Fraudulent behavior identification method and device, equipment, storage medium and program product
By building the target map of telecommunications network data and using preset graph algorithms to identify user behavior and their association relationships, the shortcomings of traditional anti-fraud measures in identifying complex new types of fraud are solved, and higher identification accuracy and revealing gang behavior are achieved.
Patent Information
- Application Number
- CN202510655079.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-20
- Publication Date
- 2025-08-08
AI Technical Summary
Traditional anti-fraud measures mainly rely on rules engines or risk scoring systems based on statistical models, making it difficult to capture complex and changeable new types of fraud, resulting in low accuracy in identifying fraud.
By obtaining the telecommunications network data of the users to be identified, a target map is built, and analyzing user behavior and its association relationships are used to analyze user behavior and its association relationships, and fraudulent behavior and its association relationships are identified, including the use of the Qiang Unicom sub-graph algorithm, tag propagation algorithm, community discovery algorithm and centralized algorithm.
It improves the accuracy of identification of fraud, can understand the complex and changeable new types of fraud, identify fraud gangs and internal connections, and improves the effectiveness of anti-fraud.
Smart Images

Figure CN120455514A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of deep learning technology, and in particular to fraudulent behavior identification methods, devices, equipment, storage media and program products. Background Art
[0002] Traditional anti-fraud measures mainly rely on rule engines or risk scoring systems based on statistical models. However, these methods can usually only identify known patterns and have difficulty capturing complex and changing new types of fraud, thereby reducing the accuracy of fraud identification. Summary of the Invention
[0003] The main purpose of this application is to provide a fraudulent behavior identification method, device, equipment, storage medium and program product, aiming to solve the technical problem of low accuracy in fraudulent behavior identification.
[0004] To achieve the above objectives, this application proposes a fraudulent behavior identification method, which includes:
[0005] Acquiring first telecommunication network data of the user to be identified;
[0006] constructing a target graph based on the first telecommunications network data;
[0007] Based on the target graph, a target recognition result is outputted through a preset graph algorithm, where the target recognition result includes the fraudulent behaviors of the user to be identified and the correlation between the fraudulent behaviors.
[0008] In one embodiment, the step of constructing a target graph based on the first telecommunications network data includes:
[0009] Extracting data features of the first telecommunication network data, the data features including entity features, relationship features between entities, and attribute features of entities;
[0010] Defining each node of the target graph to be constructed based on the entity features, defining each edge of the target graph to be constructed based on the relationship features, and assigning target attributes to each node based on the attribute features;
[0011] A target graph is constructed based on the nodes, the edges, and the target attributes corresponding to the nodes.
[0012] In one embodiment, the entity features include multiple fraud pathways, the target graph includes graph information corresponding to each fraud pathway, the target recognition result includes a recognition result corresponding to each fraud pathway, and the step of outputting the target recognition result using a preset graph algorithm based on the target graph includes:
[0013] In response to an analysis requirement for a target fraud pathway, based on graph information corresponding to the target fraud pathway in the target graph, outputting an identification result corresponding to the target fraud pathway through a preset graph algorithm;
[0014] Wherein, after the step of outputting the target recognition result based on the target graph by using a preset graph algorithm, the method further includes:
[0015] Based on the identification result corresponding to the target fraud path, a fraud analysis result corresponding to the analysis requirement is determined.
[0016] In one embodiment, before the step of obtaining the first telecommunication network data of the user to be identified, the method further includes:
[0017] Obtaining the second telecommunication network data of the historical first user;
[0018] constructing a historical graph based on the second telecommunication network data;
[0019] determining a historical identification result based on the second telecommunication network data, and using the historical identification result as a label for the second telecommunication network data;
[0020] Based on the historical graph and the labels, the graph algorithm to be trained is iteratively trained until a preset condition is met, thereby obtaining the preset graph algorithm.
[0021] In one embodiment, the second telecommunications network data includes first network behavior data and network traffic data, and the historical identification result includes historical fraudulent behavior of the historical user, and the historical fraudulent behavior includes target network fraud, abnormal traffic usage, abnormal permission request, and abnormal communication behavior;
[0022] The step of determining a historical identification result based on the second telecommunications network data includes at least one of the following:
[0023] Based on the first network behavior data, identifying target network fraud behavior through a preset behavior recognition model;
[0024] Based on the network traffic data, identifying abnormal traffic usage behavior through a random forest algorithm;
[0025] Based on the first network behavior data, abnormal permission requests and / or abnormal communication behaviors are determined through a preset analysis tool.
[0026] In one embodiment, the preset behavior recognition model includes a first behavior recognition model and a second behavior recognition model. The step of identifying the target network fraud behavior based on the first network behavior data using the preset behavior recognition model includes:
[0027] Based on the first network behavior data, outputting suspected network fraud behavior using a first behavior recognition model, wherein the first behavior recognition model is obtained by iteratively training an unsupervised model based on second network behavior data corresponding to normal network behavior;
[0028] Based on the second network behavior data corresponding to the suspected network fraud behavior, the target network fraud behavior is output through the second behavior recognition model, wherein the second behavior recognition model is obtained by iteratively training the reinforcement learning model based on the historical third network behavior data of suspected network fraud.
[0029] In addition, to achieve the above-mentioned purpose, the present application also proposes a fraudulent behavior identification device, which includes:
[0030] An acquisition module, configured to acquire first telecommunication network data of a user to be identified;
[0031] A construction module, configured to construct a target graph based on the first telecommunications network data;
[0032] The identification module is used to output a target identification result based on the target graph through a preset graph algorithm, and the target identification result includes the fraudulent behavior of the user to be identified and the correlation relationship between each fraudulent behavior.
[0033] In addition, to achieve the above-mentioned purpose, the present application also proposes a fraudulent behavior identification device, which includes: a memory, a processor, and a computer program stored on the memory and executable on the processor, wherein the computer program is configured to implement the steps of the fraudulent behavior identification method as described above.
[0034] In addition, to achieve the above-mentioned purpose, the present application also proposes a storage medium, which is a computer-readable storage medium. A computer program is stored on the storage medium, and when the computer program is executed by a processor, the steps of the fraud identification method described above are implemented.
[0035] In addition, to achieve the above-mentioned purpose, the present application also provides a computer program product, which includes a computer program, and when the computer program is executed by a processor, it implements the steps of the fraudulent behavior identification method as described above.
[0036] One or more technical solutions proposed in this application have at least the following technical effects:
[0037] The present application obtains first telecommunications network data of the user to be identified; constructs a target graph based on the first telecommunications network data; and outputs a target identification result based on the target graph through a preset graph algorithm, wherein the target identification result includes the fraudulent behavior of the user to be identified and the correlation between each fraudulent behavior; compared with traditional anti-fraud measures that mainly rely on rule engines or risk scoring systems based on statistical models, the present application is based on the first telecommunications network data and the target graph. Through a preset graph algorithm, it can comprehensively understand user behavior based on historical behavior patterns, thereby accurately identifying individual fraudulent behaviors. At the same time, it can also reveal hidden behavior patterns (correlations between each fraudulent behavior) by analyzing the connection patterns and paths between nodes in the graph, and deeply explore the intrinsic connections between different user behaviors under the network, thereby gaining insight into complex and changeable new fraud behaviors (for example, if a newly created account quickly establishes connections with multiple high-risk accounts, then this account may also be involved in fraud), thereby improving the accuracy of fraudulent behavior identification. BRIEF DESCRIPTION OF THE DRAWINGS
[0038] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the present application and, together with the description, serve to explain the principles of the present application.
[0039] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, for ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.
[0040] Figure 1 A flowchart of the first embodiment of the fraud identification method of this application is provided;
[0041] Figure 2 A schematic diagram of a scenario provided for the first embodiment of the fraud identification method of this application;
[0042] Figure 3 A flowchart of the second embodiment of the fraud identification method of this application is provided;
[0043] Figure 4 This is a schematic diagram of the module structure of the fraud behavior identification device according to an embodiment of the present application;
[0044] Figure 5 Schematic diagram of the device structure of the hardware operating environment involved in the fraud identification method in the embodiment of the present application.
[0045] The purpose, features and advantages of this application will be further explained in conjunction with the embodiments and with reference to the accompanying drawings. DETAILED DESCRIPTION
[0046] It should be understood that the specific embodiments described herein are merely used to explain the technical solutions of the present application and are not intended to limit the present application.
[0047] In order to better understand the technical solution of the present application, a detailed description will be given below in conjunction with the accompanying drawings and specific implementation methods.
[0048] It should be noted that the execution subject of this embodiment may be a computing service device with data processing, network communication, and program execution capabilities, such as a tablet computer, personal computer, or mobile phone, or an electronic device capable of performing the aforementioned functions, such as a fraud detection device. This embodiment and the following embodiments will be described below using the fraud detection device as an example.
[0049] Based on this, the present invention provides a fraudulent behavior identification method. Figure 1 , Figure 1 This is a flow chart of the first embodiment of the fraud identification method of the present application.
[0050] In this embodiment, the fraudulent behavior identification method includes steps S10 to S30:
[0051] Step S10, obtaining first telecommunication network data of the user to be identified;
[0052] It should be noted that the fraudulent behavior identification device can be subordinate to the fraudulent behavior identification equipment, and can also be subordinate to the fraudulent behavior identification system. The fraudulent behavior identification system includes a fraudulent identification enhancement module, a fraudulent label layer module, a fraudulent model layer module, a fraudulent application layer module, etc. Figure 2 .
[0053] Among them, the fraud identification enhancement module is used to integrate the telecommunications network data collected by the collection sub-module; the fraud label layer module is used to structure the collected data and label it for easy sharing with other modules; the fraud model layer module is built on the label layer, which is used to deepen data analysis and accurately identify fraud behaviors and den clusters through multiple models; the fraud application layer module visualizes the identification results of the fraud model layer module to support real-time monitoring and rapid response; specifically, the fraud behavior identification system also includes basic operations, data source access, model task data overview, model task operation report monitoring, data label sharing and other functions; the fraud application layer module also provides rapid customization of anti-fraud models, visual development, visual orchestration, visual management, visual monitoring, development sharing and other functions.
[0054] Specifically, as shown in Table 1 below, telecommunications network data includes 4G (fourth-generation mobile information system) data, 5GDPI (Deep Packet Inspection, a fifth-generation mobile communication technology used to inspect the data packet passing through the inspection point) data, and IMS (Information Management System, a hierarchical data system) data, etc.
[0055] Table 1. Types of telecommunication network data
[0056]
[0057] Step S20: constructing a target graph based on the first telecommunication network data;
[0058] It should be noted that, in order to better analyze user behaviors and the implicit relationships between them, this embodiment first constructs a target graph based on the first telecommunications network data of each user to be identified.
[0059] Among them, the graph framework is a semantic network used to describe the relationship between entities, which can be understood and processed by computers; in the graph framework, things or concepts in the real world are abstracted as entities, and these entities are described by attributes; in this embodiment, each user to be identified and his / her first telecommunications network data are described by constructing a graph, so as to more clearly and intuitively display and analyze user behavior patterns and associations.
[0060] Specifically, the specific implementation of constructing the target graph based on the first telecommunications network data may be:
[0061] Extract data features of the first telecommunications network data, where the data features include entity features, relationship features between entities, and attribute features of the entities; define each node of a target graph to be constructed based on the entity features, define each edge of the target graph to be constructed based on the relationship features, and assign a target attribute to each node based on the attribute features; and construct a target graph based on each of the nodes, each of the edges, and the target attributes corresponding to each node.
[0062] It should be noted that the data characteristics of the first telecommunications network data include entity characteristics, relationship characteristics between entities, and attribute characteristics of entities, among which entity characteristics can be telephone numbers, APPs, user IDs, user behaviors, etc.; relationship characteristics between entities can be interactive relationships, inherent connections, etc. between entity characteristics, such as call records, installation relationships, transfer records, account relationships, etc.; attribute characteristics of entities can be the call frequency of a telephone number, the download source of an APP, etc.
[0063] After extracting the data features of the first telecommunication network data, the data features may be stored in a graph database to facilitate subsequent real-time processing.
[0064] Furthermore, the entity features are defined as the nodes of the target graph to be constructed, the relationship features are defined as the edges of the target graph to be constructed, and target attributes are assigned to each node based on the attribute features, and the defined node types, edge types, and target attributes are stored in the graph database.
[0065] For example, if the nodes in the target graph include phone numbers, then multiple nodes represent one phone number respectively, and the target attributes of the node may include the number of calls, call duration, active time, etc.; if there are call records between two phone numbers, an edge can be created between the corresponding nodes, and the weight of the edge can represent the frequency or duration of the calls.
[0066] Furthermore, a graph database is used to store and query graph data, so that a target graph is constructed based on each of the nodes, each of the edges, and the target attributes corresponding to each node stored in the graph database.
[0067] In addition, a specific implementation of constructing a target graph based on the first telecommunications network data may also be:
[0068] On the basis of the first telecommunications network data, geographic location information, user social network connection information, etc. are added to construct a more comprehensive graph; or, on the basis of the corresponding graph of the preset graph algorithm, the corresponding information of the first telecommunications network data is added to obtain an incremental graph.
[0069] Step S30: Based on the target graph, a target recognition result is output through a preset graph algorithm. The target recognition result includes the fraudulent behaviors of the user to be identified and the correlation between the fraudulent behaviors.
[0070] It can be understood that the target graph constructed in the above manner can comprehensively reflect user behaviors and the relationships between user behaviors. This embodiment is based on the target graph and identifies user behaviors through a preset graph algorithm to identify the fraudulent behaviors of the users to be identified and the correlation between the fraudulent behaviors.
[0071] Since there is shared information among fraud gangs and there are many connections between gang members, risk points can be identified through the above method; specifically, the preset graph algorithm may include a strong connectivity subgraph algorithm and a label propagation algorithm. Based on the target graph, the specific implementation method of identifying the fraudulent behavior of the user to be identified and the correlation between each fraudulent behavior through the preset graph algorithm may be: using the strong connectivity subgraph algorithm to exclude isolated points or nodes with weak connectivity, and using the label propagation algorithm to cluster nodes with the same characteristics, and finally obtaining a fraud gang composed of users who have committed fraudulent behavior.
[0072] In addition, the preset graph algorithm may also include a community discovery algorithm and a centrality algorithm. When the fraudulent behavior is specifically call fraud, the above-mentioned specific implementation method of identifying the fraudulent behavior of the user to be identified and the correlation between each fraudulent behavior based on the target graph through the preset graph algorithm may be: through the community discovery algorithm, identify closely connected phone number groups in the target graph, these phone number groups may involve gang fraud behavior, use the centrality algorithm to obtain key nodes in the target graph, these key nodes may represent the central figures of the fraud gang, extract features from the target graph, such as node height, clustering coefficient, PageRank (an algorithm for measuring node importance), etc., to reflect the activity level of the phone number and the importance of the phone number in the network, etc., so as to analyze and obtain gang fraud behavior.
[0073] It can be understood that by analyzing the correlation between various fraudulent behaviors, it can be determined whether there is a fraud gang.
[0074] It should be noted that the entity features include multiple fraud pathways, such as application (APP) fraud, call fraud, and other pathways. For example, application fraud involves a variety of potentially fraudulent business APPs or user behaviors: private chat APPs, virtual currency trading APPs, remote control APPs, wired mobile phone port dedicated APPs, Internet phone and SMS APPs, screen sharing behaviors, social behaviors, counterfeit financial stock loan investment APPs, fake order rebate APPs, dating APPs, gambling games, etc. The target graph includes graph information corresponding to each fraud pathway, such as application interaction information corresponding to application fraud, phone numbers corresponding to call fraud, etc. The target identification results include identification results corresponding to each fraud pathway, such as the association between application fraud users, call fraud users, and two-way call fraud users.
[0075] Specifically, the specific implementation of outputting the target recognition result based on the target graph through a preset graph algorithm may be:
[0076] In response to the analysis requirements for the target fraud pathway, based on the graph information corresponding to the target fraud pathway in the target graph, the recognition result corresponding to the target fraud pathway is output through a preset graph algorithm.
[0077] It should be noted that in order to improve the prediction accuracy and the adaptability of the graph algorithm to new types of fraudulent behaviors, after the target identification results are output based on the target graph through the preset graph algorithm, the target graph and the preset graph algorithm can be updated based on the fraudulent behaviors of the users to be identified, the correlation between the fraudulent behaviors, and the corresponding telecommunications network data as historical data.
[0078] In order to improve convenience, users can trigger fraud behavior identification instructions through the fraud-related application layer module in the fraud behavior identification system, and input the target fraud path to be identified or the required fraud identification results.
[0079] Reference Figure 2 Users can propose analysis requirements for the phone numbers corresponding to call fraud behaviors based on the call fraud channels, and can also propose analysis requirements for the user identity information corresponding to the fraud behaviors based on each fraud channel. They can also propose analysis requirements for tracing the user's trajectory corresponding to the fraud behaviors based on each fraud channel, etc.
[0080] In this embodiment, the fraud-related application layer module responds to the analysis requirements for the target fraud pathway, and based on the graph information corresponding to the target fraud pathway in the target graph, outputs the identification result corresponding to the target fraud pathway through a preset graph algorithm; for example, in response to the analysis requirements for the telephone number corresponding to the call fraud behavior proposed for the call fraud pathway, the preset graph algorithm can analyze the call fraud behavior based only on the graph information corresponding to the call fraud pathway (for example, telephone number, call duration, call frequency, etc.).
[0081] In the case where the fraud channel is call fraud, the above-mentioned specific implementation method of identifying the fraudulent behavior of the user to be identified and the correlation between each fraudulent behavior through a preset graph algorithm based on the target graph can be: when analyzing the newly added mobile phone numbers based on the graph information corresponding to the call fraud channel in the target graph, if the analysis finds that the same person has multiple mobile phones with different locations, it is determined to be a malicious account; if the analysis finds that more than three mobile phone numbers with different locations appear in the communication list of the same user within one month, it is determined that the user is an organization that illegally purchases personal information; if the analysis finds that a batch of new mobile phone cards are from the same source, and a large number of account opening applications appear in a short period of time, it is determined to be a den gathering area of a telecommunications fraud organization, etc.
[0082] Furthermore, in order to be able to meet the analysis requirements proposed by users in a targeted manner, after the step of outputting the target recognition result based on the target graph through a preset graph algorithm, it is also possible to: determine the fraud analysis result corresponding to the analysis requirement based on the recognition result corresponding to the target fraud path.
[0083] Specifically, in response to the user's request for analyzing the telephone number corresponding to the call fraud behavior, the telephone number corresponding to the call fraud behavior can be output based on the identification result corresponding to the target fraud path.
[0084] Among them, the above-mentioned fraud analysis results can also be reflected in the visualization interface in the following ways: providing the time trend of the reported number, the time trend of the anti-fraud output number, the time trend of the anti-fraud output number follow-up confirmation result, the potential fraud den analysis model, the GIS (Geographic Heat Map) heat map of the number set (a map used to display the visualization effect of data distribution and density), the spatiotemporal dynamic map of a single number, the effectiveness visualization report capability, etc.; the proportion of various types of suspicious numbers and fraud APPs and their distribution can also be statistically obtained, including: the proportion of abnormal industry categories (for example, finance, operators, etc.), the proportion of abnormal identity categories (for example, the elderly, students, corporate legal persons, etc.) and the proportion of abnormal areas, etc.
[0085] It should be noted that after the step of outputting the target recognition result based on the target graph through the preset graph algorithm, the target recognition result can also be returned to the supervision platform through the interface for further processing by the supervision platform; the intelligent voice dialing service can also be used to send a verification message to the user whose target recognition result is fraudulent behavior, and record the feedback result.
[0086] In this embodiment, compared with traditional anti-fraud measures that mainly rely on rule engines or risk scoring systems based on statistical models, this application is based on the first telecommunications network data and target graph, and through a preset graph algorithm, it can comprehensively understand user behavior based on historical behavior patterns, thereby accurately identifying individual fraudulent behaviors. At the same time, it can also reveal hidden behavior patterns by analyzing the connection patterns and paths between nodes in the graph, and deeply explore the intrinsic connections between different user behaviors under the network, so as to gain insight into complex and changeable new fraud behaviors, thereby improving the accuracy of fraud identification.
[0087] Based on the first embodiment of the present application, in the second embodiment of the present application, the same or similar contents as those in the above embodiment 1 can be referred to the above introduction and will not be described in detail later. Figure 3 Before step S10, the fraudulent behavior identification method further includes steps S01 to S04:
[0088] Step S01, obtaining historical second telecommunication network data of a first user;
[0089] Step S02: constructing a historical graph based on the second telecommunication network data;
[0090] Step S03: determining a historical recognition result based on the second telecommunication network data, and using the historical recognition result as a label for the second telecommunication network data;
[0091] It should be noted that in order to accurately analyze user fraudulent behavior based on telecommunications network data, this embodiment proposes a training process for a graph algorithm. Specifically, the second telecommunications network data of the historical first user can be obtained first, and a historical graph can be constructed based on the second telecommunications network data. The specific implementation method is basically the same as the above-mentioned acquisition of the first telecommunications network data and construction of the target graph based on the first telecommunications network data, and will not be repeated here.
[0092] In order to improve data processing efficiency and reduce manual labeling errors, this embodiment can automatically determine historical recognition results based on the acquired second telecommunication network data, and use the historical recognition results as labels for the second telecommunication network data for training and evaluating models.
[0093] The specific implementation method of determining the historical identification result based on the second telecommunication network data may be to identify fraudulent behavior based on the second telecommunication network data through a pre-trained neural network model, and directly obtain the fraudulent behavior existing in the second telecommunication network data.
[0094] Alternatively, since telecommunications network data includes data from multiple aspects, users may also commit fraud in multiple ways. This embodiment may utilize different methods and technologies to detect possible fraud from multiple dimensions.
[0095] It should be noted that the second telecommunications network data includes the first network behavior data and network traffic data, and the historical identification results include historical fraud behaviors of historical users, and the historical fraud behaviors include target network fraud behaviors, abnormal traffic usage behaviors, abnormal permission requests, abnormal communication behaviors and other dimensions.
[0096] Specifically, the step of determining the historical identification result based on the second telecommunications network data includes at least one of the following:
[0097] First, based on the first network behavior data, target network fraud behavior is identified through a preset behavior recognition model.
[0098] First, network behavior data includes data such as timestamps, operation types, and system calls. Network behavior includes the behavior of the APP during runtime, such as startup behavior, background activities, resource consumption, etc. Abnormal network behavior patterns may reveal its hidden malicious intentions, such as installing malware in the background or consuming large amounts of data in the background.
[0099] In order to accurately identify abnormal network behavior patterns, this embodiment identifies target network fraud behavior based on the first network behavior data through a preset behavior recognition model; wherein the preset behavior recognition model can be a neural network model obtained in advance through training.
[0100] Alternatively, the preset behavior recognition model includes a first behavior recognition model and a second behavior recognition model. The specific implementation method of identifying the target network fraud behavior based on the first network behavior data through the preset behavior recognition model may also be:
[0101] Based on the first network behavior data, a suspected network fraud behavior is output through a first behavior recognition model, wherein the first behavior recognition model is obtained by iteratively training an unsupervised model based on the second network behavior data corresponding to the normal network behavior; based on the second network behavior data corresponding to the suspected network fraud behavior, a target network fraud behavior is output through a second behavior recognition model, wherein the second behavior recognition model is obtained by iteratively training a reinforcement learning model based on historical third network behavior data of suspected network fraud.
[0102] Since some suspected fraudulent behaviors in online behaviors are actually not fraudulent behaviors, this embodiment first outputs the suspected online fraud behaviors through a first behavior recognition model based on the first online behavior data, and then outputs the target online fraud behaviors through a second behavior recognition model based on the second online behavior data corresponding to the suspected online fraud behaviors, thereby improving the recognition accuracy of online fraud behaviors.
[0103] Specifically, the first behavior recognition model can be a supervised model or an unsupervised model. Since there is an implicit correlation between the first network behavior data in this embodiment, this embodiment preferably uses an unsupervised model as the first behavior recognition model.
[0104] Among them, the unsupervised first behavior recognition model can be constructed by: first collecting user behavior data, such as browsing habits, click sequences, transaction time and amount, etc.; using an unsupervised learning algorithm (for example, a Gaussian mixture model (the Gaussian mixture model is more suitable for describing complex correlation relationships compared to other unsupervised models)), based on the second network behavior data corresponding to normal network behavior, analyzing the distribution characteristics of normal network behavior, establishing quantitative indicators of normal network behavior, and identifying abnormal behavior patterns (suspected network fraud behavior) through iterative training by comparing the actual user behavior with the behavior predicted by the model.
[0105] Specifically, suspected online fraud behavior may be abnormal transaction frequency, atypical time pattern, or abnormal purchase combination, etc.
[0106] Since some online behaviors that are suspected to be fraudulent may not actually be fraudulent, this embodiment outputs target online fraud behaviors through a second behavior recognition model based on the second online behavior data corresponding to the suspected online fraud behaviors.
[0107] The second behavior recognition model may be obtained by training based on an unsupervised learning algorithm or a reinforcement learning algorithm.
[0108] Since the reinforcement learning algorithm can automatically find a balance between exploring unknown options (exploration) and utilizing the best known options (exploitation) to ensure that potentially better solutions are not missed and inefficient options are not over-tried, this embodiment preferably uses the second behavior recognition model to iteratively train the reinforcement learning model based on historical third network behavior data of suspected online fraud.
[0109] Specifically, in order to improve the accuracy of analysis of target online fraud behaviors (real online fraud behaviors) among suspected online fraud behaviors, this embodiment adopts a reinforcement learning method to select the optimal behavior strategy based on the current environment and historical experience. In the malicious fraud behavior judgment scenario, the reinforcement learning algorithm is applied to define the fraud detection problem and clarify the agent, state, action, and reward functions.
[0110] Among them, the intelligent agent can be a detection system, the state is the second network behavior data corresponding to the suspected network fraud behavior, the action is the decision made by the intelligent agent (such as marking it as the target network fraud behavior or normal network behavior), and the reward is the feedback of the action result, for example, correct marking receives a positive reward and incorrect marking receives a negative reward.
[0111] The state space is the set of all states that an agent may encounter. In fraud identification, the state can be user behavior characteristics, transaction information, historical records and other data. These data are preprocessed and feature extracted to form an effective state representation.
[0112] The action space is the set of all possible actions that the agent can take in each state; in fraud behavior identification, the action can be "marked as target network fraud behavior", "marked as normal network behavior" or "need more information", etc.
[0113] The reward function provides immediate feedback based on the agent's actions and the results produced. In fraud identification, the reward function is: if the target network fraud behavior is successfully identified, a positive reward is given; if normal network behavior is falsely reported, a negative reward is given.
[0114] In the above manner, the reinforcement learning model is iteratively trained based on historical third network behavior data suspected of network fraud to obtain the second behavior recognition model.
[0115] Among them, the reinforcement learning model can be a deep Q-network (DQN) or a value-based method, etc. Since the deep Q-network combines the advantages of deep learning and Q learning, the deep Q-network approximates the Q function by using a neural network, so that it can process high-dimensional inputs and is more suitable for processing network behavior data with complex relationships. In this embodiment, the reinforcement learning model is preferably a deep Q-network.
[0116] Specifically, in the process of training the deep Q network using the third network behavior data, cross-validation technology can be used to find the optimal model parameters; the performance of the deep Q network model is evaluated using the test set data, and the evaluation indicators include accuracy, recall rate, F1 score, AUC-ROC (Area under curve-Receiver operating characteristic curve, the area under the receiver operating characteristic curve and the coordinate axis) curve, etc.; as the third network data continues to accumulate, the performance of the deep Q network model is continuously monitored, and the deep Q network model is updated as needed to adapt to changes in user behavior.
[0117] Second, based on the network traffic data, abnormal traffic usage behavior is identified through a random forest algorithm.
[0118] It should be noted that when analyzing network traffic data, sudden spikes or abnormal increases in traffic are identified, this indicates the creation of a large number of fake accounts or malicious activity. For example, a large number of registration requests, login attempts, or frequent API (Application Programming Interface) calls within a short period of time are generally considered abnormal traffic usage.
[0119] In order to improve the accuracy of behavior recognition, this embodiment adopts the random forest algorithm to identify abnormal traffic usage behavior in network traffic data. Specifically, when processing complex, nonlinear network behavior data, the random forest algorithm improves the accuracy and stability of the model by constructing multiple decision trees and combining their prediction results.
[0120] Specifically, the random forest algorithm is trained based on the following method: historical network traffic data is obtained, such as traffic size, request frequency, and source and destination IP addresses, and the random forest algorithm is used for iterative training to identify normal traffic patterns. The trained random forest algorithm is used to monitor network traffic in real time and identify abnormal traffic usage behavior.
[0121] Third, based on the first network behavior data, determine abnormal permission requests and / or abnormal communication behaviors through a preset analysis tool.
[0122] It should be noted that the preset analysis tools include network traffic analysis tools and static analysis tools.
[0123] Because abnormal permission requests may indicate potential malicious intent, this embodiment determines whether there is potential malicious intent by checking whether the actual functions of the APP are consistent with the description and whether these functions are reasonable. Specifically, it includes reviewing the APP's permission requests: determining whether sensitive data beyond the permissions required for normal operation is requested, such as access to contacts, location information, or cameras.
[0124] Among them, the specific method of reviewing the APP's permission request can be: through static analysis tools (for example, AppinfoScanner, SonarQube, etc.). Since AppinfoScanner checks the software without executing the code to discover potential security vulnerabilities, code defects and other problems, this embodiment prefers AppinfoScanner as the static analysis tool; specifically, DEX (Dalvik Executable), APK (Android Package), IPA (iOS App Store Package) and other files can be obtained through AppinfoScanner, which helps to identify the APP's requested permissions.
[0125] This embodiment can also capture and analyze the first network behavior data, such as network data packets, through network traffic analysis tools. By checking the source address, destination address, port number and protocol type of the network data packets, abnormal communication behavior can be identified. Abnormal communication behavior can be frequent non-standard port connections or communications with known malicious servers.
[0126] It is understood that the aforementioned target network fraud behavior, abnormal traffic usage behavior, abnormal permission request and / or abnormal communication behavior are all abnormal behaviors in the context of APP fraud. To ensure that the preset graph algorithm can identify fraud behaviors in various channels, this embodiment can also identify abnormal behaviors in the context of call fraud. The specific identification method can be:
[0127] DPI data is obtained. Since DPI data includes metadata extracted from mobile networks or Internet voice services, this embodiment uses call records based on DPI data to identify fraudulent online behavior and abnormal voice call behavior. The specific identification method can be:
[0128] Collect mobile phone number segments with multiple numbers under one ID card and extract all traffic package information in the current mobile phone market; clean the mobile phone numbers contained in each traffic package, and remove duplicate traffic card lists while retaining the mobile phone numbers. If there are multiple mobile phone numbers with different mobile phone cards registered under the same ID card, remove the redundant mobile phone numbers to obtain a complete set of newly added mobile phone numbers, identify the calling behavior of these newly added mobile phone numbers, and detect call fraud.
[0129] To identify abnormal call behavior, a real-time updated basic information database can be obtained. This basic information database includes each user's identity information, contact information, basic personal information, base station information in their area, and home address information. The core elements of each field are extracted as the basis for subsequent analysis. The extraction of core elements depends on the correlation between the fields. The correlation priority can be sorted and divided according to phone number segments. Further filtering and deduplication are performed based on the number segments. Finally, the remaining numbers are stored. A representative sample set of numbers is selected as a training set to build the training model. To ensure that the deep learning model has good generalization capabilities, numbers with high duplication rates are avoided when selecting the training set. Sample numbers from different regions are selected as much as possible. Generally, the amount of sample data must exceed 20,000 before modeling can begin. The preprocessed raw data is imported into the deep learning framework and run to obtain the model parameter file. The obtained model parameter file is converted into the corresponding format, and the trained model is deployed and applied, thereby realizing the construction of a model for identifying abnormal call behavior.
[0130] Furthermore, the historical identification results obtained by the above identification (target network fraud behavior, abnormal traffic usage behavior, abnormal permission request, abnormal communication behavior, and / or call fraud behavior) are used as labels to annotate the first network behavior data, thereby obtaining the first network behavior data with labels.
[0131] The specific labeling method can be: labeling calls and APPs as "normal" or "fraud" respectively; specifically, the corresponding labels of APPs can be labels of black and gray industries such as private chat, conference and remote control, counterfeit finance, gambling games, dating and marriage, and fake orders and rebates; the corresponding labels of calls can be labels such as unfamiliar calls and unanswered calls.
[0132] Step S04: Based on the historical graph and the labels, the graph algorithm to be trained is iteratively trained until a preset condition is met, thereby obtaining the preset graph algorithm.
[0133] Furthermore, based on the above labels and historical graphs, the graph algorithm to be trained is iteratively trained until preset conditions are met, thereby obtaining the preset graph algorithm (fraudster identification model).
[0134] Based on the above method, various types of identification models can be constructed, including victim identification models, fraudster identification models, etc., refer to Table 3; among them, victim identification models include high-risk APP counterfeit finance, high-risk APP gambling games, high-risk APP dating and marriage, high-risk APP order-brushing rebate, high-risk APP general, stranger call entrance victim model, screen sharing victim model, friend entry victim model (low no communication), etc.; fraudster identification models include general voice model, machine learning voice model, wired mobile phone port model, wireless mobile phone port model, conversion terminal model (one card multiple terminals), old terminal model, high-risk APP general, high-risk APP secret chat type, high-risk APP remote control conference type, high-risk APP virtual currency type, FaceTime (video call service) anti-fraud model, domestic roaming voice model, international roaming voice model, Internet account model, general fraudster model (low no communication), etc., and can be deployed to the model application layer.
[0135] Table 3. Different types of models.
[0136]
[0137]
[0138] In this embodiment, a multi-dimensional analysis method (involving independent identification strategies for different fraudulent behaviors (for example, APPs, phone calls, etc.)) is used to identify various fraudulent behaviors in historical data, and a labeling system is established. A set of preset graph algorithms for identifying fraudulent APPs, calls, and other behaviors is established. Through the fraud identification system, fraudulent behaviors and den clusters are accurately identified, and the fraud entity is traced and predicted, thereby eliminating the generation of fraudulent information.
[0139] This application also provides a fraud identification device, please refer to Figure 4 , the fraudulent behavior identification device includes:
[0140] An acquisition module 10 is configured to acquire first telecommunication network data of a user to be identified;
[0141] A construction module 20 is configured to construct a target graph based on the first telecommunication network data;
[0142] The identification module 30 is used to output a target identification result based on the target graph through a preset graph algorithm. The target identification result includes the fraudulent behaviors of the user to be identified and the correlation between the fraudulent behaviors.
[0143] In one embodiment, the building block 20 includes:
[0144] an extraction submodule, configured to extract data features of the first telecommunication network data, wherein the data features include entity features, relationship features between entities, and attribute features of entities;
[0145] A definition submodule, configured to define each node of the target graph to be constructed based on the entity features, define each edge of the target graph to be constructed based on the relationship features, and assign target attributes to each node based on the attribute features;
[0146] The construction submodule is used to construct a target graph based on each of the nodes, each of the edges, and the target attributes corresponding to each node.
[0147] In one embodiment, the entity features include multiple fraud pathways, the target graph includes graph information corresponding to each fraud pathway, the target recognition result includes recognition results corresponding to each fraud pathway, and the recognition module 30 includes:
[0148] a response submodule, configured to respond to an analysis requirement for a target fraud pathway and output an identification result corresponding to the target fraud pathway through a preset graph algorithm based on graph information corresponding to the target fraud pathway in the target graph;
[0149] The identification module 30 further includes:
[0150] The analysis submodule is used to determine the fraud analysis result corresponding to the analysis requirement based on the identification result corresponding to the target fraud path.
[0151] In one embodiment, the fraudulent behavior identification device further includes:
[0152] A data acquisition module, configured to acquire historical second telecommunication network data of the first user;
[0153] A graph construction module, configured to construct a historical graph based on the second telecommunication network data;
[0154] a determination module, configured to determine a historical identification result based on the second telecommunication network data, and use the historical identification result as a label for the second telecommunication network data;
[0155] The training module is used to iteratively train the graph algorithm to be trained based on the historical graph and the labels until the preset conditions are met to obtain the preset graph algorithm.
[0156] In one embodiment, the second telecommunications network data includes first network behavior data and network traffic data, and the historical identification result includes historical fraudulent behavior of the historical user, and the historical fraudulent behavior includes target network fraud, abnormal traffic usage, abnormal permission request, and abnormal communication behavior;
[0157] The determining module includes at least one of the following:
[0158] A first identification submodule is configured to identify target network fraud behavior based on the first network behavior data and using a preset behavior identification model;
[0159] A second identification submodule is configured to identify abnormal traffic usage behavior based on the network traffic data using a random forest algorithm;
[0160] The third identification submodule is used to determine abnormal permission requests and / or abnormal communication behaviors based on the first network behavior data through a preset analysis tool.
[0161] In one embodiment, the preset behavior recognition model includes a first behavior recognition model and a second behavior recognition model, and the first recognition submodule includes:
[0162] a first identification unit configured to output suspected online fraud behavior using a first behavior identification model based on the first online behavior data, wherein the first behavior identification model is obtained by iteratively training an unsupervised model based on second online behavior data corresponding to normal online behavior;
[0163] The second identification unit is used to output the target network fraud behavior through a second behavior identification model based on the second network behavior data corresponding to the suspected network fraud behavior, wherein the second behavior identification model is obtained by iteratively training the reinforcement learning model based on historical third network behavior data of suspected network fraud.
[0164] The fraud identification device provided in this application utilizes the fraud identification method described in the aforementioned embodiments to address the technical issue of low fraud identification accuracy. Compared to the prior art, the fraud identification device provided in this application achieves the same beneficial effects as the fraud identification method described in the aforementioned embodiments. Other technical features of the fraud identification device are the same as those disclosed in the aforementioned embodiments and are not further elaborated upon here.
[0165] The present application provides a fraudulent behavior identification device, which includes: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions that can be executed by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to execute the fraudulent behavior identification method in the above-mentioned embodiment one.
[0166] Reference below Figure 5 , which shows a schematic diagram of the structure of a fraud identification device suitable for implementing the embodiments of the present application. The fraud identification device in the embodiments of the present application may include, but is not limited to, mobile terminals such as mobile phones, tablet computers, laptop computers, digital broadcast receivers, PDAs (Personal Digital Assistants), PMPs (Portable Media Players), and in-vehicle terminals (such as in-vehicle navigation terminals), as well as fixed terminals such as digital TVs (televisions) and desktop computers. Figure 5 The fraudulent behavior identification device shown is merely an example and should not limit the functions and scope of use of the embodiments of the present application.
[0167] like Figure 5As shown, the fraudulent behavior identification device may include a processing device 1001 (e.g., a central processing unit, a graphics processing unit, etc.), which can perform various appropriate actions and processes based on programs stored in a read-only memory (ROM) 1002 or programs loaded from a storage device 1003 into a random access memory (RAM) 1004. RAM 1004 also stores various programs and data required for the operation of the fraudulent behavior identification device. Processing device 1001, ROM 1002, and RAM 1004 are interconnected via a bus 1005. An input / output (I / O) interface 1006 is also connected to the bus. Typically, the following systems can be connected to I / O interface 1006: input devices 1007, such as a touchscreen, touchpad, keyboard, mouse, image sensor, microphone, accelerometer, gyroscope, etc.; output devices 1008, such as a liquid crystal display (LCD), speaker, vibrator, etc.; storage device 1003, such as a magnetic tape or hard disk; and communication device 1009. Communication device 1009 can allow the fraud identification device to communicate with other devices wirelessly or wired to exchange data. Although the figure shows a fraud identification device with various systems, it should be understood that it is not required to implement or have all of the systems shown. More or fewer systems can be implemented or provided instead.
[0168] In particular, according to the embodiments disclosed in the present application, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, the embodiments disclosed in the present application include a computer program product comprising a computer program carried on a computer-readable medium, the computer program comprising program code for executing the method shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from a network via a communication device, or installed from a storage device 1003, or installed from a ROM 1002. When the computer program is executed by the processing device 1001, the above-mentioned functions defined in the method of the embodiment disclosed in the present application are executed.
[0169] The fraudulent behavior identification device provided in this application utilizes the fraudulent behavior identification method described in the aforementioned embodiment to address the technical issue of low fraudulent behavior identification accuracy. Compared to the prior art, the fraudulent behavior identification device provided in this application achieves the same beneficial effects as the fraudulent behavior identification method described in the aforementioned embodiment. Other technical features of the fraudulent behavior identification device are the same as those disclosed in the aforementioned embodiment and are not further elaborated here.
[0170] It should be understood that the various parts disclosed in this application can be implemented using hardware, software, firmware, or a combination thereof. In the description of the above embodiments, specific features, structures, materials, or characteristics can be combined in any one or more embodiments or examples in a suitable manner.
[0171] The above description is merely a specific embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in this application should be included in the scope of protection of this application. Therefore, the scope of protection of this application should be based on the scope of protection of the claims.
[0172] The present application provides a computer-readable storage medium having computer-readable program instructions (ie, computer program) stored thereon, wherein the computer-readable program instructions are used to execute the fraudulent behavior identification method in the above-mentioned embodiment.
[0173] The computer-readable storage medium provided in this application may be, for example, a USB flash drive, but is not limited to electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems, systems or devices, or any combination thereof. More specific examples of computer-readable storage media may include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination thereof. In this embodiment, the computer-readable storage medium may be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, system or device. The program code contained on the computer-readable storage medium may be transmitted using any appropriate medium, including but not limited to: wires, optical cables, RF (Radio Frequency), etc., or any suitable combination thereof.
[0174] The computer-readable storage medium may be included in the fraudulent behavior identification device, or may exist independently without being incorporated into the fraudulent behavior identification device.
[0175] The computer-readable storage medium carries one or more programs. When the one or more programs are executed by the fraudulent behavior identification device, the fraudulent behavior identification device executes the fraudulent behavior identification method.
[0176] Computer program code for performing the operations of the present application may be written in one or more programming languages, or a combination thereof, including object-oriented programming languages such as Java, Smalltalk, C++, and conventional procedural programming languages such as "C" or similar programming languages. The program code may be executed entirely on the user's computer, partially on the user's computer, as a stand-alone software package, partially on the user's computer and partially on a remote computer, or entirely on the remote computer or server. In cases involving a remote computer, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., through the Internet using an Internet service provider).
[0177] The flow charts and block diagrams in the accompanying drawings illustrate the possible architecture, functions and operations of the systems, methods and computer program products according to the various embodiments of the present application. In this regard, each box in the flow chart or block diagram can represent a module, program segment or a part of code, and the module, program segment or a part of code contains one or more executable instructions for realizing the prescribed logical functions. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in a different order than that marked in the accompanying drawings. For example, two boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram and / or flow chart, and the combination of the boxes in the block diagram and / or flow chart can be implemented by a dedicated hardware-based system that performs the prescribed function or operation, or can be implemented by a combination of dedicated hardware and computer instructions.
[0178] The modules described in the embodiments of the present application may be implemented in software or hardware, wherein the name of a module does not necessarily limit the unit itself.
[0179] The computer-readable storage medium provided in this application stores computer-readable program instructions (i.e., a computer program) for executing the aforementioned fraudulent behavior identification method, thereby resolving the technical issue of low fraudulent behavior identification accuracy. Compared to the prior art, the beneficial effects of the computer-readable storage medium provided in this application are the same as those of the fraudulent behavior identification method provided in the aforementioned embodiments, and are not further elaborated here.
[0180] The present application also provides a computer program product, comprising a computer program, which implements the steps of the above-mentioned fraudulent behavior identification method when executed by a processor.
[0181] The computer program product provided in this application can solve the technical problem of low accuracy in identifying fraudulent behavior. Compared with the prior art, the beneficial effects of the computer program product provided in this application are the same as those of the fraudulent behavior identification method provided in the above embodiment, and will not be repeated here.
[0182] The above description is only part of the embodiments of the present application and does not limit the patent scope of the present application. All equivalent structural transformations made by using the contents of the present application specification and drawings under the technical concept of the present application, or direct / indirect application in other related technical fields are included in the patent protection scope of the present application.
Claims
1. A fraudulent behavior identification method, characterized in that: The method includes: Acquiring first telecommunication network data of the user to be identified; constructing a target graph based on the first telecommunications network data; Based on the target graph, a target recognition result is outputted through a preset graph algorithm, where the target recognition result includes the fraudulent behaviors of the user to be identified and the correlation between the fraudulent behaviors.
2. The method according to claim 1, wherein The step of constructing a target graph based on the first telecommunication network data includes: Extracting data features of the first telecommunication network data, the data features including entity features, relationship features between entities, and attribute features of entities; Defining each node of the target graph to be constructed based on the entity features, defining each edge of the target graph to be constructed based on the relationship features, and assigning target attributes to each node based on the attribute features; A target graph is constructed based on the nodes, the edges, and the target attributes corresponding to the nodes.
3. The method according to claim 2, wherein The entity features include multiple fraud pathways, the target graph includes graph information corresponding to each fraud pathway, the target recognition result includes recognition results corresponding to each fraud pathway, and the step of outputting the target recognition result based on the target graph using a preset graph algorithm includes: In response to an analysis requirement for a target fraud pathway, based on graph information corresponding to the target fraud pathway in the target graph, outputting an identification result corresponding to the target fraud pathway through a preset graph algorithm; Wherein, after the step of outputting the target recognition result based on the target graph by using a preset graph algorithm, the method further includes: Based on the identification result corresponding to the target fraud path, a fraud analysis result corresponding to the analysis requirement is determined.
4. The method according to claim 1, wherein Before the step of obtaining the first telecommunication network data of the user to be identified, the method further includes: Obtaining the second telecommunication network data of the historical first user; constructing a historical graph based on the second telecommunication network data; determining a historical identification result based on the second telecommunication network data, and using the historical identification result as a label for the second telecommunication network data; Based on the historical graph and the labels, the graph algorithm to be trained is iteratively trained until a preset condition is met, thereby obtaining the preset graph algorithm.
5. The method according to claim 4, wherein The second telecommunications network data includes the first network behavior data and network traffic data, the historical identification result includes historical fraudulent behavior of the historical user, and the historical fraudulent behavior includes target network fraud, abnormal traffic usage, abnormal permission request, and abnormal communication behavior; The step of determining a historical identification result based on the second telecommunications network data includes at least one of the following: Based on the first network behavior data, identifying target network fraud behavior through a preset behavior recognition model; Based on the network traffic data, identifying abnormal traffic usage behavior through a random forest algorithm; Based on the first network behavior data, abnormal permission requests and / or abnormal communication behaviors are determined through a preset analysis tool.
6. The method according to claim 5, wherein The preset behavior recognition model includes a first behavior recognition model and a second behavior recognition model. The step of identifying the target network fraud behavior based on the first network behavior data using the preset behavior recognition model includes: Based on the first network behavior data, outputting suspected network fraud behavior using a first behavior recognition model, wherein the first behavior recognition model is obtained by iteratively training an unsupervised model based on second network behavior data corresponding to normal network behavior; Based on the second network behavior data corresponding to the suspected network fraud behavior, the target network fraud behavior is output through the second behavior recognition model, wherein the second behavior recognition model is obtained by iteratively training the reinforcement learning model based on the historical third network behavior data of suspected network fraud.
7. A fraudulent behavior identification device, characterized in that: The device comprises: An acquisition module, configured to acquire first telecommunication network data of a user to be identified; A construction module, configured to construct a target graph based on the first telecommunications network data; The identification module is used to output a target identification result based on the target graph through a preset graph algorithm, and the target identification result includes the fraudulent behavior of the user to be identified and the correlation relationship between each fraudulent behavior.
8. A fraudulent behavior identification device, characterized in that: The device includes: a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the computer program is configured to implement the steps of the fraudulent behavior identification method according to any one of claims 1 to 6.
9. A storage medium, characterized in that: The storage medium is a computer-readable storage medium, and a computer program is stored on the storage medium. When the computer program is executed by a processor, the steps of the fraudulent behavior identification method according to any one of claims 1 to 6 are implemented.
10. A computer program product, characterized in that The computer program product comprises a computer program, and when the computer program is executed by a processor, the steps of the fraudulent behavior identification method according to any one of claims 1 to 6 are implemented.
Citation Information
Patent Citations
Internet financial gang fraud behavior detection method based on knowledge graph
CN112053221A
Communication fraud identification method and device, and electronic equipment
CN113727351A
Fraud risk identification method and device, electronic equipment and storage medium
CN116308408A
Fraud detection method and device, equipment and storage medium
CN117172875A
Financial fraud risk identification method, electronic equipment and storage medium
CN118467755A
Cited By
Number card anti-fraud risk control method based on dynamic risk assessment model
CN120812590A