Matlas indexing method, user risk assessment method and related device
By dynamically adjusting the index depth and path risk score of the person-relationship map, the balance between efficiency and accuracy in user risk assessment is solved, and fast and accurate risk decision-making is achieved in real-time transaction scenarios.
Patent Information
- Application Number
- CN202511004852.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-21
- Publication Date
- 2025-10-14
AI Technical Summary
Existing technologies find it difficult to strike a balance between query efficiency and query accuracy in user risk assessment. Traditional methods ignore potentially important related information when improving indexing efficiency, affecting the completeness and accuracy of the indexing results. The pursuit of high accuracy leads to excessively high computing resources and time costs, which cannot meet the decision-making needs of real-time transaction scenarios.
By obtaining the user information of the user to be identified, dynamically adjusting the index depth of the person-relationship graph according to the initial risk score, and combining abnormal social information and path risk scores, the potential risk assessment of the user to be identified is achieved. The index depth is dynamically adjusted to reduce the computational overhead of low-risk users and ensure the in-depth analysis accuracy of high-risk users.
It achieves the goal of reducing the computational overhead of low-risk users while ensuring the accuracy of in-depth analysis of high-risk users, achieving an effective balance between indexing efficiency and accuracy, and enabling rapid and accurate risk decisions in real-time trading scenarios.
Smart Images

Figure CN120780879A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the field of user risk analysis, in particular to a graph index method, a user risk assessment method and related devices. BACKGROUND
[0002] In some business scenarios, it is necessary to analyze whether a user has risks. For example, in the actual operation of a live broadcast platform, malicious users may use the refund mechanism of the operating system to first charge on the platform and make rewards / consumptions to anchors or accompany players, and then apply for a refund to the platform, causing economic losses to the platform. Since the platform can only intercept risks at the user charging or consumption link, it is impossible to recover funds or restrict the anchor from withdrawing funds after the transaction is completed, therefore, it is urgent to identify the risks of users involved in transactions before the transaction occurs.
[0003] When a traditional method usually performs risk assessment based on the attribute or behavior data of a single user, this method can only obtain local information and is difficult to discover deep risk patterns hidden in complex relationship networks. For example, a user may not have any obvious abnormal characteristics, but if other users who have social relationships with him have high-risk signals, the user may also be involved in potential risks. Therefore, to solve this problem, a user risk assessment method based on a knowledge graph is proposed in related technology, which constructs a multi-dimensional relationship network between users to mine more extensive behavior associations and risk propagation paths.
[0004] However, it is found in practice that in order to improve the indexing efficiency, a simplification strategy is usually needed. For example, by limiting the search range, reducing the computational complexity or using an approximate algorithm to speed up the query. However, this method improves the response speed, but inevitably causes some potential important association information to be ignored, thereby affecting the integrity and accuracy of the index result. On the contrary, if higher indexing accuracy is pursued, more context information, more complex association relationships and deeper graph traversal depth need to be considered, which inevitably requires higher computational resources and time cost, thereby significantly affecting the query efficiency.
[0005] Therefore, how to balance the query efficiency and the query accuracy has become a problem to be solved at present. SUMMARY
[0006] In order to overcome at least one deficiency in the prior art, the present application provides a graph index method, a user risk assessment method and related devices, comprising: In a first aspect, the present application provides a graph index method, the method comprising: obtaining user information of a to-be-identified user; obtaining an initial risk score of the to-be-identified user according to the user information; According to the initial risk score, an index depth of a person relationship graph is obtained, wherein the person relationship graph records social relationships between the to-be-identified user and other users, and the index depth represents a farthest exploration level of the person relationship graph; According to the index depth, abnormal social information of the to-be-identified user is obtained from the person relationship graph.
[0007] According to the abnormal social information, a potential risk score of the to-be-identified user is obtained, wherein the potential risk score is used as a basis for decision-making of a risk control measure.
[0008] In a second aspect, the present application further provides a user risk assessment method, and the method comprises: According to the abnormal social information obtained by the graph index method, an abnormal social path of the to-be-identified user is determined, wherein the abnormal social path represents that the to-be-identified user has a social relationship with a recognized risk user; According to the abnormal social path, a path risk score of the abnormal social path is obtained; The path risk scores of the abnormal social paths in the abnormal social information are integrated to obtain a potential risk score of the to-be-identified user, wherein the potential risk score is used as a basis for decision-making of a risk control measure.
[0009] In a third aspect, the present application further provides a graph index device, and the device comprises: An initial risk score module is configured to obtain user information of a to-be-identified user; The initial risk score module is further configured to obtain an initial risk score of the to-be-identified user according to the user information; A graph index module is configured to obtain an index depth of a person relationship graph according to the initial risk score, wherein the person relationship graph records social relationships between the to-be-identified user and other users, and the index depth represents a farthest exploration level of the person relationship graph; The graph index module is further configured to obtain abnormal social information of the to-be-identified user from the person relationship graph according to the index depth.
[0010] In a fourth aspect, the present application provides a risk user assessment device, and the device comprises: An initial risk score module is configured to obtain user information of a to-be-identified user; The initial risk score module is further configured to obtain an initial risk score of the to-be-identified user according to the user information; a graph index module configured to obtain an index depth of a person relationship graph according to the initial risk score, wherein the person relationship graph records social relationships between the to-be-identified user and other users, and the index depth represents a farthest exploration level of the person relationship graph; The graph index module is further configured to obtain abnormal social information of the to-be-identified user from the person relationship graph according to the index depth.
[0011] Compared with the prior art, the present application has the following beneficial effects: The present application provides a graph index method, a user risk assessment method, and related devices. An electronic device obtains user information of a to-be-identified user; according to the user information, an initial risk score of the to-be-identified user is obtained; according to the initial risk score, an index depth of a person relationship graph is obtained; wherein the person relationship graph records social relationships between the to-be-identified user and other users, and the index depth represents a farthest exploration level of the person relationship graph; and according to the index depth, abnormal social information of the to-be-identified user is obtained from the person relationship graph. In this way, the index depth of the person relationship graph is dynamically adjusted according to the initial risk score, which ensures the depth analysis accuracy of high-risk users while reducing the computational overhead of low-risk users, thereby achieving an effective balance between index efficiency and accuracy. BRIEF DESCRIPTION OF DRAWINGS
[0012] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following will briefly introduce the drawings needed in the embodiments. It should be understood that the following drawings only show some embodiments of the present application, and therefore should not be regarded as a limitation on the scope. For those skilled in the art, other related drawings can also be obtained without creative labor.
[0013] Figure 1 a flowchart of the graph index method provided by the embodiments of the present application; Figure 2 a detailed diagram of a sub-step in the graph index method provided by the embodiments of the present application; Figure 3 a flowchart of the user risk assessment method provided by the embodiments of the present application; Figure 4 a detailed diagram of a sub-step in the user risk assessment method provided by the embodiments of the present application; Figure 5A a flowchart of the user risk assessment method provided by the embodiments of the present application; Figure 5B a flowchart of the user risk assessment method provided by the embodiments of the present application; Figure 6A schematic diagram of the overall principle of the user risk assessment method provided in an embodiment of the present application; Figure 7A A schematic diagram of the structure of a graph indexing device provided in an embodiment of the present application; Figure 7B A schematic diagram of the structure of a user risk assessment device provided in an embodiment of the present application; Figure 8 A schematic diagram of the structure of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0014] To make the objectives, technical solutions, and advantages of the embodiments of the present application (hereinafter referred to as the embodiments) more clear, the technical solutions in the embodiments of the present application will be clearly and completely described below in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present application, not all of them. Generally, the components of the embodiments of the present application described and shown in the drawings herein can be arranged and designed in various different configurations.
[0015] Therefore, the following detailed description of the embodiments of the present application provided in the accompanying drawings is not intended to limit the scope of the present application for protection, but merely represents selected embodiments of the present application. All other embodiments obtained by persons of ordinary skill in the art based on the embodiments in the present application without creative work are within the scope of protection of the present application.
[0016] It should be noted that similar reference numerals and letters denote similar items in the following drawings, and therefore, once an item is defined in one drawing, it does not need to be further defined or explained in subsequent drawings.
[0017] In the description of this application, it should be noted that the terms "first", "second", "third", etc. are used only to distinguish descriptions and should not be understood as indicating or implying relative importance. In addition, the terms "comprises", "comprising" or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device comprising a series of elements includes not only those elements, but also includes other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of other identical elements in the process, method, article or device comprising the element.
[0018] Based on the above statement, as introduced in the background technology, how to strike a balance between query efficiency and query accuracy has become an urgent problem that needs to be solved.
[0019] Exemplarily, continue to take the live broadcast platform as an example. For a live broadcast platform with a transaction volume of tens of millions per day, the data nodes and edge relationships that need to be processed will grow exponentially, and if a full-amount fund flow graph is constructed for all transactions and a deep traversal is performed, the computational complexity will quickly rise. For example, when the graph traversal depth exceeds three layers, the amount of calculation required will increase significantly. In this case, if only query efficiency is pursued, the response speed can be accelerated by limiting the traversal depth or simplifying the algorithm, but this often misses some hidden deep risk associations, thereby reducing the accuracy of the query results.
[0020] In addition, if only query accuracy is focused on and efficiency is ignored, the system will also be unable to make quick decisions in real-time transaction scenarios. For example, in the problem of malicious refund identification, risks can exist not only in the direct behavior of a single user, but also can be spread through complex indirect associations, such as device sharing, abnormal interactions in social networks, and the like. In order to fully capture these potential risks, a multi-layer relationship network needs to be analyzed in depth, which will inevitably bring higher computational overhead. However, real-time risk control scenarios require the system to complete risk assessment and give decisions within a very short time, and obviously, too long a calculation time cannot meet this demand.
[0021] Therefore, in the risk control scenario of the live broadcast platform, it is important to consider both the query efficiency and the query accuracy of the knowledge graph.
[0022] Based on the discovery of the above technical problems, the following technical solutions are proposed after creative labor to solve or improve the above problems. It should be noted that the defects in the above prior art solutions are the result of careful research and practice, and therefore, the discovery process of the above problems and the solutions proposed by the embodiments of the present application to solve the above problems should be considered as contributions to the present application in the process of invention and creation, and should not be understood as technical content known to those skilled in the art.
[0023] In view of this, the present embodiment provides a graph index method applied to an electronic device. As shown in the method includes: Figure 1 S1A, obtaining user information of a to-be-identified user.
[0024] S2A, obtaining an initial risk score of the to-be-identified user according to the user information.
[0025] S3A, obtaining an index depth of a person relationship graph according to the initial risk score.
[0026] The person relationship graph records the social relationship between the to-be-identified user and other users, and the index depth represents the farthest exploration level of the person relationship graph.
[0027] S4A, obtaining the abnormal social information of the to-be-identified user from the person relationship graph according to the index depth.
[0028] In this way, the index depth of the person relationship graph is dynamically adjusted according to the initial risk score, which reduces the calculation overhead of low-risk users while ensuring the depth analysis accuracy of high-risk users, thereby achieving an effective balance between index efficiency and accuracy.
[0029] For the user risk assessment method provided in the embodiment, the electronic device implementing the method can be, but is not limited to, a mobile terminal, a tablet computer, a laptop computer, a desktop computer, a server, etc. Among them, the server can be a single server, or a server group. The server group can be centralized or distributed (for example, the server can be a distributed system). In some embodiments, the server can be local or remote relative to the user terminal. In some embodiments, the server can be implemented on a cloud platform; for example only, the cloud platform can include a private cloud, a public cloud, a hybrid cloud, a community cloud, a distributed cloud, an inter-cloud, a multi-cloud, etc., or any combination thereof. In some embodiments, the server can be implemented on an electronic device with one or more components.
[0030] To make the scheme provided in the embodiment clearer, the following will take the server as the electronic device implementing the method, and elaborate on each step of the method shown in Figure 1 It should be understood that the operations of the flowchart can not be implemented in sequence, and the steps without logical context relationship can be reversed in order or implemented simultaneously. In addition, one or more other operations can be added to the flowchart or one or more operations can be removed from the flowchart under the guidance of the content of the present application. Continue to refer to Figure 1 The method comprises: S1A, obtaining user information of a to-be-identified user.
[0031] Taking the live broadcast platform as an example, the server completes the receiving and extracting operations of data through the transaction request. It should be noted that the transaction request is the first entrance, mainly responsible for processing the recharge and consumption requests from the live broadcast platform. Specifically, the server interfaces the transaction request initiated by the client through the API gateway, and extracts key user information therefrom, including but not limited to user ID, device information, IP address, transaction amount, and transaction target (such as anchor ID).
[0032] It should be understood that the extracted user information not only covers the user's own identification features (such as user ID), but also includes contextual information closely related to the transaction environment (such as device information, IP address, etc.), which together constitute the core input source for the subsequent initial risk score calculation.
[0033] Based on the description of the user information in step S1A in the above embodiment, the following is Figure 1 Step S2A in the following is explained: S2A, based on user information, obtains the initial risk score of the user to be identified.
[0034] In this embodiment, the server provides a rule library for performing multi-dimensional feature analysis and risk assessment on the user to be identified, thereby obtaining an initial risk score. Therefore, the server can obtain the initial risk score based on the matching results between the user information and the scoring rules in the rule library.
[0035] Specifically, when the above steps are executed, the server obtains the input information required by the rule engine based on the extracted user information, including but not limited to user attribute characteristics (for example, account age, registration channel, real-name authentication status, historical behavior rating and other static characteristics), behavioral interaction characteristics (for example, login frequency, operation behavior pattern, consumption habits, device switching frequency and other dynamic characteristics), device environment characteristics (for example, device ID, IP address, system version, network environment, geographic location and other environmental characteristics), transaction behavior characteristics (for example, transaction amount, occurrence time, transaction object, payment channel, transaction frequency and other business characteristics), and associated historical characteristics (for example, user historical transaction records, risk tag history, account status change and other temporal characteristics).
[0036] The server then uses a rules engine to match the input information against the scoring rules in the rule base, one by one, to obtain a matching result. It should be understood that each rule contains multiple elements, including a unique identifier, rule name, rule description, risk score, rule type, and execution policy. Rule types can be categorized into various levels, such as "interception," "freeze," "manual review," and "warning," based on different risk levels. Each rule is independently configured with a risk score (positive for normal conditions and negative for risk). Therefore, the independent rule scoring mechanism ensures that each rule can independently calculate a risk score based on its triggering conditions.
[0037] Ultimately, the server accumulates the risk scores of all matching scoring rules to form an initial risk score for the user to be identified. Because each rule's independently configured risk score has positive values indicating normal behavior and negative values indicating risky behavior, if the final score falls below the set threshold, the user is considered high-risk.
[0038] In addition, in addition to the above-mentioned scoring mode based on the rule engine, the server can also process the user information of the to-be-identified user through a machine learning-based scoring model to obtain the initial risk score of the to-be-identified user.
[0039] Based on the above embodiment for explaining the initial risk score in step S2A, the following continues to explain step S2A in the above embodiment: Figure 1 S3A, obtaining the index depth of the person relationship graph according to the initial risk score.
[0040] The person relationship graph records the social relationship between the to-be-identified user and other users, and the index depth represents the farthest exploration level of the person relationship graph. The person relationship graph is constructed based on a knowledge graph, and the graph includes a plurality of nodes, and the relationship between the nodes is embodied by a connection line.
[0041] During the execution of the above steps, the server determines the index depth of subsequent person relationship graph analysis based on the initial risk score output by the rule engine. It should be understood that the person relationship graph records the social relationship between the to-be-identified user and other users, and the index depth represents the farthest level of traversal in the graph.
[0042] For example, if the initial risk score is low, it is determined to be a low-risk transaction, at which time the index depth is set to 1, and only the directly associated user nodes are explored; if the initial risk score is at an intermediate level, it is determined to be a medium-risk transaction, at which time the index depth is set to 2, and the indirectly associated user nodes are further explored; if the initial risk score is high, it is determined to be a high-risk transaction, at which time the index depth is set to 3, and deeper potential social relationships are further explored.
[0043] Based on the above embodiment for explaining the index depth in step S3A, the following continues to explain step S4A in the above embodiment: Figure 1 S4A, obtaining the abnormal social information of the to-be-identified user from the person relationship graph according to the index depth.
[0044] For step S4A, it is found in practice that when the person relationship graph is analyzed, if the risk type of the to-be-identified user and the corresponding matching path are not considered, and the entire graph is directly and comprehensively indexed, the computational complexity will be significantly increased. In particular, in a high-concurrency scene such as a live broadcast platform, the data scale is large and the nodes are complexly associated, and the indiscriminate traversal method will consume a large amount of computing resources, and it is difficult to meet the real-time requirement. In view of this, as shown in the above embodiment, the present embodiment also provides the following optional implementation manner of step S4A: Figure 2 S4A-1, based on the user information, obtain the risk type of the user to be identified.
[0045] During the execution of the above steps, the server can determine the risk type of the user to be identified based on the matching results of user information and the rule library. It can be understood that the risk type is a conclusion drawn from the rule library's multi-dimensional analysis of user information, which reflects the specific risk areas that the user may be involved in. For example, if the rule library matches that a user's device frequently switches or is associated with high-risk devices, the user's risk type is determined to be "device risk"; if the rule library matches that the user's consumption behavior is abnormally concentrated around a specific anchor, the risk type is determined to be "transaction target risk." By clarifying the risk type, it can provide precise guidance for the subsequent graph analysis path selection.
[0046] Continue to see Figure 2 , then continue to Figure 2 Step S4A-1 in FIG. 1 is explained as follows: S4A-2, based on the risk type, determine the path to be indexed that matches the risk type from the person relationship graph.
[0047] The execution of the above steps relies on pre-defined path mapping rules. For example, when the risk type is "device risk", the server prioritizes analyzing the "user-device-user" path to explore whether multiple users share the same device; when the risk type is "transaction target risk", the server prioritizes analyzing the "user-consumption-anchor" path to assess whether the potential association between the user and the anchor is abnormal.
[0048] It should be understood that the number of paths to be indexed can be one or more, depending on the complexity of the risk type of the user to be identified. When the risk type is single and clear, selecting a single, most matching path can effectively locate anomalous social information. However, when the risk type involves multiple dimensions or is uncertain, multiple paths must be selected to comprehensively cover different social relationship patterns, thereby constructing a more complete risk profile.
[0049] Therefore, by specifically selecting the paths to be indexed, unnecessary computational overhead can be significantly reduced, while improving the efficiency and accuracy of abnormal social information extraction.
[0050] Continue to see Figure 2 , then continue to Figure 2 Step S4A-3 in the following example is explained: S4A-3, based on the index depth, index the abnormal social information of the user to be identified from the path to be indexed.
[0051] On the basis of determining the path to be indexed, the server further analyzes the selected path in combination with the index depth calculated previously, and extracts abnormal social information therefrom. It should be noted that the setting of the index depth directly affects the analysis range, thereby ensuring the rationality of resource allocation. For example, if the index depth is 1, only the directly associated nodes are analyzed; if the index depth is 2, the indirectly associated nodes are expanded. In this way, for a high-risk user, a deeper index depth can be set to obtain more comprehensive information, while for a low-risk user, a shallower index depth can be set, thereby achieving an effective balance between index efficiency and accuracy.
[0052] Research has found that the malicious behavior of some users has characteristics such as concealment, gang nature and spreadability, and it is often difficult to accurately identify the real risk attributes of users only by relying on their own transaction or behavior data. The traditional user risk assessment method usually ignores the complex social relationship network between users and lacks an effective quantitative mechanism for social paths and their risk propagation ability, resulting in one-sidedness of the assessment results and a high misjudgment rate.
[0053] Take the malicious refund scene in the live broadcast platform as an example. In the huge user group of the live broadcast platform, the financial flow relationship between users is complex, and the social connection usually presents a multi-level network structure. There may be various types of associated paths, such as device sharing, IP address coincidence, mutual friendship, etc., and these paths may become important channels for risk propagation. Therefore, in order to improve the accuracy of risk identification, it is necessary to mine abnormal social paths from abnormal social information that represent suspicious associations between the target user and the known risk user, and to quantify the impact of the path on the overall risk level of the target user through a risk scoring mechanism at the path level.
[0054] Therefore, based on the abnormal social information provided by the above graph indexing method, the embodiment also provides a user risk assessment method. As shown in Figure 3 the user risk assessment method provided by the embodiment includes: S1B, determining abnormal social paths of the user to be identified from the abnormal social information obtained according to the graph indexing method.
[0055] Among them, the abnormal social path represents that the user to be identified and the identified risk user have a social relationship. It should be understood that when the potential risk source of the user to be identified is single and clear, only one abnormal social path needs to be analyzed; when the risk source is diverse or complex, multiple paths need to be selected for comprehensive evaluation. Therefore, the number of abnormal social paths can be one or more. The expression is:
[0056] In the formula, represents the set of all abnormal social paths, represents one of the abnormal social paths, Nodes representing risky users, represents the target node, represents the total number of nodes in abnormal social paths, Indicates the index depth.
[0057] Based on the above description of abnormal social paths, Figure 3 Explanation of step S2B in the following example: S2B, based on the abnormal social path, obtains the path risk score of the abnormal social path.
[0058] S3B, integrate the path risk scores of each abnormal social path in the abnormal social information to obtain the potential risk score of the user to be identified.
[0059] The potential risk score serves as a basis for decision-making on risk control measures. Based on this potential risk score, the server can take further preventative measures against the user to be identified. For example, on a live streaming platform, if the potential risk score of the user to be identified exceeds the threshold, the user's consumption behavior will be suspended, including but not limited to prohibiting the user from making top-ups or spending on the live streaming platform.
[0060] In this way, by conducting hierarchical analysis of social paths and assigning corresponding scores, we can more accurately capture risk signals hidden in complex relationship networks.
[0061] Next, we will continue to use the server as an electronic device to implement this method. Figure 3 Each step of the method shown is described in detail. However, it should be understood that the operations of the flowchart can be implemented in any order, and steps that have no logical contextual relationship can be reversed or implemented simultaneously. In addition, those skilled in the art can add one or more other operations to the flowchart or remove one or more operations from the flowchart under the guidance of the content of this application. Figure 3 , the method comprising: S1B, based on the abnormal social information obtained by the graph indexing method, the abnormal social path of the user to be identified is determined.
[0062] Among them, abnormal social paths represent the social relationship between the user to be identified and the identified risk users.
[0063] S2B, based on the abnormal social path, obtains the path risk score of the abnormal social path.
[0064] Research has found that the relationships between users to be identified and risky users in the persona graph are often multidimensional and dynamically changing. For example, on live streaming platforms, the relationship between users isn't solely determined by the existence of a direct connection; it involves the combined effects of multiple factors. Therefore, traditional assessment methods often rely on a single metric, failing to fully reflect the complex social connections between the two.
[0065] In view of this, if Figure 4 As shown, this embodiment also provides Figure 3 The following optional implementations of step S2B: S2B-1, based on the abnormal social path, obtain the social relationship score, social distance score and social intensity score of the abnormal social path.
[0066] Among them, the social relationship score represents the degree of intimacy between the user to be identified and the risk user, the social distance score represents the attenuation degree caused by the risk transfer of the risk user to the user to be identified, and the social strength score represents the social strength between the user to be identified and the risk user.
[0067] It should be understood that even if two social paths are the same length, the user relationships they reflect may differ significantly due to differences in social type and direction. For example, in the context of live streaming platforms, the risk transmission capacity of "transaction relationships" is generally higher than that of "friend relationships" because the former involves actual capital flows and is more likely to spread risky behaviors such as malicious refunds. At the same time, the direction of social interaction can also reflect the relationship between users. For example, if there is a two-way interaction between two users in the character relationship map, that is, there are multiple transactions between the two parties, then the relationship between the two is generally much stronger than that between users with only one-way interactions.
[0068] Based on the invention concept, Figure 4 Regarding S2B-1 in this embodiment, the following optional implementations are also provided: S2B-1-1, identify subpathways from the aberrant social pathway.
[0069] Among them, the subpath represents the path between two adjacent nodes in the abnormal social path. Expressed as:
[0070] Where, Indicates the nodes, Indicates the Node and subpaths between nodes.
[0071] Based on the above expression of abnormal social paths, it is not difficult to see that in the character relationship graph, each abnormal social path is composed of multiple sub-paths, and each sub-path reflects the specific connection method between two adjacent nodes. In order to more accurately measure the relationship between the user to be identified and the risk user, it is necessary to conduct a refined analysis of these sub-paths. Therefore, the server extracts each sub-path from the abnormal social path and calculates the corresponding relationship sub-score based on the social type and social direction corresponding to each sub-path. Based on the inventive concept, step S2B-1 also includes: S2B-1-2, based on the social type and social direction corresponding to the sub-path, obtain the relationship sub-score of the sub-path; S2B-1-3, integrate the relationship sub-scores of each sub-path in the abnormal social path to obtain the social relationship score.
[0072] Specifically, this embodiment pre-assigns different weights to different social types. For example, in a live broadcast platform scenario, a transaction relationship may have a higher risk transfer capability than a simple friend relationship, so its weight will be correspondingly higher.
[0073] At the same time, the social direction weight function takes into account the directionality of the interaction, for example, whether it is one-way attention or two-way interaction. If a sub-path shows two-way interaction (such as multiple financial transactions between the two parties), its weight value will be further increased. To address this, this embodiment also introduces a two-way connection bonus coefficient to amplify the impact of two-way interaction behavior. The corresponding expression is as follows:
[0074] Where, represents the social relationship score, Represents a subpath The weight value of Represents a subpath The direction weight value of Pointing to a node Social behavior of nodes, for example, To the node Make a transfer; Indicates the two-way connection bonus coefficient, which is used to amplify the impact of the two-way connection. The two-way connection bonus coefficient needs to be the same as the two-way connection identifier. Used together, two-way connection mark , used to indicate subpaths Is it a bidirectional connection? If a bidirectional connection exists, then ;otherwise .
[0075] In this way, social types are used to evaluate users to be identified and risky users, and the role of two-way interaction is strengthened, thereby improving the evaluation accuracy.
[0076] The study also found that in the person-to-person relationship graph, unusual social paths reflect the association characteristics between the user to be identified and the risky user. However, traditional assessment methods often focus solely on the existence or distance of social relationships, ignoring the actual intensity of interactions between users. To this end, this example further quantifies the closeness of interactions between users by introducing two key indicators: social frequency and social amount.
[0077] For example, in the live streaming platform scenario, if a user frequently exchanges funds with risky users, it means the connection between the two is closer. Similarly, the amount of social transactions reflects the scale of financial transactions between users. For example, if the amount of transactions between a user and a risky user is large, it indicates a stronger interest relationship between the two.
[0078] Based on the invention concept, Figure 4 Regarding S2B-1 in this embodiment, the following optional implementations are also provided: S2B-1-4, identify subpathways from the aberrant social pathway.
[0079] The subpath represents a path between two adjacent nodes in the abnormal social path. For details about the subpath, please refer to the relevant description in the above embodiment, which will not be repeated here.
[0080] S2B-1-5, according to the social frequency of each sub-path in the abnormal social path, obtain the frequency score of the abnormal social path.
[0081] When executing the above steps, the server will count the interaction frequencies corresponding to each sub-path in the abnormal social path and accumulate these frequency values to obtain the total interaction frequency for the path. Then, to ensure the comparability of frequency values between different paths, the server will compare and normalize this total interaction frequency with a preset frequency saturation threshold. The expression is as follows:
[0082] Where, represents the frequency score, represents the number of nodes in the abnormal social path, represents the frequency saturation threshold, Representation and subpath Corresponding interaction frequency, Represents a minimum function that ensures that the frequency score does not exceed 1.
[0083] Based on the description of the frequency score in the above embodiment, step S2B-1 further includes: S2B-1-6, obtain the amount score of the abnormal social path based on the social amount of each sub-path in the abnormal social path.
[0084] When executing the above steps, the server will count the transaction amounts corresponding to each edge in the path and add up these amounts to obtain the total transaction amount on the path. Then, to ensure the comparability of the amounts between different paths, the server will compare and normalize the total transaction amount with a preset amount saturation threshold. The expression is as follows:
[0085] Where, Indicates the amount score, represents the number of nodes in the abnormal social path, Indicates the amount saturation threshold, Representation and subpath The corresponding transaction amount, Represents a minimum function, which is used to ensure that the amount score does not exceed 1.
[0086] Based on the description of the amount score in the above implementation, step S2B-1 further includes: S2B-1-7, integrate the frequency score and amount score to obtain the social intensity score of the abnormal social path.
[0087] When executing the above steps, the server can weight the frequency score and the amount score to obtain the social strength score. The expression is as follows:
[0088] Where, represents the social strength score, In this way, the relationship between the identified user and the risky user is evaluated from the two levels of social frequency and social amount, which improves the accuracy of the evaluation.
[0089] For the above social distance score, this embodiment can convert the number of nodes in the abnormal social path into a social distance score using the following expression:
[0090] Where, represents the social distance score, represents the distance attenuation factor, Indicates the number of nodes in the abnormal social path.
[0091] Based on the social relationship score, social distance score and social strength score obtained in the above embodiment, Figure 4Step S2B-2 in the following example is explained: S2B-2, integrates the social relationship score, social distance score, and social strength score to obtain the path risk score of the user to be identified.
[0092] By comprehensively considering the three dimensions of social relationship score, social distance score, and social strength score, this approach overcomes the limitations of traditional single-metric assessment methods, significantly improves the accuracy and reliability of risk assessment, and achieves a comprehensive quantitative assessment of the risk contribution of abnormal social paths. The integration methods provided in this embodiment include, but are not limited to, weighted fusion of the social relationship score, social distance score, and social strength score, or multiplying the social relationship score, social distance score, and social strength score.
[0093] Taking the multiplication of social relationship score, social distance score and social strength score as an example, the corresponding expression is:
[0094] Where, represents the path risk score, Indicates the risk value of the source node. If the source node represents a risky user ,on the contrary, , represents the social relationship score, represents the social distance score, In this way, the combination of scores from multiple aspects improves the comprehensiveness and accuracy of the assessment.
[0095] Based on the path risk scores of each abnormal social path obtained in the above embodiment, we will continue to Figure 3 Step S3B in the following example is explained: S3B, integrate the path risk scores of each abnormal social path in the abnormal social information to obtain the potential risk score of the user to be identified.
[0096] The potential risk score serves as a basis for decision-making on risk control measures. During the above steps, the server obtains all abnormal social paths associated with the target user. These abnormal social paths represent all possible transmission paths from known risk users to the target user. Each path is assigned a path risk score, which measures the impact of that path on the target user's risk. Therefore, based on the path risk scores in the abnormal social information, the server can sum these path risk scores to generate a final risk assessment result for the target user.
[0097] In some implementations, a basic risk score can also be introduced to represent the basic risk level of the target user itself, and the final risk assessment result of the target user is generated by summing it with these path risk scores. The corresponding expression is as follows:
[0098] Where, represents the basic risk score, represents all abnormal social paths, Indicates the Path risk scores of abnormal social paths.
[0099] This enables a quantitative assessment of a user's potential risk, extending risk identification beyond the user's own attributes or behavioral characteristics to include indirect connections within their social network. By layering and assigning scores to social paths, we can more accurately capture risk signals hidden within complex networks of relationships.
[0100] In practice, it is found that user risk assessment faces a variety of complex scenarios. For example, in some cases, the initial risk score and the potential risk score may be highly consistent; in other cases, the two results may be significantly different. If a single fixed fusion method is used (for example, a simple weighted average or directly selecting one of the results), it will not be able to flexibly respond to changes in these scenarios, resulting in some high-risk signals being ignored or low-risk users being misjudged. In view of this, Figure 1 On the basis of Figure 5A as well as Figure 5B As shown, the user risk assessment method provided in this embodiment also includes: S4B, obtain the degree of consensus between the initial risk score and the potential risk score.
[0101] When executing the above steps, the server can obtain the absolute difference between the initial risk score and the potential risk score. To measure the relative importance of this difference, the server further compares the absolute difference with the higher score of the two. If the difference between the two is small, it indicates that the judgment is relatively consistent, and the consensus value will be closer to 1. Conversely, if the difference between the two is large, it indicates that there is a significant difference in their judgment, and the consensus value will be closer to 0. The corresponding expression is as follows:
[0102] Where, Indicates the degree of consensus, represents the initial risk score, Indicates the potential risk score.
[0103] Of course, the method for evaluating the degree of consensus between the initial risk score and the potential risk score is not limited to this. The server can also use the ratio of the smaller value to the larger value between the initial risk score and the potential risk score as the degree of consensus between the two.
[0104] S5B, if the consensus degree is greater than the consensus threshold, the initial risk score and the potential risk score are integrated to obtain the final risk score of the user to be identified.
[0105] S6B: If the consensus level is less than or equal to the consensus threshold, the larger one between the initial risk score and the potential risk score is selected as the final risk score of the user to be identified.
[0106] In this embodiment, if the degree of consensus is greater than the set consensus threshold, it is determined that the judgment results of the two judgment methods are basically the same. At this time, the initial risk score and the potential risk score can be integrated by weighted average to obtain the final risk score. On the contrary, if the degree of consensus is less than or equal to the consensus threshold, it is determined that there is a significant difference in the judgment results of the two judgment methods. In this case, the maximum risk principle can be adopted to select the larger value of the initial risk score and the potential risk score as the final risk score. This method is similar to the "sentinel mechanism" and can effectively avoid the situation where a risk signal that one of the judgment methods fails to detect leads to a misjudgment. The corresponding expression is as follows:
[0107] Where, represents the final risk score, In this way, by dynamically integrating the initial risk score with the potential risk score, we can avoid misjudgment or omission of the identified user.
[0108] Because the final risk score comprehensively considers both the initial risk score and the potential risk score, the server can optionally combine the final risk score to enhance the effectiveness of the risk management strategy. For example, on a live streaming platform, if the final risk score of the user to be identified is higher than the score threshold, the user's consumption behavior will be suspended, including but not limited to prohibiting the identified user from recharging or making purchases on the live streaming platform.
[0109] In summary, the following Figure 6 , which provides an intuitive demonstration of the entire embodiment above. Figure 6 The server receives a transaction request from a user to be identified and then processes it using the rules engine and graph computing engine. In the rules engine, the server extracts risk features and performs rule scoring on the user to be identified.
[0110] The results of the rule engine's calculations drive adjustments to the graph computing engine, specifically index depth. Therefore, within the graph computing engine, the server performs operations such as graph data queries and potential risk calculations for users to be identified based on the rules. The results of the graph computing engine's calculations are used to further enhance the rule engine, specifically by optimizing its scoring rules. This includes, but is not limited to, optimizing the parameters of existing scoring rules or adding new scoring rules.
[0111] Finally, the server makes collaborative decisions based on the calculation results of the two, including: consensus calculation, final risk score calculation, and implementation of preventive measures.
[0112] Based on the same inventive concept as the graph indexing method provided in this embodiment, this embodiment also provides a graph indexing device, which includes at least one software function module that can be stored in a memory or fixed in an electronic device in the form of software. The processor in the electronic device is used to execute the executable module stored in the memory. For example, the software function module and computer program included in the device. Please refer to Figure 7A Functionally, the device can include: The initial risk scoring module 11A is used to obtain user information of the user to be identified; The initial risk scoring module 11A is further used to obtain an initial risk score of the user to be identified based on the user information; A graph indexing module 12A is configured to obtain an index depth of a person relationship graph based on the initial risk score, wherein the person relationship graph records the social relationships between the user to be identified and other users, and the index depth represents the furthest exploration level of the person relationship graph; The graph indexing module 12A is further configured to obtain abnormal social information of the user to be identified from the character relationship graph according to the index depth.
[0113] In this embodiment, the initial risk scoring module 11A is used to implement Figure 1 In steps S1A and S2A, the atlas index module 12A is used to implement Figure 1 Therefore, the detailed description of each module mentioned above can refer to the specific implementation of the corresponding step.
[0114] Since the user risk assessment method provided in this embodiment has the same inventive concept, the user risk assessment device can also implement other steps or sub-steps of the method through the above modules.
[0115] Optionally, the atlas indexing module 12A is further configured to: According to the user information, the risk type of the user to be identified is obtained; According to the risk type, determine the path to be indexed that matches the risk type from the person relationship map; According to the index depth, the abnormal social information of the user to be identified is indexed from the path to be indexed.
[0116] Optionally, the initial risk scoring module 11A is further configured to: The initial risk score is obtained based on the matching results between user information and the scoring rules in the rule base.
[0117] Based on the same inventive concept as the user risk assessment method provided in this embodiment, this embodiment also provides a user risk assessment device, which includes at least one software function module that can be stored in a memory or fixed in an electronic device in the form of software. The processor in the electronic device is used to execute the executable module stored in the memory. For example, the software function module and computer program included in the device. Please refer to Figure 7B Functionally, the device can include: A social path module 11B is configured to determine an abnormal social path of the user to be identified based on the abnormal social information obtained by the graph indexing method, wherein the abnormal social path indicates that the user to be identified has a social relationship with the identified risky users; A potential risk module 12B is used to obtain a path risk score of the abnormal social path based on the abnormal social path; The potential risk module 12B is further configured to integrate the path risk scores of each abnormal social path in the abnormal social information to obtain the potential risk score of the user to be identified, wherein the potential risk score is used as a decision basis for risk control measures.
[0118] Optionally, the potential risk module 12B is further specifically configured to: Based on the abnormal social path, the social relationship score, social distance score, and social strength score of the abnormal social path are obtained. Among them, the social relationship score represents the degree of intimacy between the user to be identified and the risk user, the social distance score represents the attenuation degree of the risk transferred from the risk user to the user to be identified, and the social strength score represents the social strength between the user to be identified and the risk user; The social relationship score, social distance score, and social strength score are integrated to obtain the path risk score of the user to be identified.
[0119] Optionally, the potential risk module 12B is further specifically configured to: Determine a subpath from the abnormal social path, wherein the subpath represents a path between two adjacent nodes in the abnormal social path; According to the social type and social direction corresponding to the sub-path, the relationship sub-score of the sub-path is obtained; The relationship sub-scores of each sub-path in the abnormal social path are integrated to obtain the social relationship score.
[0120] Optionally, the potential risk module 12B is further specifically configured to: Determine a subpath from the abnormal social path, wherein the subpath represents a path between two adjacent nodes in the abnormal social path; According to the social frequency of each sub-path in the abnormal social path, the frequency score of the abnormal social path is obtained; According to the social amount of each sub-path in the abnormal social path, the amount score of the abnormal social path is obtained; The frequency score and amount score are integrated to obtain the social intensity score of the abnormal social path.
[0121] Optionally, the potential risk module 12B is further configured to: Obtain the degree of consensus between the initial risk score and the potential risk score; If the consensus level is greater than the consensus threshold, the initial risk score and the potential risk score are integrated to obtain the final risk score of the user to be identified; If the degree of consensus is less than or equal to the consensus threshold, the larger of the initial risk score and the potential risk score is selected as the final risk score of the user to be identified.
[0122] In addition, the functional modules in each embodiment of the present application can be integrated together to form an independent part, or each module can exist independently, or two or more modules can be integrated to form an independent part.
[0123] It should also be understood that if the above embodiments are implemented in the form of software functional modules and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, or the portion that contributes to the prior art, or the portion of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes a number of instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present application.
[0124] Therefore, this embodiment further provides a computer-readable storage medium. The storage medium stores a computer program that, when executed by a processor, implements the user risk assessment method provided in this embodiment. The storage medium can be any medium capable of storing program code, such as a USB flash drive, a mobile hard drive, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk.
[0125] This embodiment provides an electronic device for implementing a user risk assessment method. Figure 8 As shown, the electronic device may include a processor 22 and a memory 21. In addition, the memory 21 stores a computer program, and the processor implements the user risk assessment method provided in this embodiment by reading and executing the computer program corresponding to the above embodiment in the memory 21.
[0126] Continue to see Figure 8 The electronic device further includes a communication unit 23. The memory 21, the processor 22 and the communication unit 23 are electrically connected to each other directly or indirectly via a system bus 24 to achieve data transmission or interaction.
[0127] The memory 21 may be an information recording device based on any electronic, magnetic, optical or other physical principles, for recording execution instructions, data, etc. In some embodiments, the memory 21 may be, but is not limited to, a volatile memory, a non-volatile memory, a storage drive, etc.
[0128] In some embodiments, the volatile memory may be a random access memory (RAM); in some embodiments, the non-volatile memory may be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), a flash memory, etc.; in some embodiments, the storage drive may be a magnetic disk drive, a solid-state drive, any type of storage disk (such as a CD, DVD, etc.), or a similar storage medium, or a combination thereof.
[0129] The communication unit 23 is configured to transmit and receive data via a network. In some embodiments, the network may include a wired network, a wireless network, a fiber optic network, a telecommunications network, an intranet, the Internet, a local area network (LAN), a wide area network (WAN), a wireless local area network (WLAN), a metropolitan area network (MAN), a wide area network (WAN), a public switched telephone network (PSTN), a Bluetooth network, a ZigBee network, or a near field communication (NFC) network, or any combination thereof. In some embodiments, the network may include one or more network access points. For example, the network may include a wired or wireless network access point, such as a base station and / or a network switching node, through which one or more components of the service request processing system may connect to the network to exchange data and / or information.
[0130] The processor 22 may be an integrated circuit chip having signal processing capabilities, and the processor may include one or more processing cores (e.g., a single-core processor or a multi-core processor). By way of example only, the processor may include a central processing unit (CPU), an application-specific integrated circuit (ASIC), an application-specific instruction-set processor (ASIP), a graphics processing unit (GPU), a physical processing unit (PPU), a digital signal processor (DSP), a field programmable gate array (FPGA), a programmable logic device (PLD), a controller, a microcontroller unit, a reduced instruction set computer (RISC), or a microprocessor, or any combination thereof.
[0131] I understand. Figure 8The structure shown is for reference only. Figure 8 More or fewer components than shown, or with Figure 8 Different configurations shown. Figure 8 The components shown may be implemented in hardware, software, or a combination thereof.
[0132] It should be understood that the devices and methods disclosed in the above embodiments may also be implemented in other ways. The device embodiments described above are merely illustrative. For example, the flowcharts and block diagrams in the accompanying drawings show the possible architectures, functions, and operations of the devices, methods, and computer program products according to multiple embodiments of the present application. In this regard, each box in the flowchart or block diagram may represent a module, a program segment, or a portion of code, which contains one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions marked in the box may also occur in an order different from that marked in the accompanying drawings. For example, two consecutive boxes may actually be executed substantially in parallel, or they may sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram and / or flowchart, and the combination of boxes in the block diagram and / or flowchart, may be implemented using a dedicated hardware-based system that performs a specified function or action, or may be implemented using a combination of dedicated hardware and computer instructions.
[0133] The above descriptions are merely examples of various embodiments of the present application, but the scope of protection of the present application is not limited thereto. Any modifications or substitutions that can be readily conceived by a person skilled in the art within the technical scope disclosed in the present application should be included within the scope of protection of the present application. Therefore, the scope of protection of the present application should be based on the scope of protection of the claims.
Claims
1. A graph indexing method, characterized in that: The method comprises: Obtain user information of the user to be identified; Obtaining an initial risk score for the user to be identified based on the user information; Obtaining an index depth of a person relationship graph based on the initial risk score, wherein the person relationship graph records the social relationships between the user to be identified and other users, and the index depth represents the furthest exploration level of the person relationship graph; According to the index depth, abnormal social information of the user to be identified is obtained from the character relationship graph.
2. The atlas indexing method according to claim 1, characterized in that: Obtaining abnormal social information of the user to be identified from the character relationship graph according to the index depth includes: Obtaining the risk type of the user to be identified based on the user information; According to the risk type, determining a path to be indexed that matches the risk type from the person relationship graph; According to the index depth, abnormal social information of the user to be identified is indexed from the path to be indexed.
3. The atlas indexing method according to claim 1, characterized in that: Obtaining an initial risk score for the user to be identified based on the user information includes: The initial risk score is obtained based on the matching result between the user information and the scoring rules in the rule base.
4. A user risk assessment method, characterized in that: The method comprises: Abnormal social information obtained by the graph indexing method according to any one of claims 1 to 3 is used to determine an abnormal social path of the user to be identified, wherein the abnormal social path indicates that the user to be identified has a social relationship with an identified risk user; Obtaining a path risk score of the abnormal social path according to the abnormal social path; The path risk scores of the abnormal social paths in the abnormal social information are integrated to obtain a potential risk score of the user to be identified, wherein the potential risk score is used as a decision basis for risk control measures.
5. The user risk assessment method according to claim 4, characterized in that: Obtaining a path risk score of the abnormal social path according to the abnormal social path includes: According to the abnormal social path, a social relationship score, a social distance score, and a social strength score of the abnormal social path are obtained, wherein the social relationship score represents the degree of intimacy between the user to be identified and the risk user, the social distance score represents the degree of attenuation caused by the risk of the risk user being transferred to the user to be identified, and the social strength score represents the social strength between the user to be identified and the risk user; The social relationship score, the social distance score, and the social strength score are integrated to obtain a path risk score for the user to be identified.
6. The user risk assessment method according to claim 5, characterized in that: Obtaining a social relationship score for the abnormal social path according to the abnormal social path includes: Determining a subpath from the abnormal social path, wherein the subpath represents a path between two adjacent nodes in the abnormal social path; Obtaining a relationship sub-score for the sub-path according to the social type and social direction corresponding to the sub-path; The relationship sub-scores of the sub-paths in the abnormal social path are integrated to obtain the social relationship score.
7. The user risk assessment method according to claim 5, characterized in that: Obtaining a social strength score of the abnormal social path according to the abnormal social path includes: Determining a subpath from the abnormal social path, wherein the subpath represents a path between two adjacent nodes in the abnormal social path; Obtaining a frequency score of the abnormal social path according to the social frequency of each subpath in the abnormal social path; Obtaining a money score for the abnormal social path based on the social money amount of each subpath in the abnormal social path; The frequency score and the amount score are integrated to obtain a social intensity score of the abnormal social path.
8. The user risk assessment method according to any one of claims 4 to 7, characterized in that: The method further comprises: Obtaining a degree of consensus between the initial risk score of the user to be identified and the potential risk score; If the consensus level is greater than the consensus threshold, the initial risk score and the potential risk score are integrated to obtain a final risk score for the user to be identified; If the consensus level is less than or equal to the consensus threshold, the larger one between the initial risk score and the potential risk score is selected as the final risk score of the user to be identified.
9. A graph indexing device, characterized in that: The device comprises: An initial risk scoring module is used to obtain user information of the user to be identified; The initial risk scoring module is further configured to obtain an initial risk score of the user to be identified based on the user information; A graph indexing module, configured to obtain an index depth of a person relationship graph based on the initial risk score, wherein the person relationship graph records the social relationships between the user to be identified and other users, and the index depth represents the furthest exploration level of the person relationship graph; The graph index module is further configured to obtain abnormal social information of the user to be identified from the character relationship graph according to the index depth.
10. A user risk assessment device, characterized in that: The device comprises: A social path module, configured to determine an abnormal social path of the user to be identified based on the abnormal social information obtained by the graph indexing method according to any one of claims 1 to 3, wherein the abnormal social path indicates that the user to be identified has a social relationship with an identified risk user; A potential risk module, configured to obtain a path risk score of the abnormal social path based on the abnormal social path; The potential risk module is further configured to integrate the path risk scores of the abnormal social paths in the abnormal social information to obtain the potential risk score of the user to be identified, wherein the potential risk score is used as a decision basis for risk control measures.