Telecommunication network fraud case investigation training system and method based on virtual reality

By building a telecommunications network fraud case investigation and training system based on virtual reality, the problem of single cases and incomplete processes in the existing technology is solved, and rich interaction methods and scoring mechanisms are provided, which improves the practicality and effectiveness of the training system.

CN120356375APending Publication Date: 2025-07-22HANGZHOU TONGPENG INTELLIGENT TECH
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
CN202510490644.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-18
Publication Date
2025-07-22

AI Technical Summary

Technical Problem

The existing telecommunications network fraud case investigation and training system has a single scenario case and incomplete process, which cannot meet the actual training needs.

Method used

A telecommunications network fraud case investigation training system based on virtual reality is designed, including server and database modules, teacher-side modules and student-side modules. Virtual scenes and case situations are constructed through graphical editing tools, and natural language processing and decision tree models are used to assist training, providing rich interaction methods and scoring mechanisms.

Benefits of technology

It realizes diversified training scenarios and complete processes, enhances the interaction and pertinence of training, improves the learning effect, and meets the needs of actual reconnaissance training.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120356375A_ABST
    Figure CN120356375A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of police tactical training, and particularly discloses a telecommunication network fraud case investigation training system based on virtual reality, which comprises a server and database module, a teacher end module, a scene editing unit, a case editing unit, a data management and publishing unit, a student end module and a case receiving and displaying unit, the system comprises a scene reconnaissance unit, a dialogue simulation unit, a virtual platform unit, a simulation process unit, an event progress unit and a training data recording unit. Through the teacher end module, a teacher autonomously edits a scene and a case, the editing mode is simple and efficient, a plurality of cases for training can be quickly created, the whole process of training is perfected, the problems of single scene case, incomplete process and the like in the prior art are solved, and actual training requirements are met.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of case investigation training, and particularly relates to a telecommunication network fraud case investigation training system and method based on virtual reality. Background Art

[0002] A patent with the Chinese patent application number CN2023110560013 discloses a telecommunication anti-fraud model training method, device, equipment, and storage medium. The method includes: reading real user data of the local edge telecommunication node; generating synthetic data based on the real user data, where the synthetic data is similar to the real user data but does not contain real user data; and sending the synthetic data to a joint training node for training a first anti-fraud model by the joint training node.

[0003] With the development of computer technology, virtual reality training systems are increasingly widely used. However, existing telecommunication network fraud case investigation training systems have problems such as single scene cases and incomplete processes, and cannot meet actual training needs. Summary of the Invention

[0004] In order to solve the problems of single scene cases and incomplete processes in the prior art, the present invention proposes a telecommunication network fraud case investigation training system and method based on virtual reality to enrich the investigation training scenarios and processes of telecommunication network fraud cases.

[0005] The first technical solution of the present invention: A telecommunication network fraud case investigation training system based on virtual reality includes: A server and database module, which is used to build a server architecture and store and manage system operation data; A teacher terminal module, which includes: A scene editing unit, which is used to construct a virtual scene; A case situation editing unit, which is used to edit case situation information, the identity, appearance, and behavioral characteristics of character models, as well as communication information, transfer information, and evidence information, predict the development direction of the case situation information, generate a case situation development event tree, construct a virtual case situation, and set investigation standards and processes in the virtual case situation; A data management and publishing unit, which is used to sort and classify the virtual scene and virtual case situation and store them in the server and database module; A student terminal module, which includes: A case situation receiving and displaying unit, which is used to receive the virtual scene and virtual case situation from the server and database module, load the virtual scene in a virtual reality environment, and generate an operation interface; A scene investigation unit, which is used to interact with the virtual scene through actions; A dialogue simulation unit, which is used to simulate scene dialogues; A virtual platform unit, which constructs a virtual network platform based on the virtual case situation, generates virtual social information and transfer records; A simulation process unit, which generates evidence options based on the virtual case situation, compares the evidence options with the evidence information, and judges and generates case progress data; An event progress unit, which generates a virtual arrest scene and a virtual interrogation scene according to the case progress data; A training data recording unit, which is used to record operation data, score the operation data, and generate a score report.

[0006] Preferably, the scene editing unit is used to generate a graphical editing interface, import scene models, exhibit models, character models, and prop models, construct a virtual scene, and perform layout design on the virtual scene, and set the position, angle, and size parameters of the models in the scene.

[0007] Preferably, based on the virtual scene, the scene investigation unit generates scene investigation options, binds action interaction scripts, and according to the scene investigation options, interacts with the scene models in the virtual scene and feeds back the attribute information of the exhibit models.

[0008] Preferably, based on the virtual case situation, the dialogue simulation unit configures a language processing model, generates a text input box, understands the text content in the text input box, and generates a reply text.

[0009] The present invention is developed based on the Unity development engine. By building a server architecture, a database management system is used to store and manage various types of data generated during the operation of the system, including virtual scene data, case information, student operation data, etc.

[0010] Using graphical editing technology, models such as scenes, exhibits, characters, and props are imported through the 3D modeling software interface, and the virtual scene is laid out using graphical interface tools, and the position, angle, and size parameters of the models are set.

[0011] Using text editing tools to edit case information, defining the identity, appearance, behavior characteristics, etc. of the character models through character attribute setting tools, integrating information such as communication, transfer, and evidence, and using the event tree generation algorithm to predict the development direction of the case and construct an event tree for the development of the case.

[0012] Sort and classify virtual scenarios and virtual case data according to the set classification rules, and use database operation instructions to store the data in the server and database module.

[0013] Obtain virtual scenario and virtual case data from the server and database module through network communication technology, load the virtual scenario using a virtual reality engine, and generate an operation interface based on graphical user interface technology.

[0014] Based on virtual reality interaction technology, generate interactive investigation options in the virtual scenario, write action interaction scripts to achieve interaction with the scene model, and feedback the attribute information of the exhibit model through the model data interface.

[0015] Configure a natural language processing language model, obtain the text input by the student using a text input box, perform semantic analysis and understanding on the text through the model, and generate a reply text.

[0016] Construct a virtual network platform according to the virtual case, and use data generation algorithms to generate virtual social information and transfer records.

[0017] Generate evidence options according to the virtual case, compare the evidence options with the evidence information stored in the database through a data comparison algorithm, and judge and generate case progress data.

[0018] According to the case progress data, use animation generation technology to generate virtual arrest scenes and virtual interrogation scenes.

[0019] Record the operation data of the student during the training process through logging technology, and use data analysis algorithms to score the operation data and generate a score report.

[0020] Preferably, the teacher end module includes a case template unit, and the case template unit creates case templates and constructs a case template library; the case templates include scene settings, character relationships, case clues, and evidence distribution.

[0021] The present invention provides editing tools such as a graphical interface and a text editing box, allowing teachers to independently design elements such as scene settings, character relationships, case clues, and evidence distribution.

[0022] Preferably, the student end module includes an auxiliary prompt unit, and the auxiliary prompt unit generates a prompt interface based on investigation standards and processes at preset time intervals.

[0023] The present invention pre-combs and stores the investigation standards and processes of telecommunications network fraud cases. During the student training process, it monitors the operations of students in real time and uses timer technology to set an adjustable time interval parameter in the student-side software. When the student starts training, the timer is activated and sends inspection instructions to the system at the preset time interval to determine whether the conditions for generating a prompt are met. If so, it calls the interface generation technology to create and display a prompt interface.

[0024] Preferably, the student-side module includes a virtual prop unit. The virtual prop unit generates a virtual usage interface of the prop based on the prop model. The prop model includes a network monitoring device, a data analysis device, and a forensics tool, and feeds back the operation result according to the operation information of the virtual usage interface.

[0025] The present invention uses 3D modeling technology to construct prop models such as network monitoring devices, data analysis devices, and forensics tools, and imports the models into a virtual reality development environment. Through graphical user interface development technology, according to the functions and usage logics of the props, it designs and generates corresponding virtual usage interfaces. For example, for a network monitoring device, it designs an interface containing elements such as a signal strength display area and a monitoring range setting area; for a data analysis device, it constructs functional areas such as data import, analysis method selection, and result display.

[0026] The present invention sets up interaction event monitoring on the virtual usage interface. When a student performs operations such as clicking and swiping, the system captures the operation information, generates a corresponding operation result, and feeds it back to the student through the virtual reality interface. For example, when a student adjusts the monitoring range on the virtual usage interface of the network monitoring device, the system calculates the new monitoring range according to the adjustment parameters and updates the area displaying the signal strength on the interface to show the signal conditions within the new range.

[0027] Preferably, the investigation training system includes a case library module. The case library module is used to establish a case library of telecommunications network fraud cases, set the common decision points in the telecommunications network fraud cases, and establish a decision tree.

[0028] The present invention collects various types of telecommunications network fraud cases, organizes and classifies the cases, and stores the case data in a database after structured processing to form a case library. It analyzes the characteristics and detection processes of different types of telecommunications network fraud cases, finds out the common decision points among them, such as judging the reliability of fraud clues and selecting appropriate investigation directions. Using the decision tree algorithm, with the decision points as nodes and branching according to different decision results, it constructs a decision tree model for assisting investigation training and case analysis.

[0029] Preferably, the common decision points in the telecommunications network fraud cases are extracted from the case library. The decision point information includes suspicious calls, suspicious links, and suspicious information. A decision point information dataset is established, and binary variables are used to encode the categorical features in the decision point information dataset to obtain the numerical features of the categories. The mean of the numerical features is calculated. The formula is as follows:

[0030]

[0031] In the formula, represents the i-th numerical feature of the k-th sample under category j; represents the mean of the numerical features; represents the centralized data of the numerical features; represents the number of samples under category j. The sample refers to the decision point information; Substitute the centralized data into the decision point information dataset for centralized processing to obtain a centralized dataset, and calculate the covariance between the numerical features. The formula is as follows:

[0032] In the formula, represents the numerical feature after centralization of the m-th numerical value under category i, represents the mean of the m-th numerical feature under category i, represents the number of samples under category i; represents the numerical feature after centralization of the n-th numerical value under category i, represents the mean of the n-th numerical feature under category i, represents the covariance between the m-th numerical feature and the n-th numerical feature in category i; Calculate the Pearson correlation coefficient. The formula is as follows:

[0033] In the formula, represents the Pearson correlation coefficient; represents the standard deviation of the m-th numerical feature under category i. The represents the standard deviation of the m-th numerical feature under category i; Create a Pearson correlation coefficient matrix, which is expressed as follows:

[0034] Among them, each element in the Pearson correlation coefficient matrix represents the Pearson correlation coefficient between a pair of features, and the value of each element ranges from -1 to +1; and the absolute value of the element 0.7 in the Pearson correlation coefficient matrix is selected as the common decision point.

[0035] The present invention extracts decision point information related to suspicious calls, suspicious links, and suspicious information from the case base and organizes it into a structured decision point information data set. This data set contains various types of feature data related to telecommunications network fraud. Binary variables are used to encode the categorical features in the decision point information data set, converting non-numerical categorical data into a numerical form that is easy for a computer to process. Through operations such as calculating the mean and centering the data, the data is preprocessed to prepare for further analysis of the relationships between the data.

[0036] Preferably, the calculation formula for the standard deviation is as follows,

[0037]

[0038] In the formula, represents the standard deviation of the m-th numerical feature under category i, and the represents the standard deviation of the n-th numerical feature under category i.

[0039] In the present invention, the standard deviation is used to measure the fluctuation of the numerical features of each category in the decision point information data set. When calculating the Pearson correlation coefficient, the standard deviation is used to standardize the covariance, making the correlations between different features comparable. By calculating the standard deviations of the numerical features of each category, it participates in the construction process of the Pearson correlation coefficient matrix, thereby assisting in determining the common decision points.

[0040] Preferably, the Pearson correlation coefficient matrix is a symmetric matrix, denoted as , and the elements on the main diagonal of the symmetric matrix are 1.

[0041] The present invention can observe the correlation from the perspective of any two numerical features without distinguishing the order.

[0042] Preferably, for predicting the development direction of the case information, the probability of an event occurring is analyzed based on the following formula,

[0043] In the formula, x represents the input vector, including call records and transaction records; w represents the weight vector, indicating the importance of call records and transaction records, b represents the bias term, and p(y = 1|x) represents the probability prediction of the positive class.

[0044] The present invention uses a linear combination method to analyze the influence of numerical features on the probability of an event occurring.

[0045] Preferably, the training data recording unit scores the operation data as follows, Establish an evaluation matrix , denoted as,

[0046] wherein, represents the original score of the m-th user on the k-th index; Perform an exponential transformation on the original scores of the users in the evaluation matrix to obtain the transformed evaluation matrix , denoted as,

[0047] wherein, represents the value after the exponential transformation of the original score of the m-th user on the k-th index; Based on the normalization formula, perform normalization processing on the transformed evaluation matrix to obtain the normalized scores of the users in the evaluation matrix , and the normalization formula is denoted as,

[0048] wherein, represents the normalized score of the m-th user on the k-th index; Establish a normalized evaluation matrix R, denoted as,

[0049] Establish a weight matrix W, denoted as

[0050]

[0051] wherein, represents the preset weight value on the k-th index; Based on the normalized evaluation matrix R and the weight matrix W, calculate the weighted comprehensive score of the user, and the formula is as follows,

[0052] wherein, S m is the weighted comprehensive score of the m-th user and serves as the operation score of the user.

[0053] In the present invention, the exponential transformation effectively amplifies the differences between the original scores, enabling users with similar performances on certain metrics to have more distinct scores after transformation. For example, in terms of the action accuracy metric, the original scores of two users are 80 points and 85 points respectively, with an insignificant difference. However, after the exponential transformation, the score gap may be enlarged, more accurately reflecting the actual performance differences between them on this metric, and thus more precisely reflecting the level differences between users in the final scoring. The normalization process makes the scores of different metrics comparable. During training, the dimensions of metrics such as action completion time and dialogue rationality are different. Directly calculating scores would lead to unreasonable results. Through normalization, the scores of all metrics are unified into the interval [0, 1], eliminating the influence of dimensions, ensuring that each metric can play a fair role in scoring, and improving the scientific nature of scoring. The setting of the weight matrix can highlight the importance of metrics according to the training focus. Based on this scoring rule, it is possible to further analyze the correlations between different metrics, the performance differences of users in different scenarios, etc. based on the scoring data of a large number of users. For example, if it is found through data analysis that users generally score low on a certain metric in a certain scenario, the training content can be optimized or the scoring rule can be adjusted accordingly, thereby continuously improving the quality and effect of the training system and better meeting the training requirements.

[0054] The second technical solution of the present invention: A method for investigating and training telecommunications network fraud cases based on virtual reality, including the following steps, (S01) The teacher uses the teacher - end module to import and create model data, arrange scenes, exhibits, and characters, set character information, communication information, and transfer information, construct a virtual scene and a virtual case situation, store the virtual scene and the virtual case situation after editing, and publish them to the student - end module; (S02) The student receives the virtual scene and the virtual case situation at the student - end, wears the hardware device, and enters the virtual scene; (S03) The student conducts an investigation of the virtual scene, including opening the door, searching the room, and inspecting items; (S04) The student observes, measures, and detects the exhibit models in the virtual scene to obtain the attribute information of the exhibit models; (S05) The student conducts a simulated conversation with the character models in the virtual scene, inputs the conversation text into the text input box, and obtains the reply text; (S06) The student logs in to the virtual network platform to search for virtual social information and transfer records; (S07) The student holds a case analysis meeting to discuss based on the information collected, selects evidence options, and obtains case progress data; (S08) The student enters the virtual arrest scene, watches the virtual arrest scene and the virtual interrogation scene, and ends the training; (S09) Score the operation data of the students to generate a score report.

[0055] The present invention has the following beneficial effects: (1) Through the teacher terminal module, the teacher can independently edit the scenario and the case situation. The editing method is simple and efficient, and can quickly create multiple cases for training and improve the overall training process, solving the problems of single scenario cases and incomplete processes in the prior art, and meeting the actual training needs.

[0056] (2) Through the student terminal module, students can interact with the virtual scenario in various ways, such as scene investigation, evidence detection, character dialogue, virtual platform operation, etc., obtain rich information and promote the progress of the case, enhancing the interactivity and pertinence of the training and improving the learning effect.

[0057] (3) Through the enrichment and optimization of the case library, a large number of up-to-date cases are provided for investigation training. At the same time, with the assistance of the decision tree model for analysis, it helps students better understand and master the investigation ideas and methods. BRIEF DESCRIPTION OF THE DRAWINGS

[0058] Figure 1 is a schematic diagram of the overall structure of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0059] The present invention will be further described below in conjunction with the drawings and embodiments, but it shall not be used as a basis for limiting the present invention.

[0060] The investigation training system for telecommunications network fraud cases based on virtual reality, as Figure 1 shown, includes, The server and database module, which is used to build the server architecture and store and manage the system operation data; The teacher terminal module, which includes, The scene editing unit, which is used to construct a virtual scene; The case situation editing unit, which is used to edit the case situation information, the identity, appearance, and behavior characteristics of the character model, as well as the communication information, transfer information, and evidence information, and predict the development direction of the case situation information, generate an event tree for the development of the case situation, construct a virtual case situation, and set the investigation standards and processes in the virtual case situation; The data management and publishing unit, which is used to organize and classify the virtual scene and the virtual case situation and store them in the server and database module; The student terminal module, which includes, Case Receiving and Display Unit. The Case Receiving and Display Unit is used to receive virtual scenarios and virtual cases from the server and database module, load the virtual scenarios in the virtual reality environment, and generate an operation interface; Scene Investigation Unit. The Scene Investigation Unit is used to perform action interactions with the virtual scenario; Dialogue Simulation Unit. The Dialogue Simulation Unit is used to simulate scene dialogues; Virtual Platform Unit. The Virtual Platform Unit constructs a virtual network platform based on the virtual case, and generates virtual social information and transfer records; Simulation Process Unit. The Simulation Process Unit generates evidence options based on the virtual case, compares the evidence options with the evidence information, and judges and generates case progress data; Event Progress Unit. The Event Progress Unit generates virtual arrest scenes and virtual interrogation scenes according to the case progress data; Training Data Recording Unit. The Training Data Recording Unit is used to record operation data, score the operation data, and generate a score report.

[0061] The Scene Editing Unit is used to generate a graphical editing interface, import scene models, exhibit models, character models, and prop models, construct a virtual scene, and perform layout design on the virtual scene, and set the position, angle, and size parameters of the models in the scene.

[0062] Based on the virtual scenario, the Scene Investigation Unit generates scene investigation options, binds action interaction scripts, and according to the scene investigation options, performs action interactions with the scene models in the virtual scenario and feeds back the attribute information of the exhibit models.

[0063] Based on the virtual case, the Dialogue Simulation Unit configures a language processing model, generates a text input box, understands the text content in the text input box, and generates a reply text.

[0064] The teacher - end module includes a case template unit. The case template unit creates case templates and constructs a case template library; the case templates include scene settings, character relationships, case clues, and evidence distribution.

[0065] The student - end module includes an auxiliary prompt unit. The auxiliary prompt unit presets a time interval based on the investigation standards and processes and generates a prompt interface.

[0066] The student - end module includes a virtual prop unit. The virtual prop unit generates a virtual usage interface for props based on prop models. The prop models include network monitoring devices, data analysis devices, and forensic tools, and feed back operation results according to the operation information of the virtual usage interface.

[0067] The investigation training system includes a case library module. The case library module is used to establish a case library of telecommunications network fraud cases, set common decision points in the telecommunications network fraud cases, and establish a decision tree.

[0068] Setting the common decision points in the telecommunications network fraud cases is to extract decision point information from the case library. The decision point information includes suspicious calls, suspicious links, and suspicious information. Establish a decision point information data set, encode the categorical features in the decision point information data set using binary variables, obtain the numerical features of the categories, and calculate the mean of the numerical features. The formula is as follows.

[0069]

[0070] In the formula, represents the i-th numerical feature of the k-th sample under category j; represents the mean of the numerical features; represents the centralized data of the numerical features; represents the number of samples under category j. The sample refers to the decision point information. Substitute the centralized data into the decision point information data set for centralized processing to obtain a centralized data set, and calculate the covariance between the numerical features. The formula is as follows.

[0071] In the formula, represents the numerical feature after centralization of the m-th numerical value under category i, represents the mean of the m-th numerical feature under category i, represents the number of samples under category i; represents the numerical feature after centralization of the n-th numerical value under category i, represents the mean of the n-th numerical feature under category i, represents the covariance between the m-th numerical feature and the n-th numerical feature in category i; Calculate the Pearson correlation coefficient. The formula is as follows.

[0072] In the formula, represents the Pearson correlation coefficient; represents the standard deviation of the m-th numerical feature under category i, represents the standard deviation of the m-th numerical feature under category i; Create a Pearson correlation coefficient matrix, which is expressed as follows.

[0073] Among them, each element in the Pearson correlation coefficient matrix represents the Pearson correlation coefficient between a pair of features, and the value of each element ranges from -1 to +1; and the absolute value of the element 0.7 in the Pearson correlation coefficient matrix is selected as the common decision point.

[0074] The calculation formula of the standard deviation is as follows.

[0075]

[0076] In the formula, represents the standard deviation of the m-th numerical feature under category i. represents the standard deviation of the n-th numerical feature under category i.

[0077] The Pearson correlation coefficient matrix is a symmetric matrix, denoted as and the elements on the main diagonal of the symmetric matrix are 1.

[0078] Predict the development direction of the case information, and analyze the probability of the event occurring based on the following formula.

[0079] In the formula, x represents the input vector, including call records and transaction records; w represents the weight vector, indicating the importance of call records and transaction records, b represents the bias term, and p(y = 1|x) represents the probability prediction of the positive class.

[0080] The training data recording unit scores the operation data as follows. Establish an evaluation matrix denoted as

[0081] Among them, represents the original score of the m-th user on the k-th index. Perform an exponential transformation on the original scores of the users in the evaluation matrix X to obtain the transformed evaluation matrix denoted as

[0082] Among them, represents the value after the exponential transformation of the original score of the m-th user on the k-th index. Based on the normalization formula, perform normalization processing on the transformed evaluation matrix to obtain the normalized scores of the users in the evaluation matrix The normalization formula is denoted as

[0083] Among them, represents the normalized score of the m-th user on the k-th indicator; Establish a normalized evaluation matrix R, expressed as

[0084] Establish a weight matrix W, expressed as

[0085]

[0086] Among them, represents the preset weight value on the k-th indicator; Based on the normalized evaluation matrix R and the weight matrix W, calculate the weighted comprehensive score of the user, and the formula is as follows

[0087] Among them, S m is the weighted comprehensive score of the m-th user and serves as the operation score of the user.

[0088] A virtual reality-based training method for investigating telecommunications network fraud cases includes the following steps (S01) The teacher uses the teacher-side module to import and create model data, arrange scenes, exhibits, and characters, set character information, communication information, and transfer information, construct a virtual scene and a virtual case, store the virtual scene and the virtual case after editing, and publish them to the student-side module; (S02) The student receives the virtual scene and the virtual case on the student side, wears the hardware device, and enters the virtual scene; (S03) The student conducts an investigation of the virtual scene, including opening the door, searching the room, and checking items; (S04) The student observes, measures, and detects the exhibit model in the virtual scene to obtain the attribute information of the exhibit model; (S05) The student conducts a simulated conversation with the character model in the virtual scene, enters the conversation text into the text input box, and obtains the reply text; (S06) The student logs in to the virtual network platform to search for virtual social information and transfer records; (S07) The student holds a case analysis meeting to discuss based on the information collected, selects evidence options, and obtains case progress data; (S08) The student enters the virtual arrest scene, watches the virtual arrest scene and the virtual interrogation scene, and ends the training; (S09) Score the operation data of the student and generate a score report.

[0089] Embodiment 1: A virtual reality-based investigation training system for telecommunications network fraud cases, as Figure 1 shown, includes a server and database module, which is used to build a server architecture and store and manage system operation data; a teacher client module, which includes a scene editing unit, which is used to construct a virtual scene; a case editing unit, which is used to edit case information, the identity, appearance, and behavior characteristics of character models, as well as communication information, transfer information, and evidence information, predict the development direction of case information, generate an event tree for case development, construct a virtual case, and set investigation standards and processes in the virtual case; a data management and publishing unit, which is used to organize and classify the virtual scene and virtual case, and store them in the server and database module; a student client module, which includes a case receiving and displaying unit, which is used to receive the virtual scene and virtual case from the server and database module, load the virtual scene in a virtual reality environment, and generate an operation interface; a scene investigation unit, which is used to perform action interaction with the virtual scene; a dialogue simulation unit, which is used to simulate scene dialogues; a virtual platform unit, which constructs a virtual network platform based on the virtual case and generates virtual social information and transfer records; a simulation process unit, which generates evidence options based on the virtual case, compares the evidence options with the evidence information, judges and generates case progress data; an event progress unit, which generates a virtual arrest scene and a virtual interrogation scene according to the case progress data; a training data recording unit, which is used to record operation data, score the operation data, and generate a score report.

[0090] The scene editing unit is used to generate a graphical editing interface, import scene models, exhibit models, character models, and prop models, construct a virtual scene, and perform layout design on the virtual scene, and set the position, angle, and size parameters of the models in the scene.

[0091] Based on the virtual scene, the scene investigation unit generates scene investigation options, binds action interaction scripts, and performs action interaction with the scene models in the virtual scene according to the scene investigation options, and feeds back the attribute information of the exhibit models.

[0092] The dialogue simulation unit configures a language processing model based on a virtual case scenario, generates a text input box, understands the text content in the text input box, and generates a reply text.

[0093] The teacher - side module includes a case template unit. The case template unit creates case templates and constructs a case template library; the case templates include scene settings, character relationships, case clues, and evidence distribution.

[0094] The student - side module includes an auxiliary prompt unit. The auxiliary prompt unit presets a time interval based on investigation standards and procedures and generates a prompt interface.

[0095] The student - side module includes a virtual prop unit. The virtual prop unit generates a virtual usage interface for props based on prop models. The prop models include network monitoring devices, data analysis devices, and forensic tools, and feedbacks operation results according to the operation information of the virtual usage interface.

[0096] This embodiment takes the scenario and dialogue options of simulating a case alarm as an example.

[0097] In this embodiment, the teacher first uses the scene editing unit of the teacher - side module to present a graphical editing interface. This interface has a navigation bar and operation buttons for the convenience of the teacher's operation. The teacher can screen and import various models related to telecom network fraud cases from the local resource library and the online material platform through the resource retrieval window, or create models by themselves. For example, the model of the alarm room includes multiple alarm desks with office facilities such as computers, telephones, and document materials placed on them, which can be obtained by downloading existing model resources on the Internet.

[0098] Using the case information editing unit, the teacher can edit case information; first, set the identity of the reporter as a white - collar worker in the workplace, with an appearance feature of wearing a professional suit and a behavioral feature of showing anxious eyes. When editing communication information, set that the reporter received a call from a strange overseas number. The caller claimed to be a customer service of a large financial institution and induced the reporter to transfer money on the grounds of an abnormal transaction risk in the account, trying to defraud funds.

[0099] The teacher further sets the transfer information. Among them, the amount transferred by the reporter is 80,000 yuan, the purpose of the transfer is falsely claimed to be for fund security verification, and the transfer time is limited within 1 hour to increase the sense of urgency. At the same time, edit the evidence information, that is, the screenshot of the call record saved on the reporter's mobile phone, showing the call number and call duration; the screenshot of the fraud text message, the content of which includes clue information such as inducement words and transfer account information.

[0100] In addition, based on their experience and knowledge, teachers predict the development direction of case information and construct an event tree for case development. For example, if a student (playing a police officer) asks the reporting person whether they have clicked on the link in the fraud text message, two main situations may occur: First, the reporting person clicks on the link, and malicious software is immediately implanted in the mobile phone, resulting in the leakage of information such as the address book and payment password. Subsequently, the investigation direction will focus on tracing the origin of the malicious software, defining the scope of information leakage, and tracking the flow of funds. Second, the reporting person does not click on the link, and the investigation direction will focus on tracing the contact information of the fraudster, and finding information such as the number's place of origin and associated numbers through telecom operator data.

[0101] Teachers also need to set the investigation standards and processes in the virtual case, clearly stipulating that students should first calm the emotions of the reporting person, and then ask the reporting person for personal information, the time and place of the fraud, etc. Subsequently, students should check the evidence such as call records and text messages provided by the reporting person, then analyze the fraud means, and set prompt information and operation specifications for each step.

[0102] Teachers can also search in the case template library, input keywords such as "case acceptance", screen out similar case templates, and thus edit by applying the templates. Teachers can also create templates by themselves, and store the created case templates in the case template library according to dimensions such as case type and difficulty level, for convenient subsequent retrieval and reuse.

[0103] After completing the editing, teachers can use the data transmission interface to store the data in the server and database modules, waiting for the call of the student client module.

[0104] In this embodiment, students establish a network connection with the server and database modules through the student client module, and receive the virtual scenario and virtual case data released by the teacher. Students can wear hardware devices such as HTC Vive, and use the Unity VR engine to load the virtual scenario. After loading is completed, students enter the virtual police station reception room scenario, and an operation interface is displayed, with floating function buttons on the interface, such as a dialogue input box, a scene investigation tool, an evidence viewing option, etc., which is convenient for students to operate.

[0105] Subsequently, students can start a simulated conversation with the reporting person model. The dialogue simulation unit configures a language processing model based on the virtual case, and GPT-Neo can be selected to generate a freely inputtable text input box. Students enter the dialogue content in the input box, such as "Hello, please don't worry. Please slowly tell me the whole story in detail." The language processing model performs semantic analysis and understanding on the input text, generates a logically reasonable reply text, and the reporting person model presents the reply to the student through text display: "I was at work today when I suddenly received a call. The other party said that there was an abnormality in my account and I had to transfer 80,000 yuan to their designated account immediately for verification, otherwise the account would be frozen!" According to the virtual case, this embodiment presets multiple dialogue options that fit the actual investigation needs for students to choose, such as "Did you transfer the money as required by the other party?" "What is the other party's phone number? Do you remember it?" "Did the other party say anything abnormal about the account on the phone?" "Did you disclose other information about yourself to the other party, such as your ID number, verification code?" etc. After students select different dialogue options, the reporter model will generate corresponding reply texts based on the analysis results of the virtual case and the language processing model. For example, if the student selects "Did you transfer the money as required by the other party?", the reporter model replies: "I almost transferred the money, and I had already opened the transfer interface, but suddenly I remembered that the company had organized anti-fraud training before, so I hesitated and didn't dare to transfer.", so that students can further understand the case.

[0106] Through the above embodiments, the scenario and dialogue options of receiving case alarms can be successfully simulated in the telecommunications network fraud case investigation training system based on virtual reality, providing students with an interactive experience and improving the practicality and effectiveness of the training system.

[0107] Embodiment 2: This embodiment is basically the same as Embodiment 1, except that this embodiment takes a simulated physical evidence analysis interface as an example.

[0108] In this embodiment, the teacher edits the laboratory scenario model for physical evidence analysis through the teacher-side module, and at the same time, edits the evidence models related to telecommunications network fraud cases, such as mobile phones involved in the case, storage devices containing fraudulent information, and communication tools suspected of being used for fraud.

[0109] Furthermore, teachers can edit case information around evidence. For the mobile phone involved in the case, set the identity of the suspect or victim to which it belongs. For example, a mobile phone belongs to a suspect, and its communication records may contain the content of calls with multiple victims and contact information with gang members. Then when the teacher edits the case information, it is set that the mobile phone stores evidence such as fraud speech templates, transfer record documents, and victim information forms.

[0110] Teachers can set relevant analysis points and expected results for each piece of evidence to build the logic of the case development and physical evidence analysis. For example, if students search and analyze the call records of a mobile phone, they may find the call time between the suspect and the victim, and then infer the time of the fraud; by searching and analyzing the transfer record documents of the mobile phone, they can track the flow of funds and determine the fraudulent collection account and fund transfer path.

[0111] In this embodiment, students can use the student terminal module to select the edited exhibits, such as the mobile phone involved in the case. After selection, an evidentiary analysis interface will pop up. On the left side of the interface, a 3D model of the mobile phone is displayed, which can be rotated, enlarged, and reduced to facilitate students to view the details of the mobile phone. The right area is divided into multiple functional sections. For example, the basic information column shows the brand, model, etc. of the mobile phone; for the call record, when students click on it, they can enter the call record viewing interface, and the interface presents information such as call time and call duration in a list form; for the file directory, students can open the folders layer by layer to view the files, and at the same time, file attributes such as creation time, modification time, and file size are displayed.

[0112] Through the above embodiments, in the virtual reality-based telecommunications network fraud case investigation training system, it is possible to successfully simulate the evidentiary analysis interface, provide an interactive experience for students, and improve the practicality and effectiveness of the training system.

[0113] Embodiment 3: This embodiment is basically the same as Embodiment 1, except that in this embodiment, the scenario of simulating a case analysis meeting is taken as an example.

[0114] In this embodiment, the teacher uses the teacher terminal module to edit the meeting room scene model for case analysis, including a long meeting table, seats, a projector, an electronic whiteboard, etc. Subsequently, based on the case information, the teacher edits the background of the case analysis meeting, including the time line of the case occurrence, the main characters involved, the fraud means, and the discussion direction of the case analysis meeting, and constructs the logical framework of the case analysis. For example, the teacher can set questions to guide students to think: "From these transfer records, can we analyze the fund flow pattern of the fraud gang?" "Based on the call recordings of the suspects, judge their possible places of operation and the number of accomplices." At the same time, set reference answers for each question for students to refer to.

[0115] In this embodiment, students enter the meeting room scene through the student terminal module. After the meeting starts, students introduce the case background and clues to each other through voice, and elaborate on their understanding and analysis ideas of the case. For example, student A says: "I have checked these transfer records and found that the funds were dispersed to multiple different accounts in a short period of time. This may mean that the fraud gang adopted the method of dispersing funds to avoid investigation." Other students can respond and discuss through voice, putting forward different views or supplementing evidence.

[0116] Through the above embodiments, in the virtual reality-based telecommunications network fraud case investigation training system, it is possible to successfully simulate the case analysis meeting scene, provide an interactive experience for students, and improve the practicality and effectiveness of the training system.

[0117] Embodiment 4: This embodiment is basically the same as Embodiment 1, except that in this embodiment, the scenario of simulating the arrest of a suspect is taken as an example.

[0118] In this embodiment, the teacher edits a virtual arrest scenario, such as the room where the suspect hides, through the teacher terminal module. In addition, the teacher can edit the appearance and clothing of the suspect, and use the model resources downloaded from the Internet to quickly generate a simple suspect model, or the teacher can also create the model by himself / herself; at the same time, a text display interface is set up to explain the arrest time, location and people in words, which is convenient for students to understand.

[0119] In this embodiment, the student watches the virtual arrest scenario through the student terminal module, and a prompt box pops up, listing the evidence successfully found by the student, enhancing the student's sense of immersion.

[0120] Through the above embodiments, it is possible to successfully simulate the scenario of arresting a suspect in the virtual reality-based telecommunications network fraud case investigation training system, provide an interactive experience for students, and improve the practicality and effectiveness of the training system.

[0121] Embodiment 5: This embodiment is basically the same as Embodiment 1, except that this embodiment takes the scenario of simulating the interrogation of a suspect as an example.

[0122] In this embodiment, the teacher edits a virtual interrogation scenario, such as an interrogation room, through the teacher terminal module. In addition, the teacher can edit the appearance and clothing of the suspect when being detained, and use the model resources downloaded from the Internet to quickly generate a simple suspect model, or the teacher can also create the model by himself / herself; at the same time, a text display interface is set up to explain the interrogation process and results in words, which is convenient for students to understand.

[0123] In this embodiment, the student watches the virtual interrogation scenario through the student terminal module, and a prompt box pops up to end this training and summarize the score of the student.

[0124] Through the above embodiments, it is possible to successfully simulate the scenario of interrogating a suspect in the virtual reality-based telecommunications network fraud case investigation training system, provide an interactive experience for students, and improve the practicality and effectiveness of the training system.

[0125] Embodiment 6: On the basis of Embodiment 1, this embodiment supplements the technical solution: the training data recording unit scores the operation data as follows. An evaluation matrix X is established, expressed as

[0126] where represents the original score of the m-th user on the k-th index; The original scores of the users in the evaluation matrix X are subjected to an exponential transformation to obtain the transformed evaluation matrix , expressed as

[0127] where It represents the value after exponential transformation of the original score of the m-th user on the k-th index; Based on the normalization formula, the transformed evaluation matrix is normalized to obtain the normalized scores of users in the evaluation matrix . The normalization formula is expressed as

[0128] where represents the normalized score of the m-th user on the k-th index; A normalized evaluation matrix R is established, which is expressed as

[0129] A weight matrix W is established, which is expressed as

[0130]

[0131] where represents the preset weight value on the k-th index; Based on the normalized evaluation matrix R and the weight matrix W, the weighted comprehensive score of the user is calculated, and the formula is as follows

[0132] where S m is the weighted comprehensive score of the m-th user and serves as the score of the user.

[0133] In this embodiment, taking police officer A, police officer B, and police officer C as examples, the weighted comprehensive score is evaluated on three indicators, including the action indicator X1, the dialogue indicator X2, and the time indicator X3.

[0134] Police officer X1 X2 X3 A 85 70 90 B 75 80 85 C 90 65 75 Substitute the data in the table to obtain the evaluation matrix:

[0135] The natural exponential function is used to perform exponential transformation on the data in the above evaluation matrix X, and the transformed evaluation matrix:

[0136] The transformed scores are compressed to the range of [0, 1] through the min-max normalization method:

[0137] where ; Then the normalized matrix:

[0138] Furthermore, manually set the weight corresponding to each index to Then the weight matrix: ; Subsequently, calculate the weighted comprehensive score of each police officer: ; After simplification: ; Furthermore, simplify the above-mentioned weighted comprehensive score: ; Insert specific values for exponential calculation:

[0139] Then, substitute the above calculation results into the weighted comprehensive score to calculate the approximate value:

[0140] The normalized value:

[0141] The final weighted comprehensive score:

[0142] According to the weighted comprehensive score, the rankings of Police Officer A, Police Officer B, and Police Officer C are as follows: 1. Police Officer C (score 0.413), 2. Police Officer A (score 0.294), 3. Police Officer B (score 0.174).

[0143] The above is only a preferred specific embodiment of the present invention, but the protection scope of the present invention is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present invention, according to the technical solution of the present invention and its invention structure.

Claims

1. A virtual reality-based investigation training system for telecommunications network fraud cases, characterized by: Including, A server and database module, which is used to build a server architecture and store and manage system operation data; A teacher-side module, which includes, A scenario editing unit, which is used to construct a virtual scenario; A case editing unit, which is used to edit case information, the identity, appearance, and behavior characteristics of character models, as well as communication information, transfer information, and evidence information, predict the development direction of case information, generate an event tree of case development, construct a virtual case, and set the investigation standards and processes in the virtual case; A data management and publishing unit, which is used to organize and classify the virtual scenario and virtual case and store them in the server and database module; A student-side module, which includes, A case receiving and displaying unit, which is used to receive the virtual scenario and virtual case from the server and database module, load the virtual scenario in a virtual reality environment, and generate an operation interface; A scene investigation unit, which is used to perform action interaction with the virtual scenario; A dialogue simulation unit, which is used to simulate scene dialogues; A virtual platform unit, which constructs a virtual network platform based on the virtual case and generates virtual social information and transfer records; A simulation process unit, which generates evidence options based on the virtual case, compares the evidence options with the evidence information, judges and generates case progress data; An event progress unit, which generates a virtual arrest scene and a virtual interrogation scene according to the case progress data; A training data recording unit, which is used to record operation data, score the operation data, and generate a score report.

2. The virtual reality-based telecommunications network fraud case investigation training system according to claim 1, characterized in that: The scenario editing unit is used to generate a graphical editing interface, import scenario models, exhibit models, character models, and prop models, construct a virtual scenario, and perform layout design on the virtual scenario, and set the position, angle, and size parameters of the models in the scenario.

3. The virtual reality-based telecommunication network fraud case investigation training system according to claim 1, characterized in that: Based on the virtual scenario, the scene investigation unit generates scene investigation options, binds an action interaction script, performs action interaction with the scene models in the virtual scenario according to the scene investigation options, and feeds back the attribute information of the exhibit models.

4. The virtual reality-based telecommunication network fraud case investigation training system according to claim 1, wherein: Based on the virtual case, the dialogue simulation unit configures a language processing model, generates a text input box, understands the text content in the text input box, and generates a reply text.

5. The virtual reality-based telecommunication network fraud case investigation training system according to claim 1, characterized in that: The teacher-side module includes a case template unit, which creates case templates and constructs a case template library; the case templates include scene settings, character relationships, case clues, and evidence distribution.

6. The virtual reality-based telecommunications network fraud case investigation training system according to claim 1, characterized in that: The student-side module includes an auxiliary prompt unit, which presets a time interval based on the investigation standards and processes and generates a prompt interface; The student-side module includes a virtual prop unit, which generates a virtual usage interface for props based on prop models. The prop models include network monitoring devices, data analysis devices, and forensic tools, and feedbacks operation results according to the operation information of the virtual usage interface.

7. The virtual reality-based telecommunication network fraud case investigation training system according to claim 1, characterized in that: The described investigation training system includes a case library module. The case library module is used to establish a case library of telecommunications network fraud cases, set common decision points in the telecommunications network fraud cases, and establish a decision tree.

8. The virtual reality-based telecommunication network fraud case investigation training system according to claim 4, characterized in that: The setting of the common decision points in the telecommunications network fraud cases is to extract decision point information from the case library. The decision point information includes suspicious calls, suspicious links, and suspicious information. A decision point information data set is established, and binary variables are used to encode the categorical features in the decision point information data set to obtain the numerical features of the categories.

9. The virtual reality-based telecommunication network fraud case investigation training system according to claim 1, characterized in that: The prediction of the development direction of the case information is based on the following formula to analyze the probability of the event occurrence. , In the formula, x represents the input vector, including call records and transaction records; w represents the weight vector, indicating the importance of call records and transaction records, b represents the bias term, and p(y = 1|x) represents the probability prediction of the positive class.

10. A method for investigating and training telecommunications network fraud cases based on virtual reality, characterized in that: It includes the following steps (S01) The teacher uses the teacher - end module to import and create model data, arrange scenes, exhibits, and characters, set character information, communication information, and transfer information, construct a virtual scene and a virtual case, store the virtual scene and the virtual case after editing, and publish them to the student - end module; (S02) The student receives the virtual scene and the virtual case at the student - end, wears the hardware device, and enters the virtual scene; (S03) The student conducts an investigation of the virtual scene, including opening the door, searching the room, and checking items; (S04) The student observes, measures, and detects the exhibit models in the virtual scene to obtain the attribute information of the exhibit models; (S05) The student conducts a simulated conversation with the character models in the virtual scene, inputs the conversation text into the text input box, and obtains the reply text; (S06) The student logs in to the virtual network platform to search for virtual social information and transfer records; (S07) The student holds a case analysis meeting to discuss based on the information collected, selects evidence options, and obtains case progress data; (S08) The student enters the virtual arrest scene, watches the virtual arrest scene and the virtual interrogation scene, and ends the training; (S09) Score the operation data of the student to generate a score report.

Citation Information

Patent Citations

  • Virtual simulation practical training teaching application system and method for criminal investigation

    CN109637256A

  • Method and device for acquiring identification characteristics of electric fraud case and application of method and device

    CN114186623A

  • Multi-user intelligent interaction system based on virtual reality and terminal equipment

    CN118349118A

  • Health big data-oriented delivery and education integrated intelligent prediction method and implementation method thereof

    CN119207741A

  • Network vulnerability detection method based on Spark multi-source data fusion and feature analysis

    CN119603019A