Fraudulent call identification method, device and equipment, storage medium and computer program product
By inputting call recordings, SMS content, and data traffic into the Transformer large model, extracting fraud features, and setting thresholds, the problem of low accuracy in fraud call identification in existing technologies is solved, achieving more accurate fraud call identification.
Patent Information
- Application Number
- CN202511110454.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-08
- Publication Date
- 2025-11-07
AI Technical Summary
Existing technologies for identifying fraudulent calls based on objective data are not very accurate, with high false alarm or false negative rates.
By inputting multimodal call content text data (including call recording data, SMS content data, and traffic data) into a preset fraud call identification model, deep learning is performed using a Transformer large model to extract fraud text features, and a fraud feature threshold is used to determine whether the call is a fraudulent call.
It improves the accuracy of fraud call identification, reduces false alarm and false negative rates, and provides a more comprehensive fraud call identification capability.
Smart Images

Figure CN120915876A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of information security, and particularly relates to a fraudulent phone call identification method and device, equipment, a storage medium and a computer program product. BACKGROUND
[0002] With the rapid development of information technology, telephone communication has become an indispensable part of people's daily life. At the same time, fraudulent phone calls are increasing, which not only threatens personal property safety, but also seriously affects social harmony and stability.
[0003] At present, the traditional technical solution for identifying fraudulent phone numbers mainly focuses on the analysis of objective data, such as detecting and analyzing the data of the source of the phone number, call frequency, call time period, etc. to identify whether the phone number is a fraudulent phone number. However, since the objective data cannot comprehensively cover all characteristics of fraudulent behavior, the false positive rate or false negative rate is high, resulting in low accuracy of fraudulent phone call identification. SUMMARY
[0004] The main purpose of the present application is to provide a fraudulent phone call identification method, device, equipment, storage medium and computer program product, which aims to solve the technical problem of low accuracy of fraudulent phone call identification based on objective data in the prior art.
[0005] To achieve the above purpose, the present application provides a fraudulent phone call identification method, which comprises: inputting the multi-modal call content text data corresponding to the to-be-identified phone into a preset fraudulent phone call identification model, wherein the multi-modal call content text data comprises telephone recording data, short message content data and traffic data; acquiring fraudulent text features based on the telephone recording data, the short message content data and the traffic data through the preset fraudulent phone call identification model, wherein the fraudulent text features are features related to fraudulent behavior; judging whether the to-be-identified phone is a fraudulent phone based on the fraudulent text features and a preset fraudulent feature threshold value through the preset fraudulent phone call identification model, obtaining a fraudulent phone call identification result, and determining the preset fraudulent feature threshold value based on the recall rate and the misjudgment rate of the preset fraudulent phone call identification model.
[0006] In an embodiment, the fraudulent text features include user awareness features, tone features and emotion features; the step of judging whether the to-be-identified phone is a fraudulent phone based on the fraudulent text features and a preset fraudulent feature threshold value through the preset fraudulent phone call identification model, and obtaining a fraudulent phone call identification result, comprises: determine first text representation, second text representation and third text representation corresponding to user awareness feature, tone feature and emotion feature in the fraud text feature respectively; map the first text representation, the second text representation and the third text representation to a high-dimensional feature space through the preset fraud phone identification model to generate a high-dimensional feature vector, and the high-dimensional feature vector is used to represent the matching degree between the phone recording data, the short message content data and the traffic data and the fraud behavior feature; determine whether the to-be-identified phone is a fraud phone based on the high-dimensional feature vector and a preset fraud feature threshold to obtain a fraud phone identification result.
[0007] In an embodiment, the step of determining whether the to-be-identified phone is a fraud phone based on the high-dimensional feature vector and a preset fraud feature threshold to obtain a fraud phone identification result comprises: comparing the high-dimensional feature vector with a preset fraud feature threshold; determining whether there is a fraud behavior sentence in the to-be-identified phone according to the comparison result, wherein the fraud behavior sentence includes an inducement sentence, an emergency implication sentence and a special emotion expression sentence; if so, determining that the to-be-identified phone is a fraud phone to obtain a fraud phone identification result.
[0008] In an embodiment, before the step of inputting the multi-modal call content text data corresponding to the to-be-identified phone into a preset fraud phone identification model, the method further comprises: collecting voice sample data, short message content sample data and traffic sample data generated by Internet of Things conversation; performing fraud behavior data labeling on the voice sample data, the short message content sample data and the traffic sample data to obtain voice fraud data, short message content fraud data and traffic fraud data; training an initial fraud phone identification model based on the voice sample data, the short message content sample data, the traffic sample data, the voice fraud data, the short message content fraud data and the traffic fraud data to obtain a preset fraud phone identification model.
[0009] In an embodiment, the step of training an initial fraud phone identification model based on the voice sample data, the short message content sample data, the traffic sample data, the voice fraud data, the short message content fraud data and the traffic fraud data to obtain a preset fraud phone identification model comprises: training an initial fraud phone identification model based on the voice sample data, the short message content sample data, the traffic sample data, the voice fraud data, the short message content fraud data and the traffic fraud data. In the training process, a difference between a prediction result of the initial fraud phone identification model and a true label is determined by a cross-entropy loss function; When the difference reaches a preset difference threshold, a preset fraud phone identification model is obtained.
[0010] In an embodiment, after the step of determining the difference between the prediction result of the initial fraud phone identification model and the true label by the cross-entropy loss function in the training process, the method further comprises: In the training process, a first fraud phone quantity and a second fraud phone quantity in all fraud phones are obtained by the initial fraud phone identification model in real time, the first fraud phone quantity is a quantity of fraud phones correctly judged in the all fraud phones, and the second fraud phone quantity is a quantity of fraud phones misjudged in the all fraud phones; A recall rate of the initial fraud phone identification model is determined according to the first fraud phone quantity; A misjudgment rate of the initial fraud phone identification model is determined according to the second fraud phone quantity; A preset fraud feature threshold is determined based on the recall rate and the misjudgment rate.
[0011] In addition, to achieve the above-mentioned purpose, the present application also provides a fraud phone identification device, which comprises: A data input module is configured to input multi-modal call content text data corresponding to a phone to be identified into a preset fraud phone identification model, wherein the multi-modal call content text data comprises telephone recording data, short message content data and traffic data; A feature extraction module is configured to obtain fraud text features related to fraud behaviors based on the telephone recording data, the short message content data and the traffic data by the preset fraud phone identification model; A fraud phone identification module is configured to determine whether the phone to be identified is a fraud phone based on the fraud text features and a preset fraud feature threshold by the preset fraud phone identification model, and obtain a fraud phone identification result, wherein the preset fraud feature threshold is determined based on a recall rate and a misjudgment rate of the preset fraud phone identification model.
[0012] In addition, to achieve the above-mentioned purpose, the present application also provides a fraud phone identification device, which comprises a memory, a processor and a computer program stored in the memory and executable on the processor, wherein the computer program is configured to implement the steps of the fraud phone identification method as described above.
[0013] In addition, to achieve the above object, the application further provides a storage medium, which is a computer readable storage medium, and a computer program is stored on the storage medium, and the computer program is executed by a processor to implement the steps of the fraud telephone identification method.
[0014] In addition, to achieve the above object, the application further provides a computer program product, which comprises a computer program, and the computer program is executed by a processor to implement the steps of the fraud telephone identification method.
[0015] The application provides a fraud telephone identification method, and the application discloses inputting multi-modal call content text data corresponding to a telephone to be identified into a preset fraud telephone identification model, wherein the multi-modal call content text data comprises telephone recording data, short message content data and traffic data; obtaining fraud text features based on the telephone recording data, the short message content data and the traffic data through the preset fraud telephone identification model, wherein the fraud text features are features related to fraud behaviors; determining whether the telephone to be identified is a fraud telephone based on the fraud text features and a preset fraud feature threshold value through the preset fraud telephone identification model, obtaining a fraud telephone identification result, and determining the preset fraud feature threshold value based on a recall rate and a false negative rate of the preset fraud telephone identification model; compared with the prior art, the fraud telephone identification method has a higher false positive rate or a false negative rate when detecting and analyzing objective data to identify whether the telephone number is a fraud telephone number, and the fraud telephone identification accuracy is affected; since the fraud telephone identification method determines fraud text features in the telephone recording data, the short message content data and the traffic data corresponding to the telephone to be identified through the preset fraud telephone identification model, and determines whether the telephone to be identified is a fraud telephone based on the fraud text features and the preset fraud feature threshold value, the technical problem of low accuracy of fraud telephone identification based on objective data in the prior art is solved. BRIEF DESCRIPTION OF DRAWINGS
[0016] The accompanying drawings, which are incorporated into and form a part of the specification, illustrate an embodiment consistent with the present application and, together with the description, serve to explain the principles of the application.
[0017] In order to more clearly illustrate the technical solutions in the embodiments of the application or the prior art, the accompanying drawings needed to be used in the embodiments or the prior art description will be briefly introduced as follows. Obviously, for those skilled in the art, other drawings can also be obtained based on these drawings without creative labor.
[0018] Figure 1 A flowchart is provided for the fraud telephone identification method embodiment one of the application; Figure 2 A flowchart is provided for the fraud telephone identification method embodiment two of the application; Figure 3 A flowchart is provided for the third embodiment of the fraud phone identification method of the present application. Figure 4 A flowchart is provided for the fraud phone identification method of the present application. Figure 5 A module structure diagram is provided for the fraud phone identification device of the present application. Figure 6 A device structure diagram is provided for the hardware operating environment involved in the fraud phone identification method of the present application.
[0019] The object implementation, functional features and advantages of the present application will be further described with reference to the embodiments and the accompanying drawings. DETAILED DESCRIPTION
[0020] It should be understood that the specific embodiments described herein are merely intended to explain the technical solutions of the present application, and are not intended to limit the present application.
[0021] In order to better understand the technical solutions of the present application, the specific embodiments will be described in detail below with reference to the drawings and the specific embodiments.
[0022] The main solution of the present application is to input the multi-modal call content text data corresponding to the to-be-identified phone into a preset fraud phone identification model, the multi-modal call content text data including phone recording data, SMS content data and traffic data; obtain fraud text features based on the phone recording data, the SMS content data and the traffic data through the preset fraud phone identification model, the fraud text features being features related to fraud behavior; determine whether the to-be-identified phone is a fraud phone based on the fraud text features and a preset fraud feature threshold value through the preset fraud phone identification model, and obtain a fraud phone identification result, the preset fraud feature threshold value being determined based on the recall rate and the false negative rate of the preset fraud phone identification model.
[0023] Since the prior art detects and analyzes objective data to identify whether the phone number is a fraud phone number, the false positive rate or the false negative rate is high, which affects the identification accuracy of the fraud phone.
[0024] The present application provides a solution, which can determine the fraud text features in the phone recording data, the SMS content data and the traffic data corresponding to the to-be-identified phone through a preset fraud phone identification model, and determine whether the to-be-identified phone is a fraud phone based on the fraud text features and a preset fraud feature threshold value, thereby solving the technical problem of low accuracy of fraud phone identification based on objective data in the prior art.
[0025] It should be noted that the executing entity in this embodiment can be a computing service device with data processing, network communication, and program execution functions, such as a tablet computer, personal computer, or mobile phone, or an electronic device or fraud call identification device capable of the above functions. The following description uses a fraud call identification device (hereinafter referred to as the device) as an example to illustrate this embodiment and the subsequent embodiments.
[0026] Based on this, embodiments of this application provide a method for identifying fraudulent phone calls, referring to... Figure 1 , Figure 1 This is a flowchart illustrating the first embodiment of the fraudulent call identification method of this application.
[0027] In this embodiment, the fraudulent call identification method includes steps S10 to S30: Step S10: Input the multimodal call content text data corresponding to the phone number to be identified into the preset fraudulent call identification model. The multimodal call content text data includes call recording data, SMS content data and traffic data.
[0028] It is understood that the aforementioned phone number to be identified can be any external phone number that calls into the device. In this implementation, the device can identify all phone numbers not stored locally as numbers to be identified and perform fraud call identification on these numbers when they call.
[0029] It should be understood that the aforementioned multimodal call content text data can be data collected from multiple modalities during a call between the device and the telephone to be identified. In this embodiment, the multimodal call content text data can include call recording data, SMS content data, and data traffic data. The call recording data can be the voice signal of the telephone to be identified during a call. After digital processing, these voice signals can be used to analyze the caller's tone, intonation, speech rate, vocabulary habits, and other characteristics. The SMS content data can be SMS text messages sent or received by the user. The SMS content can directly reflect the characteristics of fraudulent behavior, such as enticing statements (e.g., "High-yield investment, no risk") and urgency hints (e.g., "Limited-time offer, don't miss it!"). The data traffic data can be the network traffic information generated by the telephone to be identified during a call. This data can reflect the device's communication behavior, such as the frequency, amount, and duration of data transmission.
[0030] It should be noted that the preset fraud phone identification model can be a model for identifying whether the incoming phone number has fraud behavior. In the present embodiment, the preset fraud phone identification model can be a Transformer large model, where the Transformer large model is a deep learning model widely used in the field of natural language processing (NLP), and its core feature is to use self-attention mechanism to process sequence data. The preset fraud phone identification model in the present embodiment can be provided with a data analysis module and a prediction judgment module, where the data analysis module can be used for deep analysis and prediction of the text information of the call content, and capture the features related to fraud behavior; the prediction judgment module can judge whether the corresponding phone number is a fraud phone number according to the features.
[0031] In practical applications, the preset fraud phone identification model can be constructed by using variants such as BERT (Bidirectional Encoder Representations from Transformers) or GPT (Generative Pretrained Transformer), and the model parameters can be customized and adjusted according to the specific needs of fraud phone number identification, for example, adjusting the number of layers, the number of heads (head) and other hyperparameters of the model. In the present embodiment, GPT-4 can be selected as the architecture of the large model for training according to the actual application requirements, and the preset fraud phone identification model is obtained.
[0032] Step S20: obtaining fraud text features related to fraud behavior based on the phone recording data, the SMS content data and the traffic data by the preset fraud phone identification model.
[0033] It should be understood that the fraud text features described above can be text features related to fraud behavior extracted from the phone recording data, the SMS content data and the traffic data. The fraud text features in the present embodiment can include but are not limited to user awareness features, tone features and emotion features, for example, inducement sentences (such as "high-yield investment, no risk") appearing in fraud calls, urgency hints (such as "limited-time offer, miss no longer") and specific emotional expressions (such as excessive enthusiasm or threatening tone) and the like.
[0034] In the embodiment, after receiving the telephone recording data, the short message content data and the traffic data, the preset fraud telephone identification model can perform deep analysis and prediction on the data through the data analysis module. Through learning a large amount of known fraud and normal call text data, the module can capture specific language patterns, emotional tendencies and other features related to fraudulent behavior in the multi-modal call content text data, thereby obtaining the fraud text features.
[0035] Step S30: determining whether the telephone to be identified is a fraud telephone based on the fraud text features and a preset fraud feature threshold through the preset fraud telephone identification model to obtain a fraud telephone identification result, wherein the preset fraud feature threshold is determined based on a recall rate and a misjudgment rate of the preset fraud telephone identification model.
[0036] It should be understood that the preset fraud feature threshold can be a value for determining whether the fraud text features are truly related to fraudulent behavior. In the embodiment, if the value of the fraud text features exceeds the preset fraud feature threshold, the model can determine that the call content of the telephone to be identified may involve fraudulent behavior, and then determine that the telephone to be identified is a fraud telephone number, otherwise, it indicates that the telephone to be identified is not a fraud telephone number.
[0037] It should be noted that the recall rate can be the proportion of fraud calls that the model can correctly identify, and a high recall rate indicates that the model can identify more fraudulent behavior, but may misjudge some normal calls as fraud; the misjudgment rate can be the proportion of normal calls that the model incorrectly judges as fraud calls, and a low misjudgment rate indicates that the model has less misjudgment on normal calls, but may miss some fraudulent behavior. In the embodiment, the preset fraud feature threshold can be determined by balancing the recall rate and the misjudgment rate of the preset fraud telephone identification model.
[0038] The embodiment provides a fraudulent phone identification method. The method discloses inputting multi-modal call content text data corresponding to a to-be-identified phone into a preset fraudulent phone identification model, wherein the multi-modal call content text data comprises phone recording data, short message content data and traffic data; obtaining fraudulent text features based on the phone recording data, the short message content data and the traffic data through the preset fraudulent phone identification model, wherein the fraudulent text features are features related to fraudulent behaviors; determining whether the to-be-identified phone is a fraudulent phone based on the fraudulent text features and a preset fraudulent feature threshold value through the preset fraudulent phone identification model, obtaining a fraudulent phone identification result, and determining the preset fraudulent feature threshold value based on a recall rate and a misjudgment rate of the preset fraudulent phone identification model. Compared with the prior art, the to-be-identified phone is determined to be a fraudulent phone based on the fraudulent text features and the preset fraudulent feature threshold value, so that the technical problem of low accuracy of fraudulent phone identification based on objective data in the prior art is solved.
[0039] Based on the first embodiment of the present application, in the second embodiment of the present application, the same or similar contents as the above-mentioned first embodiment can be referred to the above introduction, and will not be described in detail. On this basis, please refer to Figure 2 , Figure 2 The flowchart provided for the second embodiment of the fraudulent phone identification method of the present application.
[0040] In the embodiment, the fraudulent text features include user awareness features, tone features and emotion features; step S30 further includes steps S301-S303: Step S301: determining first text representation, second text representation and third text representation corresponding to the user awareness features, the tone features and the emotion features in the fraudulent text features, respectively.
[0041] It can be understood that the above-mentioned user awareness features can be features for reflecting subjective intentions and behavior patterns of users in the process of the call, such as inducement statements, urgency hints, false promises, etc. The above-mentioned tone features can be features for reflecting language styles and expression methods used by users in the process of the call, such as tone changes, speech speeds, pauses, etc. The above-mentioned emotion features can be features for reflecting emotional states of users in the process of the call, such as nervous emotions, angry emotions, etc.
[0042] It should be noted that the first text representation can be text content in the telephone recording data, the short message content data and the traffic data for reflecting user awareness, such as an inducible statement, a false promise, an emergency implication, etc.; the second text representation can be text content in the telephone recording data, the short message content data and the traffic data for reflecting user tone, such as an inducible tone text, a threatening tone text, a continuous tone text, etc.; and the third text representation can be text content in the telephone recording data, the short message content data and the traffic data for reflecting user emotion, such as text reflecting nervous emotion, happy emotion and angry emotion, which is not limited in the embodiment.
[0043] In step S302, the first text representation, the second text representation and the third text representation are mapped to a high-dimensional feature space by the preset fraud telephone identification model to generate a high-dimensional feature vector, which is used to represent the matching degree between the telephone recording data, the short message content data and the traffic data and the fraud behavior feature.
[0044] It should be understood that the high-dimensional feature space can be a feature space with a feature number much larger than a sample number or a high feature dimension. In the embodiment, a multi-dimensional feature space, i.e., the high-dimensional feature space, can be constructed in the model after the data of different modalities are input into the preset fraud telephone identification model. The high-dimensional feature space can include user awareness features, tone features and emotion features, so that the feature representation of the fraud behavior can be more rich and comprehensive, and a foundation for more accurate identification can be laid.
[0045] It can be understood that the fraud behavior feature can be a text feature related to the fraud behavior. In the embodiment, the data analysis module in the preset fraud telephone identification model can perform nonlinear transformation on the input multi-modal call content text data, map the original text representation in the telephone recording data, the short message content data and the traffic data that can exist in the fraud behavior to a high-dimensional feature space, and finally obtain a feature vector that can reflect the matching degree between the call content and the fraud behavior related feature, i.e., the high-dimensional feature vector.
[0046] In step S303, whether the telephone to be identified is a fraud telephone is judged based on the high-dimensional feature vector and a preset fraud feature threshold value, and a fraud telephone identification result is obtained.
[0047] In actual application, the device can preset a fraud feature threshold value. After obtaining the high-dimensional feature vector representing the matching degree between the multi-modal call content text data and the fraud behavior feature, the high-dimensional feature vector can be compared with the fraud feature threshold value, and whether the telephone to be identified is a fraud telephone can be judged according to the comparison result.
[0048] Specifically, the step S303 comprises: comparing the high-dimensional feature vector with a preset fraud feature threshold; judging whether the to-be-identified phone contains fraud behavior statements according to a comparison result, the fraud behavior statements including inducement statements, emergency implication statements and special emotional expression statements; if yes, determining the to-be-identified phone as a fraud phone to obtain a fraud phone identification result.
[0049] It should be understood that the fraud behavior statements can be statements that can embody fraud intention and behavior patterns. In the embodiment, the fraud behavior statements can include inducement statements, emergency implication statements and special emotional expression statements, wherein the inducement statements can be statements that induce a user to take certain actions, which usually contain false information, exaggerated content or unrealistic promises; the emergency implication statements can be statements that can create a sense of urgency, which usually contain time limits, threatening content or descriptions of emergency situations; and the special emotional expression statements can be statements that can affect the emotions of a user, which usually contain excessive enthusiasm, threatening tone or nervous emotions.
[0050] In the embodiment, after obtaining the high-dimensional feature vector, the device can compare the high-dimensional feature vector with a preset fraud feature threshold. If the high-dimensional feature vector does not exceed the preset fraud feature threshold, it indicates that the phone recording data, the short message content data and the traffic data of the to-be-identified phone do not contain fraud behavior statements, that is, the to-be-identified phone is not a fraud phone. If the high-dimensional feature vector exceeds the preset fraud feature threshold, it indicates that the phone recording data, the short message content data and the traffic data of the to-be-identified phone contain fraud behavior statements, that is, the to-be-identified phone may contain fraud behavior. In this case, the to-be-identified phone can be determined as a fraud phone.
[0051] In the embodiment, the first text representation, the second text representation and the third text representation corresponding to the user awareness feature, the tone feature and the emotion feature in the fraud text feature are determined respectively. The first text representation, the second text representation and the third text representation are mapped to a high-dimensional feature space through a preset fraud phone identification model to generate a high-dimensional feature vector, which is used to represent the matching degree between the phone recording data, the short message content data and the traffic data and the fraud behavior feature. Whether the to-be-identified phone is a fraud phone is judged based on the high-dimensional feature vector and a preset fraud feature threshold to obtain a fraud phone identification result. Since the original text representation corresponding to the fraud text feature is mapped to the high-dimensional feature space to obtain the high-dimensional feature vector in the embodiment, the feature representation of the fraud behavior is more rich and comprehensive, which is conducive to improving the accuracy of subsequent identification of fraud phones.
[0052] Based on the first and / or second embodiments of the present application, in the third embodiment of the present application, the same or similar contents as the above embodiments can be referred to the above description, and the subsequent description will not be repeated. On this basis, please refer to Figure 3 , Figure 3 The flowchart provided in the third embodiment of the fraud phone identification method of the present application is shown.
[0053] In this embodiment, before step S10, the method further comprises steps S01-S03: Step S01: collecting voice sample data, short message content sample data and traffic sample data generated in the Internet of Things conversation.
[0054] It can be understood that the above Internet of Things conversation can be a conversation generated in the process of interaction and communication between devices through the Internet of Things. Correspondingly, the above language sample data can be data used to represent the tone, speed, word habit, etc. of the caller in the Internet of Things conversation; the above short message content sample data can be data used to represent the fraud features in the text expression in the Internet of Things conversation; and the above traffic sample data can be data used to represent the abnormal communication behavior of the device in the Internet of Things conversation.
[0055] In specific implementation, the device can pre-collect voice sample data, short message content sample data and traffic sample data in the Internet of Things conversation, and train the fraud phone identification model through these data. In this embodiment, by combining voice sample data, short message content sample data and traffic sample data to identify fraud phone, the limitation of relying on single data type in traditional fraud phone identification can be broken through, so as to provide a more comprehensive information perspective. In this embodiment, by inputting these different modal data into the Transformer large model for training, a multi-dimensional feature space can be constructed inside the model, which integrates voice features, short message semantic features, traffic usage pattern features, etc. so that the feature representation of fraud behavior can be more rich and comprehensive, and thus the identification accuracy of fraud phone can be improved.
[0056] Step S02: marking the fraud behavior data of the voice sample data, the short message content sample data and the traffic sample data, to obtain voice fraud data, short message content fraud data and traffic fraud data.
[0057] It should be understood that the voice fraud data described above can be data in which fraud exists in the voice sample data; the short message content fraud data described above can be data in which fraud exists in the short message content sample data; and the traffic fraud data described above can be data in which fraud exists in the traffic sample data. In actual application, in the process of data collection, data in which fraud exists in the Internet of Things conversation can be collected and marked as a fraud identifier. Specifically, the device can collect all voice sample data, short message content sample data and traffic sample data in the Internet of Things conversation, and mark data in which fraud exists in these data as a fraud identifier, thereby obtaining voice fraud data, short message content fraud data and traffic fraud data. Finally, the device can use the voice fraud data, the short message content fraud data and the traffic fraud data, together with data in which normal behavior exists in the voice sample data, the short message content sample data and the traffic sample data, as a Transformer large model training data set for model training.
[0058] In actual application, after collecting the voice sample data, the short message content sample data and the traffic sample data in the Internet of Things conversation, the voice sample data, the short message content sample data and the traffic sample data can be preprocessed, such as noise removal, special character processing, irrelevant information elimination, etc. In addition, the short message content sample data and the traffic sample data can also be subjected to word segmentation processing, i.e., text is segmented into words or phrases, and then tokenization processing is performed, to obtain voice fraud data, short message content fraud data and traffic fraud data, and then the words or phrases are converted into digital vectors, so as to be used as inputs of the Transformer large model subsequently.
[0059] Step S03: training an initial fraud phone identification model based on the voice sample data, the short message content sample data, the traffic sample data, the voice fraud data, the short message content fraud data and the traffic fraud data, to obtain a preset fraud phone identification model.
[0060] It should be noted that the initial fraud phone identification model described above can be a Transformer large model without training. In actual application, the device can customize and adjust the model parameters of the Transformer large model according to the specific needs of fraud phone number identification. In this embodiment, the model parameters of the Transformer large model can be set, such as the number of layers, the number of heads, and the dimension of the hidden layer. For example, the number of layers of the Transformer large model is set to 6 layers, the number of heads is set to 8, and the dimension of the hidden layer is set to 512. After setting the parameters of the Transformer large model, the voice sample data, the SMS content sample data, the traffic sample data, and the voice fraud data, the SMS content fraud data, and the traffic fraud data with fraud behavior can be input to the Transformer large model through the standard API interface for continuous iteration and optimization training, and finally a preset fraud phone identification model is obtained. During the training process, the model can learn the semantic information and the context relationship in the text through the self-attention mechanism, capture the features related to fraud behavior in the text, and at the same time, the Transformer large model can use its self-attention mechanism (Self-Attention mechanism) to model the relationship between each word vector labeled as fraud behavior and other word vectors in the multi-modal data such as voice, traffic, or SMS. Among them, since the self-attention mechanism of the Transformer large model can effectively capture the long-distance dependency relationship in the data information, it can comprehensively understand the semantic information of the multi-modal data and improve the fraud identification accuracy.
[0061] It should be noted that in this embodiment, the integrated multi-modal data and the Transformer large model are used to analyze the multi-modal data in depth, so that the model can learn more comprehensive and detailed fraud features, such as reflecting the tone, speed, and word usage habits of the caller through voice data; directly showing fraud features in the text expression through SMS content; and suggesting abnormal communication behavior of the device through traffic data, so as to provide a more comprehensive information perspective, and then more accurately distinguish between fraud and normal Internet of Things phone calls, and reduce false positives. In addition, since the present scheme can convert multi-modal data into an input form suitable for the Transformer, the model can automatically capture the complex relationships within different modal data and between different modal data, such as associating specific expressions in the voice with similar rhetoric in the SMS when processing combined data of voice and SMS, which is conducive to better identifying fraud phone calls.
[0062] Specifically, the step S03 comprises: Step S031: training an initial fraud call identification model based on the voice sample data, the short message content sample data, the traffic sample data, the voice fraud data, the short message content fraud data, and the traffic fraud data.
[0063] Step S032: in the training process, determining the difference between the prediction result of the initial fraud call identification model and the true label by a cross-entropy loss function.
[0064] Step S033: obtaining a preset fraud call identification model when the difference reaches a preset difference threshold.
[0065] In actual applications, in the training process of the Transformer large model, the embodiment can use an optimization algorithm, a loss function Adam optimizer, and a cross-entropy loss function to continuously adjust the model parameters to improve the performance of the model. In the embodiment, the Adam optimizer can be used as the optimization algorithm, the learning rate is set to 0.001, the training round number is set to 10, and the Transformer large model is trained. At the same time, the cross-entropy loss function can be used as the loss function of the model to measure the difference between the prediction result of the model and the true label, and finally a preset fraud call identification model is obtained when the difference reaches a preset difference threshold.
[0066] Further, after the step S032, it further includes: in the training process, obtaining the number of first fraud calls and the number of second fraud calls in all fraud calls in real time by the initial fraud call identification model, the number of first fraud calls is the number of fraud calls correctly judged in the all fraud calls, and the number of second fraud calls is the number of fraud calls misjudged in the all fraud calls; determining the recall rate of the initial fraud call identification model according to the number of first fraud calls; determining the misjudgment rate of the initial fraud call identification model according to the number of second fraud calls; determining a preset fraud feature threshold based on the recall rate and the misjudgment rate.
[0067] It should be noted that the above-mentioned recall rate can be the probability that the Transformer large model correctly judges the real fraud call as a fraud call; and the above-mentioned misjudgment rate can be the probability that the Transformer large model misjudges the normal call as a fraud call. In actual applications, the device can count the total number of fraud calls input to the Transformer large model, the number of real fraud calls correctly judged as fraud calls (i.e., the number of first fraud calls), and the number of normal calls misjudged as fraud calls (i.e., the number of second fraud calls), and calculate the recall rate based on the total number and the number of first fraud calls, and calculate the misjudgment rate based on the total number and the number of second fraud calls.
[0068] In a specific implementation, if the feature vector corresponding to the call content text calculated by the Transformer large model is greater than or equal to the preset fraud feature threshold, it can be determined that the feature vector may involve fraudulent behavior, and then the phone number is determined as a fraudulent phone number. The preset fraud feature threshold can be determined by multiple tests on the validation subset. On the validation subset, the device can adjust the threshold to make the model achieve the best balance when identifying fraudulent calls, that is, it has a high recall rate and a low misjudgment rate. In practical applications, in order to identify the balance point between the recall rate and the misjudgment rate, that is, the point at which the misjudgment rate is as low as possible while ensuring a certain recall rate, the embodiment can start from the minimum value of the feature vector value and gradually increase the threshold by a certain step (0.01). At the same time, for each threshold, the number of fraudulent calls determined can be calculated. In this embodiment, after continuously training the Transformer large model, it is found that when the threshold is set to 0.82, the recall rate is 95.2%, and the misjudgment rate is 2.3%, the best fraud feature threshold can be determined. At this time, the fraud feature threshold can be set to 0.82.
[0069] In this embodiment, after constructing the preset fraud phone identification model, the device can realize real-time updating of the large model by using the updating mechanism of the Transformer large model. Specifically, the device can periodically obtain new voice, traffic, short message and other multi-modal data, including new fraudulent and normal call cases, and continuously train and optimize the Transformer large model through these data. At the same time, the Transformer large model can also be trained and optimized through the fraud call content manually identified by user feedback. In addition, the Transformer large model can also be retrained by using the method of incremental learning. Incremental learning can fine-tune the model according to the new training data set on the basis of the original model parameters, thereby reducing the time and resource consumption of retraining. During the retraining of the model, a suitable Adam optimization algorithm can also be used, and the learning rate, batch size and other training parameters of the model can be adjusted according to the size and characteristics of the new training data set. At this time, the model retrained through continuous iteration can learn new fraud and normal call features, thereby continuously improving the accuracy and adaptability of the model.
[0070] In a specific implementation, refer to Figure 4 , Figure 4 is the overall flowchart of the fraud phone identification method of the present application. As Figure 4As shown, first, multi-modal data such as telephone recording, traffic information and SMS content text of Internet of Things conversation can be collected, and the multi-modal data is preprocessed, including removing noise, special character processing, irrelevant information elimination and the like for multi-modal data telephone recording, traffic, SMS content, and then the preprocessed voice, traffic, SMS and the like fraud behavior data and normal behavior voice, traffic, SMS data can be input to the Transformer large model through the standard API interface, so that the model is continuously iteratively optimized and trained to obtain a preset fraud telephone identification model. Subsequently, when identifying a fraud telephone, the recording data, traffic data and SMS content data of the telephone to be identified can be input to the preset fraud telephone identification model, and the preset fraud telephone identification model can output the identification result of the telephone.
[0071] In the embodiment, voice sample data, SMS content sample data and traffic sample data generated by Internet of Things conversation are collected; the voice sample data, SMS content sample data and traffic sample data are marked with fraud behavior data to obtain voice fraud data, SMS content fraud data and traffic fraud data; an initial fraud telephone identification model is trained based on the voice sample data, SMS content sample data, traffic sample data, voice fraud data, SMS content fraud data and traffic fraud data to obtain a preset fraud telephone identification model; since the preset fraud telephone identification model can be trained in advance based on the voice sample data, SMS content sample data and traffic sample data generated by Internet of Things conversation, the subsequent fraud identification of the telephone to be identified can be directly input to the preset fraud telephone identification model, thereby improving the efficiency of fraud identification of the telephone.
[0072] It should be noted that the above examples are only used to understand the present application and do not constitute a limitation on the fraud telephone identification method of the present application. More forms of simple transformation based on this technical concept are within the protection scope of the present application.
[0073] The present application also provides a fraud telephone identification device, please refer to Figure 5 , the fraud telephone identification device comprises: The data input module 10 is configured to input the multi-modal conversation content text data corresponding to the telephone to be identified to the preset fraud telephone identification model, wherein the multi-modal conversation content text data comprises telephone recording data, SMS content data and traffic data. The feature extraction module 20 is configured to acquire fraud text features based on the telephone recording data, the SMS content data and the traffic data through the preset fraud telephone identification model, wherein the fraud text features are features related to fraud behavior. The fraud phone identification module 30 is configured to determine whether the to-be-identified phone is a fraud phone based on the fraud text features and a preset fraud feature threshold by using the preset fraud phone identification model, and obtain a fraud phone identification result, wherein the preset fraud feature threshold is determined based on a recall rate and a misjudgment rate of the preset fraud phone identification model.
[0074] The fraud phone identification device provided in the present application adopts the fraud phone identification method in the above embodiments, and can solve the technical problem of low accuracy of fraud phone identification based on objective data in the prior art. Compared with the prior art, the fraud phone identification device provided in the present application has the same beneficial effects as the fraud phone identification method provided in the above embodiments, and other technical features in the fraud phone identification device are the same as the features disclosed in the above embodiments, which will not be repeated here.
[0075] The present application provides a fraud phone identification device, which comprises at least one processor and a memory connected with the at least one processor, wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to perform the fraud phone identification method in Embodiment I.
[0076] Reference will be made to the following description of the embodiments of the present application, taken in conjunction with the accompanying drawings, in which Figure 6 which shows a structural schematic diagram of a fraud phone identification device suitable for implementing the embodiments of the present application. The fraud phone identification device in the embodiments of the present application can include, but is not limited to, mobile terminals such as mobile phones, notebook computers, digital broadcast receivers, PDAs (Personal Digital Assistant), PADs (Portable Application Description), PMPs (Portable Media Player), vehicle-mounted terminals (such as vehicle-mounted navigation terminals), and the like, and fixed terminals such as digital TVs, desktop computers, and the like. Figure 6 The fraud phone identification device shown is only an example, and should not bring any limitation to the functions and use range of the embodiments of the present application.
[0077] As Figure 6As shown, the fraudulent phone identification device can include a processing device 1001 (e.g., a central processing unit, a graphics processing unit, etc.) that can perform various appropriate actions and processes according to programs stored in a read-only memory 1002 or loaded from a storage device 1003 into a random access memory 1004. Various programs and data required for the fraudulent phone identification device to operate are also stored in the random access memory 1004. The processing device 1001, the read-only memory 1002, and the random access memory 1004 are connected to each other by a bus 1005. An input / output interface 1006 is also connected to the bus. Generally, the following systems can be connected to the input / output interface 1006: input devices 1007 including, for example, a touch screen, a touch pad, a keyboard, a mouse, an image sensor, a microphone, an accelerometer, a gyroscope, etc.; output devices 1008 including, for example, a liquid crystal display (LCD), a speaker, a vibrator, etc.; the storage device 1003 including, for example, a magnetic tape, a hard disk, etc.; and a communication device 1009. The communication device 1009 can allow the fraudulent phone identification device to communicate with other devices wirelessly or by wire to exchange data. Although the fraudulent phone identification device with various systems is shown in the figure, it should be understood that all the shown systems are not required to be implemented or possessed. More or less systems can be alternatively implemented or possessed.
[0078] In particular, according to the embodiments disclosed in the present application, the processes described above with reference to the flowcharts can be implemented as a computer software program. For example, the embodiments disclosed in the present application include a computer program product comprising a computer program carried on a computer readable medium, the computer program containing program codes for executing the methods shown in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network by a communication device, or installed from the storage device 1003, or installed from the read-only memory 1002. When the computer program is executed by the processing device 1001, the above-mentioned functions defined in the methods of the embodiments disclosed in the present application are performed.
[0079] The fraudulent phone identification device provided by the present application adopts the fraudulent phone identification method in the above-mentioned embodiments, and can solve the technical problem of fraudulent phone identification. Compared with the prior art, the fraudulent phone identification device provided by the present application has the same beneficial effects as the fraudulent phone identification method provided by the above-mentioned embodiments, and other technical features in the fraudulent phone identification device are the same as the features disclosed in the previous embodiment method, which will not be described here.
[0080] It should be understood that parts of the present application can be realized by hardware, software, firmware or a combination thereof. In the description of the above embodiments, specific features, structures, materials or characteristics can be combined in any one or more embodiments or examples in a suitable manner.
[0081] The above merely provides a specific implementation of the present application, but the protection scope of the present application is not limited thereto, and any person skilled in the art can easily think of changes or replacements within the technical scope disclosed by the present application, which should be covered within the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.
[0082] The present application provides a computer readable storage medium having stored thereon computer readable program instructions (i.e. computer programs) for performing the fraudulent phone identification method in the above embodiments.
[0083] The computer readable storage medium provided by the present application may, for example, be a U disk, but is not limited to an electric, magnetic, optical, electromagnetic, infrared, or semiconductor system or device, or any combination of the above. More specific examples of the computer readable storage medium can include, but are not limited to, an electric connection with one or more conductive wires, a portable computer disk, a hard disk, a random access memory (RAM), a read only memory (ROM), an erasable programmable read only memory (EPROM or flash memory), an optical fiber, a portable compact disk read only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present embodiment, the computer readable storage medium can be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system or device. The program code contained on the computer readable storage medium can be transmitted by any suitable medium, including but not limited to an electric wire, an optical cable, an RF (Radio Frequency), etc., or any suitable combination of the above.
[0084] The above computer readable storage medium can be contained in the fraudulent phone identification device; or can exist separately without being assembled into the fraudulent phone identification device.
[0085] The computer readable storage medium described above carries one or more programs, when the one or more programs are executed by the fraudulent phone identification device, cause the fraudulent phone identification device to: input multi-modal call content text data corresponding to a to-be-identified phone into a preset fraudulent phone identification model, the multi-modal call content text data including phone recording data, short message content data and traffic data; obtain fraudulent text features based on the phone recording data, the short message content data and the traffic data through the preset fraudulent phone identification model, the fraudulent text features being features related to fraudulent behaviors; determine whether the to-be-identified phone is a fraudulent phone based on the fraudulent text features and a preset fraudulent feature threshold value through the preset fraudulent phone identification model, obtain a fraudulent phone identification result, and the preset fraudulent feature threshold value is determined based on a recall rate and a misjudgment rate of the preset fraudulent phone identification model.
[0086] Computer program code for carrying out operations of the present application can be written in any combination of one or more programming languages, including an object oriented programming language such as Java, Smalltalk, C++ or the like and conventional procedural programming languages, such as the "C" programming language or similar programming languages. The program code can execute entirely on the user's computer, partly on the user's computer, as a stand-alone software package, partly on the user's computer and partly on a remote computer or entirely on the remote computer or server. In the latter scenario, the remote computer can be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or the connection can be made to an external computer (for example, through the Internet using an Internet Service Provider).
[0087] The flow diagrams and the block diagrams in the drawings are illustrations of architectures, functionalities, and operations of possible implementations of systems, methods, and computer program products according to various embodiments of present application. In this regard, each block in the flow diagrams or block diagrams can represent a module, a segment, or a portion of code, which comprises one or more executable instructions for implementing the specified logical functions. It should also be noted that in some alternative implementations, the functions noted in the blocks can occur out of the order noted in the figures. For example, two blocks shown in succession may, in fact, be executed substantially concurrently or the blocks may
[0088] The modules described in the embodiments of the present application can be implemented in the form of software or in the form of hardware. In some cases, the name of the module does not constitute a limitation on the module itself.
[0089] The readable storage medium provided by the present application is a computer readable storage medium, which stores computer readable program instructions (i.e., a computer program) for executing the fraud telephone identification method described above, and can solve the technical problem of low accuracy of fraud telephone identification based on objective data in the prior art. Compared with the prior art, the computer readable storage medium provided by the present application has the same beneficial effects as the fraud telephone identification method provided by the above embodiments, and will not be described here.
[0090] The present application also provides a computer program product comprising a computer program, which, when executed by a processor, implements the steps of the fraud telephone identification method as described above.
[0091] The computer program product provided by the present application can solve the technical problem of low accuracy of fraud telephone identification based on objective data in the prior art. Compared with the prior art, the computer program product provided by the present application has the same beneficial effects as the fraud telephone identification method provided by the above embodiments, and will not be described here.
[0092] The above only describes some embodiments of the present application, and does not limit the patent scope of the present application. Any equivalent structural transformation, direct / indirect application in other related technical fields based on the technical concept of the present application, and the contents of the present application and the accompanying drawings are included in the patent protection scope of the present application.
Claims
1. A fraudulent phone identification method, characterized by, The method comprises: inputting multi-modal call content text data corresponding to a telephone to be identified into a preset fraud telephone identification model, wherein the multi-modal call content text data comprises telephone recording data, short message content data and traffic data; acquiring fraud text features based on the telephone recording data, the short message content data and the traffic data through the preset fraud telephone identification model, wherein the fraud text features are features related to fraud behaviors; judging whether the telephone to be identified is a fraud telephone based on the fraud text features and a preset fraud feature threshold through the preset fraud telephone identification model, and obtaining a fraud telephone identification result, wherein the preset fraud feature threshold is determined based on a recall rate and a misjudgment rate of the preset fraud telephone identification model.
2. The method of claim 1, wherein, The fraud text features comprise user awareness features, tone features and emotion features; the step of judging whether the telephone to be identified is a fraud telephone based on the fraud text features and a preset fraud feature threshold through the preset fraud telephone identification model, and obtaining a fraud telephone identification result, comprises: determining first text representations, second text representations and third text representations corresponding to the user awareness features, the tone features and the emotion features in the fraud text features respectively; mapping the first text representations, the second text representations and the third text representations to a high-dimensional feature space through the preset fraud telephone identification model to generate high-dimensional feature vectors, wherein the high-dimensional feature vectors are used to represent matching degrees between the telephone recording data, the short message content data, the traffic data and the fraud behavior features; judging whether the telephone to be identified is a fraud telephone based on the high-dimensional feature vectors and a preset fraud feature threshold, and obtaining a fraud telephone identification result.
3. The method of claim 2, wherein, The step of judging whether the telephone to be identified is a fraud telephone based on the high-dimensional feature vectors and a preset fraud feature threshold, and obtaining a fraud telephone identification result, comprises: comparing the high-dimensional feature vectors with the preset fraud feature threshold; judging whether there are fraud behavior sentences in the telephone to be identified according to the comparison result, wherein the fraud behavior sentences comprise inducing sentences, emergency hint sentences and special emotional expression sentences; if there are, determining that the telephone to be identified is a fraud telephone, and obtaining a fraud telephone identification result.
4. The method of any one of claims 1 to 3, wherein, Before the step of inputting multi-modal call content text data corresponding to a telephone to be identified into a preset fraud telephone identification model, the method further comprises: collecting voice sample data, short message content sample data and traffic sample data generated in Internet of Things conversations; performing fraud behavior data labeling on the voice sample data, the short message content sample data and the traffic sample data to obtain voice fraud data, short message content fraud data and traffic fraud data; training an initial fraud telephone identification model based on the voice sample data, the short message content sample data, the traffic sample data, the voice fraud data, the short message content fraud data and the traffic fraud data to obtain a preset fraud telephone identification model.
5. The method of claim 4, wherein, The step of training the initial fraud call identification model based on the voice sample data, the short message content sample data, the traffic sample data, the voice fraud data, the short message content fraud data, and the traffic fraud data to obtain a preset fraud call identification model includes: training the initial fraud call identification model based on the voice sample data, the short message content sample data, the traffic sample data, the voice fraud data, the short message content fraud data, and the traffic fraud data; in the training process, the difference between the prediction result of the initial fraud call identification model and the true label is determined by a cross-entropy loss function; when the difference reaches a preset difference threshold, a preset fraud call identification model is obtained.
6. The method of claim 5, wherein, The step of determining the difference between the prediction result of the initial fraud call identification model and the true label by a cross-entropy loss function in the training process further includes: in the training process, the first fraud call quantity and the second fraud call quantity in all fraud calls are obtained in real time by the initial fraud call identification model, the first fraud call quantity is the number of fraud calls correctly judged as fraud calls in the all fraud calls, and the second fraud call quantity is the number of fraud calls misjudged as fraud calls in the all fraud calls; the recall rate of the initial fraud call identification model is determined according to the first fraud call quantity; the misjudgment rate of the initial fraud call identification model is determined according to the second fraud call quantity; a preset fraud feature threshold is determined based on the recall rate and the misjudgment rate.
7. A fraudulent phone identification apparatus, characterized by, The device comprises: a data input module for inputting the multi-modal call content text data corresponding to the telephone to be identified into a preset fraud call identification model, the multi-modal call content text data including telephone recording data, short message content data, and traffic data; a feature extraction module for obtaining fraud text features related to fraud behavior based on the telephone recording data, the short message content data, and the traffic data by the preset fraud call identification model; a fraud call identification module for determining whether the telephone to be identified is a fraud call based on the fraud text features and a preset fraud feature threshold by the preset fraud call identification model to obtain a fraud call identification result, the preset fraud feature threshold being determined based on the recall rate and the misjudgment rate of the preset fraud call identification model.
8. A fraudulent phone identification device, characterized by, The device comprises a memory, a processor, and a computer program stored on the memory and executable on the processor, the computer program being configured to implement the steps of the fraud call identification method according to any one of claims 1 to 6.
9. A storage medium, characterized by The storage medium is a computer-readable storage medium, and the storage medium stores a computer program, which is executed by a processor to implement the steps of the fraud call identification method according to any one of claims 1 to 6.
10. A computer program product, characterised in that, The computer program product comprises a computer program, which is executed by a processor to implement the steps of the fraud call identification method according to any one of claims 1 to 6.