Mobile fraud detection method and device based on multi-modal fusion analysis

Through multimodal fusion analysis methods, behavioral sequences are constructed and association rules and deep learning models are used to identify new types of fraudulent behaviors on mobile devices, solving the problem of insufficient response capabilities of traditional detection technologies and achieving efficient and accurate fraud detection.

CN120751390APending Publication Date: 2025-10-03HANGZHOU HIGH-TECH ZONE (BINJIANG) INSTITUTE OF BLOCKCHAIN & DATA SECURITY +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411833267.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-12
Publication Date
2025-10-03

AI Technical Summary

Technical Problem

Traditional mobile device fraud detection technology is difficult to deal with new fraud methods, lacks response capabilities, and cannot quickly identify complex and diverse forms of fraud.

Method used

Through multimodal fusion analysis methods, user behavior data is extracted, behavior sequences are constructed, association rules and preset fraud pattern matching are used, and deep learning models and clustering algorithms are combined to identify suspected fraud behaviors and improve detection accuracy and response speed.

Benefits of technology

It achieves efficient identification and rapid response to new types of fraud, improves the accuracy and scope of fraud detection, and adapts to complex and diverse forms of fraud.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120751390A_ABST
    Figure CN120751390A_ABST
Patent Text Reader

Abstract

The invention relates to a mobile fraud detection method and device based on multi-modal fusion analysis. The method comprises the following steps: extracting various data associated with a current user behavior; determining a first behavior sequence of suspected fraud in current user behaviors according to the various data; establishing an association rule between behaviors according to historical user behaviors, and obtaining a second behavior sequence meeting the association rule from the first behavior sequence; and obtaining a first probability that the user is defrauded according to the second behavior sequence. By adopting the method, the capability of coping with novel fraud behaviors can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of network security technology, and in particular to a mobile fraud detection method and device based on multimodal fusion analysis. Background Art

[0002] Telecommunications fraud is a major form of cybercrime, and mobile devices, such as mobile phones, are the primary means by which internet users are victimized by these scams. Fraudulent phone calls and text messages not only cause direct financial losses but also lead to the leakage of sensitive user information.

[0003] Traditional mobile device fraud detection technology primarily relies on pre-set databases and rules, such as databases of fraudulent phone numbers and malicious websites. This approach allows users to receive timely alerts or block malicious calls or websites, mitigating fraud risks to a certain extent. However, it exhibits significant limitations in addressing evolving fraud methods. With fraudsters leveraging new methods like screen sharing, third-party payment, and social media phishing, fraud has become increasingly diverse and subtle. Traditional fraud detection methods, which only cover simpler methods like phone calls and text messages, struggle to address these new threats. Fraudsters also exploit mobile apps and various internet-based public services, making it difficult for fraud detection technologies that rely on static databases to respond quickly. With the rapid evolution of fraud methods, traditional fraud detection systems are unable to keep pace with the evolving threat landscape, necessitating more flexible and intelligent solutions.

[0004] From this, we can see that there is currently no effective solution to the problem of insufficient ability to deal with new types of fraud in related technologies. Summary of the Invention

[0005] Based on this, it is necessary to provide a mobile fraud detection method and equipment based on multimodal fusion analysis that can solve the problem of insufficient ability to deal with new types of fraud in response to the above technical problems.

[0006] First, in this embodiment, a mobile fraud detection method based on multimodal fusion analysis is provided, the method comprising:

[0007] Extract various types of data associated with current user behavior;

[0008] Determine the first behavior sequence suspected of fraud in the current user behavior based on the various types of data;

[0009] Constructing association rules between behaviors based on historical user behaviors, and obtaining a second behavior sequence that satisfies the association rules from the first behavior sequence;

[0010] A first probability of the user being defrauded is obtained according to the second behavior sequence.

[0011] In some embodiments, after obtaining the first probability that the user has been defrauded based on the second behavior sequence, the method further includes:

[0012] In the first behavior sequence, a third behavior sequence matching a behavior sequence in a preset fraud pattern is obtained;

[0013] Obtaining a second probability that the user has been defrauded according to the third behavior sequence;

[0014] The first probability and the second probability are combined.

[0015] In some embodiments, obtaining a third behavior sequence that matches a preset fraudulent behavior sequence in the first behavior sequence includes:

[0016] Obtaining the number of operations required to convert the first behavior sequence to a behavior sequence in the preset fraud mode based on preset operation rules; wherein the preset operation rules include at least one of the following: deleting a behavior in the first behavior sequence, adding a behavior in the first behavior sequence, modifying an access object involved in the first behavior sequence, or modifying a fraud probability of the access object;

[0017] determining, based on the number of operations, a degree of matching between the first behavior sequence and a behavior sequence in the preset fraud pattern;

[0018] The third behavior sequence is obtained according to the matching degree.

[0019] In some embodiments, after obtaining a second behavior sequence that satisfies the association rule from the first behavior sequence, the method further includes:

[0020] Clustering the second behavior sequence to obtain a new preset fraud pattern;

[0021] The preset fraud pattern is updated according to the new preset fraud pattern.

[0022] In some embodiments, the association rules between behaviors constructed based on historical user behaviors include:

[0023] Constructing frequent itemsets according to the support of the itemsets of the historical user behaviors;

[0024] The association rule is obtained by screening the multiple rules constructed by the frequent item set according to the confidence of each rule.

[0025] In some embodiments, the various types of data associated with the current user behavior include at least one of the following: media content, application behavior, and visited website codes involved in executing the user behavior.

[0026] In some embodiments, the various types of data associated with the current user behavior include multimodal media content, and determining the first behavior sequence suspected of fraud in the current user behavior based on the various types of data includes:

[0027] integrating the multimodal media content;

[0028] Obtaining preset learning tasks corresponding to media content of different modalities;

[0029] Detecting the fused media content based on the preset learning tasks to obtain multiple fraud probabilities corresponding to media content of different modalities;

[0030] User behaviors are selected based on the fraud probability to construct the first behavior sequence.

[0031] In some embodiments, the various types of data associated with the current user behavior include the application behavior, and determining a first behavior sequence suspected of fraud in the current user behavior based on the various types of data includes:

[0032] When the degree of matching between the application behavior and the behavior rules in the preset rule library is greater than a preset value, the application behavior is classified based on a pre-trained deep learning model, and the user behavior suspected of fraud is determined to construct the first behavior sequence.

[0033] In some embodiments, the various types of data associated with the current user behavior include the visited website code, and determining a first behavior sequence suspected of fraud in the current user behavior based on the various types of data includes:

[0034] Identifying whether there is a code structure and / or code content that meets preset characteristics in the website code;

[0035] If so, based on the code structure and / or code content that meets the preset characteristics, the user behavior suspected of fraud is determined to construct the first behavior sequence.

[0036] In some embodiments, the extracting of various types of data associated with the current user behavior includes:

[0037] When it is detected that the current user behavior meets the preset risk behavior, various types of data associated with the current user behavior are extracted.

[0038] On the second aspect, a computer device is provided in this embodiment, including a memory and a processor, wherein the memory stores a computer program, and when the processor executes the computer program, it implements the mobile fraud detection method of multimodal fusion analysis described in the first aspect.

[0039] On the third aspect, in this embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the mobile fraud detection method based on multimodal fusion analysis described in the first aspect is implemented.

[0040] In a fourth aspect, a computer program product is provided in this embodiment, comprising a computer program, which, when executed by a processor, implements the mobile fraud detection method of multimodal fusion analysis described in the first aspect above.

[0041] The above-mentioned mobile fraud detection method and equipment based on multimodal fusion analysis obtains the first behavior sequence in user behavior that indicates the probability of fraud by identifying various types of data associated with user behavior, mines association rules from the accumulated user behavior sequences, and identifies the first probability of new fraudulent behavior from the first behavior sequence by matching the association rules with the first behavior sequence, thereby solving the problem of low ability to respond to new frauds. BRIEF DESCRIPTION OF THE DRAWINGS

[0042] Figure 1 FIG1 is a diagram showing an application environment of a mobile fraud detection method based on multimodal fusion analysis in one embodiment;

[0043] Figure 2 1 is a flow chart of a mobile fraud detection method based on multimodal fusion analysis in one embodiment;

[0044] Figure 3 A structural block diagram of a fraud detection model in one embodiment;

[0045] Figure 4 1 is a flow chart of a mobile fraud detection method based on multimodal fusion analysis in another embodiment;

[0046] Figure 5 is a schematic diagram of an association analysis module in one embodiment;

[0047] Figure 6 This is a structural block diagram of a mobile fraud detection device using multimodal fusion analysis in one embodiment;

[0048] Figure 7 FIG. 1 is a diagram showing the internal structure of a computer device in one embodiment. DETAILED DESCRIPTION

[0049] In order to make the purpose, technical solutions and advantages of this application more clear, the following further describes this application in detail with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain this application and are not intended to limit this application.

[0050] The mobile fraud detection method based on multimodal fusion analysis provided in the embodiment of the present application can be applied to Figure 1 In the application environment shown. Among them, the terminal 102 communicates with the server 104 through the network. The data storage system can store the data that the server 104 needs to process. The data storage system can be integrated on the server 104, or it can be placed on the cloud or other network servers. The user behavior is detected and analyzed by the terminal, and the first behavior sequence of suspected fraud is identified, and the preset fraud behavior sequence and the sequence based on historical user behavior are matched to realize the identification of fraudulent behavior. Among them, the terminal 102 can be but is not limited to various personal computers, laptops, smart phones, tablets and portable wearable devices. The portable wearable devices can be smart watches, smart bracelets, head-mounted devices, etc. The server 104 can be implemented as an independent server or a server cluster consisting of multiple servers.

[0051] In one embodiment, Figure 2 As shown in the figure, a mobile fraud detection method based on multimodal fusion analysis is provided. Figure 1 The following steps are used as an example to illustrate the terminal in the figure:

[0052] Step S202: extract various types of data associated with the current user behavior.

[0053] The current user behavior refers to the user's interactions with applications and / or websites on the terminal during the fraud detection process. User behaviors include, but are not limited to, text messages, phone calls, application downloads, and website visits. The various types of data associated with the current user behavior are the data involved in the terminal's execution of the user behavior. Data types can include text, images, videos, and code. These data types include, but are not limited to, the code of websites with which the user interacted during fraud detection, media content accessed by the user while using the terminal, and logs of application behaviors with which the user interacted.

[0054] Optionally, in response to a fraud detection instruction, the current user behavior is continuously acquired to obtain data related to the terminal device during the execution of the current user behavior. The fraud detection instruction can be initiated by the user or automatically when it is determined that fraud detection is required.

[0055] Step S204: determining the first behavior sequence suspected of fraud in the current user behavior based on various data.

[0056] The first behavior sequence is a sequence of current user behaviors corresponding to data related to fraudulent behaviors. One or more first behavior sequences can be obtained based on various types of data.

[0057] Optionally, based on prior knowledge corresponding to each type of data, it is determined whether the extracted data may involve fraudulent behavior. If it is detected that the current data may involve fraudulent behavior, the user behavior corresponding to the data is considered to be suspected fraudulent behavior, and the user behavior corresponding to the data is converted into a first behavior sequence. Specifically, prior knowledge corresponding to each type of data can be obtained based on known fraudulent methods and stored in the form of a pattern library. Each type of data is then matched with the corresponding pattern library to identify the data and determine the user behavior that may involve fraud.

[0058] Optionally, after obtaining user behaviors involving fraud, the fraud probability of the user behaviors corresponding to each data type is obtained based on the detection results of each type of data; the user behaviors are converted into behavior sequences by combining the data type and the corresponding fraud probability. Taking the data types including media content, application behavior, website code, and the fraud probability of low, medium, and high as an example, based on the data type (content, application behavior, website) and the fraud probability (low, medium, high), user / APP behaviors such as "receiving a text message with a high fraud probability" can be mapped, thereby forming a set of behavior sequences, namely, obtaining a first behavior sequence.

[0059] Step S206 : constructing association rules between behaviors based on historical user behaviors, and obtaining a second behavior sequence that meets the association rules from the first behavior sequence.

[0060] Historical user behavior refers to the behavior performed by a user on a terminal within a historical time period. The historical time period can be set and modified as needed. Optionally, historical user behavior may also include current user behavior. Optionally, historical user behavior within the historical time period is obtained and converted into a sequence to obtain multiple sets of historical behavior sequences. Association analysis is performed on the multiple sets of historical behavior sequences. For example, a neural network model can be used to capture the correlation coefficients and temporal dependencies between the multiple sets of historical behavior sequences. Association analysis can also be implemented based on self-attention mechanisms, FP-Growth algorithms, Apriori algorithms, and other methods to generate association rules.

[0061] Optionally, after obtaining the association rule, the association rule is matched with the first behavior sequence to determine whether the first behavior sequence is included in the association rule. If so, the behavior sequence is determined to satisfy the association rule and is used as the second behavior sequence.

[0062] Step S208: Obtain a first probability that the user has been defrauded based on the second behavior sequence.

[0063] The more association rules the second behavior sequence satisfies, the higher the first probability of the user being defrauded; conversely, the lower the first probability of the user being defrauded. Optionally, a relationship between the number of association rules satisfied by the second behavior sequence and the probability of fraud is pre-set, thereby obtaining the first probability based on the number of association rules satisfied. Optionally, different association rules can be assigned different weights, and the first probability of the user being defrauded is output through a weighted summation based on the association rules satisfied by the current second behavior sequence and the corresponding weights.

[0064] In the above-mentioned mobile fraud detection method based on multimodal fusion analysis, after determining the first behavior sequence in which the probability of fraud exists in user behavior by analyzing various types of data associated with user behavior, association rules are mined from the accumulated historical user behavior sequence, and by matching the association rules, the second behavior sequence that may belong to a new type of fraud behavior is identified in the first behavior sequence, and the first probability of being defrauded is obtained, thereby realizing the identification of new fraud and solving the problem of insufficient response ability to new fraud.

[0065] Furthermore, related technologies rely heavily on database matching or user reports to identify fraudulent activity, resulting in slow response times and an inability to respond in real time. This delayed detection method can potentially harm users before fraudulent activity is identified. The mobile fraud detection method based on multimodal fusion analysis in this embodiment can be directly applied to terminals, improving the response speed of fraud detection.

[0066] In one embodiment, after obtaining a first probability that the user has been defrauded based on the second behavior sequence, the method further includes: obtaining a third behavior sequence in the first behavior sequence that matches the behavior sequence in a preset fraud pattern; obtaining a second probability that the user has been defrauded based on the third behavior sequence; and combining the first probability and the second probability.

[0067] The preset fraud patterns are behavioral sequences consisting of user behavior and website and / or app behavior on the terminal. Each preset fraud pattern represents a process by which a user experiences fraud on a mobile terminal. These patterns can be extracted from known fraud cases. For ease of understanding, using the traditional fraud pattern of SMS fraud as an example, the corresponding behavioral sequence for this fraud pattern includes: "receiving a high-scam SMS message → redirecting to a payment app." Taking the example of ticket refund and change fraud, the corresponding behavioral sequence for this fraud pattern includes: "receiving an unknown call → downloading an app → the app requests screen sharing permissions → the user accesses a payment / finance app → receiving a verification code." Arrows connect different behaviors and indicate the order of these behaviors. Optionally, the first behavioral sequence is matched against behavioral sequences in one or more preset fraud patterns. A match is determined based on the similarity between the first and default fraud patterns. The greater the similarity, the higher the degree of match. If the degree of match exceeds a specified threshold, the corresponding behavioral sequence can be used as the third behavioral sequence.

[0068] Optionally, a first probability is obtained based on the number and / or weight of one or more association rules satisfied by the second behavior sequence; a second probability is obtained based on the degree of similarity between the third behavior sequence and a behavior sequence in a preset fraud pattern; and the first and second probabilities are combined to obtain a probability that the user has been defrauded. The combination of the first and second probabilities can be achieved using existing mathematical methods, such as addition, averaging, or weighting.

[0069] In this embodiment, by matching the preset fraud pattern with the first behavior sequence and identifying whether the user behavior conforms to the known fraud pattern, the accuracy of fraud detection can be improved.

[0070] Furthermore, in one embodiment, in the first behavior sequence, obtaining a third behavior sequence that matches a preset fraud behavior sequence includes: obtaining the number of operations required to convert the first behavior sequence to a behavior sequence in a preset fraud mode based on preset operation rules; wherein the preset operation rules include at least one of the following: deleting a behavior in the first behavior sequence, adding a behavior in the first behavior sequence, modifying an access object involved in the first behavior sequence, and modifying the fraud probability of the access object; determining the degree of matching between the first behavior sequence and the behavior sequence in the preset fraud mode based on the number of operations; and obtaining the third behavior sequence based on the degree of matching.

[0071] The fewer the number of operations required, the higher the degree of match between the first behavior sequence and the behavior sequence in the preset fraud pattern; conversely, the lower the degree of match between the first behavior sequence and the behavior sequence in the preset fraud pattern. Based on the number of operations, a sequence with a degree of match greater than or equal to a preset degree is selected as the third behavior sequence. For example, the third behavior sequence is set to a sequence with a number of operations less than or equal to a preset number.

[0072] Optionally, if the behaviors included in the first behavior sequence are different from the behavior sequence in the preset fraud pattern, it is necessary to delete or add corresponding behaviors based on the difference between the two; each deletion or addition of a corresponding behavior is recorded as one operation. If the access object involved in the first behavior sequence is different from the behavior sequence in the preset fraud pattern, it is necessary to perform an operation to modify the access object involved in the first behavior sequence; each modification of an access object is recorded as one operation. The behavior sequence in the preset fraud pattern includes access objects, and the corresponding fraud probability is pre-set according to the access object. The first behavior sequence is obtained based on the analysis of various types of data. Therefore, the fraud probability of the first behavior sequence can be obtained based on the analysis of various types of data. If the fraud probability corresponding to the first behavior sequence is different from the fraud probability corresponding to the behavior sequence in the preset fraud pattern, it is necessary to perform the step of modifying the fraud probability of the access object; each modification of the fraud probability of an access object is recorded as one operation.

[0073] In this embodiment, the degree of match between the terminal's current behavior sequence and the behavior sequence in the known preset fraud pattern is judged based on the number of operations. This can not only improve the accuracy of fraud detection and identification, but also expand the detection range and further discover fraudulent behaviors with complex steps and involving multiple low-fraud-probability objects.

[0074] In one embodiment, after obtaining a second behavior sequence that satisfies the association rule in the first behavior sequence, the method further includes: clustering the second behavior sequence to obtain a new preset fraud pattern; and updating the preset fraud pattern according to the new preset fraud pattern.

[0075] The second behavior sequences can be clustered based on characteristics such as distance, hierarchy, and density between the second behavior sequences. When the step of "obtaining a third behavior sequence matching a behavior sequence in a preset fraud pattern from the first behavior sequence" is performed again, the first behavior sequence is matched against the updated preset fraud pattern.

[0076] Optionally, a specific neighborhood range and sample count requirement are set, and clustering is performed using the DBSCAN algorithm. Based on the clustering results, a new batch of fraud patterns is generated. Pre-set fraud patterns are stored in a fraud behavior pattern library, and the library is updated with new fraud patterns generated through clustering. It is understood that other clustering algorithms, such as K-Means clustering and HBSCAN clustering, can also be used.

[0077] In this embodiment, new fraud patterns are identified by clustering the second behavior sequences, thereby improving the ability to respond to new types of fraud.

[0078] In one embodiment, association rules between behaviors are constructed based on historical user behaviors, including: constructing frequent itemsets based on the support of itemsets of historical user behaviors; and filtering multiple rules constructed from the frequent itemsets based on the confidence of each rule to obtain association rules.

[0079] Support represents the frequency of an itemset's occurrence across all transactions. Confidence represents the probability that, given the presence of a certain itemset, another itemset will also occur. Itemsets refer to items and / or elements in historical user behavior, and frequent itemsets include items and / or elements that frequently appear in historical user behavior.

[0080] Optionally, when historical user behaviors are obtained, the support of the itemsets for each historical user behavior is calculated. Frequent itemsets are constructed based on the historical user behaviors that meet a support threshold. Multiple rules are mined from the frequent itemsets, and association rules between historical user behaviors whose confidence meets a confidence threshold are determined from the multiple rules. The support threshold and confidence threshold are pre-set ranges and can be modified based on application requirements.

[0081] In this embodiment, association rules between historical user behaviors are obtained through support and confidence mining, so that new fraud behaviors can be discovered based on historical user behaviors, thereby improving the detection capabilities of new frauds.

[0082] In one embodiment, extracting various types of data associated with the current user behavior includes: extracting various types of data associated with the current user behavior when it is detected that the current user behavior meets the preset risk behavior.

[0083] Pre-defined risk behaviors are behaviors related to fraud, including but not limited to: answering unfamiliar phone calls, receiving sensitive text messages, downloading and installing unknown applications, redirecting to payment applications, etc. Optionally, when risky behaviors are detected, relevant mobile device data is collected, including screenshots, text message content, conversation voice, application behavior logs, website code, etc.

[0084] In this embodiment, when it is detected that the current user behavior has a risk of being defrauded based on the preset risk behavior, various types of data are extracted to improve the response speed of fraud detection.

[0085] In one embodiment, the various types of data associated with the current user behavior include at least one of the following: media content, application behavior, and visited website codes involved in executing the user behavior.

[0086] Among them, media content includes data in one or more of the following modes: audio, text, pictures, and videos. Application behavior includes the application's network behavior, permission request behavior, file reading and writing behavior, and interaction behavior with other applications. Optionally, the application behavior can be obtained by collecting the application's behavior log. The website code is the source code of the website accessed by the user behavior. Optionally, the website source code is obtained by using a crawler to obtain the website source code and analyze it. In this embodiment, by obtaining and analyzing data associated with user behavior from multiple perspectives, the analysis results of multiple types of data are integrated to identify the probability of fraud for each user behavior, thereby improving the accuracy of fraud.

[0087] If the various types of data associated with the current user behavior include multimodal media content, in one embodiment, a first behavior sequence suspected of fraud in the current user behavior is determined based on the various types of data, including: fusing multimodal media content; obtaining preset learning tasks corresponding to media content of different modalities; detecting the fused media content based on the preset learning tasks respectively to obtain multiple fraud probabilities corresponding to media content of different modalities; and selecting user behaviors based on the fraud probabilities to construct the first behavior sequence.

[0088] Multimodal media content includes one or more of audio, text, images, and video. Optionally, this multimodal media content is fed into a multimodal Transformer model, where it is further integrated through a shared attention mechanism and interactive autoencoders to achieve preliminary feature extraction and alignment. Furthermore, the media content can be converted into the same semantic space to achieve semantic alignment.

[0089] Among them, different modal media content corresponds to different preset learning tasks. Optionally, for audio, the corresponding preset learning task is used to process the speech emotion features of the audio data, detect whether the audio may involve fraud based on the emotion features, and obtain the corresponding fraud probability. For text, the corresponding preset learning task is used to process text data, determine whether the text may involve fraud through semantic analysis, and obtain the corresponding fraud probability. For pictures, the corresponding preset learning task is used to analyze the deceptive information in the picture through image recognition technology, determine whether the picture may involve fraud, and obtain the corresponding fraud probability. For video, the corresponding video task is used to analyze video data, detect fraudulent behavior in the video, and obtain the corresponding fraud probability. User behaviors involving fraud can be selected according to the fraud probabilities corresponding to multiple preset learning tasks, and user behaviors involving fraud can be used as behaviors for constructing the first behavior sequence.

[0090] Optionally, after the multimodal media content is fused based on a shared underlying feature extraction network including a multimodal Transformer model, the fused multimodal media content is detected by respective preset learning tasks, and each preset learning task has its own independent classifier.

[0091] In this embodiment, by integrating multimodal media content, the data is mapped to a unified representation space, ensuring that data of different modalities can be effectively utilized through preset learning tasks in the future. By jointly learning multiple tasks, unified detection of various fraudulent content can be achieved, thereby improving detection efficiency while ensuring detection quality.

[0092] If the various types of data associated with the current user behavior include the application behavior, in one embodiment, determining a first behavior sequence suspected of fraud in the current user behavior based on the various types of data includes: when the degree of matching between the application behavior and the behavior rules in the preset rule library is greater than a preset value, classifying the sequence of the current user behavior based on a pre-trained deep learning model, and determining the user behavior suspected of fraud to construct the first behavior sequence.

[0093] Application behavior includes network activity, permission requests, file read / write behavior, and interactions with other applications. Different behavior rules in the pre-set rule library correspond to different fraudulent behaviors. If an application's behavior matches fraudulent application behavior, the application is determined to match the behavior rules in the pre-set rule library. The more rules in the pre-set rule library an application's behavior matches, the higher the degree of match. When the match value exceeds a pre-set value, a deep learning model is activated for in-depth analysis.

[0094] The deep learning model, trained on a dataset of fraudulent and normal application behaviors, is used to capture temporal dependencies and complex patterns in behavioral sequences, thereby determining the potential risk of current behavior. This allows for application behavior detection and classification of suspected fraudulent user behaviors. The first behavioral sequence can be constructed based on suspected fraudulent user behaviors.

[0095] In this embodiment, a simple and fast preliminary screening is provided through a preset rule library. When more application behaviors that match the preset rule library are detected, the risk gradually increases. When the matching degree reaches a certain threshold, the model is activated to conduct in-depth analysis of the application behavior. By combining the rule library and the deep learning model, the system can achieve efficient and accurate fraud detection.

[0096] If the various types of data associated with the current user behavior include the visited website code, in one embodiment, determining a first behavior sequence suspected of fraud in the current user behavior based on the various types of data includes: identifying whether there is a code structure and / or code content that meets preset characteristics in the website code; if so, obtaining the first behavior sequence based on the code structure and / or code content that meets the preset characteristics.

[0097] The code structure of the pre-set characteristics is used to indicate the code structure of a fraudulent website; the code content of the pre-set characteristics is used to indicate the code content of a fraudulent website. The code structure includes the structure of HTML and the content of CSS (Cascading Style Sheets) style sheets. The code content includes the script behavior, function calls, API (Application Programming Interface) calls, and external resource references involved in the code.

[0098] Optionally, the website code structure is checked to determine whether it contains structural features of known fraudulent website code. The website code content is also checked to determine whether it contains content features found on known fraudulent websites. If so, the website corresponding to the website code is determined to be potentially fraudulent, and the user behavior corresponding to the website code is treated as suspected fraudulent user behavior and included in the first behavior sequence.

[0099] In this embodiment, by performing feature detection on the structure and content of the website code, the website code is fully analyzed and potential security risks are accurately identified.

[0100] In one embodiment, Figure 3 A fraud detection model is provided, based on which a mobile fraud detection method can be implemented. Figure 3As shown, the fraud detection model includes a content analysis module, an application behavior analysis module, a code analysis module, and an association analysis module. The content analysis module uses a multimodal model and integrates a multi-task learning framework to detect a variety of fraudulent content. The application behavior analysis module combines a fraudulent behavior rule library and a sequence model to detect multiple types of fraudulent application behaviors. The code analysis module further analyzes the websites visited by users to discover potential fraudulent elements on the websites. The association analysis module integrates the outputs of the above-mentioned content analysis module, application behavior analysis module, and code analysis module, and uses a library of known fraud patterns for matching to identify known fraudulent behaviors involving content, application behavior, and website code. The association analysis module also discovers possible new fraudulent behaviors by correlating the relationships between fraudulent content, fraudulent application behaviors, and fraudulent websites, and further uses the DBSCAN algorithm to cluster new fraudulent behaviors to obtain new preset fraud patterns.

[0101] The model uses collected data related to application behavior as input and is calculated using a fraud detection model. This model can be deployed on the device side, using its output to calculate the probability of encountering fraud. This probability is continuously updated over time, and when it reaches a set threshold, a warning is issued to the user on their mobile device, indicating that they may be experiencing fraud.

[0102] based on Figure 3 The fraud detection model shown, Figure 4 Another mobile fraud detection method based on multimodal fusion analysis is provided, e.g. Figure 4 Shown, including:

[0103] Identify user risk behaviors. This is done by monitoring user fraud risk behaviors, including answering unfamiliar calls, receiving sensitive text messages, downloading and installing unknown applications, and redirecting to payment applications.

[0104] When risky user behavior is detected, information is collected, including screenshots, text messages, voice chats, app activity logs, and website code from the mobile device. The system also uses a built-in application to read the user's voice chat content. During this process, the operating status of the mobile device is monitored to ensure the integrity and accuracy of the data captured. By not storing any data, user privacy and data security requirements are met.

[0105] The information collected includes: multimodal media content including audio, text, images, and videos, application behaviors including inter-application interactions, network requests, permission requests, and file read requests, and web page source code.

[0106] Multimodal media content is analyzed through the content analysis module. The content analysis module mainly includes a multimodal fusion model and a multi-task learning framework. The two are implemented by a unified network sharing part structure. The content analysis module analyzes the multimodal media content output and may involve behaviors corresponding to fraudulent data. The behaviors output by the content analysis module can be used as behaviors for constructing the first behavior sequence.

[0107] The multimodal fusion model first preprocesses the data from each modality, including feature extraction and alignment. Feature extraction uses the lightweight feature extraction model MobileNet to process the data from each modality (including audio, text, images, and video), outputting a corresponding representation vector for each modality. Alignment aligns the representation vectors for each modality's data, ensuring uniform processing of features across all modalities, enabling subsequent models to effectively utilize data from different modalities.

[0108] After feature alignment is completed, the data of each modality after feature alignment is mapped to a unified representation space. Optionally, through a shared network architecture, the data features of multiple modalities such as audio, text, pictures, and videos are converted to the same feature space. Optionally, the multimodal fusion model can also adopt a shared attention mechanism and self-supervised learning method to further optimize the representation of features in the unified representation space. For example, the multimodal CLIP model can be used to map the speech features in the audio, the language features in the text, and the action features in the video to the same semantic space, thereby achieving semantic alignment.

[0109] After achieving a unified representation of data from each modality, the content analysis module performs multimodal Transformer processing on the data. This involves receiving data from different modalities through multiple input channels. Each modal data is processed by a separate Transformer encoder to generate a contextual feature representation specific to that modality. Based on this, the intermediate layer fuses the data from different modalities through a cross-modal attention mechanism, capturing shared information and complementary features between the modalities. For example, the content analysis module can capture common semantics between text and images, including the text and text content in images. The content analysis module can also model temporal correlations in audio and video, such as the synchronization between speech and action. Optionally, after fusing the data from different modalities through the cross-modal attention mechanism, the content analysis module can also map these fused features into the same semantic space using CLIP (Contrastive Language-Image Pre-training), ensuring semantic alignment and information sharing between the data from different modalities, further enhancing the processing capabilities of multimodal tasks.

[0110] Optionally, the content analysis module is provided with a shared feature extraction layer, and the above-mentioned unified representation of the data and data fusion process are completed for each modality data based on the shared feature extraction layer.

[0111] The fused data is used as the basic features of multi-task learning, and a plurality of different task branches are set according to the data modality, namely the preset learning tasks in the above embodiment. Specific modalities and tasks are optimized through a plurality of different task branches. Optionally, a specific speech model is used in the audio task branch to identify emotional features such as inductive tone, or to detect specific language patterns in fraudulent calls. The text task branch uses text classification and natural language processing technology to detect tempting language and fraudulent words in phishing text messages and emails. The image task branch detects image elements in phishing websites and deceptive content in advertising images, and identifies potential fraudulent information in these images. The video task branch identifies the behavioral characteristics of scammers by analyzing elements such as body language, facial expressions, and forged documents displayed in the video.

[0112] Furthermore, the content analysis module uses a joint loss function to coordinate and optimize the learning between data and tasks of different modalities. The loss of the task branches for audio, text, pictures, and videos is obtained, and the loss function of each modality data is designed according to the specific task. Optionally, the loss of audio, text, and picture tasks uses cross-entropy loss; BERT (Bidirectional Encoder Representations from Transformers, masked language model) loss is used in generation tasks; IoU (Intersection over Union) loss is used for picture tasks, and CTC (Connectionist Temporal Classification, conditional random field loss) loss is used for video tasks to be suitable for time series data processing.

[0113] The joint loss function performs a weighted combination of the losses of the task branches of audio, text, image, and video, enabling the model to simultaneously optimize different modalities and tasks. The total loss L of the joint loss function is total It can be expressed as:

[0114] L total =α1L audio +α2L text +α3L image +α4L video

[0115] Among them, α1, α2, α3, and α4 are weight coefficients that adjust the relative importance of different modes, which are used to ensure that the loss of each modality task has an appropriate contribution to the overall optimization. audio is the loss of the audio task branch, α1 is the weight of the audio task branch; L text The loss of the text task branch, α2 is the weight of the text task branch; L image is the loss of the image task branch, α3 is the weight of the image task branch; L video is the loss of the video task branch, and α4 is the weight of the video task branch. In actual applications, the fraud detection model uses dynamic weight adjustment to dynamically adjust weights based on the task convergence speed. To avoid excessive resource consumption on the device side, weight adjustment uses a simplified fixed weight scheme. Model optimization is also used to ensure balance and efficiency across different tasks and modalities.

[0116] Application behavior is analyzed through the Application Behavior Analysis module, which combines a rule library with a deep learning network based on sequence modeling to achieve efficient and accurate fraud detection on mobile devices. The module analyzes application behavior and outputs a sequence of application behaviors that may be fraudulent, representing the first behavior sequence described above.

[0117] Specifically, the application behavior analysis module conducts a rapid preliminary screening based on a preset rule base to determine whether the application behavior complies with the behavioral rules in the preset rule base. As the number of application behaviors that comply with the behavioral rules in the preset rule base increases and the degree of match between application behavior and the rule base increases, the probability of fraudulent activity will gradually increase. When the degree of match between application behavior and the rule base reaches a preset threshold, the application behavior analysis module activates a deep learning model based on behavior sequences, inputs a series of existing behavior sequences and the current behavior sequence into the deep learning model, and analyzes the current application's behavior sequence.

[0118] The deep learning model, derived through sequence modeling techniques, is used to capture the temporal dependencies and complex patterns in behavioral sequences, classify abnormal behaviors, and determine the potential risk of the current behavior. By learning the patterns of normal behavior on user devices, it can identify malicious behavior that is inconsistent with normal operations. Optionally, the risk assessment output by the deep learning model includes the risk level of the specific behavior, the triggered rules, and the confidence level of the deep learning model. All output results are presented as structured data (such as JSON or XML format) to facilitate subsequent correlation analysis.

[0119] The code analysis module analyzes the website's source code. It retrieves the website's HTML (Hypertext Markup Language) source code from the browser and performs a series of in-depth analyses, including HTML structure parsing, JavaScript code analysis, external resource dependency analysis, and CSS injection risk analysis. Through this multi-faceted analysis, the code analysis module can identify and flag potential risks associated with fraudulent activities, ensuring the security of the website's page content and structure. By analyzing the network source code and outputting application behaviors that may involve fraud, the code analysis module can use the behaviors output by the code analysis module as the first behavior in the sequence.

[0120] Among them, HTML structure parsing is used to analyze the overall structure of HTML documents, focusing on identifying sensitive data exposure that may lead to information leakage, suspicious form processing methods, and embedded potential fraudulent inline scripts. The code analysis module will also detect whether there are hidden fraudulent elements in the page, such as buttons that induce users to click, invisible links, etc.; whether there are non-standard DOM (Document Object Model) structures used for fraudulent purposes, such as disguised input fields or hidden forms used for phishing attacks. Furthermore, HTML structure parsing also analyzes the script behavior in the page, identifies redirects that may lead users to perform unnecessary operations, cross-site scripting attacks (XSS) or other forms of script injection behaviors, and further marks potential risks related to fraud. Especially in mobile scenarios, the code analysis module can quickly identify and respond to automatic jump behaviors without user authorization to prevent users from being directed to phishing websites or other fraudulent pages.

[0121] JavaScript code analysis is used to identify dangerous function calls and unsafe API usage within scripts. Unsafe API calls include, but are not limited to, directly manipulating the eval function or executing XHR (XML Http Request, cross-origin requests). These unsafe calls are often used by scammers to conceal their operations. Optionally, the code analysis module specifically focuses on code segments within scripts that may be used to construct fraudulent processes, such as disguising user behavior or automatically submitting forms, to prevent scammers from using scripts to trick users into performing inappropriate operations.

[0122] External resource dependency analysis is used to analyze external resources and third-party libraries referenced by a website. These third-party libraries can be JavaScript files or plugins loaded by a CDN (Content Delivery Network). The code analysis module focuses on analyzing whether these external resources and third-party libraries are linked to fraudulent activities. When certain external resources and third-party libraries are malicious, often used as tools or resources for fraudulent activities, the code analysis module checks the versions and sources of these resources to determine whether the external resources and third-party libraries referenced by the website are commonly used by fraudsters, and the corresponding fraud probability.

[0123] CSS injection risk analysis examines the content of CSS files and style sheets for rules or injection techniques that could be exploited for fraudulent purposes. These techniques include, but are not limited to, using CSS pseudo-class selectors to disguise interfaces and mislead users into entering sensitive information. The code analysis module also detects unauthorized CSS file loading or link redirects in website code to prevent users from being directed to fraudulent pages and ensure that the website's style and appearance have not been tampered with for fraudulent purposes.

[0124] Through the above analysis steps, the code analysis module can comprehensively parse the source code and related dependencies of the website and identify potential security risks. Based on the security risks, it obtains the first behavioral demand with a higher probability of fraud to provide reliable data input for the association analysis module, ensuring in-depth detection and prevention of possible malicious behaviors or fraudulent activities.

[0125] The behaviors outputted by the content analysis module, the application behavior analysis module, and the code analysis module are obtained, and a first behavior sequence is constructed. The second behavior sequence and the third behavior sequence are obtained based on the analysis of the first behavior sequence by the association analysis module. Figure 5 A schematic diagram of an association analysis module is provided.

[0126] The association analysis module determines the third behavior sequence from the first behavior sequence by integrating the first behavior sequence determined by the content analysis module, the application behavior analysis module, and the code analysis module within the current behavior sequence, matching the first behavior sequence with behavior sequences in a preset fraud pattern library, and using the identified known fraudulent behaviors involving content, application behavior, and website code as the third behavior sequence to obtain a probability of the known fraudulent behavior, i.e., the second probability in the above-mentioned embodiment. The third behavior sequence may involve one or more of the following: fraudulent content, fraudulent application behavior, or fraudulent website.

[0127] Among them, the preset fraud pattern library is constructed by manually extracting fraud behavior patterns from known fraud cases. The extracted preset fraud pattern is a sequence composed of user behavior and APP behavior. Each preset fraud pattern represents a process in which a user suffers fraud on a mobile terminal. The user behaviors that make up the sequence include exposure to fraudulent content (text messages, advertisements, etc.), visiting fraudulent websites, downloading APPs, accessing APPs, etc. The APP behaviors that make up the sequence include APP requesting specific permissions (contacts, text message reading, accessibility, sensors, etc.), jumping to other APPs, etc.

[0128] Matching the first behavior sequence with behavior sequences in a preset fraud pattern library includes calculating the edit distance between the terminal's first behavior sequence and the preset fraud pattern. For two behavior sequences, the edit distance is the minimum number of operations required to transform one into the other by deleting a behavior, adding a behavior, modifying the behavior's access object, or modifying the access object's fraud probability. A greater number of operations indicates a lower degree of match, and vice versa. A successful match is determined when the edit distance between the terminal's current behavior sequence and a known preset fraud pattern is less than a specified threshold. The smaller the edit distance, the higher the degree of match.

[0129] The association analysis module determines the second behavior sequence from the first behavior sequence by calculating associations from historical behavior sequences using the FP-growth algorithm, mining association rules, and thereby identifying possible new fraudulent behaviors. Historical behavior sequences are accumulated from previously acquired behavior sequences. Furthermore, the DBSCAN algorithm is used to cluster new fraudulent behaviors, identifying new pre-set fraud patterns from the clustering results and adding them to the pre-set fraud pattern library to counter new fraudulent methods.

[0130] Mining association rules involves constructing frequent item sets from historical user behavior sequences based on a specific support threshold, and then mining association rules based on a specific confidence threshold. Mined association rules might look like "download app → app requests screen sharing permissions" or "app requests accessibility permissions → user receives bank verification code." Each association rule indicates that when the left part of the association rule, such as "download app," appears in multiple successful detections of one or more fraudulent content, application behaviors, or websites, the right part, such as "app requests screen sharing permissions," will likely also appear. The association rules are then matched against the first behavior sequence. If the association rule exists in the behavior sequence, the match is successful. The greater the number of successfully matched association rules, the greater the probability of encountering a new type of fraudulent behavior. Based on the matched association rules, the second behavior sequence and the probability of the new fraudulent behavior, i.e., the first probability, are obtained.

[0131] Using the DBSCAN algorithm to cluster new fraudulent behaviors involves: For all discovered new fraudulent behaviors, i.e., the second behavior sequence, calculate the edit distance between sequences. Using the behavior sequence as a sample, calculate the distance between all samples. Set the neighborhood radius and the "number of samples in the neighborhood" required for a sample to become a core sample. Starting with any sample, mark the core sample, and ultimately identify several core samples from all new fraudulent behaviors. Based on the core samples (behavior sequences), new fraudulent behaviors are derived. Each core new fraudulent behavior can be used as a new pre-set fraud pattern.

[0132] The correlation analysis module ultimately combines the first and second probabilities to output the probability that the user is currently experiencing fraud. This probability is continuously updated over time, and when it reaches a threshold, a warning is issued to the user, indicating that they may be experiencing fraud.

[0133] In this embodiment, the multimodal model within the content analysis module enables unified detection of multiple types of fraudulent content across multiple information modalities. Furthermore, the multi-task learning framework within the content analysis module enables the model to share underlying features across different fraud scenarios, improving its generalization and adaptability, enabling it to effectively address a wide range of fraudulent tactics. The application behavior analysis module, combined with fraud patterns, enables detection of the entire fraud process. Traditional mobile fraud detection methods can only detect isolated fraud at a specific level within text messages, websites, or apps. The application behavior analysis module improves detection of complex fraudulent behaviors. The code analysis module examines website source code from multiple perspectives to determine if it contains fraudulent content, improving detection accuracy. The fraud detection model integrates data from various sources, providing comprehensive and accurate data support, ensuring the model can extract effective features from diverse information. The correlation analysis module analyzes the relationships between fraudulent behavior in user-visible content, application behavior, and the code of websites visited by users. This allows detection of known fraudulent behaviors and the correlation of fraudulent content, fraudulent application behavior, and fraudulent websites to identify potential new fraudulent behaviors and subsequently identify new pre-defined fraud patterns.

[0134] Based on the same inventive concept, the embodiments of the present application also provide a mobile fraud detection device for implementing the multimodal fusion analysis of the method embodiments mentioned above. The implementation solution provided by this device is similar to the implementation solution described in the above method. Therefore, the specific limitations of one or more mobile fraud detection device embodiments for multimodal fusion analysis provided below can be found in the above-mentioned limitations of the mobile fraud detection method based on multimodal fusion analysis, and will not be repeated here.

[0135] In one embodiment, Figure 6 As shown, a mobile fraud detection device with multimodal fusion analysis is provided, comprising:

[0136] Data collection module, used to extract various types of data related to current user behavior;

[0137] An analysis module, configured to determine a first behavior sequence suspected of fraud in the current user behavior based on the various types of data;

[0138] an association module, configured to construct an association rule between behaviors based on historical user behaviors, and obtain a second behavior sequence satisfying the association rule from the first behavior sequence;

[0139] The probability acquisition module is used to obtain a first probability that the user has been defrauded based on the second behavior sequence.

[0140] In one embodiment, after obtaining the first probability that the user has been defrauded based on the second behavior sequence, the method further includes: obtaining a third behavior sequence in the first behavior sequence that matches the behavior sequence in a preset fraud pattern; obtaining a second probability that the user has been defrauded based on the third behavior sequence; and combining the first probability and the second probability.

[0141] In one embodiment, in a first behavior sequence, obtaining a third behavior sequence that matches a preset fraud behavior sequence includes: obtaining the number of operations required to convert the first behavior sequence to a behavior sequence in a preset fraud mode based on preset operation rules; wherein the preset operation rules include at least one of the following: deleting a behavior in the first behavior sequence, adding a behavior in the first behavior sequence, modifying an access object involved in the first behavior sequence, and modifying the fraud probability of the access object; determining the degree of match between the first behavior sequence and the behavior sequence in the preset fraud mode based on the number of operations; and obtaining the third behavior sequence based on the degree of match.

[0142] After obtaining a second behavior sequence that meets the association rule in the first behavior sequence, the method further includes: clustering the second behavior sequence to obtain a new preset fraud pattern; and updating the preset fraud pattern according to the new preset fraud pattern.

[0143] In one embodiment, association rules between behaviors are constructed based on historical user behaviors, including: constructing frequent itemsets based on the support of itemsets of historical user behaviors; and filtering multiple rules constructed from the frequent itemsets based on the confidence of each rule to obtain association rules.

[0144] In one embodiment, the various types of data associated with the current user behavior include at least one of the following: media content, application behavior, and visited website codes involved in executing the user behavior.

[0145] If the various types of data associated with the current user behavior include multimodal media content, determining the first behavior sequence suspected of fraud in the current user behavior based on the various types of data includes: fusing the multimodal media content; obtaining preset learning tasks corresponding to media content of different modalities; detecting the fused media content based on the preset learning tasks respectively, and obtaining multiple fraud probabilities corresponding to media content of different modalities; and constructing the first behavior sequence based on the user behavior with fraud probability.

[0146] If the various types of data associated with the current user behavior include application behavior, determining the first behavior sequence suspected of fraud in the current user behavior based on the various types of data includes: when the degree of match between the application behavior and the behavior rules in the preset rule library is greater than a preset value, classifying the sequence of the current user behavior based on the pre-trained deep learning model, and determining the user behavior suspected of fraud to construct the first behavior sequence.

[0147] If the various types of data associated with the current user behavior include the code of the website visited, determining the first behavior sequence suspected of fraud in the current user behavior based on the various types of data includes: identifying whether there is a code structure and / or code content that meets preset characteristics in the website code; if so, determining the user behavior suspected of fraud based on the code structure and / or code content that meets the preset characteristics to construct the first behavior sequence.

[0148] In one embodiment, extracting various types of data associated with the current user behavior includes: extracting various types of data associated with the current user behavior when it is detected that the current user behavior meets the preset risk behavior.

[0149] Each module in the aforementioned multimodal fusion analysis mobile fraud detection device may be implemented in whole or in part through software, hardware, or a combination thereof. Each module may be embedded in or independent of a processor within a computer device in hardware form, or may be stored in a computer device memory in software form, allowing the processor to call and execute the corresponding operations of each module.

[0150] In one embodiment, a computer device is provided. The computer device may be a server, and its internal structure diagram may be as follows: Figure 7 As shown. The computer device includes a processor, a memory, an input / output interface (Input / Output, abbreviated as I / O) and a communication interface. The processor, memory and input / output interface are connected through a system bus, and the communication interface is connected to the system bus through the input / output interface. The processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program and a database. The internal memory provides an environment for the operation of the operating system and computer program in the non-volatile storage medium. The database of the computer device is used to store data associated with user behavior. The input / output interface of the computer device is used to exchange information between the processor and an external device. The communication interface of the computer device is used to communicate with an external terminal through a network connection. When the computer program is executed by the processor, a mobile fraud detection method based on multimodal fusion analysis is implemented.

[0151] Those skilled in the art will understand that Figure 7 The structure shown in the figure is only a block diagram of a part of the structure related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied. The specific computer device may include more or fewer components than shown in the figure, or combine certain components, or have a different component arrangement.

[0152] In one embodiment, a computer device is further provided, including a memory and a processor. The memory stores a computer program, and the processor implements the steps in the above method embodiments when executing the computer program.

[0153] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the steps in the above-mentioned method embodiments are implemented.

[0154] In one embodiment, a computer program product is provided, including a computer program, which implements the steps in the above method embodiments when executed by a processor.

[0155] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of relevant data must comply with the relevant laws, regulations and standards of relevant countries and regions.

[0156] Those skilled in the art will appreciate that all or part of the processes in the above-mentioned embodiment methods can be implemented by instructing the relevant hardware through a computer program, and the computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above-mentioned methods. Among them, any reference to memory, database or other media used in the embodiments provided in this application may include at least one of non-volatile and volatile memory. Non-volatile memory may include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory may include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM). The database involved in the various embodiments provided herein may include at least one of a relational database and a non-relational database. Non-relational databases may include, but are not limited to, distributed databases based on blockchains. The processor involved in the various embodiments provided herein may be, but are not limited to, a general-purpose processor, a central processing unit, a graphics processing unit, a digital signal processor, a programmable logic unit, a data processing logic unit based on quantum computing, and the like.

[0157] The technical features of the above embodiments can be combined arbitrarily. To make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.

[0158] The above-described embodiments merely represent several implementation methods of the present application. While the descriptions are relatively specific and detailed, they should not be construed as limiting the scope of the present application. It should be noted that a person of ordinary skill in the art may make various modifications and improvements without departing from the spirit of the present application, and these modifications and improvements fall within the scope of protection of the present application. Therefore, the scope of protection of the present application shall be determined by the appended claims.

Claims

1. A mobile fraud detection method based on multimodal fusion analysis, characterized in that: The method comprises: Extract various types of data associated with current user behavior; Determine the first behavior sequence suspected of fraud in the current user behavior based on the various types of data; Constructing association rules between behaviors based on historical user behaviors, and obtaining a second behavior sequence that satisfies the association rules from the first behavior sequence; A first probability of the user being defrauded is obtained according to the second behavior sequence.

2. The method according to claim 1, characterized in that After obtaining the first probability that the user has been defrauded according to the second behavior sequence, the method further includes: In the first behavior sequence, a third behavior sequence matching a behavior sequence in a preset fraud pattern is obtained; Obtaining a second probability that the user has been defrauded according to the third behavior sequence; The first probability and the second probability are combined.

3. The method according to claim 2, characterized in that The step of obtaining, in the first behavior sequence, a third behavior sequence that matches a preset fraudulent behavior sequence includes: Obtaining the number of operations required to convert the first behavior sequence to a behavior sequence in the preset fraud mode based on preset operation rules; wherein the preset operation rules include at least one of the following: deleting a behavior in the first behavior sequence, adding a behavior in the first behavior sequence, modifying an access object involved in the first behavior sequence, or modifying a fraud probability of the access object; determining, based on the number of operations, a degree of matching between the first behavior sequence and a behavior sequence in the preset fraud pattern; The third behavior sequence is obtained according to the matching degree.

4. The method according to claim 2, characterized in that After obtaining a second behavior sequence that satisfies the association rule from the first behavior sequence, the method further includes: Clustering the second behavior sequence to obtain a new preset fraud pattern; The preset fraud pattern is updated according to the new preset fraud pattern.

5. The method according to claim 1, wherein The association rules between behaviors constructed based on historical user behaviors include: Constructing frequent itemsets according to the support of the itemsets of the historical user behaviors; The association rule is obtained by screening the multiple rules constructed by the frequent item set according to the confidence of each rule.

6. The method according to claim 1, characterized in that The various types of data associated with the current user behavior include at least one of the following: media content, application behavior, and visited website codes involved in executing the user behavior.

7. The method according to claim 6, characterized in that The various types of data associated with the current user behavior include multimodal media content, and determining the first behavior sequence suspected of fraud in the current user behavior based on the various types of data includes: integrating the multimodal media content; Obtaining preset learning tasks corresponding to media content of different modalities; Detecting the fused media content based on the preset learning tasks to obtain multiple fraud probabilities corresponding to media content of different modalities; User behaviors are selected based on the fraud probability to construct the first behavior sequence.

8. The method according to claim 6, characterized in that The various types of data associated with the current user behavior include the application behavior, and determining a first behavior sequence suspected of fraud in the current user behavior based on the various types of data includes: When the degree of matching between the application behavior and the behavior rules in the preset rule library is greater than a preset value, the application behavior is classified based on a pre-trained deep learning model, and the user behavior suspected of fraud is determined to construct the first behavior sequence.

9. The method according to claim 6, characterized in that The various types of data associated with the current user behavior include the visited website code, and determining the first behavior sequence suspected of fraud in the current user behavior based on the various types of data includes: Identifying whether there is a code structure and / or code content that meets preset characteristics in the website code; If so, based on the code structure and / or code content that meets the preset characteristics, the user behavior suspected of fraud is determined to construct the first behavior sequence.

10. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 9 are implemented.