Data processing method and device, equipment and storage medium
By constructing a graph neural network to utilize user historical behavior data, the problem of inaccurate identification of abnormal objects in the existing technology is solved, early identification and processing of abnormal objects is realized, and the security of Internet users is improved.
Patent Information
- Application Number
- CN202410017170.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-01-04
- Publication Date
- 2025-07-04
AI Technical Summary
Existing inter-user relationship mining technologies are difficult to accurately identify abnormal objects before abnormal behavior, making it difficult to ensure the security of Internet users.
By obtaining the historical behavior data of the object to be identified, a relationship diagram and historical behavior characteristics are constructed, a graph neural network is established, node representation is obtained, and the identification results are determined based on node representation.
Improve the accuracy of identifying abnormal objects before abnormal behavior and improve the security of Internet users.
Smart Images

Figure CN120256981A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of artificial intelligence, and in particular, to a data processing method, apparatus, device, and storage medium. Background Art
[0002] With the development of Internet technology, sharing information through the Internet has become an indispensable part of people's daily lives. Therefore, how to effectively predict the influence of information dissemination has become an important topic in Internet research.
[0003] The online Internet network stores a vast amount of interaction data between users, making it of great research value to mine the correlation relationships between users. At the same time, it also has broad application prospects in aspects such as advertising and recommendation systems, and is a research hotspot in current Internet interaction network analysis. Currently, the mining of correlation relationships between users can generally adopt the following two schemes: One is an identification scheme based on the behavior patterns of objects. This identification scheme often combines the behavior patterns and characteristics of improper industries, sets thresholds for screening layer by layer, and then discriminates potential abnormal objects. The disadvantage is that it is easily bypassed by improper industries and requires continuous updating of strategies according to the methods of improper industries; The other is an identification scheme based on text keywords. This scheme mainly uses text recognition algorithms to identify reported texts and screens out abnormal sets from the reported texts. The advantage is that there is sufficient evidence and high accuracy, but the disadvantage is that this identification is already in the post-event stage and it is difficult to stop losses in a timely manner at the beginning of abnormal behaviors to protect the safety of Internet users.
[0004] Therefore, there is an urgent need for a scheme that can improve the accuracy of identifying abnormal objects before abnormal behaviors occur. Summary of the Invention
[0005] Embodiments of this application provide a data processing method, apparatus, device, and storage medium for improving the accuracy of identifying abnormal objects before abnormal behaviors occur.
[0006] In view of this, on the one hand, this application provides a data processing method, including: obtaining historical behavior data of multiple objects to be identified, where the historical behavior data includes attribute data of the objects to be identified and association data with other objects to be identified; obtaining an association relationship graph of the multiple objects to be identified and historical behavior characteristics of each object to be identified based on the historical behavior data, where the nodes of the association relationship graph are objects to be identified, and the edges of the association relationship graph are historical behavior relationships between the objects to be identified; constructing a graph neural network based on the association relationship graph and the historical behavior characteristics of each object to be identified; obtaining node representations of each node in the graph neural network; determining identification results of the multiple objects to be identified based on the node representations.
[0007] On the other hand, the present application provides a data processing device, including: an acquisition module, configured to acquire historical behavior data of a plurality of objects to be recognized, where the historical behavior data includes attribute data of the objects to be recognized and association data with other objects to be recognized;
[0008] a processing module, configured to obtain an association relationship graph of the plurality of objects to be recognized and historical behavior characteristics of each of the plurality of objects to be recognized based on the historical behavior data, where nodes of the association relationship graph are objects to be recognized, and edges of the association relationship graph are historical behavior relationships between the objects to be recognized; construct a graph neural network based on the association relationship graph and the historical behavior characteristics of each of the objects to be recognized; obtain node representations of each node in the graph neural network;
[0009] a recognition module, configured to determine recognition results of the plurality of objects to be recognized based on the node representations.
[0010] In a possible design, in another implementation manner of the other aspect of the embodiments of the present application, the processing module is configured to determine a set of target recognition objects from the plurality of objects to be recognized according to a first preset rule based on the historical behavior data, where the objects to be recognized in the set of target recognition objects are suspicious objects, and other objects to be recognized are confirmed as normal objects;
[0011] determine an association relationship between each of the objects to be recognized in the set of target recognition objects based on the historical behavior data;
[0012] construct an association relationship graph corresponding to the set of target recognition objects according to the association relationship, where the association relationship graph corresponding to the set of target recognition objects is used as the association relationship graph of the plurality of objects to be recognized.
[0013] In a possible design, in another implementation manner of the other aspect of the embodiments of the present application, the processing module is configured to determine that there is an association relationship between two objects to be recognized when the historical behavior data indicates that the account login addresses of the two objects to be recognized are the same;
[0014] determine that there is an association relationship between two objects to be recognized when the historical behavior data indicates that the two objects to be recognized belong to the same community;
[0015] determine that there is an association relationship between two objects to be recognized when the historical behavior data indicates that the two objects to be recognized are friends with each other;
[0016] determine that there is an association relationship between two objects to be recognized when the historical behavior data indicates that the two objects to be recognized have an interaction behavior;
[0017] Traverse the set of target recognition objects in this way to determine the association relationship between each of the objects to be recognized in the set of target recognition objects.
[0018] In a possible design, in another implementation of another aspect of the embodiments of the present application, the processing module is configured to determine a set of target recognition objects from the multiple objects to be recognized according to a first preset rule based on the historical behavior data, where the objects to be recognized in the set of target recognition objects are suspicious objects, and the other objects to be recognized are confirmed as normal objects;
[0019] Perform feature preprocessing and feature splicing on the historical behavior data to obtain the historical behavior features of each object to be recognized in the set of target recognition objects.
[0020] In a possible design, in another implementation of another aspect of the embodiments of the present application, the processing module is configured to obtain a set of adjacent objects of the first node;
[0021] Perform clustering processing on the historical behavior features of each node in the set of adjacent objects to obtain a first node representation of the first node;
[0022] Traverse each node in the graph neural network in turn to obtain intermediate node representations of each node in the graph neural network;
[0023] Repeat the above operation N times to obtain node representations of each node in the graph neural network, where N is a positive integer.
[0024] In a possible design, in another implementation of another aspect of the embodiments of the present application, the recognition module is configured to call a classification network to perform classification processing on the node representations of each node to obtain recognition results of the multiple objects to be recognized.
[0025] In a possible design, in another implementation of another aspect of the embodiments of the present application, the classification network is a pre-trained network or a classification network trained according to training samples, and the training samples are graph neural networks constructed based on historical behavior data.
[0026] In a possible design, in another implementation of another aspect of the embodiments of the present application, the recognition module is configured to use a clustering algorithm to perform clustering processing on each node based on the node representations within the graph neural network to obtain multiple clustering sets;
[0027] Obtain the outliers of the multiple clustering sets;
[0028] Determine the recognition results of the multiple clustering sets according to the outliers;
[0029] Determine the recognition results of the multiple objects to be recognized according to the recognition results of the multiple clustering sets.
[0030] In a possible design, in another implementation of another aspect of the embodiments of the present application, the recognition module is configured to calculate the outliers of the multiple clustering sets according to a second preset rule and the historical behavior data;
[0031] The second preset rule includes calculating the outliers of the clustering set according to the number of historical abnormal behaviors of each object to be recognized.
[0032] In a possible design, in another implementation of another aspect of the embodiments of the present application, the processing module is configured to report the abnormal object when the recognition result is used to indicate that there is an abnormal object among the multiple objects to be recognized.
[0033] Another aspect of the present application provides a computer device, including: a memory, a processor, and a bus system;
[0034] Wherein, the memory is used to store programs;
[0035] The processor is configured to execute the programs in the memory, and the processor is configured to execute the methods of the above aspects according to the instructions in the program code;
[0036] The bus system is used to connect the memory and the processor to enable the memory and the processor to communicate.
[0037] Another aspect of the present application provides a computer-readable storage medium, in which instructions are stored, and when they run on a computer, the computer is enabled to execute the methods of the above aspects.
[0038] Another aspect of the present application provides a computer program product or a computer program, the computer program product or the computer program includes computer instructions, and the computer instructions are stored in a computer-readable storage medium. The processor of the computer device reads the computer instructions from the computer-readable storage medium, and the processor executes the computer instructions, so that the computer device executes the methods provided in the above aspects.
[0039] As can be seen from the above technical solutions, the embodiments of the present application have the following advantages: Feature extraction is performed on the historical behavior data of the object to be recognized to obtain historical behavior features and an association relationship graph, and then a graph neural network is constructed based on the historical behavior features and the association relationship graph; Finally, the node representation of the object to be recognized is learned based on the graph neural network. At this time, the node representation has stronger feature representation, so more comprehensive feature information can be provided for the abnormal recognition of the object to be recognized. At the same time, the historical behavior data is the attribute data of the abnormal object and the association data between the abnormal objects. The above information can be obtained before the abnormal behavior of the abnormal object occurs. Therefore, the recognition accuracy of the abnormal object before the abnormal behavior can be improved. Description of the Drawings
[0040] Figure 1 It is a schematic diagram of the system architecture of an application scenario of the data processing method in the embodiment of the present application;
[0041] Figure 2 It is a schematic diagram of a process of the data processing method in the embodiment of the present application;
[0042] Figure 3 It is a schematic diagram of an embodiment of the data processing method in the embodiment of the present application;
[0043] Figure 4 It is a schematic diagram of an embodiment of the data processing device in the embodiment of the present application;
[0044] Figure 5 It is a schematic diagram of another embodiment of the data processing device in the embodiment of the present application;
[0045] Figure 6 It is a schematic diagram of another embodiment of the data processing device in the embodiment of the present application. Detailed implementation manners
[0046] The embodiment of the present application provides a data processing method, device, equipment and storage medium, which are used to improve the recognition accuracy of abnormal objects before abnormal behaviors.
[0047] In the specification and claims of the present application and the above-mentioned drawings, the terms "first", "second", "third", "fourth", etc. (if any) are used to distinguish similar objects, and do not have to be used to describe a specific order or sequence. It should be understood that the data used in this way can be interchanged under appropriate circumstances, so that the embodiments of the present application described here can be implemented in an order other than those illustrated or described here. In addition, the terms "including" and "corresponding to" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or equipment that includes a series of steps or units does not have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products or equipment.
[0048] In the embodiment of the present application, the term "module" or "unit" refers to a computer program with a predetermined function or a part of a computer program, and works together with other related parts to achieve a predetermined goal, and can be fully or partially implemented by using software, hardware (such as a processing circuit or a memory) or a combination thereof. Similarly, a processor (or multiple processors or memories) can be used to implement one or more modules or units. In addition, each module or unit can be a part of the overall module or unit that includes the function of the module or unit.
[0049] With the development of Internet technology, sharing information through the Internet has become an indispensable part of people's daily lives. Therefore, how to effectively predict the influence of information dissemination has become an important topic in Internet research. The online Internet network stores a vast amount of interaction data between users, making it of great research value to mine the correlation relationships between users. At the same time, it also has broad application prospects in aspects such as advertising and recommendation systems, and is a research hotspot in the current analysis of Internet interaction networks. Currently, the mining of correlation relationships between users can usually adopt the following two schemes: One is the recognition scheme based on the behavior patterns of objects. This recognition scheme often discriminates potential abnormal objects through the combination of behavior patterns and characteristics of improper industries, and sets thresholds for screening layer by layer. The disadvantage is that it is easy to be bypassed by improper industries and requires continuous updating of strategies according to the methods of improper industries; the other is the recognition scheme based on text keywords. This scheme mainly uses text recognition algorithms to identify reported texts and screens out abnormal sets from the reported texts. The advantage is that there is sufficient evidence and high accuracy, but the disadvantage is that this recognition is already in the post-event stage and it is difficult to stop losses in a timely manner at the beginning of abnormal behaviors to protect the safety of Internet users. Therefore, there is an urgent need for a scheme that can improve the recognition accuracy of abnormal objects before abnormal behaviors occur.
[0050] To solve the above technical problems, the present application provides the following technical solutions: Obtain the historical behavior data of multiple objects to be recognized, where the historical behavior data includes the attribute data of the objects to be recognized and the correlation data with other objects to be recognized; Based on the historical behavior data, obtain the correlation relationship graph of the multiple objects to be recognized and the historical behavior characteristics of each object to be recognized among the multiple objects to be recognized. Among them, the nodes of the correlation relationship graph are the objects to be recognized, and the edges of the correlation relationship graph are the historical behavior relationships between the objects to be recognized; Construct a graph neural network based on the correlation relationship graph and the historical behavior characteristics of each object to be recognized; Obtain the node representations of each node in the graph neural network; Determine the recognition results of the multiple objects to be recognized based on the node representations. In this way, the historical behavior data of the objects to be recognized is used for feature extraction to obtain historical behavior characteristics and a correlation relationship graph, and then a graph neural network is constructed based on the historical behavior characteristics and the correlation relationship graph; Finally, the node representations of the objects to be recognized are learned based on the graph neural network. At this time, the node representations have stronger feature representations, so more comprehensive feature information can be provided for the abnormal recognition of the objects to be recognized. At the same time, the historical behavior data is the attribute data of abnormal objects and the correlation data between abnormal objects, and the above information can all be obtained before the abnormal objects have abnormal behaviors. Therefore, the recognition accuracy of abnormal objects before abnormal behaviors can be improved.
[0051] The data processing methods of the optional embodiments of this application can be implemented based on artificial intelligence technology. Artificial intelligence is the theory, method, technology, and application system that uses digital computers or machines controlled by digital computers to simulate, extend, and expand human intelligence, perceive the environment, acquire knowledge, and use knowledge to obtain the best results. In other words, artificial intelligence is a comprehensive technology in computer science that attempts to understand the essence of intelligence and produce a new intelligent machine that can react in a way similar to human intelligence. Artificial intelligence also studies the design principles and implementation methods of various intelligent machines to enable machines to have the functions of perception, reasoning, and decision-making.
[0052] Artificial intelligence technology is an interdisciplinary subject with a wide range of fields, including both hardware-level technologies and software-level technologies. The basic technologies of artificial intelligence generally include sensors, dedicated artificial intelligence chips, cloud computing, distributed storage, big data processing technology, pre-trained model technology, operation / interaction systems, mechatronics, etc. Among them, the pre-trained model, also known as the large model or the foundation model, can be widely applied to downstream tasks in various directions of artificial intelligence after fine-tuning. The software technologies of artificial intelligence mainly include several major directions such as computer vision technology, speech processing technology, natural language processing technology, and machine learning / deep learning.
[0053] The pre-training model (Pre-training model), also known as the cornerstone model or the large model, refers to a deep neural network (Deep neural network, DNN) with a large number of parameters. It is trained on a large amount of unlabeled data, and the function approximation ability of the large-parameter DNN is used to enable the PTM to extract common features from the data. Through techniques such as fine-tuning, parameter-efficient fine-tuning (PEFT), and prompt-tuning, it is applicable to downstream tasks. Therefore, the pre-training model can achieve ideal results in few-shot or zero-shot scenarios. PTM can be divided into language models (ELMO, BERT, GPT), vision models (swin-transformer, ViT, V-MOE), speech models (VALL-E), multi-modal models (ViBERT, CLIP, Flamingo, Gato), etc. according to the data modalities processed. Among them, the multi-modal model refers to a model that establishes feature representations of two or more data modalities. The pre-training model is an important tool for outputting artificial intelligence-generated content (AIGC) and can also be used as a general interface connecting multiple specific task models.
[0054] Computer Vision Technology (CV) Computer vision is a science that studies how to enable machines to "see". More specifically, it refers to machine vision that uses cameras and computers to replace human eyes for tasks such as object recognition, tracking, and measurement, and further performs image processing to make the computer-processed images more suitable for human eye observation or transmission to instrument detection. As a scientific discipline, computer vision studies related theories and technologies and attempts to build artificial intelligence systems that can obtain information from images or multi-dimensional data. Large model technology has brought important changes to the development of computer vision technology. Pre-trained models in the visual field such as swin-transformer, ViT, V-MOE, and MAE can be quickly and widely applied to downstream specific tasks after fine-tuning. Computer vision technology usually includes technologies such as image processing, image recognition, image semantic understanding, image retrieval, OCR, video processing, video semantic understanding, video content / behavior recognition, 3D object reconstruction, 3D technology, virtual reality, augmented reality, simultaneous localization and mapping, etc., and also includes common biometric recognition technologies such as face recognition and fingerprint recognition.
[0055] This application is also related to cloud technology. Among them, cloud technology is a hosting technology that unifies system resources such as hardware, software, and networks within a wide area network or local area network to achieve data computing, storage, processing, and sharing.
[0056] Cloud technology is the general term for network technology, information technology, integration technology, management platform technology, application technology, etc. based on the cloud computing business model, which can form a resource pool, be used on demand, and is flexible and convenient. Cloud computing technology will become an important support. The background services of technical network systems require a large amount of computing and storage resources, such as video websites, picture websites, and more portal websites. With the highly developed and applied Internet behavior, in the future, each item may have its own identification mark and needs to be transmitted to the background system for logical processing. Data at different levels will be processed separately, and various industry data requires a powerful system backup support, which can only be achieved through cloud computing. The cloud technology involved in this application mainly refers to the transmission of historical behavior data of objects to be recognized between terminal devices or servers through the "cloud", etc.
[0057] For easy understanding, some terms in this application are explained below.
[0058] Graph neural network: It refers to a general term for a class of algorithms that use neural networks to learn graph-structured data. Among them, the graph neural network can usually be divided into five categories, namely: Graph Convolution Networks (GCN), Graph Attention Networks (GAN), Graph Autoencoders, Graph Generative Networks, and Graph Spatial-temporal Networks.
[0059] Among them, the graph convolution network generalizes the convolution operation from traditional data (such as images) to graph data. Its core idea is to learn a function mapping, through which the nodes in the graph can aggregate their own features and the features of their neighbors to generate new representations of the nodes. The graph convolution network is the basis for many complex graph neural network models, including autoencoder-based models, generative models, and spatio-temporal networks, etc.
[0060] Machine Learning (ML) is a multi-disciplinary and cross-disciplinary field that involves multiple disciplines such as probability theory, statistics, approximation theory, convex analysis, and algorithm complexity theory. It specifically studies how computers simulate or implement human learning behaviors to acquire new knowledge or skills and reorganize the existing knowledge structure to continuously improve their own performance. Machine learning is the core of artificial intelligence and the fundamental way to make computers intelligent, and its applications cover all fields of artificial intelligence. Machine learning and deep learning usually include technologies such as artificial neural networks, belief networks, reinforcement learning, transfer learning, inductive learning, and rote learning. With the research and progress of artificial intelligence technology, artificial intelligence technology has been studied and applied in multiple fields. For example, common ones include smart homes, smart wearable devices, virtual assistants, smart speakers, smart marketing, driverless, autonomous driving, drones, robots, smart healthcare, smart customer service, etc. It is believed that with the development of technology, artificial intelligence technology will be applied in more fields and play an increasingly important role.
[0061] Neural network: An artificial neural network (ANN) is composed of numerous neurons with adjustable connection weights, and has characteristics such as large-scale parallel processing, distributed information storage, and good self-organization and self-learning abilities.
[0062] A data processing method, apparatus, device, and storage medium provided by an embodiment of the present application are used to improve the recognition accuracy of abnormal objects before abnormal behaviors. The following describes an exemplary application of the electronic device provided by the embodiment of the present application. The electronic device provided by the embodiment of the present application can be implemented as various types of user terminals or can also be implemented as a server.
[0063] By running the data processing method provided by the embodiment of the present application, the electronic device is used to improve the recognition accuracy of abnormal objects before abnormal behaviors. That is, it improves the recognition accuracy of the electronic device for abnormal objects before abnormal behaviors.
[0064] The above solution can be applied to many artificial intelligence fields, including the field of abnormal object review. When using the data processing method provided by the embodiment of the present application to help users identify abnormal objects, this method can be implemented as an independent online application installed in the computer device or the background server used by the user, facilitating the user to use this program to identify abnormal objects.
[0065] In this scenario, the user inputs the historical behavior data of the object to be recognized through the input interface on the application program interface, then constructs an association relationship graph based on this historical behavior data, and performs feature preprocessing and feature splicing on this historical behavior data to obtain the historical behavior features corresponding to this historical behavior data; then constructs the graph neural network based on this association relationship graph and the historical behavior features corresponding to each node in this association relationship graph; finally, learns the node representation (i.e., the final feature representation) of the object to be recognized based on this graph neural network; finally, obtains the recognition result of the object to be recognized based on this node representation, and determines the specific operation for the object to be recognized according to this recognition result. For example, for a normal object, normal functions and normal permissions are maintained. For an abnormal object, it is reported to the application service provider, so that the application server can perform corresponding processing on the object to be recognized through the server (such as blocking the account, blocking functions, etc.). Among them, blocking the account means punishing an abnormal account, such as kicking the abnormal account offline and prohibiting login. Blocking the function means restricting the functions of an abnormal account, such as intercepting access to communities (such as chat groups), intercepting adding friends, intercepting sending messages, and so on.
[0066] In an exemplary solution, the data processing method can be applied to the abnormal account review of a social platform. For example, obtain the historical behavior data corresponding to each account on the social platform, then construct an association relationship graph between each account on the social platform based on the historical behavior data, and perform feature preprocessing and feature splicing on the historical behavior data to obtain the historical behavior features corresponding to each account; then construct a graph neural network based on the association relationship graph and the historical behavior features; finally, learn the node representations (i.e., the final feature representations) corresponding to each account based on the graph neural network; finally, obtain the recognition results of each account based on the node representations, and determine the specific operations for each account according to the recognition results. For example, a normal account maintains normal functions and normal permissions (wherein, the normal account can be understood as an account with a relatively long active time, regular social activities (such as interacting with friends through messages, posting and commenting on the Moments, reading public account articles, etc.), and no punishment records). An abnormal account is reported to the application service provider, so that the application server can perform corresponding processing on the object to be recognized through the server (such as blocking the account, restricting functions, etc.). Blocking the account means punishing the abnormal account, such as kicking the abnormal account offline and prohibiting login. Restricting functions means restricting the functions of the abnormal account, such as intercepting access to communities (such as chat groups), intercepting adding friends, intercepting sending messages, etc.).
[0067] Of course, in addition to being applied to the above scenarios, the method provided in the embodiments of the present application can also be applied to other scenarios that require data processing. The embodiments of the present application do not limit the specific application scenarios.
[0068] See Figure 1 , Figure 1It is an optional architecture diagram in an application scenario of the data processing solution provided by the embodiments of the present application. To implement and support a data processing solution, the terminal device 100 is connected to the server 300 via the network 200, and the server 300 is connected to the database 400. The network 200 can be a wide area network, a local area network, or a combination of both. The client for implementing the data processing solution is deployed on the terminal device 100. The client can run on the terminal device 100 in the form of a browser or in the form of an independent application (APP), etc. The specific presentation form of the client is not limited herein. The server 300 involved in the present application can be an independent physical server, a server cluster or a distributed system composed of multiple physical servers, or a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, Content Delivery Network (CDN), and big data and artificial intelligence platforms. The terminal device 100 can be a smart phone, a tablet computer, a laptop computer, a handheld computer, a personal computer, a smart TV, a smart watch, a vehicle-mounted device, a wearable device, a smart voice interaction device, a smart home appliance, an aircraft, etc., but is not limited thereto. The terminal device 100 and the server 300 can be directly or indirectly connected via the network 200 by wired or wireless communication means, which is not limited in the present application. The number of the server 300 and the terminal device 100 is also not limited. The solution provided by the present application can be independently completed by the terminal device 100, independently completed by the server 300, or completed in cooperation with the terminal device 100 and the server 300. The present application does not make specific limitations thereon. Among them, the database 400 can be regarded as an electronic filing cabinet in short - a place for storing electronic files. Users can perform operations such as adding, querying, updating, and deleting data in the files. The so - called "database" is a data set stored together in a certain way, shared by multiple users, with the smallest possible redundancy, and independent of application programs. The Database Management System (DBMS) is a computer software system designed to manage databases and generally has basic functions such as storage, interception, security guarantee, and backup.Database management systems can be classified according to the database models they support, such as relational, Extensible Markup Language (XML); or according to the types of computers they support, such as server clusters, mobile phones; or according to the query languages used, such as Structured Query Language (SQL), XQuery; or according to the performance impulse focus, such as maximum scale, highest running speed; or other classification methods. Regardless of the classification method used, some DBMSs can span categories. For example, they can support multiple query languages simultaneously. In this application, the database 400 can be used to store the training samples of the classification network, the classification network, and the historical behavior data of the object to be recognized. Of course, the storage locations of the training samples of the classification network, the classification network, and the historical behavior data of the object to be recognized are not limited to the database. For example, they can also be stored in the terminal device 100, the blockchain, or the distributed file system of the server 300, etc.
[0069] In some embodiments, both the server 300 and the terminal device 100 can execute the data processing method provided in the embodiments of this application.
[0070] Based on the above description, the data processing method in this application will be described below with Figure 2 the following flow schematic diagram:
[0071] 1. Collection of historical behavior data. In this embodiment, the historical behavior data includes the attribute data of the object to be recognized and the association data between the objects to be recognized. Among them, the attribute data is used to indicate the quantitative data and qualitative data of the object to be recognized. Qualitative data can be understood as data such as the nickname, avatar, account source, registration and login, personal profile, etc. of the account to which the object to be recognized belongs. Quantitative data can be understood as information such as the account level, number of friends, etc. of the account to which the object to be recognized belongs. In this embodiment, based on different application scenarios, the historical behavior data can have different data attributes. For example, in an instant messaging application, the historical behavior data can include the account source, registration and login, personal profile, and interaction relationship chain (such as entering and leaving communities, adding / deleting friends, etc.). Among them, the account source is used to indicate whether the account is registered with personal real information, or an account purchased from others, or an account stolen from others. And the registration and login is used to indicate whether the account is registered with personal real information or stolen information, and the network protocol address of the account login. The personal profile is used to indicate information such as the account avatar, account nickname, account signature, account avatar modification record, account nickname modification record, and account signature modification record. The interaction relationship chain is used to indicate information such as the account entry community record, account exit community record, add friend record, delete friend record, create community record, etc.
[0072] 2. Construct an association relationship graph. In this embodiment, after obtaining the historical behavior data, traverse the historical behavior data, and determine whether there is an association relationship between each object to be recognized according to the corresponding rules. If there is an association relationship, when constructing the association relationship graph, an edge can be created between the two objects to be recognized. In an exemplary solution, use G=(V, E) to represent the association relationship graph, where V represents the set of nodes of the graph (in this embodiment, it can be understood as the set of objects to be recognized), and E={(x, y)|x∈V, y∈V, x≠y} represents the edges of the association relationship graph. It should be understood that the association relationship graph constructed according to the above historical behavior data is an undirected graph. And the rule can be set as follows: the objects to be recognized have an association relationship when they belong to the same community, the objects to be recognized have an association relationship when they have the same login network protocol address (i.e., IP address), and the objects to be recognized have an association relationship when they are friends with each other. Traverse the objects to be recognized according to the above rules to establish an association relationship graph. For the nodes in the graph, the relationship between the objects to be recognized A and B in the association relationship graph can be defined as:
[0073] (A, B)∈E if A ip =B ip or (A∈room x and B∈room x ) or A∈B friends
[0074] 3. Extract historical behavior features. In this embodiment, numerical processing can be performed on each historical behavior data, and then feature splicing is performed to obtain a feature sequence. For example, different account sources are represented by different values, different login behaviors are represented by different values, abnormal registration behaviors are represented by different values, the number of friends is represented by a set of values, and so on. Suppose the historical behavior data of user A is as follows: "The account is registered with the user's real information; the login behavior is logging in at location A on the first day, logging in at location B on the second day, and logging in at location C on the third day; the number of friends is 100; the friend groups include the work group, the family group, and the classmate group". According to the above rules, the historical behavior features of user A can be represented as follows "1, 1, 0, 100, 1". Among them, the first number "1" is used to represent that the account source of user A is self-registered, the second number "1" is used to represent that the account registration behavior of user A is with the user's real information, the third number "0" is used to represent that the login address of user A has changed, the fourth number "100" is used to represent that the number of friends of user A is 100, and the fifth number "1" is used to represent that the friend grouping of user A is normal.
[0075] 4. Construct a graph neural network. In this embodiment, a graph neural network is established based on the association relationship graph and the historical behavior characteristics of each object to be recognized. Specifically, the graph neural network is defined as follows:
[0076] G=(V, E)
[0077] U∈V if U is potential fraud user
[0078] (U a , U b )∈E if A ip =B ip or (A∈room x and B∈room x ) or A∈B friends
[0079] Where U represents a user, and A ip , B ip represent the login network protocol addresses of the object A to be recognized and the object B to be recognized respectively, room x represents a community, and B friends represents a friend of the object B to be recognized. Among them, for each node of the graph neural network, it contains historical behavior characteristics. Therefore, the node feature matrix of the entire graph neural network can be expressed as follows:
[0080] X =
[0081] [x 11 x 12 …x 1n
[0082] x 21 x 22 ...x 23
[0083] ……………
[0084] x m1 x m2 …x mn
[0085] Where x ij represents the j-th eigenvalue of the i-th object to be recognized.
[0086] 5. Calculate and output the node representations of the graph neural network. In this embodiment, based on this graph neural network, node representation calculations are performed on each node in the graph neural network, and the final node representations are output. In an exemplary solution, the classical GraphSage algorithm can be used to mine the node representations of each node in the graph neural network. Among them, the key steps of the GraphSage algorithm include:
[0087] a. Sampling: For each node v, randomly sample a part of its neighbor nodes, denoted as N(v). Here, N(v) represents the set of neighbor nodes of node v.
[0088] b. Aggregation: For each node v and its sampled neighbor nodes N(v), aggregate their historical behavior features to generate a new feature representation h(v) of node v. The aggregation formula can be expressed as follows:
[0089] h(v) = mean{h(u) for u in N(v)}
[0090] c. Update: Update the feature representation of the node using the aggregated new feature representation.
[0091] d. Iteration: Repeat the above steps for multiple rounds to capture more neighbor information and global structure.
[0092] 6. Perform classification or clustering processing based on the node representations to obtain recognition results. In this embodiment, call the classification network to perform classification prediction on the node representations of each node in the graph neural network to obtain the recognition results corresponding to each node. Or perform clustering processing on each node in the graph neural network based on the node representation to obtain multiple clustering sets; then calculate the outliers corresponding to each clustering set; finally, determine the recognition results of each clustering set according to the outliers, and determine the recognition results of the objects to be recognized according to the recognition results of the clustering sets.
[0093] 7. Perform corresponding operations based on the recognition results. In this embodiment, after obtaining the recognition results of each object to be recognized, perform corresponding operations according to the recognition results. For example, a normal account maintains normal functions and normal permissions (where the normal account can be understood as an account with a relatively long active time, regular social activities (such as interacting with friends by messages, posting and commenting on Moments, reading official account articles, etc.), and no punishment records). An abnormal account is reported to the application service provider, so that the application server can perform corresponding processing on the object to be recognized through the server (such as blocking the account, blocking functions, etc.). Blocking the account means punishing the abnormal account, such as kicking the abnormal account offline and prohibiting login. Blocking the function means restricting the functions of the abnormal account, such as intercepting access to communities (such as chat groups), intercepting adding friends, intercepting sending messages, etc.
[0094] Combined with the above introduction, taking the server as the execution entity, the data processing method in this application is introduced below. Please refer to Figure 3 , an embodiment of the data processing method in the embodiment of this application includes:
[0095] 301. Obtain the historical behavior data of multiple objects to be recognized, where the historical behavior data includes the attribute data of the objects to be recognized and the association data with other objects to be recognized.
[0096] In this embodiment, the server can perform anomaly recognition according to a preset period. Therefore, the historical behavior data of the object to be recognized can be the behavior data within a preset period or the behavior data within a fixed duration. For example, if the server performs anomaly behavior recognition on the accounts of an instant messaging platform once a day, the historical behavior data of the object to be recognized can be the behavior data within one day or can be fixed as the behavior data within N days before the current detection (for example, N is 7). At the same time, for the objects recognized as normal objects in the previous round, the recognition can be performed at a longer interval. For example, if account A was recognized as a normal object in the previous anomaly recognition, it can be not recognized for anomalies in the current anomaly recognition, and then it is set to be recognized again after seven anomaly recognitions.
[0097] It should be understood that based on different application scenarios, the historical behavior data of the object to be recognized can have different data attributes. Among them, the operating environment data can be understood as the account description information of the object to be recognized, such as account source, registration and login, personal profile, etc. data. And the association data can be understood as the interaction description information of the object to be recognized, such as friend relationship, community membership relationship, friend grouping information, note information for friends, and so on. For example, in an instant messaging application, the historical behavior data can include account source, registration and login, personal profile, and interaction relationship chain (such as entering / leaving a community, adding / deleting friends, etc.). Among them, the account source is used to indicate whether the account is registered with personal real information, or an account purchased from others, or an account stolen from others. And the registration and login is used to indicate whether the account is registered with personal real information or stolen information, and the network protocol address of the account login. The personal profile is used to indicate information such as account avatar, account nickname, account signature, account avatar modification record, account nickname modification record, and account signature modification record. The interaction relationship chain is used to indicate information such as account entry into community record, account exit from community record, friend addition record, friend deletion record, community creation record, etc.
[0098] 302. Based on the historical behavior data, obtain the association relationship graph of the multiple objects to be recognized and the historical behavior characteristics of each object to be recognized among the multiple objects to be recognized. Among them, the nodes of the association relationship graph are the objects to be recognized, and the edges of the association relationship graph are the association relationships between the objects to be recognized.
[0099] In this embodiment, after obtaining the historical behavior data, the server traverses the historical behavior data and determines whether there is an association relationship between each object to be recognized according to corresponding rules. If there is an association relationship, when constructing the association relationship graph, an edge can be created between two objects to be recognized. In an exemplary solution, let G=(V, E) represent the association relationship graph, where V represents the node set of the graph (in this embodiment, it can be understood as the set of objects to be recognized), and E={(x, y)|x∈V, y∈V, x≠y} represents the edge of the association relationship graph. It should be understood that the association relationship graph constructed according to the above historical behavior data is an undirected graph. And the rules can be set as follows: there is an association relationship when the objects to be recognized belong to the same community, there is an association relationship when the objects to be recognized have the same login network protocol address (i.e., IP address), and there is an association relationship when the objects to be recognized are in a friend relationship. Traverse the objects to be recognized according to the above rules to establish an association relationship graph. For the nodes in the graph, the relationship between the objects to be recognized A and B in the association relationship graph can be defined as:
[0100] (A, B)∈E if A ip =B ip or (A∈room x and B∈room x ) or A∈B friends
[0101] It should be understood that in order to reduce the amount of calculation, when constructing the association relationship graph, the server can also filter the objects to be recognized according to the first preset rule, and only perform subsequent recognition on suspicious objects. The first preset rule can be set as follows: an account registered with personal real information and whose login environment conforms to a normal distribution is a normal object, and those that do not meet the above requirements are suspicious objects. Then the server constructs an association relationship graph for the suspicious objects.
[0102] It should be understood that when constructing the association relationship graph, the weights of the edges can also be calculated according to the association relationships between the objects to be recognized, so as to determine the number of edges in the association relationship graph according to the weights. Assume that the weights of the edges are obtained by synthesizing multiple determination conditions. For example, if the object to be recognized A and the object to be recognized B belong to the same community, then there is an edge between the object to be recognized A and the object to be recognized B, and the weight of the edge is 1 at this time; then if the object to be recognized A and the object to be recognized B belong to the same login network protocol address, the weight of the edge is updated to 2 at this time; then if the object to be recognized A and the object to be recognized B are friends with each other, the weight of the edge is updated to 3 at this time. Traverse all the objects to be recognized according to this scheme to determine the edges and the weights of the edges. Finally, filter between nodes according to the weights of the edges. For example, there are edges between the object to be recognized A and the object to be recognized B, the object to be recognized C and the object to be recognized D, and the weight of the edge between the object to be recognized A and the object to be recognized B is 1, while the weight of the edge between the object to be recognized A and the object to be recognized C is 5, and the weight of the edge between the object to be recognized A and the object to be recognized D is 6. At this time, the edge between the object to be recognized A and the object to be recognized B can be filtered out.
[0103] When the server extracts the historical behavior characteristics of the object to be recognized based on the historical behavior data, it can perform feature preprocessing and feature splicing on the historical behavior data. Among them, the method of the feature preprocessing can be numerical processing or other schemes, which are not specifically limited here. In an exemplary scheme, when numerical processing is adopted, the specific process can be as follows: numerical processing can be performed on each piece of historical behavior data, and then feature splicing is performed to obtain a feature sequence. For example, different account sources are represented by different numerical values, different login behaviors are represented by different numerical values, abnormal registration behaviors are represented by different numerical values, the number of friends is represented by a group of numerical values, and so on. Assume that the historical behavior data of user A is as follows: "The account is registered with the user's real information; the login behavior is logging in at location A on the first day, logging in at location B on the second day, and logging in at location C on the third day; the number of friends is 100; the friend groups include the work group, the family group, and the classmate group". According to the above rules, the historical behavior characteristics of user A can be represented as follows: "1, 1, 0, 100, 1". Among them, the first number "1" is used to represent that the account source of user A is self-registered, the second number "1" is used to represent that the account registration behavior of user A is with the user's real information, the third number "0" is used to represent that the login address of user A has changed, the fourth number "100" is used to represent that the number of friends of user A is 100, and the fifth number "1" is used to represent that the friend grouping of user A is normal.
[0104] Among them, the feature processing of the nickname and the avatar can be as follows: for example, compare the nickname with the nicknames classified as abnormal nicknames to obtain corresponding values; compare the avatar with the avatars classified as abnormal avatars to obtain corresponding values. For example, calculate the similarity between the nickname and the abnormal nickname or calculate the similarity between the avatar and the abnormal avatar, and then convert it into a corresponding value based on the similarity. Among them, the edit distance algorithm can be used to calculate the nickname similarity; the mean value or difference or perceptual hashing algorithm can be used to calculate the avatar similarity.
[0105] 303. Construct a graph neural network based on the association relationship graph and the historical behavior characteristics of each object to be recognized.
[0106] In this embodiment, based on the association relationship graph and the historical behavior characteristics of each object to be recognized, a graph neural network is established. Specifically, the graph neural network is defined as follows:
[0107] G=(V,E)
[0108] U∈V if U is potential fraud user
[0109] (U a ,U b )∈E if A ip =B ip or(A∈room x and B∈room x )or A∈B friends
[0110] Among them, U represents the user, A ip ,B ip respectively represent the login network protocol addresses of the object A to be recognized and the object B to be recognized, room x represents the community, and B friends represents the friend of the object B to be recognized. Among them, for each node of the graph neural network, it contains historical behavior characteristics. Therefore, the node feature matrix of the entire graph neural network can be represented as follows:
[0111] X=
[0112] [x 11 x 12 …x 1n
[0113] x 21 x 22 ...x 23
[0114] ……………
[0115] x m1 xm2 …x mn
[0116] where x ij represents the j-th eigenvalue of the i-th object to be recognized.
[0117] 304. Obtain the node representations of each node in the graph neural network.
[0118] In this embodiment, after obtaining the graph neural network, the server calculates the node representations of each node in the graph neural network based on the graph neural network and outputs the final node representations. In an exemplary solution, the classical GraphSage algorithm can be used to mine the node representations of each node in the graph neural network. The key steps of the GraphSage algorithm include:
[0119] a. Sampling: For each node v, randomly sample a part of its neighbor nodes, denoted as N(v). Here, N(v) represents the set of neighbor nodes of node v.
[0120] b. Aggregation: For each node v and its sampled neighbor nodes N(v), aggregate their historical behavior features to generate a new feature representation h(v) of node v. The aggregation formula can be expressed as follows:
[0121] h(v) = mean{h(u) for u in N(v)}
[0122] c. Update: Update the feature representation of the node using the aggregated new feature representation.
[0123] d. Iteration: Repeat the above steps for multiple rounds to capture more neighbor information and global structure.
[0124] It should be understood that the server can also use other graph neural algorithms, which are not specifically limited here.
[0125] 305. Determine the recognition results of the multiple objects to be recognized based on the node representations.
[0126] In this embodiment, the server can call a classification network to perform classification prediction on the node representations of each node in the graph neural network to obtain the recognition results corresponding to each node. Or perform clustering processing on each node in the graph neural network based on the node representations to obtain multiple clustering sets; then calculate the outliers corresponding to each clustering set; finally, determine the recognition results of each clustering set based on the outliers and determine the recognition results of the objects to be recognized based on the recognition results of the clustering sets.
[0127] Among them, when using a classification network to perform classification prediction processing on the node representation, the classification network can be a pre-trained model; it can also be a model obtained by fine-tuning the pre-trained model; it can also be a model trained for a specific application scenario. In an exemplary solution, if the classification network is a model trained for a specific application scenario, its specific training process can be as follows: Obtain training samples and an initial classification network, where the training samples include a dataset of normal objects and abnormal objects, and each sample includes a sample label; then construct an association graph based on the training samples, and extract the feature representation of the training samples; then construct a graph neural network based on the feature representation and the association graph; obtain the node representation of the training samples based on the graph neural network; finally, call the initial classification network to predict the node representation to obtain a training prediction label; calculate a loss value based on the training prediction label and the sample label; finally, train the initial classification network according to the loss value to obtain the classification network.
[0128] When using a clustering algorithm to cluster each node in the graph neural network based on the node representation, various clustering algorithms can be used. For example, the classic louvin algorithm, for example, the partitioning-based clustering algorithm, for example, the density-based clustering algorithm, etc. Specifically, it is not limited here.
[0129] In this embodiment, after obtaining multiple clustering sets by clustering, the abnormal behavior processing records and the feature records conforming to the abnormal behavior of each object to be recognized can be obtained from the historical behavior data, and then the abnormal value corresponding to the clustering set can be calculated based on the abnormal behavior processing records and the feature records conforming to the abnormal behavior; when the abnormal value is greater than the threshold, it is determined that the clustering set is an abnormal set, and the objects to be recognized in it are all recognized as abnormal objects.
[0130] The data processing device in the present application will be described in detail below. Please refer to Figure 4 , Figure 4 FIG. is a schematic diagram of an embodiment of the data processing device in the embodiment of the present application. The data processing device 20 includes:
[0131] An acquisition module 201, configured to acquire historical behavior data of multiple objects to be recognized, where the historical behavior data includes attribute data of the objects to be recognized and association data with other objects to be recognized;
[0132] A processing module 202, configured to obtain an association graph of the multiple objects to be recognized and the historical behavior features of each object to be recognized among the multiple objects to be recognized based on the historical behavior data, where the nodes of the association graph are the objects to be recognized, and the edges of the association graph are the historical behavior relationships between the objects to be recognized; construct a graph neural network based on the association graph and the historical behavior features of each object to be recognized; obtain the node representation of each node in the graph neural network;
[0133] An identification module 203, configured to determine an identification result of the multiple objects to be identified based on the node representation.
[0134] In an embodiment of the present application, a data processing device is provided. By using the above device, historical behavior features and an association relationship graph are extracted from the historical behavior data of the object to be identified, and then a graph neural network is constructed based on the historical behavior features and the association relationship graph; finally, a node representation of the object to be identified is learned based on the graph neural network. At this time, the node representation has stronger feature representation, so more comprehensive feature information can be provided for the anomaly identification of the object to be identified. At the same time, the historical behavior data is the attribute data of the abnormal object and the association data between the abnormal objects. The above information can be obtained before the abnormal behavior of the abnormal object occurs. Therefore, the identification accuracy of the abnormal object before the abnormal behavior can be improved.
[0135] Optionally, on the basis of the corresponding embodiment above, Figure 4 In another embodiment of the data processing device 20 provided in the embodiment of the present application,
[0136] The processing module 202 is configured to determine a target identification object set from the multiple objects to be identified according to a first preset rule based on the historical behavior data. The objects to be identified in the target identification object set are suspicious objects, and the other objects to be identified are confirmed as normal objects;
[0137] Determine the association relationship between the objects to be identified in the target identification object set based on the historical behavior data;
[0138] Construct an association relationship graph corresponding to the target identification object set according to the association relationship, where the association relationship graph corresponding to the target identification object set is used as the association relationship graph of the multiple objects to be identified.
[0139] In an embodiment of the present application, a data processing device is provided. By using the above device, a preliminary screening of the object to be identified is performed, thereby reducing the subsequent calculation amount. At the same time, a graph structure is constructed, and the advantage of the graph structure data can be utilized to mine the relationship chain features of the abnormal object and improve the identification accuracy of the abnormal object.
[0140] Optionally, on the basis of the corresponding embodiment above, Figure 4 In another embodiment of the data processing device 20 provided in the embodiment of the present application, the processing module 202 is configured to determine that there is an association relationship between two objects to be identified when the historical behavior data indicates that the account login addresses of the two objects to be identified are the same;
[0141] When the historical behavior data indicates that two objects to be recognized belong to the same community, it is determined that there is an association relationship between the two objects to be recognized;
[0142] When the historical behavior data indicates that two objects to be recognized are friends with each other, it is determined that there is an association relationship between the two objects to be recognized;
[0143] When the historical behavior data indicates that there is an interaction behavior between two objects to be recognized, it is determined that there is an association relationship between the two objects to be recognized;
[0144] Traverse the target recognition object set in this way to determine the association relationships between the objects to be recognized in the target recognition object set.
[0145] In the embodiments of the present application, a data processing device is provided. By using the above device, by constructing a co-edge construction graph structure between the objects to be recognized, the relationship chain characteristics between the objects to be recognized can be effectively recognized, thereby improving the recognition accuracy of abnormal objects.
[0146] Optionally, on the basis of the corresponding embodiments above, Figure 4 In another embodiment of the data processing device 20 provided in the embodiments of the present application,
[0147] The processing module 202 is configured to determine a target recognition object set from the multiple objects to be recognized according to a first preset rule based on the historical behavior data, the objects to be recognized in the target recognition object set are suspicious objects, and the other objects to be recognized are confirmed as normal objects;
[0148] Perform feature preprocessing and feature splicing on the historical behavior data to obtain the historical behavior features of the objects to be recognized in the target recognition object set.
[0149] In the embodiments of the present application, a data processing device is provided. By using the above device, the objects to be recognized are screened first, thereby reducing the subsequent calculation amount. At the same time, feature extraction and feature splicing are performed on the historical behavior data, so that the objects to be recognized can be represented by features, which is convenient for subsequent graph neural networks to mine relationship chains, and further improves the recognition accuracy of abnormal objects.
[0150] Optionally, on the basis of the corresponding embodiments above, Figure 4 In another embodiment of the data processing device 20 provided in the embodiments of the present application,
[0151] The processing module 202 is configured to obtain a set of adjacent objects of the first node;
[0152] Perform clustering processing on the historical behavior features of each node in the set of adjacent objects to obtain a first node representation of the first node;
[0153] Traverse each node in the graph neural network in turn to obtain the intermediate node representations of each node in the graph neural network;
[0154] Repeat the above operation N times to obtain the node representations of each node in the graph neural network, where N is a positive integer.
[0155] In the embodiments of the present application, a data processing device is provided. By using the above device, node representation aggregation is performed on each node based on the graph neural network, so that each node can learn richer adjacent node information and global features, thereby increasing the feature representation of each node, and further improving the recognition accuracy of abnormal objects.
[0156] Optionally, based on the corresponding embodiment above, in another embodiment of the data processing device 20 provided in the embodiments of the present application, the recognition module 203 is used to call a classification network to classify the node representations of each node to obtain the recognition results of the multiple objects to be recognized. Figure 4
[0157] In the embodiments of the present application, a data processing device is provided. By using the above device, after obtaining the node representations of each node in the graph neural network, a classification network is called to classify and recognize the object to be recognized based on the node representation, so as to obtain the recognition result of the object to be recognized. This effectively improves the timeliness of recognition. At the same time, the classification task can be set according to the actual situation, thereby increasing the feasibility of the solution. At the same time, the repeated calculation of manual strategies is reduced, and the recognition efficiency of abnormal objects is improved.
[0158] Figure 4 Optionally, based on the corresponding embodiment above, in another embodiment of the data processing device 20 provided in the embodiments of the present application, the recognition module 203 is used to perform clustering processing on each node by using a clustering algorithm based on the node representations in the graph neural network to obtain multiple clustering sets;
[0159] Obtain the outliers of the multiple clustering sets;
[0160] Determine the recognition results of the multiple clustering sets according to the outliers;
[0161] Determine the recognition results of the multiple objects to be recognized according to the recognition results of the multiple clustering sets.
[0162] In an embodiment of the present application, a data processing device is provided. Using the above device, after obtaining the node representation of each node in the graph neural network, a clustering algorithm is used to cluster each node based on the node representation, thereby obtaining multiple cluster sets; then the cluster sets are subjected to abnormal probability judgment, which can effectively achieve the overall disposal rate and timeliness of abnormal objects, while reducing the repeated calculation of manual strategies and improving the recognition efficiency of abnormal objects.
[0163] Optionally, in the above Figure 4 On the basis of the corresponding embodiment, in another embodiment of the data processing device 20 provided in the embodiment of the present application, the clustering algorithm includes at least one of the following: a density-based clustering algorithm, a partition-based clustering algorithm, a hierarchy-based clustering algorithm or a grid-based clustering algorithm.
[0164] The data processing device provided in this application can be used in a server, see Figure 5 , Figure 5 : is a schematic diagram of a server structure provided in an embodiment of the present application. The server 300 may have relatively large differences due to different configurations or performances, and may include one or more central processing units (CPU) 322 (for example, one or more processors) and memory 332, and one or more storage media 330 (for example, one or more mass storage devices) storing application programs 342 or data 344. Among them, the memory 332 and the storage medium 330 can be short-term storage or permanent storage. The program stored in the storage medium 330 may include one or more modules (not shown in the figure), and each module may include a series of instruction operations on the server. Furthermore, the central processing unit 322 can be configured to communicate with the storage medium 330 to execute a series of instruction operations in the storage medium 330 on the server 300.
[0165] The server 300 may also include one or more power supplies 326, one or more wired or wireless network interfaces 350, one or more input and output interfaces 358, and / or one or more operating systems 341, such as Windows Server 2000. TM , Mac OS X TM , Unix TM ,Linux TM , FreeBSD TM etc.
[0166] The steps performed by the server in the above embodiment can be based on the Figure 5 The server structure shown.
[0167] The data processing device provided by this application can be used in a terminal device. Please refer to Figure 6 , for the sake of convenience in description, only the parts related to the embodiments of this application are shown. For the specific technical details not disclosed, please refer to the method part of the embodiments of this application. In the embodiments of this application, a smart phone is taken as an example of the terminal device for illustration:
[0168] Figure 6 The figure shows a block diagram of a part of the structure of a smart phone related to the terminal device provided by the embodiments of this application. Refer to Figure 6 , the smart phone includes: a radio frequency (RF) circuit 410, a memory 420, an input unit 430, a display unit 440, a sensor 450, an audio circuit 460, a wireless fidelity (WiFi) module 470, a processor 480, and a power supply 490 and other components. Those skilled in the art can understand that Figure 6 the structure of the smart phone shown in does not constitute a limitation on the smart phone, and it may include more or fewer components than shown in the figure, or combine certain components, or have different component arrangements.
[0169] The following will specifically introduce each component of the smart phone in combination with Figure 6 :
[0170] The RF circuit 410 can be used for receiving and sending signals during information reception or call processes. Specifically, after receiving the downlink information from the base station, it is given to the processor 480 for processing; in addition, it sends the designed uplink data to the base station. Generally, the RF circuit 410 includes but is not limited to antennas, at least one amplifier, a transceiver, a coupler, a low noise amplifier (LNA), a duplexer, etc. In addition, the RF circuit 410 can also communicate with the network and other devices through wireless communication. The above wireless communication can use any communication standard or protocol, including but not limited to the global system of mobile communication (GSM), general packet radio service (GPRS), code division multiple access (CDMA), wideband code division multiple access (WCDMA), long term evolution (LTE), email, short messaging service (SMS), etc.
[0171] The memory 420 can be used to store software programs and modules. The processor 480 executes various functional applications and data processing of the smart phone by running the software programs and modules stored in the memory 420. The memory 420 mainly includes a program storage area and a data storage area. Among them, the program storage area can store an operating system, application programs required for at least one function (such as a sound playback function, an image playback function, etc.); the data storage area can store data created according to the use of the smart phone (such as audio data, phone book, etc.). In addition, the memory 420 can include a high-speed random access memory, and can also include a non-volatile memory, such as at least one magnetic disk storage device, a flash memory device, or other volatile solid-state storage devices.
[0172] The input unit 430 can be used to receive input digital or character information, and generate key signal inputs related to the user settings and function controls of the smart phone. Specifically, the input unit 430 can include a touch panel 431 and other input devices 432. The touch panel 431, also known as a touch screen, can collect touch operations of the user on or near it (such as operations of the user using a finger, a stylus, or any suitable object or accessory on or near the touch panel 431), and drive corresponding connection devices according to a preset program. Optionally, the touch panel 431 can include two parts: a touch detection device and a touch controller. Among them, the touch detection device detects the touch position of the user, detects the signal brought by the touch operation, and transmits the signal to the touch controller; the touch controller receives the touch information from the touch detection device, converts it into contact coordinates, and then sends it to the processor 480, and can receive and execute commands sent by the processor 480. In addition, various types such as resistive, capacitive, infrared, and surface acoustic wave can be used to implement the touch panel 431. In addition to the touch panel 431, the input unit 430 can also include other input devices 432. Specifically, the other input devices 432 can include, but are not limited to, one or more of a physical keyboard, function keys (such as volume control keys, power on / off keys, etc.), a trackball, a mouse, a joystick, etc.
[0173] The display unit 440 can be used to display information input by the user or information provided to the user, as well as various menus of the smart phone. The display unit 440 may include a display panel 441. Optionally, the display panel 441 can be configured in the form of, for example, a liquid crystal display (LCD), an organic light-emitting diode (OLED), etc. Further, a touch panel 431 can cover the display panel 441. When the touch panel 431 detects a touch operation on or near it, it transmits the operation to the processor 480 to determine the type of touch event. Subsequently, the processor 480 provides a corresponding visual output on the display panel 441 according to the type of touch event. Although in Figure 6 the touch panel 431 and the display panel 441 are implemented as two independent components to realize the input and output functions of the smart phone, in some embodiments, the touch panel 431 and the display panel 441 can be integrated to realize the input and output functions of the smart phone.
[0174] The smart phone may further include at least one sensor 450, such as a light sensor, a motion sensor, and other sensors. Specifically, the light sensor may include an ambient light sensor and a proximity sensor. Among them, the ambient light sensor can adjust the brightness of the display panel 441 according to the brightness of the ambient light, and the proximity sensor can turn off the display panel 441 and / or the backlight when the smart phone is moved to the ear. As a kind of motion sensor, the accelerometer sensor can detect the magnitude of acceleration in all directions (generally three axes). When stationary, it can detect the magnitude and direction of gravity, and can be used in applications for identifying the posture of the smart phone (such as landscape / portrait screen switching, related games, magnetometer attitude calibration), vibration recognition related functions (such as pedometer, tapping), etc.; As for other sensors that the smart phone can also be configured with, such as gyroscopes, barometers, hygrometers, thermometers, infrared sensors, etc., they will not be elaborated here.
[0175] The audio circuit 460, the speaker 461, and the microphone 462 can provide an audio interface between the user and the smart phone. The audio circuit 460 can transmit the electrical signal converted from the received audio data to the speaker 461, and the speaker 461 converts it into a sound signal for output; on the other hand, the microphone 462 converts the collected sound signal into an electrical signal, which is received by the audio circuit 460 and then converted into audio data. After the audio data is output to the processor 480 for processing, it is sent through the RF circuit 410 to, for example, another smart phone, or the audio data is output to the memory 420 for further processing.
[0176] WiFi belongs to short - range wireless transmission technology. Through the WiFi module 470, a smart phone can help users send and receive emails, browse the web, and access streaming media, etc. It provides users with wireless broadband Internet access. Although Figure 6 the WiFi module 470 is shown, it can be understood that it does not belong to an essential component of the smart phone and can be omitted entirely within the scope of not changing the essence of the invention as needed.
[0177] The processor 480 is the control center of the smart phone. It connects various parts of the entire smart phone using various interfaces and circuits. By running or executing software programs and / or modules stored in the memory 420, and by invoking data stored in the memory 420, it executes various functions of the smart phone and processes data, thereby monitoring the smart phone as a whole. Optionally, the processor 480 may include one or more processing units; optionally, the processor 480 may integrate an application processor and a modem processor. Among them, the application processor mainly processes the operating system, user interface, and application programs, etc., and the modem processor mainly processes wireless communications. It can be understood that the above - mentioned modem processor may not be integrated into the processor 480 either.
[0178] The smart phone also includes a power source 490 (such as a battery) that powers each component. Optionally, the power source can be logically connected to the processor 480 through a power management system, thereby implementing functions such as management of charging, discharging, and power consumption management through the power management system.
[0179] Although not shown, the smart phone may also include a camera, a Bluetooth module, etc., which will not be elaborated here.
[0180] In the above - mentioned embodiments, the steps executed by the terminal device can be based on the Figure 6 shown terminal device structure.
[0181] In the embodiments of the present application, a computer - readable storage medium is also provided. A computer program is stored in the computer - readable storage medium. When it runs on a computer, it causes the computer to execute the methods described in the foregoing various embodiments.
[0182] In the embodiments of the present application, a computer program product including a program is also provided. When it runs on a computer, it causes the computer to execute the methods described in the foregoing various embodiments.
[0183] Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the systems, devices, and units described above can refer to the corresponding processes in the foregoing method embodiments and will not be elaborated here.
[0184] In several embodiments provided in the present application, it should be understood that the disclosed systems, devices, and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the units is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed coupling, direct coupling, or communication connection between each other can be through some interfaces. The indirect coupling or communication connection of the device or unit can be in electrical, mechanical, or other forms.
[0185] The units described as separate components may or may not be physically separated. The components displayed as units may or may not be physical units, that is, they can be located in one place or distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0186] In addition, each functional unit in various embodiments of the present application can be integrated into a processing unit, or each unit can exist physically alone, or two or more units can be integrated into one unit. The above-mentioned integrated units can be implemented in the form of hardware or in the form of software functional units.
[0187] If the above-mentioned integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, or all or part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to enable a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of the present application. The foregoing storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical discs that can store program codes.
[0188] As mentioned above, the above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them; although the present application has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of various embodiments of the present application.
Claims
1. A data processing method, characterized in that, Including: Obtain the historical behavior data of multiple objects to be recognized, where the historical behavior data includes the attribute data of the objects to be recognized and the association data with other objects to be recognized; Based on the historical behavior data, obtain the association relationship graph of the multiple objects to be recognized and the historical behavior characteristics of each object to be recognized among the multiple objects to be recognized. Among them, the nodes of the association relationship graph are the objects to be recognized, and the edges of the association relationship graph are the association relationships between the objects to be recognized; Construct a graph neural network based on the association relationship graph and the historical behavior characteristics of each object to be recognized; Obtain the node representations of each node in the graph neural network; Determine the recognition results of the multiple objects to be recognized based on the node representations.
2. The method according to claim 1, characterized in that, The obtaining the association relationship graph of the multiple objects to be recognized based on the historical behavior data includes: Based on the historical behavior data, determine a set of target recognition objects from the multiple objects to be recognized according to a first preset rule. The objects to be recognized in the set of target recognition objects are suspicious objects, and other objects to be recognized are confirmed as normal objects; Based on the historical behavior data, determine the association relationships between the objects to be recognized in the set of target recognition objects; Construct an association relationship graph corresponding to the set of target recognition objects according to the association relationships, where the association relationship graph corresponding to the set of target recognition objects is used as the association relationship graph of the multiple objects to be recognized.
3. The method according to claim 2, wherein Based on the historical behavior data, determining the association relationships between the objects to be recognized in the set of target recognition objects includes: When the historical behavior data indicates that the account login addresses of two objects to be recognized are the same, determine that there is an association relationship between the two objects to be recognized; When the historical behavior data indicates that two objects to be recognized belong to the same community, determine that there is an association relationship between the two objects to be recognized; When the historical behavior data indicates that two objects to be recognized are friends with each other, determine that there is an association relationship between the two objects to be recognized; When the historical behavior data indicates that two objects to be recognized have an interaction behavior, determine that there is an association relationship between the two objects to be recognized; Traverse the set of target recognition objects in turn to determine the association relationships between the objects to be recognized in the set of target recognition objects.
4. The method according to claim 1, characterized in that, Based on the historical behavior data, obtaining the historical behavior characteristics of each object to be recognized among the multiple objects to be recognized includes: Based on the historical behavior data, determine a set of target recognition objects from the multiple objects to be recognized according to a first preset rule. The objects to be recognized in the set of target recognition objects are suspicious objects, and other objects to be recognized are confirmed as normal objects; Perform feature preprocessing and feature splicing on the historical behavior data to obtain the historical behavior characteristics of each object to be recognized in the set of target recognition objects.
5. The method according to any one of claims 1 to 4, characterized in that, Obtaining the node representations of each node in the graph neural network includes: Obtain the set of adjacent objects of the first node; Perform clustering processing on the historical behavior characteristics of each node in the set of adjacent objects to obtain the first node representation of the first node; Traverse each node in the graph neural network in turn to obtain the intermediate node representations of each node in the graph neural network; Repeat the above operation N times to obtain the node representations of each node in the graph neural network, where N is a positive integer.
6. The method according to any one of claims 1 to 4, characterized in that The determining the recognition results of the multiple objects to be recognized based on the node representations includes: Invoking a classification network to classify the node representations of each node to obtain the recognition results of the multiple objects to be recognized.
7. The method according to any one of claims 1 to 4, characterized in that The determining the recognition results of the multiple objects to be recognized based on the node representations includes: Using a clustering algorithm to cluster each node based on the node representations within the graph neural network to obtain multiple clustering sets; Obtaining the outliers of the multiple clustering sets; Determining the recognition results of the multiple clustering sets according to the outliers; Determining the recognition results of the multiple objects to be recognized according to the recognition results of the multiple clustering sets.
8. A data processing device, characterized in that, Includes: An acquisition module, configured to acquire historical behavior data of multiple objects to be recognized, where the historical behavior data includes attribute data of the objects to be recognized and association data with other objects to be recognized; A processing module, configured to obtain an association relationship graph of the multiple objects to be recognized and historical behavior characteristics of each object to be recognized among the multiple objects to be recognized based on the historical behavior data, where the nodes of the association relationship graph are objects to be recognized, and the edges of the association relationship graph are historical behavior relationships between the objects to be recognized; constructing a graph neural network based on the association relationship graph and the historical behavior characteristics of each object to be recognized; obtaining the node representations of each node in the graph neural network; A recognition module, configured to determine the recognition results of the multiple objects to be recognized based on the node representations.
9. A computer device, characterized in that, Includes: A memory, a processor, and a bus system; Wherein, the memory is used to store programs; The processor is configured to execute the programs in the memory, and the processor is configured to execute the method according to any one of claims 1 to 7 according to the instructions in the program code; The bus system is used to connect the memory and the processor to enable communication between the memory and the processor.
10. A computer-readable storage medium, including instructions, which when running on a computer, cause the computer to execute the method according to any one of claims 1 to 7.