User security identification system and method based on multiple participation feature changes
By analyzing the time series changes of the multiple participation features of multiple user interactions and combining them with training models to identify user security, the problem of insufficient accuracy in identifying safety hazards of multiple participating users is solved, and the efficiency and accuracy of security monitoring are improved.
Patent Information
- Application Number
- CN202510599558.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-12
- Publication Date
- 2025-10-10
AI Technical Summary
Existing technologies have difficulty effectively identifying the changing trends of multiple participation characteristics of users who interact multiple times, resulting in insufficient accuracy in identifying security risks. In particular, when multiple participating users occupy resources or data for a long time, there is a risk of data loss, resource loss, and platform crash.
By collecting multiple participation features of multiple user interactions, training the initial model, and performing derivative processing to generate a time series change sequence, the recognition model is retrained in combination with the current interaction features and time series sequence to achieve a comprehensive analysis of user security.
It improves the accuracy of user security identification, optimizes the efficiency and accuracy of security monitoring of dynamically changing big data on the Internet, and reduces the misjudgment rate of identifying security risks.
Smart Images

Figure CN120765243A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of computer application technology, and in particular to a user security identification system and method based on changes in multiple participation characteristics. Background Art
[0002] With the development of the internet, various interactive platforms have emerged. These platforms often share, pre-provision, or pre-provision resources and data with users, or offer various services, enabling business interactions between the platforms and users. They may even provide data, resources, and services first, then reclaim the resources and data and charge service fees after the data resources are applied or the service is completed. Common examples include online shopping platforms, sharing platforms, and domestic service platforms. For example, online shopping platforms offer pay-later products or services, restricting certain products to delivery-later payment options, as well as ride-hailing and bike-sharing platforms. While these platforms offer significant convenience to users, their close integration with the internet also presents various security risks due to the massive and dynamically changing volume of monitored data. These include the possibility of platform or interaction data being intercepted and stolen, maliciously appropriated, fraudulently obtained, and dishonest (non-payment) data. Currently, intelligent analysis and identification of large amounts of dynamically changing network data primarily utilizes machine learning models (models) to identify these data providers, who may pose security risks and be illegal or anomalous users.
[0003] In practice, many interactive business processes on platforms, servers, and networks often involve multiple users. These users may engage in interactive activities for the same product or service on multiple platforms simultaneously over a period of time. This can include trading the same product or service on two servers, websites, or platforms, or requesting the same resource or access on three platforms. This is essentially multi-platform participation. Generally speaking, when a user engages in multiple activities, they face significant pressure to return occupied resources or data, accessed ports or servers, and so on, requiring a timely exit. Prolonged possession, or even failure to return or exit, increases the probability of security risks such as data loss, resource loss, and platform crashes. For example, in transactional transactions, users are more likely to engage in security risks such as dishonesty, fraud, and theft. For example, in remote transmission services, users are more likely to intentionally occupy access ports, preventing other legitimate users from accessing the platform or even causing platform crashes. Therefore, the multi-participation characteristics of a user's interactions are often analyzed to identify these security risks, anomalies, and illegality. However, the multiple participation characteristics of this interaction can only reflect the characteristics of the user's interaction at that time, and cannot reflect the changing trend of the multiple participation characteristics of previous interactions. Therefore, for users who have multiple interactions, there is an urgent need for a method that can analyze the changing trend of the multiple participation characteristics of previous interactions, thereby improving the accuracy of identifying whether the user is safe, whether there are security risks, or whether it is illegal / abnormal. Summary of the Invention
[0004] In view of this, the main purpose of the present invention is to propose a user security identification system and method based on changes in multiple participation characteristics, in order to at least partially solve at least one of the above technical problems.
[0005] In order to solve the above technical problems, the first aspect of the present invention provides a user security identification system based on changes in multiple participation characteristics, wherein the system is used to securely identify users who have interacted multiple times, and the system includes:
[0006] The first training module is used to collect multiple participation features of the user's current interaction to train the initial model;
[0007] A processing module is used to collect multiple participation features of users' previous interactions and perform derivative processing to obtain a time-series change sequence of the user's multiple participation features;
[0008] The second training module is used to input the multiple participation features of the user's current interaction and the temporal change sequence into the trained initial model for retraining to obtain a recognition model;
[0009] The identification module is used to securely identify users based on the multiple participation features of the user's current interaction, the temporal change sequence, and the identification model.
[0010] According to a preferred embodiment of the present application, the processing module comprises:
[0011] The first comparison module is configured to compare the multi-participation feature of the current interaction of the user with the multi-participation feature of the previous interaction, and obtain a change amount of the multi-participation feature of the current interaction of the user.
[0012] The first sorting module is configured to arrange the change amounts of the multi-participation features of the interactions of the user in chronological order, and obtain a time sequence of the changes of the multi-participation features of the user.
[0013] According to a preferred embodiment of the present application, the processing module comprises:
[0014] The second comparison module is configured to compare the multi-participation feature of the current interaction of the user with a representative value of the multi-participation feature of the current interaction of the user within a preset time period, and obtain a change amount of the multi-participation feature of the current interaction of the user.
[0015] The second sorting module is configured to arrange the change amounts of the multi-participation features of the interactions of the user in chronological order, and obtain a time sequence of the changes of the multi-participation features of the user.
[0016] According to a preferred embodiment of the present application, the processing module comprises:
[0017] The calculation module is configured to calculate a differential change rate of the multi-participation feature of the current interaction of the user according to the multi-participation features of the current interaction and all previous interactions of the user.
[0018] The sub-sorting module is configured to arrange the differential change rates of the multi-participation features of the interactions of the user in chronological order, and obtain a time sequence of the changes of the multi-participation features of the user.
[0019] To solve the above technical problems, the second aspect of the present application provides a user security identification method based on multi-participation feature changes, which is used for security identification of multiple interactions of a user, and comprises the following steps:
[0020] An initial model is trained according to the multi-participation feature of the current interaction of the user.
[0021] The multi-participation features of all previous interactions of the user are collected and processed to obtain a time sequence of the changes of the multi-participation features of the user.
[0022] The multi-participation feature of the current interaction of the user and the time sequence of the changes are input into the trained initial model for retraining to obtain an identification model.
[0023] The user is identified according to the multi-participation feature of the current interaction of the user, the time sequence of the changes, and the identification model.
[0024] According to a preferred embodiment of the present application, the multiple participation features of all previous interactions are derived to obtain a time sequence of the multiple participation features of the user, including:
[0025] The multiple participation feature of the current interaction of the user is compared with the multiple participation feature of the previous interaction to obtain a multiple participation feature change amount of the current interaction of the user;
[0026] The multiple participation feature change amounts of the interactions of the user are arranged in time sequence to obtain the time sequence of the multiple participation features of the user.
[0027] According to a preferred embodiment of the present application, the multiple participation features of all previous interactions are derived to obtain a time sequence of the multiple participation features of the user, including:
[0028] The multiple participation feature of the current interaction of the user is compared with the representative value of the multiple participation features in the latest preset time period of the current interaction of the user to obtain a multiple participation feature change amount of the current interaction of the user;
[0029] The multiple participation feature change amounts of the interactions of the user are arranged in time sequence to obtain the time sequence of the multiple participation features of the user.
[0030] According to a preferred embodiment of the present application, the multiple participation features of all previous interactions are derived to obtain a time sequence of the multiple participation features of the user, including:
[0031] The differential change rate of the multiple participation features of the current interaction of the user is calculated according to the multiple participation features of the current interaction and all previous interactions of the user;
[0032] The differential change rates of the multiple participation features of the interactions of the user are arranged in time sequence to obtain the time sequence of the multiple participation features of the user.
[0033] To solve the above technical problems, the third aspect of the present application provides an electronic device, comprising:
[0034] a processor; and
[0035] a memory storing computer executable instructions which, when executed, cause the processor to perform the method according to any one of the above.
[0036] To solve the above technical problems, the fourth aspect of the present application provides a computer program product, comprising a computer program, characterized in that the computer program is executed by a processor to implement the method according to any one of the above.
[0037] In summary, the present invention, based on the training of an initial model using the multiple participation features of the user's current interaction, derives the multiple participation features of previous interactions to mine a temporal change sequence of the user's multiple participation features that can reflect the changing trends of the user's historical multiple participation features; and then inputs the multiple participation features of the user's current interaction and the temporal change sequence into the trained initial model for retraining to obtain a recognition model. In this way, the recognition model can analyze and identify whether the user is safe, abnormal, or illegal based on the multiple participation features and temporal change sequence of the user's current interaction, thereby improving the accuracy of user security identification and optimizing and enhancing the efficiency, accuracy, and security monitoring performance of intelligent security monitoring in processing dynamically changing Internet big data. BRIEF DESCRIPTION OF THE DRAWINGS
[0038] In order to make the technical problems solved by the present invention, the technical means adopted, and the technical effects achieved more clearly, specific embodiments of the present invention will be described in detail below with reference to the accompanying drawings. However, it should be noted that the drawings described below are only drawings of exemplary embodiments of the present invention. Those skilled in the art can derive drawings of other embodiments based on these drawings without inventive effort.
[0039] Figure 1 Schematic diagram of the structural framework of a user security identification system based on changes in multiple participating characteristics provided by an embodiment of the present invention;
[0040] Figure 2 1 is a flow chart of a user security identification method based on changes in multiple participation characteristics provided by an embodiment of the present invention;
[0041] Figure 3 is a structural block diagram of an exemplary embodiment of an electronic device according to the present invention;
[0042] Figure 4 is a schematic diagram of an embodiment of a computer-readable medium of the present invention. DETAILED DESCRIPTION
[0043] Under the premise of being consistent with the technical concept of the present invention, the structure, performance, effect or other characteristics described in a specific embodiment may be combined with one or more other embodiments in any appropriate manner.
[0044] In the introduction of specific embodiments, the structural, performance, effect or other characteristics of the details are described in order to make the embodiments fully understood by those skilled in the art. However, it does not exclude that those skilled in the art can implement the present application without the above-mentioned structure, performance, effect or other characteristics in specific cases. The figures in the drawings are only exemplary demonstrations, and do not represent that all the contents, operations and steps in the figures must be included in the scheme of the present application, nor must they be executed in the order shown in the figures.
[0045] Reference Figure 1 , Figure 1 A user security identification system based on multiple participation feature changes is provided in an embodiment of the present application. The system is used for security identification of multiple interaction users, such as Figure 1 As shown in the figure, the system comprises:
[0046] A first training module 21 is configured to collect multiple participation features of the current interaction of a user to train an initial model. The multiple participation features include at least one of the following: interaction times, interaction platform quantity, maximum interval days of interaction, minimum interval days of interaction, maximum monthly interaction times and minimum monthly interaction times. Here, the interaction refers to a business interaction or exchange in a business provided by a platform.
[0047] A processing module 22 is configured to collect multiple participation features of previous interactions of the user to derive and obtain a time sequence change sequence of the multiple participation features of the user.
[0048] A second training module 23 is configured to input the multiple participation features of the current interaction of the user and the time sequence change sequence into the trained initial model to retrain and obtain an identification model.
[0049] An identification module 24 is configured to perform security identification of the user according to the multiple participation features of the current interaction of the user, the time sequence change sequence and the identification model.
[0050] In an optional embodiment, the processing module 22 comprises:
[0051] A first comparison module is configured to compare the multiple participation features of the current interaction of the user with the multiple participation features of the previous interaction to obtain a change amount of the multiple participation features of the current interaction of the user.
[0052] A first sorting module is configured to arrange the change amount of the multiple participation features of the interaction of the user in time sequence to obtain the time sequence change sequence of the multiple participation features of the user.
[0053] In an optional embodiment, the processing module 22 comprises:
[0054] The second comparison module is used to compare the multiple participation characteristics of the user's current interaction with the representative value of the multiple participation characteristics of the user's current interaction within a recent preset time period to obtain a change in the multiple participation characteristics of the user's current interaction;
[0055] The second sorting module is used to arrange the changes in the multiple participation characteristics of user interactions in chronological order to obtain a temporal change sequence of the multiple participation characteristics of users.
[0056] In an optional embodiment, the processing module 22 includes:
[0057] A calculation module, configured to calculate a differential change rate of the multiple participation features of the user's current interaction based on the multiple participation features of the user's current interaction and all previous interactions;
[0058] The sub-sorting module is used to arrange the differential change rates of the user interaction multiple participation features in chronological order to obtain a temporal change sequence of the user multiple participation features.
[0059] based on Figure 1 The user security identification system based on multiple participation feature changes, the embodiment of the present invention also provides a schematic diagram of a user security identification method based on multiple participation feature changes. This method can be used to securely identify users who have interacted with the platform multiple times (i.e., repeat purchase users). In this embodiment, the interaction may include: applying for rental, leasing, buying and selling, etc. Figure 2 As shown, the method includes:
[0060] S1. Collect multiple participation features of the user's current interaction to train the initial model;
[0061] In this embodiment, the multiple participation feature can reflect the behavior of users in realizing business interactions on two or more platforms within a period of time, such as the behavior of a user trading products or services on two shopping websites. The user's multiple participation feature can reflect the level of the user's ability to return the money later. Except for special cases of fraud, the more platforms the user interacts with or the amount of interactive products / services, the greater the possibility of unsafe / abnormal / non-safe return on time. Normally, the data collected by the device within a preset time period of the interaction day (such as within one month before the interaction day, before the interaction day, or between the interaction day and the previous interaction day) that is selected for disclosure or desensitization will be generated to generate the multiple participation features of the interaction day, wherein: the multiple participation features may include: at least one of the number of interactions, the number of interaction platforms, the maximum number of days between interactions, the minimum number of days between interactions, the maximum number of monthly interactions, and the minimum number of monthly interactions.
[0062] For example, this step can collect multiple engagement features of the user's current interaction date from public data on various platforms and / or data that the user chooses to make public, and input them into the initial model for training. The initial model can be a basic pre-trained model that has not been fine-tuned for a specific task, such as the base model, or a LightGBM model.
[0063] Furthermore, in order to improve the training effect, the user characteristics can be input into the initial model together with the multiple participation characteristics of the users in this interaction for training. Among them: user characteristics can be any user-related data that the user chooses to make public or has been desensitized. It may include at least one of: the user's region, user return records, user information, and user behavior information. The user return record refers to the record of whether the product is returned on time after the user interacts with the platform product. The product can be a physical product, a virtual product, a service, etc., and the present invention does not make specific limitations. The user information may include: the user's gender, age, education level, fraud record, violation record, etc. The user behavior information refers to the user's operation information on the platform, such as browsing, visiting, collecting, clicking, etc.
[0064] S2. Collect multiple participation features of the user's previous interactions and perform derivative processing to obtain a time series of changes in the user's multiple participation features;
[0065] In this embodiment, all previous interactions include the current interaction and all interactions before the current interaction. In one example, multiple participation features of the user's current interaction and each interaction time before the current interaction (such as the interaction day or the exchange day, more specifically, the transaction day of multi-platform transaction products or services, etc.) can be collected. Among them: the interaction day is not limited to the traditional transaction completion date, it can also be the rental date of the rental, the application date of the user's interaction application, etc. For example: the user's current rental application and the previous rental applications or multiple participation features v0, v1, ... vn (sorted in reverse order by rental application or rental time) can be collected, as well as the corresponding rental application or rental time point t0, t1, ... tn, where: n is a natural number.
[0066] This step derives the multiple participation features of the user's previous interactions to obtain a time series of changes in the user's multiple participation features that can reflect the changing trends of the user's historical multiple participation features. This extracts time series data that can more accurately depict the user's non-security risks, thereby improving risk control effectiveness.
[0067] In one derivative processing approach, the multiple participation characteristics of a user's current interaction can be compared with those of the previous interaction to obtain the change in the multiple participation characteristics of the current interaction. These changes in the multiple participation characteristics of the user's interactions are then arranged chronologically to obtain a temporal change sequence of the user's multiple participation characteristics. For example, the difference between the multiple participation characteristics of the user's current interaction and the previous interaction can be used as the change in the multiple participation characteristics of the user's current interaction, resulting in a temporal change sequence of the user's multiple participation characteristics {v0-v1, v1-v2...vn-1-vn}.
[0068] In another derivative processing method, the multiple participation characteristics of the user's current interaction can be compared with the representative value of the multiple participation characteristics of the user's current interaction within the most recent preset time period to obtain the change amount of the multiple participation characteristics of the user's current interaction; the change amount of the multiple participation characteristics of the user's interaction can be arranged in chronological order to obtain a temporal change sequence of the user's multiple participation characteristics. Among them: the most recent preset time period can be the most recent 30, 60, 90, 180, or 360 days, and the representative value can be an average value, a maximum value, or a minimum value. For example: the difference between the multiple participation characteristics of the user's current interaction and the maximum value of the multiple participation characteristics of the user's current interaction within the most recent 90 days can be used as the change amount of the multiple participation characteristics of the user's current interaction, and the temporal change sequence of the user's multiple participation characteristics can be obtained {v0-v 1最大 , v1-v 2最大 ...vn-1-v n最大}. v i最大 The maximum value of multiple engagement features in the last 90 days for the user's i-th interaction.
[0069] In another derivative processing method, the differential change rate of the user's multiple participation characteristics for the current interaction and all previous interactions can be calculated; the differential change rates of the user's multiple participation characteristics for the current interaction can be arranged in chronological order to obtain a time-series change sequence of the user's multiple participation characteristics. The differential change rate Fi of the user's multiple participation characteristics for the i-th interaction can be obtained by averaging the monthly changes in the multiple participation characteristics, i.e., by the following formula:
[0070] Fi=mean((v0-v1) / (t0-t1)*30+(v1-v2) / (t1-t2)*30+....).
[0071] Alternatively, the time decay factor can be introduced through the following formula to calculate the differential change rate Fi of the multiple participation features of the user's i-th interaction:
[0072] Fi=mean((v0-v1) / (t0-t1)*30*w1+(v1-v2) / (t1-t2)*30+*w2....);
[0073] Where wi = e^(-0.1*(observation time point - ti)).
[0074] S3. Input the multiple participation features of the user's current interaction and the temporal change sequence into the trained initial model for retraining to obtain a recognition model;
[0075] Among them: the initial model can use a general pre-training model, or a model for a specific task (such as the LightGBM model).
[0076] Exemplarily, in this step, the multiple participation features of the user's current interaction and the temporal change sequence can be input into the LightGBM model trained in step S1, and the LightGBM model can be retrained to obtain a recognition model.
[0077] S4. Securely identify the user based on the multiple participation features, temporal change sequence, and recognition model of the user's current interaction.
[0078] The multiple participation features and time-series change sequence of the current user's current interaction are input into the recognition model, and the security recognition result of the current user is output.
[0079] In addition, in order to verify the user security identification method based on the changes of multiple participation features of the present invention, the multiple participation features of the user's interaction at that time are input into the trained initial model for user security identification, and the multiple participation features of the user's interaction at that time and the time-series change sequence are input into the recognition model for user security identification. After experimental verification, the ACU of the recognition model increased by 1% compared with the initial model, which can effectively improve the accuracy of identifying user security conditions (unsafe / abnormal / illegal or safe).
[0080] Those skilled in the art will appreciate that the modules in the above device embodiments may be distributed in the device as described, or may be modified accordingly and distributed in one or more devices different from the above embodiments. The modules in the above embodiments may be combined into one module or further split into multiple submodules.
[0081] The following describes an electronic device embodiment of the present invention. This electronic device can be considered a physical implementation of the method and apparatus embodiments of the present invention described above. Details described in the electronic device embodiment of the present invention should be considered supplementary to the above-described method or apparatus embodiments; details not disclosed in the electronic device embodiment of the present invention can be implemented with reference to the above-described method or apparatus embodiments.
[0082] Figure 3 is a structural block diagram of an exemplary embodiment of an electronic device according to the present invention. Figure 3 The electronic device shown is only an example and should not limit the functions and scope of use of the embodiments of the present invention.
[0083] like Figure 3 As shown, the electronic device 300 of this exemplary embodiment is in the form of a general-purpose data processing device. Components of the electronic device 300 may include, but are not limited to, at least one processing unit 310, at least one storage unit 320, a bus 330 connecting different electronic device components (including the storage unit 320 and the processing unit 310), a display unit 340, and the like.
[0084] The storage unit 320 stores a computer-readable program, which may be a source program or a code of a read-only program. The program may be executed by the processing unit 310, so that the processing unit 310 performs the steps of various embodiments of the present invention. For example, the processing unit 310 may perform the following steps: Figure 1 Steps shown.
[0085] Bus 330 may represent one or more of several types of bus structures, including a memory bus or memory controller, a peripheral bus, an accelerated graphics port, a processing unit, or a local bus using any of a variety of bus architectures.
[0086] The electronic device 300 may also communicate with one or more external devices 100 (e.g., a keyboard, a display, a network device, a Bluetooth device, etc.), allowing a user to interact with the electronic device 300 via these external devices 100, and / or allowing the electronic device 300 to communicate with one or more other data processing devices (e.g., a router, a modem, etc.). Such communication may be performed through an input / output (I / O) interface 350, and may also be performed through a network adapter 360 to communicate with one or more networks (e.g., a local area network (LAN), a wide area network (WAN), and / or a public network). The network adapter 360 may communicate with other modules of the electronic device 300 via the bus 330.
[0087] Figure 4 Schematic diagram of a computer readable medium embodiment of the present invention. Figure 4As shown, the computer program can be stored on one or more computer-readable media. The computer-readable medium can be a readable signal medium or a readable storage medium. When the computer program is executed by one or more data processing devices, the computer-readable medium can implement the above-mentioned method of the present invention, namely: collecting multiple participation features of the user's current interaction to train the initial model; the multiple participation features include: the number of interactions, the number of interaction platforms, the maximum number of days between interactions, the minimum number of days between interactions, the maximum number of monthly interactions, and at least one of the minimum number of monthly interactions; collecting the multiple participation features of the user's previous interactions and performing derivative processing to obtain a time series change sequence of the user's multiple participation features; inputting the multiple participation features of the user's current interaction and the time series change sequence into the trained initial model for retraining to obtain a recognition model; securely identifying the user based on the multiple participation features of the user's current interaction, the time series change sequence, and the recognition model.
[0088] In summary, the present invention can be implemented by executing a computer program method, apparatus, system, electronic device, or computer-readable medium. In practice, a general-purpose data processing device such as a microprocessor or digital signal processor (DSP) can be used to implement some or all of the functions of the present invention.
[0089] The specific embodiments described above further illustrate the objectives, technical solutions, and beneficial effects of the present invention. It should be understood that the present invention is not inherently related to any specific computer, virtual device, or electronic device, and various general-purpose devices can also implement the present invention. The above description is only a specific embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present invention shall be included in the scope of protection of the present invention.
Claims
1. A user security identification system based on multiple participation feature changes, characterized in that: The system is used to securely identify users who have had multiple business interactions, and the system includes: The first training module is used to collect multiple participation features of the user's current interaction to train the initial model; A processing module is used to collect multiple participation features of users' previous interactions and perform derivative processing to obtain a time-series change sequence of the user's multiple participation features; The second training module is used to input the multiple participation features of the user's current interaction and the temporal change sequence into the trained initial model for retraining to obtain a recognition model; The identification module is used to securely identify users based on the multiple participation features of the user's current interaction, the temporal change sequence, and the identification model.
2. The system according to claim 1, wherein: The processing module includes: A first comparison module is used to compare the multiple participation features of the user's current interaction with the multiple participation features of the previous interaction to obtain a change in the multiple participation features of the user's current interaction; The first sorting module is used to arrange the changes in the multiple participation characteristics of user interactions in chronological order to obtain a temporal change sequence of the multiple participation characteristics of users.
3. The system according to claim 1, wherein: The processing module includes: The second comparison module is used to compare the multiple participation characteristics of the user's current interaction with the representative value of the multiple participation characteristics of the user's current interaction within a recent preset time period to obtain a change in the multiple participation characteristics of the user's current interaction; The second sorting module is used to arrange the changes in the multiple participation characteristics of user interactions in chronological order to obtain a temporal change sequence of the multiple participation characteristics of users.
4. The system according to claim 1, wherein: The processing module includes: A calculation module, configured to calculate a differential change rate of the multiple participation features of the user's current interaction based on the multiple participation features of the user's current interaction and all previous interactions; The sub-sorting module is used to arrange the differential change rates of the user interaction multiple participation features in chronological order to obtain a temporal change sequence of the user multiple participation features.
5. A user security identification method based on changes in multiple participation characteristics, characterized in that: The method is used to securely identify a user who has interacted multiple times, and the method includes: Collect multiple engagement features of the user's interaction to train the initial model; Collect multiple participation features of users' previous interactions and perform derivative processing to obtain a time-series change sequence of users' multiple participation features; Inputting the multiple participation features of the user's current interaction and the temporal change sequence into the trained initial model for retraining to obtain a recognition model; Users are securely identified based on the multiple participation features, temporal change sequences, and recognition models of their current interactions.
6. The method according to claim 5, characterized in that The multiple participation features of all interactions are derived to obtain the temporal change sequence of the user's multiple participation features, including: Compare the multiple participation features of the user's current interaction with the multiple participation features of the previous interaction to obtain the change in the multiple participation features of the user's current interaction; Arrange the changes of multiple participation features of user interaction in chronological order to obtain the temporal change sequence of user multiple participation features.
7. The method according to claim 5, characterized in that The multiple participation features of all interactions are derived to obtain the temporal change sequence of the user's multiple participation features, including: Compare the multiple participation features of the user's current interaction with the representative value of the multiple participation features of the user's current interaction within a recent preset time period to obtain the change in the multiple participation features of the user's current interaction; Arrange the changes of multiple participation features of user interaction in chronological order to obtain the temporal change sequence of user multiple participation features.
8. The method according to claim 5, characterized in that The multiple participation features of all interactions are derived to obtain the temporal change sequence of the user's multiple participation features, including: Calculate the differential change rate of the user's multiple participation features based on the user's current interaction and all previous interactions; The differential change rates of the user interaction multiple participation features are arranged in chronological order to obtain the temporal change sequence of the user multiple participation features.
9. An electronic device comprising: processor; as well as A memory storing computer executable instructions which, when executed, cause the processor to perform the method according to any one of claims 5 to 8.
10. A computer program product comprising a computer program, characterized in that When the computer program is executed by a processor, the method according to any one of claims 5 to 8 is implemented.