Terminal equipment control method and device based on circulation linkage, equipment and medium

By constructing user equipment association graphs and flow graphs, abnormal flow and linkage behaviors of terminal devices are identified, solving the problems of small identification range and low accuracy in existing technologies, and realizing precise control of terminal devices and reduction of server load.

CN120994504AActive Publication Date: 2025-11-21中信证券股份有限公司

Patent Information

Application Number
CN202511500453.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-10-21
Publication Date
2025-11-21
Estimated Expiration
2045-10-21

AI Technical Summary

Technical Problem

Existing technologies for identifying and controlling abnormal flow behavior of terminal devices suffer from problems such as small identification range, low accuracy, high server load, and high security risks, making it difficult to effectively identify abnormal linkage behavior between individual users and groups.

Method used

By acquiring user multi-source login association information and value object flow information, a knowledge graph and flow graph are constructed. The graph is divided and flow relationship is mined to identify abnormal flow linkages, thereby achieving precise monitoring and interception of terminal devices.

Benefits of technology

It improves the accuracy of terminal device traffic interception and early warning, reduces server load, enhances server security, and reduces missed detections and false detections.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120994504A_ABST
    Figure CN120994504A_ABST
Patent Text Reader

Abstract

The embodiment of the invention discloses a terminal equipment control method and device based on circulation linkage, equipment and a medium. A specific embodiment of the method comprises the following steps: acquiring a user multi-source login association information set and a user value object circulation information set; performing knowledge graph construction on the user multi-source login association information set to obtain a user equipment association graph; performing graph division on the user equipment association graph to obtain a user login association sub-graph set; performing circulation relation mining on the user value object circulation information set to obtain a circulation relation information set; generating a user value object circulation graph; performing abnormal circulation linkage identification on the user value object circulation graph to obtain a circulation linkage abnormal association graph set; and carrying out monitoring and early warning processing on the terminal equipment set, and carrying out circulation interception control on the terminal equipment set. According to the embodiment, the accuracy of traffic interception and early warning of the server on the terminal equipment can be improved, the load effect of the server is reduced, and the security of the server is improved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] Embodiments of the present disclosure relate to the technical field of computer technology, and particularly relate to a terminal device control method and device based on flow linkage, a terminal device, and a medium. BACKGROUND

[0002] The flow linkage of the value object can be identified as group abnormal behavior identification of a group composed of multiple users, and the terminal device with abnormal behavior can be monitored, warned, and flow intercepted. At present, when the flow linkage of the value object is controlled, the commonly used method is: using a machine learning algorithm to identify the abnormal behavior of a single user with respect to the flow of the value object, obtaining abnormal user information, then identifying the similar behavior of a user set associated with the abnormal user information to obtain an abnormal user group, and finally controlling the flow of the terminal device corresponding to the abnormal user group.

[0003] However, in practice, it is found that when the flow linkage of the value object is controlled by using the above method, the following technical problems often exist: the flow behavior detected by identifying the flow behavior of a single user with respect to the value object is relatively single, the range of the flow group identified by identifying the flow linkage of the user associated with the abnormal user is small, it is difficult to accurately identify both single behavior abnormality and group abnormal linkage behavior, the number of flow behavior indicators selected by the machine learning algorithm is small, it is difficult to effectively and accurately identify the flow linkage behavior, the possibility of missing detection and false detection is increased, the accuracy of abnormal behavior identification is low, the precision of the flow interception control of the server to the terminal device is poor, the server carries more flow requests, and the effect of reducing the load of the server is poor, and the security risk of the server is increased.

[0004] The above information disclosed in this BACKGROUND section is only for the purpose of enhancing the understanding of the background of the present disclosure and, therefore, can include information that does not form the prior art that is already known to those of ordinary skill in the art. SUMMARY

[0005] The summary section is provided to introduce concepts briefly in a simplified form, which will be described in detail in the specific embodiments section. The summary section is not intended to identify key or essential features of the claimed technology nor is it intended to be used to limit the scope of the claimed technology.

[0006] Some embodiments of the present disclosure propose a terminal device control method and device based on flow linkage, a terminal device, and a medium to solve one or more of the technical problems mentioned in the background section.

[0007] In a first aspect, some embodiments of the present disclosure provide a terminal device control method based on flow linkage, comprising: obtaining a user multi-source login association information set and a user value object flow information set; constructing a knowledge graph based on the user multi-source login association information set to obtain a user device association graph; dividing the user device association graph to obtain a user login association subgraph set; mining flow relationship based on the user value object flow information set to obtain a flow relationship information set; generating a user value object flow graph based on the user value object flow information set and the flow relationship information set; identifying abnormal flow linkage based on the user login association subgraph set and the user value object flow graph to obtain an abnormal flow linkage association graph set; sending the abnormal flow linkage association graph set to a flow alarm device to control the flow alarm device to monitor and warn the value object flow information of a terminal device set corresponding to the abnormal flow linkage association graph set, and in response to determining that the flow alarm device sends a warning information, controlling the flow interception of the terminal device set.

[0008] In a second aspect, some embodiments of the present disclosure provide a terminal device control apparatus based on flow linkage, comprising: an obtaining unit configured to obtain a user multi-source login association information set and a user value object flow information set; a knowledge graph construction unit configured to construct a knowledge graph based on the user multi-source login association information set to obtain a user device association graph; a graph division unit configured to divide the user device association graph to obtain a user login association subgraph set; a flow relationship mining unit configured to mine flow relationship based on the user value object flow information set to obtain a flow relationship information set; a generating unit configured to generate a user value object flow graph based on the user value object flow information set and the flow relationship information set; an abnormal flow linkage identification unit configured to identify abnormal flow linkage based on the user login association subgraph set and the user value object flow graph to obtain an abnormal flow linkage association graph set; and a flow interception control unit configured to send the abnormal flow linkage association graph set to a flow alarm device to control the flow alarm device to monitor and warn the value object flow information of a terminal device set corresponding to the abnormal flow linkage association graph set, and in response to determining that the flow alarm device sends a warning information, control the flow interception of the terminal device set.

[0009] In a third aspect, some embodiments of the present disclosure provide an electronic device, comprising: one or more processors; a storage device having one or more programs stored thereon, when the one or more programs are executed by the one or more processors, the one or more processors implement the method described in any of the implementations of the first aspect.

[0010] In a fourth aspect, some embodiments of the present disclosure provide a computer readable medium having stored thereon a computer program, wherein the computer program, when executed by a processor, implements the method described in any implementation manner of the first aspect.

[0011] The above various embodiments of the present disclosure have the following beneficial effects: the terminal device control method based on flow transfer linkage of some embodiments of the present disclosure can improve the accuracy of the server in intercepting and warning the flow of terminal devices, reduce the load of the server, and improve the security of the server. Specifically, the reason why the related terminal device carries more flow transfer requests, the effect of reducing the load of the terminal device is poor, and the security risk of the terminal device is increased is that the flow transfer behavior detected by identifying the value object flow transfer behavior of a single user is relatively single, the range of the flow transfer group identified by the flow transfer linkage identification of the user associated with the abnormal user is small, it is difficult to accurately identify both single behavior anomaly and group anomaly linkage behavior, the number of flow transfer behavior indicators selected by the machine learning algorithm is small, it is difficult to effectively and accurately identify the flow transfer linkage behavior, the possibility of missing detection behavior and false detection behavior is increased, the accuracy of abnormal behavior identification is low, the precision of the server in intercepting the flow of terminal devices is poor, the server carries more flow transfer requests, the effect of reducing the load of the server is poor, and the security risk of the server is increased. Based on this, the terminal device control method based on flow transfer linkage of some embodiments of the present disclosure can first acquire a user multi-source login association information set and a user value object flow transfer information set. Here, the user multi-source login association information set and the user value object flow transfer information set facilitate the construction of the user device association graph and the user value object flow transfer graph. Secondly, the knowledge graph is constructed based on the user multi-source login association information set to obtain a user device association graph. Here, the strong association potential association relationship between users existing through login devices and personal information except for value object flow transfer and explicit social relationship (for example, relatives, friends) can be effectively identified, efficient association between users is realized, and the range and comprehensiveness of identification are increased. Thirdly, the user device association graph is divided into a user login association subgraph set. Here, the multiple users with strong association relationship are divided from the graph, which can reduce the useless data of users and devices that have no association relationship with the users, thereby reducing the data amount of the user login association subgraph and facilitating the improvement of the speed of subsequent abnormal flow transfer linkage identification. Then, the flow transfer relationship information set is obtained by performing flow transfer relationship mining on the user value object flow transfer information set. Here, the flow transfer relationship mining can mine potential flow transfer relationship and improve the comprehensiveness of the flow transfer relationship information set. Subsequently, the user value object flow transfer graph is generated according to the user value object flow transfer information set and the flow transfer relationship information set. Here, the accuracy and comprehensiveness of the user value object flow transfer graph can be improved, and each user value object node and flow transfer edge in the user value object flow transfer graph includes a large amount of attribute information. Then, the user value object flow transfer graph is subjected to abnormal flow transfer linkage identification according to the user login association subgraph set to obtain a flow transfer linkage abnormal association graph set.Here, the user login association subgraph and the user value object flow transfer graph are used in conjunction with each other, the user login association subgraph can accurately divide and identify the range, find the strong association group based on the device and information sharing, reduce the calculation data volume and complexity, the user value object flow transfer graph accurately identifies through the flow transfer behavior, improves the comprehensiveness and accuracy of the flow transfer linkage abnormal association graph, reduces the occurrence of missed and false detection. Finally, the above flow transfer linkage abnormal association graph set is sent to the flow transfer alarm device to control the flow transfer alarm device, monitor and warn the value object flow transfer information of the terminal device set corresponding to the flow transfer linkage abnormal association graph set, and in response to determining that the flow transfer alarm device sends warning information, the terminal device set is controlled. Here, through the accuracy and high quality of the flow transfer linkage abnormal association graph set, the real-time and accuracy of the monitoring and warning can be improved, and the accuracy of the flow transfer interception control of the terminal device can be improved, which can effectively reduce the flow transfer volume and load of the server and improve the security of the server. Therefore, the terminal device control method based on flow transfer linkage can effectively associate the potential user association information through the terminal device and information sharing through the user login association graph, and after the graph is divided, the user value object flow transfer graph can improve the accuracy and speed of abnormal flow transfer linkage identification, and then improve the accuracy of abnormal terminal device warning and interception, reduce the load of the server and improve the security of the server. BRIEF DESCRIPTION OF DRAWINGS

[0012] The above and other features, advantages and aspects of the present disclosure will become more apparent as various embodiments thereof are described in conjunction with the following detailed description, taken in conjunction with the accompanying drawings. Throughout the drawings, like or similar reference numerals are used to refer to like or similar elements. It should be understood that the drawings are schematic and elements and features are not necessarily to scale.

[0013] Figure 1 is a flow chart of some embodiments of the terminal device control method based on abnormal flow transfer linkage identification according to the present disclosure; Figure 2 is a schematic diagram of a user device association graph in some embodiments of the terminal device control method based on abnormal flow transfer linkage identification according to the present disclosure; Figure 3 is a schematic diagram of a user value object flow transfer graph in some embodiments of the terminal device control method based on abnormal flow transfer linkage identification according to the present disclosure; Figure 4 is a structural schematic diagram of some embodiments of the terminal device control apparatus based on abnormal flow transfer linkage identification according to the present disclosure; Figure 5 is a structural schematic diagram of an electronic device suitable for implementing some embodiments of the present disclosure. DETAILED DESCRIPTION

[0014] Embodiments of the present disclosure will be described below in greater detail with reference to the accompanying drawings. While certain embodiments of the present disclosure are shown in the drawings, it is understood that the present disclosure can be embodied in various forms and should not be interpreted as being limited to the embodiments set forth herein. Rather, these embodiments are provided so that the present disclosure can be more thoroughly and completely understood. It should be understood that the drawings of the present disclosure are only for illustrative purposes and are not intended to limit the scope of protection of the present disclosure.

[0015] It should also be noted that only parts related to the present application are shown in the drawings for ease of description. The embodiments in the present disclosure and the features in the embodiments can be combined with each other without conflict.

[0016] It should be noted that the terms "first", "second", and the like mentioned in the present disclosure are only used to distinguish different devices, modules or units, and are not intended to limit the order or interdependence of the functions performed by these devices, modules or units.

[0017] It should be noted that the terms "one", "multiple" mentioned in the present disclosure are illustrative and not restrictive, and those skilled in the art should understand that unless otherwise explicitly stated in the context, it should be understood as "one or more".

[0018] The names of the messages or information exchanged between the devices in the embodiments of the present disclosure are only for illustrative purposes, and are not intended to limit the scope of the messages or information.

[0019] The present disclosure will be described in detail below with reference to the accompanying drawings and in conjunction with the embodiments.

[0020] Figure 1 Flow 100 of some embodiments of a terminal device control method based on abnormal flow transfer linkage identification according to the present disclosure is shown. The terminal device control method based on abnormal flow transfer linkage identification includes the following steps: Step 101, obtaining a user multi-source login association information set and a user value object flow transfer information set.

[0021] In some embodiments, the subject (for example, an electronic device) of the terminal device control method based on abnormal flow linkage recognition described above can obtain the user multi-source login association information set and the user value object flow information set through wired connection or wireless connection. The user multi-source login association information set can be a set of information from different data sources related to user information and user login terminal device value object flow operation information. The user login terminal device can include but is not limited to at least one of the following: a mobile phone, a personal computer, and a desktop computer. For example, the user multi-source login association information set can include but is not limited to at least one of the following: a multi-type user information database set, and a login information set on a value object flow terminal device set (user transaction terminal device set). The multi-type user information database set can be a database that stores different types of user information. The multi-type user information database set can include: an ECIF (Enterprise Customer Information Facility), a personal customer information library, an institutional customer information library, and a product customer information library. The personal customer information library can be a database that stores customer information based on the type of personal customer identification and the corresponding identification number for opening an account (opening a securities account and a fund account). The institutional customer information library can be a database that stores company-related information based on the company's business license and unified social credit code for opening an account. The product customer information library can be a database that stores the identification information of the user corresponding to the product based on the name of the product for opening an account. The user value object flow information (securities transaction information, securities subject attribute information) in the user value object flow information set can be user information and user value object flow information.

[0022] Step 102, constructing a knowledge graph for the user multi-source login association information set to obtain a user device association graph.

[0023] In some embodiments, the execution subject can perform knowledge graph construction on the user multi-source login association information set to obtain a user device association graph. The user device association graph can be a knowledge graph that describes the association relationship between user information and terminal login devices used by the user, and has multiple connected graphs. The nodes in the user device association graph can include user nodes, user personal information, and device nodes. The user personal information and device nodes can be nodes composed of information of terminal devices used by the user and user personal information stored by the terminal devices. For example, the user personal information and device nodes can include, but are not limited to, at least one of the following: user terminals (such as mobile phones, computers), user information stored by user terminals (such as registered mobile phone numbers), universally unique identifiers (UUID) of terminal use devices, international mobile equipment identity (IMEI) of terminal use devices, device location (MAC address) of terminal use devices, MAC_HD (Macintosh HD, default startup disk of macOS system). The edges in the user device association graph can be connection edges that describe the association relationship between the user nodes, the user personal information, and the device nodes. The knowledge graph construction can be performed using a bottom-up knowledge graph construction method. As shown in Figure 2 Figure 2 The user device association graph composed of user nodes, user personal information, and device nodes is shown.

[0024] In some optional implementations of some embodiments, the knowledge graph construction on the user multi-source login association information set to obtain a user device association graph can include the following steps: First, data fusion is performed on the user multi-source information set included in the user multi-source login association information set to obtain user login association fusion information. The user multi-source information set can be information related to the user from different data sources. The user login association fusion information can be information obtained by fusing the data of the user multi-source information set based on user identification information representing the user's identity. The user identification information can include, but is not limited to, at least one of the following: information of the type of certificate and the corresponding certificate number.

[0025] ​Secondly, the execution subject can firstly perform data preprocessing on the user login associated fusion information to obtain preprocessed user login associated fusion information. Secondly, the execution subject can perform fuzzy matching on the name information set of the value object included in the preprocessed user login associated fusion information by using a fuzzy matching algorithm to obtain an object fuzzy matching name information set. For example, the object fuzzy matching name information is named differently in different customer information, and is named as "xxx growth fund 2025" in user multi-source information A in the user multi-source information set and is named as "xxx growth 2025 fund" in user multi-source information B in the user multi-source information set. By using the fuzzy matching algorithm, "xxx growth fund 2025" and "xxx growth 2025 fund" are determined as the name of the same value object, and the object fuzzy matching name information set is obtained. Then, the execution subject can perform fuzzy matching on the user information set included in the preprocessed user login associated fusion information according to the user certificate type and the user certificate code to obtain a user fuzzy matching information set. Finally, the execution subject can perform fuzzy matching on the object fuzzy matching name information set and the user fuzzy matching information set to determine the user information set that matches successfully as the same user information as the fuzzy value object user information set.

[0026] Thirdly, the execution subject can perform user identity disambiguation processing on the user login associated fusion information to obtain a user identity disambiguation information set. The user identity disambiguation information in the user identity disambiguation information set can be information that identifies user information with the same meaning and different user names as the same user. In practice, the execution subject can perform user identity disambiguation processing on the user login associated fusion information by using the user certificate type information in the user information and the user certificate number corresponding to the user certificate type information to obtain the user identity disambiguation information set, that is, the user information with the same user certificate type and the same user certificate number is determined as the same user information.

[0027] Fourthly, the execution subject can determine the fuzzy value object user information set and the user identity disambiguation information set as a user entity information set. The user entity information in the user entity information set can be information representing a user with the same user attribute information. The user attribute information can include but is not limited to at least one of the following: user name, user identity information, user certificate type information, and user certificate number corresponding to the user certificate type information.

[0028] In the fifth step, the user equipment information set included in the value object order information set in the user multi-source login association information set is extracted to obtain a user equipment entity information set. The value object order information in the value object order information set can be information about the equipment used by the user in the value object circulation process (user transaction process) and the user's reserved contact information. The user equipment entity in the user equipment entity information set can be equipment information and user login information used by the user to log in to the terminal equipment to circulate the value object. For example, the user equipment entity information set can include, but is not limited to, at least one of the following: a hard disk, a registered mobile phone number, a user mailbox, an IDFV (Identifier For Vendor, vendor identifier of terminal equipment). In practice, the execution subject can first perform data cleaning on the value object order information set based on the Greenplum distributed database to obtain a cleaned value object order information set. The cleaned value object order information set can include, but is not limited to, at least one of the following: value object circulation information (transaction flow information), value attribute value circulation information (fund flow), and user information. Then, the equipment circulation information set stored in the terminal equipment set corresponding to the cleaned value object order information set is pre-analyzed to obtain the user equipment entity information set.

[0029] In the sixth step, the user equipment association relationship information set of the user equipment entity information set and the user entity information set is determined. The user equipment association relationship information in the user equipment association relationship information set can be association information between the user equipment entity information and the user entity information, and between the user entity information and the user entity information. The user equipment association relationship information set can include equipment use relationship information and user association relationship information. The equipment use relationship information can represent the relationship information of the user using the terminal use equipment or the personal information owned by the user. Different users can be indirectly associated through the same personal information and homologous equipment. The user association relationship can represent the direct relationship between users through non-personal information and the indirect relationship established through the terminal use equipment. For example, the user association relationship can include, but is not limited to, at least one of the following: a second contact, a legal representative, and an agent.

[0030] In the seventh step, the user equipment association graph is generated according to the user entity information set, the user equipment entity information set, and the user equipment association relationship information set.

[0031] As an example, the execution subject can first perform triad construction on the user entity information set, the user device entity information set, and the user device association relationship information set to obtain a user device triad set. Then, the user device triad set is input into a graph database to obtain a user device association graph. The graph database can be an existing graph database. For example, the graph database can be a Noe4j graph database.

[0032] Step 103: performing graph division on the user device association graph to obtain a user login association subgraph set.

[0033] In some embodiments, the execution subject can perform graph division on the user device association graph to obtain a user login association subgraph set. The user login association subgraph in the user login association subgraph set can be the largest connected graph of the user device association graph, which is composed of user nodes, user personal information and device nodes, corresponding association relationships, and use relationships belonging to the same community.

[0034] In some optional implementations of some embodiments, the graph division on the user device association graph to obtain a user login association subgraph set can include the following steps: First, determine the user device node degree set of the user device association graph. The user device node degree in the user device node degree set can represent the importance of the user node or the user personal information and device node, i.e., the number of connections with other nodes.

[0035] Second, determine the user device node access sequence according to the user device node degree set. The user device node access sequence can be obtained by sorting the user device nodes included in the user device node degree set in descending order according to the user device node degree set. Each user device node can be a node set composed of user nodes, user personal information and device nodes.

[0036] Third, based on the user device node access sequence, perform the following subgraph determination steps: Substep 1: based on the starting user device node, perform the following access graph generation step: First substep: according to the user device association graph, determine the user device node located after the starting user device node as the user device depth node, wherein the starting user device node is the node located at the initial position in the node access sequence. The user device depth node can be a user device node located after the starting user device node and not yet visited. The determination can be made by the connection edge in the user device association graph.

[0037] In a second sub-step, the user device depth node and the starting user device node are added to a preset data stack to obtain a node access stack. The preset data stack can be a stack data structure preset for storing the user device depth node and the starting user device node.

[0038] In a third sub-step, in response to determining that the node access stack satisfies a node depth access condition, a node access graph is generated according to the starting user device node and the user device depth node. The node depth access condition can be a condition that each user device node included in the node access stack in a reverse order of an adding order of being added to the node access stack has no subsequent unvisited node. The node access graph can be a graph composed of a plurality of user device nodes from the starting user device node to the user device depth node. The generation can be performed by using a depth-first search algorithm.

[0039] In sub-step 2, in response to determining that the node access stack does not satisfy the node depth access condition, the user device depth node is determined as the starting user device node to execute the generating step again.

[0040] In sub-step 3, in response to determining that the node unvisited sequence is empty, each obtained node access graph is determined as a user login association sub-graph set. The node unvisited sequence is a user device node access sequence after each access sequence corresponding to each node access graph is removed.

[0041] In a fourth step, in response to determining that the node unvisited sequence is not empty, the node unvisited sequence is determined as a user device node access sequence to execute the determining step again.

[0042] Further, in the process of solving the technical problems mentioned in the background of the application by the technical solutions, the following technical problems often occur: due to the existence of a large number of different types of connection edges and user equipment nodes in the user equipment association graph, and the continuous change, it is difficult to accurately divide the user equipment association graph, resulting in low user association of the user login association subgraph, some useless and error nodes and edges, reducing the accuracy and division speed of the user login association subgraph, increasing the load of the server and reducing the security of the server. In view of the above technical problems, the conventional solution is generally: using a streaming graph division method to divide the user equipment association graph to obtain a user login association subgraph set. However, the above conventional solution still has the following problems: due to the same importance of all user equipment nodes and connection edges in the streaming graph division method, it is difficult to accurately distinguish the importance of different nodes and edges, and the subgraph structure information needs to be obtained in advance when processing the large amount of connection edge and user equipment node data in the partition, resulting in low division efficiency and division speed, uneven division efficiency and division quality, and low quality of the user login association subgraph. Considering the shortcomings of the above conventional solution, and combining the advantages / technical status of the abnormal behavior recognition technology owned by the company, we decide to use the following solution: In some optional implementations of some embodiments, the above-mentioned graph division of the user equipment association graph to obtain a user login association subgraph set can include the following steps: First, the user equipment association graph is time-sliced to obtain an association time sequence graph sequence. The association time sequence graph in the association time sequence graph sequence can be a user equipment association graph formed by a user multi-source login association information set within 1 day. The time slicing can be slicing processing according to a division period of 1 day. The time slicing can capture the structural changes of the user equipment association graph in the time dimension.

[0043] Second, using a user equipment heterogeneous graph attention model, the node semantic attention aggregation of each association time sequence graph in the association time sequence graph sequence is performed to generate a node adjacent relationship fusion feature vector group, and a node adjacent relationship fusion feature vector group sequence is obtained. The user equipment heterogeneous graph attention model can be a deep neural network that aggregates node-level attention and semantic-level attention features of the input association time sequence graph in the association time sequence graph sequence to output node adjacent relationship fusion feature vectors. For example, the user equipment heterogeneous graph attention model can be a heterogeneous graph attention network. The node-level attention can be an attention network for aggregating adjacent nodes of the same type of connection relationship. The semantic-level attention can be an attention network for aggregating adjacent nodes of different types of connection relationships.

[0044] In the third step, the node adjacency relation fusion feature vector group sequence is subjected to time-aware embedding processing to obtain a node time sequence embedding feature vector group sequence. The node time sequence embedding feature vector in the node time sequence embedding feature vector group sequence can be a feature vector after fusing node-level feature information, semantic-level feature information, and time sequence feature information. In practice, the execution subject can perform dynamic graph self-attention network on the node adjacency relation fusion feature vector group sequence to obtain the node time sequence embedding feature vector group sequence.

[0045] In the fourth step, the user equipment association graph is subjected to streaming community division processing according to the node time sequence embedding feature vector group sequence to obtain an initial association community set. The initial association community in the initial association community set can be a community in which the embedding similarity of the node time sequence embedding feature vectors of the user equipment nodes included in the community is relatively similar, the connection edges are relatively dense, and the communities are relatively sparse.

[0046] As an example, the execution subject can first traverse each user equipment node included in the user equipment association graph according to the user equipment node appearance order to obtain a to-be-divided user equipment node sequence. Then, a community is created for the to-be-divided user equipment node at the initial position in the to-be-divided user equipment node sequence to obtain an initial node community. Subsequently, each to-be-divided user equipment node in the to-be-divided user equipment node sequence after removing the to-be-divided user equipment node at the initial position is determined as an output node equipment to obtain a node community set. The determination can be that first, the average value of the cosine similarity of the current to-be-divided user equipment node and each user equipment node included in the node community that has a connection relationship and has completed division is determined, and when the average value is greater than or equal to a preset embedding similarity threshold, the current to-be-divided user equipment node is divided into the node community that has a connection relationship, otherwise, a new node community is created. The preset embedding similarity threshold can be a minimum value that is preset to determine the same node community. For example, the preset embedding similarity threshold can be 0.7. Finally, the initial node community and the node community set are determined as the initial association community set.

[0047] In the fifth step, the initial associated community set is processed by community partition mapping to obtain a mapped associated community set. The mapped associated community in the mapped associated community set can be a community obtained by merging or dividing the initial associated community to achieve load balancing after mapping and partitioning. In practice, the execution subject can first sort the initial associated community set in descending order of community volume to obtain an initial associated community sequence. The community volume can be the sum of the degrees of each user equipment node included in the initial associated community. Then, the community modularity increment groups of each preset community partition in the initial associated community sequence are determined in sequence according to the sorting order to obtain a community modularity increment group set. The community modularity increment can be a value obtained by subtracting the number of edges included in an initial associated community from the number of connection edges in the user equipment association graph to measure the quality of the initial associated community. The community modularity increment can be the proportion of the sum of the normalized weights of the connection edges of the initial associated community to the sum of the normalized weights of the user equipment association graph, and the difference between the proportion of the total degree of the user equipment nodes included in the initial associated community to the total degree of the user equipment association graph. Finally, the initial associated community set is processed by community partition mapping according to the community modularity increment group set by using a greedy algorithm to obtain the mapped associated community set.

[0048] In the sixth step, the overload edge set and the cut edge set included in the above-mentioned mapping associated community set are subjected to community-aware partitioning to obtain a mapping-optimized associated community set as the user login associated subgraph set. The overload edge in the above-mentioned overload edge set can be an edge that exceeds the load corresponding to the preset community partition set. The cut edge in the above-mentioned cut edge set can be an edge between the mapping associated communities included in the mapping associated community set. The above-mentioned mapping-optimized associated community set can be a community set obtained by allocating the overload edge set and the cut edge set to the above-mentioned mapping associated community set. In practice, the above-mentioned execution subject can perform the following awareness partitioning steps for each edge in the above-mentioned overload edge set and the cut edge set: first, determine the mapping associated communities in which the two user equipment nodes associated with the edge are located to obtain a first mapping associated community and a second mapping associated community. Second, determine the normalized edge weight values of the edges connected to the two associated user equipment nodes, respectively, as a first associated edge weight value and a second associated edge weight value. Third, determine a first replication factor value and a second replication factor value of the edge belonging to the first mapping associated community and the second mapping associated community, respectively. The first replication factor score can be 2, the ratio of the first associated edge weight value, the difference between the first associated edge weight value and the second associated edge weight value, and the sum of 0 if the first user equipment node of the two associated user equipment nodes is in the first mapping associated community and the second user equipment node is in the second mapping associated community. The 0 can be 0 because the second user equipment node is not in the first mapping associated community. Next, determine a first semantic association value and a second semantic association value of the edge belonging to the first mapping associated community and the second mapping associated community, respectively. The first semantic association value can be the product of the cosine similarity value of the node time sequence embedding feature vector of the first user equipment node and the average node time sequence embedding feature vector of the node time sequence embedding feature vector set included in the first mapping associated community, and the normalized weight value of the edge. Then, determine the sum of the first replication factor value and the first semantic association value as a first edge allocation value, and determine the sum of the second replication factor value and the second semantic association value as a second edge allocation value. Finally, determine the value with a larger value between the first edge allocation value and the second edge allocation value as a target edge allocation value, and allocate the edge to the mapping associated community in which the target edge allocation value is located. If the load of the mapping associated community in which the target edge allocation value is located exceeds the preset community load, the edge is subjected to community-aware partitioning by a DBH (Dynamic Balance Hierarchy) edge partitioning method to obtain a mapping-optimized associated community set as the user login associated subgraph.

[0049] In the seventh step, the flow transfer linkage abnormal association graph set is determined according to the user login associated subgraph set, and the terminal equipment corresponding to the flow transfer linkage abnormal association graph set is subjected to flow transfer interception control. The specific implementation manner of this step can refer to the implementation manners of steps 104-107, which will not be described again.

[0050] The technical solutions and related contents described above are one of the invention points of the embodiments of the present disclosure, which solve the technical problems mentioned in the background art. The factors that lead to the reduction of the accuracy and division speed of the user login association subgraph, the increase of the load of the server and the reduction of the security of the server are often as follows: due to the existence of a large number of different types of connection edges and user equipment nodes in the user equipment association graph, and the continuous change, it is difficult to accurately divide the user equipment association graph, resulting in low user association of the user login association subgraph obtained by division, some useless and incorrect nodes and edges, reducing the accuracy and division speed of the user login association subgraph, increasing the load of the server and reducing the security of the server. If the above factors are solved, the accuracy and division speed of the user login association subgraph can be improved, the load of the terminal device can be reduced, and the security can be improved. In order to achieve this effect, the present disclosure first performs time slicing processing on the user equipment association graph, and performs node-level, semantic-level and time sequence-level embedding on the association time sequence slice graph sequence, which can capture the structural changes of the graph in the time dimension in real time, accurately measure the different weights of the heterogeneous edges and heterogeneous nodes of the user equipment association graph, improve the comprehensiveness and accuracy of the node time sequence embedding feature vector, and avoid the semantic fragmentation caused by subsequent division. Secondly, according to the node time sequence embedding feature vector group sequence, the streaming community division is performed, which can reduce the memory consumption through single-pass scanning division, can provide global graph structure guidance for subsequent community partition mapping processing, and can avoid semantic fragmentation caused by division. Then, the initial association community set is subjected to community partition mapping processing, which can preserve the integrity of the community and ensure the load balancing of the mapped association community set, and through wired allocation of the same community edge, the number of partition edges can be reduced, and the division data amount of subsequent community perception can be reduced. After that, the community perception division is performed on the overloaded edge set and the cut edge set, and the mapping optimization association community set is obtained. By determining only the user equipment nodes associated with the edge mapping association community, the calculation amount can be reduced, the processing speed of the community perception division can be improved, and by combining the replication factor value and the semantic association value for perception, the perception division quality and speed can be balanced. Finally, the flow transfer linkage abnormal association graph set is determined, and the terminal device corresponding to the flow transfer linkage abnormal association graph set is subjected to flow transfer interception control, which can improve the accuracy of the flow transfer interception of the terminal device, improve the security of the server and effectively reduce the load of the server.

[0051] Step 104, the user value object flow information set is subjected to flow relationship mining to obtain a flow relationship information set.

[0052] In some embodiments, the execution subject described above can perform flow relationship mining on the user value object flow information set described above to obtain a flow relationship information set. The user value object flow information in the flow relationship information set can be information extracted and mined from the user value object flow information set, representing the connection relationship between the user information and the user value object. The flow relationship information can include, but is not limited to, at least one of the following: flow frequency, flow attribute value (transaction amount), flow attribute value change information, value object flow unit price information (transaction price), flow days, value object storage flow state information (stock holding state information). In practice, the execution subject can first use an association rule mining algorithm to perform flow relationship mining processing on the user value object flow information set to obtain a flow mining relationship information set. The association rule mining algorithm can be an Apriori algorithm. Then, at least one flow mining relationship information that meets the flow relationship constraint condition is selected from the flow mining relationship information set. The flow relationship constraint condition can be a condition that the flow buy or sell attribute value (transaction amount) is greater than or equal to a preset flow attribute threshold value. The preset flow attribute threshold value can be the minimum value of the preset flow attribute value. Then, the Pearson correlation coefficient algorithm is used to determine the relationship correlation degree value set of the at least one flow mining relationship information. Finally, a plurality of flow mining relationships corresponding to the relationship correlation degree value less than or equal to a preset correlation degree threshold value are selected from the at least one flow mining relationship information to obtain a flow relationship information set. The preset correlation degree threshold value can be a preset maximum value representing any two flow mining relationship information.

[0053] Step 105, generating a user value object flow graph according to the user value object flow information set and the flow relationship information set.

[0054] In some embodiments, the aforementioned executing entity can generate a user value object circulation graph based on the aforementioned user value object circulation information set and the aforementioned circulation relationship information set. The aforementioned user value object circulation graph can be a knowledge graph describing the connection relationships between user information and value objects. Nodes in the aforementioned user value object circulation graph can include user nodes and value object nodes. Connecting edges in the aforementioned user value object circulation graph can include, but are not limited to, at least one of the following: minimum successful inflow count (minimum number of buy transactions per day) within a preset time range, maximum successful inflow count (maximum number of buy transactions per day) within a preset time range, percentage of minimum successful inflow count, circulation buy, circulation sell, circulation attribute value (transaction amount), circulation days, and value object storage (securities holdings). The aforementioned preset time range can be a pre-defined time range for value object circulation. For example, the aforementioned preset time range can be 20 days. Figure 3 As shown, Figure 3 It displays a user value object flow graph consisting of user nodes and value object nodes.

[0055] As an example, the aforementioned execution entity can first use a named entity recognition model to perform entity recognition on the aforementioned user value object flow information set, obtaining a user entity node information set and a value object entity node information set. The named entity recognition model can be a deep neural network used to identify the user entities and user value entities included in the aforementioned user value object flow information set. For example, the named entity recognition model can be a model composed of a Bidirectional Long Short-Term Memory (BiLSTM) and a Conditional Random Field (CRF) connected in series. Then, a set of flow triples is generated for the user entity node information set, the value object entity node information set, and the aforementioned flow relationship information set. Finally, the flow triples are input into a graph database to obtain a user value object flow graph.

[0056] In some optional implementations of certain embodiments, generating a user value object flow graph based on the user value object flow information set and the flow relationship information set may include the following steps: The first step is to preprocess the aforementioned user value object flow information set to obtain a preprocessed user value object flow information set. This preprocessing may include, but is not limited to, at least one of the following: data cleaning, format conversion, missing value handling, outlier detection, and standardization and normalization.

[0057] Secondly, the pre-processed user value object circulation information set is filtered to obtain a target value object circulation information set. The target value object circulation information in the target value object circulation information set can be filtered from the pre-processed user value object circulation information set under the condition that the user information and the value object information participating in circulation within 20 days closest to the current time are filtered, and the transaction amount of the connection edge of the user information and the value object information is greater than or equal to a preset circulation attribute threshold. The preset circulation attribute threshold can be the minimum value of the preset circulation attribute value.

[0058] Thirdly, a user portrait is constructed based on the target value object circulation information set to obtain a user circulation index information set. The user circulation index information in the user circulation index information set can be information describing the style (user transaction style) and personal preference of the user for value object circulation. The user circulation index information set can include but is not limited to at least one of the following: user basic attribute value (net asset), value object circulation board information (preferred listed board), user preference information about value object (preferred industry), preferred selection information of circulating value object (circulating plate preference), value object attribute value selection preference information (security price preference), and value object selection ability information (stock selection ability information).

[0059] Fourthly, value object index information is extracted from the target value object circulation information set to obtain a value object index information set. The value object index information in the value object index information set can be information describing the value object. The value object index information set can include but is not limited to at least one of the following: value object derived index information, value object market attribute value (security market value), value object circulation transaction attribute value (security transaction amount), value object conversion object frequency (security turnover rate), value object P / E ratio, value object P / B ratio, and value object suspension state information. The value object derived index information can be index information of changes derived from the attribute value (price) of the value object itself. For example, the value object derived index information can include but is not limited to at least one of the following: the difference between the absolute value of the price fluctuation range of the value object itself, the maximum value and the minimum value of the attribute value of the value object within one year, and the correlation between the current attribute value of the value object and the historical maximum point or minimum point.

[0060] In the fifth step, the user flow indicator information set, the value object indicator information set, and the flow relationship information set are used to construct triples to obtain a flow triple set. The flow triple in the flow triple set can be a data structure in the form of a triple representing the association relationship between the user flow indicator information, the value object indicator information, and the flow relationship information. For example, the flow triple can be <user preference information, flow attribute value, value object type>.

[0061] In the sixth step, the flow triple set is input into a preset graph database to obtain a user value object flow graph. The preset graph database can be an existing database for storing graph data structures. For example, the preset graph database can be a Neo4j database.

[0062] In step 106, the user value object flow graph is subjected to abnormal flow linkage identification according to the user login association subgraph set to obtain a flow linkage abnormal association graph set.

[0063] In some embodiments, the execution subject can identify the abnormal flow linkage of the user value object flow graph according to the user login association subgraph set to obtain a flow linkage abnormal association graph set. The flow linkage abnormal association graph in the flow linkage abnormal association graph set can be a subgraph in which the value object flow relationship between each user node included in the user login association subgraph exhibits converging transaction abnormal behavior. The flow linkage abnormal association graph can be an association graph including only user nodes.

[0064] In some optional implementations of some embodiments, the identification of the abnormal flow linkage of the user value object flow graph according to the user login association subgraph set to obtain a flow linkage abnormal association graph set can include the following steps: In the first step, the user value object node set and the flow edge set included in the user value object flow conversion graph are subjected to feature extraction to obtain a flow node feature vector set and a flow edge feature vector set. The user value object node in the user value object node set can be a user node or a value object node. The flow node feature vector in the flow node feature vector set can represent the attribute information of the user value object node set in the form of a feature vector. The flow edge feature vector in the flow edge feature vector set can represent the association strength and frequency between the two connected user value object nodes in the form of a feature vector. In practice, the execution subject can first standardize the numerical data included in the user value object node set and the flow edge set to obtain a first flow node feature vector set and a first flow edge feature vector set. Then, the categorical data included in the user value object node set and the flow edge set are subjected to one-hot encoding to obtain a second flow node feature vector set and a second flow edge feature vector set. Finally, the first flow node feature vector set, the first flow edge feature vector set, the second flow node feature vector set, and the second flow edge feature vector set are subjected to feature splicing to obtain the flow node feature vector set and the flow edge feature vector set.

[0065] In the second step, based on the user value object graph identification layer included in the user value object graph identification model, the following associated graph generation step is performed: Sub-step 1, determine the adjacent node feature vector group set of the flow node feature vector set, wherein the user value object graph identification model comprises a multi-layer user value object graph identification layer. The user value object graph identification model can be a graph depth neural network model that integrates the input flow edge feature vector set into the message aggregation of the flow node feature vector set according to the depth, and superimposes the flow node feature vector set according to the importance of the node. The user value object graph identification layer can be a graph depth neural network layer that performs importance embedding on the input flow node feature vector set and flow edge feature vector set. The adjacent node feature vector group in the adjacent node feature vector group set can be the feature vector set of the adjacent user value object node set having a one-hop connection relationship with the user value object node. The user value object graph identification model is trained by the following steps: first, generate a model training positive sample set and a negative sample set. The positive sample set can be randomly selected 1000 user nodes, and user nodes having the same type of flow edge as each user node are selected as the positive sample set. The negative sample set can be randomly selected 50 user nodes as negative samples for each user node. The training number of positive samples can be 1000, and the training number of negative samples can be 50,000. The positive sample needs to be deleted when training the user value object graph identification model to prevent data leakage. Second, the model training positive sample set and the negative sample set are trained by the Mini-Batch method. In the Mini-Batch method, each batch includes a graph composed of one model training positive sample and one negative sample, and the target node set included in one model training positive sample and one negative sample is the inner target node set, and the first-order adjacent and second-order adjacent nodes of the target node set constitute a heterogeneous batch. The training parameters of the user value object graph identification model can include: the period can be 10, the sample pair included in each batch can be 1024, the learning rate can be 0.001, and the loss function can be the dot product between the sample pair composed of the model training positive sample and the negative sample.

[0066] Sub-step 2, input the flow edge feature vector set to the edge encoder included in the user value object graph identification layer to obtain the edge encoding feature vector set, wherein the user value object graph identification layer further comprises a relationship perception attention mechanism and a graph structure fusion layer. The edge encoder can be a deep neural network that maps the input flow edge feature vector set to a high-dimensional representation and embeds depth information. For example, the edge encoder can be a multi-layer perception machine. The edge encoding feature vector in the edge encoding feature vector set can be a high-dimensional representation including depth information and attribute information of the flow edge.

[0067] Sub-step 3, after feature splicing of the edge coding feature vector set and the adjacent embedding feature vector group set, a linear transformation is performed to obtain a spliced and transformed feature vector group set. The spliced and transformed feature vector in the spliced and transformed feature vector group set can be a feature vector obtained by fusing the feature information of the adjacent user value object node and the adjacent flow edge and then performing linear transformation. The linear transformation can be a linear transformation performed by a linear layer.

[0068] Sub-step 4, using a relationship-aware attention mechanism, an association relationship attention weight set is generated according to the spliced and transformed feature vector group set and the flow node feature vector set. The association relationship attention weight in the association relationship attention weight set can represent the importance weight of each adjacent user value object node to the user value object node. The relationship-aware attention mechanism can be an attention mechanism for determining different importance degrees of each adjacent user value object node to the user value object node. For example, the relationship-aware attention mechanism can be a neural network including a feedforward network, a LeakyReLU activation function and a Softmax activation function connected in series. In practice, the execution subject can first perform feature splicing on the spliced and transformed feature vector set and the flow node feature vector set to obtain a spliced node feature vector set. Then, the spliced node feature vector set is input into the relationship-aware attention mechanism for normalization processing to obtain the association relationship attention weight set.

[0069] Sub-step 5, by a graph structure fusion layer, feature fusion is performed on the association relationship attention weight set and the spliced and transformed feature vector group set to obtain a node fusion feature vector set. The graph structure fusion layer can be a deep neural network model for fusing adjacent nodes based on graph structure based on the input association relationship attention weight set and the spliced and transformed feature vector set. For example, the graph structure fusion layer can be a graph convolution network. The node fusion feature vector in the node fusion feature vector set can be a feature vector that fuses adjacent user value object nodes with different influence degrees and feature vectors of adjacent flow edges. The node fusion feature vector can represent information of user information flowing to value object information. In practice, the execution subject can first perform weighted summation on each association relationship attention weight in the association relationship attention weight set and the corresponding spliced and transformed feature vector group in the spliced variable feature vector group set, and then perform cumulative summation to obtain an attention weight fusion feature vector set. Then, the attention weight fusion feature vector set is input into the graph structure fusion layer to obtain the node fusion feature vector set.

[0070] Sub-step 6, in response to determining that the value object graph identification layer meets the model layer constraint condition, generating a set of flow linkage abnormal association graphs according to the set of node fusion feature vectors and the set of user login association sub-graphs. Wherein, the model layer constraint condition can be that the value object graph identification layer is the identification layer located at the last layer of the user value object graph identification model.

[0071] Optionally, the method can further include the following steps: First step, in response to determining that the value object graph identification layer does not meet the model layer constraint condition, determining the value object graph identification layer located after the value object graph identification layer as the value object graph identification layer.

[0072] Second step, determining the set of node fusion feature vectors as the set of flow node feature vectors.

[0073] Third step, determining each node fusion feature vector in the set of node fusion feature vectors that has a target association relationship with the node fusion feature vector as an adjacent node feature vector, obtaining a set of adjacent node feature vectors, and executing the association graph generation step again. Wherein, the target association relationship can be that the user value object node corresponding to the node fusion feature vector has a one-hop connection relationship.

[0074] In some optional implementations of some embodiments, the generating a set of flow linkage abnormal association graphs according to the set of node fusion feature vectors and the set of user login association sub-graphs can include the following steps: First step, filtering out the node fusion feature vectors representing user nodes from the set of node fusion feature vectors to obtain a set of user node fusion feature vectors.

[0075] Second step, for each user node fusion feature vector in the set of user node fusion feature vectors, executing the following abnormal association graph generation step: Sub-step 1, determining the user node similarity between the user node fusion feature vector and each node fusion feature vector in the set of node fusion feature vectors to obtain a user node similarity group. Wherein, the user node similarity can represent the similarity between the corresponding two user nodes in the flow behavior information of the value object information. The determination can be made using the cosine similarity formula.

[0076] Sub-step 2, according to the user node similarity group described above, the user node fusion feature vector set is screened to obtain the screened user node fusion feature vector set. Wherein, the screened user node fusion feature vector set can be empty set, can also be non-empty set. As an example, the execution subject can first filter out the user node fusion feature vector greater than or equal to the preset similarity threshold value from the user node fusion feature vector set, as the target user node fusion feature vector, to obtain the target user node fusion feature vector set. The preset similarity threshold value can be a preset minimum value for determining whether there is similar value object flow behavior between the user nodes corresponding to the user node fusion feature vector. For example, the preset similarity threshold value can be 0.8. Then, the target user node fusion feature vector set located in the top 20 after the user node similarity is sorted from high to low is filtered out from the target user node fusion feature vector set, as the screened user node fusion feature vector set.

[0077] Sub-step 3, determine the user node set existing in the user node set corresponding to the screened user node fusion feature vector set and the user node set included in the user login association subgraph set at the same time, to obtain the target user node set.

[0078] Sub-step 4, determine the user node proportion value of the target user node set and the user node set included in the user login association subgraph set. Wherein, the user node proportion value can represent the ratio of the number of user nodes with similar value object flow behavior to the number of user nodes included in the user login association subgraph. In practice, the execution subject can determine the ratio of the number of target user nodes included in the target user node set to the number of user nodes included in the user node set included in the user login association subgraph set as the user node proportion value.

[0079] Sub-step 5, in response to determining that the user node proportion value is greater than or equal to the preset node proportion threshold value, generating a flow linkage abnormal association graph according to the target user node set. Wherein, the preset node proportion threshold value can be a preset critical value for determining abnormal flow linkage. For example, the preset node proportion threshold value can be 0.4.

[0080] As an example, the execution subject can first filter out at least one target user node satisfying the preset flow attribute value condition from the target user node set. Wherein, the preset flow attribute value condition can be a condition that the flow attribute value (transaction amount) of the value object information between the target user nodes is greater than or equal to the preset flow attribute threshold value. The preset flow attribute threshold value can be a preset maximum attribute value. Then, the subgraph including the at least one target user node corresponding to the user value object flow graph is filtered out as the flow linkage abnormal association graph.

[0081] Further, in the process of solving the technical problems mentioned in the background of the application by the technical solutions, the following technical problems often occur: due to the dynamic changes of the value object flow behavior, it is difficult to accurately describe the timing of the flow behavior, and it is difficult to detect short-term user linkage abnormal flow behavior, there is a missed detection problem, resulting in low accuracy of abnormal flow linkage recognition, increasing the flow request load of the server, and reducing the security of the server. In view of the above technical problems, the conventional solution is generally: multiple static graphs of dynamic changes of flow behavior are analyzed, and the proportion of the node similarity of the user value object flow graph in the corresponding user login association subgraph is greater than the preset threshold value for abnormal identification, and the flow linkage abnormal association graph set is obtained. However, the above conventional solution still has the following problems: multiple analyses are performed through static graphs, there are repeated contents for multiple abnormal identifications, resulting in low speed of abnormal identification, and fixed threshold for abnormal identification can easily lead to high false negative rate and high false positive rate, in addition, the similarity calculation of the node only measures the node features, and does not consider the influence of heterogeneous association relationship, resulting in low accuracy of abnormal identification, high flow request load of the server, and low security of the server. The inventors consider the shortcomings of the above conventional solution, and combine the advantages / technical status of the abnormal behavior identification technology possessed by the company where the inventors work, and we decide to adopt the following solution: In some optional implementations of some embodiments, the above abnormal flow linkage identification of the user value object flow graph based on the user login association subgraph set can include the following steps: First, the user login association subgraph set and the user value object flow graph are subjected to heterogeneous graph completion fusion processing to obtain a user flow heterogeneous graph set. The user flow heterogeneous graph in the user flow heterogeneous graph set can be a heterogeneous graph obtained by adding the user nodes, value object nodes and corresponding flow edges included in the user value object flow graph to the user login association subgraph for graph fusion. In practice, the execution subject can first fuse the user login association subgraph set and the corresponding subgraph set in the user value object flow graph according to the user nodes to obtain a fusion graph set. Then, the fusion graph set is subjected to graph disambiguation to obtain a disambiguated fusion graph set. Finally, the disambiguated fusion graph set is subjected to meta-path-based relationship completion processing to obtain the user flow heterogeneous graph set.

[0082] Secondly, the user flow conversion heterogeneous graph set is subjected to time edge embedding processing to obtain a user flow conversion time heterogeneous graph set. The user flow conversion time heterogeneous graph in the user flow conversion time heterogeneous graph set can be a heterogeneous graph embedded with time information in a day as a construction period. In practice, the execution subject can use ST-GCN (Spatio-Temporal Convolutional Networks) to perform time edge embedding processing on the user flow conversion heterogeneous graph set to obtain the user flow conversion time heterogeneous graph set.

[0083] Thirdly, the user flow conversion time heterogeneous graph set is subjected to meta-path fusion to obtain a node path fusion feature vector set. The node path fusion feature vector in the node path fusion feature vector set can represent the dynamic weight of the meta-path determined heterogeneous connection edge and the multi-dimensional attribute information of the heterogeneous node. In practice, the execution subject can use RGAT (Relation-based Graph Attention) to perform meta-path fusion on the user flow conversion time heterogeneous graph set to obtain the node path fusion feature vector set.

[0084] Fourthly, the cosine similarity set, the adjacency distance similarity set and the global similarity set of each user node included in the user flow conversion heterogeneous graph set are determined. The cosine similarity in the cosine similarity set can be used to describe the local similarity between nodes with an association relationship, emphasizing explicit association. The adjacency distance similarity in the adjacency distance similarity set can be used to describe the similarity of node neighbor structure, emphasizing contextual association, i.e., two nodes are similar if they have similar neighbors. The global similarity in the global similarity set can be used to describe the global similarity of multi-hop paths (greater than or equal to 3) or subgraph structures to capture nonlinear relationships. The adjacency distance similarity can be a similarity obtained by a LINE (Large-scale Information Network Embedding) second-order loss algorithm. The global similarity can be a similarity obtained by a tensor decomposition formula.

[0085] Fifthly, the user value object flow graph is subjected to preliminary flow linkage identification according to the cosine similarity set, the adjacency distance similarity set and the global similarity set to obtain a preliminary flow linkage graph set. The preliminary flow linkage graph in the preliminary flow linkage graph set can be an influence-oriented subgraph sampled from the user value object flow graph to retain high-weight adjacent nodes of core nodes.

[0086] As an example, the execution subject can first perform dynamic weighted summation processing on the cosine similarity set, the adjacency distance similarity set, and the global similarity set to obtain a node multi-order similarity set. Then, according to the node multi-order similarity set, the core node set is selected from the user value object flow conversion graph by the PageRank algorithm. Finally, the adjacency subgraph of the core node set is determined by the eigenvector centrality algorithm to obtain a preliminary flow conversion linkage graph set.

[0087] In the sixth step, the counterfactual verification result information set is obtained by performing counterfactual verification processing on the initial flow conversion linkage graph set. The counterfactual verification result information in the counterfactual verification result information set can represent information about whether the causal relationship in the causal graph exists. The causal graph in the causal graph set can be a graph in the initial flow conversion linkage graph that has a causal relationship.

[0088] In the seventh step, the terminal device set of each user included in the flow conversion linkage abnormal association graph set is requested to perform flow conversion interception control according to the counterfactual verification result information set.

[0089] As an example, the execution subject can first generate a generative flow conversion linkage identification on at least one initial flow conversion linkage graph in the counterfactual verification result information set that represents a failed verification to obtain a generative abnormal subgraph set. The generative abnormal subgraph in the generative abnormal subgraph set can be an initial flow conversion linkage graph that has a user convergence linkage abnormality. The generative flow conversion linkage identification can be an abnormality identification performed by a generative adversarial network. Then, the generative abnormal subgraph set and at least one initial flow conversion linkage graph that represents a passed verification are determined as a flow conversion linkage abnormal association graph set, and the terminal device set of each user included in the flow conversion linkage abnormal association graph set is requested to perform flow conversion interception control.

[0090] The technical solution and related content above are an inventive point of an embodiment of the present disclosure, which solves the technical problem mentioned in the background art that it is difficult to accurately describe the time sequence of the flow behavior of the value object and to detect short-term user linkage abnormal flow behavior due to the dynamic changes in the flow behavior of the value object, there is a missed detection problem, which leads to low accuracy of abnormal flow linkage recognition, increases the flow request load of the server, and reduces the security of the server. The factors that lead to low accuracy of abnormal flow linkage recognition, increase the flow request load of the server, and reduce the security of the server are often as follows: it is difficult to accurately describe the time sequence of the flow behavior of the value object and to detect short-term user linkage abnormal flow behavior due to the dynamic changes in the flow behavior of the value object, there is a missed detection problem, which leads to low accuracy of abnormal flow linkage recognition, increases the flow request load of the server, and reduces the security of the server. If the above factors are solved, the accuracy of abnormal flow linkage recognition can be improved, the flow request load of the server can be reduced, and the security of the server can be improved. To achieve this effect, the present disclosure first fuses the user login correlation subgraph set and the user value object flow graph, and then performs time sequence embedding and meta-path fusion, which can fuse more dimensional attribute information of each node and edge, and capture multi-scale time sequence information, to accurately describe the incremental dynamic changes of the flow behavior and reduce the computational overhead of repeated content abnormal recognition. Meta-path fusion can assign weights according to meta-paths to accurately reflect the heterogeneity of the heterogeneous graph. Secondly, the cosine similarity set, the adjacency distance similarity set, and the global similarity set are determined and weighted summed, which can dynamically integrate multi-dimensional information to facilitate subsequent discovery of potential hidden flow linkage user groups. Then, preliminary flow linkage recognition is performed through the node multi-order similarity set, and the influence-oriented subgraph sampling can reduce the size of the subgraph and reduce the computational resource consumption of subsequent abnormal recognition. After that, generative flow linkage recognition is performed after the counterfactual verification processing of the causal graph set. Through the analysis of the causal relationship in the initial flow linkage graph set, pseudo-related transactions can be filtered, and real causal relationships can be retained, which improves the accuracy of user group linkage abnormal recognition. Counterfactual verification and generative abnormal recognition can further improve the determination of causal relationships, reduce the false positive rate of abnormalities, and improve the accuracy of abnormal flow linkage recognition. Finally, the terminal device set of each user included in the flow linkage abnormal association graph set is subjected to flow transfer interception control, which can effectively reduce the flow request load of the server and improve the security of the server.

[0091] In step 107, the flow linkage abnormal association graph set is sent to a flow alarm device to control the flow alarm device to monitor and warn the value object flow information of the terminal device set corresponding to the flow linkage abnormal association graph set, and in response to determining that the flow alarm device sends warning information, the terminal device set is subjected to flow transfer interception control.

[0092] In some embodiments, the execution subject can send the flow linkage abnormal association graph set to a flow alarm device to control the flow alarm device to monitor and warn the value object flow information of the terminal device set corresponding to the flow linkage abnormal association graph set, and in response to determining that the flow alarm device sends a warning information, to control the flow interception of the terminal device set. The flow alarm device can be a terminal device for abnormally alarming the identified behavior of converging transactions. The flow interception control can include, but is not limited to, at least one of the following: discarding the flow request of the terminal device, starting a form submission task to prohibit the flow operation of the value object corresponding to the terminal device, and modifying the device type of the terminal device in the server to an abnormal device.

[0093] Further referring to Figure 4 , as an implementation of the method shown in the above figures, the present disclosure provides some embodiments of a terminal device control apparatus based on flow linkage, which corresponds to the method embodiments shown in Figure 1 , and the terminal device control apparatus based on flow linkage can be applied to various electronic devices.

[0094] As shown in Figure 4 , a terminal device control apparatus 400 based on flow linkage includes an acquisition unit 401, a knowledge graph construction unit 402, a graph division unit 403, a flow relationship mining unit 404, a generation unit 405, an abnormal flow linkage identification unit 406, and a flow interception control unit 407. The acquisition unit 401 is configured to acquire a user multi-source login association information set and a user value object flow information set. The knowledge graph construction unit 402 is configured to construct a user device association graph based on the user multi-source login association information set. The graph division unit 403 is configured to divide the user device association graph into a user login association subgraph set. The flow relationship mining unit 404 is configured to mine a flow relationship information set from the user value object flow information set. The generation unit 405 is configured to generate a user value object flow graph based on the user value object flow information set and the flow relationship information set. The abnormal flow linkage identification unit 406 is configured to identify an abnormal flow linkage association graph set from the user login association subgraph set based on the user value object flow graph. The flow interception control unit 407 is configured to send the abnormal flow linkage association graph set to a flow alarm device to control the flow alarm device to monitor and warn the value object flow information of the terminal device set corresponding to the abnormal flow linkage association graph set, and in response to determining that the flow alarm device sends a warning information, to control the flow interception of the terminal device set.

[0095] It can be understood that the units described in the terminal equipment control device 400 based on flow conversion linkage correspond to the respective steps in the method described above. Figure 1 The operations, features, and advantages described above for the method also apply to the terminal equipment control device 400 based on flow conversion linkage and the units contained therein, and are not repeated here.

[0096] Reference is made below to Figure 5 which shows a structural schematic diagram of an electronic device (e.g., an electronic device) 500 suitable for implementing some embodiments of the present disclosure. Figure 5 The electronic device shown is merely an example and should not impose any limitation on the function and scope of use of embodiments of the present disclosure.

[0097] As shown in Figure 5 , the electronic device 500 can include a processing device (e.g., a central processor, a graphics processor, etc.) 501 that can perform various appropriate actions and processes according to programs stored in a read-only memory (ROM) 502 or loaded from a storage device 508 into a random access memory (RAM) 503. In the RAM 503, various programs and data required for the operation of the electronic device 500 are also stored. The processing device 501, the ROM 502, and the RAM 503 are connected to each other through a bus 504. An input / output (I / O) interface 505 is also connected to the bus 504.

[0098] Generally, the following devices can be connected to the I / O interface 505: input devices 506 including, for example, a touch screen, a touchpad, a keyboard, a mouse, a camera, a microphone, an accelerometer, a gyroscope, etc.; output devices 507 including, for example, a liquid crystal display (LCD), a speaker, a vibrator, etc.; storage devices 508 including, for example, a magnetic tape, a hard disk, etc.; and communication devices 509. The communication devices 509 can allow the electronic device 500 to communicate wirelessly or wired with other devices to exchange data. Although Figure 5 The electronic device 500 is shown with various devices, but it should be understood that all the devices shown are not required to be implemented or possessed. More or fewer devices can be alternatively implemented or possessed. Figure 5 Each block shown in

[0099] In particular, the processes described above with reference to the flowcharts can be implemented as a computer software program according to some embodiments of the present disclosure. For example, some embodiments of the present disclosure include a computer program product comprising a computer program carried on a computer readable medium, the computer program comprising program code for performing the methods illustrated by the flowcharts. In some such embodiments, the computer program can be downloaded and installed from a network via the communication device 509, or installed from the storage device 508, or installed from the ROM 502. When the computer program is executed by the processing device 501, the above-mentioned functions defined in the methods of some embodiments of the present disclosure are performed.

[0100] It should be noted that the computer readable medium mentioned above in some embodiments of the present disclosure can be a computer readable signal medium or a computer readable storage medium or any combination of the two. The computer readable storage medium may, for example, be, but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, device or apparatus, or any combination of the above. More specific examples of the computer readable storage medium can include, but are not limited to, an electrical connection having one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In some embodiments of the present disclosure, the computer readable storage medium can be any tangible medium that contains or stores a program that can be used by or in connection with an instruction execution system, apparatus or device. In some embodiments of the present disclosure, the computer readable signal medium can include a data signal carried in a baseband or as part of a carrier wave, in which the computer readable program code is carried. Such a propagated data signal can take many forms, including but not limited to, an electromagnetic signal, an optical signal, or any suitable combination of the above. The computer readable signal medium can also be any computer readable medium that is not a computer readable storage medium and that can communicate, propagate or transport a program for use by or in connection with an instruction execution system, apparatus or device. The program code contained on the computer readable medium can be transmitted by any suitable medium, including but not limited to, wire, cable, RF (radio frequency), etc., or any suitable combination of the above.

[0101] In some embodiments, the client, server, or both can communicate using any known or later developed form of computer-readable media, including wireless media, wire-based media, optical or electrical media, and the like. The information can be communicated using any known or later developed form of medium or protocol, including wireless media, wire-based media, optical or electrical media, and the like. Examples of a communication network include a local area network ("LAN"), a wide area network ("WAN"), the Internet, and peer-to-peer networks (e.g., ad hoc peer-to-peer networks), as well as any currently known or later developed networks.

[0102] The computer-readable medium described above can be included in the electronic device described above; or can exist separately from the electronic device and can be accessed via the electronic device. The computer-readable medium described above carries one or more programs that, when executed by the electronic device, cause the electronic device to: acquire a user multi-source login association information set and a user value object flow transfer information set; perform knowledge graph construction on the user multi-source login association information set to obtain a user device association graph; perform graph division on the user device association graph to obtain a user login association subgraph set; perform flow transfer relationship mining on the user value object flow transfer information set to obtain a flow transfer relationship information set; generate a user value object flow transfer graph according to the user value object flow transfer information set and the flow transfer relationship information set; perform abnormal flow transfer linkage identification on the user value object flow transfer graph according to the user login association subgraph set to obtain a flow transfer linkage abnormal association graph set; and send the flow transfer linkage abnormal association graph set to a flow transfer alarm device to control the flow transfer alarm device to perform monitoring and early warning processing on value object flow transfer information of a terminal device set corresponding to the flow transfer linkage abnormal association graph set, and in response to determining that the flow transfer alarm device sends an early warning information, perform flow transfer interception control on the terminal device set.

[0103] Computer program code for carrying out operations of some embodiments of the present disclosure can be written in any of one or more programming languages, including object oriented programming languages such as Java, Smalltalk, C++, or conventional procedural programming languages, such as the "C" programming language or similar programming languages. The program code can execute entirely on the user's computer, partly on the user's computer, as a stand-alone software package, partly on the user's computer and partly on a remote computer, or entirely on the remote computer or server. In the latter scenario, the remote computer can be connected to the user's computer through any type of network, including a local area network ("LAN") or a wide area network ("WAN"), or the connection can be made to an external computer (for example, through the Internet using an Internet Service Provider).

[0104] The flow diagrams and the block diagrams in the drawings are illustrations of architectures, functionalities, and operations of possible implementations of systems, methods, and computer program products according to various embodiments of present disclosure. In this regard, each block in the flow diagrams or block diagrams can represent a module, a segment, or a portion of code, which comprises one or more executable instructions for implementing the specified logical function(s). It should also be noted that in some alternative implementations, the functions noted in the block can occur out of the order noted in the figures. For example, two blocks shown in succession may, in fact, be executed substantially concurrently or the blocks may sometimes be executed in the reverse order, depending upon the functionality involved. It will also be noted that each block of the block diagrams and / or flow diagrams, and combinations thereof, can be implemented by special purpose hardware-based systems that perform the specified functions or operations, or combinations of special purpose hardware and computer instructions.

[0105] The units described in some embodiments of the present disclosure can be implemented by means of software, or implemented by means of hardware. The described units can also be arranged in a processor, for example, it can be described that: a processor includes an acquisition unit, a knowledge graph construction unit, a graph division unit, a flow transfer relationship mining unit, a generation unit, an abnormal flow transfer linkage identification unit and a flow transfer interception control unit. Among them, the names of these units do not constitute a limitation to the units themselves in some cases, for example, the acquisition unit can also be described as "a unit for acquiring a user multi-source login association information set and a user value object flow transfer information set".

[0106] The functions described above in this document can be performed, at least in part, by one or more hardware logic components. For example, non-limiting example types of hardware logic components that can be used include: Field-programmable Gate Arrays (FPGAs), Application-specific Integrated Circuits (ASICs), Application-specific Standard Products (ASSPs), System-on-a-chip systems (SOCs), Complex Programmable Logic Devices (CPLDs), etc.

[0107] The above description is merely some of the preferred embodiments of the present disclosure and a description of the principles of the technology used. Those skilled in the art should understand that the scope of the application involved in the embodiments of the present disclosure is not limited to the technical solutions formed by the specific combinations of the above technical features, and should also cover other technical solutions formed by any combination of the above technical features or equivalent features without departing from the above inventive concept. For example, the above features are replaced with each other to form a technical solution with similar functions disclosed in the embodiments of the present disclosure (but not limited to).

Claims

1. A terminal device control method based on abnormal flow linkage identification, comprising: Obtain the user's multi-source login association information set and the user's value object transfer information set; A knowledge graph is constructed from the user multi-source login association information set to obtain a user device association graph; The user equipment association graph is divided into graph segments to obtain a user login association sub-graph set; The user value object flow information set is subjected to flow relationship mining to obtain a flow relationship information set; Based on the user value object flow information set and the flow relationship information set, a user value object flow graph is generated; Based on the user login associated sub-graphet, abnormal flow linkage identification is performed on the user value object flow graph to obtain an abnormal flow linkage associated graphet. The abnormal flow association graph is sent to the flow alarm device to control the flow alarm device to monitor and warn the flow information of the value objects of the terminal device set corresponding to the abnormal flow association graph, and to control the flow interception of the terminal device set in response to the warning information issued by the flow alarm device.

2. The method according to claim 1, wherein, The step of constructing a knowledge graph from the user multi-source login association information set to obtain a user device association graph includes: Data fusion is performed on the user multi-source login association information set, which includes the user multi-source information set, to obtain user login association fusion information; The user login association fusion information is subjected to fuzzy identification of value object users to obtain a fuzzy value object user information set; The user login association fusion information is subjected to user identity disambiguation processing to obtain a user identity disambiguation information set; The fuzzy value object user information set and the user identity disambiguation information set are determined as the user entity information set; User device information is extracted from the value object order information set included in the user multi-source login association information set to obtain the user device entity information set; Determine the user equipment entity information set and the user equipment association relationship information set of the user entity information set; A user equipment association graph is generated based on the user entity information set, the user equipment entity information set, and the user equipment association relationship information set.

3. The method according to claim 1, wherein, The step of partitioning the user equipment association graph to obtain a user login association sub-graph set includes: Determine the degree set of user equipment nodes in the user equipment association graph; Based on the user equipment node degree set, determine the user equipment node access sequence; Based on the user equipment node access sequence, the following subgraph determination steps are performed: Based on the initial user equipment node, perform the following access graph generation steps: Based on the user equipment association graph, user equipment nodes located after the starting user equipment node are determined as user equipment depth nodes, wherein the starting user equipment node is the node located at the initial position in the node access sequence; Add the user equipment depth node and the starting user equipment node to the preset data stack to obtain the node access stack; In response to determining that the node access stack satisfies the node depth access condition, a node access graph is generated based on the starting user equipment node and the user equipment depth node. In response to the determination that the node access stack does not meet the node depth access conditions, the user equipment depth node is determined as the starting user equipment node, and the generation step is executed again; In response to the determination that the node unaccessed sequence is empty, the obtained node access graphs are determined as user login associated subgraph sets, wherein the node unaccessed sequence is the user device node access sequence after removing the corresponding access sequences of each node access graph; In response to the determination that the node unvisited sequence is not empty, the node unvisited sequence is determined as the user equipment node access sequence, and the determination step is performed again.

4. The method according to claim 1, wherein, The step of generating a user value object flow graph based on the user value object flow information set and the flow relationship information set includes: The user value object flow information set is preprocessed to obtain a preprocessed user value object flow information set. The preprocessed user value object flow information set is filtered to obtain the target value object flow information set; User profiles are constructed from the target value object flow information set to obtain a user flow indicator information set. Value object indicators are extracted from the target value object flow information set to obtain a value object indicator information set. The user flow indicator information set, the value object indicator information set, and the flow relationship information set are used to construct triplet sets to obtain flow triplet sets. The flow triplet set is input into a preset graph database to obtain a user value object flow graph.

5. The method according to claim 1, wherein, The step of identifying abnormal flow linkages in the user value object flow graph based on the user login association sub-graph set, to obtain an abnormal flow linkage association graph set, includes: Feature extraction is performed on the user value object node set and flow edge set included in the user value object flow graph to obtain the flow node feature vector set and flow edge feature vector set; Based on the user value object graph recognition layer included in the user value object graph recognition model, the following association graph generation steps are performed: The set of adjacent node feature vectors of the flow node feature vector set is determined, wherein the user value object graph recognition model includes a multi-layer user value object graph recognition layer; The flow edge feature vector set is input into the edge encoder included in the user value object graph recognition layer to obtain the edge encoded feature vector set. The user value object graph recognition layer also includes: a relationship-aware attention mechanism and a graph structure fusion layer. After concatenating the edge-encoded feature vector set and the adjacency-embedded feature vector set, a linear transformation is performed to obtain the concatenated transformed feature vector set. By utilizing a relation-aware attention mechanism, a set of relational attention weights is generated based on the set of concatenated transformation feature vectors and the set of transition node feature vectors. Through the graph structure fusion layer, the attention weight set of the association relationship and the set of splicing transformation feature vectors are fused to obtain the node fusion feature vector set; In response to the determination that the value object graph identification layer satisfies the model layer constraints, a flow linkage anomaly association graph set is generated based on the node fusion feature vector set and the user login association sub-graph set.

6. The method according to claim 5, wherein, The method further includes: In response to determining that the value object graph identification layer does not meet the model layer constraints, the value object graph identification layer located after the value object graph identification layer is determined as the value object graph identification layer; The node fusion feature vector set is determined as the flow node feature vector set; Each node fusion feature vector that has a target association relationship with each node fusion feature vector in the node fusion feature vector set is identified as an adjacent node feature vector, thus obtaining an adjacent node feature vector set, and the association graph generation step is executed again.

7. The method according to claim 5, wherein, The step of generating a flow linkage anomaly association graph set based on the node fusion feature vector set and the user login association subgraph set includes: From the set of node fusion feature vectors, node fusion feature vectors representing user nodes are selected to obtain the set of user node fusion feature vectors; For each user node fusion feature vector in the user node fusion feature vector set, perform the following anomaly association graph generation steps: Determine the user node similarity between the user node fusion feature vector and each node fusion feature vector in the set of node fusion feature vectors to obtain a user node similarity group; Based on the user node similarity group, the user node fusion feature vector set is filtered to obtain the filtered user node fusion feature vector set. Determine the set of user nodes that simultaneously exist in the user node fusion feature vector set after filtering and the user node set included in the user login association subgraph set to obtain the target user node set; Determine the percentage of user nodes in the target user node set and the user login associated subgraph set; In response to determining that the proportion of user nodes is greater than or equal to a preset node proportion threshold, a flow linkage anomaly association diagram is generated based on the target user node set.

8. A terminal equipment control device based on abnormal flow linkage identification, comprising: The acquisition unit is configured to acquire a set of user multi-source login association information and a set of user value object transfer information. The knowledge graph construction unit is configured to construct a knowledge graph from the user multi-source login association information set to obtain a user device association graph. The graph partitioning unit is configured to partition the user equipment association graph to obtain a user login association sub-graph set. The circulation relationship mining unit is configured to perform circulation relationship mining on the user value object circulation information set to obtain the circulation relationship information set. The generation unit is configured to generate a user value object flow map based on the user value object flow information set and the flow relationship information set; The abnormal flow linkage identification unit is configured to perform abnormal flow linkage identification on the user value object flow graph based on the user login association sub-graph set, and obtain the abnormal flow linkage association graph set. The flow interception control unit is configured to send the flow linkage anomaly association graph to the flow alarm device to control the flow alarm device to monitor and warn the flow information of the value objects of the terminal device set corresponding to the flow linkage anomaly association graph, and to control the flow interception of the terminal device set in response to the determination that the flow alarm device has issued a warning message.

9. An electronic device, comprising: One or more processors; Storage device, on which one or more programs are stored, When the one or more programs are executed by the one or more processors, the one or more processors implement the method as described in any one of claims 1-7.

10. A computer-readable medium having a computer program stored thereon, wherein, When the computer program is executed by a processor, it implements the method as described in any one of claims 1-7.

Citation Information

Patent Citations

  • Value object information sending method, device and equipment and computer readable medium

    CN116662672A

  • Information interception method and system based on abnormal traffic identification

    CN116684182A

Cited By

  • Terminal equipment control method and device, electronic equipment and computer readable medium

    CN121435092A

  • Terminal device control method and apparatus, electronic device, and computer readable medium

    CN121435092B

  • File carrying method, device and equipment based on diliary investigation information and medium

    CN121707517A

  • Equipment association method and device based on behavior blocking and probability matching

    CN122112353A