Risk control strategy coverage rate detection method and device, storage medium and electronic equipment
By performing policy analysis and branch detection code generation of risk control strategies, and using code generation large model to detect policy branch coverage, the problem of unknown policy branch coverage in risk control strategy verification is solved, the convenience and efficiency of policy branch coverage is improved, and the accuracy of risk control strategy is ensured.
Patent Information
- Application Number
- CN202510892197.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-27
- Publication Date
- 2025-08-15
- Estimated Expiration
- 2045-06-27
AI Technical Summary
During the verification process of risk control strategy, it is impossible to determine the coverage ratio of the policy branches in the risk control strategy, resulting in the inability to ensure the integrity and accuracy of the policy branches.
By obtaining the target risk control strategy and policy verification parameters in the risk control strategy verification scenario, performing policy analysis and processing to obtain risk control logic expressions, generating branch expression detection codes, and using code generation large model to detect policy branch coverage, and generating risk control strategy coverage detection data.
Automatic policy branch coverage statistics are realized, the convenience and efficiency of policy branch coverage are improved, and the accuracy and stability of risk control strategies are ensured.
Smart Images

Figure CN120492356A_ABST
Abstract
Description
Technical Field
[0001] This specification relates to the field of computer technology, and in particular to a risk control strategy coverage detection method, device, storage medium, and electronic device. Background Art
[0002] In related technologies, conducting thorough strategy testing and verification is a crucial step before a risk control strategy for a specific platform or institution is released and launched. During the risk control strategy verification process, the input parameters of the risk control strategy are usually constructed, and the expected results corresponding to the input parameters are set based on the previous transaction logic and transaction goals. The input parameters are then executed by the risk control strategy to obtain the output parameters. Relevant personnel compare the output parameters with the input parameters to verify whether the strategy works as expected. This ensures that the actual effect of the new strategy after launch is consistent with expectations, thereby effectively reducing risks and ensuring the stability and security of platform or institutional transactions. Summary of the Invention
[0003] This specification provides a risk control policy coverage detection method, device, storage medium, and electronic device. The technical solution is as follows: In a first aspect, this specification provides a method for detecting risk control policy coverage, the method comprising: Obtaining a target risk control strategy in a risk control strategy verification scenario, and obtaining strategy verification parameters for the target risk control strategy; Performing policy parsing processing on the target risk control strategy to obtain a risk control logic expression, and performing policy branch detection code generation processing on the target risk control strategy based on the risk control logic expression to obtain a branch expression detection code; Based on the strategy verification parameters and the branch expression detection code, the target risk control strategy is subjected to strategy branch coverage detection processing to obtain risk control strategy coverage detection data.
[0004] In a possible implementation, performing strategy branch detection code generation processing on the target risk control strategy based on the risk control logic expression to obtain a branch expression detection code includes: Performing strategy branch splitting processing on the risk control logic expression to obtain a strategy branch expression; Based on the strategy branch expression, branch coverage detection code generation processing is performed on the target risk control strategy to obtain a branch expression detection code.
[0005] In a possible implementation, performing branch coverage detection code generation processing on the target risk control strategy based on the strategy branch expression to obtain the branch expression detection code includes: Obtaining a logical operator of the risk control logic expression, and generating a target interpretation and execution code based on the logical operator and the policy branch expression; A first expression detection code for the policy branch expression and a second expression detection code for the risk control logic expression are inserted into the target interpreted execution code to obtain a branch expression detection code.
[0006] In a possible implementation, performing strategy branch splitting processing on the risk control logic expression to obtain a strategy branch expression includes: Performing expression verification processing on the risk control logic expression to obtain an expression verification result; If the expression verification result is a verification success type, the risk control logic expression is split to obtain a strategy branch expression.
[0007] In a possible implementation, performing policy parsing on the target risk control policy to obtain a risk control logic expression includes: Performing strategy analysis on the target risk control strategy to obtain target risk control conditions; The target risk control condition is subjected to conditional logic conversion processing to obtain a risk control logic expression.
[0008] In a possible implementation, performing a policy branch coverage detection process on the target risk control policy based on the policy verification parameter and the branch expression detection code to obtain risk control policy coverage detection data includes: Using a code generation model to perform coverage detection code generation processing based on the strategy verification parameters and the branch expression detection code to obtain a target detection code; Code execution processing is performed on the target detection code to obtain risk control strategy coverage detection data.
[0009] In a possible implementation, the code generation macro model is used to perform coverage detection code generation processing based on the strategy verification parameters and the branch expression detection code to obtain the target detection code, including: Determining a code generation prompt word based on the strategy verification parameter and the branch expression detection code; Based on the code generation prompt word, a code generation large model is used to perform code task analysis processing to obtain a target code generation task, and based on the target code generation task, a coverage detection code generation processing is performed to obtain a target detection code.
[0010] In a possible implementation, performing code execution processing on the target detection code to obtain risk control strategy coverage detection data includes: Performing code execution processing on the target detection code to obtain a first coverage result of the policy verification parameter on the risk control logic expression and a second coverage result of the policy verification parameter on the policy branch expression; Based on the first coverage result and the second coverage result, generate risk control strategy coverage detection data In a second aspect, this specification provides a risk control strategy coverage detection device, the device comprising: A strategy acquisition module is used to obtain the target risk control strategy in the risk control strategy verification scenario and obtain strategy verification parameters for the target risk control strategy; a code generation module, configured to perform policy parsing processing on the target risk control policy to obtain a risk control logic expression, and perform policy branch detection code generation processing on the target risk control policy based on the risk control logic expression to obtain a branch expression detection code; The branch detection module is used to perform strategy branch coverage detection processing on the target risk control strategy based on the strategy verification parameters and the branch expression detection code to obtain risk control strategy coverage detection data.
[0011] In a third aspect, this specification provides a computer storage medium having a plurality of instructions, wherein the instructions are suitable for being loaded by a processor and executing the above method.
[0012] In a fourth aspect, this specification provides a computer program product, wherein the computer program product stores at least one instruction, and the at least one instruction is loaded by a processor to execute the above method.
[0013] In a fifth aspect, this specification provides an electronic device, which may include: a memory and a processor; wherein the memory stores a computer program, and the computer program is suitable for being loaded by the memory and executing the above method.
[0014] The beneficial effects of the technical solutions provided in this specification include at least: The risk control strategy coverage detection method provided in the embodiment of this specification, after obtaining the target risk control strategy in the risk control strategy verification scenario and the policy verification parameters for the target risk control strategy, performs policy parsing on the target risk control strategy to obtain the risk control logic expression, and then performs policy branch detection code generation processing on the target risk control strategy according to the risk control logic expression to obtain the branch expression detection code, and then performs policy branch coverage detection processing on the target risk control strategy according to the policy verification parameters and the branch expression detection code to obtain the risk control strategy coverage detection data. Therefore, by reusing the policy verification parameters constructed in the risk control strategy verification scenario, the coverage statistics of the policy branches can be automatically performed according to the branch expression detection code, and the risk control strategy developer does not need to perform additional operations, which increases the convenience of obtaining the policy branch coverage in the risk control strategy and effectively improves the efficiency of obtaining the policy branch coverage. BRIEF DESCRIPTION OF THE DRAWINGS
[0015] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without paying any creative work.
[0016] Figure 1 This is a scenario diagram of a risk control strategy coverage detection system provided by an embodiment of this specification; Figure 2 This is a flow chart of a method for detecting risk control strategy coverage provided by an embodiment of this specification; Figure 3 This is a schematic diagram of a risk control strategy verification scenario provided by an embodiment of this specification; Figure 4 This is a flow chart of another risk control strategy coverage detection method provided in an embodiment of this specification; Figure 5 This is a schematic diagram of the structure of a risk control strategy coverage detection device provided in an embodiment of this specification; Figure 6 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this specification. DETAILED DESCRIPTION
[0017] In order to make the invention objectives, features, and advantages of the embodiments of this specification more obvious and easy to understand, the technical solutions in the embodiments of this specification will be clearly and completely described below in conjunction with the drawings in the embodiments of this specification. Obviously, the embodiments described are only part of the embodiments of this specification, not all of the embodiments. Based on the embodiments in this specification, all other embodiments obtained by those skilled in the art without making creative efforts shall fall within the scope of protection of this specification.
[0018] In the description of this specification, it should be understood that the terms "first", "second", etc. are used for descriptive purposes only and should not be understood as indicating or implying relative importance. In the description of this specification, it should be noted that, unless otherwise clearly specified and limited, "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions. For example, a process, method, system, product or device that includes a series of steps or units is not limited to the listed steps or units, but optionally also includes steps or units that are not listed, or optionally also includes other steps or units inherent to these processes, methods, products or devices. For those of ordinary skill in the art, the specific meanings of the above terms in this specification can be understood according to the specific circumstances. In addition, in the description of this specification, unless otherwise specified, "multiple" refers to two or more. "And / or" describes the association relationship of associated objects, indicating that three relationships can exist. For example, A and / or B can represent: A exists alone, A and B exist at the same time, and B exists alone. The character " / " generally indicates that the associated objects before and after are in an "or" relationship.
[0019] In related technologies, during the risk control strategy verification process, the output parameters obtained from executing the risk control strategy input parameters are compared with the expected results corresponding to the input parameters to verify whether the risk control strategy has any problems. However, during this process, the number of policy branches in the risk control strategy that can be covered by the input parameters constructed for the risk control strategy is unknown. Therefore, during the risk control strategy verification process, there is an issue with determining the coverage rate of the policy branches in the risk control strategy by the input parameters.
[0020] In order to solve the above technical problems, this specification is described in detail below in conjunction with specific embodiments.
[0021] See Figure 1 , is a scenario diagram of a risk control strategy coverage detection system provided in an embodiment of this specification. Figure 1 As shown, the scenario diagram may include at least a terminal cluster and a server.
[0022] In some embodiments, the terminal cluster may include at least one terminal, such as Figure 1As shown, it specifically includes terminal 1 corresponding to user 1, terminal 2 corresponding to user 2, ..., terminal n corresponding to user n, where n is an integer greater than 0.
[0023] Each terminal in the terminal cluster can be a smart device with communication capabilities, including but not limited to wearable devices, handheld devices, personal computers, tablet computers, smartphones, computing devices, or other processing devices connected to a wireless modem. Smart devices may be called different names in different networks, such as user equipment, access terminal, subscriber unit, subscriber station, mobile station, mobile station, remote station, remote terminal, mobile device, user terminal, terminal, wireless communication device, user agent or user device, cellular phone, cordless phone, personal digital assistant (PDA), and electronic devices in 5G networks or future evolution networks.
[0024] In some embodiments, a server is a hardware device with strong computing capabilities. Specifically, the server can use a separate server device, such as a rack-mounted, blade, tower, or cabinet-mounted server device, or a workstation, mainframe computer, or other hardware device. A server cluster composed of multiple servers can also be used. The servers in the service cluster can be composed in a symmetrical manner, where each server has equivalent functions and status in the transaction link, and each server can provide services to the outside world independently. Providing services independently can be understood as not requiring the assistance of additional servers.
[0025] In some embodiments, the electronic device that executes the risk control policy coverage detection method can be a server, and the server and the terminals in the terminal cluster can establish a communication connection, and the data interaction in the risk control policy coverage detection process is completed based on the communication connection. For example, in the risk control policy coverage detection method, the terminal of the terminal cluster is a terminal used by the risk control policy developer, and the terminal stores the target risk control policy in the risk control policy verification scenario and the policy verification parameters for the target risk control policy. The server can obtain the target risk control policy in the risk control policy verification scenario from the terminal, obtain the policy verification parameters for the target risk control policy, perform policy parsing processing on the target risk control policy to obtain a risk control logic expression, perform policy branch detection code generation processing on the target risk control policy based on the risk control logic expression to obtain a branch expression detection code, perform policy branch coverage detection processing on the target risk control policy based on the policy verification parameters and the branch expression detection code, and obtain risk control policy coverage detection data.
[0026] It should be noted that the server and the terminal establish a communication connection through a network for interactive communication, wherein the network can be a wireless network or a wired network. Wireless networks include but are not limited to cellular networks, wireless local area networks, infrared networks, or Bluetooth networks, and wired networks include but are not limited to Ethernet, universal serial bus (USB), or controller area network. In one or more embodiments of the specification, technologies and / or formats including Hypertext Markup Language (HTML) and Extensible Markup Language (XML) are used to represent data (such as target compressed packages) exchanged over the network. In addition, conventional encryption technologies such as Secure Sockets Layer (SSL), Transport Layer Security (TLS), Virtual Private Network (VPN), and Internet Protocol Security (IPsec) can also be used to encrypt all or some links. In other embodiments, customized and / or dedicated data communication technologies can also be used to replace or supplement the above data communication technologies.
[0027] The risk control policy coverage detection system embodiments provided in this specification share the same concept as the risk control policy coverage detection method described in one or more embodiments. The execution entity corresponding to the risk control policy coverage detection method described in one or more embodiments of this specification may be an electronic device, which may be the aforementioned server. The specific implementation process of the risk control policy coverage detection system embodiments can be found in the following method embodiments and will not be further elaborated here.
[0028] In one embodiment, Figure 2 As shown in the figure, a risk control strategy coverage detection method is proposed. This method can be implemented by a computer program and can be run on a risk control strategy coverage detection device based on the von Neumann architecture. The computer program can be integrated into an application or run as a standalone tool application.
[0029] Specifically, the risk control strategy coverage detection method includes: S102: Obtain a target risk control strategy in a risk control strategy verification scenario, and obtain strategy verification parameters for the target risk control strategy.
[0030] It is understood that risk control strategy verification scenarios refer to situations in which the accuracy and effectiveness of risk control strategies are verified. Risk control strategies are strategies deployed on specific platforms and in specific areas to identify, assess, and control potential risks. Risk control strategies can be deployed on many platforms or institutions, including credit platforms, e-commerce platforms, financial investment platforms, payment platforms, consumer finance institutions, and insurance institutions.
[0031] For example, see Figure 3 The following is a schematic diagram of a risk control strategy verification scenario. Figure 3 As shown in the figure, in the risk control strategy verification scenario, after configuring the risk control strategy, the risk control strategy developer constructs a strategy verification input table according to the risk control strategy content, and then submits the strategy verification task to the risk control management platform, where the strategy verification input table includes parameters for verifying the risk control strategy; after reading the strategy verification input table, the risk control management platform compiles the source code of the risk control strategy to obtain Java code, and submits the verification task to the open data processing service for execution; the open data processing service produces the strategy output result to obtain the strategy verification output table; finally, the risk control strategy developer compares the strategy verification output table to see whether it meets the expected results to verify the accuracy and effectiveness of the risk control strategy.
[0032] It is understandable that the target risk control strategy may include one or more risk control strategies that are awaiting verification or have been verified in the risk control strategy verification scenario.
[0033] Strategy validation parameters refer to the input data required to validate the risk control strategy. These input data are parameters that may cause risks in the simulated real-world scenario. For example, strategy validation parameters may include user personal data, user behavior data, transaction information, account status, etc.
[0034] Exemplarily, the policy verification parameters may include verification parameter sets of multiple users, each user corresponds to a verification parameter set, and each verification parameter set may include multi-dimensional verification parameters of the user.
[0035] In some embodiments, step S102 may specifically include determining a risk control strategy to be tested in a risk control strategy verification scenario, determining the risk control strategy to be tested as a target risk control strategy, and obtaining policy verification parameters for the target risk control strategy from a policy verification configuration file. It is understood that the policy verification configuration file may store policy verification parameters for multiple risk control strategies involved in the risk control strategy verification scenario, and the policy verification parameters may be manually configured based on expert experience or generated using a large language model.
[0036] In some other embodiments, step S102 may be performed by obtaining a target risk control strategy and a policy verification parameter for the target risk control strategy in a risk control strategy verification scenario from a user terminal, wherein the user terminal may be a terminal used by a risk control strategy developer.
[0037] S104: Perform policy parsing processing on the target risk control policy to obtain a risk control logic expression, and perform policy branch detection code generation processing on the target risk control policy based on the risk control logic expression to obtain a branch expression detection code.
[0038] It is understood that a risk control logic expression refers to a computer-understandable logical expression that represents the risk control rules of a target risk control strategy. A risk control logic expression can be used to represent risk control conditions, as well as operators between multiple risk control conditions. For example, a risk control logic expression for a simple risk control rule may include only one risk control condition. Another example is a risk control logic expression for a complex risk control rule that may include multiple risk control conditions and operators between them.
[0039] Branch expression detection code refers to the functional code used to detect the coverage of a single strategy branch in the target risk control strategy.
[0040] In some embodiments, in step S104, risk control conditions are extracted from the target risk control strategy. If there are multiple risk control conditions, the risk control logical expression is determined based on the logical relationship between the multiple risk control conditions and the multiple risk control conditions; if there is one risk control condition, the risk control logical expression is determined based on the risk control condition.
[0041] S106: Perform a policy branch coverage detection process on the target risk control policy based on the policy verification parameters and the branch expression detection code to obtain risk control policy coverage detection data.
[0042] It can be understood that the risk control strategy coverage detection data is data including the strategy branch coverage of the target risk control strategy.
[0043] In some embodiments, a policy branch coverage detection task can be generated based on the policy verification parameters and branch expression detection code, and the code corresponding to the policy branch coverage detection task can be executed to obtain the risk control policy coverage detection data including the policy branch coverage of the target risk control policy represented by the risk control logic expression and the branch coverage of the policy branch expression. Among them, the policy branch coverage of the target risk control policy can be understood as the percentage of the number of policy branches in the target risk control policy that are hit by the policy verification parameters to the total number of policy branches in the target risk control policy. The branch coverage of the policy branch expression is used to characterize whether a single policy branch in the target risk control policy is hit by the policy verification parameters. If a single policy branch is hit by the policy verification parameters, the branch coverage of the policy branch expression corresponding to the policy branch is 100%. If a single policy branch is not hit by the policy verification parameters, the branch coverage of the policy branch expression corresponding to the policy branch is 0.
[0044] The risk control strategy coverage detection method provided in the embodiment of this specification, after obtaining the target risk control strategy in the risk control strategy verification scenario and the policy verification parameters for the target risk control strategy, performs policy parsing on the target risk control strategy to obtain the risk control logic expression, and then performs policy branch detection code generation processing on the target risk control strategy according to the risk control logic expression to obtain the branch expression detection code, and then performs policy branch coverage detection processing on the target risk control strategy according to the policy verification parameters and the branch expression detection code to obtain the risk control strategy coverage detection data. Therefore, by reusing the policy verification parameters constructed in the risk control strategy verification scenario, the coverage statistics of the policy branches can be automatically performed according to the branch expression detection code, and the risk control strategy developer does not need to perform additional operations, which increases the convenience of obtaining the policy branch coverage in the risk control strategy and effectively improves the efficiency of obtaining the policy branch coverage.
[0045] See Figure 4 , is a flow chart of another embodiment of a method for detecting risk control policy coverage provided in the embodiments of this specification. Specifically, the method may include the following steps: S202: Obtain a target risk control strategy in a risk control strategy verification scenario, and obtain strategy verification parameters for the target risk control strategy.
[0046] Specifically, the implementation of step S202 can be found in Figure 2 The description of the relevant steps in the illustrated embodiment will not be repeated in detail here.
[0047] S204: Perform policy analysis on the target risk control policy to obtain target risk control conditions.
[0048] It's understood that risk control conditions are defined within a risk control strategy based on specific rules. These conditions are used to determine whether a particular risk control decision should be triggered. Risk control conditions can be set based on specific transaction needs and risk management objectives, and they involve examining multiple dimensions of data, including user behavior, personal information, account status, and transaction information.
[0049] Exemplarily, risk control conditions may include: determining whether the transaction amount exceeds a preset limit; determining whether the user's real-name status is verified; determining whether the number of transactions within a specific time range exceeds a preset limit, etc.
[0050] In some embodiments, executing step S204 may include: querying a target Structured Query Language (SQL) statement corresponding to the target risk control strategy from a risk control rule data table or a risk control rule configuration file, and performing sentence parsing on the SQL statement to obtain the target risk control condition.
[0051] For example, the part of the target SQL statement corresponding to a target risk control strategy may be "case when age>18 and user_is_realnamed = 1 then 1 else 0 end as rule_0", where "age>18and user_is_realnamed = 1" is the target risk control condition.
[0052] S206: Perform conditional logic conversion on the target risk control condition to obtain a risk control logic expression.
[0053] In some embodiments, a conditional expression can be determined based on the conditional logic of the target risk control condition, and the conditional expression can be converted into a risk control logic expression written in a preset programming language. It is understood that the preset programming language refers to the programming language used to generate the detection code for detecting the branch coverage of the risk control strategy, such as Java.
[0054] S208: Perform strategy branch splitting processing on the risk control logic expression to obtain a strategy branch expression.
[0055] Among them, the strategy branch expression refers to the sub-expression separated from the risk control logic expression. Each strategy branch expression corresponds to a specific judgment condition or a decision path (also called a strategy branch) in the risk control strategy. These strategy branches work together to form a complete risk control logic judgment of the risk control strategy.
[0056] For example, a risk control logic expression may include a logical "AND" operator, and the two sub-expressions connected by this operator are the strategy branch expressions.
[0057] In some embodiments, executing step S208 may include: performing expression verification processing on the risk control logic expression to obtain an expression verification result; if the expression verification result is a verification success type, performing expression splitting processing on the risk control logic expression to obtain a strategy branch expression.
[0058] It is understood that the expression verification process performed on the risk control logic expression may include syntax checking and logic verification. The risk control logic expression is verified to ensure that the expression is syntactically and logically correct. If the risk control logic expression is syntactically and logically correct, a verification success result may be generated. If the risk control logic expression contains syntax errors and / or logic errors, a verification failure result may be generated.
[0059] In the process of splitting the risk control logic expression, the logical operator in the risk control logic expression is obtained, and the strategy branch expression connected by the logical operator is determined in the risk control logic expression.
[0060] For example, if "age>18 and user_is_realnamed = 1" in the SQL statement is the target risk control condition, the risk control logic expression obtained by converting the target risk control condition is "age>18&&user_is_realnamed ==1", where "&&" is the logical AND operator, and the two policy branch expressions connected by this operator are "age>18" and "user_is_realnamed == 1".
[0061] It can be understood that, taking the risk control logic expression as the main node and the policy branch expression as the sub-node as an example, the risk control logic expression can include a policy branch expression without sub-nodes, or a policy branch expression with sub-nodes. For example, assuming that there are three policy branch expressions, expression 1, expression 2, and expression 3, in some scenarios, expression 1, expression 2, and expression 3 can be three sub-nodes directly obtained by splitting from the risk control logic expression; in other scenarios, expression 1 and expression 4 are two sub-nodes directly obtained by splitting from the risk control logic expression, and expression 2 and expression 3 are two other sub-nodes obtained by further splitting expression 4. In this way, after the risk control logic expression is split, the three policy branch expressions, expression 1, expression 2, and expression 3, are obtained.
[0062] Optionally, when the expression verification result is a verification failure type, the process can return to step S206 to regenerate the risk control logic expression, and then perform expression verification processing and expression splitting processing on the regenerated risk control logic expression through step S208; or, a prompt message of expression verification error can be generated, and the prompt message can be sent to the user terminal to facilitate the user terminal to manually review the risk control logic expression generated by step S206. When the user of the user terminal confirms that the risk control logic expression is an incorrect expression, the risk control logic expression can be manually rewritten, and the user terminal uploads the rewritten risk control logic expression to the electronic device. The electronic device performs expression verification processing and expression splitting processing on the risk control logic expression uploaded by the user terminal by executing step S208.
[0063] S210 , performing branch coverage detection code generation processing on the target risk control strategy based on the strategy branch expression to obtain a branch expression detection code.
[0064] It can be understood that the branch expression detection code refers to the functional code used to detect the coverage of a single strategy branch in the target risk control strategy. The branch expression detection code can be used to detect whether the strategy branch expression is hit rather than just detecting whether the risk control logic expression as a whole is hit. In the embodiment of this specification, the branch expression detection code can specifically be an interpreted execution code. Interpreted execution code means that when the program is executed, the code is executed by interpretation rather than compilation. Interpreted execution refers to the process in which the interpreter reads the source code line by line when the program is executed, converts the source code into machine language and executes it. Compiled execution is to compile the entire source code into machine code at one time and then execute it.
[0065] In some embodiments, executing step S210 may specifically include the following steps: A2: Obtain the logical operators of the risk control logic expression and generate the target interpretation and execution code based on the logical operators and the policy branch expression. A4: Insert the first expression detection code for the policy branch expression and the second expression detection code for the risk control logic expression into the target interpreted execution code to obtain the branch expression detection code.
[0066] In step A2, when executing the step of generating the target interpreted execution code based on the logical operator and the policy branch expression, the first code generation task description information can be determined according to the logical operator and the policy branch expression, the first output code description information can be determined, and the first prompt word can be generated according to the logical operator, the policy branch expression, the first code generation task description information, and the first output code description information. Based on the first prompt word, the code generation large model is used to perform code generation processing to obtain the target interpreted execution code.
[0067] In step A4, the first expression detection code is used to detect whether the policy branch expression is hit, and the second expression detection code is used to detect whether the risk control logic expression as a whole is hit. When executing step A4, the second code generation task description information is generated based on the target interpretation and execution code, the second output code description information is determined, and a second prompt word is generated based on the target interpretation and execution code, the second code generation task description information, and the second output code description information. Based on the second prompt word, the code generation macro model is used to insert the first expression detection code for the policy branch expression and the second expression detection code for the risk control logic expression into the target interpretation and execution code to obtain the branch expression detection code.
[0068] In this way, by generating interpreted code such as branch expression detection code, it can not only be used to detect whether the strategy branch expression is hit, but also, since there is no need for the interpreter to generate executable files in advance, it can also write and test code faster, thereby improving code generation efficiency.
[0069] S212, using a large code generation model to perform coverage detection code generation processing based on strategy verification parameters and branch expression detection code to obtain target detection code.
[0070] It is understandable that the target detection code can be used to detect whether the policy verification parameters hit the policy branch expression and whether the policy verification parameters hit the risk control logic expression.
[0071] In some embodiments, executing step S312 may include the following steps: B2: Determine code generation hints based on strategy validation parameters and branch expression detection code; B4: Based on the code generation prompt word, the code generation large model is used to perform code task analysis processing to obtain the target code generation task, and coverage detection code generation processing is performed based on the target code generation task to obtain the target detection code.
[0072] In step B2, code task description information for the policy verification parameters and branch expression detection code is determined, code output description information is determined, and a code generation prompt is generated that includes the policy verification parameters, branch expression detection code, code task description information, and code output description information. The code task description information includes instructions for the large model to generate detection code for detecting policy branch coverage based on the policy verification parameters and branch expression detection code.
[0073] In step B4, the code generation prompt word is input into the code generation model, the code generation model is used to perform code task analysis processing to obtain the target code generation task, and the code generation model is used to perform coverage detection code generation processing based on the target code generation task to obtain the target detection code.
[0074] It is understood that in the embodiments of this specification, the code generation model used refers to a large language model with strong programming capabilities, which can understand, generate and process code. The programming capabilities of the code generation large model are reflected in the ability to understand the syntax and structure of multiple programming languages (such as Python, Java, JavaScript, etc.), the ability to understand the intention of the code, and the ability to automatically generate corresponding code based on the description of natural language. The code generation large model can be fine-tuned based on the basic programming large model, and the code generation large model can also directly use the basic programming large model. The programming large model is a large model with strong programming capabilities.
[0075] S214: Perform code execution processing on the target detection code to obtain risk control strategy coverage detection data.
[0076] It can be understood that the risk control policy coverage detection data includes the coverage detection data of the policy verification parameters for the policy branch expressions and the coverage detection data of the policy verification parameters for the risk control logic expressions.
[0077] In some embodiments, executing step S214 may specifically include: C2: Perform code execution processing on the target detection code to obtain the first coverage result of the strategy verification parameter on the risk control logic expression and the second coverage result of the strategy verification parameter on the strategy branch expression; C4: Generate risk control strategy coverage detection data based on the first coverage result and the second coverage result.
[0078] In step C2, during the process of the processor executing the target detection code, after judging the policy verification parameters through the policy branch expression, the execution status of the policy branch expression will be recorded. If there are parameters in the policy verification parameters that can hit the policy branch expression, the execution status of the policy branch expression is hitting the policy branch expression, and the second coverage result of the policy verification parameters on the policy branch expression is the hit type; if there are no parameters in the policy verification parameters that can hit the policy branch expression, the execution status of the policy branch expression is missing the policy branch expression, and the second coverage result of the policy verification parameters on the policy branch expression is the missed type.
[0079] For example, if the logical operator of the risk control logic expression is a logical AND operator, then when all second coverage results are of the hit type, the first coverage result is of the hit type, and when at least one second coverage result is of the miss type, the first coverage result is of the miss type. If the logical operator of the risk control logic expression is a logical OR operator, then when at least one second coverage result is of the hit type, the first coverage result is of the hit type, and when all second coverage results are of the miss type, the first coverage result is of the miss type.
[0080] In step C4, for each second coverage result, if the second coverage result is a miss type, the branch coverage of the policy branch expression corresponding to the second coverage result is 0; if the second coverage result is a hit type, the branch coverage of the policy branch expression corresponding to the second coverage result is 100%. In this way, fine-grained coverage information of statistical policy branch expressions can be achieved. For the risk control logic expression corresponding to the first coverage result, the target number of second coverage results of the hit type is determined, the total number of second coverage results is determined, and the target percentage of the target number to the total number is determined. The target percentage is the policy branch coverage of the target risk control strategy represented by the risk control logic expression. Further, risk control strategy coverage detection data including the policy branch coverage of the target risk control strategy represented by the risk control logic expression and the branch coverage of the policy branch expression can be generated. Among them, the branch coverage of the policy branch expression is used to characterize whether a single policy branch in the target risk control strategy is hit by the policy verification parameter.
[0081] In this way, the embodiments of this specification can provide policy branch coverage during the risk control policy verification process, provide finer-grained statistical information for risk control policy verification, facilitate the discovery of branches missed during the risk control policy verification process, and thus improve the policy coverage of the risk control policy verification process.
[0082] In the risk control strategy coverage detection method provided in this specification, after obtaining the target risk control strategy in the risk control strategy verification scenario and the policy verification parameters for the target risk control strategy, the target risk control condition is obtained by performing policy parsing processing on the target risk control strategy, and the target risk control condition is subjected to conditional logic conversion processing to obtain a risk control logic expression. In this way, a logically accurate and syntactically accurate risk control logic expression is obtained by parsing the target risk control strategy; thereafter, a policy branch splitting processing is performed on the risk control logic expression to obtain a policy branch expression, and a branch coverage detection code generation processing is performed on the target risk control strategy based on the policy branch expression to obtain a branch expression detection code. In this way, the risk control logic expression is split into multiple policy branch expressions to facilitate the insertion of expression detection code, and the execution of the policy branch can be analyzed without additional manual intervention marking. situation; then, a code generation big model is used to perform coverage detection code generation processing based on the strategy verification parameters and branch expression detection code to obtain the target detection code, and the target detection code is executed to obtain the risk control strategy coverage detection data. In this way, by generating the detection code through the big model, the manpower of writing code is saved and the generation efficiency of the detection code is improved. By executing the target detection code, the coverage statistics of the strategy branches in the target risk control strategy and the execution status of each strategy branch can be automatically obtained. Since the strategy verification parameters are obtained from the risk control verification scenario, the risk control strategy developer does not need to perform additional operations. This not only increases the convenience of obtaining the strategy branch coverage in the risk control strategy, but also makes it easier for the risk control strategy developer to improve the strategy branch coverage according to the execution status of the strategy branch, so as to better ensure the accuracy of the risk control strategy.
[0083] The following will be combined Figure 5 , the risk control strategy coverage detection device provided by the embodiment of this specification is introduced in detail. It should be noted that, Figure 5 The risk control strategy coverage detection device shown is used to execute this instruction Figures 2 to 4 For the convenience of explanation, only the part related to the embodiment of this specification is shown. For the specific technical details not disclosed, please refer to this specification. Figures 2 to 4 The embodiment shown.
[0084] See Figure 5 , which shows a schematic diagram of the structure of the risk control policy coverage detection device according to an embodiment of this specification. The risk control policy coverage detection device 1 can be implemented as all or part of the device through software, hardware, or a combination of both. According to some embodiments, the risk control policy coverage detection device 1 includes a policy acquisition module 11, a code generation module 12, and a branch detection module 13, which are specifically used to: A strategy acquisition module 11 is used to acquire a target risk control strategy in a risk control strategy verification scenario and acquire strategy verification parameters for the target risk control strategy; A code generation module 12 is configured to perform policy parsing processing on the target risk control policy to obtain a risk control logic expression, and perform policy branch detection code generation processing on the target risk control policy based on the risk control logic expression to obtain a branch expression detection code; The branch detection module 13 is used to perform a policy branch coverage detection process on the target risk control policy based on the policy verification parameters and the branch expression detection code to obtain risk control policy coverage detection data.
[0085] Optionally, the code generation module 12 includes: An expression splitting unit, configured to perform strategy branch splitting processing on the risk control logic expression to obtain a strategy branch expression; A code generation unit is used to perform branch coverage detection code generation processing on the target risk control strategy based on the strategy branch expression to obtain a branch expression detection code.
[0086] Optional code generation unit, specifically used for: Obtaining a logical operator of the risk control logic expression, and generating a target interpretation and execution code based on the logical operator and the policy branch expression; A first expression detection code for the policy branch expression and a second expression detection code for the risk control logic expression are inserted into the target interpreted execution code to obtain a branch expression detection code.
[0087] Optional, expression split unit, specifically used for: Performing expression verification processing on the risk control logic expression to obtain an expression verification result; If the expression verification result is a verification success type, the risk control logic expression is split to obtain a strategy branch expression.
[0088] Optionally, the code generation module 12 includes: A policy parsing unit, configured to perform policy parsing on the target risk control policy to obtain target risk control conditions; An expression generation unit is used to perform conditional logic conversion processing on the target risk control condition to obtain a risk control logic expression.
[0089] Optionally, the branch detection module 13 includes: A detection code generation unit, configured to use a code generation macro model to perform coverage detection code generation processing based on the strategy verification parameters and the branch expression detection code to obtain a target detection code; The branch detection unit is used to perform code execution processing on the target detection code to obtain risk control strategy coverage detection data.
[0090] Optionally, a detection code generation unit is used to: Determining a code generation prompt word based on the strategy verification parameter and the branch expression detection code; Based on the code generation prompt word, a code generation large model is used to perform code task analysis processing to obtain a target code generation task, and based on the target code generation task, a coverage detection code generation processing is performed to obtain a target detection code.
[0091] Optionally, a branch detection unit is used to: Performing code execution processing on the target detection code to obtain a first coverage result of the policy verification parameter on the risk control logic expression and a second coverage result of the policy verification parameter on the policy branch expression; Based on the first coverage result and the second coverage result, risk control strategy coverage detection data is generated.
[0092] The risk control strategy coverage detection device provided in the embodiment of this specification, after obtaining the target risk control strategy in the risk control strategy verification scenario and the policy verification parameters for the target risk control strategy, performs policy analysis on the target risk control strategy to obtain the risk control logic expression, and then performs policy branch detection code generation processing on the target risk control strategy according to the risk control logic expression to obtain the branch expression detection code, and then performs policy branch coverage detection processing on the target risk control strategy according to the policy verification parameters and the branch expression detection code to obtain the risk control strategy coverage detection data. Therefore, by reusing the policy verification parameters constructed in the risk control strategy verification scenario, the coverage statistics of the policy branches can be automatically performed according to the branch expression detection code, and the risk control strategy developer does not need to perform additional operations, which increases the convenience of obtaining the policy branch coverage in the risk control strategy and effectively improves the efficiency of obtaining the policy branch coverage.
[0093] Please refer to Figure 6 , which shows a schematic diagram of the structure of an electronic device provided by an exemplary embodiment of this specification. The electronic device described in this specification may include one or more of the following components: a processor 110, a memory 120, an input device 130, an output device 140, and a bus 150. The processor 110, the memory 120, the input device 130, and the output device 140 may be connected via the bus 150.
[0094] Processor 110 may include one or more processing cores. Using various interfaces and circuits, processor 110 connects various components within the terminal. It executes instructions, programs, code sets, or instruction sets stored in memory 120, as well as accesses data stored in memory 120, to perform various functions and process data for terminal 100. Optionally, processor 110 may be implemented in hardware using at least one of a digital signal processing (DSP), a field-programmable gate array (FPGA), and a programmable logic array (PLA). Processor 110 may integrate one or a combination of a central processing unit (CPU), a graphics processing unit (GPU), and a modem. The CPU primarily handles the operating system, user interface, and application programs; the GPU is responsible for rendering and drawing display content; and the modem handles wireless communications. It is understood that the modem may also be implemented independently of the processor 110 via a separate communications chip.
[0095] The memory 120 may include a random access memory (RAM) or a read-only memory (ROM). Optionally, the memory 120 includes a non-transitory computer-readable storage medium. The memory 120 may be used to store instructions, programs, codes, code sets, or instruction sets. The memory 120 may include a program storage area and a data storage area, wherein the program storage area may store instructions for implementing an operating system, instructions for implementing at least one function (e.g., a touch function, a sound playback function, an image playback function, etc.), instructions for implementing the following various method embodiments, etc. The operating system may be an Android system, including systems deeply developed based on the Android system, an iOS system developed by Apple, including systems deeply developed based on the iOS system, or other systems.
[0096] In order for the operating system to distinguish the specific application scenarios of third-party applications, it is necessary to open up data communication between third-party applications and the operating system so that the operating system can obtain the current scenario information of third-party applications at any time, and then perform targeted system resource adaptation based on the current scenario.
[0097] The input device 130 is used to receive input commands or data and includes, but is not limited to, a keyboard, a mouse, a camera, a microphone, or a touch-sensitive device. The output device 140 is used to output commands or data and includes, but is not limited to, a display device and a speaker. In one example, the input device 130 and the output device 140 may be combined, and the input device 130 and the output device 140 may be a touch-sensitive display.
[0098] The touch display screen can be designed as a full screen, a curved screen or a special-shaped screen. The touch display screen can also be designed as a combination of a full screen and a curved screen, or a combination of a special-shaped screen and a curved screen, which is not limited in the embodiments of this specification.
[0099] In addition, those skilled in the art will understand that the structures of the electronic devices shown in the above figures do not limit the electronic devices. The electronic devices may include more or fewer components than shown, or may combine certain components or arrange the components differently. For example, the electronic devices may also include radio frequency circuits, input units, sensors, audio circuits, wireless fidelity (WiFi) modules, power supplies, Bluetooth modules, and other components, which will not be described in detail here.
[0100] In some embodiments, Figure 6 In the electronic device shown, the processor 110 may be configured to call a program for detecting the risk control policy coverage ratio stored in the memory 120 and specifically perform the following operations: Obtaining a target risk control strategy in a risk control strategy verification scenario, and obtaining strategy verification parameters for the target risk control strategy; Performing policy parsing processing on the target risk control strategy to obtain a risk control logic expression, and performing policy branch detection code generation processing on the target risk control strategy based on the risk control logic expression to obtain a branch expression detection code; Based on the strategy verification parameters and the branch expression detection code, the target risk control strategy is subjected to strategy branch coverage detection processing to obtain risk control strategy coverage detection data.
[0101] Optionally, when executing the step of performing policy branch detection code generation processing on the target risk control policy based on the risk control logic expression to obtain a branch expression detection code, the processor 110 specifically performs the following operations: Performing strategy branch splitting processing on the risk control logic expression to obtain a strategy branch expression; Based on the strategy branch expression, branch coverage detection code generation processing is performed on the target risk control strategy to obtain a branch expression detection code.
[0102] Optionally, when executing the step of performing branch coverage detection code generation processing on the target risk control policy based on the policy branch expression to obtain the branch expression detection code, the processor 110 specifically performs the following operations: Obtaining a logical operator of the risk control logic expression, and generating a target interpretation and execution code based on the logical operator and the policy branch expression; A first expression detection code for the policy branch expression and a second expression detection code for the risk control logic expression are inserted into the target interpreted execution code to obtain a branch expression detection code.
[0103] Optionally, when executing the step of performing policy branch splitting processing on the risk control logic expression to obtain a policy branch expression, the processor 110 specifically performs the following operations: Performing expression verification processing on the risk control logic expression to obtain an expression verification result; If the expression verification result is a verification success type, the risk control logic expression is split to obtain a strategy branch expression.
[0104] Optionally, when executing the step of performing policy parsing on the target risk control policy to obtain a risk control logic expression, the processor 110 specifically performs the following operations: Performing strategy analysis on the target risk control strategy to obtain target risk control conditions; The target risk control condition is subjected to conditional logic conversion processing to obtain a risk control logic expression.
[0105] Optionally, when executing the step of performing policy branch coverage detection processing on the target risk control policy based on the policy verification parameter and the branch expression detection code to obtain risk control policy coverage detection data, the processor 110 specifically performs the following operations: Using a code generation model to perform coverage detection code generation processing based on the strategy verification parameters and the branch expression detection code to obtain a target detection code; Code execution processing is performed on the target detection code to obtain risk control strategy coverage detection data.
[0106] Optionally, when executing the step of using the code generation large model to perform coverage detection code generation processing based on the strategy verification parameters and the branch expression detection code to obtain the target detection code, the processor 110 specifically performs the following operations: Determining a code generation prompt word based on the strategy verification parameter and the branch expression detection code; Based on the code generation prompt word, a code generation large model is used to perform code task analysis processing to obtain a target code generation task, and based on the target code generation task, a coverage detection code generation processing is performed to obtain a target detection code.
[0107] Optionally, when executing the step of performing code execution processing on the target detection code to obtain risk control strategy coverage detection data, the processor 110 specifically performs the following operations: Performing code execution processing on the target detection code to obtain a first coverage result of the policy verification parameter on the risk control logic expression and a second coverage result of the policy verification parameter on the policy branch expression; Based on the first coverage result and the second coverage result, risk control strategy coverage detection data is generated.
[0108] An embodiment of this specification also provides a computer-readable storage medium, which stores at least one instruction, and the at least one instruction is used to be executed by a processor to implement the risk control strategy coverage detection method as described in the above embodiments.
[0109] An embodiment of this specification also provides a computer program product, which stores at least one instruction, and the at least one instruction is loaded and executed by the processor to implement the risk control strategy coverage detection method described in the above embodiments.
[0110] Those skilled in the art will appreciate that in one or more of the above examples, the functions described in the embodiments of this specification can be implemented using hardware, software, firmware, or any combination thereof. When implemented using software, these functions can be stored in a computer-readable medium or transmitted as one or more instructions or codes on a computer-readable medium. Computer-readable media include computer storage media and communication media, wherein communication media include any medium that facilitates the transmission of computer programs from one place to another. The storage medium can be any available medium that can be accessed by a general-purpose or special-purpose computer.
[0111] The above description is only an optional embodiment of this specification and is not intended to limit this specification. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of this specification should be included in the scope of protection of this specification.
[0112] The foregoing description of this specification describes specific embodiments. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims can be performed in an order different from that described in the embodiments and still achieve the desired results. Furthermore, the processes depicted in the accompanying drawings do not necessarily require the specific order shown or the sequential order to achieve the desired results. In certain embodiments, multitasking and parallel processing are also possible or may be advantageous.
Claims
1. A method for detecting risk control strategy coverage, characterized in that: The method comprises: Obtaining a target risk control strategy in a risk control strategy verification scenario, and obtaining strategy verification parameters for the target risk control strategy; Performing policy parsing processing on the target risk control strategy to obtain a risk control logic expression, and performing policy branch detection code generation processing on the target risk control strategy based on the risk control logic expression to obtain a branch expression detection code; Based on the strategy verification parameters and the branch expression detection code, the target risk control strategy is subjected to strategy branch coverage detection processing to obtain risk control strategy coverage detection data.
2. The method according to claim 1, characterized in that The performing strategy branch detection code generation processing on the target risk control strategy based on the risk control logic expression to obtain a branch expression detection code includes: Performing strategy branch splitting processing on the risk control logic expression to obtain a strategy branch expression; Based on the strategy branch expression, branch coverage detection code generation processing is performed on the target risk control strategy to obtain a branch expression detection code.
3. The method according to claim 2, characterized in that The step of performing branch coverage detection code generation processing on the target risk control strategy based on the strategy branch expression to obtain a branch expression detection code includes: Obtaining a logical operator of the risk control logic expression, and generating a target interpretation and execution code based on the logical operator and the policy branch expression; A first expression detection code for the policy branch expression and a second expression detection code for the risk control logic expression are inserted into the target interpreted execution code to obtain a branch expression detection code.
4. The method according to claim 2, characterized in that The performing strategy branch splitting processing on the risk control logic expression to obtain a strategy branch expression includes: Performing expression verification processing on the risk control logic expression to obtain an expression verification result; If the expression verification result is a verification success type, the risk control logic expression is split to obtain a strategy branch expression.
5. The method according to claim 1, wherein The performing of policy parsing on the target risk control policy to obtain a risk control logic expression includes: Performing strategy analysis on the target risk control strategy to obtain target risk control conditions; The target risk control condition is subjected to conditional logic conversion processing to obtain a risk control logic expression.
6. The method according to claim 1, characterized in that The performing a strategy branch coverage detection process on the target risk control strategy based on the strategy verification parameter and the branch expression detection code to obtain risk control strategy coverage detection data includes: Using a code generation model to perform coverage detection code generation processing based on the strategy verification parameters and the branch expression detection code to obtain a target detection code; Code execution processing is performed on the target detection code to obtain risk control strategy coverage detection data.
7. The method according to claim 6, characterized in that The code generation macro model is used to perform coverage detection code generation processing based on the strategy verification parameters and the branch expression detection code to obtain the target detection code, including: Determining a code generation prompt word based on the strategy verification parameter and the branch expression detection code; Based on the code generation prompt word, a code generation large model is used to perform code task analysis processing to obtain a target code generation task, and based on the target code generation task, a coverage detection code generation processing is performed to obtain a target detection code.
8. The method according to claim 6, characterized in that The code execution processing is performed on the target detection code to obtain risk control strategy coverage detection data, including: Performing code execution processing on the target detection code to obtain a first coverage result of the policy verification parameter on the risk control logic expression and a second coverage result of the policy verification parameter on the policy branch expression; Based on the first coverage result and the second coverage result, risk control strategy coverage detection data is generated.
9. A risk control strategy coverage detection device, characterized in that: The device comprises: A strategy acquisition module is used to obtain the target risk control strategy in the risk control strategy verification scenario and obtain strategy verification parameters for the target risk control strategy; a code generation module, configured to perform policy parsing processing on the target risk control policy to obtain a risk control logic expression, and perform policy branch detection code generation processing on the target risk control policy based on the risk control logic expression to obtain a branch expression detection code; The branch detection module is used to perform strategy branch coverage detection processing on the target risk control strategy based on the strategy verification parameters and the branch expression detection code to obtain risk control strategy coverage detection data.
10. A computer storage medium, characterized in that The computer storage medium stores a plurality of instructions, and the instructions are suitable for being loaded by a processor and executing the method according to any one of claims 1 to 8.
11. A computer program product, characterized in that The computer program product stores at least one instruction, and the at least one instruction is loaded by a processor to execute the method according to any one of claims 1 to 8.
12. An electronic device, characterized in that: include: A processor and a memory; wherein the memory stores a computer program, and the computer program is suitable for being loaded by the processor and executing the method according to any one of claims 1 to 8.
Citation Information
Patent Citations
Code coverage analysis method and application server
CN107797923A
A method and a device for risk control strategy and business risk control
CN109002949A
Branch strategy generation method and device, terminal equipment and storage medium
CN114489617A
Risk control strategy processing method and device, medium and equipment
CN116433015A
Risk control strategy evaluation method and device and computing equipment
CN119515568A