Point operation activity risk prevention and control method and device, computer equipment, readable storage medium and program product

By collecting and analyzing multi-source heterogeneous data, the total risk score of users is determined, and intelligent risk assessment and management of user accounts is realized, the problem of points ecological fairness is solved, and the occurrence of points illegally obtained is reduced.

CN120494481APending Publication Date: 2025-08-15SHENZHEN COMTOP INFORMATION TECH
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510470353.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-15
Publication Date
2025-08-15

AI Technical Summary

Technical Problem

In the prior art, some users obtain points through abnormal means, destroying the fairness of the points ecosystem.

Method used

Collect multi-source heterogeneous data, including user behavior data, user transaction data and risk database, determine the user's total risk score through feature data and feature weights, and release, mark or intercept user accounts according to the scoring threshold.

Benefits of technology

It realizes intelligent risk assessment of user accounts, reduces the occurrence of illegal points acquisition incidents, and maintains the fairness of the points ecosystem.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120494481A_ABST
    Figure CN120494481A_ABST
Patent Text Reader

Abstract

The invention relates to a point operation activity risk prevention and control method and device, computer equipment, a readable storage medium and a program product. The method comprises the following steps: acquiring multi-source heterogeneous data including user behavior data, user transaction data and a risk library, and determining a total risk score of a user according to each feature data in the multi-source heterogeneous data and a corresponding feature weight; under the condition that the total risk score is smaller than or equal to a first score threshold value, releasing the user account; when the total risk score is greater than a first score threshold and the total risk score is less than or equal to a second score threshold, marking the user account as an account needing to be manually rechecked; and when the total risk score is greater than a second score threshold, intercepting the user account.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the technical field of risk prevention and control of points operation activities, and in particular to a method, apparatus, computer equipment, computer-readable storage medium, and computer program product for risk prevention and control of points operation activities. Background Art

[0002] With the rapid development of the internet economy, point-based marketing activities have become an important means for companies to improve user stickiness and promote user activity. Users can earn points by participating in point-based marketing activities (such as check-ins, consumption, sharing, etc.), and these points can be redeemed for prizes or privileges.

[0003] However, some users illegally obtain points through abnormal means (such as fake orders, false transactions, etc.) or loopholes in the points operation activities, which undermines the fairness of the points ecosystem. Summary of the Invention

[0004] Based on this, it is necessary to provide a risk prevention and control method, device, computer equipment, computer-readable storage medium and computer program product for points operation activities that can maintain the fairness of the points ecosystem in response to the above technical problems.

[0005] In the first aspect, this application provides a method for risk prevention and control of point operation activities, including:

[0006] Collect multi-source heterogeneous data; multi-source heterogeneous data includes user behavior data, user transaction data and risk database;

[0007] Determine the overall risk score of the user account based on the feature data and corresponding feature weights in multi-source heterogeneous data;

[0008] If the total risk score is less than or equal to the first score threshold, release the user account;

[0009] If the total risk score is greater than the first scoring threshold and less than or equal to the second scoring threshold, mark the user account as an account requiring manual review;

[0010] If the total risk score is greater than the second score threshold, the user account is blocked;

[0011] The first scoring threshold is smaller than the second scoring threshold.

[0012] In one embodiment, after the step of collecting multi-source heterogeneous data, the method further includes:

[0013] Perform data cleaning on multi-source heterogeneous data.

[0014] In one embodiment, the steps of performing data cleaning on multi-source heterogeneous data include:

[0015] Verify each feature data;

[0016] If the feature data does not meet the corresponding verification logic, the user account is blocked from entering the database;

[0017] If the feature data satisfies the corresponding verification logic and does not meet the field requirements, the feature data is corrected.

[0018] In one embodiment, the step of performing data cleaning on multi-source heterogeneous data further includes:

[0019] Extract features from various feature data in multi-source heterogeneous data; features include time series features, correlation features and composite features;

[0020] If each feature does not meet the corresponding feature requirements, the user account will be blocked from entering the database.

[0021] In one embodiment, the method further includes:

[0022] Obtain the corresponding action results for the total risk score; the action results include releasing the user account, marking the user account, and blocking the user account;

[0023] Adjusting prevention and control parameters; the prevention and control parameters include at least one of a first scoring threshold, a second scoring threshold, and a feature weight;

[0024] Based on the multi-source heterogeneous data and the adjusted prevention and control parameters, the steps from "determining the user's total risk score" to "blocking the user account if the total risk score is greater than the second score threshold" are executed to obtain the corresponding treatment results of the adjusted prevention and control parameters;

[0025] According to the difference between the treatment results corresponding to the total risk score and the treatment results corresponding to the adjusted prevention and control parameters, the prevention and control parameters before adjustment are corrected, and the degree of correction is positively correlated with the degree of difference.

[0026] In one embodiment, the method further includes:

[0027] Introducing adversarial samples; adversarial samples include sample behavior data and sample transaction data;

[0028] Based on the feature data and corresponding feature weights in the adversarial sample, execute the steps from "determining the user's total risk score" to "blocking the user account if the total risk score is greater than the second score threshold" to obtain the corresponding handling result of the adversarial sample;

[0029] According to the difference between the disposal results corresponding to the total risk score and the disposal results corresponding to the adversarial sample, the prevention and control parameters corresponding to the total risk score are corrected, and the degree of correction is positively correlated with the degree of difference.

[0030] Secondly, this application also provides a risk prevention and control device for point-based operation activities, including:

[0031] Data collection module, used to collect multi-source heterogeneous data; multi-source heterogeneous data includes user behavior data, user transaction data and risk database;

[0032] The total risk score determination module is used to determine the user's total risk score based on each feature data and corresponding feature weights in multi-source heterogeneous data;

[0033] A first handling module is configured to release the user account if the total risk score is less than or equal to a first score threshold;

[0034] A second handling module is configured to mark the user account as requiring manual review when the total risk score is greater than the first scoring threshold and less than or equal to the second scoring threshold;

[0035] A third handling module is configured to block the user account if the total risk score is greater than a second score threshold;

[0036] The first scoring threshold is smaller than the second scoring threshold.

[0037] In a third aspect, the present application also provides a computer device comprising a memory and a processor, wherein the memory stores a computer program, and when the processor executes the computer program, it implements any step in the above-mentioned method for risk prevention and control of point operation activities.

[0038] In a fourth aspect, the present application also provides a computer-readable storage medium on which a computer program is stored, and when the computer program is executed by a processor, any step in the above-mentioned risk prevention and control method for point operation activities is implemented.

[0039] In a fifth aspect, the present application also provides a computer program product, including a computer program, which, when executed by a processor, implements any step in the above-mentioned point operation activity risk prevention and control method.

[0040] The aforementioned points-based operation activity risk control method, apparatus, computer equipment, computer-readable storage medium, and computer program product collect multi-source heterogeneous data, including user behavior data, user transaction data, and a risk library, and determine a user's total risk score based on the feature data and corresponding feature weights in the multi-source heterogeneous data. If the total risk score is less than or equal to a first scoring threshold, the user account is released; if the total risk score is greater than the first scoring threshold and less than or equal to a second scoring threshold, the user account is marked as requiring manual review; and if the total risk score is greater than the second scoring threshold, the user account is blocked. The points-based operation activity risk control method can assess the risk of user accounts based on the points obtained during the activity, and then, based on the risk assessment results, release, mark, or block the user account, thereby significantly reducing the occurrence of illegal activity point acquisition incidents and maintaining the fairness of the points ecosystem. This points-based operation activity risk control method can achieve intelligent risk control while balancing control efficiency and labor costs. BRIEF DESCRIPTION OF THE DRAWINGS

[0041] In order to more clearly illustrate the technical solutions in the embodiments of the present application or related technologies, the following briefly introduces the drawings required for use in the embodiments of the present application or related technical descriptions. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other related drawings can be obtained based on these drawings without paying any creative work.

[0042] Figure 1 This is a diagram of an application environment of a risk prevention and control method for a points operation activity in one embodiment;

[0043] Figure 2 A flowchart of a risk prevention and control method for a points operation activity in one embodiment;

[0044] Figure 3 This is a structural block diagram of a risk prevention and control device for point-based operation activities in one embodiment;

[0045] Figure 4 FIG. 1 is a diagram showing the internal structure of a computer device in one embodiment. DETAILED DESCRIPTION

[0046] In order to make the purpose, technical solutions and advantages of this application more clear, the following further describes this application in detail with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain this application and are not intended to limit this application.

[0047] The risk prevention and control method of the points operation activity provided in the embodiment of the present application can be applied to Figure 1In the application environment shown, terminal 102 communicates with server 104 via a network. The data storage system can store multi-source heterogeneous data that server 104 needs to process, including user behavior data, user transaction data, and a risk database. The data storage system can be integrated with server 104 or placed on a cloud or other network server. Server 104 obtains the multi-source heterogeneous data stored in the data storage system and then determines the user's total risk score based on the feature data in the multi-source heterogeneous data and the feature weights corresponding to these feature data. If the total risk score is less than or equal to a first scoring threshold, the corresponding user account is deemed to have no violations, and server 104 releases the user account normally. If the total risk score is greater than the first scoring threshold and less than or equal to a second scoring threshold, the corresponding user account is deemed to have violated the rules and requires manual review. Server 104 marks the user account as requiring manual review. If the total risk score is greater than the second scoring threshold, the corresponding user account is deemed to have violated the rules and server 104 blocks the user account. Server 104 can transmit the results of its actions for releasing, marking, and blocking user accounts to terminal 102 via the network, allowing staff to review the specific status of each user account and manually review marked user accounts. Terminal 102 may include, but is not limited to, various personal computers, laptops, smartphones, tablets, IoT devices, and portable wearable devices. IoT devices may include smart speakers, smart TVs, smart air conditioners, smart car devices, projectors, etc. Portable wearable devices may include smart watches, smart bracelets, head-mounted devices, etc. Head-mounted devices may include virtual reality (VR) devices, augmented reality (AR) devices, smart glasses, etc. Server 104 may be a standalone physical server, a server cluster or distributed system consisting of multiple physical servers, or a cloud server providing cloud computing services.

[0048] In an exemplary embodiment, Figure 2 As shown, a risk prevention and control method for point operation activities is provided, which is applied to Figure 1 The server 104 in FIG. 1 is used as an example to illustrate the invention, including:

[0049] S202, collecting multi-source heterogeneous data; the multi-source heterogeneous data includes user behavior data, user transaction data and risk database.

[0050] User behavior data includes the user's login behavior, check-in behavior, etc. for the user account they own.

[0051] User transaction data includes points acquisition, points redemption and other points change behaviors in user accounts.

[0052] The risk database includes a blacklist and an IP (Internet Protocol) risk database. The blacklist can store user accounts with known threats, such as those with malicious IP addresses, those with a history of fraudulent activity, and those that have illegally obtained points. Predefined blacklists enable direct blocking of user accounts posing known threats. The IP risk database can store user accounts with high-risk IP addresses; the risk level can be determined based on dynamic analysis. Dynamic analysis includes assessment methods such as IP association graphs and behavioral entropy. The IP risk database enables precise prevention and control.

[0053] To collect multi-source heterogeneous data, Apache Kafka can be used as a message queue. Flink CDC (Flink Change Data Capture) then captures change logs for each feature data element within this multi-source heterogeneous data, enabling real-time collection. Server logs are then collected using Filebeat (a log collector) and Logstash (a data collection engine), standardized, and written to Elasticsearch. Apache Kafka is an open-source messaging system project written in Scala. Its goal is to provide a unified, high-throughput, and low-latency platform for processing real-time data. Elasticsearch is a distributed, highly scalable, and highly real-time search and data analytics engine. Logstash and Filebeat help collect, aggregate, and enrich multi-source heterogeneous data and store it in Elasticsearch.

[0054] S204: Determine the total risk score of the user account based on each feature data in the multi-source heterogeneous data and the corresponding feature weight.

[0055] S206: If the total risk score is less than or equal to the first score threshold, release the user account.

[0056] If the total risk score is less than or equal to the first score threshold, the user account can be considered to have no violations and is not in the risk database. In other words, the user account is not in the blacklist database, and the IP address to which the user account belongs is not in the IP risk database. In this case, it can be determined that the user account does not pose a risk of illegally obtaining activity points. The user account can be directly released and can use the user account normally.

[0057] S208: If the total risk score is greater than a first scoring threshold and less than or equal to a second scoring threshold, mark the user account as requiring manual review, where the first scoring threshold is less than the second scoring threshold.

[0058] If the total risk score is greater than the first scoring threshold and less than or equal to the second scoring threshold, it can be considered that the currently detected user account may have violated regulations and requires further manual review. In this case, the user account can be marked, so that staff can verify whether the marked user account has violated regulations through a marking list. If the marked user account has violated regulations, the user account can be manually blocked. If the marked user account has not violated regulations, the user account can be manually released. The marking list is a list of marked user accounts.

[0059] S210: If the total risk score is greater than a second score threshold, block the user account.

[0060] If the total risk score exceeds the second threshold, the user account can be considered to have violated regulations or be in the risk database, that is, the user account is blacklisted in the blacklist database, or the IP address associated with the user account is in the IP risk database. In this case, the user account is directly blocked to prevent the user from illegally obtaining activity points.

[0061] The higher the first and second scoring thresholds are, the stricter the requirements for the user account are. For example, the first scoring threshold may be 30, and the second scoring threshold may be 70.

[0062] The above-mentioned risk control method for points operation activities collects multi-source heterogeneous data including user behavior data, user transaction data, and risk libraries, and determines the user's total risk score based on the feature data and corresponding feature weights in the multi-source heterogeneous data; if the total risk score is less than or equal to the first score threshold, the user account is released; if the total risk score is greater than the first score threshold and the total risk score is less than or equal to the second score threshold, the user account is marked as an account requiring manual review; if the total risk score is greater than the second score threshold, the user account is blocked. The risk control method for points operation activities can be used to assess the risk of user accounts based on the acquisition of activity points, and then, based on the risk assessment results, the user account is released, marked, or blocked, thereby significantly reducing the occurrence of illegal acquisition of activity points and maintaining the fairness of the points ecosystem. This risk control method for points operation activities can achieve intelligent risk control, taking into account both control efficiency and labor costs.

[0063] In an exemplary embodiment, after the step of collecting multi-source heterogeneous data, the method further includes:

[0064] Perform data cleaning on multi-source heterogeneous data.

[0065] Data cleaning processing of multi-source heterogeneous data can improve the reliability of individual feature data in multi-source heterogeneous data, thereby obtaining a reliable overall risk score and achieving accurate identification of user accounts.

[0066] In an exemplary embodiment, the steps of performing data cleaning on multi-source heterogeneous data include:

[0067] Verify each feature data.

[0068] If the feature data does not meet the corresponding verification logic, the user account will be blocked from entering the database.

[0069] If the feature data satisfies the corresponding verification logic and does not meet the field requirements, the feature data is corrected.

[0070] Verify each feature data including completeness, accuracy, consistency and timeliness.

[0071] Integrity verification includes checking the integrity of required fields such as the user ID and transaction serial number. If a required field is missing, the user account is blocked from being entered into the database, implementing a preemptive interception to ensure that the required fields of the user account entering the database are always missing.

[0072] The accuracy check includes checking the numerical range and filling format of the user account. The check of the numerical range includes checking the age corresponding to the user account. For example, the age range is set to 0~120 years old. When the age corresponding to the user account is within the age range, the age corresponding to the user account is considered accurate. When the age corresponding to the user account is outside the age range, the age corresponding to the user account is considered inaccurate, and the user account is blocked from being stored, thereby achieving pre-interception. The check of the filling format includes format verification of the mobile phone number corresponding to the user account. The user account is allowed to be stored only when the input mobile phone number meets the format specifications of the mobile phone number.

[0073] Consistency verification involves verifying cross-system data in a user account. For example, cross-system data might be order amounts and payment records. If the order amounts and payment records match, the data is considered to have passed the logical alignment verification, and the user account is allowed to be stored.

[0074] Timeliness verification includes checking the update status of the feature data in the user account to ensure that the update frequency of each feature data meets business requirements. For example, it verifies whether the delay of user behavior data is less than or equal to 5 minutes.

[0075] If the repairable data in multi-source heterogeneous data meets the aforementioned validation logic but the fields do not meet the field requirements, the repairable data can be automatically filled in or a completion program can be triggered. Automatic filling can use a system-preset default value. The completion program can remind the user to fill in the repairable data again, enabling post-processing corrections. For example, the repairable data can be a user's address.

[0076] In an exemplary embodiment, the step of performing data cleaning on multi-source heterogeneous data further includes:

[0077] Feature extraction is performed on each feature data in multi-source heterogeneous data; features include time series features, correlation features and composite features.

[0078] If each feature does not meet the corresponding feature requirements, the user account will be blocked from entering the database.

[0079] Time series features include the activity points earned by a user account within a preset timeframe. For example, the frequency of activity points earned by a user account over the past seven days and the daily peak number of activity points earned can be obtained. If the frequency of activity points earned by a user account over the past seven days is too high and / or the daily peak number of activity points exceeds the normal value, it can be assumed that the user account is maliciously acquiring activity points, and the user account can be blocked from accessing the database.

[0080] Association characteristics include the number of user accounts associated with the same device and the geographic clustering of the IP addresses of each user account. For example, if more than three user accounts are associated with the same device, it can be considered malicious activity point acquisition, and the device can be blocked from adding new user accounts to the database. If multiple user accounts share the same IP address, it can be considered malicious activity point acquisition, and these user accounts can be blocked from adding them to the database.

[0081] Composite features include the ratio of activity points consumed to activity points earned, as well as the proportion of operations performed during abnormal times. Periods of low user activity, such as early morning, can be considered abnormal times. If a user account experiences frequent operations during these abnormal times, the account can be considered abnormal and its access can be blocked. High-frequency operations include both high-frequency acquisition and high-frequency consumption of activity points. For example, redeeming activity points more than five times within an hour can be considered a high-frequency operation.

[0082] In an exemplary embodiment, blocking user accounts from entering the database may include marking the user accounts, temporarily blocking these user accounts from entering the database, and then manually releasing or blocking the marked user accounts after manual review. Blocking user accounts from entering the database may also include directly blocking the user accounts.

[0083] In one embodiment, intercepting a user account includes soft interception, hard interception, and coordinated handling.

[0084] Soft interception includes sending pop-up verification codes or SMS verification codes.

[0085] Hard interception includes freezing user accounts, rolling back abnormal activity points, etc.

[0086] Collaborative disposal includes synchronizing the user account ID to the risk library.

[0087] In one embodiment, when the characteristic data includes batch registration of user accounts with the same IP address, forced face verification can be used to block the entry of user accounts into the database.

[0088] In one embodiment, when the characteristic data includes the existence of a timed script check-in to obtain activity points, the acquisition of activity points can be limited by setting an upper limit for daily activity points.

[0089] In one embodiment, when the characteristic data includes new devices frequently accessing the redemption interface of activity points, or the parameter information of multiple user accounts is patterned, human-machine verification can be set or redemption link traffic can be broken to suspend high-frequency activity points redemption, thereby preventing scalpers from rushing to redeem points.

[0090] In one embodiment, the risk prevention and control method for the points operation activity further includes:

[0091] In the case of marking a user account or blocking a user account, an early warning notification can be issued so that staff can take quick countermeasures to maintain the balance of the points ecosystem.

[0092] In an exemplary embodiment, the above-mentioned point operation activity risk prevention and control method further includes:

[0093] Obtain the disposal results corresponding to the total risk score; disposal results include releasing the user account, marking the user account, and blocking the user account.

[0094] Adjust the prevention and control parameters; the prevention and control parameters include at least one of the first scoring threshold, the second scoring threshold and the feature weight.

[0095] Based on multi-source heterogeneous data and the adjusted prevention and control parameters, the steps between "determining the user's total risk score" and "blocking the user account when the total risk score is greater than the second score threshold" are executed to obtain the disposal results corresponding to the adjusted prevention and control parameters.

[0096] According to the difference between the treatment results corresponding to the total risk score and the treatment results corresponding to the adjusted prevention and control parameters, the prevention and control parameters before adjustment are corrected, and the degree of correction is positively correlated with the degree of difference.

[0097] Based on the characteristic data in the multi-source heterogeneous data and the adjusted prevention and control parameters, the corresponding treatment results can be determined. By comparing the treatment results corresponding to the total risk score with the treatment results corresponding to the adjusted prevention and control parameters, the reliability and effectiveness of the total risk score can be verified.

[0098] In an exemplary embodiment, the above-mentioned point operation activity risk prevention and control method further includes:

[0099] Introduce adversarial samples; adversarial samples include sample behavior data and sample transaction data.

[0100] Based on the feature data and corresponding feature weights in the adversarial sample, the steps between "determining the user's total risk score" and "blocking the user account when the total risk score is greater than the second score threshold" are executed to obtain the disposal result corresponding to the adversarial sample.

[0101] According to the difference between the disposal results corresponding to the total risk score and the disposal results corresponding to the adversarial sample, the prevention and control parameters corresponding to the total risk score are corrected, and the degree of correction is positively correlated with the degree of difference.

[0102] Since the disposal results of the adversarial samples are known, if there is a difference between the disposal results corresponding to the total risk score and the disposal results corresponding to the adversarial samples, it means that there is a problem with the prevention and control parameters corresponding to the total risk score. At this time, the prevention and control parameters corresponding to the total risk score can be adjusted, and the disposal results corresponding to the total risk score can be obtained again until the disposal results corresponding to the total risk score are consistent with the disposal results corresponding to the adversarial samples. At this time, it can be considered that the prevention and control parameters corresponding to the total risk score are reliable, which can ensure the reliability of the risk prevention and control method of the points operation activities and reduce the false interception rate.

[0103] In one embodiment, the step of determining the user's overall risk score based on each feature data and corresponding feature weights in the multi-source heterogeneous data includes:

[0104] Get the user risk score formula.

[0105] The user's overall risk score is determined based on each feature data and the corresponding feature weight, and based on the user risk score formula.

[0106] The above user risk score formula is:

[0107]

[0108] Among them, RiskScore is the total risk score; f i (x) is the i-th feature data; w i is the feature weight corresponding to the i-th feature data; is the model bias term.

[0109] Model bias is a comprehensive reflection of latent factors and / or random errors (e.g., collection errors in heterogeneous multi-source data, unexpected events, etc.) not captured in the user risk scoring formula. Uncaptured latent factors can be understood as other data behaviors that are not identified as uncharacterized data, such as frequent changes in user account contact information.

[0110] It should be understood that, although the various steps in the flowcharts involved in the various embodiments described above are displayed in sequence according to the instructions of the arrows, these steps are not necessarily executed in sequence in the order indicated by the arrows. Unless otherwise specified herein, there is no strict order restriction on the execution of these steps, and these steps can be executed in other orders. Moreover, at least a portion of the steps in the flowcharts involved in the various embodiments described above can include multiple steps or multiple stages, and these steps or stages are not necessarily executed and completed at the same time, but can be executed at different times, and the execution order of these steps or stages is not necessarily to be carried out in sequence, but can be executed in turn or alternately with other steps or at least a portion of steps or stages in other steps.

[0111] Based on the same inventive concept, the present application also provides a point-based operation activity risk prevention and control device for implementing the above-mentioned point-based operation activity risk prevention and control method. The implementation solution provided by this device is similar to the implementation solution described in the above-mentioned method. Therefore, the specific limitations in one or more embodiments of the point-based operation activity risk prevention and control device provided below can be referred to the limitations of the point-based operation activity risk prevention and control method above, and will not be repeated here.

[0112] In an exemplary embodiment, Figure 3 As shown, a risk prevention and control device 300 for a points operation activity is provided, comprising: a data collection module 302, a total risk score determination module 304, a first handling module 306, a second handling module 308, and a third handling module 310, wherein:

[0113] The data collection module 302 is used to collect multi-source heterogeneous data; the multi-source heterogeneous data includes user behavior data, user transaction data and risk database.

[0114] The total risk score determination module 304 is used to determine the user's total risk score based on each feature data in the multi-source heterogeneous data and the corresponding feature weights.

[0115] The first handling module 306 is configured to release the user account if the total risk score is less than or equal to a first score threshold.

[0116] The second handling module 308 is configured to mark the user account as requiring manual review when the total risk score is greater than the first scoring threshold and less than or equal to the second scoring threshold.

[0117] The third handling module 310 is configured to block the user account if the total risk score is greater than a second score threshold.

[0118] The first scoring threshold is smaller than the second scoring threshold.

[0119] The point-based activity risk control device 300 can assess the risk of user accounts based on the acquisition of activity points, and then, based on the risk assessment results, release, mark, or block the user accounts, thereby significantly reducing the occurrence of illegal activity point acquisition and maintaining the fairness of the point-based ecosystem. This method for risk control of point-based activities can achieve intelligent risk control, balancing control efficiency and labor costs.

[0120] In one embodiment, the above-mentioned point operation activity risk prevention and control device 300 further includes: a data cleaning module.

[0121] The data cleaning module is used to perform data cleaning on multi-source heterogeneous data.

[0122] In one embodiment, the data cleaning module includes: a verification module, a first blocking module and a correction module.

[0123] The verification module is used to verify each feature data.

[0124] The first blocking module is used to block the storage of the user account when the characteristic data does not meet the corresponding verification logic.

[0125] The correction module is used to correct the feature data when the feature data meets the corresponding verification logic and the feature data does not meet the field requirements.

[0126] In one embodiment, the data cleaning module further includes: a feature extraction module and a second blocking module.

[0127] The feature extraction module is used to extract features from various feature data in multi-source heterogeneous data; features include time series features, correlation features and composite features.

[0128] The second blocking module is used to block the user account from being stored in the database when each feature does not meet the corresponding feature requirements.

[0129] In one embodiment, the above-mentioned point operation activity risk prevention and control device 300 further includes: a first processing result acquisition module, an adjustment module, a second processing result acquisition module and a first prevention and control parameter correction module.

[0130] The first disposal result acquisition module is used to obtain the disposal result corresponding to the total risk score; the disposal results include releasing the user account, marking the user account and blocking the user account.

[0131] The adjustment module is used to adjust the prevention and control parameters; the prevention and control parameters include at least one of a first scoring threshold, a second scoring threshold, and a feature weight.

[0132] The second disposal result acquisition module is used to execute the steps between "determining the user's total risk score" to "intercepting the user account when the total risk score is greater than the second score threshold" based on multi-source heterogeneous data and adjusted prevention and control parameters, and obtain the disposal results corresponding to the adjusted prevention and control parameters.

[0133] The first prevention and control parameter correction module is used to correct the prevention and control parameters before adjustment based on the difference between the treatment result corresponding to the total risk score and the treatment result corresponding to the adjusted prevention and control parameters. The degree of correction is positively correlated with the degree of difference.

[0134] In one embodiment, the above-mentioned point operation activity risk prevention and control device 300 also includes: an adversarial sample introduction module, a third processing result acquisition module and a second prevention and control parameter correction module.

[0135] The adversarial sample introduction module is used to introduce adversarial samples; adversarial samples include sample behavior data and sample transaction data.

[0136] The third disposal result acquisition module is used to execute the steps between "determining the user's total risk score" to "blocking the user account when the total risk score is greater than the second score threshold" based on the feature data and corresponding feature weights in the adversarial sample to obtain the disposal result corresponding to the adversarial sample.

[0137] The second prevention and control parameter correction module is used to correct the prevention and control parameters corresponding to the total risk score based on the difference between the treatment result corresponding to the total risk score and the treatment result corresponding to the adversarial sample. The degree of correction is positively correlated with the degree of difference.

[0138] Each module in the aforementioned risk prevention and control device for point-based operation activities may be implemented in whole or in part through software, hardware, or a combination thereof. Each module may be embedded in or independent of a processor in a computer device in hardware form, or may be stored in a computer device's memory in software form, so that the processor can call and execute the corresponding operations of each module.

[0139] In an exemplary embodiment, a computer device is provided. The computer device may be a terminal, and its internal structure diagram may be as shown in FIG. Figure 4 As shown. The computer device includes a processor, memory, an input / output interface, a communication interface, a display unit, and an input device. The processor, memory, and input / output interface are connected via a system bus, and the communication interface, display unit, and input device are connected to the system bus via the input / output interface. The processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and internal memory. The non-volatile storage medium stores an operating system and computer programs. The internal memory provides an environment for the operation of the operating system and computer programs in the non-volatile storage medium. The input / output interface of the computer device is used to exchange information between the processor and external devices. The communication interface of the computer device is used to communicate with external terminals via wired or wireless means, and the wireless means can be achieved via Wi-Fi, mobile cellular networks, near-field communication (NFC), or other technologies. When executed by the processor, the computer program implements a method for risk prevention and control of point-based operation activities. The display unit of the computer device is used to produce visual images and can be a display screen, a projection device, or a virtual reality imaging device. The display screen can be a liquid crystal display screen or an electronic ink display screen, and the input device of the computer device can be a touch layer covering the display screen, or a button, trackball or touchpad set on the computer device casing, or an external keyboard, touchpad or mouse.

[0140] Those skilled in the art will understand that Figure 4 The structure shown in the figure is only a block diagram of a part of the structure related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied. The specific computer device may include more or fewer components than shown in the figure, or combine certain components, or have a different component arrangement.

[0141] In an exemplary embodiment, a computer device is provided, including a memory and a processor, wherein a computer program is stored in the memory, and the processor executes the steps of any of the above-mentioned methods for risk prevention and control of point operation activities.

[0142] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the steps of any method of the above-mentioned point operation activity risk prevention and control method are implemented.

[0143] In one embodiment, a computer program product is provided, comprising a computer program, which, when executed by a processor, implements the steps of any of the above-mentioned methods for risk prevention and control of point-based operating activities.

[0144] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of relevant data must comply with relevant regulations.

[0145] Those skilled in the art will understand that all or part of the processes in the above-mentioned embodiments can be implemented by instructing the relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above-mentioned methods. In particular, any reference to memory, database, or other media used in the embodiments provided in this application can include at least one of non-volatile memory and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can take various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM). The databases involved in the various embodiments provided herein may include at least one of a relational database and a non-relational database. Non-relational databases may include, but are not limited to, blockchain-based distributed databases. The processors involved in the various embodiments provided herein may be, but are not limited to, general-purpose processors, central processing units (CPUs), graphics processing units (GPUs), digital signal processors (DSPs), programmable logic devices (PLDs), quantum computing-based data processing logic devices, artificial intelligence (AI) processors, and the like.

[0146] The technical features of the above embodiments can be combined arbitrarily. In order to make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this application.

[0147] The above-described embodiments merely represent several implementation methods of the present application. While the descriptions are relatively specific and detailed, they should not be construed as limiting the scope of the present application. It should be noted that a person of ordinary skill in the art may make various modifications and improvements without departing from the spirit of the present application, and these modifications and improvements fall within the scope of protection of the present application. Therefore, the scope of protection of the present application shall be determined by the appended claims.

Claims

1. A method for risk prevention and control of point operation activities, characterized in that: The method comprises: Collecting multi-source heterogeneous data; the multi-source heterogeneous data includes user behavior data, user transaction data and risk database; Determining an overall risk score for the user account based on each feature data in the multi-source heterogeneous data and the corresponding feature weights; If the total risk score is less than or equal to a first score threshold, releasing the user account; If the total risk score is greater than the first scoring threshold and the total risk score is less than or equal to the second scoring threshold, marking the user account as an account requiring manual review; If the total risk score is greater than the second score threshold, blocking the user account; The first scoring threshold is smaller than the second scoring threshold.

2. The method according to claim 1, characterized in that After the step of collecting multi-source heterogeneous data, the method further includes: Perform data cleaning on the multi-source heterogeneous data.

3. The method according to claim 2, characterized in that The data cleaning process for the multi-source heterogeneous data includes: Verifying each of the characteristic data; If the characteristic data does not satisfy the corresponding verification logic, blocking the storage of the user account; If the characteristic data satisfies the corresponding verification logic and the characteristic data does not meet the field requirement, the characteristic data is corrected.

4. The method according to claim 2, characterized in that The data cleaning process for the multi-source heterogeneous data further includes: Extracting features from each feature data in the multi-source heterogeneous data; the features include time series features, correlation features, and composite features; If each of the features does not meet the corresponding feature requirements, the user account is blocked from entering the database.

5. The method according to claim 1, wherein The method further comprises: Obtaining a handling result corresponding to the total risk score; the handling result includes releasing the user account, marking the user account, and blocking the user account; Adjusting prevention and control parameters; the prevention and control parameters include at least one of the first scoring threshold, the second scoring threshold, and the feature weight; Based on the multi-source heterogeneous data and the adjusted prevention and control parameters, executing the steps between "determining the user's total risk score" and "blocking the user account if the total risk score is greater than the second score threshold" to obtain a disposal result corresponding to the adjusted prevention and control parameters; According to the difference between the treatment result corresponding to the total risk score and the treatment result corresponding to the adjusted prevention and control parameters, the prevention and control parameters before adjustment are corrected, and the degree of correction is positively correlated with the degree of the difference.

6. The method according to claim 1, characterized in that The method further comprises: Introducing adversarial samples; the adversarial samples include sample behavior data and sample transaction data; Based on the feature data and corresponding feature weights in the adversarial sample, perform the steps between "determining the user's total risk score" and "blocking the user account if the total risk score is greater than the second score threshold" to obtain a handling result corresponding to the adversarial sample; According to the difference between the treatment result corresponding to the total risk score and the treatment result corresponding to the adversarial sample, the prevention and control parameters corresponding to the total risk score are corrected, and the degree of correction is positively correlated with the degree of the difference.

7. A risk prevention and control device for point operation activities, characterized in that: The device comprises: A data collection module is used to collect multi-source heterogeneous data; the multi-source heterogeneous data includes user behavior data, user transaction data and risk database; A total risk score determination module, configured to determine a user's total risk score based on each feature data and corresponding feature weights in the multi-source heterogeneous data; a first handling module, configured to release the user account if the total risk score is less than or equal to a first score threshold; a second handling module, configured to mark the user account as requiring manual review if the total risk score is greater than the first scoring threshold and the total risk score is less than or equal to a second scoring threshold; a third handling module, configured to block the user account if the total risk score is greater than the second score threshold; The first scoring threshold is smaller than the second scoring threshold.

8. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 6 are implemented.

9. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 6 are implemented.

10. A computer program product comprising a computer program, characterized in that When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 6 are implemented.

Citation Information

Cited By

  • Operation background management method and management system

    CN121580163A