Risk assessment method and device, computing equipment, readable storage medium and product

By obtaining user behavior data and using risk analysis models for semantic reasoning and evaluation, and generating risk assessment results, the problem of insufficient identification of traditional risk control systems in complex risk scenarios is solved, flexible judgment and timely prevention and control of risks are achieved, and the flexibility and accuracy of risk assessment are improved.

CN120297739APending Publication Date: 2025-07-11ZHEJIANG E COMMERCE BANK CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510432337.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-07
Publication Date
2025-07-11

AI Technical Summary

Technical Problem

When traditional risk control systems face complex risk scenarios, the update speed of rules is difficult to keep up with the pace of risk evolution, resulting in insufficient risk identification capabilities and the inability to prevent and control malicious prize swipes and automated cheating in a timely manner, affecting project fairness and causing resource waste.

Method used

By obtaining user behavior data of the target project, using the risk analysis model to perform semantic inference, determining risk behavior patterns, and conducting risk assessment based on the model, generating risk assessment results, and combining with the big model Agent platform to automatically generate update rules and implement risk control strategies.

Benefits of technology

In-depth risk analysis and judgment of complex scenarios has been achieved, the flexibility, accuracy and efficiency of risk assessment have been enhanced, risks can be prevented and controlled in a timely manner, and system safety and project fairness have been improved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120297739A_ABST
    Figure CN120297739A_ABST
Patent Text Reader

Abstract

Embodiments of the invention provide a risk assessment method and apparatus, a computing device, a readable storage medium and a product. The method comprises the steps of obtaining user behavior data of a target project; and performing semantic reasoning on the user behavior data based on the project rule of the target project by using the risk analysis model, determining risk behavior data, extracting a risk behavior mode corresponding to the risk behavior data, performing risk assessment on the risk behavior data based on the risk behavior mode, and obtaining a risk assessment result. The semantic analysis and logical reasoning capabilities of the risk analysis model are utilized to deeply mine potential risks in the user behavior data, the risk behavior mode corresponding to the risk behavior data is extracted, and risk assessment is performed on the risk behavior data based on the risk behavior mode. According to the invention, deep risk research and judgment of a complex scene can be realized based on the extracted deep behavior characteristics, so that flexible judgment and timely prevention and control of the risk are realized, and the flexibility, accuracy and efficiency of risk assessment are enhanced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments of this specification relate to the technical field of information technology, and in particular, to a risk assessment method, apparatus, computing device, readable storage medium, and product. Background Art

[0002] In the digital project ecosystem, as the project scale expands and technology continues to evolve, risk prevention and control issues are becoming increasingly prominent, and project risk prevention and control faces severe challenges. A large number of risky behaviors, such as malicious award-brushing and automated cheating, frequently occur, seriously undermining the fairness of project activities, easily leading to ineffective consumption of resources, and even causing serious economic losses.

[0003] At present, traditional risk control systems often rely on manually maintained rule bases to deal with these complex risk scenarios. However, in a rapidly changing project environment, the speed of rule updates cannot keep up with the pace of risk evolution, resulting in the traditional risk control system's insufficient ability to identify new risk behaviors and can only identify risks based on fixed rules, making it difficult to make more flexible and timely judgments on risks. Therefore, a more efficient risk assessment method is urgently needed to achieve timely protection against risk control issues. Summary of the invention

[0004] In view of this, an embodiment of this specification provides a risk assessment method. One or more embodiments of this specification also relate to a risk assessment device, a computing device, a computer-readable storage medium and a computer program product to solve the technical defects existing in the prior art.

[0005] According to a first aspect of an embodiment of this specification, a risk assessment method is provided, comprising: Obtain user behavior data for the target project; Utilize the risk analysis model, perform semantic reasoning on user behavior data based on the project rules of the target project, determine the risk behavior data, and extract the risk behavior pattern corresponding to the risk behavior data. Based on the risk behavior pattern, perform risk assessment on the risk behavior data to obtain the risk assessment result.

[0006] According to a second aspect of an embodiment of this specification, a risk assessment device is provided, comprising: A data collection module, configured to obtain user behavior data of a target project; A model analysis module is configured to utilize the risk analysis model to perform semantic reasoning on the user behavior data based on the project rules of the target project, determine the risk behavior data, and extract the risk behavior pattern corresponding to the risk behavior data; The risk warning module is configured to utilize the risk analysis model to perform risk assessment on the risk behavior data based on the risk behavior pattern to obtain a risk assessment result.

[0007] According to a third aspect of an embodiment of this specification, a computing device is provided, including: Memory and processor; The memory is used to store computer executable instructions, and the processor is used to execute the computer executable instructions. When the computer executable instructions are executed by the processor, the steps of the above-mentioned risk assessment method are implemented.

[0008] According to a fourth aspect of the embodiments of this specification, a computer-readable storage medium is provided, which stores computer-executable instructions, and when the instructions are executed by a processor, the steps of the above-mentioned risk assessment method are implemented.

[0009] According to a fifth aspect of the embodiments of this specification, a computer program product is provided, including a computer program / instruction, which implements the steps of the above-mentioned risk assessment method when executed by a processor.

[0010] One embodiment of the present specification realizes obtaining user behavior data of a target project; using a risk analysis model, based on the project rules of the target project, semantic reasoning is performed on the user behavior data, risk behavior data is determined, and risk behavior patterns corresponding to the risk behavior data are extracted; based on the risk behavior patterns, risk assessment is performed on the risk behavior data to obtain risk assessment results. By obtaining user behavior data of the target project, the semantic analysis and logical reasoning capabilities of the risk analysis model can be used to deeply explore potential risks in user behavior data; by extracting risk behavior patterns corresponding to risk behavior data, risk assessment is performed on risk behavior data based on risk behavior patterns, and in-depth risk assessment of complex scenarios can be achieved based on the extracted deep behavioral features, thereby achieving flexible judgment and timely prevention and control of risks, and enhancing the flexibility, accuracy and efficiency of risk assessment. BRIEF DESCRIPTION OF THE DRAWINGS

[0011] Figure 1 is a flow chart of a risk assessment method provided by an embodiment of this specification; Figure 2 is a process flow chart of a risk assessment method applied to digital marketing provided by an embodiment of this specification; Figure 3 It is a schematic diagram of the structure of a risk assessment device provided by an embodiment of this specification; Figure 4 It is a structural function diagram of a risk assessment device provided by an embodiment of this specification; Figure 5 It is a structural block diagram of a computing device provided by an embodiment of this specification. DETAILED DESCRIPTION

[0012] In the following description, numerous specific details are set forth in order to provide a thorough understanding of this specification. However, this specification can be implemented in many other ways different from those described herein, and those skilled in the art can make similar generalizations without departing from the connotation of this specification. Therefore, this specification is not limited by the specific implementations disclosed below.

[0013] The terms used in one or more embodiments of this specification are for the purpose of describing specific embodiments only and are not intended to limit one or more embodiments of this specification. The singular forms "a", "the", and "said" used in one or more embodiments of this specification and the appended claims are also intended to include the plural forms unless the context clearly dictates otherwise. It should also be understood that the term "and / or" used in one or more embodiments of this specification refers to and encompasses any and all possible combinations of one or more of the associated listed items.

[0014] It should be understood that although the terms first, second, etc. may be used in one or more embodiments of this specification to describe various information, such information should not be limited to these terms. These terms are only used to distinguish the same type of information from each other. For example, without departing from the scope of one or more embodiments of this specification, the first may also be referred to as the second, and similarly, the second may also be referred to as the first. Depending on the context, the word "if" as used herein may be interpreted as "when" or "while" or "in response to determining".

[0015] In addition, it should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in one or more embodiments of this specification are all information and data that have been authorized by the user or fully authorized by all parties, and the collection, use, and processing of the relevant data need to comply with the relevant laws, regulations, and standards of the relevant countries and regions, and corresponding operation entrances are provided for the user to select authorization or rejection.

[0016] First, the noun terms involved in one or more embodiments of this specification are explained.

[0017] Large Language Model (LLM for short): Also known as a large model, a large-scale neural network model trained by deep learning algorithms, with powerful natural language understanding and generation capabilities, capable of handling complex text parsing and information extraction tasks.

[0018] Large model Agent: Refers to an intelligent system built based on large language models (such as GPT, BERT, etc.), with logical reasoning, natural language understanding, and generation capabilities, used for analyzing, making decisions, and executing tasks.

[0019] Global data of marketing activities: It refers to all user participation data, channel information, records of activity configuration changes, etc. related to marketing activities, covering the entire life cycle of marketing activities.

[0020] Activity configuration change: In an enterprise's digital marketing activities or e-commerce activities, there are corresponding activity rules and parameter settings, such as activity time, activity threshold, participation conditions, award-giving rules, etc. Activity configuration change can be understood as an action where the activity rules change from strict restrictions to loose conditions (such as canceling population restrictions and frequency restrictions).

[0021] High-frequency click / automatic click: It is an abnormal user behavior, which may be an unnatural click operation implemented by an automated script (such as a robot).

[0022] Process Hook: It is a technical means used to monitor or tamper with the behavior of an application during runtime, and may be maliciously used to bypass security policies.

[0023] Security interface: It can be understood as a set of basic security protection capabilities, which can implement functions such as intercepting specified users, specified IPs, or specified marketing activity requests, and triggering secondary verification.

[0024] In this specification, a risk assessment method is provided. This specification also relates to a risk assessment device, a computing device, a computer-readable storage medium, and a computer program product, which will be described in detail one by one in the following embodiments.

[0025] See Figure 1 , Figure 1 which shows a flowchart of a risk assessment method provided according to an embodiment of this specification, specifically including the following steps.

[0026] Step 102: Obtain user behavior data of the target project.

[0027] The embodiments of this specification are applied to applications, websites, or system platforms with risk assessment capabilities. For example, the background system of an e-commerce platform for managing promotions and marketing activities, or for another example, the risk assessment module integrated in an Enterprise Resource Planning (ERP) system, which supports risk analysis of internal process changes in an enterprise. Still for another example, a digital marketing service platform for optimizing online marketing and advertising placement strategies.

[0028] The target project is a specific project for a particular organization, including a set of activity rules with clear goals, scopes, and time frames. The target project contains activity rules with a series of predefined operation logics and parameters, which are used to guide the execution process of the project. The activity rules can be configured in code form to ensure that the project is automatically executed according to the predetermined plan. For example, enterprise management projects, platform marketing projects, etc.

[0029] Optionally, the target project can provide users with multiple project participation channels and support multiple different types of devices.

[0030] Currently, during the online operation of the target project, there are easily a large number of risk behaviors such as malicious prize brushing and automated cheating. These risk behaviors not only affect the fairness of the project but may also lead to resource waste and economic losses. Traditional risk control systems usually rely on manual maintenance of the rule library, with lagging rule updates and inflexible risk identification, unable to achieve in-depth risk judgment. Therefore, the identification effect of potential risks in complex scenarios is not good, and there is a lack of real-time response ability to risks, unable to conduct risk prevention and control in a timely manner.

[0031] Specifically, user behavior data can be understood as the data set generated by the interaction between users and various links of the project during the development of the target project, which can comprehensively record information such as the user's behavior trajectory, participation channels, the environment where the user is located, and relevant backgrounds in the project. Exemplarily, in the case where the target project is a digital marketing activity project, the user behavior data can be understood as the global data of the digital marketing activity.

[0032] In an optional embodiment of this specification, obtaining the user behavior data of the target project may include: Obtaining the original user behavior data of the target project; Performing data cleaning on the original user behavior data to obtain the user behavior data.

[0033] Optionally, the tagging code can be embedded in relevant application programs of the target project (such as websites, mobile apps), and various user operation behaviors, such as clicks, browsing, swiping, input, etc., can be captured through the tagging code. For example, in an e-commerce website, when a user clicks on a product link, adds an item to the cart, submits an order, etc., the tagging code will record these behaviors in a timely manner and send the relevant data to the data collection server. Log files can also be generated to record the detailed information of the user's interaction with the system. These logs can include the user's login information, accessed pages, executed operations, system errors, etc. By monitoring the log files in real time and extracting relevant user behavior data from them, real-time tracking of user behavior can be achieved. For example, server logs can record information such as the request time, requested URL, request parameters, IP, device model, etc. of each user, so as to understand the user's access path and operation process. Raw user behavior data can also be obtained through database monitoring, third-party data analysis tools, message queues, etc.

[0034] Furthermore, the raw user behavior data can be cleaned to obtain user behavior data. The data cleaning process may involve processing operations such as missing value handling, outlier handling, duplicate value handling, data format standardization, and data consistency checking.

[0035] Optionally, the user behavior data can include at least one of user participation information in the target project, project channel information, and project configuration change information of the target project.

[0036] Specifically, the user participation information can include various operation information of the user in the project, device hardware information used by the user, network-related information, etc. These data can reflect the user's direct participation in the project.

[0037] Exemplarily, the various operation information can include timestamps, sequences, and specific operation details of behaviors such as user login, page browsing, button clicking, task completion, etc.; the device hardware information can include device model, operating system, screen resolution, etc.; the network-related information can include IP address, network access method, etc.

[0038] The project channel information can reflect the source channels through which users enter the target project. Specifically, it can include the names of promotion channels (such as social media platform names, search engine names, mobile app names, etc.), promotion link characteristics, affiliated promotion activity identifiers, etc.; the project channel information can also be used to analyze the impact of different channels on user participation in the project. Specifically, it can include traffic data brought by different channels, such as channel access volume, page stay duration, bounce rate, etc.

[0039] Project configuration change information is used to record adjustments to activity rules, function settings, etc. during the project operation process. For example, it can include changes to the probability of winning a prize in a project activity, changes to task reward rules, adjustments to activity participation thresholds (such as user level requirements, spending amount limits), and system backend operations on page layout, enabling or disabling function modules, etc., which can reflect the dynamic changes in the project's own rules and settings.

[0040] By applying this embodiment, user participation information, project channel information and project configuration change information can provide a data basis for risk analysis, thereby enabling real-time risk assessment and risk control response to be achieved in the future.

[0041] Step 104: Using the risk analysis model, based on the project rules of the target project, semantic reasoning is performed on the user behavior data to determine the risk behavior data, and the risk behavior pattern corresponding to the risk behavior data is extracted. Based on the risk behavior pattern, risk assessment is performed on the risk behavior data to obtain a risk assessment result.

[0042] In actual applications, based on the project rules of the target project, risk identification can be performed on any one of the user participation information, project channel information, and project configuration change information; risk identification can also be performed on the correlation between any at least two of the user participation information, project channel information, and project configuration change information, thereby determining risk behavior data.

[0043] Specifically, the risk analysis model can be understood as a pre-trained large model with powerful semantic analysis, contextual reasoning and knowledge generalization capabilities. It can conduct in-depth analysis of complex input data and mine potential risk information.

[0044] The project rules of the target project may include various types of rules such as risk control rules, alarm rules, activity rules, etc. for the target project. It can also be understood as a rule set composed of multiple rules, which is mainly used to guide the analysis of user behavior data and can regulate the security and fairness of the project.

[0045] For example, the project rules for a digital marketing campaign may include: 1. This event is open to a specific user group. Invited users can participate in the event on the designated page and complete relevant operations on the page to receive rewards.

[0046] 2. The user needs to follow the instructions on the page, select "Transfer in" or "Transfer resource quota", and complete the transfer of resource quota from other accounts to the specified account according to the prompts. After successful completion, there will be a chance to receive corresponding rewards. Please note that only resource quota transfers completed through the above specified process are eligible for rewards.

[0047] 3. Each time a certain amount of resources is successfully transferred, one reward will be obtained. Specifically, one reward will be obtained for each two units of resources transferred, and the maximum cumulative reward can be five. For example, if two units of resources are transferred, one reward will be obtained; if ten units of resources are transferred, a total of five rewards will be obtained.

[0048] 4. This activity starts on December 11, 2024 and ends on December 31, 2024.

[0049] Specifically, risk behavior data can be understood as information that is risky or has potential risks that is inferred and identified by the risk analysis model from user behavior data. The risk assessment results can include the description of the risk content, probability of occurrence, risk level, possible impact, and executable strategies.

[0050] Risk behavior patterns can be understood as a combination of features extracted from risk behavior data that can reflect the essential characteristics of risk behavior. They are composed of deep features extracted by a large model after in-depth analysis of risk behavior data, such as a collection of multi-dimensional features such as the frequency of user operations, operation time distribution, and operation path rules. These features are combined to form a specific pattern that is used to characterize behaviors with similar risk characteristics.

[0051] Furthermore, based on the risk assessment results, warning information can be generated, which can include risk content description, risk probability, risk level, impact scope and other information corresponding to the risk assessment results, and can also include risk control strategies corresponding to the risk assessment results.

[0052] One embodiment of the present specification realizes obtaining user behavior data of a target project; using a risk analysis model, based on the project rules of the target project, semantic reasoning is performed on the user behavior data, risk behavior data is determined, and risk behavior patterns corresponding to the risk behavior data are extracted; based on the risk behavior patterns, risk assessment is performed on the risk behavior data to obtain risk assessment results. By obtaining user behavior data of the target project, the semantic analysis and logical reasoning capabilities of the risk analysis model can be used to deeply explore potential risks in user behavior data; by extracting risk behavior patterns corresponding to risk behavior data, risk assessment is performed on risk behavior data based on risk behavior patterns, and in-depth risk assessment of complex scenarios can be achieved based on the extracted deep behavioral features, thereby achieving flexible judgment and timely prevention and control of risks, and enhancing the flexibility, accuracy and efficiency of risk assessment.

[0053] In an optional embodiment of the present specification, based on the project rules of the target project, semantic reasoning is performed on the user behavior data to determine the risk behavior data, and the risk behavior pattern corresponding to the risk behavior data is extracted, which may include: Based on the project rules of the target project, perform context semantic reasoning on the user behavior data to determine the risk behavior data; Extract at least one behavior feature from the risk behavior data to obtain a risk behavior pattern composed of at least one behavior feature.

[0054] In practical applications, the large model Agent platform can utilize the risk analysis model to perform semantic reasoning on the user behavior data based on the project rules of the target project, determine the risk behavior data, extract the corresponding risk behavior pattern of the risk behavior data, and perform risk assessment on the risk behavior data based on the risk behavior pattern to obtain the risk assessment result.

[0055] Optionally, the project rules of the target project can include rules manually formulated by operation and maintenance personnel, or can include rules automatically generated by the risk analysis model retrieving the case library based on existing cases. Further, the rules automatically generated by the risk analysis model can be sent by the large model Agent platform to the front end of the operation and maintenance personnel. After being adjusted and confirmed by the operation and maintenance personnel, the adjusted rules are then fed back by the front end of the operation and maintenance personnel to the large model Agent platform, so as to add the adjusted rules to the project rules of the target project.

[0056] Optionally, the risk analysis model can perform context semantic reasoning on the user behavior data based on the project rules of the target project to determine the risk behavior data.

[0057] Further, performing context semantic reasoning on the user behavior data can include data encoding, context injection, and semantic analysis reasoning. Among them, data encoding can include: converting the preprocessed user behavior data (including user participation information, project channel information, and configuration change information) into a vector representation form that the risk analysis model can understand. For text-type data, such as channel names, operation descriptions, etc., word embedding techniques, such as Word2Vec, GloVe, etc., are used to convert each word into a vector of a fixed dimension. For numerical-type data, such as operation time, operation frequency, etc., after normalization processing, it is directly converted into the corresponding dimension of the vector. The vectors of different types of data are concatenated to form a complete vector representation of the user behavior data.

[0058] Context injection can include: inputting the project rules of the target project as static context information into the risk analysis model. The project rules can be stored in the database in a structured form and read and converted into a format that the model can process during reasoning. For example, project activity rules are represented as a set of logical expressions. At the same time, real-time dynamic context information, such as the current time, the latest configuration change situation, etc., is input into the model together with the user behavior data vector. The model can utilize this context information to better understand the semantics and underlying logical relationships of the user behavior data.

[0059] Semantic analysis and reasoning may include: The risk analysis model is based on a deep learning architecture, such as the Transformer model, and uses its internal neural network layers to process the input user behavior data vector and context information. Through multiple layers of attention mechanisms, the model can focus on different parts of the data and capture the semantic associations and logical relationships between the data. For example, the model will analyze the relationship between the user operation frequency and the operation frequency allowed in the item rules to determine whether the user behavior exceeds the normal range. At the same time, the model will also combine historical data and existing risk knowledge to reason about the user behavior and determine whether there are potential risk behaviors. If the model finds that the user has performed a large number of operations beyond the normal range through the same device in a short period of time, and these operations are similar to the known automated script operation patterns, it will initially determine that there is a risk in the user behavior.

[0060] In practical applications, through semantic analysis and reasoning of the context, potential risk behaviors such as high-frequency clicks / auto-clicks and process Hooks can be identified.

[0061] Specifically, the behavior characteristics can be understood as the deep-level characteristics extracted from the risk behavior data by the risk analysis model through context semantic analysis and logical reasoning. The behavior characteristics can include one or more, and these behavior characteristics together form the risk behavior pattern corresponding to the risk behavior data.

[0062] Optionally, the risk analysis model can extract deep-level characteristics from the risk behavior data determined by semantic reasoning, which can include composite characteristics, temporal characteristics, rule association characteristics, etc. For composite characteristics, the model comprehensively analyzes and calculates data from multiple dimensions such as user operation frequency, device usage, and behavior path. Exemplarily, calculate the operation frequency of the user within a period of time, and combine factors such as whether the device is frequently used by multiple accounts and whether the behavior path shows regularity to extract composite characteristics reflecting the risk of automated script operations. For temporal characteristics, the model uses a recurrent neural network (RNN) or its variants, such as long short-term memory network (LSTM), gated recurrent unit (GRU), to process the time series data of user behavior and extract characteristics such as the distribution law of operation time and the standard deviation of task completion time. For rule association characteristics, the model analyzes the temporal relationship between user behavior and project rule changes, the degree of compliance of user behavior with new rules, etc., and extracts relevant characteristics.

[0063] Furthermore, the extracted behavior characteristics can be processed through feature screening and dimensionality reduction to obtain the risk behavior pattern.

[0064] Applying this embodiment, by performing context semantic reasoning on user behavior data based on the project rules of the target project to determine risk behavior data, potential risks in complex scenarios can be identified through context semantic reasoning, combined with multi-dimensional information such as activity rules and user behavior; by extracting at least one behavior feature from the risk behavior data to obtain a risk behavior pattern composed of at least one behavior feature, the deep behavior features in the risk behavior data can be extracted, so as to comprehensively cover risk behaviors, flexibly identify new risks, and achieve in-depth risk judgment.

[0065] In an optional embodiment of this specification, based on the risk behavior pattern, risk assessment is performed on the risk behavior data to obtain a risk assessment result, which may include: Based on the risk behavior pattern, retrieve a reference risk behavior pattern similar to the risk behavior pattern; Using the reference risk behavior pattern as an evaluation reference, perform risk assessment on the risk behavior data to obtain a risk assessment result.

[0066] Specifically, the reference risk behavior pattern refers to a risk behavior pattern that already exists in historical data and is similar in characteristics to the current risk behavior pattern to be evaluated. The reference risk behavior pattern usually has been analyzed and evaluated and has known risk assessment results, including information such as risk level, risk cause, and scope of influence. The reference risk behavior pattern can be used as a reference standard for evaluating the current risk behavior data.

[0067] The risk assessment result can be understood as a series of conclusive information obtained after evaluating the risk behavior data, which may include a risk level, used to quantify the severity of the risk, usually described by numbers or levels, such as high, medium, and low risks; a risk cause, that is, the specific factors leading to the risk, such as rule bypassing, malicious attacks, etc.; a risk description, which details the specific manifestations and characteristics of the risk behavior; and a scope of influence, indicating the project areas, user groups, or system modules that the risk may affect.

[0068] Optionally, the similarity between each behavior feature vector in the risk behavior pattern and each behavior feature vector in the historical risk behavior pattern can be calculated by means such as cosine similarity and Euclidean distance.

[0069] Furthermore, according to the similarity calculation result, a first similarity threshold can be set, or directly preset by the operation and maintenance personnel. Screen out the historical risk behavior patterns with a similarity higher than the first similarity threshold as the reference risk behavior patterns. For example, if the first similarity threshold is set to 0.8, then the historical risk behavior patterns with a similarity greater than 0.8 will be selected.

[0070] Applying this embodiment, by retrieving a reference risk behavior pattern similar to the risk behavior pattern, historical experience can be fully utilized to improve the accuracy and reliability of risk assessment, and relevant risk assessment information can be quickly obtained to improve the assessment efficiency; through the comparative analysis of a large number of reference risk behavior patterns and the current risk behavior pattern, it is conducive to discovering the evolution law of risk behavior, and these laws can provide a basis for risk prediction to help enterprises take preventive measures in advance.

[0071] In an optional embodiment of this specification, after extracting the risk behavior pattern corresponding to the risk behavior data, it may further include: Based on the risk behavior pattern, generate an update item rule for the target project and add the update item rule to the item rule.

[0072] In practical applications, a case library can be constructed based on existing cases. The case library can record historical risk behavior data and the corresponding historical risk behavior patterns and item rules.

[0073] Optionally, a second similarity threshold can be set. When the similarity between the historical risk behavior pattern and the risk behavior pattern is not higher than the second similarity threshold, the risk analysis model can combine with the case library to automatically generate an update item rule for the target project based on the risk behavior pattern. The second similarity threshold can be the same as or different from the first similarity threshold.

[0074] Furthermore, the automatically generated update item rule can be sent by the large model Agent platform to the front end of the operation and maintenance personnel. After being adjusted and confirmed by the operation and maintenance personnel, the front end of the operation and maintenance personnel can then feedback the adjusted rule to the large model Agent platform, so as to add the adjusted rule to the item rule of the target project.

[0075] Applying this embodiment, by generating an update item rule for the target project based on the risk behavior pattern and adding the update item rule to the item rule, the self-learning ability of the large model Agent can be fully utilized to assist the operation and maintenance personnel in dynamically generating new rules, improving the rule update speed and avoiding rule lag, and being able to better adapt to the complex and changeable project environment.

[0076] In an optional embodiment of this specification, after performing a risk assessment on the risk behavior data based on the risk behavior pattern to obtain a risk assessment result, it may further include: Execute the corresponding risk control strategy based on the risk assessment result.

[0077] Specifically, the risk control strategy is a series of measures and methods formulated to deal with the identified potential risks, reduce the losses that the risks may bring, and ensure the normal operation of the target project.

[0078] Optionally, the risk control strategy can be customized according to factors such as the nature, level, and impact scope of the risk, aiming to control the risk within an acceptable range. The risk control strategy can be automatically generated by a risk analysis model based on the risk assessment results. The risk analysis model can retrieve the risk control strategy corresponding to the historical risk assessment results and use the retrieved results as enhanced guidance information to generate the risk control strategy corresponding to the risk assessment results.

[0079] Applying this embodiment, by executing the corresponding risk control strategy based on the risk assessment results, risks can be responded to in a timely manner, and appropriate risk control strategies can be selected according to the specific information in the risk assessment results, such as the risk cause, impact scope, etc., so as to more precisely handle the risks, improve the effect of risk control, reduce risk losses, maintain project continuity, and enhance reliability.

[0080] Optionally, the risk control strategy can include: generating and sending an alarm message to the front-end of the operation and maintenance personnel based on the risk assessment results; or it can also include: invoking a security interface to execute the risk control strategy.

[0081] In an optional embodiment of this specification, executing the corresponding risk control strategy based on the risk assessment results may include: Generating an alarm message based on the risk assessment results and sending the alarm message to the user.

[0082] Specifically, the alarm message is a kind of notification information, which can include risk description information, risk level, possible causes of the risk, impact scope, etc. in the risk assessment results. The user can specifically be the operation and maintenance personnel.

[0083] Optionally, the alarm message can be a text message, a pop-up notification, an email, etc.

[0084] Applying this embodiment, by generating an alarm message based on the risk assessment results and sending the alarm message to the user, potential risks can be timely informed to the operation and maintenance personnel, achieving the purpose of continuously monitoring and feedback on risks, and enhancing the effect of risk management and control.

[0085] In an optional embodiment of this specification, generating an alarm message based on the risk assessment results may include: In the case where the risk assessment results reach the preset risk level, generating an alarm message based on the risk level of the risk assessment results so that the user can perform project operation and maintenance operations corresponding to the risk level on the target project.

[0086] Specifically, the risk level can be divided into different levels such as low, medium, and high, and can be specifically set according to the requirements in actual applications.

[0087] Optionally, when the risk level reaches the preset risk level, the warning message may carry information indicating the corresponding project operation and maintenance operations for the operation and maintenance personnel, so as to manually intervene to solve problems with higher risks. The preset risk level can be specifically set according to the requirements in actual applications.

[0088] Exemplarily, the preset risk level can be a high risk level.

[0089] Specifically, the project operation and maintenance operations can be understood as a series of specific operation processes and measures for maintaining and managing the target project formulated for different risk levels. These operations are aimed at reducing the risk impact, restoring the normal operation state of the project or strengthening the risk resistance ability of the project through manual intervention. For example, it may be necessary to immediately suspend some project functions, perform emergency vulnerability repairs or activate the emergency response plan, etc.

[0090] Applying this embodiment, by generating a warning message based on the risk level of the risk assessment result when the risk assessment result reaches the preset risk level, it is possible to ensure that users can receive notifications in a timely manner when the risk reaches a certain severity through the preset risk level and the automatic trigger warning mechanism, greatly shortening the time difference between risk discovery and response. Users can effectively contain the further expansion of the risk and reduce the losses caused by the risk to the project by timely performing the project operation and maintenance operations corresponding to the risk level according to the warning message.

[0091] In an optional embodiment of this specification, based on the risk assessment result, executing the corresponding risk control strategy may include: Invoking a security interface to execute the risk control strategy corresponding to the risk assessment result, where the risk control strategy includes at least one of an abnormal request interception strategy, a verification code triggering strategy, and a face recognition verification strategy.

[0092] Specifically, the security interface can be understood as a set of program interfaces with basic security capabilities, which can realize functions such as intercepting specified users, specified IPs or specified project activity requests and triggering secondary verification. It is a key component for implementing security handling actions and provides the system with fine-grained security control capabilities.

[0093] The abnormal request interception strategy is a risk control measure that intercepts requests determined to be abnormal (such as requests from abnormal IP addresses, user requests that do not conform to normal project logic, etc.) through the security interface to prevent them from further execution to prevent potential risks from occurring.

[0094] The verification code triggering strategy is to trigger the verification code mechanism through the security interface, requiring users to enter the correct verification code to continue the operation. Thereby increasing the security of the operation and preventing malicious users from automating operations or illegal access.

[0095] The facial recognition verification strategy uses a security interface to initiate facial recognition technology for user authentication. Only users who pass the facial recognition verification can continue with relevant operations. It is applicable to scenarios with high security requirements and can effectively prevent others from misusing identities for operations.

[0096] Other risk control strategies can also be formulated according to the requirements in actual applications, or new risk control strategies can be automatically generated by a risk analysis model.

[0097] Furthermore, to reduce the disturbance to users participating in the project and avoid repeatedly executing the same risk control strategy, the execution conditions of the risk control strategy can also be combined. For example, in the case of initially identifying a potential risk, verification requests such as "slide the slider to verify", "click on the specified text", and "click on the specified graphics in sequence" can be sent to the user. If it is detected that the user subsequently triggers relevant risk operations, the trigger verification code strategy can be executed. If risks are continuously detected later, the facial recognition verification strategy can be executed. If risks are detected again later, all operations of the user can be intercepted.

[0098] Optionally, the security interface can be called programmatically, and the selected risk control strategy can be passed as a parameter to the security interface. For example, write code using a specific programming language (such as Python, Java, etc.) to call the functions or methods of the security interface and pass in relevant parameters, such as the request information to be intercepted, the type of trigger verification code, etc.

[0099] Furthermore, after receiving the call request and relevant parameters, the security interface performs corresponding operations according to the incoming risk control strategy. Exemplarily: If it is the intercept abnormal request strategy, the security interface checks the source and content of the request to determine whether it meets the interception conditions. If it does, the further processing of the request is blocked; if it is the trigger verification code strategy, the security interface generates a verification code and sends it to the user, waiting for the user to input the correct verification code; if it is the facial recognition verification strategy, the security interface calls the facial recognition system to collect and verify the user's facial information. After the security interface executes the risk control strategy, it can also feedback the execution result to the calling party (such as a risk assessment system) and record relevant operation logs for subsequent query and auditing. For example, record the intercepted request information, whether the verification code input by the user is correct, the result of the facial recognition verification, etc.

[0100] Applying this embodiment, by calling the security interface and executing the risk control strategy corresponding to the risk assessment result, automated protection can be achieved, real-time response to risk behaviors can be realized, thereby improving the system security and the fairness of project activities, and avoiding resource losses.

[0101] One embodiment of this specification realizes obtaining user behavior data of a target project; using a risk analysis model, based on the project rules of the target project, performing semantic reasoning on the user behavior data to determine risk behavior data, extracting the risk behavior patterns corresponding to the risk behavior data, and based on the risk behavior patterns, performing risk assessment on the risk behavior data to obtain a risk assessment result. By obtaining the user behavior data of the target project, the semantic analysis and logical reasoning capabilities of the risk analysis model can be utilized to deeply explore the potential risks in the user behavior data; by extracting the risk behavior patterns corresponding to the risk behavior data and performing risk assessment on the risk behavior data based on the risk behavior patterns, the deep risk judgment of complex scenarios can be realized based on the extracted deep behavior characteristics, and then the flexible judgment and timely prevention and control of risks can be realized, enhancing the flexibility, accuracy and efficiency of risk assessment.

[0102] The following combines the attached Figure 2 , taking the application of the risk assessment method provided in this specification in digital marketing activities as an example, further illustrates the risk assessment method. Among them, Figure 2 FIG. shows the processing procedure flowchart of a risk assessment method applied to digital marketing provided by an embodiment of this specification, which specifically includes the following steps.

[0103] Step 202: During the implementation of digital marketing activities, collect the global marketing activity data covering user participation data, channel information, and activity configuration change records.

[0104] Step 204: Based on the semantic analysis ability of the large model, according to the activity rules of the digital marketing activities, perform logical reasoning on the global marketing activity data to identify risk behavior data.

[0105] In this process, the large model Agent will deeply analyze the global marketing activity data. For example, by analyzing the activity configuration change data, it is judged whether the configuration threshold has an abnormal decrease; by monitoring the user participation data, it is found whether there is an abnormal situation of high-frequency participation, so as to explore potential risk behaviors.

[0106] Step 206: Extract the patterns of risk behaviors corresponding to the risk behavior data, and retrieve existing cases to obtain reference risk behavior patterns similar to the risk behavior patterns.

[0107] Step 208: Using the reference risk behavior pattern as an evaluation reference, perform risk assessment on the risk behavior data to obtain a risk assessment result, and based on the risk assessment result, generate an alarm message.

[0108] Step 210: Call the security interface to execute the risk control strategy corresponding to the risk assessment result.

[0109] Step 212: When generating updated activity rules using a large model based on risk behavior patterns, send the updated activity rules to the front end of the operation staff, receive the adjusted updated activity rules returned by the front end of the operation staff, and add the adjusted updated activity rules to the activity rules of the digital marketing activity.

[0110] Applying this embodiment, by collecting the global marketing activity data covering user participation data, channel information, and activity configuration change records, real-time global activity data can be obtained during the implementation of the marketing activity; by using the large model to perform logical reasoning on the global marketing activity data according to the activity rules of the digital marketing activity, the semantic analysis and context reasoning capabilities of the large model can be utilized to identify potential risk behaviors; by extracting the patterns of risk behaviors, deep behavior characteristics can be mined, thereby realizing in-depth judgment of risks; by invoking the security interface and executing the risk control strategy corresponding to the risk assessment result, real-time prevention and control of risks can be achieved, improving the security and fairness of the marketing activity. By generating updated activity rules corresponding to the risk behavior patterns using the large model, new rules can be automatically generated when there are no matching known cases for the risk behavior patterns, thereby improving the flexibility of rule generation and avoiding rule lag.

[0111] Corresponding to the above method embodiment, this specification also provides an embodiment of a risk assessment device. Figure 3 The structural schematic diagram of a risk assessment device provided by an embodiment of this specification is shown. As Figure 3 shown, the device includes: Data acquisition module 302: Configured to obtain the user behavior data of the target project.

[0112] Model analysis module 304: Configured to perform semantic reasoning on the user behavior data based on the project rules of the target project using a risk analysis model, determine the risk behavior data, and extract the risk behavior patterns corresponding to the risk behavior data.

[0113] Risk warning module 306: Configured to perform a risk assessment on the risk behavior data based on the risk behavior patterns using a risk analysis model to obtain a risk assessment result.

[0114] Optionally, the data acquisition module 302 is further configured to: Obtain at least one of the user participation information of the user participating in the target project, the project channel information, and the project configuration change information of the target project.

[0115] Optionally, the model analysis module 304 is further configured to: Perform context semantic reasoning on the user behavior data based on the project rules of the target project to determine the risk behavior data; At least one behavior feature is extracted from the risk behavior data to obtain a risk behavior pattern composed of the at least one behavior feature.

[0116] Optionally, the risk warning module 306 is further configured to: Based on the risk behavior pattern, a reference risk behavior pattern similar to the risk behavior pattern is retrieved; Using the reference risk behavior pattern as an assessment reference, risk assessment is performed on the risk behavior data to obtain risk assessment results.

[0117] Optionally, the device further comprises an emergency handling module configured to: Based on the risk assessment results, corresponding risk control strategies are implemented.

[0118] Optionally, the emergency handling module is further configured to: Generate an alert message based on the risk assessment result and send it to the user.

[0119] Optionally, the emergency handling module is further configured to: When the risk assessment result reaches a preset risk level, an alarm message is generated based on the risk level of the risk assessment result, so that the user can perform project operation and maintenance operations corresponding to the risk level on the target project.

[0120] Optionally, the emergency handling module is further configured to: The security interface is called to execute the risk control strategy corresponding to the risk assessment result, wherein the risk control strategy includes at least one of an abnormal request interception strategy, a verification code triggering strategy, and a facial recognition verification strategy.

[0121] By applying this embodiment, by acquiring user behavior data of the target project, the semantic analysis and logical reasoning capabilities of the risk analysis model can be utilized to deeply explore the potential risks in the user behavior data; by extracting the risk behavior patterns corresponding to the risk behavior data, and based on the risk behavior patterns, risk assessment is performed on the risk behavior data, and in-depth risk analysis of complex scenarios can be achieved based on the extracted deep behavioral features, thereby achieving flexible judgment and timely prevention and control of risks, thereby enhancing the flexibility, accuracy and efficiency of risk assessment.

[0122] The above is a schematic scheme of a risk assessment device of this embodiment. It should be noted that the technical scheme of the risk assessment device and the technical scheme of the risk assessment method described above are of the same concept, and the details of the technical scheme of the risk assessment device that are not described in detail can be found in the description of the technical scheme of the risk assessment method described above.

[0123] With the above Figure 3 The device embodiment corresponds to the following: Figure 4The following shows a structural and functional schematic diagram of a risk assessment device provided by an embodiment of this specification, as Figure 4 shown below: The data acquisition module, model analysis module, risk warning module, and emergency response module are the four main component modules of the large model Agent.

[0124] The function of the data acquisition module is to collect global marketing activity data covering user participation data, channel information, and activity configuration change records, and to transmit the global marketing activity data to the model analysis module in real time through a unified interface.

[0125] The function of the model analysis module is to perform logical reasoning on the global marketing activity data according to the activity rules of the digital marketing activity based on the semantic analysis ability of the large model, identify risk behavior data, extract the patterns of the risk behaviors corresponding to the risk behavior data, and retrieve existing cases to obtain reference risk behavior patterns similar to the risk behavior patterns.

[0126] The function of the risk warning module is to use the reference risk behavior pattern as an evaluation reference to perform a risk assessment on the risk behavior data to obtain a risk assessment result, and to generate a warning message based on the risk assessment result.

[0127] The function of the emergency response module is to call a security interface and execute the risk control strategy corresponding to the risk assessment result.

[0128] Each embodiment in this specification is described in a progressive manner. For the same or similar parts between each embodiment, reference can be made to each other. The key point of each embodiment is to illustrate the differences from other embodiments. In particular, for the risk assessment device, since it is basically similar to the embodiment of the risk assessment method, the description is relatively simple, and reference can be made to the corresponding part of the embodiment of the risk assessment method for relevant content.

[0129] Figure 5 The following shows a block diagram of the structure of a computing device 500 provided by an embodiment of this specification. The components of the computing device 500 include but are not limited to a memory 510 and a processor 520. The processor 520 is connected to the memory 510 through a bus 530, and a database 550 is used to store data.

[0130] The computing device 500 also includes an access device 540, which enables the computing device 500 to communicate via one or more networks 560. Examples of such networks include the Public Switched Telephone Network (PSTN), Local Area Network (LAN), Wide Area Network (WAN), Personal Area Network (PAN), or a combination of communication networks such as the Internet. The access device 540 may include one or more of any type of wired or wireless network interfaces (e.g., network interface controller (NIC)), such as IEEE 802.11 Wireless Local Area Network (WLAN) wireless interface, Worldwide Interoperability for Microwave Access (Wi-MAX) interface, Ethernet interface, Universal Serial Bus (USB) interface, cellular network interface, Bluetooth interface, Near Field Communication (NFC).

[0131] In one embodiment of the present specification, the above components of the computing device 500 and Figure 5 other components not shown therein may also be connected to each other, for example, via a bus. It should be understood that Figure 5 the block diagram of the computing device shown is for illustrative purposes only and is not a limitation on the scope of the present specification. Those skilled in the art may add or replace other components as needed.

[0132] The computing device 500 can be any type of stationary or mobile computing device, including mobile computers or mobile computing devices (e.g., tablet computers, personal digital assistants, laptop computers, notebook computers, netbooks, etc.), mobile phones (e.g., smartphones), wearable computing devices (e.g., smartwatches, smart glasses, etc.) or other types of mobile devices, or stationary computing devices such as desktop computers or personal computers (PCs). The computing device 500 can also be a mobile or stationary server.

[0133] Among them, the processor 520 is used to execute the following computer-executable instructions, which when executed by the processor implement the steps of the above risk assessment method.

[0134] The above is a schematic solution of a computing device according to this embodiment. It should be noted that the technical solution of this computing device and the technical solution of the above risk assessment method belong to the same concept. For the details not described in detail in the technical solution of the computing device, reference can be made to the description of the technical solution of the above risk assessment method.

[0135] An embodiment of this specification also provides a computer-readable storage medium, which stores computer-executable instructions. When the computer-executable instructions are executed by a processor, the steps of the above risk assessment method are implemented.

[0136] The above is a schematic solution of a computer-readable storage medium according to this embodiment. It should be noted that the technical solution of this storage medium and the technical solution of the above risk assessment method belong to the same concept. For the details not described in detail in the technical solution of the storage medium, reference can be made to the description of the technical solution of the above risk assessment method.

[0137] An embodiment of this specification also provides a computer program product, including a computer program / instructions. When the computer program / instructions are executed by a processor, the steps of the above risk assessment method are implemented.

[0138] The above is a schematic solution of a computer program product according to this embodiment. It should be noted that the technical solution of this computer program product and the technical solution of the above risk assessment method belong to the same concept. For the details not described in detail in the technical solution of the computer program product, reference can be made to the description of the technical solution of the above risk assessment method.

[0139] The above describes specific embodiments of this specification. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims may be performed in a different order than in the embodiments and still achieve the desired result. Additionally, the processes depicted in the figures do not necessarily require the particular order or sequential order shown to achieve the desired result. In certain implementations, multitasking and parallel processing are also possible or may be advantageous.

[0140] The computer instructions include computer program code, which may be in the form of source code, object code, executable files or some intermediate forms, etc. The computer-readable medium may include: any entity or device capable of carrying the computer program code, recording medium, USB flash drive, mobile hard disk, magnetic disk, optical disk, computer memory, read-only memory (ROM), random access memory (RAM), electrical carrier signal, telecommunication signal, and software distribution medium, etc. It should be noted that the content included in the computer-readable medium may be appropriately increased or decreased according to the requirements of patent practice. For example, in some regions, according to patent practice, the computer-readable medium does not include electrical carrier signals and telecommunication signals.

[0141] It should be noted that for the foregoing method embodiments, for the sake of simplicity of description, they are all expressed as a series of action combinations. However, those skilled in the art should know that the embodiments of this specification are not limited by the described action sequence, because according to the embodiments of this specification, some steps may be performed in other sequences or simultaneously. Secondly, those skilled in the art should also know that the embodiments described in the specification are all preferred embodiments, and the actions and modules involved are not necessarily essential to the embodiments of this specification.

[0142] In the above embodiments, the descriptions of each embodiment have their own emphases. For the parts not detailed in a certain embodiment, reference may be made to the relevant descriptions of other embodiments.

[0143] The preferred embodiments of this specification disclosed above are only used to help explain this specification. The optional embodiments do not describe all the details in detail, nor do they limit the invention to the specific embodiments described. Obviously, many modifications and changes can be made according to the content of the embodiments of this specification. These embodiments are selected and specifically described in this specification to better explain the principles and practical applications of the embodiments of this specification, so that those skilled in the art can understand and utilize this specification well. This specification is only limited by the claims and their full scope and equivalents.

Claims

1. A risk assessment method, comprising: Obtaining user behavior data of a target project; Using a risk analysis model, based on the project rules of the target project, performing semantic reasoning on the user behavior data to determine risk behavior data, and extracting a risk behavior pattern corresponding to the risk behavior data, and based on the risk behavior pattern, performing risk assessment on the risk behavior data to obtain a risk assessment result.

2. The method according to claim 1, wherein the performing semantic reasoning on the user behavior data based on the project rules of the target project to determine risk behavior data, and extracting a risk behavior pattern corresponding to the risk behavior data, comprises: Performing context semantic reasoning on the user behavior data based on the project rules of the target project to determine risk behavior data; Extracting at least one behavior feature from the risk behavior data to obtain the risk behavior pattern composed of the at least one behavior feature.

3. The method according to claim 1 or 2, wherein the user behavior data includes at least one of user participation information of the user in the target project, project channel information, and project configuration change information of the target project.

4. The method according to claim 1, wherein the performing risk assessment on the risk behavior data based on the risk behavior pattern to obtain a risk assessment result, comprises: Retrieving a reference risk behavior pattern similar to the risk behavior pattern based on the risk behavior pattern; Using the reference risk behavior pattern as an evaluation reference to perform risk assessment on the risk behavior data to obtain a risk assessment result.

5. The method according to claim 1, after extracting the risk behavior pattern corresponding to the risk behavior data, further comprises: Generating an updated project rule for the target project based on the risk behavior pattern, and adding the updated project rule to the project rules.

6. The method according to claim 1, after performing risk assessment on the risk behavior data based on the risk behavior pattern to obtain a risk assessment result, further comprises: Executing a corresponding risk control strategy based on the risk assessment result.

7. The method according to claim 6, wherein the executing a corresponding risk control strategy based on the risk assessment result, comprises: Generating an alarm message based on the risk assessment result and sending the alarm message to the user.

8. The method according to claim 7, wherein the generating an alarm message based on the risk assessment result, comprises: In the case where the risk assessment result reaches a preset risk level, generating an alarm message based on the risk level of the risk assessment result, so that the user performs project operation and maintenance operations corresponding to the risk level on the target project.

9. The method according to claim 6 or 7, wherein the executing a corresponding risk control strategy based on the risk assessment result, comprises: Invoking a security interface to execute the risk control strategy corresponding to the risk assessment result, wherein the risk control strategy includes at least one of an abnormal request interception strategy, a verification code trigger strategy, and a face recognition verification strategy.

10. A risk assessment device, comprising: A data acquisition module, configured to obtain user behavior data of a target project; A model analysis module, configured to use a risk analysis model to perform semantic reasoning on the user behavior data based on the project rules of the target project, determine risk behavior data, and extract a risk behavior pattern corresponding to the risk behavior data; A risk warning module, configured to use a risk analysis model to perform a risk assessment on the risk behavior data based on the risk behavior pattern, and obtain a risk assessment result.

11. The apparatus according to claim 10, wherein the data acquisition module is further configured to: Obtain at least one of user participation information of a user in the target project, project channel information, and project configuration change information of the target project.

12. The apparatus according to claim 10, wherein the model analysis module is further configured to: Perform context semantic reasoning on the user behavior data based on the project rules of the target project to determine risk behavior data; Extract at least one behavior feature from the risk behavior data to obtain the risk behavior pattern composed of the at least one behavior feature.

13. The apparatus according to claim 10, wherein the risk warning module is further configured to: Retrieve a reference risk behavior pattern similar to the risk behavior pattern based on the risk behavior pattern; Use the reference risk behavior pattern as an evaluation reference to perform a risk assessment on the risk behavior data to obtain a risk assessment result.

14. The apparatus according to claim 10, further comprising: An emergency handling module, configured to execute a corresponding risk control strategy based on the risk assessment result.

15. The apparatus according to claim 14, wherein the emergency handling module is further configured to: Generate an alarm message based on the risk assessment result and send the alarm message to the user.

16. The apparatus according to claim 15, wherein the emergency handling module is further configured to: In a case where the risk assessment result reaches a preset risk level, generate an alarm message based on the risk level of the risk assessment result, so that the user performs project operation and maintenance operations corresponding to the risk level on the target project.

17. The apparatus according to claim 14 or 15, wherein the emergency handling module is further configured to: Call the security interface and execute the risk control strategy corresponding to the risk assessment result, where The risk control strategy includes at least one of an abnormal request interception strategy, a verification code trigger strategy, and a face recognition verification strategy.

18. A computing device, comprising: A memory and a processor; The memory is used to store computer programs / instructions, and the processor is used to execute the computer programs / instructions. When the computer programs / instructions are executed by the processor, the steps of the risk assessment method according to any one of claims 1 to 9 are implemented.

19. A computer-readable storage medium storing computer programs / instructions, and when the computer programs / instructions are executed by a processor, the steps of the risk assessment method according to any one of claims 1 to 9 are implemented.

20. A computer program product comprising computer programs / instructions which, when executed by a processor, implement the steps of the risk assessment method according to any one of claims 1 to 9.