Risk control model updating method and system for financial service fraud event
By constructing a temporally correlated fraud event evolution network and dynamically adjusting the feature dimensions of the risk control model, the problem that traditional risk control models cannot adapt to the dynamic changes of fraud events is solved, and real-time risk control and fraud identification in financial services are realized.
Patent Information
- Application Number
- CN202511016216.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-23
- Publication Date
- 2025-10-21
AI Technical Summary
Traditional financial service risk control models cannot capture the dynamic changes of fraud events in real time, causing rules to become ineffective and new fraud patterns to be unable to be identified in a timely manner, resulting in economic losses and reputational risks for financial service institutions.
By obtaining the real-time fraud event logs generated during the financial services process, we build a fraud event evolution network with time-series correlation, dynamically adapt the feature dimension system of the risk control model, iteratively adjust the rule judgment logic, generate an updated risk control model rule set with self-adaptive capabilities, and conduct validity verification and deployment.
It has achieved dynamic optimization of the risk control model, which can respond to fraud incidents in a timely and accurate manner, improving the efficiency and accuracy of financial service risk control and reducing fraud risks.
Smart Images

Figure CN120823032A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of financial services risk control technology, and more specifically, to a method and system for updating risk control models for financial services fraud incidents. Background Art
[0002] In the financial services sector, fraud incidents are becoming increasingly complex and dynamic. Traditional risk control model updates rely primarily on periodic manual data collection and analysis, coupled with rule-based approaches based on historical static data. Manual data collection is not only inefficient but also struggles to capture the real-time evolution of fraud scenarios, dynamic business operation chains, and evolving behavior patterns of connected accounts within financial services. For example, new online financial fraud methods can rapidly alter transaction scenarios and operational processes, making manual approaches unable to keep up. Furthermore, rules based on historical static data struggle to adapt to the dynamic nature of fraudulent behavior. Fraudsters constantly adjust their strategies, rendering existing rules ineffective. Traditional approaches are unable to dynamically adjust the feature dimensions and rule-based decision logic of risk control models based on the temporal correlation and variability of fraud incidents. Consequently, risk control models fail to promptly and accurately identify new fraud patterns, resulting in significant financial losses and reputational risks for financial services institutions. Summary of the Invention
[0003] In view of this, the purpose of this application is to provide a method and system for updating risk control models for financial service fraud incidents.
[0004] According to a first aspect of the present application, a method for updating a risk control model for financial services fraud events is provided, the method comprising: Obtain a set of fraud event logs generated in real time during the financial service process, which includes real-time scenario evolution information of multiple fraud events, dynamic business operation chains, and behavioral trajectory changes of associated accounts; Constructing a fraud event evolution network with temporal correlation based on the fraud event log set. The fraud event evolution network is used to present the interactive influence relationship between the scene evolution correlation, operation chain similarity, and account behavior trajectory changes of different fraud events in the time dimension; A feature dimension system of a risk control model dynamically adapted to the fraud event evolution network, wherein the feature dimension system includes dynamic feature items corresponding to each temporal correlation relationship in the fraud event evolution network and weight adaptation rules between feature items that change over time; Based on the conflict analysis results of the feature dimension system and historical risk control rules, iteratively adjust the rule judgment logic of the risk control model to generate an updated risk control model rule set with self-adaptive capabilities; The updated risk control model rule set is validated, and after verification, the updated risk control model rule set is deployed to the financial service risk control system, synchronously triggering the archiving of the original rule set and the real-time effectiveness process of the new rules.
[0005] According to the second aspect of the present application, a risk control model update system for financial services fraud events is provided. The risk control model update system for financial services fraud events includes a machine-readable storage medium and a processor. The machine-readable storage medium stores machine-executable instructions. When the processor executes the machine-executable instructions, the risk control model update system for financial services fraud events implements the aforementioned risk control model update method for financial services fraud events.
[0006] According to a third aspect of the present application, a computer-readable storage medium is provided, wherein the computer-readable storage medium stores computer-executable instructions. When the computer-executable instructions are executed, the aforementioned risk control model update method for financial service fraud events is implemented.
[0007] According to any of the above aspects, the technical effects of this application are: By capturing a rich collection of fraud event logs generated in real time during financial services, a time-series-correlated fraud event evolution network is constructed based on this collection. This method clearly illustrates the complex temporal relationships between different fraud events, overcoming the limitations of traditional methods in capturing the dynamic evolution of fraud events. The risk control model's feature dimension system is dynamically adapted to the fraud event evolution network, enabling the feature dimension to keep pace with changes in fraudulent behavior. Dynamic feature items and weight adaptation rules corresponding to the evolution network are included, improving the timeliness and relevance of the feature dimension. The rule decision logic is iteratively adjusted based on conflict analysis results between the feature dimension system and historical risk control rules, generating an updated, self-adaptive risk control model rule set. This achieves dynamic optimization and self-adjustment of risk control rules. The updated rule set is effectively verified and deployed to the financial services risk control system, with the original rules archived and the new rules taking effect in real time. This ensures that the risk control model can respond to fraud incidents in financial services in a timely and accurate manner, effectively improving the efficiency and accuracy of financial services risk control and reducing fraud risks. BRIEF DESCRIPTION OF THE DRAWINGS
[0008] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following is a brief introduction to the drawings required for use in the embodiments. It should be understood that the following drawings only illustrate certain embodiments of the present application and therefore should not be regarded as limiting the scope. For ordinary technicians in this field, other relevant drawings can be obtained based on these drawings without any creative work.
[0009] Figure 1 A flow chart of a method for updating a risk control model for financial services fraud events provided by an embodiment of the present application is shown; Figure 2 A schematic diagram of the component structure of a risk control model updating system for financial service fraud events provided by an embodiment of the present application for implementing the above-mentioned risk control model updating method for financial service fraud events is shown. DETAILED DESCRIPTION
[0010] The following describes the embodiments of the present application in conjunction with the accompanying drawings. It should be understood that the embodiments described below in conjunction with the accompanying drawings are exemplary descriptions for explaining the technical solutions of the embodiments of the present application and do not constitute a limitation on the technical solutions of the embodiments of the present application.
[0011] Those skilled in the art will appreciate that, unless expressly stated, the singular forms "a", "an", "said" and "the" used herein may also include plural forms. It should be further understood that the terms "including" and "comprising" used in the embodiments of the present application refer to that the corresponding features can be implemented as the features, information, data, steps, operations, elements and / or components presented, but do not exclude implementation as other features, information, data, steps, operations, elements, components and / or combinations thereof supported by the present technical field. It should be understood that when an element is said to be "connected" or "coupled" to another element, the element can be directly connected or coupled to the other element, or it can refer to that the element and the other element establish a connection relationship through an intermediate element. In addition, the "connection" or "coupling" used herein may include wireless connection or wireless coupling, and the term "and / or" used herein indicates at least one of the items defined by the term, for example, "A and / or B" can be implemented as "A", or as "B", or as "A and B".
[0012] In order to make the purpose, technical solutions and advantages of the present application clearer, the embodiments of the present application will be further described in detail with reference to the accompanying drawings. The following description of several exemplary embodiments will illustrate the technical solutions of the embodiments of the present application and the technical effects produced by the technical solutions of the present application. It should be noted that the following embodiments can refer to, draw on or combine with each other, and the same terms, similar features and similar implementation steps in different embodiments will not be repeated.
[0013] Figure 1The following is a flow chart of a method and system for updating a risk control model for financial services fraud events provided by an embodiment of the present application. It should be understood that in other embodiments, the order of some steps in the method for updating a risk control model for financial services fraud events of this embodiment may be shared, or some steps may be omitted or maintained, depending on actual needs. The detailed steps of the method for updating a risk control model for financial services fraud events include: Step S110: Obtain a fraud event log set generated in real time during the financial service process, wherein the fraud event log set includes real-time scenario evolution information of multiple fraud events, dynamic business operation chains, and behavioral trajectory changes of associated accounts.
[0014] In online loan business scenarios, when fraud occurs, relevant business interaction data is recorded in real time. These records cover all types of information related to the fraudulent behavior from the time the incident occurs to its development. For example, in a fraud incident, a user submitted a loan application using false identity information and subsequently made a series of unusual loan limit adjustments. These operations, along with all transactions involving the account before and after the incident, are included in the fraud event log collection.
[0015] Real-time scenario evolution information records changes in the scenario surrounding the fraudulent incident, such as the transition from the initial loan application page to the identity verification stage and then to the credit limit approval interface. The changes in scenario characteristics at each stage are recorded in detail. The dynamic business operation chain chronologically arranges every user action in the loan process, including actions such as clicking buttons, entering information, and submitting materials, as well as the status changes of these actions, such as resubmitting after a failed submission. The behavioral trajectory changes of associated accounts track the behavior of other accounts that have financial transactions or information exchanges with the fraudulent account, such as changes in the login locations, transaction amounts, and transaction partners of these accounts before and after the fraudulent incident.
[0016] Step S111: receiving the initial fraud event log pushed in real time by the financial service system when a fraud event is monitored. The initial fraud event log includes a dynamic business type identifier, account identifier, and operation sequence chain during the occurrence and development of the event.
[0017] The financial services system has real-time monitoring capabilities. When it detects fraudulent activity in online loan transactions, it can immediately push the initial fraud event log. The transaction type identifier changes dynamically as the event progresses. In the aforementioned fraudulent loan example, the initial transaction type identifier was "Personal Credit Loan Application." When the user adjusted the loan amount, the transaction type identifier changed to "Loan Amount Adjustment."
[0018] An account identifier is a unique code for each account, used to distinguish different accounts. In this example, the fraudulent account identifier is a specific string combination, which can be used to accurately identify the corresponding account. An operation sequence chain is a chronological record of user actions, such as clicking the "Apply for a Loan" button at a certain point in time, entering ID information some time later, and then submitting proof of income. Each action is accurately timestamped.
[0019] Step S112: extracting real-time scenario evolution information from the initial log of the fraud event, tracking the business attribute changes, dynamic adjustment of environmental attributes and interactive channel switching process of the fraud event scenario, and generating real-time scenario evolution information.
[0020] Based on the initial fraud event logs received, we begin extracting real-time scenario evolution information. Regarding changes in business attributes, in the case of fraudulent loan applications, if the loan application amount is changed from one initial value to another, or the loan term is adjusted from a short-term to a long-term one, these changes in business attributes are recorded.
[0021] Dynamic adjustments to environmental attributes involve changes in the network and device environments during user operations. For example, a user might start an operation on a wireless network and then switch to a mobile data network, the device's operating system might be updated from one version to another, or the screen resolution might change. Switching interaction channels might involve switching from a mobile app to a computer webpage, or from an official application to a third-party partner platform. These switches are tracked and recorded in detail, generating real-time scene evolution information.
[0022] Step S113: Analyze the operation sequence chain in the initial log of the fraud event, extract the continuous business operation instruction sequence that progresses over time, the dynamic changes in the state parameters of each operation instruction, and the operation interruption and recovery nodes, and generate a dynamic business operation chain.
[0023] When parsing the operation sequence chain, the continuous business operation instruction sequence will be extracted in chronological order. In the case of a fake identity loan, the sequence may be: "Open the loan app - log in to the account - enter the loan application page - fill in basic information - upload a fake ID photo - submit the application - the application is rejected - modify the information - submit again."
[0024] The dynamic changes in the status parameters of each operation instruction include the execution status of each operation, such as the status of the "Submit Application" operation changing from "Pending" to "Under Review" and then to "Rejected", as well as related parameters during the operation, such as changes in the size and format of the uploaded photo during the modification process. The operation interruption and resumption nodes record pauses during the operation. For example, if a user logs out of the app while filling in information and logs back in a few hours later to continue filling in the information, the time points of exiting and re-entering are the interruption and resumption nodes.
[0025] Step S114: retrieve the full business interaction records of the account before and after the fraud event according to the account identifier, filter the interaction behavior data change fragments related to the development process of the fraud event, and generate the behavior trajectory change of the associated account.
[0026] Based on the fraudulent account identifier, retrieve all business interaction records for the account before and after the incident. In a fraudulent loan incident, the account may have made several small loan inquiries before the incident; after the incident, there may be fund transfer records with other suspicious accounts.
[0027] From these full records, we filter out fragments related to the development of the fraud incident. For example, before the incident, the account had frequent information interactions with a certain account, and the account had a previous fraud record. These fragments of interaction behavior data changes will be integrated to form the behavioral trajectory changes of the associated accounts, including the time, content, and method of interaction.
[0028] Step S115: The real-time scenario evolution information, dynamic business operation chain and behavior trajectory changes of associated accounts are stored in a time-series manner to form a fraud event log set.
[0029] The extracted real-time scenario evolution information, dynamic business operation chains, and behavioral trajectory changes of associated accounts are stored in chronological order. During the storage process, the scenario information, operation behavior, and associated account behavior corresponding to each time point will be correlated with each other.
[0030] For example, at a certain point in time, real-time scenario evolution information shows that the user is in the "loan limit adjustment" scenario. The operation at that point in time in the dynamic business operation chain is "submitting a limit adjustment application." The behavioral trajectory changes of the associated accounts show that at this time, an associated account transferred funds to the fraudulent account. These three pieces of information will be stored together to form a complete log record. Many of the above records constitute a fraud event log collection.
[0031] Step S120: constructing a fraud event evolution network with time series correlation based on the fraud event log set, wherein the fraud event evolution network is used to present the interactive influence relationship of scene evolution correlation, operation chain similarity and account behavior trajectory change of different fraud events in the time dimension.
[0032] Using the established fraud event log collection, we began to construct a fraud event evolution network. This fraud event evolution network uses different fraud events as nodes, and the connections between nodes reflect the various associations between events, and these associations have time attributes.
[0033] In online loan scenarios, there may be multiple similar false identity loan fraud incidents. Some incidents have similarities in scenario evolution, some have commonalities in the operation chain, and some have mutual influence on account behavior trajectories. These will all be reflected in the evolutionary network. Through the network, we can clearly see the development of different fraud incidents over time and the relationship between them.
[0034] Step S121: Extract key scenario evolution elements from the real-time scenario evolution information of each fraud event from the fraud event log set, wherein the key scenario evolution elements include changes in core business types in business attribute changes, evolution of interactive environment characteristics in dynamic adjustment of environmental attributes, and channel type conversion in the process of interactive channel switching.
[0035] From the fraud event log collection, we extract key scenario evolution factors based on the real-time scenario evolution information for each fraud event. In online loan fraud cases, the core business type change may be from "personal credit loans" to "mortgage loans." This is because fraudsters, realizing the strict review process for credit loans, switch to mortgage loans, which have a more relaxed review process.
[0036] The evolution of interactive environment characteristics involves changes in network and device environments, such as changes in network latency from low to high, or changes in device screen size from a standard size to an unusual size. Channel type conversions may involve switching from an official mobile app to a third-party partner website, as third-party channels may have loopholes in their review processes, facilitating fraudulent activity.
[0037] Step S122: Compare key scenario evolution elements of different fraud events within the same time interval, calculate the dynamic overlap of the scenario evolution elements, and determine the scenario evolution correlation between different fraud events based on the changing trend of the dynamic overlap over time.
[0038] We selected multiple online loan fraud incidents and compared their key scenario evolution factors over the same time period. For example, we selected Event A and Event B. During a certain time period, Event A's core business type changed from "personal credit loans" to "mortgage loans." Event B also underwent the same core business type change during the same time period. Furthermore, the evolution of the interaction environment characteristics of both incidents showed an increasing trend in network latency, and the channel type changed from the official app to a third-party website.
[0039] The dynamic overlap of these key scenario evolution elements is calculated, that is, the proportion of the same elements appearing in the same time interval, and how these proportions change over time. If the dynamic overlap remains high for a long time, it means that the scenario evolution correlation between Event A and Event B is strong; if the dynamic overlap fluctuates greatly and is generally low, the correlation is weak.
[0040] Step S123: Perform a timing pattern comparison on the dynamic business operation chain of each fraud event in the fraud event log set, extract the time sequence changes of the operation instruction sequence, the similarity rules of the dynamic changes of the state parameters, and the synchronization of the operation interruption and recovery nodes, and calculate the timing pattern matching degree between different dynamic business operation chains as the operation chain similarity.
[0041] We compared the temporal patterns of the dynamic business operation chains for each fraud event. Regarding the temporal changes in the operational instruction sequences, we compared the operational sequences of Event C and Event D. The operational sequence for Event C was "apply for a loan - submit documents - review failed - modify documents - resubmit," while the operational sequence for Event D was "apply for a loan - modify documents - submit documents - review failed - resubmit." We analyzed the differences and similarities between the two temporal sequences.
[0042] The similarity of dynamic changes in status parameters, such as the number of format errors in submitted materials and the interval between modification times, in Event C and Event D, is also important. The synchronization of interruption and recovery nodes is determined by whether the interruption and recovery times of the two events are within a similar time period.
[0043] Taking all of these factors into account, we calculate the timing pattern matching degree. The higher the matching degree, the more similar the operation chains are. For example, if the time sequence of the operation instruction sequences of two events is mostly the same, the state parameter change patterns are similar, and the interrupt and recovery nodes are highly synchronized, then the operation chains are highly similar.
[0044] Step S124: Analyze the behavior trajectory changes of the associated accounts in the fraud event log set, identify the cross-operation nodes of different account behavior trajectories on the time axis, the overlapping time periods of interaction objects, and the synchronous variation points of behavior patterns, and determine the interactive impact relationship of the account behavior trajectory changes.
[0045] Analyze the changes in the behavioral trajectories of related accounts. A cross-operation node refers to different accounts performing the same or related operations at the same time point. For example, account E and account F transfer funds to the same suspicious account at the same time point. This time point is a cross-operation node.
[0046] An overlapping period of interaction occurs when both account E and account F interact with account G. A synchronous behavioral pattern change occurs when the behavior patterns of account E and account F undergo similar, unusual changes at the same time. For example, if they initially traded small amounts, they suddenly begin making large transactions at the same time.
[0047] By identifying these characteristics, we can determine the interactive influence relationship between changes in account behavior trajectories. If two accounts have more cross-operation nodes, longer overlapping periods of interaction objects, and multiple synchronous variation points in behavior patterns, it means that their interactive influence relationship is strong.
[0048] Step S125: Based on the fraud event nodes containing timestamps, the interactive influence relationships of scenario evolution correlation, operation chain similarity, and account behavior trajectory changes are used as edges with temporal weights to construct a fraud event evolution network with temporal correlation.
[0049] Each fraud event is treated as a node, each with a precise timestamp indicating the time of the event. Edges are then added between nodes based on the previously determined interaction relationships between scenario evolution relevance, operation chain similarity, and account behavior trajectory changes.
[0050] These edges carry temporal weights, determined by the strength of the association. The stronger the association, the greater the weight, and the weights change over time. For example, if Event A and Event B are strongly correlated in the early stages of scenario evolution, the edge weight will be high. Later, as the correlation weakens, the weight will decrease. This approach constructs a fraud event evolution network with temporal correlations, visually demonstrating the connections between different fraud events and how they change over time.
[0051] Step S130: dynamically adapting the feature dimension system of the risk control model according to the fraud event evolution network, wherein the feature dimension system includes dynamic feature items corresponding to each temporal correlation relationship in the fraud event evolution network and weight adaptation rules between feature items that change over time.
[0052] Based on the established fraud event evolution network, we began adapting the feature dimension system of the risk control model. Dynamic feature items needed to correspond to the temporal relationships in the network, such as those corresponding to the correlation between scenario evolution and the similarity between operation chains.
[0053] The weight adaptation rules will specify how the weights of these feature items change over time. In the online loan fraud scenario, when the scenario evolution correlation of a certain type of fraud incident becomes stronger in the near future, the weight of the corresponding dynamic feature item will increase accordingly to improve the risk control model's sensitivity to such correlated features.
[0054] Step S131: Analyze the scenario evolution correlation in the fraud event evolution network, and extract dynamic scenario characteristic factors corresponding to the scenario evolution correlation. The dynamic scenario characteristic factors include core business type change correlation factors, interactive environment feature evolution correlation factors, and channel type conversion correlation factors.
[0055] Analyze the scenario evolution correlation in the fraud event evolution network and extract the core business type change correlation factor. The core business type change correlation factor reflects the degree of correlation between the core business type changes in different fraud events. For example, in multiple fraud events, the core business type changes from "personal credit loan" to "mortgage loan".
[0056] The interaction environment feature evolution correlation factor reflects the correlation between interaction environment feature evolution across different events, such as changes in network latency and device parameter adjustments. The channel type conversion correlation factor reflects the correlation between channel type conversions across different events, such as the degree of correlation between switching from an official app to a third-party website.
[0057] Step S1311: traverse all edges with time-series weights that represent scenario evolution relevance in the fraud event evolution network in chronological order, and record the core business type change process of the two fraud events corresponding to each edge at different time nodes.
[0058] Check the edges in the network that represent the correlation of scenario evolution and have temporal weights one by one in chronological order. For each edge, record the change process of the core business type of the two fraud events connected by it at different time nodes.
[0059] For example, an edge connects event H and event I. At time node t1, the core business type of event H changes from "personal credit loan" to "mortgage loan", and the core business type of event I changes from "consumer loan" to "mortgage loan"; at time node t2, the core business type of event H does not change, and the core business type of event I changes from "mortgage loan" to "operating loan". These change processes will be recorded in detail.
[0060] Step S1312: Count the time frequency distribution of the same core business type change process combination appearing in the scenario evolution correlation edge, calculate the temporal correlation degree between the core business type changes based on the time frequency distribution, and generate a core business type change correlation factor.
[0061] We count the number of occurrences of the same core business type change process combination and the corresponding time to form a time frequency distribution. For example, we can count the number of occurrences of the combination "Event A changes from personal credit loans to mortgage loans, and Event B changes from consumer loans to mortgage loans" at different time points.
[0062] Based on the time frequency distribution, the temporal correlation degree between core business type changes is calculated. The higher the frequency and the more concentrated the time distribution, the higher the temporal correlation degree. Based on this, the core business type change correlation factor is generated. The core business type change correlation factor is a multi-dimensional numerical set, and each dimension corresponds to the correlation degree of a change process combination.
[0063] Step S1313: Extract the evolution process of the interactive environment characteristics corresponding to the scene evolution correlation edge, compare the similar attribute evolution trajectories of the interactive environment characteristics of different fraud events in the same time interval, calculate the change curve of the overlap ratio of the similar attribute evolution trajectories over time, and determine the interactive environment characteristic evolution correlation factor based on the change curve.
[0064] Extract the evolution of the interactive environment features corresponding to each scenario evolution correlation edge and compare the evolution trajectories of similar attributes of interactive environment features across different fraud events within the same time period. For example, compare the network latency change trajectories and device resolution adjustment trajectories of event J and event K within a certain time period.
[0065] The overlap ratio of these similar attribute evolution trajectories is calculated—that is, the proportion of identically changing parts of the trajectories relative to the total trajectories—and a curve of this ratio over time is generated. If the curve shows a high and stable overlap ratio, it indicates a strong correlation between the evolution of the interaction environment characteristics. Based on this, a correlation factor for the evolution of the interaction environment characteristics is determined. This factor is also multidimensional, encompassing the correlation between different interaction environment characteristics.
[0066] Step S1314: Collect the channel type conversion processes involved in the scenario evolution correlation edges, analyze the temporal co-occurrence windows of different channel type conversions in the associated fraud events, and generate a channel type conversion correlation factor based on the duration and occurrence frequency of the temporal co-occurrence windows.
[0067] Collect the channel type conversion processes involved in the scenario evolution correlation edges, such as event L converting from the official app to a third-party website, and event M also converting from the official app to a third-party website. Analyze the temporal co-occurrence windows of these conversions in the associated events, that is, the time overlap intervals when the same channel conversion occurs between two events.
[0068] Based on the duration and frequency of the temporal co-occurrence window, a channel type conversion correlation factor is generated. The longer the duration and the higher the frequency of occurrence, the larger the value of the correlation factor. The channel type conversion correlation factor is a multi-dimensional set that corresponds to the degree of correlation between different channel type conversion combinations.
[0069] Step S1315: Integrate the core business type change correlation factor, the interactive environment feature evolution correlation factor, and the channel type conversion correlation factor into a dynamic scenario feature factor.
[0070] The previously generated factors associated with core business type changes, interaction environment feature evolution, and channel type conversion are integrated to form dynamic scenario feature factors. The integration process involves arranging and combining the multidimensional values of these three factors according to a specific structure to form a more comprehensive set of multidimensional feature factors that fully reflect the characteristics corresponding to the scenario's evolutionary relevance.
[0071] Step S132: Based on the similarity of the operation chain in the fraud event evolution network, a dynamic operation sequence characteristic factor is generated. The dynamic operation sequence characteristic factor includes an operation instruction time sequence change correlation factor, a state parameter dynamic change law correlation factor, and an operation interruption recovery synchronization correlation factor.
[0072] Based on the similarity of operation chains in the fraud event evolution network, a dynamic operation sequence characteristic factor is generated. The operation instruction temporal sequence change correlation factor reflects the correlation between the temporal sequence changes of operation instructions in different fraud events, such as the degree of correlation between the order of operation sequence adjustments in two events.
[0073] The dynamic change pattern correlation factor of state parameters reflects the correlation of the change pattern of the state parameters of the operation instructions, such as the change pattern of the number of times the submitted document format is modified. The operation interruption and recovery synchronization correlation factor reflects the degree of synchronization between the interruption and recovery nodes in time.
[0074] Step S1321: for the edges with time series weights corresponding to the similarity of the operation chains in the fraud event evolution network, extract the dynamic business operation chains of the two fraud events connected by the edges in different time segments.
[0075] Focusing on edges with temporal weights corresponding to the similarity of operation chains in the network, for each such edge, the dynamic business operation chains of the two connected fraud events at different time segments are extracted. In an online loan fraud scenario, an edge connects event N and event O, with time segments divided into t3-t4, t5-t6, and so on. During the t3-t4 time segment, the dynamic business operation chain for event N is "log in to account - select loan product - enter loan amount - submit false income certificate - wait for review", while the dynamic business operation chain for event O is "log in to account - select loan product - enter loan term - submit false income certificate - wait for review". During the t5-t6 time segment, the operation chain for event N changes to "rejected review - modify loan amount - resubmit", while the operation chain for event O changes to "rejected review - modify loan term - resubmit". These dynamic business operation chains at different time segments are accurately extracted.
[0076] Step S1322: Compare the time sequence changes of the operation instructions in the two dynamic business operation chains, identify the operation instruction fragments with the same time sequence change pattern, calculate the time proportion of the operation instruction fragments in the two dynamic business operation chains, and generate the operation instruction time sequence change correlation factor based on the change trend of the time proportion.
[0077] Compare the chronological changes in the dynamic business operation chains of Event N and Event O at different time segments. During the t3-t4 time segment, the chronological changes in the "log in to your account - select a loan product - submit a false income certificate" sequence are identical for both: first log in, then select a product, and finally submit the certificate.
[0078] Calculate the proportion of the same pattern of operation instruction fragments in the total time of the dynamic business operation chain of event N, and the proportion of the same pattern of operation instruction fragments in the total time of the dynamic business operation chain of event O. For example, the proportion of the fragment in the t3-t4 operation chain of event N is a certain proportion, and the proportion in the t3-t4 operation chain of event O is another proportion. Track the changing trends of these time proportions in different time segments. If the trend is consistent and the proportion is always high, the generated operation instruction time sequence change correlation factor has a large value. The operation instruction time sequence change correlation factor is a multi-dimensional set, corresponding to the time sequence change correlation of different operation instruction fragments.
[0079] Step S1323: Analyze the dynamic changes of the state parameters corresponding to each operation instruction in the dynamic business operation chain, extract the dynamic regularity characteristics of the state parameters, calculate the fluctuation value of the degree of consistency of the dynamic regularity of the state parameters in the two dynamic business operation chains over time, and determine the correlation factor of the dynamic change regularity of the state parameters based on the fluctuation value.
[0080] Analyze the dynamic changes in the status parameters of each operation instruction in the dynamic business operation chain. For example, the status parameters of the "Submit Application" operation in Events P and Q include review wait time and the number of document supplements. In Event P, the review wait time gradually increases, and the number of document supplements is two with uniform intervals. In Event Q, the review wait time also gradually increases, and the number of document supplements is two with intervals similar to those in Event P. These are the dynamic regular characteristics of the status parameters.
[0081] Calculate the degree of consistency between the dynamic patterns of state parameters in two dynamic business operation chains—that is, the matching ratio of the same pattern characteristics—and determine the fluctuation of this consistency over time. Smaller fluctuations indicate more stable consistency. Based on this, determine the correlation factor for the dynamic change pattern of state parameters. This factor is a multi-dimensional set that covers the correlation between the dynamic patterns of different state parameters.
[0082] Step S1324: Identify the operation interruption and recovery nodes in the dynamic business operation chain, compare the time synchronization of the operation interruption and recovery nodes of different fraud events, calculate the time deviation value distribution of synchronization, and generate the operation interruption recovery synchronization correlation factor based on the time deviation value distribution of synchronization.
[0083] In the dynamic business operation chain, identify the operation interruption and recovery nodes. For example, during the operation process, event R interrupts the operation at time t7 and resumes the operation at t8; during the operation process, event S interrupts the operation at time t9 and resumes the operation at t10.
[0084] Compare the time synchronization of these nodes and calculate the time deviation between t7 and t9, and between t8 and t10, to form a distribution of synchronization time deviations. Small and concentrated deviations indicate high synchronization. Based on this, we generate an operation interruption and recovery synchronization correlation factor. This operation interruption and recovery synchronization correlation factor is a multi-dimensional set that corresponds to the synchronization correlation of different interruption and recovery node combinations.
[0085] Step S1325: Integrate the operation instruction time sequence change correlation factor, the state parameter dynamic change law correlation factor, and the operation interruption recovery synchronization correlation factor into a dynamic operation sequence characteristic factor.
[0086] The dynamic operation sequence characteristic factor is formed by integrating the correlation factors of the temporal sequence changes of operation instructions, the correlation factors of the dynamic change patterns of state parameters, and the correlation factors of the synchronization of operation interruption and recovery. The integration method combines the multi-dimensional values of these three factors according to a specific structure to form a set of characteristic factors corresponding to the comprehensive similarity of the operation chain.
[0087] Step S133: Determine dynamic account behavior characteristic factors based on the interactive influence relationship of account behavior trajectory changes in the fraud event evolution network. The dynamic account behavior characteristic factors include cross-operation node correlation factors, interactive object overlapping period correlation factors, and behavior pattern synchronous variation correlation factors.
[0088] Dynamic account behavior characteristic factors are determined based on the interactive influence relationships among account behavior trajectories within the fraud event evolution network. The cross-operation node correlation factor reflects the degree of association between different accounts at cross-operation nodes, the interaction object overlap period correlation factor reflects the association between account interaction objects during overlapping periods, and the behavior pattern synchronization variation correlation factor reflects the degree of association between synchronized variations in account behavior patterns.
[0089] Step S1331: Analyze the edges of the interactive influence relationship representing the changes in the account behavior trajectory in the fraud event evolution network, and extract the cross-operation nodes of the different account behavior trajectories involved in the edges on the time axis.
[0090] Analyze the edges in the network that represent the interactive influence relationships between account behavior trajectories and extract the cross-operation nodes between different account behavior trajectories on the timeline. For example, consider an edge connecting accounts T and U. On the timeline, account T performs a "transfer to an unfamiliar account" operation at time t11, and account U also performs a "transfer to the same unfamiliar account" operation at time t11. t11 is a cross-operation node; account T performs a "change bound mobile phone number" operation at time t12, and account U also performs a "change login password" operation at time t12. t12 is also a cross-operation node. These nodes are all extracted.
[0091] Step S1332: Count the frequency and duration of occurrence of cross-operation nodes in the same business scenario, calculate the degree of behavioral coordination of different accounts at the cross-operation nodes, and generate a cross-operation node correlation factor based on the degree of behavioral coordination.
[0092] Statistics were collected to determine the frequency and duration of cross-operation nodes in the same business scenario. For example, in the "online loan application" business scenario, the cross-operation nodes of account V and account W appeared multiple times, with each duration ranging from a few seconds to several minutes.
[0093] The degree of behavioral coordination between different accounts at cross-operation nodes is calculated, including the relevance of operation objectives and results. The higher the degree of coordination, the closer the account connections at the cross-operation nodes. Based on this, a cross-operation node correlation factor is generated. This cross-operation node correlation factor is a multi-dimensional set that corresponds to the correlation between different cross-operation node combinations.
[0094] Step S1333: Track the interactive objects corresponding to the interactive impact relationship of the changes in the account behavior trajectory, determine the temporal overlapping periods of the interactive objects of different accounts, calculate the proportion of the overlapping periods in the entire event duration and the interaction frequency within the overlapping periods, and generate an interactive object overlapping period correlation factor based on the proportion and interaction frequency.
[0095] Track the interaction objects corresponding to the interactive impact relationships that change the trajectory of account behavior. For example, account X's interaction objects include account Y, account Z, etc., and account A1's interaction objects include account Y, account B1, etc. Determine the time period when the interaction objects of account X and account A1 overlap in time, that is, the time period when both accounts X and A1 interact with account Y.
[0096] Calculate the proportion of the overlapping period in the entire event duration and the frequency of interaction with account Y during the overlapping period. The higher the proportion and the higher the interaction frequency, the stronger the correlation between the overlapping periods of the interaction objects. Based on this, generate the interaction object overlapping period correlation factor. This interaction object overlapping period correlation factor is a multi-dimensional set that covers the overlapping period correlation of different interaction object combinations.
[0097] Step S1334: Analyze the behavioral pattern variation points in the changes of account behavior trajectories, identify the time synchronization of the behavioral pattern variation points of different accounts and the similarity of the variation trends, calculate the synchronization deviation value and the trend similarity coefficient, and generate the behavioral pattern synchronization variation correlation factor based on the synchronization deviation value and the trend similarity coefficient.
[0098] Analyze the behavioral pattern variation points in the account behavior trajectory changes, such as the time point t13 when the behavior pattern of account C1 changed from "regular small transactions" to "frequent large transactions", and the time point t14 when the behavior pattern of account D1 changed from "regular login time" to "random login time".
[0099] Identify the temporal synchronization of behavioral pattern variation points across different accounts and calculate the synchronization deviation between t13 and t14. Analyze the similarity of variation trends, such as if they all transition from normal to abnormal behavior, and calculate the trend similarity coefficient. Generate a behavioral pattern synchronization variation correlation factor based on the synchronization deviation and trend similarity coefficient. The smaller the deviation and the higher the coefficient, the larger the correlation factor. This behavioral pattern synchronization variation correlation factor is a multi-dimensional set that corresponds to the correlation between different combinations of behavioral pattern variation points.
[0100] Step S1335: Integrate the cross-operation node correlation factor, the interaction object overlapping period correlation factor, and the behavior pattern synchronous variation correlation factor into a dynamic account behavior characteristic factor.
[0101] The dynamic account behavior characteristic factors are formed by integrating the cross-operation node correlation factors, the interaction object overlapping period correlation factors, and the behavior pattern synchronous variation correlation factors. During the integration, the multi-dimensional values of these three factors are arranged in a specific structure to form a characteristic factor set that comprehensively reflects the interactive influence relationship between the changes in account behavior trajectory.
[0102] Step S134: Using the dynamic scenario feature factor, the dynamic operation sequence feature factor, and the dynamic account behavior feature factor as dynamic feature items, an initial dynamic feature dimension system is constructed.
[0103] The previously generated dynamic scenario, operation sequence, and account behavior factors are used as dynamic feature items to construct an initial dynamic feature dimension system. In the online loan fraud scenario, this initial dynamic feature dimension system encompasses all dynamic feature items related to scenario evolution, operation sequence, and account behavior. Each feature item has a corresponding multi-dimensional numerical set, which together constitute the initial feature dimension system.
[0104] Step S135: Track the expansion or contraction trend of the influence range and the fluctuation of the correlation strength of each dynamic feature item in the fraud event evolution network over time, construct weight adaptation rules that are dynamically adjusted between each dynamic feature item over time, and generate a feature dimension system of the risk control model after dynamic adaptation.
[0105] Track the expansion or contraction trend of the influence range of each dynamic feature item in the fraud event evolution network over time. For example, the channel type conversion correlation factor in the dynamic scenario feature factor has an expanding influence range in a certain period, involving more fraud events; while in another period, the influence range gradually shrinks.
[0106] We also monitor fluctuations in correlation strength. For example, the correlation strength of the correlation factor associated with changes in the chronological order of operational instructions fluctuates over time. Based on these trends and fluctuations, we construct adaptive weighting rules for each dynamic feature item, dynamically adjusting them over time. For example, as the influence of the correlation factor associated with channel type conversion expands, its weight increases accordingly; while as the correlation strength of the correlation factor associated with changes in the chronological order of operational instructions decreases, its weight decreases accordingly. This generates the characteristic dimension system of the dynamically adapted risk control model.
[0107] Step S140: Based on the conflict analysis results of the feature dimension system and historical risk control rules, iteratively adjust the rule judgment logic of the risk control model to generate an updated risk control model rule set with self-adaptation capability.
[0108] Combining the conflict analysis results between the feature dimension system and historical risk control rules, we iteratively adjust the risk control model's rule-determination logic. In online loan fraud scenarios, historical risk control rules may have some incompatibilities with the new feature dimension system. By analyzing these conflicts and continuously optimizing the rule-determination logic, we ensure that the generated, updated risk control model rule set automatically adjusts to the actual situation and adapts to different fraud scenarios.
[0109] Step S141: Retrieve the original historical rule determination logic of the risk control model, and analyze the rule entries and rule applicable time range corresponding to the dynamic feature items of the feature dimension system in the historical rule determination logic.
[0110] The original historical rule judgment logic of the risk control model is retrieved, which contains multiple rule items, such as "When the account is logged in from a different location and a loan is applied for, it is judged as high risk" and "When the submitted identity information does not match the credit record, the loan application is rejected".
[0111] Analyze the parts of these rule entries that correspond to the dynamic features of the feature dimension system. For example, "remote login" corresponds to the "login location change" feature in the dynamic account behavior feature factor, and "submission information discrepancy" corresponds to the "material submission status change" feature in the dynamic operation sequence feature factor. Also, determine the applicable timeframe for each rule entry. For example, some rules may only apply in a specific quarter or during a specific business promotion period.
[0112] Step S142: Perform a matching analysis on the dynamic feature items and historical rule items in the feature dimension system, identify the rule contents with conflicts, and generate conflict analysis results. The conflicts include feature item weight mismatch, overlapping rule application time ranges, and opposite judgment logic.
[0113] A matching analysis is performed on the dynamic feature items and historical rule items in the feature dimension system. For example, the weight of the "channel type conversion correlation factor" in the dynamic scenario feature factor is relatively high, but the corresponding "third-party channel loan application" rule item in the historical rule has a relatively low weight. This is a conflict situation where the feature item weights do not match.
[0114] For example, the historical rule entry "Priority review for loan applications submitted between 9:00 AM and 6:00 PM on weekdays" overlaps with the rule entry "Priority review for loan applications submitted on non-business days" in applicable time ranges, and their decision logic is opposite. This is also a conflict. These conflicts are organized into conflict analysis results.
[0115] Step S143: Based on the conflict analysis results and the weight adaptation rules in the feature dimension system, the judgment weights of the dynamic feature items in the conflicting historical rule entries are adjusted first, and the rule sub-entries corresponding to the newly added dynamic feature items and the applicable time intervals of the sub-entries are added.
[0116] Based on the conflict analysis results and the weight adaptation rules in the feature dimension system, the weights of conflicting historical rule entries are adjusted first. For example, if the feature item weights do not match, the weight of the "Channel Type Conversion Correlation Factor" in the "Third-Party Loan Application" rule entry will be increased to align with the weight adaptation rules in the feature dimension system.
[0117] For newly added dynamic feature items, such as "correlation factor of synchronous variation of behavioral patterns", add corresponding rule sub-items, such as "When the behavioral patterns of two associated accounts show synchronous variation, increase the risk level", and set the applicable time range for the sub-item, such as applicable to all time periods throughout the year, or only applicable during periods of high fraud incidence.
[0118] For example, step S1431: parsing the conflict type and conflict degree identified in the conflict analysis result, combining the weight adaptation rules in the feature dimension system, and determining the historical rule items that need to be adjusted first and the adjustment priority order.
[0119] Analyze the conflict types identified in the conflict analysis results, such as feature item weight mismatch, overlapping rule application time ranges and opposite judgment logic, and evaluate the degree of conflict, such as the impact on risk control results and the frequency of occurrence.
[0120] Combined with the weight adaptation rules in the feature dimension system, historical rule entries that require prior adjustment are determined. Rule entries with higher conflict levels and greater deviations from the weight adaptation rules receive higher adjustment priority. For example, rule entries with overlapping applicable time ranges and contradictory decision logic, resulting in a large number of misjudgments, will receive higher adjustment priority than rule entries with only minor mismatches in feature item weights.
[0121] Step S1432: According to the adjustment priority order and based on the weight proportions of the dynamic feature items in the weight adaptation rules at different times, the judgment weight values of the corresponding dynamic feature items in the conflicting historical rule entries are adjusted proportionally.
[0122] The judgment weights of the corresponding dynamic feature items in the conflicting historical rule entries are adjusted proportionally, based on the weight proportions of each dynamic feature item in the weight adaptation rule at different times, in the order of adjustment priority. For example, if the weight proportion of the "Interaction Environment Feature Evolution Correlation Factor" in the weight adaptation rule is a certain proportion in the time period t13-t14, and the judgment weight proportion of the corresponding feature item in the historical rule is lower than this proportion, the judgment weight proportion will be increased proportionally to the corresponding value.
[0123] Step S1433: Identify the newly added dynamic feature items in the feature dimension system, construct corresponding judgment conditions for each newly added dynamic feature item, and generate rule sub-entries. The judgment conditions include the trigger threshold of the feature item, judgment logic, and the association relationship with other feature items.
[0124] Identify new dynamic feature items in the feature dimension system, such as the "cross-operation node correlation factor" and the "behavior pattern synchronization variation correlation factor." Construct corresponding judgment conditions for each new dynamic feature item. For example, for the "cross-operation node correlation factor," set the trigger threshold to trigger when one of the multi-dimensional values of the factor reaches a specific level. The judgment logic is "If triggered, indicate the risk of account collaborative fraud." Also clarify the relationship with the "interaction object overlap period correlation factor." For example, if both trigger simultaneously, the risk level increases. Generate rule sub-items based on these conditions.
[0125] Step S1434: according to the time range of influence of the newly added dynamic feature item in the fraud event evolution network, an applicable time interval is set for each rule sub-item, and the time interval is consistent with the time range of influence of the newly added dynamic feature item.
[0126] According to the time range of the influence of the newly added dynamic feature items in the fraud event evolution network, for example, the "behavioral pattern synchronous variation correlation factor" has a larger impact within one week after the fraud event occurs, and then gradually decreases, the applicable time interval of its corresponding rule sub-item is set to "within one week after the fraud event occurs" to ensure that this time interval is consistent with the influence range time of the newly added dynamic feature items.
[0127] Step S1435: Associating and binding the rule sub-item with the relevant historical rule item, determining the triggering timing and execution priority of the rule sub-item during the execution of the historical rule item, so that the rule sub-item and the historical rule item are executed in coordination in the time dimension.
[0128] Associate and bind the rule sub-entry with the relevant historical rule entry, such as binding the rule sub-entry corresponding to the "cross-operation node association factor" with the historical rule entry related to the "account abnormal transaction".
[0129] Determine when a rule sub-item should be triggered during the execution of a historical rule entry, such as triggering the rule sub-item when the historical rule entry reaches the "Detect Account Transaction Behavior" stage. Also set an execution priority, such as giving a rule sub-item a higher priority than some historical rule sub-items, to ensure that the two can execute together in time and avoid execution conflicts.
[0130] Step S1436: Check whether the adjusted judgment weights and newly added rule sub-items meet the overall time adaptation requirements of the weight adaptation rules, verify the coordination and consistency of the weights between the rule items at different time nodes, and if there is any inconsistency, readjust them until they meet the requirements.
[0131] Check whether the adjusted judgment weights and newly added rule sub-items meet the overall time adaptation requirements of the weight adaptation rules. For example, at different time nodes, whether the sum of the weight ratios of each dynamic feature item is reasonable, and whether there is a situation where the weight of a feature item is too high or too low, resulting in an overall imbalance.
[0132] Verify the coordination and consistency of the weights between rule items at different time points. For example, at time point t15, verify whether the weight of the rule item corresponding to the "Channel Type Conversion Correlation Factor" is coordinated with the weight of the rule item corresponding to the "Operation Instruction Time Sequence Change Correlation Factor" and whether they comply with the overall weight adaptation rules. If there is any inconsistency, readjust the weight values until they meet the requirements.
[0133] Step S144: Analyze the correlation between the dynamic feature items in the feature dimension system that changes over time, construct a dynamic feature item combination judgment condition, and integrate the dynamic feature item combination judgment condition into the rule judgment logic. The dynamic feature item combination judgment condition includes the feature item collaborative judgment logic at different time nodes.
[0134] Analyzing the temporal correlations between dynamic feature items in a feature dimension system requires tracking the numerical changes of each dynamic feature item at different time points and their mutual influence. For example, in an online loan fraud scenario, the "channel type conversion correlation factor" in the dynamic scenario feature factor and the "operation instruction time sequence change correlation factor" in the dynamic operation sequence feature factor are correlated in the temporal dimension. When the "channel type conversion correlation factor" increases in value within a certain time period, the value of the "operation instruction time sequence change correlation factor" also shows an upward trend, indicating that the two dynamic feature items have a positive correlation within that time period.
[0135] When constructing the judgment conditions for combining dynamic feature items, these relationships need to be comprehensively considered. For different time nodes, set the collaborative judgment logic for feature items. For example, at time node t16, when the value of the "channel type conversion correlation factor" reaches a certain range, the value of the "operation instruction time sequence change correlation factor" is also within the corresponding range, and the "state parameter dynamic change pattern correlation factor" meets specific conditions, it is determined that there is a fraud risk.
[0136] By integrating these dynamic feature item combination judgment conditions into the rule judgment logic, rule judgments not only consider the performance of a single dynamic feature item, but also integrate the performance of multiple related dynamic feature items at different time points, improving the accuracy and comprehensiveness of rule judgments. For example, the original rule judgment logic only made judgments based on the "channel type conversion correlation factor." After incorporating the combined judgment conditions, the relevant operation sequence feature factors can be combined to make a joint judgment, reducing the risk of misjudgment due to a single feature item.
[0137] Step S145: Perform multiple rounds of conflict detection on the adjusted rule judgment logic. After each round of detection, further optimize the rule items and sub-items based on the detection results until all conflicts are eliminated, generating an updated risk control model rule set with self-adaptive capabilities.
[0138] To conduct multiple rounds of conflict detection on the adjusted rule judgment logic, it is first necessary to set the conflict detection standards, such as different rule entries have different judgment thresholds for the same dynamic feature item at the same time node, the applicable time intervals between rule sub-entries overlap and the judgment results are opposite, etc.
[0139] In the first round of testing, all rule entries and sub-entries are traversed, comparing their decision logic for the same time node and the same dynamic feature item. For example, if rule entry A is detected to have a decision threshold for the "interaction environment feature evolution correlation factor" at time node t17 within a certain range, while rule sub-entry B has a decision threshold for the same factor within a different range at the same time node, and the two ranges overlap and the decision results are opposite, this is a conflict.
[0140] Based on the results of the first round of testing, optimize the conflicting rule entries and sub-entries, such as adjusting the decision threshold or applicable time range. After optimization, perform a second round of testing to check for new or unresolved conflicts.
[0141] After multiple rounds of the above detection and optimization, until there are no conflicts between all rule items and sub-items, the generated rule set has the ability to self-adapt and can make accurate judgments based on the changes in dynamic feature items at different time nodes and the correlation between them, that is, the updated risk control model rule set.
[0142] Step S150: Verify the validity of the updated risk control model rule set. After verification, deploy the updated risk control model rule set to the financial service risk control system, and simultaneously trigger the archiving of the original rule set and the real-time effectiveness of the new rules.
[0143] In online loan fraud scenarios, validating the updated risk control model rule set is a critical step in ensuring its ability to accurately identify fraudulent incidents. Once validated, it is deployed to the financial services risk control system, replacing the original rule set. The original rule set is also archived to ensure orderly rule management.
[0144] Step S151: Fraud event records from different historical periods, normal business records of different business types, and simulated new fraud event records are selected to form a verification data set, which contains event records from different time periods and different business scenarios than the fraud event log set.
[0145] We selected fraud records from different historical periods, including online loan fraud incidents that occurred over the past six months, a year, and other time periods. These records capture the characteristics of fraudulent methods employed during these periods. We also examined normal business records from various business types, including personal credit loans, mortgages, and consumer loans, with no evidence of fraudulent activity, to test the rule set's ability to misjudge normal business activity.
[0146] Simulated new fraud incident records are generated based on emerging fraud trends and tactics within the industry, such as simulated loan applications using artificial intelligence to generate false identity information. These records collectively form a validation dataset, ensuring diversity in time span and business scenarios, enabling comprehensive validation of the effectiveness of the updated risk control model rule set.
[0147] Step S152: Input the verification data set into the test system that applies the updated risk control model rule set in time segments, and obtain the fraud determination results output by the test system in different time segments. The fraud determination results include the determination type, dynamic feature items based on which the determination is made, and the determination timestamp.
[0148] Divide the validation dataset into multiple time periods in chronological order, such as one month as a time segment, and input the dataset of each time segment into the test system that applies the updated risk control model rule set.
[0149] The test system processes and determines the input data, outputting a fraud determination result. Determination types are categorized as "fraud risk present" or "fraud risk not present." Dynamic feature items used as the basis for determination refer to the dynamic feature items the system primarily considers during the determination process, such as the "channel type conversion correlation factor" and the "operation instruction time sequence change correlation factor." The determination timestamp indicates the specific time the system made the determination.
[0150] Step S153: Compare the fraud determination results of each time segment with the nature of the actual events in the verification data set, and calculate the determination accuracy, missed determination rate and false determination rate of the updated risk control model rule set in different time segments and different business scenarios.
[0151] The fraud determination results of each time segment are compared with the actual event nature recorded in the verification data set. The actual event nature is known, that is, it is clear whether the event is a fraud event or a normal event.
[0152] The statistical judgment accuracy rate refers to the proportion of the number of judgment results that are consistent with the nature of the actual event to the total number of judgments; the missed judgment rate refers to the proportion of the number of actual fraud events that are judged as "not having fraud risks" to the total number of actual fraud events; the misjudgment rate refers to the proportion of the number of actual normal events that are judged as "having fraud risks" to the total number of actual normal events.
[0153] The above statistics are conducted separately in different business scenarios, such as personal credit loan scenarios and mortgage loan scenarios, to fully understand the performance of the updated risk control model rule set in different business scenarios.
[0154] Step S154: If the judgment accuracy rate reaches the preset standard and the missed judgment rate and false judgment rate are both lower than the preset threshold in all time segments and business scenarios, it is determined that the updated risk control model rule set has passed the validity verification.
[0155] Preset standards and thresholds are set based on the risk control requirements and historical data of the financial services industry. For example, the preset standard for accuracy is no less than 95%, the preset threshold for missed detection rate is no more than 3%, and the preset threshold for false positive rate is no more than 2%.
[0156] Check whether the updated risk control model rule set achieves an accuracy rate of 95% or higher, a false positive rate of less than 3%, and a false positive rate of less than 2% across all time periods and business scenarios. If all these conditions are met, the rule set passes validation. If any time period or business scenario fails to meet these requirements, return and readjust the rule set until validation is passed.
[0157] Step S155: The updated risk control model rule set that has passed verification is transmitted to the financial service risk control system, so that the financial service risk control system triggers the archiving process of the original rule set, stores the original rule set in the historical rule library and marks the archiving time, and at the same time triggers the real-time effectiveness process of the new rules, updates the rule engine of the financial service risk control system, deploys and uses the updated risk control model rule set, and synchronously records the effective time and the initial operating status after the effective time.
[0158] The updated risk control model rule set that has passed validity verification is transmitted to the financial services risk control system. After receiving the rule set, the financial services risk control system initiates the archiving process for the original rule set, transferring the original rule set from the active rule base to the historical rule base for storage, and marking the specific archiving time in the storage record, such as year, month, day, hour, minute, and second.
[0159] At the same time, the real-time effectiveness process of the new rules is triggered, the rule engine of the financial services risk control system is updated, and the updated risk control model rule set is loaded into the rule engine to replace the original rule set, so that it can be deployed and used in the actual risk control of online loan business.
[0160] Synchronously record the effective time of the new rule and the initial operating status after it takes effect, such as the response time of the rule engine and the output of the judgment results, so as to monitor and evaluate the operation of the new rule later.
[0161] Figure 2 A risk control model updating system 100 for financial service fraud events provided in an embodiment of the present application is shown, including a processor 1001, a memory 1003 and a program code stored on the memory 1003. The processor 1001 executes the above program code to implement the steps of the risk control model updating method for financial service fraud events.
[0162] Figure 2 The risk control model update system 100 for financial services fraud events shown includes: a processor 1001 and a memory 1003. The processor 1001 and the memory 1003 are connected, such as through a bus 1002. Optionally, the risk control model update system 100 for financial services fraud events may also include a transceiver 1004. The transceiver 1004 may be used for data interaction between the risk control model update system for financial services fraud events and other risk control model update systems for financial services fraud events, such as data sending and / or data receiving. It should be noted that in actual scheduling, the transceiver 1004 is not limited to one, and the structure of the risk control model update system 100 for financial services fraud events does not constitute a limitation on the embodiments of the present application.
[0163] The memory 1003 is used to store program codes for executing the embodiments of the present application, and the execution is controlled by the processor 1001. The processor 1001 is used to execute the program codes stored in the memory 1003 to implement the steps shown in the above method embodiments.
[0164] An embodiment of the present application provides a computer-readable storage medium having program code stored thereon. When the program code is executed by a processor, the steps and corresponding contents of the aforementioned method embodiment can be implemented.
[0165] It should be understood that, although each operation step is indicated by arrows in the flow chart of the embodiment of the present application, the order of implementation of these steps is not limited to the order indicated by the arrows. Unless otherwise clearly stated herein, in some implementation scenarios of the embodiment of the present application, the implementation steps in each flow chart can be performed in other orders based on demand. In addition, some or all of the steps in each flow chart can include multiple sub-steps or multiple stages according to actual implementation scenario, and some or all of these sub-steps or stages can be executed at the same time, and each sub-step or stage in these sub-steps or stages can also be executed at different times respectively. Under different scenarios at the execution time, the order of execution of these sub-steps or stages can be flexibly configured based on demand, and the embodiment of the present application does not limit this.
[0166] The above is only an optional implementation method for some implementation scenarios of this application. It should be pointed out that for ordinary technicians in this technical field, without departing from the technical concept of the solution of this application, other similar implementation methods based on the technical ideas of this application also fall within the protection scope of the embodiments of this application.
Claims
1. A method for updating a risk control model for financial service fraud incidents, characterized in that: The method comprises: Obtain a set of fraud event logs generated in real time during the financial service process, which includes real-time scenario evolution information of multiple fraud events, dynamic business operation chains, and behavioral trajectory changes of associated accounts; Constructing a fraud event evolution network with temporal correlation based on the fraud event log set. The fraud event evolution network is used to present the interactive influence relationship between the scene evolution correlation, operation chain similarity, and account behavior trajectory changes of different fraud events in the time dimension; A feature dimension system of a risk control model dynamically adapted to the fraud event evolution network, wherein the feature dimension system includes dynamic feature items corresponding to each temporal correlation relationship in the fraud event evolution network and weight adaptation rules between feature items that change over time; Based on the conflict analysis results of the feature dimension system and historical risk control rules, iteratively adjust the rule judgment logic of the risk control model to generate an updated risk control model rule set with self-adaptive capabilities; The updated risk control model rule set is validated, and after verification, the updated risk control model rule set is deployed to the financial service risk control system, synchronously triggering the archiving of the original rule set and the real-time effectiveness process of the new rules.
2. The method for updating the risk control model for financial service fraud events according to claim 1, characterized in that: The fraud event log set generated in real time during the acquisition of financial services includes: Receive the initial fraud event log pushed in real time by the financial service system when a fraud event is monitored. The initial fraud event log includes a dynamic identifier of the business type, account identifier, and operation sequence chain during the occurrence and development of the event; Extracting real-time scenario evolution information from the initial log of the fraud event, tracking changes in business attributes, dynamic adjustments to environmental attributes, and switching of interactive channels in the scenario where the fraud event occurred, and generating real-time scenario evolution information; Parsing the operation sequence chain in the initial log of the fraud event, extracting the continuous business operation instruction sequence over time, the dynamic changes in the state parameters of each operation instruction, and the operation interruption and recovery nodes, to generate a dynamic business operation chain; Retrieving all business interaction records of the account before and after the fraud incident based on the account identifier, screening out interaction behavior data change fragments related to the development process of the fraud incident, and generating behavioral trajectory changes of the associated account; The real-time scenario evolution information, dynamic business operation chain and behavioral trajectory changes of associated accounts are stored in a time-series correlation manner to form a fraud event log set.
3. The risk control model updating method for financial service fraud events according to claim 1, characterized in that: The step of constructing a fraud event evolution network with temporal association based on the fraud event log set includes: Extracting key scenario evolution elements from the real-time scenario evolution information of each fraud event from the fraud event log collection, wherein the key scenario evolution elements include core business type changes in business attribute changes, evolution of interactive environment characteristics in dynamic adjustment of environmental attributes, and channel type conversion in the process of interactive channel switching; Compare key scenario evolution factors of different fraud incidents within the same time period, calculate the dynamic overlap of the scenario evolution factors, and determine the scenario evolution correlation between different fraud incidents based on the changing trend of the dynamic overlap over time; Performing a time sequence pattern comparison on the dynamic business operation chain of each fraud event in the fraud event log set, extracting the similarity patterns of the temporal sequence changes of the operation instruction sequence, the dynamic changes of the state parameters, and the synchronization of the operation interruption and recovery nodes, and calculating the time sequence pattern matching degree between different dynamic business operation chains as the operation chain similarity; Analyze the behavioral trajectory changes of the associated accounts in the fraud event log set, identify the cross-operation nodes of different account behavioral trajectories on the time axis, the overlapping periods of interaction objects, and the synchronous variation points of behavior patterns, and determine the interactive impact relationship of the account behavior trajectory changes; Based on the fraud event nodes containing timestamps, and with the interactive influence relationships of scenario evolution correlation, operation chain similarity, and account behavior trajectory changes as edges with temporal weights, a fraud event evolution network with temporal correlation is constructed.
4. The method for updating the risk control model for financial service fraud events according to claim 1, characterized in that: The characteristic dimension system of the risk control model dynamically adapted to the network evolution according to the fraud event includes: Analyzing the scenario evolution correlation in the fraud event evolution network and extracting dynamic scenario characteristic factors corresponding to the scenario evolution correlation, wherein the dynamic scenario characteristic factors include a core business type change correlation factor, an interactive environment feature evolution correlation factor, and a channel type conversion correlation factor; Generate dynamic operation sequence characteristic factors based on the similarity of the operation chains in the fraud event evolution network. The dynamic operation sequence characteristic factors include a correlation factor of the temporal sequence change of operation instructions, a correlation factor of the dynamic change law of state parameters, and a correlation factor of the synchronization of operation interruption and recovery; Determining dynamic account behavior characteristic factors based on the interactive influence relationship of account behavior trajectory changes in the fraud event evolution network, wherein the dynamic account behavior characteristic factors include a cross-operation node correlation factor, an interactive object overlapping period correlation factor, and a behavior pattern synchronous variation correlation factor; The dynamic scenario characteristic factors, dynamic operation sequence characteristic factors and dynamic account behavior characteristic factors are used as dynamic feature items to construct the initial dynamic feature dimension system; Track the expansion or contraction trend of the influence range and fluctuation of the correlation strength of each dynamic feature item in the fraud event evolution network over time, construct weight adaptation rules that are dynamically adjusted between each dynamic feature item over time, and generate a feature dimension system of the risk control model after dynamic adaptation.
5. The method for updating the risk control model for financial service fraud events according to claim 4, characterized in that: The analyzing the scene evolution correlation in the fraud event evolution network and extracting the dynamic scene feature factors corresponding to the scene evolution correlation include: Traversing all edges with time-series weights that represent scenario evolution relevance in the fraud event evolution network in chronological order, and recording the core business type change process of the two fraud events corresponding to each edge at different time nodes; Counting the time frequency distribution of the same core business type change process combination appearing in the scenario evolution correlation edge, calculating the temporal correlation degree between the core business type changes based on the time frequency distribution, and generating the core business type change correlation factor; Extract the evolution process of the interactive environment features corresponding to the scenario evolution correlation edge, compare the evolution trajectories of similar attributes of the interactive environment features of different fraud events within the same time interval, calculate the change curve of the overlap ratio of similar attribute evolution trajectories over time, and determine the correlation factor of the interactive environment feature evolution based on this change curve; Collect the channel type conversion processes involved in the scenario evolution correlation edges, analyze the temporal co-occurrence windows of different channel type conversions in the associated fraud events, and generate a channel type conversion correlation factor based on the duration and frequency of the temporal co-occurrence windows; The core business type change correlation factors, interactive environment feature evolution correlation factors and channel type conversion correlation factors are integrated into dynamic scenario feature factors.
6. The method for updating the risk control model for financial service fraud events according to claim 4, characterized in that: The generating of a dynamic operation sequence characteristic factor based on the similarity of the operation chain in the fraud event evolution network includes: For the edges with time series weights corresponding to the similarity of the operation chains in the fraud event evolution network, the dynamic business operation chains of the two fraud events connected by the edges in different time segments are extracted; Compare the time sequence changes of operation instructions in two dynamic business operation chains, identify operation instruction segments with the same time sequence change pattern, calculate the time proportion of the operation instruction segment in the two dynamic business operation chains, and generate the operation instruction time sequence change correlation factor based on the change trend of the time proportion; Analyze the dynamic changes of state parameters corresponding to each operation instruction in the dynamic business operation chain, extract the dynamic regularity characteristics of the state parameters, calculate the fluctuation value of the degree of consistency of the dynamic regularity of the state parameters in the two dynamic business operation chains over time, and determine the correlation factor of the dynamic change regularity of the state parameters based on the fluctuation value; Identify the operation interruption and recovery nodes in the dynamic business operation chain, compare the time synchronization of the operation interruption and recovery nodes of different fraud events, calculate the time deviation value distribution of synchronization, and generate the operation interruption and recovery synchronization correlation factor based on the time deviation value distribution of synchronization; The correlation factors of the time sequence changes of operation instructions, the correlation factors of the dynamic change rules of state parameters and the correlation factors of the synchronization of operation interruption and recovery are integrated into the dynamic operation sequence characteristic factors.
7. The method for updating the risk control model for financial service fraud events according to claim 4, characterized in that: Determining the dynamic account behavior characteristic factors based on the interactive influence relationship of the account behavior trajectory changes in the fraud event evolution network includes: Analyzing the edges in the fraud event evolution network that represent the interactive influence relationship between changes in account behavior trajectories, and extracting the cross-operation nodes on the time axis of different account behavior trajectories involved in the edges; Count the frequency and duration of occurrence of cross-operation nodes in the same business scenario, calculate the degree of behavioral coordination of different accounts at the cross-operation nodes, and generate a cross-operation node correlation factor based on the degree of behavioral coordination; Tracking the interaction objects corresponding to the interactive impact relationships of changes in account behavior trajectories, determining the temporal overlap of interaction objects of different accounts, calculating the proportion of the overlapping period in the entire event duration and the interaction frequency within the overlapping period, and generating an interaction object overlapping period correlation factor based on the proportion and interaction frequency; Analyze the behavioral pattern variation points in the account behavior trajectory changes, identify the time synchronization of the behavioral pattern variation points of different accounts and the similarity of the variation trends, calculate the synchronization deviation value and the trend similarity coefficient, and generate the behavioral pattern synchronization variation correlation factor based on the synchronization deviation value and the trend similarity coefficient; The cross-operation node correlation factor, the interaction object overlapping period correlation factor and the behavior pattern synchronous variation correlation factor are integrated into the dynamic account behavior characteristic factor.
8. The method for updating the risk control model for financial service fraud events according to claim 1, characterized in that: The conflict analysis results based on the feature dimension system and historical risk control rules are used to iteratively adjust the rule judgment logic of the risk control model to generate an updated risk control model rule set with self-adaptive capabilities, including: Retrieving the original historical rule judgment logic of the risk control model, and analyzing the rule entries and rule applicable time range corresponding to the dynamic feature items of the feature dimension system in the historical rule judgment logic; Perform matching analysis on dynamic feature items and historical rule entries in the feature dimension system, identify conflicting rule contents, and generate conflict analysis results. The conflict situations include feature item weight mismatch, overlapping rule application time ranges, and opposite judgment logic. Based on the conflict analysis results and the weight adaptation rules in the feature dimension system, the judgment weights of the dynamic feature items in the conflicting historical rule items are adjusted first, and the rule sub-items corresponding to the newly added dynamic feature items and the applicable time intervals of the sub-items are added; Analyze the temporal correlation between dynamic feature items in the feature dimension system, construct a dynamic feature item combination determination condition, and integrate the dynamic feature item combination determination condition into the rule determination logic. The dynamic feature item combination determination condition includes the feature item collaborative determination logic at different time nodes. Perform multiple rounds of conflict detection on the adjusted rule judgment logic. After each round of detection, further optimize the rule items and sub-items based on the detection results until all conflicts are eliminated, generating an updated risk control model rule set with self-adaptive capabilities.
9. The method for updating the risk control model for financial service fraud events according to claim 1, characterized in that: The validity verification of the updated risk control model rule set is performed, and after passing the verification, the updated risk control model rule set is deployed to the financial service risk control system, and the archiving of the original rule set and the real-time effectiveness of the new rule set are simultaneously triggered, including: Fraud event records from different historical periods, normal business records from different business types, and simulated new fraud event records are selected to form a validation dataset. The validation dataset contains event records from different time periods and business scenarios than the fraud event log set. Input the validation dataset into a test system that applies the updated risk control model rule set in time segments, and obtain fraud determination results output by the test system at different time segments. The fraud determination results include the determination type, dynamic feature items used as the determination basis, and the determination timestamp; Compare the fraud determination results for each time segment with the nature of actual events in the validation dataset, and calculate the accuracy, missed detection rate, and false positive rate of the updated risk control model rule set in different time segments and business scenarios; If the judgment accuracy rate reaches the preset standard and the missed judgment rate and false judgment rate are both lower than the preset threshold in all time segments and business scenarios, the updated risk control model rule set is judged to have passed the validity verification; The verified updated risk control model rule set is transmitted to the financial service risk control system, so that the financial service risk control system triggers the archiving process of the original rule set, stores the original rule set in the historical rule library and marks the archiving time, and at the same time triggers the real-time effectiveness process of the new rules, updates the rule engine of the financial service risk control system, deploys and uses the updated risk control model rule set, and synchronously records the effective time and the initial operating status after the effective time.
10. A risk control model update system for financial service fraud incidents, characterized in that: It includes a processor and a computer-readable storage medium, wherein the computer-readable storage medium stores machine-executable instructions, and when the machine-executable instructions are executed by the processor, the method for updating the risk control model for financial service fraud events described in any one of claims 1 to 9 is implemented.
Citation Information
Cited By
Supply chain financial fraud behavior identification method and system for multi-source data
CN121836900A
Supply chain finance fraud behavior identification method and system for multi-source data
CN121836900B