Fraud risk assessment method, equipment, medium, program product and system

Through collaboration between edge servers in the wireless communication network, the local terminal feature data set is used to update the fraud risk assessment model, which solves the data security risks and complex time-consuming problems caused by cloud dependence, and achieves a more efficient and accurate fraud risk assessment.

CN120499672APending Publication Date: 2025-08-15INNER MONGOLIA MOBILE +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510611772.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-13
Publication Date
2025-08-15

AI Technical Summary

Technical Problem

In the prior art, the training and update of the telephone fraud identification model need to rely on the cloud, resulting in data security risks and complex and time-consuming problems.

Method used

In the wireless communication network, edge servers are updated locally in fraud risk assessment models, and through collaboration between edge servers, they use local terminal feature data sets to update models to reduce dependence on the cloud.

Benefits of technology

It improves the accuracy and data security of fraud risk assessment, and reduces the cost and complexity of model updates.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120499672A_ABST
    Figure CN120499672A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of communication, and particularly provides a fraud risk assessment method, device, medium, program product and system, and the method comprises the steps: carrying out the fraud risk assessment of a plurality of first user terminals based on a fraud risk assessment model, and obtaining a fraud risk assessment value of each first user terminal; constructing first communication feature data of a plurality of first user terminals under the condition of determining a triggering model updating process according to the plurality of fraud risk assessment values, and sending the first communication feature data to each second edge server; if a terminal feature data set sent by at least one candidate second edge server is received, updating the fraud risk assessment model based on the terminal feature data sets of the first edge server and the at least one candidate second edge server to obtain an updated fraud risk assessment model, fraud risk assessment is carried out based on the updated fraud risk assessment model; the fraud risk assessment accuracy can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the field of communication technology, and in particular to a fraud risk assessment method, device, medium, program product, and system. Background Art

[0002] Telecom fraud is an illegal criminal activity carried out with the help of today's advanced communication technologies and network platforms. Criminals usually use social platforms, instant messaging software, and Internet calls to disguise their identities, pretending to be staff members of official agencies or well-known companies to carry out fraudulent activities. In this serious situation, using technical means to predict telecom fraud has become an important measure to resist telecom fraud.

[0003] In related technologies, fraudulent behavior identification can be performed based on edge-cloud collaboration, where the edge nodes in the wireless communication network can send the communication behavior information of the user terminal to the cloud for the cloud to train and update the telephone fraud identification model, and perform fraudulent behavior identification based on the telephone fraud identification model sent from the cloud.

[0004] However, the fraud behavior identification method provided in the relevant technology and the training and updating of the telephone fraud identification model all need to be implemented based on the cloud, which is a highly centralized fraud behavior identification technology. Not only does it have data security risks, but the updating process of the telephone fraud identification model is also complicated and time-consuming. Summary of the Invention

[0005] In view of the above problems, the present disclosure provides a fraud risk assessment method, device, medium, program product and system, which can improve the accuracy of fraud risk assessment.

[0006] According to a first aspect of the present disclosure, a fraud risk assessment method is provided. The method is applied to a first edge server in a wireless communication network, comprising:

[0007] Based on a pre-trained fraud risk assessment model, performing fraud risk assessments on multiple first user terminals to obtain a fraud risk assessment value for each of the first user terminals;

[0008] In a case where a trigger model update process is determined based on the multiple fraud risk assessment values, first communication feature data of the multiple first user terminals is constructed, and the first communication feature data is sent to each second edge server in the wireless communication network, wherein the second edge server is configured to send terminal feature data sets of the multiple second user terminals to the first edge server when it is determined that the first communication feature data and the second communication feature data of the multiple second user terminals served by the second edge server meet feature-related conditions, wherein the communication feature data includes communication behavior feature data and / or communication spatiotemporal feature data related to the fraud event;

[0009] If a terminal feature data set is received from at least one candidate second edge server, the fraud risk assessment model is updated based on the terminal feature data set of the at least one candidate second edge server and the terminal feature data set of the first edge server to obtain an updated fraud risk assessment model, and a fraud risk assessment is performed on the first user terminal based on the updated fraud risk assessment model.

[0010] According to a second aspect of the present disclosure, a fraud risk assessment method is provided. The method is applied to a second edge server in a wireless communication network, comprising:

[0011] In response to receiving first communication feature data sent by a first edge server in the wireless communication network, determining a communication feature data correlation determination result based on the first communication feature data and second communication feature data of multiple second user terminals served by the second edge server, wherein the first communication feature data is generated by the first edge server when a model update process is determined to be triggered during a fraud risk assessment performed on the multiple first user terminals served by the first edge server based on a pre-trained fraud risk assessment model;

[0012] When the communication feature data correlation judgment result indicates that the first communication feature data and the second communication feature data meet the feature correlation conditions, the terminal feature data sets of the multiple second user terminals are sent to the first edge server, wherein the first edge server is used to update the fraud risk assessment model based on the terminal feature data set sent by the second edge server and the terminal feature data set of the first edge server to obtain an updated fraud risk assessment model, and perform fraud risk assessment on the first user terminal based on the updated fraud risk assessment model.

[0013] According to a third aspect of the present disclosure, an electronic device is provided, comprising a memory, a processor, and a computer program stored in the memory, wherein the processor executes the computer program to implement the above-mentioned fraud risk assessment method.

[0014] According to a fourth aspect of the present disclosure, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the above-mentioned fraud risk assessment method is implemented.

[0015] According to a fifth aspect of the present disclosure, a computer program product is provided, comprising a computer program, which implements the above-mentioned fraud risk assessment method when executed by a processor.

[0016] According to a sixth aspect of the present disclosure, a fraud risk assessment system is provided. The system is a wireless communication network system. The fraud risk assessment system includes multiple edge servers, wherein:

[0017] The first edge server performs fraud risk assessment on each of the plurality of first user terminals based on a pre-trained fraud risk assessment model to obtain a fraud risk assessment value for each of the first user terminals;

[0018] The first edge server constructs first communication feature data of the plurality of first user terminals and sends the first communication feature data to each second edge server in the wireless communication network when determining to trigger a model update process based on the plurality of fraud risk assessment values.

[0019] Each second edge server, upon determining that the first communication feature data and the second communication feature data of multiple second user terminals served by the second edge server meet feature-related conditions, sends terminal feature data sets of the multiple second user terminals to the first edge server, where the communication feature data includes communication behavior feature data and / or communication spatiotemporal feature data related to the fraud incident;

[0020] If the first edge server receives a terminal feature data set sent by at least one second edge server, the fraud risk assessment model is updated based on the terminal feature data set of the at least one second edge server and the terminal feature data set of the first edge server to obtain an updated fraud risk assessment model, and a fraud risk assessment is performed on the first user terminal based on the updated fraud risk assessment model.

[0021] The present disclosure provides a fraud risk assessment method, device, medium, program product and system. On the one hand, it provides a decentralized fraud risk assessment model update solution in the edge-cloud collaborative fraud risk assessment scenario, which delegates the update process of the fraud risk assessment model to each edge server. The edge server does not need to report data to the cloud device for the cloud device to update the model, ensuring data security and reducing the model update cost. The edge server can obtain an updated fraud risk assessment model for the edge server based on the terminal feature data set in the edge server, thereby improving the fraud risk assessment accuracy of the updated fraud risk assessment model in the edge server. On the other hand, after the edge server triggers the fraud risk assessment model update process, it can also obtain the terminal feature data set of the second edge server whose communication feature data related to the fraud event meets the feature-related conditions to update the fraud risk assessment model. Since the communication feature data of other edge servers that meet the feature-related conditions between the communication feature data related to the fraud event are basically the same as the communication data features of the defrauded users of the edge server, the recognition accuracy of the updated fraud risk assessment model can be further improved on the basis of ensuring the matching degree between the updated fraud risk assessment model and the edge server.

[0022] It is to be understood that both the foregoing general description and the following detailed description are exemplary, and are intended to provide further explanation of the technology as claimed. BRIEF DESCRIPTION OF THE DRAWINGS

[0023] The above and other purposes, features, and advantages of the present disclosure will become more apparent through a more detailed description of the embodiments of the present disclosure in conjunction with the accompanying drawings. The accompanying drawings are intended to provide a further understanding of the embodiments of the present disclosure and constitute a part of the specification. Together with the embodiments of the present disclosure, they are used to explain the present disclosure and are not intended to limit the present disclosure. In the drawings, the same reference numerals generally represent the same components or steps.

[0024] Figure 1 2 is a schematic diagram illustrating an application scenario of the fraud risk assessment method according to an embodiment of the present disclosure.

[0025] Figure 2 is a flowchart illustrating a fraud risk assessment method according to an embodiment of the present disclosure.

[0026] Figure 3 is a flowchart illustrating another fraud risk assessment method according to an embodiment of the present disclosure.

[0027] Figure 4 It is an interactive flow chart illustrating a fraud risk assessment method according to an embodiment of the present disclosure.

[0028] Figure 51 is a schematic block diagram illustrating a fraud risk assessment device according to an embodiment of the present disclosure.

[0029] Figure 6 2 is a schematic block diagram illustrating another fraud risk assessment device according to an embodiment of the present disclosure.

[0030] Figure 7 is a schematic diagram illustrating a computer program product according to an embodiment of the present disclosure.

[0031] Figure 8 is a hardware block diagram illustrating an electronic device according to an embodiment of the present disclosure. DETAILED DESCRIPTION

[0032] In order to make the purpose, technical solutions and advantages of the present disclosure more apparent, the following will describe in detail exemplary embodiments of the present disclosure with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of the present disclosure, rather than all the embodiments of the present disclosure, and it should be understood that the present disclosure is not limited to the exemplary embodiments described herein.

[0033] In the related technology, in the process of identifying fraudulent behavior, the cloud can pre-train a telephone fraud identification model and send the telephone fraud identification model to each edge node so that the edge node can identify fraudulent behavior based on the telephone fraud identification model, and upload the user's call feature information and identification results to the cloud so that the cloud can update the telephone fraud identification model for optimization.

[0034] Among them, since the training and updating processes of the fraud identification model need to be executed by the cloud, especially during the updating process of the fraud identification model, the edge node is required to upload the user's call feature data and identification results to the cloud, which is not only complicated and time-consuming, but also prone to information leakage and data security risks; at the same time, the fraud identification model based on centralized cloud training is usually unable to effectively consider the call characteristics of the users served by each edge node itself, resulting in poor accuracy of the identification results in each edge node after the fraud identification model is sent to each edge node.

[0035] In order to solve the above problems, the present disclosure provides a fraud risk assessment method. Figure 1 A schematic diagram of an application scenario of the fraud risk assessment method provided by an embodiment of the present disclosure is shown. Figure 1As shown, the implementation scenario 100 includes multiple edge servers 101, cloud devices 102, and multiple user terminals 103 served by each edge server 101, wherein the edge server 101 can be a server of an edge node in a wireless communication network, the cloud device 102 is a cloud server in the wireless communication network, and the user terminal 103 can be a terminal device used by a user accessing the edge server, and the terminal device can be a computer, a notebook, a mobile phone, a tablet computer, a wearable device, etc.;

[0036] A communication link is established between the cloud device 102 and each edge server 101, and between the edge server 101 and the user terminal 103, so that the cloud device 102 pushes the trained initial fraud risk assessment model to each edge server 101 to perform fraud risk assessment on the user terminal 103. At the same time, a communication link is established between each two edge servers so that each edge server performs fraud risk assessment based on the fraud risk assessment method provided in the embodiment of the present disclosure. The method for each edge server to perform fraud risk assessment based on the fraud risk assessment method provided in the embodiment of the present disclosure may include:

[0037] The first edge server performs fraud risk assessment on each of the plurality of first user terminals based on a pre-trained fraud risk assessment model to obtain a fraud risk assessment value for each of the first user terminals;

[0038] The first edge server constructs first communication feature data of the plurality of first user terminals and sends the first communication feature data to each second edge server in the wireless communication network when determining to trigger a model update process based on the plurality of fraud risk assessment values.

[0039] Each second edge server, upon determining that the first communication feature data and the second communication feature data of multiple second user terminals served by the second edge server meet feature-related conditions, sends terminal feature data sets of the multiple second user terminals to the first edge server, where the communication feature data includes communication behavior feature data and / or communication spatiotemporal feature data related to the fraud incident;

[0040] If the first edge server receives a terminal feature data set sent by at least one second edge server, the fraud risk assessment model is updated based on the terminal feature data set of the at least one second edge server and the terminal feature data set of the first edge server to obtain an updated fraud risk assessment model, and a fraud risk assessment is performed on the first user terminal based on the updated fraud risk assessment model.

[0041] The present disclosure provides a fraud risk assessment method, which can be applied to a first edge server in a wireless communication network, such as Figure 2 As shown, Figure 2 A flowchart of a fraud risk assessment method provided by an embodiment of the present disclosure is shown, including:

[0042] Step S201: Based on a pre-trained fraud risk assessment model, fraud risk assessment is performed on a plurality of first user terminals to obtain a fraud risk assessment value for each first user terminal;

[0043] Step S202: When a model update process is determined to be triggered based on multiple fraud risk assessment values, construct first communication feature data of multiple first user terminals and send the first communication feature data to each second edge server in the wireless communication network;

[0044] The second edge server is configured to send terminal feature data sets of the plurality of second user terminals to the first edge server upon determining that the first communication feature data and the second communication feature data of the plurality of second user terminals served by the second edge server meet feature-related conditions, wherein the communication feature data includes communication behavior feature data and / or communication spatiotemporal feature data related to the fraud incident;

[0045] In step S203, if a terminal feature data set is received from at least one candidate second edge server, the fraud risk assessment model is updated based on the terminal feature data set of the at least one candidate second edge server and the terminal feature data set of the first edge server to obtain an updated fraud risk assessment model, and a fraud risk assessment is performed on the first user terminal based on the updated fraud risk assessment model.

[0046] In summary, the fraud risk assessment method provided by the embodiment of the present disclosure, on the one hand, provides a decentralized fraud risk assessment model update solution in the edge-cloud collaborative fraud risk assessment scenario, and delegates the update process of the fraud risk assessment model to each edge server. The edge server does not need to report data to the cloud device for the cloud device to update the model, which ensures data security and reduces the model update cost. The edge server can obtain an updated fraud risk assessment model for the edge server based on the terminal feature data set in the edge server, thereby improving the fraud risk assessment accuracy of the updated fraud risk assessment model in the edge server. On the other hand, after the edge server triggers the fraud risk assessment model update process, it can also obtain the terminal feature data set of the second edge server whose communication feature data related to the fraud event meets the feature-related conditions to update the fraud risk assessment model. Since the communication feature data of other edge servers that meet the feature-related conditions between the communication feature data related to the fraud event are basically the same as the communication data features of the defrauded users of the edge server, the recognition accuracy of the updated fraud risk assessment model can be further improved on the basis of ensuring the matching degree between the updated fraud risk assessment model and the edge server.

[0047] The following Figure 2 The specific implementation of each step in the embodiment shown is described in detail:

[0048] In step S201, the first edge server performs fraud risk assessment on multiple first user terminals based on a pre-trained fraud risk assessment model to obtain a fraud risk assessment value for each of the first user terminals.

[0049] In an embodiment of the present disclosure, the first edge server may be any edge server under a wireless communication network, wherein the fraud risk assessment model may be an initial fraud risk assessment model sent by a cloud device, or the fraud risk assessment model may be a model obtained after the first edge server last updated the fraud risk assessment model, wherein the first user terminal is a service object of the first edge server; the fraud risk assessment value is used to characterize the probability of a user being defrauded, wherein the higher the fraud risk assessment value, the more likely the user is to be defrauded.

[0050] It is understandable that after the edge server cluster in the wireless communication network is put into use for the first time, the cloud device can send an initial fraud risk assessment model to each edge server so that each edge server can perform a fraud risk assessment on the user terminals it serves, and when it is determined that the fraud risk assessment model needs to be updated, each edge server can trigger the update of the fraud risk assessment model.

[0051] In an optional embodiment, the first edge server performs fraud risk assessment on multiple first user terminals based on a pre-trained fraud risk assessment model. The process of obtaining the fraud risk assessment value of each first user terminal may include: for each first user terminal connected to the first edge server, inputting the terminal feature data set of the first user terminal into the fraud risk assessment model to obtain the fraud risk assessment value of the first user terminal; wherein the terminal feature data set includes at least one of call behavior data, SMS behavior data, Internet behavior data and user basic attribute data; specifically, it can be determined based on actual needs, and the embodiment of the present disclosure is not limited to this.

[0052] Among them, call behavior data may include the number of calls, the number of calls, call duration, call frequency, roaming call status, the number of callers and / or access base station information, etc.; SMS behavior data may include the number of SMS sent, the number of SMS received, and whether the SMS contains suspicious links or keywords, etc.; Internet behavior data includes: data traffic usage, Internet usage time and / or application (APP) usage data, etc.; user basic attribute data may include user information: such as age, gender and / or network access time, etc.; tariff information: such as package type, average monthly call charges and / or arrears information, etc.; terminal device information: such as device type, device usage and device configuration information, etc.

[0053] Optionally, the data in the terminal feature data set obtained by the first edge server may be terminal feature data obtained within a preset historical period when determining to perform a fraud risk assessment on the first user terminal. The length of the preset historical period may be determined based on actual needs and is not limited in this embodiment of the present disclosure. For example, the preset historical period may be 5 days or 15 days before the time when the fraud risk assessment on the first user terminal is determined.

[0054] In step S202, when the first edge server determines to trigger the model update process based on the multiple fraud risk assessment values, it constructs the first communication feature data of the multiple first user terminals and sends the first communication feature data to each second edge server in the wireless communication network.

[0055] In an embodiment of the present disclosure, the second edge server is all edge servers in the wireless communication network except the first edge server. The second edge server is used to send the terminal feature data sets of the multiple second user terminals to the first edge server when determining that the first communication feature data and the second communication feature data of the multiple second user terminals served by the second edge server meet the feature-related conditions. The communication feature data includes communication behavior feature data and / or communication spatiotemporal feature data related to the fraud incident.

[0056] It should be noted that in the embodiment of the present disclosure, the first edge server can periodically evaluate whether it is necessary to trigger the update of the fraud risk assessment model according to the preset model update evaluation cycle, wherein the model update evaluation cycle can be determined based on actual needs, and the embodiment of the present disclosure does not limit this. For example, the model update evaluation cycle can be evaluated once a week, or once every half a month.

[0057] In an optional embodiment, the process of the first edge server determining whether to trigger the model update process based on multiple fraud risk assessment values may include: obtaining the fraud risk assessment value of each first user terminal determined within the current assessment period, and then, for each first user terminal, determining the fraud risk assessment value change index value based on the fraud risk assessment value of the first user terminal and the baseline fraud risk value; further, if the average of the fraud risk assessment value change indexes of multiple first user terminals is within the risk indicator threshold range, then determining to trigger the model update process; it should be noted that the risk indicator threshold range and the baseline fraud risk value can be determined based on actual needs, and the embodiments of the present disclosure do not limit this.

[0058] The first edge server may determine a fraud risk assessment value change index value based on the fraud risk assessment value of the first user terminal, the baseline fraud risk value, and a first formula, where the first formula is:

[0059]

[0060] In Formula 1, ΔR k is the fraud risk assessment value change index value of the kth first user terminal, I k is the fraud risk assessment value of the kth first user terminal, and I0 is the baseline fraud risk value.

[0061] It can be understood that if the first edge server determines that the average of the fraud risk assessment value change indicators of multiple first user terminals is not within the risk indicator threshold range, it is determined that the model update process will not be triggered, and in the next evaluation cycle, it will continue to determine whether to trigger the model update process.

[0062] In an optional embodiment, the process of the first edge server constructing the first communication characteristic data of the multiple first user terminals may include: determining the terminal traffic characteristic data based on the traffic time series of the multiple first user terminals; then, determining the terminal connection behavior characteristic data based on the connection behavior data of each of the first user terminals and the base station; further, combining the terminal traffic characteristic data and the terminal connection behavior characteristic data to obtain the communication behavior characteristic data of the multiple first user terminals, and determining the first communication characteristic data of the multiple first user terminals based on the communication behavior characteristic data of the multiple first user terminals. The user communication characteristics related to the fraud event can be characterized from two dimensions: the traffic characteristics of the user terminal and the connection behavior characteristics of the terminal and the base station, so as to consider the terminal traffic under the fraud event and the abnormality of the interaction between the terminal and the base station, conduct fraud risk assessment, and improve the accuracy of the determined fraud risk assessment results.

[0063] The process of determining terminal traffic feature data by the first edge server based on the traffic time series of the plurality of first user terminals can be implemented based on different time series feature extraction algorithms. Specifically, the algorithm can be determined based on actual needs, and the present disclosure does not limit this. For example, the time series feature extraction algorithm can be a statistical feature extraction algorithm (such as mean, variance, skewness, and / or kurtosis) or a frequency domain feature extraction algorithm (such as fast Fourier transform or wavelet transform).

[0064] Optionally, the process of the first edge server determining the terminal traffic characteristic data based on the traffic time series of multiple first user terminals may include: integrating the traffic time series for each first user terminal to obtain the integral coverage area of the traffic time series, then dividing the integral coverage area of the traffic time series into multiple integral blocks of the same duration, and determining the minimum number of integral blocks corresponding to the preset time length, and determining the integral block duration and the minimum number of integral blocks as a group of data to be processed, repeating the above process until the minimum number of integral blocks corresponding to the preset time length is obtained when the duration approaches zero, and then processing each group of data to be processed using a preset feature processing formula to obtain terminal traffic characteristic data, wherein the feature processing formula is:

[0065]

[0066] In formula 2, D i is the terminal traffic characteristic data determined when the integration block length is the i-th time length, τ is the size of the integration block, N(τ) is the minimum number of integration blocks corresponding to the preset time length, wherein the preset time length can be determined based on actual needs, and the embodiment of the present disclosure does not limit this.

[0067] In an optional embodiment, the process of the first edge server determining the terminal connection behavior characteristic data based on the connection behavior data of each of the first user terminals and the base station may include: constructing a bipartite graph of the association relationship between the first user terminal and the base station, and determining the ratio of the clustering coefficient of each node in the bipartite graph to the characteristic path length to obtain the terminal connection behavior characteristic data; wherein, the bipartite graph of the association relationship between the first user terminal and the base station includes a first node set, a second node set, and an edge set, the first node set is a set of first user terminals, the second node set is a set of base stations, and the edge set is a set of connection relationships between the first user terminal and the base station, and the connection relationship may include the time when the first user terminal is connected to the base station, the duration of the first user terminal's connection to the base station and / or the signal strength, etc.

[0068] For example, assume that the bipartite graph of the association relationship between the first user terminal and the base station is G = (U, B, E); wherein the first node set U = (u1, u2, ..., u n ), represents a set of n first user terminals, and the second node set B=(b1, b2,…, b m ), represents the set of m base stations; the edge set E={(u i ,b j )}, indicating the connection relationship between the first user terminal and the base station.

[0069] The clustering coefficient of each node is Among them, E i is the number of edges of nodes adjacent to the i-th node, k i is the node degree; L i is the characteristic path length between any two nodes, then the ratio of the clustering coefficient to the characteristic path length is

[0070] In an optional embodiment, the process of constructing the first communication feature data of the multiple first user terminals by the first edge server may include: determining terminal fraud probability feature data based on the number of times each first user terminal has been defrauded in each unit time period and the total number of times the multiple first user terminals have been defrauded in multiple unit time periods; then, determining terminal mobility feature data based on distance change data between each first user terminal and a base station at different times; further, combining the terminal fraud probability feature data and the terminal mobility feature data to obtain communication spatiotemporal feature data of the multiple first user terminals, and determining the first communication feature data of the multiple first user terminals based on the communication spatiotemporal feature data of the multiple first user terminals. User communication features related to fraud events can be characterized from two dimensions: the probability of a user being defrauded at different times and the terminal's location change characteristics, so as to facilitate fraud risk assessment by considering the terminal's fraudulent event and abnormal location changes during the fraud event, thereby improving the accuracy of the determined fraud risk assessment results.

[0071] Among them, the unit duration can be the unit duration in the preset communication duration, the preset communication duration can be the duration of the current evaluation cycle, and the unit duration is less than the duration of the current evaluation cycle. Specifically, the length of the unit duration can be determined based on actual needs. The embodiment of the present disclosure does not limit this. For example, if the duration of the current evaluation cycle is 1 day, the unit duration can be every hour or every half hour, or, if the duration of the current evaluation cycle is 7 days, the unit duration can be 1 day.

[0072] Among them, the first edge server determines the terminal fraud probability characteristic data based on the number of times each first user terminal is defrauded in each unit time length and the total number of times multiple first user terminals are defrauded in multiple unit time lengths: for each first user terminal, the ratio of the number of times the first user terminal is defrauded in each unit time length and the total number of times multiple first user terminals are defrauded in multiple unit time lengths is determined as the first user terminal's fraud probability value in each unit time length; then, the fraud probability values of each first user terminal in each unit time length are combined to obtain the terminal fraud probability characteristic data.

[0073] The probability of being defrauded can be determined by the second formula, which is:

[0074]

[0075] In formula 3, P norm (h) is the probability of being defrauded in the h-th unit time, P(h) is the number of times the first user terminal is defrauded in the h-th unit time, is the total number of times that multiple first user terminals are defrauded within multiple unit time periods, where the number of the multiple unit time periods is H+1.

[0076] Among them, the process of the first edge server determining the terminal movement feature data based on the distance change data between each of the first user terminals and the base station at different times may include: determining the distance matrix between the first user terminal and the base station at each historical moment based on the connection information between the terminal and the base station at multiple historical moments in the current evaluation period; then, determining multiple transition entropies of the first user terminal based on the distance matrices of two adjacent historical moments, and determining the multiple transition entropies of the first user terminal as terminal displacement feature data, wherein the transition entropy is used to characterize the possibility of position movement of the first user terminal, and the multiple historical moments are any moments in the current evaluation period.

[0077] Among them, at any historical moment T, the distance matrix B between the first user terminal and the base station is T for:

[0078]

[0079] In formula 4, the element Indicates the distance from the first user terminal 1 to the base station 1 at the historical time T, and the distance matrix B T The meaning of other elements in the The meaning of is similar, and this embodiment of the present disclosure will not be elaborated on, wherein, It represents the distance from the first user terminal k to the base station i at the historical time T.

[0080] The transition entropy D is:

[0081]

[0082] In formula 5, P is the distance matrix of the earlier historical moment between two adjacent historical moments. Each element in is transferred to the distance matrix at a later historical moment The probability of P 1 is the true probability, P 2 is an approximate probability, wherein the true probability is determined by the first edge server according to the statistical result of the location change of the first user terminal, and the approximate probability is estimated by the first edge server according to the location change of the first user terminal.

[0083] It should be noted that, in the embodiment of the present disclosure, the process of the first edge server combining the terminal traffic feature data and the terminal connection behavior feature data to obtain the communication behavior feature data of the multiple first user terminals, and / or the process of combining the terminal fraud probability feature data and the terminal mobility feature data to obtain the communication spatiotemporal feature data of the multiple first user terminals, can be implemented based on the torch.cat function.

[0084] Optionally, when the first edge server obtains communication behavior characteristic data of multiple first user terminals, the first edge server determines the communication behavior characteristic data of the multiple first user terminals as the first communication characteristic data, or, when the first edge server obtains communication spatiotemporal characteristic data of multiple first user terminals, the first edge server determines the communication spatiotemporal characteristic data of the multiple first user terminals as the first communication characteristic data of the multiple first user terminals.

[0085] Alternatively, when the first edge server obtains the communication behavior feature data and the communication spatiotemporal feature data of multiple first user terminals, the first edge server determines the communication behavior feature data and the communication spatiotemporal feature data of the multiple first user terminals as the first communication feature data of the multiple first user terminals. The user communication features related to the fraud event can be characterized from four dimensions: the traffic features of the user terminal, the connection behavior features of the terminal and the base station, the probability of the user being defrauded at different times, and the location change features of the terminal, so as to construct the feature richness of the communication feature data related to fraud, so as to facilitate the second edge server to more accurately determine the correlation between the communication feature data related to fraud in the second edge server and the first edge server.

[0086] Among them, after the first edge server determines the communication behavior feature data and communication spatiotemporal feature data of the multiple first user terminals as the first communication feature data of the multiple first user terminals, the first communication feature data TE g for:

[0087]

[0088] In formula 6, TE1 is the communication behavior feature data, and TE2 is the communication spatiotemporal feature data, wherein the communication behavior feature data and the communication spatiotemporal feature data are respectively present in the form of vectors, te nm is the element in the nth row and mth column of the communication behavior feature data.

[0089] Optionally, after the first edge server determines the first communication feature data of multiple first user terminals, the first communication feature data can be dimensionally compressed and the compressed first communication feature data can be sent to each second edge server, wherein the dimension of the compressed first communication feature data can be determined based on actual needs, and the embodiment of the present disclosure is not limited to this. For example, the compressed first communication feature data can be three-dimensional data, so as to reduce the amount of data sent to the second edge server and improve interaction efficiency.

[0090] In an optional embodiment, the process of the second edge server determining whether the first communication feature data and the second communication feature data of multiple second user terminals served by the second edge server meet the feature correlation condition may include: processing the first communication feature data based on a feature coefficient determination model to obtain a first feature coefficient of the first communication feature data, and processing the second communication feature data based on the feature coefficient determination model to obtain a second feature coefficient of the second communication feature data, and further processing the first feature coefficient and the second feature coefficient based on a feature correlation model to obtain a feature correlation value; wherein, if the feature correlation value is less than a feature correlation threshold, it is determined that the first communication feature data and the second communication feature data meet the feature correlation condition; or, if the feature correlation value is greater than or equal to the feature correlation threshold, it is determined that the first communication feature data and the second communication feature data do not meet the feature correlation condition, and the first communication feature data is filtered. The feature correlation threshold can be determined based on actual needs, and the embodiments of the present disclosure are not limited to this.

[0091] It should be noted that, in the embodiment of the present disclosure, the second communication feature data of the second user terminal may be the communication feature data determined by the second edge server during the last update of the fraud risk assessment model; it can be understood that the process of the second edge server determining the second communication feature data is similar to the process of the first edge server determining the first communication feature data, and the embodiment of the present disclosure will not elaborate on this.

[0092] In the case where the communication feature data is compressed into three-dimensional feature data, the feature coefficient determination model is:

[0093]

[0094] In Formula 7, w is the characteristic coefficient, ε is the high-frequency attenuation factor, which can be used to suppress high-dimensional noise and can be determined based on actual needs; x, y, and z are dimensional indices of the three dimensions, respectively, which can be determined based on a dimensionality compression algorithm.

[0095] When the communication feature data is compressed into three-dimensional feature data, the feature correlation model is:

[0096]

[0097] In formula 8, C is the feature correlation value, is the correlation constant, which can be determined based on actual needs, w1 is the first characteristic coefficient, and w2 is the second characteristic coefficient.

[0098] In step S203, if the first edge server receives a terminal feature data set sent by at least one second edge server, the fraud risk assessment model is updated based on the terminal feature data set of the at least one second edge server and the terminal feature data set of the first edge server to obtain an updated fraud risk assessment model, and a fraud risk assessment is performed on the first user terminal based on the updated fraud risk assessment model.

[0099] In an embodiment of the present disclosure, the terminal feature data set sent by the second edge server is a terminal feature data set of each second user terminal served by the second edge server within the first target historical duration, wherein the first target historical duration is the first historical duration before the target moment, wherein the target moment is the moment when the second edge server receives the first communication feature data sent by the first edge server. The first historical duration can be determined based on actual needs, and the embodiment of the present disclosure does not limit this. For example, the first historical duration is one week before the target moment, or two weeks before the target moment, etc.

[0100] It should be noted that in the embodiment of the present disclosure, the second edge server, while sending the terminal feature data set of each second user terminal, also sends a label value associated with the terminal feature data set of each second user terminal. The label value is the fraud risk assessment value obtained by the second edge server after processing the terminal feature data set of the second user terminal using the fraud risk assessment model deployed in the second edge server.

[0101] Similarly, the terminal feature data set of the first edge server may include the terminal feature data set of each first user terminal served by the first edge server within the first target historical duration. The first edge server may also determine the fraud risk assessment value determined based on the terminal feature data set of each first user terminal as a label value associated with the terminal feature data set of each first user terminal; wherein the first target historical duration is the second historical duration before the moment of determining the triggering model update process, and the second historical duration may also be determined based on actual needs, which is not limited in this embodiment of the present disclosure.

[0102] In an optional embodiment, the first edge server updates the fraud risk assessment model based on the terminal feature data set of at least one of the second edge servers and the terminal feature data set of the first edge server. The process of obtaining the updated fraud risk assessment model may include: determining the terminal feature data set of each second user terminal and the label value corresponding to the terminal feature data of the second user terminal as a group of samples, and determining the terminal feature data set of each first user terminal and the label value corresponding to the terminal feature data of the first user terminal as a group of samples to obtain a sample data set; then, using the sample data set to iteratively train the fraud risk assessment model until the model convergence condition is met, thereby obtaining the updated fraud risk assessment model.

[0103] Among them, the model convergence condition can be determined based on actual needs, and the embodiments of the present disclosure do not limit this. For example, the model convergence condition can be that the sample fraud risk assessment model of the fraud risk assessment model and the loss function value of the label value are less than or equal to the loss function value threshold, or, the model convergence condition can be that the number of iterations is greater than the iteration number threshold, wherein the loss function, the loss function value threshold, and the iteration number threshold can be determined based on actual needs, and the embodiments of the present disclosure do not limit this.

[0104] In an optional embodiment, the number of the candidate second edge servers includes multiple, and the terminal feature data set of the candidate second edge server is a terminal feature data difference set of each second user terminal served by the candidate second edge server in at least two historical time periods. The first edge server updates the fraud risk assessment model based on the terminal feature data set of at least one candidate second edge server and the terminal feature data set of the first edge server. The process of obtaining the updated fraud risk assessment model may include: based on the terminal feature data difference set associated with each candidate second edge server and the terminal feature data set of the first edge server, updating the fraud risk assessment model in multiple candidate second edge servers. at least one target second edge server is determined; then, a target terminal feature data set is requested from each of the target second edge servers, wherein the target terminal feature data set is a terminal feature data set of multiple second user terminals served by the target second edge server; further, based on the at least one target terminal feature data set and the terminal feature data set of the first edge server, the fraud risk assessment model is updated to obtain an updated fraud risk assessment model, wherein the terminal feature data difference set of the target second edge server and the terminal feature data set of the first edge server meet a preset similarity condition, and the preset similarity condition can be determined based on actual needs, which is not limited in the embodiment of the present disclosure. On the one hand, the first edge server continues to screen out a terminal feature data set of the first user terminal served by the first edge server from multiple second edge servers using the terminal feature data. A target second edge server that meets the preset similarity condition can, based on the second edge server screened out based on the communication feature data, further screen out a target second edge server with terminal feature data similar to the terminal feature data of the first user terminal served by the first edge server based on the terminal feature data, and update the fraud risk assessment model based on the terminal feature data sets of the first edge service and the target second edge server, so as to improve the accuracy of the trained updated fraud risk assessment model in understanding the terminal feature data set of the first user terminal served by the first edge server. On the other hand, the second edge server returns the terminal feature data difference set of the second user terminal to the first edge server for the first edge server to determine the similarity of the terminal features between the first edge server and the second edge server. This can prevent the risk of data leakage caused by directly returning the terminal feature data set of the second user terminal served by the second edge server to the first edge server, thereby improving the data security of the update of the fraud risk assessment model based on edge server interaction.

[0105] It should be noted that in the embodiment of the present disclosure, at least two time periods may include at least two historical time periods before the target moment, wherein the length of the historical time period can be determined based on actual needs, and the embodiment of the present disclosure does not limit this. For example, the length of the historical time period can be 24 hours or 12 hours.

[0106] In an optional embodiment, to further enhance data transmission security, the terminal feature data difference set returned by the second edge server to the first edge server may be an encrypted terminal feature data difference set. The process by which the second edge server encrypts the terminal feature data difference set may include: reading a pre-stored target key sequence between the first edge server and the first edge server, then processing the target key sequence into an orthogonal matrix to obtain a target key matrix, and encrypting the terminal feature data difference set using the target key matrix to obtain an encrypted terminal feature data difference set. The target key sequence is a random sequence pre-generated by either the first edge server or the second edge server and synchronized to the other edge server. The data length of the target key sequence may be determined based on actual needs, and this is not limited in the present embodiment.

[0107] Optionally, after the second edge server reads the target key sequence, it can perform binarization on the target key sequence to reduce the complexity and data volume of the target key sequence. For example, when the random sequence length is N bits, the second edge server can perform binarization on the target key sequence K based on a binarization function to obtain a binarized target key sequence K'. The binarized target key sequence K' is:

[0108]

[0109] In Formula 9, x n The character value of the nth bit in the N-bit target key sequence. For example, N can be 256.

[0110] Optionally, when the target key sequence K is not binarized, the target key matrix is:

[0111]

[0112] In formula 10, Orto is an orthogonal matrix identifier.

[0113] Wherein, when the terminal feature data difference set is m, the encrypted terminal feature data difference set is:

[0114] enc(m)=P t m

[0115] In an optional embodiment, the process of determining at least one target second edge server from a plurality of candidate second edge servers by a first edge server based on the terminal feature data difference set associated with each candidate second edge server and the terminal feature data set of the first edge server may include: determining a plurality of terminal feature correlation values based on the terminal feature data difference set associated with each candidate second edge server and the terminal feature data set of the first edge server; and then determining the candidate second edge server associated with the maximum terminal feature correlation value as the target second edge server. The candidate second edge server with the terminal features most similar to those of the first user terminal served by the first edge server may be determined as the target second edge server, so as to facilitate updating the updated fraud risk assessment model based on the terminal feature data set of the target second edge server and the user terminal served by the first edge server, thereby improving the accuracy of the updated fraud risk assessment model in understanding the features of the terminal feature data set of the first user terminal served by the first edge server, thereby improving the accuracy of the determined fraud risk assessment value for the first user terminal.

[0116] It can be understood that the multiple terminal feature-related values include a terminal feature-related value associated with each candidate second edge server.

[0117] Optionally, after the first edge server obtains multiple terminal feature correlation values, it can also: sort the multiple terminal feature correlation values in order from large to small to obtain a terminal feature correlation value sequence, and starting from the largest terminal feature correlation value in the terminal feature correlation value sequence, select a preset number of terminal feature correlation values to obtain a target terminal feature correlation value set, and determine the candidate second edge server associated with each target terminal feature correlation value in the target terminal feature correlation value set as the target second edge server, and determine multiple candidate second edge servers with terminal features similar to the first user terminal served by the first edge server as the target second edge server, so as to facilitate the update of the updated fraud risk assessment model based on the terminal feature data sets of the multiple target second edge servers and the user terminals served by the first edge server, so as to improve the accuracy of the updated fraud risk assessment model in understanding the features of the terminal feature data set of the first user terminal served by the first edge server, and improve the generalization ability of the model.

[0118] It should be noted that the process of the terminal feature correlation value of the first edge server can be implemented based on the inner product or cosine similarity algorithm; the first edge server updates the fraud risk assessment model based on the at least one target terminal feature data set and the terminal feature data set of the first edge server to obtain the updated fraud risk assessment model. The process can refer to the first edge server in the above embodiment based on the terminal feature data set of the at least one second edge server and the terminal feature data set of the first edge server to update the fraud risk assessment model to obtain the updated fraud risk assessment model. The present embodiment does not elaborate on this.

[0119] In an optional embodiment, if the first edge server does not receive at least one terminal feature data set sent by the second edge server, the fraud risk assessment model is updated based on the terminal feature data set of the first edge server to obtain an updated fraud risk assessment model. In the case that there is no second edge server among multiple second edge servers with terminal feature data similar to that of the first user terminal served by the first edge server, the fraud risk assessment model is directly updated based on the terminal feature data set of the first edge server, thereby improving the accuracy of the updated fraud risk assessment model in understanding the features of the terminal feature data set of the first user terminal served by the first edge server.

[0120] In an optional embodiment, the first edge server may further: send the updated fraud risk assessment model to each of the candidate second edge servers, wherein each of the candidate second edge servers is configured to perform fraud risk assessment on multiple second user terminals served by each second edge server based on the updated fraud risk assessment model. The updated fraud risk assessment model may be synchronized to the candidate second edge servers so that the candidate second edge servers can directly perform fraud risk assessment on the second user terminals based on the updated fraud risk assessment model of the first edge server. Since the terminal features of the second user terminals served by the candidate second edge servers are similar to the terminal features of the first user terminals served by the first edge server, and the first edge server utilizes the terminal feature dataset of the candidate second edge server during the process of updating the fraud risk assessment model, the second edge server can use the updated fraud risk assessment model sent by the first edge server to perform fraud risk assessment on the second user terminals with higher feature understanding accuracy of the terminal feature dataset of the second user terminals, thereby improving the accuracy of the fraud risk assessment value of the second user terminal determined by the candidate second edge server.

[0121] The present disclosure provides a fraud risk assessment method, which can be applied to a second edge server in a wireless communication network, such as Figure 3 As shown, Figure 3 A flowchart of a fraud risk assessment method provided by an embodiment of the present disclosure is shown, including:

[0122] Step S301, in response to receiving first communication feature data sent by a first edge server in a wireless communication network, determining a communication feature data correlation determination result based on the first communication feature data and second communication feature data of a plurality of second user terminals served by a second edge server;

[0123] The first communication feature data is generated by the first edge server when a model update process is determined to be triggered during a fraud risk assessment process of a plurality of first user terminals served by the first edge server based on a pre-trained fraud risk assessment model;

[0124] Step S302 : When the communication feature data correlation judgment result indicates that the first communication feature data and the second communication feature data meet the feature correlation condition, the terminal feature data sets of the plurality of second user terminals are sent to the first edge server.

[0125] The first edge server is used to update the fraud risk assessment model based on the terminal feature data set sent by the second edge server and the terminal feature data set of the first edge server to obtain an updated fraud risk assessment model, and perform fraud risk assessment on the first user terminal based on the updated fraud risk assessment model.

[0126] To sum up, the fraud risk assessment method provided by the embodiment of the present disclosure, after the first edge server in the wireless communication network triggers the fraud risk assessment model update process and sends the first communication feature data to the second edge server, the second edge server can determine that the communication feature data related to the fraud event of the second edge server meets the characteristic-related conditions, and then send the terminal feature data set of multiple second user terminals of the second edge server to the first edge server, so that the first edge server can update the fraud risk assessment model based on more sample data, thereby improving the recognition accuracy of the updated fraud risk assessment model.

[0127] It should be noted that, in the embodiment of the present disclosure, the process of the second edge server determining whether the first communication feature data and the second communication feature data meet the feature-related conditions can refer to the above embodiment, and the embodiment of the present disclosure will not elaborate on this.

[0128] In an optional embodiment, the second edge server may further: receive the updated fraud risk assessment model sent by the first edge server; and then, based on the updated fraud risk assessment model, perform a fraud risk assessment on each second user terminal served by the second edge server to obtain a fraud risk assessment value for each second user terminal. The updated fraud risk assessment model sent by the first edge server can be used to perform fraud risk assessment on the second user terminal. Because the first edge server determines that the terminal characteristics of the second user terminal served by the second edge server are similar to the terminal characteristics of the first user terminal served by the first edge server, and the first edge server utilizes the terminal feature dataset of the candidate second edge server during the process of updating the fraud risk assessment model, the updated fraud risk assessment model is sent to the second edge server only when the first edge server utilizes the terminal feature dataset of the candidate second edge server. This allows the second edge server to have a higher accuracy in understanding the characteristics of the terminal feature dataset of the second user terminal during the fraud risk assessment on the second user terminal using the updated fraud risk assessment model, thereby improving the accuracy of the fraud risk assessment value of the second user terminal determined by the candidate second edge server.

[0129] For example, Figure 4 As shown, Figure 4 The following is an interactive flow chart of a fraud risk assessment method provided by an embodiment of the present disclosure, including:

[0130] Step S401: After training the initial fraud risk assessment model, the cloud device synchronizes the initial fraud risk assessment model to each edge server;

[0131] In step S402, the first edge server performs fraud risk assessment on each of the plurality of first user terminals based on a pre-trained fraud risk assessment model to obtain a fraud risk assessment value for each of the first user terminals.

[0132] Step S403: When the first edge server determines to trigger the model update process based on the multiple fraud risk assessment values, it determines terminal traffic feature data based on the traffic time series of the multiple first user terminals, and determines terminal connection behavior feature data based on the connection behavior data between each of the first user terminals and the base station, and combines the terminal traffic feature data and the terminal connection behavior feature data to obtain communication behavior feature data of the multiple first user terminals.

[0133] Step S404: The first edge server determines terminal fraud probability feature data based on the number of times each first user terminal is defrauded in each unit time period and the total number of times multiple first user terminals are defrauded in multiple unit time periods, determines terminal mobility feature data based on distance change data between each first user terminal and a base station at different times, and combines the terminal fraud probability feature data and the terminal mobility feature data to obtain communication spatiotemporal feature data of the multiple first user terminals.

[0134] Step S405: combining the communication behavior feature data and the communication spatiotemporal feature data of the plurality of first user terminals to construct first communication feature data of the plurality of first user terminals, and sending the first communication feature data to each second edge server in the wireless communication network;

[0135] Step S406: The second edge server determines whether the first communication feature data and the second communication feature data of the plurality of second user terminals served by the second edge server meet feature-related conditions;

[0136] Step S407: If the conditions are met, the encrypted terminal feature data difference sets of the plurality of second user terminals are sent to the first edge server;

[0137] Step S408: If the first edge server receives encrypted terminal feature data difference sets sent by multiple candidate second edge servers, the first edge server determines multiple terminal feature correlation values based on the terminal feature data difference sets associated with each candidate second edge server and the terminal feature data set of the first edge server, and determines the candidate second edge server associated with the maximum terminal feature correlation value as the target second edge server.

[0138] Step S409: The first edge server requests each of the target second edge servers to obtain a target terminal feature dataset;

[0139] Step S410: The first edge server updates the fraud risk assessment model based on the at least one target terminal feature dataset and the terminal feature dataset of the first edge server to obtain an updated fraud risk assessment model;

[0140] Step S411: Perform fraud risk assessment on the first user terminal based on the updated fraud risk assessment model.

[0141] An exemplary embodiment of the present disclosure provides a fraud risk assessment device, which may be a chip of a first edge server in a wireless communication network. Figure 5FIG. 1 shows a schematic block diagram of the functional modules of a fraud risk assessment device according to an exemplary embodiment of the present disclosure. Figure 5 As shown, the fraud risk assessment device 500 includes:

[0142] An evaluation module 501 is configured to perform fraud risk evaluation on each of the plurality of first user terminals based on a pre-trained fraud risk evaluation model to obtain a fraud risk evaluation value for each of the first user terminals;

[0143] The processing module 502 is configured to, upon determining that a model update process is triggered based on the multiple fraud risk assessment values, construct first communication feature data of the multiple first user terminals, and send the first communication feature data to each second edge server in the wireless communication network, wherein the second edge server is configured to, upon determining that the first communication feature data and the second communication feature data of the multiple second user terminals served by the second edge server meet feature-related conditions, send terminal feature data sets of the multiple second user terminals to the first edge server, where the communication feature data includes communication behavior feature data and / or communication spatiotemporal feature data related to the fraud event;

[0144] The update module 503 is configured to update the fraud risk assessment model based on the terminal feature dataset of the at least one candidate second edge server and the terminal feature dataset of the first edge server if a terminal feature dataset is received, to obtain an updated fraud risk assessment model, and to perform a fraud risk assessment on the first user terminal based on the updated fraud risk assessment model.

[0145] Optionally, the processing module 502 is configured to:

[0146] Determining terminal traffic characteristic data based on traffic time series of the plurality of first user terminals;

[0147] Determining terminal connection behavior feature data based on the connection behavior data between each of the first user terminals and the base station;

[0148] The terminal traffic characteristic data and the terminal connection behavior characteristic data are combined to obtain communication behavior characteristic data of the multiple first user terminals, and based on the communication behavior characteristic data of the multiple first user terminals, the first communication characteristic data of the multiple first user terminals are determined.

[0149] Optionally, the processing module 502 is configured to:

[0150] Determining terminal fraud probability characteristic data based on the number of frauds suffered by each first user terminal in each unit time length and the total number of frauds suffered by multiple first user terminals in multiple unit time lengths;

[0151] Determining terminal movement characteristic data based on distance change data between each of the first user terminals and the base station at different times;

[0152] The terminal fraud probability feature data and the terminal movement feature data are combined to obtain the communication spatiotemporal feature data of the multiple first user terminals, and based on the communication spatiotemporal feature data of the multiple first user terminals, the first communication feature data of the multiple first user terminals are determined.

[0153] Optionally, the number of the candidate second edge servers includes multiple, and the terminal feature data set of the candidate second edge server is a terminal feature data difference set of each second user terminal served by the candidate second edge server in at least two historical time periods,

[0154] The update module 503 is configured to:

[0155] Determining at least one target second edge server from the plurality of candidate second edge servers based on the terminal feature data difference set associated with each candidate second edge server and the terminal feature data set of the first edge server, wherein the terminal feature data difference set of the target second edge server and the terminal feature data set of the first edge server meet a preset similarity condition;

[0156] Requesting each of the target second edge servers to obtain a target terminal feature data set, wherein the target terminal feature data set is a terminal feature data set of multiple second user terminals served by the target second edge server;

[0157] Based on the at least one target terminal feature data set and the terminal feature data set of the first edge server, the fraud risk assessment model is updated to obtain an updated fraud risk assessment model.

[0158] Optionally, the updating module 503 is configured to:

[0159] Determining a plurality of terminal feature-related values based on the terminal feature data difference set associated with each candidate second edge server and the terminal feature data set of the first edge server;

[0160] The candidate second edge server associated with the maximum terminal feature correlation value is determined as the target second edge server.

[0161] Optionally, the apparatus further includes a first sending module 504 configured to:

[0162] The updated fraud risk assessment model is sent to each of the candidate second edge servers, wherein each of the candidate second edge servers is configured to perform fraud risk assessment on multiple second user terminals served by each second edge server based on the updated fraud risk assessment model.

[0163] An exemplary embodiment of the present disclosure provides a fraud risk assessment device, which may be a chip of a second edge server in a wireless communication network. Figure 6 FIG. 1 shows a schematic block diagram of the functional modules of a fraud risk assessment device according to an exemplary embodiment of the present disclosure. Figure 6 As shown, the fraud risk assessment device 600 includes:

[0164] Determination module 601 is configured to, in response to receiving first communication feature data sent by a first edge server in the wireless communication network, determine a communication feature data relevance determination result based on the first communication feature data and second communication feature data of multiple second user terminals served by the second edge server, wherein the first communication feature data is generated by the first edge server when a model update process is determined to be triggered during a fraud risk assessment process of the multiple first user terminals served by the first edge server based on a pre-trained fraud risk assessment model;

[0165] The second sending module 602 is configured to send the terminal feature data sets of the multiple second user terminals to the first edge server when the communication feature data correlation judgment result indicates that the first communication feature data and the second communication feature data meet the feature correlation conditions, wherein the first edge server is used to update the fraud risk assessment model based on the terminal feature data set sent by the second edge server and the terminal feature data set of the first edge server to obtain an updated fraud risk assessment model, and perform fraud risk assessment on the first user terminal based on the updated fraud risk assessment model.

[0166] Optionally, the apparatus further includes a receiving module 603 configured to:

[0167] receiving the updated fraud risk assessment model sent by the first edge server;

[0168] Based on the updated fraud risk assessment model, a fraud risk assessment is performed on each second user terminal served by the second edge server to obtain a fraud risk assessment value of each second user terminal.

[0169] The exemplary embodiments of the present disclosure further provide an electronic device, comprising: at least one processor; and a memory communicatively connected to the at least one processor. The memory stores a computer program executable by the at least one processor, the computer program being configured to cause the electronic device to perform a method according to an exemplary embodiment of the present disclosure when executed by the at least one processor.

[0170] Exemplary embodiments of the present disclosure further provide a non-transitory computer-readable storage medium storing a computer program, wherein the computer program, when executed by a processor of a computer, is used to cause the computer to perform a method according to an embodiment of the present disclosure.

[0171] like Figure 7 As shown, the exemplary embodiment of the present disclosure further provides a computer program product 700, including a computer program 701, wherein when the computer program is executed by a processor of a computer, it is used to enable the computer to perform the method according to the embodiment of the present disclosure.

[0172] refer to Figure 8 , a structural block diagram of an electronic device 800 that can be used as a terminal device of the present disclosure will now be described, which is an example of a hardware device that can be applied to various aspects of the present disclosure. The electronic device is intended to represent various forms of digital electronic computer devices, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital processing, cellular phones, smart phones, wearable devices and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely examples and are not intended to limit the implementation of the present disclosure described and / or required herein.

[0173] like Figure 8 As shown, the electronic device 800 includes a computing unit 801, which can perform various appropriate actions and processes according to a computer program stored in a read-only memory (ROM) 802 or a computer program loaded from a storage unit 808 into a random access memory (RAM) 803. In the RAM 803, various programs and data required for the operation of the electronic device 800 can also be stored. The computing unit 801, the ROM 802, and the RAM 803 are connected to each other via a bus 804. An input / output (I / O) interface 805 is also connected to the bus 804.

[0174] Multiple components within electronic device 800 are connected to I / O interface 805, including an input unit 806, an output unit 807, a storage unit 808, and a communication unit 809. Input unit 806 can be any type of device capable of inputting information into electronic device 800. Input unit 806 can receive input numeric or character information and generate key input signals related to user settings and / or function control of the electronic device. Output unit 807 can be any type of device capable of presenting information and may include, but is not limited to, a display, a speaker, a video / audio output terminal, a vibrator, and / or a printer. Storage unit 808 may include, but is not limited to, a magnetic disk or an optical disk. Communication unit 809 allows electronic device 800 to exchange information / data with other devices via computer networks such as the Internet and / or various telecommunication networks and may include, but is not limited to, a modem, a network card, an infrared communication device, a wireless communication transceiver and / or a chipset, such as a Bluetooth™ device, a WiFi device, a WiMax device, a cellular communication device, and / or the like.

[0175] The computing unit 801 may be a variety of general and / or special processing components with processing and computing capabilities. Some examples of the computing unit 801 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various dedicated artificial intelligence (AI) computing chips, various computing units for running machine learning model algorithms, digital signal processors (DSPs), and any appropriate processors, controllers, microcontrollers, etc. The computing unit 801 performs the various methods and processes described above. For example, in some embodiments, the method of the embodiment of the present disclosure may be implemented as a computer software program, which is tangibly included in a machine-readable medium, such as a storage unit 808. In some embodiments, part or all of the computer program may be loaded and / or installed on the electronic device 800 via the ROM 802 and / or the communication unit 809. In some embodiments, the computing unit 801 may be configured to perform the method of the embodiment of the present disclosure by any other appropriate means (e.g., by means of firmware).

[0176] The program code for implementing the method of the present disclosure can be written in any combination of one or more programming languages. These program codes can be provided to a processor or controller of a general-purpose computer, a special-purpose computer, or other programmable data processing device so that when the program code is executed by the processor or controller, the functions / operations specified in the flow chart and / or block diagram are implemented. The program code can be executed entirely on the machine, partially on the machine, as a stand-alone software package, partially on the machine and partially on a remote machine, or entirely on a remote machine or server.

[0177] In the context of the present disclosure, a machine-readable medium can be a tangible medium that can contain or store a program for use by or in conjunction with an instruction execution system, device or equipment. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can include, but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, device or equipment, or any suitable combination of the foregoing. A more specific example of a machine-readable storage medium can include an electrical connection based on one or more lines, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0178] As used in this disclosure, the terms "machine-readable medium" and "computer-readable medium" refer to any computer program product, apparatus, and / or device (e.g., magnetic disk, optical disk, memory, programmable logic device (PLD)) for providing machine instructions and / or data to a programmable processor, including machine-readable media that receives machine instructions as a machine-readable signal. The term "machine-readable signal" refers to any signal for providing machine instructions and / or data to a programmable processor.

[0179] To provide interaction with a user, the systems and techniques described herein can be implemented on a computer having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user can provide input to the computer. Other types of devices can also be used to provide interaction with the user; for example, the feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, voice input, or tactile input).

[0180] The systems and techniques described herein can be implemented in a computing system that includes back-end components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes front-end components (e.g., a user computer having a graphical user interface or a web browser through which a user can interact with implementations of the systems and techniques described herein), or a computing system that includes any combination of such back-end components, middleware components, or front-end components. The components of the system can be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include a local area network (LAN), a wide area network (WAN), and the Internet.

[0181] In the above embodiments, they can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using software, they can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer programs or instructions. When the computer program or instructions are loaded and executed on a computer, the processes or functions described in the embodiments of the present disclosure are performed in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, a terminal, a user device, or other programmable device. The computer program or instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer program or instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired or wireless means. The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or data center that integrates one or more available media. The available medium can be a magnetic medium, such as a floppy disk, a hard disk, or a tape; it can also be an optical medium, such as a digital video disc (DVD); it can also be a semiconductor medium, such as a solid state drive (SSD).

[0182] Although the present disclosure has been described with reference to specific features and embodiments thereof, it will be apparent that various modifications and combinations may be made thereto without departing from the spirit and scope of the present disclosure. Accordingly, this specification and the drawings are merely illustrative of the present disclosure as defined by the appended claims and are deemed to cover any and all modifications, variations, combinations or equivalents within the scope of the present disclosure. Obviously, those skilled in the art may make various modifications and variations to the present disclosure without departing from the spirit and scope of the present disclosure. Thus, the present disclosure is intended to include such modifications and variations if they fall within the scope of the claims of the present disclosure and their equivalents.

Claims

1. A fraud risk assessment method, characterized in that: The method is applied to a first edge server in a wireless communication network, and includes: Based on a pre-trained fraud risk assessment model, performing fraud risk assessments on multiple first user terminals to obtain a fraud risk assessment value for each of the first user terminals; In a case where a trigger model update process is determined based on the multiple fraud risk assessment values, first communication feature data of the multiple first user terminals is constructed, and the first communication feature data is sent to each second edge server in the wireless communication network, wherein the second edge server is configured to send terminal feature data sets of the multiple second user terminals to the first edge server when it is determined that the first communication feature data and the second communication feature data of the multiple second user terminals served by the second edge server meet feature-related conditions, wherein the communication feature data includes communication behavior feature data and / or communication spatiotemporal feature data related to the fraud event; If a terminal feature data set is received from at least one candidate second edge server, the fraud risk assessment model is updated based on the terminal feature data set of the at least one candidate second edge server and the terminal feature data set of the first edge server to obtain an updated fraud risk assessment model, and a fraud risk assessment is performed on the first user terminal based on the updated fraud risk assessment model.

2. The fraud risk assessment method according to claim 1, characterized in that: The constructing the first communication feature data of the plurality of first user terminals includes: Determining terminal traffic characteristic data based on traffic time series of the plurality of first user terminals; Determining terminal connection behavior feature data based on the connection behavior data between each of the first user terminals and the base station; The terminal traffic characteristic data and the terminal connection behavior characteristic data are combined to obtain communication behavior characteristic data of the multiple first user terminals, and based on the communication behavior characteristic data of the multiple first user terminals, the first communication characteristic data of the multiple first user terminals are determined.

3. The fraud risk assessment method according to claim 1, characterized in that: The constructing the first communication feature data of the plurality of first user terminals includes: Determining terminal fraud probability characteristic data based on the number of frauds suffered by each first user terminal in each unit time length and the total number of frauds suffered by multiple first user terminals in multiple unit time lengths; Determining terminal movement characteristic data based on distance change data between each of the first user terminals and the base station at different times; The terminal fraud probability feature data and the terminal movement feature data are combined to obtain the communication spatiotemporal feature data of the multiple first user terminals, and based on the communication spatiotemporal feature data of the multiple first user terminals, the first communication feature data of the multiple first user terminals are determined.

4. The fraud risk assessment method according to claim 1, characterized in that: The number of the candidate second edge servers includes multiple ones, and the terminal feature data set of the candidate second edge server is a terminal feature data difference set of each second user terminal served by the candidate second edge server in at least two historical periods. The updating of the fraud risk assessment model based on the terminal feature dataset of the at least one candidate second edge server and the terminal feature dataset of the first edge server to obtain an updated fraud risk assessment model includes: Determining at least one target second edge server from the plurality of candidate second edge servers based on the terminal feature data difference set associated with each candidate second edge server and the terminal feature data set of the first edge server, wherein the terminal feature data difference set of the target second edge server and the terminal feature data set of the first edge server meet a preset similarity condition; Requesting each of the target second edge servers to obtain a target terminal feature data set, wherein the target terminal feature data set is a terminal feature data set of multiple second user terminals served by the target second edge server; Based on the at least one target terminal feature data set and the terminal feature data set of the first edge server, the fraud risk assessment model is updated to obtain an updated fraud risk assessment model.

5. The fraud risk assessment method according to claim 4, characterized in that: The determining at least one target second edge server from a plurality of candidate second edge servers based on the terminal feature data difference set respectively associated with each candidate second edge server and the terminal feature data set of the first edge server includes: Determining a plurality of terminal feature-related values based on the terminal feature data difference set associated with each candidate second edge server and the terminal feature data set of the first edge server; The candidate second edge server associated with the maximum terminal feature correlation value is determined as the target second edge server.

6. The fraud risk assessment method according to claim 1, characterized in that: The method further comprises: The updated fraud risk assessment model is sent to each of the candidate second edge servers, wherein each of the candidate second edge servers is configured to perform fraud risk assessment on multiple second user terminals served by each second edge server based on the updated fraud risk assessment model.

7. A fraud risk assessment method, characterized in that: The method is applied to a second edge server in a wireless communication network, and includes: In response to receiving first communication feature data sent by a first edge server in the wireless communication network, determining a communication feature data correlation determination result based on the first communication feature data and second communication feature data of multiple second user terminals served by the second edge server, wherein the first communication feature data is generated by the first edge server when a model update process is determined to be triggered during a fraud risk assessment performed on the multiple first user terminals served by the first edge server based on a pre-trained fraud risk assessment model; When the communication feature data correlation judgment result indicates that the first communication feature data and the second communication feature data meet the feature correlation conditions, the terminal feature data sets of the multiple second user terminals are sent to the first edge server, wherein the first edge server is used to update the fraud risk assessment model based on the terminal feature data set sent by the second edge server and the terminal feature data set of the first edge server to obtain an updated fraud risk assessment model, and perform fraud risk assessment on the first user terminal based on the updated fraud risk assessment model.

8. The fraud risk assessment method according to claim 7, characterized in that: The method further comprises: receiving the updated fraud risk assessment model sent by the first edge server; Based on the updated fraud risk assessment model, a fraud risk assessment is performed on each second user terminal served by the second edge server to obtain a fraud risk assessment value of each second user terminal.

9. An electronic device comprising a memory, a processor, and a computer program stored in the memory, characterized in that: The processor executes the computer program to implement the fraud risk assessment method according to any one of claims 1 to 6 or claims 7 to 8.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the fraud risk assessment method according to any one of claims 1 to 6 or claims 7 to 8 is implemented.

11. A computer program product comprising a computer program, characterized in that When the computer program is executed by a processor, the fraud risk assessment method according to any one of claims 1 to 6 or claims 7 to 8 is implemented.

12. A fraud risk assessment system, characterized in that: The system is a wireless communication network system, and the fraud risk assessment system includes multiple edge servers, wherein: The first edge server performs fraud risk assessment on each of the plurality of first user terminals based on a pre-trained fraud risk assessment model to obtain a fraud risk assessment value for each of the first user terminals; The first edge server constructs first communication feature data of the plurality of first user terminals and sends the first communication feature data to each second edge server in the wireless communication network when determining to trigger a model update process based on the plurality of fraud risk assessment values. Each second edge server, upon determining that the first communication feature data and the second communication feature data of multiple second user terminals served by the second edge server meet feature-related conditions, sends terminal feature data sets of the multiple second user terminals to the first edge server, where the communication feature data includes communication behavior feature data and / or communication spatiotemporal feature data related to the fraud incident; If the first edge server receives a terminal feature data set sent by at least one second edge server, the fraud risk assessment model is updated based on the terminal feature data set of the at least one second edge server and the terminal feature data set of the first edge server to obtain an updated fraud risk assessment model, and a fraud risk assessment is performed on the first user terminal based on the updated fraud risk assessment model.