Risk assessment method, device, equipment, medium and program product

By simulating the execution of change orders and using a target large model to generate risk assessment results, the problem of the accuracy of risk assessment during the upgrade of financial trading systems was solved, and the reliability and accuracy of the assessment were improved.

CN120911964APending Publication Date: 2025-11-07INDUSTRIAL AND COMMERCIAL BANK OF CHINA
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511082519.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-04
Publication Date
2025-11-07

AI Technical Summary

Technical Problem

When upgrading or introducing new functions, financial trading systems are prone to various problems, and existing technologies make it difficult to conduct accurate risk assessments.

Method used

By simulating the execution of change orders, the target large model is used to process the change orders and simulation execution results. Combined with the evaluation strategy, risk assessment results are generated, including simulated transaction process and behavioral data, to identify change results and generate risk assessments with reasoning logic chains.

Benefits of technology

Simulating the trading process in advance avoids risks in a real environment, improves the reliability and accuracy of risk assessment results, and reduces risks in actual trading.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120911964A_ABST
    Figure CN120911964A_ABST
Patent Text Reader

Abstract

The invention provides a risk assessment method, and relates to the field of artificial intelligence. The method comprises the steps that in response to an evaluation request, a change instruction is executed in a simulation mode, a simulation execution result is obtained, the change instruction indicates at least one transaction parameter to be changed, and the simulation execution result comprises at least one item of at least one transaction parameter after change and transaction data executed in a simulation mode based on the at least one transaction parameter after change; and guiding the target large model to process the change instruction and the simulation execution result based on a first cue word to obtain a risk assessment result of the change instruction, the first cue word comprising an assessment strategy preset based on the at least one transaction parameter. The invention further provides a risk assessment device and equipment, a storage medium and a program product.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the field of artificial intelligence, and more particularly to a risk assessment method, device, equipment, medium and program product. BACKGROUND

[0002] A financial transaction system supports the operation of complex transaction business, and processes a large amount of transactions. Problems that occur in the operation process of the financial transaction system can cause losses to users. When the financial transaction system is upgraded or new functions are introduced, because it may involve changes to the hardware, software, application services or business processes of the financial transaction system, various problems are easily triggered. Therefore, accurate risk assessment of changes to the financial transaction system is a problem to be solved. SUMMARY

[0003] In view of the above problems, the present application provides a risk assessment method, device, equipment, medium and program product.

[0004] According to a first aspect of the present application, a risk assessment method is provided, comprising: in response to an evaluation request, simulating execution of a change instruction to obtain a simulation execution result, the change instruction indicating at least one transaction parameter to be changed, the simulation execution result including at least one of the at least one changed transaction parameter and transaction data simulated based on the at least one changed transaction parameter; guiding a target large model to process the change instruction and the simulation execution result based on a first prompt word to obtain a risk assessment result of the change instruction, the first prompt word including an evaluation strategy preset based on the at least one transaction parameter.

[0005] According to an embodiment of the present application, in response to the evaluation request, simulating execution of the change instruction to obtain the simulation execution result comprises: in response to the evaluation request, calling a simulation environment to process the change instruction to simulate execution of at least one of the following: changing the at least one transaction parameter; simulating a transaction process based on the at least one changed transaction parameter, the simulation environment being consistent with a production environment in which real transactions are executed.

[0006] According to an embodiment of the present application, in the case of simulating a transaction process based on the at least one changed transaction parameter, the method further comprises: in the case of obtaining authorization, matching target behavior data from a candidate behavior set based on the at least one transaction parameter, the candidate behavior set including transaction behavior of a target object in a real transaction; guiding the target large model to process the target behavior data based on a second prompt word to generate simulation behavior data, the simulation behavior data indicating simulation transaction actions in the simulation transaction process, the second prompt word including a behavior simulation strategy obtained based on at least one of a target object role, a target object behavior, a change parameter association and a transaction type.

[0007] According to an embodiment of the present application, the method further comprises: obtaining the risk assessment result of the change instruction based on the first prompt word guiding the target large model to process the change instruction and the simulation execution result comprises: processing the change instruction and the simulation execution result by using the target large model, identifying a target change result, the target change result comprising at least one of a field addition, a field deletion, a data type modification, a specific dependency relationship change, a database performance, a specific transaction type, specific transaction process data and a specific transaction result; processing the target change result based on an evaluation strategy by using the target large model to generate a risk assessment result with an inference logic chain.

[0008] According to an embodiment of the present application, the method further comprises: obtaining the risk assessment result of the change instruction based on the first prompt word guiding the target large model to process the change instruction and the simulation execution result comprises: processing the change instruction and the simulation execution result by using the target large model, identifying a target change result, the target change result comprising at least one of a field addition, a field deletion, a data type modification, a specific dependency relationship change, a database performance, a specific transaction type, specific transaction process data and a specific transaction result; processing the target change result based on an evaluation strategy by using the target large model to generate a risk assessment result with an inference logic chain.

[0009] According to an embodiment of the present application, before the method of obtaining the risk assessment result of the change instruction based on the first prompt word guiding the target large model to process the change instruction and the simulation execution result, the method further comprises: evaluating the simulation execution result based on at least one preset evaluation rule to obtain an initial evaluation result; in a case where the initial evaluation result is a specific result, inputting the simulation execution result into the target large model; or, in a case where the initial evaluation result is a non-specific result, taking the initial evaluation result as the risk assessment result of the change instruction, the specific result being determined according to an evaluation range of the at least one preset evaluation rule.

[0010] According to an embodiment of the present application, the method further comprises: obtaining the risk assessment result of the change instruction based on the first prompt word guiding the target large model to process the change instruction and the simulation execution result comprises: obtaining a matched compliance knowledge fragment from a compliance knowledge base based on the change instruction and the simulation execution result, the compliance knowledge base comprising compliance knowledge content obtained according to a transaction business associated with at least one transaction parameter; performing a compliance check on the change instruction and the simulation execution result based on a compliance evaluation strategy in the evaluation strategy and the compliance knowledge fragment by using the target large model to obtain the risk assessment result of the change instruction.

[0011] The second aspect of the present application provides a risk assessment device, comprising: a simulation execution module, configured to simulate execution of a change instruction in response to an assessment request, to obtain a simulation execution result, wherein the change instruction indicates at least one transaction parameter to be changed, and the simulation execution result comprises at least one of the changed at least one transaction parameter and transaction data simulated based on the changed at least one transaction parameter; and a risk assessment module, configured to guide a target large model to process the change instruction and the simulation execution result based on a first prompt word, to obtain a risk assessment result of the change instruction, wherein the first prompt word comprises an evaluation strategy preset based on the at least one transaction parameter.

[0012] The third aspect of the present application provides an electronic device, comprising: one or more processors; and a memory for storing one or more computer programs, wherein the one or more processors execute the one or more computer programs to implement the steps of the method.

[0013] The fourth aspect of the present application further provides a computer-readable storage medium having stored thereon a computer program or instructions, wherein the computer program or instructions are executed by a processor to implement the steps of the method.

[0014] The fifth aspect of the present application further provides a computer program product comprising a computer program or instructions, wherein the computer program or instructions are executed by a processor to implement the steps of the method.

[0015] The one or more embodiments described above can at least achieve the following technical effects: simulating execution of the change instruction in advance can avoid risks caused by direct execution in a real transaction environment. The target large model is not limited to limited information of the change instruction, but can obtain more rich information from the simulated transaction process and transaction result before and after the change transaction parameter, and effectively improve the reliability of the risk assessment result of the change instruction generated by the target large model in combination with the evaluation strategy preset based on the transaction parameter. BRIEF DESCRIPTION OF DRAWINGS

[0016] The above and other objects, features and advantages of the present application will become more apparent from the following description of the embodiments of the present application, taken in conjunction with the accompanying drawings, in which:

[0017] Figure 1 A scenario diagram of application of a risk assessment method according to an embodiment of the present application is schematically shown;

[0018] Figure 2 A flowchart of a risk assessment method according to an embodiment of the present application is schematically shown;

[0019] Figure 3 A flowchart of a risk assessment method according to another embodiment of the present application is schematically shown;

[0020] Figure 4 FIG. 1 illustrates a flowchart of generating a risk assessment result with a chain of reasoning logic according to an embodiment of the present application;

[0021] Figure 5 FIG. 2 illustrates a flowchart of generating a risk assessment result with a chain of reasoning logic according to another embodiment of the present application;

[0022] Figure 6 FIG. 3 illustrates a flowchart of filtering an assessment according to an embodiment of the present application;

[0023] Figure 7 FIG. 4 illustrates a flowchart of obtaining a risk assessment result for compliance according to an embodiment of the present application;

[0024] Figure 8 FIG. 5 illustrates a block diagram of a risk assessment apparatus according to an embodiment of the present application; and

[0025] Figure 9 FIG. 6 illustrates a block diagram of an electronic device suitable for implementing a risk assessment method according to an embodiment of the present application; DETAILED DESCRIPTION

[0026] Hereinafter, embodiments of the present application will be described with reference to the accompanying drawings. It should be understood, however, that the description which follows is merely illustrative and is not intended to limit the scope of the present application. In the following detailed description of embodiments of the present application, numerous specific details are set forth in order to provide a thorough understanding of the present application. However, it will be apparent to one skilled in the art that one or more embodiments of the present application can be practiced without these specific details. In other instances, well-known structures and functions have not been described in detail in order to avoid obscuring aspects of the present application.

[0027] The terms used herein are merely used to describe specific embodiments and are not intended to limit the present application. The terms "include", "comprise", and the like used herein indicate the presence of the features, steps, operations, and / or components, but do not exclude the presence or addition of one or more other features, steps, operations, or components.

[0028] All terms used herein, including technical and scientific terms, have the same meanings as those generally understood by those skilled in the art, unless otherwise defined. It should be noted that the terms used herein should be interpreted as having meanings consistent with the context of the present specification, and should not be interpreted in an idealized or overly formal manner.

[0029] In the case of using expressions similar to "at least one of A, B, and C, etc.", it is generally intended to include any of A, B, and C alone, or a combination of A, B, and C, etc. For example, "a system having at least one of A, B, and C" is intended to include a system having A alone, a system having B alone, a system having C alone, a system having A and B together, a system having A and C together, a system having B and C together, and / or a system having A, B, and C together, etc.

[0030] In the technical solutions of the present application, the user information (including but not limited to user personal information, user image information, user equipment information, such as location information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved are all information and data authorized by the user or authorized by all parties, and the collection, storage, use, processing, transmission, provision, disclosure and application of related data comply with relevant laws, regulations and standards, necessary security measures are taken, do not violate public order and good customs, and provide corresponding operation portal for user to choose authorization or refusal.

[0031] In the scenario of using personal information for automated decision-making, the method, device and system provided by the embodiments of the present application all provide corresponding operation portal for the user to choose to agree or refuse the automated decision-making result; if the user chooses to refuse, the expert decision-making process is entered. The expression "automated decision-making" here refers to the activity of automatically analyzing, evaluating the behavior habits, interests and hobbies, or economic, health, credit status, etc. of a person through a computer program, and making decisions. The expression "expert decision-making" here refers to the activity of making decisions by personnel who are engaged in a certain field of work, have special experience, knowledge and skills, and reach a certain professional level.

[0032] Figure 1 The application scenario diagram of the risk assessment method according to the embodiments of the present application is schematically shown.

[0033] As shown in Figure 1 The application scenario 100 according to the embodiments can include a first terminal device 101, a second terminal device 102, a third terminal device 103, a network 104 and a server 105. The network 104 is used to provide a communication link medium between the first terminal device 101, the second terminal device 102, the third terminal device 103 and the server 105. The network 104 can include various connection types, such as wired, wireless communication links or optical fiber cables, etc.

[0034] Users can use the first terminal device 101, the second terminal device 102, and the third terminal device 103 to interact with the server 105 via the network 104 to receive or send messages, etc. Various communication client applications can be installed on the first terminal device 101, the second terminal device 102, and the third terminal device 103, such as shopping applications, web browser applications, search applications, instant messaging tools, email clients, social media platform software, etc. (for example only).

[0035] The first terminal device 101, the second terminal device 102, and the third terminal device 103 can be various electronic devices with displays and support web browsing, including but not limited to smartphones, tablets, laptops, and desktop computers.

[0036] Server 105 can be a server that provides various services, such as a backend management server that supports websites browsed by users using the first terminal device 101, the second terminal device 102, and the third terminal device 103 (this is just an example). The backend management server can analyze and process data such as received user requests, and feed back the processing results (such as web pages, information, or data obtained or generated according to user requests) to the terminal devices.

[0037] It should be noted that the risk assessment method provided in this application embodiment can generally be executed by server 105. Correspondingly, the risk assessment device provided in this application embodiment can generally be located in server 105. The risk assessment method provided in this application embodiment can also be executed by a server or server cluster that is different from server 105 and capable of communicating with the first terminal device 101, the second terminal device 102, the third terminal device 103, and / or server 105. Correspondingly, the risk assessment device provided in this application embodiment can also be located in a server or server cluster that is different from server 105 and capable of communicating with the first terminal device 101, the second terminal device 102, the third terminal device 103, and / or server 105.

[0038] It should be understood that Figure 1 The number of terminal devices, networks, and servers shown is merely illustrative. Depending on implementation needs, any number of terminal devices, networks, and servers can be included.

[0039] The following will be based on Figure 1 The described scene, through Figures 2-7 The risk assessment method according to the embodiments of this application will be described in detail.

[0040] Figure 2 A flowchart illustrating a risk assessment method according to an embodiment of this application is shown.

[0041] likeFigure 2 As shown, the risk assessment method of this embodiment includes operation S210 to operation S220, which can be executed by the server 105.

[0042] In operation S210, in response to the evaluation request, the simulation execution instruction is executed to obtain a simulation execution result, wherein the change instruction indicates at least one transaction parameter to be changed, and the simulation execution result includes at least one of the changed at least one transaction parameter and transaction data simulated based on the changed at least one transaction parameter.

[0043] For example, the evaluation request can be initiated by a user or automatically generated by the server 105. The change instruction can be an instruction that specifies the transaction parameter to be modified parsed from the evaluation request. The transaction parameter includes a variable in the financial transaction process, which is used to affect the execution content and execution process of the financial transaction, such as bank transfer transaction, financial transaction and lending transaction, etc. The simulated transaction data can include various data generated in the simulated transaction process and the transaction result, such as data related to the transaction subject, transaction instruction, process state, system interaction and transaction result in the bank transfer transaction.

[0044] In operation S220, the target large model is guided to process the change instruction and the simulation execution result based on the first prompt word, and a risk assessment result of the change instruction is obtained, wherein the first prompt word includes an evaluation strategy preset based on the at least one transaction parameter.

[0045] The prompt engineering can guide the artificial intelligence model to generate more accurate and efficient output by designing and optimizing the input text (prompt word). By inputting the first prompt word into the target large model, the target large model can be guided to generate the risk assessment result according to the preset evaluation strategy. For example, the evaluation strategy can consider safety, accuracy and efficiency, etc., which can include evaluation dimensions such as table structure, table data, transaction compliance, transaction process, performance impact of hardware and software in the transaction process, etc. The risk assessment result can quantify or describe the risk of the change instruction, such as risk level, probability value or text description, etc.

[0046] The large model refers to a deep learning model with large-scale model parameters. The large model usually contains tens of billions, hundreds of billions, thousands of billions, ten thousand billions or even more than one hundred thousand billions of model parameters. The large model can include a large language model (LLM), a visual large model, a multi-modal large model, etc. The large model involved in the embodiments of the present application can be a general large model, or can also be a specialist large model obtained by fine tuning based on requirements, which is not limited by the embodiments of the present application. For example, the target large model can include a general large model, or can also be a specialist large model obtained by fine tuning based on the evaluation requirements of the change instruction.

[0047] According to the embodiments of the present application, the change instruction is simulated in advance, which can avoid the risk caused by directly executing in the real transaction environment. The target large model is not limited to the limited information of the change instruction, but can obtain more rich information from the simulated transaction process and transaction result before and after the change of the transaction parameter, and combine the evaluation strategy based on the preset transaction parameter to effectively improve the reliability of the risk evaluation result of the change instruction generated by the target large model.

[0048] In some embodiments, in response to the evaluation request, the change instruction is simulated to obtain a simulation execution result, which includes: in response to the evaluation request, calling the simulation environment to process the change instruction to simulate at least one of the following: changing at least one transaction parameter; simulating a transaction process based on the changed at least one transaction parameter, and the simulation environment is consistent with the production environment for executing real transactions.

[0049] For example, in the bank transaction system operation and maintenance scenario, the change of the database table is involved, and the operation and maintenance personnel usually need to have high-level professional skills to manually audit the database table structure. However, the embodiments of the present application can create a simulation environment as a sandbox, replicate the same database and interface of the production environment for simulation, such as the change operation of the database table and the subsequent transfer operation. The production environment refers to the environment for actually running the transaction system to process real transactions and data. The simulation transaction process includes the transaction steps virtually executed in the simulation environment, such as including order submission, matching and execution, etc.

[0050] According to the embodiments of the present application, the simulation environment consistent with the production environment can improve the consistency of the real change of the transaction parameter and the real execution of the transaction process after the change, improve the evaluation accuracy of the target large model, and reduce the risk of problems in the execution of real transactions.

[0051] Figure 3 The flowchart of the risk evaluation method according to another embodiment of the present application is schematically shown.

[0052] As shown in Figure 3 In the case of simulating the transaction process based on the changed at least one transaction parameter, the risk evaluation method of this embodiment includes:

[0053] In operation S310, in the case of obtaining authorization, the target behavior data is matched from the candidate behavior set based on the at least one transaction parameter, and the candidate behavior set includes the transaction behavior of the target object in the real transaction.

[0054] In the embodiments of the present application, a corresponding operation portal can be provided for the user to select to agree or reject the automatic decision result. That is, before the transaction behavior of the real transaction is collected, the instruction of the user input through the corresponding operation portal to agree or reject the processing / decision can be obtained. If the user agrees to process / decide, the transaction behavior of the real transaction of the user is collected. If the user refuses to process / decide, the transaction behavior of the real transaction of the user is not collected.

[0055] In operation S320, the target large model LLM 301 is guided to process the target behavior data based on the second prompt word to generate simulated behavior data, and the simulated behavior data indicates simulated transaction actions in a simulated transaction process. The second prompt word includes a behavior simulation strategy obtained based on at least one of a target object role, a target object behavior, a change parameter association, and a transaction type.

[0056] Exemplarily, the candidate behavior set stores the behavior records of the target object (such as a user or an entity) generated in the real transaction, for example, the transaction behavior of the target object in the real transaction can be obtained by recording, burying points, and the like. The target behavior data includes specific behavior records selected from the candidate behavior set, representing real behaviors related to the current simulation scene, as input for generating simulation data, such as through similarity calculation (such as cosine similarity) or a rule engine (such as if-then rule), the most relevant record is retrieved from the candidate behavior set based on the transaction parameter (such as the price range). The behavior simulation strategy is used to construct the second prompt word, which is constructed based on at least one of the target object role (such as user identity), the target object behavior (such as transaction habit), the change parameter association (such as how A parameter change affects B parameter), and the transaction type (such as transfer transaction). By introducing real behavior data, the simulation process is closer to the actual scene.

[0057] Referring to Figure 3 According to the change instruction in the evaluation request, the transaction parameter can be simulated to change in the simulation environment, and the simulated transaction can be performed in the simulation environment based on the simulated behavior data. Then, the change instruction and the simulation execution result are input into the target large model LLM 301 to obtain the risk evaluation result.

[0058] According to the embodiments of the present application, by matching the target behavior data from the candidate behavior set, and guided by the behavior simulation strategy of the second prompt word, the target large model outputs the simulated behavior data based on the real transaction matching the transaction parameter, which is closer to the actual scene.

[0059] Figure 4 A flowchart of generating a risk evaluation result with an inference logic chain according to an embodiment of the present application is schematically shown.

[0060] As Figure 4As shown, the embodiment generates a risk assessment result with a reasoning logic chain, which includes:

[0061] In operation S410, the target change result is identified by processing the change instruction and the simulation execution result using the target large model, and the target change result includes at least one of field addition, field deletion, data type modification, specific dependency relationship change, database performance, specific transaction type, specific transaction process data, and specific transaction result.

[0062] In operation S420, the target change result is processed based on the evaluation strategy using the target large model to generate a risk assessment result with a reasoning logic chain.

[0063] For example, during the update of the balance of a bank account, the database table structure is generally changed, that is, the table storing account information in the database is modified. For example, when a developer modifies a transaction database (such as adding a new field or changing the data type) in a bank system upgrade, the change execution is automatically simulated, and the risk is evaluated using a reasoning logic chain. For example, the change instruction is “modify the ‘transaction amount’ field from integer to float”, and the simulation execution result shows that the query delay is increased.

[0064] The reasoning logic chain refers to the reasoning process generated by the target large model to explain the causal relationship of risk assessment in a logical sequence (such as step A leads to step B). The logic chain can enhance the explainability of the result. For example, the evaluation strategy includes one or more pre-set risk assessment questions and the corresponding reasoning thought chain of each question, which consists of a series of intermediate reasoning steps (i.e. reasons) and expected answers. The target large model can refer to the output of the risk assessment result with a reasoning logic chain.

[0065] The target change result includes the change key points identified by the target large model. For example, field addition includes adding a new data field, such as adding a “discount rate” field. Field deletion includes removing an existing field, such as deleting a “transaction ID” field. Data type modification includes changing the data type of a field, such as changing from “integer” to “string”. Specific dependency relationship change includes modifying the dependency between data, business processes, or systems, such as changing the association between the transaction table and the user table. Database performance includes changes that affect database efficiency, such as index modification causing slow queries. Specific transaction type includes changes related to specific transaction categories, such as “stocks” or “futures”. Specific transaction process data includes data that affects the transaction execution process, such as order processing log changes. Specific transaction result includes data that affects the transaction output result, such as settlement amount changes.

[0066] For example, the target large model performs syntax and semantic analysis on the input SQL (Structured Query Language) statement, accurately identifies the type of the statement and its target table. Then, the target large model performs target change result identification, focusing on important changes in the statement, including the addition, deletion, and data type modification of fields, etc.

[0067] Then, the target large model performs impact assessment on each identified target change result, predicting its potential impact on the existing database. For example, adding a field may lead to adjustment of the existing index design, deleting a field may affect the query logic and view that depend on the field, and data type modification may affect data storage and retrieval efficiency.

[0068] Then, the target large model also performs dependency analysis, carefully checking the dependencies between the change statement and other objects in the database, such as foreign key constraints, triggers, and stored procedures, etc. Ensuring that the change operation does not damage the integrity and consistency of the database.

[0069] In terms of performance, the target large model predicts the potential impact of the change on the performance of the database, including query response time, transaction processing speed, and lock contention, etc. The target large model also performs security assessment on the change statement to identify the potential SQL injection risk, and ensures that the change does not affect the encryption and desensitization of data, thereby ensuring data security.

[0070] According to the embodiments of the present application, the target large model identifies the target change result, and then generates a reasoning logic chain to provide causal analysis, enhance explainability, and make the result more credible, which is beneficial to reduce misjudgment.

[0071] Figure 5 The flowchart of generating a risk assessment result with a reasoning logic chain according to another embodiment of the present application is schematically shown.

[0072] As shown in Figure 5 , the embodiment of generating a risk assessment result with a reasoning logic chain includes:

[0073] In operation S510, the target change result is parsed by the target large model to obtain at least one change element.

[0074] In operation S520, the target large model writes the at least one change element into the reasoning logic chain template of the evaluation strategy to obtain a risk assessment result with a reasoning logic chain, and the reasoning logic chain template is determined based on the transaction business process associated with the at least one transaction parameter.

[0075] The change elements include key data units extracted from the target change result, such as change instructions, field names, performance indicators, and the like. The reasoning logic chain template includes a predefined text framework containing placeholders and logical relationship descriptions, for generating a risk assessment result with causal reasoning. For example, “If {change element 1}, then {impact 1}; and further cause {risk 1}”. For example, after filling in, it is “If a new commission fee field is added, the transaction calculation time is increased; and further cause the timeout risk to increase”. The transaction business process includes a standardized operation sequence (such as order placement → payment → settlement) of a specific transaction type, for determining the logical relationship structure of the reasoning logic chain.

[0076] According to an embodiment of the present application, the reasoning logic chain is predefined based on the business process (such as the payment process), and the change elements are filled in to generate an interpretable risk assessment result, solving the randomness problem of the model output, so that the risk assessment result conforms to the business logic.

[0077] Figure 6 A flowchart of filtering evaluation according to an embodiment of the present application is schematically shown.

[0078] As shown in Figure 6 Before the target large model is guided to process the change instruction and the simulation execution result based on the first prompt word, filtering evaluation can also be performed to reduce the data amount processed by the target large model, specifically including:

[0079] In operation S610, the simulation execution result is evaluated based on at least one preset evaluation rule to obtain an initial evaluation result.

[0080] In operation S620, it is determined whether the initial evaluation result is a specific result. If yes, operation S630 is performed, and if no, operation S640 is performed.

[0081] In operation S630, in the case where the initial evaluation result is the specific result, the simulation execution result is input into the target large model.

[0082] In operation S640, in the case where the initial evaluation result is a non-specific result, the initial evaluation result is taken as the risk assessment result of the change instruction. The specific result is determined according to the evaluation range of the at least one preset evaluation rule.

[0083] The preset evaluation rule includes a predefined logical condition or threshold value, for quickly evaluating the risk of the simulation execution result and reducing unnecessary large model calls. The initial evaluation result includes a preliminary judgment of the simulation execution result through the preset rule, such as “low risk” (no need to call the large model) for the simulation execution result of “delay 8 ms (milliseconds)”. The specific result includes a conclusion (such as “high risk” or “uncertain”) determined by the preset rule that the large model needs to be involved.

[0084] According to the embodiment of the present application, the pre-evaluation stage with filtering effect is passed in advance, the risk level of the simulation result is quickly judged based on the evaluation rule, frequent calling of the large model can be avoided, the waste of computing resources is reduced, and the evaluation efficiency can be improved.

[0085] Figure 7 A flowchart of obtaining a risk evaluation result for compliance is schematically shown according to the embodiment of the present application.

[0086] As Figure 7 shown, the embodiment of obtaining a risk evaluation result for compliance can include:

[0087] In operation S710, matched compliance knowledge fragments are obtained from a compliance knowledge base based on the change instruction and the simulation execution result, and the compliance knowledge base includes compliance knowledge content obtained according to at least one transaction parameter associated with a transaction business.

[0088] In operation S720, the target large model is used to perform compliance checking on the change instruction and the simulation execution result based on a compliance evaluation strategy in the evaluation strategy and the compliance knowledge fragments, and a risk evaluation result of the change instruction is obtained.

[0089] Exemplarily, the compliance knowledge base includes a structured database or a knowledge graph, and stores compliance content such as laws and regulations, industry standards, and regulatory provisions related to a specific transaction business. The compliance knowledge fragments include specific provisions or rule paragraphs matched from the compliance knowledge base, and are related to the change instruction and the simulation result (such as data privacy clauses), such as using a semantic retrieval algorithm to match relevant provisions from the knowledge base. The compliance evaluation strategy is used for compliance checking, for example, guiding the model to judge whether it complies with the compliance knowledge fragments. For example, the change instruction is “add a cross-border transfer field”, and the simulation result shows “cross-border transfer failure”. The matched compliance knowledge fragments are “cross-border data encryption related content”.

[0090] According to the embodiment of the present application, the technical change can be accurately associated with the compliance requirements according to dynamic matching of the compliance requirements, so that the change instruction, the change to the transaction parameter, and the change of the transaction process triggered thereby have compliance, and based on the target large model fusing the compliance knowledge fragments, whether the change is compliant is accurately analyzed based on the compliance evaluation strategy.

[0091] Based on the above risk evaluation method, the present application further provides a risk evaluation device. The device will be described in detail below. Figure 8

[0092] Figure 8 A structural block diagram of a risk evaluation device according to an embodiment of the present application is schematically shown.

[0093] As Figure 8 ​As shown, the risk assessment apparatus 800 of this embodiment includes a simulation execution module 810 and a risk assessment module 820.

[0094] The simulation execution module 810 can perform operation S210 for simulating execution of the change instruction in response to the assessment request, to obtain a simulation execution result, wherein the change instruction indicates at least one transaction parameter to be changed, and the simulation execution result includes at least one of the changed at least one transaction parameter and transaction data simulated based on the changed at least one transaction parameter.

[0095] The risk assessment module 820 can perform operation S220 for guiding the target large model to process the change instruction and the simulation execution result based on a first prompt word, to obtain a risk assessment result of the change instruction, wherein the first prompt word includes an assessment strategy preset based on the at least one transaction parameter.

[0096] In some embodiments, the simulation execution module 810 can further respond to the assessment request to call a simulation environment to process the change instruction, to simulate execution of at least one of the following: changing the at least one transaction parameter; and simulating a transaction process based on the changed at least one transaction parameter, wherein the simulation environment is consistent with a production environment for executing real transactions.

[0097] In some embodiments, the risk assessment apparatus 800 can further include a simulation strategy module for, in the case of authorization, matching target behavior data from a candidate behavior set based on the at least one transaction parameter, wherein the candidate behavior set includes transaction behaviors of the target object in real transactions; and guiding the target large model to process the target behavior data based on a second prompt word, to generate simulation behavior data, wherein the simulation behavior data indicates simulation transaction actions in the simulation transaction process, and the second prompt word includes a behavior simulation strategy obtained based on at least one of a target object role, a target object behavior, a change parameter association, and a transaction type.

[0098] In some embodiments, the risk assessment module 820 can further utilize the target large model to process the change instruction and the simulation execution result, to identify a target change result, wherein the target change result includes at least one of field addition, field deletion, data type modification, specific dependency relationship change, database performance, specific transaction type, specific transaction process data, and specific transaction result; and utilize the target large model to process the target change result based on the assessment strategy, to generate a risk assessment result with an inference logic chain.

[0099] In some embodiments, the risk assessment module 820 can further utilize the target large model to analyze the target change result, to obtain at least one change element; and utilize the target large model to write the at least one change element into an inference logic chain template of the assessment strategy, to obtain a risk assessment result with an inference logic chain, wherein the inference logic chain template is determined based on a transaction business process associated with the at least one transaction parameter.

[0100] In some embodiments, the risk assessment device 800 can further include a filtering module configured to evaluate the simulation execution result based on at least one preset evaluation rule to obtain an initial evaluation result; in a case where the initial evaluation result is a specific result, input the simulation execution result into the target large model; or in a case where the initial evaluation result is a non-specific result, take the initial evaluation result as the risk assessment result of the change instruction, the specific result being determined according to an evaluation range of the at least one preset evaluation rule.

[0101] In some embodiments, the risk assessment module 820 can be further configured to obtain a matched compliance knowledge fragment from a compliance knowledge base based on the change instruction and the simulation execution result, the compliance knowledge base including compliance knowledge content obtained according to a transaction business associated with the at least one transaction parameter; and perform a compliance check on the change instruction and the simulation execution result based on a compliance evaluation strategy in the evaluation strategies and the compliance knowledge fragment to obtain the risk assessment result of the change instruction.

[0102] According to embodiments of the present application, any of the plurality of modules in the simulation execution module 810 and the risk assessment module 820 can be combined in one module, or any of the plurality of modules can be split into a plurality of modules. Alternatively, at least part of the functions of one or more of the modules can be combined with at least part of the functions of other modules, and implemented in one module. According to embodiments of the present application, at least one of the simulation execution module 810 and the risk assessment module 820 can be at least partially implemented as a hardware circuit, such as a field programmable gate array (FPGA), a programmable logic array (PLA), a system on chip, a system on board, a system on package, an application specific integrated circuit (ASIC), or any other reasonable manner of integrating or packaging a circuit, etc. hardware or firmware, or in any one of software, hardware and firmware or in any appropriate combination of any of them. Alternatively, at least one of the simulation execution module 810 and the risk assessment module 820 can be at least partially implemented as a computer program module that can perform corresponding functions when the computer program module is run.

[0103] Figure 9 A block diagram of an electronic device suitable for implementing the risk assessment method according to embodiments of the present application is schematically shown.

[0104] As Figure 9As shown, the electronic device 900 according to an embodiment of the present application includes a processor 901 which can perform various appropriate actions and processes according to a program stored in a read only memory (ROM) 902 or a program loaded from a storage section 908 into a random access memory (RAM) 903. The processor 901 can include, for example, a general purpose microprocessor (e.g., a CPU), an instruction set processor, and / or a related chipset, and / or a special purpose microprocessor (e.g., an application specific integrated circuit (ASIC)), and so on. The processor 901 can also include an on-board memory for cache use. The processor 901 can include a single processing unit or multiple processing units for executing different actions of the method processes according to embodiments of the present application.

[0105] In the RAM 903, various programs and data required for the operation of the electronic device 900 are stored. The processor 901, the ROM 902, and the RAM 903 are connected to each other via a bus 904. The processor 901 performs various operations of the method processes according to embodiments of the present application by executing the programs in the ROM 902 and / or the RAM 903. Note that the programs can also be stored in one or more memories other than the ROM 902 and the RAM 903. The processor 901 can also perform various operations of the method processes according to embodiments of the present application by executing the programs stored in the one or more memories.

[0106] According to embodiments of the present application, the electronic device 900 can also include an input / output (I / O) interface 905 which is also connected to the bus 904. The electronic device 900 can also include one or more of the following components connected to the input / output (I / O) interface 905: an input section 906 including a keyboard, a mouse, etc.; an output section 907 including a display such as a cathode ray tube (CRT), a liquid crystal display (LCD), etc., and a speaker, etc.; a storage section 908 including a hard disk, etc.; and a communication section 909 including a network interface card such as a LAN card, a modem, etc. The communication section 909 performs communication processing via a network such as the Internet. A drive 910 is also connected to the input / output (I / O) interface 905 as necessary. A removable medium 911 such as a magnetic disk, a magneto-optical disk, a semiconductor memory, etc. is attached to the drive 910 as necessary, so that a computer program read out from the removable medium 911 is installed in the storage section 908 as necessary.

[0107] The application further provides a computer readable storage medium, which can be included in the device / apparatus / system described in the above embodiments, or can exist independently without being assembled into the device / apparatus / system. The computer readable storage medium carries one or more programs, which, when executed, implement the method according to the embodiments of the application.

[0108] According to the embodiments of the application, the computer readable storage medium can be a non-volatile computer readable storage medium, which can include, but is not limited to, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any appropriate combination thereof. In this application, a computer readable storage medium can be any tangible medium that contains or stores a program for use by or in connection with an instruction execution system, apparatus, or device. For example, according to the embodiments of the application, the computer readable storage medium can include one or more of the above-described ROM 902 and / or RAM 903 and / or one or more memories other than the ROM 902 and the RAM 903.

[0109] The embodiments of the application also include a computer program product, which includes a computer program containing program codes for executing the method shown in the flow chart. When the computer program product is run in a computer system, the program codes are used to make the computer system implement the risk assessment method provided by the embodiments of the application.

[0110] The above-described functions defined in the system / apparatus of the embodiments of the application are performed when the computer program is executed by the processor 901. According to the embodiments of the application, the above-described system, apparatus, module, unit, etc. can be implemented by computer program modules.

[0111] In one embodiment, the computer program can rely on a tangible storage medium such as an optical storage device, a magnetic storage device, etc. In another embodiment, the computer program can also be transmitted, distributed, and downloaded in the form of a signal on a network medium, and be downloaded and installed through the communication part 909, and / or installed from the detachable medium 911. The program codes contained in the computer program can be transmitted by any appropriate network medium, including but not limited to wireless, wired, etc., or any appropriate combination thereof.

[0112] In such embodiments, the computer program can be downloaded and installed from the network via the communication section 909, and / or installed from the removable media 911. When the computer program is executed by the processor 901, the above-described functions defined in the system of the embodiments of the present application are performed. According to the embodiments of the present application, the system, device, apparatus, module, unit, and the like described above can be implemented by the computer program modules.

[0113] According to the embodiments of the present application, the program code for executing the computer program provided by the embodiments of the present application can be written in any combination of one or more programming languages, and specifically, these computer programs can be implemented using high-level procedural and / or object-oriented programming language, and / or assembly / machine language. The programming language includes, but is not limited to, such as Java, C++, python, "C" language, or similar programming language. The program code can be executed entirely on the user computing device, partially on the user device, partially on a remote computing device, or entirely on a remote computing device or server. In the case involving a remote computing device, the remote computing device can be connected to the user computing device through any kind of network, including a local area network (LAN) or a wide area network (WAN), or can be connected to an external computing device (for example, connected to the Internet through an Internet service provider).

[0114] The flowcharts and block diagrams in the drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of the present application. In this regard, each block in the flowcharts or block diagrams can represent a module, a program segment, or a portion of code, which contains one or more executable instructions for implementing the specified logical functions. It should also be noted that in some alternative implementations, the functions noted in the blocks can occur in a different order than that shown in the figures. For example, two blocks noted in succession can actually be executed substantially concurrently, or they can sometimes be executed in reverse order, depending on the functionality involved. It should also be noted that each block in the flowcharts or block diagrams, and combinations of blocks in the flowcharts or block diagrams, can be implemented by dedicated hardware-based systems that perform the specified functions or operations, or can be implemented by a combination of dedicated hardware and computer instructions.

[0115] Those skilled in the art can understand that the features described in various embodiments of the present application can be combined and / or integrated in various combinations and / or integrations, even if such combinations or integrations are not explicitly described in the present application. In particular, the features described in various embodiments of the present application can be combined and / or integrated in various combinations and / or integrations without departing from the spirit and teachings of the present application. All such combinations and / or integrations fall within the scope of the present application.

Claims

1. A risk assessment method, comprising: in response to an assessment request, simulating execution of a change instruction to obtain a simulation execution result, the change instruction indicating at least one transaction parameter to be changed, and the simulation execution result including at least one of the changed at least one transaction parameter and transaction data simulated based on the changed at least one transaction parameter; directing a target large model to process the change instruction and the simulation execution result based on a first prompt word to obtain a risk assessment result of the change instruction, the first prompt word including an evaluation strategy preset based on the at least one transaction parameter.

2. The method of claim 1, wherein, The response to the assessment request, simulating execution of the change instruction to obtain a simulation execution result includes: in response to the assessment request, calling a simulation environment to process the change instruction to simulate execution of at least one of: changing the at least one transaction parameter; simulating a transaction process based on the changed at least one transaction parameter, the simulation environment being consistent with a production environment for executing real transactions.

3. The method of claim 2, wherein, In the case of simulating a transaction process based on the changed at least one transaction parameter, the method further comprises: in the case of obtaining authorization, matching target behavior data from a candidate behavior set based on the at least one transaction parameter, the candidate behavior set including transaction behavior of a target object in a real transaction; directing the target large model to process the target behavior data based on a second prompt word to generate simulation behavior data, the simulation behavior data indicating simulation transaction actions in the simulation transaction process, and the second prompt word including a behavior simulation strategy based on at least one of a target object role, a target object behavior, a change parameter association, and a transaction type.

4. The method of claim 1, wherein, The directing the target large model to process the change instruction and the simulation execution result based on the first prompt word to obtain the risk assessment result of the change instruction includes: processing the change instruction and the simulation execution result using the target large model to identify a target change result, the target change result including at least one of field addition, field deletion, data type modification, specific dependency relationship change, database performance, specific transaction type, specific transaction process data, and specific transaction result; processing the target change result based on the evaluation strategy using the target large model to generate a risk assessment result with an inference logic chain.

5. The method of claim 4, wherein, The processing the target change result based on the evaluation strategy using the target large model to generate a risk assessment result with an inference logic chain includes: analyzing the target change result using the target large model to obtain at least one change element; writing the at least one change element into an inference logic chain template of the evaluation strategy using the target large model to obtain a risk assessment result with an inference logic chain, the inference logic chain template being determined based on a transaction business process associated with the at least one transaction parameter.

6. The method of claim 1, wherein, Before the directing the target large model to process the change instruction and the simulation execution result based on the first prompt word, the method further comprises: evaluating the simulation execution result based on at least one preset evaluation rule to obtain an initial evaluation result; In a case where the initial evaluation result is a specific result, the simulation execution result is input into the target large model; or in a case where the initial evaluation result is a non-specific result, the initial evaluation result is taken as a risk evaluation result of the change instruction, and the specific result is determined according to an evaluation range of the at least one preset evaluation rule.

7. The method of claim 1, wherein, The risk evaluation result of the change instruction is obtained by guiding the target large model to process the change instruction and the simulation execution result based on the first prompt word, and the obtaining comprises: obtaining a matched compliance knowledge fragment from a compliance knowledge base based on the change instruction and the simulation execution result, the compliance knowledge base comprising compliance knowledge content obtained according to a transaction business associated with the at least one transaction parameter; performing compliance checking on the change instruction and the simulation execution result based on a compliance evaluation strategy in the evaluation strategy and the compliance knowledge fragment by using the target large model, to obtain the risk evaluation result of the change instruction.

8. A risk evaluation device, comprising: a simulation execution module configured to simulate execution of a change instruction in response to an evaluation request to obtain a simulation execution result, wherein the change instruction indicates at least one transaction parameter to be changed, and the simulation execution result comprises at least one of the changed at least one transaction parameter and transaction data simulated based on the changed at least one transaction parameter; a risk evaluation module configured to guide a target large model to process the change instruction and the simulation execution result based on a first prompt word to obtain a risk evaluation result of the change instruction, wherein the first prompt word comprises an evaluation strategy preset based on the at least one transaction parameter.

9. An electronic device, comprising: one or more processors; a memory for storing one or more computer programs, characterized in that the one or more processors execute the one or more computer programs to implement the steps of the method according to any one of claims 1-7.

10. A computer readable storage medium having stored thereon a computer program or instructions, characterized in that, The computer program or instructions are executed by the processor to implement the steps of the method according to any one of claims 1-7.

11. A computer program product comprising computer programs or instructions, characterized in that, The computer program or instructions are executed by the processor to implement the steps of the method according to any one of claims 1-7. The computer program or instructions are executed by the processor to implement the steps of the method according to any one of claims 1-7.