0.23² + 0.45²) = sqrt(0.0529 + 0.2025) = sqrt(0.2554) ≈ 0.50". Finally, the cosine similarity is "0.1806 / (0.36×0.50) ≈ 1.00" (here, due to approximations in the calculation process, the actual value may vary slightly). Calculate the cosine similarities of all corresponding vectors in the same way to obtain the initial attention weights, assumed to be "[1.00, 0.80, 0.60]".
[0061] Step S1333: Normalize the initial attention weights to generate a normalized attention weight distribution.
[0062] In this embodiment, the purpose of normalization is to make the sum of all attention weights equal to 1. The calculation process is as follows: First, calculate the sum of the initial attention weights "1.00 + 0.80 + 0.60 = 2.40". Then, divide each initial attention weight by the sum to obtain the normalized attention weight distribution. The first weight is "1.00 / 2.40 ≈ 0.42", the second weight is "0.80 / 2.40 ≈ 0.33", and the third weight is "0.60 / 2.40 ≈ 0.25", that is, the normalized attention weight distribution is "[0.42, 0.33, 0.25]".
[0063] Step S1334, perform a weighted summation operation on the value vector group according to the normalized attention weight distribution to generate a primary correlation feature.
[0064] For example, taking the value vector group "[[0.33, 0.55], [0.77, 0.99], [0.13, 0.25]]" as an example, the calculation process of the weighted summation is: Multiply the first value vector by the first normalized attention weight, that is, "[0.33 × 0.42, 0.55 × 0.42] = [0.1386, 0.231]"; multiply the second value vector by the second normalized attention weight, that is, "[0.77 × 0.33, 0.99 × 0.33] = [0.2541, 0.3267]"; multiply the third value vector by the third normalized attention weight, that is, "[0.13 × 0.25, 0.25 × 0.25] = [0.0325, 0.0625]". Then add these three results to get "[0.1386 + 0.2541 + 0.0325, 0.231 + 0.3267 + 0.0625] = [0.4252, 0.6202]", which is the generated primary correlation feature.
[0065] Step S1335, perform a residual connection process on the primary correlation feature and the first high-dimensional feature vector to generate a normalized risk correlation feature.
[0066] For example, the primary correlation feature "[0.4252, 0.6202]" can be subjected to residual connection processing with the first high-dimensional feature vector "[0.12, 0.34, 0.56, …, 0.98]" to generate a normalized risk correlation feature. The calculation method of the residual connection is to add the corresponding dimensions of the primary correlation feature and the first high-dimensional feature vector (if the dimensions do not match, some dimension adjustment operations may be required. Here, it is assumed that the dimensions match). For example, add the first dimension of the primary correlation feature to the first dimension of the first high-dimensional feature vector, "0.4252 + 0.12 = 0.5452"; add the second dimension, "0.6202 + 0.34 = 0.9602", and so on, finally generating a normalized risk correlation feature. Assume that after the complete calculation, the risk correlation feature is "[0.5452, 0.9602, 1.02, …, 1.20]".
[0067] Step S134, call the classifier in the transaction risk detection model to perform probability mapping processing on the risk correlation feature, and generate risk determination probability values corresponding to each risk type identifier of the transaction sequence.
[0068] In this embodiment, the classifier in the transaction risk detection model can be called to perform probability mapping processing on the generated risk correlation feature "[0.5452, 0.9602, 1.02, …, 1.20]" to generate risk determination probability values corresponding to each risk type identifier of the transaction sequence. The classifier will analyze and calculate the risk correlation feature according to the pre-trained model parameters and algorithms. For example, for risk type A, through a series of calculations and mappings, the risk determination probability value is 0.7; for risk type B, the probability value is 0.2; for risk type C, the probability value is 0.1.
[0069] Step S135, generate the risk determination result according to the comparison result between the risk determination probability value and the preset threshold.
[0070] Assume that the preset threshold is 0.6. For risk type A, its probability value 0.7 is greater than 0.6, so it is determined that the transaction sequence has the risk of risk type A; for risk type B, the probability value 0.2 is less than 0.6, it is determined that there is no risk of risk type B; for risk type C, the probability value 0.1 is less than 0.6, it is determined that there is no risk of risk type C. Finally, by comprehensively the above comparison results, the risk determination result of the transaction sequence is generated, that is, there is the risk of risk type A.
[0071] In a possible implementation manner, step S150 may include:
[0072] Step S151, capture the operation status data of each transaction verification event in the transaction verification interface in real time. The operation status data includes a verification response timestamp, a verification result identifier, and an exception error code.
[0073] In this embodiment, in a previously set transaction scenario, the transaction verification interface runs continuously and records the relevant information of each transaction verification event. For example, for a certain transaction verification event, the verification response timestamp in its operation status data is recorded as "2023-10-02 14:30:15", accurate to the specific year, month, day, hour, minute, and second. This timestamp clearly indicates the moment when the verification operation is completed; the verification result identifier shows "success", clarifying the final result of this verification; the exception error code is "000", indicating that there is no exception error situation in this verification process. For another transaction verification event, the verification response timestamp is "2023-10-02 14:32:20", the verification result identifier is "failure", and the exception error code is "102". Different results and error codes represent different verification situations.
[0074] Step S152, perform a structured parsing process on the operation status data to extract the execution efficiency indicators of verification success events and the risk trigger types of verification failure events.
[0075] For example, for a verification success event, taking the event corresponding to the verification response timestamp of "2023-10-02 14:30:15" as an example, the execution efficiency indicators can be considered from multiple aspects. The response time from the moment when the transaction request is initiated to the moment when the verification is completed is an important indicator. Assuming that the transaction request initiation time is "2023-10-02 14:29:50", then the response time is "2023-10-02 14:30:15 - 2023-10-02 14:29:50 = 25 seconds". The verification operation duration is also a key indicator. Assuming that the time elapsed from the start of the verification to the end of the verification for this verification operation is 10 seconds. For a verification failure event, such as the event of "2023-10-02 14:32:20", parse the risk trigger type from the exception error code "102". The corresponding relationship between the error code and the risk trigger type is preset in the system. The risk trigger type corresponding to "102" is "insufficient account balance".
[0076] Step S153, perform an association annotation process on the execution efficiency indicators and the risk trigger types with the corresponding risk determination results to generate a timestamped feedback data set.
[0077] For example, in a possible implementation manner, step S153 includes:
[0078] Step S1531: Extract the transaction sequence identifier of the verification success event from the operation status data, and match the corresponding risk type identifier and risk determination probability value from the risk determination result based on the transaction sequence identifier.
[0079] Suppose the transaction sequence identifier of the verification success event extracted from the operation status data is "TX_007". Then, based on this transaction sequence identifier "TX_007", the corresponding risk type identifier and risk determination probability value can be matched from the previously generated risk determination result. Suppose the risk type identifier corresponding to this transaction sequence in the risk determination result is "low risk", and the risk determination probability value is 0.85.
[0080] Step S1532: Parse the risk trigger type code from the exception error code of the verification failure event, and match the corresponding risk type identifier and risk determination probability value from the risk determination result based on the transaction sequence identifier.
[0081] For the verification failure event, after parsing the risk trigger type code from the exception error code "102", the corresponding risk type identifier and risk determination probability value are matched from the risk determination result based on the transaction sequence identifier "TX_008". Suppose the risk type identifier is "Risk Type A", and the risk determination probability value is 0.9.
[0082] Step S1533: Perform segmented quantization processing on the execution efficiency index of the verification success event to generate an execution efficiency quantization vector including a response time interval code and a verification duration level code.
[0083] For example, for a response time of 25 seconds, according to the pre-set interval division, the code for the "20 - 30 seconds" interval is "03"; for a verification duration of 10 seconds, the code for the "8 - 12 seconds" level is "02", thus generating the execution efficiency quantization vector "03_02".
[0084] Step S1534: Perform multi-level classification mapping processing on the risk trigger type code of the verification failure event to generate a risk trigger classification vector including a risk trigger source code and an exception severity code.
[0085] For example, the multi-level classification mapping processing can be performed on the risk trigger type code "102" of the verification failure event to generate a risk trigger classification vector including a risk trigger source code and an exception severity code. The risk trigger source code corresponding to "102" is "related to account funds", and the exception severity code is "high", generating the risk trigger classification vector "related to account funds_ high".
[0086] Step S1535, performing field alignment processing on the execution efficiency quantization vector, the corresponding risk type identifier, and the risk determination probability value, and generating a verification success feedback record with the verification response timestamp.
[0087] For example, the execution efficiency quantization vector "03_02" can be field aligned with the corresponding risk type identifier "low risk" and the risk judgment probability value 0.85 to generate a verification success feedback record "TX_007_Low Risk_0.85_03_02_2023-10-02 14:30:15" with a verification response timestamp "2023-10-02 14:30:15".
[0088] Step S1536: perform field alignment processing on the risk trigger classification vector, the corresponding risk type identifier, and the risk determination probability value to generate a verification failure feedback record with the verification response timestamp.
[0089] For example, the risk trigger classification vector "Account Funds Related_High" can be field aligned with the corresponding risk type identifier "Risk Type A" and the risk judgment probability value 0.9 to generate a verification failure feedback record "TX_008_High Risk_0.9_Account Funds Related_High_2023-10-02 14:32:20" with a verification response timestamp "2023-10-0214:32:20".
[0090] Step S1537, performing timestamp sorting processing on the verification success feedback record and the verification failure feedback record to generate an initial feedback record queue arranged in ascending order of timestamps.
[0091] In this queue, the feedback record with the earliest timestamp is at the front, and the feedback record with the latest timestamp is at the back. For example, after sorting, the first feedback record in the queue is "TX_007_Low Risk_0.85_03_02_2023-10-02 14:30:15", followed by other feedback records such as "TX_008_High Risk_0.9_Account Funds Related_High_2023-10-02 14:32:20".
[0092] Step S1538, performing field integrity check processing on each feedback record in the initial feedback record queue, removing invalid feedback records that are missing the transaction sequence identifier or the risk determination probability value, and generating a standard feedback record set.
[0093] During the inspection process, each feedback record can be inspected one by one. For example, for a certain feedback record, if it is found that the transaction sequence identifier is missing, then this feedback record will be marked as invalid and removed from the queue; if the risk determination probability value is missing, it will also be removed. After such verification processing, the remaining valid feedback records form the standard feedback record set.
[0094] Step S1539, perform balanced sampling processing on the verified successful feedback records and verified failed feedback records in the standard feedback record set according to a preset ratio to generate a feedback data subset.
[0095] Assume the preset ratio is 1:1, that is, half of the verified successful feedback records and half of the verified failed feedback records are taken. Randomly select a certain number of verified successful feedback records and the same number of verified failed feedback records from the standard feedback record set to form a feedback data subset. For example, records such as "TX_007_Low Risk_0.85_03_02_2023-10-02 14:30:15" are selected from the verified successful feedback records, and records such as "TX_008_High Risk_0.9_Account Funds Related_High_2023-10-02 14:32:20" are selected from the verified failed feedback records to jointly form the feedback data subset.
[0096] Step S15310, add a data source identifier and a data version number to each feedback record in the feedback data subset to generate a timestamped feedback data set.
[0097] In this embodiment, the data source identifier can indicate which specific data source the above feedback data comes from. Assume the data source identifier is "source_01". The data version number is used to identify the version information of the data. Assume the current version number is "v1.0". For example, for the feedback record "TX_007_Low Risk_0.85_03_02_2023-10-02 14:30:15", after adding the data source identifier and the data version number, it becomes "TX_007_Low Risk_0.85_03_02_2023-10-02 14:30:15_source_01_v1.0". After the addition operation for all feedback records, a complete timestamped feedback data set is formed.
[0098] Step S154, call an online learning algorithm to perform incremental sampling processing on the feedback data set to generate an incremental training sample set.
[0099] In a possible implementation manner, step S154 includes:
[0100] Step S1541: Generate data weight coefficients according to the timestamps of each feedback data in the feedback data set, where the data weight coefficients are positively correlated with the newness or oldness of the timestamps.
[0101] For example, for the feedback record "TX_007_Low Risk_0.85_03_02_2023-10-02 14:30:15_source_01_v1.0", the timestamp "2023-10-02 14:30:15" is relatively old. Assuming according to the weight calculation rule, its data weight coefficient is 0.3. For a feedback record with a newer timestamp, such as "TX_008_High Risk_0.9_Account Funds Related_High_2023-10-02 14:32:20_source_01_v1.0", its data weight coefficient may be 0.6. Here, the calculation of the weight coefficient is based on a pre-set function, which determines the size of the weight coefficient according to factors such as the difference between the timestamp and the current time.
[0102] Step S1542: Perform weighted random sampling processing on the feedback data set based on the data weight coefficients to generate an initial sampling data set.
[0103] In this embodiment, during the sampling process, the probability of a feedback data with a high weight coefficient being selected is relatively large. For example, in one sampling, there are 10 feedback data, among which 3 feedback data have a weight coefficient of 0.3, 3 have a weight coefficient of 0.4, and 4 have a weight coefficient of 0.6. Then, when randomly sampling, the possibility of a feedback data with a weight coefficient of 0.6 being selected is greater than that of a feedback data with a weight coefficient of 0.3. Through this weighted random sampling method, a certain number of feedback data are selected from the feedback data set to form an initial sampling data set.
[0104] Step S1543: Perform noise injection processing on the transaction environment features and transaction behavior features in the initial sampling data set to generate an enhanced feature set.
[0105] In this embodiment, for the trading environment features, assume that the trading environment feature corresponding to a certain feedback record in the initial sampling dataset is "fingerprint_56789abcdef1234region_B_002stable_01". During the noise injection process, random minor changes may be made to the device fingerprint encoding part. For example, a certain character is randomly replaced. Assume that "a" is replaced by "b", becoming "fingerprint_56789bbcdef1234region_B_002stable_01". For the trading behavior features, such as "2 minutes and 30 seconds_4 seconds, 2 minutes and 30 seconds_5 seconds, 2 minutes and 30 seconds_3 seconds", minor random adjustments may be made to the time intervals or durations. For example, the first time interval "2 minutes and 30 seconds" is adjusted to "2 minutes and 25 seconds", becoming "2 minutes and 25 seconds_4 seconds, 2 minutes and 30 seconds_5 seconds, 2 minutes and 30 seconds_3 seconds". By injecting noise into the trading environment features and trading behavior features in this way, an enhanced feature set is generated.
[0106] Step S1544, mix and recombine the enhanced feature set with the original features in the initial sampling dataset to generate the incremental training sample set.
[0107] In this embodiment, the process of mixing and recombining is to combine the features in the enhanced feature set with the original features according to certain rules. For example, for a feedback record, its original trading environment feature is "fingerprint_56789abcdef1234region_B_002stable_01", and the enhanced trading environment feature is "fingerprint_56789bbcdef1234region_B_002stable_01". Part of the features of the two may be combined in a certain proportion. For example, the first half uses the original features, and the second half uses the enhanced features, forming a new trading environment feature "fingerprint_56789abcdef1234region_B_002stable_01 (second half: the second half feature of fingerprint_56789bbcdef1234region_B_002stable_01)". Similar mixing and recombining operations are also performed on the trading behavior features. After such processing, an incremental training sample set is finally generated. This incremental training sample set will be used to perform gradient update processing on the model parameters of the trading risk detection model to adjust the model weight distribution, so that the trading risk detection model can better adapt to new data and trading situations and improve the accuracy and effectiveness of risk detection.
[0108] Step S155: Based on the incremental training sample set, perform gradient update processing on the model parameters of the transaction risk detection model to adjust the model weight distribution.
[0109] In a possible implementation manner, the pre-training process of the transaction risk detection model includes:
[0110] Step S210: Obtain a sample IC card transaction sample set, where the sample IC card transaction sample set includes verified secure transaction samples and labeled risk transaction samples.
[0111] In this embodiment, in a previously set scenario, the collected sample IC card transaction samples cover numerous different transaction records. For example, in the verified secure transaction samples, there is a transaction that occurred at "2023-10-01 10:15:00" with a transaction amount of 300 yuan. The terminal device identification information in the transaction request event is "device_7890abcd1234", the network protocol address information is "192.168.1.110", and the signal strength information is "-70dBm". The corresponding transaction verification event was completed at "2023-10-01 10:15:10" with a verification operation duration of 5 seconds and a verification result of success. Such a series of verified secure transaction records constitute the part of the verified secure transaction samples. In the labeled risk transaction samples, there is a transaction at "2023-10-02 14:45:00" with a relatively large transaction amount of 2000 yuan. The terminal device identification information is "device_efgh56789012", the network protocol address information is "192.168.2.120", the signal strength information is "-85dBm", the transaction verification event was completed at "2023-10-02 14:45:20" with a verification operation duration of 15 seconds, and the verification result was failure, and it was labeled as a risk transaction sample.
[0112] Step S220: Perform positive sample enhancement processing on the verified secure transaction samples to generate an augmented secure sample set. The positive sample enhancement processing includes adding device fingerprint perturbations to the transaction environment features and performing time window translation on the transaction behavior features.
[0113] In this embodiment, for the verified secure transaction sample of "2023-10-01 10:15:00" mentioned above, in terms of transaction environment characteristics, perturbations can be added to the device fingerprint "device_7890abcd1234". For example, randomly change several characters among them, assuming it becomes "device_7890efgh1234", while keeping the network protocol address information "192.168.1.110" and the signal strength information "-70dBm" unchanged, forming new transaction environment characteristics. In terms of transaction behavior characteristics, translate the time window. The original transaction request time was "2023-10-01 10:15:00" and the transaction verification time was "2023-10-01 10:15:10". Translate the entire time window backward by 5 minutes, that is, the transaction request time becomes "2023-10-01 10:20:00" and the transaction verification time becomes "2023-10-01 10:20:10", while the verification operation duration remains 5 seconds, thus generating new transaction behavior characteristics. By performing similar processing on multiple verified secure transaction samples, an augmented secure sample set is generated.
[0114] Step S230, perform negative sample enhancement processing on the marked risky transaction samples to generate an augmented risky sample set. The negative sample enhancement processing includes randomly replacing the network protocol address and adding noise to the verification operation duration.
[0115] For example, taking the marked risky transaction sample of "2023-10-02 14:45:00" as an example, randomly replace the network protocol address "192.168.2.120", assuming it is replaced with "192.168.3.130". For the verification operation duration of 15 seconds, add noise. For example, according to the set rules, add a random noise value to the duration. Assuming the randomly generated noise value is 3 seconds, then the verification operation duration after superposition becomes 15 + 3 = 18 seconds. By performing such processing on each marked risky transaction sample, an augmented risky sample set is generated.
[0116] Step S240, merge the augmented secure sample set and the augmented risky sample set into a pre-training data set.
[0117] Step S250, divide the pre-training data set into an environment feature training batch and a behavior feature training batch. The environment feature training batch includes the transaction environment characteristics and corresponding risk labels in the augmented secure sample set and the augmented risky sample set. The behavior feature training batch includes the transaction behavior characteristics and corresponding risk labels in the augmented secure sample set and the augmented risky sample set.
[0118] For example, select the trading environment feature "device_7890efgh1234, 192.168.1.110, -70dBm" from the augmented security sample set, and its corresponding risk label is "Risk Type A"; select the trading environment feature "device_efgh56789012, 192.168.3.130, -85dBm" from the augmented risk sample set, and its corresponding risk label is "Risk Type B". Thus, the above combination can form an environmental feature training batch. The behavioral feature training batch includes the trading behavioral features and corresponding risk labels in the augmented security sample set and the augmented risk sample set. For example, select the trading behavioral feature "2023-10-01 10:20:00, 2023-10-01 10:20:10, 5 seconds" from the augmented security sample set, and the risk label is "Risk Type A"; select the trading behavioral feature "2023-10-02 14:45:00, 2023-10-02 14:45:20 (after enhancement becomes 2023-10-02 14:45:38), 18 seconds" from the augmented risk sample set, and the risk label is "Risk Type B", thus forming a behavioral feature training batch.
[0119] Step S260, in the first-round training stage, fix the model parameters of the trading behavioral feature encoder in the initial risk detection model, and use the environmental feature training batch to perform backpropagation training on the environmental feature encoder in the initial risk detection model, update the weight parameters of the environmental feature encoder, and generate a first dynamic weight matrix.
[0120] During training, input the trading environment features in the environmental feature training batch into the environmental feature encoder. For example, input "device_7890efgh1234, 192.168.1.110, -70dBm" into the environmental feature encoder, and the environmental feature encoder processes it, converting the above features into a high-dimensional vector representation. During the processing, according to the difference between the output result of the initial risk detection model and the true risk label (here it is "Risk Type A"), calculate the gradient through the backpropagation algorithm. For example, there is a deviation between the risk determination result output by the initial risk detection model and the "Risk Type A" label, and calculate the gradient corresponding to this deviation. Assume that after a series of calculations, the direction and magnitude of the adjustment of each weight parameter in the environmental feature encoder are determined. Then, update the weight parameters of the environmental feature encoder according to the above calculation results. While updating the weight parameters, generate a first dynamic weight matrix, which records the dynamic changes of the weight parameters of the environmental feature encoder during this training process and is used for subsequent training stages.
[0121] Step S270: In the second training phase, fix the model parameters of the environmental feature encoder and the first dynamic weight matrix, and use the behavioral feature training batches to perform backpropagation training on the transaction behavioral feature encoder, update the weight parameters of the transaction behavioral feature encoder, and generate a second dynamic weight matrix.
[0122] In this embodiment, the transaction behavioral features in the behavioral feature training batches can be input into the transaction behavioral feature encoder. For example, input "2023-10-01 10:20:00, 2023-10-01 10:20:10, 5 seconds". The encoder performs operations such as sliding window convolution on it and converts it into corresponding feature representations. Similarly, according to the difference between the model output result and the true risk label ("Risk type A"), the gradient is calculated through the backpropagation algorithm. Assume that it is calculated that some weight parameters in the transaction behavioral feature encoder need to be increased and some need to be decreased. Update the weight parameters of the transaction behavioral feature encoder according to the calculation results and generate a second dynamic weight matrix. This second dynamic weight matrix records the dynamic changes of the weight parameters of the transaction behavioral feature encoder during this training.
[0123] Step S280: In the subsequent alternating training phase, cyclically switch the input order of the environmental feature training batches and the behavioral feature training batches, and perform joint gradient optimization on the environmental feature encoder and the transaction behavioral feature encoder based on the updated first dynamic weight matrix and the second dynamic weight matrix until the change rate of the loss function of the initial risk detection model is lower than a preset convergence threshold.
[0124] In this embodiment, in each round of training, when the environmental feature training batches are input, the environmental feature encoder is optimized in combination with the first dynamic weight matrix; when the behavioral feature training batches are input, the transaction behavioral feature encoder is optimized in combination with the second dynamic weight matrix. For example, in a certain round of training, first input the environmental feature training batches, calculate the gradient of the environmental feature encoder according to the current first dynamic weight matrix and the difference between the model output and the true label, and further adjust its weight parameters; then input the behavioral feature training batches, calculate the gradient of the transaction behavioral feature encoder and update the weight parameters according to the second dynamic weight matrix and the model output situation. Continuously repeat this process to continuously adjust the weight parameters of the two encoders. During the training process, monitor the change rate of the loss function of the initial risk detection model. For example, calculate the value of the loss function after each round of training, compare it with the value of the loss function in the previous round, calculate the change rate. When this change rate continuously decreases and is lower than the preset convergence threshold, it indicates that the model has converged. At this time, a transaction risk detection model is generated, and this model can more accurately detect and determine the risks of IC card transactions.
[0125] In a possible implementation manner, step S250 includes:
[0126] Step S251, extracting the transaction environment feature vector and the transaction behavior feature vector of each sample from the pre-training dataset. The transaction environment feature vector is composed of the splicing of the device fingerprint encoding, the geographical area encoding, and the network fluctuation encoding. The transaction behavior feature vector is composed of the splicing of the time interval distribution feature and the verification operation duration feature.
[0127] In this embodiment, in the pre-training dataset generated by the previously set transaction scenario, taking a certain sample as an example, in terms of its transaction environment features, the device fingerprint encoding is "fingerprint_1234abcd", the geographical area encoding is mapped according to the network protocol address "192.168.1.105", assumed to be "region_01", and the network fluctuation encoding is generated based on the signal strength "-72dBm", for example, "fluctuation_02". Thus, the above encodings can be spliced in sequence to form the transaction environment feature vector "fingerprint_1234abcdregion_01fluctuation_02".
[0128] For the transaction behavior feature vector, the time interval distribution feature between consecutive transaction verification events in this sample. Assume that the interval between the first two transaction verification events is 1 minute and 20 seconds, the interval between the second and the third is 1 minute and 30 seconds, and the verification operation duration features are 4 seconds, 5 seconds, and 3 seconds respectively. Splice the above information in a certain order to generate the transaction behavior feature vector "1 minute and 20 seconds_4 seconds, 1 minute and 30 seconds_5 seconds, 1 minute and 30 seconds_3 seconds". Such extraction operations are performed on each sample in the pre-training dataset to obtain the transaction environment feature vector and the transaction behavior feature vector corresponding to each sample.
[0129] Step S252, performing standard scaling processing on the transaction environment feature vector to generate a normalized environment feature vector, and performing temporal alignment processing on the transaction behavior feature vector to generate a behavior feature vector with an equal-length time window.
[0130] For example, for the trading environment feature vector "fingerprint_1234abcdregion_01fluctuation_02", the standardization scaling process needs to first determine the value range and scaling rules for each part. For example, for the device fingerprint encoding part, assume that the value range of its character combination can be mapped to a fixed interval through a certain hash algorithm, such as 0 - 100. For "fingerprint_1234abcd", after calculating through the hash algorithm, a value is obtained, assume it is 30. For the geographical region encoding "region_01", the corresponding value is preset to 10 (according to a certain classification and numbering rule of the region). For the network fluctuation encoding "fluctuation_02", the corresponding value is assumed to be 20 (also based on the classification and numbering of the fluctuation degree). Combine the above values together to get a vector "[30, 10, 20]". Then perform standardization scaling on this vector, calculate the modulus length of the vector, that is, "sqrt(30² + 10² + 20²) = sqrt(900 + 100 + 400) = sqrt(1400) ≈ 37.42". Divide each element in the vector by the modulus length to get the normalized vector "[30 / 37.42, 10 / 37.42, 20 / 37.42] ≈ [0.80, 0.27, 0.53]", which is the generated normalized environment feature vector.
[0131] For the trading behavior feature vector "1 minute 20 seconds_4 seconds, 1 minute 30 seconds_5 seconds, 1 minute 30 seconds_3 seconds", perform time series alignment processing. First, convert both the time interval and duration to seconds, that is, "80 seconds_4 seconds, 90 seconds_5 seconds, 90 seconds_3 seconds". Assume a fixed time window length of 100 seconds is set. For time intervals less than 100 seconds, perform padding or truncation processing. The first time interval of 80 seconds is padded with 20 seconds of "0" values at the back (indicating no trading activity), becoming "80 seconds_4 seconds, 20 seconds_0 seconds, 90 seconds_5 seconds, 10 seconds_0 seconds, 90 seconds_3 seconds, 10 seconds_0 seconds". In this way, a behavior feature vector with an equal-length time window is generated. Perform corresponding processing on all trading environment feature vectors and trading behavior feature vectors in the pre-training dataset.
[0132] Step S253, generate an environmental feature training batch index list according to the dimension distribution of the normalized environmental feature vector, and generate a behavior feature training batch index list according to the time series continuity of the behavior feature vector with an equal-length time window.
[0133] For example, for the normalized environmental feature vector, assuming its dimension distribution is three-dimensional, representing device fingerprint, geographical area, and network fluctuation-related features respectively. Classify according to the values of the above dimensions. For example, according to the magnitude of the dimension value related to the device fingerprint, divide the vectors into different groups. Assume that the vectors with device fingerprint dimension values between 0 and 0.5 form one group, and those between 0.5 and 1 form another group. Number each group to generate a list of environmental feature training batch indices. For example, the group numbered 1 contains the normalized environmental feature vectors with device fingerprint dimension values between 0 and 0.5, and the group numbered 2 contains the vectors with device fingerprint dimension values between 0.5 and 1.
[0134] For the behavior feature vectors with equal-length time windows, group them according to their continuity in the time series. For example, group the vectors that are adjacent in the time series and have similar features. Assume that several behavior feature vectors are similar in terms of the change trends of time interval and verification duration, such as both showing a gradually increasing time interval and a relatively stable verification duration, and group them together. Number the above groups to generate a list of behavior feature training batch indices. For example, the group numbered A contains the behavior feature vectors with the above similar features, and the group numbered B contains other vectors with different time series features.
[0135] Step S254, divide the normalized environmental feature vectors into multiple environmental feature training subsets based on the list of environmental feature training batch indices, and divide the behavior feature vectors with equal-length time windows into multiple behavior feature training subsets based on the list of behavior feature training batch indices.
[0136] For example, according to the list of environmental feature training batch indices, extract the normalized environmental feature vectors in the group numbered 1 to form the first environmental feature training subset; extract the vectors in the group numbered 2 to form the second environmental feature training subset, and so on. For the behavior feature training subsets, according to the list of behavior feature training batch indices, extract the behavior feature vectors with equal-length time windows in the group numbered A to form the first behavior feature training subset; extract the vectors in the group numbered B to form the second behavior feature training subset, thus completing the division of the pre-training dataset.
[0137] For example, in a possible implementation manner, step S260 includes:
[0138] Step S261, input the normalized environmental feature vectors into the environmental feature encoder for hierarchical embedding processing to generate environmental high-dimensional feature vectors.
[0139] In this embodiment, taking a normalized environmental feature vector "[0.80, 0.27, 0.53]" in the first environmental feature training subset as an example, it is input into the environmental feature encoder for hierarchical embedding processing. The environmental feature encoder first extracts features for each dimension of the vector. For example, for the first dimension 0.80, through a specific mapping function, it is converted into a vector representation in a higher-dimensional space. Suppose the mapping function maps 0.80 to a vector "[0.1, 0.2, 0.3, 0.4, 0.5, 0.6, 0.7, 0.8, 0.9, 0.1]" containing 10 elements. Similar processing is performed on other dimensions of the vector, and then the processed vectors are combined together to generate an environmental high-dimensional feature vector, which is supposed to be a vector "[0.1, 0.2, 0.3, 0.4, 0.5, 0.6, 0.7, 0.8, 0.9, 0.1, 0.2, 0.3, 0.4, 0.5, 0.6, 0.7, 0.8, 0.9, 0.1, 0.2, 0.3, 0.4, 0.5]" containing 30 elements.
[0140] Step S262: Input the environmental high-dimensional feature vector into the dynamic weight allocation mechanism in the cross-dimensional association module, and perform self-attention calculation on the environmental high-dimensional feature vector based on the first dynamic weight matrix to generate an environmental self-attention feature vector.
[0141] In this embodiment, the first dynamic weight matrix is a preset matrix, and suppose its size is 30×30. For each element in the environmental high-dimensional feature vector, a dot product operation is performed with the corresponding row vector in the first dynamic weight matrix. For example, the first element 0.1 of the environmental high-dimensional feature vector performs a dot product operation with the first row vector "[0.1, 0.2, 0.3, …, 0.30]" of the first dynamic weight matrix. The calculation process is "0.1×0.1 + 0.1×0.2 + 0.1×0.3 + … + 0.1×0.30 = 0.1×(0.1 + 0.2 + 0.3 + … + 0.30) = 0.1×4.65 = 0.465". Such calculations are performed for each element of the environmental high-dimensional feature vector to obtain a new set of values. Then, the above values are normalized so that their sum is 1. Suppose a set of weight values "[0.05, 0.1, 0.15, …, 0.03]" is obtained after normalization. The above weight values are used for weighted summation with the environmental high-dimensional feature vector. For example, "0.05×0.1 + 0.1×0.2 + 0.15×0.3 + … + 0.03×0.5 = a certain value". By performing such calculations for each dimension, an environmental self-attention feature vector is generated.
[0142] Step S263: Input the environmental self-attention feature vector into the classifier for probability mapping processing to generate an environmental feature risk prediction probability.
[0143] In this embodiment, the classifier processes the environmental self-attention feature vector according to its internal parameters and algorithms. Assume that there is a set of weight parameters and bias terms inside the classifier. For each element of the environmental self-attention feature vector, multiply it by the corresponding weight parameter and add the bias term, and then pass it through an activation function, such as the Sigmoid function. For example, for the first element of the environmental self-attention feature vector, assume the weight parameter is 0.2 and the bias term is 0.1. Calculate "0.2 × this element + 0.1", and then input the result into the Sigmoid function "1 / (1 + e to the negative power of (0.2 × this element + 0.1))" to obtain an output value. Perform such calculations on all elements of the environmental self-attention feature vector, and finally obtain a value representing the environmental feature risk prediction probability, assume it is 0.6.
[0144] Step S264: Calculate the parameter gradient of the environmental feature encoder according to the cross-entropy loss calculation result between the environmental feature risk prediction probability and the risk label.
[0145] Assume the risk label of this sample is "Risk Type A", and the corresponding probability value is 1 (in cross-entropy calculation, the "Risk Type A" label usually represents a probability of 1). The formula for cross-entropy loss is "- (true label probability × log(predicted probability))", here it is "- (1 × log(0.6))". First calculate log(0.6), assume it is approximately -0.51 through logarithmic calculation. Then the cross-entropy loss is "- (1 × -0.51) = 0.51". According to this loss value, calculate the parameter gradient of the environmental feature encoder through the backpropagation algorithm. The backpropagation algorithm will adjust the parameters of the environmental feature encoder during the process of generating the environmental high-dimensional feature vector according to the loss value. For example, for a parameter in the environmental feature encoder that maps the input dimension to the high-dimensional space, determine the magnitude by which the parameter needs to be reduced according to the loss value and the gradient calculation rule. Assume that after a series of calculations, it is determined that a certain parameter needs to be reduced by 0.01.
[0146] Step S265: Update the weight parameters of the environmental feature encoder based on the parameter gradient, and synchronously update the first dynamic weight matrix in the cross-dimensional association module.
[0147] In this embodiment, the weight parameters of the environmental feature encoder can be adjusted according to the calculated parameter gradients. For example, if it is just determined that a certain parameter needs to be decreased by 0.01, then subtract 0.01 from this parameter. At the same time, according to the changes in the weight parameters of the environmental feature encoder and the current training situation, the first dynamic weight matrix in the cross-dimensional association module is updated. For example, according to the adjustment amplitude of the weight parameters of the environmental feature encoder, certain elements in the first dynamic weight matrix may be increased or decreased according to certain rules to meet the training and optimization requirements of the model.
[0148] For example, in a possible implementation manner, step S270 includes:
[0149] Step S271, input the behavior feature vectors of the equal-length time windows into the transaction behavior feature encoder for sliding window convolution processing to generate behavior high-dimensional feature vectors.
[0150] Taking the behavior feature vectors of an equal-length time window in the first behavior feature training subset, namely "80 seconds_4 seconds, 20 seconds_0 seconds, 90 seconds_5 seconds, 10 seconds_0 seconds, 90 seconds_3 seconds, 10 seconds_0 seconds" as an example, input it into the transaction behavior feature encoder for sliding window convolution processing to generate behavior high-dimensional feature vectors. The transaction behavior feature encoder will slide on the behavior feature vectors with a fixed-size window, for example, a window with a size of 3 time interval and duration combinations. For the first window "80 seconds_4 seconds, 20 seconds_0 seconds, 90 seconds_5 seconds", the encoder performs a convolution operation on it. For example, perform weighted summation on the time interval and duration respectively, assuming the weights are 0.6 and 0.4. For the time interval part "0.6×80 + 0.6×20 + 0.6×90 = 114", and for the duration part "0.4×4 + 0.4×0 + 0.4×5 = 3.6". Combine these two results and convert them into an element in a high-dimensional vector through a certain mapping function. As the window slides on the behavior feature vectors, such processing is performed on each window, and finally a behavior high-dimensional feature vector is generated, assuming it is a vector containing 20 elements, "[0.2, 0.3, 0.4,..., 0.1]".
[0151] Step S272, input the behavior high-dimensional feature vectors into the dynamic weight allocation mechanism in the cross-dimensional association module, and perform temporal attention calculation on the behavior high-dimensional feature vectors based on the second dynamic weight matrix to generate behavior temporal attention feature vectors.
[0152] In this embodiment, the second dynamic weight matrix is also a preset matrix, assumed to be of size 20×20. For each element in the high-dimensional behavior feature vector, a dot product operation is performed with the corresponding row vector in the second dynamic weight matrix. For example, the first element 0.2 of the high-dimensional behavior feature vector is dot-producted with the first row vector "[0.1, 0.2, 0.3, …, 0.20]" of the second dynamic weight matrix, and "0.2×0.1 + 0.2×0.2 + 0.2×0.3 + … + 0.2×0.20 = 0.2×(0.1 + 0.2 + 0.3 + … + 0.20) = 0.2×2.1 = 0.42". Such calculations are performed for all elements of the high-dimensional behavior feature vector to obtain a new set of values. Then, the above values are normalized so that their sum is 1, resulting in a set of weight values "[0.08, 0.12, 0.15, …, 0.05]". The above weight values are weighted and summed with the high-dimensional behavior feature vector to generate a behavior time attention feature vector.
[0153] Step S273: Input the behavior time attention feature vector into the classifier for probability mapping processing to generate a behavior feature risk prediction probability.
[0154] In this embodiment, the classifier processes the behavior time attention feature vector according to its internal parameters and algorithms. Similar to the calculation process of the environmental feature risk prediction probability, through the operations of weight parameters, bias terms, and activation functions, a value representing the behavior feature risk prediction probability is obtained, assumed to be 0.4.
[0155] Step S274: Calculate the parameter gradient of the transaction behavior feature encoder according to the calculation result of the cross-entropy loss between the behavior feature risk prediction probability and the risk label.
[0156] For example, assume that the risk label of this sample is "risk type A" and the probability value is 1. According to the cross-entropy loss calculation formula "- (true label probability × log(predicted probability))", calculate "- (1×log(0.4))". First, calculate log(0.4), which is assumed to be approximately -0.92. Then the cross-entropy loss is "- (1× -0.92) = 0.92". According to this loss value, the parameter gradient of the transaction behavior feature encoder is calculated through the backpropagation algorithm. For example, determine the adjustment amplitude required for a certain parameter in the transaction behavior feature encoder during the sliding window convolution process, assumed to be increased by 0.02 after calculation.
[0157] Step S275: Update the weight parameters of the transaction behavior feature encoder based on the parameter gradient, and synchronously update the second dynamic weight matrix in the cross-dimensional association module.
[0158] For example, according to the calculated parameter gradient, the corresponding parameter in the transaction behavior feature encoder can be increased by 0.02. At the same time, according to the change of the weight parameter of the transaction behavior feature encoder and the current training situation, the second dynamic weight matrix in the cross-dimensional association module is updated according to certain rules. For example, some elements in the matrix are adjusted accordingly to ensure the accuracy and effectiveness of the model during the training process, so that the model can be continuously optimized to better meet the requirements of transaction risk detection.
[0159] In one possible implementation manner, step S140 includes:
[0160] Step S141, parsing the risk probability value and risk type identifier in the risk determination result.
[0161] In a previously set transaction scenario, for a certain transaction sequence, after analysis by the transaction risk detection model, a risk determination result is obtained. For example, for a transaction initiated at "2023-10-03 11:15:00", the risk determination result shows that the risk probability value is 0.75 and the risk type identifier is "Risk Type A". Here, the risk probability value is a numerical value obtained by the transaction risk detection model through analyzing the transaction environment features and transaction behavior features, which reflects the likelihood of risk for this transaction sequence; the risk type identifier clarifies the category of the risk, and "Risk Type A" indicates that this transaction may have a relatively large security risk.
[0162] Step S142, when the risk probability value exceeds the first dynamic threshold, generate a first-level security policy including multi-factor authentication rules and real-time transaction blocking rules.
[0163] Suppose the first dynamic threshold is set to 0.7. In the above example, the risk probability value of 0.75 exceeds the first dynamic threshold. At this time, the multi-factor authentication rules in the generated first-level security policy require the user to provide multiple authentication methods. For example, in addition to requiring the user to enter a preset transaction password, fingerprint recognition and SMS verification code verification are also required. Fingerprint recognition is performed through the fingerprint recognition sensor of the mobile terminal. Only when the collected fingerprint matches the pre-registered fingerprint to a certain standard, the fingerprint recognition is passed. Suppose the matching standard is set to 90%, that is, when the number of matching fingerprint feature points collected and the registered fingerprint feature points reaches 90% of the total number of feature points, it is considered a successful match. The SMS verification code is a text message containing a verification code sent by the system to the user's registered mobile phone number, and the user needs to accurately enter the received verification code into the mobile terminal within a specified time, such as within 3 minutes.
[0164] The real-time transaction blocking rule stipulates that before all multi-factor authentication passes, the transaction will be blocked in real-time and cannot continue. For example, if the transaction password entered by the user is incorrect, or the fingerprint recognition does not reach 90% matching, or the SMS verification code is not correctly entered within 3 minutes, the transaction will stop immediately and no subsequent fund transfer operations will be carried out to prevent possible risky transactions from occurring.
[0165] Step S143, when the risk probability value is between the second dynamic threshold and the first dynamic threshold, generate a second-level security policy including a dynamic adjustment rule for the transaction amount and a strengthened verification process rule.
[0166] Assume that the second dynamic threshold is set to 0.5. For another transaction at "2023-10-03 11:30:00", the risk determination result shows that the risk probability value is 0.6, which is between 0.5 and 0.7. At this time, the dynamic adjustment rule for the transaction amount in the generated second-level security policy will adjust the operable amount of this transaction according to the risk probability value. For example, originally the user's transaction amount is 5000 yuan. According to the preset adjustment rule, when the risk probability value is 0.6, the transaction amount will be adjusted to 60% of the original amount, that is, 5000×60% = 3000 yuan. This means that the user can only operate a maximum of 3000 yuan of funds in this transaction.
[0167] Regarding the strengthened verification process rule, additional verification steps will be added on the basis of the regular verification process. For example, after the user enters the transaction password, the system will analyze the input time of the password. Assume that under normal circumstances, the user enters the password within 10 - 30 seconds. If the input time is too long or too short this time, such as less than 5 seconds or more than 60 seconds, the system will consider it abnormal and require the user to re-enter the password. At the same time, the system will further verify the location where the transaction is initiated. By obtaining the GPS location information of the mobile terminal and comparing it with the user's pre-set common transaction locations. If it is found that the transaction initiation location is significantly different from the common location, such as the distance exceeds 50 kilometers, the system will require the user to perform additional identity verification, such as answering preset security questions, etc.
[0168] Step S144, when the risk probability value is lower than the second dynamic threshold, generate a third-level security policy including a quick matching rule for device fingerprints and a location verification rule.
[0169] For example, for a transaction at "2023-10-03 11:45:00", the risk determination result shows that the risk probability value is 0.4, which is lower than the second dynamic threshold of 0.5. The device fingerprint quick matching rule will speed up the verification of the device fingerprint. When a transaction request is initiated, the system quickly collects the device fingerprint information of the mobile terminal and compares it with the pre-stored device fingerprint template. Suppose the device fingerprint information consists of a series of hardware identifiers and software configuration information. A fast hash algorithm is used to process the collected device fingerprint information to generate a hash value. Then, this hash value is compared with the hash value of the pre-stored device fingerprint template. For example, the hash value of the pre-stored device fingerprint template is "hash_123456", and the hash value of the collected device fingerprint is "hash_789012". The similarity of the two hash values is calculated through a comparison algorithm. Suppose the similarity calculation method is to calculate the proportion of the same characters in the two hash values. If the proportion of the same characters reaches 80%, it is considered that the device fingerprint matching is successful, and the device fingerprint verification is quickly completed.
[0170] The geographical location verification rule will verify whether the geographical location where the transaction is initiated meets the preset range. The system obtains the geographical location information of the current transaction initiation through the GPS module of the mobile terminal, such as the latitude and longitude coordinates "30.1234 N, 120.5678 E". Then, this coordinate is compared with the range of the user's preset common transaction locations. Suppose the range of the user's preset common transaction locations is a circular area with a radius of 20 kilometers centered on their home address. By calculating the distance between the current location and the home address (for example, using a distance calculation formula to convert the latitude and longitude coordinates into an actual distance), if the distance is less than 20 kilometers, it is considered that the geographical location meets the requirements and the transaction can continue; if the distance is greater than 20 kilometers, the user may be required to perform additional identity verification or take other security measures.
[0171] Step S145, dynamically configure the first-level security policy, the second-level security policy, or the third-level security policy to the policy execution queue of the transaction verification interface.
[0172] For example, for a high-risk transaction at "2023-10-03 11:15:00", the generated first-level security policy will be immediately sent to the policy execution queue of the transaction verification interface. The policy execution queue is an ordered list that stores security policies and is arranged in the chronological order of policy generation. In this policy execution queue, each security policy has a unique identifier for subsequent management and invocation. For example, the identifier of the first-level security policy is "policy_001", and it is added to the end of the policy execution queue waiting for subsequent processing.
[0173] And, step S146, create a policy priority evaluation thread in the transaction verification interface, and run the policy priority evaluation thread to calculate the policy execution priority according to the real-time load status of the current transaction request.
[0174] During the peak transaction period, for example, from 11:00 to 12:00 every day, the number of transaction requests increases significantly, and the real-time load status of the system is relatively high. The policy priority evaluation thread will monitor the load of the system in real time. For example, it evaluates the load status by counting the number of transaction requests being processed currently and the consumption of system resources (such as CPU usage rate, memory occupancy rate, etc.). Suppose the number of transaction requests being processed in the current system is 100, the CPU usage rate reaches 80%, and the memory occupancy rate reaches 70%. According to the preset evaluation rules, it is determined that the system load is relatively high at this time.
[0175] For the calculation of the policy execution priority, multiple factors are comprehensively considered. For example, the higher the risk level of the policy, the higher the priority. At the same time, the higher the system load, the relatively lower the priority of the newly generated policy. For the first-level security policy, since it is targeted at high-risk transactions, it inherently has a relatively high priority. However, in the current high-load state, its priority will be appropriately adjusted according to the load situation. Suppose the original priority of the first-level security policy is 10 (the larger the priority value, the higher the priority). Due to the current high load, according to the adjustment rule, its priority is adjusted to 8. For the second-level and third-level security policies, the priority calculation and adjustment are carried out in a similar way. For example, the original priority of the second-level security policy is 6, and it is adjusted to 4 under high load; the original priority of the third-level security policy is 4, and it is adjusted to 2. Through such calculations and adjustments, it is ensured that under different system load states, the security policies can be executed in a reasonable priority order.
[0176] Step S147, sort the security policies in the policy execution queue according to the policy execution priority, generate an ordered policy execution sequence, and allocate an independent memory cache area for each security policy in the ordered policy execution sequence.
[0177] After calculating the priorities of each security policy, sort the policy execution queue. Taking the previous example, the priority of the first-level security policy "policy_001" is adjusted to 8, the priority of the second-level security policy "policy_002" is adjusted to 4, and the priority of the third-level security policy "policy_003" is adjusted to 2. After sorting, the policy execution queue is arranged in descending order of priority, generating an ordered policy execution sequence, that is, "policy_001, policy_002, policy_003".
[0178] Allocating an independent memory cache area for each security policy is to improve the efficiency of policy execution and data security. For example, the memory cache area allocated for "policy_001" has the address "memory_area_001" and a size of 1024KB. In this memory cache area, all data related to this security policy is stored, such as the rule parameters for multi-factor authentication, the control logic for real-time transaction blocking, etc. For "policy_002" and "policy_003", independent memory cache areas "memory_area_002" and "memory_area_003" are also allocated respectively, and appropriate memory spaces are allocated according to the complexity of the policy and the size of the data volume.
[0179] Step S148, when a new transaction request event arrives, the corresponding verification rule executor is called in sequence according to the ordered policy execution sequence to generate a composite verification instruction set, and the composite verification instruction set is atomically executed through the trusted execution environment of the mobile terminal.
[0180] For example, at "2023-10-03 12:00:00", a new transaction request arrives. At this time, the system first checks the ordered policy execution sequence and finds that the first-level security policy "policy_001" is at the top. The system calls the verification rule executors related to "policy_001", namely the multi-factor authentication rule executor and the real-time transaction blocking rule executor.
[0181] The multi-factor authentication rule executor first starts the fingerprint recognition verification process. The fingerprint recognition sensor of the mobile terminal starts to work and collects the user's fingerprint information. Suppose the fingerprint information collected is processed to obtain a feature vector "fingerprint_vector_1", which is compared with the pre-stored registered fingerprint feature vector "fingerprint_vector_registered". The comparison process is to calculate the similarity between the two vectors. For example, the cosine similarity algorithm is used. Calculate the dot product of the two vectors. Suppose the dot product of "fingerprint_vector_1" and "fingerprint_vector_registered" is 0.85, and calculate the modulus lengths of the two vectors respectively. Suppose the modulus length of "fingerprint_vector_1" is 1.2 and the modulus length of "fingerprint_vector_registered" is 1.3. Then the cosine similarity is 0.85 / (1.2×1.3)≈0.54. Since the preset matching standard is 0.9, the fingerprint recognition fails at this time.
[0182] Next, the system sends a SMS verification code to the mobile phone number registered by the user according to the rule of "policy_001". Suppose the SMS verification code is "123456", and the user needs to enter it into the mobile terminal within 3 minutes. After the user enters the verification code, the system conducts verification. If the user enters it correctly, at this time, part of the multi-factor authentication passes. However, since the fingerprint recognition fails, according to the real-time transaction blocking rule, the transaction is still blocked and cannot continue.
[0183] In this process, a series of verification instructions generated by the multi-factor authentication rule executor and the real-time transaction blocking rule executor together constitute a composite verification instruction set. For example, the composite verification instruction set may include instructions such as "initiate fingerprint recognition", "send SMS verification code", "verify SMS verification code", "judge whether the transaction is blocked", etc. The above instructions are atomically executed through the trusted execution environment of the mobile terminal. The trusted execution environment is a secure execution environment, which can ensure that the above instructions will not be tampered with or interfered with during the execution process. For example, when executing the instruction of "verify SMS verification code", the trusted execution environment will strictly follow the preset verification logic and will not be affected by external malicious programs, ensuring the accuracy and security of the verification process. Only when all relevant verification instructions are correctly executed in sequence will the system decide whether the transaction continues according to the final verification result. If all verifications pass, the transaction can proceed normally; if any one verification fails, the transaction will be stopped, thus ensuring the security and reliability of the transaction.
[0184] Figure 2 FIG. shows a schematic diagram of exemplary hardware and software components of an IC card transaction security processing system 100 based on a mobile terminal system that can implement the idea of the present application provided by some embodiments of the present application. For example, the processor 120 can be used on the IC card transaction security processing system 100 based on the mobile terminal system and is used to execute the functions in the present application.
[0185] The IC card transaction security processing system 100 based on the mobile terminal system can be a general-purpose server or a special-purpose server, both of which can be used to implement the IC card transaction security processing method based on the mobile terminal system of the present application. Although only one server is shown in the present application, for convenience, the functions described in the present application can be implemented in a distributed manner on multiple similar platforms to balance the processing load.
[0186] For example, an IC card transaction security processing system 100 based on a mobile terminal system may include a network port 110 connected to a network, one or more processors 120 for executing program instructions, a communication bus 130, and different forms of storage media 140, such as disks, ROM, or RAM, or any combination thereof. Exemplarily, the IC card transaction security processing system 100 based on the mobile terminal system may further include program instructions stored in ROM, RAM, or other types of non-transitory storage media, or any combination thereof. The method of the present application can be implemented according to the above program instructions. The IC card transaction security processing system 100 based on the mobile terminal system further includes an input / output (I / O) interface 150 between the computer and other input / output devices.
[0187] For ease of explanation, only one processor is described in the IC card transaction security processing system 100 based on the mobile terminal system. However, it should be noted that the IC card transaction security processing system 100 based on the mobile terminal system in the present application may further include multiple processors. Therefore, the steps executed by one processor described in the present application may also be jointly executed or separately executed by multiple processors. For example, if the processor of the IC card transaction security processing system 100 based on the mobile terminal system executes step A and step B, it should be understood that step A and step B may also be jointly executed by two different processors or separately executed in one processor. For example, the first processor executes step A, the second processor executes step B, or the first processor and the second processor jointly execute steps A and B.
[0188] In addition, an embodiment of the present invention further provides a readable storage medium, in which computer-executable instructions are preset. When the processor executes the computer-executable instructions, the above-mentioned IC card transaction security processing method based on the mobile terminal system is implemented.
[0189] It should be noted that, in order to simplify the description of the present invention disclosure and thus help the understanding of one or more embodiments of the invention, in the previous description of the embodiments of the present invention, sometimes multiple features are merged into one embodiment, drawing, or description thereof.
Claims
1. A method for secure processing of IC card transactions based on a mobile terminal system, characterized in that, The method includes: Obtaining a historical transaction data set of a target IC card on a mobile terminal, where the historical transaction data set includes multiple transaction sequences, and each transaction sequence is composed of a transaction request event and a corresponding transaction verification event; Performing transaction feature extraction processing on the historical transaction data set to obtain the transaction environment feature and the transaction behavior feature of each transaction sequence; Invoking a pre-trained transaction risk detection model to perform transaction risk prediction on the transaction environment feature and the transaction behavior feature, and generating a risk determination result of the transaction sequence; Generating a dynamic transaction security policy based on the risk determination result, and feeding back the dynamic transaction security policy to the transaction verification interface of the mobile terminal to trigger a verification operation; Generating a feedback data set according to the execution log of the transaction verification interface, and incrementally updating the model parameters of the transaction risk detection model based on the feedback data set; The performing transaction feature extraction processing on the historical transaction data set to obtain the transaction environment feature and the transaction behavior feature of each transaction sequence includes: Performing environment parameter parsing processing on the transaction request event, and extracting the terminal device identification information, the network protocol address information, and the signal strength information when the transaction request event occurs; Generating a device fingerprint code based on the terminal device identification information, generating a geographical area code based on the network protocol address information, and generating a network fluctuation code based on the signal strength information; Performing feature fusion processing on the device fingerprint code, the geographical area code, and the network fluctuation code to generate the transaction environment feature of the transaction sequence; Performing time series analysis processing on the transaction verification event, and extracting the time interval distribution feature and the verification operation duration feature between consecutive transaction verification events; Performing time series association processing on the time interval distribution feature and the verification operation duration feature to generate the transaction behavior feature; The invoking a pre-trained transaction risk detection model to perform transaction risk prediction on the transaction environment feature and the transaction behavior feature, and generating a risk determination result of the transaction sequence includes: Invoking an environment feature encoder in the transaction risk detection model to perform hierarchical embedding processing on the transaction environment feature, and generating a first high-dimensional feature vector; Invoking a transaction behavior feature encoder to perform sliding window convolution processing on the transaction behavior feature, and generating a second high-dimensional feature vector; Inputting the first high-dimensional feature vector and the second high-dimensional feature vector into a cross-dimensional association module in the transaction risk detection model, and performing feature interaction processing on the first high-dimensional feature vector and the second high-dimensional feature vector based on a dynamic weight allocation mechanism to generate a risk association feature; Invoking a classifier in the transaction risk detection model to perform probability mapping processing on the risk association feature, and generating risk determination probability values corresponding to each risk type identifier of the transaction sequence; Generating the risk determination result according to the comparison result between the risk determination probability value and a preset threshold.
2. The IC card transaction security processing method based on a mobile terminal system according to claim 1, wherein Performing feature interaction processing on the first high-dimensional feature vector and the second high-dimensional feature vector based on the dynamic weight allocation mechanism to generate risk-associated features, including: Mapping the first high-dimensional feature vector to a query vector group, and mapping the second high-dimensional feature vector to a key vector group and a value vector group; Calculating the cosine similarity between each query vector in the query vector group and the corresponding key vector in the key vector group to generate initial attention weights; Performing normalization processing on the initial attention weights to generate a normalized attention weight distribution; Performing a weighted summation operation on the value vector group according to the normalized attention weight distribution to generate primary associated features; Performing a residual connection process on the primary associated features and the first high-dimensional feature vector to generate normalized risk-associated features.
3. The IC card transaction security processing method based on a mobile terminal system according to claim 1, characterized in that, Generating a feedback data set according to the execution log of the transaction verification interface, and incrementally updating the model parameters of the transaction risk detection model based on the feedback data set, including: Real-time capturing the operation status data of each transaction verification event in the transaction verification interface, where the operation status data includes a verification response timestamp, a verification result identifier, and an exception error code; Performing structured parsing processing on the operation status data to extract the execution efficiency index of the verification success event and the risk trigger type of the verification failure event; Performing an association annotation process on the execution efficiency index and the risk trigger type with the corresponding risk determination result to generate a timestamped feedback data set; Invoking an online learning algorithm to perform incremental sampling processing on the feedback data set to generate an incremental training sample set; Performing gradient update processing on the model parameters of the transaction risk detection model based on the incremental training sample set to adjust the model weight distribution.
4. The IC card transaction security processing method based on the mobile terminal system according to claim 3, characterized in that, Invoking an online learning algorithm to perform incremental sampling processing on the feedback data set to generate an incremental training sample set, including: Generating a data weight coefficient according to the timestamp of each feedback data in the feedback data set, where the data weight coefficient is positively correlated with the newness and oldness of the timestamp; Performing weighted random sampling processing on the feedback data set based on the data weight coefficient to generate an initial sampling data set; Performing noise injection processing on the transaction environment features and transaction behavior features in the initial sampling data set to generate an enhanced feature set; Performing a hybrid recombination process on the enhanced feature set and the original features in the initial sampling data set to generate the incremental training sample set.
5. The IC card transaction security processing method based on a mobile terminal system according to claim 1, wherein, The pre-training process of the transaction risk detection model includes: Obtaining a sample IC card transaction sample set, where the sample IC card transaction sample set includes verified secure transaction samples and marked risk transaction samples; Performing positive sample enhancement processing on the verified secure transaction samples to generate an expanded secure sample set, where the positive sample enhancement processing includes adding device fingerprint perturbations to the transaction environment features and performing time window translation on the transaction behavior features; Performing negative sample enhancement processing on the marked risk transaction samples to generate an expanded risk sample set, where the negative sample enhancement processing includes randomly replacing the network protocol address and adding noise to the verification operation duration; Merge the augmented secure sample set and the augmented risk sample set into a pre-training data set; Divide the pre-training data set into an environmental feature training batch and a behavioral feature training batch. The environmental feature training batch includes the transaction environmental features and corresponding risk labels in the augmented secure sample set and the augmented risk sample set, and the behavioral feature training batch includes the transaction behavioral features and corresponding risk labels in the augmented secure sample set and the augmented risk sample set; In the first-round training stage, fix the model parameters of the transaction behavioral feature encoder in the initial risk detection model, and use the environmental feature training batch to perform backpropagation training on the environmental feature encoder in the initial risk detection model, update the weight parameters of the environmental feature encoder, and generate a first dynamic weight matrix; In the second-round training stage, fix the model parameters of the environmental feature encoder and the first dynamic weight matrix, and use the behavioral feature training batch to perform backpropagation training on the transaction behavioral feature encoder, update the weight parameters of the transaction behavioral feature encoder, and generate a second dynamic weight matrix; In the subsequent alternating training stage, cyclically switch the input order of the environmental feature training batch and the behavioral feature training batch, and perform joint gradient optimization on the environmental feature encoder and the transaction behavioral feature encoder based on the updated first dynamic weight matrix and the second dynamic weight matrix until the change rate of the loss function of the initial risk detection model is lower than a preset convergence threshold.
6. The IC card transaction security processing method based on a mobile terminal system according to claim 5, characterized in that, The dividing the pre-training data set into an environmental feature training batch and a behavioral feature training batch includes: Extract the transaction environmental feature vector and the transaction behavioral feature vector of each sample from the pre-training data set. The transaction environmental feature vector is composed of the concatenation of the device fingerprint code, the geographical area code, and the network fluctuation code, and the transaction behavioral feature vector is composed of the concatenation of the time interval distribution feature and the verification operation duration feature; Perform standardized scaling processing on the transaction environmental feature vector to generate a normalized environmental feature vector, and perform time series alignment processing on the transaction behavioral feature vector to generate a behavioral feature vector with an equal-length time window; Generate an environmental feature training batch index list according to the dimension distribution of the normalized environmental feature vector, and generate a behavioral feature training batch index list according to the time series continuity of the equal-length time window behavioral feature vector; Divide the normalized environmental feature vector into multiple environmental feature training subsets based on the environmental feature training batch index list, and divide the equal-length time window behavioral feature vector into multiple behavioral feature training subsets based on the behavioral feature training batch index list.
7. The IC card transaction security processing method based on a mobile terminal system according to claim 1, wherein, The generating a dynamic transaction security policy based on the risk determination result and feeding back the dynamic transaction security policy to the transaction verification interface of the mobile terminal to trigger a verification operation includes: Parse the risk probability value and the risk type identifier in the risk determination result; When the risk probability value exceeds the first dynamic threshold, generate a first-level security policy including multi-factor authentication rules and real-time transaction blocking rules; When the risk probability value is between the second dynamic threshold and the first dynamic threshold, generate a second-level security policy including a dynamic adjustment rule for the transaction amount and a strengthening rule for the verification process; When the risk probability value is lower than the second dynamic threshold, generate a third-level security policy including a fast matching rule for device fingerprints and a verification rule for geographical locations; Dynamically configure the first-level security policy, the second-level security policy or the third-level security policy to the policy execution queue of the transaction verification interface; And, create a policy priority evaluation thread in the transaction verification interface, and run the policy priority evaluation thread to calculate the policy execution priority according to the real-time load status of the current transaction request; Sort the security policies in the policy execution queue according to the policy execution priority, generate an ordered policy execution sequence, and allocate an independent memory cache area for each security policy in the ordered policy execution sequence; When a new transaction request event arrives, sequentially call the corresponding verification rule executor according to the ordered policy execution sequence to generate a composite verification instruction set, and perform atomic execution processing on the composite verification instruction set through the trusted execution environment of the mobile terminal.
8. An IC card transaction security processing system based on a mobile terminal system, characterized in that, The IC card transaction security processing system based on the mobile terminal system includes a processor and a memory, the memory is connected to the processor, the memory is used to store programs, instructions or codes, and the processor is used to execute the programs, instructions or codes in the memory to implement the IC card transaction security processing method based on the mobile terminal system according to any one of claims 1-7 above.
Citation Information
Patent Citations
Risk behavior perception method and device based on deep learning
CN119939576A