Anti-addiction warning method and system based on network traffic data analysis

By collecting device status data, using a hybrid discriminant model to identify usage scenarios, and analyzing and evaluating addictive behavior based on network traffic data, the problem of misjudgment of anti-addiction systems in existing technologies is solved, and more accurate anti-addiction warnings are achieved.

CN120472630BActive Publication Date: 2025-09-26联通(陕西)产业互联网有限公司
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202510968625.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-07-15
Publication Date
2025-09-26
Estimated Expiration
2045-07-15

AI Technical Summary

Technical Problem

Existing anti-addiction systems rely on users' page access data or application usage time, and lack understanding of users' actual usage scenarios, resulting in misjudgments or failed interventions, affecting the accuracy of anti-addiction warnings.

Method used

By collecting the target user's device status data, using the rule-learning hybrid discriminant model to identify usage scenarios, and establishing a mapping relationship between scenarios and addictive behaviors based on network traffic data analysis, the addictive behavior is scored, and the comprehensive score is used to send anti-addiction warning signals.

Benefits of technology

It improves the accuracy of anti-addiction warnings, avoids the problem of inaccurate intervention caused by a single model, and achieves more accurate identification and intervention of addictive behaviors.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120472630B_ABST
    Figure CN120472630B_ABST
Patent Text Reader

Abstract

The present application provides an anti-addiction warning method and system based on network traffic data analysis, which relates to the technical field of network traffic data analysis. The method includes: collecting device status data of a target user's authorized mobile device; inputting a scene recognition module to obtain the current usage scene; establishing a mapping relationship between the target user and the network traffic data in each usage scene, weighting the current usage scene with an addiction behavior score, and outputting a first addiction score; scoring the cross-scene addiction behavior of continuous usage scenes, and outputting a second addiction score; combining the first addiction score and the second addiction score to output a comprehensive addiction score, and sending an anti-addiction warning signal to the authorized mobile device. This application solves the technical problem in the prior art that anti-addiction relies heavily on the user's page access data, lacks consideration of the actual usage scene, and is prone to misjudgment or intervention failure. By combining usage scenarios, the accuracy of anti-addiction warnings is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the technical field of network traffic data analysis, and in particular to an anti-addiction warning method and system based on network traffic data analysis. Background Art

[0002] With the increasing prevalence of mobile devices and fragmented application usage, users' online behavior is no longer limited to a single scenario. Instead, they continuously use online services across multiple scenarios (such as learning, entertainment, and rest), forming an addictive characteristic of continuous use across multiple scenarios. Currently, most anti-addiction systems rely primarily on users' web page access data or application usage time to assess addictive behavior, setting static time or frequency thresholds for anti-addiction warnings. Because users use different online services in different scenarios, for example, if a user uses educational applications for a long time during the learning process, judging addictive behavior based solely on duration or access frequency may misjudge normal use as addictive behavior or miss true addictive behavior, resulting in misjudgment or ineffective intervention.

[0003] To sum up, there are technical problems in the existing technology because anti-addiction measures mostly rely on users' page access data or application usage time, lack of understanding of users' actual usage scenarios, and are prone to misjudgment or intervention failure, thus affecting the accuracy of anti-addiction warnings. Summary of the Invention

[0004] The purpose of this application is to provide an anti-addiction warning method and system based on network traffic data analysis, in order to solve the technical problems in the existing technology that anti-addiction relies more on the user's page access data or application usage time, lacks the understanding of the user's actual usage scenarios, is prone to misjudgment or intervention failure, and thus affects the accuracy of anti-addiction warnings.

[0005] In view of the above problems, this application provides an anti-addiction warning method and system based on network traffic data analysis.

[0006] In the first aspect, the present application provides an anti-addiction warning method based on network traffic data analysis, which is implemented by an anti-addiction warning system based on network traffic data analysis, wherein the anti-addiction warning method based on network traffic data analysis includes: collecting device status data of the target user's authorized mobile device; inputting the device status data into a scene recognition module to obtain the target user's current usage scene; establishing a mapping relationship between the target user and the network traffic data in each usage scene, and performing an addiction behavior weight score on the network traffic data corresponding to the current usage scene based on the mapping relationship and a pre-built scene addiction weight model, and outputting a first addiction score; performing a cross-scene addiction behavior score on the network traffic data corresponding to the target user in the continuous usage scene, and outputting a second addiction score; combining the first addiction score and the second addiction score to output a comprehensive addiction score, and sending an anti-addiction warning signal to the authorized mobile device according to the comprehensive addiction score.

[0007] Optionally, feature extraction is performed on the device status data to obtain key feature variables for scene recognition, wherein the device status data includes time information, location information, screen status and usage status; the key feature variables are combined and input into the scene recognition module, wherein the scene recognition module includes a pre-trained rule-learning hybrid discriminant model, the rule-learning hybrid discriminant model includes a discriminant rule layer and a machine learning layer, and the scene recognition module outputs the current usage scenario of the target user.

[0008] Optionally, the scene recognition module also includes a timing analysis layer, which is connected to the input end of the discrimination rule layer and the machine learning layer; constructs a timing sample window to perform timing processing on the device status data to obtain processed device timing status data; performs scene transfer node prediction on the device timing status data through the timing analysis layer, and outputs multiple scene transfer nodes; divides the device timing status data according to the multiple scene transfer nodes, outputs multiple device timing status data, and outputs multiple usage scenarios corresponding to the multiple device timing status data according to the rule-learning hybrid discrimination model.

[0009] Optionally, the scene recognition module includes a pre-trained rule-learning hybrid discriminant model, and the rule-learning hybrid discriminant model includes a discriminant rule layer and a machine learning layer; the discriminant rule layer and the machine learning layer are confidence fusion weighted modeled, and a rule-learning hybrid discriminant model is output; wherein, the discriminant rule layer includes a defined initial fuzzy discriminant rule set and corresponding usage scenario labels; a training data set is collected, and the training data set is used to perform model parameter supervised training to obtain a trained machine learning layer, wherein the training data set includes device status data samples under multiple known scene labels.

[0010] Optionally, a time series sample window is constructed to perform time series processing on the collected network traffic data to obtain processed network time series traffic data; the network time series traffic data is divided according to the multiple scenario transfer nodes, and multiple network time series traffic data are output; according to the multiple scenario transfer nodes and the multiple network time series traffic data, a mapping relationship between the target user and the network traffic data in each usage scenario is established.

[0011] Optionally, based on the mapping relationship, key indicators of network traffic data in the current usage scenario are extracted, including the total application traffic, data packet frequency, communication protocol characteristics and connection duration of the same access application; the corresponding addiction behavior weight in the current usage scenario is obtained according to the scenario addiction weight model; the key indicators are subjected to logistic regression scoring calculation according to the corresponding addiction behavior weight in the current usage scenario, and the first addiction score in the current usage scenario is output.

[0012] Optionally, the scenario addiction weight model is used to obtain the corresponding addiction behavior weight in the current usage scenario, wherein the addiction behavior weight includes content stickiness weight, usage time period weight, usage duration weight, task irrelevance weight and frequent switching weight.

[0013] Optionally, continuous usage scenarios of the target user within a preset period are obtained, and a continuous usage scenario sequence is output; cross-scenario behavior feature extraction is performed on the network traffic data corresponding to the continuous usage scenario, and a cross-scenario behavior feature vector is output, including behavior continuity feature, immersion time superposition feature, deviation behavior feature and short-term switching frequency feature; an addiction behavior weight sequence corresponding to the continuous usage scenario sequence is obtained; the cross-scenario behavior feature vector is calculated according to the addiction behavior weight sequence, and a second addiction score is output.

[0014] Optionally, a preset addiction score threshold is obtained according to the identity information of the target user; when the comprehensive addiction score is greater than the preset addiction score threshold, an anti-addiction warning signal is sent to the authorized mobile device.

[0015] In the second aspect, the present application also provides an anti-addiction warning system based on network traffic data analysis, which is used to execute the anti-addiction warning method based on network traffic data analysis as described in the first aspect, wherein the anti-addiction warning system based on network traffic data analysis includes: a device status acquisition module, which is used to collect device status data of the target user's authorized mobile device; a usage scenario determination module, which is used to input the device status data into the scene recognition module to obtain the current usage scenario of the target user; a first scoring module, which is used to establish a mapping relationship between the target user and the network traffic data in each usage scenario, and based on the mapping relationship and the pre-built scene addiction weight model, perform an addiction behavior weight score on the network traffic data corresponding to the current usage scenario, and output a first addiction score; a second scoring module, which is used to perform a cross-scenario addiction behavior score on the network traffic data corresponding to the target user in the continuous usage scenario, and output a second addiction score; an addiction warning module, which is used to integrate the first addiction score and the second addiction score, output a comprehensive addiction score, and send an anti-addiction warning signal to the authorized mobile device according to the comprehensive addiction score.

[0016] One or more technical solutions provided in this application have at least the following beneficial effects:

[0017] By collecting the device status data of the target user's authorized mobile device; inputting the device status data into the scene recognition module to obtain the target user's current usage scene; establishing a mapping relationship between the target user in each usage scene and the network traffic data, and based on the mapping relationship and the pre-built scene addiction weight model, performing an addiction behavior weight score on the network traffic data corresponding to the current usage scene, and outputting a first addiction score; performing a cross-scene addiction behavior score on the network traffic data corresponding to the target user in the continuous use scene, and outputting a second addiction score; combining the first addiction score and the second addiction score to output a comprehensive addiction score, and sending an anti-addiction warning signal to the authorized mobile device according to the comprehensive addiction score. In other words, by obtaining the device status data of the target user's authorized mobile device, judging the user's current usage scene, establishing a mapping relationship between the scene and the network traffic data, scoring the user's addiction behavior according to the characteristics of each usage scene, and performing a cross-scene addiction behavior score on the continuous use scene, and combining the addiction score, sending an anti-addiction warning signal, avoiding the intervention inaccuracy problem caused by a single model, and improving the accuracy of the anti-addiction warning.

[0018] The above description is only an overview of the technical solution of the present application. In order to more clearly understand the technical means of the present application, which can be implemented in accordance with the contents of the description, and to make the above and other purposes, features and advantages of the present application more obvious and easy to understand, the specific implementation methods of the present application are specifically listed below. It should be understood that the content described in this section is not intended to identify the key or important features of the embodiments of the present application, nor is it intended to limit the scope of the present application. Other features of the present application will become easy to understand through the following description. BRIEF DESCRIPTION OF THE DRAWINGS

[0019] In order to more clearly illustrate the technical solutions in this application or the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are merely exemplary, and a person of ordinary skill in the art can obtain other drawings based on the provided drawings without creative work.

[0020] Figure 1 This is a flow chart of the anti-addiction warning method based on network traffic data analysis in this application.

[0021] Figure 2 This is a structural diagram of the anti-addiction warning system based on network traffic data analysis in this application.

[0022] Description of the accompanying drawings: device status acquisition module 11, usage scenario determination module 12, first scoring module 13, second scoring module 14, addiction warning module 15. DETAILED DESCRIPTION

[0023] This application solves the technical problem in the prior art that anti-addiction warnings are prone to misjudgment or intervention failure, thus affecting the accuracy of anti-addiction warnings, by providing an anti-addiction warning method and system based on network traffic data analysis. This method relies heavily on users' page access data or application usage time, lacks awareness of users' actual usage scenarios, and is prone to misjudgment or intervention failure, thereby affecting the accuracy of anti-addiction warnings. By obtaining the device status data of the target user's authorized mobile device, judging the user's current usage scenario, and establishing a mapping relationship between the scenario and network traffic data, the user's addiction behavior is scored according to the characteristics of each usage scenario, and cross-scenario addiction behavior scores are performed for continuous usage scenarios. The comprehensive addiction score is used to send anti-addiction warning signals, avoiding the problem of inaccurate intervention caused by a single model, and improving the accuracy of anti-addiction warnings.

[0024] Below, the technical solutions in this application will be clearly and completely described with reference to the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of this application, rather than all the embodiments of this application. It should be understood that this application is not limited to the example embodiments described herein. Based on the embodiments of this application, all other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of this application. It should also be noted that, for the convenience of description, only the parts related to this application, rather than all of them, are shown in the accompanying drawings.

[0025] For example, see the attached Figure 1 The present application provides an anti-addiction warning method based on network traffic data analysis, wherein the anti-addiction warning method based on network traffic data analysis is executed by an anti-addiction warning system based on network traffic data analysis, and the anti-addiction warning method based on network traffic data analysis specifically includes the following steps:

[0026] S100: Collecting device status data of a target user's authorized mobile device.

[0027] Specifically, the target user must explicitly authorize the collection of device status data on their mobile device, typically through authorization within the app or system settings. For example, upon first use of an app, a privacy agreement will pop up, clearly informing the user that data such as their location, device status, and app usage will be collected for monitoring and early warning of addictive behavior, and requesting user authorization. If the user refuses authorization, the mobile device will not be able to collect their device data.

[0028] After obtaining user authorization, real-time data collection begins via various sensors and APIs on the authorized mobile device (such as GPS positioning services, accelerometers, and device management APIs). Using the GPS positioning interface, the user's geographic location is obtained at regular intervals (e.g., every minute) to identify the user's behavior, such as whether the user is at home, school, or work. For example, between 9:00 and 12:00, the user's location can be determined to be at school based on their connection to the school network. Screen brightness data is obtained by accessing the authorized mobile device's system API, and the duration of each screen activation is recorded (e.g., screen brightness data for each use exceeding 5 minutes). For example, if a user uses a learning app between 9:00 and 10:00 AM, the screen brightness is 300 cd / m² for 60 minutes; while using a social app between 8:00 and 9:00 PM, the screen brightness is 100 cd / m² for 30 minutes.

[0029] The system interface collects the current system time, the applications used by the user, and their usage duration. For example, a user used a learning app for 10 minutes, a gaming app for 15 minutes, and a social app for 20 minutes within a certain period. Furthermore, the accelerometer can monitor the device's motion status, such as whether the user was walking, running, or stationary, helping to distinguish the user's activity status. For example, between 10:00 AM and 11:00 AM, the device detected that the user was stationary (acceleration of 0.2g). By analyzing the device's network connection (such as Wi-Fi, 4G / 5G, etc.), it can be determined whether the user is continuously connected to the network or disconnected. The battery voltage and power consumption statistics service are continuously monitored by the built-in fuel gauge chip in the authorized mobile device to calculate power consumption. For example, between 2:00 PM and 6:00 PM, the authorized mobile device was connected to the home network, the network status was good, and the average download speed was 800Mbps.

[0030] The frequency of data collection can be determined based on specific needs and privacy compliance requirements. For example, location data can be collected every 30 seconds, app usage time can be updated every 10 seconds, and screen brightness can be collected every minute. The collected data needs to be stored in the local device cache, anonymized, and regularly uploaded to the cloud for further processing and analysis. By collecting device status data and comprehensively considering multiple dimensions such as user location, usage scenarios, and app behavior, we can gain a comprehensive understanding of the user's behavioral context.

[0031] S200: Inputting the device status data into a scene recognition module to obtain the current usage scene of the target user.

[0032] Furthermore, the present application S200 includes:

[0033] Feature extraction is performed on the device status data to obtain key feature variables for scene recognition, wherein the device status data includes time information, location information, screen status and usage status; the key feature variables are combined and input into the scene recognition module, wherein the scene recognition module includes a pre-trained rule-learning hybrid discriminant model, the rule-learning hybrid discriminant model includes a discriminant rule layer and a machine learning layer, and the scene recognition module outputs the current usage scenario of the target user.

[0034] The scene recognition module includes a pre-trained rule-learning hybrid discriminant model, which includes a discriminant rule layer and a machine learning layer; the discriminant rule layer and the machine learning layer are confidence fusion weighted modeled to output a rule-learning hybrid discriminant model; wherein, the discriminant rule layer includes a defined initial fuzzy discriminant rule set and corresponding usage scenario labels; a training data set is collected, and the training data set is used to perform model parameter supervised training to obtain a trained machine learning layer, wherein the training data set includes device status data samples under multiple known scene labels.

[0035] Specifically, we extract important variable features from device status data to generate key feature vectors for scene recognition. Device status data includes at least time information (such as the current system time and continuous usage duration), location information (latitude and longitude data obtained through GPS / Wi-Fi / base station positioning), item status (whether the screen is on and how long it lasts), and usage status (type of applications currently running in the foreground, switching frequency, and input interaction activity).

[0036] Specific time information for each usage period is extracted from the device's usage history, including the specific date and time (e.g., weekdays, weekends) the user used the authorized mobile device, and the time of day (e.g., morning, lunch break, evening). The user's geographic location is then extracted based on GPS positioning data. For example, if a user spends a significant amount of time in a specific area, such as school, library, or home, it can be inferred that the user is in a learning setting. If a user spends a significant amount of time in an entertainment area, shopping mall, or cafe, it can be inferred that the user is in an entertainment setting. Frequent location changes (e.g., from home to school, from the office to a cafe, etc.) can be used as a signal of scene transitions to identify whether the user is engaging in cross-scene activities.

[0037] By analyzing the duration of device screen on time, we can determine user usage time. For example, if a user continuously uses an educational app for over 60 minutes, it indicates a learning situation. If a user keeps social and entertainment apps open for extended periods at night, it indicates an obsessive behavior. Based on screen brightness data, we can infer the user's usage environment. For example, if a user's screen brightness is higher during the day and lower at night, we can infer whether the user is in a static environment (such as studying or working) or a dynamic environment (such as walking or eating).

[0038] By monitoring a user's app usage history, we can extract the duration and frequency of app use. For example, if a user uses educational apps for an extended period of time, this is classified as a learning scenario. If a user uses gaming or entertainment apps continuously at night, exceeding a certain threshold, this is considered an addiction. By recording the types of apps used on a device (such as social media, videos, games, and office apps), we can infer user behavior patterns. For example, if a user frequently uses social, office, or learning apps, they are likely working or studying normally. If a user frequently uses gaming or entertainment apps, they are likely addicted.

[0039] Based on the extracted features, key feature vectors for scene recognition are derived, including user behavior patterns over time, location, screen behavior, and application usage. For example, time information can be converted into the user's active hours (morning, lunch break, evening, etc.); location information is used to identify whether the user is at work, home, or entertainment venues; screen status (such as screen brightness and touch behavior) is used to determine whether the user is actively using the system; and usage status reflects whether the user is currently playing games, studying, or resting.

[0040] The scene recognition module includes a pre-trained rule-based hybrid discriminant model, combining a discriminant rule layer and a machine learning layer to improve scene recognition accuracy. The discriminant rule layer uses predefined rules for rapid judgment, while the machine learning layer is trained based on historical data and autonomously learns to discriminate complex scenes. The rule-based hybrid discriminant model combines these two layers and performs a weighted fusion based on actual application scenarios.

[0041] The discrimination rule layer consists of an initial fuzzy discrimination rule set defined by experts and corresponding usage scenario labels. Based on expert experience, some fuzzy discrimination rules are defined. The initial fuzzy discrimination rule set includes multiple fuzzy discrimination rules. The usage scenario label is the corresponding label of the scenario in which each fuzzy discrimination rule is located, which is used to indicate the specific scenario in which the user is currently located, such as learning, office, entertainment, etc. For example, if the authorized mobile device is located at home, and the application used is an entertainment or game application, and the duration is greater than one hour, it is determined to be an entertainment scene; if the authorized mobile device is located in an office building, and the application used is a social application and an office application, it is determined to be an office scene. Based on fuzzy discrimination rules, some common and obvious situations can be quickly judged, but for complex user behavior scenarios, simple rules may not be able to fully cover them.

[0042] Each fuzzy discrimination rule includes a threshold, typically based on common addictive behaviors derived from extensive data analysis. Furthermore, each fuzzy discrimination rule possesses a degree of fuzziness, allowing for flexibility under specific conditions and tolerating fluctuations and uncertainties in user behavior. For example, a user's 30 minutes of social media use between 9 PM and 11 PM might, in some cases, be considered entertainment, even though this behavior doesn't fully conform to the fuzzy discrimination rule.

[0043] Device status data is input into the discrimination rule layer, where it is judged based on the initial fuzzy discrimination rule set. The corresponding fuzzy discrimination rule is determined, and the corresponding usage scenario label is output as a preliminary judgment for scene recognition. Due to the constant changes in user behavior and device status, the initially defined fuzzy discrimination rule set may become less accurate over time and with the addition of new data. By collecting large amounts of new behavioral data and user feedback, experts can adjust the rule set. For example, if the judgment results for certain scenarios are found to be poor, experts can adjust the threshold or add new rules to improve the judgment results.

[0044] By collecting status data samples from authorized mobile devices and similar devices, a training dataset is generated. This dataset contains user time information, location information, screen status, and usage status. Each device status data sample includes a known scenario label. The training dataset needs to cover a variety of different scenarios and user behaviors and be representative. For example, if the scenario label is "learning," the device status data includes: time information (8:00 AM - 6:00 PM), location information (school), screen brightness (400 cd / m²), and usage status (45 minutes of learning app use with 15-minute intervals). If the scenario label is "entertainment," the device status data includes: time information (10:00 PM - 12:00 AM), location information (home), screen brightness (150 cd / m²), and usage status (game app use / entertainment app use / mixed app use for more than 60 minutes). If the scenario label is "work," the device status data includes: time information (8:00 AM - 6:00 PM), location information (office building), screen brightness (400 cd / m²), and usage status (work app / social app use for more than 3 hours).

[0045] Preprocess the training dataset, including removing irrelevant or noisy data, normalizing, and standardizing. This eliminates the influence of irrelevant data and different dimensions, and converts the features in the training dataset into numerical features to facilitate input into the machine learning model. Each data sample in the training dataset includes device state features (time, location, screen state, application state, etc.) and corresponding known scenario labels (such as learning, entertainment, social networking, and office work).

[0046] After the training dataset is collected, an appropriate machine learning model, such as a random forest classifier, is selected. The random forest classifier is a decision tree-based ensemble learning method that generates multiple decision trees and votes on the outputs of all trees to determine the final classification result. Each decision tree is trained on a different subset of the training data. The ensemble of random forests effectively reduces the risk of overfitting of individual decision trees, thereby improving classification accuracy and robustness. The training dataset is divided into an 80% training set and a 20% validation set. The device status data (input) and its corresponding scenario labels (output) from the training set are input into the random forest classifier. Data is randomly sampled from the training set (with replacement), and a subset of features is randomly selected from the features to generate each decision tree. The CART algorithm is used to make splitting decisions for each tree. At each node split, a subset of features is randomly selected for the optimal split, rather than using all features, to reduce the risk of overfitting. Each decision tree continues splitting, starting from the root node, using features from the training data until the maximum tree depth is reached or the number of samples in the node falls below the preset minimum number of samples. For example, assuming the maximum depth is 10 and the minimum number of samples is 5, each tree will grow under these two conditions until these constraints are met.

[0047] As multiple decision trees are generated, the random forest will vote on the predictions of each tree to arrive at a final prediction. For example, if there are 100 trees, 80 of which predict the scenario as learning and 20 predict the scenario as entertainment, the final prediction scenario will be learning. With each round of training, the model will continuously optimize its parameters to improve the accuracy of predictions for new samples. The loss function (such as cross-entropy loss) during supervised training guides model optimization, reducing prediction errors by continuously adjusting the structure of the decision tree. For example, using cross-validation techniques, the training dataset is divided into multiple subsets (e.g., 10 subsets). In each training session, 9 subsets are used as training sets, and the remaining subset is used as a validation set. Hyperparameters such as the number of trees, maximum depth, and minimum number of samples are adjusted based on the validation results of the validation set.

[0048] After training, the random forest classifier can predict the corresponding scene label based on input device status data (such as time, location, and usage status). The random forest model can provide voting or weighted decisions by integrating the results of multiple decision trees to ensure the accuracy of the final scene label prediction. Confidence fusion weight modeling is performed on the discriminant rule layer and the machine learning layer. This combines the predictions of the two layers to produce a more confident final prediction. Confidence fusion typically involves taking a weighted average of the outputs of different models or determining the final output through voting or weighted voting. During the fusion process, the output of each model (the discriminant rule layer and the machine learning layer) is assigned a weight. This weight can be based on model accuracy, robustness, or other evaluation metrics, with higher weights generally assigned to higher-performing models. The purpose of weight modeling is to dynamically adjust the fusion results based on the confidence of different models, thereby enhancing the predictive capabilities of the rule-learning hybrid discriminant model.

[0049] The discriminant rule layer makes a preliminary judgment on device status data based on a predefined set of fuzzy rules and outputs a scenario label. The discriminant rule layer makes preliminary scenario judgments based on simple conditions (such as time, location, screen status, and app usage), but its accuracy is low, especially when dealing with complex and ambiguous user behaviors. The machine learning layer uses supervised learning from training data to predict user behavior scenarios. Device status data is input into the machine learning layer, which outputs a predicted scenario label. The prediction results from the discriminant rule layer and the machine learning layer are combined to produce a more accurate scenario label based on confidence scores. Each model (discriminant rule layer and machine learning layer) is assigned a weight. For example, the machine learning layer receives a higher weight due to its ability to learn complex patterns from large amounts of data, while the discriminant rule layer receives a lower weight due to its fast response but slightly lower accuracy. The output results (scenario labels) of the two models are voted on, and the voting weights are allocated according to their respective accuracy. For example, the weight of the machine learning layer is 70%, and the weight of the discriminant rule layer is 30%. Assuming that the discriminant rule layer predicts that the current usage scenario of the target user is learning with a confidence of 0.7, and the machine learning layer predicts that the current usage scenario of the target user is learning with a confidence of 0.9, the confidence fusion result is the final confidence = 0.4*0.7+0.6*0.9=0.82. If the final confidence is greater than the preset threshold (such as 0.75), the scene label learning is considered to be the final prediction result.

[0050] After confidence fusion, the rule-learning hybrid discriminant model outputs the final scenario label, which is a weighted fusion of the prediction results of the discriminant rule layer and the machine learning layer, taking into account the advantages of both, as the target user's current usage scenario. For example, assuming that the key feature variables extracted from the device status data of an authorized mobile device include: time is morning, location is school, device screen brightness is 400cd / m², and the user uses a learning app for 60 minutes, the discriminant rule layer makes an initial prediction of the scenario as learning, and the rule-based reasoning result is accurate to 70%, the confidence level is 0.7; the device status data is input into the machine learning layer, and the usage scenario is identified as learning. The model learned by the machine learning layer through historical data predicts a learning scenario with a probability of 90% for the input device status data, the confidence level is 0.9, and the overall confidence level is 0.82, indicating the output is a learning scenario.

[0051] After evaluation by the rule-based and machine learning layers, the target user's current usage scenario is output—that is, the user's specific environment or activity status, such as at work or at home. By inputting device status data into the scene recognition module, the target user's current usage scenario is identified. This combines the advantages of predefined rules and machine learning to improve the accuracy and robustness of scene recognition.

[0052] Furthermore, the present application further comprises the following steps:

[0053] The scene recognition module also includes a timing analysis layer, which is connected to the input ends of the discrimination rule layer and the machine learning layer; constructs a timing sample window to perform timing processing on the device status data to obtain processed device timing status data; uses the timing analysis layer to predict scene transition nodes on the device timing status data and outputs multiple scene transition nodes; divides the device timing status data according to the multiple scene transition nodes, outputs multiple device timing status data, and outputs multiple usage scenarios corresponding to the multiple device timing status data according to the rule-learning hybrid discrimination model.

[0054] Specifically, the scene recognition module also includes a time series analysis layer, which analyzes the time series characteristics of device status data. By processing the time series of device status data, it identifies the patterns and regularities of device status changes over time. The output layer of the time series analysis layer is connected to the input of the discrimination rule layer and the machine learning layer.

[0055] In order to capture the dynamic characteristics of user behavior over time, a time series sample window is constructed to perform time series processing on the device status data. The data interval within the time period is defined to capture the changing characteristics of the device status. The device status data is processed through the time series sample window, that is, the device status data is divided into multiple time series sample windows in chronological order. The data in each window represents the device status within a continuous time period. For example, if the time series sample window is 1 hour, the device status data is divided into multiple one-hour time series sample windows. The device time series status data is data processed by the time series sample window, which contains information about changes in the device status within a continuous time period, such as the usage status, screen brightness, location, and other information of authorized mobile devices at different time points.

[0056] The processed device time series status data is passed as input to the time series analysis layer. By analyzing the authorized mobile device's location changes, screen brightness fluctuations, and usage status over a period of time, the time series analysis layer can identify user behavior trends and capture how device status changes over time. The device status data is divided into time series sample windows, forming multiple time series segments. Each segment represents device status information for a specific time period, such as 9:00 AM to 10:00 AM or 10:00 AM to 11:00 AM. The time series analysis layer analyzes the temporal changes in the device status data to identify these scene transitions. Scene transition nodes are points in time when user behavior patterns significantly change. Using sliding window technology, the device status data is locally processed to identify trends and turning points in the state transition. For example, the transition from a learning scenario to an entertainment scenario occurs.

[0057] Scene transition nodes are key nodes in the time series analysis of device state data, marking when a user switches from one scene to another. For example, a sudden change in data such as screen brightness, usage duration, and location may indicate that the user has switched from one scene to another. By analyzing the device's time series state data, multiple scene transition nodes are output, each representing a point in time when user behavior changes significantly. For example, if a user moves from school to home between 10:00 and 11:00, and switches from a learning application to an entertainment application, and the usage duration changes, this is a scene transition node.

[0058] The device time series status data is divided according to multiple scene transition nodes, and the entire time series data is divided into multiple parts. Each part corresponds to a continuous usage scenario, resulting in multiple device time series status data. The divided multiple device time series status data are input into the rule-learning hybrid discriminant model to obtain multiple usage scenarios corresponding to the multiple device time series status data, that is, the usage scenario for each divided time period. For example, based on multiple scene transition nodes, the device time series status data is divided into the learning scenario from 9:00 to 10:40 and the entertainment scenario from 10:40 to 11:00.

[0059] By introducing a timing analysis layer, we can accurately capture and understand how users' usage scenarios change over time, identify scene transition nodes, and accurately divide the usage time periods of different scenes, thus avoiding misjudgments caused by ignoring scene switching. Through scene transition node prediction and data segmentation, we can track user behavior changes in real time and adjust scene recognition strategies in a timely manner.

[0060] S300: Establish a mapping relationship between the target user in each usage scenario and the network traffic data, perform an addiction behavior weight score on the corresponding network traffic data in the current usage scenario based on the mapping relationship and a pre-built scenario addiction weight model, and output a first addiction score.

[0061] Furthermore, the present application S300 includes:

[0062] Construct a time series sample window to perform time series processing on the collected network traffic data to obtain processed network time series traffic data; divide the network time series traffic data according to the multiple scenario transfer nodes and output multiple network time series traffic data; establish a mapping relationship between the target user and the network traffic data in each usage scenario according to the multiple scenario transfer nodes and the multiple network time series traffic data.

[0063] Specifically, network traffic data from authorized mobile devices is collected and time-series sample windows are defined. These are used to divide the network traffic data into time periods, each containing a certain number of network traffic data points. The collected raw network traffic data is then divided into multiple time periods (i.e., sample windows), each typically of a fixed length, to produce processed time-series traffic data. For example, the network time-series traffic data from 9:00 to 10:00 shows a sending rate of 300 Mbps and a receiving rate of 50 Mbps; the network time-series traffic data from 10:00 to 11:00 shows a sending rate of 350 Mbps and a receiving rate of 70 Mbps.

[0064] Similarly, the network time series traffic data is divided according to multiple scene transfer nodes, that is, according to the time corresponding to the multiple scene transfer nodes, the network time series traffic data is divided into multiple network time series traffic data, each network time series traffic data corresponds to a continuous usage scene, which also corresponds to multiple device time series status data. By analyzing multiple network time series traffic data, a mapping relationship between each usage scene and the network traffic data is established, and the network traffic data corresponding to each usage scene is determined. For example, the network fluctuation in the learning scene is usually low, while the entertainment scene usually has a higher bandwidth requirement. Establishing a mapping relationship means finding the corresponding relationship between each usage scene and the network traffic data by analyzing the network traffic data characteristics in each usage scene. By constructing a time series sample window and processing the network traffic data, the user's network activity pattern over a period of time is obtained, and a mapping relationship between the user's usage scene and the network traffic is established, so as to accurately identify the user's network usage scene.

[0065] Furthermore, the present application further comprises the following steps:

[0066] Based on the mapping relationship, key indicators of network traffic data in the current usage scenario are extracted, including the total application traffic, data packet frequency, communication protocol characteristics and connection duration of the same access application; the corresponding addiction behavior weight in the current usage scenario is obtained according to the scenario addiction weight model; the key indicators are subjected to logistic regression scoring calculation according to the corresponding addiction behavior weight in the current usage scenario, and the first addiction score in the current usage scenario is output.

[0067] The scenario addiction weight model is used to obtain the corresponding addiction behavior weight in the current usage scenario, wherein the addiction behavior weight includes content stickiness weight, usage time period weight, usage duration weight, task irrelevance weight and frequent switching weight.

[0068] Specifically, based on the mapping relationship between the target user's usage scenarios and network traffic data, the mapping relationship is traversed according to the target user's current usage scenario to determine the key network traffic data indicators corresponding to the target user's current usage scenario, including the total application traffic, packet frequency, communication protocol characteristics, and connection duration for the same accessed application. Total application traffic represents the total traffic generated by the user within a specific application (such as video traffic, social network traffic, etc.); packet frequency represents the number of packets transmitted over the network per unit time, with a high frequency indicating high-frequency application interaction; communication protocol characteristics are the characteristics of the protocols used for network communication (such as HTTP, TCP, UDP, etc.), and the usage patterns of these protocols may vary in different scenarios; connection duration represents the duration of the user's connection to the network. Longer connection durations may be associated with addictive behavior. For example, the total application traffic for a user watching a 45-minute 1080P video is 1.2GB, with a packet frequency of 200-300 packets / second, TCP as the communication protocol, and a connection duration of 2 hours.

[0069] The scenario-based addiction weighting model models online behavior characteristics across different scenarios and determines the risk weights for addictive behavior in each scenario. Different scenarios (such as learning, entertainment, and socializing) correspond to different online behavior characteristics and, therefore, different addiction risks. The addictive behavior weight is a quantitative value calculated using the scenario-based addiction weighting model that describes a user's addiction risk in a specific usage scenario. A higher weight indicates a higher likelihood of addictive behavior. Typically, the addictive behavior weight ranges from [0, 1], where 0 indicates no risk of addiction and 1 indicates an extremely high risk of addiction.

[0070] Collect a large amount of user behavior data, including device status data, network traffic data, application usage data, etc. The data will have different characteristics for different scenarios. Extract features related to addictive behavior from the collected data, including total application traffic, packet frequency, connection duration, communication protocol characteristics, and behavioral patterns (such as continuous long-term use, frequent application switching, and multiple applications running simultaneously are all considered addictive behaviors). Set the impact weight of each feature based on expert rules and historical data. For example, in entertainment scenarios, longer connection durations are given a higher weight, reflecting the risk of addiction; high packet frequency may indicate high interaction frequency, which may mean a lower risk of addiction in scenarios such as social media, but in certain gaming scenarios, frequent interactions may actually increase addiction.

[0071] Machine learning models are trained by collecting historical data with known labels (such as addicted vs. non-addicted). The dataset should include user behavior data from multiple scenarios, with each scenario labeled to indicate whether the user is addicted. Logistic regression is selected as the training model to learn how to predict addiction risk based on input features (such as application traffic, packet frequency, connection duration, etc.). During the training process, the model gradually adjusts the feature weight coefficients to minimize the error between its output prediction value and the actual label (addicted or not). To ensure the model's generalization ability, cross-validation techniques can be used to verify the model and avoid overfitting. After training, the model can be applied to new user behavior data. For each usage scenario, the model calculates the corresponding addictive behavior weight based on the input features. The addictive behavior weight value for each scenario is predicted by the model.

[0072] Content stickiness measures the user's engagement with a particular app by recording the length of time a user spends in the app and the frequency of interaction. For example, if a user spends a long time in a video app and watches frequently updated content, the content has high stickiness. Usage time records the specific time periods during which a user uses their device and assigns weights based on the characteristics of each time period. Generally speaking, late-night use or use outside of work / study hours carries a higher risk of addiction. Duration of use records the length of time a user spends in an app each time. Long periods of continuous use of an app may be a sign of addictive behavior. Task irrelevance assesses user behavior during a specific task. For example, frequent checking of social media or video platforms while studying indicates high task irrelevance. Frequent switching analyzes the frequency with which a user switches between multiple apps. Frequent switching may indicate excessive distraction, increasing the likelihood of addiction. Each feature is assigned a weighting coefficient based on expert rules or training based on historical data.

[0073] The scenario-based addiction weight model is used to assign weights to addictive behaviors within the current usage scenario. Different scenarios place different emphasis on the assessment of addictive behaviors. For example, in an evening leisure scenario, content stickiness may be weighted higher, as users may be drawn to interesting video content. In an entertainment scenario, frequent switching may be weighted higher, as rapidly switching between multiple entertainment apps indicates addictive behavior. And in a weekday work scenario, task irrelevance may be weighted higher, as users engaging in non-work-related activities during work hours may indicate potential addictive behavior.

[0074] Based on the determined behavioral addiction weights, a logistic regression score is calculated for the key indicators to generate a first addiction score. Logistic regression is used to calculate an addiction score based on the user's key indicators and addiction behavior weights in the current scenario. Higher scores indicate a greater risk of addiction. The first addiction score is calculated using a logistic regression equation, combining the key indicators with the addiction behavior weights. Based on the input data and weights, the logistic regression model outputs a value between 0 and 1, representing the user's risk of addiction in that scenario. For example, if a user watches a video for three hours in the evening and the content has a high stickiness weight, the model may output an addiction score close to 1, indicating a high risk of addiction. For example, if the user is in an entertainment scenario, with a total application traffic of 1Gb, a packet rate of 200 packets / second, and a connection duration of two hours, the addiction behavior weight is calculated to be 0.85, indicating a high risk of addiction. The resulting addiction score calculated by the logistic regression model is 0.9995, close to 1, indicating a very high risk of addiction in the entertainment scenario. By extracting key indicators and calculating addiction scores, the user's addiction risk in specific scenarios is quantitatively assessed. By combining scenario characteristics and network traffic data, the accuracy and personalization of addiction behavior assessment are improved.

[0075] S400: Performing a cross-scenario addiction behavior score on the network traffic data corresponding to the target user in the continuous usage scenario, and outputting a second addiction score.

[0076] Furthermore, the present application S400 includes:

[0077] Obtain the target user's continuous usage scenarios within a preset period and output a continuous usage scenario sequence; extract cross-scenario behavior features from the network traffic data corresponding to the continuous usage scenarios, and output a cross-scenario behavior feature vector, including behavior continuity features, immersion time superposition features, deviation behavior features, and short-term switching frequency features; obtain an addiction behavior weight sequence corresponding to the continuous usage scenario sequence; calculate the cross-scenario behavior feature vector according to the addiction behavior weight sequence, and output a second addiction score.

[0078] Specifically, the target user's continuous usage scenarios within a preset period (such as a day) are obtained, including the process of the user switching from one scenario to the next within a specific time period. For example, a user may experience multiple scenarios such as work, commuting, and family life in a single day. The target user's usage scenarios within the preset period are arranged into a sequence in chronological order to obtain a continuous usage scenario sequence. Cross-scenario behavioral feature extraction is performed on the network traffic data under the continuous usage scenario, extracting behavioral continuity features, immersion time superposition features, deviation behavior features, and short-term switching frequency features.

[0079] Cross-scenario behavior characteristics refer to the behavior characteristics exhibited by users across multiple usage scenarios, which help capture the user's switching patterns and continuity between different scenarios. The behavior continuity feature refers to whether the user's behavior remains continuous when using the device in multiple scenarios. A higher continuity may indicate user addiction. The immersion time superposition feature refers to the user's cumulative usage time in multiple scenarios. The superposition of these times reflects the user's addictive behavior. Continuous immersion in use between different scenarios indicates a higher risk of addiction. The deviation behavior feature refers to whether the user's behavior deviates from the normal pattern. For example, if a user frequently switches to entertainment scenarios while working, it may indicate that their behavior has deviated, increasing the risk of addiction. The short-term switching frequency feature refers to the frequency with which the user frequently switches from one scenario to another in a short period of time. Frequent switching indicates that the user is not focused and exhibits potential addictive behavior.

[0080] For each scenario in the continuous usage sequence, a pre-built addictive behavior weight model is used to calculate a corresponding addictive behavior weight. For example, because entertainment content (such as games and videos) is typically highly engaging and leads users to spend extended time, the entertainment scenario has a higher addictive behavior weight (0.9). On the other hand, users tend to be more focused when studying, so the learning scenario has a lower addictive behavior weight (0.3). Social media can lead to prolonged browsing and interaction, so the addictive behavior weight is 0.6. Based on the user's scenario in the continuous usage sequence, the pre-built addictive behavior weight model is used to output a corresponding addictive behavior weight sequence, such as 0.9, 0.6, and 0.3. The addictive behavior weight for each scenario is assigned using the pre-built addictive behavior weight model, typically weighted based on the user's specific behavioral characteristics in that scenario (such as visit duration and interaction frequency). This addictive behavior weight sequence is calculated based on the user's behavioral characteristics in different scenarios, resulting in a sequence of addictive risk weights for each scenario. The weight value for each scenario represents the level of the user's addiction risk in that scenario.

[0081] The second addiction score is calculated by weighting the cross-scenario behavior feature vectors and the addictive behavior weight sequence. Each feature is multiplied by the corresponding scenario's addiction weight and then summed up. The second addiction score is calculated based on the cross-scenario behavior features and the addictive behavior weight sequence, representing the user's overall addiction risk across the entire sequence of continuous use scenarios. By combining cross-scenario behavior features and addictive behavior weights, the user's addiction risk across the entire continuous use scenario is assessed, providing more accurate predictions of addictive behavior.

[0082] S500: Combining the first addiction score and the second addiction score to output a comprehensive addiction score, and sending an anti-addiction warning signal to the authorized mobile device according to the comprehensive addiction score.

[0083] Furthermore, the present application S500 includes:

[0084] A preset addiction score threshold is obtained according to the identity information of the target user; and when the comprehensive addiction score is greater than the preset addiction score threshold, an anti-addiction warning signal is sent to the authorized mobile device.

[0085] Specifically, the first addiction score is calculated by analyzing key metrics of the current usage scenario (such as total traffic volume, packet frequency, connection duration) and the weights of addictive behaviors (such as content stickiness, usage time, and immersive time). This score reflects a user's addiction risk in a specific scenario. The second addiction score is calculated by comprehensively analyzing cross-scenario behavioral characteristics (such as behavioral continuity, overlapping immersive time, frequent switching) and the weighted sequence of addictive behaviors across multiple consecutive usage scenarios. This score reflects a user's addiction risk across multiple scenarios. The first and second addiction scores are weighted averaged to produce a comprehensive addiction score. The second addiction score (cross-scenario behavioral characteristics) is generally considered to better reflect actual addiction and is therefore given a higher weight. The formula for calculating the comprehensive addiction score is: Comprehensive Addiction Score = a * First Addiction Score + b * Second Addiction Score, where a and b correspond to the weighting coefficients of the first and second addiction scores, respectively, and a + b = 1.

[0086] Preset addiction score thresholds are based on the target user's identity information. For example, underage users may have a lower addiction score threshold, while adults or those with high-intensity jobs may have a higher threshold. The addiction score threshold is automatically adjusted based on the user's identity information, such as age, gender, and frequency of social activities. When the overall addiction score exceeds the preset addiction score threshold, it indicates that the user is at high risk of addiction and requires intervention. Once the overall addiction score exceeds the preset addiction score threshold, an anti-addiction warning signal, such as a pop-up reminder, text message, or in-app notification, is sent to the target user's device (such as a mobile phone or computer). The warning signal typically includes reminders to rest, device usage time limits, or health recommendations. A warning signal is sent to the user's device, prompting the user to take appropriate breaks or limit usage. For example, if the target user's addiction scores over a period of time are as follows: the first addiction score is 0.85 (indicating that the user has a high risk of addiction in the current scenario), the second addiction score is 0.75 (indicating that the user has a high risk of addiction in multiple continuous usage scenarios), and the set weights are 0.4 for the first addiction score and 0.6 for the second addiction score, then the comprehensive addiction score is 0.4*0.85+0.6*0.75=0.79.

[0087] By combining the first addiction score and the second addiction score, a comprehensive addiction score is obtained, and then compared with the preset addiction score threshold based on the identity information of the target user to ensure that when the addiction score exceeds the threshold, an anti-addiction warning signal is sent to the device in a timely manner to effectively prevent the user from becoming addicted and protect their physical and mental health.

[0088] In summary, the anti-addiction warning method based on network traffic data analysis provided by this application has the following beneficial effects:

[0089] By collecting the device status data of the target user's authorized mobile device; inputting the device status data into the scene recognition module to obtain the target user's current usage scene; establishing a mapping relationship between the target user in each usage scene and the network traffic data, and based on the mapping relationship and the pre-built scene addiction weight model, performing an addiction behavior weight score on the network traffic data corresponding to the current usage scene, and outputting a first addiction score; performing a cross-scene addiction behavior score on the network traffic data corresponding to the target user in the continuous use scene, and outputting a second addiction score; combining the first addiction score and the second addiction score to output a comprehensive addiction score, and sending an anti-addiction warning signal to the authorized mobile device according to the comprehensive addiction score. In other words, by obtaining the device status data of the target user's authorized mobile device, judging the user's current usage scene, establishing a mapping relationship between the scene and the network traffic data, scoring the user's addiction behavior according to the characteristics of each usage scene, and performing a cross-scene addiction behavior score on the continuous use scene, and combining the addiction score, sending an anti-addiction warning signal, avoiding the intervention inaccuracy problem caused by a single model, and improving the accuracy of the anti-addiction warning.

[0090] Example 2, based on the same inventive concept as the anti-addiction warning method based on network traffic data analysis in the above-mentioned Example 1, this application also provides an anti-addiction warning system based on network traffic data analysis, please refer to the attached Figure 2 The anti-addiction warning system based on network traffic data analysis includes:

[0091] The device status collection module 11 is used to collect the device status data of the target user's authorized mobile device; the usage scenario determination module 12 is used to input the device status data into the scenario recognition module to obtain the current usage scenario of the target user; the first scoring module 13 is used to establish a mapping relationship between the target user and the network traffic data in each usage scenario, and perform an addiction behavior weight score on the network traffic data corresponding to the current usage scenario based on the mapping relationship and the pre-built scenario addiction weight model, and output a first addiction score; the second scoring module 14 is used to perform a cross-scenario addiction behavior score on the network traffic data corresponding to the target user in the continuous usage scenario, and output a second addiction score; the addiction warning module 15 is used to combine the first addiction score and the second addiction score to output a comprehensive addiction score, and send an anti-addiction warning signal to the authorized mobile device according to the comprehensive addiction score.

[0092] Furthermore, the usage scenario determination module 12 in the anti-addiction warning system based on network traffic data analysis is also used to: perform feature extraction on the device status data to obtain key feature variables for scene recognition, wherein the device status data includes time information, location information, screen status and usage status; combine the key feature variables and input them into the scene recognition module, wherein the scene recognition module includes a pre-trained rule-learning hybrid discriminant model, the rule-learning hybrid discriminant model includes a discriminant rule layer and a machine learning layer, and the scene recognition module outputs the current usage scenario of the target user.

[0093] Furthermore, the usage scenario determination module 12 in the anti-addiction warning system based on network traffic data analysis is also used for: the scenario recognition module also includes a timing analysis layer, and the timing analysis layer is connected to the input end of the discrimination rule layer and the machine learning layer; constructing a timing sample window to perform timing processing on the device status data to obtain processed device timing status data; performing scene transfer node prediction on the device timing status data through the timing analysis layer, and outputting multiple scene transfer nodes; dividing the device timing status data according to the multiple scene transfer nodes, outputting multiple device timing status data, and outputting multiple usage scenarios corresponding to the multiple device timing status data according to the rule-learning hybrid discrimination model.

[0094] Furthermore, the usage scenario determination module 12 in the anti-addiction warning system based on network traffic data analysis is also used for: the scene recognition module includes a pre-trained rule-learning hybrid discriminant model, and the rule-learning hybrid discriminant model includes a discriminant rule layer and a machine learning layer; the discriminant rule layer and the machine learning layer are confidence fusion weight modeled, and a rule-learning hybrid discriminant model is output; wherein, the discriminant rule layer includes a defined initial fuzzy discriminant rule set and corresponding usage scenario labels; a training data set is collected, and the training data set is used to perform model parameter supervised training to obtain a trained machine learning layer, wherein the training data set includes device status data samples under multiple known scenario labels.

[0095] Furthermore, the first scoring module 13 in the anti-addiction warning system based on network traffic data analysis is also used to: construct a time series sample window to perform time series processing on the collected network traffic data to obtain processed network time series traffic data; divide the network time series traffic data according to the multiple scene transfer nodes and output multiple network time series traffic data; establish a mapping relationship between the target user and the network traffic data in each usage scenario according to the multiple scene transfer nodes and the multiple network time series traffic data.

[0096] Furthermore, the first scoring module 13 in the anti-addiction warning system based on network traffic data analysis is also used to: extract key indicators of network traffic data in the current usage scenario based on the mapping relationship, including the total application traffic, data packet frequency, communication protocol characteristics and connection duration of the same access application; obtain the corresponding addiction behavior weight in the current usage scenario according to the scenario addiction weight model; perform logistic regression scoring calculation on the key indicators according to the corresponding addiction behavior weight in the current usage scenario, and output the first addiction score in the current usage scenario.

[0097] Furthermore, the first scoring module 13 in the anti-addiction warning system based on network traffic data analysis is also used for: the scenario addiction weight model is used to obtain the corresponding addiction behavior weight in the current usage scenario, wherein the addiction behavior weight includes content stickiness weight, usage time period weight, usage duration weight, task irrelevant weight and frequent switching weight.

[0098] Furthermore, the second scoring module 14 in the anti-addiction warning system based on network traffic data analysis is also used to: obtain the continuous usage scenarios of the target user within a preset period, and output a continuous usage scenario sequence; extract cross-scenario behavior features of the corresponding network traffic data under the continuous usage scenarios, and output a cross-scenario behavior feature vector, including behavior continuity features, immersion time superposition features, deviation behavior features, and short-term switching frequency features; obtain the addiction behavior weight sequence corresponding to the continuous usage scenario sequence; calculate the cross-scenario behavior feature vector according to the addiction behavior weight sequence, and output a second addiction score.

[0099] Furthermore, the addiction warning module 15 in the anti-addiction warning system based on network traffic data analysis is also used to: obtain a preset addiction score threshold based on the identity information of the target user; when the comprehensive addiction score is greater than the preset addiction score threshold, send an anti-addiction warning signal to the authorized mobile device.

[0100] The various embodiments in this specification are described in a progressive manner, and each embodiment focuses on the differences from other embodiments. Figure 1 The anti-addiction warning method based on network traffic data analysis and the specific examples in Example 1 are also applicable to the anti-addiction warning system based on network traffic data analysis in this embodiment. Through the above detailed description of the anti-addiction warning method based on network traffic data analysis, those skilled in the art can clearly understand the anti-addiction warning system based on network traffic data analysis in this embodiment, so for the sake of brevity of the specification, it will not be described in detail here.

[0101] The above description of the disclosed embodiments is intended to enable one skilled in the art to implement or use the present application. Various modifications to these embodiments will be readily apparent to one skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the present application. Therefore, the present application is not limited to the embodiments shown herein, but is intended to conform to the widest scope consistent with the principles and novel features disclosed herein.

[0102] Obviously, for those skilled in the art, several improvements and modifications can be made to the present application without departing from the principles of the present application, and these improvements and modifications also fall within the scope of protection of the present application.

Claims

1. Anti-addiction warning method based on network traffic data analysis, characterized in that: include: Collect device status data of the target user's authorized mobile devices; Inputting the device status data into a scene recognition module to obtain the current usage scene of the target user; Establishing a mapping relationship between the target user in each usage scenario and the network traffic data, performing an addiction behavior weight score on the network traffic data corresponding to the current usage scenario based on the mapping relationship and a pre-built scenario addiction weight model, and outputting a first addiction score; Performing a cross-scenario addiction behavior score on the target user's corresponding network traffic data in the continuous usage scenario, and outputting a second addiction score; Combining the first addiction score and the second addiction score to output a comprehensive addiction score, and sending an anti-addiction warning signal to the authorized mobile device according to the comprehensive addiction score; The method of performing an addiction behavior weight score on the network traffic data corresponding to the current usage scenario based on the mapping relationship and the pre-built scenario addiction weight model and outputting a first addiction score includes: Extracting key indicators of network traffic data in the current usage scenario based on the mapping relationship, including the total application traffic volume, packet frequency, communication protocol characteristics, and connection duration of the same access application; Obtaining the corresponding addiction behavior weight in the current usage scenario according to the scenario addiction weight model; A logistic regression score calculation is performed on the key indicators according to the addiction behavior weight corresponding to the current usage scenario, and a first addiction score for the current usage scenario is output.

2. The anti-addiction warning method based on network traffic data analysis according to claim 1, characterized in that: Inputting the device status data into a scene recognition module to obtain the current usage scene of the target user includes: Performing feature extraction on the device status data to obtain key feature variables for scene recognition, wherein the device status data includes time information, location information, screen status, and usage status; The key feature variables are combined and input into the scene recognition module, wherein the scene recognition module includes a pre-trained rule-learning hybrid discriminant model, the rule-learning hybrid discriminant model includes a discriminant rule layer and a machine learning layer, and the scene recognition module outputs the current usage scenario of the target user.

3. The anti-addiction warning method based on network traffic data analysis according to claim 2, characterized in that: The scene recognition module further includes a time series analysis layer, which is connected to the input terminals of the discrimination rule layer and the machine learning layer, and further includes: Constructing a time series sample window to perform time series processing on the device status data to obtain processed device time series status data; Performing scene transition node prediction on the device time series state data through the time series analysis layer, and outputting multiple scene transition nodes; The device timing state data is divided according to the multiple scenario transfer nodes, multiple device timing state data are output, and multiple usage scenarios corresponding to the multiple device timing state data are output according to the rule-learning hybrid discriminant model.

4. The anti-addiction warning method based on network traffic data analysis according to claim 2, characterized in that: The scene recognition module includes a pre-trained rule-learning hybrid discriminant model, and the rule-learning hybrid discriminant model includes a discriminant rule layer and a machine learning layer; Perform confidence fusion weight modeling on the discrimination rule layer and the machine learning layer, and output a rule-learning hybrid discrimination model; The discrimination rule layer includes a defined initial fuzzy discrimination rule set and corresponding usage scenario labels; A training data set is collected and model parameter supervised training is performed using the training data set to obtain a trained machine learning layer, wherein the training data set includes device status data samples under multiple known scenario labels.

5. The anti-addiction warning method based on network traffic data analysis according to claim 3 is characterized in that: Establishing a mapping relationship between the target user and network traffic data in various usage scenarios, including: Construct a time series sample window to perform time series processing on the collected network traffic data to obtain processed network time series traffic data; Dividing the network time series flow data according to the multiple scene transfer nodes, and outputting multiple network time series flow data; According to the multiple scenario transfer nodes and the multiple network time series traffic data, a mapping relationship between the target user in each usage scenario and the network traffic data is established.

6. The anti-addiction warning method based on network traffic data analysis according to claim 1, characterized in that: The scenario addiction weight model is used to obtain the corresponding addiction behavior weight in the current usage scenario, wherein the addiction behavior weight includes content stickiness weight, usage time period weight, usage duration weight, task irrelevance weight and frequent switching weight.

7. The anti-addiction warning method based on network traffic data analysis according to claim 1, characterized in that: Performing a cross-scenario addiction behavior score on the network traffic data corresponding to the target user in the continuous usage scenario and outputting a second addiction score, including: Obtain the target user's continuous usage scenarios within a preset period and output a sequence of continuous usage scenarios; Extract cross-scenario behavior features from the network traffic data corresponding to continuous usage scenarios and output a cross-scenario behavior feature vector, including behavior continuity features, immersion time superposition features, deviation behavior features, and short-term switching frequency features; Obtaining an addictive behavior weight sequence corresponding to the continuous usage scenario sequence; The cross-scenario behavior feature vector is calculated according to the addiction behavior weight sequence, and a second addiction score is output.

8. The anti-addiction warning method based on network traffic data analysis according to claim 1, characterized in that: Sending an anti-addiction warning signal to the authorized mobile device according to the comprehensive addiction score includes: Obtaining a preset addiction score threshold based on the identity information of the target user; When the comprehensive addiction score is greater than the preset addiction score threshold, an anti-addiction warning signal is sent to the authorized mobile device. 9.Anti-addiction warning system based on network traffic data analysis, characterized by: The steps for implementing the anti-addiction warning method based on network traffic data analysis according to any one of claims 1 to 8, wherein the anti-addiction warning system based on network traffic data analysis comprises: Device status collection module, used to collect device status data of mobile devices authorized by target users; A usage scenario determination module, configured to input the device status data into a scenario recognition module to obtain the current usage scenario of the target user; A first scoring module is configured to establish a mapping relationship between the target user in each usage scenario and the network traffic data, perform an addiction behavior weight score on the network traffic data corresponding to the current usage scenario based on the mapping relationship and a pre-built scenario addiction weight model, and output a first addiction score; A second scoring module is configured to score the target user's cross-scenario addiction behavior based on the network traffic data corresponding to the continuous usage scenario, and output a second addiction score; The addiction warning module is used to integrate the first addiction score and the second addiction score to output a comprehensive addiction score, and send an anti-addiction warning signal to the authorized mobile device according to the comprehensive addiction score.

Citation Information

Patent Citations

  • User network surfing identification method and apparatus, and storage medium

    CN107707421A