Risk early warning method, device and system based on few-sample dynamic risk field

By dividing multi-dimensional risk data into few samples and residual samples, dimensionality reduction builds initial and target risk fields, and updates the risk fields in real time, it solves the problem of difficulty in dealing with dynamics and concealment in traditional risk monitoring technologies, and achieves efficient risk detection and early warning in small sample scenarios.

CN120218602APending Publication Date: 2025-06-27HUAZHONG UNIV OF SCI & TECH
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510270044.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-07
Publication Date
2025-06-27

AI Technical Summary

Technical Problem

Traditional risk monitoring technologies are difficult to effectively deal with the dynamic and concealment of social governance risks, especially in the case of small sample scenarios, the generalization ability of the model is insufficient, the static risk model is difficult to update in real time, and the complex correlation increases the difficulty of extracting key features and quantifying risk levels from high-dimensional data.

Method used

By dividing multi-dimensional risk data related to social governance into few samples and residual samples, preset dimensionality reduction methods are used to reduce potential features, initial and target risk fields are built, and the risk field is updated in real time when data changes to conduct risk warnings.

Benefits of technology

Building an efficient risk field based on a small amount of labeled data will significantly reduce data acquisition costs, improve the robustness and practicality of the model, enhance the processing ability of multi-source risk data, and improve the accuracy of risk detection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120218602A_ABST
    Figure CN120218602A_ABST
Patent Text Reader

Abstract

The invention discloses a risk early warning method, device and system based on a few-sample dynamic risk field, and belongs to the technical field of data network security. Mapping the second low-dimensional anchor nodes corresponding to the remaining samples into the initial risk field to obtain a target risk field; when any sample has data change, remapping the changed sample into the target risk field; and carrying out risk early warning according to the variable quantity between the corresponding current mapping position after the change and the corresponding initial mapping position when the change is not carried out. According to the method, the efficient risk field is constructed on the basis of a small amount of annotated data, so that the data acquisition cost is remarkably reduced. Meanwhile, in order to adapt to a highly dynamic social risk environment, a dynamic risk field modeling and online updating mechanism is adopted, so that the robustness and practicability of the model can be effectively improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of data network security, and more specifically, relates to a risk early warning method, device, and system based on a few-shot dynamic risk field. Background Art

[0002] With the acceleration of the digitalization process, social risk events such as financial fraud and cyberattacks occur frequently, and the dynamics and concealment of these events pose severe challenges to traditional risk monitoring methods. Specifically:

[0003] Data sparsity: The cost of annotating risk events is high, and new risk patterns emerge continuously, which makes the generalization ability of the model seriously insufficient in the few-shot scenario.

[0004] Dynamic adaptability: Risk sources (such as fraud means and attack patterns) change frequently, and static risk models are difficult to update in real time to cope with new threats.

[0005] Complex correlation: The multi-dimensional intertwined risk factors increase the difficulty of extracting key features from high-dimensional data and quantifying the risk level.

[0006] Current technologies mainly rely on rule engines or supervised learning methods, which require a large amount of labeled data and are difficult to adapt to the rapidly changing risk environment. For example, static risk assessment models based on historical data often fail when facing newly emerging risk patterns; traditional clustering analysis lacks in-depth mining of risk causal relationships, resulting in a high false alarm rate. In addition, existing detection systems usually rely on expert experience to define risk thresholds and cannot capture new fraud patterns. Although fully supervised deep learning models have powerful expressive capabilities, they require a large amount of labeled data support, and the model update speed lags behind the risk evolution.

[0007] In the context of the social digital transformation, events such as pension fraud, financial fraud, and cybersecurity threats occur frequently, and traditional risk monitoring technologies are difficult to effectively cope with their dynamics and concealment. For example, the fraud means in pension fraud continue to escalate, and victims are difficult to identify risks in a timely manner due to information asymmetry, resulting in economic losses and social trust crises. Summary of the Invention

[0008] In view of the above deficiencies or improvement requirements of the prior art, the present invention provides a risk early warning method, device, and system based on a few-shot dynamic risk field, aiming to solve the technical problem that traditional risk monitoring technologies are difficult to effectively cope with the dynamics and concealment of social governance risks.

[0009] To achieve the above object, according to one aspect of the present invention, a risk early warning method based on a few-shot dynamic risk field is provided, including:

[0010] S1: Divide the multi-dimensional risk data related to social governance into few-shot samples corresponding to complete risk data and remaining samples corresponding to incomplete risk data;

[0011] S2: Perform feature modeling on the few-shot samples and the remaining samples to obtain the potential feature vectors of the few-shot samples and the potential features of the remaining samples;

[0012] S3: Use the preset dimensionality reduction method to reduce the dimensionality of the potential features of the few-shot samples to obtain the first low-dimensional anchor nodes; determine the initial risk field according to the boundaries of the first low-dimensional anchor nodes;

[0013] S4: Use the preset dimensionality reduction method to reduce the dimensionality of the potential features of the remaining samples to obtain the second low-dimensional anchor nodes, and map the second low-dimensional anchor nodes into the initial risk field to obtain the target risk field;

[0014] S5: When any sample in the multi-dimensional risk data has data changes, remap the changed any sample into the target risk field;

[0015] S6: Perform risk warning according to the change amount between the current mapping position corresponding to the changed any sample and the initial mapping position corresponding to the unchanged any sample.

[0016] Further, the S6 includes: If the change amount between the current mapping position corresponding to the changed any sample and the initial mapping position corresponding to the unchanged any sample is greater than the threshold, it is considered that the any sample enters the high-risk area, and a first warning signal is generated.

[0017] Further, the S6 further includes: If it is considered that the any sample enters the high-risk area, perform causal analysis on the changed data in the any sample to find out the main risk factors causing the entry into the high-risk area; judge whether the current mapping position in the target risk field is moved to the high-risk area after other people change the main risk factors. If so, generate a second warning signal.

[0018] Further, the S2 includes: Perform preprocessing of cleaning, normalization and feature extraction on the multi-dimensional risk data including the few-shot samples and the remaining samples; perform feature modeling on the preprocessed few-shot samples and the remaining samples to obtain the potential features of the few-shot samples and the potential features of the remaining samples.

[0019] Further, the preprocessing further includes: Perform outlier removal operations and missing value filling operations on the few-shot samples and the remaining samples respectively.

[0020] Further, the preset dimensionality reduction method is the independent component analysis method or t-SNE.

[0021] Further, determining an initial risk field according to the boundary of the first low-dimensional anchor node includes: determining the risk level of the corresponding area according to the risk boundary mapped by the first low-dimensional anchor node to construct an original risk field; and performing denoising processing on the original risk field to obtain the initial risk field.

[0022] According to another aspect of the present invention, there is provided a risk warning device based on a few-shot dynamic risk field, including:

[0023] A partitioning module for partitioning multi-dimensional risk data related to social governance into a few-shot corresponding to complete risk data and a remaining sample corresponding to incomplete risk data;

[0024] A modeling module for performing feature modeling on the few-shot and the remaining sample to obtain the potential feature vector of the few-shot and the potential features of the remaining sample;

[0025] A first dimensionality reduction module for reducing the dimension of the potential features of the few-shot by using the preset dimensionality reduction method to obtain a first low-dimensional anchor node; and determining an initial risk field according to the boundary of the first low-dimensional anchor node;

[0026] A second dimensionality reduction module for reducing the dimension of the potential features of the remaining sample by using the preset dimensionality reduction method to obtain a second low-dimensional anchor node, and mapping the second low-dimensional anchor node into the initial risk field to obtain a target risk field;

[0027] A mapping module for remapping the changed arbitrary sample into the target risk field when there is a data change in any sample in the multi-dimensional risk data;

[0028] A warning module for performing risk warning according to the change amount between the current mapping position corresponding to the changed arbitrary sample and the initial mapping position corresponding to the unchanged arbitrary sample.

[0029] According to another aspect of the present invention, there is provided a risk warning system including a memory and a processor, where the memory stores a computer program, and the processor implements the steps of the above risk warning method when executing the computer program.

[0030] According to another aspect of the present invention, there is provided a computer-readable storage medium storing a computer program, and the computer program implements the steps of the above risk warning method when executed by a processor.

[0031] Generally speaking, compared with the prior art by the above technical solution conceived by the present invention, the following beneficial effects can be achieved:

[0032] (1) The present invention provides a risk warning method based on a few-shot dynamic risk field, which determines an initial risk field based on the boundaries of the first low-dimensional anchor nodes corresponding to the few-shot samples, and maps the second low-dimensional anchor nodes corresponding to the remaining samples into the initial risk field to obtain a target risk field; when any sample in the multi-dimensional risk data has data changes, remap the changed any sample into the target risk field; and perform risk warning according to the change amount between the current mapping position corresponding to the any sample after the change and the initial mapping position corresponding to the any sample when it has not changed. The present invention constructs an efficient risk field based on a small amount of labeled data, thereby significantly reducing the data acquisition cost. At the same time, to adapt to the highly dynamic social risk environment, the dynamic risk field modeling and online update mechanism can effectively improve the robustness and practicality of the model. Aiming at the problems of high dimensionality, low information density, and noise interference existing in multi-source risk data, the feature space can be effectively compressed through denoising techniques and contrast learning, redundant information can be reduced, and further the accuracy of risk detection can be improved, providing strong support for coping with the increasingly complex modern social risks. BRIEF DESCRIPTION OF THE DRAWINGS

[0033] Figure 1 FIG. is a flowchart of the risk warning method based on a few-shot dynamic risk field provided in Embodiment 1 of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0034] In order to make the objectives, technical solutions and advantages of the present invention clearer and more understandable, the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention. In addition, the technical features involved in the various embodiments of the present invention described below can be combined with each other as long as they do not conflict with each other.

[0035] Embodiment 1

[0036] As Figure 1As shown in the figure, this embodiment provides a risk early warning method based on a few-shot dynamic risk field, including: S1: Divide the multi-dimensional risk data related to social governance into a few-shot corresponding to the complete risk data and the remaining samples corresponding to the incomplete risk data; S2: Perform feature modeling on the few-shot and the remaining samples to obtain the potential feature vectors of the few-shot and the potential features of the remaining samples; S3: Use a preset dimensionality reduction method to reduce the dimension of the potential features of the few-shot to obtain the first low-dimensional anchor node; determine the initial risk field according to the boundary of the first low-dimensional anchor node; S4: Use a preset dimensionality reduction method to reduce the dimension of the potential features of the remaining samples to obtain the second low-dimensional anchor node, and map the second low-dimensional anchor node into the initial risk field to obtain the target risk field; S5: When any sample in the multi-dimensional risk data has data changes, remap the changed any sample into the target risk field; S6: Perform risk early warning according to the change amount between the current mapping position corresponding to any sample after the change and the initial mapping position corresponding to any sample when it has not changed.

[0037] The present invention constructs an efficient risk field on the basis of a small amount of labeled data by introducing semi-supervised learning and contrast learning techniques, thereby significantly reducing the data acquisition cost. At the same time, in order to adapt to the highly dynamic social risk environment, the use of dynamic risk field modeling and online update mechanisms can effectively improve the robustness and practicality of the model. Aiming at the problems of high dimensionality, low information density and noise interference existing in multi-source risk data, the feature space can be effectively compressed and redundant information can be reduced through denoising techniques and contrast learning, thereby improving the accuracy of risk detection and providing strong support for coping with the increasingly complex modern social risks.

[0038] Specifically, for data acquisition in S1: First, collect multi-dimensional risk data from various sources (such as financial transaction records, network logs, user behavior analysis, etc.). These data may include multiple dimensions such as timestamps, amounts, geographical locations, user interaction patterns, etc. Complete data screening: Based on the data integrity criteria (for example, all key fields exist and there are no obvious errors), screen out the complete data set from the collected data as the "few-shot". This step is crucial for ensuring the effectiveness of subsequent steps, because any missing or outlier values may lead to model bias.

[0039] Specifically, the feature modeling in S2 includes a model selection process and a potential feature generation process. First, select a suitable feature modeling method according to the application scenario. For example, principal component analysis (PCA) can be used to reduce the data dimension and extract the main components, or t-SNE can be used for non-linear dimensionality reduction to better capture complex patterns. The potential features are generated through the above methods, and these features can more effectively represent the core structure of the original data and provide a basis for subsequent risk assessment.

[0040] Specifically, the dimensionality reduction process in S3 and S4 involves low-dimensional representation and parameter tuning. Low-dimensional representation: Apply the selected dimensionality reduction technique to process the few-shot latent features to obtain low-dimensional anchor nodes. This not only reduces the computational burden but also helps to focus on the most important features, facilitating the construction of an effective risk field. Parameter tuning: During the dimensionality reduction process, it may be necessary to adjust parameters through methods such as cross-validation to achieve the best dimensionality reduction effect.

[0041] Among them, regarding the construction of the initial risk field: Use a specific algorithm to determine its risk boundary, thereby constructing the initial risk field. This process requires precisely defining which regions are considered high-risk areas. For example, algorithms such as Support Vector Machine (SVM) or Local Outlier Factor (LOF) can be used to identify and delimit high-risk regions to ensure the accuracy of risk assessment. Regarding the construction of the target risk field: To further optimize the accuracy of risk assessment, denoise the initial risk field to eliminate unnecessary interference factors and generate a more precise target risk field. This step helps to improve the accuracy of the final risk assessment. Filters or robust statistical methods can be used to remove noise to ensure that the risk field reflects the true distribution of high-risk regions.

[0042] Among them, the mapping of incomplete data in S4 includes data mapping and continuous update. Data mapping means: Map the remaining unlabeled or partially labeled incomplete risk data into the target risk field through a similar dimensionality reduction method to complete the overall construction of the risk field. This process ensures that all available information is fully utilized, improving the comprehensiveness and accuracy of the model. Continuous update means: As new data is continuously added, regularly update the risk field to maintain its timeliness and effectiveness.

[0043] Among them, the risk warning in S6 involves: real-time update and warning mechanism. Real-time update: When new data changes occur, remap the affected samples to the complete risk field and perform causal analysis based on their position changes. This step emphasizes the dynamic adaptation ability of the system. The warning mechanism means: If a new position is found to be in a high-risk area, issue a warning signal; at the same time, compare the risk field position changes of other samples after changing the same risk factors to verify the effectiveness of the warning. In addition, an automated feedback mechanism can be set up to allow the system to self-learn and improve.

[0044] Furthermore, S6 includes: If the change amount between the current mapping position corresponding to any sample after modification and the initial mapping position corresponding to the same sample when it has not changed is greater than the threshold, it is considered that the sample enters the high-risk area and a first warning signal is generated.

[0045] Further, S6 further includes: if it is considered that any sample enters the high-risk area, perform causal analysis on the changing data in any sample to find out the main risk factors that cause the entry into the high-risk area; determine whether the current mapping position in the target risk field is moved to the high-risk area after changing the main risk factors in other populations, and if so, generate a second warning signal.

[0046] Further, S2 includes: performing preprocessing of cleaning, normalization, and feature extraction on the multi-dimensional risk data of the remaining samples including few samples; performing feature modeling on the preprocessed few samples and remaining samples to obtain the potential features of the few samples and the potential features of the remaining samples.

[0047] Specifically, the cleaning process is as follows: remove outliers and duplicates from the data, and fill in missing values. This process can be completed using statistical methods (such as the Z-score method to identify outliers) or machine learning techniques (such as the KNN algorithm to fill in missing values). The normalization process is as follows: in order to eliminate the scale differences between different features, use normalization techniques (such as Min-Max scaling or Z-score standardization) to adjust all features to the same scale. The feature extraction process is as follows: use feature selection algorithms (such as recursive feature elimination RFE or model-based importance scoring) to extract the most valuable features from the original data. This step helps to reduce redundant information and improve the performance of subsequent models.

[0048] Further, the preprocessing further includes: performing outlier removal operations and missing value filling operations on the remaining samples of the few samples respectively.

[0049] Further, the preset dimensionality reduction method is the independent component analysis method or t-SNE. Among them, use dimensionality reduction techniques such as principal component analysis (PCA) and t-SNE to convert the potential features of the few samples into a low-dimensional representation, and generate low-dimensional anchor nodes. The purpose is to reduce the computational complexity while retaining the most important information. Through dimensionality reduction processing, not only can the computational cost be reduced, but also the core features of the data can be better focused on, preparing for constructing the initial risk field.

[0050] Further, determining the initial risk field according to the boundary of the first low-dimensional anchor node includes: determining the risk level of the corresponding area according to the risk boundary mapped by the first low-dimensional anchor node to construct the original risk field; performing denoising processing on the original risk field to obtain the initial risk field.

[0051] Among them, the boundary is defined as follows: Use a specific algorithm (such as Support Vector Machine SVM or Local Outlier Factor LOF) to determine the risk boundary of low-dimensional anchor nodes, and initially construct an initial risk field. This step involves defining which regions are considered high-risk areas, and usually requires combining domain knowledge and data analysis results. The risk level is divided as follows: According to the different degrees of risk, the regional division within the risk field can be further refined to more accurately locate high-risk points.

[0052] In addition, the initial risk field obtained by denoising the original risk field includes: noise elimination and fine adjustment. Noise elimination refers to: Using denoising techniques (such as filters, robust statistical methods, etc.) to optimize the initial risk field and remove unnecessary interference factors. This step is crucial for improving the accuracy of the final risk assessment. Fine adjustment refers to: According to actual needs, it may also be necessary to finely adjust the denoised risk field to ensure that it can accurately reflect the true risk distribution.

[0053] Embodiment 2

[0054] This embodiment provides a risk warning device based on a few-shot dynamic risk field, including:

[0055] A partitioning module, configured to partition multi-dimensional risk data related to social governance into a few-shot corresponding to complete risk data and a remaining sample corresponding to incomplete risk data;

[0056] A modeling module, configured to perform feature modeling on the few-shot and the remaining sample to obtain a potential feature vector of the few-shot and potential features of the remaining sample;

[0057] A first dimensionality reduction module, configured to perform dimensionality reduction on the potential features of the few-shot using a preset dimensionality reduction method to obtain a first low-dimensional anchor node; determine an initial risk field according to the boundary of the first low-dimensional anchor node;

[0058] A second dimensionality reduction module, configured to perform dimensionality reduction on the potential features of the remaining sample using a preset dimensionality reduction method to obtain a second low-dimensional anchor node, and map the second low-dimensional anchor node into the initial risk field to obtain a target risk field;

[0059] A mapping module, configured to, when any sample in the multi-dimensional risk data has data changes, remap the changed any sample into the target risk field;

[0060] A warning module, configured to perform risk warning according to the change amount between the current mapping position corresponding to any sample after change and the initial mapping position corresponding to any sample when it has not changed.

[0061] Embodiment 3

[0062] This embodiment provides a risk warning system, which includes a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, the steps of the above-mentioned risk warning method are implemented.

[0063] Embodiment 4

[0064] This embodiment provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps of the above-mentioned risk warning method are implemented.

[0065] Those skilled in the art can easily understand that the above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent replacements, and improvements made within the spirit and principle of the present invention should be included in the protection scope of the present invention.

Claims

1. A risk warning method based on a small number of sample dynamic risk fields, characterized in that: include: S1: Divide the multidimensional risk data related to social governance into a small number of samples corresponding to complete risk data and the remaining samples corresponding to incomplete risk data; S2: performing feature modeling on the minority samples and the remaining samples to obtain potential feature vectors of the minority samples and potential features of the remaining samples; S3: using the preset dimensionality reduction method to reduce the dimensionality of the potential features of the few samples to obtain a first low-dimensional anchor node; determining an initial risk field according to the boundary of the first low-dimensional anchor node; S4: using the preset dimensionality reduction method to reduce the dimensionality of the potential features of the remaining samples to obtain a second low-dimensional anchor node, and mapping the second low-dimensional anchor node to the initial risk field to obtain a target risk field; S5: When there is data change in any sample in the multi-dimensional risk data, re-map the modified sample to the target risk field; S6: issuing a risk warning according to the amount of change between the current mapping position corresponding to the modification of the arbitrary sample and the initial mapping position corresponding to the unchanged arbitrary sample.

2. The risk early warning method based on a small number of sample dynamic risk fields as claimed in claim 1, characterized in that: The S6 includes: If the amount of change between the current mapping position corresponding to the modification of the arbitrary sample and the initial mapping position corresponding to the unchanged arbitrary sample is greater than a threshold, it is considered that the arbitrary sample enters a high-risk area and a first warning signal is generated.

3. The risk early warning method based on a small number of sample dynamic risk fields as claimed in claim 2, characterized in that: The S6 further includes: If it is considered that the arbitrary sample has entered the high-risk area, a causal analysis is performed on the change data in the arbitrary sample to find out the main risk factors causing the entry into the high-risk area; It is determined whether the current mapping position in the target risk field is moved to a high-risk area after other groups of people change the main risk factors, and if so, a second warning signal is generated.

4. The risk early warning method based on a small number of sample dynamic risk fields as claimed in claim 1, characterized in that: The S2 includes: Preprocessing the multidimensional risk data of the remaining samples including the minority samples by cleaning, normalizing and feature extraction; Feature modeling is performed on the preprocessed minority samples and the remaining samples to obtain potential features of the minority samples and potential features of the remaining samples.

5. The risk early warning method based on a small number of sample dynamic risk fields as claimed in claim 4, characterized in that: The preprocessing further includes: performing an outlier removal operation and a missing value filling operation on the remaining samples of the minority samples respectively.

6. The risk early warning method based on a small number of sample dynamic risk fields as claimed in claim 1, characterized in that: The preset dimensionality reduction method is autonomous component analysis or t-SNE.

7. The risk early warning method based on a small number of sample dynamic risk fields according to claim 1, characterized in that: Determining the initial risk field according to the boundary of the first low-dimensional anchor node includes: determining the risk level of the corresponding area according to the risk boundary mapped by the first low-dimensional anchor node to construct an original risk field; and denoising the original risk field to obtain the initial risk field.

8. A risk warning device based on a small number of sample dynamic risk fields, characterized in that: include: A partitioning module, used to partition the multidimensional risk data related to social governance into a small number of samples corresponding to the complete risk data and a remaining sample corresponding to the incomplete risk data; A modeling module, used for performing feature modeling on the minority samples and the remaining samples to obtain potential feature vectors of the minority samples and potential features of the remaining samples; A first dimensionality reduction module, configured to reduce the dimensionality of the potential features of the few samples by using the preset dimensionality reduction method to obtain a first low-dimensional anchor node; and determine an initial risk field according to the boundary of the first low-dimensional anchor node; A second dimensionality reduction module, configured to use the preset dimensionality reduction method to reduce the dimensionality of the potential features of the remaining samples to obtain a second low-dimensional anchor node, and map the second low-dimensional anchor node to the initial risk field to obtain a target risk field; A mapping module, used for re-mapping any sample after the change to the target risk field when there is data change in any sample in the multi-dimensional risk data; The early warning module is used to issue a risk early warning according to the change between the current mapping position corresponding to the modification of the arbitrary sample and the initial mapping position corresponding to the unchanged arbitrary sample.

9. A risk early warning system, comprising a memory and a processor, wherein the memory stores a computer program, characterized in that: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 7 are implemented.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 7 are implemented.