Risk detection method and system based on network order
By preprocessing and feature extraction of order data of online trading platforms, and using blacklist model for risk prediction analysis, the problems of SKU security level lag and one-sidedness are solved, and the accuracy of risk user detection and operational security are improved.
Patent Information
- Application Number
- CN202510379238.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-28
- Publication Date
- 2025-07-11
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
In the prior art, the security level of SKU is lagging and one-sided, making it difficult to identify risky users and increasing store operating costs.
By obtaining order data from online trading platforms, performing data preprocessing and feature extraction, using blacklist models for risk prediction analysis, correcting the security level of SKU, and improving the accuracy and efficiency of risk user detection.
It improves the accuracy and efficiency of risk user detection, promptly corrects the security level of SKU, and ensures the security of store operations.
Smart Images

Figure CN120298075A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of network risk detection, and particularly relates to a risk detection method and system based on network orders. Background Art
[0002] A risk user refers to a person who collects evidence of infringing goods hired by a foreign law firm. They collect evidence by purchasing infringing goods and hand over the evidence to the agency law firm, which then sues the purchased store to obtain huge compensation. Usually, the infringement process includes the following situations:
[0003] (1) Malicious evidence collection: Users will purchase and collect evidence of the infringing SKUs in the store. Some risk users will use screenshots of the store's sales as evidence. The latter merchants have a greater hope of winning the lawsuit, so currently the mainstream is still mainly placing orders for infringement.
[0004] (2) Freezing funds after a case is filed: After the evidence collection is completed, the law firm will notify the target store and freeze the store's funds. At this time, the store can still sell goods and receive funds normally, but the funds cannot be withdrawn. Usually, the funds of multiple stores will be frozen at one time.
[0005] (3) The platform sends an email reminder: Foreign platforms will provide the law firm with the frozen amount and sales volume data of the frozen store to help the law firm better negotiate the settlement amount, but domestic platforms usually do not.
[0006] (4) Entrusting a lawyer for settlement: After the store's funds are frozen, it is necessary to entrust a relevant lawyer to settle with the law firm. The settlement amount is related to the total amount of the frozen store.
[0007] (5) Withdrawing the lawsuit and unfreezing funds: After the store pays the settlement amount, the platform will unfreeze the store's funds. At this time, the remaining funds of the store can be withdrawn. Due to the existence of handling fees, the store's funds cannot be withdrawn every day.
[0008] Currently, since the security level of the SKU is the company's internal annotation of the smallest inventory unit of the SKU and the infringing SKU, which has lag and one-sidedness, resulting in a low security level of the SKU, making it too difficult to identify risk users hidden among the ordering customers and increasing the normal operation cost of the store. Therefore, there is an urgent need to provide a risk detection method and system based on network orders to solve the above existing technical problems. Summary of the Invention
[0009] In view of this, the present invention provides a risk detection method and system based on network orders, which can timely correct the security level of the SKU, improve the accuracy and efficiency of risk user detection, and enhance the security of store operations. The specific technical solutions are as follows.
[0010] In a first aspect, the present invention provides a risk detection method based on online orders, comprising the following steps:
[0011] Obtain order data of an online trading platform, and perform data preprocessing on the order data to obtain an order data set;
[0012] Determine a blacklist data set corresponding to the order data set according to preset data metrics, wherein the preset data metrics include a user ID, a mailing name, a mailing phone number, a mailing street, and a mailing code registered by a user on the online trading platform, and the blacklist data set includes at least one of the user ID, the mailing name, the mailing phone number, the mailing street, or the mailing code;
[0013] Extract features from the blacklist data set to obtain blacklist features, and input the blacklist features into a trained blacklist model for risk prediction analysis to obtain a risk prediction result of the order data.
[0014] As a preference of the above technical solution, obtaining order data of an online trading platform and performing data preprocessing on the order data to obtain an order data set includes:
[0015] Obtain infringement product identifiers in a historical infringement freeze table of the online trading platform;
[0016] Statistically analyze sample data corresponding to the infringement product identifiers according to the preset data metrics, wherein the sample data includes the total number of sku purchases and the number of infringement product links;
[0017] Calculate a risk value according to the total number of sku purchases and the number of infringement product links, and the corresponding expression is:
[0018]
[0019] wherein, risk represents the risk value, risk_items represents the number of infringement product links, totol_sku represents the total number of sku purchases, and formula (1) represents the number of types of infringement product links included in the quantity of each purchased sku;
[0020] Select sample data with a risk value risk greater than zero, and construct a blacklist model of the sample data according to the preset data metrics.
[0021] As a preference of the above technical solution, constructing a blacklist model of the sample data according to the preset data metrics includes:
[0022] Obtain the order form stored in the database of the online trading platform, and retrieve the first order data that meets the preset conditions from the order form, where the preset conditions include user ID, mailing name, mailing street, mailing phone number, mailing code, platform code, mailing country, and mailing city name;
[0023] Retain the mailing street, mailing name, and mailing phone number in the order form and correspondingly obtain the market blacklist features, where the market blacklist features include a list of purchase IDs, a list of mailing names, a list of mailing phone numbers, and a list of mailing streets;
[0024] And / or retrieve the second order data by searching the order form according to the preset infringement CO number, and perform feature extraction on the second order data to obtain a corresponding high-risk value.
[0025] As a preference of the above technical solution, obtaining the order form stored in the database of the online trading platform and retrieving the first order data that meets the preset conditions from the order form includes:
[0026] Obtain the influencing factors of the order form, and extract the sensitive postal code corresponding to the influencing factors according to the preset sensitive identifier, where the influencing factors include at least one of mailing name, mailing phone number, or mailing street;
[0027] Search in the database for the target influencing factor that is the same as the sensitive postal code and does not contain the sensitive identifier;
[0028] Replace the influencing factor with the target influencing factor to determine the first order data corresponding to the target influencing factor.
[0029] As a preference of the above technical solution, before obtaining the influencing factors of the order form, it includes:
[0030] Delete the data used for testing in the database, and obtain the first order data that meets the preset conditions in the order form according to the market blacklist features;
[0031] If the preset data indicators and preset conditions in the first order data match successfully with the market blacklist features, then regard the first order data as an infringing order;
[0032] Calculate the risk value of the infringing order according to formula (1).
[0033] As a preference of the above technical solution, when the market blacklist feature is the list of mailing names, find the target order data set in the order form where the field is the mailing name and appears in the list of mailing names;
[0034] Group the target order dataset according to the shipping name, and count the first order quantity corresponding to each shipping name, as well as the second order quantity in the orders of each shipping name where the target fields are in the market blacklist features, where the target fields include user ID, shipping street, and shipping phone number;
[0035] Obtain the risk value of the shipping name according to the ratio of the first order quantity to the second order quantity.
[0036] As an optimization of the above technical solution, calculating the risk value according to the total number of sku purchases and the number of infringing product links includes:
[0037] Perform Bayesian smoothing on risk, calculate the proportional average value p and proportional variance s of the sample data in all the order data, and use formula (2) to calculate the estimated values α and β correspondingly:
[0038]
[0039] Where α and β respectively represent the estimated values corresponding to the proportional average value p and proportional variance s, substitute the estimated values α and β into formula (1) to obtain the Bayesian smoothing value, and the corresponding formula (1) is:
[0040]
[0041] Where risk' represents the Bayesian smoothing value, order_id_risk represents the number of orders with risks in all order data, and order_id represents the number of orders in the order data.
[0042] As an optimization of the above technical solution, determine the risk level label according to the Bayesian smoothing value, the average value corresponding to the proportional average value p, and the standard deviation corresponding to the proportional variance s;
[0043] When the average value is greater than 0.6, or the standard deviation is greater than or equal to 0.6, the corresponding risk level label is high risk;
[0044] When the average value is greater than 0.5 and less than 0.6, or the standard deviation is greater than or equal to 0.5 and less than 0.6, the corresponding risk level label is medium risk;
[0045] When the average value is less than or equal to 0.5, or the standard deviation is less than 0.5, the corresponding risk level label is low risk.
[0046] In a second aspect, the present invention also provides a risk detection system based on online orders, including applying the risk detection method based on online orders as described above, including:
[0047] A data acquisition unit, configured to acquire order data of an online trading platform and perform data preprocessing on the order data to obtain an order data set;
[0048] A data judgment unit, configured to determine a blacklist data set corresponding to the order data set according to preset data metrics, where the preset data metrics include a user ID, a mailing name, a mailing phone number, a mailing street, and a mailing code registered by a user on the online trading platform, and the blacklist data set includes at least one of a user ID, a mailing name, a mailing phone number, a mailing street, or a mailing code;
[0049] A risk prediction unit, configured to extract features from the blacklist data set to obtain blacklist features, and input the blacklist features into a trained blacklist model for risk prediction analysis to obtain a risk prediction result of the order data.
[0050] The present invention provides a risk detection method and system based on network orders. By acquiring order data of an online trading platform, performing data preprocessing on the order data to obtain an order data set, determining a blacklist data set corresponding to the order data set according to preset data metrics, extracting features from the blacklist data set to obtain blacklist features, and inputting the blacklist features into a trained blacklist model for risk prediction analysis to obtain a risk prediction result of the order data, multiple judgment metrics for the order data are constructed according to the preset data metrics and the blacklist data set, enriching sample data and business maintenance data, improving the multi-dimensional risk detection accuracy of the order data. According to the risk detection result, the security level of the SKU can be corrected in a timely manner, improving the accuracy and efficiency of risk user detection, and effectively ensuring the security of store operations. BRIEF DESCRIPTION OF THE DRAWINGS
[0051] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings required for use in the embodiments will be briefly introduced below. It should be understood that the following drawings only show some embodiments of the present invention, and thus should not be regarded as limiting the scope. For those of ordinary skill in the art, other related drawings can be obtained based on these drawings without creative efforts.
[0052] Figure 1 It is a flowchart of the risk detection method based on network orders provided by the present invention;
[0053] Figure 2 It is a flowchart of the market blacklist correlation analysis provided by the present invention;
[0054] Figure 3 It is a structural block diagram of the risk detection system based on network orders provided by the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0055] Embodiments of the present invention will be described in detail below. Examples of the embodiments are shown in the accompanying drawings, where like or similar reference numerals denote like or similar elements or elements having like or similar functions throughout. The embodiments described by referring to the accompanying drawings are exemplary and are only used to explain the present invention and should not be construed as a limitation to the present invention.
[0056] Referring to Figure 1 , the present invention provides a risk detection method based on network orders, including the following steps:
[0057] S1: Obtain order data of a network trading platform, and perform data preprocessing on the order data to obtain an order data set;
[0058] S2: Determine a blacklist data set corresponding to the order data set according to preset data metrics, where the preset data metrics include user ID, mailing name, mailing phone number, mailing street, and mailing code registered by a user on the network trading platform, and the blacklist data set includes at least one of user ID, mailing name, mailing phone number, mailing street, or mailing code;
[0059] S3: Extract features from the blacklist data set to obtain blacklist features, and input the blacklist features into a trained blacklist model for risk prediction analysis to obtain a risk prediction result of the order data.
[0060] In this embodiment, obtaining order data of a network trading platform and performing data preprocessing on the order data to obtain an order data set includes:
[0061] Obtain infringement product identifiers in a historical infringement freeze table of the network trading platform;
[0062] Statistically analyze sample data corresponding to the infringement product identifiers according to the preset data metrics, where the sample data includes the total number of sku purchases and the number of infringement product links;
[0063] Calculate a risk value according to the total number of sku purchases and the number of infringement product links, and the corresponding expression is:
[0064]
[0065] where risk represents the risk value, risk_items represents the number of infringement product links, totol_sku represents the total number of sku purchases, and formula (1) represents the number of types of infringement product links included in the quantity of each purchased sku;
[0066] Select sample data with a risk value risk greater than zero, and construct a blacklist model of the sample data according to the preset data metrics.
[0067] Determine the blacklist dataset corresponding to the order dataset according to preset data metrics, including:
[0068] Obtain the blacklist dataset corresponding to the order data in the database according to the preset data metrics;
[0069] Judge whether the data metrics in the order dataset exist in the blacklist dataset;
[0070] If so, return the total quantity of the corresponding order data, the number of infringing product links, and the risk value.
[0071] It should be noted that sku is the abbreviation of stock-keeping unit, representing a kind of product in the retailer's inventory; sku code is a unique identifier containing letters and numbers, used to describe the important features of the product, such as brand, color, and size. The preset data metrics mainly include the user ID, mailing name, mailing phone, mailing street, and mailing code registered by the user on the online trading platform (such as the international station, e-commerce shopping platform, etc.). The ID registered by the user on the platform is denoted as buyer_id, the mailing name is denoted as ship_name, the mailing phone is denoted as ship_phone, the mailing street is denoted as ship_street, and the mailing code is denoted as ship_zip; buyer_id is unique and can be used alone for blacklist judgment; ship_name is not unique and needs to be judged jointly with other metrics; ship_phone is unique and can be used alone for blacklist judgment; ship_street is unique and can be used alone for blacklist judgment; ship_zip is not unique and needs to be judged jointly with other metrics. Taking the data of the metrics with uniqueness as influencing factors, taking the law firm buyer with buyer_id as an example, multiple assumptions are proposed: (1) Assume that the law firm buyer will not repeatedly purchase at the same infringing product link; (2) Assume that the law firm buyer will adopt the sku allocation rule of maximizing benefits, that is, the number of skus it purchases should cover as many infringing product links of different stores as possible; (3) Assume that the law firm buyer places orders in batches through scripts and will not change buyer_id, ship_phone, ship_street, ship_name, and ship_zip at the same time.
[0072] Specifically, obtain the infringing product identifier from the historical infringement freeze table and denote it as item_id; count the total number of skus purchased and the number of infringing item_ids respectively according to the five dimensions of buyer_id, ship_phone, ship_street, ship_name, and ship_zip, and denote them as total_sku and risk_items respectively; calculate risk using formula (1). The meaning of formula (1) is the number of types of infringing product links contained in the quantity of each purchased sku. The larger this value, the more frequent the interaction with the infringing product links and the greater the likelihood of being a law firm buyer; adding 1 to the denominator is to reduce the weight of first-time users under the infringing links. If 1 is removed, it will become 100%, which will interfere with subsequent judgments; filter out the sample data with risk greater than 0 and form five blacklists of buyer_id, ship_phone, ship_street, ship_name, and ship_zip, namely the blacklist model.
[0073] Specifically, perform data preprocessing on the data indicators in the newly arrived order data. The corresponding data indicators are denoted as buyer_id1, ship_phone1, ship_street1, ship_name1, and ship_zip1 respectively. Obtain the blacklist data set of all buyer_id1, ship_phone1, ship_street1, ship_name1, and ship_zip1 from the database, and check whether the preprocessed buyer_id2, ship_phone2, ship_street2, ship_name2, and ship_zip2 are in the corresponding blacklist data set; if at least one is in, return the corresponding total_qty (total quantity), risk_items, risk, otherwise return null.
[0074] Specifically, determine the risk level label of the order according to the value of the returned risk. From small to large, they are no_risk (no risk), risky (low risk), medium_risk (medium risk), and high_risk (high risk). If the ship_country (shipping country) of the order is US, the ship_stateor province (shipping state / province) is IL or ILLINOIS, and fte (full-time equivalent) appears in the ship_name (shipping name), then modify the risk level of the order to high_risk (high risk) and add the label of fte. Among them, as long as the order returned by the blacklist model, it will be automatically labeled with risk_model (risk model). If a new infringing item_id appears in the historical infringement freeze library (table), the blacklist of buyer_id, ship_phone, ship_street, ship_name, and ship_zip will be automatically updated.
[0075] It should be understood that by obtaining the order data of the online trading platform and preprocessing the order data to obtain an order data set, determining the corresponding blacklist data set of the order data set according to the preset data indicators, extracting the blacklist features from the blacklist data set, and inputting the blacklist features into the trained blacklist model for risk prediction analysis to obtain the risk prediction result of the order data, constructing multiple judgment indicators of the order data according to the preset data indicators and the blacklist data set, enriching the sample data and business maintenance data, improving the multi-dimensional risk detection accuracy of the order data, timely correcting the security level of the SKU according to the risk detection result, improving the accuracy and efficiency of risk user detection, and effectively ensuring the security of the store operation.
[0076] Refer to Figure 2 , optionally, constructing the blacklist model of the sample data according to the preset data indicators includes:
[0077] Obtain the order table stored in the database of the online trading platform, and retrieve the first order data that meets the preset conditions from the order table. Among them, the preset conditions include user ID, shipping name, shipping street, shipping phone, shipping code, platform code, shipping country, and shipping city name;
[0078] Retain the shipping street, shipping name, and shipping phone in the order table and correspondingly obtain the market blacklist features. Among them, the market blacklist features include a list of purchase IDs, a list of shipping names, a list of shipping phones, and a list of shipping streets;
[0079] And / or retrieve the order table according to the preset infringing CO number to obtain the second order data, and perform feature extraction on the second order data to obtain a corresponding risk value of high risk.
[0080] In this embodiment, the order table stored in the database of the network trading platform is obtained, and the first order data that meets the preset conditions is retrieved from the order table, including: obtaining the impact factor of the order table, and extracting the sensitive postal code corresponding to the impact factor according to the preset sensitive identifier, wherein the impact factor includes at least one of the mailing name, mailing phone number or mailing street; searching the database for a target impact factor that is the same as the sensitive postal code and does not contain the sensitive identifier; replacing the impact factor with the target impact factor to determine the first order data corresponding to the target impact factor. Before obtaining the impact factor of the order table, it includes: removing the data used for testing in the database, and obtaining the first order data that meets the preset conditions in the order table according to the market blacklist feature; if the preset data indicators and preset conditions in the first order data successfully match the market blacklist feature, the first order data is used as an infringing order; and the risk value of the infringing order is calculated according to formula (1). Wherein. The first order data and the second order data can be historical orders or newly added orders, which are not limited by the present invention.
[0081] It should be noted that when the market blacklist feature is a mailing name list, a target order data set whose field is a mailing name and appears in the mailing name list is found from the order table; the target order data set is grouped according to the mailing name, and the number of first orders corresponding to each mailing name and the number of second orders in each order of the mailing name with the target field in the market blacklist feature are counted, wherein the target field includes user ID, mailing street and mailing phone number; the risk value of the mailing name is obtained according to the ratio of the first order quantity to the second order quantity. The risk value is calculated based on the total number of sku purchases and the number of infringing product links, including:
[0082] Perform Bayesian smoothing on risk, calculate the proportional mean p and proportional variance s of the risk values of all sample data in the order data, and use formula (2) to calculate the estimated values α and β accordingly:
[0083]
[0084] Among them, α and β represent the estimated values corresponding to the proportion mean p and the proportion variance s respectively. Substituting the estimated values α and β into formula (1) to obtain the Bayesian smoothing value, the corresponding formula (1) is:
[0085]
[0086] Among them, risk' represents the Bayesian smoothing value, order_id_risk represents the number of orders with risks in all order data, and order_id represents the number of orders in the order data.
[0087] Above, determine the risk level label according to the Bayesian smoothing value, the average corresponding to the ratio average p, and the standard deviation corresponding to the ratio variance s; when the average is greater than 0.6, or the standard deviation is greater than or equal to 0.6, the corresponding risk level label is high risk; when the average is greater than 0.5 and less than 0.6, or the standard deviation is greater than or equal to 0.5 and less than 0.6, the corresponding risk level label is medium risk; when the average is less than or equal to 0.5, or the standard deviation is less than 0.5, the corresponding risk level label is low risk.
[0088] Specifically, the market blacklist correlation analysis process includes data source, data desensitization, data blocking, market expansion, Bayesian smoothing, and risk level determination. The specific analysis processes corresponding to them are as follows:
[0089] Data source: According to the ID (account number) and EMAIL (email) in ueb_bi_md_rw.dwi_md_ueb_order_black_list (a text file containing user registration information, blacklist, orders, data indicators, etc., and the text file is stored in the database), retrieve the eligible order data from the order table, and the fields are buyer_id, ship_name, ship_street, ship_phone, ship_zip, platform_code, ship_country, ship_city_name; at the same time, retain ship_street1, ship_name, ship_phone existing in ueb_bi_md_rw.dwi_md_ueb_order_black_list (file storage path) to obtain four market (transaction) blacklist features: buyers_list (purchase ID list, i.e., buyer account list), ship_name_list (mailing name list), ship_phone_list (mailing phone list), ship_street_list (mailing street list); it is also possible to directly input the infringement CO number, and the model (blacklist model) will automatically retrieve the relevant order data for feature extraction. At this time, the risk value of the extracted feature is high risk.
[0090] Data Masking: Data masking is a technique for converting or modifying sensitive information such as mobile phone numbers and ID card numbers, which is applied to scenarios such as testing, development, and training to protect user privacy. Static data masking is used in non-production environments, while dynamic data masking processes data in real time in production environments. Common masking methods include invalidation, random values, data replacement, symmetric encryption, averaging, and offset rounding. Extract the (postal) zip codes in the order data where ship_name, ship_street, and ship_phone contain asterisks (sensitive identifiers), and search the database for ship_name, ship_street, and ship_phone that are the same as the zip code but do not contain asterisks for replacement.
[0091] Data Blocking: Exclude the data used for testing in the market database from the scope of analysis;
[0092] Market Expansion: Obtain the order data that meets the conditions (preset conditions) in the order table based on buyers_list, ship_name_list, ship_phone_list, and ship_street_list. The fields are buyer_id, ship_name, ship_street, ship_phone, and order_id. If there are other fields in the market blacklist features in addition to these fields themselves, then the order is considered an infringing order. Add up the number of infringing orders and divide by the total number of orders for the corresponding feature (field), and use the resulting value as the risk value (risk score) for that feature. Taking ship_name_list as an example, find the order data set in the order table where the ship_name field appears in ship_name_list, then group the order data set by ship_name, count the number of orders corresponding to each ship_name (the first order count), and the number of orders in which there are other features (buyer_id, ship_street, ship_phone) in the market blacklist features for each ship_name (the second order count). Divide the two to obtain the risk value of ship_name, denoted as risk. It should be noted that if the feature is originally in ueb_bi_md_rw.dwi_md_ueb_order_black_list, then risk is constantly 1.
[0093] Bayesian Smoothing: Since the risk values are sparse, Bayesian smoothing is performed on the risk values. First, calculate the average value p of the proportion of risky orders among all orders, calculate the variance s of these proportions, and estimate α and β using the following formula; then substitute the estimated values into the formula to obtain Bayesian smoothing. Among them, risky orders can be judged according to the risk value in formula (1) being greater than 0.
[0094] Risk Level Determination: The risk level is determined by the mean and standard deviation. Those greater than 0.6 are recorded as high risks, those less than 0.6 but greater than 0.5 are recorded as medium risks, and the rest are recorded as low risks. During the training process of the blacklist model, if more than 60% of the orders in the order set of the attribution feature have problems, then this feature is a high risk; if there is only a little more than 0.5, then this feature has a medium risk; otherwise, this feature is a low risk.
[0095] It should be understood that the risk detection method based on network orders provided by the present invention can solve multiple business difficulties, specifically including: (1) There is no specific infringement CO number and personal information of the law firm buyer, so it is necessary to construct statistical indicators for judgment; (2) The law firm buyers are highly concealed and the number is small, and it is difficult for a single judgment indicator to judge all of them; (3) There are few types of data, only the relevant data of the orders. It is also possible to set an effective model risk assessment process, that is, risk, risk correlation risk, and ITEM and correlation risk of law firm compensation.
[0096] Refer to Figure 3 , the present invention also provides a risk detection system based on network orders, including applying the above-mentioned risk detection method based on network orders, including:
[0097] A data acquisition unit, configured to acquire order data of a network trading platform and perform data preprocessing on the order data to obtain an order data set;
[0098] A data judgment unit, configured to determine a blacklist data set corresponding to the order data set according to preset data indicators, where the preset data indicators include user ID, mailing name, mailing phone, mailing street, and mailing code registered by the user on the network trading platform, and the blacklist data set includes at least one of user ID, mailing name, mailing phone, mailing street, or mailing code;
[0099] A risk prediction unit, configured to extract blacklist features from the blacklist data set, and input the blacklist features into a trained blacklist model for risk prediction analysis to obtain a risk prediction result of the order data.
[0100] In all examples shown and described herein, any specific values should be construed as merely exemplary and not as a limitation. Thus, other examples of the exemplary embodiments may have different values.
[0101] It should be noted that like reference numerals and letters refer to like items in the following figures. Thus, once an item is defined in one figure, it need not be further defined and explained in subsequent figures.
[0102] The embodiments described above merely represent several implementation manners of the present invention. The description is relatively specific and detailed, but it should not be construed as a limitation to the scope of the present invention. It should be pointed out that for those of ordinary skill in the art, without departing from the concept of the present invention, several modifications and improvements can be made, and these all fall within the protection scope of the present invention.
Claims
1. A risk detection method based on online orders, characterized in that, It includes the following steps: Obtain the order data of the online trading platform, and perform data preprocessing on the order data to obtain an order data set; Determine the blacklist data set corresponding to the order data set according to preset data metrics, where the preset data metrics include the user ID, mailing name, mailing phone number, mailing street, and mailing code registered by the user on the online trading platform, and the blacklist data set includes at least one of the user ID, mailing name, mailing phone number, mailing street, or mailing code; Extract features from the blacklist data set to obtain blacklist features, and input the blacklist features into a trained blacklist model for risk prediction analysis to obtain the risk prediction result of the order data.
2. The risk detection method based on network orders according to claim 1, wherein Obtain the order data of the online trading platform, and perform data preprocessing on the order data to obtain an order data set, including: Obtain the infringing product identifiers in the historical infringement freeze table of the online trading platform; Statistically analyze the sample data corresponding to the infringing product identifiers according to the preset data metrics, where the sample data includes the total number of sku purchases and the number of infringing product links; Calculate the risk value according to the total number of sku purchases and the number of infringing product links, and the corresponding expression is: where risk represents the risk value, risk_items represents the number of infringing product links, totol_sku represents the total number of sku purchases, and formula (1) represents the number of types of infringing product links included in the quantity of each purchased sku; Select the sample data with a risk value risk greater than zero, and construct a blacklist model for the sample data according to the preset data metrics.
3. The risk detection method based on network orders according to claim 2, wherein Construct a blacklist model for the sample data according to the preset data metrics, including: Obtain the order table stored in the database of the online trading platform, and retrieve the first order data that meets the preset conditions from the order table, where the preset conditions include the user ID, mailing name, mailing street, mailing phone number, mailing code, platform code, mailing country, and mailing city name; Retain the mailing street, mailing name, and mailing phone number in the order table and correspondingly obtain the market blacklist features, where the market blacklist features include a list of purchase IDs, a list of mailing names, a list of mailing phone numbers, and a list of mailing streets; and / or retrieve the second order data from the order table according to a preset infringement CO number, and perform feature extraction on the second order data to obtain a high risk corresponding to the risk value.
4. The risk detection method based on network orders according to claim 3, wherein Obtain the order table stored in the database of the online trading platform, and retrieve the first order data that meets the preset conditions from the order table, including: Obtain the influencing factors of the order table, and extract the sensitive postal code corresponding to the influencing factors according to a preset sensitive identifier, where the influencing factors include at least one of the mailing name, mailing phone number, or mailing street; Search for the target influencing factor in the database that is the same as the sensitive postal code and does not contain the sensitive identifier; Replace the influencing factor with the target influencing factor to determine the first order data corresponding to the target influencing factor.
5. The risk detection method based on network orders according to claim 4, wherein, Before obtaining the influencing factors of the order table, it includes: Delete the data used for testing in the said database, and obtain the first order data in the order table that meets the preset conditions according to the characteristics of the market blacklist; If the preset data indicators and preset conditions in the first order data match the characteristics of the market blacklist successfully, then regard the first order data as an infringing order; Calculate the risk value of the infringing order according to formula (1).
6. The risk detection method based on network orders according to claim 5, wherein It also includes: When the market blacklist feature is a list of mailing names, find the target order data set in the order table whose field is the mailing name and appears in the list of mailing names; Group the target order data set according to the mailing name, and count the number of the first orders corresponding to each mailing name, and the number of the second orders in the orders corresponding to each mailing name whose target fields are in the market blacklist features, where the target fields include user ID, mailing street and mailing phone; Obtain the risk value of the mailing name according to the ratio of the number of the first orders to the number of the second orders.
7. The risk detection method based on network orders according to claim 2, wherein Calculating the risk value according to the total number of sku purchases and the number of infringing product links includes: Perform Bayesian smoothing on risk, calculate the proportional average value p and proportional variance s of the risk values of the sample data in all the order data, and use formula (2) to calculate the estimated values α and β correspondingly: Where α and β respectively represent the estimated values corresponding to the proportional average value p and proportional variance s, substitute the estimated values α and β into formula (1) to obtain the Bayesian smoothing value, and the corresponding formula (1) is: Where risk' represents the Bayesian smoothing value, order_id_risk represents the number of orders with risks in all order data, and order_id represents the number of orders in the order data.
8. The risk detection method based on network orders according to claim 7, characterized in that It also includes: Determine the risk level label according to the Bayesian smoothing value, the average value corresponding to the proportional average value p and the standard deviation corresponding to the proportional variance s; When the average value is greater than 0.6, or the standard deviation is greater than or equal to 0.6, the corresponding risk level label is high risk; When the average value is greater than 0.5 and less than 0.6, or the standard deviation is greater than or equal to 0.5 and less than 0.6, the corresponding risk level label is medium risk; When the average value is less than or equal to 0.5, or the standard deviation is less than 0.5, the corresponding risk level label is low risk.
9. The risk detection method based on network orders according to claim 1, wherein Determine the blacklist data set corresponding to the order data set according to the preset data indicators, including: Obtain the blacklist data set corresponding to the order data in the database according to the preset data indicators; Judge whether the data indicators in the order data set exist in the blacklist data set; If so, return the total number, the number of infringing product links and the risk value of the corresponding order data.
10. A risk detection system based on online orders, characterized in that, It includes applying the risk detection method based on network orders according to any one of claims 1-9, including: A data acquisition unit, configured to acquire order data of a network trading platform, and perform data preprocessing on the order data to obtain an order data set; A data judgment unit, configured to determine a blacklist data set corresponding to the order data set according to preset data metrics, where the preset data metrics include a user ID, a mailing name, a mailing phone number, a mailing street, and a mailing code registered by the user on the online trading platform, and the blacklist data set includes at least one of a user ID, a mailing name, a mailing phone number, a mailing street, or a mailing code; A risk prediction unit, configured to extract features from the blacklist data set to obtain blacklist features, and input the blacklist features into a trained blacklist model for risk prediction analysis to obtain a risk prediction result of the order data.
Citation Information
Patent Citations
Transaction risk control method and device
CN108876105A
Risk network construction method and device
CN110175924A
Customer risk rating method and device based on big data, equipment and storage medium
CN112668859A
Method for standardizing risk indicators and predicting risk rating and computing device
CN116384751A