Interception method and system for abnormal logistics
By collecting and analyzing logistics data, identifying abnormal aggregation points and black industry networks, and optimizing interception strategies, the problem of difficult black industry activities in the logistics network is solved, effectively predicting and preventing potential fraudulent behaviors, and reducing economic losses.
Patent Information
- Application Number
- CN202510728557.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-03
- Publication Date
- 2025-07-01
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
The lack of a global perspective of the logistics network in existing logistics technologies, making it difficult to effectively block complex black industry activities, resulting in the neglect of key risks, increasing operating costs and reducing market competitiveness.
By collecting logistics data on order time, location and return rate, mining frequent return points areas, conducting geographical analysis to identify abnormal gathering points, establishing a correlation chart between the shipper, the receiving party and the logistics node, analyzing the logistics black industry network, and optimizing the interception strategy to detect abnormal transactions.
The data mining process is optimized, complex anomalies can be identified, risk assessment and prevention strategies are provided, and the ability to predict and prevent potential fraud is enhanced, and economic losses caused by black industry networks are reduced.
Smart Images

Figure CN120235543A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of logistics technology, and in particular to an interception method and system for abnormal logistics. Background Art
[0002] The field of logistics technology involves the design, implementation, and management of the effective flow and storage of materials, information, and funds from the origin to the point of consumption. This field adopts a variety of technical solutions to improve supply chain efficiency, reduce operating costs, and optimize resource allocation.
[0003] However, in the existing logistics technology, there is a lack of a global perspective on the logistics network, making it difficult to grasp and block complex black production activities, which limits the ability of enterprises to cope with the challenges of the global supply chain. The failure to effectively integrate and analyze multi-source data points often leads to the neglect of key risks, increases operating costs, and reduces market competitiveness. Therefore, improvements are needed. Summary of the Invention
[0004] The purpose of the present invention is to solve the drawbacks existing in the prior art, and to propose an interception method and system for abnormal logistics.
[0005] To achieve the above purpose, the present invention adopts the following technical solutions. An interception method for abnormal logistics includes the following steps: Collect logistics data of order time, location, and return rate, mine the area of frequent return points to obtain a preliminary data analysis result; through geographical analysis, identify abnormal aggregation points in the logistics network to obtain a geographical analysis result; Based on the preliminary data analysis result and the geographical analysis result, classify abnormal return points and abnormal traffic order areas, identify abnormal patterns to obtain an abnormal pattern recognition result; perform behavior pattern learning on the abnormal pattern recognition result to obtain a behavior pattern learning result; Adopt the behavior pattern learning result to establish an association graph between the shipper, consignee, and logistics nodes, analyze the association graph, identify the logistics black production network to obtain a logistics network analysis result; based on the logistics network analysis result, adjust the interception parameters to obtain an optimized interception strategy result; Use the optimized interception strategy result to perform abnormal transaction detection, monitor the receiving address and account to obtain a transaction monitoring result.
[0006] Preferably, the step of obtaining the preliminary data analysis result is as follows: Collect the timestamp, location, and return rate of each order to obtain a preliminary order data set; Based on the preliminary order data set, calculate the return probability of each location. The calculation formula is: ; Where Returns the probability of returns for a location where is a set of orders is the location of the return orders is the location and is the number of return orders for the location Based on the return probability, filter out the risk locations where the return probability exceeds the set threshold, form a frequent return point area, and obtain the preliminary data analysis result.
[0007] Preferably, the steps for obtaining the geographical analysis result are as follows: Extract all order delivery points from the logistics network, record the latitude and longitude coordinates of each delivery point, and construct a delivery point coordinate set. Count the number of orders at each delivery point to obtain the geographical distribution data of the delivery points. Based on the geographical distribution data of the delivery points, calculate the abnormal aggregation degree of each delivery point. The calculation formula is: ; where represents the abnormal aggregation degree of the delivery point is the total number of delivery points is the latitude and longitude coordinates of the delivery point is the latitude and longitude coordinates of the currently analyzed delivery point is the number of orders at the delivery point is the number of orders at the delivery point is the number of return orders at the delivery point is the number of order cancellations at the delivery point is the number of order cancellations at the delivery point is the number of order cancellations at the delivery point is the number of return orders at the delivery point is the number of return orders at the delivery point is the number of order cancellations at the delivery point is the number of order cancellations at the delivery point is the number of order cancellations at the delivery point is the number of order cancellations at the delivery point; Based on the abnormal aggregation degree, determine the abnormal aggregation points in the logistics network to obtain the geographical analysis result.
[0008] Preferably, the steps for obtaining the abnormal pattern recognition result are as follows: According to the preliminary data analysis result and the geographical analysis result, construct an abnormal order area data set to obtain abnormal order area data. Based on the abnormal order area data, calculate the abnormal fitness of each area. The expression is: ; where represents the identifier of a specific area represents the abnormal fitness of the area is the abnormal fitness of the area Total number of orders within the representative area and and respectively represent the order quantity and the number of return times of the th order in the area and respectively represent the order quantity and the number of return times of the th order in the area represents the average order quantity of the area represents the average number of return times of the area ; Based on the abnormal fitness, an abnormal pattern classification is formed according to the level of the abnormal fitness, and an abnormal pattern recognition result is obtained.
[0009] Preferably, the steps for obtaining the behavior pattern learning result are as follows: According to the abnormal pattern recognition result, extract the order features, return behaviors, transaction frequencies, and geographical distribution information corresponding to various abnormal patterns, screen the abnormal transaction records, and obtain the abnormal order behavior feature data; Based on the abnormal order behavior feature data, analyze the activity level of the abnormal patterns in different time periods, count the distribution of the abnormal behaviors in the target time interval, classify the abnormal transaction types, and obtain the abnormal behavior pattern data; Based on the abnormal behavior pattern data, analyze the similarity between the abnormal behaviors, judge the aggregation degree of the abnormal behaviors, classify the abnormal behavior pattern categories, and extract the change trend of the abnormal behavior patterns to obtain the behavior pattern learning result.
[0010] Preferably, the steps for obtaining the logistics network analysis result are as follows: According to the behavior pattern learning result, extract all transaction records of the shipper, consignee, and logistics nodes, including order numbers, transaction times, transaction frequencies, the number of return occurrences, and abnormal order flag information, organize the transaction paths between the shipper and the consignee, and arrange all transaction path data in chronological order, remove duplicate paths and isolated transaction points, and obtain the transaction path association data; Based on the transaction path association data, construct a logistics transaction relationship network, use the shipper, consignee, and logistics nodes as vertices in the graph, use the transaction paths and transaction times as the connection attributes of the edges, organize the interaction structure between the logistics nodes, screen the abnormal transaction relationship chains, and obtain the logistics network graph structure; Based on the logistics network graph structure, screen the paths including abnormal transaction frequencies and return concentration degrees to obtain the logistics network analysis result.
[0011] Preferably, the steps for obtaining the optimized result of the interception strategy are as follows: According to the logistics network analysis result, extract the transaction data of the shipper, consignee, and logistics nodes involved in the abnormal transaction chain to obtain the abnormal transaction chain parameter data; Based on the abnormal transaction chain parameter data, calculate the interception fitness, and the calculation formula is: ; Wherein, represents the interception fitness of path , is the total number of abnormal transaction paths, is the number of transactions of path , is the return ratio of path , is the return ratio of path , is the number of rejected orders of path , is the number of cancelled orders of path ; Based on the interception fitness, screen the abnormal transaction paths that need to be intercepted, update the interception rules of the shipper, consignee, and logistics nodes, set the interception strategy parameters, and obtain the optimized result of the interception strategy.
[0012] Preferably, the steps for obtaining the transaction monitoring result are as follows: Based on the optimized result of the interception strategy, implement real-time monitoring of all transactions, record all potential abnormal activities, and generate an abnormal transaction report; Based on the abnormal transaction report, investigate the transactions identified as suspicious, verify the legality of the transactions, and update the monitoring parameters and rules according to the investigation results to obtain the transaction monitoring result.
[0013] The present invention provides an interception system, including: A data collection module that collects the time data, location data, and return rate data of the target order to generate a data set; A preliminary analysis module that, based on the data set, performs frequency statistics, identifies abnormal return points, and obtains a preliminary analysis result; A geographical identification module that uses the preliminary analysis result to perform geographical location clustering, identifies abnormal aggregation points, and obtains a geographical identification result; A pattern learning module that, based on the geographical identification result, classifies abnormal return points and abnormal traffic, identifies abnormal behavior patterns, performs behavior pattern learning, and outputs a pattern learning result; A network analysis module that uses the pattern learning result to construct an association graph between the shipper and the consignee, identifies the black production network, adjusts the interception strategy based on the network structure, and generates a network analysis result.
[0014] Compared with the prior art, the advantages and positive effects of the present invention are as follows: In the present invention, the data mining process is optimized, enabling valuable insights to be extracted from regions with high return rates and abnormal aggregation points in the logistics network. Furthermore, by analyzing this data, complex abnormal patterns can be identified. This in-depth analysis provides risk assessment and prevention strategy formulation, enhancing the ability to predict and prevent potential fraud. Using association graphs to analyze data associations in the logistics network can reveal deeper structures and potential risks, enabling logistics companies to take measures before problems occur and effectively reducing economic losses caused by black production networks. BRIEF DESCRIPTION OF THE DRAWINGS
[0015] Figure 1 It is a schematic diagram of the steps of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0016] In order to make the objectives, technical solutions and advantages of the present invention clearer, the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention.
[0017] Please refer to Figure 1 , the present invention provides a technical solution, an interception method for abnormal logistics, including the following steps: Collect logistics data on order time, location, and return rate, mine regions with frequent return points, and obtain preliminary data analysis results; through geographical analysis, identify abnormal aggregation points in the logistics network and obtain geographical analysis results.
[0018] Based on the preliminary data analysis results and geographical analysis results, classify abnormal return points and abnormal traffic order regions, identify abnormal patterns, and obtain abnormal pattern recognition results; perform behavior pattern learning on the abnormal pattern recognition results to obtain behavior pattern learning results.
[0019] Adopt the behavior pattern learning results, establish an association graph between the shipper, consignee, and logistics nodes, analyze the association graph, identify the logistics black production network, and obtain logistics network analysis results; based on the logistics network analysis results, adjust the interception parameters to obtain optimized interception strategy results.
[0020] Use the optimized interception strategy results to detect abnormal transactions, monitor the delivery address and account, and obtain transaction monitoring results.
[0021] The steps for obtaining the preliminary data analysis results are as follows: Collect the timestamp, location, and return rate of each order to obtain a preliminary order data set; Based on the preliminary order dataset, calculate the return probability for each location, with the calculation formula as follows: ; where represents the return probability of location , is the order set, is the location of the returned order, is the location 's order return count; Based on the return probability, screen the risk locations with a return probability exceeding the set threshold to form a frequent return point area, and obtain the preliminary data analysis result.
[0022] Specifically, when collecting the timestamp, location, and return rate of orders, the timestamp in the system needs to adopt the YYYY-MM-DD HH:MM:SS format and record the moment information accurate to the second. The location information is obtained through GPS coordinates and discrete address numbers and converted into a unique identifier for recording. The return rate value ranges from 0 to 1 and is obtained by dividing the actual return quantity of each order by the total number of goods in the order. Subsequently, the three pieces of information are matched by order number and recorded in the database table. By continuously collecting thousands of order data, the integrity of the timestamps can be uniformly checked, and records with inconsistent formats can be excluded. By comparing with the range from 0 to 1, it can be confirmed whether the return rate value is within a reasonable range, and outliers can be excluded. The location data is used to match the longitude and latitude coordinates by parsing the pre-saved geographical location mapping table and generate the corresponding unique address identifier. During the location mapping process, duplicate and conflicting location numbers need to be checked and split for storage. After each record is summarized, a time series structure can be formed according to the timestamp. Referring to the monitoring and collection process implemented in the same database structure in the past, this collection covers nearly 50,000 order information of each location within seven days, and more than 1,000 returned orders are marked. By separately counting the return rate information for returned orders and non-returned orders and combining the location distribution data, a preliminary order dataset containing fields such as timestamp, location number, and return rate is formed.
[0023] The benefit of the formula is that it can combine the distance decay between locations and the logarithmic mapping of return counts. Through the comprehensive analysis of geographical location distance and return frequency, it quantifies the relationship between geographical factors and return frequency, and statistically identifies locations with a relatively high degree of deviation, which has direct reference significance for the subsequent formation of an abnormal interception strategy based on geographical location; The acquisition steps of parameter : Represents the location number, with the numerical type being a positive integer, used to distinguish different locations within the system. The specific acquisition method is to first assign a unique identification number to each location, then read the mapping table of numbers and addresses from the location information in the database and record the corresponding relationship between the number and the corresponding longitude and latitude coordinates. By combining the obtained location number with the transaction data completed at that location for the corresponding order, The actual range depends on the number of locations covered by the business. For example, when the system monitors five stations, It can take values between 1 and 5. In a detection implementation, the five locations that have been collected are numbered 1, 2, 3, 4, and 5 respectively, and they are written into the location number table.
[0024] Parameter Acquisition steps: Represents the scale of the order set, which consists of all the recorded orders in the system for the purpose of counting the total number of orders. It can be obtained by selecting order records that meet the time interval conditions and have been successfully submitted in the database. Each order contains information such as order number, quantity of goods, order placement time, payment amount, etc., constituting a complete order list. The scale of the order set depends on the progress of the actual sales business and can be determined by performing a statistical query in the ERP system and judging whether this order is included based on the order status field being "ordered" and "shipped". During a monitoring process, it is found that the number of valid orders generated by the business system in the recent seven days is 5,200, thus obtaining .
[0025] Parameter Acquisition steps: Represents the location number of the return order. By retrieving information such as the return flag field in the order table, the orders with the return status of "returned" are found and mapped to the specific location number, and then these location numbers are used as The value of. The size is between 1 and the maximum value of the location number, and this value can be obtained by identifying the location marked by the more concentrated return locations. In an actual monitoring, by querying the return order records in the recent three days, it is found that 15 return orders all belong to the warehousing site with the location number 3, and they are recorded as .
[0026] Parameter Acquisition steps: Represents the location The corresponding number of order returns can be obtained by querying the order table for the location number All orders are tallied and the total number of orders with the return flag marked as "returned" is accumulated, resulting in a non - negative integer value. The larger the value, the more times returns occur at that location. To incorporate into the system monitoring process, it is necessary to traverse all relevant orders for each location and count the return records. Taking the data obtained from an actual collection as an example, for location 1, there are a total of 300 orders in seven days, and 15 of them are return orders. Then ; for location 2, the total number of return orders is 35, then . And so on, the for all locations can be obtained.
[0027] Calculation process: In a specific monitoring environment, let contain the order sets corresponding to five locations, . Let the number of return times at these five locations be in turn, and let represent the location number where return orders occur at location 3. Calculate the distance numbers between locations to get
[0028] Substitute these values into the summation symbol for calculation. First, calculate the distance attenuation factor part:
[0029] Numerically, , so the above summation result is approximately , and then divide by to get the average distance factor:
[0030] Next, select locations for an example of calculating the return probability. , then:
[0031] Multiply the above intermediate results to get:
[0032] This result indicates that the return probability at location 2 is approximately 1.4389. When this value is greater than 1, it means that the location is relatively active in terms of returns. Combining the obtained previously and the location distance number information, the return risk of this location can be further marked for subsequent judgment on whether this location enters the interception range and becomes a key focus object; Based on the return probability, a risk threshold needs to be set to determine whether the return probability of a location reaches a critical level. The value of the threshold can be derived from actual monitoring results. For example, by calculating the average return probability of all locations in the most recent month and adding a coefficient offset to this average to obtain the risk threshold. The specific method is to first sum up the return probabilities of each location during this time period to get a total value S1, calculate the number of locations N, then let the average return probability M1 = S1 / N, measure the fluctuations of M1 within the range of 0 to 2 and set an adjustable coefficient K. Since it is found during the monitoring process that the return probabilities of most locations are concentrated between 0.5 and 1.2, K is selected as 0.2. By calculating T = M1 + K to obtain the threshold T and comparing it with the return probabilities of each location, when it is found that the return probability exceeds T, that location is classified as a risk location and the number of such locations is counted. Subsequently, these risk locations are aggregated and marked on the geographical coordinates, and risk points that are relatively close are further merged to form continuous regional groups to avoid marking two adjacent locations as separate risk points. Finally, a list of areas with frequent return points is output and recorded in the database. Combining all the address mapping information obtained previously, the true geographical distribution of these high-return-probability areas can be accurately located, and preliminary data analysis results can be obtained.
[0033] The steps to obtain the geographical analysis results are as follows: Extract all order delivery points from the logistics network, record the latitude and longitude coordinates of each delivery point, and construct a set of delivery point coordinates. Count the number of orders at each delivery point to obtain the geographical distribution data of the delivery points. Based on the geographical distribution data of the delivery points, calculate the abnormal aggregation degree of each delivery point. The calculation formula is: ; Where, represents the abnormal aggregation degree of delivery point , is the total number of delivery points, is the latitude and longitude coordinates of delivery point , is the latitude and longitude coordinates of the currently analyzed delivery point, is the order quantity of delivery point , is the order quantity of delivery point , is the number of return orders of delivery point , is the number of order cancellations of delivery point , is the number of order cancellations of delivery point ; Based on the abnormal aggregation degree, determine the abnormal aggregation points in the logistics network to obtain the geographical analysis results.
[0034] Specifically, all order delivery points are extracted from the logistics network, the delivery addresses indicated in each order are read and matched to the corresponding geographical coordinates, the longitude and latitude values are saved in one-to-one correspondence with the delivery point numbers, and then the cumulative number of orders that appear at each delivery point within a specified time period is counted. Batch processing is performed with reference to the delivery point field and the order quantity field in the order details, and records with duplicate addresses or abnormal coordinates are excluded. The total number of orders for the delivery point is obtained by summing the order numbers of the delivery points with the same number. The delivery points distributed in different regions and their total order numbers are combined and sorted out, and then a delivery point coordinate set is constructed with longitude and latitude coordinates and the corresponding order statistical values are bound. Among them, the longitude and latitude data need to be matched with a pre-established geographical positioning comparison table. The order data scattered in multiple urban areas or townships is incorporated into the same detailed list for induction. With reference to the administrative region boundaries listed in the comparison table, it can be determined whether the longitude and latitude fall within the valid range. For example, the latitude is compared with the range of -90° to 90°, and the longitude is compared with the range of -180° to 180°. Records outside the range are regarded as invalid and marked for exclusion. Finally, the longitude and latitude coordinates of all valid delivery points and their order quantity information are recorded simultaneously, thereby generating the geographical distribution data of the delivery points.
[0035] The benefit of the formula lies in the quantitative measurement of the abnormal aggregation of orders at the delivery points through the comprehensive analysis of the attenuation of geographical location distance and the fluctuation of order indicators, which helps to quickly distinguish high-risk areas and provide a clear basis for subsequent logistics network control. Parameter The acquisition steps are as follows: is the total number of delivery points. The delivery point numbers of all valid order records are read from the order database, and a delivery point set is generated in a deduplicated manner. Then, the elements in this set are counted to obtain In actual monitoring, the delivery point numbers will be continuously updated. For example, if a total of 52 delivery points that generated orders in the most recent week are retrieved in a system, then can be obtained. If a new delivery point is added to the system, only the delivery point number needs to be included in the statistics when obtaining orders, so as to ensure that the calculation of is continuously updated. For example, if 8 new delivery points are added to this system later, then can be updated to 60 for subsequent operations in the formula. Parameter The acquisition steps are as follows: respectively represent the longitude and latitude coordinates of the delivery point where corresponds to the latitude value, The corresponding longitude values are all obtained by recording the geolocation information of each delivery point in the order system. The longitude and latitude ranges are based on the global coordinate standard within and Each delivery point has a unique number bound to its longitude and latitude. When collecting coordinates, a distance resolution of up to six decimal places is required to ensure accuracy. For example, when querying in the database, it is found that the coordinates corresponding to the delivery point are and . These two values can be confirmed through map positioning or on-site GPS survey. These coordinate information are stored in the same table together with the order quantity statistical field; Parameter acquisition steps: is the longitude and latitude coordinates of the delivery point currently being analyzed. Its meaning and acquisition method are the same as . The difference is that this coordinate is used to compare the geographical distance between the delivery point and other delivery points in the formula. The overall coordinate system remains consistent. For example, through network retrieval, it is determined that the coordinates in this area generally fall within the latitude range of 25° to 35° and the longitude range of 110° to 122°. In a monitoring, if the coordinates of the delivery point are then this coordinate is written into the calculation process. By comparing the Euclidean distances between and and respectively, it is used to judge the degree of geographical distribution aggregation; Parameter acquisition steps: represents the order quantity of the delivery point . It can be obtained by retrieving the corresponding order records in the database and aggregating and counting according to the delivery point number. The statistical range covers a certain time window. For example, all orders in the most recent 30 days are selected for calculation. For each order, the delivery point number and valid status are marked in its details, and then the order numbers with the same number are superimposed and summarized to form . In a business monitoring, query data shows that the delivery point has completed 4,200 orders in the past 30 days, then . If subsequent data is updated, the new orders within this time window can be incrementally counted again and updated. The same method is used for other delivery points, so that each can truly reflect the current business volume; Parameter acquisition steps: and The meaning is similar, but it targets the destination delivery point analyzed in the formula , retrieve the delivery point number in the database by the same statistical method as before , the order volume corresponding within the past 30 days, count and sum each order that meets the time range to obtain , for example, in a certain query, if the order number of the delivery point reaches 3,900 orders, then record , if it is found in subsequent monitoring that 100 new orders are added to this delivery point, then update it to 4,000, so that a new value can be brought in for subsequent abnormal aggregation calculation to form continuous risk tracking; Parameter acquisition steps: represents the number of return orders of the delivery point , which is obtained by counting the orders with the return flag field as "returned" in the database. To ensure data accuracy, invalid return records or incompletely filled return requests will be excluded. In actual collection, all orders of this delivery point will be retrieved first, and then the number of returns will be located among them to obtain is a non - negative integer. For example, in a set of monitoring data, it is found that there are 147 return orders at the delivery point , then ; Parameter acquisition steps: represents the number of order cancellations of the delivery point , similar to the return statistics, the records with the cancellation status marked as "cancelled" in the order details are accumulated and counted through the same database query method. This value varies between 0 and several integers, and each new cancellation behavior will generate a relevant record in the order system. For example, when summarizing data for the past 60 days, for the delivery point retrieve 89 cancelled orders, then , if 10 more cancellation records are found two days later, then can be updated to 99; Parameter acquisition steps: is the number of order cancellations of the target delivery point , the statistical method is the same as , except that at this time, the retrieval is performed on the delivery point with the number , for example, the delivery point has a cumulative cancellation count of 76 in a recent period of time, then , in the further data monitoring stage, if this delivery point has an additional 20 cancellation records, then Updated to 96; Calculation process: In a centralized monitoring, the following has been obtained indicating that there are 5 delivery points, numbered 1, 2, 3, 4, and 5 and the results after querying in the database. Their latitude and longitude coordinates are in turn , , , , , and the corresponding order quantities are , , , , , and the return order quantities are in turn , , , , , and the order cancellation times are in turn , , , , , select of the delivery points as the target. First, calculate the Euclidean distance to other delivery points and multiply by , then divide by , and then sum up the calculation results for all from 1 to 5 and divide by ; First step, calculate the distance of each :
[0036] Substitute and into it, and get , and similarly get , , , ; Second step, calculate the numerator term by term:
[0037] Take as an example, , and , and calculate the others in turn; Third step, calculate the denominator term by term:
[0038] Among them , , then , similar operations can be used to obtain other ; The fourth step is to calculate the individual values and sum them, and finally divide by :
[0039] By entering the values one by one and accumulating them, we get ,but:
[0040] The results show that when When the value is 0.465, there is a certain degree of difference in the number of orders and return distribution between distribution point 3 and other distribution points. If the value increases in the direction greater than 1, it means that distribution point 3 is more outliers from the surrounding distribution points in data performance. The higher the value, the more obvious the abnormal aggregation. If the value tends to 0, it means that the difference between this point and the surrounding is small. In the subsequent links, this result can be used to analyze the high Carry out stricter inspections at distribution points of high value; Based on the abnormal concentration, all distribution points need to be The values are compared centrally. First, the calculated values of each distribution point are summarized and the abnormal concentration result set is constructed. The values are arranged in descending order in the same list. For the values that are ranked high and significantly higher than other distribution points, an empirical threshold T can be set in the system for identification. The threshold T can be determined by all the distribution points in the past three months. The average level is obtained by adding an offset constant. For example, the average value M of the abnormal aggregation of all delivery points is summed up and then divided by the total number of delivery points. After obtaining the result, an offset K is added. If it exceeds T, it is regarded as an abnormal aggregation point. If it is lower than T, it is regarded as a normal distribution point. All points exceeding T need to be marked and the correlation between their latitude and longitude information and order records needs to be confirmed again. During the marking process, other delivery points within a few kilometers around each abnormal point can be counted, and the delivery indicators of these neighboring points can be checked one by one, and the quantities of each item can be compared with an established valid range. For example, the number of orders can be compared with the range of 100 to 5000 orders, the number of return orders can be compared with the range of 0 to 500 orders, and the number of cancellations can be compared with the range of 0 to 100 times. Check whether there are a large number of cases that exceed the range or seriously deviate from the average value. Finally, these distribution points that meet the abnormal aggregation judgment conditions are collectively output to form an abnormal area location list to obtain the geographical analysis results.
[0041] The steps to obtain abnormal pattern recognition results are: According to the preliminary data analysis results and geographic analysis results, an abnormal order area data set is constructed to obtain abnormal order area data; Based on the data of abnormal order regions, calculate the abnormal fitness of each region. The expression is as follows: ; Wherein, represents the identifier of a specific region, represents the abnormal fitness of region , represents the total number of orders within region , and respectively represent the order quantity and the number of return times of the th order in region , and respectively represent the order quantity and the number of return times of the th order in region , represents the average order quantity of region , represents the average number of return times of region ; Based on the abnormal fitness, form an abnormal pattern classification according to the level of abnormal fitness to obtain the abnormal pattern recognition result.
[0042] Specifically, according to the preliminary data analysis results and geographical analysis results obtained previously, sort out information such as the time range, order quantity, and return overview of order records involved in each region. Match this information according to the region code and record the longitude and latitude indexes of the region range. Referring to the previously obtained return frequency and abnormal aggregation point positions, screen out the region codes with overlapping or adjacent phenomena and extract the corresponding order number list. Retrieve and load fields such as the consignee address, order time, payment status, and return flag in the order item by item for the order number list. Aggregate these order data according to the region code and conduct duplicate comparison checks. For example, compare the region code of each order with the previously listed region numbers item by item. When the two are consistent, classify the order number under this region. Centralize all eligible order numbers to form a complete order list for this region. Subsequently, conduct quantitative statistics in combination with the order quantity, actual return times, and partial cancellation records in the order list to avoid missing orders outside the monitoring time period or duplicate order records that have been revoked. For the situation where the region codes are the same but the geographical locations are on the edges of different areas, it is necessary to continue to view the detailed division of each region boundary coordinate in the geographical analysis result and confirm the belonging of the order according to the vertex coordinates of the region polygon. When the confirmation is correct, incorporate the data fields of the order into the summary of this region. Through this multiple cross-checking, duplicate or invalid data entries can be excluded to obtain the data of abnormal order regions.
[0043] The advantage of the formula is to quantitatively evaluate the fit of each region in terms of abnormal orders through the degree of co-variation between the order quantity distribution and the return quantity distribution, and use methods such as absolute value and variance denominator to reduce the bias caused by data heteroscedasticity; Parameter Obtaining steps: is the total number of orders in the region, which can be obtained by retrieving the abnormal order region data constructed previously and counting the order records of each region within the specified period. Usually, a unique ID is assigned to each order in the database. When these IDs are all in the same region, the count can be incremented by 1 to accumulate . In actual monitoring, the order list obtained previously can be de-duplicated and summarized according to the region code. For example, if the region contains 1452 order IDs, then . If new order IDs are later found to be included in this region, can be updated to 1452 plus the number of new order entries, so as to continuously maintain an accurate grasp of this parameter.
[0044] Parameter Obtaining steps: represents the order quantity of order , which is used to describe the number of items in a single order. Its value can be found in the order details table. By using a database statement to filter out the order records with ID , reading its product list and summing up the total number of products contained, a positive integer value is obtained. To obtain the of all orders, the same operation needs to be performed on the product items of each order. For example, in a single query, order may contain 3 different SKUs with a total of 12 products, then .
[0045] Parameter Obtaining steps: is the average order quantity of the region. First, sum up all the values in the same region in the previous step, and then divide by the total number of orders to obtain it. Its value can be updated in real time from the order system according to the order statistics within the same time range or business cycle. During actual monitoring, the sum of each order can be set as , then . For example, among the 1452 orders in region , the cumulative number of products is 38256 pieces, then If there are other orders incorporated into this area subsequently, re - count and update according to the same method. .
[0046] Parameter acquisition steps: represents the number of return times of order , records the number of return behaviors initiated in this order. If all the goods of the order are returned at one time, then it can be recorded as 1. If there are multiple partial returns, they are accumulated. It is summarized by comparing the order ID with the return record table in the database, and the value is mostly from 0 to several integers. For example, for order if there have been 2 partial returns after it is issued, then . Combining the of all orders can depict the return situation within the area and provide input for subsequent anomaly assessment.
[0047] Parameter acquisition steps: represents the average number of return times of the area. After summarizing all the orders within the same area , it is calculated in the form of , and it also needs to be continuously updated similar to . In a monitoring data, if there are 110 cumulative return records among 1452 orders in area , then . If there are additional returns in the next stage, update to reflect the new return situation, thus ensuring the real - time nature of subsequent calculations.
[0048] Calculation process: First, assume that there are orders in area . Denote the total number of goods of each order as , and the number of return times as . Sum up all and respectively and divide by to obtain . . Then calculate for each order and , multiply the two and accumulate to form the numerator part. At the same time, sum and respectively, take the square root and multiply them to get the denominator. Finally, take the absolute value and divide the numerator by the denominator to obtain .
[0049] This result indicates that when When it is close to 1, it means that the degree of coordinated change between the number of regional orders and the number of returns is high, and there may be large-scale abnormal situations. When it is close to 0, it means that the correlation between the number of regional orders and the number of returns is low, and the order distribution in the region is relatively balanced.
[0050] Based on the abnormal fitness, it is necessary to The values are summarized and sorted one by one, and in the sorting process all the regions List and compare the difference ranges. For example, first check the average order quantity and average return number in different regions separately, and then compare the average order quantity and average return number in each region. Is it above a benchmark threshold T? If you want to set the threshold T, you can obtain it by centrally evaluating the monitoring results of all areas in recent time. For example, After taking the average value of 0.45, we select an offset of 0.1 and set the threshold T to 0.55. Value to minimum The values are compared one by one, and additional checks are performed on areas exceeding 0.55. The corresponding order list is called out and cross-checked in combination with the discreteness of the number of returns and the abnormal fields in the order. During this period, each order is scanned to see if there are any orders that exceed the defined range of product quantity or number of returns. For example, the range of product quantity is set between 1 and 1000 and the range of return number is set between 0 and 20. The exceeding records are marked as suspected abnormal items. If a large number of suspected abnormal items appear cumulatively in the same area, the area is recorded as a high abnormal mode area. On the contrary, if only a small number of orders or no orders trigger the abnormal threshold under the 0.55 threshold, the area is recorded as a low abnormal mode area. Finally, after the classification is completed according to the above process, the abnormal mode labels of each area are concentrated in a summary table to form the abnormal mode recognition results.
[0051] The steps to obtain the behavior pattern learning results are: According to the abnormal pattern recognition results, the order characteristics, return behavior, transaction frequency and geographical distribution information corresponding to each abnormal pattern are extracted, and abnormal transaction records are screened to obtain abnormal order behavior characteristic data; Based on the abnormal order behavior feature data, analyze the activity level of abnormal patterns in different time periods, count the distribution of abnormal behaviors in the target time interval, classify abnormal transaction types, and obtain abnormal behavior pattern data; Based on abnormal behavior pattern data, the similarity between abnormal behaviors is analyzed, the degree of aggregation of abnormal behaviors is determined, and abnormal behavior pattern categories are divided. The changing trend of abnormal behavior patterns is extracted to obtain behavior pattern learning results.
[0052] Specifically, according to the abnormal pattern recognition results obtained previously, all the orders marked as abnormal in the system are centrally screened, and their order characteristics, return behaviors, transaction frequencies, and geographical distribution information are read. These information are cross-checked with the order list obtained previously, and combined with the regional coding and time interval fields to determine whether they belong to the same target region or the same time period. Compare item by item whether the transaction frequency exceeds the threshold obtained by adding a fixed offset value to the historical average level. If the actual transaction frequency is higher than this threshold, it is marked as a high transaction frequency order in memory and continue to compare its return behavior. The judgment of the return behavior needs to refer to the ratio of the number of returns to the number of items in the order details. Compare the corresponding return ratio with the benchmark value set in advance. This benchmark value is obtained by statistically calculating the average return rate of all similar items in the recent three months and adding an offset. Multiply the number of returns of each order by the number of items and compare it with this benchmark value to determine whether there is a significant deviation. If the deviation is too large, it is marked as a potentially abnormal return order. At the same time, it is necessary to proofread the coordinate information in the geographical distribution field and evaluate whether it falls around some areas determined to have abnormal aggregation degrees. Compare the coordinates item by item with the coverage ranges of these areas. If it is found that the coordinates are within the ranges of these areas, the abnormal mark is intensified. For consecutive multiple similar abnormal orders that appear concentratedly, it is necessary to compare the three indicators of transaction frequency, return behavior, and geographical distribution again to determine whether they constitute the same type of abnormal transaction group. Through this process, incomplete or incorrect records in the data can be eliminated one by one, and finally, complete abnormal order behavior characteristic data is formed.
[0053] Based on the abnormal order behavior characteristic data, gradually read the timestamp information of each order and classify it into different time periods. Set the time period division standard with 24 hours as a basic division, and calculate the distribution of the transaction quantities of all abnormal orders in this time period and compare it with the historical average value obtained previously. If the number of abnormal orders in this time period increases by a certain extent compared with the previous cycle, mark this time period as an abnormal active peak. This amplitude value can be obtained by adding 2 times the standard deviation to the average value of the previously statistically recorded history. If the measured value exceeds this preset threshold, it is determined that the activity level has increased significantly. After completing the time period division, retrieve the number of returns and order characteristics of each abnormal order again. By comparing whether the number of returns exceeds the reference interval within a period of time, for example, compare the number of returns with the interval from 0 to 20 times. If it exceeds 20 times, it is recorded as a high return distribution. At the same time, combined with the trend of the transaction frequency, observe whether this high return distribution appears in the same time period. If there is a significant coincidence, mark this type of abnormal behavior as the high return - high frequency type according to the label. Otherwise, combine other indicators to judge different abnormal transaction types. When all orders are classified, the proportion of the quantities of these abnormal transaction types in the target time interval can be summarized and recorded, and thus abnormal behavior pattern data is obtained.
[0054] Based on the abnormal behavior pattern data, similarity analysis needs to be carried out for all identified abnormal transaction types. First, several key fields of each record in the same type are extracted from the time interval, including geographical coordinate information and the number of returns, etc. The difference degree of these fields within the same type is statistically calculated and the result is compared with another type. If the average difference of the key fields between the two types is small, it can be determined that the similarity is high. For calculating the difference, a benchmark threshold T can be set as a measurement boundary. This threshold T is set according to the average difference of similar behaviors in historical data plus 3 times the standard deviation. If the measured difference is less than this threshold, it is considered that there is an obvious aggregation between the two types. If it is greater than this threshold, it is regarded as significantly different. After processing the similarity between all types, the types with a high degree of aggregation are merged or marked as the same behavior pattern category in the statistical table. At the same time, it is necessary to track the change of the quantity of these aggregated categories over time again. For example, taking half a month as an observation period, the order quantity and the change of return behavior of the categories with high similarity are statistically calculated. When the order volume of a certain category continues to increase and the return rate fluctuates greatly, it can be registered as a type with a significant pattern change in the statistical table. After this classification and trend recording, the behavior pattern learning result is obtained.
[0055] The steps to obtain the logistics network analysis result are as follows: According to the behavior pattern learning result, all transaction records of the shipper, consignee and logistics nodes are extracted, including order number, transaction time, transaction frequency, number of return occurrences and abnormal order marking information. The transaction paths between the shipper and the consignee are sorted out, and all transaction path data are arranged in chronological order. Duplicate paths and isolated transaction points are removed to obtain the transaction path association data; Based on the transaction path association data, a logistics transaction relationship network is constructed. The shipper, consignee and logistics nodes are used as the vertices in the graph, and the transaction path and transaction times are used as the connection attributes of the edges. The interaction structure between logistics nodes is sorted out, and abnormal transaction relationship chains are screened to obtain the logistics network graph structure; Based on the logistics network graph structure, the paths including abnormal transaction frequency and return concentration are screened to obtain the logistics network analysis result.
[0056] Specifically, for all transaction records of the shipper, consignee, and logistics nodes extracted from the behavior pattern learning results, read the order numbers one by one and retrieve their corresponding transaction times and transaction frequencies. At the same time, compare the number of return occurrences and abnormal order flag information to confirm whether high-risk transaction characteristics are presented within the current time period. If the transaction frequency value is counted as more than 50 times within a day, it is recorded as a high frequency. This threshold is obtained by calculating the average value of the records in the previous month and adding an offset of 15 times. Then, collect the information of shippers and consignees with valid transactions or marked as abnormal within the specified time window, associate and sort the shipper IDs and consignee IDs, and then generate the actual path from the shipper to the consignee in combination with the logistics node information of each transaction. For duplicate paths, deduplication can be performed according to the order number and time. If the same path appears more than 20 times within 12 hours, it is considered to have a high degree of duplication. If a shipper or consignee appears only once, it is recorded as an isolated transaction point and temporarily excluded. When performing path sorting, the transaction sequence needs to be arranged in timestamp order and the continuous relationship between the shipper and the consignee is connected according to adjacent logic. Finally, all associated paths in the result set are summarized to obtain transaction path association data.
[0057] Based on the transaction path association data, first extract the IDs of the shipper, consignee, and logistics nodes and define them as nodes in the network. Find the connection relationship between each pair of nodes according to the transaction path and record the number of transactions to determine whether it is higher than the threshold of 30 times within a month. This standard is set by referring to the average value of the transaction quantities between nodes in the past three months plus an offset. When the number of transactions of the connection relationship exceeds this threshold, it is marked as a high connection strength. Immediately, summarize all nodes and connection relationships and compare them segment by segment according to the time line. Directly exclude the edges with a connection strength lower than 5 times and a long time interval between each other's updates. At the same time, observe whether the abnormal order flag information is concentrated between certain nodes. If the concentration is large, mark these connection relationships as abnormal transaction relationship chains. Sort all nodes according to the total frequency and re-check them in combination with the visible abnormal transaction relationship chains. If high-frequency transaction nodes appear in the sorted list and the corresponding edges are largely associated with abnormal orders, judge whether they form an obvious interaction structure through time interval comparison and connection quantity comparison. Finally, integrate these abnormal chains into the logistics network diagram structure.
[0058] Based on the logistics network diagram structure, select all paths where the transaction frequency in the connections is greater than 30 times or the return concentration is greater than a specified ratio for investigation. This specified ratio can be obtained by adding 0.2 times the standard deviation to the average value of the return data in the past two months. If the ratio of the cumulative number of returns corresponding to the path to the total orders of the path exceeds this range, it is recorded as a high return concentration channel. Then, cross-compare the high return concentration channels with the paths of high transaction frequency, count the repeated shipping nodes and receiving nodes among them, and query whether there is the same tendency in the previous monitoring period. When certain nodes appear in the high return and high frequency paths multiple times in different time periods, they are marked as abnormal hotspots. List these hotspots and their paths again and summarize them in the business system. If it is found that there are more than three abnormal nodes in a single path, it is recorded as an extremely abnormal chain. After all the screening is completed, compile the finally determined high-risk paths into a summary data table to obtain the logistics network analysis result.
[0059] The steps to obtain the optimization result of the interception strategy are as follows: According to the logistics network analysis result, extract the transaction data of the shipper, consignee, and logistics nodes involved in the abnormal transaction chain to obtain the abnormal transaction chain parameter data; Based on the abnormal transaction chain parameter data, calculate the interception adaptability. The calculation formula is: ; Among them, represents the interception adaptability of path , is the total number of abnormal transaction paths, is the transaction times of path , is the return ratio of path , is the return ratio of path , is the number of rejected orders of path , is the number of order cancellations of path ; Based on the interception adaptability, screen the abnormal transaction paths that need to be intercepted, update the interception rules of the shipper, consignee, and logistics nodes, set the interception strategy parameters, and obtain the optimization result of the interception strategy.
[0060] Specifically, based on the logistics network analysis results obtained previously, all the transaction chains marked as abnormal need to be disassembled one by one, and the detailed transaction data of the shipper, consignee, and logistics nodes need to be retrieved from the database. This includes a timestamp field to distinguish the transaction occurrence time, a status field to identify whether the transaction is completed or revoked, and an abnormal flag field to confirm whether the transaction has been recorded as an abnormal event. Then, these data are unified and merged according to the transaction chain number and sorted based on the timestamp. During the sorting process, first check the order numbers that repeatedly appear within the same transaction chain. If it is confirmed that these order numbers do not duplicate with the archived isolated records, they are included in the subsequent processing; otherwise, they are excluded and the reason for the repeated occurrence is marked in the statistical table. After that, based on the combination of the shipper ID, consignee ID, and logistics node ID, the main relationship of the transaction chain is formed. For some transaction chains with connection jumps, it is necessary to verify whether the interval duration between the previous-hop consignee and the next-hop shipper is within the specified range. For example, compare the interval duration with the range from 0 hours to 48 hours. Those exceeding 48 hours are regarded as non-continuous jumps and split into different transaction chain segments. This can avoid stringing together transactions with too long an interval that are not relevant. When all the transaction chain segments are segmented by continuous duration, each segment will be further compared in the system and the repeated times of the shipper and consignee in it will be counted. If the repeated times of some segments are higher than the frequency threshold calculated from historical data, for example, the average repeated times of all segments in the past two weeks is 4 times and an offset of 1 time is added to get the threshold of 5 times, then it is determined that these segments have too high a repetition degree and they are added to the high-risk list. Finally, the sorted segments and their transaction information of the shipper, consignee, and logistics nodes are integrated to form the abnormal transaction chain parameter data.
[0061] The benefit of the formula is that by combining multiple indicators such as the number of transactions, return ratio, number of rejected orders, and number of order cancellations in the form of exponential and logarithmic mappings, the abnormal severity of the target path can be numerically evaluated, enabling subsequent interception decisions to consider the comprehensive impact of multiple indicators. parameter acquisition steps: represents the total number of abnormal transaction paths, which consists of all the suspected risk paths collected previously. The quantity can be obtained by retrieving and de-duplicating the path numbers in the abnormal transaction chain parameter data. For example, if it is statistically found that there are 37 abnormal paths in a monitoring period, then , during the subsequent business operation process, newly added abnormal paths will be inserted into this parameter data table and continue to be accumulated during regular analysis to form a new , when the unified summary of all paths is completed, the value used in this formula can be fixed, which can ensure that the calculation process is consistent with the real-time business data; parameter Obtaining steps of Indicates the path The number of transactions, the value of which can be queried in the order table or transaction table of the database. Each path has a specific shipper, consignee, and logistics node sequence. As long as the path numbers match the same records, the quantities of these transactions can be accumulated to obtain , the range is usually from 0 to thousands of transactions. If a shipper or consignee is particularly active, it will be relatively large. To obtain accurate values, the system will filter transactions within the statistical period based on timestamps and perform summation on them. For example, in a statistics, the path involves 150 order records, then ; Parameter Obtaining steps of Is the return ratio of the path , which is calculated from the ratio of return orders to total orders among the orders covered by this path. The value mostly ranges from 0 to 1. Specifically, first find all the order numbers associated with the path in the database, then determine whether each order is a return order, record the number of return orders as , record the total number of orders as , then , for example, in a collection, the path collects a total of 200 orders, among which 40 are return orders, then ; Parameter Obtaining steps of Indicates the path The return ratio of, the acquisition method is the same as , except that here it is for the target path , still need to query the order details associated with this path from the abnormal transaction chain parameter data, record the proportion of return orders as . If it is found that the order volume of the target path has increased significantly recently, then recalculate the proportion of return orders after updating the order quantity to make continuously maintain the latest status. For example, in a detection, the path has 300 orders and 90 return orders, then ; Parameter Obtaining steps of Is the number of rejected orders of the path , query the records in the database where the order status field is "rejected", and accumulate all the records belonging to the path The order can be obtained. This value is between 0 and a certain integer, and the attribution of a specific order is determined by referring to the path number in the abnormal transaction chain parameter data. For example, if there are 15 rejection records under the path , and if multiple new rejected orders are found to be added to the path during subsequent monitoring , it needs to be added to the cumulative value for subsequent recalculation of the formula, so that the system can timely evaluate the interception risk according to the increase in rejected orders; Parameter acquisition steps: Let be the number of order cancellations for the path . Similar to the rejection statistics, retrieve the orders with the cancellation status in the order table and confirm whether they belong to the path . If they meet the criteria, accumulate their quantities. This value usually increases with the increase in the number of events where customers actively cancel or logistics abnormalities cause cancellations. During one investigation, there may be 25 cancellation records found within the path . When new cancellation events are detected by the system, add them in, so that can reflect the cancellation frequency status of this path. In the formula, this parameter is used to jointly measure the abnormality degree of the path with other indicators; Calculation process: To demonstrate the complete operation process of this formula, let represent that there are three abnormal transaction paths, which are respectively marked as Path 1, Path 2, and Path 3. Assume the current target path . Query the number of transactions for these three paths in sequence and obtain , , , and at the same time obtain the return ratio , , , and query the return ratio of . Continue to retrieve the number of rejected orders , , and the number of order cancellations , , . Substitute all these values into the formula: In the first step, first calculate the fraction corresponding to each path :
[0062] For example, for Path 1:
[0063] For path 2:
[0064] For path 3:
[0065] In the second step, multiply the above results by the corresponding and sum them up:
[0066] After substituting the numerical values, we get: ; The total is ; In the third step, calculate the exponential term and substitute it into the formula:
[0067] After numerical calculation, ; This result indicates that for the target path the interception adaptability is 0.783. When this value is greater than a certain reference value (for example, the average adaptability of all paths in the system plus 0.1), this path can be classified as a high interception priority. The closer the value is to 1, the more significant the abnormal risk is in the dimension defined by this system.
[0068] Based on the interception adaptability, the system needs to centrally proofread the numerical values of all abnormal transaction paths. First, these paths can be sorted in descending order and the shipper, consignee, and logistics nodes included in each path can be compared one by one in a record table. Mark the high interception priority paths as key monitoring targets, and at the same time conduct a thorough screening of the shipper information involved. During this process, if it is found that the historical order volume of certain shippers has been continuously exceeding a pre-set reference range, for example, setting the threshold as twice the average order volume of this shipper in the past two months plus 5 offset volumes, and this shipper also appears multiple times in the paths with high interception adaptability, then it is recorded as a very frequent abnormal transaction source and additional monitoring is established. The same method is also used for the consignee and logistics nodes to observe whether they enter the high interception priority path list multiple times. In this way, a group of high-risk entities can be obtained. Finally, updated interception rules are adopted for this group of entities and the specific interception strategy parameters are recorded. After completion, the optimized result of the interception strategy is generated.
[0069] The steps to obtain the transaction monitoring result are as follows: Based on the optimized result of the interception strategy, implement real-time monitoring of all transactions, record all potential abnormal activities, and generate an abnormal transaction report; Based on the abnormal transaction report, investigate the transactions identified as suspicious, verify the legality of the transactions, update the monitoring parameters and rules according to the investigation results, and obtain the transaction monitoring results.
[0070] Specifically, based on the optimization result of the interception strategy, it is necessary to monitor all transaction data in real time and continuously record the monitoring logs. First, include the previously identified shipper, consignee, and logistics node identifiers in the monitoring scope and mark each new order. Compare each transaction record with the time stamp accurate to the second with the previous interception strategy parameters one by one, collect and record fields such as transaction frequency, return quantity, and order cancellation number in the system's abnormal monitoring record. During the recording process, if the order number exceeds the threshold within one day for the transaction frequency, mark it separately. The threshold can be obtained by taking the average daily order volume X in the previous month, adding 2 times the standard deviation, and then adding an offset. Mark the transactions exceeding this threshold as high-frequency and simultaneously detect whether other fields also show abnormalities. If it is detected that the number of returns has exceeded the benchmark value within a one-month cycle, mark such records as multiply suspicious. At the same time, it is necessary to check whether the geographical location or logistics node corresponding to the transaction is within the high-risk range found previously. Verify this check process in combination with geographical coordinates and path numbers and accumulate the occurrence times. If a single transaction shows deviations from the normal level in multiple dimensions, it is regarded as potential abnormal activity and recorded. To ensure stability, classify and count abnormal activities in the system and summarize the statistical results every hour. If it is statistically found that the frequency of certain types of abnormalities has increased significantly, add additional tags to the log record table and conduct further aggregation analysis in the next stage. During this process, transactions that have been revoked or have duplicate numbers should also be excluded. Confirm whether they are pseudo-duplicates by comparing their IDs with the previously stored list of invalid records. Finally, write the key fields of all potential abnormal activities into the abnormal transaction report, so that a more comprehensive investigation of potential risks can be carried out in subsequent links.
[0071] Based on the abnormal transaction report, first retrieve all the transactions identified as suspicious from the report and locate the timestamp, shipper and consignee information, and logistics node identifier of each transaction one by one. Determine when the transaction was listed as suspicious and investigate the reason for suspicion. For example, by checking the comparison result with the historical average or examining whether the number of returns exceeds the reference interval in the past week. If it is found that there are indeed a large number of returns or multiple cancellations in the suspicious transaction, notify the operation and maintenance personnel for targeted verification. When conducting a legality investigation on the notified transactions, the delivery address can be further compared with the registered valid range, and the address information can be compared within the longitude range of -180° to 180° and the latitude range of -90° to 90°, excluding records with obvious coordinate errors. At the same time, trace the transaction frequency obtained previously. If the frequency exceeds the acceptable range, such as more than 100 consecutive transactions in a day and the return ratio is above 0.3, then mark this transaction as severely abnormal. In the verification logic, it is also possible to determine whether the transaction is within the normal range by checking the payment method or the order remarks field. When the investigation of all suspicious transactions is completed, mark the truly abnormal transactions more severely and update the baseline threshold in the monitoring parameters to ensure the reliability of the system's detection by adding a new offset to the original threshold or recalculating the new average. It is also possible to cancel the direct shielding or strengthen the review of transactions that meet the preset conditions. Finally, synchronize the updated monitoring rules to the global configuration, complete this process, and output the transaction monitoring results.
[0072] The present invention provides an interception system, including: A data collection module that collects time data, location data, and return rate data of target orders and generates a data set; A preliminary analysis module that runs frequency statistics based on the data set, identifies abnormal return points, and obtains preliminary analysis results; A geographical identification module that uses the preliminary analysis results to perform geographical location clustering, identifies abnormal clustering points, and obtains geographical identification results; A pattern learning module that classifies abnormal return points and abnormal traffic based on the geographical identification results, identifies abnormal behavior patterns, conducts behavior pattern learning, and outputs pattern learning results; A network analysis module that uses the pattern learning results to construct an association graph between the shipper and the consignee, identifies the black production network, adjusts the interception strategy based on the network structure, and generates network analysis results.
[0073] The above is only a preferred embodiment of the present invention, and it does not limit the present invention in other forms. Any person skilled in the art may use the disclosed technical content to make changes or modifications into equivalent embodiments with equivalent changes and apply them to other fields. However, as long as it does not depart from the technical content of the technical solution of the present invention, any simple modification, equivalent change, and modification made to the above embodiments based on the technical essence of the present invention still fall within the protection scope of the technical solution of the present invention.
Claims
1. An interception method for abnormal logistics, characterized in that, Including the following steps: Collect logistics data on order time, location, and return rate, mine the areas with frequent return points, and obtain the preliminary data analysis results; Through geographical analysis, identify the abnormal aggregation points in the logistics network and obtain the geographical analysis results; Based on the preliminary data analysis results and geographical analysis results, classify the abnormal return points and abnormal traffic order areas, identify the abnormal patterns, and obtain the abnormal pattern recognition results; Conduct behavior pattern learning on the abnormal pattern recognition results to obtain the behavior pattern learning results; Adopt the behavior pattern learning results to establish an association graph between the shipper, consignee, and logistics nodes, analyze the association graph, identify the logistics black production network, and obtain the logistics network analysis results; Based on the logistics network analysis results, adjust the interception parameters to obtain the interception strategy optimization results; Use the interception strategy optimization results to conduct abnormal transaction detection, monitor the delivery address and account, and obtain the transaction monitoring results.
2. The interception method for abnormal logistics according to claim 1, wherein The steps for obtaining the preliminary data analysis results are as follows: Collect the timestamp, location, and return rate of each order to obtain the preliminary order data set; Based on the preliminary order data set, calculate the return probability of each location. The calculation formula is: ; Among them, represents the return probability at a location, is the order set, is the location of the returned order, is the location of the number of order returns; Based on the return probability, screen the risk locations where the return probability exceeds the set threshold to form the areas with frequent return points and obtain the preliminary data analysis results.
3. The interception method for abnormal logistics according to claim 1, wherein, The steps for obtaining the geographical analysis results are as follows: Extract all order delivery points from the logistics network, record the longitude and latitude coordinates of each delivery point, construct a set of delivery point coordinates, and count the number of orders at each delivery point to obtain the geographical distribution data of the delivery points; Based on the geographical distribution data of the delivery points, calculate the abnormal aggregation degree of each delivery point. The calculation formula is: ; Among them, represents the abnormal aggregation degree of the delivery point , is the total number of delivery points, is the longitude and latitude coordinates of the delivery point , is the longitude and latitude coordinates of the delivery point currently being analyzed, is the order quantity of the delivery point , is the order quantity of the delivery point , is the number of return orders of the delivery point , is the number of order cancellations of the delivery point , is the number of order cancellations of the delivery point ; Based on the abnormal aggregation degree, judge the abnormal aggregation points in the logistics network to obtain the geographical analysis results.
4. The interception method for abnormal logistics according to claim 1, characterized in that, The steps for obtaining the abnormal pattern recognition results are as follows: According to the preliminary data analysis results and the geographical analysis results, construct a data set of abnormal order areas to obtain the abnormal order area data; Based on the abnormal order area data, calculate the abnormal fitness of each area. The expression is: ; wherein represents an identifier for a specific area, represents the area 's abnormal adaptation degree, represents the area 's total number of orders, and respectively represent the order quantity and the number of return times of the th order in the area and respectively represent the order quantity and the number of return times of the th order in the area represents the average order quantity of the area and represents the average number of return times of the area ; Based on the abnormal fitness, form an abnormal pattern classification according to the high and low of the abnormal fitness to obtain the abnormal pattern recognition results.
5. The interception method for abnormal logistics according to claim 1, characterized in that, The steps for obtaining the behavior pattern learning results are as follows: According to the abnormal pattern recognition results, extract the order characteristics, return behaviors, transaction frequencies, and geographical distribution information corresponding to various abnormal patterns, screen the abnormal transaction records, and obtain the abnormal order behavior characteristic data; Based on the abnormal order behavior characteristic data, analyze the activity level of the abnormal patterns in different time periods, count the distribution of abnormal behaviors in the target time interval, and classify the abnormal transaction types to obtain the abnormal behavior pattern data; Based on the abnormal behavior pattern data, analyze the similarity between abnormal behaviors, judge the aggregation degree of abnormal behaviors, divide the categories of abnormal behavior patterns, and extract the change trend of abnormal behavior patterns to obtain the behavior pattern learning results.
6. The interception method for abnormal logistics according to claim 1, wherein The steps for obtaining the logistics network analysis results are as follows: According to the learning results of the behavior patterns, all transaction records of the shipper, consignee and logistics nodes are extracted, including order numbers, transaction times, transaction frequencies, the number of return occurrences and abnormal order flag information, the transaction paths between the shipper and the consignee are sorted out, and all transaction path data are arranged in chronological order. Duplicate paths and isolated transaction points are removed to obtain transaction path association data; Based on the transaction path association data, a logistics transaction relationship network is constructed. The shipper, consignee and logistics nodes are used as vertices in the graph, and the transaction paths and transaction times are used as the connection attributes of the edges. The interaction structure between logistics nodes is sorted out, and abnormal transaction relationship chains are screened to obtain the logistics network graph structure; Based on the logistics network graph structure, paths including abnormal transaction frequencies and return concentration are screened to obtain the logistics network analysis results.
7. The interception method for abnormal logistics according to claim 1, characterized in that The steps for obtaining the optimized interception strategy result are as follows: According to the logistics network analysis results, the transaction data of the shipper, consignee and logistics nodes involved in the abnormal transaction chain are extracted to obtain abnormal transaction chain parameter data; Based on the abnormal transaction chain parameter data, the interception adaptability is calculated. The calculation formula is: ; Among them, represents the interception adaptation degree of the path , is the total number of abnormal transaction paths, is the number of transactions of the path , is the return ratio of the path , is the return ratio of the path , is the number of rejected orders of the path , is the number of order cancellations of the path ; Based on the interception adaptability, abnormal transaction paths that need to be intercepted are screened, the interception rules of the shipper, consignee and logistics nodes are updated, and interception strategy parameters are set to obtain the optimized interception strategy result.
8. The interception method for abnormal logistics according to claim 1, characterized in that The steps for obtaining the transaction monitoring result are as follows: Based on the optimized interception strategy result, real-time monitoring of all transactions is implemented, all potential abnormal activities are recorded, and an abnormal transaction report is generated; Based on the abnormal transaction report, transactions marked as suspicious are investigated, the legitimacy of the transactions is verified, and the monitoring parameters and rules are updated according to the investigation results to obtain the transaction monitoring result.
9. The interception system for the interception method of abnormal logistics according to any one of claims 1-8, characterized in that, Including: A data collection module that collects time data, location data, and return rate data of target orders to generate a data set; A preliminary analysis module that, based on the data set, runs frequency statistics, identifies abnormal return points, and obtains preliminary analysis results; A geographical identification module that uses the preliminary analysis results to perform geographical location clustering, identifies abnormal aggregation points, and obtains geographical identification results; A pattern learning module that, based on the geographical identification results, classifies abnormal return points and abnormal traffic, identifies abnormal behavior patterns, performs behavior pattern learning, and outputs pattern learning results; A network analysis module that uses the pattern learning results to construct an association graph between the shipper and the consignee, identifies the black production network, adjusts the interception strategy based on the network structure, and generates network analysis results.
Citation Information
Cited By
E-commerce logistics distribution system based on intelligent supply chain
CN120450570A