Group fraud identification method and device, equipment, storage medium and product
By building a community network and conducting star ring detection to identify group fraud, the problem of low efficiency of insurance companies in group fraud identification is solved, and efficient group fraud identification is achieved.
Patent Information
- Application Number
- CN202510659437.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-21
- Publication Date
- 2025-09-26
AI Technical Summary
When identifying group fraud, insurance companies rely on set rules and the experience of anti-fraud personnel, resulting in inefficient identification.
By obtaining fraud-related data, building a community network, conducting star ring detection, identifying gang fraud, and using the star ring network structure to characterize the structural characteristics of nodes in gang fraud, gang fraud can be identified.
It improves the efficiency and accuracy of gang fraud identification and reduces investigation costs.
Smart Images

Figure CN120707307A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of fraud identification technology, and in particular to a method, device, equipment, storage medium and product for identifying gang fraud. Background Art
[0002] When identifying auto insurance fraud, insurance companies typically rely on set rules and the experience of anti-fraud personnel to identify fraudulent behavior. However, when faced with gang fraud, since gang fraud usually involves multi-faceted collaboration and disguise, the amount of data required to identify gang fraud is huge. Relying solely on set rules and the experience of anti-fraud personnel to identify fraudulent behavior and complex gang fraud will lead to inefficient identification of gang fraud. Summary of the Invention
[0003] The main purpose of this application is to provide a method, device, equipment, storage medium and product for identifying gang fraud, aiming to solve the technical problem of low efficiency in identifying gang fraud.
[0004] To achieve the above objectives, this application proposes a method for identifying gang fraud, which includes:
[0005] Acquiring fraud-related data, wherein the fraud-related data includes at least one of underwriting data, claims data, and external data;
[0006] A community network is obtained, and a star ring detection is performed on each community in the community network to obtain a star ring network structure. Based on the star ring network structure, gang fraud is identified, wherein the star ring network structure represents the structural characteristics of nodes in gang fraud, and the community network is constructed based on associated nodes between fraud-related information.
[0007] In one embodiment, the step of obtaining a community network, performing a star ring detection on each community in the community network to obtain a star ring network structure, and identifying gang fraud based on the star ring network structure includes:
[0008] Acquiring fraud-related data, wherein the fraud-related data includes at least one of underwriting data, claims data, and external data;
[0009] Based on the fraud-related data, a node association network is constructed, wherein the node association network represents the association relationship between the vehicle, the person, the case, the phone number, the repair shop, and the payment account;
[0010] Clustering the nodes in the node association network that meet a merging gain threshold to obtain a clustered community network, wherein the merging gain represents the closeness of the nodes in the community.
[0011] In one embodiment, the star ring network structure includes a star network structure and a ring network structure, and the step of performing star ring detection on each community in the community network to obtain the star ring network structure includes:
[0012] Traversing all nodes of each community in the community network, and taking the traversed nodes as target nodes;
[0013] Determining a ring network structure based on label information in a storage container corresponding to the target node;
[0014] Based on the node type corresponding to the target node, a star network structure is determined.
[0015] In one embodiment, the step of determining the ring network structure based on the label information in the storage container corresponding to the target node includes:
[0016] Determining whether the target node receives the label information;
[0017] If the target node does not receive the label information, storing the label information corresponding to the target node in a storage container corresponding to the target node, wherein the label information is a unique identifier representing the target node;
[0018] If the target node receives the label information, the label information of the target node is spliced after the received label information, and the spliced label information is stored in the storage container;
[0019] A ring network structure is determined based on the tag information in the storage container.
[0020] In one embodiment, the step of determining the ring network structure based on the label information in the storage container includes:
[0021] Determine whether the start tag and the end tag of the tag information are consistent;
[0022] If the start label is consistent with the end label, determining a ring network structure based on the nodes corresponding to the label information;
[0023] If the starting label is inconsistent with the ending label, the label information is sent to the adjacent node connected to the target node, and the remaining nodes are traversed until the starting label of the label information in the storage container corresponding to the target node is consistent with the ending label. Based on the label information of the target node where the starting label is consistent with the ending label, the ring network structure is determined.
[0024] In one embodiment, the step of determining the star network structure based on the node type corresponding to the target node includes:
[0025] Determine whether the node type corresponding to the target node is the target type;
[0026] If the node type is the target type, traverse the adjacent nodes connected to the target node to determine whether the node type corresponding to the adjacent node is a case node;
[0027] If the adjacent node is the case node, determining whether the occurrence time of the case node is within a preset time based on the node attribute information of the adjacent node connected to the target node;
[0028] If the occurrence time is within the preset time, the case node is recorded;
[0029] It is determined whether the number of the recorded case nodes is greater than a threshold; if the number is greater than the threshold, a star network structure is determined based on the target node and the adjacent nodes.
[0030] In addition, to achieve the above-mentioned purpose, the present application also proposes a gang fraud identification device, which includes:
[0031] The detection module is used to obtain a community network, perform star ring detection on each community in the community network to obtain a star ring network structure, and identify gang fraud based on the star ring network structure, wherein the star ring network structure represents the structural characteristics of nodes in gang fraud, and the community network is constructed based on the associated nodes between fraud-related information.
[0032] In addition, to achieve the above-mentioned purpose, the present application also proposes a gang fraud identification device, which includes: a memory, a processor, and a computer program stored on the memory and runnable on the processor, and the computer program is configured to implement the steps of the gang fraud identification method described above.
[0033] In addition, to achieve the above-mentioned purpose, the present application also proposes a storage medium, which is a computer-readable storage medium. A computer program is stored on the storage medium, and when the computer program is executed by the processor, the steps of the gang fraud identification method described above are implemented.
[0034] In addition, to achieve the above-mentioned purpose, the present application also provides a computer program product, which includes a computer program, and when the computer program is executed by a processor, it implements the steps of the gang fraud identification method as described above.
[0035] One or more technical solutions proposed in this application have at least the following technical effects:
[0036] Compared with the identification of group fraud, which requires processing huge amounts of data and relies solely on set rules and the experience of anti-fraud personnel to identify fraudulent behavior and complex group fraud, resulting in low efficiency in identifying group fraud, the present application obtains a community network, performs star ring detection on each community in the community network, obtains a star ring network structure, and identifies group fraud based on the star ring network structure, wherein the star ring network structure represents the structural characteristics of nodes in group fraud, and the community network is constructed based on the associated nodes between fraud-related information. It can be understood that the present application identifies the star ring network structure that represents the structural characteristics of nodes in group fraud in each community through the community network constructed based on the associated nodes between fraud-related information, and identifies group fraud, thereby solving the problem that relying solely on set rules and the experience of anti-fraud personnel to identify fraudulent behavior and complex group fraud will lead to low efficiency in identifying group fraud. BRIEF DESCRIPTION OF THE DRAWINGS
[0037] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the present application and, together with the description, serve to explain the principles of the present application.
[0038] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, for ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.
[0039] Figure 1 This is a ring network structure diagram of the gang fraud identification method of this application;
[0040] Figure 2 A flowchart for determining the ring network structure of the gang fraud identification method of this application;
[0041] Figure 3 This is a star network structure diagram of the gang fraud identification method of this application;
[0042] Figure 4 A flow chart for determining the star network structure of the gang fraud identification method of this application;
[0043] Figure 5 and Figure 6 A schematic diagram of the ring network structure of the gang fraud identification method of this application;
[0044] Figure 7 A flowchart of the second embodiment of the method for identifying group fraud provided in this application;
[0045] Figure 8 This is a schematic diagram of the module structure of the gang fraud identification device according to an embodiment of the present application;
[0046] Figure 9 Schematic diagram of the device structure of the hardware operating environment involved in the gang fraud identification method in the embodiment of the present application.
[0047] The purpose, features and advantages of this application will be further explained in conjunction with the embodiments and with reference to the accompanying drawings. DETAILED DESCRIPTION
[0048] It should be understood that the specific embodiments described herein are merely used to explain the technical solutions of the present application and are not intended to limit the present application.
[0049] In order to better understand the technical solution of the present application, a detailed description will be given below in conjunction with the accompanying drawings and specific implementation methods.
[0050] The main solution of the embodiment of the present application is: obtaining a community network, performing star ring detection on each community in the community network to obtain a star ring network structure, and identifying gang fraud based on the star ring network structure, wherein the star ring network structure represents the structural characteristics of nodes in gang fraud, and the community network is constructed based on the associated nodes between fraud-related information.
[0051] When identifying auto insurance fraud, insurance companies typically rely on set rules and the experience of anti-fraud personnel to identify fraudulent behavior. However, when faced with gang fraud, since gang fraud usually involves multi-faceted collaboration and disguise, the amount of data required to identify gang fraud is huge. Relying solely on set rules and the experience of anti-fraud personnel to identify fraudulent behavior and complex gang fraud will lead to inefficient identification of gang fraud.
[0052] This application identifies gang fraud by building a community network based on the associated nodes between fraud-related information, identifying the star ring network structure that represents the structural characteristics of nodes in gang fraud in each community, and solving the problem of low efficiency in identifying complex gang fraud by relying solely on set rules and the experience of anti-fraud personnel to identify fraudulent behavior.
[0053] It should be noted that the execution entity of this embodiment may be a computing service device with data processing, network communication, and program execution capabilities, such as a tablet computer, personal computer, or mobile phone, or an electronic device capable of performing the aforementioned functions, such as a gang fraud detection device. This embodiment and the following embodiments will be described below using the gang fraud detection device as an example.
[0054] Based on this, an embodiment of the present application provides a method for identifying gang fraud. In this embodiment, the method for identifying gang fraud includes step S100:
[0055] Step S100: Acquire a community network, perform star ring detection on each community in the community network to obtain a star ring network structure, and identify gang fraud based on the star ring network structure, wherein the star ring network structure represents the structural characteristics of nodes in gang fraud, and the community network is constructed based on associated nodes between fraud-related information.
[0056] It should be noted that the executor of this embodiment is the gang fraud identification device. When fraud gangs use a two-on-one collision method to commit crimes, a closed ring structure will be formed in the associated network. If the fraud activity is dominated by a single party, it will appear in the network diagram as a star structure with a central node (such as vehicle A) connected to multiple other nodes (such as vehicles B and C). Therefore, the gang fraud identification device can accurately identify this star-ring network structure, thereby revealing hidden fraud patterns. This layout can be deeply analyzed using the star network structure detection algorithm to help identify the core of the fraud and its scope of influence.
[0057] It is understandable that the gang fraud identification device can identify high-risk groups that may be involved in gang fraud by performing star ring detection on each community in the community network, and then further identify gang fraud through information in the star ring network structure.
[0058] In a feasible implementation, a community network is obtained, and a star ring detection is performed on each community in the community network to obtain a star ring network structure. Based on the star ring network structure, the step of identifying gang fraud includes:
[0059] Acquiring fraud-related data, wherein the fraud-related data includes at least one of underwriting data, claims data, and external data;
[0060] It should be noted that the implementation entity of this embodiment is the group fraud identification device. Insurance data includes information about the policyholder and the insured vehicle. Claims information includes information about the auto insurance case. External information includes the policyholder's insurance information from other insurance companies.
[0061] It is understandable that the gang fraud identification device obtains fraud-related data including at least one of underwriting data, claim data and external data.
[0062] Furthermore, after obtaining fraud-related data, the gang fraud identification device will perform data cleaning on the fraud-related data in order to clean out fraud-related data stored in format problems, such as incorrect or irregular digits in the ID card number, inaccurate digits and format of the telephone number, disordered formats of the license plate and frame number, the same ID card number but different names, and repeated data entries. After data cleaning, it can avoid the subsequent identification of the StarRing network structure, which may cause serious interference and misleading of the identification process by erroneous data, resulting in deviations in the identification results.
[0063] Based on the fraud-related data, a node association network is constructed, wherein the node association network represents the association relationship between the vehicle, the person, the case, the phone number, the repair shop, and the payment account;
[0064] It should be noted that the gang fraud identification device uses multiple elements in the fraud-related data, namely cars, people, cases, telephones, repair shops and collection accounts as nodes in the node association network, and uses the correlation between the above nodes to build connecting edges between each node, thereby forming a complete node association network with an undirected graph structure, and using the relevant information of each node as the attribute information of the node.
[0065] Furthermore, the specific definition of each node is as follows:
[0066] Vehicle: includes the target vehicle (the insured vehicle) and third-party vehicles (third-party vehicles involved in the traffic accident). Each vehicle is an independent node that contains attribute information such as license plate number, vehicle frame number (VIN) and vehicle model.
[0067] People: covers the insured, beneficiaries and injured persons; each person is a node, which contains attribute information such as name, ID number and contact information.
[0068] Case: Each insurance case is a node, which contains attribute information such as case number, occurrence time and loss description.
[0069] Phone: Each phone number is a node and may be associated with one person or multiple cases as part of the contact information.
[0070] Repair shop: The repair shop involved in the repair work is regarded as a node, which contains attribute information such as name, address and contact information.
[0071] Receiving account: The bank account used to receive compensation serves as a node, containing information such as the account holder's name and bank account number.
[0072] Furthermore, the connection rules of undirected edges in the node association network are as follows:
[0073] Between vehicles and cases: Establish connections based on accident or loss situations, such as which vehicle is involved in which case.
[0074] Between people and cars: connections are established through ownership, driving relationships, etc., for example, a person is the owner or driver of a car.
[0075] Between cases and persons: Determine who is the policyholder, beneficiary or victim in the case.
[0076] Between phone and person: reflects the ownership of the phone number, that is, which phone belongs to which person.
[0077] Between the receiving account and the person: Indicates the identity of the account holder, that is, which account belongs to which person.
[0078] Between repair shops and cars: Establish associations based on repair services, such as which car was repaired at which repair shop.
[0079] Clustering the nodes that meet a merging gain threshold in the node association network to obtain a clustered community network, wherein the merging gain represents the closeness of the nodes in the community;
[0080] It is understandable that the preferred value of the merge gain threshold is 0.00001. This threshold is used to evaluate the gain change brought about by the merger of nodes into the community. If the merger gain is lower than this threshold, the current community structure is considered to be stable enough and no further merger is required; conversely, if the gain exceeds the threshold, a community merger operation is performed to form a tighter community structure.
[0081] It should be noted that the gang fraud identification device uses the Louvain algorithm in the associated network. This algorithm has the characteristics of low average time complexity and fast calculation speed, and is suitable for large-scale network analysis. The Louvain algorithm will try to assign each node to the community that can bring the maximum modularity gain. By comparing the modularity gain before and after each merger, it decides whether to merge the community. Ultimately, several community units with close internal relationships are obtained, and a unique identification number is assigned to each community. By analyzing the relationship chain between information nodes involving people, vehicles and cases, those nodes that are closely connected to each other can be classified into the same community; this method is based on community discovery algorithms (such as the Louvain algorithm) and can effectively identify potential fraud groups.
[0082] Furthermore, the more finely the community is divided by the Louvain algorithm, the higher the degree of node association within each community. This provides a clearer target group for subsequent StarRing network structure detection, improving detection efficiency and accuracy.
[0083] Furthermore, the gang fraud identification device is also equipped with a maximum number of iterations, which can be set to 30. This limits the maximum number of iterations of the algorithm to ensure that the algorithm does not execute in an infinite loop while giving enough time to find a better solution. In each round of iteration, the algorithm will try to assign each node to the community that can bring the maximum modularity gain. When all possible mergers cannot make the modularity gain exceed the set threshold, the algorithm stops iterating.
[0084] Furthermore, when the group fraud identification device receives new fraud-related information, it is necessary to update the current community network and identify the star ring network structure based on the updated community network, thereby improving the timeliness and accuracy of group fraud identification.
[0085] In a feasible implementation, the step of performing star ring detection on each community in the community network to obtain a star ring network structure includes:
[0086] Traversing all nodes of each community in the community network, and taking the traversed nodes as target nodes;
[0087] It can be understood that the gang fraud identification device obtains the complete structure of the community network, including all communities and their internal nodes and edges. For each community, it obtains the set of all nodes in the community and traverses the node set. During each traversal, the traversed node is marked as the target node.
[0088] Furthermore, in the community network analysis, filtering out nodes that may lead to erroneous results (such as group individual or specific institution nodes) by the gang fraud identification device is a key step to ensure the accuracy and effectiveness of subsequent analysis.
[0089] Specifically, the node types that need to be filtered are as follows:
[0090] Group single person: a personal node for special roles such as the reporter or agent.
[0091] Specific institutions: Institutional nodes with high-frequency interactions, such as taxi companies and rental companies.
[0092] Other abnormal nodes: nodes with abnormally high connectivity or whose behavior patterns do not conform to normal rules.
[0093] Determining a ring network structure based on information in a storage container corresponding to the target node;
[0094] It should be noted that the key role of the ring network structure is to identify fraud gangs that use the method of mutual collision. Since fraud gangs create false collision accidents with each other, the entire associated network eventually presents a ring network structure feature, for example Figure 1 , Figure 1A ring network structure diagram is provided. The gang fraud identification device determines the ring network structure in the community based on the information in the storage container corresponding to each target node, referring to Figure 2 , Figure 2 A flow chart for determining the ring network structure is provided.
[0095] Based on the node type corresponding to the target node, a star network structure is determined.
[0096] It is understandable that the key role of the star network structure is to identify a network pattern with multiple edges radiating from a certain node, because fraud gangs usually carry out activities around a core node (such as the mastermind's vehicle or personnel), forming a typical star network structure, such as Figure 3 As shown, Figure 3 Provides a star network structure diagram. The gang fraud identification device determines the star network structure based on the node type of the target node, refer to Figure 4 , Figure 4 A flow chart for determining the star network structure is provided.
[0097] In a feasible implementation, the step of determining the ring network structure based on the label information in the storage container corresponding to the target node includes:
[0098] Determining whether the target node receives the label information;
[0099] It should be noted that the tag information provides a unique identifier (ID) for each node, which is used to distinguish different nodes in the associated network. The gang fraud identification device will determine whether the target node traversed has received any tag information.
[0100] If the target node does not receive the label information, storing the label information corresponding to the target node in a storage container corresponding to the target node, wherein the label information is a unique identifier representing the target node;
[0101] It is understandable that if the gang fraud identification device determines that the target node has not received any label information, it uses its own unique identifier as the initial label and stores it in the storage container of the target node.
[0102] If the target node receives the label information, the label information of the target node is spliced after the received label information, and the spliced label information is stored in the storage container;
[0103] It should be noted that if the gang fraud identification device determines that the target node has received the label information, it will splice the unique identifier of the target node to the received label information and store the updated label information in the storage container.
[0104] A ring network structure is determined based on the tag information in the storage container.
[0105] It can be understood that the storage container of each node records the path from a certain starting node to the node (stored in the form of a node ID list), so the gang fraud identification device can determine the ring network structure through the label information in the storage container of the target node.
[0106] In a feasible implementation manner, the step of determining the ring network structure based on the label information in the storage container includes:
[0107] Determine whether the start tag and the end tag of the tag information are consistent;
[0108] It should be noted that the gang fraud identification device determines whether the starting label and the ending label of the label information in the storage container of each traversed node are consistent.
[0109] If the start label is consistent with the end label, determining a ring network structure based on the nodes corresponding to the label information;
[0110] It is understandable that if the gang fraud identification device determines that the starting label and the ending label of the obtained label information are consistent, it means that a closed loop path is found, and the ring network structure is determined based on the nodes on this path.
[0111] If the starting label is inconsistent with the ending label, the label information is sent to the adjacent node connected to the target node, and the remaining nodes are traversed until the starting label of the label information in the storage container corresponding to the target node is consistent with the ending label. Based on the label information of the target node where the starting label is consistent with the ending label, the ring network structure is determined.
[0112] It should be noted that if the gang fraud identification device determines that the starting label and the ending label are inconsistent, it will send the label information to all neighboring nodes of the current node and continue to traverse the remaining nodes until it detects that the starting label of the label information in the storage container of the currently traversed node is consistent with the ending label, and then determine the ring network structure. Figure 5 and Figure 6 , Figure 5 and Figure 6 A schematic diagram of the ring network structure is provided.
[0113] In this embodiment, the gang fraud identification device uses information such as vehicles, cases and people to identify the star ring network structure, and then identify gang fraud, thereby improving investigation efficiency and reducing investigation costs.
[0114] Based on the first embodiment of the present application, in the second embodiment of the present application, the same or similar contents as those in the above embodiment 1 can be referred to the above introduction and will not be described in detail later. Figure 7 The gang fraud identification method further includes steps S01 to S05, wherein the step of determining the star network structure based on the node type corresponding to the target node is as follows:
[0115] Step S01, determining whether the node type corresponding to the target node is the target type;
[0116] It is understandable that the target type can be a car type. As can be seen from step S200, each target node has corresponding attribute information, so the gang fraud identification device can determine whether the node type of the target node is a car type based on the attribute information of the target node.
[0117] Step S02: If the node type is the target type, traverse the adjacent nodes connected to the target node to determine whether the node type corresponding to the adjacent node is a case node;
[0118] It can be understood that if the gang fraud identification device determines that the node type of the target node is a car type, it obtains all neighbor nodes of the target node and traverses these neighbor nodes to check whether their type is a "case node".
[0119] Step S03: If the adjacent node is the case node, then based on the node attribute information of the adjacent nodes connected to the target node, determine whether the occurrence time of the case node is within a preset time;
[0120] It should be noted that the preset time period can be set to 6 months. Only nodes with frequent accidents within a short period of time are analyzed. This can avoid misidentifying normal accident nodes as star-shaped nodes due to a long time span. If the gang fraud identification device determines that an adjacent node is a case node, for each case node, the occurrence time is checked to see if it falls within the preset time window (e.g., within 6 months).
[0121] Step S04: if the occurrence time is within the preset time, record the case node;
[0122] It is understandable that if the gang fraud identification device determines that the occurrence time of the case node meets the requirements, it will record the case node. If it does not meet the requirements, it will skip the node and continue to traverse the next neighbor node.
[0123] Step S05 , determining whether the number of the recorded case nodes is greater than a threshold; if the number is greater than the threshold, determining a star network structure based on the target node and the adjacent nodes.
[0124] It should be noted that the threshold can be set to 3. The gang fraud identification device counts the number of eligible case nodes connected to the current target node. If the number of recorded case nodes is greater than a preset threshold (such as 3), the target node and its connected case nodes are marked as a star network structure.
[0125] In this embodiment, the star structure in the community network can be efficiently identified through strict node type judgment, time window filtering and quantity threshold verification.
[0126] It should be noted that the above examples are only used to understand this application and do not constitute a limitation on the gang fraud identification method of this application. More simple transformations based on this technical concept are all within the scope of protection of this application.
[0127] This application also provides a gang fraud identification device, please refer to Figure 8 , the gang fraud identification device includes:
[0128] Detection module 10 obtains a community network, performs star ring detection on each community in the community network, obtains a star ring network structure, and identifies gang fraud based on the star ring network structure, wherein the star ring network structure represents the structural characteristics of nodes in gang fraud, and the community network is constructed based on the associated nodes between fraud-related information.
[0129] Optionally, the detection module includes:
[0130] The clustering submodule is configured to obtain fraud-related data, wherein the fraud-related data includes at least one of underwriting data, claims data, and external data; construct a node association network based on the fraud-related data, wherein the node association network represents the association between vehicles, people, cases, telephone numbers, repair shops, and collection accounts; and cluster nodes in the node association network that meet a merge gain threshold to obtain a clustered community network, wherein the merge gain represents the closeness of nodes within the community.
[0131] Optionally, the detection module includes:
[0132] The traversal submodule is used to traverse all nodes of each community in the community network and use the traversed node as the target node; determine the ring network structure based on the label information in the storage container corresponding to the target node; and determine the star network structure based on the node type corresponding to the target node.
[0133] Optionally, the traversal submodule includes:
[0134] A ring determination unit is used to determine whether the target node has received the label information; if the target node has not received the label information, the label information corresponding to the target node is stored in a storage container corresponding to the target node, wherein the label information is a unique identifier representing the target node; if the target node has received the label information, the label information of the target node is spliced after the received label information, and the spliced label information is stored in the storage container; based on the label information in the storage container, a ring network structure is determined.
[0135] A star determination unit is used to determine whether the node type corresponding to the target node is the target type; if the node type is the target type, traverse the adjacent nodes connected to the target node to determine whether the node type corresponding to the adjacent nodes is a case node; if the adjacent node is the case node, determine whether the occurrence time of the case node is within a preset time based on the node attribute information of the adjacent nodes connected to the target node; if the occurrence time is within the preset time, record the case node; determine whether the number of recorded case nodes is greater than a threshold value, and if the number is greater than the threshold value, determine a star network structure based on the target node and the adjacent nodes.
[0136] Optionally, the ring determination unit includes:
[0137] The consistency judgment subunit is used to judge whether the starting label and the ending label of the label information are consistent; if the starting label and the ending label are consistent, the ring network structure is determined based on the node corresponding to the label information; if the starting label and the ending label are inconsistent, the label information is sent to the adjacent node connected to the target node, and the remaining nodes are continued to be traversed until the starting label and the ending label of the label information in the storage container corresponding to the target node are consistent, and the ring network structure is determined based on the label information of the target node whose starting label and the ending label are consistent.
[0138] The gang fraud identification device provided in this application utilizes the gang fraud identification method described in the aforementioned embodiments to address the technical challenges of gang fraud identification. Compared to the prior art, the gang fraud identification device provided in this application achieves the same beneficial effects as the gang fraud identification method described in the aforementioned embodiments. Other technical features of the gang fraud identification device are the same as those disclosed in the aforementioned embodiments and are not further elaborated here.
[0139] The present application provides a gang fraud identification device, which includes: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions that can be executed by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to execute the gang fraud identification method in the above-mentioned embodiment one.
[0140] Reference below Figure 9 , which shows a schematic diagram of the structure of a gang fraud identification device suitable for implementing the embodiments of the present application. The gang fraud identification device in the embodiments of the present application may include, but is not limited to, mobile terminals such as mobile phones, laptops, tablet computers, digital broadcast receivers, PDAs (Personal Digital Assistants), PMPs (Portable Media Players), and in-vehicle terminals (such as in-vehicle navigation terminals), as well as fixed terminals such as digital TVs and desktop computers. Figure 9 The gang fraud identification device shown is merely an example and should not impose any limitations on the functions and scope of use of the embodiments of the present application.
[0141] like Figure 9 As shown, the gang fraud identification device may include a processing device 1001 (e.g., a central processing unit, graphics processing unit, etc.), which can perform various appropriate actions and processes based on programs stored in a read-only memory (ROM) 1002 or programs loaded from a storage device 1003 into a random access memory (RAM) 1004. RAM 1004 also stores various programs and data required for the operation of the gang fraud identification device. Processing device 1001, ROM 1002, and RAM 1004 are interconnected via a bus 1005. An input / output (I / O) interface 1006 is also connected to the bus. Typically, the following systems may be connected to I / O interface 1006: input devices 1007, such as a touchscreen, touchpad, keyboard, mouse, image sensor, microphone, accelerometer, gyroscope, etc.; output devices 1008, such as a liquid crystal display (LCD), speaker, vibrator, etc.; storage device 1003, such as a magnetic tape or hard disk; and communication device 1009. The communication device 1009 can allow the gang fraud identification device to communicate wirelessly or wired with other devices to exchange data. Although the figure shows a gang fraud identification device with various systems, it should be understood that it is not required to implement or have all of the systems shown. More or fewer systems may be implemented or provided instead.
[0142] In particular, according to the embodiments disclosed in the present application, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, the embodiments disclosed in the present application include a computer program product comprising a computer program carried on a computer-readable medium, the computer program comprising program code for executing the method shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from a network via a communication device, or installed from a storage device 1003, or installed from a ROM 1002. When the computer program is executed by the processing device 1001, the above-mentioned functions defined in the method of the embodiment disclosed in the present application are executed.
[0143] The gang fraud identification device provided in this application utilizes the gang fraud identification method described in the aforementioned embodiment to address the technical issues surrounding gang fraud identification. Compared to the prior art, the beneficial effects of the gang fraud identification device provided in this application are the same as those of the gang fraud identification method described in the aforementioned embodiment. Other technical features of the gang fraud identification device are the same as those disclosed in the aforementioned embodiment and are not further elaborated here.
[0144] It should be understood that the various parts disclosed in this application can be implemented using hardware, software, firmware, or a combination thereof. In the description of the above embodiments, specific features, structures, materials, or characteristics can be combined in any one or more embodiments or examples in a suitable manner.
[0145] The above description is merely a specific embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in this application should be included in the scope of protection of this application. Therefore, the scope of protection of this application should be based on the scope of protection of the claims.
[0146] The present application provides a computer-readable storage medium having computer-readable program instructions (ie, computer programs) stored thereon, and the computer-readable program instructions are used to execute the gang fraud identification method in the above-mentioned embodiment.
[0147] The computer-readable storage medium provided in this application may be, for example, a USB flash drive, but is not limited to electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems, systems or devices, or any combination thereof. More specific examples of computer-readable storage media may include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination thereof. In this embodiment, the computer-readable storage medium may be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, system or device. The program code contained on the computer-readable storage medium may be transmitted using any appropriate medium, including but not limited to: wires, optical cables, RF (Radio Frequency), etc., or any suitable combination thereof.
[0148] The computer-readable storage medium may be included in the gang fraud identification device; or it may exist independently without being assembled into the gang fraud identification device.
[0149] The computer-readable storage medium carries one or more programs, which, when executed by the gang fraud identification device, cause the gang fraud identification device to: obtain fraud-related data, wherein the fraud-related data includes at least one of underwriting data, claims data, and external data;
[0150] Based on the fraud-related data, a node association network is constructed, wherein the node association network represents the association between vehicles, people, cases, telephones, repair shops, and collection accounts; nodes in the node association network that meet a merging gain threshold are clustered to obtain a clustered community network, wherein the merging gain represents the closeness of nodes in the community; star ring detection is performed on each community in the community network to obtain a star ring network structure; based on the star ring network structure, gang fraud is identified, wherein the star ring network structure represents the structural characteristics of nodes in gang fraud, and the star ring network structure includes a star network structure and a ring network structure.
[0151] Computer program code for performing the operations of the present application may be written in one or more programming languages, or a combination thereof, including object-oriented programming languages such as Java, Smalltalk, C++, and conventional procedural programming languages such as "C" or similar programming languages. The program code may be executed entirely on the user's computer, partially on the user's computer, as a stand-alone software package, partially on the user's computer and partially on a remote computer, or entirely on the remote computer or server. In cases involving a remote computer, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., through the Internet using an Internet service provider).
[0152] The flow charts and block diagrams in the accompanying drawings illustrate the possible architecture, functions and operations of the systems, methods and computer program products according to various embodiments of the present application. In this regard, each box in the flow chart or block diagram can represent a module, program segment or a part of code, and the module, program segment or a part of code contains one or more executable instructions for realizing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in a different order than that marked in the accompanying drawings. For example, two boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram and / or flow chart, and the combination of the boxes in the block diagram and / or flow chart can be implemented by a dedicated hardware-based system that performs the specified function or operation, or can be implemented by a combination of dedicated hardware and computer instructions.
[0153] The modules described in the embodiments of the present application may be implemented in software or hardware, wherein the name of a module does not necessarily limit the unit itself.
[0154] The computer-readable storage medium provided in this application stores computer-readable program instructions (i.e., a computer program) for executing the aforementioned method for identifying group fraud, thereby resolving the technical problem of identifying group fraud. Compared to the prior art, the beneficial effects of the computer-readable storage medium provided in this application are the same as those of the method for identifying group fraud provided in the aforementioned embodiments, and are not further elaborated here.
[0155] The present application also provides a computer program product, including a computer program, which implements the steps of the above-mentioned gang fraud identification method when executed by a processor.
[0156] The computer program product provided in this application can solve the technical problem of gang fraud identification. Compared with the existing technology, the beneficial effects of the computer program product provided in this application are the same as the beneficial effects of the gang fraud identification method provided in the above embodiment, and will not be repeated here.
[0157] The above description is only part of the embodiments of the present application and does not limit the patent scope of the present application. All equivalent structural transformations made by using the contents of the present application specification and drawings under the technical concept of the present application, or direct / indirect application in other related technical fields are included in the patent protection scope of the present application.
Claims
1. A method for identifying gang fraud, characterized in that: The gang fraud identification method includes: A community network is obtained, and a star ring detection is performed on each community in the community network to obtain a star ring network structure. Based on the star ring network structure, gang fraud is identified, wherein the star ring network structure represents the structural characteristics of nodes in gang fraud, and the community network is constructed based on associated nodes between fraud-related information.
2. The method for identifying gang fraud according to claim 1, wherein: The steps of obtaining a community network, performing a star ring detection on each community in the community network to obtain a star ring network structure, and identifying gang fraud based on the star ring network structure include: Acquiring fraud-related data, wherein the fraud-related data includes at least one of underwriting data, claims data, and external data; Based on the fraud-related data, a node association network is constructed, wherein the node association network represents the association relationship between the vehicle, the person, the case, the phone number, the repair shop, and the payment account; Clustering the nodes in the node association network that meet a merging gain threshold to obtain a clustered community network, wherein the merging gain represents the closeness of the nodes in the community.
3. The method for identifying gang fraud according to claim 1, wherein: The star ring network structure includes a star network structure and a ring network structure. The step of performing star ring detection on each community in the community network to obtain the star ring network structure includes: Traversing all nodes of each community in the community network, and taking the traversed nodes as target nodes; Determining a ring network structure based on information in a storage container corresponding to the target node; Based on the node type corresponding to the target node, a star network structure is determined.
4. The method for identifying gang fraud according to claim 3, wherein: The step of determining the ring network structure based on the information in the storage container corresponding to the target node includes: Determining whether the target node receives the label information; If the target node does not receive the label information, storing the label information corresponding to the target node in a storage container corresponding to the target node, wherein the label information is a unique identifier representing the target node; If the target node receives the label information, the label information of the target node is spliced after the received label information, and the spliced label information is stored in the storage container; A ring network structure is determined based on the tag information in the storage container.
5. The method for identifying gang fraud according to claim 4, wherein: The step of determining the ring network structure based on the label information in the storage container includes: Determine whether the start tag and the end tag of the tag information are consistent; If the start label is consistent with the end label, determining a ring network structure based on the nodes corresponding to the label information; If the starting label is inconsistent with the ending label, the label information is sent to the adjacent node connected to the target node, and the remaining nodes are traversed until the starting label of the label information in the storage container corresponding to the target node is consistent with the ending label. Based on the label information of the target node where the starting label is consistent with the ending label, the ring network structure is determined.
6. The method for identifying gang fraud according to claim 3, wherein: The step of determining the star network structure based on the node type corresponding to the target node includes: Determine whether the node type corresponding to the target node is the target type; If the node type is the target type, traverse the adjacent nodes connected to the target node to determine whether the node type corresponding to the adjacent node is a case node; If the adjacent node is the case node, determining whether the occurrence time of the case node is within a preset time based on the node attribute information of the adjacent node connected to the target node; If the occurrence time is within the preset time, the case node is recorded; It is determined whether the number of the recorded case nodes is greater than a threshold; if the number is greater than the threshold, a star network structure is determined based on the target node and the adjacent nodes.
7. A gang fraud identification device, characterized in that: The device comprises: The detection module is used to obtain a community network, perform star ring detection on each community in the community network to obtain a star ring network structure, and identify gang fraud based on the star ring network structure, wherein the star ring network structure represents the structural characteristics of nodes in gang fraud, and the community network is constructed based on the associated nodes between fraud-related information.
8. A gang fraud identification device, characterized in that: The device includes: a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the computer program is configured to implement the steps of the gang fraud identification method according to any one of claims 1 to 6.
9. A storage medium, characterized in that: The storage medium is a computer-readable storage medium, and a computer program is stored on the storage medium. When the computer program is executed by a processor, the steps of the gang fraud identification method according to any one of claims 1 to 6 are implemented.
10. A computer program product, characterized in that The computer program product includes a computer program, which, when executed by a processor, implements the steps of the gang fraud identification method according to any one of claims 1 to 6.