Method, device and equipment for fraud analysis using a fraud analysis model
Patent Information
- Application Number
- CN202511165296.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-19
- Publication Date
- 2026-09-25
- Estimated Expiration
- 2045-08-19
AI Technical Summary
[0003]目前,通常是基于单一维度的数据分析,例如交易金额异常检测,或者,静态规则库匹配,对用户租赁物品行为数据进行欺诈分析,无法快速且准确识别欺诈行为,尤其不适用于欺诈组织的欺诈行为场景
本发明实施例中,获取多个用户在目标时间段内,如一周内,针对所租赁/购买物品/服务产生的多个维度数据,如用户社交数据、对象交易数据、进行对象交易时所使用的交易设备的设备共享数据,并提取对应维度数据的数据特征,再基于提取出的多维度的数据特征,构建用户群对应的交易图谱,从而基于交易图谱,对用户的行为进行欺诈风险分析,得到欺诈行为分析结果,提高了欺诈行为检测的准确性与效率,以提高物品的充分利用率,以及实现了对跨账号欺诈组织的欺诈行为的高效、精准识别。
Smart Images

Figure CN120910472B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of fraud behavior analysis technology, and in particular to a method, apparatus, and equipment for fraud behavior analysis using a fraud analysis model. Background Technology
[0002] Given the advantages of item rental, such as low asset intensity, low cost, and adaptability to diverse needs, more and more users prefer to rent items to meet their usage requirements. However, as rental business scenarios become more complex, item rental fraud has also emerged, leading to the inability to fully utilize the rental items and harming the interests of lessors. Therefore, it is essential to conduct fraud analysis on users' item rental behavior.
[0003] Currently, data analysis is typically based on a single dimension, such as detecting anomalies in transaction amounts, or matching static rule bases to perform fraud analysis on user rental behavior data. This approach cannot quickly and accurately identify fraudulent behavior, and is particularly unsuitable for scenarios involving organized fraud. Therefore, technical solutions that improve the accuracy and efficiency of fraud detection to enhance the full utilization of rental items are of paramount importance. Summary of the Invention
[0004] This invention provides a method, apparatus, and equipment for analyzing fraudulent behavior using a fraud analysis model, which can improve the accuracy and efficiency of fraud detection, thereby increasing the full utilization rate of goods.
[0005] To address the aforementioned technical problems, a first aspect of the present invention discloses a method for analyzing fraudulent behavior using a fraud analysis model, the method comprising: Acquire multi-dimensional data of a user group for the transaction object within a target time period. The user group consists of multiple users, and all the multi-dimensional data corresponding to the user group include at least two of the following: user social data of all users in the user group, object transaction data of all users in the user group, and device sharing data of the transaction devices used by all users in the user group for object transactions. For any of the stated dimension data, extract the data features of the stated dimension data, and construct the transaction graph corresponding to the user group based on the data features of all the stated dimension data; Fraud behavior analysis is performed on the transaction graph corresponding to the user group to obtain the fraud behavior analysis results corresponding to the user group.
[0006] A second aspect of this invention discloses an apparatus for analyzing fraudulent behavior using a fraud analysis model, the apparatus comprising: The acquisition module is used to acquire multiple dimensions of data generated by a user group for the transaction object within a target time period. The user group consists of multiple users, and all the dimensions of data corresponding to the user group include at least two of the following: user social data of all users in the user group, object transaction data of all users in the user group, and device-shared data of the transaction devices used by all users in the user group to conduct object transactions. The extraction module is used to extract the data features of any of the said dimensional data; A construction module is used to construct a transaction graph corresponding to the user group based on the data characteristics of all the dimensions of data. The analysis module is used to perform fraud behavior analysis on the transaction graph corresponding to the user group and obtain the fraud behavior analysis results corresponding to the user group.
[0007] A third aspect of the present invention discloses a fraud detection device, the fraud detection device comprising: Memory containing executable program code; A processor coupled to the memory; The processor calls the executable program code stored in the memory to execute some or all of the steps in any of the methods for fraud behavior analysis using fraud analysis models disclosed in the first aspect of the present invention.
[0008] The fourth aspect of the present invention discloses a computer storage medium storing computer instructions, which, when invoked, are used to execute some or all of the steps in any of the methods for fraud behavior analysis using a fraud analysis model disclosed in the first aspect of the present invention.
[0009] Compared with the prior art, the embodiments of the present invention have the following beneficial effects: In this embodiment of the invention, multiple dimensions of data generated by multiple users within a target time period, such as a week, regarding the rented / purchased items / services are acquired. These data include user social data, object transaction data, and device sharing data of the transaction devices used during object transactions. Data features of the corresponding dimensions are extracted, and a transaction graph corresponding to the user group is constructed based on the extracted multi-dimensional data features. Based on the transaction graph, fraud risk analysis is performed on user behavior to obtain fraud behavior analysis results, thereby improving the accuracy and efficiency of fraud behavior detection, increasing the full utilization rate of items, and achieving efficient and accurate identification of fraud behavior by cross-account fraud organizations. Attached Figure Description
[0010] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0011] Figure 1 This is a flowchart illustrating a method for analyzing fraudulent behavior using a fraud analysis model, as disclosed in an embodiment of the present invention. Figure 2 This is a flowchart illustrating another method for analyzing fraudulent behavior using a fraud analysis model, as disclosed in an embodiment of the present invention. Figure 3 This is a schematic diagram of the structure of a device for analyzing fraudulent behavior using a fraud analysis model, as disclosed in an embodiment of the present invention. Figure 4 This is a schematic diagram of another device for analyzing fraudulent behavior using a fraud analysis model, as disclosed in an embodiment of the present invention. Figure 5 This is a schematic diagram of the structure of a fraud detection device disclosed in an embodiment of the present invention. Detailed Implementation
[0012] To enable those skilled in the art to better understand the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0013] The terms "first," "second," etc., used in the specification, claims, and accompanying drawings of this invention are used to distinguish different objects, not to describe a specific order. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion. For example, a process, method, apparatus, product, or device that includes a series of steps or units is not limited to the listed steps or units, but may optionally include steps or units not listed, or may optionally include other steps or units inherent to these processes, methods, products, or devices.
[0014] In this document, the term "embodiment" means that a particular feature, structure, or characteristic described in connection with an embodiment may be included in at least one embodiment of the invention. The appearance of this phrase in various places throughout the specification does not necessarily refer to the same embodiment, nor is it a separate or alternative embodiment mutually exclusive with other embodiments. It will be explicitly and implicitly understood by those skilled in the art that the embodiments described herein can be combined with other embodiments.
[0015] This invention discloses a method, apparatus, and device for fraud behavior analysis using a fraud analysis model. It acquires multi-dimensional data from multiple users within a target time period, such as a week, regarding rented / purchased goods / services. This data includes user social data, transaction data, and device-shared data of the transaction devices used during transactions. Data features of the corresponding dimensions are extracted, and a transaction graph corresponding to the user group is constructed based on these extracted multi-dimensional data features. Based on this transaction graph, fraud risk analysis is performed on user behavior, yielding fraud behavior analysis results. This improves the accuracy and efficiency of fraud behavior detection, thereby increasing the full utilization of goods and achieving efficient and accurate identification of fraudulent activities by cross-account fraud organizations. Detailed explanations follow.
[0016] Example 1 Please see Figure 1 , Figure 1 This is a flowchart illustrating a method for fraud behavior analysis using a fraud analysis model, as disclosed in an embodiment of the present invention. This method can be applied to any scenario requiring fraud behavior analysis, such as a goods rental scenario, provided that the scenario has a corresponding device. This device includes one of the following: a fraud detection device, a fraud detection system (local system or cloud system), and a fraud detection server (local server or cloud server). Figure 1 As shown, the method may include the following operations: 101. Obtain multi-dimensional data on the transaction objects generated by the user group within the target time period.
[0017] In this embodiment of the invention, the transaction object can be understood as a tangible item and / or a non-tangible service. Terms such as leasing, renting, and purchasing, which imply interaction between two parties, can all be understood as transactions.
[0018] In this embodiment of the invention, optionally, the target time period can be uniformly preset, such as one week, or it can be dynamically determined according to the analysis needs. For example, the target time period for type A items can be one week, and the target time period for type A items can be one month. Optionally, the user group consists of multiple users, and all dimension data corresponding to the user group include at least two of the following: user social data of all users in the user group, object transaction data of all users in the user group, and device-shared data of the transaction devices used by all users in the user group for object transactions.
[0019] In this embodiment of the invention, optionally, the user social data corresponding to the user group includes the friend relationships between all users in the user group, the interaction data between all users, the data of the community to which each user belongs, and the user's activity data in the community. For example, the more times a user speaks in the group, the more active they are. The interaction data between all users includes the number of interactions and / or the interaction time period and / or the interaction duration, and the data of the community to which each user belongs includes the number of people in the community and / or the type of community (such as work group, life group, social group).
[0020] In this embodiment of the invention, optionally, the object transaction data of all users in the user group includes the transaction account identifier and payment method identifier of all users in the user group for the transaction object. The payment method identifier includes bank card identifier and / or third-party payment account identifier and / or mobile payment identifier, such as Alipay account identifier, WeChat Pay account identifier, etc.
[0021] In this embodiment of the invention, optionally, the transaction data corresponding to the user group further includes the transaction time of all users in the user group for the transacted object, and / or the transaction data of all users in the user group for the transacted object. Optionally, the transaction data corresponding to the user group includes the number of transactions for each user in the user group for the transacted object, the time of each transaction, and the time of each refund. Optionally, the transaction data corresponding to the user group also includes the object identifier and / or type and / or transaction period for the transacted object, such as a one-month rental. Optionally, the transaction data corresponding to the user group also includes the transaction amount and / or refund amount.
[0022] In this embodiment of the invention, optionally, the device-shared data corresponding to the user group includes the device identifier of the transaction device (such as mobile phone, computer, etc.) used by all users in the user group, the IP login address of each user when logging into the transaction account, the login time of each user when logging into the transaction account, and the geographical location of each user when logging into the transaction account.
[0023] The more content each dimension of data contains, the more effective it is in improving the accuracy of data feature extraction, thereby further improving the accuracy and reliability of transaction image construction, and ultimately further improving the accuracy and reliability of fraud detection.
[0024] 102. For any dimension of data, extract the data features of the dimension data, and construct the transaction graph corresponding to the user group based on the data features of all dimensions of data.
[0025] In this embodiment of the invention, optionally, before executing step 102, for any dimension of data, invalid data cleaning operation and / or data format standardization operation can be performed on the dimension of data.
[0026] Optionally, invalid data cleaning operations specifically include missing value cleaning and / or outlier cleaning. Missing value cleaning specifically involves using scripts or tools (such as Python's pandas library) to scan for null values (such as NaN or empty strings) in the data for that dimension. If the missing field is minor information or does not affect fraud analysis, the data is directly deleted, such as user notes. If the field is critical (such as the ID of a transaction device) but the missing rate is low (e.g., <3%), a default value (e.g., unknown) is filled in. If the missing rate is high (e.g., >3%), the data is retained and marked "pending verification" for subsequent review, such as manual review. Outlier cleaning specifically involves processing the value according to its input method if the verified value is outside the preset range, such as ensuring the amount is not negative or exceeds a reasonable range (e.g., rental amount > 90,000,000 yuan). If the outlier is caused by an input error (e.g., entering an extra zero), it is corrected to a reasonable value. If it cannot be corrected, the data or its value is deleted.
[0027] Optionally, the standardized data format processing operations specifically include timestamp format processing operations and / or device identification encoding operations for trading devices. The timestamp format processing operation specifically includes converting the timestamps of the data in this dimension to a unified time zone, such as UTC, and converting them to a unified format, such as YYYY-MM-DD HH:MM:SS. Any algorithm capable of achieving time standardization can be used. The device identification encoding operation for trading devices specifically includes removing special characters and unifying them to a combination of uppercase letters and numbers of fixed length.
[0028] 103. Conduct fraud behavior analysis on the transaction risk map corresponding to the user group to obtain the fraud behavior analysis results corresponding to the user group.
[0029] It is evident that implementation Figure 1The described method acquires multi-dimensional data from multiple users within a target time period, such as a week, regarding the items / services they rent / purchase. This data includes user social data, transaction data, and device sharing data of the transaction devices used during the transaction. Data features of these corresponding dimensions are extracted, and a transaction graph corresponding to the user group is constructed based on these extracted multi-dimensional data features. Based on this transaction graph, fraud risk analysis is performed on user behavior, resulting in improved accuracy and efficiency in fraud detection. This enhances the full utilization of goods and enables efficient and accurate identification of fraudulent activities by cross-account fraud organizations.
[0030] In this embodiment of the invention, optionally, for any dimension of data, extracting the data features of the dimension data includes: When the dimensional data consists of user social data corresponding to a user group, the social characteristics of each user in the user group are analyzed based on this data. Each user's social characteristics include social degree centrality and / or social betweenness centrality. A higher value for a user's social degree centrality indicates more direct interaction with other users within the user group, meaning they are more likely to be a key node in information dissemination and thus have greater direct influence. Conversely, a higher value for a user's social betweenness centrality indicates a greater likelihood that their user group is a fraudulent organization.
[0031] When the dimension data is transaction data corresponding to a user group, the transaction characteristics of all users in the user group for the transacted object are determined based on the transaction data corresponding to the user group. These transaction characteristics include the transaction frequency and all payment methods for all users in the user group for the transacted object. Optionally, the transaction frequency for each transacted object includes the transaction frequency of each user for that transacted object and the transaction frequency of all users in the user group for that transacted object; all payment methods for each transacted object include all payment methods of each user for that transacted object and all payment methods of all users in the user group for that transacted object. Payment methods include bank payment methods and / or third-party account payment methods, such as Alipay and WeChat Pay.
[0032] When the dimensional data is device-shared data corresponding to a user group, the device-shared characteristics of the transaction devices used by all users in the user group for object transactions are identified based on the device-shared data corresponding to the user group. These device-shared characteristics include the number of accounts logging in through the same transaction device and the overlapping time periods for each transaction account using the same transaction device. Optionally, for the overlapping time periods of the same transaction device, for example, if user A uses mobile phone 123 from 10:00 to 11:00 on December 23, 2024, and user B uses mobile phone 123 from 10:20 to 11:00 on December 23, 2024, then the overlapping time period for mobile phone 123 is December 23, 2024, 10:20 to 11:00.
[0033] As can be seen, the embodiments of the present invention can also perform specific analysis on the specific content of data in different dimensions separately to obtain the data features of the corresponding dimensions, thereby improving the accuracy and reliability of data feature analysis and thus improving the accuracy and reliability of transaction image construction.
[0034] In this embodiment of the invention, optionally, the social characteristics of each user in the user group are analyzed based on the user social data corresponding to the user group, including: For any user in the user group, based on the user's social data, analyze the number of all users in the user group who directly interact with the user, and determine the user's social centrality feature based on the number of users corresponding to the user and the total number of users in the user group; and / or Based on the user's social data, analyze all one-way interaction paths in the user group; for any user in the user group, determine all one-way paths passing through that user based on all one-way interaction paths, and determine the user's social betweenness center characteristics based on the number of all one-way paths corresponding to that user and the number of all one-way interaction paths in the user group.
[0035] In this embodiment of the invention, direct interaction can be understood as the ability to communicate directly, such as through WeChat voice or text communication. The more users a user has, the higher the value of their social centrality feature.
[0036] In this embodiment of the invention, a one-way interaction path is understood as each user interacting with other users in only one direction / arrow. The more one-way paths a user has, the higher the value of their social betweenness center feature.
[0037] As can be seen, for each user, the embodiments of the present invention can also analyze the number of users who directly interact with the user group and the number of paths that must pass through the user for the interaction between users in the user group, so as to obtain the social degree center feature and the social betweenness center feature, and can realize the accurate analysis of the influence of the corresponding user in the group.
[0038] In this embodiment of the invention, optionally, a transaction graph corresponding to a user group is constructed based on the data characteristics of all dimensions of data, including: Based on the data characteristics of all dimensions, identify all first sub-user groups in the user group that have related relationships. The relationships include at least two of the following: social relationships, transaction relationships, and device sharing relationships. Each first sub-user group consists of multiple users in the user group. For any association relationship of any first sub-user group, determine the initial weight of the first sub-user group for the association relationship, and perform an update operation on the initial weight of the association relationship based on the data characteristics of the first sub-user group for the association relationship to obtain the target weight of the updated association relationship. Based on the target weights of all relationships within all first sub-user groups, construct the transaction graph corresponding to each user group.
[0039] In this embodiment of the invention, optionally, the target weight of all relationships in each first sub-user group includes at least two of the following: social association weight, transaction association weight, and device sharing association weight.
[0040] In this embodiment of the invention, optionally, a pre-existing basic transaction graph of the user group is used. This transaction graph is constructed by using all users in the user group as nodes and the relationships between users as edges. The more interactions between users, the higher the weight of the corresponding relationship, and the greater the weight of its edge.
[0041] In this embodiment of the invention, optionally, the weight (initial weight or target weight) of any association relationship for each first sub-user group is determined in the following way: Obtain the number of associations and the duration of associations between users in the first sub-user group; Based on the number of associations, the preset maximum number of associations, and the preset number of association weight coefficients, the association number weight corresponding to the first sub-user group is determined. Based on the association duration, the preset maximum association duration, and the preset time weight coefficient, the association duration weight corresponding to the first sub-user group is determined. The weight of any association relationship in the first sub-user group is determined based on the association frequency weight and association duration weight corresponding to the first sub-user group.
[0042] In this embodiment of the invention, optionally, for social association relationships, the number of associations and the duration of association can be understood as the number of direct social interactions and the duration of direct interactions; for transaction association relationships, the number of associations and the duration of association can be understood as the number of transactions and the duration of transactions for the same transaction object; for device sharing association relationships, the number of associations and the duration of association can be understood as the number of device sharing interactions and the duration of device sharing.
[0043] In this embodiment of the invention, to make the weight update clearer to those skilled in the art, the device sharing relationship is used as an example for illustration. Assume user A and user B share the same mobile phone, with an initial sharing association count of 4 times and a total duration of 600 minutes. The preset maximum sharing association count and preset maximum sharing association duration are 15 times and 1500 minutes respectively, and the preset count weight coefficient and time weight coefficient are 0.7 and 0.3 respectively. Then the initial weight is: W AB =0.7×4 / 15+0.3×600 / 1500=0.187+0.12=0.307. If user A continues to use the phone for 120 minutes, the target weight is: W AB =0.7×5 / 15+0.3×720 / 1500=0.233+0.144=0.377, which is greater than 0.307. Therefore, the weight of the device sharing relationship between user A and user B is increased.
[0044] In this embodiment of the invention, optionally, the target weight of the association relationship is compared with multiple preset weights of the association relationship. If the target weight is greater than a first preset weight, it indicates that the first sub-user group has a high fraud risk; if the target weight is greater than a second preset weight and less than the first preset weight, it indicates that the first sub-user group has a medium fraud risk; and if the target weight is less than the second preset weight, it indicates that the first sub-user group has a low fraud risk. The first preset weight is less than the second preset weight, such as 0.5 or 0.3. When the first sub-user group corresponds to either medium or high fraud risk, it is marked with a risk flag, and the corresponding data feature is updated.
[0045] In this embodiment of the invention, optionally, the number of associations or the duration of association corresponding to any association relationship can also be determined based on the association decay factor, the time of each association, and the current time. Specifically: Calculate the time interval between the current time and each associated time, and determine the attenuation value corresponding to each associated time based on the time interval and the attenuation factor corresponding to each associated time. Determine the number of associations based on the attenuation values corresponding to all associated times. Based on the decay value corresponding to each association time and the current time, determine the time decay value corresponding to each association time, and determine the association duration based on the time decay values corresponding to all association times.
[0046] As can be seen, the embodiments of the present invention can also dynamically construct a transaction graph based on the dynamic changes in the association duration and number of associations among multiple users with related relationships in a group, thereby improving the accuracy and reliability of the dynamic construction of the transaction graph, which is conducive to improving the accuracy and reliability of timely identification of fraudulent behavior.
[0047] In this embodiment of the invention, optionally, for any first sub-user group, it is determined whether there are users in the first sub-user group who have made abnormal refunds. When it is determined that there are users who have made abnormal refunds, the abnormal refund situation of the users in the first sub-user group who have made abnormal refunds is obtained, and an abnormal behavior coefficient corresponding to the first sub-user group is generated based on the abnormal refund situation of the first sub-user group. Based on the abnormal behavior coefficient corresponding to the first sub-user group, an adjustment operation is performed on the target weight corresponding to the first sub-user group.
[0048] In this embodiment of the invention, optionally, regarding abnormal refunds, please refer to the relevant description of abnormal refund frequency in this embodiment of the invention, which will not be repeated here. Optionally, the abnormal refund situation of a user includes multiple attributes of the object being refunded, such as refund time, transaction time, refund amount, refund location, number of refunds, and transaction location. The attribute data of the object includes, but is not limited to, multiple attributes such as object type, identifier, function, color, size, texture, shape, and level. A higher level indicates a higher importance of the object and / or a higher level of popularity. Correspondingly, if the number of refunds increases relative to the historical number of refunds, the corresponding abnormal behavior coefficient increases, and the corresponding target weight increases. Furthermore, the abnormal refund situation of a user may also include the number of people in the first sub-user group who made refunds for the same transaction object; correspondingly, the more people, the higher the corresponding abnormal behavior coefficient.
[0049] In this embodiment of the invention, optionally, historical abnormal refund information corresponding to the first sub-user group within a past historical period can be obtained, and the historical abnormal refund information can be compared with the actual abnormal refund information. Based on the comparison result, a corresponding abnormal behavior coefficient can be generated. For example, if the total number of refunds increases, the corresponding target weight increases; if the total number of refunds remains the same but the number of refunds for popular items increases, the corresponding target weight increases.
[0050] In this embodiment of the invention, optionally, the target weight corresponding to the first sub-user group is adjusted based on the behavioral analysis coefficients corresponding to the first sub-user group. Specifically, the target weight of transaction association can be adjusted. Furthermore, the target weights of social association and / or device sharing association can also be adjusted.
[0051] As can be seen, the embodiments of the present invention can also adjust the relevant weights by analyzing the abnormal refund situation of users in the user group and further combining it with the historical abnormal refund situation, so as to make the obtained relevant weights match the actual abnormal refund situation, further improve the accuracy of determining the relevant weights, thereby further improving the accuracy and reliability of constructing the dynamic transaction graph, and further improving the accuracy and reliability of analyzing the fraudulent behavior of cross-account fraud organizations.
[0052] In this embodiment of the invention, optionally, fraud behavior analysis is performed on the transaction graph corresponding to the user group to obtain the fraud behavior analysis results corresponding to the user group, including: Based on the transaction graph corresponding to the user group, the relationship between all users in the user group is analyzed to obtain all second sub-user groups; wherein, the correlation between all users in each second sub-user group is greater than or equal to the first preset correlation, and the correlation between all second sub-user groups is less than the second preset correlation, and the first preset correlation is greater than the second preset correlation. For any second sub-user group, based on the data characteristics of each user in the second sub-user group, determine the node importance of each user in the second sub-user group, and locate the target user from the second sub-user group based on the node importance of all users, wherein the node importance of the target user is greater than the node importance of other users in the second sub-user group, wherein the data characteristics of each user include the social characteristics of each user. In this embodiment of the invention, the fraud behavior analysis results corresponding to the user group include all second sub-user groups and the target users of each second sub-user group.
[0053] In this embodiment of the invention, optionally, the fraud behavior analysis results corresponding to the user group may further include the node position of each target user in the corresponding second sub-user group and / or the number and quantity of other users who have direct interaction with it and / or the number of paths through which one-way interaction paths pass, and these are marked on the transaction graph. This allows for a more intuitive and clearer understanding of the analysis results of fraud organizations.
[0054] In this embodiment of the invention, optionally, for any user in the second sub-user group, the higher the value of their social degree centrality feature and / or social betweenness centrality feature, the higher their node importance. The node importance of a user in the second sub-user group can be analyzed using any algorithm capable of analyzing node importance, such as the PageRank algorithm, without limitation. Similarly, the relationships between users in the user group can be analyzed using any algorithm capable of analyzing association relationships, such as the Louvain algorithm, without limitation.
[0055] To make the present invention clearer to those skilled in the art, an example is given below. Suppose that in a user group's transaction graph, there are users A, B, C, D, and E, and their relationships are as follows: A has close social and transactional relationships with B and C; B has a close social relationship with C; D and E have a close device-sharing relationship; and the relationships between A, B, C, D, and E are relatively few. Analysis of the relationships between A, B, C, D, and E identifies two second sub-user groups: one consisting of users A, B, and C, which may constitute a potential fraud organization; and the other consisting of users D and E, which has fewer connections to the sub-user group consisting of users A, B, and C, and may constitute another independent fraud organization. Using the PageRank algorithm to analyze the sub-user groups consisting of users A, B, and C and D and E respectively, it is found that users A and D have the highest node importance in their respective sub-user groups. This indicates that users A and D have the greatest influence in their respective sub-user groups and are core members or high-risk users.
[0056] As can be seen, the embodiments of the present invention can also improve the accuracy of fraud behavior analysis by mining the implicit relationships in the constructed real-time dynamic transaction graph, further improve the accuracy and efficiency of cross-account fraud behavior analysis, and further help improve the accuracy and reliability of fraud behavior analysis of fraud organizations.
[0057] Example 2 Please see Figure 2 , Figure 2 This is a flowchart illustrating another method for fraud behavior analysis using a fraud analysis model disclosed in an embodiment of the present invention. This method can be applied to any scenario requiring fraud behavior analysis, such as an item rental scenario, where a corresponding device is provided. This device includes one of the following: a fraud detection device, a fraud detection system (local system or cloud system), and a fraud detection server (local server or cloud server). Figure 2 As shown, the method may include the following operations: 201. Obtain multi-dimensional data on the transaction objects generated by the user group within the target time period.
[0058] 202. For any dimension of data, extract the data features of the dimension data, and construct the transaction graph corresponding to the user group based on the data features of all dimensions of data.
[0059] 203. Conduct fraud behavior analysis on the transaction risk map corresponding to the user group to obtain the fraud behavior analysis results corresponding to the user group.
[0060] For further descriptions of steps 201-203 in this invention, please refer to the detailed description of steps 101-103 in Embodiment 1, which will not be repeated here.
[0061] 204. Input the target data into the pre-trained fraud analysis model for analysis to obtain the fraud analysis results of the user group; wherein, the target data includes the data characteristics of all dimensions of data and the fraud behavior analysis results corresponding to the user group.
[0062] In this embodiment of the invention, optionally, the target data may include data features of all dimensions and fraud behavior analysis results corresponding to the user group, and may also include transaction graphs corresponding to the user group. Optionally, the fraud analysis results for the user group may include multiple factors such as fraud probability, team size, and fraud location.
[0063] In this embodiment of the invention, optionally, the fraud probability of a user group is determined in the following ways: For any data feature, obtain the feature weight that matches the data feature from multiple feature weights in the fraud analysis model, and analyze the fraud parameters corresponding to the data feature based on the data feature and the feature weight corresponding to the data feature. Based on the fraud parameters corresponding to all data features and the basic feature weights of the fraud analysis model, the basic fraud parameters of the user group are determined. The fraud probability of a user group is determined based on the basic fraud parameters of the user group and the basic feature weights of the fraud analysis model.
[0064] In this model, the sum of the weights of multiple features and the weight of the basic feature in the fraud analysis model is equal to 1.
[0065] In this embodiment of the invention, optionally, the fraud analysis model can be trained based on any model capable of fraud behavior analysis, especially fraud probability analysis, such as the random forest model, without limitation.
[0066] In this embodiment of the invention, optionally, the user group can be multiple second sub-user groups. In this case, the fraud analysis result includes the fraud analysis results of all second sub-user groups. Optionally, the fraud analysis result also includes transaction device data, wherein the transaction device data includes the device identifier of the transaction device and / or the number of transactions conducted using that transaction device.
[0067] In this embodiment of the invention, optionally, the feature weight corresponding to each data feature is a dynamic weight, that is, obtained by training the fraud analysis model.
[0068] It is evident that implementation Figure 2The described method acquires multi-dimensional data from multiple users within a target time period, such as a week, regarding rented / purchased items / services. This data includes user social data, transaction data, and device-sharing data of the transaction equipment used. Data features are extracted from these dimensions, and a transaction graph corresponding to the user group is constructed based on these features. This graph is then used to analyze user behavior for fraud risk, resulting in improved accuracy and efficiency in fraud detection. This enhances the utilization rate of goods and enables efficient and accurate identification of cross-account fraud organizations. Furthermore, by combining multi-dimensional data features, dynamic transaction graphs, and machine learning models, the method quantifies the probability of fraud and analyzes important data such as fraud locations, further improving the accuracy and reliability of detecting cross-account related fraud.
[0069] In an optional embodiment, the method may further include the following steps: Determine whether the fraud analysis model needs to be optimized. If it is determined that optimization is needed, obtain the behavioral data of the latest sample user group. The behavioral data of the latest sample user group can be understood as the behavioral data currently generated by the system, including the user's social data, transaction data, device sharing data and corresponding fraud tags. Based on the latest behavioral data of the sample user group, the fraud analysis model is optimized and trained to obtain the optimized fraud analysis model.
[0070] In this optional embodiment, optionally, when a decrease in the accuracy of the fraud analysis model is detected, and / or when a new fraud pattern is detected, such as virtual IP tampering or cross-platform collaboration, and / or when the real-time time reaches a preset optimization time, such as in the past quarter, and / or when a new type of transaction object is detected, and / or when an adjustment to the risk control threshold is detected, such as an adjustment to the refund anomaly threshold, it is determined that the fraud analysis model needs to be optimized and trained.
[0071] In this optional embodiment, the behavioral data of the latest sample user group may be cleaned first, and then the fraud analysis model may be optimized and trained. Data cleaning includes, but is not limited to, removing missing values and outliers, such as negative amounts, and adding new features, such as IP geographic dispersion and device fingerprint change frequency.
[0072] In this optional embodiment, parameters such as number depth and number of leaf nodes in the fraud analysis model may be optimized. After parameter optimization, the optimized fraud analysis model is validated through cross-validation and / or performance metrics such as accuracy and / or recall.
[0073] In this optional embodiment, after the fraud analysis model is optimized and trained, the new model is deployed to a preset traffic flow and compared with the old model. If the analysis accuracy is improved to the preset accuracy and the false positive rate is stable, then the model is fully deployed, that is, the trained fraud analysis model is used directly and completely.
[0074] In this optional embodiment, the behavioral data of the latest sample user group can optionally be data from a partial consecutive period, such as 3-6 months, to reduce noise in historical data. And / or, the fraud analysis model and corresponding training data before optimization training can be retained for easier traceability. And / or, a distributed approach can be used for optimization training to accelerate computation, such as a Spark cluster.
[0075] As can be seen, this optional embodiment detects different situations requiring optimized training of the fraud analysis model, so as to train the fraud analysis model in a timely manner, and optimizes the model training based on the behavioral data of the latest sample user group. This improves the accuracy of the optimized training of the fraud analysis model, resulting in a fraud analysis model that is more suitable for the current real-time scenario, so as to ensure that fraudulent behavior can be accurately identified in every cross-account analysis of fraudulent organizations.
[0076] In another alternative embodiment, the method may further include the following steps: Based on the payment method identifier and other identifiers of all payment methods corresponding to the user group, analyze all third sub-user groups in the user group that have payment association relationships. Each third sub-user group consists of at least two users. For any third sub-user group, analyze the payment data of all users in the third sub-user group based on the transaction data of the object corresponding to the user group; For any third sub-user group, the payment method association weight among all users in the third sub-user group is determined based on the payment data corresponding to the third sub-user group and the pre-determined payment coefficient. Associate the payment methods corresponding to all third sub-user groups with weights and update the transaction characteristics corresponding to the user groups.
[0077] In this optional embodiment, other identifiers may optionally include all transaction account identifiers, or all transaction account identifiers and transaction device identifiers and / or IP login addresses. Optionally, payment association relationships may include direct payment association relationships or indirect payment association relationships. Direct payment association relationships indicate that multiple users directly share the same payment method. Indirect payment association relationships indicate that multiple users do not directly share the same payment method, all share the same payment method with another user, or multiple users conduct transactions through the same transaction target, where the same transaction target includes the same transaction device and / or the same IP login address.
[0078] In this optional embodiment, for cases where multiple users transact through the same transaction target, other data shared by the devices can be further considered. For example, if the geographical locations of the users logging into their transaction accounts are similar, an indirect payment association can be further identified. Optionally, a payment association graph corresponding to the user group is pre-established, and this graph is constructed using all payment methods corresponding to the user group as payment nodes and all users in the user group as edges. The weight of each edge varies based on the number of times payment methods are shared between users; the more times payment methods are shared, the higher the weight.
[0079] In this optional embodiment, the payment data corresponding to the third sub-user group may include the number of shared payment methods (such as the number of shared bank cards) of all users in the third sub-user group, the total number of payment methods of all users in the third sub-user group, and the overlapping duration of payment periods of all users in the third sub-user group, such as the cumulative duration of transactions between two users within the same hour.
[0080] In this optional embodiment, the payment coefficient may include a preset payment weight and a preset payment time threshold, such as 24 hours. The preset payment weight includes a preset quantity weight and a preset time weight. Optionally, the payment method association weight among all users in each third sub-user group is determined in the following way: Obtain the number of shared payment methods and the duration of overlapping payment periods for all users in the third sub-user group; determine the shared payment method situation based on the number of shared payment methods and the total number of payment methods for all users in the third sub-user group; The weight of the shared payment method is determined based on the shared payment method and the preset quantity weight; the shared payment time is determined based on the overlapping duration of payment periods and the preset payment time threshold. Based on the shared payment time situation and the preset time weight, the shared payment time weight is determined; based on the shared payment time weight and the shared payment method weight, the payment method association weight is determined.
[0081] The sum of the preset quantity weight and the preset time weight is equal to 1.
[0082] In this optional embodiment, the payment method association weight is further optionally compared with multiple preset payment method weights. Specifically, if the payment method association weight is greater than the first preset payment method weight, it indicates that the third sub-user group is a high-risk association, such as sharing more than 3 bank cards with highly overlapping time periods; if the payment method association weight is greater than the second preset payment method weight but less than the first preset payment method weight, it indicates that the third sub-user group is a medium-risk association, such as sharing 1-2 bank cards; if the payment method association weight is less than the second preset payment method weight, it indicates that the third sub-user group is a low-risk association, such as only sharing IPs but having no direct payment association. The first preset payment method weight is greater than the second preset payment method weight, for example, 0.8 or 0.5. When the third sub-user group corresponds to medium-risk or high-risk associations, it is risk-marked and updated in the corresponding dimension's data features.
[0083] In this optional embodiment, the payment method identifiers and other identifiers of all payment methods corresponding to the user group, along with the transaction data of the objects corresponding to the user group, are first cleaned, and then the payment method correlation is detected. This data cleansing includes removing invalid data, such as incomplete bank card numbers or unverified third-party accounts; standardizing data formats, such as standardizing bank card numbers to 16 or 19 digits; and hashing sensitive information (such as cardholder names) to ensure privacy compliance.
[0084] As can be seen, this optional embodiment improves the timeliness of the payment method association weights among users in a group by detecting the correlation between payment methods for transaction objects in the group and updating the payment method association weights among users in the group based on real-time transaction data, thereby ensuring the timeliness of risk rating and enriching the data features of multi-dimensional data, further improving the accuracy and reliability of identifying fraudulent organizations.
[0085] In yet another optional embodiment, the method may further include the following steps: For any user in the user group, analyze the user's refund data within the target time period based on the user's corresponding transaction data. The refund data for each user includes the number of refunds and the time interval between each refund, optionally in hours or minutes. The time interval between each refund represents the time between the current refund and the transaction time. For any user in the user group, based on the user's corresponding refund data and a pre-determined anomaly coefficient, identify the frequency of abnormal refunds for the user within the target time period; where the anomaly coefficient includes a refund anomaly coefficient and a time anomaly coefficient; Update the abnormal refund frequency for any user in the user group to the transaction characteristics corresponding to the user group.
[0086] In this optional embodiment, the frequency of abnormal refunds for each user may be determined in the following ways: The number of refunds for a user is determined based on the number of refunds and a preset refund threshold; the frequency of refunds for a user is determined based on the number of refunds and the refund anomaly coefficient. Based on the user's preset refund time threshold and the time interval between each refund, determine the user's refund time status; based on the user's refund time status and time anomaly coefficient, determine the user's refund time frequency; The frequency of abnormal refunds for a user is determined based on the frequency of refund time and the frequency of refund occurrences. The sum of the refund abnormality coefficient and the time abnormality coefficient is equal to 1.
[0087] In this optional embodiment, the abnormal refund frequency can be further compared with multiple preset abnormal refund frequencies. Specifically, if the abnormal refund frequency is greater than a first preset abnormal refund frequency, the corresponding user is considered a high-risk user, such as having four abnormal refunds within a week; if the abnormal refund frequency is greater than a second preset abnormal refund frequency but less than the first preset abnormal refund frequency, the corresponding user is considered a medium-risk user, such as having two abnormal refunds within a week with each refund interval less than one hour; if the abnormal refund frequency is less than the second preset abnormal refund frequency, the corresponding user is considered a low-risk user, such as having only one abnormal refund within a week. The first preset abnormal refund frequency is greater than the second preset abnormal refund frequency, such as 1.0 or 0.5. When a user is classified as a medium-risk or high-risk user, a risk marker is applied, updated to the corresponding dimension's data features, and the operation of freezing the user's transaction account and conducting fraud organization association analysis is triggered.
[0088] In this optional embodiment, the user's transaction data may be cleaned first, followed by an analysis of abnormal refund frequency. This data cleaning operation includes, but is not limited to, removing invalid data, such as incomplete refunds, and / or standardizing the time format, such as UTC timestamps.
[0089] As can be seen, this optional embodiment analyzes the abnormal refunds of each user's transaction data in the user group to obtain the corresponding abnormal refund frequency, and performs account freezing and fraud organization association analysis based on the abnormal refund frequency. It also enriches the transaction features and helps to further improve the accuracy and reliability of fraud organization identification.
[0090] In yet another optional embodiment, the method may further include the following steps: Based on the IP login address, login time, and account identifier of each user in the user group when logging into their trading account, determine whether there exists a first IP login address that has been used by multiple users to log into the corresponding trading account within a preset time period. If such an IP login address is found, select each first IP login address from all IP login addresses as an IP login address with account association attributes, and update all first IP login addresses to the device sharing characteristics corresponding to the user group; and / or Based on the geographical location and IP address of each user when logging into their trading account, determine whether there exist all first IP login addresses that simultaneously appear within a preset area. If so, filter out all second IP login addresses that match the preset area from all IP login addresses, and use these as IP login addresses with location-related attributes. Update the device sharing characteristics corresponding to the user group with all second IP login addresses that match the preset area. Based on each user's transaction account identifier, each user's IP login address when logging into the transaction account, each user's login time when logging into the transaction account, and / or each user's number of refunds, determine whether there is a third IP login address among all IP login addresses that meets the pre-determined abnormal login conditions. When it is determined that there is, filter each third IP login address from all IP login addresses as an IP login address with abnormal attributes, and update all third IP login addresses to the device sharing characteristics corresponding to the user group.
[0091] In this optional embodiment, the preset time period can be any time period, such as within one hour. Optionally, if each first IP login address is logged in by multiple users within the corresponding preset time period, such as IP login address 203.0.113.5 being logged in by users A, B, and C between 10:00 and 10:30, then it is determined that the IP login address has account association attributes and is a high-risk association, meaning it may be a fraudulent organization sharing the same network.
[0092] In this optional embodiment, the preset area range can be any area, such as 1 kilometer, and the number is greater than or equal to 1. Each preset area range contains multiple IP login addresses. For example, IP login address 203.0.113.5 resolves to "Zhengjia Plaza," and IP login address 203.0.113.6 resolves to "Sports Center," and the two locations are 500 meters apart. Therefore, the two IP login addresses are determined to have a location association attribute and a high-risk association, meaning the users corresponding to the two IP login addresses are fraudulent organizations.
[0093] In this optional embodiment, abnormal login situations may include, but are not limited to, frequent switching of trading accounts from the same IP login address and / or frequent refunds from the same IP login address. For example, if IP login address 203.0.113.5 is associated with 10 different trading accounts within a day, or if the user of IP login address 203.0.113.5 has frequent refund activity, it is determined to be a high-risk IP login address, i.e., it may be a fraudulent organization.
[0094] In this optional embodiment, optionally, data cleaning operations are first performed on the IP login address, login time, transaction account identifier, login time, number of refunds, and geographical location of each user in the user group when logging into their transaction account. Then, IP login address correlation detection is performed. This data cleaning operation includes removing invalid IP login addresses, such as private addresses like 192.168.xx, standardizing IP formats (e.g., converting to IPv4 standard format), and de-identifying user identities to protect user privacy.
[0095] As can be seen, this optional embodiment improves the accuracy of IP login address association detection and enriches device sharing features by performing account association attribute detection and / or location association attribute detection and / or abnormal login detection on IP login addresses in the user group, which is conducive to further improving the accuracy and reliability of identifying cross-account fraud by fraud organizations.
[0096] Example 3 Please see Figure 3 , Figure 3 This is a schematic diagram of a device for analyzing fraudulent behavior using a fraud analysis model, as disclosed in an embodiment of the present invention. The device can be applied to any scenario requiring fraudulent behavior analysis, such as a goods rental scenario, and includes one of the following: a fraud detection device, a fraud detection system (local system or cloud system), and a fraud detection server (local server or cloud server). Figure 3 As shown, the device may include: The acquisition module 301 is used to acquire multi-dimensional data generated by the user group for the transaction object within the target time period. The user group consists of multiple users, and the multi-dimensional data corresponding to the user group includes at least two of the following: user social data of all users in the user group, object transaction data of all users in the user group, and device sharing data of the transaction devices used by all users in the user group for object transactions.
[0097] Extraction module 302 is used to extract data features of dimensional data for any dimensional data; Module 303 is used to construct a transaction graph corresponding to the user group based on the data characteristics of all dimensions of data; Analysis module 304 is used to perform fraud behavior analysis on the transaction graph corresponding to the user group and obtain the fraud behavior analysis results corresponding to the user group.
[0098] It is evident that implementation Figure 3 The described device acquires multi-dimensional data from multiple users within a target time period, such as a week, regarding rented / purchased items / services. This data includes user social data, transaction data, and device-sharing data of the transaction equipment used during the transaction. The device extracts data features from the corresponding dimensions and then constructs a transaction graph corresponding to the user group based on the extracted multi-dimensional data features. Based on this transaction graph, fraud risk analysis is performed on user behavior to obtain fraud behavior analysis results. This improves the accuracy and efficiency of fraud behavior detection, thereby increasing the full utilization of items and enabling efficient and accurate identification of fraudulent activities by cross-account fraud organizations.
[0099] In this embodiment of the invention, optionally, the extraction module 302 extracts the data features of any dimension data in a specific manner, including: When the dimension data is the social data of users corresponding to the user group, the social characteristics of each user in the user group are analyzed based on the social data of users corresponding to the user group. The social characteristics of each user include social degree center features and / or social betweenness center features. When the dimension data is the object transaction data corresponding to a user group, the transaction characteristics of all users in the user group for the transaction object are determined based on the object transaction data corresponding to the user group; wherein, the object transaction data corresponding to the user group includes the transaction account identifier and payment method identifier of all users in the user group for the transaction object; wherein, the transaction characteristics corresponding to the user group include the transaction frequency and all payment methods of all users in the user group for the transaction object; When the dimensional data is device-shared data corresponding to a user group, the device-shared characteristics of the trading devices used by all users in the user group for object transactions are identified based on the device-shared data corresponding to the user group. Specifically, the device-shared data corresponding to the user group includes the device identifier of the trading devices used by all users in the user group, the IP login address of each user when logging into their trading account, the login time of each user when logging into their trading account, and the geographical location of each user when logging into their trading account. The device-shared characteristics corresponding to the user group include the number of accounts that log into their trading accounts through the same trading device and the overlapping time periods during which each trading account uses the same trading device. Specifically, the extraction module 302 analyzes the social characteristics of each user in the user group based on the user social data corresponding to the user group, including: For any user in the user group, based on the user's social data, analyze the number of all users in the user group who directly interact with the user, and determine the user's social centrality feature based on the number of users corresponding to the user and the total number of users in the user group; and / or Based on the user's social data, analyze all one-way interaction paths in the user group; for any user in the user group, determine all one-way paths passing through the user based on all one-way interaction paths, and determine the user's social betweenness center characteristics based on the number of all one-way paths corresponding to the user and all one-way interaction paths in the user group.
[0100] As can be seen, the embodiments of the present invention can also perform specific analysis on the specific content of data in different dimensions separately to obtain the data features of the corresponding dimensions, thereby improving the accuracy and reliability of data feature analysis and thus improving the accuracy and reliability of transaction image construction; and for each user, it can also analyze the number of users who directly interact with him / her in the user group and the number of paths that must pass through the user in the interaction between users in the user group, to obtain social degree center features and social betweenness center features, which can realize the accurate analysis of the influence of the corresponding user in the group.
[0101] In this embodiment of the invention, optionally, the specific method by which the construction module 303 constructs the transaction graph corresponding to the user group based on the data characteristics of all dimensions of data includes: Based on the data characteristics of all dimensions, identify all first sub-user groups with relationships within the user group. These relationships include at least two of the following: social relationships, transaction relationships, and device sharing relationships. Each first sub-user group consists of multiple users from the user group. For any association relationship of any first sub-user group, determine the initial weight of the first sub-user group for the association relationship, and perform an update operation on the initial weight of the association relationship based on the data characteristics of the first sub-user group for the association relationship to obtain the target weight of the updated association relationship. Based on the target weights of all relationships in all first sub-user groups, construct the transaction graph corresponding to each user group; The target weights for all relationships within each first sub-user group include at least two of the following: social association weights, transaction association weights, and device sharing association weights.
[0102] As can be seen, the embodiments of the present invention can also dynamically construct a transaction graph based on the dynamic changes in the association duration and number of associations among multiple users with related relationships in a group, thereby improving the accuracy and reliability of the dynamic construction of the transaction graph, which is conducive to improving the accuracy and reliability of fraud identification.
[0103] In this embodiment of the invention, optionally, the analysis module 304 performs fraud behavior analysis on the transaction graph corresponding to the user group to obtain the fraud behavior analysis results for the user group, including the following specific methods: Based on the transaction graph corresponding to the user group, the relationship between all users in the user group is analyzed to obtain all second sub-user groups; wherein, the correlation between all users in each second sub-user group is greater than or equal to the first preset correlation, and the correlation between all second sub-user groups is less than the second preset correlation, and the first preset correlation is greater than the second preset correlation. For any second sub-user group, based on the data characteristics of each user in the second sub-user group, determine the node importance of each user in the second sub-user group, and based on the node importance of all users, locate the target user from the second sub-user group. The node importance of the target user is greater than the node importance of other users in the second sub-user group. The data characteristics of each user include the social characteristics of each user. The fraud behavior analysis results for user groups include all second sub-user groups and the target users of each second sub-user group.
[0104] As can be seen, the embodiments of the present invention can also improve the accuracy of fraud behavior analysis by mining the implicit relationships in the constructed real-time dynamic transaction graph, further improve the accuracy and efficiency of cross-account fraud behavior analysis, and further help improve the accuracy and reliability of fraud behavior analysis of fraud organizations.
[0105] In an optional embodiment, such as Figure 3 As shown, the analysis module 304 is also used to input the target data into a pre-trained fraud analysis model for analysis to obtain fraud analysis results of the user group; wherein, the target data includes the data characteristics of all dimensions of data and the fraud behavior analysis results corresponding to the user group; The fraud analysis results for user groups include multiple factors such as fraud probability, team size, transaction device data, and fraud location. The probability of fraud among user groups is determined in the following ways: For any data feature, obtain the feature weight that matches the data feature from multiple feature weights in the fraud analysis model, and analyze the fraud parameters corresponding to the data feature based on the data feature and the feature weight corresponding to the data feature. Based on the fraud parameters corresponding to all data features and the basic feature weights of the fraud analysis model, the basic fraud parameters of the user group are determined. The fraud probability of a user group is determined based on the basic fraud parameters of the user group and the basic feature weights of the fraud analysis model.
[0106] In this model, the sum of the weights of multiple features and the weight of the basic feature in the fraud analysis model is equal to 1.
[0107] As can be seen, this optional embodiment combines multi-dimensional data features, dynamic transaction graphs and machine learning models to quantify the probability of fraud and analyze important data such as the location of fraud by fraud organizations, thereby further improving the accuracy and reliability of detecting cross-account related fraud.
[0108] In another optional embodiment, the object transaction data corresponding to the user group also includes the transaction times of all users in the user group for the transacted object. And as... Figure 3 As shown, the analysis module 304 is further used to analyze all third sub-user groups with payment association relationships in the user group based on the payment method identifier and other identifiers of all payment methods corresponding to the user group. Each third sub-user group consists of at least two users. Among them, other identifiers include all transaction account identifiers, or all transaction account identifiers and transaction device identifiers and / or IP login addresses. The payment association relationship includes direct payment association relationship or indirect payment association relationship. Direct payment association relationship is used to indicate that multiple users directly share the same payment method. Indirect payment association relationship is used to indicate that multiple users do not directly share the same payment method, all share the same payment method with another user, or multiple users conduct transactions through the same transaction target. Among them, the same transaction target includes the same transaction device and / or the same IP login address. The analysis module 304 is also used to analyze the payment data of all users in any third sub-user group based on the object transaction data corresponding to the user group; wherein, the payment data corresponding to the third sub-user group includes the number of shared payment methods of all users in the third sub-user group, the total number of payment methods of all users in the third sub-user group, and the overlap duration of payment periods of all users in the third sub-user group. Figure 4 This is a schematic diagram of another device for analyzing fraudulent behavior using a fraud analysis model, as disclosed in an embodiment of the present invention. Figure 4 As shown, the device may further include: The determination module 305 is used to determine the payment method association weight among all users in any third sub-user group based on the payment data corresponding to the third sub-user group and the pre-determined payment coefficient. The first update module 306 is used to associate the weights of the payment methods corresponding to all third sub-user groups and update the transaction features corresponding to the user groups.
[0109] It is evident that implementation Figure 4The described device improves the timeliness of the payment method association weights among users in a group by detecting the correlation between payment methods for transaction objects within the group and updating the association weights of payment methods among users in the group based on real-time transaction data. This ensures the timeliness of risk rating and enriches the data features of multi-dimensional data, further improving the accuracy and reliability of identifying fraudulent organizations.
[0110] In another optional embodiment, the object transaction data corresponding to the user group also includes transaction data of all users in the user group for the transacted object, wherein the transaction data corresponding to the user group includes the number of transactions for each user in the user group for the transacted object, the time of each transaction, and the time of each refund; such as Figure 4 As shown, the analysis module 304 is also used to analyze the refund data of any user in the user group within a target time period based on the user's corresponding transaction data; wherein, the refund data for each user includes the number of refunds and the time interval between each refund, wherein the time interval between each refund is used to represent the time interval between the current refund time and the transaction time; And such as Figure 4 As shown, the device may further include: The identification module 307 is used to identify the frequency of abnormal refunds for any user in the user group within a target time period, based on the user's corresponding refund data and a pre-determined abnormality coefficient; wherein, the abnormality coefficient includes a refund abnormality coefficient and a time abnormality coefficient. The second update module 308 is used to update the abnormal refund frequency corresponding to any user in the user group to the transaction characteristics corresponding to the user group.
[0111] It is evident that implementation Figure 4 The described device analyzes the transaction data of each user in the user group to obtain the corresponding abnormal refund frequency, and performs account freezing and fraud organization association analysis based on the abnormal refund frequency. It also enriches the transaction characteristics, which helps to further improve the accuracy and reliability of fraud organization identification.
[0112] In yet another alternative embodiment, such as Figure 4 As shown, the device may further include: The judgment module 309 is used to determine, based on the IP login address of each user when logging into the trading account, the login time of each user when logging into the trading account, and the trading account identifier of each user, whether there is a first IP login address among all IP login addresses that has been logged into the corresponding trading account by multiple users within a preset time period. The filtering module 310 is used to filter each first IP login address from all IP login addresses when it is determined that the IP login address exists, and use it as the IP login address with account association attribute. The third update module 311 is used to update all first IP login addresses to the device sharing characteristics corresponding to the user group; and / or The judgment module 309 is used to determine, based on the geographical location of each user when logging into the trading account and the IP login address of each user when logging into the trading account, whether there are any first IP login addresses that appear simultaneously within a preset area range among all IP login addresses; The filtering module 310 is used to filter out all second IP login addresses that match the preset area range from all IP login addresses when it is determined that they exist, and use them as IP login addresses with location association attributes. The third update module 311 is used to update all second IP login addresses that match the preset area range to the device sharing features corresponding to the user group; and / or The judgment module 309 is used to determine, based on each user's transaction account identifier, each user's IP login address when logging into the transaction account, each user's login time when logging into the transaction account, and / or each user's number of refunds, whether there is a third IP login address among all IP login addresses that meets the pre-determined abnormal login situation. The filtering module 310 is used to filter each third IP login address from all IP login addresses as an IP login address with abnormal attributes when it is determined that the existence exists. The third update module 311 is used to update all third-party IP login addresses to the device sharing characteristics corresponding to the user group.
[0113] It is evident that implementation Figure 4 The described device improves the accuracy of IP login address association detection by performing account association attribute detection and / or location association attribute detection and / or abnormal login detection on IP login addresses in a user group, and enriches the device sharing features, which is conducive to further improving the accuracy and reliability of identifying cross-account fraud by fraud organizations.
[0114] Example 4 Please see Figure 5 , Figure 5 This is a schematic diagram of the structure of a fraud detection device disclosed in an embodiment of the present invention. This device can be applied to any scenario requiring fraud behavior analysis, such as an item rental scenario. Figure 5 As shown, the device may include: Memory 401 storing executable program code; Processor 402 coupled to memory 401; Furthermore, it may also include an input interface 403 and an output interface 404 coupled to the processor 402; The processor 402 calls the executable program code stored in the memory 401 to execute the steps in the method for analyzing fraud behavior using the fraud analysis model described in Embodiment 1 or Embodiment 2.
[0115] Example 5 This invention discloses a computer storage medium storing computer instructions. When these computer instructions are invoked, they are used to execute the steps in the method for analyzing fraud behavior using a fraud analysis model as described in Embodiment 1 or Embodiment 2.
[0116] Example 6 This invention discloses a computer program product, which includes a non-transitory computer-readable storage medium storing a computer program, and the computer program is operable to cause a computer to perform the steps in the method for performing fraud behavior analysis using a fraud analysis model as described in Embodiment 1 or Embodiment 2.
[0117] The device embodiments described above are merely illustrative. The modules described as separate components may or may not be physically separate, and the components shown as modules may or may not be physical modules; that is, they may be located in one place or distributed across multiple network modules. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. Those skilled in the art can understand and implement this without any creative effort.
[0118] Through the detailed description of the above embodiments, those skilled in the art can clearly understand that each implementation method can be implemented by means of software plus necessary general-purpose hardware platforms, and of course, it can also be implemented by hardware. Based on this understanding, the above technical solutions, in essence or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, including read-only memory (ROM), random access memory (RAM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), one-time programmable read-only memory (OTPROM), electrically-Erasable Programmable Read-Only Memory (EEPROM), compact disc read-only memory (CD-ROM) or other optical disc storage, disk storage, magnetic tape storage, or any other computer-readable medium that can be used to carry or store data.
[0119] Finally, it should be noted that the method, apparatus, and device for fraud behavior analysis using a fraud analysis model disclosed in the embodiments of the present invention are merely preferred embodiments of the present invention and are only used to illustrate the technical solutions of the present invention, not to limit it. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.
Claims
1. A method for analyzing fraudulent behavior using a fraud analysis model, characterized in that, The method includes: Acquire multi-dimensional data of a user group for the transaction object within a target time period. The user group consists of multiple users, and all the multi-dimensional data corresponding to the user group include at least two of the following: user social data of all users in the user group, object transaction data of all users in the user group, and device sharing data of the transaction devices used by all users in the user group for object transactions. For any of the stated dimension data, extract the data features of the stated dimension data, and construct the transaction graph corresponding to the user group based on the data features of all the stated dimension data; Fraud behavior analysis is performed on the transaction graph corresponding to the user group to obtain the fraud behavior analysis results corresponding to the user group. The target data is input into a pre-trained fraud analysis model for analysis to obtain the fraud analysis results of the user group; wherein, the target data includes the data features of all the dimensions and the fraud behavior analysis results corresponding to the user group; The step of constructing the transaction graph corresponding to the user group based on the data characteristics of all the said dimensional data includes: Based on the data characteristics of all the dimensions, determine all first sub-user groups that have relationships within the user group. The relationships include at least two of the following: social relationships, transaction relationships, and device sharing relationships. Each first sub-user group consists of multiple users from the user group. For any association relationship of any first sub-user group, determine the initial weight of the first sub-user group for the association relationship, and perform an update operation on the initial weight of the association relationship based on the data characteristics of the first sub-user group for the association relationship to obtain the updated target weight of the association relationship. Based on the target weights of all the relationships in the first sub-user group, construct the transaction graph corresponding to the user group; The target weights for all the relationships in each of the first sub-user groups include at least two of the following: social association weights, transaction association weights, and device sharing association weights. The weight for any association relationship in each of the first sub-user groups is determined in the following way, and the weight includes an initial weight or a target weight: Obtain the number of associations and the duration of associations between users in the first sub-user group; Based on the number of associations, the preset maximum number of associations, and the preset number of association weight coefficient, the association number weight corresponding to the first sub-user group is determined. Based on the association duration, the preset maximum association duration, and the preset time weight coefficient, the association duration weight corresponding to the first sub-user group is determined. The weight of any association relationship in the first sub-user group is determined based on the association frequency weight and the association duration weight corresponding to the first sub-user group.
2. The method for analyzing fraudulent behavior using a fraud analysis model according to claim 1, characterized in that, For any of the said dimensional data, extracting the data features of the dimensional data includes: When the dimension data is the user social data corresponding to the user group, analyze the social characteristics of each user in the user group based on the user social data corresponding to the user group; When the dimension data is the object transaction data corresponding to the user group, the transaction characteristics of all users in the user group for the transaction object are determined according to the object transaction data corresponding to the user group. When the dimension data is device-shared data corresponding to the user group, the device-shared characteristics of the transaction devices used by all users in the user group for object transactions are identified based on the device-shared data corresponding to the user group. The step of analyzing the social characteristics of each user in the user group based on the user social data corresponding to the user group includes: For any user in the user group, based on the user's social data, analyze the number of all users in the user group who have directly interacted with the user, and determine the user's social degree centrality feature based on the number of users corresponding to the user and the total number of users in the user group; and / or Based on the user's social data, analyze all one-way interaction paths in the user group; for any user in the user group, determine all one-way paths passing through the user based on all the one-way interaction paths, and determine the user's social betweenness center characteristics based on the number of all one-way paths corresponding to the user and the number of all one-way interaction paths in the user group.
3. The method for analyzing fraudulent behavior using a fraud analysis model according to claim 1, characterized in that, The fraud behavior analysis of the transaction graph corresponding to the user group, to obtain the fraud behavior analysis results corresponding to the user group, includes: Based on the transaction graph corresponding to the user group, the relationship between all users in the user group is analyzed to obtain all second sub-user groups; wherein, the correlation degree between all users in each second sub-user group is greater than or equal to the first preset correlation degree, and the correlation degree between all second sub-user groups is less than the second preset correlation degree, and the first preset correlation degree is greater than the second preset correlation degree. For any second sub-user group, the node importance of each user in the second sub-user group is determined according to the data characteristics corresponding to each user in the second sub-user group, and the target user is located from the second sub-user group according to the node importance of all users. The node importance of the target user is greater than the node importance of other users in the second sub-user group. The data characteristics corresponding to each user include the social characteristics corresponding to each user. The fraud behavior analysis results corresponding to the user groups include all the second sub-user groups and the target users of each second sub-user group.
4. The method for analyzing fraudulent behavior using a fraud analysis model according to any one of claims 1-3, characterized in that, The fraud analysis results for the user group include multiple factors such as fraud probability, team size, transaction device data, and fraud location.
5. The method for analyzing fraudulent behavior using a fraud analysis model according to claim 2, characterized in that, The object transaction data corresponding to the user group also includes the transaction time of all users in the user group for the transacted object; The method further includes: Based on the payment method identifier and other identifiers of all payment methods corresponding to the user group, analyze all third sub-user groups in the user group that have payment association relationships, and each third sub-user group consists of at least two users; wherein, the other identifiers include all transaction account identifiers, or, all transaction account identifiers and transaction device identifiers and / or IP login addresses; For any of the aforementioned third sub-user groups, the payment data of all users in the third sub-user group is analyzed based on the object transaction data corresponding to the user group; wherein, the payment data corresponding to the third sub-user group includes the number of shared payment methods of all users in the third sub-user group, the total number of payment methods of all users in the third sub-user group, and the overlap duration of payment periods of all users in the third sub-user group. For any of the third sub-user groups, the payment method association weight among all users in the third sub-user group is determined based on the payment data corresponding to the third sub-user group and the pre-determined payment coefficient. Associate the payment methods corresponding to all the third sub-user groups with weights and update the transaction features corresponding to the user groups.
6. The method for analyzing fraudulent behavior using a fraud analysis model according to claim 2, characterized in that, The transaction data corresponding to the user group also includes the transaction data of all users in the user group for the transaction object, wherein the transaction data corresponding to the user group includes the number of transactions, the time of each transaction and the time of each refund for each user in the user group for the transaction object; The method further includes: For any user in the user group, the refund data of the user within the target time period is analyzed based on the transaction data corresponding to the user; wherein, the refund data corresponding to each user includes the number of refunds for the user and the time interval between each refund, wherein each refund time interval is used to represent the time interval between the current refund time and the transaction time; For any user in the user group, based on the user's corresponding refund data and a pre-determined anomaly coefficient, the frequency of abnormal refunds for the user within the target time period is identified; wherein, the anomaly coefficient includes a refund anomaly coefficient and a time anomaly coefficient; Update the abnormal refund frequency corresponding to any user in the user group to the transaction characteristics corresponding to the user group.
7. The method for analyzing fraudulent behavior using a fraud analysis model according to claim 2, characterized in that, The method further includes: Based on the IP login address, login time, and transaction account identifier of each user in the user group when logging into their transaction account, it is determined whether there exists a first IP login address among all the IP login addresses that has been used by multiple users to log into the corresponding transaction account within a preset time period. If such a first IP login address is found, it is selected from all the IP login addresses as IP login addresses with account association attributes, and all first IP login addresses are updated to the device sharing characteristics corresponding to the user group; and / or Based on the geographical location and IP address of each user when logging into their transaction account, determine whether there exist all first IP login addresses that simultaneously appear within a preset area range. If such an IP login address is found, filter out all second IP login addresses that match the preset area range as IP login addresses with location-related attributes, and update the device sharing characteristics corresponding to the user group with all second IP login addresses that match the preset area range; and / or Based on each user's transaction account identifier, each user's IP login address when logging into the transaction account, each user's login time when logging into the transaction account, and / or each user's number of refunds, determine whether there is a third IP login address among all the IP login addresses that meets the pre-determined abnormal login conditions. When it is determined that there is, each third IP login address is selected from all the IP login addresses as an IP login address with abnormal attributes, and all the third IP login addresses are updated to the device sharing characteristics corresponding to the user group.
8. An apparatus for analyzing fraudulent behavior using a fraud analysis model, characterized in that, The apparatus is used to implement the method for fraud behavior analysis using a fraud analysis model as described in any one of claims 1-7, the apparatus comprising: The acquisition module is used to acquire multiple dimensions of data generated by a user group for the transaction object within a target time period. The user group consists of multiple users, and all the dimensions of data corresponding to the user group include at least two of the following: user social data of all users in the user group, object transaction data of all users in the user group, and device-shared data of the transaction devices used by all users in the user group to conduct object transactions. The extraction module is used to extract the data features of any of the said dimensional data; A construction module is used to construct a transaction graph corresponding to the user group based on the data characteristics of all the dimensions of data. The analysis module is used to perform fraud behavior analysis on the transaction graph corresponding to the user group and obtain the fraud behavior analysis results corresponding to the user group.
9. A fraud detection device, characterized in that, The device includes: Memory containing executable program code; A processor coupled to the memory; The processor calls the executable program code stored in the memory to execute the method for fraud behavior analysis using the fraud analysis model as described in any one of claims 1-7.
Citation Information
Patent Citations
Insurance blackout identification and response system based on associated network analysis technology
CN117688055A
Bank anti-call fraud data model construction method based on multi-feature fusion
CN117993919A
Fraud detection method based on graph data and related equipment
CN119903245A