Safety brain dynamic monitoring system and method based on artificial intelligence

By integrating data from e-commerce platforms and applying multiple algorithms, the data island problem in e-commerce transactions is solved, real-time identification and early warning of abnormal behaviors is achieved, and the security of e-commerce transactions is improved.

CN120278729AInactive Publication Date: 2025-07-08SHENZHEN ZHIANTUO TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510306834.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-15
Publication Date
2025-07-08
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

The existing e-commerce transaction security protection system lacks intelligent cores and cannot integrate and analyze and make intelligent decisions on multiple data. Each protection module is independent and the data cannot be shared, making it difficult to effectively identify abnormal behaviors, especially the risks of order brushing and account theft.

Method used

Using a secure brain dynamic monitoring system based on artificial intelligence, through Apriori algorithm, time series analysis, One-Class SVM model and clustering algorithm, the purchase records, user information and logistics information of e-commerce platforms are integrated, in-depth analysis and intelligent decision-making, monitoring and marking abnormal behaviors in real time, and comprehensive evaluation and early warning are used for random forest models.

Benefits of technology

It realizes the global risk assessment of e-commerce transactions, can timely identify and warn of abnormal behaviors, improves the overall security protection capabilities of e-commerce platforms, dynamically adjusts risk assessment strategies, and reduces the risk of account theft and malicious order brushing.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120278729A_ABST
    Figure CN120278729A_ABST
Patent Text Reader

Abstract

The invention discloses a safe brain dynamic monitoring system and method based on artificial intelligence, and belongs to the technical field of artificial intelligence. The method comprises the following steps: connecting an e-commerce platform to obtain a purchase record, user information and logistics information of a user; mining potential association between user purchase behaviors based on the purchase record of the user, and marking abnormality; using a time sequence analysis algorithm to monitor the abnormal fluctuation of the purchase frequency and the purchase amount, and marking the abnormality; carrying out feature engineering, learning a normal login behavior mode of the user, and when detecting that a new login behavior deviates from the learned normal mode, judging that the login is abnormal; clustering the logistics information of the user by using a clustering algorithm; if the logistics information of a certain user has an isolated clustering condition, it is judged that an account abnormal use condition exists; training and verification are carried out through a random forest model, the risk condition of the account is judged according to the prediction result of the model, and the high-risk account is processed.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of artificial intelligence technology, and specifically to a dynamic monitoring system and method for a security brain based on artificial intelligence. Background Art

[0002] With the booming development of e-commerce, the transaction scale and the number of users of e-commerce platforms have increased explosively. Numerous consumers shop through e-commerce platforms and enjoy convenient life services; merchants also expand their sales channels and obtain commercial benefits through this. However, behind this prosperity, e-commerce transaction security issues have become increasingly prominent. With the rise of technologies such as big data and artificial intelligence, these advanced technologies have begun to be introduced into the field of e-commerce security to build a more intelligent security protection system. The concept of a security brain has emerged, aiming to integrate various data and advanced algorithms to deeply analyze and make intelligent decisions on various types of data in e-commerce transactions like the human brain, so as to escort the security of e-commerce transactions.

[0003] The identification of abnormal behaviors mainly relies on fixed rules and has poor flexibility. Once violators change their strategies and evade existing rules, it is difficult for the system to accurately judge. Existing e-commerce security protection mainly focuses on preventing risks in a single link or a single type, such as only paying attention to brushing behavior or only protecting account login security, and does not form an organic whole. Each protection module is independent of each other, and data cannot be shared, and it is impossible to comprehensively evaluate account risks from a global perspective. Existing technologies lack an intelligent core like a security brain and cannot perform fusion analysis and intelligent decision-making on various types of data. Summary of the Invention

[0004] The purpose of the present invention is to provide a dynamic monitoring system and method for a security brain based on artificial intelligence to solve the problems raised in the existing technology.

[0005] To achieve the above purpose, the present invention provides the following technical solutions: A dynamic monitoring method for a security brain based on artificial intelligence, the method includes the following steps: Connect to the e-commerce platform, obtain the purchase records, user information, and logistics information of users, perform data cleaning, data sorting, and data association, and store them in the database; Use the Apriori algorithm to mine the potential associations between user purchase behaviors based on the purchase records of users. When it is found that the user's purchase behavior does not conform to their historical purchase preferences and there are associated purchases that match the characteristics of brushing behavior, mark them as abnormal; use the time series analysis algorithm to monitor abnormal fluctuations in the purchase frequency and purchase amount to determine whether there is malicious brushing behavior and mark it as abnormal; integrate the purchase records marked as abnormal into the purchase record abnormal data set; Feature engineering is carried out, and the One-Class SVM model is adopted. By learning the normal login behavior patterns of users, when a new login behavior deviates from the learned normal pattern, it is determined as an abnormal login, forming an abnormal user information dataset; Using the clustering algorithm, cluster the logistics information of users; if the logistics information of a certain user shows an isolated clustering situation, it is determined that there is an abnormal use of the account, forming an abnormal logistics information dataset; Integrate the abnormal purchase record dataset, the abnormal user information dataset and the abnormal logistics information dataset, input them into the random forest model, adjust the model parameters, conduct model training and verification, and judge the risk status of the account according to the prediction results of the model; Based on the risk status of the account, notify the e-commerce platform to handle high-risk accounts.

[0006] The Security Brain is an innovative concept that integrates big data and artificial intelligence technologies, aiming to provide intelligent protection for e-commerce transaction security. In the present invention, the Security Brain plays a core role. It integrates multi-source data such as purchase records, user information and logistics information in the e-commerce platform, and uses advanced algorithms to conduct in-depth analysis and intelligent decision-making on these data.

[0007] In the data processing stage, the Security Brain uses efficient data cleaning, sorting and association technologies to deeply integrate the massive and complex e-commerce data, and discovers the potential connections between the data. For example, through the correlation analysis of the purchase records of multiple accounts under the same IP address, the abnormal behaviors of the brushstroke gangs can be discovered in time, providing a solid data basis for subsequent risk assessment.

[0008] In terms of risk identification, the Security Brain uses a variety of advanced algorithms, such as the Apriori algorithm to mine the potential associations of user purchase behaviors, the time series analysis algorithm to monitor the fluctuations of purchase frequency and amount, and the One-Class SVM model to learn the normal login behavior patterns of users. These algorithms work together to monitor the purchase, login and logistics information of users in real time. Once an abnormality is found, it can be quickly and accurately identified and marked, and a warning is issued in time, effectively reducing the risks such as account theft and malicious brushstrokes.

[0009] In building the protection system, the Security Brain comprehensively analyzes multiple abnormal datasets, namely abnormal purchase records, abnormal user information and abnormal logistics information, and inputs them into the random forest model for training and verification. It can dynamically adjust the risk assessment strategy according to the weights and correlation relationships of different risk factors, and comprehensively evaluate the account risk from a global perspective. For high-risk accounts, the e-commerce platform is notified in time for processing, forming an organic and intelligent overall protection system to escort the security and stability of e-commerce transactions.

[0010] Furthermore, the purchase record includes purchase time, category of purchased goods, purchase frequency, purchase amount and order status; the user information includes registration information and login information, the registration information includes name, user ID, contact information and registration address, the login information includes login IP, login device, login time interval and account activity, and the account activity is analyzed based on the frequency of browsing goods and the frequency of participating in platform interactions; the logistics information includes the delivery address, logistics order number, logistics track update status and logistics delivery time; The data cleaning means removing duplicate data and erroneous data, the data sorting means sorting in chronological order, and the data association means associating purchase records, user information and logistics information based on the user ID in the user information; and storing them in a database.

[0011] Furthermore, for each user, their purchase records are organized into a data set suitable for Apriori algorithm input, and the commodity category code of each purchase is combined into a transaction, and all transactions constitute the user's purchase behavior data set; according to the business characteristics and historical data of the e-commerce platform, the support and confidence thresholds are set for the Apriori algorithm. The support reflects the frequency of a certain commodity combination in all transactions, and the confidence indicates the probability of purchasing the latter commodity when the former commodity is purchased; The purchase behavior dataset is scanned starting from a single commodity, the number of occurrences of each commodity code is counted, commodities that meet the support threshold are screened out, and frequent itemsets are formed; an item set is generated based on the frequent item set, and the item set represents a combination of two commodities; the purchase behavior dataset is scanned again, the number of occurrences of the item set is counted, and frequent itemsets that meet the support threshold are screened out; and higher-order frequent itemsets are continuously generated until no new frequent itemsets that meet the support threshold can be generated.

[0012] Furthermore, association rules are generated based on the generated frequent item sets; based on the association rules and the user's historical purchase records, the user's historical purchase preferences are analyzed, and the combinations of product categories that the user frequently purchases, as well as the associations between the product category combinations, are counted; the user's current purchase behavior is compared with the historical purchase preferences, and when it is found that the user has associated purchases that are consistent with the characteristics of fake order behavior, and the purchase behavior does not conform to his historical purchase preferences, it is marked as an abnormality.

[0013] Further, the time series analysis algorithm adopts the ARIMA model, uses historical purchase data to train the selected time series model. During the training process, by continuously adjusting the model parameters, the model can fit the changing trend of historical data; uses the trained time series model to predict the purchase frequency and purchase amount within a certain period in the future; based on the model prediction results, calculates the standard deviation of the predicted values, and regards the data exceeding the mean ± g times the standard deviation as abnormal data, where g is determined according to the business risk preference; Compares the actual purchase frequency and purchase amount data with the predicted values. When the actual data exceeds the set abnormal threshold range and shows the typical characteristics of malicious brushing behavior, determines that this data point is abnormal; Integrates the purchase records marked as abnormal into the purchase record abnormal data set.

[0014] Further, determines the key features for training the One-Class SVM model, including the specific location of login, the type number of the login device, and the login time pattern. Based on the login IP, converts the IP address into longitude and latitude to obtain the specific location of login. Based on the login device, assigns different numbers to mobile phones and computers of different brands and models to obtain the type number of the login device. Based on the login time interval, divides a day into multiple time periods, and counts the number of logins of each user in each time period to obtain the login time pattern; Removes the login IP, login device, and login time interval from the user information, and combines the key features with the processed user information respectively to obtain the data after feature engineering; Initializes the One-Class SVM model, uses the data after feature engineering to train the model. During the training process, the model learns the normal login behavior pattern of users; Each time a user logs in to the e-commerce platform, collects the login information, converts the new login information into the data after feature engineering to obtain a new feature vector; Uses the trained One-Class SVM model to judge whether the new feature vector is normal, and marks it as an abnormal login when it is determined to be abnormal, forming a user information abnormal data set.

[0015] Further, the clustering algorithm selects the K-Means clustering algorithm, uses the elbow method to determine the value of K, calculates the sum of squared errors SSE of clustering under different values of K, and the formula is: ; Among them, represents the i-th cluster, is the centroid of the i-th cluster, and x is the data point within the cluster; By plotting the relationship graph between SSE and the value of K, finds the inflection point of the curve, and takes the inflection point as the value of K; Randomly selects K data points as the initial centroids; For each logistics information data point, calculate its distance from the K centroids using the Euclidean distance; after all data points are assigned to the corresponding clusters, recalculate the centroid of each cluster; the centroid is calculated as the mean of all data points within the cluster. For a cluster containing multiple logistics information data points, the value of each dimension of its centroid is the average of all data points within the cluster in the corresponding dimension, where each dimension of the centroid corresponds to the dimension of the logistics delivery duration; repeat the steps of calculating distances and updating centroids until the centroids no longer change or reach the preset maximum number of iterations; After obtaining the clustering results, check the situation of each cluster; when the number of data points in a certain cluster is less than the set threshold, and the difference in the receiving address from the addresses in other clusters exceeds the set threshold and the logistics delivery duration deviates from the mean of other clusters, then this cluster is determined to be an isolated cluster; extract the data points belonging to the isolated cluster to form a logistics information abnormal data set.

[0016] Furthermore, integrate the purchase record abnormal data set, user information abnormal data set, and logistics information abnormal data set to determine the adjustment range of parameters; use the grid search method to conduct a comprehensive search within the set parameter range, try all possible parameter combinations through grid search, and evaluate the performance of each combination using cross-validation; divide the integrated data set into a training set and a validation set according to a certain proportion; Use the training set data to train the random forest model with adjusted parameters. During the training process, the random forest model constructs multiple decision trees, and each decision tree is trained based on a random subset of the training data and a subset of features; use the majority voting method to synthesize the prediction results of the decision trees to obtain the final prediction result; for the situation of judging whether an account has malicious brushing or has been stolen, each decision tree can give a prediction result, and the random forest model synthesizes the results of all decision trees to obtain a final judgment.

[0017] Furthermore, based on the risk status of the account, identify high-risk accounts and summarize the user information of high-risk accounts; send the user information of the high-risk accounts to the security management department of the e-commerce platform in the form of a warning notice and establish a real-time communication mechanism with the security management department; After the security management department receives the notice and confirms it, freeze the trading function of the high-risk accounts and restrict the login of high-risk accounts; send an account abnormality notice to the account owner through the contact information provided during user registration; guide the user to cooperate with the platform's investigation and handling work in the notice and require the user to conduct identity verification.

[0018] An artificial intelligence-based security brain dynamic monitoring system, comprising: Data collection and preprocessing module: including: a data collection unit and a data preprocessing unit; among them, the data collection unit is connected to the e-commerce platform to obtain the purchase records, user information, and logistics information of users, and the data preprocessing unit performs data cleaning, data sorting, and data association and stores them in the database; Purchase record analysis module: an association rule mining unit, a time series analysis unit, and an abnormal purchase record integration unit; the association rule mining unit uses the Apriori algorithm to mine the potential associations between user purchase behaviors based on the purchase records of users. When it is found that the user's purchase behavior does not conform to their historical purchase preferences and there are associated purchases that match the characteristics of brush orders, it is marked as abnormal; the time series analysis unit uses the time series analysis algorithm to monitor the abnormal fluctuations in the purchase frequency and purchase amount to determine whether there is malicious brush order behavior and marks it as abnormal; the abnormal purchase record integration unit integrates the purchase records marked as abnormal into the purchase record abnormal data set; User information analysis module: including: a One-Class SVM training and detection unit and an abnormal user information integration unit; the One-Class SVM training and detection unit performs feature engineering and adopts the One-Class SVM model. By learning the normal login behavior pattern of users, when a new login behavior deviates from the learned normal pattern, it is determined as an abnormal login, and the abnormal user information integration unit forms an abnormal user information data set; Logistics information analysis module: including: a clustering algorithm processing unit and an abnormal logistics information integration unit; among them, the clustering algorithm processing unit uses the clustering algorithm to cluster the logistics information of users; if the logistics information of a certain user shows an isolated clustering situation, it is determined that there is an abnormal use of the account, and the abnormal logistics information integration unit forms an abnormal logistics information data set; Security brain analysis and processing module: including: a data set integration unit, a random forest model training and verification unit, a security brain analysis unit, and a security brain processing unit; among them, the data set integration unit integrates the purchase record abnormal data set, the user information abnormal data set, and the logistics information abnormal data set, and the random forest model training and verification unit inputs the integrated data set into the random forest model, adjusts the model parameters, and performs model training and verification. The security brain analysis unit judges the risk status of the account according to the prediction result of the model; the security brain processing unit notifies the e-commerce platform to process high-risk accounts based on the risk status of the account.

[0019] Compared with the prior art, the beneficial effects of the present invention are: 1. The present invention utilizes a variety of advanced algorithms and models, such as the Apriori algorithm, time series analysis algorithm, One-Class SVM model, clustering algorithm, and random forest model. These algorithms and models cooperate with each other to more effectively identify various complex malicious behavior patterns.

[0020] 2. The present invention realizes real-time dynamic monitoring of accounts, can timely detect abnormal behaviors of accounts and issue early warnings. The system obtains data from the e-commerce platform in real time, conducts real-time analysis on each operation and transaction of users. Once abnormal situations are found, the early warning mechanism is immediately activated to notify the security management department of the e-commerce platform and users.

[0021] 3. The present invention introduces the concept of a security brain, and through the collaborative work of a variety of advanced algorithms, realizes intelligent analysis and decision-making of e-commerce transaction data; the security brain can dynamically adjust the risk assessment strategy according to the weights and correlation relationships of different risk factors, and timely notify the e-commerce platform to handle high-risk accounts, effectively improving the overall security protection ability of the e-commerce platform. BRIEF DESCRIPTION OF THE DRAWINGS

[0022] Figure 1 is a schematic diagram of the steps of a method for dynamically monitoring a security brain based on artificial intelligence according to the present invention; Figure 2 is a system structure diagram of a system for dynamically monitoring a security brain based on artificial intelligence according to the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0023] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.

[0024] Embodiment: As Figure 1 - Figure 2 shown, the present invention provides a technical solution, According to an embodiment of the present invention, as Figure 1 shown in the schematic diagram of the steps of a method for dynamically monitoring a security brain based on artificial intelligence, a method for dynamically monitoring a security brain based on artificial intelligence, the method includes the following steps: Connect to the e-commerce platform, obtain the purchase records, user information, and logistics information of users, perform data cleaning, data sorting, and data association, and store them in the database; Use the Apriori algorithm to mine the potential associations between users' purchase behaviors based on their purchase records. When it is found that a user's purchase behavior does not conform to their historical purchase preferences and there are associated purchases that match the characteristics of brush sales behavior, mark it as abnormal; use the time series analysis algorithm to monitor abnormal fluctuations in the purchase frequency and purchase amount to determine whether there is malicious brush sales behavior and mark it as abnormal; integrate the purchase records marked as abnormal into the abnormal purchase record dataset; Perform feature engineering and adopt the One-Class SVM model. By learning the normal login behavior patterns of users, when a new login behavior deviates from the learned normal pattern, it is determined as an abnormal login, forming an abnormal user information dataset; Use the clustering algorithm to cluster the logistics information of users; if there is an isolated clustering situation in a user's logistics information, it is determined that there is an abnormal use of the account, forming an abnormal logistics information dataset; Integrate the abnormal purchase record dataset, the abnormal user information dataset, and the abnormal logistics information dataset, input them into the random forest model, adjust the model parameters, perform model training and verification, and judge the risk status of the account based on the prediction results of the model; based on the risk status of the account, notify the e-commerce platform to handle high-risk accounts.

[0025] Further, the purchase records include purchase time, purchased product category, purchase frequency, purchase amount, and order status; the user information includes registration information and login information. The registration information includes name, user ID, contact information, and registration address. The login information includes login IP, login device, login time interval, and account activity. The account activity is analyzed based on the frequency of browsing products and the frequency of participating in platform interactions; the logistics information includes the delivery address, logistics order number, logistics track update situation, and logistics delivery duration; The data cleaning means removing duplicate data and error data. The data sorting means sorting in chronological order. The data association means associating the purchase records, user information, and logistics information based on the user ID in the user information; store them in the database.

[0026] Further, for each user, organize their purchase records into a dataset form suitable for input into the Apriori algorithm. Code the product categories of each purchase to form a transaction, and all transactions constitute the purchase behavior dataset of this user; according to the business characteristics and historical data situation of the e-commerce platform, set the support and confidence thresholds for the Apriori algorithm. The support reflects the frequency of a certain product combination appearing in all transactions, and the confidence indicates the probability of purchasing the subsequent product given that the previous product has been purchased; In this embodiment, there is an e-commerce user "User1", and the purchase records within a period of time are shown in Table 1 User Purchase Record Table: Table 1 User Purchase Record Table Encode the product categories: mobile phone - 1, phone case - 2, earphone - 3, charger - 4. Compose the product category codes of each purchase into transactions to obtain the purchase behavior dataset of this user: Transaction 1: {1}, Transaction 2: {2}, Transaction 3: {3}, Transaction 4: {1}, Transaction 5: {4}, Transaction 6: {1}, Transaction 7: {2}.

[0027] According to the business characteristics and historical data of the e-commerce platform, set the support threshold to 0.2 (that is, the frequency of a certain product combination in all transactions reaches at least 20%), and the confidence threshold to 0.6 (that is, in the case of purchasing the previous product, the probability of purchasing the subsequent product is at least 60%).

[0028] Start scanning the purchase behavior dataset from a single product, and count the number of occurrences of each product code: Product 1 (mobile phone) appears 3 times, and the support is 3 / 7 ≈ 0.43 > 0.2, which is a frequent 1-item set.

[0029] Product 2 (phone case) appears 2 times, and the support is 2 / 7 ≈ 0.29 > 0.2, which is a frequent 1-item set.

[0030] Product 3 (earphone) appears 1 time, and the support is 1 / 7 ≈ 0.14 < 0.2, which is not a frequent 1-item set.

[0031] Product 4 (charger) appears 1 time, and the support is 1 / 7 ≈ 0.14 < 0.2, which is not a frequent 1-item set.

[0032] Generate 2-item sets based on the frequent 1-item sets: The 2-item set {1, 2} (mobile phone and phone case) appears 2 times, and the support is 2 / 7 ≈ 0.29 > 0.2, which is a frequent 2-item set.

[0033] The support of other 2-item set combinations is less than 0.2, which are not frequent 2-item sets.

[0034] Continue to generate 3-item sets, but since there is only one frequent 2-item set {1, 2}, no frequent 3-item set that meets the support threshold can be generated, and the generation of frequent item sets ends here.

[0035] Generate association rules from the frequent 2-item set {1, 2}: “1->2” (Buy a phone case when buying a phone), with a confidence of 2 / 3 ≈ 0.67 > 0.6, is a valid association rule.

[0036] “2->1” (Buy a phone when buying a phone case), with a confidence of 2 / 2 = 1 > 0.6, is a valid association rule.

[0037] Analyze the user's historical purchase preferences and find that the user often buys phones and phone cases, and there is an association relationship of "may buy a phone case after buying a phone" and "may buy a phone after buying a phone case".

[0038] This user suddenly bought a large number of "mice" (assuming the code is 5) in subsequent purchase records, and there is no association with the previously purchased items. This purchase behavior does not conform to their historical purchase preferences and is consistent with the characteristics of brush trading behavior (suddenly buying items unrelated to historical purchases), so it is marked as abnormal.

[0039] Extract the user's purchase frequency and purchase amount data, and use the ARIMA model for training. After multiple trials and parameter adjustments, the model parameters are determined to be ARIMA(1,1,1).

[0040] Use the trained model to predict the purchase frequency and purchase amount for the next week (2024-11-05 - 2024-11-11). The prediction results are that the purchase frequency is about 1 time / week and the purchase amount is about 2000 yuan.

[0041] Calculate the standard deviation of the predicted values. Assume that after calculation, the standard deviation of the purchase frequency is 0.1 and the standard deviation of the purchase amount is 100. According to the business risk preference, set g = 2.

[0042] The abnormal threshold ranges are as follows: Abnormal threshold range for purchase frequency: [1 - 2×0.1, 1 + 2×0.1] = [0.8, 1.2]; Abnormal threshold range for purchase amount: [2000 - 2×100, 2000 + 2×100] = [1800, 2200]; Assume that during the period from 2024-11-05 to 2024-11-11, the actual purchase frequency is 3 times / week and the purchase amount is 50 yuan. The actual purchase frequency exceeds the abnormal threshold range, and the purchase amount shows regular small fluctuations (a large difference from the previous purchase amount), presenting typical characteristics of malicious brush trading behavior. Determine that this data point is abnormal.

[0043] Integrate the above purchase records marked as abnormal (the records of buying "mice" and the records with abnormal purchase frequency and amount) into the purchase record abnormal data set to provide data support for subsequent comprehensive judgment of account risks.

[0044] Further, the key features for training the One-Class SVM model are determined, including the specific location of login, the type number of the login device, and the time pattern of login. Based on the login IP, the IP address is converted into longitude and latitude to obtain the specific location of login. Based on the login device, different brands and models of mobile phones and computers are assigned different numbers to obtain the type number of the login device. Based on the login time interval, a day is divided into multiple time periods, and the number of logins of each user in each time period is counted to obtain the time pattern of login. The login IP, login device, and login time interval are removed from the user information, and the key features are respectively combined with the processed user information to obtain the data after feature engineering. Initialize the One-Class SVM model, and use the feature-engineered data to train the model. During the training process, the model learns the user's normal login behavior pattern. Each time the user logs in to the e-commerce platform, the login information is collected, and the new login information is converted into feature-engineered data to obtain a new feature vector. Use the trained One-Class SVM model to determine whether the new feature vector is normal, and mark it when it is determined to be an abnormal login, thereby forming a user information abnormality data set.

[0045] In this embodiment, the user information abnormal data set of the user with user ID U001 is: the normal login location is mainly in city A (latitude and longitude: [latitude1, longitude1]), but one day he suddenly logged in from city B (latitude and longitude: [latitude2, longitude2]), and the login device changed from the commonly used mobile phone (device number: 003) to an unfamiliar computer (device number: 015), and the login time also changed from the previous daytime active to frequent logins in the early morning.

[0046] The abnormal user information data set of the user with user ID U002 is as follows: he has been using a mobile phone of brand X and model Y (device number: 007) to log in, but recently he suddenly used multiple mobile phones of different brands and models (device numbers: 011, 018, 022) to log in alternately in a short period of time, and the login location also frequently switched between multiple different areas.

[0047] The abnormal user information data set of the user with user ID U003 is as follows: the user's usual login time is 9-11 am and 7-9 pm every day. However, in the past week, there have been a large number of login records from 2-4 am, and the location corresponding to the login IP is very different from before.

[0048] Furthermore, the clustering algorithm uses the K-Means clustering algorithm, uses the elbow method to determine the K value, and calculates the clustering error sum of squares SSE under different K values. The formula is: ; Among them, represents the i-th cluster, is the centroid of the i-th cluster, x is the data point within the cluster; by plotting the relationship between SSE and the value of K, finding the inflection point of the curve, and taking the inflection point as the value of K; randomly selecting K data points as the initial centroids; For each logistics information data point, calculate its distances from the K centroids using the Euclidean distance; after all data points are assigned to the corresponding clusters, recalculate the centroid of each cluster; the calculation method of the centroid is the mean of all data points within the cluster. For a cluster containing multiple logistics information data points, the value of each dimension of its centroid is the average of all data points within the cluster in the corresponding dimension, where each dimension of the centroid is the dimension corresponding to the logistics delivery duration; repeat the steps of calculating distances and updating centroids until the centroids no longer change or reach the preset maximum number of iterations; After obtaining the clustering results, check the situation of each cluster; when the number of data points in a certain cluster is less than the set threshold, and the difference in the receiving address from the addresses in other clusters exceeds the set threshold and the logistics delivery duration deviates from the mean of other clusters, then determine that cluster as an isolated cluster; extract the data points belonging to the isolated cluster to form a logistics information abnormal data set.

[0049] In this embodiment, the logistics information abnormal data set of user ID L005 is as follows: Its logistics information is clustered into an isolated cluster. The number of data points within this cluster is only 5 (the set threshold is 10), the receiving address is significantly different from the addresses in other clusters, changing from being concentrated in certain fixed areas to suddenly having multiple remote and unassociated addresses. The logistics delivery duration also deviates from the mean of other clusters, and the average delivery duration extends from the original 3 - 5 days to 10 - 15 days.

[0050] Furthermore, integrate the purchase record abnormal data set, user information abnormal data set, and logistics information abnormal data set to determine the adjustment range of parameters; adopt the grid search method to conduct a comprehensive search within the set parameter range, try all possible parameter combinations through grid search, and evaluate the performance of each combination using cross - validation; divide the integrated data set into a training set and a validation set according to a certain proportion; Use the training set data to train the random forest model with adjusted parameters. During the training process, the random forest model constructs multiple decision trees, and each decision tree is trained based on a random subset of the training data and a subset of features; use the majority voting method to synthesize the prediction results of the decision trees to obtain the final prediction result; for the situation of judging whether an account has malicious order brushing or has been stolen, each decision tree can give a prediction result, and the random forest model synthesizes the results of all decision trees to obtain a final judgment.

[0051] Further, based on the risk status of the account, high-risk accounts are identified, and the user information of high-risk accounts is aggregated; the user information of the high-risk accounts is sent to the security management department of the e-commerce platform in the form of a warning notice, and a real-time communication mechanism is established with the security management department; After the security management department receives the notice and confirms it, the trading function of the high-risk account is frozen, and the login of the high-risk account is restricted; through the contact information provided during user registration, an account abnormality notice is sent to the account owner; the user is guided to cooperate with the platform's investigation and handling work in the notice, and the user is required to authenticate their identity.

[0052] An artificial intelligence-based security brain dynamic monitoring system, comprising: Data acquisition and preprocessing module: including: a data acquisition unit and a data preprocessing unit; wherein, the data acquisition unit is connected to the e-commerce platform to obtain the purchase records, user information and logistics information of users, and the data preprocessing unit performs data cleaning, data sorting and data association and stores them in the database; Purchase record analysis module: an association rule mining unit, a time series analysis unit and an abnormal purchase record integration unit; the association rule mining unit uses the Apriori algorithm to mine the potential associations between user purchase behaviors based on the purchase records of users. When it is found that the user's purchase behavior does not conform to their historical purchase preferences and there are associated purchases that match the characteristics of brushing orders, it is marked as abnormal; the time series analysis unit uses the time series analysis algorithm to monitor the abnormal fluctuations of the purchase frequency and purchase amount to determine whether there is malicious brushing behavior and marks it as abnormal; the abnormal purchase record integration unit integrates the purchase records marked as abnormal into the purchase record abnormal data set; User information analysis module: including: a One-Class SVM training and detection unit and an abnormal user information integration unit; the One-Class SVM training and detection unit performs feature engineering, adopts the One-Class SVM model, and learns the normal login behavior pattern of users. When a new login behavior deviates from the learned normal pattern, it is determined as an abnormal login, and the abnormal user information integration unit forms an abnormal user information data set; Logistics information analysis module: including: a clustering algorithm processing unit and an abnormal logistics information integration unit; wherein, the clustering algorithm processing unit uses the clustering algorithm to cluster the logistics information of users; if the logistics information of a certain user shows an isolated clustering situation, it is determined that there is an abnormal use of the account, and the abnormal logistics information integration unit forms an abnormal logistics information data set; Secure Brain Analysis and Processing Module: It includes: a dataset integration unit, a random forest model training and validation unit, a Secure Brain analysis unit, and a Secure Brain processing unit; among them, the dataset integration unit integrates the abnormal purchase record dataset, the abnormal user information dataset, and the abnormal logistics information dataset, and the random forest model training and validation unit inputs the integrated dataset into the random forest model, adjusts the model parameters, and conducts model training and validation. The Secure Brain analysis unit determines the risk status of the account according to the prediction results of the model; the Secure Brain processing unit notifies the e-commerce platform to process high-risk accounts based on the risk status of the account.

[0053] In this embodiment, the parameter adjustment range of the random forest model is determined. For example, the range of the number of decision trees (n_estimators) is set to [50, 200], the range of the maximum depth (max_depth) is set to [3, 10], the range of the minimum number of samples for splitting (min_samples_split) is set to [2, 10], and the range of the minimum number of samples for leaves (min_samples_leaf) is set to [1, 5].

[0054] Using the grid search method, a comprehensive search is conducted within the set parameter range, and the performance of each parameter combination is evaluated through 5-fold cross-validation. After multiple experiments, the optimal parameter combination is finally determined as n_estimators = 100, max_depth = 6, min_samples_split = 5, and min_samples_leaf = 2.

[0055] The integrated dataset is divided according to the ratio of 70% training set and 30% validation set.

[0056] The training set data is used to train the random forest model. The model learns the features and patterns in the data, constructs decision trees, and makes comprehensive judgments.

[0057] The validation set is used to validate the trained model, and metrics such as the accuracy, recall rate, and F1 value of the model on the validation set are calculated. After verification, the accuracy rate of the model reaches 85%, the recall rate is 80%, and the F1 value is 0.82, indicating that the model has good performance.

[0058] The risk threshold is set to 0.6. When the predicted risk probability value is greater than 0.6, it is determined that the account has a high risk; when the risk probability value is less than or equal to 0.6, it is determined that the account has a low risk or is normal.

[0059] After model prediction, the risk probability values of the accounts with user IDs 001, 023, and 105 are 0.8, 0.85, and 0.75 respectively, all of which are greater than the set threshold of 0.6. Therefore, it is determined that these three accounts have a high risk.

[0060] For accounts determined to be high-risk, the system immediately notifies the security management department of the e-commerce platform. The notification content includes the detailed abnormal information of the account, such as the details of abnormal purchase records, the details of abnormal user information, and the details of abnormal logistics information, as well as the risk probability value predicted by the model.

[0061] For those skilled in the art, it is obvious that the present invention is not limited to the details of the above exemplary embodiments, and the present invention can be implemented in other specific forms without departing from the spirit or basic characteristics of the present invention. Therefore, from any point of view, the embodiments should be regarded as exemplary and non-limiting. The scope of the present invention is defined by the appended claims rather than the above description. Therefore, all changes falling within the meaning and scope of the equivalent elements of the claims are intended to be embraced by the present invention. Any reference signs in the claims should not be construed as limiting the claims involved.

Claims

1. A dynamic monitoring method for a security brain based on artificial intelligence, characterized in that, The method includes the following steps: Connect to the e-commerce platform, obtain the purchase records, user information, and logistics information of users, perform data cleaning, data sorting, and data association, and store them in a database; Use the Apriori algorithm to mine the potential associations between user purchase behaviors based on the purchase records of users. When it is found that the user's purchase behavior does not conform to their historical purchase preferences and there are associated purchases that match the characteristics of brushstroke orders, mark them as abnormal; use the time series analysis algorithm to monitor the abnormal fluctuations in the purchase frequency and purchase amount, judge whether there are malicious brushstroke order behaviors, and mark them as abnormal; integrate the purchase records marked as abnormal into the abnormal purchase record dataset; Perform feature engineering, adopt the One-Class SVM model, and by learning the normal login behavior patterns of users, when a new login behavior is detected to deviate from the learned normal pattern, it is determined as an abnormal login, forming an abnormal user information dataset; Use the clustering algorithm to cluster the logistics information of users; if the logistics information of a certain user shows an isolated clustering situation, it is determined that there is an abnormal use of the account, forming an abnormal logistics information dataset; Integrate the abnormal purchase record dataset, the abnormal user information dataset, and the abnormal logistics information dataset, input them into the random forest model, adjust the model parameters, perform model training and verification, and judge the risk status of the account according to the prediction results of the model; based on the risk status of the account, notify the e-commerce platform to process high-risk accounts.

2. The dynamic monitoring method of a security brain based on artificial intelligence according to claim 1, characterized in that: The purchase records include the purchase time, the category of purchased goods, the purchase frequency, the purchase amount, and the order status; the user information includes registration information and login information. The registration information includes the name, user ID, contact information, and registration address. The login information includes the login IP, login device, login time interval, and account activity. The account activity is analyzed based on the frequency of browsing goods and the frequency of participating in platform interactions; the logistics information includes the delivery address, logistics order number, logistics track update situation, and logistics delivery duration; The data cleaning means removing duplicate data and error data. The data sorting means sorting in chronological order. The data association means associating the purchase records, user information, and logistics information based on the user ID in the user information; and storing them in a database.

3. A dynamic monitoring method for a security brain based on artificial intelligence according to claim 1, characterized in that: For each user, organize their purchase records into a dataset form suitable for input to the Apriori algorithm. Code the categories of purchased goods for each purchase to form a transaction, and all transactions constitute the purchase behavior dataset of the user; according to the business characteristics and historical data situation of the e-commerce platform, set the support and confidence thresholds for the Apriori algorithm. The support reflects the frequency of occurrence of a certain commodity combination in all transactions, and the confidence indicates the probability of purchasing the subsequent commodity given that the previous commodity has been purchased; Scan the purchase behavior dataset starting from a single commodity, count the number of occurrences of each commodity code, and filter out the commodities that meet the support threshold to form a frequent item set; Generate item sets based on the frequent item set. The item set represents a combination of two commodities; Scan the purchase behavior data set again, count the number of occurrences of item sets, and filter out frequent item sets that meet the support threshold; Continue to generate higher-order frequent item sets until no new frequent item sets that meet the support threshold can be generated.

4. The dynamic monitoring method of a security brain based on artificial intelligence according to claim 3, characterized in that: Generate association rules based on the generated frequent item sets; analyze the user's historical purchase preferences based on the association rules and the user's historical purchase records, count the combinations of product categories that the user frequently purchases, and the associations between the product category combinations; compare the user's current purchase behavior with the historical purchase preferences, and mark it as abnormal when it is found that the user has associated purchases that are consistent with the characteristics of fake order behavior, and the purchase behavior does not conform to his historical purchase preferences.

5. A dynamic monitoring method for a security brain based on artificial intelligence according to claim 1, characterized in that: The time series analysis algorithm adopts the ARIMA model and uses historical purchase data to train the selected time series model. During the training process, the model parameters are continuously adjusted to enable the model to fit the changing trend of historical data. The trained time series model is used to predict the purchase frequency and purchase amount in the future. Based on the model prediction results, the standard deviation of the predicted value is calculated, and data exceeding the mean ±g times the standard deviation is regarded as abnormal data, where g is determined according to the business risk preference. Compare the actual purchase frequency and purchase amount data with the predicted values. When the actual data exceeds the set abnormal threshold range and shows typical characteristics of malicious order-brushing behavior, the data point is determined to be abnormal. The purchase records marked as abnormal are integrated into the purchase record abnormality dataset.

6. The dynamic monitoring method of a security brain based on artificial intelligence according to claim 1, characterized in that: Determine the key features for training the One-Class SVM model, including the specific location of login, the type number of the login device, and the time pattern of login. Based on the login IP, convert the IP address into longitude and latitude to obtain the specific location of login. Based on the login device, assign different numbers to mobile phones and computers of different brands and models to obtain the type number of login devices. Based on the login time interval, divide a day into multiple time periods, count the number of logins of each user in each time period, and obtain the time pattern of login. Remove the login IP, login device, and login time interval from the user information, and combine the key features with the processed user information to obtain feature-engineered data. Initialize the One-Class SVM model, and use the feature-engineered data to train the model. During the training process, the model learns the user's normal login behavior pattern. Each time the user logs in to the e-commerce platform, the login information is collected, and the new login information is converted into feature-engineered data to obtain a new feature vector. Use the trained One-Class SVM model to determine whether the new feature vector is normal, and mark it when it is determined to be an abnormal login, thereby forming a user information abnormality data set.

7. A dynamic monitoring method for a security brain based on artificial intelligence according to claim 1, characterized in that: The clustering algorithm uses the K-Means clustering algorithm, uses the elbow method to determine the K value, and calculates the clustering error sum of squares SSE under different K values. The formula is: ; Among them, represents the i-th cluster, is the centroid of the i-th cluster, and x is the data point within the cluster; by plotting the relationship between SSE and the value of K, find the inflection point of the curve and take the inflection point as the value of K; randomly select K data points as the initial centroids; For each logistics information data point, use the Euclidean distance to calculate its distance from the K centroids; after all data points are assigned to corresponding clusters, recalculate the centroid of each cluster; the centroid is calculated by the mean of all data points in the cluster. For a cluster containing multiple logistics information data points, the value of each dimension of its centroid is the average value of all data points in the cluster on the corresponding dimension, where each dimension of the centroid is the dimension corresponding to the logistics delivery time; repeat the steps of calculating the distance and updating the centroid until the centroid no longer changes or the preset maximum number of iterations is reached; After obtaining the clustering results, check the situation of each cluster; when the number of data points in a cluster is less than the set threshold, and the difference between the delivery address and the addresses in other clusters exceeds the set threshold and the logistics delivery time deviates from the mean of other clusters, the cluster is judged as an isolated cluster; the data points belonging to the isolated cluster are extracted to form a logistics information anomaly data set.

8. A dynamic monitoring method for a security brain based on artificial intelligence according to claim 1, characterized in that: The purchase record abnormal data set, user information abnormal data set and logistics information abnormal data set are integrated to determine the adjustment range of parameters; a grid search method is used to conduct a comprehensive search within the set parameter range, all possible parameter combinations are tried through grid search, and the performance of each combination is evaluated using cross-validation; the integrated data set is divided into a training set and a validation set according to the proportion; Use the training set data to train the random forest model with adjusted parameters. During the training process, the random forest model constructs multiple decision trees, each of which is trained based on a random subset of the training data and a feature subset. The majority voting method is used to synthesize the prediction results of the decision trees to obtain the final prediction result. To determine whether the account has been maliciously placed or stolen, each decision tree can give a prediction result. The random forest model combines the results of all decision trees to reach a final judgment.

9. The method for dynamically monitoring a security brain based on artificial intelligence according to claim 8, wherein: Based on the risk status of the account, identify high-risk accounts and summarize user information of the high-risk accounts; Send the user information of the high-risk account to the security management department of the e-commerce platform in the form of an early warning notification, and establish a real-time communication mechanism with the security management department; After the security management department receives and confirms the notification, it will freeze the transaction function of the high-risk account and restrict the login of the high-risk account; send an account abnormality notification to the account owner through the contact information provided by the user when registering; guide the user to cooperate with the platform's investigation and handling work in the notification, and require the user to perform identity authentication.

10. A dynamic monitoring system for a security brain based on artificial intelligence, which uses a dynamic monitoring method for a security brain based on artificial intelligence according to any one of claims 1-9, characterized in that, include: Data collection and preprocessing module: including: data collection unit and data preprocessing unit; wherein the data collection unit connects to the e-commerce platform to obtain the user's purchase record, user information and logistics information, and the data preprocessing unit performs data cleaning, data sorting and data association, and stores the data in the database; Purchase record analysis module: association rule mining unit, time series analysis unit, and abnormal purchase record integration unit; the association rule mining unit uses the Apriori algorithm to mine potential associations between user purchase behaviors based on the user's purchase records. When it is found that the user's purchase behavior does not conform to their historical purchase preferences and there are associated purchases that match the characteristics of brush sales behavior, it is marked as abnormal; the time series analysis unit uses time series analysis algorithms to monitor abnormal fluctuations in purchase frequency and purchase amount to determine whether there is malicious brush sales behavior and marks it as abnormal; the abnormal purchase record integration unit integrates the purchase records marked as abnormal into the purchase record abnormal data set; User information analysis module: including: One-Class SVM training and detection unit and abnormal user information integration unit; the One-Class SVM training and detection unit performs feature engineering and uses the One-Class SVM model. By learning the normal login behavior pattern of users, when a new login behavior is detected to deviate from the learned normal pattern, it is determined as an abnormal login, and the abnormal user information integration unit forms the user information abnormal data set; Logistics information analysis module: including: clustering algorithm processing unit and abnormal logistics information integration unit; among them, the clustering algorithm processing unit uses clustering algorithms to cluster the user's logistics information; if the logistics information of a certain user shows an isolated clustering situation, it is determined that there is an abnormal use of the account, and the abnormal logistics information integration unit forms the logistics information abnormal data set; Security brain analysis and processing module: including: data set integration unit, random forest model training and verification unit, security brain analysis unit, and security brain processing unit; among them, the data set integration unit integrates the purchase record abnormal data set, user information abnormal data set, and logistics information abnormal data set. The random forest model training and verification unit inputs the integrated data set into the random forest model, adjusts the model parameters, and performs model training and verification. The security brain analysis unit judges the risk status of the account according to the prediction results of the model; the security brain processing unit notifies the e-commerce platform to process high-risk accounts based on the risk status of the account.