Telecommunication service fraud-related risk security assessment system based on multi-modal fusion model

Through multimodal fusion model and machine learning technology, a telecommunications service fraud risk assessment system is built, which solves the problems of artificial dependence and poor accuracy in the existing technology, and realizes intelligent and automated assessment of telecommunications service fraud risks, improving assessment efficiency and accuracy.

CN120541599APending Publication Date: 2025-08-26BEIJING WEIZHIXINYE TECH CO LTD

Patent Information

Application Number
CN202510580544.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-07
Publication Date
2025-08-26

AI Technical Summary

Technical Problem

The prior art relies on manual in the assessment of telecom fraud risk, which is inefficient, incomplete coverage, poor accuracy, and difficult to effectively identify multimodal correlations of complex fraud-related behaviors, and insufficient cross-modal data fusion.

Method used

The multimodal fusion model is adopted to acquire and preprocess telecommunications service data through multi-source data acquisition components, and use machine learning to build a fraud-related risk assessment model, combining natural language processing and machine learning technology to achieve intelligent risk assessment and automated early warning.

Benefits of technology

It has realized the intelligent and automated assessment of fraud-related risks in telecommunications services, improved the systematicity and timeliness of assessment, reduced the labor workload, improved the accuracy and comprehensiveness of assessment, and formed a full-process prevention and control system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120541599A_ABST
    Figure CN120541599A_ABST
Patent Text Reader

Abstract

The invention provides a telecommunication service fraud-related risk security assessment system based on a multi-modal fusion model, and the system comprises a multi-source data collection assembly which is responsible for obtaining original telecommunication service data in multiple ways, carrying out the preprocessing of the original telecommunication service data, and obtaining first telecommunication service data; performing feature extraction and behavior pattern analysis on the first telecommunication service data to obtain key features related to the telecommunication service; the assessment model construction component is responsible for constructing a fraud-related risk assessment model based on machine learning, inputting the key features into the fraud-related risk assessment model, outputting an intelligent assessment control matrix, classifying and rating fraud-related risks, and generating a risk assessment result; and the service collaborative linkage assembly is responsible for early warning the risk level of the telecommunication service system according to the risk assessment result, and taking prevention measures according to the risk level. According to the method, an objective evaluation standard is established, and the conversion of risk identification from experience judgment to data driving is realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of security assessment, and in particular to a telecommunications business fraud risk security assessment system based on a multimodal fusion model. Background Art

[0002] Telecom fraud methods are constantly evolving, from traditional phone scams to online and text message scams, with diverse and highly concealed forms. Existing technologies rely heavily on manual evaluation methods, consuming significant manpower and resulting in slow response times and long evaluation cycles. Furthermore, given the vast diversity of telecom services and the significant differences between different basic telecom operators, new fraud methods are constantly emerging. Relying entirely on manual evaluation methods, comprehensiveness and accuracy cannot be guaranteed. Even with the assistance of computer software, accuracy is still limited, requiring the assistance of professional personnel, and improving the accuracy of security assessments of telecom fraud risks is limited.

[0003] Prior art 1, application number: CN202410366304.3 discloses a fraud risk monitoring method, device, equipment and storage medium. First, based on the transaction status of each account over a continuous period of time, the transaction features of each account are extracted, and then the transaction features are arranged in chronological order to construct a transaction feature sequence. Implicit transaction features are extracted from the transaction feature sequence, and finally, the probability of account fraud is determined based on the implicit transaction features. Although there is no need to rely heavily on manually constructed risk prevention and control rules, human errors can be avoided to a certain extent, and since fraudulent transactions are usually not periodic, the use of implicit transaction features that can characterize account transaction habits to determine the probability of account fraud can improve the accuracy of fraud risk monitoring to a certain extent and reduce the possibility of fraud misjudgment to a certain extent; however, relying on a single transaction feature sequence, multimodal data (such as call records, text message content, network traffic, etc.) is not fully utilized, resulting in insufficient risk monitoring coverage dimensions and difficulty in capturing the multimodal correlation of complex fraudulent behaviors; for example, only analyzing transaction features may ignore key signals such as abnormal user behavior or abnormal communication patterns.

[0004] Prior art 2, application number: CN202411826556.6 discloses a training method and system for a multimodal feature vector embedder for a fraudulent APP. The steps of this method include: after the user provides protection permission, collecting basic information of the application and user behavior data; calculating the current fraud risk value and setting an initial fraud risk threshold. When the current fraud risk value is greater than the initial fraud risk threshold, running a two-layer training embedding strategy, and forming a fraudulent APP judgment model by combining a shallow feedforward neural network model and a deep fraud APP feature classification model; when the current fraud risk value is less than or equal to the initial fraud risk threshold, directly running an adaptive data migration strategy, and obtaining a migration cycle based on the APP active state and the fraud risk value. Although it balances the model training efficiency and real-time response capability, and enables the system to flexibly adapt to different data quality, avoiding the model performance being affected by noisy data or low-quality data; however, the multimodal data fusion is insufficient, mainly focusing on APP feature classification, and has not effectively solved the deep fusion problem across modalities (such as text, image, and time series behavior); without combining speech-to-text, image slicing and other technologies, it is difficult to achieve unified representation of heterogeneous data.

[0005] Prior art three, application number: CN202411955187.0 discloses a method and device for predicting bank fraudulent accounts based on relationship learning, the method comprising: obtaining bank account information within a preset time period, and multiple current blacklist accounts; based on the bank account information, constructing multiple first relationship subgraphs with multiple blacklist accounts as starting points; wherein each first relationship subgraph corresponds to a relationship link type; based on multiple first relationship subgraphs, determining multiple suspicious accounts and their respective corresponding feature information; inputting the respective feature information of multiple suspicious accounts into a fraud risk prediction model, obtaining the fraud risk prediction value of each suspicious account output by the fraud risk prediction model; based on the fraud risk prediction value of each suspicious account, determining the fraudulent account from multiple suspicious accounts. Although the prediction of fraudulent accounts can be achieved; however, the prediction method based on the bank account relationship graph is limited to financial scenarios, does not cover the multi-dimensional dynamic data of telecommunications services (such as real-time communication behavior, network logs), and lacks a collaborative linkage mechanism across business systems.

[0006] The existing technologies currently have problems such as low efficiency, incomplete coverage, reliance on manual labor, poor accuracy, and long processing times. Therefore, the present invention provides a telecommunications fraud risk security assessment system based on a multimodal fusion model. Summary of the Invention

[0007] In order to solve the above technical problems, the present invention provides a telecommunications business fraud risk security assessment system based on a multimodal fusion model, comprising:

[0008] The multi-source data acquisition component is responsible for acquiring original telecommunications service data through multiple channels, pre-processing the original telecommunications service data to obtain first telecommunications service data, performing feature extraction and behavior pattern analysis on the first telecommunications service data to obtain key features related to telecommunications services;

[0009] The assessment model building component is responsible for building a fraud risk assessment model based on machine learning, inputting key features into the fraud risk assessment model, outputting an intelligent assessment control matrix, classifying and rating fraud risks, and generating risk assessment results;

[0010] The business collaboration component is responsible for warning the telecommunications business system of its risk level based on the risk assessment results and taking preventive measures based on the risk level.

[0011] Optional, multi-source data acquisition components, including:

[0012] A preprocessing module is responsible for performing denoising, filling missing values, and preprocessing of the original telecommunication service data to unify the data format, thereby obtaining the first telecommunication service data;

[0013] The data identification module is responsible for separating identifiable data from non-identifiable data from the first telecommunications service data, performing semantic analysis on the identifiable data to identify fraud keywords, and extracting key features from the non-identifiable data through analysis;

[0014] The classification processing module is responsible for inputting key features into the fraud risk assessment model, classifying fraud risks by fraud keywords, grouping users corresponding to identifiable data, and identifying abnormal groups.

[0015] Optionally, identifiable data includes text message content and call recordings; non-identifiable data includes high-frequency calls, abnormal text message content, and suspicious IP addresses.

[0016] Optional data identification module, including:

[0017] The identification program triggering submodule is responsible for receiving a data set to be analyzed consisting of the first telecommunications service data, and triggering a structured content identification program and an unstructured feature identification program when the data set to be analyzed completes preprocessing;

[0018] The data type identification submodule is responsible for implementing the structured content identification program to perform parsability verification on data records containing clear semantic carriers, and through content feature detection, determine whether they conform to language expression specifications and mark them as recognizable data types; unstructured feature recognition detects communication frequency characteristics, analyzes network connection characteristics, identifies content distribution characteristics, and marks data records that do not have direct semantic expression but contain behavioral characteristics as non-recognizable data types;

[0019] The data channel confirmation submodule is responsible for entering the corresponding data channel according to the recognition results of the structured content recognition program and the unstructured feature recognition program, extracting text semantics from structured content, establishing a keyword matching rule library, performing contextual association analysis, and outputting a set of fraud keywords; for non-identifiable data, quantifying communication frequency indicators, calculating network feature anomalies, modeling content distribution patterns, and outputting risk feature vectors;

[0020] The output result association submodule is responsible for directly associating the identifiable data processing results with the subsequent risk level determination, and connecting the non-identifiable data processing results to the risk assessment model input layer. The classification identifiers of the two types of data are used as the basis parameters for user grouping.

[0021] Optional, classification processing module, including:

[0022] The semantic feature extraction submodule is responsible for extracting semantic features based on the text messages and call recordings output by the data recognition module, screening out words or phrases with potential fraudulent associations and enhancing them based on contextual relevance.

[0023] The keyword dynamic stratification submodule is responsible for dividing the extracted fraud keywords into a multi-layer structure based on risk intensity and behavior patterns;

[0024] The risk classification mapping submodule is responsible for dynamically binding the stratified keywords with the user grouping rules in the classification processing module. If direct risk layer keywords are detected in the user data, they are classified into the confirmed fraud group without the need for additional feature verification; if only indirect association layer keywords exist, they are weighted based on the features in the non-identifiable data to decide whether to classify them into the suspected fraud or low-risk group; the environment-dependent layer keywords need to call the non-identifiable data analysis results in the data identification module, and if there is a match, the classification level is upgraded.

[0025] Optionally, the multi-layer structure of the keyword dynamic layering submodule includes: the direct risk layer contains words that clearly indicate fraudulent instructions, which directly trigger high-risk classification; the indirect association layer contains words that are harmless in themselves, but form fraudulent rhetoric after combination, and the risk level needs to be determined by co-occurrence frequency; the riskiness of words in the environment-dependent layer depends on the characteristics of communication behavior.

[0026] Optional, evaluation model building components, including:

[0027] The multimodal feature fusion module is responsible for analyzing network traffic and abnormal connection patterns in network logs based on unstructured features, quantifying the deviation of user behavior, establishing a temporal behavior baseline based on abnormal user operation logs with dynamic behavior characteristics, and identifying sudden changes in behavior. It also forms a multimodal risk feature set through feature cross-validation.

[0028] The model hierarchical training module is responsible for adopting a phased modeling strategy to output risk probability scores and risk classification labels;

[0029] The control matrix construction module is responsible for mapping risk assessment results to a matrix analysis framework, covering the entire business life cycle, comparing business data with the compliance baseline, and quantifying the degree of deviation; based on the output risk probability, it divides the inherent risk level of the business link; the output is a risk heat map, marking the risk level and control shortcomings of each business link.

[0030] Optionally, the phased modeling strategy of the model layer training module includes: the inherent risk identification layer trains the classification model based on the annotated data of historical fraud cases to distinguish high-risk behaviors from low-risk routine operations; the control measures compensation layer introduces business management data to evaluate the suppression effect of existing protective measures on inherent risks and dynamically adjusts risk weights; the residual risk prediction layer combines real-time data streams to optimize the model through incremental learning to identify potential risks not covered by existing control measures; and outputs risk probability scores and risk classification labels.

[0031] Optional, control matrix building block, including:

[0032] The data preprocessing submodule is responsible for receiving the risk probability score dataset output by the model hierarchical training module, performing statistical analysis on the risk probability distribution, calculating the probability mean, variance, and extreme value ratio of each business link, establishing a probability distribution histogram, and identifying natural breakpoints as initial classification thresholds;

[0033] The sub-module of the risk level determination stage is responsible for adjusting the absolute score of the comprehensive risk probability, the degree of baseline deviation, and the three-dimensional spatial mapping to locate the business link in the risk level matrix;

[0034] The heat map generation sub-module is responsible for constructing a risk distribution map for the entire business life cycle based on the grading results, superimposing the effectiveness data of control measures, marking key risk shortcoming areas, and verifying the accuracy of the grading through the actual early warning effects of the business collaborative linkage components.

[0035] Optional business collaboration components include:

[0036] The risk feature mapping module is responsible for extracting core dimensional indicators from the risk assessment results based on the output intelligent assessment control matrix, including risk classification codes, grade scores, and temporal and spatial distribution characteristics. It also aligns these parameters with the interface specifications of the telecommunications business system and establishes a mapping relationship table between risk labels and business rules.

[0037] The dynamic threshold adaptation module is responsible for automatically matching the preset response strategy library based on the risk rating results in the intelligent assessment control matrix; the strategy library contains a set of trigger conditions corresponding to each risk level;

[0038] The multi-dimensional early warning distribution module is responsible for converting risk assessment results into three types of parallel outputs through the intelligent routing engine built into the business collaboration component.

[0039] The present invention has built a full-process prevention and control system covering risk identification, analysis and judgment, disposal and response, which has improved the systematicness and timeliness of anti-fraud work in telecommunications services; the system has achieved process-based and standardized fraud risk prevention and control through the technical paths of standardized data processing, intelligent risk assessment and automated early warning response. By adopting natural language processing and machine learning technologies, and applying scientific methods and means such as matrix assessment method, it systematically identifies the fraud risks existing in the entire life cycle of telecommunications services, and realizes the intelligence and automation of fraud risk assessment work; it helps to improve the standardization and effectiveness of telecommunications business fraud risk security assessment, so that telecommunications business operations and effective fraud governance can develop in a coordinated manner, and help basic telecommunications operators improve their business management level through fraud risk security assessment, and comprehensively reduce business fraud risks.

[0040] Other features and advantages of the present invention will be described in the following description, and in part will become apparent from the description, or will be understood by practicing the present invention. The purpose and other advantages of the present invention can be realized and obtained by the structures particularly pointed out in the written description and the accompanying drawings.

[0041] The technical solution of the present invention is further described in detail below through the accompanying drawings and embodiments. BRIEF DESCRIPTION OF THE DRAWINGS

[0042] The accompanying drawings are used to provide a further understanding of the present invention and constitute a part of the specification. Together with the embodiments of the present invention, they are used to explain the present invention and do not constitute a limitation of the present invention. In the accompanying drawings:

[0043] Figure 1 This is a block diagram of a telecommunications business fraud risk security assessment system based on a multimodal fusion model in Example 1 of the present invention;

[0044] Figure 2 This is a block diagram of a multi-source data acquisition component in Example 2 of the present invention;

[0045] Figure 3 A block diagram of components for constructing the evaluation model in Example 5 of the present invention;

[0046] Figure 4 This is a block diagram of the business collaborative linkage components in Example 7 of the present invention. DETAILED DESCRIPTION

[0047] The preferred embodiments of the present invention are described below with reference to the accompanying drawings. It should be understood that the preferred embodiments described herein are only used to illustrate and explain the present invention, and are not used to limit the present invention.

[0048] The terms used in the embodiments of the present application are for the purpose of describing specific embodiments only and are not intended to limit the embodiments of the present application. The singular forms "a", "the" and "the" used in the embodiments of the present application are also intended to include plural forms unless the context clearly indicates otherwise. It should also be understood that the term "and / or" used herein refers to and includes any or all possible combinations of one or more associated listed items.

[0049] When the following description refers to the accompanying drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with the present application. On the contrary, they are merely examples of devices and methods consistent with some aspects of the present application. In the description of the present application, it should be understood that the terms "first", "second", "third", etc. are only used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence, nor can they be understood as indicating or implying relative importance. For those of ordinary skill in the art, the specific meanings of the above terms in the present application can be understood according to the specific circumstances.

[0050] Example 1: Figure 1 As shown, an embodiment of the present invention provides a telecommunications business fraud risk security assessment system based on a multimodal fusion model, comprising:

[0051] The multi-source data acquisition component is responsible for acquiring original telecommunications service data through multiple channels, pre-processing the original telecommunications service data to obtain first telecommunications service data, performing feature extraction and behavior pattern analysis on the first telecommunications service data to obtain key features related to telecommunications services;

[0052] Telecommunications business data includes business data from basic telecommunications companies and internet companies, such as call records, SMS content, user behavior, network traffic, network connection logs, and user abnormal operation logs, etc., which are multi-dimensional, massive, and multi-modal data and can be accessed through bypass mirroring. Data on business management data resources, business technology construction resources, fraud prevention and governance resources, etc., some of which can be automatically imported through system correlation analysis, and some can be manually entered by evaluators.

[0053] The assessment model building component is responsible for building a fraud risk assessment model based on machine learning, inputting key features into the fraud risk assessment model, outputting an intelligent assessment control matrix, classifying and rating fraud risks, and generating risk assessment results;

[0054] The business collaboration component is responsible for warning the telecommunications business system of its risk level based on the risk assessment results and taking preventive measures based on the risk level.

[0055] The working principle and beneficial effects of the above technical solution are as follows: the multi-source data acquisition component of this embodiment obtains original telecommunications business data through multiple channels, pre-processes the original telecommunications business data to obtain first telecommunications business data, extracts features and analyzes behavior patterns on the first telecommunications business data, and obtains key features related to telecommunications business; the assessment model construction component constructs a fraud risk assessment model based on machine learning, inputs key features into the fraud risk assessment model, outputs an intelligent assessment control matrix, classifies and rates fraud risks, and generates risk assessment results; the business collaboration and linkage component warns the telecommunications business system of its risk level based on the risk assessment results, and takes preventive measures according to the risk level. The above solution achieves closed-loop management of telecommunications fraud risks through a modular architecture. The multi-source data acquisition component provides standardized input for risk assessment by structured processing of raw data and extracting key features, thus solving the problem of data heterogeneity. The assessment model construction component uses machine learning algorithms to convert feature data into quantifiable risk levels, establishes objective assessment standards, and realizes the transformation of risk identification from empirical judgment to data-driven. The business collaboration and linkage component uses a risk warning mechanism to feed back assessment results to the business system in real time, forming a complete "monitoring-assessment-disposal" chain to ensure that risk control measures can be triggered in a timely manner.

[0056] In summary, this embodiment has built a full-process prevention and control system covering risk identification, analysis and judgment, disposal and response, which has improved the systematicness and timeliness of anti-fraud work in telecommunications services; the system has achieved process-based and standardized fraud risk prevention and control through the technical path of standardized data processing, intelligent risk assessment and automated early warning response. By adopting natural language processing and machine learning technologies, and applying scientific methods and means such as matrix assessment method, it systematically identifies fraud risks existing in the entire life cycle of telecommunications services, and realizes the intelligence and automation of fraud risk assessment work; it helps to improve the standardization and effectiveness of telecommunications business fraud risk security assessment, so that telecommunications business operations and effective fraud governance can develop in a coordinated manner, and help basic telecommunications operators improve their business management level through fraud risk security assessment, and comprehensively reduce business fraud risks.

[0057] This embodiment introduces a machine learning algorithm into the telecommunications business fraud risk security assessment system based on a multimodal fusion model. By training the model, it automatically identifies and classifies telecommunications business fraud risks, greatly improving assessment efficiency and reducing manual workload. Deep learning technology is used to continuously optimize the model to adapt it to the ever-changing fraud methods and ensure the accuracy and timeliness of the assessment. Strengthen the management of the entire process to achieve closed-loop management from risk analysis and identification, research and judgment to matching control measures. Through measures such as system construction, personnel management, data identification and hierarchical management, solve the problems of incomplete risk assessment, insufficient technical means, and inability to normalize detection in the past, and ensure the quality and effectiveness of the assessment work. The matrix assessment method realizes the standardization and process of the assessment process, reduces the dependence on the ability level of the assessors, provides strong data support for subsequent improvement measures, and makes the assessment work more standardized and efficient.

[0058] Example 2: Figure 2 As shown, based on Example 1, the multi-source data acquisition component provided by the embodiment of the present invention includes:

[0059] A preprocessing module is responsible for performing denoising, filling missing values, and preprocessing of the original telecommunication service data to unify the data format, thereby obtaining the first telecommunication service data;

[0060] The data identification module is responsible for classifying and obtaining identifiable data and non-identifiable data from the first telecommunications service data. Identifiable data undergoes semantic analysis to identify fraudulent keywords, while non-identifiable data is analyzed to extract key features. Identifiable data includes SMS content and call recordings, while non-identifiable data includes high-frequency calls, abnormal SMS content, and suspicious IP addresses.

[0061] The classification processing module is responsible for inputting key features into the fraud risk assessment model, classifying fraud risks by fraud keywords, grouping users corresponding to identifiable data, and identifying abnormal groups.

[0062] The working principle and beneficial effects of the above technical solution are as follows: the preprocessing module of this embodiment performs denoising, filling missing values ​​and preprocessing to unify the data format of the original telecommunications business data to obtain the first telecommunications business data; the data identification module classifies and obtains identifiable data and non-identifiable data from the first telecommunications business data, performs semantic analysis on the identifiable data and identifies fraud keywords; the non-identifiable data extracts key features through analysis; the identifiable data includes text message content and call recordings; the non-identifiable data includes high-frequency calls, abnormal text message content and suspicious IP addresses; the classification processing module inputs the key features into the fraud risk assessment model, classifies the fraud risks by fraud keywords, groups the users corresponding to the identifiable data, and identifies abnormal groups. The multi-source data acquisition component of the above solution realizes structured processing and risk identification of telecommunications business data through a systematic process, which is specifically manifested in: data standardization and improved usability. The preprocessing module converts the original telecommunications data into regular first telecommunications business data through denoising, missing value filling and format unification, providing high-quality input for analysis and ensuring data consistency and integrity. Risk feature layered extraction: The data identification module processes structured data (text messages / call content) and unstructured data (call frequency / IP address, etc.) through the dual paths of semantic analysis and feature extraction, respectively, to achieve direct identification of fraud keywords and quantitative extraction of potential risk features, covering explicit and implicit risk signals. Risk quantification and group screening: The classification processing module converts keyword matching and feature analysis results into actionable fraud risk levels based on the feature assessment model, and locates abnormal groups through user grouping, and finally outputs risk classification results with action-oriented guidance to support precise prevention and control decisions. This embodiment realizes end-to-end analysis capabilities from raw telecommunications business data to risk groups.

[0063] Example 3: Based on Example 2, the data identification module provided by this embodiment of the present invention includes:

[0064] The identification program triggering submodule is responsible for receiving a data set to be analyzed consisting of the first telecommunications service data, and triggering a structured content identification program and an unstructured feature identification program when the data set to be analyzed completes preprocessing;

[0065] The data type identification submodule is responsible for implementing the structured content recognition program to perform parsability verification on data records containing clear semantic carriers (text-based SMS content, voice-to-text call records), and through content feature detection, determine whether they conform to language expression specifications and mark them as recognizable data types. Unstructured feature recognition detects communication frequency characteristics (number of interactions per unit time) for data records that do not have direct semantic expression but contain behavioral characteristics, analyzes network connection characteristics (determines access source anomalies), identifies content distribution characteristics (non-natural language text patterns), and marks them as non-recognizable data types.

[0066] The data channel confirmation submodule is responsible for entering the corresponding data channel according to the recognition results of the structured content recognition program and the unstructured feature recognition program, extracting text semantics from structured content, establishing a keyword matching rule library, performing contextual association analysis, and outputting a set of fraud keywords; for non-identifiable data, quantifying communication frequency indicators, calculating network feature anomalies, modeling content distribution patterns, and outputting risk feature vectors;

[0067] The output result association submodule is responsible for directly associating the identifiable data processing results (keyword set) with the subsequent risk level determination, and connecting the non-identifiable data processing results (feature vectors) to the input layer of the risk assessment model. The classification identifiers of the two types of data are used as the basis parameters for user grouping.

[0068] The working principle and beneficial effects of the above technical solution are as follows: the recognition program triggering submodule of this embodiment receives a data set to be analyzed consisting of the first telecommunications business data, and when the data set to be analyzed completes preprocessing, it triggers the structured content recognition program and the unstructured feature recognition program; the data type recognition submodule implements the structured content recognition program to perform parsability verification on data records containing clear semantic carriers (text-type SMS content, voice-to-text call records), and determines that they comply with the language expression specifications through content feature detection; and marks them as recognizable data types; the unstructured feature recognition detects the communication frequency characteristics (the number of interactions per unit time) of data records that do not have direct semantic expression but contain behavioral characteristics, and analyzes the network connection characteristics (access source abnormality judgment). The data channel confirmation submodule enters the corresponding data channel according to the recognition results of the structured content recognition program and the unstructured feature recognition program, extracts text semantics from the structured content, establishes a keyword matching rule library, performs context association analysis, and outputs a set of fraud keywords; for non-identifiable data, quantifies communication frequency indicators, calculates network feature anomalies, models content distribution patterns, and outputs risk feature vectors; the output result association submodule can directly associate the identifiable data processing results (keyword set) with subsequent risk level judgments, and the non-identifiable data processing results (feature vectors) are connected to the input layer of the risk assessment model. The classification identifiers of the two types of data are used as the basis parameters for user grouping. The above scheme establishes a standardized input interface through the triggering submodule to ensure that the first telecommunications business data forms a unified set to be analyzed after preprocessing, providing a qualified input source for subsequent identification; the preprocessing link serves as a quality checkpoint to ensure the execution basis of the identification program. The data type identification submodule constructs a binary classification framework. The structured identification path verifies semantic validity (language specification detection), and the unstructured identification path extracts behavioral features (communication pattern analysis), forming clear type labeling standards and enabling objective judgment of data attributes. The data channel confirmation submodule implements track processing based on type labels. The structured channel uses natural language processing technology (keyword extraction and context analysis), and the unstructured channel applies statistical modeling methods (indicator quantification and outlier calculation) to ensure that each type of data receives an analysis method that is adapted to its characteristics. The output result association submodule establishes a dual-track output mechanism. The semantic analysis results directly output interpretable risk evidence (keyword set) and the behavioral feature results are converted into numerical features (risk vectors) that can be processed by the model. At the same time, the original classification identifier is retained as the dimensional parameter of the user profile.

[0069] In summary, this embodiment uses a modular pipeline design to automatically classify, process, and convert telecommunications business data into standardized risk analysis materials based on their characteristic attributes, ultimately forming a structured output that supports multi-level risk assessment. The collaborative operation of each sub-module realizes the systematic transformation of raw data into risk decision-making factors, providing an input basis for risk determination that is both interpretable and quantitative.

[0070] Example 4: Based on Example 2, the classification processing module provided in this embodiment of the present invention includes:

[0071] The semantic feature extraction submodule is responsible for extracting semantic features based on the text messages and call recordings output by the data recognition module, screening out words or phrases with potential fraudulent associations and enhancing them based on contextual relevance.

[0072] The keyword dynamic stratification submodule is responsible for dividing the extracted fraud keywords into a multi-layer structure based on risk intensity and behavior patterns;

[0073] The direct risk layer contains words that clearly indicate fraudulent activity, directly triggering the high-risk classification;

[0074] Indirectly associated words are harmless in themselves, but when combined they can form fraudulent tactics, and their risk level needs to be determined by co-occurrence frequency.

[0075] The riskiness of vocabulary in the environment-dependent layer depends on the communication behavior characteristics;

[0076] The risk classification mapping submodule is responsible for dynamically binding the stratified keywords with the user grouping rules in the classification processing module. If direct risk layer keywords are detected in the user data, they are classified into the confirmed fraud group without the need for additional feature verification; if only indirect association layer keywords exist, they are weighted based on the features in the non-identifiable data to decide whether to classify them into the suspected fraud or low-risk group; the environment-dependent layer keywords need to call the non-identifiable data analysis results in the data identification module, and if there is a match, the classification level is upgraded.

[0077] The working principle and beneficial effects of the above technical solution are as follows: The semantic feature extraction submodule of this embodiment extracts semantic features based on the text message content and call recording text output by the data identification module, screens out words or phrases with potential fraud associations, and enhances them based on contextual relevance. The keyword dynamic stratification submodule is responsible for dividing the extracted fraud keywords into a multi-layer structure based on risk intensity and behavior pattern. The direct risk layer contains words that clearly indicate fraud instructions and directly triggers high-risk classification. The indirect association layer words are harmless in themselves, but when combined, they form fraudulent speech, and the risk level is determined by co-occurrence frequency. The riskiness of the environment-dependent layer words depends on the communication behavior characteristics. The risk classification mapping submodule dynamically binds the stratified keywords to the user grouping rules in the classification processing module. If the direct risk layer keywords are detected in the user data, they are classified into the confirmed fraud group without additional feature verification. If only the indirect association layer keywords are present, they are weighted based on the features in the non-identifiable data to determine whether they are classified as suspected fraud or low-risk groups. The environment-dependent layer keywords require the non-identifiable data analysis results of the data identification module to be used. If a match is found, the classification level is upgraded. This solution establishes a unified fraud keyword screening mechanism through the semantic feature extraction submodule, ensuring that potential risk features are extracted from text data from different sources (such as text messages and call recordings) using the same criteria. This enhanced contextual relevance prevents misclassification of isolated words and improves feature extraction accuracy. The dynamic keyword stratification submodule builds a scalable risk assessment framework. The direct risk layer enables rapid response and reduces complex computational requirements. The indirect association layer incorporates co-occurrence frequency analysis to balance false positives and false negatives. The environmental dependency layer facilitates access to non-identifiable data, enhancing the contextual adaptability of classification. The risk classification mapping submodule integrates two data streams, using semantic analysis results (stratified keywords) from identifiable data as the primary classification basis and non-identifiable data (communication behavior features) as auxiliary verification criteria. These two are combined through weighted logic to form the final classification decision, avoiding the limitations of a single data source. The module outputs directly associated user groupings: confirmed fraud groups (direct risk layer matches) are immediately handled; suspected fraud groups (indirect association layer + behavioral features) require further investigation; and low-risk groups (no key feature matches) are excluded from the classification process.

[0078] In summary, this embodiment organically combines semantic analysis with behavioral feature detection through a hierarchical classification mechanism, forming a risk assessment pipeline that combines both interpretability and quantitative evidence. The coordinated operation of various submodules ensures end-to-end processing from raw text to risk grouping, while retaining the flexibility of dynamic rule adjustment.

[0079] Example 5: Figure 3 As shown, based on Example 1, the evaluation model building component provided by the embodiment of the present invention includes:

[0080] The multimodal feature fusion module is responsible for analyzing network traffic and abnormal connection patterns in network logs based on unstructured features, quantifying the deviation of user behavior, establishing a temporal behavior baseline based on abnormal user operation logs with dynamic behavior characteristics, and identifying sudden changes in behavior. It also forms a multimodal risk feature set through feature cross-validation.

[0081] The model layer training module is responsible for adopting a phased modeling strategy. The inherent risk identification layer trains classification models based on annotated data from historical fraud cases to distinguish high-risk behaviors from low-risk routine operations. The control measures compensation layer introduces business management data to evaluate the effectiveness of existing protective measures in suppressing inherent risks and dynamically adjust risk weights. The residual risk prediction layer combines real-time data streams to optimize the model through incremental learning to identify potential risks not covered by existing control measures. The module then outputs risk probability scores and risk classification labels.

[0082] The control matrix construction module is responsible for mapping risk assessment results to a matrix analysis framework, covering the entire business life cycle, comparing business data with the compliance baseline, and quantifying the degree of deviation; based on the output risk probability, it divides the inherent risk level of the business link; the output is a risk heat map, marking the risk level and control shortcomings of each business link.

[0083] The working principle and beneficial effects of the above technical solution are as follows: the multimodal feature fusion module of this embodiment analyzes network traffic and abnormal connection patterns in network logs based on unstructured features, quantifies the deviation of user behavior, establishes a time-series behavior baseline based on the user's abnormal operation log with dynamic behavior characteristics, and identifies sudden behavior; a multimodal risk feature set is formed through feature cross-validation; the model hierarchical training module adopts a phased modeling strategy, and the inherent risk identification layer trains a classification model based on historical fraud case annotation data to distinguish high-risk behaviors from low-risk routine operations; the control measure compensation layer introduces business management data to evaluate the inhibitory effect of existing protective measures on inherent risks and dynamically adjusts risk weights; the residual risk prediction layer combines real-time data streams and optimizes the model through incremental learning to identify potential risks not covered by existing control measures; outputs risk probability scores and risk classification labels; the control matrix construction module maps the risk assessment results to a matrix analysis framework, covering the entire business life cycle, compares business data with the compliance baseline, and quantifies the degree of deviation; based on the output risk probability, the inherent risk level of the business link is divided; the output is a risk heat map, marking the risk level and control shortcomings of each business link. The above solution integrates unstructured data (network traffic, network logs) and dynamic behavioral features (abnormal operation logs) through a multimodal feature fusion module to form a comprehensive risk feature set; feature cross-validation enhances the robustness of risk identification and avoids misjudgment or omissions of a single data source. The model layer training module adopts phased modeling. The inherent risk identification layer ensures the accurate detection of historical fraud patterns; the control measure compensation layer quantifies the effectiveness of existing risk control strategies and dynamically adjusts risk weights; the residual risk prediction layer adapts to new fraud methods through incremental learning to fill protection blind spots; outputs risk probability scores and classification labels to provide a quantitative basis for decision-making. The control matrix construction module maps the model output to the entire business life cycle, and the baseline compliance assessment quantifies business compliance deviations; the inherent risk level classification identifies high-risk business links; the risk heat map intuitively displays the risk distribution and control shortcomings of each link; supports the precise allocation of risk control resources and prioritizes high-risk vulnerabilities.

[0084] Example 6: Based on Example 5, the control matrix building module provided in this embodiment of the present invention includes:

[0085] The data preprocessing submodule is responsible for receiving the risk probability score dataset output by the model hierarchical training module, performing statistical analysis on the risk probability distribution, calculating the probability mean, variance, and extreme value ratio of each business link, establishing a probability distribution histogram, and identifying natural breakpoints as initial classification thresholds;

[0086] The submodule in the risk level determination phase is responsible for accessing the compliance baseline database, calculating the deviation between the actual risk probability of a business link and the corresponding compliance threshold, and generating a baseline compliance index for each business link. It also verifies the initial classification threshold based on historical risk event data, optimizes the classification interval based on risk disposal records in business management data, and establishes an adaptive threshold adjustment mechanism to ensure that the classification results match the actual situation. It also locates the business link in the risk level matrix by combining the absolute risk probability score, the degree of baseline deviation, and three-dimensional spatial mapping.

[0087] The heat map generation sub-module is responsible for constructing a risk distribution map for the entire business life cycle based on the grading results, superimposing the effectiveness data of control measures, marking key risk shortcoming areas, and verifying the accuracy of the grading through the actual early warning effects of the business collaborative linkage components.

[0088] The working principle and beneficial effects of the above technical solution are as follows: the data preprocessing stage submodule of this embodiment receives the risk probability score data set output from the model hierarchical training module, performs statistical analysis on the risk probability distribution, calculates the probability mean, variance and extreme value proportion of each business link, establishes a probability distribution histogram, and identifies natural breakpoints as initial classification thresholds; the risk level determination stage submodule calls the compliance baseline database, calculates the deviation between the actual risk probability of the business link and the corresponding compliance threshold, and generates a baseline compliance index for each business link; combines historical risk event data to verify the initial classification threshold, optimizes the classification interval based on the risk disposal records in the business management data, and establishes an adaptive threshold adjustment mechanism to ensure that the classification results match the actual situation; comprehensively integrates the absolute risk probability score, baseline deviation degree and three-dimensional spatial mapping to locate the business link to the risk level matrix; the heat map generation submodule constructs a risk distribution map of the entire business life cycle based on the classification results, superimposes the effectiveness data of control measures, marks key risk shortboard areas, and verifies the accuracy of the classification through the actual warning effect of the business collaborative linkage component. The above solution, through the data preprocessing submodule, performs statistical analysis and probability distribution modeling of risk data, transforming unstructured risk data into quantifiable probabilistic indicators and implementing preliminary risk grading based on the natural breakpoint method. The risk level assessment submodule establishes a baseline compliance index system, dynamically monitoring compliance status by calculating the deviation between actual risk and compliance thresholds in real time. Combined with historical data validation and an adaptive adjustment mechanism, this ensures that risk grading standards are continuously optimized as business evolves. Three-dimensional spatial mapping technology is used to comprehensively calculate dimensions such as risk probability and baseline deviation, enabling precise positioning of business segments within the risk matrix and overcoming the limitations of traditional single-dimensional evaluation. The heat map generation submodule overlays control measure effectiveness data to visually demonstrate the matching of control measures with risk levels, identifying control weaknesses and providing a basis for optimal resource allocation. The accuracy of grading is verified through the actual early warning results of the business collaboration component, forming a closed-loop management process of "monitoring-alert-verification-optimization."

[0089] In summary, this embodiment implements full-process management from risk data collection, quantitative analysis, level determination to visual presentation, establishes a data-driven dynamic risk management system, and provides organizations with continuously optimized risk decision-making support tools.

[0090] Example 7: Figure 4 As shown, based on Example 1, the business collaboration linkage component provided by this embodiment of the present invention includes:

[0091] The risk feature mapping module is responsible for extracting core dimensional indicators from the risk assessment results based on the output intelligent assessment control matrix, including risk classification codes, grade scores, and temporal and spatial distribution characteristics. It also aligns these parameters with the interface specifications of the telecommunications business system and establishes a mapping relationship table between risk labels and business rules.

[0092] The dynamic threshold adaptation module is responsible for automatically matching the preset response strategy library based on the risk rating results in the intelligent assessment control matrix. The strategy library contains a set of trigger conditions corresponding to each risk level, including: Level 1 risk (high risk): triggering a real-time blocking strategy; Level 2 risk (medium risk): initiating an enhanced verification process; Level 3 risk (low risk): implementing behavior monitoring and tracking. Strategy parameters are dynamically adjusted based on the risk probability output by the assessment model.

[0093] The multi-dimensional warning distribution module is responsible for converting risk assessment results into three types of parallel outputs through the intelligent routing engine built into the business collaboration component:

[0094] Instruction-level output: Send standardized control instructions to core network elements, including risk disposal action codes and effective time windows;

[0095] Data-level output: Push feature vector update packages to the risk control knowledge base, including the behavioral pattern features extracted in this assessment;

[0096] Situation-level output: Push a visual risk map to the management terminal, marking risk hotspots and evolution trends.

[0097] The working principle and beneficial effects of the above technical solution are as follows: the risk feature mapping module of this embodiment extracts the core dimension indicators in the risk assessment results based on the output intelligent assessment control matrix, including risk classification code, grade score and time-space distribution characteristics and other parameters; the parameters are feature-aligned with the interface specifications of the telecommunications business system, and a mapping relationship table between risk labels and business rules is established; the dynamic threshold adaptation module automatically matches the preset response strategy library according to the risk rating results in the intelligent assessment control matrix; the strategy library contains a set of trigger conditions corresponding to each risk level, including: Level 1 risk (high risk): triggering real-time blocking strategy; Level 2 risk (high risk): triggering real-time blocking strategy; Level 3 risk (high risk): triggering real-time blocking strategy; Level 4 risk (high risk): triggering real-time blocking strategy; Level 5 risk (high risk): triggering real-time blocking strategy; Level 6 risk (high risk): triggering real-time blocking strategy; Level 7 risk (high risk): triggering real-time blocking strategy; Level 8 risk (high risk): triggering real-time blocking strategy; Level 9 risk (high risk): triggering real-time blocking strategy; Level 1 risk (high risk): triggering real-time blocking strategy; Level 1 risk (high risk): triggering real-time blocking strategy; Level 1 risk (high risk): triggering real-time blocking strategy; Level 1 risk (high risk): triggering real-time blocking strategy; Level 2 risk (high risk): triggering real-time blocking strategy; Level 1 risk (high risk): triggering real-time blocking strategy; Level 1 risk (high risk): triggering real-time blocking strategy; Level 2 risk (high risk): triggering real-time blocking strategy; Level 2 risk (high risk): triggering real-time blocking strategy; Level 1 ... Level 1 risk (medium): Initiate an enhanced verification process; Level 3 risk (low): Implement behavioral monitoring and tracking; Policy parameters dynamically adjust based on the risk probability output by the assessment model. The multi-dimensional warning distribution module, utilizing the intelligent routing engine built into the business collaboration component, converts risk assessment results into three parallel outputs: Instruction-level output: Send standardized control instructions to core network elements, including risk resolution action codes and effective time windows; Data-level output: Push feature vector updates containing behavioral pattern features extracted from the assessment to the risk control knowledge base; Situation-level output: Push a visual risk map to the management terminal, identifying risk hotspots and evolving trends. This solution ensures actionability of assessment results through feature mapping, maintains response accuracy through dynamic thresholds, achieves multi-dimensional prevention and control through multi-dimensional distribution, and ultimately achieves system self-optimization through a feedback mechanism. Each step strictly relies on the output of the preceding module. The control matrix generated by the assessment model construction component determines the boundaries of the warning strategy selection, and the execution performance of the business collaboration component in turn influences the subsequent parameter adjustments of the assessment model.

[0098] Obviously, those skilled in the art can make various changes and modifications to the present invention without departing from the spirit and scope of the present invention. Thus, if these modifications and variations of the present invention fall within the scope of the present invention's equivalent technologies, the present invention is also intended to include these modifications and variations.

Claims

1. A telecommunications fraud risk security assessment system based on a multimodal fusion model, characterized by: Include: The multi-source data acquisition component is responsible for acquiring original telecommunications service data through multiple channels, pre-processing the original telecommunications service data to obtain first telecommunications service data, performing feature extraction and behavior pattern analysis on the first telecommunications service data to obtain key features related to telecommunications services; The assessment model building component is responsible for building a fraud risk assessment model based on machine learning, inputting key features into the fraud risk assessment model, outputting an intelligent assessment control matrix, classifying and rating fraud risks, and generating risk assessment results; The business collaboration component is responsible for warning the telecommunications business system of its risk level based on the risk assessment results and taking preventive measures based on the risk level.

2. The telecommunications business fraud risk security assessment system based on a multimodal fusion model according to claim 1 is characterized in that: Multi-source data acquisition components, including: A preprocessing module is responsible for performing denoising, filling missing values, and preprocessing of the original telecommunication service data to unify the data format, thereby obtaining the first telecommunication service data; A data identification module is responsible for separating identifiable data from non-identifiable data from the first telecommunications service data, performing semantic analysis on the identifiable data, and identifying fraudulent keywords; Non-identifiable data is analyzed to extract key features; The classification processing module is responsible for inputting key features into the fraud risk assessment model, classifying fraud risks by fraud keywords, grouping users corresponding to identifiable data, and identifying abnormal groups.

3. The telecommunications business fraud risk security assessment system based on a multimodal fusion model according to claim 2, characterized in that: Identifiable data includes text message content and call recordings; non-identifiable data includes high-frequency calls, abnormal text message content and suspicious IP addresses.

4. The telecommunications business fraud risk security assessment system based on a multimodal fusion model according to claim 2, characterized in that: Data identification module, including: The identification program triggering submodule is responsible for receiving a data set to be analyzed consisting of the first telecommunications service data, and triggering a structured content identification program and an unstructured feature identification program when the data set to be analyzed completes preprocessing; The data type identification submodule is responsible for implementing the structured content identification program to perform parsability verification on data records containing clear semantic carriers, and through content feature detection, determine whether they conform to language expression specifications and mark them as recognizable data types; unstructured feature recognition detects communication frequency characteristics, analyzes network connection characteristics, identifies content distribution characteristics, and marks data records that do not have direct semantic expression but contain behavioral characteristics as non-recognizable data types; The data channel confirmation submodule is responsible for entering the corresponding data channel according to the recognition results of the structured content recognition program and the unstructured feature recognition program, extracting text semantics from the structured content, establishing a keyword matching rule library, performing context association analysis, and outputting a set of fraud keywords; Non-identifiable data, quantify communication frequency indicators, calculate network feature anomalies, model content distribution patterns, and output risk feature vectors; The output result association submodule is responsible for directly associating the identifiable data processing results with the subsequent risk level determination, and connecting the non-identifiable data processing results to the risk assessment model input layer. The classification identifiers of the two types of data are used as the basis parameters for user grouping.

5. The telecommunications business fraud risk security assessment system based on a multimodal fusion model according to claim 2, characterized in that: Classification processing module, including: The semantic feature extraction submodule is responsible for extracting semantic features based on the text messages and call recordings output by the data recognition module, screening out words or phrases with potential fraudulent associations and enhancing them based on contextual relevance. The keyword dynamic stratification submodule is responsible for dividing the extracted fraud keywords into a multi-layer structure based on risk intensity and behavior patterns; The risk classification mapping submodule is responsible for dynamically binding the stratified keywords to the user grouping rules in the classification processing module. If direct risk-layer keywords are detected in user data, the user is classified into the confirmed fraud group without the need for additional feature verification. If only indirect association layer keywords exist, they are weighted in combination with the features in the non-identifiable data to decide whether to classify them as suspected fraud-related or low-risk groups; environmental dependency layer keywords need to call the non-identifiable data analysis results in the data recognition module, and if there is a match, the classification level is upgraded.

6. The telecommunications business fraud risk security assessment system based on a multimodal fusion model according to claim 5, characterized in that: The multi-layered structure of the keyword dynamic layering submodule includes: the direct risk layer contains words that clearly indicate fraudulent activities, directly triggering high-risk classification; the indirect association layer contains words that are harmless in themselves, but when combined, they form fraudulent tactics, and the risk level is determined by co-occurrence frequency; The vocabulary risk of the environment-dependent layer depends on the communication behavior characteristics.

7. The telecommunications business fraud risk security assessment system based on a multimodal fusion model according to claim 1, characterized in that: Evaluation model building components, including: The multimodal feature fusion module is responsible for analyzing network traffic and abnormal connection patterns in network logs based on unstructured features, quantifying the deviation of user behavior, establishing a temporal behavior baseline based on dynamic behavior characteristics and abnormal user operation logs, and identifying sudden changes in behavior. Form a multimodal risk feature set through feature cross-validation; The model hierarchical training module is responsible for adopting a phased modeling strategy to output risk probability scores and risk classification labels; The control matrix building module is responsible for mapping risk assessment results into a matrix analysis framework, covering the entire business life cycle, comparing business data with compliance baselines, and quantifying the degree of deviation; Based on the output risk probability, the inherent risk level of the business link is divided; The output is a risk heat map, marking the risk level and control shortcomings of each business link.

8. The telecommunications business fraud risk security assessment system based on a multimodal fusion model according to claim 7, characterized in that: The phased modeling strategy of the model layer training module includes: the inherent risk identification layer trains the classification model based on the annotated data of historical fraud cases to distinguish high-risk behaviors from low-risk routine operations; the control measure compensation layer introduces business management data to evaluate the inhibitory effect of existing protective measures on inherent risks and dynamically adjust the risk weights; the residual risk prediction layer combines real-time data streams to optimize the model through incremental learning to identify potential risks not covered by existing control measures; and outputs risk probability scores and risk classification labels.

9. The telecommunications business fraud risk security assessment system based on a multimodal fusion model according to claim 8, characterized in that: Control matrix building blocks, including: The data preprocessing submodule is responsible for receiving the risk probability score dataset output by the model hierarchical training module, performing statistical analysis on the risk probability distribution, calculating the probability mean, variance, and extreme value ratio of each business link, establishing a probability distribution histogram, and identifying natural breakpoints as initial classification thresholds; The sub-module of the risk level determination stage is responsible for adjusting the absolute score of the comprehensive risk probability, the degree of baseline deviation, and the three-dimensional spatial mapping to locate the business link in the risk level matrix; The heat map generation sub-module is responsible for constructing a risk distribution map for the entire business life cycle based on the grading results, superimposing the effectiveness data of control measures, marking key risk shortcoming areas, and verifying the accuracy of the grading through the actual early warning effects of the business collaborative linkage components.

10. The telecommunication business fraud risk security assessment system based on a multimodal fusion model according to claim 1, characterized in that: Business collaboration components include: The risk feature mapping module is responsible for extracting core dimensional indicators from the risk assessment results based on the output intelligent assessment control matrix, including risk classification codes, grade scores, and temporal and spatial distribution characteristic parameters. It also aligns the parameters with the interface specifications of the telecommunications business system and establishes a mapping relationship table between risk labels and business rules. The dynamic threshold adaptation module is responsible for automatically matching the preset response strategy library based on the risk rating results in the intelligent assessment control matrix; the strategy library contains a set of trigger conditions corresponding to each risk level; The multi-dimensional early warning distribution module is responsible for converting risk assessment results into three types of parallel outputs through the intelligent routing engine built into the business collaboration component.

Citation Information

Patent Citations

  • Fraud-related risk monitoring method and device, equipment and storage medium

    CN118172155A

  • Training method and system for multimodal feature vector embedder of fraudulent APP

    CN119293760B

  • Bank fraud account prediction method and device based on relationship learning

    CN119762204A

Cited By

  • Squeezing risk assessment device and method

    CN120809241A

  • Purchase bid opening and evaluation risk labeling method based on supply chain cooperative processing

    CN120851032A

  • Risk dynamic processing method and device in real-time communication scene, equipment and medium

    CN121151505A

  • Method, apparatus and device for risk dynamic processing in real-time communication scenario and medium

    CN121151505B

  • Coal mine coal bunker source control anti-blocking and anti-collapse integrated intelligent system fused with big data analysis

    CN121211132A