Method and system for identifying user risk based on Internet insurance
By constructing a user behavior model and dynamic risk assessment strategy for multi-source heterogeneous data, the problem of insufficient accuracy and flexibility of traditional Internet insurance risk assessment is solved, real-time risk monitoring and evaluation is realized, and insurance companies' risk management capabilities and data security are improved.
Patent Information
- Application Number
- CN202510363028.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-26
- Publication Date
- 2025-07-11
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
Traditional Internet insurance risk assessment methods cannot effectively integrate multi-source heterogeneous data, lack of analysis of real-time behavior and environmental context, resulting in inaccurate risk assessment, lack of flexibility, and insufficient data security.
Build a user behavior model that integrates multi-source heterogeneous data, integrate online behavior, device fingerprint and social network data, conduct multi-dimensional risk prediction, set up dynamic risk assessment strategies, implement gradient-driven strategies to nonlinear adjustments to premiums and underwriting conditions, and use differential privacy technology and security multi-party computing to protect data security.
It improves the accuracy and flexibility of risk assessment, realizes real-time monitoring and evaluation of risks, protects user privacy, and enhances the market competitiveness and data security of insurance companies.
Smart Images

Figure CN120298121A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of insurance risk identification, and specifically to a method and system for identifying user risks based on Internet insurance applications. Background Art
[0002] At present, with the booming development of Internet insurance, the scale of online insurance application business continues to expand, and more and more users choose to purchase insurance products through Internet platforms. Although this trend has greatly improved the convenience and efficiency of insurance business, it has also brought unprecedented risk identification challenges to insurance companies. Traditional risk assessment methods mainly rely on static information filled in by users, such as age, occupation, health status, etc., and it is difficult to comprehensively and accurately reflect the dynamic risks of users in the Internet environment.
[0003] From the data level, the previous data sources were relatively single, and the rich user behavior data in the Internet era could not be fully utilized. In the scenario of Internet insurance application, users' online behavior data (such as browsing history, page stay duration, click heat map distribution, etc.), device fingerprint data (device model, operating system version, etc.) and social network data contain a large amount of information related to risks. However, traditional methods have not effectively integrated these multi-source heterogeneous data, resulting in a significant reduction in the accuracy of risk assessment. For example, it is difficult to determine whether there are abnormalities in the operation behavior of a user during the insurance application process and whether the user's social network relationship will affect the risk only based on the age and occupation information filled in by the user.
[0004] In terms of risk prediction, traditional models often lack effective analysis of real-time behavior and environmental context. The Internet environment is changing rapidly, and the behavior of users and the environment they are in may change at any time. Real-time behavior sequences (such as the number of abnormal form fills) and environmental context data (such as IP reputation rating, network latency metrics) are crucial for timely detection of potential risks. However, traditional risk prediction models cannot capture these dynamic information in a timely manner, resulting in difficulty in quickly responding when risks occur. For example, when a user frequently changes the IP address for insurance application operations within a short period of time, the traditional model may not be able to detect this abnormal behavior in a timely manner and issue a risk warning.
[0005] In terms of dynamic risk assessment strategies, traditional premium pricing and underwriting condition settings are relatively fixed and lack flexibility. In actual insurance business, risks are dynamically changing, and the risk status of different users may also change after insurance application. However, traditional methods cannot reasonably adjust the premium coefficient and underwriting conditions according to the real-time changes in risks. This may lead to insurance companies still charging fees according to fixed premium standards when facing high-risk users, thus increasing their own business risks; or when the risk decreases, failing to adjust the underwriting conditions in a timely manner and missing opportunities to expand business.
[0006] In addition, data security issues are also becoming increasingly prominent in the field of Internet insurance. With the frequent occurrence of data leakage incidents, users' attention to personal data security has been continuously improving. In insurance business, a large amount of sensitive information of users is involved, such as personal identity information, financial data, etc. In the process of data processing, traditional risk assessment methods often lack effective security measures and are difficult to guarantee the privacy and security of users' data. Once the data is leaked, it will not only cause huge losses to users, but also seriously damage the reputation and image of insurance companies. Summary of the Invention
[0007] The purpose of the present invention is to provide a method and system for identifying user risks based on Internet insurance applications to solve the problems raised in the above background technology.
[0008] To achieve the above purpose, the present invention provides the following technical solutions: A method for identifying user risks based on Internet insurance applications, the method includes;
[0009] Construct a user behavior model, including a high-fidelity risk assessment model that integrates multi-source heterogeneous data; the user behavior model integrates online behavior data, device fingerprint data, and social network data to generate behavior feature vectors and risk correlation coefficients; the multi-source heterogeneous data includes browsing history, transaction frequency, geographical location offset, and network latency metrics;
[0010] Perform multi-dimensional risk prediction, including constructing a risk prediction model, and obtaining a dynamic risk score by inputting real-time behavior sequences and environmental context data into the risk prediction model; the real-time behavior sequences include page stay duration, click heat map distribution, and form filling anomaly times; the environmental context data includes device model, operating system version, and IP reputation rating;
[0011] Set a dynamic risk assessment strategy, including implementing a gradient-driven strategy according to the dynamic risk score output by the risk prediction model; the gradient-driven strategy includes non-linearly adjusting the premium coefficient and underwriting conditions to achieve real-time risk hedging;
[0012] Perform real-time feedback and model optimization; the real-time feedback includes asynchronously collecting post-insurance user behavior change data and claim event tags;
[0013] The formula for the risk correlation coefficient is:
[0014]
[0015] Where γ(t) is the risk correlation coefficient at time t, α i is the weight of the i-th type of behavior feature, ΔB i(t) is the temporal fluctuation amount of feature i, Θ(t) is the environmental stability factor, β is the decay coefficient of the device fingerprint, and φ(t) is the social network association degree.
[0016] Preferably, the construction of the user behavior model includes: using a graph neural network to model the heterogeneous relationship topology of user-device-environment; adopting a reinforcement learning framework to dynamically optimize the feature extraction path; integrating a federated learning mechanism to distributively update local behavior features.
[0017] Preferably, the integration of the environmental context data includes: capturing the device hardware fingerprint in real time through a lightweight sandbox container; using a time series anomaly detection algorithm to filter out the instantaneous jumps of IP addresses; mapping the network delay metric into a spatial distribution matrix to quantify the connection stability.
[0018] Preferably, the adjustment formula of the gradient-driven policy is:
[0019]
[0020] where is the premium adjustment gradient at time t, η is the learning rate, L is the risk loss function, ω is the model parameter, is the partial derivative of the risk loss function L with respect to the model parameter ω, R(t) is the dynamic risk score, λ is the hedging intensity factor, D(t) is the historical claim density, and sigmoid and ReLU represent activation functions.
[0021] Preferably, the training process of the risk prediction model includes:
[0022] Data collection: Extract 100,000 user behavior trajectories from the insurance platform logs, and each trajectory contains a temporal action chain, a device fingerprint hash, and an environmental context snapshot;
[0023] Feature enhancement: Perform piecewise Fourier transform on the page stay duration to capture periodic patterns; apply kernel density estimation to the click heatmap distribution to generate a spatial probability density field;
[0024] Adversarial training: Introduce a generative adversarial network to synthesize high-risk adversarial samples to improve the robustness of the model;
[0025] Model fusion: Perform multi-head cross-attention fusion on the attention weights of the Transformer encoder and the output of the temporal convolutional network to generate the final risk score.
[0026] Preferably, the adversarial training includes: constructing a discriminator network to distinguish real behavior sequences from synthetic sequences; the generator network adopts a sequence generation structure with a gated recurrent unit and optimizes the adversarial loss function through a policy gradient algorithm.
[0027] Preferably, the real-time feedback and model optimization include: injecting noise into the post-insurance behavior data using differential privacy technology; compressing the incremental data into lightweight feature representations through online knowledge distillation to update the edge node parameters of the risk prediction model.
[0028] Preferably, the method further includes a data security layer: applying a homomorphic encryption algorithm to perform encrypted calculations on sensitive fields during the feature extraction stage; adopting a secure multi-party computing (MPC) protocol to achieve privacy fusion of cross-institutional data during the risk assessment stage.
[0029] Preferably, the triggering conditions for the dynamic risk assessment strategy include: when the risk score exceeds the adaptive threshold τ(t), starting the real-time premium floating mechanism; the calculation formula for the threshold τ(t) is:
[0030]
[0031] where μ is the mean of the historical risk scores, σ is the dynamic standard deviation scaling factor, N is the number of samples within the sliding time window, and R k (t - 1) is the dynamic risk score at the k-th historical moment within the time window.
[0032] Preferably, the present invention further includes a system for identifying user risks based on Internet insurance applications. The system includes:
[0033] A user behavior modeling module: used to build a user behavior model, integrate multi-source heterogeneous data to build a high-fidelity risk assessment model, integrate online behavior data, device fingerprint data, and social network data, and generate behavior feature vectors and risk correlation coefficients, where the multi-source heterogeneous data covers browsing history, transaction frequency, geographical location offset, and network latency metrics;
[0034] A multi-dimensional risk prediction module: builds a risk prediction model, receives real-time behavior sequences and environmental context data as inputs, and obtains dynamic risk scores. The real-time behavior sequences include page dwell time, click heatmap distribution, and form filling anomaly counts, and the environmental context data includes device model, operating system version, and IP reputation rating;
[0035] A dynamic risk assessment strategy module: based on the dynamic risk scores output by the risk prediction model, implements a gradient-driven strategy to non-linearly adjust the premium coefficient and underwriting conditions to achieve real-time risk hedging;
[0036] A real-time feedback and optimization module: asynchronously collects post-insurance user behavior change data and claim event labels for real-time feedback and model optimization of the system;
[0037] where the formula for the risk correlation coefficient is:
[0038]
[0039] Among them, γ(t) is the risk correlation coefficient at time t, and α i is the weight of the i-th type of behavior feature, ΔB i (t) is the time-series fluctuation amount of feature i, Θ(t) is the environmental stability factor, β is the attenuation coefficient of the device fingerprint, and φ(t) is the social network correlation degree.
[0040] Compared with the prior art, the beneficial effects of the present invention are as follows:
[0041] In terms of the accuracy of risk identification, by constructing a user behavior model that integrates multi-source heterogeneous data and integrating online behavior, device fingerprint, and social network data, it is possible to comprehensively capture user behavior characteristics. For example, browsing history can reflect the user's interest preferences for different insurance products, transaction frequency can reflect the activity level of their economic activities, and geographical location offset and network latency metrics can help judge the stability of the network environment. The behavior feature vector and risk correlation coefficient generated by integrating these data greatly improve the accuracy of risk assessment. Compared with traditional methods, it is no longer limited to static user basic information and can more deeply insight into the potential risks of users, providing a more reliable basis for risk assessment for insurance companies.
[0042] In terms of multi-dimensional risk prediction, inputting real-time behavior sequences and environmental context data into the risk prediction model to obtain dynamic risk scores realizes real-time monitoring and assessment of risks. The comprehensive analysis of real-time behavior sequences such as page residence time, click heatmap distribution, and the number of abnormal form fills, as well as environmental context data such as device model, operating system version, and IP reputation rating, enables the model to timely detect abnormal situations and potential risks in user behavior. When a user has an abnormally high number of errors when filling out an insurance application form, or the IP reputation rating of the network environment where the user is located is low, the model can quickly give a higher risk score, providing an early warning for insurance companies so that corresponding measures can be taken to reduce risks.
[0043] The implementation of the dynamic risk assessment strategy non-linearly adjusts the premium coefficient and underwriting conditions according to the dynamic risk score, realizing real-time risk hedging. This flexible adjustment mechanism enables insurance companies to reasonably price and adjust underwriting strategies according to the real-time changes in risks. For users with higher risks, appropriately increase the premium coefficient or tighten the underwriting conditions to effectively reduce the potential losses of insurance companies; for users with lower risks, the premium coefficient can be reduced or the underwriting conditions can be relaxed to attract more high-quality customers and enhance market competitiveness. In this way, insurance companies can better balance risks and returns and achieve sustainable development.
[0044] The real-time feedback and model optimization mechanism asynchronously collects the data of post-insurance user behavior changes and claim event tags, providing strong support for the continuous optimization of the model. As user behavior changes continuously and new data accumulates, the model can be updated in a timely manner to adapt to new risk patterns. The differential privacy technology is used to inject noise into the post-insurance behavior data, which not only protects user privacy but also ensures the availability of the data. By online knowledge distillation, the incremental data is compressed into lightweight feature representations to update the edge node parameters of the risk prediction model, improving the model update efficiency and adaptability. In this way, the model can always maintain high accuracy and effectiveness, providing a more reliable guarantee for risk assessment.
[0045] In terms of data security, the present invention has outstanding advantages. The homomorphic encryption algorithm is applied in the feature extraction stage to perform encrypted calculations on sensitive fields, ensuring that sensitive data remains encrypted throughout the entire calculation process. Even if the data is stolen during transmission or storage, attackers cannot obtain the real data content. In the risk assessment stage, the secure multi-party computation (MPC) protocol is adopted to achieve the privacy fusion of cross-institutional data, enabling different institutions to conduct joint risk assessment without disclosing local data. This not only makes full use of the data resources of all parties but also ensures the security and privacy of the data. This not only enhances users' trust in insurance companies but also provides a secure and reliable solution for data cooperation in the insurance industry. BRIEF DESCRIPTION OF THE DRAWINGS
[0046] Figure 1 is the working principle diagram of the method for identifying user risks in Internet insurance application of the present invention;
[0047] Figure 2 is the working flow chart of the environmental context data integration;
[0048] Figure 3 is the working flow chart of the risk prediction model training
[0049] Figure 4 is the working flow chart of the adversarial training. DETAILED DESCRIPTION OF THE INVENTION
[0050] The following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0051] Please refer to Figures 1-4 , the present invention provides a technical solution: a method for identifying user risks based on Internet insurance application, the method comprising:
[0052] Construct a user behavior model: Integrate multi-source heterogeneous data to build a high-fidelity risk assessment model, integrate online behavior data, device fingerprint data, and social network data, and generate behavior feature vectors and risk correlation coefficients. Among them, multi-source heterogeneous data covers browsing history, transaction frequency, geographical location offset, and network latency metrics, etc.
[0053] Conduct multi-dimensional risk prediction: Build a risk prediction model, and input real-time behavior sequences and environmental context data into the model to obtain dynamic risk scores. Real-time behavior sequences include page stay duration, click heatmap distribution, and the number of abnormal form fillings; environmental context data includes device model, operating system version, and IP reputation rating.
[0054] Set dynamic risk assessment strategies: According to the dynamic risk scores output by the risk prediction model, implement a gradient-driven strategy to non-linearly adjust premium coefficients and underwriting conditions to achieve real-time risk hedging.
[0055] Conduct real-time feedback and model optimization: Asynchronously collect post-insurance user behavior change data and claim event labels for real-time feedback and model optimization. The calculation formula for the risk correlation coefficient is:
[0056]
[0057] Among them, γ(t) is the risk correlation coefficient at time t, α i is the weight of the i-th type of behavior feature, ΔB i (t) is the time series fluctuation of feature i, Θ(t) is the environmental stability factor, β is the attenuation coefficient of the device fingerprint, and φ(t) is the social network correlation degree.
[0058] The present invention will be further described below in conjunction with Embodiments 1 to 5:
[0059] Embodiment 1:
[0060] This embodiment mainly elaborates on the specific ways of using graph neural networks, reinforcement learning frameworks, and federated learning mechanisms in the process of constructing a user behavior model, and its role is to more efficiently and accurately process and analyze multi-source heterogeneous data and improve the performance of the risk assessment model.
[0061] When building a user behavior model, a graph neural network is used to model the heterogeneous relationship topology of users-devices-environments. Taking the behavior data of users on an Internet insurance platform as an example, users, the devices they use, and the network environments they are in are regarded as nodes in the graph, and the interaction relationships between them are regarded as edges. For example, when a user performs an insurance purchase operation on a certain device, information such as the model and operating system version of the device, as well as the network location (reflected by the IP address) and network latency when the user operates, all constitute the connection relationships between the nodes. Through the node embedding and graph convolution operations of the graph neural network, these complex heterogeneous relationships can be transformed into feature representations that can be used for risk assessment, enabling the model to capture the correlation information between different elements and thus more comprehensively evaluate user risks.
[0062] A reinforcement learning framework is adopted to dynamically optimize the feature extraction path. When facing a large amount of multi-source heterogeneous data, how to select the most effective features for risk assessment is a key issue. The reinforcement learning framework sets an agent, whose task is to explore the optimal feature extraction path in different data feature spaces. For example, the agent can try different combinations of features, and after each try, obtain a reward value according to the performance feedback (such as accuracy, recall rate, etc.) of the risk assessment model. Through continuous exploration and learning, the agent gradually finds the optimal feature extraction strategy, thereby improving the efficiency and accuracy of the risk assessment model.
[0063] A federated learning mechanism is integrated to update local behavior features distributively. In actual application scenarios, user data may be scattered and stored in different institutions or platforms. To protect data privacy and make full use of the data of all parties, a federated learning mechanism is adopted. For example, multiple insurance companies or data partners each have a part of the behavior data of users. These data are not directly shared, but local model training is carried out using federated learning algorithms to update the local behavior feature model. Then, all parties upload the model parameters to the central server for aggregation through encrypted communication, and the central server then distributes the aggregated parameters to each participating party, enabling all parties to optimize their risk assessment models using more user data without revealing the local data privacy, and further improving the generalization ability and accuracy of the model.
[0064] Example 2:
[0065] This example details the specific operations of capturing device hardware fingerprints, filtering IP address jumps, and quantifying connection stability during the integration process of environmental context data.
[0066] Real-time capture of device hardware fingerprints through lightweight sandbox containers. When a user accesses the Internet insurance platform, a lightweight sandbox container is launched on the user's device. Without affecting the normal operation of the device, this container can safely collect the device's hardware information, such as the CPU model, memory size, hard disk serial number, etc. These hardware information constitute the device hardware fingerprint, which is an important identifier for identifying the user's device. Due to the isolation characteristics of the sandbox container, it can avoid security threats to the user's device while ensuring the accuracy and real-time nature of the obtained hardware fingerprint data.
[0067] Use time series anomaly detection algorithms to filter out instantaneous jumps in IP addresses. IP addresses are an important basis for judging the user's network environment, but IP addresses may experience instantaneous jumps, which may interfere with the accuracy of risk assessment. For example, in some areas with unstable network environments, the user's IP address may change frequently. By adopting time series anomaly detection algorithms, the changes in the user's IP address are monitored in real time. This algorithm analyzes the change trend of the IP address over a period of time and sets reasonable thresholds. When the change in the IP address exceeds the threshold range, it is determined as an abnormal jump, and these abnormal data are filtered out to ensure the stability and reliability of the IP address data used for risk assessment.
[0068] Map the network delay metric to a spatial distribution matrix to quantify connection stability. Network delay is an important metric for measuring the quality of network connections. Different network delay situations reflect the differences in the stability of the user's network connection. To more intuitively quantify this stability, the network delay metric is mapped to a spatial distribution matrix. For example, the network delay is divided into multiple intervals according to different magnitudes, and each interval corresponds to a region in the spatial distribution matrix. When the detected network delay of the user is in a certain interval, a mark or value is assigned in the corresponding region. In this way, the network delay is transformed into a visual spatial distribution matrix, which is convenient for more intuitively analyzing and evaluating the stability of the user's network connection and providing more detailed network environment information for risk assessment.
[0069] Example 3:
[0070] In the dynamic risk assessment strategy, the adjustment formula for the gradient-driven strategy is:
[0071]
[0072] Where, is the premium adjustment gradient at time t, η is the learning rate, L is the risk loss function, ω is the model parameter, is the partial derivative of the risk loss function L with respect to the model parameter ω, R(t) is the dynamic risk score, λ is the hedging intensity factor, D(t) is the historical claim density, and sigmoid and ReLU represent activation functions.
[0073] In practical applications, first, the dynamic risk score R(t) and the historical claim density D(t) are calculated according to the risk prediction model. The risk loss function L reflects the difference between the predicted risk of the model and the actual risk. By taking the partial derivative of the model parameter ω it is possible to understand the degree of influence of changes in model parameters on the risk loss. The learning rate η controls the update step of the premium adjustment gradient, avoiding the adjustment process being too aggressive or too slow.
[0074] For example, when the dynamic risk score R(t) is high, the value of sigmoid(R(t)) will approach 1. At this time this term will increase, indicating that a large adjustment of the premium needs to be made according to the gradient information of the model parameters. At the same time, if the historical claim density D(t) is also high, ReLU(D(t)) will output a positive value, and the term λ·ReLU(D(t)) will also affect the premium adjustment gradient. The hedging intensity factor λ determines the degree of influence of the historical claim density on the premium adjustment. By comprehensively considering these factors, the premium adjustment gradient is calculated using this formula and then the premium coefficient and underwriting conditions are non-linearly adjusted to achieve real-time risk hedging. For example, when the calculated premium adjustment gradient is positive and large, the premium coefficient can be appropriately increased, or the underwriting conditions can be tightened to reduce the risk faced by the insurance company.
[0075] Example 4:
[0076] This example elaborates in detail the specific operations of data collection, feature enhancement, adversarial training, and model fusion during the training process of the risk prediction model. Its role is to improve the accuracy and robustness of the risk prediction model, enabling it to more accurately evaluate user risks. The specific steps include:
[0077] Data collection: Extract 100,000 user behavior trajectories from the logs of the insurance application platform. Each trajectory includes a time-series action chain, a device fingerprint hash, and an environmental context snapshot. The logs of the insurance application platform record various operation behaviors of users on the platform, such as page browsing, button clicking, form filling, etc. These behaviors form a time-series action chain in chronological order. The device fingerprint hash is used to uniquely identify the device used by the user, and the environmental context snapshot records environmental information such as the device model, operating system version, and IP address when the user operates. By collecting a large amount of user behavior trajectory data, it provides rich samples for subsequent model training.
[0078] Feature Enhancement: Perform piecewise Fourier transform on the page dwell time to capture periodic patterns. The page dwell time is an important feature reflecting user behavior intentions. There may be certain periodic patterns in the dwell times of different users on different pages. For example, some users browse the insurance platform at fixed time periods every day, and the dwell times on some key pages are similar. Through piecewise Fourier transform, converting the page dwell time data from the time domain to the frequency domain can more clearly discover these periodic patterns, providing more valuable information for risk assessment. Apply kernel density estimation to the click heatmap distribution to generate a spatial probability density field. The click heatmap distribution shows the click positions of users on the page. Kernel density estimation is a non-parametric estimation method. By performing kernel density estimation on the click points in the click heatmap, a spatial probability density field can be generated. This density field can more accurately describe the distribution of user click behavior in the page space, helping the model better understand user behavior preferences and intentions, thereby improving the accuracy of risk assessment.
[0079] Adversarial Training: Introduce a generative adversarial network to synthesize high-risk adversarial samples to enhance model robustness. Construct a discriminator network to distinguish real behavior sequences from synthetic sequences; the generator network adopts a sequence generation structure with gated recurrent units and optimizes the adversarial loss function through policy gradient algorithms. A generative adversarial network consists of a generator and a discriminator. The task of the generator is to synthesize high-risk adversarial samples that simulate real high-risk user behavior sequences. The discriminator is responsible for distinguishing real behavior sequences from those synthesized by the generator. The generator adopts a sequence generation structure with gated recurrent units, which can better handle time series data and generate more realistic adversarial samples. By optimizing the adversarial loss function through policy gradient algorithms, the performance of the generator and discriminator gradually improves during the continuous confrontation process. When training the risk prediction model, input the generated adversarial samples together with real samples into the model for training. This allows the model to learn how to identify and handle various potential risk situations, improving the model's robustness and generalization ability.
[0080] Model Fusion: Perform multi-head cross-attention fusion on the attention weights of the Transformer encoder and the output of the temporal convolutional network to generate the final risk score. The Transformer encoder can capture long-sequence dependencies in the data through the attention mechanism, while the temporal convolutional network is good at dealing with local features in time-series data. Performing multi-head cross-attention fusion on the outputs of both can make full use of the advantages of the two models. For example, the attention weights of the Transformer encoder can help the model focus on the important associations between behavioral features at different time points, and the output of the temporal convolutional network provides more detailed local feature information. Through the multi-head cross-attention mechanism, these information are fused and weighted to finally generate a more accurate risk score and improve the performance of the risk prediction model.
[0081] Example 5:
[0082] In terms of real-time feedback and model optimization, differential privacy technology is used to inject noise into the post-insurance behavior data. After insurance, the behavioral change data and claim event labels of users are collected, and these data contain sensitive information of users. To protect user privacy, differential privacy technology is adopted. In the data collection stage, appropriate noise is added to the original data so that the true behavioral information of a single user cannot be accurately inferred from the processed data. For example, for the claim amount data of users, within the premise of not affecting the overall data distribution characteristics, random noise within a certain range is added. In this way, even if the data is leaked, it is difficult for attackers to obtain the true claim situation of users from the data interfered by noise, thus protecting user privacy.
[0083] Compress the incremental data into lightweight feature representations through online knowledge distillation to update the parameters of the edge nodes of the risk prediction model. As time goes by, new post-insurance user behavior data is continuously generated. To timely use these new data for model optimization, online knowledge distillation technology is adopted. The newly generated incremental data is processed through a specific algorithm and compressed into lightweight feature representations. These lightweight feature representations not only retain the key information of the data but also reduce the data volume. Then, use these lightweight feature representations to update the parameters of the edge nodes of the risk prediction model. For example, in a distributed risk assessment system, each edge node can generate lightweight feature representations using the incremental data collected locally and upload them to the central server for model parameter update, or directly update the model parameters of the edge nodes locally, enabling the model to adapt to new data changes in a timely manner and improve the accuracy of risk assessment.
[0084] In terms of the data security layer, the homomorphic encryption algorithm is applied to perform encrypted calculations on sensitive fields during the feature extraction stage. When processing users' sensitive data, such as personal identity information, financial data, etc., the homomorphic encryption algorithm is used. Homomorphic encryption allows specific calculations to be performed on ciphertext, and the calculation results after decryption are the same as those obtained by performing the same calculations on plaintext. For example, when calculating the user's risk correlation coefficient, if it involves sensitive behavioral feature data, such as transaction amounts, etc., these data are first homomorphically encrypted, then calculations are performed in the ciphertext state, and finally the calculation results are decrypted to obtain the final risk correlation coefficient. In this way, during the entire calculation process, the sensitive data always remains encrypted. Even if the data is stolen during transmission or storage, attackers cannot obtain the true content of the data.
[0085] In the risk assessment stage, the secure multi-party computation (MPC) protocol is adopted to achieve the privacy fusion of cross-institutional data. In actual insurance operations, it may be necessary to jointly assess risks using data from multiple institutions, such as when an insurance company cooperates with a third-party data provider. To protect the data privacy of all parties, the secure multi-party computation protocol is used. Without disclosing their local data, all parties jointly complete the risk assessment task through secure encrypted communication and collaborative computing methods. For example, an insurance company has the user's insurance history data, and a third-party data provider has the user's credit data. The two parties use the secure multi-party computation protocol to process and fuse their respective data in the encrypted state, calculate the final risk score, without disclosing the original data of any party, ensuring the security and privacy of the data.
[0086] In addition, the triggering conditions for the dynamic risk assessment strategy include: when the risk score exceeds the adaptive threshold τ(t), the real-time premium floating mechanism is activated. The calculation formula for the threshold τ(t) is:
[0087]
[0088] where μ is the mean of the historical risk scores, σ is the dynamic standard deviation scaling factor, N is the number of samples within the sliding time window, and R k (t - 1) is the dynamic risk score at the kth historical moment within the time window. In practical applications, the mean μ and the dynamic standard deviation scaling factor σ are calculated based on the historical risk score data, and combined with the number of samples N within the sliding time window and the dynamic risk scores R k (t - 1) at each historical moment, the adaptive threshold τ(t) is calculated. When the risk score obtained through real-time calculation exceeds this threshold, the real-time premium floating mechanism is activated, and the premium coefficient and underwriting conditions are adjusted accordingly to cope with different risk situations.
[0089] The present invention also includes a system for identifying user risks based on Internet insurance applications. The system includes:
[0090] User Behavior Modeling Module: It is used to build a user behavior model, integrate multi-source heterogeneous data to build a high-fidelity risk assessment model, integrate online behavior data, device fingerprint data, and social network data, and generate behavior feature vectors and risk correlation coefficients. The multi-source heterogeneous data covers browsing history, transaction frequency, geographical location offset, and network latency metrics;
[0091] Multi-dimensional Risk Prediction Module: Build a risk prediction model, receive real-time behavior sequences and environmental context data as inputs, and obtain dynamic risk scores. The real-time behavior sequences include page stay duration, click heatmap distribution, and the number of form filling anomalies. The environmental context data includes device model, operating system version, and IP reputation rating;
[0092] Dynamic Risk Assessment Strategy Module: According to the dynamic risk scores output by the risk prediction model, implement a gradient-driven strategy to non-linearly adjust the premium coefficient and underwriting conditions to achieve real-time risk hedging;
[0093] Real-time Feedback and Optimization Module: Asynchronously collect post-insurance user behavior change data and claim event tags for real-time feedback and model optimization of the system;
[0094] Among them, the formula for the risk correlation coefficient is:
[0095]
[0096] Among them, γ(t) is the risk correlation coefficient at time t, α i is the weight of the i-th type of behavior feature, ΔB i (t) is the time-series fluctuation of feature i, Θ(t) is the environmental stability factor, β is the attenuation coefficient of the device fingerprint, and φ(t) is the social network correlation degree.
[0097] The implementation method of this system refers to the above-mentioned embodiments and will not be elaborated in the specification.
[0098] It should be noted that in this article, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "include", "comprise", or any other variant thereof are intended to cover non-exclusive inclusion, so that a process, method, article, or device including a series of elements not only includes those elements, but also includes other elements not expressly listed, or also includes elements inherent to such process, method, article, or device.
[0099] Although embodiments of the present invention have been shown and described, it will be understood by those of ordinary skill in the art that various changes, modifications, substitutions and variations can be made to these embodiments without departing from the principles and spirit of the present invention, and the scope of the present invention is defined by the appended claims and their equivalents.
Claims
1. A method for identifying user risks based on Internet insurance application, characterized in that, Including: Construct a user behavior model, including a high-fidelity risk assessment model that integrates multi-source heterogeneous data; the user behavior model integrates online behavior data, device fingerprint data, and social network data to generate behavior feature vectors and risk correlation coefficients; the multi-source heterogeneous data includes browsing history, transaction frequency, geographical location offset, and network latency metrics; Perform multi-dimensional risk prediction, including constructing a risk prediction model, and obtaining a dynamic risk score by inputting real-time behavior sequences and environmental context data into the risk prediction model; the real-time behavior sequences include page stay duration, click heatmap distribution, and the number of form filling anomalies; The environmental context data includes device model, operating system version, and IP reputation rating; Set a dynamic risk assessment strategy, including implementing a gradient-driven strategy according to the dynamic risk score output by the risk prediction model; the gradient-driven strategy includes non-linearly adjusting premium coefficients and underwriting conditions to achieve real-time risk hedging; Perform real-time feedback and model optimization; the real-time feedback includes asynchronously collecting post-insurance user behavior change data and claim event tags; The formula for the risk correlation coefficient is: Among them, γ(t) is the risk correlation coefficient at time t, and α i is the weight of the i-th type of behavioral feature, ΔB i (t) is the temporal fluctuation of feature i, Θ(t) is the environmental stability factor, β is the attenuation coefficient of the device fingerprint, and φ(t) is the social network correlation degree.
2. The method for identifying user risks based on Internet insurance application according to claim 1, characterized in that The construction of the user behavior model includes: using a graph neural network to model the heterogeneous relationship topology of user-device-environment; adopting a reinforcement learning framework to dynamically optimize the feature extraction path; integrating a federated learning mechanism to distributively update local behavior features.
3. A method for identifying user risks based on Internet insurance application according to claim 1, characterized in that, The integration of the environmental context data includes: real-time capturing device hardware fingerprints through a lightweight sandbox container; using a time series anomaly detection algorithm to filter instantaneous jumps of IP addresses; mapping network latency metrics into a spatial distribution matrix to quantify connection stability.
4. A method for identifying user risks based on Internet insurance application according to claim 1, characterized in that, The adjustment formula for the gradient-driven strategy is: Among them, is the premium adjustment gradient at time t, η is the learning rate, L is the risk loss function, ω is the model parameter, is the partial derivative of the risk loss function L with respect to the model parameter ω, R(t) is the dynamic risk score, λ is the hedging intensity factor, D(t) is the historical claim density, and sigmoid and ReLU represent activation functions.
5. A method for identifying user risks based on Internet insurance application according to claim 1, characterized in that The training process of the risk prediction model includes: Data collection: Extract 100,000 user behavior trajectories from the insured platform logs, each trajectory containing a time series action chain, device fingerprint hash, and environmental context snapshot; Feature enhancement: Perform piecewise Fourier transform on the page stay duration to capture periodic patterns; apply kernel density estimation to the click heatmap distribution to generate a spatial probability density field; Adversarial training: Introduce a generative adversarial network to synthesize high-risk adversarial samples to improve model robustness; Model fusion: Perform multi-head cross-attention fusion on the attention weights of the Transformer encoder and the output of the temporal convolutional network to generate the final risk score.
6. The method for identifying user risks based on Internet insurance application according to claim 5, characterized in that The adversarial training includes: constructing a discriminator network to distinguish real behavior sequences from synthetic sequences; the generator network adopts a sequence generation structure with gated recurrent units and optimizes the adversarial loss function through a policy gradient algorithm.
7. A method for identifying user risks based on Internet insurance application according to claim 1, characterized in that The real-time feedback and model optimization include: injecting noise into post-insurance behavior data using differential privacy technology; compressing incremental data into a lightweight feature representation through online knowledge distillation to update the edge node parameters of the risk prediction model.
8. A method for identifying user risks based on Internet insurance application according to claim 1, characterized in that, The method further includes a data security layer: applying a homomorphic encryption algorithm to perform encrypted state calculations on sensitive fields during the feature extraction stage; adopting a secure multi-party computation (MPC) protocol to achieve privacy fusion of cross-institutional data during the risk assessment stage.
9. The method for identifying user risks based on Internet insurance application according to claim 1, wherein The triggering conditions of the dynamic risk assessment strategy include: when the risk score exceeds the adaptive threshold τ(t), the real-time premium floating mechanism is activated; the calculation formula of the threshold τ(t) is: where μ is the mean of historical risk scores, σ is the dynamic standard deviation scaling factor, N is the number of samples within the sliding time window, and R k (t - 1) is the dynamic risk score at the k-th historical moment within the time window.
10. A system for identifying user risks based on Internet insurance applications, characterized in that, including: User behavior modeling module: used to build a user behavior model, integrate multi-source heterogeneous data to build a high-fidelity risk assessment model, integrate online behavior data, device fingerprint data and social network data, and generate behavior feature vectors and risk correlation coefficients, where the multi-source heterogeneous data covers browsing history, transaction frequency, geographical location offset and network latency metrics; Multi-dimensional risk prediction module: build a risk prediction model, receive real-time behavior sequences and environmental context data as inputs, and obtain dynamic risk scores. The real-time behavior sequences include page residence time, click heat map distribution and form filling anomaly times, and the environmental context data includes device model, operating system version and IP reputation rating; Dynamic risk assessment strategy module: implement a gradient-driven strategy based on the dynamic risk scores output by the risk prediction model, and perform non-linear adjustment on the premium coefficient and underwriting conditions to achieve real-time risk hedging; Real-time feedback and optimization module: asynchronously collect post-insurance user behavior change data and claim event tags for real-time feedback and model optimization of the system; wherein, the formula of the risk correlation coefficient is: Among them, γ(t) is the risk correlation coefficient at time t, and α i is the weight of the i-th type of behavioral feature, and ΔB i (t) is the time-series fluctuation amount of feature i, Θ(t) is the environmental stability factor, β is the attenuation coefficient of the device fingerprint, and φ(t) is the social network correlation degree.
Citation Information
Cited By
Security insurance data interaction sharing management method based on supervision cooperation
CN120725626A
Customer identification and dynamic supervision analysis system and method based on intelligent agent
CN121010380A
Operation background management method and management system
CN121580163A