Fraud order management and control method, fraud order management and control device, equipment and medium
By obtaining a fraud detection dataset for cross-border e-commerce transactions and using a fraud detection model to identify buyer fraud, we address the difficulties of identifying buyer fraud and the lack of detection methods, enabling efficient and accurate fraud order management and ensuring transaction security and user experience.
Patent Information
- Application Number
- CN202510876274.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-27
- Publication Date
- 2025-10-10
AI Technical Summary
In existing cross-border e-commerce transactions, it is difficult to identify buyer fraud. Existing detection methods have a high missed detection rate and insufficient explainability. It is difficult to provide specific reasons for fraud and effective verification processes, which affects transaction security and platform operations.
By obtaining the fraud detection dataset of users' real-time transactions, using the preset fraud detection model to determine the fraud suspicion, and matching the corresponding fraud detection explanation items, the verification process is initiated to determine whether to execute the transaction transfer process.
It improves the accuracy and efficiency of fraud identification, reduces the misjudgment rate, enhances the explainability and credibility of fraud determination, ensures a balance between transaction security and user experience, and protects the legitimate rights and interests of both parties to the transaction.
Smart Images

Figure CN120765265A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of e-commerce technology, and in particular to a fraudulent order control method and its corresponding device, computer equipment, and computer-readable storage medium. Background Art
[0002] With the rapid development of internet technology, cross-border e-commerce transactions are booming, providing buyers with convenient shopping channels and expanding the market for merchants. However, this also poses a serious threat to the legitimate rights and interests of both parties involved in cross-border e-commerce transactions and the reputation of the platforms themselves.
[0003] In cross-border e-commerce transactions, fraudulent orders are primarily categorized into two types: merchant fraud and buyer fraud. Merchant fraud is relatively easy to identify and address, as merchants must submit application materials before opening a store. The platform can conduct preliminary identification during the application phase, and after the merchant opens, the platform can conduct subsequent assessments based on the merchant's behavior. Once a merchant is found to have violated regulations, measures such as closing the store or freezing the account can be taken to effectively curb fraudulent activity.
[0004] However, identifying order fraud at the buyer level faces numerous challenges. For one thing, most buyers are new, and platforms lack profiles of them, making identification extremely difficult. On the other hand, after buyer fraud occurs, re-identification can be easier through a complaint, but recovering losses is difficult. For example, after receiving the goods, a buyer may maliciously file a complaint with the merchant to demand compensation, or the buyer's bank card may be stolen or their account may be used illegally. This not only causes losses to the cardholder, but also exposes the merchant to unnecessary disputes and / or financial losses.
[0005] Existing fraud detection methods often focus on analyzing merchant behavior, but their ability to identify buyer fraud is limited. Some platforms attempt to detect fraud using simple rule engines, but this approach suffers from the manual process of rule development, resulting in high coverage and missed detection rates for fraudulent orders. Furthermore, while these fraud detection models can identify some fraudulent behaviors, they lack interpretability and operability, making it difficult to provide specific fraud causes and effective verification processes. This leaves platforms without a solid basis for handling fraudulent orders.
[0006] Therefore, there is an urgent need for a management and control method that can effectively identify fraudulent orders from buyers, provide detailed and reliable fraud identification explanations, and have a reliable verification process, so as to improve the security and reliability of cross-border e-commerce transactions, protect the legitimate rights and interests of both parties to the transaction, and maintain the normal operation order of the platform. Summary of the Invention
[0007] The primary purpose of this application is to solve at least one of the above problems and provide a fraudulent order control method and its corresponding device, computer equipment, and computer program product.
[0008] In order to meet the various objectives of this application, this application adopts the following technical solutions:
[0009] A fraudulent order control method provided for one of the purposes of this application includes the following steps:
[0010] Obtaining a target order generated by a user's real-time transaction, and determining a fraud detection dataset corresponding to the target order at a current moment, wherein the fraud detection dataset includes fraud detection data corresponding to a plurality of detection fields;
[0011] Inputting the fraud detection data set into a preset fraud detection model to determine the corresponding fraud suspicion;
[0012] When the fraud suspicion indicates that the transaction is suspected of fraud, determining a target detection detailed explanation item in a preset fraud detection explanation set that matches the fraud detection dataset;
[0013] Start the fraud verification process corresponding to the target detection detailed item, and determine whether to execute the transaction transfer process of the target order based on the obtained verification result.
[0014] On the other hand, a fraud order management device provided to meet one of the purposes of the present application includes a data acquisition module, a suspicion determination module, a detailed explanation item matching module and a process execution module, wherein the data acquisition module is used to obtain the target order generated by the user's real-time transaction and determine the fraud detection data set corresponding to the target order at the current moment, and the fraud detection data set includes fraud detection data corresponding to multiple detection fields; the suspicion determination module is used to input the fraud detection data set into a preset fraud detection model to determine the corresponding fraud suspicion; the detailed explanation item matching module is used to determine the target detection detailed explanation item in the preset fraud detection explanation set that matches the fraud detection data set when the fraud suspicion indicates that the transaction is suspected of fraud; the process execution module is used to start the fraud verification process corresponding to the target detection detailed explanation item, and determine whether to execute the transaction transfer process of the target order based on the obtained verification result.
[0015] On the other hand, a computer device provided to meet one of the purposes of the present application includes a central processing unit and a memory, wherein the central processing unit is used to call and run a computer program stored in the memory to execute the steps of the fraudulent order control method described in the present application.
[0016] On the other hand, a computer program product provided to meet another purpose of the present application includes a computer program / instruction, which, when executed by a processor, implements the steps of the method described in any embodiment of the present application.
[0017] The technical solution of this application has many advantages, including but not limited to the following:
[0018] This application first obtains the target orders generated by users' real-time transactions and determines the corresponding fraud detection dataset. This dataset covers data corresponding to multiple detection fields. Compared with the traditional method of making judgments based on only a small amount of simple information, it can comprehensively and deeply capture the various features and details most relevant to fraudulent behavior, avoid wasting resources on redundant features, and provide a rich and accurate data foundation for subsequent fraud detection, so that the fraud detection model can perform accurate analysis based on these detailed data, effectively improving the accuracy of fraud identification and greatly reducing the false positive rate. This is of great significance both for timely and accurate identification of orders that really pose a risk of fraud to avoid losses, and for preventing normal orders from being misjudged as fraud and affecting user experience and normal business operations.
[0019] Secondly, in terms of fraud detection efficiency, inputting the fraud detection dataset into the preset fraud detection model can quickly derive the corresponding fraud suspicion level, eliminating the need to manually check the fraud risks in a large number of orders one by one. This greatly saves time and labor costs and improves the overall efficiency of transaction processing. Especially in business scenarios with massive orders, this efficient fraud detection mechanism can ensure the smooth progress of the transaction process and will not affect the operation speed of the entire business due to delays in the fraud detection link. It plays a significant role in improving the company's operational efficiency and competitiveness.
[0020] Furthermore, when the fraud suspicion indicates that a transaction is suspected of fraud, the target detection detailed explanation items in the preset fraud detection explanation set that match the fraud detection data set can be determined, and the corresponding fraud verification process can be initiated. This not only provides a clear and specific explanation basis for fraud judgment, making fraud judgment no longer an ambiguous "black box", but also enhances the interpretability and credibility of the entire fraud control process, making it easier for relevant personnel such as platform operators to understand the basis and logic of fraud judgment, and making subsequent fraud verification more targeted. It can accurately conduct in-depth verification of suspected fraudulent orders based on the target detection detailed explanation items, and determine whether to execute the transaction transfer process of the target order based on the verification results. This rigorous and organized processing method not only ensures transaction security, but also guarantees user experience to a certain extent, avoids unnecessary troubles to users due to unreasonable fraud control measures, and achieves a balance between transaction security and user experience, which has a far-reaching impact on building good business reputation, customer relationships, and the long-term and stable development of the platform. BRIEF DESCRIPTION OF THE DRAWINGS
[0021] The above and / or additional aspects and advantages of the present application will become apparent and easily understood from the following description of the embodiments in conjunction with the accompanying drawings, in which:
[0022] Figure 1The network architecture of the e-commerce platform exemplified in this application;
[0023] Figure 2 This is a flowchart of a typical embodiment of the fraudulent order control method of the present application;
[0024] Figure 3 This is a functional block diagram of the fraudulent order control device of this application;
[0025] Figure 4 This is a schematic diagram of the structure of a computer device used in this application. DETAILED DESCRIPTION
[0026] The following describes in detail embodiments of the present application, examples of which are shown in the accompanying drawings, wherein the same or similar reference numerals throughout represent the same or similar elements or elements having the same or similar functions. The embodiments described below with reference to the accompanying drawings are exemplary and are only used to explain the present application, and are not to be construed as limiting the present application.
[0027] It will be understood by those skilled in the art that, unless expressly stated otherwise, the singular forms "a", "an", "said" and "the" used herein may also include the plural forms. It should be further understood that the term "comprising" used in the specification of the present application refers to the presence of the features, integers, steps, operations, elements and / or components, but does not exclude the presence or addition of one or more other features, integers, steps, operations, elements, components and / or groups thereof. It should be understood that when we refer to an element as being "connected" or "coupled" to another element, it may be directly connected or coupled to the other element, or there may be intermediate elements. In addition, "connected" or "coupled" as used herein may include wireless connections or wireless couplings. The term "and / or" used herein includes all or any units and all combinations of one or more associated listed items.
[0028] It will be understood by those skilled in the art that, unless otherwise defined, all terms (including technical and scientific terms) used herein have the same meaning as commonly understood by those skilled in the art to which this application belongs. It should also be understood that terms such as those defined in common dictionaries should be understood to have meanings consistent with their meanings in the context of the prior art and will not be interpreted in an idealized or overly formal sense unless specifically defined as herein.
[0029] like Figure 1 In the network architecture shown, the e-commerce platform 82 is deployed on the Internet to provide corresponding services to its users. Similarly, the devices 80 of the merchant users of the e-commerce platform 82 and the devices 81 of the consumer users are also connected to the Internet to use the services provided by the e-commerce platform.
[0030] The exemplary e-commerce platform 82 provides supply and demand matching of products and / or services to the general public with the help of Internet infrastructure. In the e-commerce platform 82, products and / or services are provided as commodity information. To simplify the description, the concepts of commodity, product, etc. are used in this application to refer to the products and / or services in the e-commerce platform 82, which may specifically be physical products, digital products, tickets, service subscriptions, other offline services, etc.
[0031] In reality, various entities can access the e-commerce platform 82 as users, use the various online services provided by the e-commerce platform 82, and achieve the purpose of participating in the business activities achieved by the e-commerce platform 82. These entities can be natural persons, legal persons, or social organizations. Corresponding to the two types of entities in business activities, merchants and consumers, the e-commerce platform 82 has two corresponding types of users: merchant users and consumer users. In business activities, all entities in the product distribution chain, including manufacturers, sellers, retailers, logistics providers, etc., can use online services on the e-commerce platform 82 as merchant users, while consumers in business activities, including real or potential consumers, can use online services on the e-commerce platform 82 as their corresponding consumer users. In actual business activities, the same entity can act as both a merchant user and a consumer user, and this should be understood flexibly.
[0032] The infrastructure used to deploy the e-commerce platform 82 primarily includes a backend architecture and frontend devices. The backend architecture runs various online services through a service cluster, including platform-facing middleware or frontend services, consumer-facing services, merchant-facing services, etc., to enrich and improve its service functions. The frontend devices primarily encompass the terminal devices used by users to access the e-commerce platform 82 as clients, including but not limited to various mobile terminals, personal computers, point-of-sale devices, etc. For example, a merchant user can use their terminal device 80 to enter product information for their online store, or generate their product information using an interface open to the e-commerce platform. A consumer user can use their terminal device 81 to access the webpage of the online store implemented by the e-commerce platform 82, trigger the shopping process through the shopping button provided on the webpage, and invoke various online services provided by the e-commerce platform 82 during the shopping process, thereby completing the purpose of placing a shopping order.
[0033] In some embodiments, the e-commerce platform 82 may be implemented by a processing facility including a processor and a memory, the processing facility storing a set of instructions that, when executed, cause the e-commerce platform 82 to perform the e-commerce and support functions described herein. The processing facility may be part of a server, client, network infrastructure, mobile computing platform, cloud computing platform, fixed computing platform, or other computing platform, and may provide electronic components of the e-commerce platform 82, merchant devices, payment gateways, application developers, marketing channels, transportation providers, customer devices, point-of-sale devices, and the like.
[0034] The e-commerce platform 82 can be implemented as an online service such as cloud computing, software as a service (SaaS), infrastructure as a service (IaaS), platform as a service (PaaS), desktop as a service (DaaS), hosted software as a service, mobile backend as a service (MBaaS), information technology management as a service (ITMaaS), etc. In some embodiments, the various functional components of the e-commerce platform 82 can be implemented to be suitable for operation on various platforms and operating systems. For example, for an online store, its administrator users can enjoy the same or similar functions regardless of the various embodiments such as iOS, Android, HomonyOS, or web pages.
[0035] The e-commerce platform 82 can implement its corresponding independent website for each merchant to run its corresponding online store, and provide merchants with corresponding business management engine instances for merchants to establish, maintain, and run one or more online stores in one or more independent websites. The business management engine instance can be used for content management, task automation, and data management of one or more online stores, and can configure various specific business processes of the online store through interfaces or built-in components to support the implementation of business activities. The independent website is the infrastructure of the e-commerce platform 82 with cross-border service functions. Merchants can maintain their online stores more centrally and independently based on the independent website. The independent website usually has a domain name and storage space dedicated to the merchant, and different independent websites are relatively independent. The e-commerce platform 82 can provide standardized or personalized technical support for a large number of independent websites, so that merchant users can customize their own business management engine instance and use this business management engine instance to maintain one or more online stores they own.
[0036] The online store can implement backend configuration and maintenance by having the merchant user log in to its business management engine instance as an administrator. With the support of various online services provided by the infrastructure of the e-commerce platform 82, the merchant user can configure various functions in its online store as an administrator, view various data, etc. For example, the merchant user can manage various aspects of its online store, such as viewing the latest activities of the online store, updating the online store product catalog, managing orders, recent visit activities, total order activities, etc.; the merchant user can also view more detailed information about the business and visitors to the merchant's online store by obtaining reports or metrics, such as showing a sales summary of the merchant's overall business, specific sales and participation data of active sales marketing channels, etc.
[0037] The e-commerce platform 82 may provide communication facilities and associated merchant interfaces for providing electronic communications and marketing, such as utilizing electronic message aggregation facilities to collect and analyze communication interactions between merchants, consumers, merchant devices, customer devices, point-of-sale devices, etc., aggregating and analyzing communications, such as for increasing the potential for providing product sales, etc. For example, a consumer may have questions about a product, which may generate a conversation between the consumer and the merchant (or an automated processor-based agent on behalf of the merchant), wherein the communication facility is responsible for the interaction and provides the merchant with analysis on how to increase the probability of sales.
[0038] In some embodiments, applications suitable for installation on terminal devices can be provided to serve the access needs of different users, so that various users can access the e-commerce platform 82 by running applications on the terminal devices, such as the merchant backend module of the online store in the e-commerce platform 82. In the process of implementing business activities through these functions, the e-commerce platform 82 can implement various functions related to supporting business activities as middleware or online services and open corresponding interfaces, and then implant toolkits corresponding to the interface access functions into the application to realize functional expansion and task implementation. The business management engine can include a series of basic functions and expose these functions to online services and / or application calls through APIs. The online services and applications use the corresponding functions by remotely calling the corresponding APIs.
[0039] Supported by the various components of the business management engine instance, the e-commerce platform 82 provides online shopping functionality, enabling merchants to connect with customers in a flexible and transparent manner. Consumers can select items online, create an order, provide a delivery address in the order, and complete payment confirmation for the order. Merchants can then review and complete or cancel the order.
[0040] A fraudulent order control method of the present application can be programmed as a computer program product and deployed in a client or server for execution. For example, in the exemplary application scenario of the present application, it can be deployed and implemented in the server of an e-commerce customer service platform. The method can be executed by accessing an interface opened after the computer program product is run and performing human-computer interaction with the process of the computer program product through a graphical user interface.
[0041] See also Figure 2 The fraudulent order control method of the present application, in its typical embodiment, includes the following steps:
[0042] Step S1100: Obtain a target order generated by a real-time transaction of a user, and determine a fraud detection dataset corresponding to the target order at the current moment, wherein the fraud detection dataset includes fraud detection data corresponding to a plurality of detection fields;
[0043] In the e-commerce platform operation scenario, when a user selects a product and completes the subscription process, the product transaction process will be started with the merchant, and a corresponding product order will be generated. Once the user performs a transaction operation on this product order, such as triggering the call of the funds transfer interface that the e-commerce platform has pre-connected with the relevant financial institution or payment platform, the terminal device used by the user will generate an order transaction request with a unique identifier for the order based on the relevant information of the order, and send the request to the server of the e-commerce platform. This identifier is equivalent to the exclusive "identity card" of the order, which is used to accurately distinguish this order from all other orders. Its specific form can be an ID, etc., and technicians in this field can flexibly set it according to actual business needs.
[0044] After receiving the order transaction request, the e-commerce platform's server responds to the request and, based on the order identifier carried in the request, confirms that the order is the target order currently requiring control. In order to accurately detect whether the order has the potential risk of buyer fraud, multiple key detection fields are pre-selected. These detection fields cover various important information during the transaction process. By collecting and analyzing the detection data corresponding to these detection fields, this data is used as the core basis for fraud detection, thereby achieving effective detection of fraudulent behavior. Thus, for each detection field, the data corresponding to the detection field of the target order at the current moment is obtained as fraud detection data. Finally, the fraud detection data corresponding to each detection field is aggregated to form a complete fraud detection dataset, providing a comprehensive and accurate data foundation for subsequent fraud detection analysis.
[0045] Step S1200: Input the fraud detection dataset into a preset fraud detection model to determine the corresponding fraud suspicion level;
[0046] Before practical application, the fraud detection model is pre-trained to convergence, learning to infer fraud suspicion based on input order-related test data. Fraud detection models can be selected from models such as LightGBM and BERT, and those skilled in the art can flexibly adapt their implementation. These models are deep learning models suitable for binary classification tasks in natural domains. Therefore, during training, the fraud detection model has learned how to extract key features from order-related test data and use these key features to determine whether the buyer of an order is fraudulent.
[0047] During the inference phase of the fraud detection model, the model processes the input order-related data through its internal neural network architecture. This neural network architecture comprises multiple hidden layers and an output layer, with each hidden layer containing a large number of neurons. These neurons perform a series of operations on the input data, including weighted summation and nonlinear transformations. Ultimately, the output layer outputs the suspicion level of buyer fraud for the order. This suspicion level is expressed as a probability value, which quantifies the likelihood of buyer fraud in the order.
[0048] Step S1300: When the fraud suspicion indicates that the transaction is suspected of fraud, determining a target detection detailed explanation item in a preset fraud detection explanation set that matches the fraud detection dataset;
[0049] In one embodiment, multiple suspected gears and their gear ranges can be pre-set to measure the degree of confidence in the currently determined fraud suspicion. These suspected gears and their gear ranges can be divided as needed by those skilled in the art. For example, the corresponding gear ranges for low, medium, and high are [0, 0.65], (0.65, 0.85), and (0.85, 1], respectively. Thus, the suspected gear corresponding to the gear range to which the currently determined fraud suspicion belongs is determined as the suspected gear to which the fraud suspicion belongs.
[0050] The fraud detection explanation set contains multiple detection explanation items. These items include specific criteria for judging the fraud detection data in the corresponding fraud detection dataset to determine the fraud suspicion of the order. For example, a detection explanation item may include: the time difference between the buyer browsing the product and the product transaction does not exceed a certain period of time... the number of times the buyer's device fingerprint triggered the product transaction in the past week does not exceed a certain number.
[0051] When the fraud suspicion level falls within the lowest level, the transaction is deemed secure and fraud-free, and the target order's transaction transfer process continues. When the fraud suspicion level falls below the lowest level, the transaction is deemed fraudulent, and the fraud detection dataset used to derive the fraud suspicion level is determined. The detection explanation item found in the fraud detection explanation set is used as the target detection explanation item. This target detection explanation item clearly and in detail explains why the fraud detection dataset detected the fraud suspicion level, providing both explanations for e-commerce platform operators and reliable analytical support for order submissions and order detection explanations.
[0052] Step S1400: Start the fraud verification process corresponding to the target detection detailed explanation item, and determine whether to execute the transaction transfer process of the target order based on the obtained verification result. In a further embodiment, the following steps are included:
[0053] Step S1410: Obtain the fraud type to which the target detection detailed explanation item belongs;
[0054] It's understandable that each detailed explanation item in the fraud detection explanation set reflects the specific fraud characteristics of the associated order. Furthermore, e-commerce platform operators can pre-collect and / or analyze orders corresponding to buyer fraud, determine the fraud type of each order, and then match these orders with the detailed explanation items in the fraud detection explanation set to identify the detailed explanation items that match these orders. This allows them to label the fraud type of each detailed explanation item as the fraud type of the order corresponding to that detailed explanation item. Different fraud types include malicious complaints against merchants, bank card theft, and account theft. Malicious merchant fraud involves buyers deliberately refusing to acknowledge legitimate transactions and filing complaints against merchants, hoping to receive compensation if the merchant loses the case. Bank card theft involves buyers using stolen bank cards that don't belong to them to conduct transactions. Account theft involves buyers using stolen accounts that don't belong to them to conduct transactions.
[0055] Step S1420: When the fraud type indicates a malicious complaint against a merchant, a merchant-side verification process is initiated to obtain a corresponding verification result;
[0056] In one embodiment, during the merchant-side verification process, the e-commerce platform's server pushes verification instructions or information to the merchant that generated the target order via a pre-set interface, prompting the merchant to proactively contact the buyer to communicate and verify the transaction details, product status, buyer's intentions, and other order details. Based on the communication process, the merchant then sends verification results back to the server via the interface, indicating whether the buyer's transaction intentions are genuine and there is no potential risk of malicious complaints.
[0057] Step S1430: When the fraud type indicates an involuntary transaction, a third-party verification process is initiated to obtain a corresponding verification result;
[0058] It is understandable that fraud types such as bank card theft and account theft both represent involuntary transactions.
[0059] In one embodiment, in the third-party verification process, the e-commerce platform utilizes the security verification mechanism of a pre-connected third-party transaction channel institution, the bank's risk control system, or a dedicated identity verification service (such as liveness detection, SMS verification code strong verification, etc.). The necessary risk information (such as encrypted transaction tokens, risk level identification) is passed to the relevant third-party transaction channel institution through a preset security interface, or an additional strong security authentication (such as SMS verification, email authentication, biometric information verification, etc.) is initiated to the buyer's device corresponding to the target order. The corresponding third-party system or the verification service it provides will confirm whether the transaction is secure or whether the buyer's identity and authorization are confirmed, and return the result to the platform's server as the verification result.
[0060] Step S1440: When the verification result indicates that the verification is passed, the transaction transfer process of the target order is executed, and a detection report is constructed based on the verification result, fraud suspicion, and target detection details, and pushed to the user;
[0061] At this point, it means that the buyer corresponding to the target order's transaction, from suspicion to confirmation, has not committed fraud, and the transaction transfer process of the target order is allowed to continue, that is, the fund transfer business between the subsequent transaction-related parties is completed to ensure the normal fulfillment of the transaction. In addition, at the same time as the transfer is completed, a detailed and sensitive information-masked detection report is dynamically constructed based on the full-link data of this fraud detection and verification. This report integrates and summarizes the fraud suspicion value that caused the high suspicion judgment, the reasons that triggered further verification, and the details of the verification results that ultimately eliminated the risk. After the construction is completed, this detection report is automatically pushed to the user terminal corresponding to the target order through a message push service (such as in-app message, SMS or email).
[0062] Of course, the test report without desensitizing sensitive information can be saved in the server so that the operators of the e-commerce platform can review and use it at any time as needed.
[0063] Step S1450: When the verification result indicates that the verification fails, the transaction transfer process of the target order is rejected.
[0064] At this point, suspicions have been raised about buyer fraud. To prevent financial losses and other potential risks, immediate action is taken to deny further transfers. Specifically, the transaction request for the order is terminated, and a transaction cancellation or failure instruction is sent to the relevant funds transaction interface to ensure that the funds are not withdrawn. At the same time, the order status may be set to "Terminated due to Fraud Risk" or a similar status, which may trigger a subsequent investigation or manual review mechanism.
[0065] Through the disclosure of this exemplary embodiment and its alternative embodiments, it can be understood that this application has many positive advantages, including but not limited to the following aspects:
[0066] First, by obtaining the target orders generated by users' real-time transactions and determining the corresponding fraud detection dataset, this dataset covers data corresponding to multiple detection fields. Compared with the traditional method of making judgments based on only a small amount of simple information, it can comprehensively and deeply capture the various features and details most relevant to fraudulent behavior, avoiding wasting resources on redundant features, and providing a rich and accurate data foundation for subsequent fraud detection, so that the fraud detection model can perform accurate analysis based on this detailed data, effectively improving the accuracy of fraud identification and greatly reducing the false positive rate. This is of great significance both for the timely and accurate identification of orders that really pose a risk of fraud to avoid losses, and for normal orders to prevent them from being misjudged as fraud and affecting user experience and normal business operations.
[0067] Secondly, in terms of fraud detection efficiency, inputting the fraud detection dataset into the preset fraud detection model can quickly derive the corresponding fraud suspicion level, eliminating the need to manually check the fraud risks in a large number of orders one by one. This greatly saves time and labor costs and improves the overall efficiency of transaction processing. Especially in business scenarios with massive orders, this efficient fraud detection mechanism can ensure the smooth progress of the transaction process and will not affect the operation speed of the entire business due to delays in the fraud detection link. It plays a significant role in improving the company's operational efficiency and competitiveness.
[0068] Furthermore, when the fraud suspicion indicates that a transaction is suspected of fraud, the target detection detailed explanation items in the preset fraud detection explanation set that match the fraud detection data set can be determined, and the corresponding fraud verification process can be initiated. This not only provides a clear and specific explanation basis for fraud judgment, making fraud judgment no longer an ambiguous "black box", but also enhances the interpretability and credibility of the entire fraud control process, making it easier for relevant personnel such as platform operators to understand the basis and logic of fraud judgment, and making subsequent fraud verification more targeted. It can accurately conduct in-depth verification of suspected fraudulent orders based on the target detection detailed explanation items, and determine whether to execute the transaction transfer process of the target order based on the verification results. This rigorous and organized processing method not only ensures transaction security, but also guarantees user experience to a certain extent, avoids unnecessary troubles to users due to unreasonable fraud control measures, and achieves a balance between transaction security and user experience, which has a far-reaching impact on building good business reputation, customer relationships, and the long-term and stable development of the platform.
[0069] In a further embodiment, after step S1200, inputting the fraud detection dataset into a preset fraud detection model and determining the corresponding fraud suspicion, the following steps are included:
[0070] Step S2200: determining the suspicion level to which the fraud suspicion level belongs, and obtaining an additional suspicion level when the suspicion level meets a preset condition;
[0071] The gear range of each suspected gear is matched with the fraud suspicion degree, and the gear range to which the fraud suspicion degree belongs is determined. The suspected gear in the gear range is used as the suspected gear to which the fraud suspicion degree belongs. When the suspected gear is not the highest suspected gear, it means that the suspected gear at this time meets the preset conditions. Further consideration is given to the additional suspicion of buyer fraud corresponding to the target order, which is quantified as the additional suspicion degree and obtained. It can be understood that when there is a reasonable suspicion that the buyer fraud corresponding to the target order has more suspicions, the additional suspicion degree should increase accordingly. In addition, considering that objectively as time increases, the suspicion of doubt should decrease accordingly. Therefore, a time decay function can be called to reduce the additional suspicion degree accordingly as time increases. The time decay function can be a time decay function including an exponential decay function, a Gaussian decay function, a linear decay function, a natural logarithmic decay function, etc. Those skilled in the art can choose one to implement as needed.
[0072] Step S2210: updating the additional suspicion level with the preset suspicion value corresponding to the suspected gear, and determining whether the updated additional suspicion level meets the standard;
[0073] The suspicious values corresponding to each suspected gear other than the highest suspected gear are used to increase the additional suspicion, and the higher the suspected gear, the higher the suspicious value, which makes the higher suspected gear have a higher suspicion. Those skilled in the art can set it as needed based on the disclosure herein.
[0074] The suspicious value of the suspicion level is added to the additional suspicion to obtain the latest additional suspicion, completing the update of the additional suspicion. Further, a suspicion level that is one level higher than the suspicion level of the fraud suspicion before the update is determined, and it is determined whether the sum of the latest additional suspicion and the current fraud suspicion falls within this determined level range. If it does, it means that the latest additional suspicion meets the standard; if it does not, it means that the latest additional suspicion does not meet the standard, and there is no need to perform subsequent steps for the operation of the additional suspicion.
[0075] Step S2220: When the additional suspicion level reaches a certain level, the fraud suspicion level is updated to a higher level using the additional suspicion level, and the additional suspicion level is updated using a preset reduction ratio corresponding to the higher level.
[0076] For each suspicious gear that is not the lowest suspicious gear, a reduction ratio of the suspicious gear is pre-configured to reduce the additional suspicion. The higher the suspicious gear, the smaller the reduction ratio, so that a higher suspicion is maintained for a higher suspicious gear. Those skilled in the art can set it as needed based on the disclosure herein.
[0077] At this point, the qualified additional suspicion level is added to the current fraud suspicion level to obtain the latest fraud suspicion level, completing the update. This fraud suspicion level will inevitably be one level higher than the level it belonged to before the update. Since the fraud suspicion level has been increased, the additional suspicion level needs to be reduced accordingly to avoid the subsequent increase in unnecessary suspicion level and ensure the legitimacy of the challenge. To this end, the additional suspicion level is multiplied by the reduction ratio corresponding to the suspicion level of the latest fraud suspicion level to obtain the latest additional suspicion level, completing the update of the additional suspicion level.
[0078] This embodiment further refines the assessment and management of fraud suspicion by introducing the concept of suspicion levels and a dynamic mechanism for acquiring, updating, and judging additional suspicions. First, categorizing fraud suspicion into different levels more intuitively reflects the varying levels of fraud risk within an order, enabling more targeted action. When a suspicion level meets pre-set criteria, additional suspicion is acquired and adjusted using a time-decay function. This fully accounts for changes in reasonable suspicion of fraud over time, avoids excessive accumulation of additional suspicions, and enhances the scientific nature and accuracy of fraud risk assessment. Next, the additional suspicion is updated using the suspicion value corresponding to the level and judged for compliance. Once compliance is achieved, the fraud suspicion is updated and the additional suspicion is added to a higher level and the corresponding ratio. This enables dynamic adjustment and optimization of the fraud suspicion level, more accurately reflecting the fraud risk of an order, thereby better ensuring transaction security and further improving transaction processing efficiency and user experience.
[0079] In a further embodiment, before step S1100, obtaining the target order generated by the user's real-time transaction, the following steps are included:
[0080] Step S1010: Call the training set to train the fraud detection model to obtain the current version of the fraud detection model that has been trained to a convergence state;
[0081] The training set is retrieved and the fraud detection model is trained until the model reaches convergence. The converged fraud detection model obtained from this training is then obtained as the current version. In one embodiment, the LightGBM model is selected as the fraud detection model. Model training is performed using the training set. Specifically, during model initialization, a gain-based feature partitioning strategy is determined, and hyperparameters such as the maximum tree depth and the minimum number of leaf node instances are set to balance model complexity and generalization performance. During training, the model sequentially builds weak classifiers based on the gradient boosted decision tree (GBDT) architecture. In each iteration, the negative gradient (pseudo-residual) is calculated based on the error between the predicted output of the current ensemble tree for the training sample and the supervisory label. A feature histogram optimization algorithm is then used to quickly locate the optimal split point to generate a new decision tree. This algorithm converts continuous features into histogram bins, thereby reducing computational costs. A leaf-wise growth strategy with a depth constraint is also used to prioritize splitting nodes with the highest gain, significantly improving training efficiency while ensuring accuracy. Ultimately, when the error between the model's output predictions for training samples and the supervisory labels falls below a predetermined threshold, the model is considered to have reached convergence. Otherwise, iterative training continues. This converged model uses a combination of multi-layered decision rules to measure fraud suspicion. Its internal tree structure captures the nonlinear connections between the multi-dimensional characteristics of buyer fraud associated with an order and outputs a fraud suspicion score within the range of 0-1. The predetermined threshold can be set based on the actual needs of those skilled in the art.
[0082] Step S1020: Determine the model performance index for this training based on whether the supervisory labels of the training samples in the training set match the output results inferred by the fraud detection model of the version, wherein the training samples include multiple candidate detection data related to historical orders;
[0083] To comprehensively evaluate the performance of fraud detection models and ensure their accuracy and reliability in practical applications, performance metrics including Area Under the Curve (AUC) and Key-Score (KS) were developed. Specifically, for each training example in the training set, the fraud detection model outputs a probability value between 0 and 1, known as the fraud suspicion level. Based on the fraud suspicion level and the supervisory label (e.g., 0 represents a normal order and 1 represents a fraudulent order), the Area Under the Curve (AUC) metric is first calculated. This is done by plotting a receiver operating characteristic (ROC) curve, with the horizontal axis representing the false positive rate (false positive rate), or the proportion of normal order examples incorrectly classified as fraudulent, and the vertical axis representing the true positive rate (true positive rate), or the proportion of fraudulent order examples correctly identified. The AUC value is calculated by measuring the area under the ROC curve, which ranges from 0.5 to 1. Values closer to 1 indicate better classification performance and are able to effectively distinguish between fraudulent and normal order examples. Furthermore, the training examples are sorted from highest to lowest fraud suspicion level. The cumulative distribution percentages of normal and fraudulent order examples are calculated, and the maximum vertical distance between the two cumulative distribution curves is calculated to obtain the KS value. A larger AUC value (theoretically, a maximum of 1) indicates a stronger ability of the model to distinguish between positive and negative examples.
[0084] Step S1030: When the model performance index meets the standard, retain the selected candidate test data in the training samples in the training set, and continue to iterate the above process based on the training set after the selected candidate test data to continue training the new version;
[0085] For each version of the fraud detection model trained each time, it is necessary to determine whether the corresponding model performance index exceeds the preset threshold. When the model performance index exceeds the preset threshold, it means that the model performance index at this time is high, that is, it meets the standard. Based on this, you can try to eliminate the alternative detection data corresponding to the same multiple fields for each training sample in the training set, so that under the premise of maintaining the model performance index above a certain level, the total number of input detection data that the model reasoning depends on is reduced as much as possible. The specific number of fields and the preset threshold here can be set by those skilled in the art as needed. For the alternative detection data that needs to be eliminated, the importance weight corresponding to each alternative detection data output by the model can be obtained before elimination, and based on this, at least one relatively unimportant alternative detection data is eliminated.
[0086] It is not difficult to understand that since the training set needs to be updated after the elimination, the fraud detection model needs to be re-adapted and updated as well. Therefore, the above training process is continued with the training set after the elimination, that is, the model needs to be trained again to a convergence state, so that the training samples in the training set can be accurately inferred, so that the error between the prediction result of the inference output and the actual supervision label is less than the corresponding preset threshold.
[0087] Step S1040, when the model performance index does not meet the standard, calling the validation set to verify each version of the fraud detection model in reverse order of training to determine the first version that meets the standard as the fraud detection model for actual application.
[0088] At this time, it means that after the above multiple elimination, the model performance index finally drops below or equal to the preset threshold, that is, the model performance index no longer meets the standard, so the fraud detection model of each version trained before this training is triggered to verify these fraud detection models one by one in the training order from the last to the first according to the time sequence. For model verification, first determine the AUC value and KS value of the fraud detection model in the model performance index of the validation set, and then compare the AUC value and KS value of the model in the model performance index of the training set. When the difference between the model performance indexes of the validation set and the training set is within the tolerance range, it is confirmed that the model meets the standard; otherwise, it is confirmed that the model does not meet the standard. The tolerance range can be set by those skilled in the art as needed.
[0089] It can be understood that the fraud detection model of the first version that meets the standard is a reliable model that can be applied online in relative verification, and the inference of the model depends on the detection data input relatively the least, so the fraud detection model of the version is used as the fraud detection model for actual application. The purpose of the embodiment is to end the entire training process of training the fraud detection model for actual application.
[0090] Step S1050, determining the candidate detection data used by the fraud detection model for actual application during training as fraud detection data, and determining the field to which the fraud detection data belongs as a detection field.
[0091] Further, first, determine the fraud detection model for actual application to infer the input of each candidate detection data. These candidate detection data have been optimized, so each of them is used as fraud detection data. Then, determine the field to which each fraud detection data belongs as a detection field.
[0092] In this embodiment, first, by training the fraud detection model until convergence, the model can effectively learn the fraud characteristics in the order data, providing a reliable model foundation for subsequent fraud detection. Next, by calculating model performance indicators (such as AUC and KS values), the model's classification performance and discrimination ability can be comprehensively evaluated, ensuring that the model has high accuracy and reliability in practical applications. Furthermore, when the model performance indicators meet the standards, the alternative detection data in the training set are optimized, and fields that are relatively unimportant to the final output results are eliminated. This helps reduce the redundancy of the model input data, reduces model complexity, and improves inference efficiency, while keeping the model performance unsignificant, thus achieving model simplification and optimization. In addition, countermeasures are considered when the model performance indicators do not meet the standards. By calling the validation set to reversely verify each version of the model, the version that first meets the standards can be selected as the fraud detection model for practical application. This process ensures that even if performance fluctuates or declines during model training, a relatively reliable and effective model version can be found and put into use in a timely manner, ensuring the stability and availability of the fraud detection system. Finally, the alternative detection data and corresponding detection fields that the fraud detection model in actual application relies on are determined, and the key data sources and characteristics required for subsequent fraud detection are clarified, so that the fraud detection process can focus more on data that is highly relevant to fraudulent behavior, further improving the accuracy and efficiency of fraud detection.
[0093] In summary, by carefully controlling the training, evaluation, optimization, and verification of the fraud detection model, we ensure the model's high performance in fraud detection tasks. At the same time, by rationally screening and utilizing detection data, we improve the effectiveness and practicality of the entire fraud management method, providing strong technical support for the transaction security of e-commerce platforms.
[0094] In a further embodiment, step S1000, calling the training set to train the fraud detection model and obtaining the current version of the fraud detection model trained to a converged state, includes the following steps:
[0095] Step S1000: Classify the samples into a pending set or a verification set according to whether the transaction trigger time corresponding to each sample in the prepared initial set meets a preset condition;
[0096] The verification condition is preset to determine whether the time difference obtained by subtracting the transaction trigger time of the order corresponding to the sample from the current time exceeds a preset threshold. Samples that do not exceed the preset threshold are confirmed as meeting the preset condition, which means that the transaction trigger time of the sample is relatively close to the current time; samples that exceed the preset threshold are confirmed as not meeting the preset condition, which means that the transaction trigger time of the sample is relatively far from the current time.
[0097] Create an empty validation set and a processing set, add all samples that meet the preset conditions and their supervised label sets to the validation set, and add all samples that do not meet the preset conditions and their supervised label sets to the processing set.
[0098] Step S1001: Eliminate a plurality of corresponding positive training samples from the to-be-processed set according to a preset time period, an adjustment ratio, and supervisory labels, and use the to-be-processed set after elimination as a training set.
[0099] Generally speaking, the proportion of fraudulent orders across an e-commerce platform should be less than 1%, or even less than 0.1%. This means the ratio of fraudulent orders to legitimate orders should be approximately 1 to 99. Correspondingly, the ratio of positive to negative samples in the processing set should also be 1 to 99. Therefore, it's necessary to extract positive samples from the processing set to reduce their proportion and avoid an extremely unbalanced binary classification set. This would make it difficult for the trained fraud detection model to extract valid features, making it difficult to fit the model, and thus ensuring the accuracy of model inference. Positive samples are samples labeled with a supervisory label indicating that the buyer in a historical order corresponding to the corresponding order was non-fraudulent. Negative samples are samples labeled with a supervisory label indicating that the buyer in a historical order corresponding to the corresponding order was fraudulent.
[0100] Therefore, in order to reduce the number of positive samples in the set to be processed and maintain the diversity of positive samples as much as possible. First, the positive samples in the set to be processed are divided according to the preset time period, and the various time periods that can be divided are determined, as well as all positive samples whose transaction trigger time is within each time period. The preset time period can be one month or one week, etc., and can be set as needed by those skilled in the art. Secondly, the adjustment ratio of the preset positive samples is calculated and multiplied by the total number of positive samples in the set to be processed to obtain the total number of positive samples sampled. Then, the total number of samples is calculated and divided by the total number of divided time periods to obtain the same total number of stratified samples for each time period. The adjustment ratio can be set as needed by those skilled in the art according to the purpose of positive sample extraction disclosed in this step, for example 0.95. Finally, for each time period, a number of positive samples corresponding to the total number of stratified samples are randomly extracted from all positive samples whose transaction trigger time is within the time period. In this way, a number of positive samples corresponding to each time period are extracted, and each extracted positive sample is used as a positive training sample. All the remaining positive samples in the set to be processed are removed, and then the extracted positive training samples are replayed into the set to be processed, and all the negative samples in the set to be processed are used as negative training samples. After this, the processing of the set to be processed is completed, and the set to be processed that has completed the processing is used as the training set.
[0101] In this embodiment, before training the fraud detection model, the initial set of samples is rationally divided according to transaction trigger time to form a validation set and a processing set. This ensures that the validation set samples are relatively timely, better simulating current transaction conditions and enabling accurate subsequent verification of model performance. Positive samples in the processing set are removed according to a preset time period and adjustment ratio to generate a training set. This effectively addresses the sample imbalance caused by the disparity between fraudulent and normal orders, and prevents the model from overfitting to majority class samples and failing to accurately identify minority class fraudulent samples. This ensures the quality and effectiveness of the fraud detection model training process, enabling the model to learn more representative and discriminative features, thereby improving its ability to identify fraudulent behavior and laying a solid foundation for subsequent accurate fraud suspicion assessment.
[0102] In a further embodiment, after step S1040, determining the version that meets the verification criteria first as the fraud detection model for actual application, the following steps are included:
[0103] Step S1041: For each training sample in the initially called training set, after applying the fraud detection model in actual use to determine the fraud suspicion of the training sample, the fraud suspicion is added to the training sample;
[0104] The fraud detection model used in practice performs inference on each training sample in the initially called training set, outputting the fraud suspicion level for each training sample. Each fraud suspicion level is then appended to the corresponding training sample.
[0105] Step S1042: Call the added training set to train the fraud explanation model until it converges;
[0106] The fraud explanation model is a decision tree model in terms of model structure. Applicable models include GBDT, XGBoost, random forest, etc. Technical personnel in this field can choose one to implement as needed.
[0107] During training, the Fraud Explanation Model iteratively builds a decision tree. Each iteration optimizes model parameters based on the error between the model's predictions for training samples and the actual supervised labels, thereby continuously improving the model's prediction accuracy. As training progresses, the error between the model's output and the actual results gradually decreases, leading to convergence. Ultimately, convergence is achieved when the error falls below a preset threshold. This threshold can be customized by those skilled in the art.
[0108] After the fraud explanation model is trained to convergence, the corresponding decision tree is obtained.
[0109] Step S1043: Determine corresponding multiple detection explanation items based on multiple reasoning paths of the fraud explanation model, and construct a fraud detection explanation set.
[0110] Furthermore, the path formed by traversing each leaf node in the decision tree to the root node yields the inference path. Each inference path is considered a detection explanation item, and all detection explanation items are combined to form the fraud detection explanation set. It can be understood that the decision path contains the rules and logic used by the fraud explanation model to determine whether the buyer of an order is fraudulent based on the input detection data.
[0111] In this embodiment, after determining the fraud detection model for actual application, the fraud suspicion inferred by the model is further added to the training samples and used to train the fraud explanation model. Finally, a fraud detection explanation set is constructed based on the reasoning path of the explanation model. This series of operations provides a more detailed, intuitive and logical explanation for the fraud detection results. The detection details in the fraud detection explanation set clearly show the rules and logical paths based on which the model determines the fraud suspicion, which helps relevant personnel to deeply understand the reasons for the fraud judgment and enhances the transparency and credibility of the fraud management process. In the case of order complaints or questions about the detection results, it can quickly provide powerful analytical support, and it is also convenient to optimize and improve the fraud detection model, further improve the fraud detection mechanism, enhance its accuracy and rationality, and promote the healthy and stable development of the e-commerce platform transaction environment.
[0112] In a further embodiment, step S1000, before classifying the samples into a pending set or a validation set based on whether the transaction trigger time corresponding to each sample in the prepared initial set meets a preset condition, includes the following steps:
[0113] Step S10000: for multiple historical orders within a preset time span, construct a sample using candidate detection data corresponding to multiple dimensions of the historical orders, wherein the dimensions include a buyer access dimension, a buyer payment dimension, and a buyer receipt dimension;
[0114] The preset time span can be set according to business needs, such as 3 months, 6 months, 1 year, etc., to ensure that a sufficient number of fraudulent orders and normal orders are collected.
[0115] Taking a single historical order as an example, the alternative detection data for the buyer access dimension includes data corresponding to multiple fields, each of which serves as alternative detection data. Any number of fields include: order access source, order access channel, order access IP address; the duration of the entire process from accessing platform products to triggering payment for the target order, the number of times the target order product was accessed, the number of times the shopping cart was added, the number of times any order was submitted, the number of times different payment methods were selected, and the number of times order information was filled in or modified; and the total number of users, the total number of triggered transaction orders, the total amount of all triggered transaction orders, the average access lifetime, and the total number of orders with similar transaction amounts (the corresponding payment amounts for different orders differed within 1%) within at least one time period before the order access IP triggered the transaction.
[0116] The alternative test data of the buyer payment dimension includes data corresponding to multiple fields, each of which serves as alternative test data. Any multiple fields include: total order payment amount, order logistics amount, ratio of order logistics amount to total order payment amount, ratio of total order discount amount to total order payment amount, order delivery address, total number of order items, total number of order item categories, average price of order items, highest price of order items, number of days order items have been on the shelf, cumulative sales volume of order items, payment currency type, number of order payment attempts, total number of optional bank cards for order payment, total number of incorrect payment passwords, total number of incorrect payment card numbers, order bank card age, total number of days until the order bank card expires, issuing bank and country of the order bank card; total number of abandoned payment orders, total number of successful payment orders, total number of failed payment orders, and total number of orders judged to be fraudulent, for the order payment device fingerprint within at least one time period before the transaction is triggered; total number of abandoned payment orders, total number of successful payment orders, total number of failed payment orders, total number of fraudulent orders, total number of associated access IP addresses, and total number of associated payment IP addresses for the order payment bank card number, mobile phone number, email address, billing address, and cardholder name, respectively, within at least one time period before the transaction is triggered.
[0117] The backup detection data for the buyer's delivery dimension includes data corresponding to multiple fields, each of which serves as backup detection data. Any multiple fields include: whether the order delivery mobile phone number is valid, whether the order delivery email address is valid, whether the order delivery email address is a commonly used email address, the resolved address, whether the order access IP resolved address is consistent with the order delivery address, whether the order payment IP resolved address is consistent with the order delivery address, whether the country of origin of the order delivery mobile phone number is consistent with the country of origin of the order access IP, and whether the country of origin of the order delivery mobile phone number is consistent with the country of origin of the order payment IP; whether the order delivery mobile phone number, order delivery email address, and order delivery address correspond to the mobile phone number, email address, and address in the order credit card billing information, respectively; and the total number of abandoned payment orders, successful payment orders, failed payment orders, fraudulent orders, associated payment device fingerprints, associated credit card numbers, order placement device fingerprints, order placement IP addresses, and payment order IP addresses within at least one time period before the transaction was triggered.
[0118] The time period includes any one or more of 15 minutes, 30 minutes, 1 hour, 3 hours, 6 hours, 12 hours, 1 day, 3 days, 5 days, and 7 days.
[0119] Step S10001: For each sample, a supervision label is assigned to the sample based on whether the buyer in the historical order corresponding to the sample is fraudulent;
[0120] Taking a single sample as an example, for this sample, if the buyer corresponding to the historical order is fraudulent, the supervision label is marked as 1; if the buyer corresponding to the historical order is not fraudulent, the supervision label is marked as 0.
[0121] Step S10002: construct an initial set using all the samples and their supervision labels.
[0122] All samples and their supervised labels are collected to form an initial set.
[0123] In this embodiment, detailed candidate detection data is collected from multiple dimensions, including buyer access, payment, and delivery, for multiple historical orders within a preset time span to construct a sample. This data is then annotated with supervisory labels to generate an initial set. This provides a rich, comprehensive, and representative data foundation for the training of the entire fraud detection model and the implementation of related algorithms. The data covering various dimensions and detailed fields fully mines the various potential features and associated information related to fraudulent behavior, enabling the trained fraud detection model and subsequent fraud detection explanation models to more accurately identify various complex fraud patterns, effectively adapting to the diverse and ever-changing transaction scenarios of e-commerce platforms. This significantly improves the practicality and accuracy of fraud control methods and provides strong data support for ensuring transaction security and the healthy development of the platform.
[0124] See also Figure 3 A fraudulent order control device provided to meet one of the purposes of the present application is a functional embodiment of the fraudulent order control method of the present application. On the other hand, the device, provided to meet one of the purposes of the present application, includes a data acquisition module 1100, a suspicion determination module 1200, a detailed explanation item matching module 1300, and a process execution module 1400. The data acquisition module 1100 is configured to acquire a target order generated by a user's real-time transaction and determine a fraud detection dataset corresponding to the target order at the current moment. The fraud detection dataset includes fraud detection data corresponding to multiple detection fields. The suspicion determination module 1200 is configured to input the fraud detection dataset into a preset fraud detection model to determine the corresponding fraud suspicion. The detailed explanation item matching module 1300 is configured to, when the fraud suspicion indicates that the transaction is suspected of fraud, determine a target detection detailed explanation item in a preset fraud detection explanation set that matches the fraud detection dataset. The process execution module 1400 is configured to initiate a fraud verification process corresponding to the target detection detailed explanation item and determine whether to execute the transaction transfer process for the target order based on the verification result.
[0125] In a further embodiment, the process execution module 1400 includes: a type acquisition submodule, used to obtain the fraud type to which the target detection detailed explanation item belongs; a first process submodule, used to start the merchant-side verification process and obtain the corresponding verification result when the fraud type represents a malicious complaint merchant; a second process submodule, used to start the third-party verification process and obtain the corresponding verification result when the fraud type represents an involuntary transaction; a user push submodule, used to execute the transaction transfer process of the target order when the verification result represents that the verification is passed, and construct a detection report based on the verification result, fraud suspicion, and target detection detailed explanation item, and push it to the user; a rejection execution submodule, used to refuse to execute the transaction transfer process of the target order when the verification result represents that the verification fails.
[0126] In a further embodiment, the suspicion determination module 1200 includes: a suspicion acquisition submodule, which is used to determine the suspicion level to which the fraud suspicion belongs, and obtain additional suspicion when the suspicion level meets the preset conditions; a standard compliance judgment submodule, which is used to update the additional suspicion with the preset suspicion value corresponding to the suspicion level, and judge whether the updated additional suspicion meets the standards; a suspicion update submodule, which is used to update the fraud suspicion to a higher suspicion level with the additional suspicion when the additional suspicion meets the standards, and update the additional suspicion with the preset reduction ratio corresponding to the suspicion level.
[0127] In a further embodiment, the data acquisition module 1100 includes, before the data acquisition module 1100, a version training submodule for calling a training set to train the fraud detection model to obtain a fraud detection model of the current version trained to a converged state; an indicator determination submodule for determining a model performance indicator for the current training based on whether the supervisory labels of the training samples in the training set match the output results inferred by the fraud detection model of the current version, wherein the training samples include multiple candidate detection data related to historical orders; a continued training submodule for retaining a portion of the candidate detection data that has been selected in the training samples in the training set when the model performance indicator meets the standard, and continuing to iterate the above process based on the training set after the candidate detection data is selected to continue training the new version; a model determination submodule for calling a validation set to reversely verify each version of the fraud detection model in the training order when the model performance indicator does not meet the standard, and determining the version that first meets the standard as the fraud detection model for actual application; and a field determination submodule for determining the candidate detection data used in the training of the fraud detection model for actual application as the fraud detection data, and using the fields to which the fraud detection data belongs as the detection fields.
[0128] In a further embodiment, the version training submodule includes: a sample division submodule, which is used to divide the samples into a processing set or a verification set according to whether the transaction trigger time corresponding to each sample in the prepared initial set meets the preset conditions; a training set determination submodule, which is used to eliminate the corresponding multiple positive training samples in the processing set according to the preset time period, adjustment ratio and supervision label, and use the eliminated processing set as the training set.
[0129] In a further embodiment, the model determination submodule includes: a feature appending submodule, which is used to apply the actual fraud detection model to each training sample in the initially called training set to determine the fraud suspicion of the training sample, and then add the fraud suspicion to the training sample; a model training submodule, which is used to call the added training set to train the fraud explanation model to a convergence state; and an explanation set construction submodule, which is used to determine the corresponding multiple detection detailed explanation items based on the multiple reasoning paths of the fraud explanation model, and construct a fraud detection explanation set.
[0130] In a further embodiment, the sample division submodule includes: a sample construction submodule for constructing samples for multiple historical orders within a preset time span using alternative detection data corresponding to multiple dimensions of the historical orders, wherein the dimensions include buyer access dimension, buyer payment dimension, and buyer receipt dimension; a label marking submodule for marking a supervisory label for each sample based on whether the buyer in the historical order corresponding to the sample is fraudulent; and an initial set construction submodule for constructing an initial set using all the samples and their supervisory labels.
[0131] In order to solve the above technical problems, the embodiment of the present application also provides a computer device. Figure 4 As shown, a schematic diagram of the internal structure of a computer device. The computer device includes a processor, a computer-readable storage medium, a memory, and a network interface connected via a system bus. Among them, the computer-readable storage medium of the computer device stores an operating system, a database, and computer-readable instructions, and the database may store a control information sequence. When the computer-readable instructions are executed by the processor, the processor may implement a fraudulent order control method. The processor of the computer device is used to provide computing and control capabilities to support the operation of the entire computer device. The memory of the computer device may store computer-readable instructions. When the computer-readable instructions are executed by the processor, the processor may execute the fraudulent order control method of the present application. The network interface of the computer device is used to connect and communicate with the terminal. Those skilled in the art will understand that Figure 4 The structure shown in the figure is only a block diagram of a part of the structure related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied. The specific computer device may include more or fewer components than shown in the figure, or combine certain components, or have a different component arrangement.
[0132] In this embodiment, the processor is used to execute Figure 3 The memory stores the program code and various data required to execute the modules and submodules. The network interface is used to transmit data between user terminals or servers. The memory in this embodiment stores the program code and data required to execute all modules and submodules in the fraudulent order control device of this application. The server can call the server's program code and data to execute the functions of all submodules.
[0133] The present application also provides a storage medium storing computer-readable instructions. When the computer-readable instructions are executed by one or more processors, the one or more processors execute the steps of the fraudulent order control method of any embodiment of the present application.
[0134] Those skilled in the art will appreciate that all or part of the processes in the above-mentioned embodiments of the present application can be implemented by instructing the relevant hardware through a computer program. The computer program can be stored in a computer-readable storage medium. When the program is executed, it can include the processes of the above-mentioned embodiments of the method. The aforementioned storage medium can be a computer-readable storage medium such as a magnetic disk, an optical disk, a read-only memory (ROM), or a random access memory (RAM).
[0135] In summary, this application can efficiently and accurately identify and verify fraudulent orders, reasonably manage transaction risks, and balance security and efficiency.
[0136] Those skilled in the art will understand that the various operations, methods, steps, measures, and schemes in the processes discussed in this application may be interchanged, changed, combined, or deleted. Furthermore, other steps, measures, and schemes in the various operations, methods, and processes discussed in this application may also be interchanged, changed, rearranged, decomposed, combined, or deleted. Furthermore, steps, measures, and schemes in the various operations, methods, and processes in the prior art that are open source and disclosed in this application may also be interchanged, changed, rearranged, decomposed, combined, or deleted.
[0137] The above description is only part of the implementation methods of the present application. It should be pointed out that for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the principles of the present application. These improvements and modifications should also be regarded as the scope of protection of the present application.
Claims
1. A fraudulent order control method, characterized in that: The steps include: Obtaining a target order generated by a user's real-time transaction, and determining a fraud detection dataset corresponding to the target order at a current moment, wherein the fraud detection dataset includes fraud detection data corresponding to a plurality of detection fields; Inputting the fraud detection data set into a preset fraud detection model to determine the corresponding fraud suspicion; When the fraud suspicion indicates that the transaction is suspected of fraud, determining a target detection detailed explanation item in a preset fraud detection explanation set that matches the fraud detection dataset; Start the fraud verification process corresponding to the target detection detailed item, and determine whether to execute the transaction transfer process of the target order based on the obtained verification result.
2. The fraudulent order control method according to claim 1, characterized in that: Initiate the fraud verification process corresponding to the target detection detailed explanation item, and determine whether to execute the transaction transfer process of the target order based on the obtained verification result, including the following steps: Obtaining the fraud type to which the target detection detailed explanation item belongs; When the fraud type indicates a malicious complaint against a merchant, a merchant-side verification process is initiated to obtain a corresponding verification result; When the fraud type represents an involuntary transaction, a third-party verification process is initiated to obtain a corresponding verification result; When the verification result indicates that the verification is passed, the transaction transfer process of the target order is executed, and a detection report is constructed based on the verification result, fraud suspicion, and target detection details, and pushed to the user; When the verification result indicates that the verification fails, the transaction transfer process of the target order is refused.
3. The fraudulent order control method according to claim 1, characterized in that: After inputting the fraud detection dataset into a preset fraud detection model and determining the corresponding fraud suspicion, the following steps are included: Determining the suspicion level to which the fraud suspicion level belongs, and obtaining an additional suspicion level when the suspicion level meets a preset condition; Updating the additional suspicion level with a preset suspicion value corresponding to the suspected gear, and determining whether the updated additional suspicion level meets the standard; When the additional suspicion level reaches a certain level, the fraud suspicion level is updated to a higher level using the additional suspicion level, and the additional suspicion level is updated using a preset reduction ratio corresponding to the higher level.
4. The fraudulent order control method according to claim 1, characterized in that: Before obtaining the target order generated by the user's real-time transaction, the following steps are included: Call the training set to train the fraud detection model and obtain the fraud detection model trained to convergence in this version. Determining a model performance metric for this training based on whether supervised labels of training samples in the training set match output results inferred by the version of the fraud detection model, wherein the training samples include multiple candidate detection data related to historical orders; When the model performance index meets the standard, retain the selected candidate test data in the training samples in the training set, and continue to iterate the above process based on the training set after the selected candidate test data to continue training the new version; When the model performance indicators do not meet the standards, the validation set is used to reversely verify the various versions of the fraud detection model in the training order, and the version that is first verified to meet the standards is determined as the fraud detection model for actual application; The candidate detection data used in the training of the fraud detection model in actual application is determined as the fraud detection data, and the field to which the fraud detection data belongs is used as the detection field.
5. The fraudulent order control method according to claim 4, characterized in that: Calling the training set to train the fraud detection model and obtaining the fraud detection model trained to convergence in this version involves the following steps: Based on whether the transaction trigger time corresponding to each sample in the prepared initial set meets the preset conditions, the samples are divided into the processing set or the verification set accordingly; According to the preset time period, adjustment ratio and supervision label, a plurality of positive training samples corresponding to the set to be processed are eliminated, and the set to be processed after elimination is used as the training set.
6. The fraudulent order control method according to claim 4, characterized in that: After determining the first verified version that meets the standards as the fraud detection model for actual application, the following steps are involved: For each training sample in the initially called training set, after applying the fraud detection model in practice to determine the fraud suspicion of the training sample, the fraud suspicion is added to the training sample; Call the added training set to train the fraud explanation model until convergence; Based on the multiple reasoning paths of the fraud explanation model, the corresponding multiple detection detailed explanation items are determined to construct a fraud detection explanation set.
7. The fraudulent order control method according to claim 5, characterized in that: Based on whether the transaction trigger time corresponding to each sample in the prepared initial set meets the preset conditions, the sample is divided into the processing set or the verification set, including the following steps: For multiple historical orders within a preset time span, samples are constructed using candidate detection data corresponding to multiple dimensions of the historical orders, wherein the dimensions include buyer access dimension, buyer payment dimension, and buyer receipt dimension; For each of the samples, a supervision label is assigned to the sample based on whether the buyer in the historical order corresponding to the sample is fraudulent; An initial set is constructed with all the samples and their supervision labels.
8. A fraudulent order control device, characterized in that: include: A data acquisition module is used to acquire a target order generated by a user's real-time transaction and determine a fraud detection dataset corresponding to the target order at the current moment, wherein the fraud detection dataset includes fraud detection data corresponding to multiple detection fields; a suspicion determination module, configured to input the fraud detection data set into a preset fraud detection model to determine a corresponding fraud suspicion; a detailed explanation item matching module, configured to determine a target detection detailed explanation item in a preset fraud detection explanation set that matches the fraud detection dataset when the fraud suspicion indicates that the transaction is suspected of fraud; The process execution module is used to start the fraud verification process corresponding to the target detection detailed item and determine whether to execute the transaction transfer process of the target order based on the obtained verification result.
9. A computer device comprising a central processing unit and a memory, characterized in that: The central processing unit is configured to call and run a computer program stored in the memory to execute the steps of the method according to any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that It stores a computer program implemented according to the method described in any one of claims 1 to 7 in the form of computer-readable instructions, and when the computer program is called and executed by a computer, the steps included in the corresponding method are executed.