Real-time communication anti-fraud method and related equipment

By desensitizing and encrypting the call voice stream on the terminal side before sending it to the cloud for fraud identification using a large model, the problems of delayed number tagging and privacy leakage in existing technologies are solved, achieving real-time and accurate fraud warnings and user privacy protection.

CN120956498APending Publication Date: 2025-11-14广州市申迪计算机系统有限公司
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202511181183.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-22
Publication Date
2025-11-14

AI Technical Summary

Technical Problem

Existing technologies for preventing telecom fraud suffer from problems such as delayed number tagging, privacy leaks, and insufficient accuracy in terminal identification, making it difficult to achieve real-time and accurate fraud warnings.

Method used

The system collects voice streams from the terminal, converts them into text, de-identifies and encrypts them, and sends them to a large model in the cloud for fraud event identification. It then combines the fraud number database and voiceprint database to conduct risk assessment and generate early warnings.

Benefits of technology

It achieves the goal of improving the accuracy and real-time nature of call fraud warnings while protecting user privacy, thus safeguarding users' assets.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120956498A_ABST
    Figure CN120956498A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides a real-time communication anti-fraud method and related equipment, and belongs to the technical field of communication. According to the method, a terminal collects a call voice stream during a call, converts the call voice stream into a call voice text, desensitizes the call voice text to obtain a call desensitized text, encrypts the call desensitized text to obtain a call encrypted text, and sends the call encrypted text to the terminal. And sending the encrypted call text to a fraud text analysis model of the cloud to perform fraud event identification so as to obtain a call early warning response from the cloud. According to the scheme, the conversation language of the terminal is processed into the text, desensitization processing is carried out, then encryption is carried out, and the text is delivered to the cloud with higher operational capability for fraud recognition, so that compared with the prior art, the accuracy of conversation fraud early warning can be improved while user privacy is protected.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of communication technology, and in particular to a real-time communication anti-fraud method and related equipment. Background Technology

[0002] As the fight against telecom fraud deepens, telecom operators have built anti-fraud models based on behavioral analysis, which can mitigate some telecom fraud to a certain extent. Simultaneously, operators have launched high-frequency anti-harassment fraud call protection functions for individual users. Currently, there are three main ways to implement call alerts for users. The first is to monitor potentially fraudulent numbers in the cloud or on the terminal based on data such as internet number tags, and then alert or block the calls. However, number tagging has a certain lag, leading to incomplete fraud identification. The second is to record user calls in the cloud, transcribe them into text, perform semantic recognition, and then alert or block the calls. While this method can more comprehensively identify fraudulent events, uploading call content to the cloud can easily leak personal privacy. The third is to record calls on the mobile phone, transcribe them into text, and then identify fraudulent keywords to alert or block the calls. While this method can effectively protect personal privacy, it is limited by the local computing power of the terminal, which can only execute simple keyword matching analysis models and cannot accurately identify fraudulent events. Summary of the Invention

[0003] The main objective of this application is to propose a real-time communication anti-fraud method and related equipment, which aims to protect user privacy while improving the accuracy of call fraud warnings.

[0004] To achieve the above objectives, one aspect of this application proposes a real-time communication anti-fraud method, applied in a call terminal, the real-time communication anti-fraud method comprising the following steps: Collect the call audio stream and convert the call audio stream into call audio text; The voice text of the call is de-identified to obtain the de-identified text of the call. The de-identified text of the call is encrypted to obtain the encrypted text of the call; The encrypted text of the call is sent to a fraud text analysis model in the cloud for fraud event identification, in order to obtain a call warning response from the cloud.

[0005] In some embodiments, the real-time communication anti-fraud method further includes the following steps: Obtain the object characteristic information of the current call, the object characteristic information including the object number; The object feature information is encrypted to obtain encrypted object information; The encrypted information of the object is sent to the cloud so that the cloud can identify fraud incidents based on the encrypted information of the object and the encrypted text of the call.

[0006] In some embodiments, the process of desensitizing the call voice text to obtain desensitized call text includes the following steps: Sensitive entity recognition is performed on the voice text of the call to obtain the attribute values ​​of multiple sensitive entities; Based on the sensitivity type to which the sensitive entity belongs, the attribute values ​​of the sensitive entity are desensitized using the desensitization strategy corresponding to the sensitivity type to obtain the call desensitized text.

[0007] In some embodiments, the sensitive types are categorized into account password, user privacy, key action, and identity association types. The step of desensitizing the attribute values ​​of the sensitive entity according to its sensitive type and employing the corresponding desensitization strategy to obtain the desensitized call text includes the following steps: For sensitive entities belonging to the category of account passwords, a partial character masking replacement desensitization strategy is used to desensitize the attribute values ​​of the sensitive entities. For sensitive entities that fall under the category of user privacy, a desensitization strategy of generalized identifier replacement is used to desensitize the attribute values ​​of the sensitive entities. For sensitive entities belonging to the category of key actions, a desensitization strategy based on the generalization of key text intent fields is used to desensitize the attribute values ​​of the sensitive entities. For sensitive entities belonging to the identity association category, a desensitization strategy of random replacement of similar words is used to desensitize the attribute values ​​of the sensitive entities; The call de-identified text is determined based on the attribute values ​​of the sensitive entities after multiple de-identification processes.

[0008] In some embodiments, encrypting the de-identified call text to obtain encrypted call text includes the following steps: Send a slice establishment request carrying an anti-fraud slice identifier to the network server, so that the network server can select a network path that meets the anti-fraud service quality to establish an encrypted tunnel according to the slice establishment request; The call de-identified text is encrypted using the session key of the encrypted tunnel to obtain the call encrypted text.

[0009] In some embodiments, the step of sending the encrypted call text to the cloud for fraud text analysis model to identify fraud events includes the following steps: The encrypted text of the call is transmitted to the network server through the encrypted tunnel, so that the network server transmits the encrypted text of the call to the fraud text analysis model in the cloud for fraud event identification. The network server is used to determine the packet loss rate of the encrypted text in the call, and if the packet loss rate exceeds the expected threshold, it reselects a network path to establish an encrypted tunnel with the call terminal.

[0010] To achieve the above objectives, another aspect of this application proposes a real-time communication anti-fraud system, comprising: A calling terminal is used to collect call voice streams and convert the call voice streams into call voice text; to perform desensitization processing on the call voice text to obtain desensitized call text; to perform encryption processing on the desensitized call text to obtain encrypted call text; and to send the encrypted call text to the cloud. In the cloud, a fraudulent text analysis model is used to identify fraudulent events in the encrypted text of the call, and a call warning response is obtained; the call warning response is then returned to the call terminal.

[0011] In some embodiments, the calling terminal is further configured to obtain object feature information of the current call, the object feature information including the object number; encrypt the object feature information to obtain object encrypted information; and send the object encrypted information to the cloud. Specifically, the cloud platform is used to decrypt the encrypted text of the call and the encrypted information of the object to obtain the de-identified text of the call and the object feature information; input the de-identified text of the call into a fraud text analysis model to obtain the fraud classification probability; input the object feature information into a fraud feature database for feature matching to obtain the fraud matching probability; fuse the fraud classification probability and the fraud matching probability to obtain the fraud identification result; and generate a call warning response when the fraud identification result indicates that a fraud event has occurred.

[0012] To achieve the above objectives, another aspect of this application provides an electronic device, which includes a memory and a processor. The memory stores a computer program, and the processor executes the computer program to implement the above-described method.

[0013] To achieve the above objectives, another aspect of the embodiments of this application proposes a computer program product, including a computer program that, when executed by a processor, implements the above-described method.

[0014] The embodiments of this application include at least the following beneficial effects: This application provides a real-time communication anti-fraud method, system, electronic device, and program product. The terminal in this solution collects the call voice stream during a call, converts the voice stream into call voice-text, then de-identifies the call voice-text to obtain de-identified call text, encrypts the de-identified call text to obtain encrypted call text, and then sends the encrypted call text to a fraud text analysis model in the cloud for fraud event identification to obtain a call warning response from the cloud. This solution processes and de-identifies the terminal's call voice-text before encrypting it and delivering it to the more powerful cloud for fraud identification. Compared with existing technologies, this can improve the accuracy of call fraud warnings while protecting user privacy. Attached Figure Description

[0015] Figure 1 This is a flowchart of the real-time communication anti-fraud method provided in the embodiments of this application; Figure 2 This is a flowchart of the terminal's processing of the call voice stream provided in the embodiments of this application; Figure 3 This is a schematic diagram of cloud-based early warning command push provided in an embodiment of this application; Figure 4 This is a schematic diagram illustrating the process of transmitting de-identified text during a call to the cloud, as provided in an embodiment of this application. Figure 5 This is a schematic diagram of cloud-based large-scale model fraud event identification provided in an embodiment of this application; Figure 6 This is a schematic diagram of the PROMPT inference stage provided in an embodiment of this application; Figure 7 This is a schematic diagram of the hardware structure of the electronic device provided in the embodiments of this application. Detailed Implementation

[0016] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative of this application and are not intended to limit it. In the following description, when referring to the accompanying drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with those of this application; they are merely examples of apparatuses and methods consistent with some aspects of the embodiments of this application as detailed in the appended claims.

[0017] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this application belongs. The terminology used herein is for the purpose of describing embodiments of this application only and is not intended to limit this application.

[0018] Before providing a detailed description of the embodiments of this application, some of the nouns and terms involved in the embodiments of this application will be explained first. The nouns and terms involved in the embodiments of this application are subject to the following interpretations.

[0019] Artificial intelligence (AI) refers to the technology of simulating human intelligence through computer systems, encompassing methods such as machine learning, deep learning, and natural language processing, enabling machines to have the ability to learn, reason, and make decisions.

[0020] The Neural Processing Unit (NPU) is a hardware unit specifically designed to accelerate neural network operations. Its core function is to efficiently perform operations such as matrix multiplication and activation functions through parallel computing structures, thereby accelerating real-time inference and training of deep learning models (such as convolutional neural networks and recurrent neural networks).

[0021] Automatic Speech Recognition (ASR) is a technology that uses artificial intelligence to convert human speech signals into text in real time. Its core processes include speech signal processing, feature extraction, acoustic model matching, and language model optimization. This technology relies on deep learning algorithms (such as convolutional neural networks) and natural language processing (NLP) to achieve accurate parsing of spoken language and is widely used in scenarios such as intelligent customer service, real-time translation, and voice assistants.

[0022] The Session Management Function (SMF) is a critical network function in the 5G core network, responsible for managing the entire lifecycle of user sessions, including session establishment, modification, and release. It also handles IP address allocation, UPF (User Plane Function) selection and control, QoS policy enforcement, and billing data collection. In the 5G architecture, the SMF collaborates with network elements such as the AMF and PCF through service-oriented interfaces (e.g., N11, N4), supporting network slicing and dynamic resource allocation. Compared to 4G's PGW-C, it offers greater flexibility and scalability. Its core technical features include UE-level granular session context management, tunnel maintenance, and the ability to interact with external data networks (DN).

[0023] Quality of Service (QoS) is a technical mechanism in communication networks used to optimize resource allocation and ensure the performance of critical applications. It ensures the reliability of high-priority services (such as VoIP and real-time video) transmission through differentiated traffic processing (e.g., priority scheduling, bandwidth reservation, latency control), while simultaneously improving overall network efficiency. Its core objectives include reducing packet loss rate, controlling jitter, and meeting the SLA (Service Level Agreement) requirements of different applications.

[0024] Software-defined networking (SDN) is a network architecture approach that separates the network control layer (control plane) from the data forwarding layer (data plane) and uses a centralized controller (such as one based on the OpenFlow protocol) to achieve dynamic and programmable network management. Its core advantage lies in decoupling control logic from hardware devices, allowing administrators to flexibly configure network policies through a unified interface (such as the northbound API), thereby improving automation and resource utilization.

[0025] The User Plane Function (UPF) is a key component of the 5G core network, responsible for high-speed forwarding, routing, and traffic control of user data. Its core functions include IP address allocation, QoS policy enforcement, and interaction with external data networks. As an evolution of the 4G EPC CUPS (Control and User Plane Separation) architecture, the UPF reduces latency and improves bandwidth efficiency by moving down to the network edge (e.g., UPF decoupling technology), while also supporting network slicing and edge computing scenarios. In the 5G architecture, the UPF works in conjunction with the SMF through the PFCP protocol to achieve complete decoupling between the data plane and the control plane.

[0026] Large Language Models (LLMs) are deep learning-based natural language processing models that learn language patterns through training on massive amounts of text, enabling them to generate, classify, or summarize text. Their core architecture typically employs a Transformer, predicting the next word in a sequence to accomplish tasks such as dialogue generation, code writing, or machine translation. Key technologies of LLMs include pre-training, fine-tuning, and contextual understanding capabilities, making them applicable to fields such as intelligent assistants and text reasoning.

[0027] Supervised Fine-Tun-ing (SFT) is a model optimization technique based on supervised learning. It involves further training a pre-trained large language model (such as GPT or LLaMA) on labeled datasets to adapt it to a specific task (e.g., dialogue generation, text classification). Its core principle is to adjust model parameters to retain the general language capabilities learned during pre-training while minimizing prediction errors on the target task. Compared to pre-training, SFT has lower computational costs and can significantly improve model performance in specific domains.

[0028] Mel-Frequency Cepstral Coefficients (MFCCs) are a speech feature extraction method based on the characteristics of human hearing. By simulating the nonlinear perception of frequency by the human ear (Mel scale), they convert speech signals into low-dimensional feature representations.

[0029] The relevant technologies can provide warnings or handle fraudulent calls to victims in the following ways: The first method involves monitoring potentially fraudulent numbers in the cloud or on-device based on data such as internet phone number tags, and then alerting or blocking victims. However, judging potentially fraudulent numbers based on internet phone number tags is time-consuming, often requiring multiple reports and tags after a number has committed multiple frauds; furthermore, many potentially fraudulent numbers may remain untagged or missed, making the method incomplete.

[0030] The second method involves recording user calls in the cloud, transcribing them into text, performing semantic recognition, and then alerting or blocking the call. While this method can more comprehensively identify fraudulent activities, uploading call content to the cloud can easily lead to the leakage of personal privacy.

[0031] The third method involves recording and transcribing calls on the mobile phone, then identifying fraudulent keywords to alert victims or block the system. However, due to limitations in the terminal's processing power, the terminal can only execute keyword matching analysis models for fraud identification, resulting in significant limitations in accuracy and recall.

[0032] In view of this, this application provides a real-time communication anti-fraud method and related equipment. In this scheme, the terminal side performs real-time recording and transcription with the user's authorization, and uploads the de-identified text to the cloud in encryption. The cloud big data model performs risk assessment, detects fraudulent calls in real time, and sends a warning command to the terminal to realize the warning reminder to the victim, protect the user's property security and protect the user's privacy.

[0033] The real-time communication anti-fraud method provided in this application relates to the field of communication technology. This method can be applied to terminals. In some embodiments, the terminal may be a smartphone, tablet, smart speaker, smartwatch, or in-vehicle terminal, etc., that has call capabilities, but is not limited to these.

[0034] In this application, the cloud refers to a device with more powerful computing capabilities than a terminal for identifying fraud incidents. For example, the cloud can be a server, which can be configured as an independent physical server, a server cluster or distributed system composed of multiple physical servers, or a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, CDN, and big data and artificial intelligence platforms. The server can also be a node server in a blockchain network.

[0035] It should be noted that in all specific embodiments of this application, when processing data related to user identity or characteristics, such as user information, user behavior data, user historical data, and user location information, user permission or consent is obtained first. Furthermore, the collection, use, and processing of this data comply with relevant laws, regulations, and standards. In addition, when embodiments of this application require access to sensitive personal information of users, separate permission or consent from the user is obtained through pop-ups or redirection to confirmation pages. Only after obtaining the user's separate permission or consent is the necessary user-related data required for the proper functioning of these embodiments acquired.

[0036] Figure 1 This is an optional flowchart of the real-time communication anti-fraud method provided in the embodiments of this application. Figure 1 The method may include, but is not limited to, steps S101 to S106.

[0037] Step S101: Collect the call audio stream and convert the call audio stream into call audio text; Step S102: De-identify the voice text of the call to obtain the de-identified text of the call. Step S103: Encrypt the de-identified text of the call to obtain the encrypted text of the call. Step S104: Send the encrypted text of the call to the fraud text analysis model in the cloud for fraud event identification, so as to obtain a call warning response from the cloud.

[0038] In steps S101 to S104 of this embodiment, the terminal collects the call voice stream during a call, converts the voice stream into voice-text, de-identifies the voice-text to obtain de-identified voice-text, encrypts the de-identified voice-text to obtain encrypted voice-text, and then sends the encrypted voice-text to a fraud text analysis model in the cloud for fraud event identification to obtain a call warning response from the cloud. This solution processes and de-identifies the terminal's call voice-text before encrypting it and sending it to the more powerful cloud for fraud identification. Compared to existing technologies, this improves the accuracy of call fraud warnings while protecting user privacy.

[0039] In step S101 of some embodiments, the calling terminal refers to a device with calling capability. During a call, the calling terminal collects the call voice stream in real time and converts the call voice stream into call voice-text. For example, please refer to... Figure 2 The flowchart illustrates the terminal's processing of the call audio stream. When a user answers a call, the terminal's AI software captures the call audio stream through a microphone array. User authorization can be granted before the software captures the audio stream to protect privacy. The call audio stream is segmented at 20ms / frame and fed into an NPU-accelerated ASR engine for MFCC feature extraction. Then, a lightweight Conformer-S model converts the audio features into call audio text.

[0040] In step S102 of some embodiments, desensitization processing refers to blurring sensitive information in the text, making it invisible to the outside world. This embodiment can apply the same desensitization rules to sensitive information in the text, such as replacing sensitive words with generalized tags or masking sensitive words. This embodiment can also perform hierarchical desensitization processing on the voice call text. Hierarchical desensitization processing refers to applying different degrees of blurring to different sensitive information in the text, thereby protecting user privacy while reducing the impact of desensitization processing on the semantic expression of the text, and thus improving the accuracy of subsequent cloud-based fraud identification. Specifically, hierarchical desensitization processing can involve identifying sensitive entities in the voice call text to obtain attribute values ​​for multiple sensitive entities; based on the sensitivity type to which the sensitive entity belongs, using the desensitization strategy corresponding to the sensitivity type to desensitize the attribute values ​​of the sensitive entity, resulting in desensitized voice call text.

[0041] In step S103 of some embodiments, to improve the security of call data during transmission between the terminal and the cloud, the terminal encrypts the anonymized call text to obtain encrypted call text, and then transmits the encrypted call text to the cloud. Specifically, the terminal uses a session key and an encryption algorithm to encrypt the anonymized call text, and the cloud uses a corresponding session key and decryption algorithm to decrypt the encrypted call text, thereby achieving encrypted transmission of the anonymized call text.

[0042] In step S104 of some embodiments, the terminal sends the encrypted call text to the cloud. The cloud decrypts the encrypted call text to obtain the anonymized call text, and then uses a fraud text analysis model to identify fraudulent events in the anonymized call text. Furthermore, the terminal can also send the target number of the call recipient to the cloud, where the cloud, based on the fraud text analysis model, matches the target number against a fraudulent number database to identify fraud.

[0043] Upon confirming a fraud incident, the cloud generates a call alert response and returns it to the terminal. In this embodiment, the fraud text analysis model can be a deep learning neural network text processing model, specifically a large language model. For example, please refer to... Figure 3 The diagram illustrates a cloud-based early warning push notification. After the cloud detects a potentially fraudulent call, it sends an encrypted and lightweight push notification with the phone number and risk tag to the mobile device via a PUSH channel (i.e., a telecom security middleware). During the call, the mobile device displays a real-time pop-up window with the warning content. This content indicates the presence of fraud risk and the type of fraud detected by the cloud, such as "High Risk: Suspected XX fraud. Users can choose to hang up if suspected fraud or acknowledge no fraud risk." The pop-up also displays a control indicating suspected fraud. Users can click this control if they believe the call is fraudulent. The terminal responds to this control by sending the caller's number to the cloud, which then stores the number in a fraud database, completing the defense loop.

[0044] In some embodiments, please continue to refer to Figure 2 After the terminal uploads the encrypted text of the call to the cloud, it can destroy the original voice in the local NPU accelerator, which can reduce memory usage.

[0045] According to some embodiments of this application, the real-time communication anti-fraud method of this application may also include, but is not limited to, the following steps: Step S201: Obtain the object characteristic information of the current call, including the object number; Step S202: Encrypt the object feature information to obtain encrypted object information; Step S203: Send the encrypted object information to the cloud so that the cloud can identify fraud incidents based on the encrypted object information and the encrypted text of the call.

[0046] In some embodiments, object feature information includes an object number, and the cloud-based fraud feature database includes a fraud number database. The object number can be obtained by reading the communication module. The terminal encrypts the object number to obtain encrypted object information, and sends the encrypted object information to the cloud. This allows the cloud to perform fraud identification by matching the object number with the fraud number database based on the fraud text analysis model, thereby improving the accuracy and comprehensiveness of fraud identification.

[0047] In some embodiments, the object feature information may further include the object's voiceprint, and the fraud feature database in the cloud includes a fraud voiceprint database. The object's voiceprint is extracted as follows: the terminal converts the call audio stream into a call spectrum; based on the locally stored owner's voiceprint features, the owner's spectrum is removed from the call spectrum to obtain the object's spectrum; the object's spectrum is then truncated according to a preset duration to obtain an object spectrum segment; and voiceprint features are extracted from this object spectrum segment to obtain the object's voiceprint. The terminal encrypts the object's voiceprint to obtain encrypted object information, which is then sent to the cloud. This allows the cloud to perform fraud identification by matching the object's voiceprint with the fraud voiceprint database, based on the fraud text analysis model, thereby improving the accuracy and comprehensiveness of fraud identification.

[0048] According to some embodiments of this application, step S102 may include, but is not limited to, the following steps: Step S301: Perform sensitive entity recognition on the voice text of the call to obtain the attribute values ​​of multiple sensitive entities; Step S302: Based on the sensitive type to which the sensitive entity belongs, the attribute values ​​of the sensitive entity are desensitized using the desensitization strategy corresponding to the sensitive type to obtain the call desensitized text.

[0049] In this embodiment, sensitive entities in the call voice text can be identified using call regularization rules and keyword database matching, or an entity extraction model can be used to identify sensitive entities in the call voice text. After identifying multiple sensitive entities and their attribute values ​​from the call voice text, the attribute values ​​of the corresponding sensitive entities are anonymized according to the sensitivity type to which each sensitive entity belongs, resulting in anonymized call text. This method of distinguishing different sensitivity types and using appropriate anonymization strategies can protect user privacy while reducing the impact of anonymization on the semantic expression of the text, thereby improving the accuracy of subsequent cloud-based fraud detection. Sensitive types can be categorized according to anonymization requirements, and each sensitive type corresponds to a defined keyword database used to identify the sensitivity type to which a sensitive entity belongs. The sensitive types in this embodiment can be divided into account password type, user privacy type, key action type, and identity association type. Account password type refers to fields that use combinations of numbers or letters, such as ID card number, bank card number, login password, payment password, verification code, etc. User privacy type refers to user personal information, such as name, mobile phone number, address, geographical location information, income, age, etc. Key action type refers to words related to fraudulent intent, such as transfer, amount, financial institution, identity verification, verification code, etc. Identity association type refers to defined non-sensitive words that may be associated with user identity, such as company, address, etc.

[0050] According to some embodiments of this application, step S302 may include, but is not limited to, the following steps: Step S401: For sensitive entities belonging to the account password category, a partial character mask replacement desensitization strategy is used to desensitize the attribute values ​​of the sensitive entities. Step S402: For sensitive entities belonging to the user privacy category, a desensitization strategy of generalized identifier replacement is used to desensitize the attribute values ​​of the sensitive entities. Step S403: For sensitive entities belonging to the critical action category, the attribute values ​​of the sensitive entities are desensitized using a desensitization strategy that generalizes the key fields of text intent. Step S404: For sensitive entities belonging to the identity association category, a desensitization strategy of random replacement of similar words is used to desensitize the attribute values ​​of the sensitive entities. Step S405: Determine the call de-identified text based on the attribute values ​​of multiple de-identified sensitive entities.

[0051] In this embodiment, the tiered anonymization technique is essentially designed to address the inherent conflict between the strength of privacy protection and the accuracy of fraud detection in real-time anti-fraud scenarios. Excessive anonymization (such as full-text encryption) may prevent large cloud-based models from parsing the semantics, rendering anti-fraud efforts ineffective, while insufficient anonymization can lead to the leakage of sensitive information such as user ID cards and bank cards. This embodiment uses dynamic sensitivity assessment to apply differentiated anonymization strengths to different types of information, achieving the technical effect of minimizing privacy exposure and maximizing the preservation of anti-fraud semantics. For example, the overall tiered anonymization strategy is shown in Table 1.

[0052] Table 1 Overall Strategy for Graded Desensitization

[0053] Specifically, the local privacy engine executes a four-level dynamic de-identification strategy, completely stripping away privacy information while retaining the semantic features required for anti-fraud measures, as follows: For sensitive information such as account passwords, the following de-identification measures should be implemented: Identify sensitive entities such as account passwords (e.g., ID card number, bank card number, login password, payment password, verification code, etc.). The attribute values ​​of such sensitive entities are masked using a dynamic masking mechanism. For example, for consecutive numbers (such as bank card number 622588******1234), only the first and last two digits are retained, and the middle part is replaced with * to avoid the leakage of the complete pattern and achieve devastating masking.

[0054] For de-identifying sensitive information related to user privacy: Identify sensitive entities related to user privacy (such as name, mobile phone number, address, geolocation information, income, age, etc.). Replace the attribute values ​​of this type of sensitive entity with typed generalized identifiers (such as [name], [phone number], [address], [geographic information], [income], [age], etc.).

[0055] For desensitizing sensitive information related to key actions: By identifying key action-related sensitive entities, the fraudulent intent of the other party can be determined, such as the intent to transfer funds or the intent to verify identity. Based on the fraudulent intent, the intent-related words in the voice text of the call can be processed in a targeted manner. If a financial transfer intent is detected, the amount can be replaced with a range identifier ([amount>10,000 yuan]); the payee information can be generalized to [payee institution] (e.g., "China Construction Bank" → [bank], "Alipay" → [payment platform]).

[0056] If an authentication intent (such as "What is your birthday?") is detected, the specific date can be anonymized as [date], retaining the "date" semantics but hiding the numerical value.

[0057] By using methods such as categorizing amounts into ranges and institutions, the expression of key semantics for fraud determination (such as the intent of "large transfer") can be preserved while eliminating privacy concerns, thereby improving the accuracy of subsequent fraud identification models.

[0058] For sensitive information related to identity (excluding key privacy terms), random perturbation can be used for desensitization: To counter "fragmented information reconstruction" attacks (inferring user identity through multiple non-sensitive words), this method uses probabilistic substitution to disrupt data correlation, significantly improving privacy and security. The specific method is as follows: For non-sensitive words that may be associated with user identity (such as the address "Chaoyang District" or the company "Tencent"), they can be randomly replaced with similar generalized words ([region], [Internet company]) with a 30% probability, thus compromising data reconstructability.

[0059] Example of desensitization: Original sentence: "Li Si, please transfer 38,000 yuan to XX Bank from 62XXXXXXXXXX78". Hierarchical desensitization: [NAME], please transfer [amount > 10,000] to [bank] from 62********78.

[0060] According to some embodiments of this application, step S103 may include, but is not limited to, the following steps: Step S501: Send a slice establishment request carrying an anti-fraud slice identifier to the network server so that the network server can select a network path that meets the anti-fraud service quality to establish an encrypted tunnel according to the slice establishment request. Step S502: Encrypt the call de-identified text according to the session key of the encrypted tunnel to obtain the call encrypted text.

[0061] In this embodiment, the network path refers to a path composed of a series of nodes. The network server (such as a base station) selects the optimal network path that meets the anti-fraud service quality requirements based on the anti-fraud slice identifier in the slice establishment request to establish an encrypted tunnel, thereby achieving real-time and efficient transmission of encrypted call text. The encrypted tunnel indicates the network path and the negotiated session key. The terminal can encrypt the de-identified call text according to the session key of the encrypted tunnel to obtain the encrypted call text, thereby improving the security of call data during transmission.

[0062] According to some embodiments of this application, step S104 may include, but is not limited to, the following steps: Step S601: The encrypted text of the call is transmitted to the network server through an encrypted tunnel, so that the network server transmits the encrypted text of the call to the fraud text analysis model in the cloud for fraud event identification. The network server is used to determine the packet loss rate of the encrypted text in the call. If the packet loss rate exceeds the expected threshold, a new network path is selected to establish an encrypted tunnel with the call terminal.

[0063] In this embodiment, the terminal encrypts the de-identified text of the call using the session key of the encrypted tunnel to obtain the encrypted text of the call. The terminal then transmits the encrypted text to the network server via the network path indicated by the encrypted tunnel. The network server then transmits the encrypted text to the cloud via the encrypted tunnel. The cloud decrypts the text using the corresponding session key and uses a fraud text analysis model to identify fraudulent events in the encrypted text of the call.

[0064] For example, please refer to Figure 4 The diagram below illustrates the process of transmitting de-identified text from a call to the cloud in encrypted form. S11, the terminal sends a slice establishment request to the 5G base station, carrying the anti-fraud special slice identifier S-NSSAI=0x010203.

[0065] S12, the AMF on the network service side verifies the slice permission. After passing the verification, the SMF selects the optimal UPF node based on the slice QoS requirements (latency ≤ 50ms, reliability 99.999%) and establishes an end-to-end IPsec ESP encrypted tunnel.

[0066] S13, the terminal security enclave generates an SM4 session key, encrypts text in blocks, and transmits it to the cloud large model access gateway through a UPF tunnel.

[0067] S14. If the packet loss rate exceeds the threshold during transmission, the SDN controller dynamically switches to the edge UPF node to ensure data transmission integrity.

[0068] This application also proposes a real-time communication anti-fraud system, including: The calling terminal is used to collect the call voice stream and convert it into call voice text; to perform desensitization processing on the call voice text to obtain desensitized call text; to encrypt the desensitized call text to obtain encrypted call text; and to send the encrypted call text to the cloud. In the cloud, a fraud text analysis model is used to identify fraudulent events in encrypted call text and generate a call alert response; the call alert response is then returned to the call terminal.

[0069] According to some embodiments of this application, the call terminal is further configured to obtain object feature information of the current call, the object feature information including the object number; encrypt the object feature information to obtain object encrypted information; and send the object encrypted information to the cloud. Specifically, the cloud-based system is used to decrypt encrypted text and object information in calls to obtain de-identified text and object feature information; input the de-identified text into a fraud text analysis model to obtain fraud classification probability; input the object feature information into a fraud feature database for feature matching to obtain fraud matching probability; fuse the fraud classification probability and fraud matching probability to obtain fraud identification result; and generate a call warning response when the fraud identification result indicates that a fraud event has occurred.

[0070] In this embodiment, taking object characteristic information including object number as an example, please refer to... Figure 5 The diagram shown illustrates a large-scale cloud-based fraud event identification model. In this embodiment, the large-scale model for fraud event identification in the cloud comprises two parts: a text-based semantic analysis model (i.e., a fraud text analysis model) and a phone number database query. The overall process is as follows: A fraud text analysis model was used to perform semantic analysis on the de-identified text to obtain the fraud classification probability (SemanticRisk). Input the target number into the number database for query and matching to obtain the fraud matching probability NumberRisk; The risk fusion engine comprehensively analyzes the fraud classification probability SemanticRisk and the fraud matching probability NumberRisk, and applies ContextFactor to obtain the fraud probability RiskScore. The fraud probability RiskScore is used to classify and determine the fraud identification result. If RiskScore ≥ 0.8, a higher-level red alert is issued; if 0.6 < RiskScore < 0.8, it is considered a suspected fraud event and a lower-level yellow alert is issued; if RiskScore ≤ 0.6, no alert is issued.

[0071] For example, the following is an implementation of cloud-based identification of fraud involving impersonation of public security, procuratorate, and court officials: Step S21: Input data.

[0072] Anonymized text (uploaded from terminal): "[NAME] is suspected of money laundering and must transfer funds to a secure account [ACCOUNT] to cooperate with the investigation, otherwise [NAME] will be arrested"; Incoming call number: +852 6673****; Step S21: Semantic analysis process.

[0073] The fraudulent text analysis model outputs a fraud intent classification, as shown in Table 2: Table 2 Classification of Fraudulent Intent

[0074] Among them, the most probable fraudulent intent was analyzed using a tactic intensity analysis formula: tactic_score = 0.6 * keyword density ("safe account") + 0.3 * threat level ("arrest") + 0.1 * urgency ("immediate transfer") = 0.93; Semantic risk value (i.e. fraud classification probability) calculation: SemanticRisk = 0.7*max(0.97,0.02,0.01)+0.3*0.93 = 0.958.

[0075] S23: Number risk inquiry.

[0076] The operator's database returned the following query results: json { "number_type": "International number", "blacklist_count": 8, "register_days": 2, "whitelist": false } Number risk (i.e., probability of being matched with a scam) calculation: NumberRisk = 0.4 (overseas) + 0.5 (number marked as scam ≥ 5 times) + 0.2 (new number) = 1.1; the number risk threshold is capped at 1.0.

[0077] S24: Risk Integration and Decision Making.

[0078] RiskScore = 0.75*0.958 + 0.25*1.0= 0.9685 S25: Decision result: If the threshold of 0.8 is exceeded, a red alert is triggered.

[0079] The fraudulent text analysis model in this embodiment is based on LLM. The following is an example of the training process for the fraudulent text analysis model: (1) Fraud sample acquisition.

[0080] First, it is necessary to obtain the corresponding call scripts based on the various popular scams currently circulating, including but not limited to the following scam types and corresponding scripts, as shown in Table 3: Table 3. Examples of Fraud Types and Scripts

[0081] (2) Selection of large language model, as shown in Table 4.

[0082] Table 4 Examples of Language Model Selection

[0083] Each of the above large models has its own advantages. In this embodiment, LLaMA-2-7B-CH can be selected. Algorithms for other large language models are also within the protection scope of this embodiment.

[0084] (3) Prompt supervised fine-tuning (PSFT), as shown in Table 5.

[0085] Table 5 Examples of PROMPT Supervisory Fine-Tuning

[0086] Data transformation example: original_text = "I am XX from XX Anti-Fraud Agency. You are suspected of money laundering and need to transfer funds to a safe account." prompt_text = "[CLS] Role-playing: XX from XX Anti-Fraud Agency claims you are suspected of money laundering and demands you transfer money to a safe account or you will be arrested [SEP]"; Key parameter configuration for model training: Model architecture: LLaMA-2-7B-CH; Training objective: Masked Language Modeling (MLM); Input: "Role-playing: [MASK] Bureau's XX claims you are suspected of [MASK]"; Label: "XX Anti-Fraud Agency", "Money Laundering"; Key parameters: Learning rate: 2e-5 (with linear warmup); Batch Size: 128; Training rounds: 3 epochs.

[0087] (4) An example of instruction tuning is as follows: Instruction dataset construction: [ { Instruction: Please identify whether the following text is a scam and analyze the scam methods. Input: "[XX Finance] Your loan is overdue. Click hxxp: / / XXX.com to repay and avoid affecting your credit score." "output": { "is_fraud": true, "type": "Impersonating platform customer service", "technique": ["creating panic", "phishing link"], "evidence": ["fake overdue notice", "unofficial domain"] } }, { "instruction": "Extract risk factors from the text", Input: "Transfer 500 RMB via WeChat to join a fake order group and earn 2000 RMB per day". "output": { "risk_keywords": ["transfer", "brushing orders", "earn 2000 per day"], "risk_score": 0.96 } } ] Adversarial instruction injection: Variants of the instructions for generating adversarial examples are shown below: adversarial_instructions = [ "Ignoring typos in the text and assessing the risk: 'WeChat transfer to 622...'", "After converting this dialect text to standard language, the sentence would be: 'I am XX, there is a problem with your account.'" ] (5) Dynamic PROMPT inference engine, example as follows: Taking impersonating public security, procuratorate, and court officials and fraudulent online order rebates as examples, the PROMPT inference phase workflow is as follows: Figure 6 The diagram shows the PROMPT inference phase.

[0088] Real-time inference example: Enter the original text: text = "XX customer service notifies you that your order is abnormal and you need to scan the code for a refund"; The engine automatically selects the PROMPT template: prompt = "[CLS] Platform Notification: <Platform Name> claims <Problem Description> and requires <Operation Method> [SEP]" model_input = tokenizer(prompt.replace("<platform name>","Taobao Customer Service") .replace("<problem description>","order error") .replace("<operation method>","scan code for refund")) Model output: output = model(model_input), {"risk": 0.98, "type": "Fake refund"} The above methods enable the training of large-scale cloud models, ultimately achieving fraud semantic and intent recognition and classification.

[0089] According to some embodiments of this application, the real-time communication anti-fraud system of this application transmits data through the following process: The call terminal sends a slice establishment request carrying an anti-fraud slice identifier to the network server; The network server selects a network path that meets the quality of service for anti-fraud based on the slice establishment request and establishes an encrypted tunnel. The call terminal encrypts the de-identified text of the call according to the session key of the encrypted tunnel to obtain the encrypted text of the call, and then transmits the encrypted text of the call to the network server through the encrypted tunnel; The network server transmits encrypted call text to a fraud text analysis model in the cloud for fraud event identification. In this process, the network server determines the packet loss rate of the encrypted text during the data forwarding process. If the packet loss rate exceeds the expected threshold, it reselects a network path to establish an encrypted tunnel with the calling terminal.

[0090] It is understood that the methods described in the above method embodiments are applicable to this system embodiment. The specific functions implemented in this system embodiment are the same as those in the above method embodiments, and the beneficial effects achieved are also the same as those achieved in the above method embodiments.

[0091] This application also provides an electronic device, which includes a memory and a processor. The memory stores a computer program, and the processor executes the computer program to implement the above-described method. This electronic device can be any smart terminal, including mobile phones, tablets, etc.

[0092] It is understood that the content of the above method embodiments is applicable to this device embodiment. The specific functions implemented by this device embodiment are the same as those of the above method embodiments, and the beneficial effects achieved are also the same as those achieved by the above method embodiments.

[0093] Please see Figure 7 , Figure 7 The hardware structure of an electronic device according to another embodiment is illustrated. The electronic device includes: The processor 901 can be implemented using a general-purpose CPU (Central Processing Unit), microprocessor, application-specific integrated circuit (ASIC), or one or more integrated circuits, and is used to execute relevant programs to implement the technical solutions provided in the embodiments of this application. The memory 902 can be implemented as a read-only memory (ROM), a static storage device, a dynamic storage device, or a random access memory (RAM). The memory 902 can store the operating system and other applications. When the technical solutions provided in the embodiments of this specification are implemented through software or firmware, the relevant program code is stored in the memory 902 and is called and executed by the processor 901. The input / output interface 903 is used to implement information input and output; The communication interface 904 is used to enable communication and interaction between this device and other devices. Communication can be achieved through wired means (such as USB, Ethernet cable, etc.) or wireless means (such as mobile network, WIFI, Bluetooth, etc.). Bus 905 transmits information between various components of the device (e.g., processor 901, memory 902, input / output interface 903, and communication interface 904); The processor 901, memory 902, input / output interface 903, and communication interface 904 are connected to each other within the device via bus 905.

[0094] This application also provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the above-described method.

[0095] It is understood that the content of the above method embodiments is applicable to this storage medium embodiment. The specific functions implemented in this storage medium embodiment are the same as those in the above method embodiments, and the beneficial effects achieved are also the same as those achieved in the above method embodiments.

[0096] This application also provides a computer program product, including a computer program that, when executed by a processor, implements the above-described method.

[0097] It is understood that the content of the above method embodiments is applicable to the embodiments of this program product. The specific functions implemented by the embodiments of this program product are the same as those of the above method embodiments, and the beneficial effects achieved are also the same as those achieved by the above method embodiments.

[0098] Memory, as a non-transitory computer-readable storage medium, can be used to store non-transitory software programs and non-transitory computer-executable programs. Furthermore, memory may include high-speed random access memory, and may also include non-transitory memory, such as at least one disk storage device, flash memory device, or other non-transitory solid-state storage device. In some embodiments, memory may optionally include memory remotely located relative to the processor, and these remote memories can be connected to the processor via a network. Examples of such networks include, but are not limited to, the Internet, intranets, local area networks, mobile communication networks, and combinations thereof.

[0099] The real-time communication anti-fraud method and related equipment provided in this application provide a new method to fill the gap in edge-cloud dual-AI real-time communication anti-fraud technology. Compared with related technologies, the embodiments of this application have at least one of the following beneficial effects: (1) It can overcome the limitations of fraud warning and interception that rely solely on data such as Internet tags. Compared with traditional fraud warning and interception methods that rely solely on data such as Internet tags, the embodiments of this application upload de-identified call text from the terminal to the cloud for large-scale model risk assessment, and finally conduct fraud call warning by combining data such as Internet tags, which makes up for the shortcomings of the lag and lack of comprehensiveness of fraud warning and interception that rely solely on data such as Internet tags.

[0100] (2) It can avoid the limitations of infringing on user privacy by recording and identifying content in the cloud. Compared with the infringement method based on recording and transcribing user calls in the cloud and then performing semantic recognition for victim alerts or interception, the embodiments of this application avoid the infringement of recording and detecting user calls unilaterally in the cloud by user authorization and encrypted uploading of desensitized text on the terminal, and have better feasibility and scalability.

[0101] (3) It can avoid the limitations of terminal fraud keyword recognition models. Compared with the solution based on recording and transcribing the call on the mobile phone and then identifying fraud keywords to remind or block the victim, the big model semantic recognition and intent recognition based on the massive computing power of the cloud can greatly improve the accuracy and recall rate of fraud call recognition and improve the prevention effect.

[0102] (4) Achieving a balance between privacy protection and fraud detection accuracy. Compared to simply encrypting and transmitting text information to the cloud, this application embodiment applies differentiated desensitization strengths to different information through dynamic sensitivity assessment, thereby minimizing privacy exposure and maximizing the retention of anti-fraud semantics to a certain extent. Call data is important personal privacy data. By using graded desensitization and encrypted transmission to ensure the security of user privacy, the inherent conflict between privacy protection strength and fraud detection accuracy in real-time anti-fraud scenarios is resolved, achieving a balance between privacy protection and fraud detection accuracy.

[0103] The embodiments described in this application are for the purpose of more clearly illustrating the technical solutions of the embodiments of this application, and do not constitute a limitation on the technical solutions provided by the embodiments of this application. As those skilled in the art will know, with the evolution of technology and the emergence of new application scenarios, the technical solutions provided by the embodiments of this application are also applicable to similar technical problems.

[0104] Those skilled in the art will understand that the technical solutions shown in the figures do not constitute a limitation on the embodiments of this application, and may include more or fewer steps than shown, or combine certain steps, or different steps.

[0105] It should be understood that in this application, "at least one (item)" means one or more, and "more than" means two or more. "And / or" is used to describe the relationship between related objects, indicating that three relationships can exist. For example, "A and / or B" can represent three cases: only A exists, only B exists, and both A and B exist simultaneously, where A and B can be singular or plural. The character " / " generally indicates that the preceding and following related objects are in an "or" relationship. "At least one (item) of the following" or similar expressions refer to any combination of these items, including any combination of single or plural items. For example, at least one (item) of a, b, or c can represent: a, b, c, "a and b", "a and c", "b and c", or "a and b and c", where a, b, and c can be single or multiple.

[0106] The preferred embodiments of the present application have been described above with reference to the accompanying drawings, but this does not limit the scope of the claims of the present application. Any modifications, equivalent substitutions, and improvements made by those skilled in the art without departing from the scope and substance of the embodiments of the present application shall be within the scope of the claims of the present application.

Claims

1. A real-time communication anti-fraud method, characterized in that, When applied to a call terminal, the real-time communication anti-fraud method includes the following steps: Collect the call audio stream and convert the call audio stream into call audio text; The voice text of the call is de-identified to obtain the de-identified text of the call. The de-identified text of the call is encrypted to obtain the encrypted text of the call; The encrypted text of the call is sent to a fraud text analysis model in the cloud for fraud event identification, in order to obtain a call warning response from the cloud.

2. The method according to claim 1, characterized in that, The real-time communication anti-fraud method further includes the following steps: Obtain the object characteristic information of the current call, the object characteristic information including the object number; The object feature information is encrypted to obtain encrypted object information; The encrypted information of the object is sent to the cloud so that the cloud can identify fraud incidents based on the encrypted information of the object and the encrypted text of the call.

3. The method according to claim 1, characterized in that, The process of desensitizing the voice call text to obtain desensitized voice call text includes the following steps: Sensitive entity recognition is performed on the voice text of the call to obtain the attribute values ​​of multiple sensitive entities; Based on the sensitivity type to which the sensitive entity belongs, the attribute values ​​of the sensitive entity are desensitized using the desensitization strategy corresponding to the sensitivity type to obtain the call desensitized text.

4. The method according to claim 3, characterized in that, The sensitive types are categorized into account password, user privacy, key action, and identity association types. The process involves de-identifying the attribute values ​​of the sensitive entity according to its sensitive type, using the corresponding de-identification strategy to obtain the de-identified call text. This includes the following steps: For sensitive entities belonging to the category of account passwords, a partial character masking replacement desensitization strategy is used to desensitize the attribute values ​​of the sensitive entities. For sensitive entities that fall under the category of user privacy, a desensitization strategy of generalized identifier replacement is used to desensitize the attribute values ​​of the sensitive entities. For sensitive entities belonging to the category of key actions, a desensitization strategy based on the generalization of key text intent fields is used to desensitize the attribute values ​​of the sensitive entities. For sensitive entities belonging to the identity association category, a desensitization strategy of random replacement of similar words is used to desensitize the attribute values ​​of the sensitive entities; The call de-identified text is determined based on the attribute values ​​of the sensitive entities after multiple de-identification processes.

5. The method according to claim 1, characterized in that, The process of encrypting the de-identified text of the call to obtain the encrypted text includes the following steps: Send a slice establishment request carrying an anti-fraud slice identifier to the network server, so that the network server can select a network path that meets the anti-fraud service quality to establish an encrypted tunnel according to the slice establishment request; The call de-identified text is encrypted using the session key of the encrypted tunnel to obtain the call encrypted text.

6. The method according to claim 5, characterized in that, The fraud text analysis model that sends the encrypted text of the call to the cloud for fraud event identification includes the following steps: The encrypted text of the call is transmitted to the network server through the encrypted tunnel, so that the network server transmits the encrypted text of the call to the fraud text analysis model in the cloud for fraud event identification. The network server is used to determine the packet loss rate of the encrypted text in the call, and if the packet loss rate exceeds the expected threshold, it reselects a network path to establish an encrypted tunnel with the call terminal.

7. A real-time communication anti-fraud system, characterized in that, include: A calling terminal is used to collect call voice streams and convert the call voice streams into call voice text; The voice text of the call is de-identified to obtain the de-identified text of the call. The de-identified text of the call is encrypted to obtain the encrypted text of the call; The encrypted text of the call is sent to the cloud; In the cloud, a fraudulent text analysis model is used to identify fraudulent events in the encrypted text of the call, and a call warning response is obtained; the call warning response is then returned to the call terminal.

8. The real-time communication anti-fraud system according to claim 7, characterized in that, The calling terminal is also used to obtain the object feature information of the current call, the object feature information including the object number; to encrypt the object feature information to obtain object encrypted information; and to send the object encrypted information to the cloud. Specifically, the cloud is used to decrypt the encrypted text of the call and the encrypted information of the object to obtain the de-identified text of the call and the characteristic information of the object; The anonymized text of the call is input into a fraud text analysis model to obtain a fraud classification probability; the object feature information is input into a fraud feature database for feature matching to obtain a fraud matching probability; the fraud classification probability and the fraud matching probability are fused to obtain a fraud identification result; and a call warning response is generated when the fraud identification result indicates that a fraud event has occurred.

9. An electronic device, characterized in that, The electronic device includes a memory and a processor, the memory storing a computer program, and the processor executing the computer program to implement the method according to any one of claims 1 to 6.

10. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the method of any one of claims 1 to 6.

Citation Information

Cited By

  • Data processing method and system based on trusted metadata

    CN121770905A